Reaching further · chapter 21 of 27 · 14 minutes
21 Emergency calls, messages, voice and location
What the core has to do differently for public warnings, short messages, voice, emergency calls, location and priority users — and which document carries the detail for each one.
21.1 Why the specification has a section like this
Everything else in TS 23.501 is machinery: sessions, flows, policy, slices. None of it is what a person buys. What people buy is a phone call, a text message, a warning siren, and the promise that the emergency number works.
Several of those services are older than 5G and several are required by law. They have their own specifications and their own working groups, so 5G grew attachment points for them instead of redesigning them.
Clause §4.4 and clause §5.16 are mostly a routing table: the small thing the 5G core does differently, and the document that carries the rest.
| Service | Settled here | The rest is in |
|---|---|---|
| Public warning | nothing | TS 23.041 |
| SMS over signalling | the SMSF and its reference points | TS 23.040, TS 23.540 |
| IMS voice | indications, address delivery, domain selection | TS 23.228 |
| Emergency services | nearly all of it | TS 23.167 (IMS side) |
| Location | nothing | TS 23.273 |
| Priority users | subscription and QoS handling | TS 22.153, TS 23.503 |
| Mission critical | access and QoS handling | TS 23.379, TS 23.281, TS 23.282 |
| Application triggering | what a trigger is | TS 23.502 |
| 5G LAN | the N19 point | §5.29 |
21.2 Warning everybody at once
An earthquake warning has to reach every phone in an area in seconds, idle ones and other operators' alike. It cannot be a message per subscriber.
Clause §4.4.1 and clause §5.16.1 each say one sentence: the Public Warning System for 5G is specified in TS 23.041. Nothing else here touches it.
21.3 Short messages on the signalling channel
A text message predates data connections and still does not need one. 5G keeps the old trick: the message rides inside the signalling the phone already exchanges with the core, over 3GPP radio and non-3GPP access alike §5.16.2.2.
The function for it is the SMSF. It sits behind the AMF (the function that tracks where a phone is and whether it can be reached) and does the subscription check and the sending §5.16.2.1.

Four reference points matter, and three of them are really service calls. N1 carries the message between the phone and the AMF inside NAS signalling — NAS is the conversation between a phone and the core that the radio only relays.
N20 carries it onward to the SMSF, N21 is how the SMSF registers its address with the UDM (the subscriber database) and reads the SMS subscription, and N8 is where the AMF reads its own copy of that subscription §4.4.2.2.
The SMSF's service-based interface is called Nsmsf §4.4.2.3. The links onward to the old message centres are still MAP or Diameter here; the service-based version is a separate document, TS 23.540 §4.4.2.0.
A phone gets one SMSF in the network it registers with, and moving it to another while registered is not supported in this release.
When the AMF changes, the SMSF identity travels in the phone's context, and a new AMF picks one only if none was selected yet §4.4.2.1. Selection follows the ordinary discovery rules §6.3.10.
The phone has to ask. During registration it sends an "SMS supported" indication, and the AMF answers with "SMS allowed" if the core can do it §5.16.2.2.
The home operator sets two preferences for a phone that can text both ways. "Preferred over IP" means try the IMS first and fall back to signalling, "not over IP" means do not try it at all §5.16.3.8.1.
A second preference picks between 3GPP access and Wi-Fi when the phone is registered on both §5.16.3.8.2.
A message can also have no phone number behind it. A device with no MSISDN is pre-configured with the address of the message centre and of the application that will receive it, and the network does no store-and-forward — the device learns success or failure from the delivery report.
Where one IMSI has several external identities, the NEF can ask the UDM which GPSI goes with the message, using the IMSI and the application port §4.4.7.
21.4 Voice does not live in the core
There is no voice function in the 5G core. Calls live in the IMS, a separate SIP system with its own specification; the core carries its packets and helps the phone find it §4.4.3.
The one architectural hook is between the PCF (the function that hands out policy rules) and the P-CSCF (the IMS box a phone talks SIP to): N5, or the older Diameter-based Rx kept for early deployments.
Where service-based interfaces are used inside one network, the P-CSCF is simply a trusted application function of the core §4.4.3.
The phone is told the P-CSCF's address during establishment of the IMS PDU session, sent by the SMF (the function that sets up a session and steers its traffic) and passed through the AMF untouched. When traffic is home-routed the home SMF sends it; with local breakout the visited one does §5.16.3.4.
The SMF may have the addresses configured, or discover P-CSCF instances through the NRF and choose on the slice, the phone's location and IP address, the access type, the data network name and proximity to the chosen UPF (the box that forwards the packets) §5.16.3.11.
21.5 How a call finds a network that can carry it
The core sends the phone an indication during registration: is an IMS voice over PS session supported here or not? It is per registration area, and it says whether voice works over 3GPP access and over non-3GPP access §5.16.3.2.
