Glossary term · Security

AUSF

Authentication Server Function

Security →

AUSF is the 5G core network function that performs primary authentication and key agreement to verify subscriber identities and establish secure session keys.

Introduced
Rel-15
Where
Core Network › 5G Core
Specifications
19 specs
Also in
Security, Services
Category
Security
Introduced
Rel-15
Where
Core Network › 5G Core
Also touches
2 segments
Specifications
19 specs
AUSF Description Purpose Related Classification Detected Changes Specifications

Description

The Authentication Server Function (AUSF) is a critical component within the 5G Core (5GC) network's security architecture, specifically part of the Security Anchor Function (SEAF) framework. It resides in the home public land mobile network (HPLMN) and is responsible for executing the primary authentication procedure with the User Equipment (UE). The AUSF interfaces with the Unified Data Management (UDM) function to retrieve authentication credentials and subscription data, and with the Security Anchor Function (SEAF), typically co-located with the Access and Mobility Management Function (AMF) in the serving network, to relay authentication vectors and results. The AUSF does not store long-term credentials itself; instead, it acts as a relay and processing node that orchestrates the 5G Authentication and Key Agreement (5G-AKA) or Extensible Authentication Protocol (EAP)-based methods defined by 3GPP.

During the authentication procedure, when a UE attempts to register with the network, the SEAF/AMF requests authentication from the AUSF. The AUSF, in turn, interacts with the UDM/ARPF (Authentication Credential Repository and Processing Function) to obtain an authentication vector. This vector contains a random challenge (RAND), an expected response (XRES*), a network authentication token (AUTN), and the crucial keying material: the anchor key (K_AUSF). The AUSF forwards the RAND and AUTN to the UE via the SEAF. The UE computes a response (RES*) using its stored subscriber key and sends it back. The AUSF compares the received RES* with the XRES* from the UDM. Upon successful verification, the AUSF generates the primary session keys: K_SEAF (for the SEAF) and the anchor key K_AUSF, which serves as the root for deriving further keys for subsequent security contexts.

The AUSF's role is pivotal in establishing a chain of trust. The K_AUSF key it generates or receives becomes the root key for the entire security context of that registration session. From K_AUSF, further keys are derived for access network security (K_AMF), NAS signaling integrity and confidentiality, and user plane integrity (if enabled). This hierarchical key derivation ensures key separation and limits the impact of a key compromise. Furthermore, the AUSF supports re-authentication and key refresh procedures. Its architecture is designed as a stateless function, with the UDM holding the permanent state, which aids in scalability and reliability within cloud-native deployments.

A key architectural advancement in 5G is the separation of the authentication server (AUSF) from the subscription data repository (UDM). This enhances security by limiting the exposure of sensitive long-term keys and allows for independent scaling of authentication workloads. The AUSF also plays a role in supporting authentication for non-3GPP access (e.g., Wi-Fi) via the Non-3GPP InterWorking Function (N3IWF) and is integral to the security framework for network slicing, ensuring that authentication policies can be slice-specific. Its interfaces, such as Nausf (service-based interface) and N13 (reference point interface to the UDM), are defined for these interactions.

Purpose & Motivation

The AUSF was introduced in 3GPP Release 15 as a fundamental part of the new 5G Service-Based Architecture (SBA) to address evolving security requirements that were inadequately served by previous generations. In 4G EPS, the authentication function was integrated within the Home Subscriber Server (HSS) and Mobility Management Entity (MME) through the S6a interface. This monolithic approach presented limitations in scalability, flexibility, and security granularity. The 5G design principles demanded a more decomposed, cloud-native, and service-based architecture to support diverse use cases like massive IoT, ultra-reliable low-latency communications, and network slicing.

The primary purpose of the AUSF is to provide a dedicated, scalable function for executing robust primary authentication. By separating authentication from subscription data management (handled by the UDM), the system achieves a stronger security posture through the principle of least privilege. No single network function holds all sensitive data (long-term key and subscription profile), reducing the attack surface. This separation also allows the AUSF to be optimized for high-volume authentication transactions, which is critical for IoT scenarios with millions of devices. Furthermore, the AUSF enables the support of new, more flexible authentication methods like EAP-5G, which allows for integration with non-3GPP credentials and third-party authentication servers, a necessity for enterprise and industrial applications.

