TDF

Traffic Detection Function

Core Network →
Introduced in Rel-11

TDF is a network function that performs application detection, gating, and redirection for traffic to enable policy and charging control.

Category
Core Network
Introduced
Rel-11
Where
Core Network › Evolved Packet Core
Specifications
18 specs
TDF Description Purpose Related Classification Detected Changes Specifications

Description

The Traffic Detection Function (TDF) is a specialized network element within the 3GPP Policy and Charging Control (PCC) architecture. Its primary role is to perform deep packet inspection (DPI) on user plane traffic to identify specific applications and services, such as streaming video, social media, or peer-to-peer applications. The TDF operates by analyzing packet headers and payloads against a set of pre-defined detection rules, which can be based on signatures, behavioral patterns, or other heuristics. Upon detecting a specific application, the TDF can report this information to the Policy and Charging Rules Function (PCRF) via the Sd reference point. The PCRF can then use this information to dynamically install or modify PCC rules in the Policy and Charging Enforcement Function (PCEF), enabling real-time policy enforcement like bandwidth throttling, blocking, or charging for the detected application flow.

Architecturally, the TDF can be deployed in two modes: as an Application Function (AF) within the PCC framework or as a standalone node. In the standalone deployment, it interacts directly with the PCRF. The TDF contains key functional components including the Traffic Detection Engine, which performs the actual DPI, and a reporting function that communicates with the PCRF. It also maintains a database of application detection rules, which can be updated by the operator. The TDF's operation is governed by ADC (Application Detection and Control) rules provisioned by the PCRF, which specify what applications to look for and what actions to take upon detection, such as reporting, gating (blocking), or redirecting the traffic.

In the network, the TDF is typically placed in the data path, often integrated with a Gateway GPRS Support Node (GGSN) or a Packet Data Network Gateway (PGW) in 4G, or the User Plane Function (UPF) in 5G. Its integration allows for granular, application-aware policy enforcement beyond simple bearer-level controls. For example, an operator can use the TDF to detect a video streaming service and apply a specific Quality of Service (QoS) policy to ensure a smooth user experience, or to identify and limit bandwidth for a file-sharing application during network congestion. The TDF's ability to provide application-level visibility is crucial for implementing service differentiation, zero-rating offers, and parental controls.

Purpose & Motivation

The TDF was created to address the growing need for operators to manage and monetize diverse internet application traffic beyond the capabilities of traditional bearer-level PCC. Prior to its introduction, policy control was primarily based on IP 5-tuple information (source/destination IP/port, protocol), which is insufficient for accurately identifying specific applications, especially those using dynamic ports, encryption, or sharing common servers. This limitation made it difficult for operators to implement fair usage policies, offer application-specific data plans, or ensure quality of experience for latency-sensitive services.

The motivation for standardizing the TDF in 3GPP Release 11 was to provide a unified, vendor-interoperable method for deep packet inspection and application-aware policy enforcement within the PCC framework. It solved the problem of application blindness in the core network, enabling new business models like sponsored data, where an application provider pays for the data usage, or tiered services where premium subscribers get better quality for specific apps. The TDF also provides the technical foundation for regulatory requirements, such as lawful interception of specific services or compliance with net neutrality rules through transparent traffic management.

Historically, operators relied on proprietary DPI solutions that were not integrated with the standardized PCC architecture, leading to operational complexity and limited scalability. The TDF standardizes the interfaces (e.g., Sd, Gx) and procedures for application detection and control, allowing operators to deploy multi-vendor solutions and ensuring that policy decisions based on application detection are consistent and enforceable across the network. It represents a key evolution from simple volume-based charging to intelligent, service-aware network management.

Classification

Specific typesARA
Related approachesPCRFPCEF

Release Timeline

Detected Changes Across Releases

from 3GPP Change Requests

Specific changes extracted from the „Change history“ tables of 3GPP specifications (2 CRs across 1 releases). Complements the general historical overview above with the evidence-based evolution of this function.

Rel-15 2 changes

In Release 15, the TDF (Traffic Detection Function) was enhanced with new charging mechanisms and reporting procedures. Specifically, charging support was extended for NSWO (Non-Seamless WLAN Offload) traffic in fixed broadband access scenarios, and procedures were defined for the TDF to generate application reports when PFDs (Packet Flow Descriptions) are removed or modified. These enhancements operate within architectural constraints where the TDF is controlled by the VPLMN in roaming scenarios and interacts with the PCRF via the Sd interface.

  • Charging enhancement on TDF for eFMSS TS 32.251CR0501
  • TDF application report when the PFDs are removed or modified TS 29.212CR1679

Explore further

Broader topics and technologies where TDF plays a role.

Defining Specifications

3GPP specifications that define or reference TDF, with the latest known release. Sourced from the 3GPP document catalog — see methodology.

SpecificationTitleRelease
TS 23.139 vj00 3GPP-Fixed Broadband Interworking Stage 2 Rel-19
TS 23.203 vj20 Policy and charging control architecture Rel-19
TS 23.214 vj00 Control and User Plane Separation for EPC Rel-19
TS 29.212 vj00 Gx/Gxx/Sd/St Diameter Protocol Rel-19
TS 29.213 vj20 PCC Signalling Flows and QoS Mapping Rel-19
TS 29.214 vj20 Policy and Charging Control over Rx Rel-19
TS 29.215 vj00 S9 Reference Point Stage 3 Specification Rel-19
TS 29.244 vj40 PFCP Specification for Control/User Plane Separation Rel-19
TS 29.250 vj00 Nu Reference Point Stage 3 Specification Rel-19
TS 29.251 vj00 Gw/Gwn Reference Points Stage 3 Specification Rel-19
TS 29.810 vd00 Diameter Load Control Study Rel-13
TS 32.240 vj40 Charging Management Architecture & Principles Rel-19
TS 32.251 vj00 PS Domain Charging Management Rel-19
TS 32.296 vj00 Online Charging System (OCS) Architecture Rel-19
TS 32.298 vj30 Charging Data Record (CDR) Parameter Specification Rel-19
TS 32.299 vj00 Diameter Charging Applications for 3GPP Rel-19
TS 32.843 vd00 PS Domain Online Charging in Roaming Rel-13
TS 32.869 vf00 Diameter Overload Control for Charging Interfaces Rel-15
Patrick Zandl

About the author: Patrick Zandl (b. 1974)

Telecommunications specialist, technology journalist (founder of the Mobil server), and developer who has been running since 2025 — the largest Czech-language resource on AI-assisted programming. Formerly Chief Wizard Architect at Prusa3D and head of development for Turris at CZ.NIC; currently a consultant and instructor on AI implementation in companies.