3GPP TS 23.501

System Architecture for the 5G System (5GS) — Stage 2
V18.6.0 (2024-06) 23-Series Architecture

1. Scope

▶

Defines the overall 5G System (5GS) architecture including Network Functions, reference points (N-interfaces), service-based interfaces, network slicing, QoS framework, and session management. This is the master architecture specification that all 33-series security specs protect.

Security context: Every NF, interface, and procedure defined in TS 23.501 has corresponding security requirements in TS 33.501 and product-class SCAS documents (TS 33.511–33.527).

2. 5GS Architecture

▶
5G System Architecture — Reference Point Model: ┌─────┐ │ NSSF│ └──┬──┘ Nnssf │ ┌─────┐ ┌─────────┤ ┌─────┐ ┌─────┐ │ NEF │ │ ┌─────┤ │ AUSF│ │ UDM │ └──┬──┘ │ │ │ └──┬──┘ └──┬──┘ Nnef │ │ │ │ Nausf│ Nudm │ ───────────┤ ┌────┴───┴──┐ │ ┌───┴──┐ ┌─────┴──┐ ├───┤ AMF ├──┤ │ AUSF │ │ UDM │ │ └────┬──────┘ │ └──────┘ └────────┘ │ N1 │ N2│ │ │ ┌────┘ │ │ │ │ ┌────┘ │ ┌──────┐ │ ┌─┴──┐ │ ┌──────┴──┐ ┌─────┐ │ UE ├───┤ │ AN ├─┤ │ SMF ├────┤ PCF │ └──────┘ │ └────┘ │ └────┬────┘ └─────┘ │ N3 │ N4 │ │ │ ┌────┴────┐ │ │ │ UPF │──── N6 ──── DN │ │ └─────────┘ │ │ N9 │ │ ┌─────────┐ │ │ │ UPF-I │ (Intermediate) │ │ └─────────┘
5G System Architecture — Service-Based Representation: ┌────┐ ┌────┐ ┌────┐ ┌────┐ ┌────┐ ┌────┐ ┌────┐ ┌────┐ ┌────┐ │NSSF│ │ NEF│ │ NRF│ │ PCF│ │ UDM│ │ UDR│ │AUSF│ │ AMF│ │ SMF│ └──┬─┘ └──┬─┘ └──┬─┘ └──┬─┘ └──┬─┘ └──┬─┘ └──┬─┘ └──┬─┘ └──┬─┘ │ │ │ │ │ │ │ │ │ ═══╪══════╪══════╪══════╪══════╪══════╪══════╪══════╪══════╪═══ Common SBI Bus (HTTP/2 + TLS) Each NF exposes services on the SBI bus NRF provides discovery & authorization All NF-to-NF communication via RESTful APIs

3. Network Functions

▶
NFFull NameKey ResponsibilitiesSecurity Spec
AMFAccess & Mobility MgmtRegistration, connection mgmt, NAS security, mobilityTS 33.515
SMFSession ManagementPDU session establishment, QoS, UPF selection, PFCPTS 33.518
UPFUser Plane FunctionPacket routing, PDR/FAR rules, GTP-U tunneling, QoS enforcementTS 33.513
AUSFAuthentication Server5G-AKA / EAP-AKA' execution, K_AUSF derivationTS 33.516
UDMUnified Data MgmtSubscription data, auth credential generation, SUPI de-concealmentTS 33.514
UDRUnified Data RepositoryStructured data storage for UDM, PCF, NEFTS 33.117 (general)
NRFNF RepositoryNF registration, discovery, OAuth 2.0 token issuanceTS 33.521
PCFPolicy ControlSM/AM/UE policies, QoS decisions, rate controlTS 33.520
NEFNetwork ExposureExternal API exposure, monitoring events, SUPI translationTS 33.519
NSSFSlice SelectionSlice selection for registration, AMF set selectionTS 33.117 (general)
SEPPSecurity Edge ProxyInter-PLMN SBI protection (N32-c/N32-f), PRINS/TLSTS 33.522
SCPService Comm ProxySBI routing, load balancing, delegated discoveryTS 33.527
gNBgNodeB (5G RAN)Radio access, PDCP/RLC/MAC, N2/N3 connectivityTS 33.512
ng-eNBNext-gen eNodeBLTE radio with 5GC connectivity (NSA/SA)TS 33.511

4. Reference Points (N-Interfaces)

▶
InterfaceBetweenProtocolSecurity
N1UE ↔ AMFNAS (5G-MM, 5G-SM)NAS encryption + integrity
N2AN ↔ AMFNGAP / SCTPIPsec (TS 33.210)
N3AN ↔ UPFGTP-UIPsec mandatory (TS 33.501)
N4SMF ↔ UPFPFCPIPsec / TLS (TS 29.244)
N6UPF ↔ DNIPPer-DN policies
N9UPF ↔ UPFGTP-UIPsec (TS 33.210)
N32SEPP ↔ SEPPHTTP/2 + PRINS/TLSN32-c (TLS), N32-f (JWS/JWE)
XnAN ↔ ANXnAP / GTPIPsec (TS 33.501)
SBINF ↔ NFHTTP/2mTLS + OAuth 2.0

