Location-Aware NAS Timer Optimization in NTN-TN Integrated Networks Cheng Liu and Peng Hu*
arXiv:2607.21947v1 [cs.NI] 24 Jul 2026
Advanced Network and Embedded Systems Lab (AEL) Dept. of Electrical and Computer Engineering, University of Manitoba, Winnipeg, Canada [email protected], [email protected]
Abstract—Efficient Non-Access Stratum (NAS) timer configuration is critical for reliable and energy-efficient Fifth Generation (5G) registration in Non-Terrestrial Network (NTN)-Terrestrial Network (TN) integrated systems, where Low Earth Orbit (LEO) satellite access introduces large registration bursts, heterogeneous propagation paths, and multi-hop satellite routing. Existing 3GPP NAS timers use fixed values, while prior closed-form timer models compute a global timer under network-level assumptions; both fail to capture user equipment (UE)-level differences in propagation delay, Access and Mobility Management Function (AMF) arrival position, and path reliability. In this paper, we propose a location-aware, UE-specific NAS timer optimization method for LEO NTN-TN integrated networks. The proposed method models the path-delay component using service-link geometry, groundstation distance, and Inter-Satellite Link (ISL) hop count, and adapts the endpoint-delay component according to each UE’s expected AMF queue exposure and path reliability. Simulation results show that our method reduces registration latency, UE energy consumption, and avoidable registration attempts compared with fixed and global timer configurations, especially when timer over-provisioning causes unnecessary waiting. Index Terms—Low Earth Orbit satellite networks, NonTerrestrial Networks, Non-Access Stratum, 5G registration, Timer adaptation.
I. I NTRODUCTION Non-Terrestrial Networks (NTNs) are becoming an important component of future Fifth Generation (5G) and Sixth Generation (6G) systems [1], especially for extending service coverage to remote, maritime, aerial, and disaster-affected areas. In NTN-Terrestrial Network (TN) integrated systems, user equipments (UEs) may access the 5G core through Low Earth Orbit (LEO) satellites, ground stations (GSs), and terrestrial core network functions [2]. Before receiving network services, a UE must complete the Non-Access Stratum (NAS) registration procedure with the Access and Mobility Management Function (AMF) [3]. The efficiency of this procedure directly affects access latency, signaling overhead, and UE energy consumption. NAS timers play a key role in NTN-TN integrated 5G-andbeyond systems. During registration, timers such as T3510, T3550, and T3560 determine how long the UE or AMF waits for the expected NAS response before retransmission. We acknowledge the support provided by the Government of Canada, and the Natural Sciences and Engineering Research Council of Canada (NSERC), [funding reference number RGPIN-2022-03364].
If a timer is too short, delayed but valid responses may be treated as failures, causing unnecessary retransmissions and additional signaling load. If a timer is too long, the UE may wait excessively before detecting packet loss or procedure failure, increasing registration delay and energy consumption. This tradeoff is particularly challenging in LEO NTN-TN integrated networks because propagation delay, inter-satellite routing, access bursts, and packet loss vary significantly across UEs [4]. Existing 3rd Generation Partnership Project (3GPP) NAS timer values are fixed and simple to deploy, but they do not account for NTN-specific path heterogeneity. A UE close to a GS may reach the core network with few or no InterSatellite Link (ISL) hops, while another UE may traverse multiple ISLs before its NAS message exits the satellite constellation [5]. As a result, a single fixed timer may be overly conservative for short-path UEs and insufficient for long-path or queue-exposed UEs. Earlier work on NTN layer-2 (L2) timers has shown that round-trip variability requires reevaluating fixed configurations [6]. More recently, closed-form NAS timer models have been proposed for LEO constellations by incorporating link variability and processing delay [7]. However, when applied as global timer configurations, they still cannot fully capture UE-level differences in satellite path length, AMF arrival position, and path reliability. In this paper, we propose a location-aware NAS timer optimization method for NTN-TN integrated networks. The key idea is to preserve the efficiency of closed-form timer computation while making the timer value UE-specific. We model the path-delay component using service-link (SL) geometry and ISL hop count, so UEs with different satellite-to-GS paths receive different propagation budgets. We further adapt the endpoint-delay component according to each UE’s expected AMF queue exposure [8] and path reliability, allowing the timer to become more conservative only when a UE is likely to benefit from additional waiting. The main contributions of this paper are summarized as follows: •
We formulate UE-specific NAS timer sizing for LEO NTN-TN integrated networks by modeling the path-delay component from SL geometry, GS distance, and ISL hop count.
