A Practical Transition to Post-Quantum Security in 5G-AKA
An Braeken, Awaneesh Kumar Yadav, Jorge Munilla · IEEE Transactions on Information Forensics and Security · 2025
The current 5G-AKA protocol faces significant security challenges, including the lack of Perfect Forward Secrecy and Post-Quantum (PQ) security. In particular, the absence of PQ protection makes current communications vulnerable to future quantum adversaries who may decrypt stored messages once large-scale quantum computers become available. To mitigate this risk, a transition to PQ security must be implemented as soon as possible. Two primary approaches exist for this transition: (1) symmetric key-based techniques, which require a secure channel for key distribution, leading to increased costs, and (2) modern PQ public-key primitives, which offer stronger security but come with high communication overhead. In this paper, we propose a solution that leverages PQ cryptographic primitives for confidentiality and privacy protection, while retaining classical public-key cryptography for authentication. This approach is viable because digital signatures must be secure today, even if they are compromised in the future. Moreover, our framework allows for a seamless transition to fully PQ-secure authentication when quantum threats become imminent. In addition, the framework also supports the zero-trust architecture in which no secure channel between Serving Network (SN) and Home Network (HN) is assumed. We have carefully analysed the security of the proposed protocol using both informal and formal (Real-Or-Random (ROR) logic and Scyther Validation tool) methods. We also compared its performance in terms of computation, communication, and storage, and found that it performs better than existing protocols.