5GC Overview¶
Summary
- 5GC (5G Core) is the network behind the RAN — everything a UE talks to once its RRC connection reaches beyond the gNB.
- Unlike LTE's EPC, which was built from a handful of fixed nodes wired together with dedicated interfaces, the 5GC is a Service-Based Architecture (SBA): a set of independent, mostly stateless Network Functions (NFs) that register themselves, discover each other, and call each other's APIs.
- Every NF does one job — mobility, session management, policy, authentication, subscriber data, packet forwarding — and the whole system is designed to be cloud-native: NFs can be scaled, replaced, or virtualized independently.
Think of the 5GC as:
"A microservices backend for connectivity — instead of a few big monolithic boxes, it's a directory of small specialized services that all speak the same API style and look each other up as needed."
Service-Based Architecture (SBA)¶
Figure 1. 5G Core Network Architecture2
3GPP defines the 5GC two ways at once: a reference point representation (point-to-point interfaces between pairs of NFs, e.g. N11 for AMF↔SMF) and a service-based representation (control-plane NFs expose services like Namf that any authorized NF discovers via the NRF and consumes over a common API style). Both describe the same network — the reference-point view is just easier to reason about procedure by procedure.1
Network Functions & Entities¶
3GPP TS 23.501 §4.2.3 lists every NF and entity in the 5G System architecture. Here's the complete set, grouped by role:1
Endpoints
| Full Name | What it is | |
|---|---|---|
| UE | User Equipment | The device — phone, module, CPE — that the whole system exists to serve. |
| (R)AN | (Radio) Access Network | The gNB/RAN side covered by the SSB, RACH, and RRC pages on this site. |
| DN | Data Network | Whatever the UE is actually trying to reach — the internet, operator services, an enterprise network, or a 3rd-party service — sitting on the other side of the UPF. |
Table 1. 5G System Endpoints
Access, mobility & session control
| NF | Full Name | What it does |
|---|---|---|
| AMF | Access and Mobility Management Function | Terminates N1 (NAS) and N2 (NGAP); handles registration, connection, reachability, and mobility management. The closest 5GC analog to LTE's MME. |
| SMF | Session Management Function | Owns the PDU session lifecycle — establishment, modification, release — selects and controls the UPF over N4, allocates UE IP addresses, and enforces QoS rules. |
| UPF | User Plane Function | The only NF that actually forwards user data. Routes packets between the RAN (N3) and the Data Network (N6), enforces QoS, and reports usage back to the SMF. |
Table 2. Access, Mobility & Session Control Functions
Subscriber data, authentication & policy
| NF | Full Name | What it does |
|---|---|---|
| AUSF | Authentication Server Function | Runs 5G-AKA / EAP-AKA' authentication together with the UDM. |
| UDM | Unified Data Management | Manages subscriber identity (SUPI/SUCI), generates authentication credentials, and manages subscription and registration data. Roughly analogous to LTE's HSS. |
| UDR | Unified Data Repository | The actual data store behind the UDM (subscription data), the PCF (policy data), and the NEF (exposure data). |
| PCF | Policy Control Function | The unified policy framework — supplies access/mobility policy, session policy, and UE policy to other NFs. Replaces LTE's PCRF. |
Table 3. Subscriber Data, Authentication & Policy Functions
Discovery, slicing & exposure
| NF | Full Name | What it does |
|---|---|---|
| NRF | NF Repository Function | The SBA's service registry — every NF registers here, and discovers every other NF here. Nothing in the SBA works without it. |
| NSSF | Network Slice Selection Function | Selects which network slice instance(s) should serve a given UE, and determines the UE's allowed NSSAI. |
| NSACF | Network Slice Admission Control Function | Enforces the maximum number of UEs and/or PDU sessions allowed on a given network slice, so a slice can't be oversubscribed. |
| NSSAAF | Network Slice-specific and SNPN Authentication and Authorization Function | Handles slice-specific secondary authentication (NSSAA), and authentication for Standalone Non-Public Networks (SNPNs). |
| NEF | Network Exposure Function | Securely exposes 5GC capabilities and events to trusted third-party applications outside the operator's domain. |
