RFC Reference Library
RFC 3748
EAPExtensible Authentication Protocol — base framework for EAP-AKA/EAP-AKA', defines method negotiation, identity exchange, success/failure, and transport layer independence
RFC 4187
EAP-AKAEAP Method for 3GPP UMTS Authentication and Key Agreement — USIM-based authentication for non-3GPP access, AT_RAND/AT_AUTN/AT_RES exchange, key derivation (MSK/EMSK)
RFC 5448
EAP-AKA'Improved EAP-AKA for 3GPP — adds key binding to access network name (AT_KDF_INPUT), prevents re-authentication key misuse across serving networks, mandatory for 5G
RFC 9048
EAP-AKA' UpdatesImproved EAP-AKA' Identity Handling — updates for 5G: SUCI-based privacy, bidding-down prevention, alignment with TS 33.501 authentication procedures
RFC 3310
HTTP Digest AKAHTTP Digest Authentication Using AKA — maps 3GPP AKA challenge/response into HTTP Digest, used in IMS (P-CSCF/S-CSCF) authentication procedures
RFC 8446
TLS 1.3The Transport Layer Security Protocol Version 1.3 — 1-RTT/0-RTT handshake, mandatory for 5G SBI (TS 29.500 §5.2), SEPP N32-c, NRF/NSSF discovery, forward secrecy via ephemeral DH
RFC 9325
TLS/DTLS Best PracticesRecommendations for TLS and DTLS — BCP 195, cipher suite recommendations, certificate validation, session resumption guidance referenced by 3GPP security profiles
RFC 6347
DTLS 1.2Datagram Transport Layer Security Version 1.2 — UDP-based TLS for SCTP-over-DTLS, used in Diameter transport and LTE eNB management interfaces
RFC 9147
DTLS 1.3The Datagram Transport Layer Security Protocol Version 1.3 — reduced handshake, connection ID support, 0-RTT data, aligned with TLS 1.3 cipher suites
RFC 4301
IPsec ArchitectureSecurity Architecture for the Internet Protocol — SAD/SPD/PAD model, tunnel/transport modes, traffic selectors; foundational for TS 33.210 NDS/IP per-interface GTP protection
RFC 4303
ESPIP Encapsulating Security Payload — encryption + integrity for IP packets, tunnel mode mandatory for GTP-U/GTP-C protection per TS 33.210 §5.3
RFC 4302
AHIP Authentication Header — connectionless integrity and data origin authentication for IP datagrams, inner header protection without encryption
RFC 7296
IKEv2Internet Key Exchange Protocol Version 2 — IKE_SA_INIT/IKE_AUTH exchanges, child SA negotiation, EAP integration; mandatory for TS 33.210 NDS/IP and ePDG/N3IWF tunnels
RFC 7383
IKEv2 FragmentationIKEv2 Message Fragmentation — handles large IKE messages (certificate chains, EAP payloads) that exceed path MTU, critical for PKI-based NDS deployments
RFC 5280
X.509 PKIInternet X.509 PKI Certificate and CRL Profile — certificate structure, extensions (SAN, KU, EKU), path validation algorithm; foundational for TS 33.310 NDS certificate profiles
RFC 4210
CMPv2Certificate Management Protocol — IR/CR/KUR/RR messages, proof-of-possession, RA model; used in TS 33.310 for NF certificate enrollment and renewal
RFC 7030
ESTEnrollment over Secure Transport — HTTPS-based certificate enrollment, simpleenroll/simplereenroll/cacerts operations; alternative to CMPv2 in TS 33.310
RFC 6960
OCSPOnline Certificate Status Protocol — real-time certificate revocation checking via HTTP, OCSP stapling, nonce-based replay prevention; referenced by TS 33.310 §6.2
RFC 6749
OAuth 2.0The OAuth 2.0 Authorization Framework — authorization code, client credentials, token endpoint; used in 5G SBI for NF-to-NF authorization via NRF (TS 29.510 / TS 33.501 §13.4)
RFC 6750
Bearer TokensThe OAuth 2.0 Authorization Framework: Bearer Token Usage — HTTP Authorization header, token transport, threat model for bearer tokens in SBI
