In the context of 5G networking, N1 and S1 modes refer to different ways a user equipment (UE) can access the network, with specific implications for the kind of network architecture the UE is interfacing with.
One more point of precision. 24.301 always qualifies the capability as N1 mode for 3GPP access, because the mode is tracked per access type. A UE can therefore be in N1 mode over a non-3GPP access while it uses another access as well. That is separate from the registration modes covered in Are N1 mode and S1 mode mutually exclusive ?
In short, N1 mode is the UE running its NAS towards the 5G core, and S1 mode is the UE running its NAS towards the EPC. The pair says which core the UE is registered or attached to. It does not say how the radio network is deployed, and the difference between the two statements is the subject of a section below.
- Quick comparison of N1 mode and S1 mode
- What do N1 mode and S1 mode actually mean ?
- Are N1 and S1 the same as SA and NSA ?
- N26 and interworking with EPS
- Are N1 mode and S1 mode mutually exclusive ?
- How can you tell which mode a UE is in ?
- Quotes from 24.501
- Reference
Quick comparison of N1 mode and S1 mode
The list below is the working comparison, and it mixes two kinds of statement. Some entries are about which core the UE talks to. Others are about what a deployment gets in return for choosing one core over the other. It is worth keeping the two apart while reading.
- N1 mode refers to the UE holding a NAS connection to the AMF in the 5G core. S1 mode refers to the UE holding a NAS connection to the MME in the EPC.
- In N1 mode, the NG interface is used between RAN and 5GC. In S1 mode, existing 4G S1 interface is reused between RAN and EPC.
- N1 mode allows full 5G core network features like network slicing, advanced QoS, unified authentication, etc. S1 mode has limitations of 4G core.
- The 5G core network functions like AMF, SMF, UPF are utilized in N1 mode. In S1 mode, 4G elements like MME, SGW, PGW are still used.
- N1 mode simplifies the architecture with a common core for different access types. S1 mode retains the overlapping 4G and 5G cores.
- N1 mode requires deploying the new 5G core first. S1 mode allows introducing 5G NR with existing 4G core.
- Performance like throughput, latency is superior in N1 mode compared to when anchored via 4G core in S1 mode.
- Initial 5G deployments are using S1 mode for faster rollout leveraging existing 4G infrastructure. N1 mode allows full 5G capabilities.
- In S1 mode, the 5G gNB connect to the 4G EPC core network using the existing S1 interface.
- To support this interworking between the two core networks, the interface between the MME and the AMF is referred to as N26.
- So N26 is the reference point for the signalling between the 4G MME and the 5G AMF. It is an interface between two core network nodes, and nothing on it reaches the gNodeB.
- NG-C and NG-U are not used towards the EPC. NG-C is another name for N2, between the NG-RAN and the AMF, and NG-U is the matching user plane towards the UPF.
The core is what the two names pick out : N1 mode puts the NAS on the AMF and S1 mode puts it on the MME.Feature availability follows the core, not the radio : network slicing, unified authentication and the 5G QoS model live in the 5G core.Interworking is the reason the pair is specified : a UE that supports both can be moved between the systems rather than dropped.N26 is a core to core interface : it joins the MME and the AMF, and it is optional for the network to support.
What do N1 mode and S1 mode actually mean ?
The two names look as though they describe networks. They describe the UE. Each one says where the NAS signalling of that UE terminates, and it says nothing else. Once that is clear the rest of the note follows easily.
23.501 lists N1 among the reference points of the 5G system, and the entry is one line. N1 is the reference point between the UE and the AMF. NAS messages between the UE and the AMF ride on it. A UE operating in N1 mode is therefore a UE whose NAS is registered with an AMF in the 5G core.
S1 is the matching reference point in the EPS, and NAS between the UE and the MME rides on it. That is where the name of the mode comes from. A UE operating in S1 mode is attached to an MME in the EPC.
Both modes are properties of the UE, and each can be enabled or disabled on its own. 23.501 speaks of N1 mode status being enabled or disabled in the UE. It also describes a UE re-enabling a disabled N1 or S1 mode after the network has redirected it. A UE that supports both carries both, and uses whichever the network in front of it will accept.
N1 mode is a state of the UE, not a type of network : it means the NAS of that UE is registered with an AMF in the 5G core.S1 mode is the same idea towards the EPC : the NAS of the UE is attached to an MME, over the S1 reference point.The two modes are enabled and disabled separately : a network can redirect a UE by rejecting it, and the UE may re-enable the disabled mode later.The pair exists so that interworking can be written down : nearly all the S1 mode text in 24.501 is about moving between the two systems.
Are N1 and S1 the same as SA and NSA ?
No, and this is the confusion worth clearing first. The two pairs get used as though they were interchangeable. They answer different questions, and treating them as one produces claims that are wrong in the cases that matter most.