That fallback has a name. If the request to set up the voice QoS flow reaches the radio network and it says no, the radio network may instead trigger redirection or handover to EPS, or to E-UTRA connected to 5GC.
A call already running is untouched if the indication later flips to "not supported" — the change applies to the next call §5.16.3.10.
The phone reacts according to one setting it declares in every registration request, its usage setting: "voice centric" or "data centric" §5.16.3.7.
A voice-centric phone that cannot get voice in 5G will not camp on a cell that only reaches the 5G core; it disables 5G, reselects to 4G and runs the older voice domain selection. A data-centric phone shrugs and stays §5.16.3.5.
Incoming calls need the answer from the other direction. The AMF reports per-area support to the UDM as a "Homogeneous Support of IMS Voice over PS Sessions" indication.
It reads "Supported" when every tracking area the AMF serves can do it, "Not supported" when none can, and is left out entirely when the answer is mixed or unknown §5.16.3.3.
When a call arrives and the IMS asks, the UDM/HSS queries the serving AMF: is voice supported where the phone is, when was the last radio contact, and which access and radio type is it on §5.16.3.6.
Two smaller pieces close the clause: P-CSCF restoration at the SMF §5.16.3.9 and HSS discovery for the IMS §5.16.3.12.
21.6 Emergency calls: the normal rules are switched off
Regulators require that dialling the emergency number works from a phone with no credit, no subscription, no SIM the network knows, standing in a barred area. Almost every other rule in this document assumes the opposite, so clause §5.16.4 is a list of suspensions.
Getting in without being a subscriber. A phone in limited service state sends an Emergency Registration and asks for a session with request type "Emergency Request" in the same breath.
If that phone is unauthenticated, no security context is set up on it at all §5.16.4.1. A phone camped normally does the opposite: register for normal service, then ask for an emergency session.
Being told it is possible. The AMF puts an Emergency Services Support indicator in the registration accept, per registration area and per radio technology.
A phone in limited service state cannot register to be told, so it reads a broadcast indicator instead — and a cell attached to both 4G and 5G cores broadcasts one for each §5.16.4.1.
Where the session is built. The AMF holds Emergency Configuration Data: the slice and the emergency DNN (the name of the data network the session reaches) used to find an SMF, an aggregate bit rate, and optionally a statically configured SMF. The SMF may hold its own, naming a UPF §5.16.4.1.
Selection always lands in the serving network, which is what makes the IP address local too §5.16.4.5, and both ends must have compatible IP versions §5.16.4.8.
Only the non-roaming architectures and the roaming one with the visited network's application function apply; home-served ones do not §5.16.4.2.
Quality without a subscription. With no subscription data to read, the starting QoS values come from the visited SMF's own configuration §5.16.4.6.
Dynamic policy control is used anyway, and the PCF hands down an ARP value — the rank that decides whose resources are taken when the network runs short — reserved for emergency use, so these flows win admission control.
It also refuses an IMS session on an emergency PDU session if the P-CSCF did not mark it as an emergency §5.16.4.7.
Restrictions ignored. Mobility and access restrictions are not applied to a phone receiving emergency services.
Where they would otherwise bite, the AMF has the SMF locally release every non-emergency session and both sides carry on as though the phone were emergency registered. Handover and registration updates ignore them at source and target alike §5.16.4.3.
The session is sealed. One emergency PDU session at a time, never converted to or from a normal one. Its flows are dedicated to IMS emergency sessions, and the UPF blocks any traffic not to or from an emergency function §5.16.4.9.
A phone emergency registered on an access may not open a normal session there and the network must reject one; it may still get normal service over a different access §5.16.4.9a.
Staying reachable, briefly. An emergency registered phone does no periodic registration updates — it drops to deregistered when the timer fires, and the AMF runs a matching one.
The point is to keep it registered a while after the call, so a second call needs no fresh registration. Over non-3GPP access there is no paging, so it is reachable only while connected §5.16.4.4.
21.7 eCall, and falling back to make the call
A car that has crashed calls by itself. A phone configured for eCall only mode stays deregistered and silent: it camps on a cell but does no signalling until it must place an eCall or a configured test call.
Afterwards it runs a timer during which it behaves normally and can answer a call back from the emergency centre or the operator, then deregisters again §5.16.4.10.
Where 5G cannot carry an emergency call at all, the network advertises Emergency Services Fallback instead. The phone sends a service request whose type says so, and the AMF pushes it to E-UTRA connected to 5GC or all the way to EPS, by handover or redirection.
The AMF tells the radio network which core to aim at, so the phone knows which signalling to speak on arrival, and a colliding security re-keying is abandoned. Fallback is a PLMN mechanism, absent in stand-alone private networks §5.16.4.11.