| AF | Application Function | Represents an application — inside or outside the operator's trust domain — that can request specific QoS or traffic routing, via the PCF (directly, if trusted) or the NEF (if not). |
Table 4. Discovery, Slicing & Exposure Functions
Charging, analytics & support functions
| NF | Full Name | What it does |
|---|---|---|
| CHF | Charging Function | Converged online/offline charging, replacing LTE's separate OCS/OFCS. |
| NWDAF | Network Data Analytics Function | Collects data from other NFs and from OAM to produce network analytics (load, slice performance, and so on) that other NFs can consume. |
| DCCF | Data Collection Coordination Function | Coordinates data-collection requests to other NFs on behalf of consumers like the NWDAF, so the same data isn't collected redundantly by multiple consumers. |
| ADRF | Analytics Data Repository Function | Stores collected data and analytics output for later retrieval — the historical record NWDAF and others can query. |
| MFAF | Messaging Framework Adaptor Function | Provides a messaging-framework-based interface between the DCCF and data sources/consumers. |
| BSF | Binding Support Function | Tracks which PCF instance is handling policy for a given UE/session, so other NFs (e.g., an AF via the NEF) can route policy requests to the right one. |
Table 5. Charging, Analytics & Support Functions
The DCCF/ADRF/MFAF footnote
3GPP notes that the functionality of DCCF and/or ADRF can also simply be hosted by an NWDAF instance rather than deployed as separate NFs — small/medium deployments often do exactly that.
Identity, capability & security
| NF | Full Name | What it does |
|---|---|---|
| 5G-EIR | 5G-Equipment Identity Register | Checks a UE's equipment identity (PEI) against allow/block/grey lists — the anti-theft/fraud function. |
| UCMF | UE radio Capability Management Function | Stores and manages standardized UE radio capability IDs, mapping short capability IDs to full capability sets to cut down on repeated capability signalling. |
Table 6. Identity, Capability & Security Functions
Time-sensitive networking
| NF | Full Name | What it does |
|---|---|---|
| TSN AF | Time Sensitive Networking AF | A specialized Application Function that bridges the 5GS with an external IEEE 802.1 Time-Sensitive Networking (TSN) domain. |
| TSCTSF | Time Sensitive Communication and Time Synchronization Function | Manages time synchronization service and deterministic/time-sensitive communication configuration natively within the 5GS. |
Table 7. Time-Sensitive Networking Functions
Non-3GPP & wireline access
| NF | Full Name | What it does |
|---|---|---|
| N3IWF | Non-3GPP InterWorking Function | Lets a UE reach the 5GC over an untrusted non-3GPP access (e.g., generic Wi-Fi), terminating IPsec/IKEv2 with the UE. |
| TNGF | Trusted Non-3GPP Gateway Function | Same role as N3IWF, but for trusted non-3GPP access networks. |
| TWIF | Trusted WLAN Interworking Function | Lets UEs without native 5G NAS support connect to the 5GC via a trusted WLAN. |
| W-AGF | Wireline Access Gateway Function | Interworking function that lets wireline (fixed broadband) access connect into the 5GC. |
| NSWOF | Non-Seamless WLAN Offload Function | Supports authentication (via the AUSF) when a UE offloads traffic to WLAN entirely outside the 5GS. |
Table 8. Non-3GPP & Wireline Access Functions
Edge computing & energy
| NF | Full Name | What it does |
|---|---|---|
| EASDF | Edge Application Server Discovery Function | Assists DNS-based discovery of Edge Application Servers, working with the SMF to intercept/handle relevant DNS queries. |
| EIF | Energy Information Function | Collects and exposes network energy-consumption information in support of 5GS energy efficiency. |
Table 9. Edge Computing & Energy Functions
Network entities (not NFs, per 3GPP's own terminology)
| Entity | Full Name | What it does |
|---|---|---|
| SCP | Service Communication Proxy | An optional intermediary for NF-to-NF traffic — centralizes routing, discovery, and load balancing so individual NFs don't each need full mesh connectivity. |
| SEPP | Security Edge Protection Proxy | Sits at the edge of the PLMN and protects inter-operator (roaming) SBA traffic over the N32 interface. |
Table 10. Network Entities (SCP, SEPP)
Entity vs. Function
3GPP is specific about this distinction: SCP and SEPP are called out separately as network entities, not network functions — everything else on this page is an NF. Practically the line matters less than it sounds; both still participate in the SBA.
