Special worlds · chapter 27 of 27 · 17 minutes
27 Overload, energy, deployment and the rest
What a 5G core does when it is too busy to cope, how it is deployed and taken out of service without dropping anybody, how it counts its own energy, and thirteen smaller features that live nowhere else.
Built from §5.19 §5.21 §5.22 §5.23 §5.24 §5.25 §5.26 §5.36 §5.38 §5.40 §5.48 §5.51 §5.52 §5.53 §5.54 §Annex C §Annex F §Annex T §Annex U
27.1 Why a network needs a plan for its worst day
A network is built for a normal Tuesday. Then a stadium empties at once, a power cut knocks out half the base stations and every phone in the city re-registers in the same minute, or one bad app on a million devices retries every second.
None of that arrives as data traffic. It arrives as signalling, handled by a small number of control-plane functions that cannot be widened in the ten seconds you have. So the specification says what "too busy" means.
Three families of measure sit under that heading: spreading load out, refusing work at the door, and telling phones to come back later. There is also a warning system — the AMF and SMF can subscribe to the NWDAF (the analytics function) for Signalling Storm Analytics and act before the storm lands §5.19.1.
27.2 Spreading the load before anything breaks
Every AMF in an AMF set advertises a Weight Factor to the radio nodes over NGAP, the protocol between a radio node and the AMF. A radio node picks an AMF with a probability proportional to that weight, so the weight normally matches the AMF's capacity §5.19.3.
The document is unusually direct about the timescale: this is not a dial you turn during an incident. A mature network should expect changes monthly, typically when hardware is added, and a newly installed AMF may get a high weight for a while so that it fills up faster §5.19.3.
Set the weight to zero and the AMF stops receiving new arrivals, but keeps the subscribers it already has.
Moving those is a separate mechanism. In load re-balancing the AMF asks some or all of its radio nodes to redirect a cross-section of the phones served by one of its GUAMIs — the name identifying an AMF — either to one named target AMF or to any other AMF in the same set §5.19.4.
For an idle phone nothing happens until it comes back: the radio node sees an initial message pointing at the old AMF and forwards it elsewhere.
For a connected phone the AMF management machinery is reused §5.21.2, except that the old AMF deregisters itself from the NRF, the register functions are found in.
Either way the new AMF hands the phone a fresh 5G-GUTI — the temporary name a phone is known by — built from its own GUAMI §5.19.4.
Two notes in that clause matter more than the text around them: re-balancing is meant for use before overload, and once an AMF really is overloaded it rarely helps, because load balancing should already have left every other AMF in the set just as overloaded §5.19.4.
Balancing across the transport connections themselves is left to the virtualized deployment machinery, which is all that clause says §5.19.2.
27.3 Refusing work at the door
When the AMF is genuinely over its limit it does two things at once: it turns on NAS congestion control, and it tells the radio network to stop sending it work §5.19.5.2.
The second is an NGAP OVERLOAD START message, sent to all its radio nodes or a proportion of them — sending it to fewer nodes is itself the volume control. It may carry a list of S-NSSAIs, the slice identifiers, so only those slices are restricted, and a percentage of connection requests to reject §5.19.5.2.
The message asks the radio node for one of these behaviours:
-
Refuse connection requests that are not emergency, not exception reporting and not high priority mobile originated services.
-
Refuse connection requests that carry uplink signalling for that AMF.
-
Refuse connection requests whose requested slice list contains only the slices named in the message.
-
Permit only emergency sessions and mobile terminated services.
-
Permit only high priority sessions, exception reporting and mobile terminated services.
The same applies to a connection resumed from RRC_INACTIVE and to a phone arriving over non-3GPP access (Wi-Fi and wireline) through an N3IWF or a TNGF, the two gateways that let such access into the core §5.19.5.2.
A refused phone is given a wait timer by the radio node, so "come back later" exists at this level too. Throughout, the AMF should keep emergency services and MPS — the priority service for authorised users — working.
Recovery is either a new OVERLOAD START with a gentler percentage, or an OVERLOAD STOP §5.19.5.2.
