School of Specs The 5G system architectureIn depth

What the system does · chapter 9 of 27 · 15 minutes

9 Registration, reachability and paging

Why a device has to register at all, the two state machines that track it, and how the network finds it again once it has gone quiet.

Built from §5.3 §5.4 §5.11

9.1 Why a device has to say who it is before anything else

A phone switched on and camped on a cell is, to the core network, a stranger. Nobody has checked who it is, nobody holds a record of it, and nobody knows which base station would reach it.

Registration fixes all three at once. It runs the access-control functions — who are you, and does your subscription allow this — and leaves a device context behind in the AMF (the function that tracks where a device is and whether it can be reached).

The identity of that serving AMF is written into the UDM, the subscriber database, so the rest of the network can find out who is serving this subscriber §5.3.2.1.

Connection management is the separate, much shorter-lived job: setting up and releasing the signalling path between the device and the AMF §5.3.1.

9.2 Two state machines, side by side

Registration management Connection management
States RM-DEREGISTERED, RM-REGISTERED CM-IDLE, CM-CONNECTED
Question it answers Does the network hold a context for this device? Is there a signalling connection right now?
Clause §5.3.2.2.1 §5.3.3.2.1

Both are kept by device and AMF, and both are per access type: a device can be registered over the radio and deregistered over Wi-Fi at once, idle on one while connected on the other §5.3.3.2.1.

9.3 The two registration states

From RM-DEREGISTERED the device attempts an Initial Registration when it needs a service that requires one. A Registration Accept moves it to RM-REGISTERED; a Registration Reject leaves it where it was §5.3.2.2.2.

Figure 5.3.2.2.4-1: RM state model in UE
Figure 5.3.2.2.4-1: RM state model in UE 5.3.2.2.4

Once registered, the device carries four standing duties §5.3.2.2.3:

  • Mobility Registration Update when the tracking area of its serving cell is not in the TAI list it was given. This is what keeps the AMF able to page.

  • Periodic Registration Update when the periodic update timer fires, to say it is still there.

  • Mobility Registration Update again, for a different reason: to change declared capabilities or re-negotiate protocol parameters.

  • Deregistration, which it may decide on at any time.

The AMF holds the mirror duties plus one the device never sees: when its implicit deregistration timer expires, it drops the context silently §5.3.2.2.3.

9.4 The registration area, and why it is kept small

The AMF hands the device a TAI list — a set of tracking areas — and that set is its registration area. Inside it the device moves and says nothing. The moment it camps on a cell whose tracking area is not in the list, it must report in §5.3.2.3.

A large list means fewer registration updates and a paging message that must go out over more cells. The specification does not spell that arithmetic out, but it says that in MICO mode the registration area "is not constrained by paging area size" §5.4.1.3 — which tells you that otherwise it is.

The AMF sizes the list from the device's Mobility Pattern and its allowed or non-allowed areas §5.3.2.3.

Two rules shape the list §5.3.2.3:

  • One list may hold tracking areas of any NG-RAN nodes in the area, but only TAIs that apply on the access type it is sent over — and in an SNPN, a private network standing on its own, never two SNPNs at once. A TAI is a country code, a network code and a three-byte tracking area code, no more.

  • A tracking area may not contain both NB-IoT cells — narrowband radio for small, cheap sensors — and cells of other radio technologies, and the AMF may not build a list mixing them. That is what forces a registration update when a device crosses into or out of NB-IoT.

Over non-3GPP access the registration area is degenerate. Each N3IWF, TNGF, TWIF or W-AGF — the gateways bringing untrusted Wi-Fi, trusted Wi-Fi and fixed lines into 5G — carries one TAI, and that single TAI is the whole registration area until the device deregisters §5.3.2.3.

9.5 One device on two accesses

The AMF keeps one registration context per access — its own state, its own registration area, its own timers — tied together by a 5G-GUTI common to both when they are in the same network.

A device already registered on one access presents that 5G-GUTI when it registers on the second, and must not start the second until the first has finished §5.3.2.4.

There is no periodic registration over non-3GPP access at all. The AMF must not give a Periodic Registration Timer for it; the device gets a Non-3GPP Deregistration timer instead, started when it goes idle there §5.3.2.4.

9.6 CM-IDLE and CM-CONNECTED

A NAS signalling connection is two pieces glued together: the signalling connection between device and access node — an RRC connection over radio, or the connection to an N3IWF or TNGF over Wi-Fi — and the N2 connection between that access node and the AMF §5.3.3.1.

