SEAF

Security Anchor Functionality

Security →
Introduced in Rel-15 Also in: Core Network

SEAF is the primary security anchor point within the 5G serving network, part of the AUSF, managing authentication and key agreement procedures with the UE.

Category
Security
Introduced
Rel-15
Where
Security
Also touches
1 segments
Specifications
6 specs
SEAF Description Purpose Related Classification Detected Changes Specifications

Description

The Security Anchor Functionality (SEAF) is a fundamental security component within the 5G System (5GS) architecture, defined as a sub-function of the Authentication Server Function (AUSF). Its primary role is to serve as the security termination point in the serving network during primary authentication and key agreement (AKA) procedures. The SEAF does not perform authentication calculations itself but orchestrates the process by interacting with the home network's Authentication Credential Repository and Processing Function (ARPF/UDM). It receives authentication vectors from the home network and uses them to authenticate the User Equipment (UE). Upon successful authentication, the SEAF derives the anchor key (K_SEAF) from the home network key (K_AUSF), establishing a security association rooted in the serving network. This K_SEAF is then used to derive further keys for securing Non-Access Stratum (NAS) signaling between the UE and the Access and Mobility Management Function (AMF). The SEAF's location in the serving network is crucial for security localization, reducing latency and dependency on the home network for subsequent security procedures like re-authentication and key refresh. Architecturally, the SEAF is co-located with the AUSF, and its interfaces, such as Nausf, are used for communication with the AMF. Its operation is central to the 5G security framework, providing a clear separation between home and serving network security responsibilities and enabling features like seamless mobility and network slicing with isolated security contexts.

Purpose & Motivation

The SEAF was introduced in 3GPP Release 15 as part of the new 5G security architecture to address limitations of previous generations, particularly 4G EPS. In EPS, the MME in the serving network acted as the security endpoint, which created a complex key hierarchy and potential vulnerabilities during inter-MME handovers. The primary motivation for SEAF was to provide a dedicated, stable security anchor in the serving network that is separate from the mobility management function (AMF). This separation of concerns enhances security by isolating the long-term anchor key (K_SEAF) and simplifies key management during mobility events. It solves the problem of key chaining and reduces the attack surface by localizing the primary security context. Furthermore, the SEAF design supports the 5G requirement for serving network visibility and control over authentication, which is essential for regulatory compliance and enabling new business models like network slicing, where each slice may require independent security anchoring from the serving network's perspective.

Classification

Part ofAMF
Specific typesAUSF
Related approachesAUSF

Release Timeline

Detected Changes Across Releases

from 3GPP Change Requests

Specific changes extracted from the „Change history“ tables of 3GPP specifications (2 CRs across 2 releases). Complements the general historical overview above with the evidence-based evolution of this function.

Rel-15 1 change

In Release 15, the SEAF (Security Anchor Functionality) was formally introduced as a key network function for establishing security in the 5G core. Its role includes anchoring the security context when a User Equipment connects via NG-RAN and managing independent NAS security contexts for multiple concurrent N1 connections, such as over standalone non-3GPP access. The updates also clarified the SEAF's requirements and its role in providing transport for SMS messages between the UE and the SMSF.

  • Update on SEAF requirements TS 33.501CR0223
Rel-16 1 change

In Release 16, the primary update for the Security Anchor Functionality (SEAF) was a clarification of its operation. This clarification addressed scenarios where a User Equipment (UE) is connected via both a NG-RAN and a standalone non-3GPP access, specifying that multiple N1 instances are secured using independent NAS security contexts. Each of these security contexts is created based on the security context held in its corresponding SEAF.

Explore further

Broader topics and technologies where SEAF plays a role.

Defining Specifications

3GPP specifications that define or reference SEAF, with the latest known release. Sourced from the 3GPP document catalog — see methodology.

SpecificationTitleRelease
TS 23.501 vk00 5G System Architecture Stage 2 Rel-20
TS 29.509 vj50 AUSF Service Based Interface Protocol Rel-19
TS 33.501 vk00 5G Security Architecture and Procedures Rel-20
TR 33.741 vi01 Home Network Triggered Authentication Rel-18
TS 33.835 vg10 Study on authentication and key management for apps Rel-16
TR 33.841 vg10 Security aspects; Study on 256-bit algorithms for 5G Rel-16
Patrick Zandl

About the author: Patrick Zandl (b. 1974)

Telecommunications specialist, technology journalist (founder of the Mobil server), and developer who has been running since 2025 — the largest Czech-language resource on AI-assisted programming. Formerly Chief Wizard Architect at Prusa3D and head of development for Turris at CZ.NIC; currently a consultant and instructor on AI implementation in companies.