Description
The Unified Data Management (UDM) function is a critical component of the 5G Core Network (5GC) based on the Service-Based Architecture (SBA). It serves as the centralized repository and management point for subscriber-related data. The UDM is responsible for storing and managing long-term subscription information, including user identities, security credentials, service profiles, and policy-related data. It interacts with other network functions through standardized service-based interfaces, primarily using HTTP/2 with JSON or CBOR encoding. The UDM's primary roles include authentication credential processing, user identification handling, access authorization, and subscription data management.
Architecturally, the UDM is a software-based network function that can be deployed in cloud environments. It often works in conjunction with the Unified Data Repository (UDR), which provides the actual persistent storage for the subscriber data. The UDM contains the application logic to process and manage this data, while the UDR acts as the database. Key internal components include the Authentication Credential Repository and Processing Function (ARPF), which stores long-term keys and runs authentication algorithms, and subscription data management logic. The UDM exposes its capabilities as services to other NFs, such as Nudm_UEAuthentication for authentication, Nudm_SubscriberDataManagement for subscription data, and Nudm_EventExposure for monitoring subscriber events.
How it works: When a user equipment (UE) attempts to register with the 5G network, the Access and Mobility Management Function (AMF) contacts the UDM. The UDM's ARPF generates authentication vectors (using the 5G Authentication and Key Agreement (5G-AKA) or EAP-AKA' procedures) and provides them to the AMF via the AUSF. For session establishment, the Session Management Function (SMF) retrieves the user's subscription data and policy profile from the UDM to determine allowed services, QoS parameters, and charging rules. The UDM also manages the binding between the user's permanent subscription identifier (SUPI) and the temporary identifier (SUCI) used for privacy, and it tracks the serving AMF for each subscriber to route signaling messages correctly.
Its role is central to network security, service personalization, and mobility management. By centralizing subscriber data, the UDM enables consistent policy enforcement across the network, supports seamless mobility and session continuity, and provides a single point of truth for user profiles. This is essential for advanced 5G features like network slicing, where the UDM provides the slice selection subscription information. Furthermore, its service-based design allows for flexible integration, scalability, and support for new services, forming the foundation for subscriber management in the 5G era.
Purpose & Motivation
The UDM was created to address the limitations of legacy subscriber data management in pre-5G networks, which was fragmented across different network elements. In 4G EPC, functions like the Home Subscriber Server (HSS) managed user profiles and authentication, but the architecture was node-based and less flexible. The proliferation of diverse 5G services, IoT, and network slicing demanded a more agile, scalable, and unified approach to data management.
The primary problem the UDM solves is the centralization and standardization of subscriber data handling. It consolidates functions previously spread across the HSS, Home Location Register (HLR), and other entities into a single, cloud-native network function. This unification simplifies operations, reduces data duplication, and provides a consistent view of the subscriber to all other core network functions. Its creation was motivated by the shift to the Service-Based Architecture (SBA), which requires network functions to expose capabilities as reusable services.
Historically, the UDM evolved from the HSS/HLR concepts but with a fundamental architectural redesign. It enables dynamic subscription management, real-time policy updates, and efficient support for massive numbers of IoT devices. By separating the application logic (UDM) from storage (UDR), it allows independent scaling and leverages modern cloud and software-defined networking principles. This addresses the need for a more programmable, automated, and service-aware core network capable of supporting the wide array of use cases envisioned for 5G and beyond.
Classification
Detected Changes Across Releases
from 3GPP Change RequestsSpecific changes extracted from the „Change history“ tables of 3GPP specifications (110 CRs across 6 releases). Complements the general historical overview above with the evidence-based evolution of this function.
