Timer Dictionary (Timer)¶
A dictionary for looking up the main 5GC timers involved in registration, authentication, session management, and mobility by their start trigger, stop trigger, behavior on timeout, and related procedures. Many are NAS (5GMM / 5GSM) timers run as a pair by the UE and AMF, specified in the timer tables of 3GPP TS 24.501 §10.2.
Related: Message Dictionary / Cause Dictionary / NAS Dictionary / Registration chapter / Mobility Registration Update / Periodic Registration Update
This dictionary does not assert timer values (seconds)
The specific value (default seconds) of each timer depends on the spec default plus the network configuration (the AMF may distribute values via broadcast or within an Accept). This dictionary focuses on indexing the number, trigger, role, and related procedures, and in principle treats the seconds as "to be confirmed" (implementation-dependent / operational configuration). For exact default values and conditions, refer to the timer tables in TS 24.501 §10.2. Uncertain correspondences between number and purpose are also not asserted and are marked to be confirmed.
How to Read Timers (Map of Classification)¶
The NAS timers of 5GC can be broadly organized as follows.
- Procedure timers — Run only while waiting for a response after sending a message of a procedure. Typically retransmit on expiry and abort at the limit (e.g., T3510, T3550, T3560). Which side (UE or AMF) runs it is important.
- State-maintenance / periodic timers — Run on a relatively long cycle to confirm UE liveness or maintain reachability (e.g., T3512 periodic registration update, mobile reachable / implicit deregistration monitoring).
- Backoff / retry timers — Run while the UE refrains from retrying on failure or congestion (e.g., T3511 retry wait, T3346 congestion backoff).
Below, the main timers are shown by category. The start/stop triggers and expiry behavior are a general organization based on TS 24.501 §10.2, and the seconds are to be confirmed.
Registration (Registration / 5GMM) Related Timers¶
| Timer | Location | Start Trigger | Stop Trigger | Behavior on Timeout | Related Procedure | Spec |
|---|---|---|---|---|---|---|
| T3510 | UE (5GMM) | On sending Registration Request | On receiving Registration Accept / Reject | Retransmit; abort the procedure when the limit is reached | Registration | TS 24.501 §10.2 |
| T3550 | AMF (5GMM) | On sending Registration Accept | On receiving Registration Complete | Retransmit Registration Accept (treat as complete/release at the limit) | Registration | TS 24.501 §10.2 |
| T3511 | UE (5GMM) | When the registration procedure fails (due to an anomaly, etc.) and waits to retry | On starting re-registration / resolution of the condition | On expiry, attempt re-registration | Registration | TS 24.501 §10.2 |
| T3512 | UE (5GMM) | Timing the periodic registration update cycle (started/restarted after registration is accepted) | Restarted on completion of the next registration procedure | On expiry, invoke Periodic Registration Update (periodic registration update) | Periodic Registration Update | TS 24.501 §10.2 |
Positioning of T3512 (Periodic Registration Update Timer)
T3512 is the timer that measures the cycle of the periodic registration update by which the UE notifies the network of its liveness at a fixed interval. Because the value may be communicated by the AMF to the UE via Registration Accept, etc. (implementation/operation-dependent), this dictionary does not assert the seconds. It corresponds to the 4G periodic TAU timer T3412 (see "4G (EPC) Correspondence" below).
Authentication / Security (5GMM) Related Timers¶
| Timer | Location | Start Trigger | Stop Trigger | Behavior on Timeout | Related Procedure | Spec |
|---|---|---|---|---|---|---|
| T3560 | AMF (5GMM) | On sending Authentication Request / Security Mode Command | On receiving the corresponding response (Authentication Response / Security Mode Complete, etc.) | Retransmit the relevant message (abort at the limit) | Authentication / Security | TS 24.501 §10.2 |
T3560 is used in both the authentication and security procedures
T3560 is used to wait for responses to 5GMM procedures where the AMF sends to the UE and waits for a response, such as Authentication Request and Security Mode Command. For the detailed target messages and conditions, refer to TS 24.501 §10.2 (to be confirmed).
