TWAN

Trusted WLAN Access Network

Core Network →
Introduced in Rel-11

TWAN is a 3GPP architectural concept for an operator-controlled WLAN that is securely integrated with the mobile core network to provide seamless 3GPP services with authentication, policy, and mobility support.

Category
Core Network
Introduced
Rel-11
Where
Core Network › 5G Core
Specifications
20 specs
TWAN Description Purpose Related Classification Detected Changes Specifications

Description

The Trusted WLAN Access Network (TWAN) is not a single device but a logical architectural construct defined by 3GPP. It represents a Wireless Local Area Network (WLAN) that is considered "trusted" by the 3GPP operator's core network. This trust is established because the TWAN implements specific 3GPP-defined interfaces and functions, allowing it to be integrated as a seamless, secure, and policy-controlled access network on par with 3GPP radio access technologies like LTE. The TWAN encompasses the collection of network functions that together provide trusted WLAN access to the Evolved Packet Core (EPC) and, in later releases, the 5G Core (5GC).

The TWAN architecture is built around three key functional entities: the Trusted WLAN Access Gateway (TWAG), the Trusted WLAN AAA Proxy (TWAP), and the underlying WLAN Access Points (APs). The TWAG handles the user plane, establishing GTP or PMIP tunnels over the S2a interface to the Packet Data Network Gateway (PGW) in the EPC. The TWAP handles the control plane, acting as a proxy for Authentication, Authorization, and Accounting (AAA) signaling between the UE/WLAN and the 3GPP AAA Server/Proxy. The WLAN APs provide the actual radio connectivity. These functions can be collocated in a single physical node or distributed. The TWAN connects to the EPC via two main reference points: STa (between TWAP and 3GPP AAA Server for AAA) and S2a (between TWAG and PGW for user data).

From a procedural standpoint, when a UE connects to a TWAN, it undergoes EAP-based authentication against the 3GPP AAA infrastructure using credentials from its USIM card. The TWAP facilitates this process. Upon successful authentication, the TWAG establishes a data bearer for the UE. The PGW assigns an IP address, and all user traffic is routed through the secure tunnel between the TWAG and PGW. This architecture allows the core network to apply consistent policy and charging control (PCC) rules, managed by the Policy and Charging Rules Function (PCRF), to traffic from the TWAN-connected UE. It also enables mobility support, such as handovers of IP sessions between the TWAN and a 3GPP access network (e.g., LTE) without changing the IP address, as the PGW serves as a common anchor.

In the context of 5G, the TWAN concept evolved. The functions were reinterpreted for interconnection with the 5G Core network via the Non-3GPP InterWorking Function (N3IWF) for untrusted access or, more directly, through a Trusted Non-3GPP Gateway Function (TNGF) which subsumes the roles of the TWAG and TWAP for trusted access. This evolution maintains the principle of a trusted non-3GPP access network but aligns it with the service-based architecture and protocols of 5G. Throughout its lifecycle, the TWAN has been pivotal in enabling operators to deploy carrier-grade Wi-Fi as an integral part of their heterogeneous network strategy.

Purpose & Motivation

The TWAN was created to formally define a standardized architecture for integrating operator-managed or partner Wi-Fi networks into the 3GPP mobile ecosystem as a trusted access type. Before its introduction, Wi-Fi was typically an unmanaged, best-effort access network, leading to a fragmented user experience, separate logins, and no integration with mobile services like IMS or seamless mobility. The primary problem was the lack of a network-based, standardized model that could provide security, authentication, policy control, and service continuity equivalent to cellular access.

The development of the TWAN in Release 11 was a strategic response to the explosive growth of Wi-Fi and the need for mobile operators to offload data traffic efficiently while maintaining control over the user experience and service quality. It addressed the limitations of the earlier "untrusted non-3GPP access" model (which required client-initiated IPsec tunnels), which was complex for device implementation and did not support efficient network-based mobility or deep policy integration. The TWAN model shifted the complexity into the network, allowing for a simpler UE and enabling the operator to treat Wi-Fi as a first-class access technology.

