Description
NAUN3 is a concept defined in 3GPP Release 18 within the context of 5G system access security. It classifies a Non-3GPP access network (N3AN) based on its capability to support authentication procedures with the 5G Core Network. Specifically, a NAUN3 is an N3AN that does not have the functionality to execute the primary authentication and key agreement procedure (5G-AKA or EAP-AKA') between the User Equipment (UE) and the 5G core's Authentication Server Function (AUSF). When a UE connects via a NAUN3, the access network itself is treated as an untrusted conduit. Therefore, the establishment of a secure connection to the 5G core must be achieved through an IPsec tunnel or other secure tunneling mechanism terminated at a Non-3GPP InterWorking Function (N3IWF) in the core network. The N3IWF acts as a security gateway. The UE first establishes a connection to the NAUN3 (e.g., associates with a Wi-Fi AP) and obtains a local IP address. It then initiates an IKEv2/IPsec tunnel establishment procedure with the N3IWF. Within this IKEv2 exchange, the EAP-AKA' authentication method is run, allowing the UE and the AUSF to authenticate each other through the N3IWF. Successful authentication results in the derivation of security keys used to secure the IPsec tunnel. All subsequent user plane and control plane traffic between the UE and the 5G core is carried within this encrypted tunnel, ensuring confidentiality and integrity despite the untrusted and non-authenticable nature of the underlying access network.
Purpose & Motivation
The NAUN3 concept was introduced to formally recognize and define the security treatment of a broad class of existing and future Non-3GPP access networks that lack integrated 3GPP authentication capabilities. This includes most public, private, and home Wi-Fi networks, which are ubiquitous but were not designed with 3GPP security protocols in mind. Prior to this formal categorization, the 5G system treated all Non-3GPP access as either 'trusted' or 'untrusted,' with untrusted access requiring tunneling via an N3IWF. NAUN3 refines the 'untrusted' category by explicitly calling out the inability to perform authentication as a key characteristic. This formalization ensures clear and consistent security procedures in the standards. It addresses the practical problem of securely integrating billions of devices using Wi-Fi and other non-cellular technologies into the 5G service fabric, without requiring upgrades to the access networks themselves. It enables operators to extend 5G services over any IP-based access while maintaining the high security standards of the 3GPP system.
Classification
Detected Changes Across Releases
from 3GPP Change RequestsSpecific changes extracted from the „Change history“ tables of 3GPP specifications (11 CRs across 1 releases). Complements the general historical overview above with the evidence-based evolution of this function.
In Release 18, the Non-Authenticable Non-3GPP (NAUN3) function was formally introduced, defining a device that connects to the 5G Core via a 5G-RG which acts on its behalf. The specifications now support a connectivity group of one or more NAUN3 devices sharing a single PDU session, and introduce Non-3GPP QoS Assistance Information (N3QAI) to enable QoS differentiation for traffic from these devices. Furthermore, updates were made to the UE Route Selection Policy (URSP) framework to handle scenarios involving NAUN3 devices behind a 5G-RG.
- Support of AUN3/NAUN3 device behind 5G-RG TS 24.501CR5421
- Introducing the AUN3 and NAUN3 devices TS 24.502CR0261
- URSP update for AUN3/NAUN3 device behind 5G-RG TS 24.526CR0194
- Clarification for NAUN3 device connecting to 5GC via 5G-RG that is connected to NG-RAN TS 24.501CR5934
- Definitions and abbreviations for NAUN3 device and AUN3 device TS 24.501CR6192
- Definitions and abbreviations for NAUN3 device and AUN3 device TS 24.502CR0300
+ 5 more changes
Explore further
Broader topics and technologies where NAUN3 plays a role.
Defining Specifications
3GPP specifications that define or reference NAUN3, with the latest known release. Sourced from the 3GPP document catalog — see methodology.
| Specification | Title | Release |
|---|---|---|
| TS 24.501 vj50 | 5G NAS Protocols Specification | Rel-19 |
| TS 24.502 vj20 | 5G Core Access via Non-3GPP Networks; Stage 3 | Rel-19 |
| TS 24.526 vj30 | UE Policies for 5GS; Stage 3 | Rel-19 |