CM-IDLE means neither piece exists, and the device does its own cell selection, cell reselection and network selection.

An idle, registered device does two things: it answers paging with a Service Request, and it starts a Service Request of its own when it has uplink signalling or data. Both are suspended in MICO mode §5.3.3.2.2.

The transition is defined by the message, not by intent. Sending an initial NAS message — Registration Request, Service Request or Deregistration Request — takes the device to CM-CONNECTED, and the arrival of the first N2 message does the same for the AMF §5.3.3.2.2.

Figure 5.3.3.2.4-1: CM state transition in UE
Figure 5.3.3.2.4-1: CM state transition in UE 5.3.3.2.4
Figure 5.3.3.2.4-2: CM state transition in AMF
Figure 5.3.3.2.4-2: CM state transition in AMF 5.3.3.2.4

Going back costs something. When a device enters CM-IDLE, the user-plane connections of every PDU session active on that access are deactivated §5.3.3.2.4. The sessions survive; their tunnels do not — The connection to a data network.

Paging never uses the permanent subscriber identity. The AMF stores what it needs to start contact and looks it up by 5G-GUTI, and the device supplies its 5G-S-TMSI as an access-network parameter when it sets a connection up §5.3.3.2.2. The identity zoo is Every name the system uses.

At release the access node may hand the AMF a list of recommended cells, tracking areas and access node identifiers §5.3.3.3.3, which the AMF stores and uses the next time it has to page §5.3.3.3.2.

9.7 The half-way state: RRC_INACTIVE

What changes is who is in charge of finding the device. In RRC_INACTIVE, reachability and paging are handled by the radio network, and the device listens for paging on both its core identity and a RAN identity §5.3.3.2.3.

It can only do that because the AMF hands it RRC Inactive Assistance Information at every N2 activation — registration, service request, handover.

That carries the device's wake-up cycle values, its registration area, the periodic registration update timer, whether MICO mode is on, and enough of the device identity to work out its paging occasions.

If any of it changes through a NAS procedure, the AMF must push a fresh copy §5.3.3.2.5.

The radio network then gives the device a RAN Notification Area and a periodic RAN Notification Area Update timer derived from the registration one, and keeps a guard timer longer than the one it handed out. The same idea one level down: move inside the area silently, report when you leave it.

The device resumes for uplink data, a NAS procedure of its own, an answer to RAN paging, having left the area, or the timer firing §5.3.3.2.5.

When RAN paging fails with a NAS message pending, the radio node releases the connection and tells the AMF it could not be delivered, dropping the device to CM-IDLE.

With only user data pending it may keep N2 up or release it by local configuration — and the specification says plainly that the data which triggered the paging can be lost §5.3.3.2.5.

9.8 Staying reachable: the timer chain

Reachability is three timers stacked, and this part sits in §5.4 rather than §5.3 — the detail is in §5.4.1.1:

  • The device starts its periodic registration timer whenever it enters CM-IDLE while registered. When it fires, it registers again.

  • The AMF starts a Mobile Reachable timer, longer than that, on the same event. If it fires the AMF decides the device is not reachable, clears the Paging Proceed Flag and stops paging it.

  • The AMF then starts an Implicit De-registration timer, much larger again. If that fires too the device is deregistered without any message, and its PDU sessions on that access are released.

Any move to CM-CONNECTED stops the last two and sets the flag again. Device and AMF negotiate one of three reachability categories at registration: normal reachability with paging, MICO mode, or unreachable because of an Unavailability Period §5.4.1.1.

9.8.1 MICO mode

MICO — Mobile Initiated Connection Only — is for devices that only ever start conversations, never receive them. The device asks at registration and the AMF decides; if it did not ask, the AMF may not turn MICO on.

With MICO on, the AMF treats the device as permanently unreachable while it is CM-IDLE and rejects downlink delivery requests outright. The device need not listen for paging at all.

It comes back for four reasons: a change needing re-registration, the periodic registration timer, pending uplink data, pending uplink signalling §5.4.1.3.

Because paging costs nothing now, an AMF serving the whole network may give an "all PLMN" registration area, after which mobility never causes a re-registration.

Emergency service and MICO do not mix: a device starting one must not ask for MICO, and if MICO was on, both sides disable it locally once the emergency PDU session is up §5.4.1.3. Small devices push MICO further — see Small devices, small messages.

9.9 Mobility restrictions: where a device may not go

Five kinds, enforced in different places §5.3.4.1.1:

  • RAT restriction — radio technologies this subscription may not use here. Enforced in the network, never told to the device.

