Skip to content

5GC Overview

Summary
  • 5GC (5G Core) is the network behind the RAN — everything a UE talks to once its RRC connection reaches beyond the gNB.
  • Unlike LTE's EPC, which was built from a handful of fixed nodes wired together with dedicated interfaces, the 5GC is a Service-Based Architecture (SBA): a set of independent, mostly stateless Network Functions (NFs) that register themselves, discover each other, and call each other's APIs.
  • Every NF does one job — mobility, session management, policy, authentication, subscriber data, packet forwarding — and the whole system is designed to be cloud-native: NFs can be scaled, replaced, or virtualized independently.

Think of the 5GC as:

"A microservices backend for connectivity — instead of a few big monolithic boxes, it's a directory of small specialized services that all speak the same API style and look each other up as needed."

Service-Based Architecture (SBA)

5G Core Network Architecture

Figure 1. 5G Core Network Architecture2

3GPP defines the 5GC two ways at once: a reference point representation (point-to-point interfaces between pairs of NFs, e.g. N11 for AMF↔SMF) and a service-based representation (control-plane NFs expose services like Namf that any authorized NF discovers via the NRF and consumes over a common API style). Both describe the same network — the reference-point view is just easier to reason about procedure by procedure.1

Network Functions & Entities

3GPP TS 23.501 §4.2.3 lists every NF and entity in the 5G System architecture. Here's the complete set, grouped by role:1

Endpoints

Full Name What it is
UE User Equipment The device — phone, module, CPE — that the whole system exists to serve.
(R)AN (Radio) Access Network The gNB/RAN side covered by the SSB, RACH, and RRC pages on this site.
DN Data Network Whatever the UE is actually trying to reach — the internet, operator services, an enterprise network, or a 3rd-party service — sitting on the other side of the UPF.

Table 1. 5G System Endpoints

Access, mobility & session control

NF Full Name What it does
AMF Access and Mobility Management Function Terminates N1 (NAS) and N2 (NGAP); handles registration, connection, reachability, and mobility management. The closest 5GC analog to LTE's MME.
SMF Session Management Function Owns the PDU session lifecycle — establishment, modification, release — selects and controls the UPF over N4, allocates UE IP addresses, and enforces QoS rules.
UPF User Plane Function The only NF that actually forwards user data. Routes packets between the RAN (N3) and the Data Network (N6), enforces QoS, and reports usage back to the SMF.

Table 2. Access, Mobility & Session Control Functions

Subscriber data, authentication & policy

NF Full Name What it does
AUSF Authentication Server Function Runs 5G-AKA / EAP-AKA' authentication together with the UDM.
UDM Unified Data Management Manages subscriber identity (SUPI/SUCI), generates authentication credentials, and manages subscription and registration data. Roughly analogous to LTE's HSS.
UDR Unified Data Repository The actual data store behind the UDM (subscription data), the PCF (policy data), and the NEF (exposure data).
PCF Policy Control Function The unified policy framework — supplies access/mobility policy, session policy, and UE policy to other NFs. Replaces LTE's PCRF.

Table 3. Subscriber Data, Authentication & Policy Functions

Discovery, slicing & exposure

NF Full Name What it does
NRF NF Repository Function The SBA's service registry — every NF registers here, and discovers every other NF here. Nothing in the SBA works without it.
NSSF Network Slice Selection Function Selects which network slice instance(s) should serve a given UE, and determines the UE's allowed NSSAI.
NSACF Network Slice Admission Control Function Enforces the maximum number of UEs and/or PDU sessions allowed on a given network slice, so a slice can't be oversubscribed.
NSSAAF Network Slice-specific and SNPN Authentication and Authorization Function Handles slice-specific secondary authentication (NSSAA), and authentication for Standalone Non-Public Networks (SNPNs).
NEF Network Exposure Function Securely exposes 5GC capabilities and events to trusted third-party applications outside the operator's domain.
AF Application Function Represents an application — inside or outside the operator's trust domain — that can request specific QoS or traffic routing, via the PCF (directly, if trusted) or the NEF (if not).

Table 4. Discovery, Slicing & Exposure Functions

Charging, analytics & support functions

NF Full Name What it does
CHF Charging Function Converged online/offline charging, replacing LTE's separate OCS/OFCS.
NWDAF Network Data Analytics Function Collects data from other NFs and from OAM to produce network analytics (load, slice performance, and so on) that other NFs can consume.
DCCF Data Collection Coordination Function Coordinates data-collection requests to other NFs on behalf of consumers like the NWDAF, so the same data isn't collected redundantly by multiple consumers.
ADRF Analytics Data Repository Function Stores collected data and analytics output for later retrieval — the historical record NWDAF and others can query.
MFAF Messaging Framework Adaptor Function Provides a messaging-framework-based interface between the DCCF and data sources/consumers.
BSF Binding Support Function Tracks which PCF instance is handling policy for a given UE/session, so other NFs (e.g., an AF via the NEF) can route policy requests to the right one.

