5G/NR - Network Architecture

 

 

 

NR Network Architecture / Network Interface - N1 / N1-Mode

N1 interface(Reference Point) indicates the connection between UE and AMF mainly for NAS layer signaling, but the exact role of N1 interface (reference point) is a little bit ambiguous to me.

That ambiguity is worth taking seriously, because it is not a gap in the reader. It is a real oddity in how the architecture is drawn.

Look at the other reference points in the same figure. N2 runs between the gNB and the AMF. N3 runs between the gNB and the UPF. N4 runs between the SMF and the UPF. Each of those is a link between two boxes, with a protocol stack you can name and, in principle, something you could unplug. N1 is drawn in exactly the same notation, with the same kind of oval and the same kind of line. But it is not the same kind of thing at all.

N1 has no protocol of its own, no transport, and nothing physical to point at. It is a relationship between the NAS layer in the UE and the NAS layer in the AMF. It is carried over whatever happens to lie underneath it at the time. That is why the line in the figure appears to skip the access network entirely. The figure is drawing who is talking to whom, not how the message gets there. There is a section further down that takes that apart properly.

There is a second thing hiding behind the same name, and the title of this page separates them for a reason. N1 the reference point is an architecture item. N1 mode is a property of the UE. It is about which core network the UE is attached to, rather than which radio it happens to be using. The two are related, but they are not interchangeable. Mixing them up is the other common source of confusion here.

So this note works through both. First, what N1 is actually made of, which turns out to be far less mysterious once you have seen the protocol stack. Then N1 mode, including the conditions under which a UE switches it off. That last part is genuinely useful when a device refuses to come up on 5G standalone and you need to work out why.

What is N1 Interface ?

According to 23.501-Figure 4.2.4-4, N1 reference point (labeled as '1') is indicated as follows. It seems obvious that N1 is the interface between UE and AMF, but there is no access network along N1. So I was wondering how UE can get access to AMF without access network.

With further looking at other parts of the document (like figures in section 23.501-4.2.8.2 and description at 23.501-5.3.3.1), it seems that N1 interface represent the interface as follows. At least for now, my understanding is as follows.

  • N1 is the interface between UE and AMF
  • N1 represents the combined path  UE <--> Access Network and Access Network <--> AMF
  • The Access Network can be a 3GPP based (e.g, gNB) or non 3GPP based.
  • Most of NAS signaling is going through N1 

There is another statement from 24.501-3.1 writing the definition of N1 NAS signalling connection as follows.

    N1 NAS signalling connection: A peer to peer N1 mode connection between UE and AMF. An N1 NAS signalling connection iseither the concatenation of an RRC connection via the Uu reference point and an NG connection via the N2 reference point for 3GPP access, orthe concatenation of an IPsec tunnel via the NWu reference point and an NG connection via the N2 reference point for non-3GPP access.

     

So what is N1 actually made of ?

The section above ends with a good question. N1 is drawn straight from the UE to the AMF, with no access network on the line. So how does the UE reach the AMF at all ?

The answer is that N1 is not a link. It is not a protocol either, and there is nothing you can put a probe on. N1 is a peer relationship between two protocol layers that happen to sit at opposite ends of the network. The reason the figure draws it as a straight line is that the figure is drawing the relationship, not the path.

N1 is the peer relationship between the NAS in the UE and the NAS in the AMF N1 has no protocol of its own. It is a peering, drawn over the top UE AMF NAS NAS N1 gNB RRC RRC NG-AP NG-AP PDCP / RLC MAC / PHY PDCP / RLC MAC / PHY SCTP / IP L2 / L1 SCTP / IP L2 / L1 Uu N2 The gNB has no NAS layer at all. It carries the NAS message without reading it. So N1 is not a protocol and not a link. It is the peering between the NAS in the UE and the NAS in the AMF. For non-3GPP access, swap Uu for NWu and the gNB for an N3IWF, and put IPsec and IKEv2 where RRC was. Everything at and above the dashed line is unchanged. That is why one N1 serves both accesses.

