DN-AAA

Data Network Authentication, Authorization and Accounting

Core Network →
Introduced in Rel-16

DN-AAA is a 5G Core Network entity that provides Authentication, Authorization, and Accounting services specifically for a user's connection to an external Data Network.

Category
Core Network
Introduced
Rel-16
Where
Core Network › 5G Core
Specifications
2 specs
DN-AAA Description Purpose Specifications

Description

DN-AAA is a logical function defined in the 5G System (5GS) architecture, residing within or interfacing with an external Data Network (DN). Its primary role is to execute AAA procedures for User Equipment (UE) accessing services in that DN. It operates in conjunction with, but is separate from, the 3GPP AAA functions performed by the Unified Data Management (UDM) and Authentication Server Function (AUSF) for core network access. The DN-AAA interacts with the 5G Core Network via the Network Exposure Function (NEF) or directly with the Session Management Function (SMF) depending on the deployment scenario.

How it works involves several steps. When a UE establishes a PDU Session to a DN that requires external AAA, the SMF may trigger DN-specific authentication/authorization. The SMF can communicate with the DN-AAA server, typically using the Diameter or RADIUS protocol over the N6 interface or via the NEF if the DN-AAA is a third-party service. The DN-AAA server authenticates the user (often using credentials separate from the 3GPP subscription), authorizes the specific service or QoS profile, and can begin accounting for the data session. The authorization result (e.g., permitted QoS, session duration limits) is conveyed back to the SMF, which enforces these policies within the 3GPP network for that PDU Session.

Key components include the DN-AAA server itself, which holds user profiles and policies for the DN, and the standardized interfaces to the 5G Core. Its role is crucial for enabling enterprise and third-party service providers to integrate their existing AAA infrastructure with 5G networks without needing direct access to the 3GPP HSS/UDM. This allows for flexible business models, such as an enterprise managing access to its corporate network for 5G users, while the mobile operator manages the radio and core network access separately.

Purpose & Motivation

DN-AAA was introduced in 5G to address the need for seamless and secure integration of external data networks (like enterprise networks, IoT platforms, or internet services) with the 5G system. Previous generations lacked a standardized, network-exposed method for a Data Network to perform its own AAA, often leading to clunky workarounds or requiring the 3GPP operator to manage all credentials on behalf of the DN operator.

Its creation was motivated by the 5G vision of network exposure and support for vertical industries. Enterprises demand control over who accesses their resources and how, using their existing identity and access management systems. DN-AAA solves this by providing a clean, standardized hook within the PDU Session establishment flow where the external network's AAA policy can be invoked. This separation of concerns is vital: the mobile operator authenticates the subscriber for network access, while the service provider authenticates the user for application access.

This solves critical problems of business autonomy, security segregation, and operational complexity. It enables new multi-party service delivery models, such as network slicing for enterprises where the slice user (the enterprise) manages access to the slice, and facilitates the convergence of fixed and mobile access with a common AAA point in the service network.

Evolution Across Releases

Rel-16 Initial

Initially introduced as part of the enhanced 5G architecture to support integration with external DN AAA servers. Defined the basic procedures for DN-AAA server discovery, authentication, and authorization triggering during PDU Session establishment, primarily documented in TS 29.512 (Session Management) and TS 29.513 (Policy and Charging).

Explore further

Broader topics and technologies where DN-AAA plays a role.

Defining Specifications

3GPP specifications that define or reference DN-AAA, with the latest known release. Sourced from the 3GPP document catalog — see methodology.

SpecificationTitleRelease
TS 29.512 vj40 5G Session Management Policy Control Service Rel-19
TS 29.513 vj40 5G PCC Signalling Flows & QoS Mapping Rel-19
Patrick Zandl

About the author: Patrick Zandl (b. 1974)

Telecommunications specialist, technology journalist (founder of the Mobil server), and developer who has been running since 2025 — the largest Czech-language resource on AI-assisted programming. Formerly Chief Wizard Architect at Prusa3D and head of development for Turris at CZ.NIC; currently a consultant and instructor on AI implementation in companies.