©2026 IEEE. Personal use of this material is permitted. Permission from IEEE must be obtained for all other uses, in any current or future media, including reprinting/republishing this material for advertising or promotional purposes, creating new collective works, for resale or redistribution to servers or lists, or reuse of any copyrighted component of this work in other works.
We design an adaptive endpoint-weighting mechanism that accounts for each UE’s expected AMF queue exposure and path reliability, reducing unnecessary timer overprovisioning while avoiding premature retransmissions. • We evaluate the proposed method through end-to-end NAS registration simulations and show that it reduces registration latency, UE energy consumption, and avoidable registration attempts compared with fixed and global timer configurations. •
The rest of the paper is structured as follows: Section II discusses the related work; Section III discusses the proposed methodology; Section IV presents the experimental results; and Section V concludes the paper and outlines the future work. II. R ELATED W ORK The integration of NTNs into 5G and beyond systems has attracted substantial attention as a means of delivering ubiquitous connectivity beyond the reach of terrestrial infrastructure [1], [9], [10]. Architectural studies have explored how LEO constellations can be coupled with the 5G core through transparent or regenerative payloads, ISLs, and ground gateways [2], [11], [12], highlighting that satellite access fundamentally differs from terrestrial access in propagation delay, link variability, and topological dynamics. To accommodate these effects, routing works on LEO constellations have investigated how hop count, link length, and queueing at intermediate satellites jointly shape end-to-end latency [4], [5], [13], showing that the satellite path traversed by a packet is highly UE-dependent rather than a single network-wide quantity. Mobility management studies further report that LEO geometry induces frequent handovers and signaling bursts that stress the control plane [14], [15]. These observations motivate revisiting control-plane procedures that were originally designed under terrestrial timing assumptions. Within the 5G control plane, NAS registration is the entrypoint procedure that governs UE access latency, signaling overhead, and energy consumption [3]. A series of studies has addressed the resulting signaling pressure from the corenetwork side: Alawe et al. [8] modeled the AMF as a queuing system and proposed control-theoretic load balancing and scale-out/scale-in policies to absorb registration bursts, while subsequent studies advocate stateless or distributed corenetwork designs for satellite so that registration signaling can be processed closer to the access edge [16]. Other proposals target the radio side, mitigating registration congestion through random-access preamble design and access-classbarring schemes adapted to NTN propagation [17]. These efforts focus on provisioning sufficient capacity for the signaling that does arrive at the AMF; however, the duration each UE waits for a NAS response before declaring failure is still controlled by NAS watchdog timers, which remain largely outside the scope of these studies. As a result, the interaction between the AMF queue formed under bursty access and the UE-side waiting policy is not directly addressed.
Serving Satellite
···
SL
LEO Satellite
LEO Satellite
Space Gateway
ISL
ISL
SL
Mid-distance UE
SL
FL
Near Gateway UE Ground Gateway
Remote UE
Core Network (CN) Other NFs
Data Network
AMF
SMF
UPF
Fig. 1: Architecture of an LEO satellite network.