Follow a registration request through that picture. The UE builds a NAS message. NAS hands it to RRC, which carries it as a container inside an RRC message over Uu. The gNB receives the RRC message, takes the NAS container out, and puts it into an NG-AP message without looking inside it. NG-AP carries it over SCTP to the AMF, which finally opens it. The NAS layer in the AMF is the first thing since the UE that has any idea what the message says.

That is the whole trick. The gNB has no NAS layer, so it cannot read the message even if it wanted to. It is a courier. And because it is only a courier, the UE and the AMF behave as if they were talking directly. That is exactly what the figure shows.

This also explains the definition quoted above from 24.501. It describes an N1 NAS signalling connection as a concatenation of an RRC connection over Uu and an NG connection over N2. Concatenation is the right word. N1 is the two halves considered as one thing.

NOTE : This is also why you will never see N1 on a protocol analyser as its own interface. You see RRC on Uu, you see NG-AP on N2, and the NAS message appears twice, once inside each.

Two accesses, two N1 connections

The second illustration on this page shows N1 drawn twice, once through the access network and once through a non-3GPP cloud. That is not a drawing of two alternatives. It is a drawing of something that can happen at the same time.

A UE can be registered over 3GPP access and over non-3GPP access simultaneously, to the same AMF. When it is, there are two N1 NAS signalling connections in existence at once. The lower halves are completely different. One is RRC over Uu through a gNB. The other is IPsec over NWu through an N3IWF. The upper half, the NAS peering with the AMF, is the same in both.

The AMF keeps one UE context, but parts of it are per access. Registration state is tracked per access. So is the connection management state. This is why the enable and disable table further down has separate rows for 3GPP and non-3GPP. N1 mode can be disabled on one access while it stays enabled on the other.

It is worth holding on to that asymmetry. A UE is not simply registered or not registered. It is registered over a particular access, and it may be in a different state on each.

What actually travels on N1

Everything on N1 is NAS, and NAS comes in two families. Knowing which is which removes most of the confusion about what the UE talks to.

Family

What it deals with

Examples

5GMM
5GS Mobility Management

Registration, identity, security, reachability and the connection itself. The AMF handles all of it.

Registration Request and Accept, Service Request, Authentication Request, Security Mode Command, Configuration Update Command, Deregistration

5GSM
5GS Session Management

PDU sessions. The AMF does not handle these. It passes them to the SMF.

PDU Session Establishment Request and Accept, PDU Session Modification, PDU Session Release

NAS transport

The envelope that carries a 5GSM message, or an SMS, inside a 5GMM message.

UL NAS TRANSPORT, DL NAS TRANSPORT

 

The third row is the one that matters, and it corrects a common mental picture. A 5GSM message never travels on its own. It is always wrapped inside a 5GMM transport message, because the AMF is the only NAS peer the UE has.

So when a UE asks for a PDU session, the request goes to the AMF like everything else. The AMF sees a transport message, takes the session management payload out without interpreting it, and forwards it to the SMF over N11. The answer comes back the same way.

That is why the UE has no reference point to the SMF anywhere in the architecture figures. It never talks to one. It talks to the AMF about the SMF, and the AMF relays.

What is N1 mode ?

In addition to N1 reference point/interface with the focus on physical connections in the overal network architecture, there is another term called N1 mode which is more focused on functional point of view (especially with the perspective of NAS signaling).

The formal definition of N1 mode is defined in 24.501-3.1 as follows

    N1 mode: A mode of a UE allowing access to the 5G core network via the 5G access network.

 

N1 mode refers to the 5G standalone architecture where the 5G core network connects directly to the 5G radio access network, without involvement of the 4G EPC core. N1 mode is the standalone deployment where the 5G radio connects directly to the 5G core network over the N1 interface to leverage the complete 5G system capabilities

  • The interface between the 5G RAN and the 5G core is N2 for the control plane and N3 for the user plane, known together as NG. That is what replaces S1. N1 is not a RAN to core interface at all. It is the UE to AMF peering described above.
  • In N1 mode the UE has a NAS connection to the AMF, and only to the AMF. Session management reaches the SMF through the AMF, and the UPF is user plane only. No anchoring via 4G is needed.
  • NG runs between the RAN and the core, and Xn runs between one RAN node and another. There is no dependence on 4G interfaces.
  • N1 mode allows the network to leverage core 5G features like network slicing, QoS flow management, advanced RAN capabilities etc.
  • 5G devices primarily support N1 mode for optimal performance, but they also support Non-standalone mode (with LTE anchor) for compatibility.
  • N1 mode simplifies the network architecture compared to NSA mode. But it requires deploying a full 5G core network first.