Table 5. Charging, Analytics & Support Functions

The DCCF/ADRF/MFAF footnote

3GPP notes that the functionality of DCCF and/or ADRF can also simply be hosted by an NWDAF instance rather than deployed as separate NFs — small/medium deployments often do exactly that.

Identity, capability & security

NF Full Name What it does
5G-EIR 5G-Equipment Identity Register Checks a UE's equipment identity (PEI) against allow/block/grey lists — the anti-theft/fraud function.
UCMF UE radio Capability Management Function Stores and manages standardized UE radio capability IDs, mapping short capability IDs to full capability sets to cut down on repeated capability signalling.

Table 6. Identity, Capability & Security Functions

Time-sensitive networking

NF Full Name What it does
TSN AF Time Sensitive Networking AF A specialized Application Function that bridges the 5GS with an external IEEE 802.1 Time-Sensitive Networking (TSN) domain.
TSCTSF Time Sensitive Communication and Time Synchronization Function Manages time synchronization service and deterministic/time-sensitive communication configuration natively within the 5GS.

Table 7. Time-Sensitive Networking Functions

Non-3GPP & wireline access

NF Full Name What it does
N3IWF Non-3GPP InterWorking Function Lets a UE reach the 5GC over an untrusted non-3GPP access (e.g., generic Wi-Fi), terminating IPsec/IKEv2 with the UE.
TNGF Trusted Non-3GPP Gateway Function Same role as N3IWF, but for trusted non-3GPP access networks.
TWIF Trusted WLAN Interworking Function Lets UEs without native 5G NAS support connect to the 5GC via a trusted WLAN.
W-AGF Wireline Access Gateway Function Interworking function that lets wireline (fixed broadband) access connect into the 5GC.
NSWOF Non-Seamless WLAN Offload Function Supports authentication (via the AUSF) when a UE offloads traffic to WLAN entirely outside the 5GS.

Table 8. Non-3GPP & Wireline Access Functions

Edge computing & energy

NF Full Name What it does
EASDF Edge Application Server Discovery Function Assists DNS-based discovery of Edge Application Servers, working with the SMF to intercept/handle relevant DNS queries.
EIF Energy Information Function Collects and exposes network energy-consumption information in support of 5GS energy efficiency.

Table 9. Edge Computing & Energy Functions

Network entities (not NFs, per 3GPP's own terminology)

Entity Full Name What it does
SCP Service Communication Proxy An optional intermediary for NF-to-NF traffic — centralizes routing, discovery, and load balancing so individual NFs don't each need full mesh connectivity.
SEPP Security Edge Protection Proxy Sits at the edge of the PLMN and protects inter-operator (roaming) SBA traffic over the N32 interface.

Table 10. Network Entities (SCP, SEPP)

Entity vs. Function

3GPP is specific about this distinction: SCP and SEPP are called out separately as network entities, not network functions — everything else on this page is an NF. Practically the line matters less than it sounds; both still participate in the SBA.

Also part of the architecture, but listed separately since it isn't role-specific: UDSF (Unstructured Data Storage Function) — an optional shared store any NF can use to persist its state, which is what lets NFs stay largely stateless.

Do I need every one of these to run a network?

Not remotely. The Try 5G Yourself lab only needs NRF, AMF, SMF, UPF, AUSF, UDM, and UDR to get a UE fully registered with a working data session. Everything else on this page adds one specific capability — slicing admission control, non-3GPP access, time-sensitive networking, edge discovery, energy reporting, and so on — that most deployments, and certainly a small lab, will never touch.

Reference Points & Interfaces

3GPP TS 23.501 §4.2.7 defines the reference points. They fall into two groups: a small set of "pure" point-to-point interfaces not mapped to a specific NF service, and a much larger set that are realized as NF service-based interactions.1

How confident is the Purpose column?

N1–N22 are grounded directly in 3GPP TS 23.501 §4.2.7 and cross-checked against multiple sources. From N23 onward, the pairing (what connects to what) is verbatim from the spec text, but most of the Purpose descriptions are inferred from each NF's defined role rather than pulled from a specific procedural clause — reasonable for a general sense of what an interface is for, but worth checking clause 6/§5 directly before relying on the exact mechanics of any of the more obscure ones (N50 onward especially).

