N11 Reference Point (AMF to SMF)

Also known as: N11 reference point, N11 interface

N11 is the 3GPP service-based reference point between the AMF and the SMF, implemented over HTTP/2 with Nsmf and Namf APIs. It carries PDU session establishment, modification and release messages, N1/N2 tunnelled NAS content and QoS updates. Attacks or misconfigurations on N11 can cause session hijack, forced re-authentication or QoS downgrade, so it must be TLS-protected with OAuth 2.0 token validation as defined in 3GPP TS 33.501.

Categories: Core NetworkSecurity ControlsEncryption and Cryptography

N11 in context

The mobile core carries subscriber sessions, mobility and policy. In 4G it is the EPC (MME, HSS, S/PGW); in 5G it is the Service-Based Architecture with AMF, SMF, UPF, AUSF, UDM and the NRF.

Security controls span signaling firewalls (SS7/Diameter/GTP screening), transport encryption (IPsec, TLS, PRINS), identity and access on OSS/BSS, and monitoring at both packet and log level. Controls are audited against GSMA FS.11/FS.19/FS.20/FS.36.

To place N11 in the wider telecom-security picture, review SBI, N12, N8, N6, HTTP and SCP: each entry cross-references back to this page so you can walk the topic in either direction.

Related terms

Related topic hubs

  • 5G Security 5G SBA, SEPP, SUCI, 5G-AKA, N32 and service-based interface security.
  • SEPP Security N32-c/N32-f, PRINS, JWE and OAuth 2.0 at the 5G roaming edge.
  • Diameter Security 4G/LTE Diameter threats across IPX/roaming and DEA defenses.
  • Diameter Attacks S6a IDR/PUR/CLR abuse, subscriber tracking, LTE signaling attacks.

More from the TelcoSec Glossary

Browse the full TelcoSec Glossary, the Ultimate Guide to Mobile Network Security, or the P1 Arsenal of telecom-security tools.