N1 mode and S1 mode : which core, not which radio

N1 mode is easiest to pin down by looking at the term it was defined against. 24.501 defines N1 mode as a mode allowing access to the 5G core network. 24.301 defines S1 mode as a mode allowing access to the Evolved Packet Core. Put the two definitions side by side and the rule becomes obvious.

The mode is decided by which core the UE is talking to, not by which radio it is using. That single sentence resolves most of the confusion, because it does not line up with the way people usually talk about SA and NSA.

Deployment

Radio

Core

The UE is in

Option 1, LTE on its own

E-UTRAN

EPC

S1 mode

Option 3 family, EN-DC. This is what is usually called NSA

LTE master, NR secondary

EPC

S1 mode, even though NR is in use

Option 2, NR standalone

NR

5GC

N1 mode

Option 5, LTE connected to 5GC

ng-eNB, so LTE radio

5GC

N1 mode, even though the radio is LTE

Option 7 family, NGEN-DC

LTE master, NR secondary

5GC

N1 mode

Option 4 family, NE-DC

NR master, LTE secondary

5GC

N1 mode

 

Two rows in that table are worth staring at, because they are the ones that break the shorthand.

  • Option 3 uses NR and is still S1 mode : the UE has NR carriers and NR throughput. But its NAS goes to an MME over S1. There is no AMF in the picture, so there is no N1.
  • Option 5 uses LTE and is N1 mode : the radio is an ng-eNB, which is an LTE radio. But it is part of NG-RAN, and it connects to a 5GC. The UE runs 5GS NAS to an AMF, so it is in N1 mode.

So the description above, that N1 mode refers to the standalone architecture, is right for the case you meet most often. It is worth knowing that options 4 and 7 are dual connectivity and are also N1 mode, because the core is a 5GC.

There is one more practical consequence. A UE that supports both modes has to advertise them separately. It does so in two different places. The next section shows the 5GS registration request, and also an LTE attach request where the UE declares N1 mode support to an EPC network. That second one is how an operator running 4G learns that a device could be moved onto 5G standalone.

UE Usage state and N1 disable/enable

When N1 mode enabled or disabled on UE side. There are specific conditions that enable / disable the mode and those conditions are specified in 24.501

Following table is based on 24.501 - 4.3.3.1, 4.3.4.1 and 4.9. I changed the format for better / quictly to be used as a cheat sheet -:)

UE Usage Setting

Network Capability

Registration Status

N1 mode status

Power Cycle (Off --> On)     Re-enable the N1 mode
USIM Removal     Re-enable t the N1 mode
Disable ->Timer Expiration(*1)     Re-enable t the N1 mode

From "data centric" to "voice centric"

"IMS voice not available" over 3GPP access only

the UE is only registered over 3GPP access

Disable the N1 mode capability for 3GPP access

From "data centric" to "voice centric"

"IMS voice not available" over both 3GPP access and non-3GPP access

the UE is registered over both 3GPP access and non-3GPP access

Disable t the N1 mode capability for 3GPP access  and non-3GPP access

From "data centric" to "voice centric"

"IMS voice not available" over both 3GPP access and non-3GPP access

the UE is registered over 3GPP access only

Disable tthe N1 mode capability for 3GPP access

From "data centric" to "voice centric"

"IMS voice not available" over both 3GPP access and non-3GPP access

the UE is registered over non-3GPP access only.

