TWIF

Trusted WLAN Interworking Function

Core Network →
Introduced in Rel-16

TWIF is the 5G core network function that enables secure interworking and protocol translation for user equipment to access 5G services over trusted WLAN networks like Wi-Fi.

Category
Core Network
Introduced
Rel-16
Where
Core Network › 5G Core
Specifications
11 specs
TWIF Description Purpose Related Classification Detected Changes Specifications

Description

The Trusted WLAN Interworking Function (TWIF) is a critical component within the 5G Core (5GC) architecture, specifically defined for Non-3GPP Interworking. It functions as a Network Function (NF) that provides a secure, standardized interface for User Equipment (UE) to connect to the 5GC via a trusted Wireless Local Area Network (WLAN), such as a carrier-managed or enterprise Wi-Fi network. The TWIF terminates the N1, N2, and N3 reference points over the non-3GPP access, effectively bridging the WLAN access network to the 5GC's control and user planes. On the network side, it interfaces with other core functions like the Access and Mobility Management Function (AMF) over N2 for control signaling, the Session Management Function (SMF) via the N4 interface for user plane policy, and the Unified Data Management (UDM) for authentication credentials.

Architecturally, the TWIF comprises two main logical entities: the Trusted WLAN Access Point (TWAP) and the Trusted WLAN AAA Proxy (TWAP). The TWAP handles the lower-layer WLAN-specific protocols and the IPsec/IKEv2 or TLS-based secure tunnel establishment with the UE. The TWAP acts as an Authentication, Authorization, and Accounting (AAA) proxy, interfacing with the 3GPP AAA Server (part of the UDM) to perform 5G-compliant authentication using the 5G Authentication and Key Agreement (5G-AKA) or EAP-AKA' methods. This ensures the UE is authenticated with the same credentials and security level as for 3GPP radio access.

In operation, when a UE attempts to attach via a trusted WLAN, it establishes a secure tunnel (IPsec or TLS) with the TWIF. The TWIF facilitates the primary authentication procedure with the 5GC, relaying Extensible Authentication Protocol (EAP) messages between the UE and the 3GPP AAA Server. Upon successful authentication, the TWIF registers the UE with the AMF, enabling mobility and session management. For user plane traffic, the TWIF acts as a Network Address Translation (NAT) point or a User Plane Function (UPF) N3 termination point, routing data packets between the WLAN and the 5GC's data network. It also enforces policies received from the Policy Control Function (PCF), such as quality of service (QoS) and charging rules, ensuring a consistent service experience across access types.

Its role is pivotal for converged access, allowing operators to offload traffic to Wi-Fi networks while maintaining core network security, subscriber management, and service continuity. It integrates WLAN into the 5G service-based architecture, making it a managed, trusted access type rather than an untrusted external network.

Purpose & Motivation

The TWIF was created to address the growing need for seamless and secure integration of high-performance WLAN networks into the 5G ecosystem. Prior to 3GPP Release 16, non-3GPP access (like Wi-Fi) was often treated as an untrusted network, requiring the UE to establish a VPN-like tunnel (via a Non-3GPP Interworking Function, N3IWF) for secure access, which added complexity and overhead. For operator-managed or certified Wi-Fi networks that meet specific security requirements, this untrusted model was inefficient.

The purpose of the TWIF is to define a "trusted" non-3GPP access path, where the access network itself is considered secure, eliminating the need for per-UE IPsec tunnels for security. This reduces signaling load, connection setup time, and processing overhead on both the UE and the network. It solves the problem of providing a streamlined, carrier-grade Wi-Fi experience that is fully integrated with 5G core services, including authentication, policy control, charging, and mobility support. This enables new use cases like fixed wireless access (FWA) over Wi-Fi, seamless mobility between 5G NR and Wi-Fi, and efficient traffic steering.

Historically, interworking with WLAN was defined in earlier releases (e.g., S2a-based trusted access in EPS), but these were not natively integrated into the new service-based architecture of 5GC. TWIF in Release 16 redefined this interworking for the 5G era, aligning it with cloud-native principles, network slicing, and unified policy framework. It addresses the limitation of previous approaches by providing a native 5GC Network Function with standard service-based interfaces (e.g., Ntwif), enabling automation, scalability, and consistent service exposure.

