Description
Network Slice-Specific Authentication and Authorization (NSSAA) is a critical security mechanism introduced in 3GPP Release 16 to complement the primary authentication and authorization performed by the Authentication Server Function (AUSF). While primary authentication verifies the UE's identity for the 5G Core Network (5GC) as a whole, NSSAA provides an additional, granular layer of security for individual network slices. This is essential because different slices may have vastly different security requirements, business models, and trust domains. For instance, a slice for massive IoT sensors may have different security postures compared to a slice for ultra-reliable low-latency communication (URLLC) in industrial automation. NSSAA ensures that access to a high-security slice is not granted based solely on credentials valid for a lower-security slice.
The NSSAA procedure is typically triggered after successful primary authentication when a UE requests a network slice that requires slice-specific authentication, as indicated by the Subscribed Network Slice Selection Assistance Information (S-NSSAI). The procedure is orchestrated by the Network Slice-Specific Authentication and Authorization Function (NSSAAF), which acts as an intermediary. The NSSAAF receives an authentication request from the Access and Mobility Management Function (AMF) and communicates with external, slice-specific Authentication, Authorization, and Accounting (AAA) servers. These external AAA servers are considered part of the slice tenant's domain and are responsible for evaluating the UE's credentials against policies specific to that slice. The communication between the NSSAAF and the external AAA server can use protocols like the Extensible Authentication Protocol (EAP), allowing for a wide range of authentication methods (EAP-AKA', EAP-TLS, etc.) as defined by the slice provider.
The architecture involves several 5GC network functions. The AMF is the main point of contact, initiating the procedure upon slice request. The NSSAAF, a dedicated logical function, can be deployed as a standalone Network Function (NF) or co-located with another NF like the AUSF. It interfaces with the external AAA server via the N33 reference point. The Unified Data Management (UDM) may store indications of which S-NSSAIs require NSSAA for a given subscriber. The procedure's result (success, failure, or on-going) is conveyed back to the AMF, which then allows or denies the UE's registration for the requested slice. A key aspect is that NSSAA can run in parallel for multiple slices, and its failure for one slice does not necessarily impact the UE's registration for other, already authorized slices. This provides flexibility and maintains service continuity where possible.
Purpose & Motivation
NSSAA was created to address the security and business model challenges inherent in network slicing. Prior to its introduction in Release 16, network slice access control was primarily based on subscription data stored in the UDM, which could indicate whether a subscriber was allowed to use a slice. However, this was a simple binary check and did not support dynamic, real-time authentication and authorization decisions that might involve external credentials or tenant-specific policies. This limitation was a significant barrier for enterprises and vertical industries wishing to operate their own slices with their own identity management systems.
The primary problem NSSAA solves is the need for enhanced security isolation between slices. In a shared physical infrastructure, it is paramount to ensure that a compromise or weak authentication in one slice does not become a vector to access a more sensitive slice. By delegating the final authorization decision to an external AAA server controlled by the slice tenant, NSSAA enables strong, domain-specific authentication. This is crucial for business models where a Mobile Network Operator (MNO) provides network-as-a-service to third-party enterprises. The enterprise can retain control over which of its devices or users are allowed onto its dedicated slice, using its existing corporate credentials and security policies, without the MNO needing to manage those identities directly. This separation of concerns facilitates the commercialization of network slicing.
Classification
Detected Changes Across Releases
from 3GPP Change RequestsSpecific changes extracted from the „Change history“ tables of 3GPP specifications (34 CRs across 4 releases). Complements the general historical overview above with the evidence-based evolution of this function.
- AMF capability of Network Slice-Specific Authentication and Authorization TS 23.501CR1588
- Alignments to support Network Slice-Specific Authentication and Authorization TS 23.501CR1723
- On NSSAA Services TS 23.501CR1979
- Correction on pending NSSAA indication to UE TS 23.501CR2005
- Re-allowing UE for services after the NSSAA revocation TS 23.501CR2011
- Clarification on pending NSSAI in Network Slice-Specific Authentication and Authorization TS 23.501CR2040
+ 10 more changes
- Remote provisioning of credentials for NSSAA or secondary authentication/authorisation TS 23.501CR2714
- Allowed NSSAI when NSSAA fails TS 23.501CR2923
- Redirection to dedicated frequency band(s) at the end of NSSAA TS 23.501CR3067
- Correction on remote provisioning of credentials for NSSAA or secondary authentication/authorization TS 23.501CR3146
- Correction on remote provisioning of credentials for NSSAA or secondary authentication/authorization TS 23.501CR3277
- Correction of NSSF involvement in Registration procedure when NSSAA is used TS 23.501CR3654
+ 3 more changes
- Clarifications about the Alternative S-NSSAI subject to NSSAA TS 23.501CR5170
- Rel-18 CR 28.204 Correction on trigger for NSSAA message content TS 28.204CR0002
- NSSAA in network slice replacement TS 29.526CR0084
- Missing Description fields in Network slice specific authentication and authorization (Nnssaaf_NSSAA API) TS 29.526CR0086
Explore further
Broader topics and technologies where NSSAA plays a role.
Defining Specifications
3GPP specifications that define or reference NSSAA, with the latest known release. Sourced from the 3GPP document catalog — see methodology.
| Specification | Title | Release |
|---|---|---|
| TS 23.501 vk20 | 5G System Architecture Stage 2 | Rel-20 |
| TS 24.501 vk00 | 5G System (5GS) Non-Access Stratum (NAS) Protocol | Rel-20 |
| TS 28.204 vi11 | Charging management | Rel-18 |
| TS 29.518 vk00 | 3GPP TS 29518 vk00: Namf Service Based Interface | Rel-20 |
| TS 29.526 vk00 | NSSAAF Service Based Interface Stage 3 | Rel-20 |
| TS 29.571 vk00 | Common Data Types for 5G SBI APIs | Rel-20 |
| TS 31.105 vj20 | Slice Subscriber Identity Module (SSIM) Application | Rel-19 |
| TR 31.826 vi00 | Technical Report | Rel-18 |
| TS 32.291 vk00 | 3GPP TS 32.291 vk00: Service Based Interface for Charging | Rel-20 |
| TR 32.847 vi00 | Technical Report | Rel-18 |
| TS 33.501 vk20 | 5G Security Architecture and Procedures | Rel-20 |
| TS 33.700 | 3GPP TR 33.700 | Rel-16 |