AUSF

Authentication Server Function

Security →
Introduced in Rel-15 Also in: Security, Services

AUSF is the 5G core network function that performs primary authentication and key agreement to verify subscriber identities and establish secure session keys for accessing services.

Category
Security
Introduced
Rel-15
Where
Core Network › 5G Core
Also touches
2 segments
Specifications
19 specs
AUSF Description Purpose Related Classification Detected Changes Specifications

Description

The Authentication Server Function (AUSF) is a critical component within the 5G Core (5GC) network's security architecture, specifically part of the Security Anchor Function (SEAF) framework. It resides in the home public land mobile network (HPLMN) and is responsible for executing the primary authentication procedure with the User Equipment (UE). The AUSF interfaces with the Unified Data Management (UDM) function to retrieve authentication credentials and subscription data, and with the Security Anchor Function (SEAF), typically co-located with the Access and Mobility Management Function (AMF) in the serving network, to relay authentication vectors and results. The AUSF does not store long-term credentials itself; instead, it acts as a relay and processing node that orchestrates the 5G Authentication and Key Agreement (5G-AKA) or Extensible Authentication Protocol (EAP)-based methods defined by 3GPP.

During the authentication procedure, when a UE attempts to register with the network, the SEAF/AMF requests authentication from the AUSF. The AUSF, in turn, interacts with the UDM/ARPF (Authentication Credential Repository and Processing Function) to obtain an authentication vector. This vector contains a random challenge (RAND), an expected response (XRES*), a network authentication token (AUTN), and the crucial keying material: the anchor key (K_AUSF). The AUSF forwards the RAND and AUTN to the UE via the SEAF. The UE computes a response (RES*) using its stored subscriber key and sends it back. The AUSF compares the received RES* with the XRES* from the UDM. Upon successful verification, the AUSF generates the primary session keys: K_SEAF (for the SEAF) and the anchor key K_AUSF, which serves as the root for deriving further keys for subsequent security contexts.

The AUSF's role is pivotal in establishing a chain of trust. The K_AUSF key it generates or receives becomes the root key for the entire security context of that registration session. From K_AUSF, further keys are derived for access network security (K_AMF), NAS signaling integrity and confidentiality, and user plane integrity (if enabled). This hierarchical key derivation ensures key separation and limits the impact of a key compromise. Furthermore, the AUSF supports re-authentication and key refresh procedures. Its architecture is designed as a stateless function, with the UDM holding the permanent state, which aids in scalability and reliability within cloud-native deployments.

A key architectural advancement in 5G is the separation of the authentication server (AUSF) from the subscription data repository (UDM). This enhances security by limiting the exposure of sensitive long-term keys and allows for independent scaling of authentication workloads. The AUSF also plays a role in supporting authentication for non-3GPP access (e.g., Wi-Fi) via the Non-3GPP InterWorking Function (N3IWF) and is integral to the security framework for network slicing, ensuring that authentication policies can be slice-specific. Its interfaces, such as Nausf (service-based interface) and N13 (reference point interface to the UDM), are defined for these interactions.

Purpose & Motivation

The AUSF was introduced in 3GPP Release 15 as a fundamental part of the new 5G Service-Based Architecture (SBA) to address evolving security requirements that were inadequately served by previous generations. In 4G EPS, the authentication function was integrated within the Home Subscriber Server (HSS) and Mobility Management Entity (MME) through the S6a interface. This monolithic approach presented limitations in scalability, flexibility, and security granularity. The 5G design principles demanded a more decomposed, cloud-native, and service-based architecture to support diverse use cases like massive IoT, ultra-reliable low-latency communications, and network slicing.

The primary purpose of the AUSF is to provide a dedicated, scalable function for executing robust primary authentication. By separating authentication from subscription data management (handled by the UDM), the system achieves a stronger security posture through the principle of least privilege. No single network function holds all sensitive data (long-term key and subscription profile), reducing the attack surface. This separation also allows the AUSF to be optimized for high-volume authentication transactions, which is critical for IoT scenarios with millions of devices. Furthermore, the AUSF enables the support of new, more flexible authentication methods like EAP-5G, which allows for integration with non-3GPP credentials and third-party authentication servers, a necessity for enterprise and industrial applications.

Another key motivation was to establish a permanent security anchor in the home network. The K_AUSF key generated during authentication remains stable in the home network even if the UE moves between different serving networks or access types (3GPP, non-3GPP). This 'home control' model enhances security by ensuring the home operator always verifies the subscriber's identity and controls the root of the key hierarchy. It solves the problem of key context transfer across network borders that existed in previous systems, providing a cleaner and more secure mobility security framework. The AUSF is, therefore, not just an evolutionary step but a foundational redesign for 5G security, enabling trust, scalability, and service flexibility.

Architecture

In the Network Map

Evolution Lineage

Classification

Part ofSEAF
Related approachesUDMAMF

Release Timeline

Detected Changes Across Releases

from 3GPP Change Requests

Specific changes extracted from the „Change history“ tables of 3GPP specifications (46 CRs across 5 releases). Complements the general historical overview above with the evidence-based evolution of this function.

Rel-15 14 changes

In Release 15, the AUSF was formally introduced as a new, standalone Authentication Server Function within the 5G Core's service-based architecture, exhibiting the Nausf service-based interface. Key introductions included its specific roles in authentication procedures with the UDM over the N13 reference point and the AMF over the N12 reference point, as well as its capability to be discovered and selected, including via mechanisms like the Routing Indicator in a SUCI. Furthermore, its functionality was defined to support scenarios like Credentials Holder authentication, where it interacts with a NSSAAF, and for Disaster Roaming service indications.

