5G Architecture

Understanding the foundational structure of 5G networks, deployment modes, and interface definitions.

SA vs NSA Deployment

5G deployment follows two primary architectural paradigms: Standalone (SA) and Non-Standalone (NSA). The Non-Standalone architecture, defined in 3GPP Release 15 Option 3 series, leverages the existing LTE Evolved Packet Core (EPC) while introducing 5G New Radio (NR) access through dual connectivity. In NSA mode, the LTE eNB serves as the master node (MN) and the 5G gNB acts as the secondary node (SN), with the control plane anchored to EPC via the S1-MME interface. This approach allowed operators to rapidly deploy 5G services without waiting for full core network upgrades, utilizing the X2 interface for inter-RAN coordination and enabling early enhanced Mobile Broadband (eMBB) use cases.

Standalone architecture, specified in 3GPP Release 15 Option 2, represents the fully-native 5G deployment where both the radio access network and core network are 5G-specific. The 5G Core (5GC) replaces EPC entirely, introducing a service-based architecture (SBA) with cloud-native network functions communicating over HTTP/2-based service interfaces. SA mode enables the full spectrum of 5G capabilities including ultra-reliable low-latency communication (URLLC), massive machine-type communication (mMTC), and advanced network slicing. The control plane in SA uses the N1 interface between UE and AMF, while user plane traffic traverses N3 (RAN to UPF) and N6 (UPF to DN) interfaces. SA deployment requires greenfield infrastructure but delivers end-to-end latency below 1ms and supports advanced features like RRC_INACTIVE state and NR standalone mobility procedures.

SA vs NSA Architecture Comparison
NSA (Option 3x) UE eNB (MN) LTE Master gNB (SN) 5G Secondary EPC Uu S1 X2 SA (Option 2) UE gNB 5G RAN AMF SMF UPF Uu N2 N4 N3 Control Plane: EPC anchored User Plane: Split bearer (LTE+NR) Control Plane: 5GC service-based User Plane: UPF-based forwarding

5GC vs EPC

The 5G Core (5GC) represents a paradigm shift from the Evolved Packet Core (EPC) in 4G LTE. While EPC was built on a monolithic, node-based architecture with dedicated hardware appliances (MME, SGW, PGW, HSS), 5GC adopts a cloud-native, service-based architecture (SBA) where network functions (NFs) are decoupled, stateless, and communicate via standardized service-based interfaces. Each NF in 5GC exposes services to other NFs through HTTP/2 REST APIs over the service-based interface (SBI), enabling flexible deployment, independent scaling, and rapid service innovation. The control plane and user plane separation (CUPS) in 5GC is mandatory and more granular than EPC's optional CUPS, allowing user plane functions (UPFs) to be distributed at the network edge for MEC deployments.

Key architectural differences include the replacement of the MME with the Access and Mobility Management Function (AMF), which handles only connection and mobility management while delegating session management to the Session Management Function (SMF). The Serving Gateway (SGW) and Packet Data Network Gateway (PGW) are replaced by the UPF, which can be deployed in a chain to support complex traffic steering. The Home Subscriber Server (HSS) evolves into the Unified Data Management (UDM) and Authentication Server Function (AUSF), separating data storage from authentication logic. Additionally, 5GC introduces entirely new functions like the Network Slice Selection Function (NSSF), Network Exposure Function (NEF), and Network Repository Function (NRF) that have no direct EPC equivalents, enabling capabilities essential for network slicing and API exposure to third-party applications.

AspectEPC (4G)5GC (5G)
ArchitectureNode-based, monolithicService-based, cloud-native
Control/User PlaneOptional CUPSMandatory separation
Mobility ManagementMMEAMF
Session ManagementMME/SGW/PGWSMF + UPF
Subscriber DataHSSUDM + AUSF + UDR
Interface ProtocolGTP-C, DiameterHTTP/2, JSON
QoS ModelEPS bearer (QCI)QoS Flow (5QI)
Network SlicingNot supportedNative support (NSSF)

RAN Evolution: gNB and ng-eNB

The 5G Radio Access Network (RAN) introduces two key node types: the gNB (Next Generation Node B) and the ng-eNB (Next Generation evolved Node B). The gNB is the full 5G base station operating in either Frequency Range 1 (FR1: 450 MHz – 7.125 GHz) or Frequency Range 2 (FR2: 24.25 GHz – 52.6 GHz, mmWave). It supports all NR features including massive MIMO, beamforming, and flexible numerologies. The ng-eNB is an upgraded LTE base station that connects to the 5G Core instead of EPC, enabling operators to leverage existing LTE infrastructure within a 5GC deployment (Option 5 or Option 7 architectures). Both node types connect to 5GC via the NG interface, with the gNB using N2 (control plane) and N3 (user plane), while the ng-eNB uses the same interfaces but operates with LTE air interface capabilities.

The gNB architecture follows a split design defined in 3GPP TR 38.801, with the option to separate into Central Unit (CU) and Distributed Unit (DU). The CU handles higher layer protocols (RRC, SDAP, PDCP) while the DU manages real-time functions (RLC, MAC, PHY). This split enables flexible deployment scenarios: the CU can be centralized in data centers while DUs are distributed at cell sites, supporting fronthaul networks with eCPRI (enhanced Common Public Radio Interface) connectivity. The F1 interface between CU and DU carries both control (F1-C) and user plane (F1-U) traffic. This disaggregated architecture is fundamental to Open RAN initiatives, allowing multi-vendor interoperability and cloud-RAN (C-RAN) deployments where baseband processing is pooled and virtualized.

5G Interfaces (N1-N40)

N1
UE ↔ AMF
NAS signaling interface carrying Registration, PDU Session, and Mobility Management messages over the RRC connection.
N2
RAN ↔ AMF
Control plane interface using NG-AP over SCTP. Handles UE context, handover signaling, and NAS transport.
N3
RAN ↔ UPF
User plane interface using GTP-U over UDP. Carries encapsulated user data packets between RAN and UPF.
N4
SMF ↔ UPF
Session management interface using PFCP. SMF provisions packet forwarding rules, QoS policies, and traffic steering.
N5
AF ↔ PCF
Application function to policy control interface for dynamic QoS and traffic routing requests from third-party apps.
N6
UPF ↔ DN
Interface to external Data Networks (Internet, enterprise VPN). IPv4/IPv6 packet exchange point.
N7
SMF ↔ PCF
Policy control interface for SMF to fetch PCC rules, QoS policies, and charging parameters per PDU session.
N8
UDM ↔ AMF
Subscription data retrieval. AMF fetches authentication vectors, access policies, and UE context from UDM.
N10
UDM ↔ SMF
Session-related subscription data. SMF retrieves DNN, SSC mode, and default QoS profiles.
N11
AMF ↔ SMF
PDU Session management. AMF relays SM NAS messages and handles SMF discovery/selection.
N12
AMF ↔ AUSF
Authentication service interface. AMF requests UE authentication from AUSF using 5G-AKA or EAP-AKA'.
N22
AMF ↔ NSSF
Network slice selection. NSSF provides allowed slice information and directs AMF to target slice instances.
5G Service-Based Architecture (SBA)
Service-Based Interface (SBI) — HTTP/2 + JSON AMF N11,N12,N15 SMF N10,N11,N7 PCF N5,N7,N15 UDM N8,N10,N13 AUSF N12,N13 NRF NF Discovery NSSF N22,N31,N27 NEF N29,N33 AF N5,N33 UDR N18,Nudr UPF N3,N4,N6,N9
Habib Mrad
📞 009613839525
GitHub LinkedIn

Network Elements

Deep-dive into 5G Core Network Functions, their roles, interfaces, and signal flows.

