5G/NR  - NAS

UL/DL NAS Transport

UL NAS Transport and DL NAS Transport are 5GMM messages used to carry another NAS payload through the 5GMM layer. The most common payload is N1 SM information, for example a 5GSM PDU Session Establishment Request in the uplink and a 5GSM PDU Session Establishment Accept in the downlink. In this case 5GMM does not interpret the 5GSM content as mobility management information; it provides the protected transport envelope between UE and AMF.

Signaling Sequence

The following sequence shows a typical use case where the UE requests a PDU session and the network returns the corresponding session establishment result. The 5GSM messages are transported inside UL/DL NAS Transport.

#

Direction

5GMM Message

Comment

1

UE -> AMF

UL NAS Transport

Carries uplink N1 SM information such as PDU Session Establishment Request.

2

AMF -> UE

DL NAS Transport

Carries downlink N1 SM information such as PDU Session Establishment Accept.

Message Structure

The key field is the Payload container type. When this value indicates N1 SM information, the payload container starts with a 5GSM message such as PDU Session Establishment Request, PDU Session Establishment Accept, PDU Session Modification Command, or PDU Session Release Command.

Example : UL NAS Transport

The following example is based on an Amarisoft MME log where the UE sends N1 SM information for PDU session establishment. The whole decoded NAS message is shown below.

04:09:34.950 [NAS] UL 0064 5GMM: UL NAS transport
        Protocol discriminator = 0x7e (5GS Mobility Management)
        Security header = 0x2 (Integrity protected and ciphered)
        Auth code = 0x44bc599f
        Sequence number = 0x03
        Protocol discriminator = 0x7e (5GS Mobility Management)
        Security header = 0x0 (Plain 5GS NAS message, not security protected)
        Message type = 0x67 (UL NAS transport)
        Payload container type = 1 (N1 SM information)
        Payload container:
          Protocol discriminator = 0x2e (5GS Session Management)
          PDU session identity = 1
          Procedure transaction identity = 49
          Message type = 0xc1 (PDU session establishment request)
          Integrity protection maximum data data:
            Maximum data rate per UE for user-plane integrity protection for uplink = 0x00 (64 kbps)
            Maximum data rate per UE for user-plane integrity protection for downlink = 0x00 (64 kbps)
          PDU session type = 0x3 (IPv4v6)
          5GSM capability:
            0x00 (TPMIC=0, ATSSS-ST=0, EPT-S1=0, MH6-PDU=0, RqoS=0)
          Extended protocol configuration options:
            Ext = 1
            Configuration protocol = 0
            Protocol ID = 0xc223 (CHAP)
            Data = 01 00 00 16 10 e3 f4 30 30 e3 f4 30 30 e3 f4 30 30 e3 f4 30 30 2a
            Protocol ID = 0xc223 (CHAP)
            Data = 02 00 00 16 10 96 a3 52 cd 73 78 3b 3d 22 d1 d5 50 a6 e9 17 17 2a
            Protocol ID = 0x8021 (IPCP)
            Data = 01 00 00 10 81 06 00 00 00 00 83 06 00 00 00 00
            Protocol ID = 0x000d (DNS Server IPv4 Address Request)
            Data =
            Protocol ID = 0x0003 (DNS Server IPv6 Address Request)
            Data =
            Protocol ID = 0x000a (IP address allocation via NAS signalling)
            Data =
            Protocol ID = 0x0005 (MS Support of Network Requested Bearer Control indicator)
            Data =
            Protocol ID = 0x0010 (IPv4 Link MTU Request)
            Data =
            Protocol ID = 0x0011 (MS support of Local address in TFT indicator)
            Data =
            Protocol ID = 0x0023 (QoS rules with the length of two octets support indicator)
            Data =
            Protocol ID = 0x0024 (QoS flow descriptions with the length of two octets support indicator)
            Data =
        PDU session ID = 1
        Request type = 0x1 (initial request)
        DNN = "internet"
                

Example : DL NAS Transport

The following example is based on the matching downlink response in the same Amarisoft MME log. The whole decoded NAS message is shown below.

04:09:34.950 [NAS] DL 0064 5GMM: DL NAS transport
        Protocol discriminator = 0x7e (5GS Mobility Management)
        Security header = 0x2 (Integrity protected and ciphered)
        Auth code = 0xa999e875
        Sequence number = 0x04
        Protocol discriminator = 0x7e (5GS Mobility Management)
        Security header = 0x0 (Plain 5GS NAS message, not security protected)
        Message type = 0x68 (DL NAS transport)
        Payload container type = 1 (N1 SM information)
        Payload container:
          Protocol discriminator = 0x2e (5GS Session Management)
          PDU session identity = 1
          Procedure transaction identity = 49
          Message type = 0xc2 (PDU session establishment accept)
          Selected PDU session type = 0x1 (IPv4)
          Selected SSC mode = 0x1 (1)
          Authorized QoS rules:
            QoS rule 1:
              QoS rule identifier = 1
              Rule operation code = 1 (create new QoS rule)
              DQR = 1 (the QoS rule is the default QoS rule)
              Number of packet filters = 1
              Packet filter identifier = 15
                Packet filter direction = 3 (bidirectional)
                Match-all
              QoS rule precedence = 255
              QFI = 1
          Session AMBR:
            Session-AMBR for downlink = 3000000 kbps
            Session-AMBR for uplink = 1000000 kbps
          5GSM cause = 0x32 (PDU session type IPv4 only allowed)
          PDU address:
            SI6LLA = 0
            PDU session type = 1 (IPv4)
            IPv4 = 192.168.3.2
          S-NSSAI:
            Length of S-NSSAI contents = 1 (SST)
            SST = 0x01
          Mapped EPS bearer contexts:
            Mapped EPS bearer context 1:
              EPS bearer identity = 5
              Operation code = 1 (create new EPS bearer)
              E = 1 (parameters list is included)
              Number of EPS parameters = 2
              Mapped EPS QoS parameters:
                QCI = 9
              APN-AMBR:
                APN-AMBR for downlink = 2816000000 bits
                APN-AMBR for uplink = 768000000 bits
          Authorized QoS flow descriptions:
            QoS flow description 1:
              QFI = 1
              Operation code = 1 (create new QoS flow description)
              E = 1 (parameters list is included)
              Number of parameters = 2
              5QI = 9
              EPS bearer identity = 5
          Extended protocol configuration options:
            Ext = 1
            Configuration protocol = 0
            Protocol ID = 0x8021 (IPCP)
            Data = 03 00 00 0a 81 06 08 08 08 08
            Protocol ID = 0x000d (DNS Server IPv4 Address)
            Data = 8.8.8.8
          DNN = "internet.mnc001.mcc001.gprs"
        PDU session ID = 1