Core reference points (not service-mapped)

Reference Point Between Purpose
N1 UE ↔ AMF NAS signalling — registration, mobility, and session management messages between the UE and the core
N2 (R)AN ↔ AMF NGAP — RAN-to-core control plane, including UE context setup and mobility
N3 (R)AN ↔ UPF User-plane data (GTP-U) between the RAN and the core
N4 SMF ↔ UPF PFCP — the SMF installs forwarding/QoS rules on the UPF and receives usage reports back
N6 UPF ↔ Data Network Where user traffic actually exits the core toward the internet or an external network
N9 UPF ↔ UPF User-plane interconnect, used to chain multiple UPFs (e.g., a branch UPF forwarding to a central one)

Table 11. Core Reference Points (Not Service-Mapped)

Core service-based reference points

Reference Point Between Purpose
N5 PCF ↔ AF (or TSN AF) Lets an application influence QoS/policy decisions for its traffic
N7 SMF ↔ PCF SMF requests session-management (SM) policy rules from the PCF
N8 UDM ↔ AMF AMF retrieves mobility-related subscription data from the UDM
N10 UDM ↔ SMF SMF retrieves session-related subscription data from the UDM
N11 AMF ↔ SMF Coordinates PDU session establishment, modification, and release
N12 AMF ↔ AUSF AMF requests UE authentication from the AUSF
N13 UDM ↔ AUSF AUSF retrieves authentication vectors from the UDM
N14 AMF ↔ AMF Context transfer during inter-AMF mobility
N15 PCF ↔ AMF AMF requests access/mobility (AM) policy from the PCF (visited-network PCF, in roaming)
N22 AMF ↔ NSSF AMF requests slice selection assistance for a UE

Table 12. Core Service-Based Reference Points

Roaming & multi-SMF

Reference Point Between Purpose
N16 SMF ↔ SMF Coordinates a PDU session across a visited-network SMF and a home-network SMF (home-routed roaming)
N16a SMF ↔ I-SMF Coordinates a session when an Intermediate SMF is inserted mid-path (e.g., for local breakout)
N24 PCF (visited) ↔ PCF (home) Coordinates policy decisions across PLMNs for a roaming UE
N27 NRF (visited) ↔ NRF (home) Lets NFs in one PLMN discover NFs in the other, for roaming
N31 NSSF (visited) ↔ NSSF (home) Coordinates slice selection decisions across PLMNs for a roaming UE
N32 SEPP ↔ SEPP Secures all inter-PLMN SBI signalling passing between two operators' networks3
N38 I-SMF ↔ I-SMF, and V-SMF ↔ V-SMF Coordination between intermediate/visited SMFs in multi-SMF topologies
N43 PCF ↔ PCF Direct PCF-to-PCF coordination

Table 13. Roaming & Multi-SMF Reference Points

Slicing & admission control

Reference Point Between Purpose
N23 PCF ↔ NWDAF PCF consumes network analytics to help inform policy decisions
N34 NSSF ↔ NWDAF NSSF consumes slice-load analytics to help inform slice selection
N80 AMF ↔ NSACF AMF checks/registers UE count against a slice's admission limits
N81 SMF ↔ NSACF SMF checks/registers PDU session count against a slice's admission limits
N82 NSACF ↔ NEF Exposes slice admission control status externally
N97 NSACF ↔ NSACF Coordinates slice admission counts across PLMNs, for roaming
N99 NSACF ↔ NSACF Coordinates admission counts between multiple NSACF instances within the same PLMN

Table 14. Slicing & Admission Control Reference Points

Data, exposure & repository

Reference Point Between Purpose
N17 AMF ↔ 5G-EIR AMF checks a UE's equipment identity against allow/block/grey lists
N18 Any NF ↔ UDSF Any NF can store/retrieve unstructured state data, keeping the NF itself stateless
N19 PSA UPF ↔ PSA UPF Connects two PDU Session Anchor UPFs for a 5G LAN-type (local switching) service
N29 NEF ↔ SMF Lets external requests (via NEF) reach session-management functionality on the SMF
N30 PCF ↔ NEF Exposes or consumes policy-related information via the NEF
N33 NEF ↔ AF The main path for an external/untrusted AF to reach 5GC capabilities
N35 UDM ↔ UDR UDM stores/retrieves subscription data from the UDR
N36 PCF ↔ UDR PCF stores/retrieves policy data from the UDR
N37 NEF ↔ UDR NEF stores/retrieves structured exposure/application data from the UDR
N51 AMF ↔ NEF Exposes AMF events/capabilities (e.g., mobility events) externally
N52 NEF ↔ UDM Exposes UDM-related subscriber data capabilities externally

Table 15. Data, Exposure & Repository Reference Points

N28/N29/N30

Per 3GPP, the functionality of N28, N29, and N30 is defined in TS 23.503, not TS 23.501 itself.