Control Plane Functions

AMF — Access & Mobility Management Function
Replaces MME | Interfaces: N1, N2, N8, N11, N12, N15, N22
The AMF is the control plane entry point for the RAN. It handles UE registration, connection management, mobility tracking, and NAS signaling relay. Unlike the MME, the AMF does not handle session management — it delegates this to the SMF via N11. The AMF maintains UE context including security context, access stratum keys, and registration area lists. It supports RRC_INACTIVE state for power-efficient IoT devices and performs slice-aware AMF selection through the NSSF.
SMF — Session Management Function
Replaces MME/SGW-C/PGW-C | Interfaces: N4, N7, N10, N11, N40
The SMF is responsible for PDU session management, IP address allocation, and UPF selection. It establishes, modifies, and releases PDU sessions, manages QoS flows by binding 5QI to DRBs, and controls traffic steering through UPF insertion. The SMF communicates with PCF via N7 for dynamic policy decisions and with UPF via N4 (PFCP) to program packet detection rules (PDRs), forwarding action rules (FARs), and usage reporting rules (URRs).
PCF — Policy Control Function
Replaces PCRF | Interfaces: N5, N7, N15, N28
The PCF provides unified policy framework for access, mobility, and session management. It maintains policy decisions based on subscription data, network conditions, and application requirements. The PCF supports both NPCF (service-based) and Rx-like interfaces (N5) for AF interaction. It delivers PCC rules including QoS parameters (5QI, GFBR, MFBR), charging methods, and traffic steering policies. PCF can be deployed hierarchically with a master PCF and multiple area PCFs.
UDM — Unified Data Management
Replaces HSS | Interfaces: N8, N10, N13
The UDM stores subscription data including SUPI, authentication vectors, access policies, DNN configurations, and subscribed S-NSSAIs. It exposes services via Nudm to AMF (N8), SMF (N10), and AUSF (N13). The UDM supports 5G-specific features like UE parameter update via UDM configuration update commands, subscription to data change notifications, and slice-specific subscription data. It typically interfaces with UDR (Unified Data Repository) for persistent storage.
AUSF — Authentication Server Function
New in 5GC | Interfaces: N12, N13
The AUSF handles authentication procedures for 3GPP and non-3GPP access. It supports 5G-AKA (primary), EAP-AKA' (for non-3GPP), and 5G-EAP-TLS. The AUSF verifies authentication confirmation from the UE, generates anchor keys (Kausf), and provides authentication result to AMF via N12. It retrieves authentication subscription data from UDM via N13. The AUSF enables secondary authentication for DN-specific AAA and supports unified authentication across trusted and untrusted non-3GPP access.
NSSF — Network Slice Selection Function
New in 5GC | Interfaces: N22, N27, N31
The NSSF is unique to 5G and enables network slicing by selecting Network Slice Instance (NSI) identifiers and determining allowed NSSAI for the UE. When a UE registers with requested S-NSSAIs, the NSSF validates against subscription data and operator policies, then returns the allowed NSSAI and target AMF set. It supports slice-specific AMF selection, load balancing across slice instances, and slice availability queries. The NSSF is fundamental to 5G's ability to provide logically isolated virtual networks on shared infrastructure.

User Plane & Support Functions

UPF — User Plane Function
Replaces SGW-U/PGW-U | Interfaces: N3, N4, N6, N9
The UPF is the cornerstone of 5G user plane architecture. It performs packet routing and forwarding, packet inspection, QoS handling per QoS flow, lawful intercept, and traffic usage reporting. UPFs can be chained (N9 interface) to support complex service function chaining and MEC scenarios. The SMF controls UPF behavior via N4 using PFCP, programming PDRs to classify traffic, FARs to define forwarding actions, QERs for QoS enforcement, and URRs for charging. UPFs support both IPv4 and IPv6, GTP-U encapsulation, and optional SRv6.
NRF — Network Repository Function
New in 5GC | Interfaces: SBI (all NFs)
The NRF maintains a registry of all available NF instances, their services, capacities, and profiles. NFs register themselves (NFProfile) and discover peer NFs via the NRF using service-based discovery procedures. It supports NF management including registration updates, deregistration, and heartbeat monitoring. The NRF enables dynamic service mesh topology, load-aware NF selection, and service authorization. In roaming scenarios, the NRF facilitates NF discovery across different PLMNs through SEPP-mediated queries.
NEF — Network Exposure Function
New in 5GC | Interfaces: N29, N33, T8
The NEF exposes 5G network capabilities to external Application Functions (AFs) through standardized APIs (CAPIF). It translates external requests into internal 5GC service calls, handling authentication, authorization, and throttling. Key capabilities exposed include: QoS on-demand (N5 via PCF), traffic routing (AF influence on UPF selection), monitoring (UE reachability, location reporting), and PFD management. The NEF acts as a security gateway for external applications, preventing direct access to internal NFs.
AF — Application Function
External to 5GC | Interfaces: N5, N33
The AF represents third-party application servers that interact with 5GC to influence traffic handling. Through N5 (direct or via NEF), the AF can request specific QoS treatment, influence UPF selection for edge computing, subscribe to UE reachability notifications, and provide Packet Flow Descriptions (PFDs) for application detection. Examples include video streaming servers requesting guaranteed bandwidth, or industrial control systems requiring URLLC slice access. The AF is not part of the operator's 5GC but is essential for vertical industry use cases.

Signal Flow: UE Registration via AMF

UE gNB AMF AUSF UDM RRC Setup Request RRC Setup Complete Initial UE Message (Registration) Nausf_UEAuth_Authenticate Nudm_UECM_Get + Auth Auth Vectors (RAND, AUTN, XRES*) Auth Response (RAND, AUTN) Authentication Request NAS Auth Request NAS Auth Response (RES*) Security Mode Command Nausf_UEAuth_Confirm Auth Result + Kausf Nudm_SDM_Get (Subscribed NSSAI) Subscription Data + NSSP Registration Accept RRC Reconfig + NAS Reg Accept Registration Complete N2 Info Ack
Habib Mrad
📞 009613839525
GitHub LinkedIn

Air Interface (NR)

New Radio physical layer, numerologies, frequency ranges, and advanced antenna technologies.