Recent studies have examined timer configurations. The 3GPP NAS specification provides only scaled fixed values for satellite access, derived from MEO/GEO assumptions and inherited from terrestrial defaults; these values are conservative and uniform across UEs, and the standard explicitly leaves LEO-specific timer settings undefined [3]. At L2, Sheemar et al. [6] have shown that packet data convergence protocol (PDCP) discard, PDCP reordering, and radio link control (RLC) reassembly timers can be tightened in NTN by estimating the effective number of retransmissions rather than assuming the maximum numbers of lower-layer hybrid automatic repeat request (HARQ) and automatic repeat request (ARQ) retransmissions, improving throughput and buffer occupancy. While this confirms that fixed timers are wasteful under NTN propagation, L2 adjustments do not translate to the NAS layer, which spans the entire UE–AMF path and is exposed to ISL multi-hop routing and core-network queueing. Most recently, AstroTimer [7] introduced a closed-form NAS timer model for LEO constellations that outperforms 3GPP defaults by accounting for link variability, processing delays, and network-function placement. However, it computes a single global timer, failing to distinguish between UEs on short satellite paths and those traversing multiple ISL hops with AMF queuing delays. This global approach also ignores per-UE path reliability, potentially forcing UEs to wait unnecessarily for messages already lost in transit. To overcome the limitations of global timers, we formulate a UE-specific, location-aware NAS timer that jointly captures SL geometry, ISL hops, AMF queue exposure, and path reliability. This tailored approach mitigates registration inefficiencies while maintaining a lightweight, closed-form structure deployable in operational NTN-TN integrated networks. III. P ROPOSED M ETHODOLOGY In this section, we present the system model and the proposed location-aware NAS registration timer policy. A. Background and Problem Statement We consider a 3GPP-compliant NTN-TN integrated network consisting of UEs on the Earth surface, a Walker-delta LEO satellite constellation, GSs, and 5G core network functions. As
shown in Fig. 1, during NAS registration, signaling messages are delivered from a UE to its serving satellite, forwarded through zero or more ISLs, relayed through a GS and Feeder Link (FL), and finally processed by the AMF. The registration procedure is governed by NAS watchdog timers, including T3510 at the UE and T3550/T3560 at the AMF. Timer expiration triggers retransmission and may increase signaling load and UE energy consumption. We build on the closed-form NAS timer formulation introduced in AstroTimer [7], which decomposes a timer into a path-delay component and an endpoint-delay component: T = RP + γE, where R is the number of NAS message exchanges, P is the one-way path delay between the timer origin and responder, E is the weighted endpoint delay, and γ = ⌊R/2⌋ + 1 accounts for how endpoint delays are accumulated across the NAS exchange. The path-delay component is defined as ⟨0,1⟩ P = Dprp +
N −1 X
i ⟨i,i+1⟩ ⟨N −1,N ⟩ Dagg + Dprp + Dprp ,
B. UE-Specific Path Delay Modeling To account for spatial heterogeneity in LEO access, we first reformulate the path-delay component as a UE-specific quantity. For UE u, the one-way path from the UE to the AMF consists of an SL, a sequence of ISL hops, and an FL. We denote the resulting path-delay component by P (u) = DSL (u) + ku κDISL + DFL +
kX u +1
sat,m Dagg ,
m=1
where DSL (u) is the SL propagation delay, ku is the number of ISL hops, DISL is the per-hop ISL propagation delay, κ as a coefficient captures path inflation relative to the shortest sat,m geometric route, DFL is the FL propagation delay, and Dagg denotes the aggregated delay at the intermediate satellite nodes. The SL delay depends on the UE’s satellite elevation angle. Let h be the satellite altitude and c be the speed of light. We compute dslant (θeff (u), h) , DSL (u) = c where dslant (·) is the slant distance between the UE and its serving satellite. The effective elevation angle is defined as
i=1
θeff (u) = (1 − η)θmean (u) + ηθmin (u),
⟨i,i+1⟩
is the propagation delay between adjacent where Dprp i is the aggregated processing and queueing delay nodes, Dagg at the intermediate node i, and N is the number of hops between the timer origin and responder. The endpoint-delay component is given by 0 N E = αDagg + βDagg , 0 Dagg
N Dagg
denote the aggregated delay at the and where timer origin and responder, respectively, and α, β ∈ (0, 1] are endpoint weighting coefficients. While this closed-form formulation captures multi-hop propagation and burst-induced queueing delay, applying it with fixed path assumptions and fixed endpoint weights is insufficient for a large-scale LEO registration scenario. In this sense, UEs at different geographic locations may attach to different serving satellites and traverse different numbers of ISL hops before reaching a GS. Therefore, the path-delay component P is inherently UE-dependent rather than a single network-wide quantity. The endpoint-delay weight is also affected by LEO routing geometry. UEs with shorter satellite-to-GS paths reach the AMF earlier and contribute to the queue seen by later arrivals, while longer-path UEs arrive after both additional propagation and partial AMF service. A single global timer must therefore compromise between short-path and long-path UEs: it may expire prematurely for UEs with larger delay or queueing exposure, while over-provisioning UEs with shorter paths. This motivates a timer formulation that preserves the closed-form structure above while accounting for UE-specific path length, arrival position, and path reliability.
