5G/NR  - NAS

 

 

 

LADN / DNN

LADN and DNN are new concept introduced in 5G. I have vague understanding about these that these concept replaces the concept of APN in LTE, but for long time the concept hasn't come clear to me.

Since these new concepts are introduced instead of using APN mainly to implement the concept of Network Slice, it would worth having some detailed picture of Network Slice. I wrote a separate note for Network Slicing.

What is LADN ?

LADN stands for Local Area Data Network, which is a feature in 5G networks that allows a local operator or enterprise to provide data services within a limited geographic area, such as a building, campus, or industrial site. It is a special type of data network in 5G that is accessible only within a specific geographical area (or areas) The LADN feature enables local operators or enterprises to provide their own 5G data services with their own network infrastructure, while still being connected to the wider 5G network.

With LADN, a local operator or enterprise can set up a private 5G network to provide specific services tailored to their needs, such as industrial automation, smart building systems, or high-speed data transfers within a limited area. The LADN can be connected to the wider 5G network through a gateway to provide access to external data services and resources.

LADN can be deployed in different modes, including standalone mode, where the LADN network is independent of the wider 5G network, and dual connectivity mode, where the LADN network is connected to the wider 5G network for seamless mobility and access to external resources. The LADN feature is defined in the 3GPP standards for 5G networks and is expected to play a significant role in enabling new use cases and applications for 5G.

The definition is easier to hold if you picture the service area first. A LADN service area is a set of Tracking Areas, and it is defined per LADN DNN. The AMF tells the UE which LADN DNNs exist and where they apply, using the LADN Information element in Registration Accept. Everything else about LADN follows from that one restriction. Inside the area the LADN DNN behaves like any other DNN. Outside it the UE is not allowed to ask for it, and an existing session cannot continue unchanged.

What the LADN service area decides A LADN is an ordinary DNN with one condition attached UE inside the LADN service area LADN service area = a set of Tracking Areas TA 1 TA 2 TA 3 UE LADN Information arrives in Registration Accept a PDU session to the LADN DNN is accepted the SMF selects a local UPF UE outside the LADN service area the same Tracking Areas, and the UE is not in them TA 1 TA 2 TA 3 UE the UE does not request the LADN DNN a request anyway is rejected by the SMF an existing session is released, or kept with no user plane The SMF subscribes to the AMF for UE presence in the LADN service area, and the AMF reports IN, OUT or UNKNOWN. LADN applies to 3GPP access only, and the service area is defined per LADN DNN.

Figure 1. LADN is one condition applied to an ordinary DNN. The service area is a list of Tracking Areas, so the network already knows whether the UE is inside it without any new positioning.

Key Characteristics of LADN:

  • Localized Accessibility: A UE can only access the LADN when it is in the defined geographical area(s). Outside that area, the UE cannot use the LADN.
  • Reduced Latency & Cost: Because traffic remains local, LADN can reduce latency and potentially lower backhaul costs compared to routing traffic out to a distant data center or the public Internet.
  • Private Networking: LADNs are often used for private networks—for example, industrial IoT devices on a factory floor can connect to a local data center for real-time process control.
  • UE Registration: The UE is informed about the availability of a LADN through network signaling (e.g., the 5G core can provide the UE a list of LADNs that are accessible in the current location).

Use Cases for LADN

  • Enterprise Campus: Employees and IoT devices connect to a private enterprise LAN while on campus.
  • Smart Factories: Machines and robots communicate with on-premises edge servers for real-time control and monitoring.
  • Stadiums / Venues: High-bandwidth local services (like instant replays, local streaming) can be delivered locally, reducing load on the operator’s core network.
  • Retail / Malls: Local content delivery, loyalty programs, or AR/VR services running in a local edge network.

