UE Policy Delivery (5G)

UE Policy is the 3GPP TS 24.526/23.503 framework for pushing policy sections — URSP, Access Network Discovery & Selection Policy (ANDSP), V2X policy, ProSe policy — from the PCF to the UE over encapsulated NAS transport (N1). Each policy section is versioned and integrity-protected end-to-end between PCF and UE.

Categories: Radio Access NetworkCore Network

UE Policy in context

The radio access network is where mobile devices attach to the operator's infrastructure. Attacks in this layer include IMSI catching, rogue base stations and downgrade attacks; defenses rest on mutual authentication, integrity-protected signaling and Open RAN supply-chain hygiene.

The mobile core carries subscriber sessions, mobility and policy. In 4G it is the EPC (MME, HSS, S/PGW); in 5G it is the Service-Based Architecture with AMF, SMF, UPF, AUSF, UDM and the NRF.

To place UE Policy in the wider telecom-security picture, review Diameter, OAuth2 in 5G Core, Slice Hopping, Service-Based Architecture (SBA) Security, UPF and HTTP: each entry cross-references back to this page so you can walk the topic in either direction.

Related terms

Related topic hubs

  • SS7 Security SS7/MAP/CAP/SCCP attacks and defenses across 2G/3G interconnect.
  • Diameter Security 4G/LTE Diameter threats across IPX/roaming and DEA defenses.
  • 5G Security 5G SBA, SEPP, SUCI, 5G-AKA, N32 and service-based interface security.
  • 5G NEF Security Network Exposure Function security in the 5G core.

More from the TelcoSec Glossary

Browse the full TelcoSec Glossary, the Ultimate Guide to Mobile Network Security, or the P1 Arsenal of telecom-security tools.