Another key motivation was to establish a permanent security anchor in the home network. The K_AUSF key generated during authentication remains stable in the home network even if the UE moves between different serving networks or access types (3GPP, non-3GPP). This 'home control' model enhances security by ensuring the home operator always verifies the subscriber's identity and controls the root of the key hierarchy. It solves the problem of key context transfer across network borders that existed in previous systems, providing a cleaner and more secure mobility security framework. The AUSF is, therefore, not just an evolutionary step but a foundational redesign for 5G security, enabling trust, scalability, and service flexibility.

Architecture

In the Network Map

Evolution Lineage

Classification

Part ofSEAF
Related approachesUDMAMF

Release Timeline

Detected Changes Across Releases

from 3GPP Change Requests

Specific changes extracted from the „Change history“ tables of 3GPP specifications (34 CRs across 4 releases). Complements the general historical overview above with the evidence-based evolution of this function.

Rel-15 13 changes
  • 5G Trace for AUSF TS 29.509CR0014
  • Supporting early trace in AUSF TS 23.501CR0791
  • AUSF clarification and alignment TS 23.501CR0302
  • UDM-AUSF Discovery TS 23.501CR0375
  • Update on AUSF service operation to support Steering of Roaming TS 23.501CR0536
  • Specify AUSF selection by UDM TS 23.501CR0548

+ 7 more changes

Rel-16 8 changes
  • eSBA communication schemas related to AUSF discovery and selection TS 23.501CR0803
  • UDM - AUSF Discovery & Selection in an SNPN TS 23.501CR1882
  • Replacing AUSF by NSSAAF to support NSSAA TS 23.501CR2372
  • UDM Initiated AUSF Service Invocation TS 29.503CR0401
  • Add UPU protection in AUSF functionality TS 29.509CR0072
  • AUSF service update for the authentication result removal TS 29.509CR0083

+ 2 more changes

Rel-17 11 changes
  • Reference point AUSF - NSSAAF TS 23.501CR3095
  • AUSF/UDM discovery based SUCI information TS 23.501CR3170
  • Interaction between AUSF and AAA Server TS 23.501CR2926
  • AUSF selection for an Onboarding UE TS 23.501CR2965
  • Evolution of SoR delivery mechanism – AUSF API Changes TS 29.509CR0108
  • selection of AUSF supporting primary authentication towards AAA server TS 23.501CR3139

+ 5 more changes

Rel-19 2 changes
  • AUSF subscribers reallocation TS 29.503CR1481
  • AUSF Selection with Default Routing Indicator TS 23.501CR6471

Explore further

Broader topics and technologies where AUSF plays a role.

Defining Specifications

3GPP specifications that define or reference AUSF, with the latest known release. Sourced from the 3GPP document catalog — see methodology.

SpecificationTitleRelease
TS 23.501 vk20 5G System Architecture Stage 2 Rel-20
TR 23.758 vh00 Study on Edge Application Architecture Rel-17
TS 24.501 vk00 5G System (5GS) Non-Access Stratum (NAS) Protocol Rel-20
TS 24.502 vk00 Non-3GPP Access Network Discovery and Selection Rel-20
TS 26.891 vg00 Media Distribution Services in 5G System Rel-16
TS 29.503 vk00 UDM Service Based Interface Stage 3 Rel-20
TS 29.509 vk00 3GPP TS 29509: Nausf Service Based Interface Rel-20
TS 29.535 vk00 AAnF AKMA Service Interface Rel-20
TS 32.255 vk20 5G Data Connectivity Charging Rel-20
TS 33.127 vj70 Lawful Interception Architecture and Functions Rel-19
TS 33.501 vk20 5G Security Architecture and Procedures Rel-20
TS 33.514 vk10 3GPP TS 33514 vk10: UDM Network Product Security Requirements Rel-20
TS 33.535 vj00 5G AKMA: Authentication and Key Management for Apps Rel-19
TS 33.545 vk00 Security Architecture for NR Femto Subsystem Rel-20
TS 33.701 vj00 Study on mitigations against bidding down attacks Rel-19
TR 33.739 vi10 Study on security enhancement of support for Rel-18
TR 33.741 vi01 Home Network Triggered Authentication Rel-18
TS 33.794 vj10 Study on Zero Trust Security Enablers for 5G Rel-19
TS 33.835 vg10 Study on authentication and key management for apps Rel-16