How it works:

  • Service Area Configuration: The 5G core predefines the geographic area(s) where the LADN is accessible (e.g., GPS coordinates or cell IDs).
  • UE Registration: When a UE enters the LADN service area:
    • The AMF (Access and Mobility Management Function) checks if the UE is authorized for the LADN.
    • The UE can establish a PDU session with the LADN DNN.
  • Outside the Service Area:
    • The UE cannot access the LADN, even if it requests it.
    • Existing LADN sessions may be suspended or terminated when the UE leaves the area.

Signaling of LADN

Key Signaling Procedures for LADN

  • LADN functionality is primarily managed during:
  • UE Registration (to inform the UE about available LADNs).
  • PDU Session Establishment (to connect to an LADN).
  • UE Mobility (to track if the UE enters/leaves an LADN service area).

Key Signaling Messages and IEs

  • A. During UE Registration
    • When a UE registers with the 5G core network, the AMF (Access and Mobility Management Function) informs the UE about the LADNs it is authorized to access.
    • Registration Accept (NAS Message)
      • Message: Sent by the AMF to the UE during registration.
      • Relevant IE:
        • LADN Information : Contains the list of LADNs (DNNs) the UE can access, along with their service areas (e.g., tracking areas, cell IDs, or geographic coordinates).
      • Purpose: The UE uses this information to determine when it is within an LADN service area.
  • B. During PDU Session Establishment : When a UE requests a PDU session for an LADN:
    • PDU Session Establishment Request (NAS Message)
      • Message: Sent by the UE to the AMF.
      • Relevant IE:
        • DNN : Specifies the LADN the UE wants to connect to (e.g., factory-ladn).
    • Nsmf_PDUSession_CreateSMContext Request (HTTP/2)
      • Message: Sent by the AMF to the SMF (Session Management Function) to trigger session setup.
      • Relevant IEs:
        • DNN
        • LADN Service Area (preconfigured in the SMF/UDM) : Validates if the UE’s current location is within the LADN’s allowed geographic area.
    • Nudm_SDM_Get (HTTP/2)
      • Message: The SMF retrieves LADN subscription data from the UDM (Unified Data Management).
      • Relevant IEs:
        • LADN Configuration : Includes the DNN, service area, and associated policies (e.g., QoS).
    • PDU Session Establishment Accept/Reject
      • Reject Cause: If the UE is outside the LADN service area, the SMF rejects the request with a cause code (e.g., LADN not available)
  • C. During Mobility Management : When the UE moves in/out of an LADN service area:
    • Service Request or Periodic Registration Update
      • The AMF tracks the UE’s location using UE Location Reporting.
      • If the UE enters an LADN service area, the AMF updates the SMF/UPF to enable LADN access.
    • N2 Message (AMF to RAN)
      • Includes LADN Indication to prioritize traffic or configure localized routing.

Example Workflow

  • UE Registration:
    • AMF sends Registration Accept with LADN Information (e.g., DNN=factory-ladn, service area=GPS coordinates).
  • UE Enters LADN Zone:
    • AMF detects UE is within the LADN service area via location reporting.
  • PDU Session Request:
    • UE sends PDU Session Establishment Request with DNN=factory-ladn.
  • SMF Validation:
    • SMF checks UE location against LADN Service Area (from UDM).
  • Session Setup:
    • If valid, SMF configures UPF for localized routing (e.g., to an on-site edge server).

What is DNN ?

DNN can also refer to the Data Network Name, which is a new feature in 5G networks that is used to support network slicing

Network slicing is a technique used in 5G to divide a physical network infrastructure into multiple virtual networks, each with its own resources and quality of service (QoS) requirements. Each virtual network is identified by a unique Data Network Name (DNN), which is used by the 5G core network to route traffic to the appropriate network slice.

For example, a mobile operator can create a dedicated network slice for a particular enterprise customer with specific QoS requirements, and assign a unique DNN to that network slice. This enables the enterprise customer to have a dedicated and secure network that is customized to their specific needs.

A DNN identifies which external data network the UE (user device) should connect to. Examples of common data networks include:

  • The public Internet.
  • A private enterprise network.
  • A cloud application network or content delivery network.

