ERP

EAP Re-authentication Protocol

Security →
Introduced in Rel-5 Also in: Radio Access Network, Core Network, User Equipment

ERP is a protocol that enables fast re-authentication without a full EAP exchange, reducing signaling overhead and latency for seamless mobility during handovers in 3GPP and non-3GPP networks.

Category
Security
Introduced
Rel-5
Where
Services › Codecs
Also touches
3 segments
Specifications
25 specs
ERP Description Purpose Related Classification Specifications

Description

The EAP Re-authentication Protocol (ERP) is a security protocol defined within the Extensible Authentication Protocol (EAP) framework, standardized by the IETF and adopted by 3GPP. Its primary function is to perform a lightweight re-authentication of an already authenticated peer (e.g., a UE) when it moves between access points or needs to refresh its security context, without executing the computationally intensive and time-consuming full EAP method again. ERP achieves this by leveraging cryptographic material derived from the initial, full EAP authentication, specifically the Master Session Key (MSK) and Extended Master Session Key (EMSK). From these keys, a Re-authentication Root Key (rRK) and subsequently a Re-authentication Integrity Key (rIK) and Re-authentication Encryption Key (rEK) are derived, forming a secure basis for the abbreviated exchange.

Architecturally, ERP involves three entities: the peer (UE), the authenticator (e.g., an access point or eNodeB/gNodeB), and the backend authentication server (e.g., an AAA server). The protocol operates by the peer initiating a re-authentication request using a dedicated EAP method, EAP-Initiate/Re-auth. This request is processed locally by the authenticator if it holds the necessary rIK, or is forwarded to the backend server. The exchange involves a minimal number of messages, typically just a request and a response, which include cryptographically protected sequence numbers and identifiers to prevent replay attacks. Successful completion results in the derivation of fresh keying material (a new MSK) for the new session, ensuring forward secrecy.

ERP's role in the 3GPP ecosystem is integral to enabling secure and fast handovers, particularly in scenarios involving non-3GPP access (like Wi-Fi) interworking with the 3GPP core, as defined in Access Network Discovery and Selection Function (ANDSF) and Non-3GPP InterWorking Function (N3IWF) architectures. It is a key component for optimizing the performance of authentication, authorization, and accounting (AAA) procedures during mobility events. By drastically reducing the authentication latency from potentially hundreds of milliseconds to tens of milliseconds, ERP directly contributes to improved user experience for latency-sensitive applications and supports the seamless mobility requirements of 5G and beyond systems.

Purpose & Motivation

ERP was created to address the significant performance bottleneck posed by full EAP authentication during frequent mobility events. In mobile networks, especially with the proliferation of heterogeneous access (e.g., switching between cellular and Wi-Fi), a device may need to re-authenticate often. A full EAP exchange involves multiple round-trips to a potentially distant AAA server, introducing substantial latency and signaling load on both the radio and core networks. This could severely degrade service continuity, causing perceptible interruptions in voice or video calls during handovers.

The motivation stemmed from the need for a standardized, cryptographically sound method to re-establish trust and session keys quickly. Prior to ERP, solutions were often vendor-specific or relied on stateful context transfer between network nodes, which had scalability and security limitations. ERP provides a stateless, protocol-based solution where the security of the re-authentication is rooted in the keys from the initial authentication. Its development was driven by requirements from 3GPP's work on System Architecture Evolution (SAE) and later 5G, which mandate efficient secure mobility across multiple access technologies.

By solving the re-authentication latency problem, ERP enables practical implementation of features like seamless offload to trusted and untrusted non-3GPP networks, fast reconnection after brief disconnections, and efficient support for massive numbers of IoT devices that may frequently sleep and wake. It is a foundational element for achieving the low-latency and high-reliability goals of modern cellular systems.

Classification

Part ofEAP
Related approachesAAAN3IWF

Release Timeline

Evolution Across Releases

Rel-5 Initial

ERP was initially introduced in 3GPP Release 5 as part of the work on Wireless Local Area Network (WLAN) interworking. The initial architecture integrated the IETF-defined ERP protocol to enable fast re-authentication for UEs moving between WLAN access points, establishing the foundational use case for reducing AAA signaling latency in heterogeneous networks.