Charging

Reference Point Between Purpose
N28 PCF ↔ CHF PCF provides charging-related policy information to the CHF
N40 SMF ↔ CHF SMF reports session usage data to the CHF for charging
N41 AMF ↔ CHF (HPLMN) AMF reports charging-relevant events to the home-network CHF
N42 AMF ↔ CHF (VPLMN) AMF reports charging-relevant events to the visited-network CHF, in roaming

Table 16. Charging Reference Points

N40/N41/N42

Functionality defined in TS 32.240, not TS 23.501 itself. N44–N49 are reserved for future allocation in the same spec.

UE capability & public warning

Reference Point Between Purpose
N50 AMF ↔ CBCF Relays Public Warning System (emergency alert) notifications for broadcast to UEs
N55 AMF ↔ UCMF AMF resolves a UE's short radio capability ID to its full capability set
N56 NEF ↔ UCMF Exposes UE capability ID management externally
N57 AF ↔ UCMF Lets an AF interact with UE radio capability ID management

Table 17. UE Capability & Public Warning Reference Points

Non-3GPP access & offload

Reference Point Between Purpose
N58 AMF ↔ NSSAAF Supports slice-specific/SNPN secondary authentication and authorization
N59 UDM ↔ NSSAAF NSSAAF retrieves the subscriber data it needs to perform slice/SNPN authentication
N60 AUSF ↔ NSWOF Supports authentication when a UE offloads traffic to WLAN outside the 5GS3
N83 AUSF ↔ NSSAAF Supports slice-specific/SNPN authentication procedures that involve the AUSF

Table 18. Non-3GPP Access & Offload Reference Points

Time-sensitive networking

Reference Point Between Purpose
N84 TSCTSF ↔ PCF Translates time-sync/TSC requirements into policy rules
N85 TSCTSF ↔ NEF Exposes time synchronization service capabilities externally
N86 TSCTSF ↔ AF Handles time-sync/TSC service requests from an application
N87 TSCTSF ↔ UDM Retrieves subscription data relevant to time synchronization service
N89 TSCTSF ↔ AMF Delivers time synchronization configuration down toward the RAN/UE path
N96 TSCTSF ↔ NRF Lets the TSCTSF discover other NFs it needs to interact with

Table 19. Time-Sensitive Networking Reference Points

Edge computing

Reference Point Between Purpose
N88 SMF ↔ EASDF SMF hands off relevant DNS queries so the EASDF can assist Edge Application Server discovery
N88a I-SMF ↔ EASDF Same purpose as N88, in deployments using an Intermediate SMF

Table 20. Edge Computing Reference Points

Energy information

Reference Point Between Purpose
N110 EIF ↔ AF Exposes network energy information to an application
N111 EIF ↔ NEF Exposes network energy information externally
N112 EIF ↔ UDM Ties energy information to subscriber/network data
N113 EIF ↔ PCF Lets energy information inform policy decisions
N114 EIF ↔ SMF Collects energy-relevant information from session management

Table 21. Energy Information Reference Points

One more

Reference Point Between Purpose
N115 SMF+PGW-C ↔ NSSAAF Supports slice-specific/SNPN authentication in EPS-interworking deployments (SMF co-located with a PGW control-plane function)

Table 22. SMF+PGW-C ↔ NSSAAF Reference Point

Reference points vs. service names

Each service-based reference point has a matching service name once you're inside the SBA view — N11 is really the AMF consuming Nsmf and the SMF consuming Namf, N12 is the AMF consuming Nausf, and so on. The reference-point tables above are the easier mental model; the service names are what you'd actually see in a packet capture or an Open5GS log.

Useful Resources

  • 3GPP TS 23.501 — System architecture for the 5G System: every NF, entity, and reference point on this page, defined in §4.2.3 and §4.2.7
  • 3GPP TS 23.502 — Procedures for the 5G System: how these NFs interact step by step
  • 3GPP TS 23.503 — Policy and charging control framework (N28/N29/N30/N43)
  • 3GPP TS 33.501 — Security architecture (N32, N60)
  • ShareTechnote — 5G Core Network Architecture
  • Open5GS Quickstart — a real, minimal 5GC you can run yourself (covers the core dozen NFs, not the full Release 17–19 set above)

  1. 3GPP. (n.d.). System architecture for the 5G System (5GS) (Technical Specification TS 23.501). 3rd Generation Partnership Project. https://portal.3gpp.org/desktopmodules/Specifications/SpecificationDetails.aspx?specificationId=3144 ↩↩↩

  2. Ryu, J. (n.d.). 5G Core Network Architecture. ShareTechnote. https://www.sharetechnote.com/html/5G/5G_NetworkArchitecture.html ↩

  3. 3GPP. (n.d.). Security architecture and procedures for 5G System (Technical Specification TS 33.501). 3rd Generation Partnership Project. https://portal.3gpp.org/desktopmodules/Specifications/SpecificationDetails.aspx?specificationId=3169 ↩↩