N1 (N1 Reference Point)

Also known as: N1 Reference Point

N1 is the 3GPP 5G reference point between the UE and the AMF, defined in TS 23.501. It carries NAS signalling (registration, authentication, security mode command, session management triggers) transported over NG-RAN via N2/NGAP. N1 is the modern equivalent of LTE's NAS-over-S1 and is where 5G-AKA, SUCI concealment and NAS integrity/ciphering apply.

Categories: Radio Access NetworkCore NetworkIdentity and Subscriber

N1 in context

The radio access network is where mobile devices attach to the operator's infrastructure. Attacks in this layer include IMSI catching, rogue base stations and downgrade attacks; defenses rest on mutual authentication, integrity-protected signaling and Open RAN supply-chain hygiene.

The mobile core carries subscriber sessions, mobility and policy. In 4G it is the EPC (MME, HSS, S/PGW); in 5G it is the Service-Based Architecture with AMF, SMF, UPF, AUSF, UDM and the NRF.

To place N1 in the wider telecom-security picture, review Confidentiality, Encryption, FDD, MNO, TMSI and UPF — each entry cross-references back to this page so you can walk the topic in either direction.

Related terms

More from the TelcoSec Glossary

Browse the full TelcoSec Glossary, the Ultimate Guide to Mobile Network Security, or the P1 Arsenal of telecom-security tools.