3GPP 24.501 v20.0.0 — the document's own text
4.6.1 General
The 5GS supports network slicing as described in 3GPP TS 23.501 [8]. Within a PLMN or SNPN, a network slice is identified by an S-NSSAI, which is comprised of a slice/service type (SST) and a slice differentiator (SD). Inclusion of an SD in an S-NSSAI is optional. A set of one or more S-NSSAIs is called the NSSAI. The following S-NSSAIs and NSSAIs are defined in 3GPP TS 23.501 [8]:
- configured NSSAI;
- requested NSSAI;
- allowed NSSAI;
- subscribed S-NSSAIs;
- pending NSSAI;
- alternative S-NSSAIs; and
- partially allowed NSSAI.
The following S-NSSAIs and NSSAIs are defined in the present document:
- rejected NSSAI for the current PLMN or SNPN;
- rejected NSSAI for the current registration area;
- rejected NSSAI for the failed or revoked NSSAA;
- rejected NSSAI for the maximum number of UEs reached;
- alternative NSSAI;
- partially rejected NSSAI;
- on-demand S-NSSAIs; and
- on-demand NSSAI.
In roaming scenarios and scenarios involving EHPLMNs, the S-NSSAI value(s) used by the serving PLMN for the above S-NSSAIs and NSSAIs can be different from the corresponding HPLMN S-NSSAIs. To enable the UE to operate in such a PLMN, the network provides the UE with mapped S-NSSAI(s) for the above S-NSSAIs and NSSAIs as follows:
- If the UE is:
- in a roaming scenario;
- in a non-roaming scenario;
- the PLMN code of the serving EHPLMN is not the PLMN code derived from the IMSI; and
- the value of any configured S-NSSAI of the serving EHPLMN is different from the value of corresponding mapped S-NSSAI; or
- in a non-subscribed SNPN,
then the network shall provide mapped S-NSSAI(s) for each S-NSSAI of the serving PLMN in the configured NSSAI, the allowed NSSAI, the partially allowed NSSAI, the partially rejected NSSAI, the alternative NSSAI, the pending NSSAI and the NSSRG information when included in the signalling to the UE. If the network provides an Extended rejected NSSAI IE, the rejected NSSAI for the current PLMN or SNPN, rejected NSSAI for the current registration area, or rejected NSSAI for the maximum number of UEs reached shall include one or more S-NSSAIs for the current PLMN and mapped S-NSSAI(s) for each S-NSSAI of the current PLMN. An S-NSSAI included in the rejected NSSAI for the failed or revoked NSSAA is an HPLMN S-NSSAI.
- In non-roaming scenarios,
- if the UE is in the HPLMN or in the EHPLMN whose PLMN code is the PLMN code derived from the IMSI, the network shall not provide any mapped S-NSSAIs; and
- if the UE is in an EHPLMN whose PLMN code is not the PLMN code derived from the IMSI, and the value of each configured S-NSSAI of the serving EHPLMN is the same as the value of corresponding mapped S-NSSAI, the network need not provide any mapped S-NSSAIs. If the network provides mapped S-NSSAIs, it shall do this as specified for case a) above.
In case of a PLMN, a serving PLMN may configure a UE with:
- the configured NSSAI per PLMN;
- NSSRG information if the UE has indicated that it supports the subscription-based restrictions to simultaneous registration of network slices feature;
- on-demand NSSAI if the UE has indicated it supports the network slice usage control feature;
- S-NSSAI time validity information if the UE has indicated that it supports S-NSSAI time validity information; and
- S-NSSAI location validity information if the UE has indicated that it supports S-NSSAI location validity information.
In addition, the HPLMN may configure a UE with a single default configured NSSAI and consider the default configured NSSAI as valid in a PLMN for which the UE has neither a configured NSSAI nor an allowed NSSAI. The support for NSSRG information by the UE and the network, respectively, is optional.
NOTE 0: In this version of the specification, the network slice usage control feature is not supported in roaming scenarios.
NOTE 1: The value(s) used in the default configured NSSAI are expected to be commonly decided by all roaming partners, e.g. values standardized by 3GPP or other bodies.
NOTE 1A: If an NSSAI (e.g. allowed NSSAI, rejected NSSAI for the current registration area) is applicable for the registered PLMN and its equivalent PLMN(s) in the registration area, the value(s) used in such NSSAI are expected to be commonly decided by these PLMNs, e.g. values standardized by 3GPP or other bodies.
In case of an SNPN, the SNPN may configure a UE which is neither registering nor registered for onboarding services in SNPN with:
- a configured NSSAI applicable to the SNPN;
- NSSRG information if the UE has indicated that it supports the subscription-based restrictions to simultaneous registration of network slices feature;
- S-NSSAI time validity information if the UE has indicated that it supports S-NSSAI time validity information;
- on-demand NSSAI if the UE has indicated it supports the network slice usage control feature; and
- S-NSSAI location validity information if the UE has indicated that it supports S-NSSAI location validity information.
In addition, the credential holder may configure a single default configured NSSAI associated with the selected entry of the "list of subscriber data" or the PLMN subscription and consider the default configured NSSAI as valid in a SNPN for which the UE has neither a configured NSSAI nor an allowed NSSAI. If the UE is registering or registered for onboarding services in SNPN, the serving SNPN shall not provide a configured NSSAI to the UE. The support for NSSRG information by the UE and the network, respectively, is optional.
The allowed NSSAI and the rejected NSSAI for the current registration area are managed per access type independently, i.e. 3GPP access or non-3GPP access, and is applicable for the registration area. If the UE does not have a valid registration area, the rejected NSSAI for the current registration area is applicable to the tracking area on which it was received. If the registration area contains TAIs belonging to different PLMNs, which are equivalent PLMNs, the allowed NSSAI, the rejected NSSAI for the current registration area, rejected NSSAI for the failed or revoked NSSAA and rejected NSSAI for the maximum number of UEs reached are applicable to these PLMNs in this registration area.