SA and NSA describe how the radio network is deployed. In Non-Standalone an LTE eNB is the master node, an NR gNB is added as a secondary node, and the core is the EPC. In Standalone the NR gNB stands on its own against the 5G core.
N1 mode and S1 mode describe where the NAS of the UE ends up. The two pairs are related, and they are not the same statement. A UE in EN-DC has its NAS on the MME, so that UE is in S1 mode. A UE on a Standalone 5G network has its NAS on the AMF, so that UE is in N1 mode. So far the two look identical.
The mapping breaks as soon as a Standalone capable UE leaves 5G coverage. It moves onto LTE, its NAS attaches to an MME, and it is now in S1 mode with no Non-Standalone deployment anywhere in sight. EPS fallback for a voice call does the same thing for the duration of the call. S1 mode therefore covers Non-Standalone, and it also covers every other case where a 5G capable UE is being served by the EPC.
SA and NSA are deployment options : they say which node is the master and which core the radio network connects to.N1 and S1 are UE modes : they say which core the NAS of the UE is registered or attached to.Every NSA UE is in S1 mode : its NAS runs to the MME, because EN-DC is anchored on the EPC.Not every UE in S1 mode is NSA : a Standalone UE that moves onto LTE, or falls back for a voice call, is in S1 mode as well.The 24.501 wording is the giveaway : it discusses S1 mode beside single registration, dual registration and N26, which are interworking ideas rather than deployment options.
N26 and interworking with EPS
N26 is the interface most often drawn in the wrong place. It is worth being exact about, because the split between single registration and dual registration hangs entirely on whether the network has it.
23.501 states it directly. N26 is an inter-CN interface between the MME and the 5GS AMF, and it exists to let the EPC and the 5G core interwork. It runs between two core network nodes. Nothing carried on it reaches the gNodeB, and it is not a radio network interface at all.
Support for N26 in the network is optional, and that option is what the registration modes turn on. When the AMF supports N26 it tells the UE that interworking without N26 is not supported, and the UE then operates in single-registration mode. When the AMF does not support N26 it signals that interworking without N26 is supported. A UE able to do so may then operate in dual-registration mode. The quoted text further down states both conditions exactly.
23.501 also records what N26 carries. It supports a subset of the functions that S10 supports between two MMEs, and the subset is the part that interworking needs. That is enough to move a UE context across. A network with N26 can therefore transfer a UE instead of making it register again from scratch.
N26 joins the MME and the AMF : it is an inter-CN interface, and no part of it touches the radio network.Support for N26 is optional : a network is allowed to interwork with EPS without it.N26 decides the registration mode : with N26 the UE uses single-registration mode, and without it a capable UE may use dual-registration mode.N26 carries a subset of S10 : it moves what interworking needs, rather than everything two MMEs exchange.
Are N1 mode and S1 mode mutually exclusive ?
This is the question the pair invites, and the answer is not a plain yes. A UE can be capable of both at once. Whether it can be in both at once is a different question, and it is settled by one thing in the network rather than by the UE.
At the capability level there is no exclusivity at all, and a 5G phone normally declares both. In an EPS ATTACH REQUEST the UE sets the N1mode bit to say it can use a 5G core. In a 5GS REGISTRATION REQUEST it sets the S1 mode bit in the 5GMM capability IE to say it can use the EPC. Both bits can be set at the same time.
The operating state is where the answer splits. 23.501 defines two registration modes for a UE that supports both 5GC and EPC NAS. In single-registration mode the UE has only one active MM state, either the RM state in 5GC or the EMM state in EPC. It is in 5GC NAS mode or in EPC NAS mode, and never in both. It keeps a single coordinated registration, and it maps the EPS-GUTI to the 5G-GUTI as it moves between the systems.
Dual-registration mode works the other way. The UE handles independent registrations for 5GC and EPC over separate RRC connections. It maintains the 5G-GUTI and the EPS-GUTI independently, rather than mapping one onto the other. 23.501 then states the consequence plainly. The UE may be registered to 5GC only, to EPC only, or to both 5GC and EPC. In that last case the UE is in N1 mode and in S1 mode at the same time.
Which registration mode applies is not the choice of the UE alone. The AMF sets the IWK N26 bit in the REGISTRATION ACCEPT, and the text quoted further down gives both branches. When the AMF has N26 the UE shall operate in single-registration mode. When the AMF has no N26 and the UE supports dual-registration, the UE may operate in dual-registration mode. A UE that supports single-registration only operates that way whatever the bit says.