where θmean (u) and θmin (u) represent the average and minimum visible elevation conditions for UE u, and η controls how conservatively the model accounts for low-elevation access. Next, we estimate the ISL hop count from the UE’s distance to the nearest GS. Let ψ(u) = min dgc (u, g), g∈G
where G is the set of GSs and dgc (·) is the great-circle distance. Given a GS coverage radius rGS and an average inter-satellite spacing dsat , the ISL hop count is 0, ψ(u) ≤ rGS , ku = ψ(u) − rGS , ψ(u) > rGS . dsat This formulation turns the path-delay term from a single network-level value into a UE-dependent quantity. UEs near a GS obtain small ku and short P (u), while UEs far from any GS accumulate additional ISL propagation and intermediatenode delay. The resulting P (u) is then used as the path component in the NAS timer formulation. C. Adaptive Endpoint Weighting After obtaining the UE-specific path-delay component P (u), we adapt the endpoint-delay component to the queueing condition expected by each UE. For timer type j, the proposed NAS timer is 0 N Tj (u) = Rj P (u) + γj α(u) Dagg + Dagg , where Rj is the number of NAS message exchanges associated with timer j, γj = ⌊Rj /2⌋ + 1, and α(u) is a UE-specific
endpoint weighting coefficient. For simplicity, the same UEspecific coefficient is applied to both endpoint-delay terms. Under bursty registration load, the AMF-side term dominates the endpoint delay, so the adaptation is primarily governed by the UE’s expected AMF queue exposure. The coefficient α(u) is designed to capture the queueing exposure of UE u at the AMF. Since the dominant difference in AMF arrival time is induced by the ISL hop count, we approximate the relative arrival position of a UE by ku . Let C(ku ) = |{v ∈ U : kv ≤ ku }| be the number of UEs whose messages are expected to reach the AMF no later than UE u. During the time required for UE u to traverse its ISL path, the AMF can process part of the earlier burst. Therefore, the remaining queue observed by UE u is estimated as Q(ku ) = max (0, C(ku ) − µNF ku DISL ) , where µNF is the AMF service rate. We then normalize this queue estimate by the number of registering UEs: Q(ku ) . αpos (u) = min 1, |U| The factor αpos (u) increases when a UE is expected to encounter a larger residual AMF queue. However, queueing exposure alone should not always lead to a longer timer. In lossy LEO paths, a registration attempt may fail due to packet loss rather than late response arrival; in such cases, excessive timer extension only delays retransmission and failure detection. We therefore weight the queue-position factor by the reliability of the UE’s path. Let pSL , pISL , and pFL denote the loss probabilities of the SL, each ISL hop, and the FL. The probability that a one-way path from UE u reaches the AMF without packet loss is ppath (u) = (1 − pSL )(1 − pISL )ku (1 − pFL ). Using a fixed reference exchange count Rref = 5, we define the reliability weight as s(u) = ppath (u)2Rref . This term provides a conservative measure of path reliability. Finally, the adaptive endpoint coefficient is α(u) = α0 + max{0, αpos (u) − α0 }s(u). where α0 is a conservative lower bound. This coefficient has two useful implications. First, since s(u) ∈ [0, 1], the endpoint weight is always lower-bounded by α0 , preventing the timer from becoming more aggressive than the chosen baseline compensation. Second, as path reliability decreases, s(u) decreases and α(u) moves toward α0 ; therefore, the timer is not extended simply because a path is long when the registration attempt is unlikely to succeed due to packet loss. Additional conservativeness is applied only when the UE is both queue-exposed and likely to benefit from waiting longer for a delayed response.