RFC 7519
JWTJSON Web Token — compact claims representation (iss, sub, aud, exp), used in 5G access tokens for NF service authorization, SEPP N32-f message protection
RFC 7515
JWSJSON Web Signature — digital signature / MAC over JWS payload with compact/JSON serialization; used in SEPP N32-f PRINS for inter-PLMN message integrity
RFC 7516
JWEJSON Web Encryption — content encryption with authenticated encryption (AEAD), key wrapping; used in SEPP N32-f for inter-PLMN message confidentiality
RFC 7517
JWKJSON Web Key — JSON data structure for cryptographic keys (RSA, EC, symmetric), JWK Set for key management, key ID (kid) for rotation
RFC 7518
JWAJSON Web Algorithms — algorithm registry: RS256/ES256 for JWS, A128GCM/A256GCM for JWE, ECDH-ES for key agreement; mandated algorithms for 5G SEPP profiles
RFC 9113
HTTP/2HTTP/2 — binary framing, stream multiplexing, server push, HPACK compression; mandatory transport for 5G SBI (TS 29.500 §5.2.1), all NF-to-NF communication
RFC 7541
HPACKHPACK: Header Compression for HTTP/2 — Huffman coding, static/dynamic table, indexing; integral to HTTP/2 SBI performance and CRIME attack mitigation
RFC 9110
HTTP SemanticsHTTP Semantics — methods (GET/POST/PUT/PATCH/DELETE), status codes, content negotiation, conditional requests; defines the API contract for all 5G SBI services
RFC 8259
JSONThe JavaScript Object Notation (JSON) Data Interchange Format — serialization format for all SBI request/response bodies in 5G core
RFC 9114
HTTP/3HTTP/3 — HTTP over QUIC, eliminates head-of-line blocking, 0-RTT connection setup, QPACK header compression; future candidate for SBI transport
RFC 9000
QUICQUIC: A UDP-Based Multiplexed and Secure Transport — integrated TLS 1.3, per-stream flow control, connection migration, 0-RTT; foundation for HTTP/3
RFC 9001
QUIC TLSUsing TLS to Secure QUIC — TLS 1.3 integration, 4 encryption levels, header protection, key derivation (quic key/iv/hp), key update mechanism
RFC 9260
SCTPStream Control Transmission Protocol — multi-homing, multi-streaming, message-oriented transport; mandatory for NGAP (N2), XnAP, S1AP, and Diameter in 3GPP networks
RFC 6083
DTLS for SCTPDTLS for Stream Control Transmission Protocol — per-association security, replay protection, key management for SCTP-based signaling where IPsec is not used
RFC 4895
SCTP AUTHAuthenticated Chunks for SCTP — AUTH chunk with HMAC-SHA1/SHA-256, per-chunk authentication without IPsec, protects dynamic address reconfiguration
RFC 6733
Diameter BaseDiameter Base Protocol — peer-to-peer AAA framework, AVP encoding, CER/CEA/DWR/DWA, transport (TCP/SCTP + TLS/DTLS); used on S6a, Gx, Gy, Rx interfaces in EPC
RFC 4006
Credit-ControlDiameter Credit-Control Application — real-time credit/charging (CCR/CCA), unit reservation, Gy interface for online charging in EPC/5G
RFC 7155
NASREQDiameter NASREQ Application — Network Access Server authentication/authorization, RADIUS-to-Diameter gateway support, EAP integration
RFC 2865
RADIUSRemote Authentication Dial In User Service — request/response AAA, Access-Request/Accept/Reject, attribute encoding; legacy AAA still present in many operator networks
RFC 3579
RADIUS EAPRADIUS Support for EAP — EAP-Message/Message-Authenticator attributes, EAP over RADIUS transport for WLAN interworking and 3GPP AAA
RFC 3580
802.1X RADIUS802.1X RADIUS Usage Guidelines — dynamic VLAN assignment, session management, key distribution for carrier WLAN 802.1X deployments
RFC 2782