< Whether N1 mode and S1 mode can be held at the same time >
|
Level |
Can the UE be in both at once ? |
What decides it |
|
Capability bits |
Not applicable. Both may be declared. |
The support of the UE itself. The N1mode bit and the S1 mode bit are independent. |
|
Single-registration mode |
No. One active MM state only. |
The AMF supports N26, or the UE supports single-registration mode only. |
|
Dual-registration mode |
Yes. 5GC only, EPC only, or both. |
The AMF does not support N26, and the UE supports dual-registration mode. |
|
A mode that has been disabled |
No. The disabled mode is unavailable. |
A reject cause from the network, as described in the section on telling the modes apart. |
Dual-registration is not a licence to attach twice through one cell. 23.501 asks a dual-registered UE not to send its E-UTRA connected to 5GC and its E-UTRAN radio capabilities to NR access while it is connected to 5GS. The reason given is to stop the UE being connected to the same E-UTRA cell towards EPC and towards 5GC at once. That would mean separate RRC connections through a single RAN node. Two registrations are meant to run over two connections.
One more mechanism sits beside all of this, and it is easy to confuse with the registration mode. Each mode can be disabled on its own. A UE with N1 mode disabled behaves as an S1 only UE until it re-enables, whatever its capability bits say. Disabling is a state the network drives through reject causes, and it is separate from whether the UE is single-registered or dual-registered.
Capability is never exclusive : a UE can declare N1 mode support and S1 mode support at the same time, and most do.Single-registration mode is exclusive : the UE holds one active MM state, either in 5GC or in EPC, and never both.Dual-registration mode is not exclusive : the UE may be registered to 5GC only, to EPC only, or to both at once.N26 decides which of the two applies : an AMF with N26 forces single-registration, and an AMF without it allows dual-registration for a UE that supports it.Two registrations need two connections : dual-registration runs over separate RRC connections, and not twice through one cell.Disabling a mode is a third mechanism : a disabled N1 or S1 mode is unavailable whatever registration mode is in force.
How can you tell which mode a UE is in ?
There is one trap to get past before any of the indicators are useful. Most of the fields with "S1 mode" or "N1 mode" in their name are capability bits, and a capability is not a state. A UE that says it supports S1 mode is telling you what it could do, not what it is doing. I have watched people read that bit from a log and conclude the UE was on the EPC. The message carrying the bit could only have been sent from N1 mode.
The decisive test is simpler than any single field. Look at which NAS protocol is running. 5GMM and 5GSM messages terminate at the AMF, so a UE exchanging them is in N1 mode. EMM and ESM messages terminate at the MME, so a UE exchanging those is in S1 mode. Every other indicator is a shortcut to that same answer.
The procedure the UE runs is the quickest version of the test. A REGISTRATION REQUEST or a Service Request is N1 mode. An ATTACH REQUEST or a TRACKING AREA UPDATE REQUEST is S1 mode. The identities move with the protocol, so a 5G-GUTI and an ngKSI belong to N1 mode, and a GUTI and an eKSI belong to S1 mode.
< Indicators of N1 mode and S1 mode, and what each one really says >
|
What you can see |
Where it appears |
What it tells you |
|
The NAS procedure being run |
NAS |
REGISTRATION REQUEST or Service Request means the UE is in N1 mode. ATTACH REQUEST or TRACKING AREA UPDATE REQUEST means S1 mode. This is a state, not a capability. |
|
The message set in use |
NAS |
5GMM and 5GSM messages run to the AMF, so N1 mode. EMM and ESM messages run to the MME, so S1 mode. |
|
The identity and key set identifier |
NAS |
A 5G-GUTI with an ngKSI belongs to N1 mode. A GUTI with an eKSI belongs to S1 mode. |
|
ng-5G-S-TMSI-Value, registeredAMF, s-NSSAI-List in RRCSetupComplete |
NR RRC, 38.331 |
These fields exist only when the UE is setting up towards a 5G core, so their presence means N1 mode. This is the fastest tell in an RRC log. |
|
guami-Type set to mapped in RRCSetupComplete |
NR RRC, 38.331 |
The GUAMI was derived from an EPS identity rather than assigned natively. The UE arrived from S1 mode, which is interworking in progress. |
|
DCNR bit, UE network capability octet 9 bit 5 |
ATTACH REQUEST, 24.301 |
The UE supports dual connectivity with NR, which is EN-DC. This is a capability, and a UE sending it is in S1 mode because the message is EMM. |
|
N1mode bit, UE network capability octet 9 bit 6 |
ATTACH REQUEST, 24.301 |
The UE supports N1 mode for 3GPP access. Still a capability. The UE sending it is in S1 mode at that moment. |
|
S1 mode bit, 5GMM capability IE |
REGISTRATION REQUEST, 24.501 |
The UE supports S1 mode. The UE sending it is in N1 mode, because a REGISTRATION REQUEST is a 5GMM message. |
|
IWK N26 bit, 5GS network feature support IE |
REGISTRATION ACCEPT, 24.501 |
Whether the AMF has N26, which decides single-registration or dual-registration mode. It describes the network, not the UE. |
Two rows of that table are worth putting side by side. DCNR and N1mode are adjacent bits in the same UE network capability IE, at octet 9 bit 5 and octet 9 bit 6. One says the UE can do EN-DC and the other says it can use a 5G core. They are separate bits because they are separate questions, which is the same point the previous section makes in words.