TABLE I: Main simulation and timer-model parameters.
Parameter Value Nchain 14 Norb × Nspo 72 × 22 θel,min 25◦ rGS 1000 km DISL 16 ms CSL 2 Mbit/s µsat 3500 pkt/ms ρNF 0.8 α0 0.5 Amax 5 Pidle 20 mW
Parameter Value h 550 km i 53◦ η 0.3 κ 1.5 DFL 2 ms CISL = CFL 20 Gbit/s µNF 0.3 req/ms tbrs 1 ms Rref 5 ∆T 1 ms Pactive U[50, 75] mW
The computation is lightweight. For each registration batch, the method estimates the nearest GS and ISL hop count for each UE, groups UEs by hop count to compute C(k), and then evaluates the closed-form timer expression. The dominant cost is nearest-GS lookup, O(|U||G|), while the remaining steps are linear in |U|. IV. E XPERIMENTAL R ESULTS In this section, we evaluate the proposed UE-specific NAS timer adaptation method against 3GPP default timers and AstroTimer using NAS registration simulations under different UE loads and packet-loss settings. A. Experimental Setup We use a Python-based simulator of the main NAS registration exchanges between the UE and AMF, including T3510, T3550, and T3560. For satellite NG-RAN access, 3GPP specifies 27 s for T3510 and 11 s for T3550/T3560, these values form the 3GPP baseline. The simulated NTN–TN network comprises terrestrial UEs, a 14-satellite LEO relay chain, an FL to the gateway, and an AMF in the 5G core. The main experiments set Nchain = 14 to capture the multi-hop path variation inherent in dense LEO routing and to clearly expose its impact on timer performance. Tests conducted with shorter chains exhibited the same qualitative trends. Each UE is assigned to a serving satellite based on its estimated ISL hop distance to the gateway. All schemes use identical UE placement, routing, loss, AMF service, and energy settings. UEs initiate registration simultaneously and may make up to five attempts, with the configured waiting interval applied after each unsuccessful attempt. Table I summarizes the fixed parameters. Norb ×Nspo gives the Walker-shell geometry used for path estimation, while ρNF and tbrs denote the AMF load and burst window. Across experiments, |U | ∈ {3000, 4000, 5000} and ploss ∈ {0, 0.1, . . . , 0.5} are varied. B. Timer Configuration We first compare the timer values assigned by the three schemes before running the end-to-end registration procedure. The 3GPP baseline uses fixed NAS timer values specified for satellite access, i.e., T3510 = 27 s and T3550/T3560 = 11 s. AstroTimer computes one closed-form timer value for each
Mean registration length (s)
Algorithm:
3GPP
3000 UEs, loss 0%
AstroTimer
Proposed
4000 UEs, loss 0%
5000 UEs, loss 0%
80 60 40 20 0
2
3
4
5
8
Geometric ISL hops
2
3
4
5
8
Geometric ISL hops
2
3
4
5
8
Geometric ISL hops
Fig. 3: Mean registration length grouped by geometric ISL hop count under loss-free operation.
Fig. 2: CDF of registration length for 3GPP, AstroTimer, and the proposed method.