Service Request / Configuration Update (5GMM) Related Timers¶
| Timer | Location | Start Trigger (general organization) | Behavior on Timeout | Related Procedure | Spec |
|---|---|---|---|---|---|
| T3517 | UE (5GMM) | Waiting for a response when sending Service Request | Retransmit / abort at the limit | Service Request | TS 24.501 §10.2 (to be confirmed) |
| T3520 | UE (5GMM) | Retransmission/retry control related to authentication (during the Authentication procedure) | Retry / interrupt the procedure | Authentication | TS 24.501 §10.2 (to be confirmed) |
| T3521 | UE (5GMM) | Waiting for a response when sending De-registration Request | Retransmit De-registration Request / treat as complete at the limit | De-registration procedure | TS 24.501 §10.2 (to be confirmed) |
| T3540 | UE (5GMM) | While waiting for connection release after the procedure completes | On expiry, allow release of the NAS signaling connection | Connection management (CM) | TS 24.501 §10.2 (to be confirmed) |
| T3570 | UE (5GMM) | Configuration/Notification response control (waiting for a configuration update response, etc.) | Retransmit / interrupt the procedure | Generic UE Config Update | TS 24.501 §10.2 (to be confirmed) |
The triggers and purposes in the table above are to be confirmed
The exact start/stop triggers, target messages, and expiry behavior of T3517/T3520/T3521/T3540/T3570 differ by Release, and the correspondence between number and purpose is also to be confirmed. Here, only a rough positioning within the framework of TS 24.501 §10.2 is presented. For precise details, refer to each timer table.
Session Management (5GSM) Related Timers¶
Session management (establishment/modification/release of PDU Session) also specifies a group of UE-side 5GSM timers (such as the T3580 series). The typical use is retransmission control while sending a PDU Session Establishment/Modification/Release Request and waiting for a response.
| Timer | Location | General Role | Related Procedure | Spec |
|---|---|---|---|---|
| 5GSM timer group (T358x series) | UE (5GSM) | Waiting for responses to PDU Session establishment/modification/release requests and retransmission control | PDU Session / PDU Session Modification/Release | TS 24.501 §10.3 (to be confirmed) |
The individual numbers of the 5GSM timers are to be confirmed
The individual number assignments, values, and expiry behavior of the 5GSM timers are specified in TS 24.501 §10.3, but because the number details differ by Release, this dictionary treats them as to be confirmed and avoids asserting individual numbers. For the flow of the session management procedures, refer to the PDU Session chapter.
Reachability / Congestion (Network/UE) Related Timers¶
| Timer | Location | General Role | On Timeout / Expiry | Spec |
|---|---|---|---|---|
| Mobile reachable timer | AMF | Monitors the reachability of a registered UE (restarted on receiving a periodic registration update) | On expiry, considers the UE unreachable and transitions to the monitoring stage | TS 24.501 / TS 23.501 (§ to be confirmed) |
| Implicit de-registration timer | AMF | After the mobile reachable timer expires, monitors whether there is no further contact from the UE for an additional period | On expiry, implicit de-registration (implicit de-registration and resource release) | TS 24.501 / TS 23.501 (§ to be confirmed) |
| T3346 | UE (5GMM) | Backoff due to congestion control (backoff value attached to a Reject) | Refrains from retrying the relevant procedure until expiry | TS 24.501 §10.2 (to be confirmed) |
Relationship between periodic registration update and implicit de-registration
When the UE sends a periodic registration update (triggered by T3512 expiry), the AMF-side mobile reachable timer is restarted. If the UE does not send an update and the timers expire in the order mobile reachable → implicit de-registration, the AMF implicitly de-registers the UE (releases resources). This is the flow of "update lapse → implicit de-registration." Details of each timer's values and relationships are to be confirmed (TS 24.501 / TS 23.501).
The figure below shows this T3512 → (update lapse) → mobile reachable → implicit de-registration timer chain in chronological order. The left is normal (the update arrives and restarts), and the right is a lapse (the timers expire in order and cause implicit de-registration).
sequenceDiagram
autonumber
participant UE
participant AMF
Note over UE,AMF: [Normal case] the UE periodically signals it is alive
Note over UE: Start T3512 (after registration is accepted)
Note over UE: … T3512 expires …
UE->>AMF: Periodic Registration Update
Note over AMF: Restart the mobile reachable timer
AMF-->>UE: Registration Accept
Note over UE: Restart T3512 (repeat the cycle)
Note over UE,AMF: [Loss-of-contact case] when updates stop arriving from the UE
Note over UE: (out of coverage, powered off, etc.)
