3GPP 23.501 v20.2.0 — the document's own text
6.2.23 NSSAAF
Taught in 4. What each network function does (The 5G system architecture, in depth), 2. Who does what in the core (The 5G system architecture, overview).
The Network Slice-specific and SNPN Authentication and Authorization Function (NSSAAF) supports the following functionality:
- Support for Network Slice-Specific Authentication and Authorization as specified in TS 23.502 [3] with a AAA Server (AAA-S). If the AAA-S belongs to a third party, the NSSAAF may contact the AAA-S via a AAA proxy (AAA-P).
- Support for access to SNPN using credentials from Credentials Holder using AAA server (AAA-S) as specified in clause 5.30.2.9.2 or using credentials from Default Credentials Server using AAA server (AAA-S) as specified in clause 5.30.2.10.2. If the Credentials Holder or Default Credentials Server belongs to a third party, the NSSAAF may contact the AAA server via a AAA proxy (AAA-P).
NOTE: When the NSSAAF is deployed in a PLMN, the NSSAAF supports Network Slice-Specific Authentication and Authorization, while when the NSSAAF is deployed in a SNPN the NSSAAF can support Network Slice-Specific Authentication and Authorization and/or the NSSAAF can support access to SNPN using credentials from Credentials Holder.