  • 5G Trace for AUSF TS 29.509CR0014
  • Supporting early trace in AUSF TS 23.501CR0791
  • AUSF clarification and alignment TS 23.501CR0302
  • UDM-AUSF Discovery TS 23.501CR0375
  • Update on AUSF service operation to support Steering of Roaming TS 23.501CR0536
  • Specify AUSF selection by UDM TS 23.501CR0548

+ 8 more changes

Rel-16 9 changes

In Release 16, the AUSF gained new capabilities for supporting Standalone Non-Public Networks (SNPNs), including procedures for AUSF discovery and selection within an SNPN and for UEs using credentials from a Credentials Holder. It introduced support for the UDM to initiate AUSF service invocation and added functionality for User Plane security policy (UPU) protection. Furthermore, the release defined the interaction between the AUSF and the Network Slice-Specific Authentication and Authorization Function (NSSAAF) to support Network Slice-Specific Authentication and Authorization (NSSAA).

  • eSBA communication schemas related to AUSF discovery and selection TS 23.501CR0803
  • UDM - AUSF Discovery & Selection in an SNPN TS 23.501CR1882
  • Replacing AUSF by NSSAAF to support NSSAA TS 23.501CR2372
  • Abbreviation of AUSF and UDM TS 24.501CR1608
  • UDM Initiated AUSF Service Invocation TS 29.503CR0401
  • Add UPU protection in AUSF functionality TS 29.509CR0072

+ 3 more changes

Rel-17 16 changes

In Release 17, the AUSF's role was expanded to support authentication for UEs using credentials from external Credentials Holders, introducing interactions with the NSSAAF and AAA Server via new reference points N83 and N60. It also gained enhanced capabilities for SNPN onboarding, including AUSF discovery based on SUCI information and serving UEs where a DCS includes an AUSF and UDM. Furthermore, specific corrections and clarifications were made, such as for the AKMA procedure involving K_AUSF and for the AUSF's operation in checking attributes within EAP-response/AKA'-challenge messages.

  • Reference point AUSF - NSSAAF TS 23.501CR3095
  • AUSF/UDM discovery based SUCI information TS 23.501CR3170
  • Interaction between AUSF and AAA Server TS 23.501CR2926
  • AUSF selection for an Onboarding UE TS 23.501CR2965
  • Evolution of SoR delivery mechanism – AUSF API Changes TS 29.509CR0108
  • selection of AUSF supporting primary authentication towards AAA server TS 23.501CR3139

+ 10 more changes

Rel-18 5 changes

In Release 18, the AUSF was enhanced to support Non-Seamless WLAN Offload (NSWO) in SNPNs both with and without a Credentials Holder. It was also updated to send the Master Session Key (MSK) to the Wireline Access Gateway Function (W-AGF) following successful EAP authentication. Furthermore, the AUSF's role in verifying the Serving Network Name was clarified and reinforced.

  • NSWO support in SNPN without CH and with CH using AUSF/UDM TS 33.501CR1756
  • AUSF sends back MSK to W-AGF after successful EAP authentication TS 33.501CR1810
  • Verification of the serving network name by the AUSF TS 33.501CR1876
  • Resolution of EN concerning indication from UDM to AUSF to select authentication with external credential holder TS 33.501CR1942
  • Serving Network Name check at AUSF TS 33.501CR2013
Rel-19 2 changes

In Release 19, the AUSF was enhanced to support the reallocation of its subscribers between instances and to enable its selection based on a Default Routing Indicator. These changes improve network management and routing flexibility, particularly for scenarios involving credentials from a Credentials Holder.

  • AUSF subscribers reallocation TS 29.503CR1481
  • AUSF Selection with Default Routing Indicator TS 23.501CR6471

Explore further

Broader topics and technologies where AUSF plays a role.

Defining Specifications

3GPP specifications that define or reference AUSF, with the latest known release. Sourced from the 3GPP document catalog — see methodology.

SpecificationTitleRelease
TS 23.501 vk00 5G System Architecture Stage 2 Rel-20
TR 23.758 vh00 Study on Edge Application Architecture Rel-17
TS 24.501 vj50 5G NAS Protocols Specification Rel-19
TS 24.502 vj20 5G Core Access via Non-3GPP Networks; Stage 3 Rel-19
TS 26.891 vg00 Media Distribution Services in 5G System Rel-16
TS 29.503 vj50 UDM Service Based Interface Stage 3 Rel-19
TS 29.509 vj50 AUSF Service Based Interface Protocol Rel-19
TS 29.535 vj40 5G AKMA Anchor Services Stage 3 Protocol Rel-19
TS 32.255 vk10 Telecom Management; Charging for 5G Data Connectivity Rel-20
TS 33.127 vj50 Lawful Interception Architecture and Functions Rel-19
TS 33.501 vk00 5G Security Architecture and Procedures Rel-20
TS 33.514 vk00 5G Security Assurance for UDM Rel-20
TS 33.535 vj00 5G AKMA: Authentication and Key Management for Apps Rel-19
TS 33.545 vj20 Security for NR Femto Subsystem Rel-19
TS 33.701 vj00 Study on mitigations against bidding down attacks Rel-19
TR 33.739 vi10 Study on security enhancement of support for Rel-18
TR 33.741 vi01 Home Network Triggered Authentication Rel-18
TS 33.794 vj10 Study on Zero Trust Security Enablers for 5G Rel-19
TS 33.835 vg10 Study on authentication and key management for apps Rel-16
Patrick Zandl

About the author: Patrick Zandl (b. 1974)

Telecommunications specialist, technology journalist (founder of the Mobil server), and developer who has been running since 2025 — the largest Czech-language resource on AI-assisted programming. Formerly Chief Wizard Architect at Prusa3D and head of development for Turris at CZ.NIC; currently a consultant and instructor on AI implementation in companies.