cannot send updates
Note over AMF: mobile reachable timer expires
→ regard the UE as "unreachable"
Note over AMF: Then start the implicit de-registration timer
Note over AMF: implicit de-registration timer expires
→ implicit de-registration (release resources)
How to Read the Figure
In the normal case, each time the UE's T3512 (periodic registration update timer) expires, it sends a Periodic Registration Update, and the AMF, upon receiving it, restarts the mobile reachable timer (liveness confirmation keeps being refreshed). In the lapse case, if the UE cannot send an update due to being out of coverage, etc., the two stages mobile reachable timer → implicit de-registration timer expire in order on the AMF side, and ultimately the AMF implicitly de-registers the UE and releases resources. In other words, the "UE-side periodic timer (T3512)" and the "AMF-side two-stage monitoring timers" mesh together to manage UE liveness. The seconds and conditions of each timer are to be confirmed (TS 24.501 / TS 23.501).
Positioning of RAN/RRC and SBI Series Timers (Delineation from NAS Timers)¶
The main focus of this dictionary is NAS (5GMM/5GSM) timers, but to avoid confusion, the positioning of timers in adjacent domains is also shown.
- RAN/RRC timers (a separate series from T3xx) — For RRC Resume / Small Data and radio connection management, there are separately RRC-layer timers (management of RRC_INACTIVE, RAN Notification Area update cycle, etc.). These are radio (RAN)-centric, specified in TS 38.331 (RRC), etc., and are a separate series from NAS T3xxx (individual values to be confirmed).
- SBI (HTTP/2) series timeouts — Inter-NF SBI communication (HTTP/2 over TLS) also has request-response timeouts and retransmissions, but these are HTTP/2 / transport-layer implementation and operational parameters, and are distinct from NAS timers (implementation-dependent).
First distinguish 'which layer's timer' it is
When investigating a timer, first distinguishing which layer it is — NAS (UE⇔AMF, T3xxx) / RRC (radio, TS 38.331) / SBI (inter-NF, HTTP/2) — avoids confusion. This dictionary focuses primarily on the NAS layer.
4G (EPC) Correspondence¶
Many of 5G's NAS timers correspond in concept to 4G (EPS) EMM/ESM timers (the numbering systems are close but not necessarily identical; details are to be confirmed).
| 5G (5GMM/5GSM) | 4G (EMM/ESM) | Corresponding Concept |
|---|---|---|
| T3510 (waiting for Registration Request response) | T3410 (waiting for Attach Request response) | Waiting for a registration/attach request response |
| T3550 (Registration Accept retransmission) | T3450 (Attach/TAU Accept retransmission) | Retransmission of the acceptance message |
| T3512 (periodic registration update) | T3412 (periodic TAU) | Periodic liveness notification |
| T3560 (waiting for Auth/SMC response) | T3460 (waiting for Auth/SMC response) | Waiting for an authentication/security response |
| Implicit de-registration timer | Implicit detach timer | Implicit release when contact lapses |
The match of numbers is not guaranteed
5G's T35xx and 4G's T34xx/T3xxx correspond in role, but the numbers, values, and conditions do not necessarily match exactly. For individual correspondences and values, treat each TS (5G = TS 24.501, 4G = TS 24.301) as to be confirmed.
3GPP Specification (References)¶
- TS 24.501 §10.2 — 5GMM timer tables (T3510/T3511/T3512/T3517/T3520/T3521/T3540/T3550/T3560/T3570/T3346, etc.). The main basis of this dictionary. For individual values and conditions, refer to each table.
- TS 24.501 §10.3 — 5GSM timers (related to PDU Session procedures, T358x series). Individual numbers are to be confirmed.
- TS 23.501 / TS 23.502 — Positioning of AMF-side reachability monitoring such as mobile reachable / implicit de-registration (§ to be confirmed).
- TS 38.331 — RRC-layer timers (a separate series from NAS).
- TS 24.301 — 4G (EPS) EMM/ESM timers (for correspondence comparison).
The Scope of Assertion in This Dictionary
What this dictionary asserts is up to the timer number and its procedural role (the framework of start/stop triggers and retransmit/abort on expiry). Specific seconds, Release-dependent number assignments, and fine-grained conditional branches are not fabricated and are marked to be confirmed / implementation-dependent. For accurate operational values, check the target network's configuration and the relevant Release of the applicable TS.