NAS timer under a given network load, and the same value is applied to all UEs. In contrast, the proposed method assigns UE-specific values for T3510, T3550, and T3560 according to each UE’s path delay and adaptive endpoint weight. C. Performance Metrics We evaluate the three timer schemes using registration length, UE energy consumption, and the number of registration attempts. Registration length measures the time from the first registration request to successful completion. UE energy consumption is accumulated over the registration period based on the UE idle and active power states. The number of registration attempts reflects the signaling overhead caused by timer expiration, packet loss, and repeated NAS retransmissions. 1) Registration length: Fig. 2 shows the CDF of registration length. In the loss-free setting, the proposed method consistently shifts the CDF to the left compared with AstroTimer. The mean registration length is reduced by 20.5%, 21.5%, and 22.0% for 3000, 4000, and 5000 UEs, respectively. This indicates that UE-specific timer assignment avoids the unnecessary waiting introduced by a single global timer. As packet loss increases, the gap becomes smaller because registration delay is increasingly dominated by failed transmissions and repeated attempts. Under these lossy settings, the proposed method remains comparable to AstroTimer while avoiding the severe degradation observed with fixed 3GPP timers under heavy load. Fig. 3 shows the loss-free registration length grouped by geometric ISL hop count. For low-hop UEs (2–4 hops), the proposed method and AstroTimer have the same registration
Fig. 4: CDF of UE energy consumption for 3GPP, AstroTimer, and the proposed method.
length because both complete registration in one attempt; the benefit of UE-specific timer adaptation becomes more apparent as the ISL hop count increases. At hop 5, the proposed method reduces mean registration length over AstroTimer by 18.9%, 20.7%, and 21.8% for 3000, 4000, and 5000 UEs, respectively. At hop 8, the reductions are 42.5%, 42.6%, and 42.7%. In contrast, 3GPP succeeds only for 45 UEs at 4000 UEs and fails to complete any registration at 5000 UEs. 2) UE energy consumption: Fig. 4 reports the CDF of UE energy consumption. The proposed method reduces mean energy consumption by 10.5%, 11.2%, and 11.5% over AstroTimer in the loss-free setting for 3000, 4000, and 5000 UEs, respectively. The gain comes from reducing over-provisioned waiting time without introducing extra retransmissions. Under packet loss, the energy gap narrows as retransmissions dominate UE active time, but the proposed method remains generally comparable to AstroTimer.
V. C ONCLUSION In this paper, we proposed a UE-specific NAS timer adaptation method for LEO satellite networks. We modeled the timer path component using SL geometry and ISL hop count, and adapted the endpoint-delay component according to each UE’s expected AMF queue exposure and path reliability. Through simulation, we showed that our method reduces registration latency, UE energy consumption, and avoidable registration attempts compared with fixed and global timer configurations, particularly when timer over-provisioning is a major source of inefficiency. Future work may explore dynamic satellite mobility, time-varying registration bursts, and online estimation of path reliability in operational NTN deployments. R EFERENCES
Fig. 5: CDF of registration attempts for 3GPP, AstroTimer, and the proposed method.
Mean registration attempts
Algorithm:
3GPP
3000 UEs, loss 0%
AstroTimer
Proposed
4000 UEs, loss 0%
5000 UEs, loss 0%
4
2
0
2
3
4
5
8
Geometric ISL hops
2
3
4
5
8
Geometric ISL hops
2
3
4
5
8
Geometric ISL hops
Fig. 6: Mean registration attempts grouped by geometric ISL hop count under loss-free operation.
3) Registration attempts: Fig. 5 shows the CDF of registration attempts per UE. Without packet loss, the proposed method completes all registrations in a single attempt across all tested UE loads, whereas AstroTimer still causes a fraction of UEs to retransmit. This confirms that per-UE timer sizing reduces avoidable retransmissions caused by path heterogeneity and AMF queueing. At high packet-loss rates, all schemes require more attempts, indicating that retransmissions are then dominated by packet drops rather than timer configuration. Fig. 6 reports the mean registration attempts by geometric ISL hop count under 0% packet loss. The proposed method completes all UEs in one attempt across all hop groups and UE loads. AstroTimer also needs one attempt for hops 2–4, but requires 1.27–1.32 attempts at hop 5 and 2.00 attempts at hop 8. The 3GPP baseline reaches nearly the retry limit under heavier load: at 4000 UEs it requires 4.87 attempts at hop 2 and 5.00 attempts for hops 3–8, while at 5000 UEs it requires 5.00 attempts for every hop group.
