Site icon Techplayon

5G Authentication and Key Management | 5G-AKA

5G Authentication and Key Management

Secure communication in any cellular network can be achieved with help of AKA procedure.  AKA is Authentication and Key Management procedure which involve mutual authentication between User Device and the network and derive crypto keys to protect the U-plane and C-plane data. Each  telecom “G” defines some authentication method to allow only legitimate users to access network and reject un-authorized users. 3GPP defined EPS-AKA for 4G LTE and similarly for 5G following three authentication methods are defined

Why we need new AKA procedures in 5G?

Security and privacy concerns are very critical and importance for any new technology to succeed. 5G networks availability is becoming reality throughout the world and new use cases are getting introduced. Security and privacy issues with previous “G” RANs network, have been extensively studied by Security Experts and Researchers. A few of such issues are listed below.

To mitigate such issues, standardization bodies like 3GPP has defined  an AKA protocol and procedures that support user authentication, signaling integrity, and signaling confidentiality, among other security properties. The 3GPP AKA protocol works on challenge-and-response authentication protocol based on a symmetric key shared between a User and a Network. After the mutual authentication between a User and a home network, crypto keys are derived to protect further communication between a User and a serving network, including C-plane and U-plane data.

5G AKA Framework

3GPP has proposed a Service Based Architecture for Core network with new network entities and new services to support a unified authentication framework. This framework makes 5G AKA procedure suitable for both open and access-network agnostic using three authentication methods namely 5G-AKA, EAP-AKA’, and EAP-TLS. The Frameworks allows multiple security contexts which can be established with one authentication execution, allowing the UE to move from a 3GPP access network to a non-3GPP network without having to be reauthenticated. The framework includes following network function within Core network relevant to 5G authentication.

5G-AKA Authentication Procedure

3GPP has defined new authentication-related services for 5G. For example, the AUSF provides authentication service through Nausf_UEAuthentication, and UDM provides its authentication service through Nudm_UEAuthentication services. Following figures show the sequence and authentication vector including a subset of data.

5G AKA and EAP-AKA’ are mandatory 5G primary authentication methods. Other EAP based authentication methods can be used optionally as well. To keep it simple for understanding lets us divide the authentication procedure in two phases.
two phases, see Figure 5.

5G and 4G Authentication and Key Management Comparison

Related Posts



Exit mobile version