3GPP TS 23.501
System Architecture for the 5G System (5GS) — Stage 2
V18.6.0 (2024-06) 23-Series Architecture 1. Scope
▶Defines the overall 5G System (5GS) architecture including Network Functions, reference points (N-interfaces), service-based interfaces, network slicing, QoS framework, and session management. This is the master architecture specification that all 33-series security specs protect.
Security context: Every NF, interface, and procedure defined in TS 23.501 has corresponding security requirements in TS 33.501 and product-class SCAS documents (TS 33.511–33.527).
2. 5GS Architecture
▶
5G System Architecture — Reference Point Model:
┌─────┐
│ NSSF│
└──┬──┘
Nnssf │
┌─────┐ ┌─────────┤ ┌─────┐ ┌─────┐
│ NEF │ │ ┌─────┤ │ AUSF│ │ UDM │
└──┬──┘ │ │ │ └──┬──┘ └──┬──┘
Nnef │ │ │ │ Nausf│ Nudm │
───────────┤ ┌────┴───┴──┐ │ ┌───┴──┐ ┌─────┴──┐
├───┤ AMF ├──┤ │ AUSF │ │ UDM │
│ └────┬──────┘ │ └──────┘ └────────┘
│ N1 │ N2│ │
│ ┌────┘ │ │
│ │ ┌────┘ │
┌──────┐ │ ┌─┴──┐ │ ┌──────┴──┐ ┌─────┐
│ UE ├───┤ │ AN ├─┤ │ SMF ├────┤ PCF │
└──────┘ │ └────┘ │ └────┬────┘ └─────┘
│ N3 │ N4 │
│ │ ┌────┴────┐
│ │ │ UPF │──── N6 ──── DN
│ │ └─────────┘
│ │ N9
│ │ ┌─────────┐
│ │ │ UPF-I │ (Intermediate)
│ │ └─────────┘
5G System Architecture — Service-Based Representation:
┌────┐ ┌────┐ ┌────┐ ┌────┐ ┌────┐ ┌────┐ ┌────┐ ┌────┐ ┌────┐
│NSSF│ │ NEF│ │ NRF│ │ PCF│ │ UDM│ │ UDR│ │AUSF│ │ AMF│ │ SMF│
└──┬─┘ └──┬─┘ └──┬─┘ └──┬─┘ └──┬─┘ └──┬─┘ └──┬─┘ └──┬─┘ └──┬─┘
│ │ │ │ │ │ │ │ │
═══╪══════╪══════╪══════╪══════╪══════╪══════╪══════╪══════╪═══
Common SBI Bus (HTTP/2 + TLS)
Each NF exposes services on the SBI bus
NRF provides discovery & authorization
All NF-to-NF communication via RESTful APIs
3. Network Functions
▶| NF | Full Name | Key Responsibilities | Security Spec |
|---|---|---|---|
| AMF | Access & Mobility Mgmt | Registration, connection mgmt, NAS security, mobility | TS 33.515 |
| SMF | Session Management | PDU session establishment, QoS, UPF selection, PFCP | TS 33.518 |
| UPF | User Plane Function | Packet routing, PDR/FAR rules, GTP-U tunneling, QoS enforcement | TS 33.513 |
| AUSF | Authentication Server | 5G-AKA / EAP-AKA' execution, K_AUSF derivation | TS 33.516 |
| UDM | Unified Data Mgmt | Subscription data, auth credential generation, SUPI de-concealment | TS 33.514 |
| UDR | Unified Data Repository | Structured data storage for UDM, PCF, NEF | TS 33.117 (general) |
| NRF | NF Repository | NF registration, discovery, OAuth 2.0 token issuance | TS 33.521 |
| PCF | Policy Control | SM/AM/UE policies, QoS decisions, rate control | TS 33.520 |
| NEF | Network Exposure | External API exposure, monitoring events, SUPI translation | TS 33.519 |
| NSSF | Slice Selection | Slice selection for registration, AMF set selection | TS 33.117 (general) |
| SEPP | Security Edge Proxy | Inter-PLMN SBI protection (N32-c/N32-f), PRINS/TLS | TS 33.522 |
| SCP | Service Comm Proxy | SBI routing, load balancing, delegated discovery | TS 33.527 |
| gNB | gNodeB (5G RAN) | Radio access, PDCP/RLC/MAC, N2/N3 connectivity | TS 33.512 |
| ng-eNB | Next-gen eNodeB | LTE radio with 5GC connectivity (NSA/SA) | TS 33.511 |
4. Reference Points (N-Interfaces)
▶| Interface | Between | Protocol | Security |
|---|---|---|---|
| N1 | UE ↔ AMF | NAS (5G-MM, 5G-SM) | NAS encryption + integrity |
| N2 | AN ↔ AMF | NGAP / SCTP | IPsec (TS 33.210) |
| N3 | AN ↔ UPF | GTP-U | IPsec mandatory (TS 33.501) |
| N4 | SMF ↔ UPF | PFCP | IPsec / TLS (TS 29.244) |
| N6 | UPF ↔ DN | IP | Per-DN policies |
| N9 | UPF ↔ UPF | GTP-U | IPsec (TS 33.210) |
| N32 | SEPP ↔ SEPP | HTTP/2 + PRINS/TLS | N32-c (TLS), N32-f (JWS/JWE) |
| Xn | AN ↔ AN | XnAP / GTP | IPsec (TS 33.501) |
| SBI | NF ↔ NF | HTTP/2 | mTLS + OAuth 2.0 |
5. Network Slicing
▶
Network Slice Architecture:
┌────────────────────────────────────────────────────┐
│ Common CP │
│ ┌─────┐ ┌─────┐ ┌─────┐ ┌─────┐ │
│ │ AMF │ │ NSSF│ │ NRF │ │AUSF │ │
│ └──┬──┘ └─────┘ └─────┘ └─────┘ │
├─────┼──────────────────────────────────────────────┤
│ │ Slice 1 (eMBB) S-NSSAI: SST=1 │
