NAS 5G UE to SMF via AMF 3GPP TS 24.501

5G NAS - PDU Session Authentication Complete

PDU Session Authentication Complete is the 5GSM message the UE sends in response to PDU Session Authentication Command to carry the EAP response and continue the session-authentication exchange.

Message Fact Sheet

Protocol nas Network 5g
Spec 3GPP TS 24.501 Spec Section 8.3.5
Direction UE to SMF via AMF Message Type 5GSM signaling
Full message name 5G NAS - PDU Session Authentication Complete
Protocol NAS
Technology 5G
Direction UE to SMF via AMF
Interface N1
Signaling bearer / channel NAS signaling / Usually carried inside UL NAS Transport on the access side
Typical trigger The UE received PDU Session Authentication Command and is returning the EAP-response for the current PDU session authentication exchange.
Main purpose Acknowledges the authentication command and returns the UE's EAP response so the network can continue or complete the PDU session authentication procedure.
Main specification 3GPP TS 24.501, 8.3.5
Release added Release 15
Procedures where used 5G PDU Session Establishment, 5G PDU Session Authentication Procedure, PDU EAP message reliable transport procedure
Related timers T3590

What is PDU Session Authentication Complete in simple terms?

PDU Session Authentication Complete is the 5GSM message the UE sends in response to PDU Session Authentication Command to carry the EAP response and continue the session-authentication exchange.

Acknowledges the authentication command and returns the UE's EAP response so the network can continue or complete the PDU session authentication procedure.

Where this message appears in the call flow

5G PDU Session Authentication Procedure

Call flow position: UE response step that answers the EAP-request contained in the authentication command.

Typical state: The UE is already in the session authentication branch and is expected to send the matching response before T3590 expires.

Preconditions:

  • The UE received PDU Session Authentication Command.
  • The EAP method can be processed by the UE or its upper-layer auth stack.

Next likely message: PDU Session Authentication Result or PDU Session Establishment Accept

5G PDU Session Establishment

Call flow position: Optional branch inside the main establishment flow before the final accept or reject is sent.

Typical state: The UE has requested a PDU session and is answering the network's session-level authentication challenge.

Preconditions:

  • The PDU Session Establishment Request is already in progress.
  • The network requested additional authentication or authorization.

Next likely message: PDU Session Authentication Result or PDU Session Establishment Accept

Call flow position

Previous message(s): PDU Session Authentication Command, UL NAS Transport

Next message(s): PDU Session Authentication Result, PDU Session Establishment Accept, PDU Session Establishment Reject, PDU Session Release Command

Message direction and transport

Sender and receiver: UE to SMF via AMF

Interface: N1

Domain: Core-side session management response with access-side NAS delivery dependency

Signaling bearer: NAS signaling

Logical channel: Usually carried inside UL NAS Transport on the access side

Transport / encapsulation: 5GSM NAS message transported end-to-end from the UE to the SMF through AMF mediation

Security context: Normally sent after registration and NAS security establishment, so the payload is usually integrity protected and often ciphered even though the EAP exchange itself is handled by the session-authentication procedure.

ASN.1 Message Syntax for 5G NAS - PDU Session Authentication Complete

This message is not typically analyzed as ASN.1 on the wire. It is usually read as a NAS or protocol field structure instead.

This is a 5GSM NAS message defined by ordered information elements in 3GPP TS 24.501 rather than ASN.1 syntax.

5G NAS - PDU Session Authentication Complete - Example Dump

PDU Session Authentication Complete
  Extended Protocol Discriminator: 5G Session Management
  PDU Session ID: 10
  PTI: No procedure transaction identity assigned
  Message Type: PDU Session Authentication Complete
  EAP Message:
    Code: Response
    Identifier: 7
    Type: EAP-AKA'
    Data: [authentication response]
  Extended Protocol Configuration Options:
    DNS IPv4 address: 10.1.1.1
    DNS IPv6 address: 2001:db8::53

Related message pages

Related Procedures

Related Tools

Use This Reference in Practice

Decode this message with the 3GPP Decoder, inspect the related message database, or open the matching call flow to see where this signaling step fits in the full procedure.