The SMF has a smaller version of the same thing. It rejects NAS requests, and it may be pushed into overload not by its own load but by a UPF restarting or partly failing underneath it §5.19.6.
27.4 Telling the phone to come back later
NAS congestion control is one idea applied at five different scopes. The idea is a back-off time handed to the phone, during which it starts no signalling for whatever the timer covers — unless the network pages it, or it needs emergency services or high priority access §5.19.7.1.
The rule that matters most is one sentence long: the core should pick each value so that the deferred requests are not synchronised §5.19.7.1. A single timeout handed to a million devices does not solve a storm, it schedules one.
General mobility management congestion control covers registrations and service requests §5.19.7.2. While the timer runs the phone may still deregister — and the timer keeps running afterwards — and may still do a mobility registration update if it is already connected. Paging stops the timer at once.
Changing cell, radio technology, tracking area or access type does not stop it, and it is explicitly not a reason to go looking for another network; it does stop on reaching a genuinely different PLMN or SNPN.
If the AMF hands out a timer longer than the phone's periodic registration and implicit deregistration timers combined, it should stretch its own timers so it does not quietly deregister a phone that is obediently waiting §5.19.7.2.
DNN based congestion control is per data network name. The phone keeps a separate timer for each DNN it uses, and may carry on using other DNNs. The timer applies in any PLMN, unless the DNN is a local area one, in which case it applies only where it was issued §5.19.7.3.
S-NSSAI based congestion control is per slice, and per slice-and-DNN pair. Here the SMF may add an indication of home network congestion: without it the timer binds only in the network that issued it, with it everywhere §5.19.7.4.
Group specific congestion control applies to phones sharing an internal group identifier §5.9.7. It runs inside the core and the phone never sees it — and the document says plainly that the logic for it is not described in this Release §5.19.7.5.
Control plane data congestion control is for small devices that send data inside signalling rather than over a user plane connection Small devices, small messages. The AMF stores one timer per phone and refuses further data-carrying requests, but a paging response and an exception report still get through §5.19.7.6.
One escape hatch runs through all of them. A phone reporting a change of its data-off setting marks the message as exempt; the AMF must then pass it on with that marking, and the SMF checks the claim and rejects the message if it was not really exempt §5.19.7.3.
27.5 Who still gets in when the door is nearly shut
The priority clause is the other side of that coin: the ways a subscriber is marked important enough to survive all of the above §5.22.1.
Some of it is subscription. The UDM (the store of what a subscriber is allowed) holds MPS and MCX — mission critical push-to-talk and data for emergency services and utilities — priority indications, handed to the AMF at registration.
The USIM holds an Access Identity that gets the phone past radio-level barring, and the ARP — the parameter that decides which flows are kept when resources run short — is set from a range the operator reserves for priority services §5.22.2.
Some of it is invocation: an application function asks the PCF (the function that turns operator policy into the rules a session is run by) for priority when a call is set up.
The PCF then rewrites the ARP and the 5QI — the number pointing into a table of delay, loss and priority values — of the flows involved §5.22.3.
Paging gets a Paging Priority so a priority call still reaches an idle phone in a congested area.
The payoff sits in one place. Prioritised services are exempt from session and mobility management congestion control, priority flows are exempt from release during rebalancing, and when packets must be dropped the radio network and UPF drop everything else first §5.22.4.
27.6 How the core is actually deployed and taken apart
This is the part of the document about running software rather than running a network. The two shapes it spells out are one network function instance spread over several locations and execution instances, or several instances grouped into an NF Set that behave as one.
The clause says outright that the list is not exhaustive, so a deployment fitting neither shape is not thereby forbidden §5.21.0.
Instances inside a set are interchangeable because they share the same context data, and the same trick is applied one level down to NF Service Sets.
For an SMF set this has a concrete consequence: if a single N4 association exists between the set and a UPF, any SMF in the set can drive it — but only one controls a given session at a time §5.21.3.2.
Between a radio node and an AMF there can be many transport connections. The AMF gives each a weight and says which carry phone-specific signalling §5.21.1.1.