  • Forbidden Area — the device may start no communication with this network here.

  • Service Area Restriction — an Allowed Area or a Non-Allowed Area.

  • Core Network type restriction — 5G core only, 4G core only, or both.

  • Closed Access Group information — a CAG names a group of subscribers allowed to use particular cells, and stops everyone else from selecting those cells automatically §5.30.3. See Networks that are not for everybody.

Who applies them depends on the state. In CM-IDLE and in RRC_INACTIVE, the device enforces them itself from what the core told it.

In RRC_CONNECTED — the radio link is up and carrying traffic — the radio network and the core do it, from a Mobility Restriction List the core sends over §5.3.4.1.1.

The network sends either an Allowed Area or a Non-Allowed Area, never both: anything outside an Allowed Area is non-allowed, anything outside a Non-Allowed Area is allowed, and a device given neither treats the whole network as allowed.

Where a Forbidden Area and a Service Area Restriction overlap, the Forbidden Area wins §5.3.4.1.1.

Emergency services override the lot §5.16.4.3, and for priority and mission-critical services, service area restrictions may not apply at all §5.3.4.1.1.

The areas come from subscription. The UDM holds a Service Area Restriction of up to about sixteen whole tracking areas, or unlimited, and it may be written as geography — longitude and latitude, postcodes — which the network maps to tracking areas before anyone outside sees it.

The PCF, the policy function, may then widen an Allowed Area, shrink a Non-Allowed Area, or raise the maximum allowed number of tracking areas — a quota the AMF fills in as the device visits new areas, never sent to the device, cleared at every Initial Registration §5.3.4.1.2.

Registration areas are built to sit on one side of the line: a device in an allowed area gets one made of allowed tracking areas, a device in a non-allowed area one made of non-allowed ones.

If the restrictions change while the device is CM-CONNECTED the AMF updates it and the radio network at once; if it is CM-IDLE the AMF may page it to run a UE Configuration Update, or wait for the next time it speaks §5.3.4.1.2.

9.10 What else the AMF carries about mobility

  • Mobility Pattern — the AMF's picture of how this device moves, from subscription, movement statistics, local policy, hints from the device or analytics. Used mainly to size registration areas §5.3.4.2.

  • RFSP Index — one number the AMF gives the radio network, which maps it to local rules for idle-mode camping priorities and for pushing active devices to other frequencies or radio technologies §5.3.4.3.1. Its slice-aware version is in One network, many networks.

  • UE mobility event notification — any authorised function may subscribe to the AMF for a device's location, or for whether it entered or left an Area of Interest given as tracking areas, cells or node identifiers §5.3.4.4. The AMF may itself subscribe to analytics, for instance on a device re-registering unusually often §5.3.5.

9.11 One device, two radio legs

Clause 5.11 is here because it is where the single connection this chapter has assumed turns out to be two.

The node that terminates N2 is the Master RAN node, and it does every N2-related job: mobility, relaying NAS messages, handling the user plane. The Secondary RAN node lends radio resources and nothing else §5.11.1.

For each PDU session the master node asks the SMF for one of two arrangements §5.11.1:

  • All downlink traffic of the session goes to one node, master or secondary. One N3 tunnel terminates at the radio network.

  • Some QoS Flows of the session go to the secondary node and the rest to the master. Two N3 tunnels terminate at the radio network, however many flows there are.

Either way there is one PDU Session ID, and the master node may change the arrangement at any point in the session's life §5.11.1. Flows themselves are What the network promises.

Three details bite. Location reporting uses the master node's serving cell, with the secondary node's primary cell optionally added. Path update signalling cannot happen at the same time as a UPF reallocation.

And the Mobility Restriction List may be the reason dual connectivity is never set up — as, in this release, is being an NR RedCap device, one built with reduced radio capability to keep it cheap and low-power §5.11.1.

9.12 Where this meets the rest of the system

Check yourself

Answers appear when you pick one, with where they come from.

Q9.1 A registered phone is in your pocket overnight, sending nothing. Which pair of states is it in?

Q9.2 What makes a registered device start a Mobility Registration Update?

Q9.3 A device is CM-CONNECTED with RRC_INACTIVE. Who pages it?

Q9.4 A Forbidden Area and a Service Area Restriction both cover where the device is standing. Which one applies?

Q9.5 What does the network send a device whose service area is limited?

Q9.6 With dual connectivity, how many N2 termination points does one device have?

This chapter was written against TS 23.501 version 20.2.0, verified 2026-08-04. A newer version of the document may say something else.