Disable t the N1 mode capability for non-3GPP access

From "voice centric" to "data centric"

N1 mode capability for 3GPP access is disabled at the UE (due to IMS voice unavailability)

  Re-enable t the N1 mode capability for 3GPP access

From "data centric" to "voice centric"

"IMS voice not available" over non-3GPP access only

the UE is only registered over non-3GPP access

Disable tthe N1 mode capability for non-3GPP access

From "voice centric" to "data centric"

N1 mode capability for non 3GPP access is disabled at the UE (due to IMS voice unavailability)

  Re-enable t the N1 mode capability for non-3GPP access

"voice centric"

"IMS voice not available" over 3GPP access only

the UE is only registered over 3GPP access

Disable t the N1 mode capability for 3GPP access

"voice centric"

"IMS voice not available" over non-3GPP access only

 

Disable t the N1 mode capability for non-3GPP access

"voice centric"

"IMS voice not available" over both 3GPP access and non-3GPP access

UE is registered over both 3GPP access and non-3GPP access.

Disable tthe N1 mode capability for 3GPP access and non-3GPP access

"voice centric"

"IMS voice not available" over both 3GPP access and non-3GPP access

UE is registered over 3GPP access only

Disable tthe N1 mode capability for 3GPP access

"voice centric"

"IMS voice not available" over both 3GPP access and non-3GPP access

UE is registered over non-3GPP access only.

Disable t the N1 mode capability for non-3GPP access

 

Let's summarize the table in a little bit different format.

  • When UE usage setting changes from data centric to voice centric:
    • If IMS voice unavailable on 3GPP, N1disabled for 3GPP.
    • If IMS voice unavailable on non-3GPP, N1disabledfor non-3GPP.
    • If IMS voice unavailable on both, N1disabledon all registered accesses.
  • When usage setting changes from voice centric to data centric:
    • N1Re-enabled for 3GPP if previously disabled.
    • N1Re-enabled for non-3GPP if previously disabled.
  • For voice centric UE:
    • If IMS voice unavailable on 3GPP, N1disabled for 3GPP.
    • If IMS voice unavailable on non-3GPP, N1disabledfor non-3GPP.
    • If IMS voice unavailable on both, N1disabledon all registered accesses.

Summarize it again in a little bit different perspective.

  • N1 mode disabled:
    • When UE usage setting changes from data centric to voice centric, if IMS voice unavailable on registered access(es).
    • For voice centric UE, if IMS voice unavailable on registered access(es).
  • N1 mode re-enabled:
    • After power cycle, USIM removal, or timer expiration.
    • When UE usage setting changes from voice centric to data centric, for any access that was previously disabled.
  • In summary:
    • N1 mode is disabled on an access when a voice centric UE cannot get IMS voice service on that access.
    • N1 mode is re-enabled when voice restrictions are removed, or when UE transitions to data centric usage.
    • Re-enabling also happens after power cycle, USIM change or timer expiration.

NOTE : More detailed description on N1 mode enable/disable condition is described in 24.501-4.9.

3GPP Statements on N1 interface/refernce point

For futher clarification and for those who would not agree with my interpretation -:), I quoted various descriptions directly from 3GPP document here.

Regarding the role N1 reference points, it is described as follows in 3GPP.

23.501 - 4.2.8.1 General Concepts to Support Non-3GPP Access

  •   A UE that accesses the 5G Core Network over a standalone non-3GPP access shall, after UE attachment, support NAS signalling with 5G Core Network control-plane functions using the N1 reference point.
  •   When a UE is connected via a NG-RAN and via a standalone non-3GPP access, multiple N1 instances shall exist for the UE i.e. there shall be one N1 instance over NG-RAN and one N1 instance over non-3GPP access.
  • N1 NAS signalling over standalone non-3GPP accesses shall be protected with the same security mechanism applied for N1 over a 3GPP access.

23.501 - 4.4.2.2 Reference point to support SMS over NAS

  •   N1: Reference point for SMS transfer between UE and AMF via NAS.

23.501 - 4.4.4.2 Reference point to support Location Services

  • N1: Reference point between UE and AMF via NAS.