Two things follow for a connected phone: the AMF may move its binding to a different connection at any time, and it may command the radio node to release that binding while the user plane on N3 stays up §5.21.1.2. The second is what makes draining an AMF invisible.
Taking an AMF out of service comes in two flavours.
-
With a UDSF (the shared store for unstructured data) the AMF writes each phone's context there and deregisters from the NRF. The radio nodes and other functions mark it unavailable, pick any AMF in the set instead, and that AMF reads the context back out §5.21.2.2.1.
-
Without a UDSF the AMF pushes the contexts itself, grouped by GUAMI, to named target AMFs in the same set, and those targets tell everyone that the old GUAMI is now theirs §5.21.2.2.2.
Unplanned failure works the same way, with a backup AMF configured per GUAMI in advance and announced during N2 setup, so a radio node that detects a dead AMF already knows where to go §5.21.2.3.
The guidelines for that shared store sit in an annex: whether it holds the only copy or a second copy is up to the implementation, every function in a set is assumed to reach the same records, and two instances racing for one record is left unresolved on purpose §Annex C.
27.7 Counting the energy
Energy is treated as a measurement problem before a control problem. The Energy Information Function collects node-level energy figures and data volumes from the management system, and per-session data volumes from the UPF through the SMF.
It then works out consumption per phone, per slice, per PDU session and per traffic flow §5.51.2.1.
The maths is a proportional share: the energy a base station burned in a time window, times this phone's share of the data volume that passed through it. The example formulas are in an annex §T.2 and the choice is the operator's §5.51.2.3.
Everything is reported on the same aligned interval, because figures from different windows cannot be added up §5.51.2.2.1.
What comes out can be a raw number, a threshold crossing, energy per bit, a category on an operator-defined scale, or a ranking of which applications used the most.
That last one comes only if the NEF, the core's door to outside software, has checked that the asking application may see it §5.51.2.4.
The control side is thinner. Subscription data may carry an Energy Saving Indicator whose meaning is configured in the PCF §5.51.5; the PCF folds that, and any energy figures, into policy decisions and marks the reason in the rule so charging can see it §5.51.6.
An NF profile may carry an Energy Priority so discovery can prefer one instance over another §5.51.7, and user plane path selection uses the same input §5.51.8. Background and planned transfers can be scheduled with an energy indicator from the application §5.51.4, §5.51.9.
In this Release only user plane resources on 3GPP access are counted §5.51.2.1.
27.8 Thirteen smaller features, in brief
Asynchronous type communication lets the AMF accept a change to a phone's context without waking it, and push it out the next time the phone is connected anyway. The asking function says whether that is acceptable, and an AMF older than Release 17 cannot even read that indication §5.23.
3GPP PS Data Off is the setting a user turns on to stop mobile data. The phone blocks its own uplink and the network blocks the rest, except for exempt operator services listed by the home network.
There is one list, or two — one for home and one for roaming; a single list covers both. Non-3GPP access is untouched, including the non-3GPP half of a multi-access session §5.24, Using two accesses at once.
Tracing is the operator's debugger. Trace requirements sit in the subscription, arrive at the AMF and SMF with the rest of it, and are propagated outward to the radio network, AUSF, PCF, SMSF and UPF — never carrying the phone's permanent identity to the radio §5.25.1.
Two smaller items share the clause: group management for 5G LANs configured by an administrator §5.25.2, and switching on quality-of-experience measurement collection §5.25.3.
Configuration transfer is a postal service for the radio network. One radio node wants to reach another before any direct link exists — to exchange addresses so Xn can be set up for self-optimising networks, say §5.26.
It wraps its message in a container with a source and target address and hands it to the core, which routes it without looking inside §5.26.1.

RIM information transfer uses the same idea for remote interference management between radio nodes, again with the AMF forwarding a container it does not interpret §5.36.
Multi-USIM support is for a phone with two active subscriptions and one radio. Five features let it cope.
They are: asking to be released from one network because the other needs the radio §5.38.2, a page that says "this is a voice call" so the phone can judge whether to leave §5.38.3, and rejecting a page outright §5.38.4.
The last two are asking to be paged only for named things §5.38.5, and asking for a new 5G-GUTI so its two paging schedules stop colliding §5.38.6.