NR Numerologies and Subcarrier Spacing

5G New Radio (NR) introduces a flexible physical layer design centered around multiple numerologies, defined by the subcarrier spacing (SCS) configuration parameter μ (mu). Unlike LTE which fixed subcarrier spacing at 15 kHz, NR supports μ = 0 through 4, corresponding to SCS values of 15, 30, 60, 120, and 240 kHz respectively. This flexibility allows NR to operate efficiently across diverse spectrum bands and use cases. Lower numerologies (μ=0,1) with 15/30 kHz SCS are optimized for coverage-centric deployments in sub-6 GHz (FR1), providing longer cyclic prefixes and better performance in high-delay-spread environments. Higher numerologies (μ=2,3,4) with 60/120/240 kHz SCS are designed for mmWave operation in FR2, where wider channel bandwidths and shorter slot durations enable the extreme data rates and low latency required for eMBB and URLLC applications.

The slot duration scales inversely with SCS: at μ=0, one slot is 1 ms; at μ=1, it is 0.5 ms; at μ=2, 0.25 ms; at μ=3, 0.125 ms; and at μ=4, 0.0625 ms. Each slot contains 14 OFDM symbols regardless of numerology. NR also introduces the concept of mini-slots (2, 4, or 7 symbols) for ultra-low latency transmission, allowing data to start mid-slot rather than waiting for slot boundaries. The number of slots per subframe equals 2^μ. A resource block in NR spans 12 subcarriers in the frequency domain, but the bandwidth of a resource block increases with μ (180 kHz at μ=0, 360 kHz at μ=1, up to 2880 kHz at μ=4). This scalable design ensures that NR can maintain consistent scheduling granularity while adapting to channel bandwidths ranging from 5 MHz to 400 MHz.

μSCS (kHz)Slot DurationSlots/SubframeUse Case
0151 ms1FR1, eMBB, coverage
1300.5 ms2FR1, eMBB, mid-band
2600.25 ms4FR1/FR2, URLLC
31200.125 ms8FR2, mmWave
42400.0625 ms16FR2, wide bandwidth

Frequency Ranges: FR1 and FR2

5G NR operates across two distinct frequency ranges defined by 3GPP. Frequency Range 1 (FR1) spans 450 MHz to 7.125 GHz and encompasses traditional cellular spectrum including existing LTE bands, 3.5 GHz mid-band (n78, n77), and 600/700 MHz low-band (n71, n28). FR1 provides excellent coverage propagation characteristics, with signals penetrating buildings and traveling long distances with relatively low path loss. This makes FR1 ideal for nationwide coverage deployment and reliable connectivity in urban, suburban, and rural environments. Most initial 5G deployments worldwide utilized FR1, often through dynamic spectrum sharing (DSS) where NR and LTE share the same carriers.

Frequency Range 2 (FR2), commonly known as mmWave, covers 24.25 GHz to 52.6 GHz and represents the true "greenfield" spectrum for 5G. FR2 offers contiguous bandwidths of 400 MHz or more per carrier, enabling multi-gigabit peak data rates exceeding 10 Gbps. However, mmWave signals experience significantly higher free-space path loss (increasing with the square of frequency), limited diffraction around obstacles, and high atmospheric absorption (especially at 28 GHz and 60 GHz oxygen absorption bands). These propagation challenges necessitate dense small cell deployments, advanced beamforming, and massive MIMO to concentrate energy in narrow beams. FR2 is primarily deployed in high-density urban hotspots, stadiums, and indoor venues where capacity demands are extreme and line-of-sight conditions can be engineered.

FR1 vs FR2 Spectrum Characteristics
FR1 (Sub-6 GHz) 450 MHz — 7.125 GHz Coverage: Excellent Bandwidth: Up to 100 MHz Bands: n1, n3, n28, n41, n77, n78 Use: Nationwide coverage, eMBB FR2 (mmWave) 24.25 GHz — 52.6 GHz Coverage: Limited (LOS preferred) Bandwidth: Up to 400 MHz (1 GHz agg) Bands: n257, n258, n260, n261 Use: Hotspots, stadiums, FWA

Beamforming and Massive MIMO

Massive MIMO (Multiple-Input Multiple-Output) is a cornerstone technology of 5G NR, scaling traditional MIMO from 8x8 in LTE-Advanced to 64x64, 128x128, or even 256x256 antenna configurations in 5G. By deploying large arrays of antenna elements at the base station, massive MIMO enables spatial multiplexing of multiple users on the same time-frequency resources through precoding. In TDD systems, channel reciprocity allows the gNB to estimate downlink channels from uplink sounding reference signals (SRS), enabling computationally efficient precoding without explicit CSI feedback. This yields significant spectral efficiency gains — 3GPP targets 3x improvement over LTE — and enables aggressive frequency reuse.

Beamforming in NR operates in two modes: analog beamforming (using phase shifters for RF beam steering, essential for mmWave due to high cost of fully-digital architectures) and hybrid beamforming (combining analog beam steering with digital baseband precoding). NR defines a beam management framework including P1 (initial beam pair establishment), P2 (beam refinement), and P3 (UE-specific beam adjustment) procedures. The SSB (Synchronization Signal Block) burst set provides beam-sweeping during initial access, with up to 64 SSB beams in FR2. CSI-RS (Channel State Information Reference Signals) enable dynamic beam tracking and channel quality estimation. For FR2 operation, beam recovery procedures handle beam failure by triggering re-establishment through candidate beam identification and random access.

OFDM and OFDMA in 5G NR

5G NR continues to use Orthogonal Frequency Division Multiplexing (OFDM) as the fundamental waveform for both downlink and uplink, a departure from LTE which used SC-FDMA in the uplink to preserve peak-to-average power ratio (PAPR) for UE power amplifiers. NR's adoption of CP-OFDM for uplink enables flexible resource allocation and simplified transceiver design, though DFT-s-OFDM (similar to SC-FDMA) remains as an optional uplink waveform for coverage-limited scenarios where PAPR matters. The OFDM waveform provides inherent robustness against multipath fading through cyclic prefix insertion and enables fine-grained frequency-domain resource allocation.

Orthogonal Frequency Division Multiple Access (OFDMA) is the multiple access scheme derived from OFDM, where different users are assigned distinct sets of resource blocks in the frequency domain. NR enhances OFDMA with several key features: flexible resource allocation starting at the symbol level (mini-slots), bandwidth parts (BWP) allowing UEs to operate on subsets of the carrier bandwidth to save power, and configurable slot formats supporting self-contained slots where downlink control, data, and uplink acknowledgment can coexist within a single slot for ultra-low latency. The resource grid in NR consists of resource elements (REs) organized into resource blocks (RBs), with each RB containing 12 subcarriers by 1 slot (14 symbols). Physical channels including PDSCH, PUSCH, PDCCH, and PUCCH are mapped to specific REs within this grid according to scheduling decisions from the MAC layer.