With the introduction of the Evolved Packet Core (EPC) and the requirement for seamless mobility between 3GPP LTE and non-3GPP accesses, ERP's role was solidified. Its specifications were enhanced to work within the new S2a (Trusted non-3GPP) and S2b (Untrusted non-3GPP) interfaces, ensuring fast re-authentication was a core part of the mobility and security framework for LTE.

Enhancements for LTE-WLAN Aggregation (LWA) and LTE-WLAN Radio Level Integration (LWIP) leveraged ERP to support fast and secure switching of data flows between LTE and WLAN links. This required optimizations to handle simultaneous connections and context management, further integrating ERP into radio-level integration scenarios.

For 5G, ERP was adapted to support secure and efficient access via the Non-3GPP InterWorking Function (N3IWF) in the 5G Core network. The protocol's principles were applied to enable fast re-authentication for UEs connecting over untrusted non-3GPP access (e.g., public Wi-Fi) to the 5G core, which is critical for supporting 5G's seamless mobility and service-based architecture.

Explore further

Broader topics and technologies where ERP plays a role.

Defining Specifications

3GPP specifications that define or reference ERP, with the latest known release. Sourced from the 3GPP document catalog — see methodology.

SpecificationTitleRelease
TR 21.905 vj00 3GPP Technical Terms and Definitions Rel-19
TR 22.804 vg30 5G Automation in Vertical Domains Study Rel-16
TR 22.832 vh40 Study on cyber-physical control in vertical domains Rel-17
TS 23.003 vj50 Numbering, addressing and identification in 3GPP Rel-19
TS 24.302 vj00 Access to EPC via non-3GPP networks; Stage 3 Rel-19
TS 26.114 vj10 IMS Multimedia Telephony Media Handling Rel-19
TS 26.118 vj00 Virtual Reality Media Formats Rel-19
TS 26.131 vj00 Terminal Acoustic Performance Requirements Rel-19
TS 26.132 vj00 Terminal Acoustic Test Methods Rel-19
TR 26.918 vj00 Virtual Reality Relevance Study for 3GPP Rel-19
TR 26.926 vj00 Traffic Models & Quality Evaluation for Media/XR in 5G Rel-19
TR 26.928 vj00 Study on eXtended Reality (XR) in 5G Rel-19
TR 26.955 vj00 Video Codec Analysis for 5G Services Rel-19
TR 26.956 vj01 Beyond 2D Video Formats & Codecs Study Rel-19
TR 26.962 vj00 ITT4RT Operation and Usage Guidelines Rel-19
TR 26.998 vj00 5G AR/MR Glasses Integration Study Rel-19
TS 29.273 vj10 AAA Protocols for Non-3GPP Access in EPS & 5GS NSWO Rel-19
TS 33.402 vj00 Security for non-3GPP access to EPS Rel-19
TS 36.755 vf00 US 600 MHz LTE Band 71 Technical Report Rel-15
TS 36.761 vf00 Extended-Band 12 Study Report Rel-15
TR 36.779 vh00 Upper 700MHz A Block E-UTRA Band Rel-17
TS 36.790 vf00 LAA/eLAA for CBRS 3.5GHz Band in US Rel-15
TR 37.843 vf70 AAS BS Radiated RF Requirement Background Rel-15
TR 38.892 vi00 Technical Report Rel-18
TS 43.050 vj00 GSM Transmission Planning for Speech Services Rel-19
Patrick Zandl

About the author: Patrick Zandl (b. 1974)

Telecommunications specialist, technology journalist (founder of the Mobil server), and developer who has been running since 2025 — the largest Czech-language resource on AI-assisted programming. Formerly Chief Wizard Architect at Prusa3D and head of development for Turris at CZ.NIC; currently a consultant and instructor on AI implementation in companies.