Each USIM uses a separate equipment identity, and none of this is offered during an emergency registration §5.38.1.
Disaster roaming lets phones from a network that has been knocked out register on a competitor's. The home network arms the feature in the phone, the surviving network broadcasts that it accepts disaster roamers, and the phone registers with a registration type that says so §5.40.4.
It is limited to the affected tracking areas, and in this Release a disaster condition applies to radio nodes only — the rest of the stricken network is assumed alive §5.40.1. Arrival and return are both throttled with wait ranges, because a whole city returning at once is its own disaster §5.40.6.
Subscription-based routing to a target core network sends a subscriber's signalling and traffic to a partner network — all of it, or only the sessions for certain DNNs or slices — by feeding a routing indicator or SUPI range into the ordinary discovery rules §5.48.1, How one function finds another.
QoS for devices behind a phone covers a laptop or sensor reaching the network through a phone and never speaking to the core itself.
The phone binds a Non-3GPP Device Identifier to it and tells the SMF which MAC address, IP address or port range that identifier owns; the PCF looks the identifier up in the UDR, where policy and subscription data are kept, and applies the rules stored there §5.52.3.
Local breakout while roaming is not supported for this in this Release §5.52.1.
Dynamic network identity is the name a phone shows in its status bar. The AMF sends it in a configuration update, taking it from operator configuration or the PCF, and passes it to the next AMF when the phone moves §5.53.1.
Mitigating abnormal user plane traffic is the data-plane counterpart of overload control. Analytics about abnormal traffic can go to the PCF, the SMF or straight to the UPF.
The response is a rule that drops, shapes or silences the offending flows — per session, or at node level for traffic belonging to no session at all §5.54.
Redundant paths using two UEs builds a doubled connection out of a device holding two subscriptions. Each is put in a Reliability Group, and the cells of the radio network are grouped too.
The two subscriptions then normally stay on separate base stations, falling back to a cell of the other group only where their own group has no coverage; different DNNs or slices push them onto different UPFs and SMFs §Annex F. It answers the reliability problem of Clocks, TSN and deterministic delivery.

Home breakout near the visited network is a roaming deployment note: the home operator puts a UPF physically close to the visited network, so a home-routed session need not drag its traffic back across a continent.
Selection uses the phone's location, and if the path to the visited UPF fails the session is released with a cause asking for re-establishment §U.2, §U.3, Being served by somebody else's network.

Check yourself
Answers appear when you pick one, with where they come from.
Q27.1 What does an overloaded AMF send to make the radio network turn phones away?
N2 overload control is the AMF invoking the overload procedure towards all or a proportion of the radio nodes it has N2 connections with, and it may carry a percentage of requests to restrict. §5.19.5.2
Q27.2 A Mobility Management back-off timer is running in a phone. Which of these is it still allowed to start?
While the timer runs the phone starts no NAS request except deregistration and procedures not subject to congestion control, and after such a deregistration the timer keeps running. §5.19.7.2
Q27.3 Why does the specification tell the core to pick a different back-off value for each phone?
Identical timers would make a large number of phones retry almost simultaneously, which recreates the storm the timer was meant to break. §5.19.7.1
Q27.4 An AMF is being taken out of service and there is no UDSF in the network. What happens to the contexts of the phones it serves?
Without a UDSF the AMF forwards registered UE contexts, grouped by the same GUAMI value, to target AMFs within the same AMF set, and then deregisters itself from the NRF. §5.21.2.2.2
Q27.5 A user switches on 3GPP PS Data Off. What still gets through?
The feature blocks IP, Unstructured and Ethernet traffic via 3GPP access except the 3GPP PS Data Off Exempt Services, and the status of a PDU session does not affect transfer over non-3GPP access. §5.24
Q27.6 Which function works out how much energy one phone, slice or session consumed?
The EIF collects the inputs, calculates consumption at UE, S-NSSAI, PDU session and service data flow granularity, and exposes the result to authorised consumers. §5.51.2.1
This chapter was written against TS 23.501 version 20.2.0, verified 2026-08-04. A newer version of the document may say something else.