By establishing the TWAN as a trusted entity, 3GPP solved several key issues: it enabled seamless authentication using 3GPP credentials (SIM-based), allowed the core network to enforce consistent quality of service and charging policies across cellular and Wi-Fi, and provided a foundation for real access network mobility. This was crucial for enabling services like Voice over Wi-Fi (VoWiFi) with IMS and for realizing true Fixed-Mobile Convergence (FMC), where a user's services are agnostic to the underlying access technology. The TWAN architecture provided the blueprint for the deep integration of WLAN, which later evolved to become a fundamental component of 5G's commitment to supporting heterogeneous access.

Classification

Part ofEPC
Specific typesTWAGTWAP

Release Timeline

Detected Changes Across Releases

from 3GPP Change Requests

Specific changes extracted from the „Change history“ tables of 3GPP specifications (3 CRs across 1 releases). Complements the general historical overview above with the evidence-based evolution of this function.

Rel-15 3 changes

In Release 15, the TWAN function was enhanced with a P-CSCF restoration extension for the HSS-based and PCRF-based solutions, allowing the PGW to send an updated list of available P-CSCF addresses to the UE via a WLCP PDN connection modification procedure without deactivating the IMS PDN connection. This requires support from the UE, the TWAN for the WLCP procedure, and the PGW. Additionally, corrections were made for emergency PDU session establishment by UEs without a valid UICC, and encoding for the TWAN PLMN-ID was addressed.

  • ePDG and TWAN emergency configuration data TS 23.402CR2982
  • Corrections of errors in emergency PDU session establishment by UE without valid UICC using SCM in TWAN TS 24.302CR0659
  • TWAN PLMN-ID encoding TS 29.274CR1896

Explore further

Broader topics and technologies where TWAN plays a role.

Defining Specifications

3GPP specifications that define or reference TWAN, with the latest known release. Sourced from the 3GPP document catalog — see methodology.

SpecificationTitleRelease
TS 23.380 vj10 IMS Restoration Procedures Rel-19
TS 23.402 vj00 EPC for Non-3GPP Access (PMIP) Rel-19
TS 23.852 vc00 Study on GTP-based S2a for WLAN Access Rel-12
TS 24.229 vj50 IMS call control protocol based on SIP and SDP Rel-19
TS 24.302 vj00 Access to EPC via non-3GPP networks; Stage 3 Rel-19
TS 24.502 vj20 5G Core Access via Non-3GPP Networks; Stage 3 Rel-19
TS 29.061 vj00 Packet Domain Interworking for PLMN Rel-19
TS 29.273 vj10 AAA Protocols for Non-3GPP Access in EPS & 5GS NSWO Rel-19
TS 29.274 vj50 GTPv2-C Control Plane Protocol Specification Rel-19
TS 29.275 vj00 PMIPv6 Mobility & Tunnelling Protocols Stage 3 Rel-19
TS 29.281 vj20 GTPv1-U Protocol Specification Rel-19
TS 29.303 vj10 DNS Procedures for Evolved Packet System Rel-19
TS 29.512 vj40 5G Session Management Policy Control Service Rel-19
TS 29.826 vd10 P-CSCF Restoration Enhancements for WLAN Rel-13
TS 32.251 vj00 PS Domain Charging Management Rel-19
TS 32.298 vj30 Charging Data Record (CDR) Parameter Specification Rel-19
TS 32.299 vj00 Diameter Charging Applications for 3GPP Rel-19
TS 33.107 vj00 Lawful Interception Architecture & Functions Rel-19
TS 33.108 vj00 LI Handover Interface Specification Rel-19
TS 33.402 vj00 Security for non-3GPP access to EPS Rel-19
Patrick Zandl

About the author: Patrick Zandl (b. 1974)

Telecommunications specialist, technology journalist (founder of the Mobil server), and developer who has been running since 2025 — the largest Czech-language resource on AI-assisted programming. Formerly Chief Wizard Architect at Prusa3D and head of development for Turris at CZ.NIC; currently a consultant and instructor on AI implementation in companies.