Key Points about DNN:

  • Identification: The DNN is used by the 5G core network to determine the packet data network or service to which the user wants to connect.
  • Policy & Charging: Different DNNs might be subject to different QoS (Quality of Service), charging policies, or traffic handling rules.
  • Network Slice Association: In 5G, a DNN can also be coupled with a Network Slice to provide a customized set of network resources for specific services.

Signaling of DNN

Key Procedures Involving DNN

  • DNN is primarily used in:
    • PDU Session Establishment: To select the external data network.
    • UE Registration: To inform the UE about allowed/supported DNNs.
    • SMF Selection: To route traffic to the correct network.

Signaling Messages and IEs for DNN

  • PDU Session Establishment : The DNN is a critical IE during session setup:
    • PDU Session Establishment Request (NAS Message)
      • Sent by: UE → AMF
      • IE: DNN : Specifies the data network the UE wants to connect to (e.g., internet, ims).
    • Nsmf_PDUSession_CreateSMContext Request (HTTP/2)
      • Sent by: AMF → SMF
      • IE: DNN : Used by the SMF to select session policies, UPF, and external network.
    • Nudm_SDM_Get (HTTP/2)
      • Sent by: SMF → UDM
      • IE: DNN : The SMF retrieves subscription data (e.g., QoS profiles) tied to the DNN.
    • PDU Session Establishment Accept (NAS Message)
      • Sent by: SMF → UE (via AMF)
      • IE: DNN : Confirms the DNN for the established session.
  • UE Registration
    • Registration Request (NAS Message)
      • Sent by: UE → AMF
      • IE: Requested DNN (optional) : The UE may request specific DNNs during registration.
    • Registration Accept (NAS Message)
      • Sent by: AMF → UE
      • IE: Allowed DNN List (optional) : Indicates DNNs the UE is authorized to use (e.g., internet, enterprise-vpn).
  • Service Request : When modifying or resuming a PDU session:
    • Service Request (NAS Message)
      • IE: DNN (implicitly tied to the PDU session ID).

Example Workflow

  • UE Request:
    • UE sends PDU Session Establishment Request with DNN=enterprise-vpn.
  • SMF Selection:
    • AMF forwards the DNN to SMF via Nsmf_PDUSession_CreateSMContext.
  • Subscription Check:
    • SMF queries UDM with Nudm_SDM_Get to validate DNN=enterprise-vpn.
  • Session Setup:
    • SMF selects UPF and policies based on the DNN.

Is a DNN the same thing as a network slice ?

The sections above use DNN and network slice almost interchangeably. They are two different identifiers, and a PDU session carries both. I had the two merged for a long time. What separated them was a single question. Which of the two does the AMF use to select the SMF? The answer is both, and that only makes sense once they are separate things.

The S-NSSAI identifies a network slice. It is what the network uses to decide which set of network functions serves the UE. The NSSF is the function that resolves it.

The DNN identifies a data network. It names the thing at the far end of the PDU session. That may be the public Internet, an IMS network, or an enterprise network. The DNN is the direct successor of the APN in LTE, and it does the same job.

Neither identifier implies the other. One DNN can be reachable from several slices, and one slice can offer several DNNs. The pair is what matters. The AMF selects an SMF using the S-NSSAI together with the DNN. The SMF then selects a UPF and an N6 interface that can reach that data network.

What the DNN identifies, and what the S-NSSAI identifies The DNN and the S-NSSAI answer different questions S-NSSAI which network slice the session belongs to DNN which external data network the session reaches LADN DNN a DNN usable only inside its LADN service area The pair (S-NSSAI, DNN) is what the AMF uses to select the SMF. One DNN can appear in several slices, and one slice can offer several DNNs.

Figure 2. Treating the DNN as the slice identifier is the most common way to get PDU session selection wrong. The DNN names the destination, and the S-NSSAI names the set of network functions that gets you there.