Architecture

In the Network Map

Classification

Part ofN3IWF
Related approachesAMF

Release Timeline

Detected Changes Across Releases

from 3GPP Change Requests

Specific changes extracted from the „Change history“ tables of 3GPP specifications (9 CRs across 4 releases). Complements the general historical overview above with the evidence-based evolution of this function.

Rel-16 4 changes

In Release 16, the TWIF's functionality was enhanced to use a PDU session identity for sessions it requests and to provide identifiers for its N3 terminations to enable User Plane Function (UPF) selection. The release also provided clarification on the TWIF's role in acting on behalf of a Non-5G-Capable over WLAN (N5CW) device during 5G Core network registration and access procedures.

  • Usage of PDU session identity for the PDU sessions requested by the TWIF TS 24.501CR1686
  • N3 terminations of W-AGF, TNGF and TWIF for UPF selection TS 29.502CR0249
  • N3 terminations of TWIF for UPF selection TS 29.510CR0282
  • Clarification on TWIF acting on behalf of N5CW device TS 24.501CR2602
Rel-17 2 changes

In Release 17, the TWIF (Trusted WLAN Interworking Function) was formally added as a Non-3GPP Access type alongside the TNGF, enabling Non-5G-Capable over WLAN (N5CW) devices to access 5G Core networks. Furthermore, the release provided clarification on the support of network slicing within TWIF deployment scenarios. The TWIF functions by terminating the N1, N2, and N3 interfaces to facilitate this access on behalf of N5CW devices.

  • Clarification on support of slicing in TWIF scenario TS 23.501CR3422
  • Addition of TWIF and TNGF as Non-3GPP Accesses TS 33.127CR0130
Rel-18 2 changes

In Release 18, the TWIF function was updated to handle decorated Network Access Identifiers (NAIs) specifically for N5CW devices. This enhancement was accompanied by a procedural correction to the TWIF's operation. These changes refined the TWIF's role in enabling N5CW devices to access 5G Core networks via trusted WLAN access.

  • TWIF handling of decorated NAI for N5CW device TS 24.501CR5544
  • TWIF procedure correction TS 33.501CR1985
Rel-19 1 change

In Release 19, the new functionality for the TWIF enables the mobility of an N5CW device connected to a Trusted WLAN Access Point (TWAP) to another TWAP that is connected to the same TWIF. This enhancement allows the device to move between different access points within the same trusted WLAN network while maintaining its 5G Core registration, which is performed by the TWIF on behalf of the device.

  • Mobility of the N5CW device connected to a TWAP to another TWAP connected to the same TWIF TS 24.502CR0317

Explore further

Broader topics and technologies where TWIF plays a role.

Defining Specifications

3GPP specifications that define or reference TWIF, with the latest known release. Sourced from the 3GPP document catalog — see methodology.

SpecificationTitleRelease
TS 23.501 vk00 5G System Architecture Stage 2 Rel-20
TS 24.501 vj50 5G NAS Protocols Specification Rel-19
TS 24.502 vj20 5G Core Access via Non-3GPP Networks; Stage 3 Rel-19
TS 29.214 vj20 Policy and Charging Control over Rx Rel-19
TS 29.413 vj00 NGAP for Non-3GPP Access Rel-19
TS 29.502 vj50 5G System; Nsmf Service Based Interface; Stage 3 Rel-19
TS 29.510 vj50 NRF Service Based Interface Protocol Rel-19
TS 33.127 vj50 Lawful Interception Architecture and Functions Rel-19
TS 33.128 vj50 3GPP TS 33.128: Lawful Interception Protocols Rel-19
TS 33.501 vk00 5G Security Architecture and Procedures Rel-20
TS 38.413 vj10 NG Application Protocol (NGAP) Rel-19
Patrick Zandl

About the author: Patrick Zandl (b. 1974)

Telecommunications specialist, technology journalist (founder of the Mobil server), and developer who has been running since 2025 — the largest Czech-language resource on AI-assisted programming. Formerly Chief Wizard Architect at Prusa3D and head of development for Turris at CZ.NIC; currently a consultant and instructor on AI implementation in companies.