NR Resource Grid Structure
NR Resource Grid (1 Slot = 14 OFDM Symbols) SC 0 SC 6 SC 12 Sym 0 Sym 3 Sym 6 Sym 9 Sym 12 PDCCH PDSCH CSI-RS DM-RS Guard Band / Unused
Habib Mrad
📞 009613839525
GitHub LinkedIn

Core Technologies

Network slicing, edge computing, virtualization, and advanced session management.

Network Slicing

Network slicing is one of the defining innovations of 5G, enabling the creation of multiple virtual networks with distinct characteristics atop a shared physical infrastructure. Each network slice is an end-to-end logical network comprising dedicated or shared resources across the RAN, transport, and core domains. A slice is identified by the Single Network Slice Selection Assistance Information (S-NSSAI), a 32-bit identifier consisting of an 8-bit Slice/Service Type (SST) and a 24-bit Slice Differentiator (SD). The SST defines the slice category: eMBB (1), URLLC (2), mMTC (3), V2X (4), and others standardized by 3GPP. The SD allows operators to create multiple instances of the same slice type for different tenants or services.

The slice lifecycle is managed through the Network Slice Management Function (NSMF) in the management plane, which orchestrates slice creation, modification, and termination via interactions with the RAN NSSI (Network Slice Subnet Instance), Transport NSSI, and Core NSSI. In the control plane, the NSSF determines which slices a UE is allowed to access based on subscription data and operator policies. The AMF is slice-aware, with different AMFs potentially serving different slices. The SMF and UPF are slice-specific, ensuring isolation of session states and traffic forwarding paths. Slice isolation can be hard (dedicated physical resources), soft (dedicated virtual resources on shared hardware), or hybrid, depending on service requirements and cost constraints.

End-to-End Network Slicing Architecture
RAN Slice gNB-eMBB gNB-URLLC gNB-mMTC Shared CU / DU Resources Transport Slice eMBB: FlexE 10Gbps URLLC: TSN 1ms mMTC: Best Effort Core Slice AMF eMBB AMF URLLC SMF eMBB SMF URLLC Shared UDR / NRF / NSSF

Multi-Access Edge Computing (MEC)

Multi-Access Edge Computing (MEC), standardized by ETSI and integrated into 3GPP 5G architecture, brings cloud computing capabilities to the edge of the network, within one to few hops of the end user. In 5G, MEC is natively supported through the UPF's flexible placement and the AF's ability to influence traffic routing. The MEC host typically co-locates with a local UPF instance (UL-CL UPF or Branching Point UPF), enabling traffic breakout to local application servers without traversing the central core. This architecture achieves end-to-end latencies of 10-20 ms, critical for applications like industrial automation, augmented reality, and autonomous vehicle coordination.

The MEC platform exposes APIs to application developers for radio network information (RNIS), location services, bandwidth management, and UE identity. Through the NEF or direct N5 interface, MEC applications can request dynamic QoS adjustments, subscribe to UE mobility events (for service continuity during handover), and influence UPF selection to ensure user plane anchoring at the optimal edge location. The MEC orchestrator, working with the 5G network orchestrator, manages the lifecycle of MEC applications, resource allocation, and service chaining. Key deployment models include: MEC at the base station site (most distributed), MEC at the aggregation point, and MEC at the network edge data center, each offering different latency/capacity tradeoffs.

SDN/NFV Integration

Software-Defined Networking (SDN) and Network Functions Virtualization (NFV) are foundational enablers of the 5G service-based architecture. NFV decouples network functions from proprietary hardware, allowing them to run as virtualized network functions (VNFs) or cloud-native network functions (CNFs) on commodity servers, containers, and Kubernetes orchestration platforms. The European Telecommunications Standards Institute (ETSI) NFV framework defines the Management and Orchestration (MANO) architecture comprising the NFV Orchestrator (NFVO), VNF Manager (VNFM), and Virtualized Infrastructure Manager (VIM). In 5G, core network functions are deployed as microservices in containers, managed by Kubernetes, enabling auto-scaling, self-healing, and rolling updates.

SDN provides centralized, programmable control of network forwarding behavior through the separation of control and data planes. In 5G transport networks, SDN controllers manage the fronthaul, midhaul, and backhaul segments, dynamically provisioning paths based on slice requirements. For example, a URLLC slice may require deterministic low-latency paths with Time-Sensitive Networking (TSN) support, while an eMBB slice may prioritize bandwidth over latency. The integration of SDN with 5GC allows the SMF to dynamically influence transport path selection through the Policy Control Function, creating an end-to-end programmable network spanning radio, core, and transport domains. This synergy is essential for delivering the service agility and operational efficiency promised by 5G.

QoS Flows and PDU Sessions

5G introduces a fundamentally different Quality of Service (QoS) architecture compared to 4G LTE. While LTE used EPS bearers with a one-to-one mapping between radio bearers and core network tunnels, 5G decouples these layers through the concept of QoS Flows. A PDU (Packet Data Unit) Session is the 5G equivalent of a PDN connection, providing IP connectivity (IPv4, IPv6, or IPv4v6) or Ethernet connectivity between the UE and a Data Network (DN). Within each PDU session, one or more QoS Flows carry traffic with different QoS requirements. Each QoS Flow is identified by a QoS Flow Identifier (QFI, 1-63) and is associated with a 5G QoS Indicator (5QI) that defines standardized QoS characteristics including priority level, packet delay budget, packet error rate, and averaging window.

The mapping between QoS flows and radio bearers is many-to-one: multiple QoS flows can be mapped to a single DRB (Data Radio Bearer) if they share similar QoS requirements, or each QoS flow can have a dedicated DRB for granular handling. The SMF provisions QoS rules to the UE (via NAS) and to the RAN (via N2) and UPF (via N4). The UPF performs packet classification using Packet Detection Rules (PDRs) to map incoming packets to QoS flows based on IP 5-tuple, application IDs, or other criteria. Reflective QoS allows the UE to derive uplink QoS rules from downlink packet markings, reducing signaling overhead. The 5QI table in 3GPP TS 23.501 defines standardized 5QIs for GBR (Guaranteed Bit Rate), Non-GBR, and Delay-Critical GBR services, with values 1-4 typically reserved for GBR and 5-9 for Non-GBR traffic.