21.8 Where the phone is
Location services are optional in this release and cover the regulatory case (an emergency centre needs the caller's position) and commercial ones. The architecture, its reference points and its service-based interfaces are defined in TS 23.273, not here §4.4.4.1.
21.9 Users who go first
When a disaster fills the radio, the people managing it still have to get through. Multimedia Priority Service gives government-authorised personnel and emergency officials priority access to system resources, end to end §5.16.5. It works at three levels.
-
Getting on the radio. The subscription entitles the USIM with a special Access Identity, so Unified Access Control lets the phone in ahead of ordinary ones during congestion, and it uses a high-priority establishment cause when it sets up or resumes its radio connection.
-
Getting the packets through. Priority flows are given ARP values matching the user's priority, with pre-emption capability and vulnerability set by operator policy, so ordinary users can be pre-empted.
The terminating network recognises the session too and pages with priority. Signalling gets it as well — authentication, security and mobility procedures included.
-
Getting it switched on. Some users have priority permanently; others are "on demand" and invoke it per session.
Priority for data transport is always on demand: the user asks an application function, the AF or the PCF authorises it, and the PCF raises the ARP and the 5QI (the number pointing into a table of delay, loss and priority values) of the default flow and any others named.
Any data network name qualifies except the well-known one for IMS.
A separate subscription switch turns priority on or off for messaging — short messages over signalling, over IP, and IMS messaging alike §5.16.5. The mechanisms are catalogued in §5.22.
Mission critical services — push-to-talk, video and data for the emergency services, utilities and railways — work the same way: special Access Identity, ARP and 5QI settings, pre-emption of ordinary users, priority paging.
What is added is that authorised users may change the QoS and policy themselves in real time, within limits the operator sets §5.16.6. They are specified in TS 23.379, TS 23.281 and TS 23.282.
21.10 The three short entries in 4.4
Waking an application. An application server can send a trigger to a device. Part of the message routes it to the right phone, part routes it to the right application, and the remainder — the trigger payload — is opaque to everyone in between, its meaning left to the implementation.
Often the application then opens a PDU session and calls home §4.4.5.
A LAN over the mobile network. For 5G LAN-type services, traffic between two phones in one group need not go out via N6. One UPF can switch it locally, or two UPFs can carry it to each other over N19, a reference point that exists per virtual network group §4.4.6.2.

The rest — groups, addressing, session management — is §5.29, and belongs to Networks that are not for everybody.
Clocks. Clause §4.4.8 draws the architectures for time-sensitive networking, AF-requested time synchronisation and deterministic networking, all taught in Clocks, TSN and deterministic delivery.
21.11 Where this meets the rest of the system
Nearly everything here is a special case of machinery taught elsewhere. Emergency and priority sessions are ordinary PDU sessions The connection to a data network whose advantage is expressed in ARP and 5QI What the network promises, set by the policy function Rules, and paying for them.
Voice and emergency fallback are the 4G interworking machinery put to one use Living next to 4G, the emergency DNN and its slice are ordinary slice selection One network, many networks, and every indication above rides registration Registration, reachability and paging.
Check yourself
Answers appear when you pick one, with where they come from.
Q21.1 A phone with no valid subscription dials the emergency number. What does the specification say the network may do?
A network supporting Emergency Services for phones in limited service state provides them regardless of whether the phone can be authenticated, has roaming or mobility restrictions, or a valid subscription. §5.16.4.1
Q21.2 The network tells a phone "IMS voice over PS session supported". What does that promise?
The indication may also be set when neither NR nor E-UTRA connected to 5GC can carry the call, as long as the radio network can hand over or redirect the phone to EPS when the voice flow is asked for. §5.16.3.2
Q21.3 What does the UPF do with traffic on an emergency PDU session that is not addressed to an emergency function?
The flows of the emergency DNN are dedicated to IMS emergency sessions, and the UPF blocks anything that is not from or to the addresses of functions providing Emergency Services, such as the P-CSCF. §5.16.4.9
Q21.4 A visiting phone makes an emergency call. Which network's SMF serves it?
Emergency SMF selection always derives an SMF in the serving PLMN or SNPN, which is what guarantees the IP address is allocated there too. §5.16.4.5
Q21.5 Can a phone's SMSF be changed while it stays registered in the same network?
Each phone has one SMS Function in the registered PLMN, and reallocation while it is in RM-REGISTERED state in that network is not supported. §4.4.2.1
Q21.6 What does an MPS subscription entitle in the USIM?
The subscription entitles a USIM with a special Access Identity, which is what Unified Access Control uses to let the phone in ahead of ordinary ones when the radio is congested. §5.16.5
This chapter was written against TS 23.501 version 20.2.0, verified 2026-08-04. A newer version of the document may say something else.