  • S-NSSAI names the slice, DNN names the data network : These are separate identifiers with separate registries. Neither one can be derived from the other.
  • A PDU session carries exactly one of each : The session belongs to one slice and reaches one data network. A UE that needs two data networks establishes two PDU sessions.
  • The mapping is many to many : The same DNN, such as internet, can be offered inside several slices with different policy and different UPFs.
  • The DNN is the APN successor, and the S-NSSAI is not : There is no LTE equivalent of the S-NSSAI. That is why the DNN feels familiar to anyone coming from EPC, and the S-NSSAI does not.
  • Subscription decides what is allowed : The UDM holds the DNNs the UE may use for each S-NSSAI, together with a default DNN. If the UE requests no DNN, the network applies that default.

How a DNN is related to LADN ?

The terms DNN (Data Network Name) and LADN (Local Area Data Network) are related concepts that are used to support network slicing and provide customized services to different types of users and devices.

A LADN is a virtual network slice that is optimized for use within a specific geographical area, such as a building, campus, or factory. It is designed to provide low-latency, high-bandwidth connectivity to local devices and applications, and can be customized with specific QoS requirements.

A DNN, on the other hand, is a unique identifier used by the 5G core network to route traffic to a specific network slice. In the context of a LADN, the DNN would be used to identify and route traffic to the LADN network slice.

For example, a factory might require a dedicated LADN network slice to support real-time monitoring and control of machines and devices on the factory floor. The LADN could be customized with specific QoS requirements to ensure low-latency, high-bandwidth connectivity, and a unique DNN would be assigned to the LADN to enable efficient routing of traffic to and from the factory.

Overall, the DNN and LADN are related concepts that are used in 5G to provide customized network services and support efficient use of network resources.

Following is brief highlights on how DNN and LADN work together.

  • DNN Selection
    • When a UE attaches to the 5G network, it may request one or more data network connections (PDU Sessions). Each PDU Session is associated with a specific DNN.
    • The 5G core network uses the requested DNN to determine the appropriate Session Management Function (SMF) and User Plane Function (UPF) to route user traffic to the intended network.
  • Local vs. Non-Local DNN
    • A standard DNN might be something like “internet” or “operator.default,” giving the user a general connection to the internet or to their service provider’s network.
    • A Local Area DNN (LADN) is a specialized DNN accessible only in a restricted region. If the UE is within that region, the network notifies the UE that LADN service is available. The UE can then establish a PDU Session to that LADN if needed.
  • UE Notification of LADN Availability
    • Broadcast or Signaling: When the UE registers with the 5G core, the core identifies that the UE is in the local area served by the LADN and can send a notification that LADN is available.
    • Policy Control: The 5G core (e.g., PCF – Policy Control Function) ensures that the user is allowed to access that LADN and enforces any local policies or QoS parameters.
  • Session Establishment
    • If the UE needs to communicate with the local data network, it sets up a PDU Session using the LADN’s DNN.
    • The SMF in the 5G core selects a local UPF which connects directly to the on-premises or local data network.
  • Mobility Implications
    • If the user device moves away from the local area where LADN is offered, the 5G core may tear down the LADN session or keep it dormant until the UE returns to the coverage area. The exact behavior depends on operator policies.

What makes a LADN different from an ordinary DNN ?

A LADN is not a separate kind of network. It is an ordinary DNN with one condition attached, and the condition is where the UE is. Every row in the table below is a consequence of that one condition.

< An ordinary DNN against a LADN DNN >

 

ordinary DNN

LADN DNN

Where it can be used

anywhere the UE is registered

only inside the LADN service area

How the UE learns of it

subscription data, and the allowed DNN list

LADN Information, in Registration Accept or UE Configuration Update

Service area

none

a set of Tracking Areas, defined per LADN DNN

Access type

3GPP and non-3GPP

3GPP access only

When the UE leaves the area

not applicable

the SMF releases the session, or keeps it with no user plane

A request from outside

not applicable

rejected by the SMF, with a cause saying the UE is outside the LADN service area

The mechanism that makes the last two rows work is location reporting between two network functions. The SMF subscribes to the AMF for the UE presence in the LADN service area. The AMF then reports one of three states, which are IN, OUT and UNKNOWN. UNKNOWN matters more than it looks. It means the AMF cannot currently tell, so the SMF has to choose a behaviour rather than assume the UE is inside.