Also part of the architecture, but listed separately since it isn't role-specific: UDSF (Unstructured Data Storage Function) — an optional shared store any NF can use to persist its state, which is what lets NFs stay largely stateless.
Do I need every one of these to run a network?
Not remotely. The Try 5G Yourself lab only needs NRF, AMF, SMF, UPF, AUSF, UDM, and UDR to get a UE fully registered with a working data session. Everything else on this page adds one specific capability — slicing admission control, non-3GPP access, time-sensitive networking, edge discovery, energy reporting, and so on — that most deployments, and certainly a small lab, will never touch.
Reference Points & Interfaces¶
3GPP TS 23.501 §4.2.7 defines the reference points. They fall into two groups: a small set of "pure" point-to-point interfaces not mapped to a specific NF service, and a much larger set that are realized as NF service-based interactions.1
How confident is the Purpose column?
N1–N22 are grounded directly in 3GPP TS 23.501 §4.2.7 and cross-checked against multiple sources. From N23 onward, the pairing (what connects to what) is verbatim from the spec text, but most of the Purpose descriptions are inferred from each NF's defined role rather than pulled from a specific procedural clause — reasonable for a general sense of what an interface is for, but worth checking clause 6/§5 directly before relying on the exact mechanics of any of the more obscure ones (N50 onward especially).
Core reference points (not service-mapped)¶
| Reference Point | Between | Purpose |
|---|---|---|
| N1 | UE ↔ AMF | NAS signalling — registration, mobility, and session management messages between the UE and the core |
| N2 | (R)AN ↔ AMF | NGAP — RAN-to-core control plane, including UE context setup and mobility |
| N3 | (R)AN ↔ UPF | User-plane data (GTP-U) between the RAN and the core |
| N4 | SMF ↔ UPF | PFCP — the SMF installs forwarding/QoS rules on the UPF and receives usage reports back |
| N6 | UPF ↔ Data Network | Where user traffic actually exits the core toward the internet or an external network |
| N9 | UPF ↔ UPF | User-plane interconnect, used to chain multiple UPFs (e.g., a branch UPF forwarding to a central one) |
Table 11. Core Reference Points (Not Service-Mapped)
Core service-based reference points¶
| Reference Point | Between | Purpose |
|---|---|---|
| N5 | PCF ↔ AF (or TSN AF) | Lets an application influence QoS/policy decisions for its traffic |
| N7 | SMF ↔ PCF | SMF requests session-management (SM) policy rules from the PCF |
| N8 | UDM ↔ AMF | AMF retrieves mobility-related subscription data from the UDM |
| N10 | UDM ↔ SMF | SMF retrieves session-related subscription data from the UDM |
| N11 | AMF ↔ SMF | Coordinates PDU session establishment, modification, and release |
| N12 | AMF ↔ AUSF | AMF requests UE authentication from the AUSF |
| N13 | UDM ↔ AUSF | AUSF retrieves authentication vectors from the UDM |
| N14 | AMF ↔ AMF | Context transfer during inter-AMF mobility |
| N15 | PCF ↔ AMF | AMF requests access/mobility (AM) policy from the PCF (visited-network PCF, in roaming) |
| N22 | AMF ↔ NSSF | AMF requests slice selection assistance for a UE |
Table 12. Core Service-Based Reference Points
Roaming & multi-SMF¶
| Reference Point | Between | Purpose |
|---|---|---|
| N16 | SMF ↔ SMF | Coordinates a PDU session across a visited-network SMF and a home-network SMF (home-routed roaming) |