Behaviour gives the other half of the answer, and it is easiest to read at the moment the mode changes. 23.501 describes both directions. To move a UE from the 5G core to the EPC, the AMF rejects a Registration Request or Service Request with an EMM cause saying the UE should not use 5GC. The UE then disables N1 mode and re-enables S1 mode.
The reverse works the same way. The MME rejects an Attach, a TAU or a Service Request with a cause saying the UE should not use EPC. The UE then disables S1 mode, and re-enables N1 mode if it was disabled. If the UE then cannot find a cell it can use, it may re-enable the mode it just disabled and try the procedure again. A UE that is flipping between the two is usually being redirected rather than misbehaving.
One reject cause names the mode directly. 5GMM cause #27 is "N1 mode not allowed". 24.501 sends it when the UE requests service in a PLMN or SNPN where subscription or operator policy does not allow N1 mode. Seeing that cause tells you both what the UE tried and why it will now be on the EPC.
Read the protocol, not the field name : a UE exchanging 5GMM messages is in N1 mode, and a UE exchanging EMM messages is in S1 mode.Most fields with a mode name in them are capabilities : the S1 mode bit and the N1mode bit say what the UE could do, not what it is doing.The carrying message settles the state : a REGISTRATION REQUEST can only come from N1 mode, and an ATTACH REQUEST can only come from S1 mode.RRCSetupComplete is the fastest tell in a radio log : registeredAMF and ng-5G-S-TMSI-Value appear only when the UE is going to a 5G core.A mapped GUAMI means the UE came from EPS : guami-Type distinguishes a native assignment from one derived during interworking.Mode changes show up as rejects : a reject that disables one mode and re-enables the other is a redirection, and 5GMM cause #27 names N1 mode outright.
Quotes from 24.501
The text below is quoted rather than summarised, because the conditions in it are exact and the wording carries them. Read it as the rule that the sections above describe. Every clause in it is about interworking with EPS, which is the point the opening of this note makes.
Followings are some of the quotes directly copied from 3GPP.
24.501 states :
If the UE included S1 mode supported indication in the REGISTRATION REQUEST message, the AMF supporting
interworking with EPS shall set the IWK N26 bit to either:
a) "interworking without N26 interface not supported" if the AMF supports N26 interface; or
b) "interworking without N26 interface supported" if the AMF does not support N26 interface
in the 5GS network feature support IE in the REGISTRATION ACCEPT message.
The UE supporting S1 mode shall operate in the mode for interworking with EPS as follows:
a) if the IWK N26 bit in the 5GS network feature support IE is set to "interworking without N26 interface not
supported", the UE shall operate in single-registration mode;
b) if the IWK N26 bit in the 5GS network feature support IE is set to "interworking without N26 interface
supported" and the UE supports dual-registration mode, the UE may operate in dual-registration mode; or
NOTE 7: The registration mode used by the UE is implementation dependent.
c) if the IWK N26 bit in the 5GS network feature support IE is set to "interworking without N26 interface
supported" and the UE only supports single-registration mode, the UE shall operate in single-registration mode.
If the UE is registered in S1 mode and operating in dual-registration mode, the PLMN that the UE chooses to
register in is specified in 24.501-4.8.3. Otherwise the UE shall perform a PLMN selection or SNPN selection
according to 23.122
If the UE indicates "mobility registration updating" in the 5GS registration type IE and the UE supports S1 mode, the
UE shall:
- set the S1 mode bit to "S1 mode supported" in the 5GMM capability IE of the REGISTRATION REQUEST
message;
- include the S1 UE network capability IE in the REGISTRATION REQUEST message; and
- if the UE supports sending an ATTACH REQUEST message containing a PDN CONNECTIVITY REQUEST
message with request type set to "handover" to transfer a PDU session from N1 mode to S1 mode, set the HO
attach bit to "attach request message containing PDN connectivity request with request type set to handover to
transfer PDU session from N1 mode to S1 mode supported" in the 5GMM capability IE of the REGISTRATION
REQUEST message.
A UE supporting S1 mode shall include the IE "S1 UE network capability", unless the UE performs a periodic registration updating procedure.
Reference
[1] 23.501 v20.2.0 : System architecture for the 5G System (5GS)
[2] 24.501 v20.0.0 : Non-Access-Stratum (NAS) protocol for 5G System (5GS)
[3] 24.301 v20.0.0 : Non-Access-Stratum (NAS) protocol for Evolved Packet System (EPS)
[4] 38.331 v19.3.0 : NR - Radio Resource Control (RRC) protocol specification