23.501 - 5.2.5 Access control and barring

  • If the UE supports both N1 and S1 modes NAS and, as defined in TS 23.401, the UE is configured for Extended Access Barring (EAB) but is not configured with a permission for overriding Extended Access Barring (EAB), when the UE wants to access the 5GS it shall perform Unified Access Control checks for Access Category 1 on receiving an indication from the upper layers as defined in TS 24.501, TS 38.331, TS 36.331.
  • If the UE supports both N1 and S1 modes NAS and, as defined in TS 23.401, the UE is configured with a permission for overriding Extended Access Barring (EAB), when the UE wants to access the 5GS it shall ignore Unified Access Control checks for Access Category 1 on receiving an indication from the upper layers, as defined in TS 24.501

23.501 - 5.3.3.1 General

  • Connection management comprises the functions of establishing and releasing a NAS signalling connection between a UE and the AMF over N1. This NAS signalling connection is used to enable NAS signalling exchange between the UE and the core network. It comprises both the AN signalling connection between the UE and the AN (RRC Connection over 3GPP access or UE-N3IWF connection over N3GPP access) and the N2 connection for this UE between the AN and the AMF.

23.501 - 5.3.3.2.3 CM-CONNECTED state

  • A UE in CM-CONNECTED state has a NAS signalling connection with the AMF over N1. A NAS signalling connection uses an RRC Connection between the UE and the NG-RAN and an NGAP UE association between the AN and the AMF for 3GPP access.

23.501 - 5.6 Session Management

  • PDU Sessions are established (upon UE request), modified (upon UE and 5GC request) and released (upon UE and 5GC request) using NAS SM signalling exchanged over N1 between the UE and the SMF.

23.501 - 5.6.2 Interaction between AMF and SMF

  • The single N1 termination point is located in AMF. The AMF forwards SM related NAS information to the SMF based on the PDU Session ID in the NAS message. Further SM NAS exchanges (e.g. SM NAS message responses) for N1 NAS signalling received by the AMF over an access (e.g. 3GPP access or non-3GPP access) are transported over the same access.
  • The serving PLMN ensures that subsequent SM NAS exchanges (e.g. SM NAS message responses) for N1 NASsignalling received by the AMF over an access (e.g. 3GPP access or non-3GPP access) are transported over the same access.
  • SMF handles the Session management part of NAS signalling exchanged with the UE.
  • The UE shall only initiate PDU Session Establishment in RM-REGISTERED state.
  • When a SMF has been selected to serve a specific PDU Session, AMF has to ensure that all NAS signalling related with this PDU Session is handled by the same SMF instance.
  • Upon successful PDU Session Establishment, the AMF and SMF stores the Access Type that the PDU Session is associated.

23.501 - 8.2.2 Control Plane Protocol Stacks between the UE and the 5GC

  • A single N1 NAS signalling connection is used for each access to which the UE is connected. The single N1 termination point is located in AMF. The single N1 NAS signalling connection is used for both Registration Management and Connection Management (RM/CM) and for SM-related messages and procedures for a UE.
  • The NAS protocol on N1 comprises a NAS-MM and a NAS-SM components.
  • There are multiple cases of protocols between the UE and a core network function (excluding the AMF) that need to be transported over N1 via NAS-MM protocol. Such cases include:
    • Session Management Signalling.
    • SMS.
    • UE Policy.
    • LCS.

Here goes the summary of N1 interfaces based on the specification lmentioned above.

  • N1 provides the NAS signaling connection between the UE and AMF over access networks like 3GPP and non-3GPP.
  • For a UE connected over multiple accesses, separate N1 instances exist over each access.
  • N1 is used for NAS signaling including registration, connection management, session management, SMS, location services, etc.
  • A single N1 instance per access is used for all NAS signaling both NAS-MM and NAS-SM.
  • N1 NAS signaling is protected by 5G security mechanisms.
  • N1 is used on an access if PDU session is established over that access. Subsequent SM NAS exchanges use the same access.
  • UE initiates PDU session establishment only in RM-REGISTERED state.
  • AMF ensures NAS signaling for a PDU session uses the same SMF instance.
  • N1 comprises NAS-MM for registration, connection management and NAS-SM for session management.

UE Capability for N1mode Support

You can check whether UE support N1mode or not by NAS message as shown below. This message is from Amari Callbox log. You may take this as an indicator whether UE support SA or not.