- UDM receives notification of target/new AMF after AMF planned removal TS 29.503CR0001
- UDM discovery clarifications TS 23.501CR0041
- UDM Discovery with SUPI as input TS 23.501CR0091
- UDM services - addition to Nudm_UEAuthentication TS 23.501CR0224
- UDM functionality support for SUCI TS 23.501CR0225
- Update and correction of table for AMF, UDM, UDR, NSSF, UDSF and BSF services TS 23.501CR0363
+ 16 more changes
- Adding UDM update the STN-SR to AMF TS 23.237CR0507
- eSBA communication schemas related to UDM and UDR discovery and selection TS 23.501CR0800
- Report 5G SRVCC Capability to UDM TS 29.503CR0215
- Subscribed NSSAI from the UDM TS 29.503CR0247
- UDM Authn. Vector Generation for HSS TS 29.503CR0389
- UDM Discovery by Internal Group ID TS 23.501CR1737
+ 12 more changes
- Discover NWDAF for UE related Analytics using UDM TS 23.501CR2702
- AUSF/UDM discovery based SUCI information TS 23.501CR3170
- IP Index in UDM TS 29.503CR0610
- NWDAF register into UDM TS 29.503CR0649
- Persistent Data Collection via UDM TS 29.503CR0705
- Provisioning Session Authorization Information in UDM TS 29.503CR0733
+ 23 more changes
- Compatibility of UDM not supporting SMS SBI TS 23.540CR0013
- Improvement to UDM-triggered PDU Session deregistration procedure TS 29.503CR0959
- UDM initiated SMF Deregistration and Implicit Unsubsribe for SMF Events TS 29.503CR1190
- Procedures update for checking mechanism of clock quality information received from UDM and AF TS 29.513CR0536
- Addition of UDM Start of Intercept and De-Reg Records Stage 2 TS 33.127CR0185
- HSS-UDM Interworking LI Stage 2 TS 33.127CR0191
+ 16 more changes
- Support for Multiple SUPI to GPSI Conversion in UDM TS 29.503CR1305
- Provision of 5G Femto Information to UDM TS 29.503CR1322
- Support for AF Specific Identifier Selection in Multiple Identifiers Translation in UDM TS 29.503CR1341
- MPS for Messaging Indicator in UDM TS 29.503CR1361
- EIF Interaction with UDM TS 29.503CR1445
- UDM AnyUe selection for Nudm_EE exposure service TS 29.503CR1498
+ 9 more changes
Explore further
Broader topics and technologies where UDM plays a role.
Defining Specifications
3GPP specifications that define or reference UDM, with the latest known release. Sourced from the 3GPP document catalog — see methodology.
| Specification | Title | Release |
|---|---|---|
| TS 23.237 vj00 | IMS Service Continuity (ISC) Stage 2 | Rel-19 |
| TS 23.292 vj00 | IMS Centralized Services (ICS) Architecture | Rel-19 |
| TS 23.380 vk00 | IMS Restoration Procedures | Rel-20 |
| TS 23.501 vk20 | 5G System Architecture Stage 2 | Rel-20 |
| TS 23.540 vj20 | 5G Service Based SMS Stage 2 | Rel-19 |
| TS 23.700 vk10 | AI/ML Application Layer Support Phase 2 | Rel-20 |
| TR 23.732 vg00 | User Data Interworking, Coexistence, Migration Study | Rel-16 |
| TR 23.758 vh00 | Study on Edge Application Architecture | Rel-17 |
| TR 23.973 vj00 | Separate HSS/UDM Deployment Scenarios & Solutions | Rel-19 |
| TS 24.229 vk00 | IMS Call Control Protocol based on SIP | Rel-20 |
| TS 24.501 vk00 | 5G System (5GS) Non-Access Stratum (NAS) Protocol | Rel-20 |
| TR 26.919 vj00 | Study on 5G Conversational Media Handling | Rel-19 |
| TS 26.942 vk00 | Sustainable Media Metrics and Architectural Impacts for 5G | Rel-20 |
| TS 28.540 vk30 | 5G Network Resource Model Stage 1 Requirements | Rel-20 |