  • The service area is a list of Tracking Areas : No new positioning is needed for LADN. The network already knows the UE Tracking Area from registration, so the check is free.
  • LADN Information is per DNN : Each entry pairs one LADN DNN with one service area. A UE can therefore be inside one LADN and outside another at the same moment.
  • There are three presence states, not two : IN and OUT are the obvious ones. UNKNOWN is the one that decides how an implementation behaves at the edges of the area.
  • Leaving the area does not always drop the session : The SMF may release the PDU session, or keep it and release the user plane. Operator policy decides which, so the observed behaviour differs between networks.
  • 3GPP access only : LADN is not defined over non-3GPP access, because a service area expressed in Tracking Areas has no meaning there.

How a DNN can be compared to APN ?

In LTE, APN (Access Point Name) is used as an identifier for a specific network operator's packet data network. It is used by the mobile device to connect to the packet data network and access the internet and other services.

In 5G, the DNN (Data Network Name) is the counterpart of APN in LTE. It is used to identify and route traffic to a specific network slice, which can be customized with specific QoS requirements for different services and applications.

Like the APN, the DNN enables efficient routing of traffic within the 5G network, and allows for customized network services to be provided to different users and devices. However, the DNN goes beyond the functionality of the APN by enabling dynamic allocation of network resources to different network slices based on their specific QoS requirements, which enables more efficient use of network resources and better performance for different services and applications.

Examples : DNN and LADN in the NAS signaling

The sections above describe the fields. This one puts them into six flows, from the most ordinary PDU session to the one that gets rejected. Each example lists the NAS messages in order, with the information elements that decide the outcome marked. Two of the six do not involve LADN at all, and that is deliberate. LADN is the exception, and an exception is easier to see once the normal case is on the page.

One point applies to every example below. The DNN and the S-NSSAI are not carried inside the PDU SESSION ESTABLISHMENT REQUEST. They travel in the UL NAS TRANSPORT message that carries that request, together with the PDU session ID and the Request type. The 5GSM message carries the session parameters, and the 5GMM message carries the identifiers that route it. RRC and NGAP messages are shown where they carry a field that decides the outcome, and left out where they only carry NAS transparently. SIB1 is how the UE learns its Tracking Area. The NGAP User Location Information is how the AMF learns it. Those two are what the LADN service area check compares. Example 1 shows the flow in full, and the later examples keep only the steps that change.

NOTE : why UL NAS TRANSPORT carries the DNN, and why NGAP does not.

5GS splits NAS into two protocols. 5GMM terminates at the AMF, and 5GSM terminates at the SMF. A 5GSM message is never sent on its own, and UL NAS TRANSPORT is the 5GMM container that carries it in the uplink. The container is general rather than session specific. The Payload container type selects what is inside it. N1 SM information, SMS, LPP and a UE policy container all travel the same way.

The AMF does not decode the payload container, because the 5GSM message is end to end between the UE and the SMF. The AMF still has to route it. That is why the identifiers sit outside the container. A function that must not read the message can still read the address written on it.

IE outside the container

What the AMF does with it

PDU session ID

identifies the session the payload belongs to

Request type

a new session, an existing session moved from EPS, or an emergency session

S-NSSAI and DNN

select the SMF, because the pair is the selection key

Old PDU session ID

correlate the two sessions during an SSC mode 3 procedure

By the time PDU SESSION RESOURCE SETUP REQUEST is sent, the routing is already decided. The SMF and the UPF are selected, and the N3 tunnel endpoints exist. The gNB only sets up radio and NG-U resources for a PDU session ID with a set of QoS flows. It never needs the name of the data network. Only the PDU session ID, the S-NSSAI and the NAS-PDU appear in both messages. The Request type, the DNN, the Old PDU session ID and the Payload container type have no NGAP counterpart.