5. Network Slicing

▶
Network Slice Architecture: ┌────────────────────────────────────────────────────┐ │ Common CP │ │ ┌─────┐ ┌─────┐ ┌─────┐ ┌─────┐ │ │ │ AMF │ │ NSSF│ │ NRF │ │AUSF │ │ │ └──┬──┘ └─────┘ └─────┘ └─────┘ │ ├─────┼──────────────────────────────────────────────┤ │ │ Slice 1 (eMBB) S-NSSAI: SST=1 │ │ ├──▷ SMF-1 ──▷ UPF-1 ──▷ DN-1 │ │ │ PCF-1 │ ├─────┼──────────────────────────────────────────────┤ │ │ Slice 2 (URLLC) S-NSSAI: SST=2 │ │ ├──▷ SMF-2 ──▷ UPF-2 ──▷ DN-2 │ │ │ PCF-2 (edge deployed) │ ├─────┼──────────────────────────────────────────────┤ │ │ Slice 3 (mMTC/IoT) S-NSSAI: SST=3 │ │ └──▷ SMF-3 ──▷ UPF-3 ──▷ DN-3 │ │ PCF-3 │ └────────────────────────────────────────────────────┘
ConceptDescriptionSecurity Aspect
S-NSSAISingle NSSAI = SST (Slice/Service Type) + SD (Slice Differentiator)Sent in registration → must be validated
SST Values1=eMBB, 2=URLLC, 3=mMTC, 4=V2X (standardized)Custom SSTs for enterprise slices
Allowed NSSAIS-NSSAIs permitted per UE per serving PLMNAMF enforces; prevents unauthorized slice access
NSSAASlice-specific auth & authorization (EAP)Per TS 33.501 §16.2; secondary auth per slice
IsolationResource isolation between slice instancesCross-slice attack prevention (TR 33.899 Key Issue #11)

6. QoS Framework

▶
QoS Architecture: UE gNB UPF DN ── ─── ─── ── │ ◀══ QoS Flow ══▷ │ ◀══ GTP-U ══════▷ │ ◀══ IP Packet ══▷ │ │ (5QI-based) │ (per-QFI │ (classified │ │ │ tunnel) │ by PDRs) │ │ │ │ │ │ DRB mapping │ QFI in GTP-U │ FAR actions │ │ (radio bearer) │ extension hdr │ (fwd/drop/buf) │
5QITypePriorityDelay BudgetExample Use
1GBR20100msConversational voice
2GBR40150msConversational video
5Non-GBR10100msIMS signaling
9Non-GBR90300msDefault internet (best effort)
82GBR1910msDiscrete automation
85GBR215msElectric power distribution
Security impact: QoS manipulation is a threat vector — unauthorized 5QI escalation grants priority bandwidth. TS 33.520 (PCF SCAS) defines test cases for QoS policy bypass.

7. PDU Session Types

▶
Session TypeDescriptionGTP Tunnel Structure
IPv4IPv4 PDU session — UE gets IPv4 address from SMF/UPFN3 GTP-U: outer IP + GTP + inner IPv4
IPv6IPv6 PDU session — prefix delegation via RAN3 GTP-U: outer IP + GTP + inner IPv6
IPv4v6Dual-stack — both v4 address and v6 prefixN3 GTP-U: per QoS flow tunnel
EthernetL2 PDU session — for LAN-type servicesN3 GTP-U: encapsulates Ethernet frames
UnstructuredRaw IP/non-IP — for IoT point-to-pointN3 GTP-U: opaque payload
PDU Session Continuity Modes: SSC Mode 1: Always-on anchor UPF UE ──▷ gNB ──N3──▷ UPF (anchor) ──N6──▷ DN Same IP address maintained across mobility SSC Mode 2: Break-before-make Old session released → new session established IP address may change SSC Mode 3: Make-before-break New session established alongside old → seamless transition Used for edge computing (UPF relocation)

8. Interworking — 4G/5G

▶
ScenarioArchitectureKey Security Interface
NSA Option 3/3a/3xen-DC: LTE master, NR secondary → EPCX2-C between eNB/en-gNB, S1 to MME
SA Option 2NR standalone → 5GCN2 (NGAP) + N3 (GTP-U), full 5G security
EPC Fallback5GC triggers 4G handover for VoLTEN26 between AMF↔MME, mapped security context
Idle Mode (N26)UE moves between 4G/5GMapped security context, ABBA protection
Bidding-down risk: Inter-RAT handover from 5G→4G can downgrade security (no UP integrity, weaker key hierarchy). AMF ABBA parameter prevents this — see TS 33.501 §6.3.

9. Security Specification Mapping

▶
23.501 DomainSecurity SpecCoverage
Overall 5G SecurityTS 33.501Master: auth, keys, SBI, slicing, GTP
SBI FrameworkTS 29.500HTTP/2 transport, OAuth, headers
GTP-U ProtocolTS 29.281N3/N9 tunnel security
GTP-C ProtocolTS 29.274Control plane signaling security
PFCP ProtocolTS 29.244N4 session/rule security
Network DomainTS 33.210IPsec/NDS for all N-interfaces
Certificate ManagementTS 33.310PKI for TLS/IPsec/SEPP certs
All NF ProductsTS 33.117Baseline security assurance