| TS 28.561 vk10 | Network Digital Twin Management | Rel-20 |
| TS 28.802 vf00 | Management Study for 5G Network Architecture | Rel-15 |
| TR 28.833 vi01 | Technical Report on 5G LAN-type Service Management | Rel-18 |
| TR 28.837 vi00 | Technical Report on Trace/MDT Management | Rel-18 |
| TR 28.840 vi10 | Technical Report | Rel-18 |
| TS 29.165 vj30 | Inter-IMS Network to Network Interface (II-NNI) | Rel-19 |
| TS 29.337 vj00 | Diameter T4 Interface for MTC Device Triggering | Rel-19 |
| TS 29.503 vk00 | UDM Service Based Interface Stage 3 | Rel-20 |
| TS 29.504 vk00 | 5G Unified Data Repository (UDR) Service Based Interface | Rel-20 |
| TS 29.505 vk00 | UDR Services for Subscription Data | Rel-20 |
| TS 29.507 vk00 | Access and Mobility Policy Control Service Stage 3 | Rel-20 |
| TS 29.508 vk00 | Session Management Event Exposure Service | Rel-20 |
| TS 29.512 vk00 | Session Management Policy Control Service | Rel-20 |
| TS 29.513 vk00 | Policy and Charging Control in 5G System | Rel-20 |
| TS 29.518 vk00 | 3GPP TS 29518 vk00: Namf Service Based Interface | Rel-20 |
| TS 29.520 vk00 | 5G Network Data Analytics Function Services | Rel-20 |
| TS 29.523 vk00 | Policy Control Event Exposure Service | Rel-20 |
| TS 29.524 vk00 | 5GC to NAS Cause Mapping Specification | Rel-20 |
| TS 29.525 vk00 | UE Policy Control Service Stage 3 | Rel-20 |
| TS 29.544 vk00 | Nspaf Service Based Interface for 5G System | Rel-20 |
| TS 29.550 vk00 | Nsoraf Service Based Interface for SOR-AF | Rel-20 |
| TS 29.552 vk00 | Network Data Analytics Procedures and Data Collection | Rel-20 |
| TS 29.563 vk00 | Nhss Services for 5G SBA Stage 3 | Rel-20 |
| TS 29.574 vk00 | Ndccf Service Based Interface (DCCF) | Rel-20 |
| TS 29.575 vk00 | 5G System; ADRF Service Based Interface; Stage 3 | Rel-20 |
| TS 29.576 vk00 | 3GPP Specification for MFAF Service Based Interface | Rel-20 |
| TR 29.829 vh10 | SMS Service-Based Interfaces for 5G Core | Rel-17 |
| TS 29.866 vj00 | IMS Disaster Prevention & Restoration Enhancement | Rel-19 |
| TS 29.890 vg00 | CT3 5G System Technical Report | Rel-16 |
| TS 32.255 vk20 | 5G Data Connectivity Charging | Rel-20 |
| TS 32.256 vk00 | 5G Connection and Mobility Charging | Rel-20 |
| TS 32.899 vf10 | 5G Charging Architecture Study | Rel-15 |
| TS 33.127 vj70 | Lawful Interception Architecture and Functions | Rel-19 |
| TS 33.501 vk20 | 5G Security Architecture and Procedures | Rel-20 |
| TS 33.514 vk10 | 3GPP TS 33514 vk10: UDM Network Product Security Requirements | Rel-20 |
| TS 33.515 vk00 | 5G SMF Security Assurance Specification | Rel-20 |
| TS 33.529 vj10 | SCAS for SMSF Security Assurance | Rel-19 |
| TS 33.535 vj00 | 5G AKMA: Authentication and Key Management for Apps | Rel-19 |
| TS 33.545 vk00 | Security Architecture for NR Femto Subsystem | Rel-20 |
| TS 33.701 vj00 | Study on mitigations against bidding down attacks | Rel-19 |
| TR 33.739 vi10 | Study on security enhancement of support for | Rel-18 |
| TS 33.749 vj00 | Study on security aspects of edge computing enhancement | Rel-19 |
| TS 33.835 vg10 | Study on authentication and key management for apps | Rel-16 |
| TS 33.836 vg10 | Security Study for Advanced V2X Services | Rel-16 |
| TR 33.847 vh10 | 5G Proximity Services Security Study | Rel-17 |
| TS 35.234 vj00 | MILENAGE-256 Algorithm Set Specification | Rel-19 |
| TS 38.300 vj30 | NR and NG-RAN Overall Description | Rel-19 |