5QITypePriorityPacket DelayPacket ErrorExample Use
1GBR20100 ms10^-2Conversational Voice
2GBR40150 ms10^-3Conversational Video
3GBR3050 ms10^-3Real-Time Gaming
5Non-GBR10100 ms10^-6IMS Signaling
6Non-GBR60300 ms10^-6Video Streaming
7Non-GBR70100 ms10^-3Voice, Video, Interactive
8Non-GBR80300 ms10^-6Best Effort (TCP)
9Non-GBR90300 ms10^-6Background Download
69Non-GBR560 ms10^-6Mission Critical
79Non-GBR6550 ms10^-2V2X Messages
82DC-GBR1910 ms10^-4Discrete Automation
Habib Mrad
📞 009613839525
GitHub LinkedIn

5G Security

Authentication, encryption, and roaming security mechanisms in 5G networks.

5G-AKA Authentication

5G-AKA (Authentication and Key Agreement) is the primary authentication mechanism defined in 3GPP TS 33.501 for 3GPP access in 5G. It represents an evolution of EPS-AKA used in 4G, with enhanced security features addressing known vulnerabilities in previous generations. The 5G-AKA procedure begins when the UE sends a Registration Request containing the 5G-GUTI or SUCI. The AMF forwards the authentication request to the AUSF, which retrieves authentication vectors (RAND, AUTN, XRES*, KAUSF) from the UDM. Unlike EPS-AKA where the RES (response) was sent in plaintext over the air, 5G-AKA introduces RES* — a hashed version of the RES using the serving network name, preventing rogue base station attacks where an attacker could replay authentication challenges.

The authentication confirmation procedure adds an additional layer of security. After the UE computes RES* and sends it to the AMF, the AMF forwards it to the AUSF for verification. The AUSF compares RES* against XRES* and returns an authentication result along with the anchor key KAUSF. The AMF then derives the KAMF (AMF key) from KAUSF, and subsequently derives KNASenc, KNASint, KgNB, and other keys for NAS and AS security. 5G-AKA also supports sequence number (SQN) freshness checks to prevent replay attacks, and the AUTN includes an authentication token with MAC and SQN to verify network legitimacy to the UE. For non-3GPP access, EAP-AKA' is used, which leverages the Extensible Authentication Protocol framework for integration with enterprise Wi-Fi and untrusted access networks.

SUPI and SUCI

The Subscription Permanent Identifier (SUPI) is the 5G equivalent of the IMSI in 4G, uniquely identifying a subscriber within a PLMN. SUPI can take several formats: IMSI-based (starting with MCC+MNC), network-specific identifier (NSI), global line identifier (GLI), or global cable identifier (GCI). Unlike the IMSI which was transmitted in plaintext during initial registration, 5G mandates privacy protection for the SUPI through the Subscription Concealed Identifier (SUCI). The SUCI is generated by encrypting the SUPI using the home network's public key before transmission over the air interface.

The SUCI generation process uses Elliptic Curve Integrated Encryption Scheme (ECIES) with the home operator's public key provisioned in the USIM/UE. The UE encrypts the SUPI along with a fresh ephemeral public key and sends the resulting SUCI to the network. Only the home network's private key can decrypt the SUCI to recover the SUPI. This mechanism prevents passive eavesdroppers from tracking subscribers by their permanent identifiers. After successful authentication, the AMF assigns a temporary identifier (5G-GUTI) for subsequent signaling, further enhancing privacy. The 5G-GUTI is refreshed periodically or upon inter-AMF mobility to prevent long-term tracking. For emergency sessions, a null-scheme SUCI may be used when the UE lacks valid credentials.

NAS and AS Security

5G security is layered into Non-Access Stratum (NAS) security and Access Stratum (AS) security, each protecting different protocol layers. NAS security protects signaling messages between the UE and AMF, including registration, session management, and mobility messages. After successful authentication, the AMF initiates a Security Mode Command (SMC) procedure, negotiating encryption and integrity algorithms for NAS signaling. 5G mandates support for 128-NEA1 (SNOW 3G), 128-NEA2 (AES), and 128-NEA3 (ZUC) for encryption, and 128-NIA1, 128-NIA2, 128-NIA3 for integrity protection. The UE must support all three algorithms, while the network must support at least NEA2/NIA2. NAS messages include a message authentication code (MAC-I) for integrity verification and a sequence number to prevent replay attacks.

AS security protects radio interface signaling (RRC) and user plane data between the UE and gNB. The gNB derives AS keys (KRRCenc, KRRCint, KUPenc, KUPint) from KgNB provided by the AMF during initial context setup. AS security algorithms are negotiated via the SecurityModeCommand RRC message. 5G introduces user plane integrity protection as an optional feature (configurable per DRB), addressing a long-standing gap in 4G where only control plane had integrity protection. This is particularly important for URLLC and mission-critical services where data integrity is paramount. Key refresh procedures (horizontal and vertical key derivation) ensure forward secrecy: horizontal derivation refreshes keys within the same gNB using a COUNT value, while vertical derivation generates fresh keys during handover or RRC state transitions.

SEPP for Roaming Security

The Security Edge Protection Proxy (SEPP) is a new network function introduced in 5G to secure inter-PLMN (roaming) signaling. In 4G LTE, roaming interfaces (S8, S9, S10) relied on IPsec or TLS at the transport layer, but application-layer messages remained unprotected end-to-end, exposing sensitive subscriber data to intermediate transit networks. The SEPP addresses this by providing application-layer security for all N32 interface messages between home and visited PLMNs. Each SEPP acts as a security gateway at the edge of its operator's network, performing mutual TLS authentication, message encryption, and integrity protection.

The SEPP operates in two modes: PRINS (Protection with IPsec and TLS for N32) and TLS-only. In PRINS mode, IPsec tunnels provide network-layer protection while TLS provides transport-layer security. The SEPP also handles topology hiding, masking internal network topology (NF FQDNs, IP addresses) from the roaming partner. For message filtering, the SEPP applies operator-defined policies to determine which IEs (Information Elements) can be passed transparently, modified, or blocked. The SEPP certificate infrastructure uses the GSMA PRD FS.38 PKI, with SEPP certificates issued by authorized certificate authorities. This end-to-end application-layer security ensures that even if transit networks are compromised, roaming signaling remains confidential and tamper-evident.

5G Security Key Hierarchy
K (USIM/UDM) CK, IK (from AKA) KAUSF (Anchor Key) KSEAF KAMF KNASenc KNASint KgNB KUPenc
Habib Mrad
📞 009613839525
GitHub LinkedIn

End-to-End Call Flow

Animated step-by-step walkthrough of UE registration, PDU session establishment, and handover procedures.