One sentence covers the difference. The RAN is slice aware, and the RAN is not DNN aware. The S-NSSAI reaches the gNB in RRCSetupComplete, and again in PDU SESSION RESOURCE SETUP REQUEST. It changes how the gNB schedules and which AMF it selects. The DNN is never sent to the RAN, because nothing in the RAN depends on it.

Example 1 : Internet access, with the DNN supplied by the UE

This is the baseline, and nothing in it is specific to LADN. The UE names a data network, the subscription allows it, and no location is checked at any step.

Step

Message

Direction

Key IEs

1

SIB1

gNB broadcast

cellAccessRelatedInfo : plmn-IdentityList, trackingAreaCode, cellIdentity

2

RRCSetupRequest / RRCSetup

UE ↔ gNB

ue-Identity, establishmentCause = mo-Signalling

3

RRCSetupComplete

UE → gNB

selectedPLMN-Identity, registeredAMF, s-nssai-List, dedicatedNAS-Message

4

REGISTRATION REQUEST

UE → AMF

5GS registration type, 5GS mobile identity, Requested NSSAI. Carried in the dedicatedNAS-Message of step 3.

5

INITIAL UE MESSAGE (NGAP)

gNB → AMF

NAS-PDU, User Location Information = NR-CGI + TAI, RRC Establishment Cause

6

REGISTRATION ACCEPT

AMF → UE

5G-GUTI, TAI list, Allowed NSSAI. Carried in DLInformationTransfer.

7

UL NAS TRANSPORT

UE → AMF

Payload container type = N1 SM information, PDU session ID = 1, Request type = initial request, S-NSSAI, DNN = internet. Carried in ULInformationTransfer.

8

PDU SESSION ESTABLISHMENT REQUEST
(inside the payload container)

UE → SMF

PTI, Integrity protection maximum data rate, PDU session type = IPv4v6, SSC mode = 1, 5GSM capability

9

Nsmf_PDUSession_CreateSMContext

AMF → SMF

SUPI, PDU session ID, S-NSSAI, DNN, UE location

10

Nudm_SDM_Get

SMF → UDM

SUPI, S-NSSAI, DNN

11

PDU SESSION RESOURCE SETUP REQUEST (NGAP)

AMF → gNB

PDU Session ID, S-NSSAI, QoS Flow Setup Request List, UL NG-U UP TNL Information, NAS-PDU

12

RRCReconfiguration /
RRCReconfigurationComplete

gNB ↔ UE

radioBearerConfig : drb-ToAddModList with the sdap-Config that binds the DRB to this pdu-Session, and dedicatedNAS-MessageList

13

DL NAS TRANSPORT

AMF → UE

Payload container = PDU SESSION ESTABLISHMENT ACCEPT, PDU session ID = 1. Delivered inside the RRCReconfiguration of step 12.

14

PDU SESSION ESTABLISHMENT ACCEPT

SMF → UE

Selected PDU session type, PDU address, Authorized QoS rules, Session-AMBR, DNN = internet, S-NSSAI

The DNN appears twice, and never inside the 5GSM message. It is sent in UL NAS TRANSPORT and echoed in the Accept. The RRC and NGAP rows are the ones that carry the location and the slice list.

Example 2 : the UE supplies no DNN, and the network fills it in

The DNN is an optional element of UL NAS TRANSPORT. If the UE omits it, the network applies the default DNN from the subscription for that S-NSSAI. The UE then learns which data network it reached only from the Accept.

Step

Message

Direction

Key IEs

1

UL NAS TRANSPORT

UE → AMF

PDU session ID = 2, Request type = initial request, S-NSSAI, DNN absent

2

PDU SESSION ESTABLISHMENT REQUEST
(inside the payload container)

UE → SMF

PTI, Integrity protection maximum data rate, PDU session type = IPv4v6, SSC mode = 1

3

Nsmf_PDUSession_CreateSMContext

AMF → SMF

S-NSSAI, DNN = the default DNN from the subscription

4

PDU SESSION ESTABLISHMENT ACCEPT

SMF → UE

PDU address, Authorized QoS rules, DNN = the DNN the network selected, S-NSSAI

A PDU session can be established without the UE ever naming a data network. This is the furthest case from LADN.