│ ├──▷ SMF-1 ──▷ UPF-1 ──▷ DN-1 │
│ │ PCF-1 │
├─────┼──────────────────────────────────────────────┤
│ │ Slice 2 (URLLC) S-NSSAI: SST=2 │
│ ├──▷ SMF-2 ──▷ UPF-2 ──▷ DN-2 │
│ │ PCF-2 (edge deployed) │
├─────┼──────────────────────────────────────────────┤
│ │ Slice 3 (mMTC/IoT) S-NSSAI: SST=3 │
│ └──▷ SMF-3 ──▷ UPF-3 ──▷ DN-3 │
│ PCF-3 │
└────────────────────────────────────────────────────┘
| Concept | Description | Security Aspect |
|---|---|---|
| S-NSSAI | Single NSSAI = SST (Slice/Service Type) + SD (Slice Differentiator) | Sent in registration → must be validated |
| SST Values | 1=eMBB, 2=URLLC, 3=mMTC, 4=V2X (standardized) | Custom SSTs for enterprise slices |
| Allowed NSSAI | S-NSSAIs permitted per UE per serving PLMN | AMF enforces; prevents unauthorized slice access |
| NSSAA | Slice-specific auth & authorization (EAP) | Per TS 33.501 §16.2; secondary auth per slice |
| Isolation | Resource isolation between slice instances | Cross-slice attack prevention (TR 33.899 Key Issue #11) |
6. QoS Framework
▶
QoS Architecture:
UE gNB UPF DN
── ─── ─── ──
│ ◀══ QoS Flow ══▷ │ ◀══ GTP-U ══════▷ │ ◀══ IP Packet ══▷ │
│ (5QI-based) │ (per-QFI │ (classified │
│ │ tunnel) │ by PDRs) │
│ │ │ │
│ DRB mapping │ QFI in GTP-U │ FAR actions │
│ (radio bearer) │ extension hdr │ (fwd/drop/buf) │
| 5QI | Type | Priority | Delay Budget | Example Use |
|---|---|---|---|---|
| 1 | GBR | 20 | 100ms | Conversational voice |
| 2 | GBR | 40 | 150ms | Conversational video |
| 5 | Non-GBR | 10 | 100ms | IMS signaling |
| 9 | Non-GBR | 90 | 300ms | Default internet (best effort) |
| 82 | GBR | 19 | 10ms | Discrete automation |
| 85 | GBR | 21 | 5ms | Electric power distribution |
Security impact: QoS manipulation is a threat vector — unauthorized 5QI escalation grants priority bandwidth. TS 33.520 (PCF SCAS) defines test cases for QoS policy bypass.
7. PDU Session Types
▶| Session Type | Description | GTP Tunnel Structure |
|---|---|---|
| IPv4 | IPv4 PDU session — UE gets IPv4 address from SMF/UPF | N3 GTP-U: outer IP + GTP + inner IPv4 |
| IPv6 | IPv6 PDU session — prefix delegation via RA | N3 GTP-U: outer IP + GTP + inner IPv6 |
| IPv4v6 | Dual-stack — both v4 address and v6 prefix | N3 GTP-U: per QoS flow tunnel |
| Ethernet | L2 PDU session — for LAN-type services | N3 GTP-U: encapsulates Ethernet frames |
| Unstructured | Raw IP/non-IP — for IoT point-to-point | N3 GTP-U: opaque payload |
PDU Session Continuity Modes:
SSC Mode 1: Always-on anchor UPF
UE ──▷ gNB ──N3──▷ UPF (anchor) ──N6──▷ DN
Same IP address maintained across mobility
SSC Mode 2: Break-before-make
Old session released → new session established
IP address may change
SSC Mode 3: Make-before-break
New session established alongside old → seamless transition
Used for edge computing (UPF relocation)
8. Interworking — 4G/5G
▶| Scenario | Architecture | Key Security Interface |
|---|---|---|
| NSA Option 3/3a/3x | en-DC: LTE master, NR secondary → EPC | X2-C between eNB/en-gNB, S1 to MME |
| SA Option 2 | NR standalone → 5GC | N2 (NGAP) + N3 (GTP-U), full 5G security |
| EPC Fallback | 5GC triggers 4G handover for VoLTE | N26 between AMF↔MME, mapped security context |
| Idle Mode (N26) | UE moves between 4G/5G | Mapped security context, ABBA protection |
Bidding-down risk: Inter-RAT handover from 5G→4G can downgrade security (no UP integrity, weaker key hierarchy). AMF ABBA parameter prevents this — see TS 33.501 §6.3.
9. Security Specification Mapping
▶| 23.501 Domain | Security Spec | Coverage |
|---|---|---|
| Overall 5G Security | TS 33.501 | Master: auth, keys, SBI, slicing, GTP |
| SBI Framework | TS 29.500 | HTTP/2 transport, OAuth, headers |
| GTP-U Protocol | TS 29.281 | N3/N9 tunnel security |
| GTP-C Protocol | TS 29.274 | Control plane signaling security |
| PFCP Protocol | TS 29.244 | N4 session/rule security |
| Network Domain | TS 33.210 | IPsec/NDS for all N-interfaces |
| Certificate Management | TS 33.310 | PKI for TLS/IPsec/SEPP certs |
| All NF Products | TS 33.117 | Baseline security assurance |