Interactive UE Registration Flow

UE Registration Procedure
1
UE → gNB: RRC Setup Request
UE sends RRCSetupRequest on CCCH using SRB0. Includes ue-Identity (random value or 5G-S-TMSI part1) and establishmentCause (mo-Signalling, mt-Access, etc.).
2
gNB → UE: RRC Setup + NAS Transport
gNB responds with RRCSetup on CCCH, allocating SRB1. UE then sends RRCSetupComplete containing NAS Registration Request with SUCI/5G-GUTI, requested NSSAI, and UE security capabilities.
3
gNB → AMF: Initial UE Message (N2)
gNB forwards NAS message in InitialUEMessage over N2 (NG-AP/SCTP). Includes RAN UE NGAP ID, NAS-PDU, user location info (TAI, ECGI), and RRC establishment cause.
4
AMF → AUSF: Authentication Request (N12)
AMF invokes Nausf_UEAuthentication_Authenticate with servingNetworkName and SUCI. AUSF retrieves auth vectors from UDM via N13 (Nudm_UEAuthentication_Get).
5
AUSF → AMF: Authentication Response
AUSF returns authType (5G-AKA), RAND, AUTN, ngKSI, and XRES*. AMF stores XRES* and forwards RAND, AUTN to UE via Authentication Request NAS message.
6
UE → AMF: Authentication Response (RES*)
UE computes RES = f2K(RAND), then RES* = KDF(RES, servingNetworkName). UE sends Authentication Response NAS message containing RES*.
7
AMF → AUSF: Authentication Confirmation
AMF forwards RES* to AUSF via Nausf_UEAuthentication_Confirm. AUSF compares RES* with XRES*. On success, returns Kausf and authResult = "AUTHENTICATION_SUCCESS".
8
AMF → UE: Security Mode Command
AMF derives KAMF from Kausf, then KNASenc/KNASint. Sends SecurityModeCommand NAS message with selected NAS algorithms, ngKSI, and replayed UE security capabilities.
9
UE → AMF: Security Mode Complete
UE verifies MAC, derives same keys, and responds with SecurityModeComplete. All subsequent NAS messages are encrypted and integrity-protected.
10
AMF → UDM: Get Subscription Data (N8)
AMF retrieves subscriber data including allowed NSSAI, default S-NSSAI, DNN list, and access restrictions. UDM also registers AMF in UE context management.
11
AMF → UE: Registration Accept
AMF sends Registration Accept with 5G-GUTI, allowed NSSAI, configured NSSAI, TAI list, and network feature support. UE is now registered and can request PDU sessions.

PDU Session Establishment Flow

PDU Session Establishment
1
UE → AMF: PDU Session Establishment Request
UE sends NAS message with S-NSSAI, DNN, PDU session type (IPv4/IPv6/Ethernet), and requested SSC mode. Included in UL NAS Transport.
2
AMF → SMF: Nsmf_PDUSession_CreateSMContext
AMF selects SMF (via NRF or local config) and sends create request with SUPI, DNN, S-NSSAI, and N1 SM container. SMF creates SM context and allocates SM context ID.
3
SMF → UDM: Get Session Data (N10)
SMF retrieves subscription data: allowed DNNs, default 5QI, SSC modes, and static IP address if configured. SMF also subscribes to data change notifications.
4
SMF → PCF: SM Policy Association (N7)
SMF requests PCC rules from PCF including: 5QI, ARP, GFBR/MFBR for GBR, charging method, and traffic steering rules. PCF may apply AF influence.
5
SMF → UPF: N4 Session Establishment
SMF selects UPF and provisions PFCP session with PDRs (packet detection), FARs (forwarding), QERs (QoS), and URRs (usage reporting). UPF allocates N3 TEID.
6
SMF → AMF: N1N2MessageTransfer
SMF sends PDU Session Establishment Accept (NAS) and N2 SM Info (PDU Session ID, QFI, UPF N3 TEID) to AMF for forwarding to UE and RAN.
7
AMF → gNB: N2 PDU Session Request
AMF sends NGAP message to gNB with NAS PDU and N2 SM info. gNB configures DRB mapping to QoS flows and prepares radio resources.
8
gNB → UE: RRC Reconfig + NAS Accept
gNB sends RRCReconfiguration with DRB-to-QoS flow mapping. UE configures PDCP/RLC and responds with RRCReconfigurationComplete. UE now has IP connectivity.
9
gNB → AMF: N2 PDU Session Response
gNB confirms successful radio bearer setup with allocated DRB IDs and RAN N3 TEID. AMF forwards to SMF to complete the N4 binding.
10
SMF → UPF: N4 Session Modification
SMF updates UPF with RAN-side N3 TEID and completes the bi-directional GTP-U tunnel. PDU session is now active; user plane traffic can flow UE↔UPF↔DN.

Xn-Based Handover Flow

Xn Handover (gNB to gNB)
1
Source gNB: Handover Decision
Source gNB measures UE signal quality (RSRP/RSRQ). Based on A3 event (neighbor > serving + offset), decides to trigger handover to target gNB.
2
Source → Target: Handover Request (Xn)
Source sends HO Request over Xn-C with UE context (security capabilities, DRB configs, QoS flows), target cell ID, and RRC config from source.
3
Target gNB: Admission Control + Resource Allocation
Target performs admission control, reserves radio resources, and derives new AS security keys from NH (Next Hop) or NCC. Prepares RRCReconfiguration.
4
Target → Source: Handover Request Ack
Target responds with HO Request Ack containing target-to-source transparent container (RRCReconfiguration), C-RNTI, and dedicated RACH preamble if allocated.
5
Source → UE: RRC Reconfiguration (HO Command)
Source sends MobilityFromNRCommand (or RRCReconfiguration in EN-DC) with target cell config. UE synchronizes to target and performs random access.
6
UE → Target: RACH + RRC Reconfig Complete
UE sends RACH preamble (contention-free if dedicated preamble provided). Target responds with RAR. UE sends RRCReconfigurationComplete on target.
7
Target → Source: UE Context Release (Xn)
Target sends UE Context Release to source, indicating successful handover. Source releases UE context and stops DL data forwarding.
8
Target → AMF: Path Switch Request (N2)
Target sends Path Switch Request to AMF with new TAI/ECGI, UE security capabilities, and list of accepted/rejected PDU sessions. AMF forwards to SMF.
9
SMF → UPF: N4 Session Modification
SMF updates UPF with new N3 endpoint (target gNB TEID/IP). UPF switches DL path to target. SMF may update PCF if location-based policies apply.
10
AMF → Target: Path Switch Ack + UE Context Release
AMF sends Path Switch Request Ack. Target sends UE Context Release Command to source. Handover complete; UE is now served by target gNB.
Habib Mrad
📞 009613839525
GitHub LinkedIn

Interactive Simulations

Hands-on labs and visualizations to reinforce 5G concepts.