DNS SRVA DNS RR for Service Location (SRV) — priority/weight-based service selection, used for Diameter peer discovery and IMS DNS-based NF resolution
RFC 4033
DNSSEC IntroDNS Security Introduction and Requirements — DNSSEC overview, threat model, trust anchors, chain of trust; protects DNS-based NF discovery from spoofing
RFC 6891
EDNS(0)Extension Mechanisms for DNS — OPT pseudo-RR, larger UDP payload sizes, extension flags; required for DNSSEC-enabled environments in operator DNS infrastructure
RFC 3261
SIPSIP: Session Initiation Protocol — INVITE/REGISTER/BYE transactions, proxy/registrar/UA roles, dialog state machines; core signaling protocol for 3GPP IMS
RFC 3329
SIP Security AgreementSecurity Mechanism Agreement for SIP — Security-Client/Server/Verify headers, IPsec-3gpp mechanism negotiation; mandatory for IMS UE registration security
RFC 3327
SIP Path ExtensionSIP Extension Header for Registering Non-Adjacent Contacts — Path header for SIP proxies in the registration path; used in IMS for P-CSCF routing
RFC 3455
3GPP SIP P-HeadersPrivate Header Extensions to SIP for 3GPP — P-Associated-URI, P-Called-Party-ID, P-Visited-Network-ID, P-Access-Network-Info headers for IMS
RFC 3711
SRTPSecure Real-time Transport Protocol — AES-CM encryption, HMAC-SHA1 authentication, replay protection for IMS VoLTE/VoNR media plane security (TS 33.328)
RFC 5213
PMIPv6Proxy Mobile IPv6 — network-based mobility management (LMA/MAG), PBU/PBA signaling, GRE/IPv6-in-IPv6 tunneling; basis for 3GPP S2a/S2b interfaces
RFC 5944
Mobile IPv4IP Mobility Support for IPv4 — HA/FA model, registration, tunneling; legacy mobility protocol referenced in 3GPP interworking scenarios
RFC 6275
Mobile IPv6Mobility Support in IPv6 — Binding Update/Ack, return routability, route optimization, Home Agent discovery; host-based mobility for dual-stack mobile IPv6
RFC 3386
Network HierarchyNetwork Hierarchy and Multilayer Survivability — framework for GTP tunnel survivability across physical, link, IP, and service layers in mobile networks
RFC 7049
CBORConcise Binary Object Representation — compact binary JSON-compatible encoding for constrained IoT devices, used in COSE/CWT for lightweight 3GPP IoT credentials
RFC 8949
CBOR (Updated)CBOR — updated specification with deterministic encoding, improved map handling, and editorial corrections for the Concise Binary Object Representation
RFC 7946
GeoJSONThe GeoJSON Format — geographic data structures (Point, Polygon, MultiPolygon); used in 5G for UE location services and NEF location API data models
RFC 5869
HKDFHMAC-based Extract-and-Expand Key Derivation Function — extract-then-expand paradigm; used in TLS 1.3, EAP-AKA', and 5G key hierarchy (K_AUSF→K_SEAF→K_AMF derivation chain)
RFC 4868
HMAC-SHA-256/384/512Using HMAC-SHA-256, HMAC-SHA-384, and HMAC-SHA-512 with IPsec — truncated MAC computation for ESP/AH authentication, mandatory algorithms for TS 33.210 cipher suites
RFC 3394
AES Key WrapAdvanced Encryption Standard Key Wrap Algorithm — KEK-based key transport (A128KW/A256KW), integrity-protected key wrapping used in JWE key management
RFC 5116
AEAD InterfaceAn Interface and Algorithms for Authenticated Encryption — AEAD abstraction (AES-GCM, AES-CCM), nonce management; mandated for TLS 1.3 and ESP cipher suites
RFC 6090
ECC FundamentalsFundamental Elliptic Curve Cryptography Algorithms — point arithmetic, ECDH key agreement, ECDSA signatures; underlying math for ES256/ES384 in JWS and TLS 1.3 key exchange
RFC 4120
Kerberos ISOKerberos Network Authentication Service (V5) — ticket-based mutual authentication using symmetric key cryptography via trusted third-party KDC