What you are actually looking for

The useful thing about these two logs is that they are mirror images of each other. A UE tells each network about the other one.

Where the UE is

What it declares

In which IE

Meaning

On 4G, sending an Attach Request to an MME

N1mode = 1

UE network capability, in 24.301

I could be moved to 5G standalone

On 5G, sending a Registration Request to an AMF

S1 mode = 1

5GMM capability, in 24.501

I could fall back to 4G

 

Read it that way and the pair makes sense. On 4G the interesting bit is N1mode, because that is a device saying it could work on 5G standalone. On 5G the interesting bit is S1 mode, because that is the same device saying it could drop back to 4G. Neither bit is about what the UE is doing now. Both are about where it could go next.

1. Registration Request, seen by the AMF

This is a UE already registering over N1. The highlighted lines are the ones worth reading.

Protocol
discriminator = 0x7e (5GS Mobility Management)
Security header = 0x1 (Integrity protected)
Auth code = 0xaab82c81
Sequence number = 0x0e
Protocol discriminator = 0x7e (5GS Mobility Management)
Security header = 0x0 (Plain 5GS NAS message, not security protected)
Message type = 0x41 (Registration request)
5GS registration type:
  Follow-on request bit = 1
  Value = 1 (initial registration)
ngKSI:
  TSC = 0
  NAS key set identifier = 6
5GS mobile identity:
  5G-GUTI
    MCC = 001
    MNC = 01 
    AMF Region ID = 128
    AMF Set ID = 4
    AMF Pointer = 1
    5G-TMSI = 0x3b2df3b5
UE security capability:
  0xf0 (5G-EA0=1, 128-5G-EA1=1, 128-5G-EA2=1, 128-5G-EA3=1, 5G-EA4=0, 5G-EA5=0, 5G-EA6=0, 5G-EA7=0)
  0x70 (5G-IA0=0, 128-5G-IA1=1, 128-5G-IA2=1, 128-5G-IA3=1, 5G-IA4=0, 5G-IA5=0, 5G-IA6=0, 5G-IA7=0)
  0xf0 (EEA0=1, 128-EEA1=1, 128-EEA2=1, 128-EEA3=1, EEA4=0, EEA5=0, EEA6=0, EEA7=0)
  0x70 (EIA0=0, 128-EIA1=1, 128-EIA2=1, 128-EIA3=1, EIA4=0, EIA5=0, EIA6=0, EIA7=0)
NAS message container:
  Protocol discriminator = 0x7e (5GS Mobility Management)
  Security header = 0x0 (Plain 5GS NAS message, not security protected)
  Message type = 0x41 (Registration request)
  5GS registration type:
    Follow-on request bit = 1
    Value = 1 (initial registration)
  ngKSI:
    TSC = 0
    NAS key set identifier = 6
  5GS mobile identity:
    5G-GUTI
      MCC = 001
      MNC = 01 
      AMF Region ID = 128
      AMF Set ID = 4
      AMF Pointer = 1
      5G-TMSI = 0x3b2df3b5
  5GMM capability:
    0x03 (SGC=0, 5G-IPHC-CP CIoT=0, N3 data=0, 5G-CP CIoT=0, RestrictEC=0, LPP=0, HO attach=1, S1 mode=1)
  UE security capability:
    0xf0 (5G-EA0=1, 128-5G-EA1=1, 128-5G-EA2=1, 128-5G-EA3=1, 5G-EA4=0, 5G-EA5=0, 5G-EA6=0, 5G-EA7=0)
    0x70 (5G-IA0=0, 128-5G-IA1=1, 128-5G-IA2=1, 128-5G-IA3=1, 5G-IA4=0, 5G-IA5=0, 5G-IA6=0, 5G-IA7=0)
    0xf0 (EEA0=1, 128-EEA1=1, 128-EEA2=1, 128-EEA3=1, EEA4=0, EEA5=0, EEA6=0, EEA7=0)
    0x70 (EIA0=0, 128-EIA1=1, 128-EIA2=1, 128-EIA3=1, EIA4=0, EIA5=0, EIA6=0, EIA7=0)
  Requested NSSAI:
    S-NSSAI
      Length of S-NSSAI contents = 1 (SST)
      SST = 0x01
  Last visited registered TAI:
    MCC = 001
    MNC = 01 
    TAC = 0x000064
  S1 UE network capability:
    0xf0 (EEA0=1, 128-EEA1=1, 128-EEA2=1, 128-EEA3=1, EEA4=0, EEA5=0, EEA6=0, EEA7=0)
    0x70 (EIA0=0, 128-EIA1=1, 128-EIA2=1, 128-EIA3=1, EIA4=0, EIA5=0, EIA6=0, EIA7=0)
    0xc0 (UEA0=1, UEA1=1, UEA2=0, UEA3=0, UEA4=0, UEA5=0, UEA6=0, UEA7=0)
    0x40 (UCS2=0, UIA1=1, UIA2=0, UIA3=0, UIA4=0, UIA5=0, UIA6=0, UIA7=0)
    0x19 (ProSe-dd=0, ProSe=0, H.245-ASH=0, ACC-CSFB=1, LPP=1, LCS=0, 1xSRVCC=0, NF=1)
    0x80 (ePCO=1, HC-CP CIoT=0, ERw/oPDN=0, S1-U data=0, UP CIoT=0, CP CIoT=0, ProSe-relay=0, ProSe-dc=0)
    0xb0 (15 bearers=1, SGC=0, N1mode=1, DCNR=1, CP backoff=0, RestrictEC=0, V2X PC5=0, multipleDRB=0)
  UE's usage setting = 0x01 (Data centric)
  LADN indication:
    Length = 0
    Data =
  Network slicing indication = 0x00 (DCNI=0, NSSCI=0)
  5GS update type = 0x01 (EPS-PNB-CIoT=no additional information, 
                                    5GS-PNB-CIoT=no additional information, NG-RAN-RCU=0, SMS requested=1)

