5G-GUTI

5G Globally Unique Temporary Identifier

Identifier →
Introduced in Rel-15

5G-GUTI is a temporary identifier assigned to a UE in 5G networks to protect the user's permanent subscription identity, used for network access, paging, and service requests.

Category
Identifier
Introduced
Rel-15
Where
Core Network › 5G Core
Specifications
6 specs
5G-GUTI Description Purpose Related Classification Detected Changes Specifications

Description

The 5G-GUTI is a fundamental identifier in 5G system architecture, designed to uniquely and temporarily identify a User Equipment (UE) within the network. It serves as a privacy-preserving alias for the permanent Subscription Permanent Identifier (SUPI), ensuring that the user's long-term identity is not exposed during radio communication, which mitigates tracking and eavesdropping risks. The identifier is structured to support efficient network operations, including registration, service requests, and mobility management, by allowing the network to correlate sessions and context without repeatedly querying the SUPI.

Architecturally, the 5G-GUTI is assigned by the Access and Mobility Management Function (AMF) during initial registration procedures. It consists of two main components: the GUAMI (Globally Unique AMF Identifier) and the 5G-TMSI (5G Temporary Mobile Subscriber Identity). The GUAMI uniquely identifies the AMF that allocated the 5G-GUTI, comprising a Mobile Country Code (MCC), Mobile Network Code (MNC), and an AMF Region ID, AMF Set ID, and AMF Pointer. The 5G-TMSI is a unique identifier within that AMF, used to distinguish the UE locally. This hierarchical structure allows for scalable routing and management, as the network can determine the serving AMF from the GUAMI and then use the 5G-TMSI to locate the specific UE context.

In operation, the UE includes the 5G-GUTI in signaling messages, such as Registration Requests or Service Requests, to identify itself to the network. The AMF validates the 5G-GUTI to retrieve the UE's security context and subscription data from its local storage or the Unified Data Management (UDM). If the 5G-GUTI is invalid or expired, the network may initiate a re-authentication procedure, potentially requesting the SUPI securely. The identifier can be reallocated or updated during mobility events, like handovers or inter-AMF transfers, to reflect changes in the serving network entity. This dynamic assignment supports seamless mobility across different AMFs and network slices.

The role of the 5G-GUTI extends beyond identity protection; it is integral to network efficiency and scalability. By using a temporary identifier, the network reduces signaling overhead, as the AMF can quickly resolve the UE context without extensive database queries. It also facilitates paging and notification procedures, where the 5G-TMSI is used to page the UE within a specific area. In scenarios involving network slicing, the 5G-GUTI helps associate the UE with the appropriate slice instance, ensuring that mobility and service continuity are maintained across slice boundaries. Overall, the 5G-GUTI is a cornerstone of 5G security and operational design, balancing privacy, performance, and flexibility.

Purpose & Motivation

The 5G-GUTI was created to address critical privacy and security vulnerabilities present in previous mobile generations, such as 4G/LTE, where temporary identifiers like the GUTI could still be linked to permanent identities over time, enabling potential tracking. In 5G, enhanced privacy is a core requirement, driven by regulations like GDPR and increased user awareness. The 5G-GUTI solves this by providing a robust mechanism to obscure the SUPI during radio transmissions, preventing passive attackers from correlating user activities or locations with their permanent identity. This separation ensures that even if temporary identifiers are intercepted, they cannot be easily mapped to the user's long-term subscription.

Historically, identifiers in 2G/3G/4G networks, such as the IMSI or 4G-GUTI, had limitations in privacy protection and scalability. The 4G-GUTI, for example, could be used to track users if not frequently refreshed, and its structure was less optimized for distributed architectures like 5G's service-based interface. The 5G-GUTI introduces a more hierarchical and globally unique design, aligning with 5G's cloud-native and sliced network environments. It supports efficient mobility management across diverse deployment scenarios, including non-public networks and edge computing, by enabling clear routing to the correct AMF instance.

Furthermore, the 5G-GUTI addresses operational challenges in large-scale networks by reducing dependency on central databases for every UE interaction. By allowing the AMF to manage temporary identifiers locally, it decreases latency and signaling load, which is crucial for 5G's low-latency use cases like URLLC. The identifier also facilitates network slicing by embedding AMF-specific information, ensuring that UE contexts are handled within the appropriate slice. Overall, the 5G-GUTI embodies 5G's principles of enhanced security, privacy by design, and scalable architecture, solving legacy issues while enabling future innovations.

Classification

Part of5G-TMSI
Specific types5G-TMSI
Related approachesSUPIAMFGUAMI

Release Timeline

Detected Changes Across Releases

from 3GPP Change Requests

Specific changes extracted from the „Change history“ tables of 3GPP specifications (25 CRs across 5 releases). Complements the general historical overview above with the evidence-based evolution of this function.

Rel-15 9 changes

In Release 15, the 5G-GUTI was newly defined as a core identifier for subscriber confidentiality, constructed from a GUAMI and a 32-bit 5G-TMSI to identify the UE and its serving AMF. The release specified its structure, its shortened form (5G-S-TMSI) for efficient radio signalling, and procedures for its allocation and use in messages like the REGISTRATION REQUEST. It also introduced the mapping mechanism between the 5G-GUTI and the EPS GUTI for mobility with E-UTRAN.