| N16a | SMF ↔ I-SMF | Coordinates a session when an Intermediate SMF is inserted mid-path (e.g., for local breakout) |
| N24 | PCF (visited) ↔ PCF (home) | Coordinates policy decisions across PLMNs for a roaming UE |
| N27 | NRF (visited) ↔ NRF (home) | Lets NFs in one PLMN discover NFs in the other, for roaming |
| N31 | NSSF (visited) ↔ NSSF (home) | Coordinates slice selection decisions across PLMNs for a roaming UE |
| N32 | SEPP ↔ SEPP | Secures all inter-PLMN SBI signalling passing between two operators' networks3 |
| N38 | I-SMF ↔ I-SMF, and V-SMF ↔ V-SMF | Coordination between intermediate/visited SMFs in multi-SMF topologies |
| N43 | PCF ↔ PCF | Direct PCF-to-PCF coordination |
Table 13. Roaming & Multi-SMF Reference Points
Slicing & admission control¶
| Reference Point | Between | Purpose |
|---|---|---|
| N23 | PCF ↔ NWDAF | PCF consumes network analytics to help inform policy decisions |
| N34 | NSSF ↔ NWDAF | NSSF consumes slice-load analytics to help inform slice selection |
| N80 | AMF ↔ NSACF | AMF checks/registers UE count against a slice's admission limits |
| N81 | SMF ↔ NSACF | SMF checks/registers PDU session count against a slice's admission limits |
| N82 | NSACF ↔ NEF | Exposes slice admission control status externally |
| N97 | NSACF ↔ NSACF | Coordinates slice admission counts across PLMNs, for roaming |
| N99 | NSACF ↔ NSACF | Coordinates admission counts between multiple NSACF instances within the same PLMN |
Table 14. Slicing & Admission Control Reference Points
Data, exposure & repository¶
| Reference Point | Between | Purpose |
|---|---|---|
| N17 | AMF ↔ 5G-EIR | AMF checks a UE's equipment identity against allow/block/grey lists |
| N18 | Any NF ↔ UDSF | Any NF can store/retrieve unstructured state data, keeping the NF itself stateless |
| N19 | PSA UPF ↔ PSA UPF | Connects two PDU Session Anchor UPFs for a 5G LAN-type (local switching) service |
| N29 | NEF ↔ SMF | Lets external requests (via NEF) reach session-management functionality on the SMF |
| N30 | PCF ↔ NEF | Exposes or consumes policy-related information via the NEF |
| N33 | NEF ↔ AF | The main path for an external/untrusted AF to reach 5GC capabilities |
| N35 | UDM ↔ UDR | UDM stores/retrieves subscription data from the UDR |
| N36 | PCF ↔ UDR | PCF stores/retrieves policy data from the UDR |
| N37 | NEF ↔ UDR | NEF stores/retrieves structured exposure/application data from the UDR |
| N51 | AMF ↔ NEF | Exposes AMF events/capabilities (e.g., mobility events) externally |
| N52 | NEF ↔ UDM | Exposes UDM-related subscriber data capabilities externally |
Table 15. Data, Exposure & Repository Reference Points
N28/N29/N30
Per 3GPP, the functionality of N28, N29, and N30 is defined in TS 23.503, not TS 23.501 itself.
Charging¶
| Reference Point | Between | Purpose |
|---|---|---|
| N28 | PCF ↔ CHF | PCF provides charging-related policy information to the CHF |
| N40 | SMF ↔ CHF | SMF reports session usage data to the CHF for charging |
| N41 | AMF ↔ CHF (HPLMN) | AMF reports charging-relevant events to the home-network CHF |
| N42 | AMF ↔ CHF (VPLMN) | AMF reports charging-relevant events to the visited-network CHF, in roaming |
Table 16. Charging Reference Points
N40/N41/N42
Functionality defined in TS 32.240, not TS 23.501 itself. N44–N49 are reserved for future allocation in the same spec.
