Within the 5GC, the NSSAAF offers services to the AMF and the AUSF via the Nnssaaf service-based interface.
The AMF shall make use of the NSSAAF service when it needs to invoke network slice-specific authentication and authorization for a specific UE and a specific S-NSSAI (see
clause 4.2.9.2 of TS 23.502, and
clauses 16.2 and
16.3 of
TS 33.501).
The NSSAAF service shall also be used by the AMF to receive slice re-authentication notification or slice authorization revocation notification sent from the AAA-S (see
clauses 4.2.9.3 and
4.2.9.4 of
TS 23.502, and
clauses 16.3 and
16.4 of
TS 33.501).
The AUSF shall make use of the NSSAAF service when it needs to invoke a primary authentication in SNPN with Credentials holder using AAA server; the AUSF shall also make use of this service during the UE onboarding procedure in SNPN scenarios, when the Default Credentials Server (DCS) uses an AAA server for primary authentication.
Figure 4.1-1 provides the reference model with focus on the NSSAAF.
Figure 4.1-1 provides the reference model with focus on the NSSAAF.