Network Sharing is a method of sharing some portions of network architecture among multiple parties. Of course, the major motivation of network sharing is to save the cost or save the critical locations. There are many types (levels) of network sharing. Depending on which portions of the network are shared, they use different terms.
The terms differ in how deep the sharing goes. Cell Site Sharing stops at the location, MOCN shares the radio access network, and an MVNO rents the whole network. This page places each term on the network architecture first, and then looks at how 3GPP supports a shared radio access network.
Followings are the topics to be covered in this page.
Types of Network Sharing
Which part of the network does each type of sharing cover? The diagram below answers it by layer. The rows on the left are the network elements from the cell site up to the HSS, and each yellow box marks the elements that one type of sharing covers.

Network sharing types against the shared network elements. Cell Site Sharing covers only the cell site, MOCN and MVNO cover the NodeB, RNC and eNodeB, and roaming uses the core network of another operator.
Cell Site Sharing : I don't think I need to explain about this. As it stands for, Cell Site Sharing is just to share a location (real estate).
MOCN : MOCN stands for Multi-Operator Core Network. Basic idea of this is to share Access Network part (NodeB, eNodeB) between two or more network operators. Sharing NodeB/eNB usually implies sharing Cell Site as well. In MOCN, the sharing parties tend to be similar scales (like each of the parties are independent Network Operators). Usually each of these operators has some existing area where they have their own NB/eNBs but try to share these resources in those area where the service area of the Network operators are overlapping.
In this type of sharing, they use USIM with multiple PLMNs and MIB (in case of 3G) is configuring the multiple PLMN (each PLMN belong to each sharing Operators).
MVNO : MVNO stands for Mobile Virtual Network Operator. Strictly speaking this may not be regarded is a 'Sharing'. In this mode, a service provider does not have their NB/eNB at all. They are just renting NB/eNB from a Network Operator. Usually small service provider (like prepaid phone service or providing a special service only). Recently (as of Sep 2015) I am seeing multiple MVNOs providing IoT/M2M related service only. Usually these operators issues their own USIM.
The diagram shows roaming in the core network row, but roaming is not network sharing. A roaming UE uses the radio and core network of another operator under a roaming agreement, and its home operator keeps the HSS. Network sharing, in contrast, is an agreement between operators that is meant to be invisible to the user.
3GPP also defines a deeper form of sharing that the diagram does not show. In a Gateway Core Network, or GWCN, the operators share the MME as well as the eNodeB. The last section of this page compares MOCN and GWCN as 23.251 defines them.
Cell Site Sharing : the location and the site facilities only.MOCN : the radio access network is shared, and each operator keeps its own core network.MVNO : a service provider without its own radio network rents capacity from a network operator.Roaming is not sharing : the visited network serves the UE under a roaming agreement.
MOCN
The typical implementation of MOCN can be illustrated as below. As you see here, core network from two different network operator shares same eNB/BTS. The eNB/BTS is transmitting multiple PLMN in SIB 1(in case of LTE or NR) and MIB (in case of WCDMA). UE is connecting to different corenetwork depending on which PLMN it camped to.

MOCN. One eNB broadcasts PLMN 1 and PLMN 2 in the PLMN list of its SIB. The UE camped on PLMN 1 is served by the core network of Operator 1, and the UE camped on PLMN 2 by that of Operator 2.
In LTE, the PLMN list sits in cellAccessRelatedInfo of SystemInformationBlockType1. Each entry is a PLMN-Identity, which is an MCC and an MNC, and the list holds up to maxPLMN-r11 = 6 entries. From Release 14, SIB1 can add up to 5 more sets in cellAccessRelatedInfoList-r14, and each additional set has its own tracking area code and cell identity. So different sharing operators can give the same cell different identities.
Following is based on
PLMN-IdentityList ::= SEQUENCE (SIZE (1..maxPLMN-r11)) OF PLMN-IdentityInfo
PLMN-IdentityInfo ::= SEQUENCE {
plmn-Identity PLMN-Identity,
cellReservedForOperatorUse ENUMERATED {reserved, notReserved}
}
CellAccessRelatedInfo-r14 ::= SEQUENCE {
plmn-IdentityList-r14 PLMN-IdentityList,
trackingAreaCode-r14 TrackingAreaCode,
cellIdentity-r14 CellIdentity
}
Each subscriber keeps the USIM of its own operator. The UE reads all the PLMNs in the list and treats each one as a separate network in PLMN selection. After it selects a PLMN, the UE reports its choice in selectedPLMN-Identity of RRCConnectionSetupComplete. That field is an index from 1 to 6 into the plmn-IdentityList, not the PLMN-Identity itself. The eNodeB then routes the initial NAS message to an MME of the chosen operator.
The choice stays in force afterwards. The MME returns a GUTI that contains the identity of the chosen operator, and the UE stores it on the USIM. The UE does not move to another sharing operator while its chosen operator can serve its location. The network does not move it by handover either. The field cellReservedForOperatorUse is also set per PLMN, so a cell can be reserved for one sharing operator and open for the other.
PLMN list in SIB1 : up to 6 PLMNs, and up to 5 more sets from Release 14.selectedPLMN-Identity : an index into the broadcast list, sent in RRCConnectionSetupComplete.Own USIM for each subscriber : the UE picks its operator from the broadcast list.GUTI carries the chosen operator : and the UE stays with that operator.
MOCN and GWCN in 3GPP
How does 3GPP describe these configurations? TS 23.251 defines two architectures for a shared network. In both, the radio access network is shared, and the difference lies in how much of the core network the operators share as well.
A Multi-Operator Core Network, MOCN, is a configuration in which only the RAN is shared. Each operator connects its own core network nodes to the shared RNC or eNodeB. A Gateway Core Network, GWCN, is a configuration in which parts of the core network are shared too, such as the MSC, SGSN or MME. In E-UTRAN, the eNodeB always relays the chosen network identity to the MME, so that a shared MME can serve the right operator in a GWCN.
23.251 also separates supporting UEs from non-supporting UEs. A supporting UE reads the list of core network operators in the broadcast system information and selects one. A non-supporting UE ignores that list. In UTRAN and GERAN, a non-supporting UE uses a common PLMN ID instead, and the network picks an operator for it, redirecting the UE if needed. In E-UTRAN, every UE uses all the broadcast PLMN IDs, so this distinction applies to UTRAN and GERAN only. In UTRAN, the list is the Multiple PLMN List in the MIB, which is why the MOCN text above mentions the MIB for WCDMA.
MOCN : only the RAN is shared.GWCN : the RAN and parts of the core network, such as the MME, are shared.Supporting and non-supporting UEs : a UTRAN and GERAN distinction; every E-UTRAN UE uses the broadcast PLMN list.
Reference
[1] 3GPP TS 23.251 v19.0.0 - Network sharing; Architecture and functional description, clauses 3.1, 4.1 and 4.2
[2] 3GPP TS 36.331 v19.3.0 - SystemInformationBlockType1, PLMN-IdentityList and RRCConnectionSetupComplete