[1] G. Araniti, A. Iera, S. Pizzi et al., “Toward 6g non-terrestrial networks,” IEEE Network, vol. 36, no. 1, pp. 113–120, 2021. [2] 3GPP, “Solutions for NR to support non-terrestrial networks (NTN),” 3rd Generation Partnership Project, Technical Report 3GPP TR 38.821, Mar. 2023, version 16.2.0, Release 16. [3] ——, “Non-access-stratum (NAS) protocol for 5G system (5GS); stage 3,” 3rd Generation Partnership Project, Technical Specification 3GPP TS 24.501, Mar. 2026, version 19.6.2, Release 19. [4] B. Soret, I. Leyva-Mayorga, F. Lozano-Cuadra et al., “Q-learning for distributed routing in leo satellite constellations,” in 2024 IEEE International Conference on Machine Learning for Communication and Networking (ICMLCN). IEEE, 2024, pp. 208–213. [5] C. Wu, S. Han, Q. Chen et al., “Enhancing LEO mega-constellations with inter-satellite links: Vision and challenges,” IEEE Wireless Communications, vol. 32, no. 5, pp. 196–202, Oct. 2025. [6] C. K. Sheemar, S. Kumar, J. Querol et al., “Adaptive timers and buffer optimization for layer-2 protocols in 5g non-terrestrial networks,” in 2023 International Conference on Software, Telecommunications and Computer Networks (SoftCOM), 2023, pp. 1–6. [7] A. R. Hezaveh and P. Hu, “AstroTimer: Rethinking non-access stratum timers in LEO constellations,” in 2026 IEEE International Conference on Communications (ICC), Glasgow, Scotland, UK, 2026. [8] I. Alawe, Y. Hadjadj-Aoul, A. Ksentini et al., “On the scalability of 5g core network: The amf case,” in 2018 15th IEEE Annual Consumer Communications & Networking Conference (CCNC), 2018, pp. 1–6. [9] F. Wang, S. Zhang, H. Yang et al., “Non-terrestrial networking for 6G: Evolution, opportunities, and future directions,” Engineering, vol. 54, pp. 56–68, Nov. 2025. [10] M. A. Jamshed, A. Kaushik, S. Manzoor et al., “A tutorial on nonterrestrial networks: Towards global and ubiquitous 6g connectivity,” Foundations and Trends in Networking, vol. 14, pp. 160–253, 2025. [11] S. Yuan, M. Peng, and Y. Sun, “Satellite-terrestrial integrated fog networks: Architecture, technologies, and challenges,” IEEE Wireless Communications, vol. 32, no. 4, pp. 208–215, Aug. 2025. [12] B. Di, H. Zhang, L. Song et al., “Ultra-dense leo: Integrating terrestrialsatellite networks into 5g and beyond for data offloading,” IEEE Transactions on Wireless Communications, vol. 18, no. 1, pp. 47–62, 2018. [13] J. W. Rabjerg, I. Leyva-Mayorga, B. Soret et al., “Exploiting topology awareness for routing in LEO satellite constellations,” in 2021 IEEE Global Communications Conference (GLOBECOM). Madrid, Spain: IEEE, Dec. 2021, pp. 1–6. [14] B. Zhang, P. Hu, A. A. Azirani et al., “Secure and efficient group handover protocol in 5g non-terrestrial networks,” in ICC 2024-IEEE International Conference on Communications, 2024, pp. 5063–5068. [15] E. Juan, M. Lauridsen, J. Wigard et al., “Handover solutions for 5g lowearth orbit satellite networks,” IEEE Access, vol. 10, pp. 93 309–93 325, 2022. [16] Y. Liu, L. Wang, Z. Lu et al., “A stateless design of satellite–terrestrial integrated core network and its deployment strategy,” IEEE Transactions on Network and Service Management, vol. 21, no. 1, pp. 953–966, 2023. [17] H. Chougrani, S. Kisseleff, W. A. Martins et al., “NB-IoT random access for nonterrestrial networks: Preamble detection and uplink synchronization,” IEEE Internet of Things Journal, vol. 9, no. 16, pp. 14 913–14 927, Aug. 2022.