Description
SDNAEPC is a feature defined in 3GPP Release 18 that extends the authentication and authorization framework for User Equipment (UE) accessing services via the Evolved Packet Core. It specifically addresses scenarios where a UE, having already undergone primary 3GPP network access authentication (e.g., via EPS AKA), needs to be authenticated and authorized separately by a secondary Data Network (DN), such as a corporate network or a specific service provider's platform. The architecture involves the UE, the serving network (EPC with MME, S-GW, P-GW), and the secondary DN's Authentication, Authorization, and Accounting (AAA) server. The process is typically integrated with the Packet Data Network (PDN) connection establishment or modification procedures. When a UE requests access to a secondary DN that requires SDNAEPC, the P-GW (acting as the gateway to that DN) interacts with the DN's AAA server. The P-GW relays Extensible Authentication Protocol (EAP) messages between the UE and the secondary DN's AAA server, facilitating an EAP-based authentication dialogue. This allows the secondary DN to validate the UE's credentials (which are separate from the USIM credentials) and apply its own authorization policies, such as granting access to specific services or applying traffic filters. The successful completion of this secondary authentication results in the establishment of the PDN connection with the authorized context. This mechanism is vital for multi-tenancy scenarios, ensuring that the secondary DN maintains control over which UEs can access its resources, providing an additional security layer independent of the mobile operator's core network trust domain.
Purpose & Motivation
SDNAEPC was created to address the growing need for secure, partitioned network access in an increasingly interconnected ecosystem. Traditional EPC access authentication (e.g., using EPS AKA) only verifies the UE's subscription with the mobile network operator (MNO). However, many enterprise, industrial IoT, and specialized service providers require their own independent authentication before granting access to their sensitive resources. Prior to SDNAEPC, such secondary authentication was often handled in an ad-hoc manner at the application layer or required complex VPN setups, which could be inefficient and lack standardization. SDNAEPC standardizes this secondary authentication at the network layer during PDN connection setup. It solves the problem of allowing a DN provider to enforce its own security policies without relying solely on the MNO's authentication. This is particularly important for scenarios like enterprise mobility, where a company needs to verify employee device credentials, or for IoT verticals where a service platform must authenticate a sensor independently. By integrating this into the 3GPP EPC procedures, it provides a streamlined, secure, and standardized method for multi-domain trust, enabling new business models and secure network slicing precursors in 4G networks.
Classification
Release Timeline
Detected Changes Across Releases
from 3GPP Change RequestsSpecific changes extracted from the „Change history“ tables of 3GPP specifications (11 CRs across 2 releases). Complements the general historical overview above with the evidence-based evolution of this function.
In Release 18, the SDNAEPC function introduced a new support indicator and specific containers for EAP messaging and a DN-specific identity within Protocol Configuration Options (PCO/ePCO). These enable the UE to indicate its capability during procedures like PDN connectivity and PDU session establishment, and allow the exchange of EAP messages for secondary DN authentication. The specifications also define procedures for rejecting a request if the UE does not support SDNAEPC and for handling the DN-specific identity in NAI format.
- Introducing the secondary DN authentication and authorization over EPC support indicator TS 24.008CR3322
- Indicating the capability of supporting SDNAEPC during the PDN connectivity procedure TS 24.301CR3851
- Rejecting PDN connectivity procedure due to SDNAEPC is not supported by the UE TS 24.301CR3852
- Exchanging the SDNAEPC EAP message in ESM procedures TS 24.301CR3853
- Resolving the EN related to exchanging the SDNAEPC EAP message TS 24.301CR3870
- Resolving the EN related to the inclusion of SDNAEPC support indicator in the PCO or the ePCO TS 24.301CR3871
+ 4 more changes
In Release 19, the SDNAEPC function was enhanced by introducing a specific support indicator and clarifying the container identifiers for EAP messages and DN-specific identities. The update formally defined the empty container for the support indicator and the precise coding for the EAP message and NAI-formatted identity within the procedure. These changes corrected and solidified the signaling mechanisms for secondary DN authentication and authorization over EPC.
- Correction to SDNAEPC in 5GSM capability IE TS 24.501CR6621
Explore further
Broader topics and technologies where SDNAEPC plays a role.
Defining Specifications
3GPP specifications that define or reference SDNAEPC, with the latest known release. Sourced from the 3GPP document catalog — see methodology.
| Specification | Title | Release |
|---|---|---|
| TS 24.008 vj50 | 3GPP TS 24008: Core Network Protocols | Rel-19 |
| TS 24.301 vj60 | NAS protocol for Evolved Packet System | Rel-19 |
| TS 24.501 vj50 | 5G NAS Protocols Specification | Rel-19 |