School of Specs 23.501v20.2.0

3GPP 23.501 v20.2.0 — the document's own text

5.30.2.12 Access to SNPN services via Untrusted non-3GPP access

Taught in 24. Networks that are not for everybody (The 5G system architecture, in depth).

Access to SNPN services via Untrusted non-3GPP access network follows the specification in the previous 5.30.2 clauses with the differences as specified in this clause.

N3IWF selection is supported as follows:

  • When UE registers to SNPN with credentials owned by the SNPN, UE uses the same N3IWF selection procedure as specified for access to stand-alone non-public network services via PLMN in clause 6.3.6.2a.

Emergency services are supported as follows:

  • UE initiates N3IWF selection for emergency services when the UE detects a user request for emergency session and determines that Untrusted non-3GPP access is to be used for the emergency access. The UE in SNPN access mode the following:
    • If the UE determines that it is located in the same country as the configured N3IWF of the subscribed SNPN, the UE uses the configured N3IWF FQDN for N3IWF selection.
    • Otherwise, the UE performs a DNS query using the Visited Country Emergency SNPN FQDN, as specified in clause 28.3.2.2.6.3 of TS 23.003 [19] to determine which SNPNs in the visited country support emergency services in untrusted non-3GPP access via N3IWF; and:
    • If the DNS response contains one or more records, the UE selects an SNPN that supports emergency services in untrusted non-3GPP access via N3IWF based on UE implementation specific methods. Each record in the DNS response shall contain the identity of an SNPN (i.e. SNPN ID) in the visited country supporting emergency services in untrusted non-3GPP access via N3IWF.

NOTE 1: Self-assigned NIDs are not supported, since a DNS cannot be properly configured for multiple SNPNs using the same self-assigned NID (i.e. in collision scenarios).

    • Once the UE has selected an SNPN, the UE selects an N3IWF for Emergency for the selected SNPN, as specified in TS 23.003 [19].

When an N3IWF has been selected, the UE initiates an Emergency Registration. If the Emergency Registration fails, the UE shall select another SNPN supporting emergency services in untrusted non-3GPP access.

If the DNS response of the Visited Country Emergency SNPN FQDN does not contain any record, or if the DNS response contains one or more records but the UE fails to select an SNPN that supports emergency services in untrusted non-3GPP access, or if the Emergency Registration procedure has failed for all SNPNs supporting emergency services in untrusted non-3GPP access, the UE deactivates the SNPN access mode over NWu and attempts emergency services via PLMN untrusted non-3GPP access, by following the N3IWF selection procedure as defined in clause 6.3.6.4.2.

NOTE 2: If the UE determines that it is located in a different country as the configured N3IWF of the subscribed SNPN, the UE can deactivate the SNPN access mode over NWu and attempts emergency services via PLMN untrusted non-3GPP access, by following the N3IWF selection procedure defined in clause 6.3.6.4.2, without performing a DNS query using the Visited Country Emergency SNPN FQDN.

UE onboarding is supported as follows:

  • When UE registers to SNPN over Untrusted non-3GPP access for UE Onboarding, if the UE determines that it is located in the country where the configured N3IWF for onboarding is located, the UE may select the N3IWF in the SNPN which supports UE Onboarding by using the configured N3IWF FQDN used for Onboarding.
  • If the UE determines that it is located in a country different from the country where the configured N3IWF for onboarding is located (called the visited country), then in order to determine which SNPNs in the visited country support Untrusted non-3GPP access for UE Onboarding via N3IWF performs a DNS query using the Visited Country FQDN for SNPN N3IWF supporting Onboarding, as specified in clause 28.3.2.2.6.2 of TS 23.003 [19]; and:
    • If no DNS response is received, the UE shall stop the N3IWF selection.
    • If the DNS response contains one or more records, the UE selects an SNPN that supports Untrusted non-3GPP access for UE Onboarding via N3IWF. Each record in the DNS response shall contain the identity of an SNPN in the visited country supporting Untrusted non-3GPP access for UE Onboarding via N3IWF. In this case:
      • The UE shall select an SNPN based on its own implementation means.

If the UE cannot select any N3IWF included in the DNS response, then the UE shall stop the N3IWF selection.

    • If the DNS response contains no records, then the UE determines that the visited country does not mandate the selection of an N3IWF that supports Untrusted non-3GPP access for UE Onboarding via N3IWF in this country. In this case the UE uses the configured N3IWF for onboarding.
    • If the UE has selected an SNPN for onboarding, the UE constructs the Operator Identifier based Onboarding FQDN for SNPN N3IWF as specified in clause 28.3.2.2.7.2 of TS 23.003 [19], based on the SNPN ID of the selected SNPN and performs a DNS query:
      • The DNS response contains the identifier of the N3IWF supporting the onboarding in the SNPN identified by the SNPN ID.
  • If the PVS is reachable from the local Untrusted non-3GPP access network (e.g. via the Internet) using the local IP connectivity, UE may connect directly (i.e. without being connected to an N3WIF) with a PVS to obtain the SNPN credentials.
  • As part of UE registration via Untrusted non-3GPP access, in Figure 4.12.2.2-1, step 5 of TS 23.502 [3], the UE provides an onboarding indication inside the AN-Parameters.