UE capability & public warning¶
| Reference Point | Between | Purpose |
|---|---|---|
| N50 | AMF ↔ CBCF | Relays Public Warning System (emergency alert) notifications for broadcast to UEs |
| N55 | AMF ↔ UCMF | AMF resolves a UE's short radio capability ID to its full capability set |
| N56 | NEF ↔ UCMF | Exposes UE capability ID management externally |
| N57 | AF ↔ UCMF | Lets an AF interact with UE radio capability ID management |
Table 17. UE Capability & Public Warning Reference Points
Non-3GPP access & offload¶
| Reference Point | Between | Purpose |
|---|---|---|
| N58 | AMF ↔ NSSAAF | Supports slice-specific/SNPN secondary authentication and authorization |
| N59 | UDM ↔ NSSAAF | NSSAAF retrieves the subscriber data it needs to perform slice/SNPN authentication |
| N60 | AUSF ↔ NSWOF | Supports authentication when a UE offloads traffic to WLAN outside the 5GS3 |
| N83 | AUSF ↔ NSSAAF | Supports slice-specific/SNPN authentication procedures that involve the AUSF |
Table 18. Non-3GPP Access & Offload Reference Points
Time-sensitive networking¶
| Reference Point | Between | Purpose |
|---|---|---|
| N84 | TSCTSF ↔ PCF | Translates time-sync/TSC requirements into policy rules |
| N85 | TSCTSF ↔ NEF | Exposes time synchronization service capabilities externally |
| N86 | TSCTSF ↔ AF | Handles time-sync/TSC service requests from an application |
| N87 | TSCTSF ↔ UDM | Retrieves subscription data relevant to time synchronization service |
| N89 | TSCTSF ↔ AMF | Delivers time synchronization configuration down toward the RAN/UE path |
| N96 | TSCTSF ↔ NRF | Lets the TSCTSF discover other NFs it needs to interact with |
Table 19. Time-Sensitive Networking Reference Points
Edge computing¶
| Reference Point | Between | Purpose |
|---|---|---|
| N88 | SMF ↔ EASDF | SMF hands off relevant DNS queries so the EASDF can assist Edge Application Server discovery |
| N88a | I-SMF ↔ EASDF | Same purpose as N88, in deployments using an Intermediate SMF |
Table 20. Edge Computing Reference Points
Energy information¶
| Reference Point | Between | Purpose |
|---|---|---|
| N110 | EIF ↔ AF | Exposes network energy information to an application |
| N111 | EIF ↔ NEF | Exposes network energy information externally |
| N112 | EIF ↔ UDM | Ties energy information to subscriber/network data |
| N113 | EIF ↔ PCF | Lets energy information inform policy decisions |
| N114 | EIF ↔ SMF | Collects energy-relevant information from session management |
Table 21. Energy Information Reference Points
One more¶
| Reference Point | Between | Purpose |
|---|---|---|
| N115 | SMF+PGW-C ↔ NSSAAF | Supports slice-specific/SNPN authentication in EPS-interworking deployments (SMF co-located with a PGW control-plane function) |
Table 22. SMF+PGW-C ↔ NSSAAF Reference Point
Reference points vs. service names
Each service-based reference point has a matching service name once you're inside the SBA view — N11 is really the AMF consuming Nsmf and the SMF consuming Namf, N12 is the AMF consuming Nausf, and so on. The reference-point tables above are the easier mental model; the service names are what you'd actually see in a packet capture or an Open5GS log.
Useful Resources¶
- 3GPP TS 23.501 — System architecture for the 5G System: every NF, entity, and reference point on this page, defined in §4.2.3 and §4.2.7
- 3GPP TS 23.502 — Procedures for the 5G System: how these NFs interact step by step
- 3GPP TS 23.503 — Policy and charging control framework (N28/N29/N30/N43)
- 3GPP TS 33.501 — Security architecture (N32, N60)
- ShareTechnote — 5G Core Network Architecture
- Open5GS Quickstart — a real, minimal 5GC you can run yourself (covers the core dozen NFs, not the full Release 17–19 set above)
-
3GPP. (n.d.). System architecture for the 5G System (5GS) (Technical Specification TS 23.501). 3rd Generation Partnership Project. https://portal.3gpp.org/desktopmodules/Specifications/SpecificationDetails.aspx?specificationId=3144 ↩↩↩
-
Ryu, J. (n.d.). 5G Core Network Architecture. ShareTechnote. https://www.sharetechnote.com/html/5G/5G_NetworkArchitecture.html ↩
-
3GPP. (n.d.). Security architecture and procedures for 5G System (Technical Specification TS 33.501). 3rd Generation Partnership Project. https://portal.3gpp.org/desktopmodules/Specifications/SpecificationDetails.aspx?specificationId=3169 ↩↩
