5G-S-TMSI

5G S-Temporary Mobile Subscription Identifier

Identifier →
Introduced in Rel-15

5G-S-TMSI is a temporary identifier assigned to a UE in 5G systems to protect the user's permanent subscription identity during initial network access and paging, used for radio resource control procedures.

Category
Identifier
Introduced
Rel-15
Where
Core Network › 5G Core
Specifications
4 specs
5G-S-TMSI Description Purpose Related Classification Detected Changes Specifications

Description

The 5G-S-TMSI (5G S-Temporary Mobile Subscription Identifier) is a critical temporary identifier within the 5G Core Network (5GC) architecture, specifically managed by the Access and Mobility Management Function (AMF). It is assigned to a User Equipment (UE) after a successful initial registration procedure. The primary purpose of the 5G-S-TMSI is to serve as a concise, temporary alias for the user's permanent and privacy-sensitive Subscription Permanent Identifier (SUPI), thereby preventing the SUPI from being transmitted in the clear over the radio interface.

Architecturally, the 5G-S-TMSI is generated and allocated by the serving AMF. It is structured to contain information that allows the network to efficiently route and manage the UE. The identifier is composed of two main parts: the AMF Set ID, AMF Pointer, and a 5G-TMSI (Temporary Mobile Subscription Identifier). The AMF Set ID identifies a group of AMFs for redundancy and load balancing, while the AMF Pointer specifies a particular AMF within that set. The 5G-TMSI is a unique number assigned by that specific AMF to the UE for the duration of its registration context. This structure enables the Radio Access Network (RAN) to determine which AMF instance is serving the UE without needing to decode the full NAS message.

In operation, the 5G-S-TMSI is used extensively in signaling procedures. During the initial random-access procedure when a UE is in RRC_IDLE or RRC_INACTIVE state, it includes the 5G-S-TMSI in the RRCSetupComplete message if it has one stored from a previous registration. More importantly, it is the primary identifier used in the Paging message broadcast by the gNB. When the network needs to reach a UE (e.g., for an incoming session), it pages the UE using the 5G-S-TMSI. Upon receiving a paging message containing its 5G-S-TMSI, the UE responds with a Service Request, including the same identifier, allowing the network to re-establish the connection and retrieve the full UE context from the AMF.

The 5G-S-TMSI's role extends beyond simple identification; it is fundamental to network efficiency and security. By using this temporary identifier for frequent over-the-air transmissions like paging and connection resumption, the permanent SUPI is shielded from eavesdroppers, addressing a significant privacy concern present in earlier generations. Furthermore, its compact size (shorter than the full GUTI from 4G in many cases) reduces signaling overhead. The inclusion of AMF routing information directly within the identifier allows for efficient and scalable AMF selection and re-selection processes within the 5GC's service-based architecture, supporting features like AMF mobility and load balancing.

Purpose & Motivation

The 5G-S-TMSI was created to address critical shortcomings in subscriber identity management from previous cellular generations, primarily focusing on enhanced privacy and signaling efficiency. In 4G LTE, the Globally Unique Temporary Identifier (GUTI) served a similar purpose but had a larger size and a different structural logic tied to the MME. The 5G system introduced a redesigned, flatter core network with a clear separation between the Access and Mobility Management Function (AMF) and the Session Management Function (SMF). This new architecture necessitated a temporary identifier optimized for the service-based interfaces and the specific procedures of 5G, such as the RRC_INACTIVE state.

A key problem the 5G-S-TMSI solves is the protection of the permanent subscriber identity (SUPI) from being transmitted in plain text over the radio link. In early mobile systems, the International Mobile Subscriber Identity (IMSI) was sometimes sent unprotected, creating a major privacy vulnerability for tracking subscribers. The 5G-S-TMSI, by replacing the SUPI in almost all radio signaling after initial authentication, effectively mitigates this threat. Its design also solves the problem of efficient network node routing. By embedding AMF Set and Pointer information, the RAN can directly determine which AMF instance holds the UE's context, enabling faster connection resumption and more efficient paging without requiring complex lookup procedures, which is essential for supporting the low-latency use cases envisioned for 5G.

Classification

Part ofGUTI
Related approachesSUPI

Release Timeline

Detected Changes Across Releases

from 3GPP Change Requests

Specific changes extracted from the „Change history“ tables of 3GPP specifications (7 CRs across 2 releases). Complements the general historical overview above with the evidence-based evolution of this function.

Rel-15 2 changes

In Release 15, the 5G-S-TMSI was newly introduced as a shortened form of the 5G-GUTI, constructed from the AMF Set ID, AMF Pointer, and 5G-TMSI to enable more efficient radio signalling procedures like paging. This release also defined its specific structure and introduced the related Truncated 5G-S-TMSI for use as a 40-bit UE identifier. Furthermore, procedures for its derivation and context retrieval in EPS interworking scenarios were established.

  • EPS Interworking: 5G-S-TMSI derivation and context retrieval TS 23.501CR0085
  • Length of 5G-S-TMSI TS 24.501CR0745
Rel-16 5 changes

In Release 16, the key new feature for the 5G-S-TMSI was the introduction of the **Truncated 5G-S-TMSI**, a 40-bit UE identifier derived from the full 5G-S-TMSI. This was configured by the AMF during Registration and UE Configuration Update procedures to enable more efficient radio signalling, specifically for use in NAS signalling for CP Relocation Indication and paging. The release also defined the associated configuration and its acknowledgement between the network and the UE.

  • Truncated 5G-S-TMSI over NAS TS 24.501CR1932
  • NAS signalling of CP Relocation Indication Truncated 5G-S-TMSI Parameters TS 23.501CR2088
  • Acknowledgement of truncated 5G-S-TMSI configuration TS 24.501CR2173
  • Definition of Truncated 5G-S-TMSI TS 23.003CR0577
  • Correction on Truncated 5G-S-TMSI TS 23.003CR0596

Explore further

Broader topics and technologies where 5G-S-TMSI plays a role.

Defining Specifications

3GPP specifications that define or reference 5G-S-TMSI, with the latest known release. Sourced from the 3GPP document catalog — see methodology.

SpecificationTitleRelease
TS 23.003 vj50 Numbering, addressing and identification in 3GPP Rel-19
TS 23.501 vk00 5G System Architecture Stage 2 Rel-20
TS 24.501 vj50 5G NAS Protocols Specification Rel-19
TS 24.890 vg00 5G NAS Protocol for 5GS Stage 3 Rel-16
Patrick Zandl

About the author: Patrick Zandl (b. 1974)

Telecommunications specialist, technology journalist (founder of the Mobil server), and developer who has been running since 2025 — the largest Czech-language resource on AI-assisted programming. Formerly Chief Wizard Architect at Prusa3D and head of development for Turris at CZ.NIC; currently a consultant and instructor on AI implementation in companies.