Example 3 : a second PDU session, for IMS

A UE that needs two data networks at once establishes two PDU sessions. The session from Example 1 remains active. The DNN differs and the PDU session ID differs, while the S-NSSAI may be the same or different.

Step

Message

Direction

Key IEs

1

UL NAS TRANSPORT

UE → AMF

PDU session ID = 5, Request type = initial request, S-NSSAI, DNN = ims

2

PDU SESSION ESTABLISHMENT REQUEST

UE → SMF

PDU session type = IPv6, SSC mode = 1, Always-on PDU session requested, Extended protocol configuration options requesting the P-CSCF address

3

PDU SESSION ESTABLISHMENT ACCEPT

SMF → UE

PDU address, Session-AMBR, DNN = ims, Extended protocol configuration options carrying the P-CSCF address

Two PDU sessions, two DNNs, one UE. The DNN is what distinguishes the two inside the core.

Example 4 : a LADN DNN, requested from inside the service area

LADN enters here, and it adds exactly two things to Example 1. The registration carries LADN information, and the session setup carries a location check. Everything else is an ordinary PDU session.

Step

Message

Direction

Key IEs

1

SIB1

gNB broadcast

trackingAreaCode = TA 2. This is how the UE knows which Tracking Area it is in.

2

REGISTRATION REQUEST

UE → AMF

LADN indication, which asks the AMF for LADN information

3

REGISTRATION ACCEPT

AMF → UE

Allowed NSSAI, TAI list, LADN information : DNN value = factory-ladn, 5GS tracking area identity list = TA 1, TA 2, TA 3

4

UL NAS TRANSPORT

UE → AMF

PDU session ID = 7, Request type = initial request, S-NSSAI, DNN = factory-ladn. Carried in ULInformationTransfer.

5

PDU SESSION ESTABLISHMENT REQUEST
(inside the payload container)

UE → SMF

PTI, Integrity protection maximum data rate, PDU session type = IPv4v6, SSC mode = 1

6

UPLINK NAS TRANSPORT (NGAP)

gNB → AMF

NAS-PDU, User Location Information = NR-CGI + TAI. This is how the AMF knows where the UE is.

7

Nsmf_PDUSession_CreateSMContext

AMF → SMF

S-NSSAI, DNN, UE location = a TAI inside the LADN service area

8

Namf_EventExposure_Subscribe

SMF → AMF

Event = UE presence in LADN service area

9

Namf_EventExposure_Notify

AMF → SMF

UE presence = IN

10

PDU SESSION RESOURCE SETUP REQUEST (NGAP)

AMF → gNB

PDU Session ID = 7, QoS Flow Setup Request List, UL NG-U UP TNL Information pointing at the local UPF

11

RRCReconfiguration /
RRCReconfigurationComplete

gNB ↔ UE

radioBearerConfig : the DRB and sdap-Config for the LADN PDU session, and dedicatedNAS-MessageList

12

PDU SESSION ESTABLISHMENT ACCEPT

SMF → UE

PDU address, Authorized QoS rules, DNN = factory-ladn

The subscription in step 8 is what makes Example 6 possible. Without it the SMF would never learn that the UE had left.

Example 5 : the same LADN DNN, requested from outside the service area

A conforming UE does not send this request at all, because it can compare its current TAI against the LADN information it holds. The network still has to handle it. The UE may be holding stale information, or it may not be conforming.