The allowed NSSAI that is associated with a registration area containing TAIs belonging to different PLMNs, which are equivalent PLMNs, can be used to form the requested NSSAI for any of the equivalent PLMNs when the UE is outside of the registration area where the allowed NSSAI was received.
When the network slice-specific authentication and authorization procedure is to be initiated for one or more S-NSSAIs in the requested NSSAI or the network slice-specific authentication and authorization procedure is ongoing for one or more S-NSSAIs, these S-NSSAI(s) will be included in the pending NSSAI. When the network slice-specific authentication and authorization procedure is completed for an NSSAI that has been in the pending NSSAI, the S-NSSAI will be moved to the allowed NSSAI or rejected NSSAI depending on the outcome of the procedure. The AMF sends the updated allowed NSSAI to the UE over the same access of the requested S-NSSAI. The AMF sends the updated partially allowed NSSAI to the UE only over the 3GPP access. The AMF sends the updated rejected NSSAI over either 3GPP access or non-3GPP access. The pending NSSAI is managed regardless of access type i.e. the pending NSSAI is applicable to both 3GPP access and non-3GPP access for the current PLMN even if sent over only one of the accesses. If the registration area contains TAIs belonging to different PLMNs, which are equivalent PLMNs, the pending NSSAI is applicable to these PLMNs in this registration area.
The rejected NSSAI for the current PLMN or SNPN is applicable for the whole registered PLMN or SNPN regardless of the access type. The AMF shall only send a rejected NSSAI for the current PLMN when the registration area consists of TAIs that only belong to the registered PLMN. If the UE receives a rejected NSSAI for the current PLMN, and the registration area also contains TAIs belonging to different PLMNs, the UE shall treat the received rejected NSSAI for the current PLMN as applicable to the whole registered PLMN.
The rejected NSSAI for the failed or revoked NSSAA includes one or more S-NSSAIs that have failed the network slice-specific authentication and authorization or for which the authorization have been revoked, and are applicable for the whole registered PLMN or SNPN regardless of the access type.
The rejected NSSAI for the maximum number of UEs reached is applicable for the whole registered PLMN or SNPN, and the access type over which the rejected NSSAI was sent. The AMF shall send a rejected NSSAI including S-NSSAI(s) with the rejection cause "S-NSSAI not available due to maximum number of UEs reached", when one or more S-NSSAIs are indicated that the maximum number of UEs has been reached. If the timer T3526 associated with the S-NSSAI(s) was started upon reception of the rejected NSSAI for the maximum number of UEs reached, the UE may remove the S-NSSAI(s) from the rejected NSSAI including S-NSSAI(s) with the rejection cause "S-NSSAI not available due to maximum number of UEs reached", if the timer T3526 associated with the S-NSSAI(s) expires. If one or more S-NSSAIs are removed from the rejected NSSAI for the maximum number of UEs reached, the timer T3526 associated with the removed S-NSSAI(s) shall be stopped, if running. The UE shall not stop the timer T3526 if the UE selects an E-UTRA cell connected to EPC.
If the UE receives a rejected NSSAI for the maximum number of UEs reached, the registration area contains TAIs belonging to different PLMNs, which are equivalent PLMNs, the UE shall treat the received rejected NSSAI for the maximum number of UEs reached as applicable to these equivalent PLMNs when the UE is in this registration area.
If the UE has indicated that the UE supports network slice replacement feature and the AMF determines to provide the mapping information between the S-NSSAI to be replaced and the alternative S-NSSAI to the UE, the network shall provide the UE with the alternative NSSAI. The alternative NSSAI is managed per access type independently, i.e. 3GPP access or non-3GPP access, and is applicable for the registration area.
If the UE has indicated that the UE supports the partial network slice feature and includes the S-NSSAI(s) in the requested NSSAI, the AMF determines the S-NSSAI(s) to be included in the partially allowed NSSAI or the partially rejected NSSAI as specified in clause 4.6.2.11. When the AMF provides both the partially allowed NSSAI and the partially rejected NSSAI to the UE, each S-NSSAI shall be either in the partially allowed NSSAI or in the partially rejected NSSAI but not both. The number of S-NSSAIs included in the partially allowed NSSAI or the partially rejected NSSAI shall not exceed 7. The sum of the number of S-NSSAI(s) stored in the partially allowed NSSAI and the allowed NSSAI shall not exceed 8. The partially allowed NSSAI is only applicable to 3GPP access and is applicable for the registration area. The partially rejected NSSAI is only applicable to 3GPP access and is applicable for the registration area.
NOTE 2: Based on local policies, the UE can remove an S-NSSAI from the rejected NSSAI for the failed or revoked NSSAA when the UE wants to register to the slice identified by this S-NSSAI.
NOTE 3: Based on network local policy, network slice-specific authentication and authorization procedure can be initiated by the AMF for an S-NSSAI in rejected NSSAI for the failed or revoked NSSAA when the S-NSSAI is requested by the UE based on its local policy.
NOTE 4: At least one S-NSSAI in the default configured NSSAI or at least one default S-NSSAI is recommended as not subject to network slice-specific authentication and authorization, in order to ensure that at least one PDU session can be established to access service, even when Network Slice-specific Authentication and Authorization fails.
NOTE 5: At least one S-NSSAI in the default configured NSSAI or at least one default S-NSSAI is recommended as not subject to network slice admission control, in order to ensure that at least one PDU session can be established to access service.
NOTE 6: The rejected NSSAI can be provided by the network via either Rejected NSSAI IE or the Extended rejected NSSAI IE.