5G/6G Academy

5G/6G Academy

Telecom certifications · since 2009

5G Auth Flow Visualizer

Step through 5G primary authentication — the 5G-AKA method and the EAP-AKA′ method side-by-side — across UE, SEAF (AMF), AUSF and UDM/ARPF. Based on 3GPP TS 33.501 §6.1 and RFC 5448.

Method:Message 1 / 14
UE
SEAF (AMF)
AUSF
UDM / ARPF
#1UE → SEAF (AMF)Registration Request
Mobile IdentitySUCI = scheme-output over SUPI
ngKSI3-bit key set identifier (0..6, 7 = no key)
UE security capabilities5G-EA / 5G-IA bitmap

About 5G primary authentication

3GPP TS 33.501 defines two mandatory primary authentication methods for 5G: 5G-AKAand EAP-AKA′. Both are rooted in the long-term key Kstored in the USIM and in the ARPF (part of UDM). Both derive the serving-network anchor key K_SEAF, from which all further NAS and AS keys (K_AMF, K_NASenc, K_NASint, K_gNB) are derived.

The key difference: 5G-AKA adds a second, lightweight verification at SEAF (comparing HRES* against HXRES*), letting the serving network drop obvious failures before going back to AUSF. EAP-AKA′ is a pure EAP method (RFC 5448) — SEAF is only a pass-through, and RES / MAC are checked at AUSF. EAP-AKA′ is mandatory for non-3GPP access (Wi-Fi offload to 5GC) and optional for 3GPP access.

In both flows, the UE’s permanent identity never travels in the clear. The SUCI (Subscription Concealed Identifier) uses ECIES to encrypt the MSIN portion of the SUPI with the home network’s public key, and only UDM/SIDF can de-conceal it — solving the IMSI-catcher problem that plagued earlier generations.

Who uses this visualizer?

Core-network and security engineers use it to map 3GPP stage-2 procedure text to the actual Nausf_UEAuthentication / Nudm_UEAuthentication service operations. Trainers use it in 5G certification courses. Penetration testers use it as a reference for which keys exist at which NF at each instant.

Related tools

7-Day Free Trial

Calculator gave you the answer? Learn the theory in 7 days, free.

$19.99/mo (global) · ₹999/mo (India). Full Pro access — 150+ hands-on exercises, 20+ troubleshooting Scenarios, 17 certifications, TelcoMentor AI coach. No credit card.

  • No credit card
  • Cancel anytime
  • Full Pro access
  • TELCOMA since 2009
Start My 7-Day Trial