Description
Authenticable Non-3GPP (AUN3) devices represent a crucial component in 5G's converged network architecture, enabling the secure integration of non-3GPP access networks with the 5G Core (5GC). These devices include Wi-Fi access points, fixed network gateways, and other access equipment that can establish trusted connections to the 5G system through standardized authentication procedures. The AUN3 framework allows these heterogeneous access technologies to be treated as trusted entry points into the 5G network, subject to the same security controls and policies as native 3GPP radio access.
The technical implementation of AUN3 involves several key components working in coordination. The Non-3GPP Interworking Function (N3IWF) serves as the primary interface between non-3GPP access networks and the 5G Core, establishing IPsec tunnels for secure data transmission. The Authentication Server Function (AUSF) performs the actual authentication of devices using Extensible Authentication Protocol (EAP) methods, while the Unified Data Management (UDM) stores authentication credentials and subscription data. The Access and Mobility Management Function (AMF) coordinates the overall authentication and registration procedures, ensuring seamless mobility between 3GPP and non-3GPP access.
The authentication process for AUN3 devices follows a sophisticated protocol flow defined in 3GPP specifications. When a device attempts to connect through non-3GPP access, it initiates an authentication request that travels through the N3IWF to the AMF. The AMF then coordinates with the AUSF to perform EAP-based authentication, which may involve various methods including EAP-AKA' for 5G-specific authentication or EAP-TLS for certificate-based authentication. During this process, the device proves its identity using credentials stored in the Universal Subscriber Identity Module (USIM) or through certificate-based mechanisms, while the network authenticates itself to the device to prevent man-in-the-middle attacks.
Security considerations for AUN3 devices are comprehensive and multi-layered. The framework mandates mutual authentication between the device and the network, ensuring both parties verify each other's identities. IPsec security associations provide confidentiality and integrity protection for user plane traffic, while control plane signaling is protected through NAS security mechanisms. The system also supports key hierarchy management, with separate keys derived for different security contexts including integrity protection, confidentiality, and key refresh procedures. This layered security approach ensures that even though the physical access medium differs from 3GPP radio, the security level remains equivalent.
The role of AUN3 in the 5G ecosystem extends beyond basic connectivity to enable advanced service capabilities. By authenticating non-3GPP devices, operators can offer seamless service continuity as users move between cellular and Wi-Fi networks, implement consistent quality of service policies across different access types, and enable network slicing that spans both 3GPP and non-3GPP domains. This convergence capability is particularly important for enterprise deployments, where private 5G networks often integrate with existing Wi-Fi infrastructure, and for fixed wireless access scenarios where 5G core services are delivered through non-cellular last-mile technologies.
Purpose & Motivation
The AUN3 framework was developed to address the growing need for converged network architectures that can seamlessly integrate diverse access technologies under a unified security and management umbrella. As 5G networks evolved beyond traditional cellular deployments, operators faced increasing pressure to incorporate Wi-Fi, fixed access, and other non-3GPP technologies into their service offerings while maintaining the robust security standards expected from 3GPP systems. Previous approaches to non-3GPP integration, such as those in 4G EPC, offered limited authentication capabilities and often treated non-3GPP access as secondary or less secure alternatives.
Historically, non-3GPP access integration suffered from fragmented security implementations and inconsistent authentication mechanisms across different technologies. Wi-Fi networks typically used WPA2/WPA3 with separate authentication servers, while fixed networks employed various proprietary authentication methods. This fragmentation created security gaps, complicated roaming scenarios, and prevented operators from applying consistent policy controls across their entire network footprint. The AUN3 framework addresses these limitations by providing a standardized, 3GPP-aligned authentication framework that brings non-3GPP devices under the same security governance as native 5G access.
The creation of AUN3 was motivated by several key industry trends: the proliferation of Wi-Fi 6/6E technologies offering performance comparable to 5G NR, the emergence of fixed wireless access as a primary broadband delivery method, and the growing enterprise demand for private networks that blend cellular and non-cellular technologies. By enabling secure authentication of non-3GPP devices, the framework supports these use cases while maintaining the end-to-end security principles that are fundamental to 3GPP systems. This allows operators to leverage their existing infrastructure investments while expanding service coverage and capabilities through heterogeneous access integration.
Classification
Detected Changes Across Releases
from 3GPP Change RequestsSpecific changes extracted from the „Change history“ tables of 3GPP specifications (24 CRs across 1 releases). Complements the general historical overview above with the evidence-based evolution of this function.
In Release 18, the AUN3 (Authenticable Non-3GPP) function was introduced to enable the authentication of non-3GPP devices via a 5G Residential Gateway (5G-RG), which acts on their behalf in NAS signaling with the AMF. The release specifies procedures for EAP-based authentication (e.g., EAP-AKA', EAP-TLS), defines separate 5GMM contexts for each AUN3 device, and supports devices both with and without 5G key hierarchy by providing either a Master Session Key or a K_WAGF key. It also covers scenarios for registration rejection, de-registration, and service area restrictions for these devices behind a 5G-RG.
- Support of AUN3/NAUN3 device behind 5G-RG TS 24.501CR5421
- Requirements for supporting AUN3 devices connected to 5G-RG TS 24.501CR5643
- Impact on registration procedure for authenticating AUN3 device behind 5G-RG TS 24.501CR5645
- EAP methods for authenticating AUN3 devices behind 5G-RG TS 24.501CR5646
- Authentication for AUN3 devices supporting 5G key hierarchy TS 24.501CR5811
- Impact on NAS signalling for supporting authentication of AUN3 devices supporting and not supporting 5G key hierarchy TS 24.501CR5812
+ 18 more changes
Explore further
Broader topics and technologies where AUN3 plays a role.
Defining Specifications
3GPP specifications that define or reference AUN3, with the latest known release. Sourced from the 3GPP document catalog — see methodology.
| Specification | Title | Release |
|---|---|---|
| TS 24.501 vj50 | 5G NAS Protocols Specification | Rel-19 |
| TS 24.502 vj20 | 5G Core Access via Non-3GPP Networks; Stage 3 | Rel-19 |
| TS 24.526 vj30 | UE Policies for 5GS; Stage 3 | Rel-19 |
| TS 29.413 vj00 | NGAP for Non-3GPP Access | Rel-19 |
| TS 33.501 vk00 | 5G Security Architecture and Procedures | Rel-20 |
| TS 38.413 vj10 | NG Application Protocol (NGAP) | Rel-19 |