Two things in there are worth a comment.

  • 5GMM capability says S1 mode = 1 : this is the UE declaring, to the 5G core, that it also supports 4G. That is what makes fallback and interworking possible. If this bit were 0, the network would know not to try moving the UE to an MME.
  • The S1 UE network capability IE is carried too, and it contains N1mode = 1 : this one confuses people, and reasonably so. Why would a UE tell the AMF it supports N1 mode when it is plainly already using it ? The answer is that this IE is not a message to the AMF. It is the 4G format capability, carried so the AMF can hand it over to an MME during interworking. The UE is packing its 4G paperwork, not making a statement about now.

2. Attach Request, seen by the MME

Now the same device on 4G. This is where the bit actually earns its keep.

Protocol discriminator = 0x7 (EPS Mobility Management)
Security header = 0x1 (Integrity protected)
Auth code = 0x57498120
Sequence number = 0x0d
Protocol discriminator = 0x7 (EPS Mobility Management)
Security header = 0x0 (Plain NAS message, not security protected)
Message type = 0x41 (Attach request)
EPS attach type = 2 (combined EPS/IMSI attach)
NAS key set identifier:
  TSC = 0
  NAS key set identifier = 0
Old GUTI or IMSI:
  MCC = 001
  MNC = 01
  MME Group ID = 32769
  MME Code = 1
  M-TMSI = 0x2f915853
UE network capability:
  0xf0 (EEA0=1, 128-EEA1=1, 128-EEA2=1, 128-EEA3=1, EEA4=0, EEA5=0, EEA6=0, EEA7=0)
  0x70 (EIA0=0, 128-EIA1=1, 128-EIA2=1, 128-EIA3=1, EIA4=0, EIA5=0, EIA6=0, EIA7=0)
  0xc0 (UEA0=1, UEA1=1, UEA2=0, UEA3=0, UEA4=0, UEA5=0, UEA6=0, UEA7=0)
  0x40 (UCS2=0, UIA1=1, UIA2=0, UIA3=0, UIA4=0, UIA5=0, UIA6=0, UIA7=0)
  0x19 (ProSe-dd=0, ProSe=0, H.245-ASH=0, ACC-CSFB=1, LPP=1, LCS=0, 1xSRVCC=0, NF=1)
  0x80 (ePCO=1, HC-CP CIoT=0, ERw/oPDN=0, S1-U data=0, UP CIoT=0, CP CIoT=0, ProSe-relay=0, ProSe-dc=0)
  0xb0 (15 bearers=1, SGC=0, N1mode=1, DCNR=1, CP backoff=0, RestrictEC=0, V2X PC5=0, multipleDRB=0)
ESM message container:
  Protocol discriminator = 0x2 (EPS Session Management)
  EPS bearer identity = 0
  Procedure transaction identity = 23
  Message type = 0xd0 (PDN connectivity request)
  Request type = 1 (initial request)
  PDN type = 3 (IPv4v6)
  ESM information transfer flag = 1
Last visited registered TAI:
  MCC = 001
  MNC = 01
  TAC = 0x0001
DRX parameter:
  Data = 0a 00
MS network capability:
  Length = 3
  Data = e5 e0 3e
Old location area identification:
  MCC = 001
  MNC = 01
  LAC = 0x0001
Mobile station classmark 2:
  Length = 3
  Data = 57 58 a6
Mobile station classmark 3:
  Length = 12
  Data = 60 14 04 e2 91 81 0f 1a 1e 50 00 00
Supported codecs:
  Length = 8
  Data = 04 02 60 04 00 02 1f 02
Voice domain preference and UE's usage setting = 0x07 (IMS PS voice preferred, CS Voice as secondary, Data centric)
Old GUTI type = 0
MS network feature support = 0x01 (MS supports the extended periodic timer in this domain)
UE additional security capability:
  0xf0 (5G-EA0=1, 128-5G-EA1=1, 128-5G-EA2=1, 128-5G-EA3=1, 5G-EA4=0, 5G-EA5=0, 5G-EA6=0, 5G-EA7=0)
  0x00 (5G-EA8=0, 5G-EA9=0, 5G-EA10=0, 5G-EA11=0, 5G-EA12=0, 5G-EA13=0, 5G-EA14=0, 5G-EA15=0)
  0x70 (5G-IA0=0, 128-5G-IA1=1, 128-5G-IA2=1, 128-5G-IA3=1, 5G-IA4=0, 5G-IA5=0, 5G-IA6=0, 5G-IA7=0)
  0x00 (5G-IA8=0, 5G-IA9=0, 5G-IA10=0, 5G-IA11=0, 5G-IA12=0, 5G-IA13=0, 5G-IA14=0, 5G-IA15=0)

N1mode and DCNR are not the same bit

Look again at the highlighted line in the attach. Two separate bits sit next to each other, and they answer different questions.

  • DCNR = 1 : the UE supports Dual Connectivity with NR, which is EN-DC. In deployment terms, it can do NSA. The core network here is still the EPC.
  • N1mode = 1 : the UE supports N1 mode, so it can attach to a 5G core directly. In deployment terms, it can do SA.

They are independent. An early 5G phone often had DCNR set and N1mode clear, because it could do NSA and nothing else. A device with both set can do either, and the network decides which. Reading only one of the two bits is a common way to reach the wrong conclusion about what a device supports.

What the network actually does with it

The bit is not decoration. An MME that sees N1mode = 1 knows the device is a candidate for 5G standalone, and that feeds into how the network steers it. It also matters in the other direction. A network can refuse. In the attach accept an MME can send back a restriction, and a UE that supports N1 mode may still be told not to use it in this area.

So there are three separate questions, and it is worth keeping them apart when you are chasing why a device will not come up on standalone.

  • Does the UE support it ? That is the N1mode bit above.
  • Has the UE disabled it ? That is the usage setting table further up this page, where a voice centric UE turns N1 mode off when it cannot get IMS voice.
  • Is the network allowing it ? That is a network decision, and it is invisible in the UE capability entirely.

NOTE : The three are checked in that order in practice. A device that reports N1mode = 1 and still refuses to register on standalone has usually failed the second or the third, not the first.

Reference

[1]