RFC 4511
LDAP ISOLightweight Directory Access Protocol (LDAP) v3 — directory services for centralized identity management, authentication, and access control
RFC 4252
SSH-Auth ISOSSH Authentication Protocol — public key, password, and keyboard-interactive authentication methods for secure remote access
RFC 4253
SSH ISOSSH Transport Layer Protocol — server authentication, encryption, and integrity for secure remote system administration
RFC 6376
DKIM ISODomainKeys Identified Mail — cryptographic email authentication using DNS-published public keys to verify sender domain identity
RFC 7208
SPF ISOSender Policy Framework — DNS-based email sender authorization, specifying which IPs may send email for a domain
RFC 7489
DMARC ISODomain-based Message Authentication, Reporting, and Conformance — policy framework unifying SPF and DKIM with reporting
RFC 8551
S/MIME ISOS/MIME 4.0 — end-to-end email encryption and digital signatures using public key cryptography for message confidentiality and integrity
RFC 5424
Syslog ISOSyslog Protocol — standardized logging framework for event notification messages, security monitoring, and compliance audit trails
RFC 5425
Syslog-TLS ISOTLS Transport for Syslog — secure, authenticated delivery of log messages over TLS for audit log integrity and confidentiality
RFC 5905
NTP ISONTPv4 — clock synchronization protocol critical for log correlation, certificate validation, Kerberos authentication, and forensic timelines
RFC 8484
DoH ISODNS over HTTPS — encrypted DNS resolution via HTTPS, preventing eavesdropping and manipulation of DNS queries
RFC 7858
DoT ISODNS over TLS — encrypted DNS resolution on dedicated port 853, providing confidentiality for enterprise DNS queries
RFC 8555
ACME ISOAutomatic Certificate Management Environment — automated certificate issuance, renewal, and revocation for zero-touch PKI operations at scale
Which RFCs reference which — showing key dependencies across the 3GPP-relevant RFC library. Read row→column: ✓ = row references column.
| 3748 | 4187 | 5448 | 8446 | 4301 | 4303 | 7296 | 5280 | 6749 | 7519 | 7515 | 9113 | 6733 | 9260 | 5869 | 3261 | |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| RFC 3748 EAP | — | · | · | · | · | · | · | · | · | · | · | · | · | · | · | · |
| RFC 4187 EAP-AKA | ✓ | — | · | · | · | · | · | · | · | · | · | · | · | · | · | · |
| RFC 5448 EAP-AKA' | ✓ | ✓ | — | · | · | · | · | · | · | · | · | · | · | · | ✓ | · |
| RFC 8446 TLS 1.3 | · | · | · | — | · | · | · | ✓ | · | · | · | · | · | · | ✓ | · |
| RFC 4301 IPsec | · | · | · | · | — | ✓ | ✓ | · | · | · | · | · | · | · | · | · |
| RFC 4303 ESP | · | · | · | · | ✓ | — | · | · | · | · | · | · | · | · | · | · |
| RFC 7296 IKEv2 | ✓ | · | · | · | ✓ | ✓ | — | ✓ | · | · | · | · | · | · | · | · |
| RFC 5280 X.509 | · | · | · | · | · | · | · | — | · | · | · | · | · | · | · | · |
| RFC 6749 OAuth 2.0 | · | · | · | · | · | · | · | · | — | · | · | · | · | · | · | · |
| RFC 7519 JWT | · | · | · | · | · | · | · | · | · | — | ✓ | · | · | · | · | · |
| RFC 7515 JWS | · | · | · | · | · | · | · | · | · | · | — | · | · | · | · | · |
| RFC 9113 HTTP/2 | · | · | · | ✓ | · | · | · | · | · | · | · | — | · | · | · | · |
| RFC 6733 Diameter | ✓ | · | · | · | ✓ | · | · | ✓ | · | · | · | · | — | ✓ | · | · |
| RFC 9260 SCTP | · | · | · | · | · | · | · | · | · | · | · | · | · | — | · | · |
| RFC 5869 HKDF | · | · | · | · | · | · | · | · | · | · | · | · | · | · | — | · |
| RFC 3261 SIP | · | · | · | · | · | · | · | ✓ | · | · | · | · | · | · | · | — |