  • Adding a new 5G-GUTI allocation condition TS 23.501CR0958
  • Use of 5G-GUTI in creation of an ATTACH REQUEST message TS 24.301CR3152
  • Correction on 5G-GUTI type encoding TS 24.501CR0329
  • Alignment of 5G-GUTI assignment with SA3 TS 24.501CR0470
  • Distinction in AMF-side abnormal cases for generic UE configuration update procedure with respect to 5G-GUTI update TS 24.501CR0547
  • 5G-GUTI provided to lower layer TS 24.501CR0836

+ 3 more changes

Rel-16 5 changes

In Release 16, enhancements for the 5G-GUTI included its inclusion as an additional GUTI during initial registration when the UE holds a 4G-GUTI, and the definition of its format as a username within an NAI structure. The release also addressed scenarios where a 5G-GUTI mapped from a 4G-GUTI is used, requiring the inclusion of an ATTACH REQUEST message within the REGISTRATION REQUEST message. Furthermore, specific handling was introduced for Standalone Non-Public Networks (SNPNs) where the 5G-GUTI is not globally unique, and octet alignment for the 5G-GUTI within the 5GS mobile identity information element was specified.

  • 5G-GUTI as additional guti in initial registration and UE holds 4G-GUTI TS 24.501CR0782
  • 5G-GUTI not globally unique in an SNPN TS 24.501CR1458
  • Octet alignment for 5G-GUTI in 5GS mobile identity IE TS 24.501CR1583
  • Inclusion of ATTACH REQUEST message in REGISTRATION REQUEST message during initial registration when 5G-GUTI mapped from 4G-GUTI is used TS 24.501CR0793
  • Native 5G-GUTI in Additional GUTI IE TS 24.501CR2258
Rel-17 8 changes

In Release 17, the 5G-GUTI function was enhanced with clarifications and new procedures for specific scenarios, including its reallocation after a mobile-terminated service request and during procedures like mobility registration updates for SNPNs. The release also introduced clarifications for maintaining the 5G-GUTI in abnormal cases and for the mapped 5G-GUTI terminology used during interworking with E-UTRAN. Furthermore, specific procedures were defined for 5G-GUTI reallocation when the UE resumes from 5GMM-IDLE mode with a suspend indication and when the timer T3346 is running.

  • Reference to UCU procedure is missing for a 5G-GUTI reallocation variant TS 24.501CR2979
  • Clarification of maintaining 5G-GUTI in an abnormal case TS 24.501CR3016
  • UE identity when onboarding in SNPN for which the UE has 5G-GUTI TS 24.501CR3392
  • NID of SNPN which assigned 5G-GUTI in mobility registration update TS 24.501CR3384
  • MRU procedure for allocation of 5G-GUTI when T3346 is running TS 24.501CR3727
  • Clarifications on the mapped 5G-GUTI terminology TS 24.501CR4080

+ 2 more changes

Rel-18 1 change

In Release 18, the specification introduced a new procedure for 5G-GUTI selection in the context of Equivalent SNPNs. This enhancement specifically addresses how the temporary identifier is chosen when a UE is operating within Standalone Non-Public Networks that are considered equivalent. The change provides a defined mechanism for this selection scenario, building upon the existing 5G-GUTI structure and its role in subscriber identity confidentiality.

  • Equivalent SNPNs: 5G-GUTI selection TS 24.501CR4997
Rel-19 2 changes

In Release 19, the specification was enhanced to define explicit UE actions upon the deletion of a 5G-GUTI. Furthermore, it addressed a lost text scenario to ensure proper handling of the REGISTRATION COMPLETE message when a 5G-GUTI is received during an initial registration procedure.

  • UE actions upon 5G-GUTI deletion TS 24.501CR6943
  • Lost text on REGISTRATION COMPLETE upon received 5G-GUTI in initial registration TS 24.501CR6661

Explore further

Broader topics and technologies where 5G-GUTI plays a role.

Defining Specifications

3GPP specifications that define or reference 5G-GUTI, with the latest known release. Sourced from the 3GPP document catalog — see methodology.

SpecificationTitleRelease
TS 23.003 vj50 Numbering, addressing and identification in 3GPP Rel-19
TS 23.501 vk00 5G System Architecture Stage 2 Rel-20
TS 24.301 vj60 NAS protocol for Evolved Packet System Rel-19
TS 24.501 vj50 5G NAS Protocols Specification Rel-19
TS 24.890 vg00 5G NAS Protocol for 5GS Stage 3 Rel-16
TS 29.518 vj50 AMF Service Based Interface Protocol Rel-19
Patrick Zandl

About the author: Patrick Zandl (b. 1974)

Telecommunications specialist, technology journalist (founder of the Mobil server), and developer who has been running since 2025 — the largest Czech-language resource on AI-assisted programming. Formerly Chief Wizard Architect at Prusa3D and head of development for Turris at CZ.NIC; currently a consultant and instructor on AI implementation in companies.