Step

Message

Direction

Key IEs

1

SIB1

gNB broadcast

trackingAreaCode = TA 9, which is not in the LADN service area the UE was given

2

UL NAS TRANSPORT

UE → AMF

PDU session ID = 7, Request type = initial request, DNN = factory-ladn

3

PDU SESSION ESTABLISHMENT REQUEST
(inside the payload container)

UE → SMF

PTI, Integrity protection maximum data rate, PDU session type = IPv4v6, SSC mode = 1

4

UPLINK NAS TRANSPORT (NGAP)

gNB → AMF

NAS-PDU, User Location Information = NR-CGI + TAI, and the TAI is outside the service area

5

Nsmf_PDUSession_CreateSMContext

AMF → SMF

S-NSSAI, DNN, UE location = a TAI outside the LADN service area

6

Namf_EventExposure_Notify

AMF → SMF

UE presence = OUT

7

DL NAS TRANSPORT

AMF → UE

Payload container = PDU SESSION ESTABLISHMENT REJECT, PDU session ID = 7. Carried in DLInformationTransfer, and no RRCReconfiguration follows.

8

PDU SESSION ESTABLISHMENT REJECT

SMF → UE

5GSM cause = Out of LADN service area, Back-off timer value (optional)

Compare this against Example 4. Only the reported TAI differs, and that single field turns the Accept into a Reject. Notice that no RRCReconfiguration appears here, because no radio bearer is ever set up.

Example 6 : the UE leaves the service area while the session is up

This case has two legal outcomes, and the trigger is the same in both. What follows depends on the policy configured in the SMF, so the observed behaviour differs between networks. A test plan has to allow for both.

Step

Message

Direction

Key IEs

1

 

the UE moves to a TAI that is not in the LADN service area

2

REGISTRATION REQUEST (mobility registration updating),
or LOCATION REPORT (NGAP)

UE → AMF,
or gNB → AMF

the new TAI reaches the AMF. NGAP LOCATION REPORT also carries UE Presence In Area Of Interest.

3

Namf_EventExposure_Notify

AMF → SMF

UE presence = OUT

4

PDU SESSION RESOURCE RELEASE COMMAND (NGAP)

AMF → gNB

PDU Session Resource To Release List, Cause

5

RRCReconfiguration

gNB → UE

radioBearerConfig : drb-ToReleaseList, which takes the user plane away on the air interface

6a

PDU SESSION RELEASE COMMAND

SMF → UE

5GSM cause = Regular deactivation. The PDU session is gone.

6b

no NAS message

 

Steps 4 and 5 happen and nothing follows. The PDU session is kept in the core with no user plane.

Steps 1 to 5 are the same in both outcomes. Only step 6 differs. UNKNOWN is a third possible value of UE presence, and it means the AMF cannot currently tell.

  • The DNN travels in UL NAS TRANSPORT : It is not an element of the PDU SESSION ESTABLISHMENT REQUEST. The 5GSM message describes the session, and the 5GMM message that carries it says where the session should go.
  • The Accept always echoes the DNN : That is how a UE which supplied no DNN finds out which data network it reached.
  • Every example carries an S-NSSAI beside the DNN : Even the ordinary ones. Selection uses the pair, so neither identifier is optional from the network side.
  • LADN adds two things and nothing else : LADN information at registration, and a location check at session setup. Compare Example 4 against Example 1 and the rest of the flow is identical.
  • One field decides Accept or Reject : Examples 4 and 5 differ only in the UE location reported to the SMF.
  • The location comes from two different places : The UE reads its Tracking Area from SIB1. The AMF reads it from the User Location Information in NGAP. The LADN check compares the second one against the LADN service area.
  • Leaving the area has two legal outcomes : Release, or keep the session with no user plane. Neither is wrong, so a test case has to accept both.

Reference

LADN is specified in TS 23.501, and the procedures that carry it are in TS 23.502. The NAS messages and information elements named on this page are defined in TS 24.501.

[1] 3GPP TS 23.501 : System architecture for the 5G System (5GS)

[2] 3GPP TS 23.502 : Procedures for the 5G System (5GS)

[3] 3GPP TS 24.501 : Non-Access-Stratum (NAS) protocol for 5G System (5GS)