Network Slice Selector

Select a slice type to see resource allocation, latency targets, and use case characteristics.

eMBB
URLLC
mMTC

Enhanced Mobile Broadband (eMBB)

Peak Data Rate
20 Gbps DL
10 Gbps UL
Latency
4 ms
User plane
Mobility
500 km/h
High-speed train
Spectral Efficiency
30 bps/Hz
Downlink peak

SST Value: 1 | Typical 5QI: 6, 7, 8, 9 | Resource Allocation: Best effort with high priority for video streaming. Wide bandwidth allocation (100 MHz FR1 or 400 MHz FR2). Massive MIMO with up to 64 layers. UPF anchored at regional data center.

Use Cases: 4K/8K video streaming, AR/VR immersive experiences, fixed wireless access (FWA), hotspot capacity, large file downloads.

Ultra-Reliable Low Latency Communication (URLLC)

Latency
1 ms
End-to-end
Reliability
99.9999%
Packet delivery
Jitter
< 1 μs
Time sync
Availability
99.999%
Service uptime

SST Value: 2 | Typical 5QI: 82, 83 (Delay-Critical GBR) | Resource Allocation: Pre-emptive scheduling, mini-slot (2-4 symbols), grant-free uplink, redundant transmission. UPF at edge (MEC). TSN integration for deterministic transport.

Use Cases: Industrial automation (Industry 4.0), remote surgery, autonomous vehicle platooning, smart grid protection, AR-assisted maintenance.

Massive Machine-Type Communication (mMTC)

Device Density
1M/km²
Connections per cell
Battery Life
10+ years
On AA battery
Data Rate
< 1 Mbps
Small bursts
Coverage
+20 dB
vs. legacy MCL

SST Value: 3 | Typical 5QI: 9 (Non-GBR) | Resource Allocation: Grant-free access, repetitions for coverage extension, power-saving mode (PSM), extended DRX (eDRX). Narrow bandwidth (5-20 MHz). UPF at centralized location. NB-IoT / RedCap integration.

Use Cases: Smart metering, asset tracking, environmental sensors, smart agriculture, wearables, connected logistics.

Beamforming Visualizer

Visualizing beam pattern for a uniform linear array (ULA). More antennas produce narrower beams with higher gain (beamforming gain ∝ N). Current: 16 elements.

5G vs 4G Performance Comparison
Network Load / Users50%
4G LTE
Peak Throughput1 Gbps
User Plane Latency25 ms
Connection Density100k/km²
Spectral Efficiency15 bps/Hz
5G NR
Peak Throughput20 Gbps
User Plane Latency4 ms
Connection Density1M/km²
Spectral Efficiency30 bps/Hz

Adjust the slider to simulate network load. 5G maintains low latency under load due to flexible numerology and shorter TTI, while 4G latency degrades significantly with increased scheduling delays.

PDU Session Builder

Build a PDU session by selecting network functions and parameters. See how the SMF orchestrates the session.

UE Request
Slice Selection
SMF Selection
UPF Placement
QoS Profile

Session Configuration Result

Select parameters above to see the orchestrated session configuration.

Habib Mrad
📞 009613839525
GitHub LinkedIn

Glossary & Reference

Searchable dictionary of 60+ 5G terms and acronyms.

5G-AKA
5G Authentication and Key Agreement. Primary authentication method for 3GPP access, using RES* to prevent rogue base station attacks.
Security
5G-GUTI
5G Globally Unique Temporary Identifier. Temporary UE identifier assigned by AMF to protect subscriber privacy after initial registration.
Security
5QI
5G QoS Identifier. Scalar value (1-255) that references standardized QoS characteristics including priority, delay budget, and error rate.
QoS
AMF
Access and Mobility Management Function. 5G Core NF handling UE registration, connection management, mobility, and NAS signaling.
Core
AUSF
Authentication Server Function. 5G Core NF responsible for UE authentication using 5G-AKA or EAP-AKA'.
Security
BWP
Bandwidth Part. A contiguous subset of PRBs on a given carrier, allowing UE to operate with narrower bandwidth to save power.
Radio
C-RNTI
Cell Radio Network Temporary Identifier. Unique UE identifier within a cell, used for DCCH/DTCH addressing on PDCCH.
Radio
CUPS
Control and User Plane Separation. Architecture principle separating control functions (SMF) from user plane forwarding (UPF).
Architecture
CU / DU
Central Unit / Distributed Unit. Split gNB architecture where CU handles RRC/PDCP and DU handles RLC/MAC/PHY, connected via F1 interface.
RAN
DC
Dual Connectivity. UE connected to two cells simultaneously (MCG and SCG) for throughput aggregation and mobility robustness.
Radio
DNN
Data Network Name. Identifies the target data network for a PDU session, equivalent to APN in 4G.
Core
DRB
Data Radio Bearer. Radio bearer carrying user plane data between UE and gNB, mapped to one or more QoS flows.
Radio
eCPRI
enhanced Common Public Radio Interface. Fronthaul interface between DU and RU (Radio Unit), carrying compressed IQ data.
RAN
eDRX
extended Discontinuous Reception. Power-saving mechanism allowing IoT devices to sleep for extended periods (minutes to hours).
IoT
eMBB
enhanced Mobile Broadband. 5G use case targeting high data rates (20 Gbps peak) and wide area coverage.
Use Case
EPC
Evolved Packet Core. 4G LTE core network comprising MME, SGW, PGW, HSS, and PCRF.
Legacy
FAR
Forwarding Action Rule. PFCP rule in UPF defining how matched packets are forwarded (pass, drop, buffer, redirect).
Core
FR1
Frequency Range 1. 5G sub-6 GHz spectrum (450 MHz – 7.125 GHz) with excellent coverage characteristics.
Spectrum
FR2
Frequency Range 2. 5G mmWave spectrum (24.25 – 52.6 GHz) offering wide bandwidths up to 400 MHz per carrier.
Spectrum
GFBR / MFBR
Guaranteed / Maximum Flow Bit Rate. QoS parameters defining minimum guaranteed and maximum allowed bit rate for GBR QoS flows.
QoS
gNB
Next Generation Node B. 5G base station supporting NR air interface, massive MIMO, and beamforming in FR1/FR2.
RAN
GTP-U
GPRS Tunneling Protocol - User Plane. Encapsulation protocol used on N3 (RAN-UPF) and N9 (UPF-UPF) interfaces.
Transport
Handover
Procedure transferring UE context and radio connection from source to target cell, via Xn (intra-AMF) or N2 (inter-AMF).
Mobility
HTTP/2
Transport protocol for 5G service-based interfaces, enabling multiplexed streams, header compression, and server push.
Protocol
KAMF
Key for AMF. Derived from KAUSF, used to derive NAS and AS security keys during registration.
Security
MEC
Multi-Access Edge Computing. Edge cloud platform co-located with local UPF for ultra-low latency application hosting.
Edge
Massive MIMO
Large-scale antenna arrays (64+ elements) enabling spatial multiplexing, beamforming, and high spectral efficiency.
Radio
mMTC
massive Machine-Type Communication. 5G use case for high-density IoT (1M devices/km²) with 10+ year battery life.
Use Case
μ (mu)
Numerology index (0-4) defining subcarrier spacing: 15×2^μ kHz. Determines slot duration and bandwidth scalability.
Radio
NAS
Non-Access Stratum. Signaling layer between UE and AMF, handling registration, session management, and mobility.
Protocol
NEF
Network Exposure Function. 5G Core NF exposing network capabilities to external AFs via standardized APIs.
Core
NG-AP
NG Application Protocol. Control plane protocol on N2 interface between RAN and AMF, carried over SCTP.
Protocol
NRF
Network Repository Function. 5G Core NF maintaining registry of available NF instances and their services.
Core
NR
New Radio. 5G air interface standard (3GPP 38-series) supporting flexible numerologies, massive MIMO, and mmWave.
Radio
NSSAI / S-NSSAI
Network Slice Selection Assistance Information. Identifies a network slice; S-NSSAI = SST (8 bits) + SD (24 bits).
Slicing
NSSF
Network Slice Selection Function. 5G Core NF determining allowed slices and target AMF set for UE registration.
Core
OFDM / OFDMA
Orthogonal Frequency Division Multiplexing / Multiple Access. 5G waveform enabling flexible resource allocation in time-frequency grid.
Radio
PCF
Policy Control Function. 5G Core NF providing unified policy framework for access, mobility, and session management.
Core
PDR
Packet Detection Rule. PFCP rule in UPF classifying packets based on IP 5-tuple, application ID, or SDF filters.
Core
PDU Session
Packet Data Unit Session. 5G equivalent of PDN connection, providing IP/Ethernet connectivity between UE and DN.
Core
PFCP
Packet Forwarding Control Protocol. Interface protocol (N4) between SMF and UPF for session rule provisioning.
Protocol
PRACH
Physical Random Access Channel. Uplink channel used by UE for initial access, contention resolution, and handover RACH.
Radio
PSS / SSS
Primary / Secondary Synchronization Signal. Signals enabling UE time/frequency sync and physical cell ID detection.
Radio
QFI
QoS Flow Identifier. 6-bit value (0-63) identifying a QoS flow within a PDU session, carried in GTP-U extension header.
QoS
QoS Flow
Finest granularity of QoS differentiation in 5G. One or more QoS flows mapped to a DRB, identified by QFI.
QoS
RAN
Radio Access Network. Comprises gNBs/ng-eNBs providing radio connectivity to UEs, connected to 5GC via NG interface.
RAN
RB / RE
Resource Block (12 subcarriers × 1 slot) / Resource Element (1 subcarrier × 1 symbol). Basic NR resource units.
Radio
RedCap
Reduced Capability NR. 5G device category for mid-tier IoT with reduced bandwidth, antenna count, and complexity.
IoT
RRC
Radio Resource Control. Layer 3 protocol managing connection establishment, mobility, measurement, and radio configuration.
Protocol
SBA
Service-Based Architecture. 5G Core design where NFs expose services via HTTP/2 APIs over a common service bus.
Architecture
SCS
Subcarrier Spacing. NR supports 15, 30, 60, 120, 240 kHz via numerologies μ=0-4, enabling flexible deployment.
Radio
SCTP
Stream Control Transmission Protocol. Reliable transport for N2 (NG-AP) and SIGTRAN, supporting multi-streaming.
Transport
SDAP
Service Data Adaptation Protocol. New NR layer mapping QoS flows to DRBs, inserting QFI in DL/PDCP headers.
Protocol
SEPP
Security Edge Protection Proxy. Roaming security gateway providing application-layer encryption for inter-PLMN signaling.
Security
SFBC
Space-Frequency Block Coding. Transmit diversity scheme using Alamouti coding across antennas and subcarriers.
Radio
SMF
Session Management Function. 5G Core NF handling PDU session lifecycle, IP allocation, UPF control via N4/PFCP.
Core
SR / BSR
Scheduling Request / Buffer Status Report. Uplink control signaling for requesting UL resources from gNB scheduler.
Radio
SSB
Synchronization Signal Block. Burst of PSS/SSS/PBCH beams used for initial cell search and beam acquisition.
Radio
SSB Burst Set
Set of up to 64 SSBs transmitted in different beams for beam-sweeping during initial access in FR2.
Radio
SUPI / SUCI
Subscription Permanent Identifier (private) / Concealed Identifier (encrypted over air). Replaces plaintext IMSI.
Security
TAI / Tracking Area
Tracking Area Identity. Geographical area where UE can move without performing Tracking Area Update.
Mobility
TEID
Tunnel Endpoint Identifier. 32-bit value identifying GTP-U tunnel endpoints between RAN and UPF.
Transport
TTI
Transmission Time Interval. Duration of one scheduling unit; 1 slot in NR (0.0625 - 1 ms depending on μ).
Radio
UDM
Unified Data Management. 5G Core NF storing subscription data, replacing HSS from 4G.
Core
UDR
Unified Data Repository. Persistent data store for UDM, PCF, and NEF subscription/policy data.
Core
UE
User Equipment. 5G terminal device comprising USIM, radio transceiver, and protocol stack.
General
UL-CL
Uplink Classifier. UPF function branching traffic to local DN (MEC) while maintaining central anchor.
Core
UPF
User Plane Function. 5G Core NF handling packet forwarding, QoS enforcement, and traffic steering.
Core
URLLC
Ultra-Reliable Low Latency Communication. 5G use case targeting <1ms latency and 99.9999% reliability.
Use Case
VNF / CNF
Virtualized / Cloud-Native Network Function. Software implementation of network functions on VMs or containers.
Virtualization
Habib Mrad
📞 009613839525
GitHub LinkedIn

Assessment Center

Test your knowledge with three certification-level exams.

Foundation Exam
20 Questions | 30 Minutes
Covers 5G basics, architecture fundamentals, key terminology, and SA vs NSA concepts. Pass: 70%
Intermediate Exam
25 Questions | 40 Minutes
Deep-dive into network functions, interfaces, air interface numerology, QoS flows, and security procedures. Pass: 75%
Advanced Exam
20 Questions | 35 Minutes
Network slicing orchestration, MEC deployment, roaming security (SEPP), call flow analysis, and troubleshooting. Pass: 80%
Habib Mrad
📞 009613839525
GitHub LinkedIn

My Progress

Track your learning journey across all modules and exams.

Module Completion

Architecture
0%
Network Elements
0%
Air Interface
0%
Core Technologies
0%
Security
0%
Call Flow
0%
Simulations
0%
Glossary
0%

Exam History

No exams completed yet. Take an exam to see your results here.

Habib Mrad
📞 009613839525
GitHub LinkedIn