> For the complete documentation index, see [llms.txt](https://docs.gxc.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.gxc.io/glossary.md).

# Glossary

This glossary defines terms commonly used across GXC’s product interfaces and documentation.

***

### 0-9

#### 3GPP

**3rd Generation Partnership Project** – A global collaboration of regional standards organizations responsible for developing and maintaining specifications for mobile communication technologies, including 3G, 4G LTE, and 5G. 3GPP ensures interoperability and consistency across global cellular networks.

#### 4G

**4th Generation Cellular** – A mobile communication standard developed by 3GPP that offers higher data speeds, lower latency, and improved spectral efficiency compared to 3G. Technologies under 4G include LTE and LTE-Advanced.

#### 5G

**5th Generation Cellular** – The latest mobile communication standard developed by 3GPP, designed to provide ultra-high data rates, low latency, massive device connectivity, and support for emerging use cases such as autonomous systems, IoT, and immersive media.

#### 5G Core

GXC’s embedded 5G Core platform, supporting 5G SA architecture with core functions including AMF, SMF, UPF, and UDM. It delivers high-throughput, low-latency performance and enables edge computing, session management, and scalable service delivery for private 5G networks.

***

### A

#### ACS

**Auto-Configuration Server** – Manages AP configuration and prioritization in Onyx Edge Pools.

#### AES

**Advanced Encryption Standard** – A symmetric encryption algorithm widely used in GXC networks for securing user traffic, signaling, and configuration data. AES is recognized for its strong security and efficiency, supporting key sizes of 128, 192, or 256 bits.

#### AGL

**Above Ground Level** - The height of an antenna measured relative to the ground directly beneath the installation site.

#### agw\_user

A limited-privilege user account in the Onyx Edge server, used by GXC partner and customer administrators to collect logs, restart services, restore factory settings, etc.

#### AKA

**Authentication and Key Agreement** – A mutual authentication protocol used primarily in mobile networks. AKA ensures that both the UE and the network can verify each other's identity, establishing shared cryptographic keys to secure communication.

#### Alert

A real-time notification in the Onyx Portal triggered by alert rules. Alerts are categorized by severity (Critical, Major, Minor, Other) and are used to monitor system health, troubleshoot issues, and maintain network performance.

#### Alert Counter Panel

An interface element in the Onyx Portal that displays real-time, color-coded counts of active Critical, Major, Minor, and Other alerts.

#### Alert Mute Rule

A user-defined rule in the Onyx Portal that temporarily suppresses alert email notifications based on severity, type, or equipment to prevent notification fatigue during planned maintenance or debugging windows.

#### Alert Receiver

A user or system configured to receive email notifications when Onyx Portal alert rules are triggered.

#### Alert Rule

A GXC-defined rule in the Onyx Portal to monitor specific network metrics or behaviors and trigger an alert when a condition is met.

#### AMF

**Access and Mobility Function** – The 5G Core function responsible for managing user access, mobility events, and signaling between devices and the network.

#### ANR

**Automatic Neighbor Relation** – A self-optimizing network feature that automates the detection and management of neighbor cells. ANR helps maintain accurate neighbor lists for handovers, improving mobility performance and reducing manual configuration.

#### AMSL

**Above Mean Sea Level** - The height of an antenna or location measured relative to mean sea level.

#### AP

**Access Point** – GXC equipment that provides 4G or 5G radio access to UE. In 4G networks, the AP integrates radio and baseband processing functions. In 5G networks, the AP role is fulfilled by an RU in a disaggregated RAN architecture, where RF functions are separated from control and user plane functions.

#### APN

**Access Point Name** – A network identifier used by UE to connect to an external PDN, such as the internet or an enterprise LAN. In GXC deployments, the APN also specifies routing and QoS rules.

#### APN-Mapped VLANs

VLAN segmentation mapped to specific APNs, used for isolating device traffic and applying granular access policies.

#### Application Group

A logical collection of user-defined applications for traffic shaping, prioritization, and [*QoS*](#qos) control within the GXC network.

#### ARP

**Allocation and Retention Priority** – [*QoS*](#qos) parameter that influences bearer setup and prioritization under network load.

#### Authorized State

A [*CBSD*](#cbsd) state indicating that the [*SAS*](#sas) has granted spectrum access and authorized the CBSD to transmit.

#### AWS

**Amazon Web Services** – A cloud platform used to deploy GXC services.

#### AWS GuardDuty

[*AWS*](#aws) threat detection service monitoring for anomalies and malicious activity in Onyx infrastructure.

#### AWS KMS

**AWS Key Management Services** – [*AWS*](#aws)-managed service for creating, managing, and using cryptographic keys to secure stored data.

***

### B

#### Backhaul

The communication link that transports user and control plane traffic between the [*Onyx Edge (Core)*](#onyx-edge-core-only) and [*RAN*](#ran) elements such as [*APs*](#ap) or [*FHMs*](#fhm). GXC supports both wired and wireless backhaul options, including LTE Mesh.

#### Bcrypt

A password hashing function designed to be computationally intensive, making brute-force attacks more difficult. Bcrypt automatically incorporates a salt and allows configurable complexity (cost), helping protect stored credentials from rainbow table and brute-force attacks.

#### BPF

**Band Pass Filter** – Device that allows selected frequency bands to pass while blocking others—used in [*DAS*](#das) for spectrum isolation.

#### BRF

**Band Reject Filter** – Filter that blocks specific frequency bands to reduce interference in shared [*DAS*](#das) environments.

#### BTS-CBSD

**Base Transceiver Station CBSD** – Fixed [*CBSD*](#cbsd) base station that provides wireless connectivity to end-user devices and CPE-CBSDs in [*CBRS*](#cbrs) deployments.

***

### C

#### CA

**Carrier Aggregation** – An [*AP*](#ap) transmission mode that combines multiple carriers (contiguous or non-contiguous) across the same or different frequency bands to increase bandwidth, enhance data rates, and optimize spectrum usage in GXC networks.

#### CA Certificate

**Certificate Authority Certificate** - A digital certificate used to verify the authenticity of certificates presented by trusted systems and services.

#### CAPTCHA

**Completely Automated Public Turing test to tell Computers and Humans Apart** – A challenge-response test used to determine whether the user is a human or an automated bot. [*reCAPTCHA*](#recaptcha), a variant helps protect login and registration interfaces from automated abuse by requiring Onyx Portal users to perform tasks that are easy for humans but difficult for machines.

#### Category A CBSD

<30 dBm/10 MHz CBSD – Low-power [*CBSD*](#cbsd) with transmit power under 30 dBm per 10 MHz; suitable for indoor or limited-range deployments.

#### Category B CBSD

<47 dBm/10 MHz CBSD – High-power [*CBSD*](#cbsd) capable of up to 47 dBm per 10 MHz; typically used for wide-area or outdoor coverage.

#### CBRS

Citizens Broadband Radio Service – A shared spectrum band (3550–3700 MHz) in the U.S., used for private 4G and 5G networks.

#### &#xD;CBRS-NID

**CBRS Network ID** – A unique identifier used to distinguish private networks operating within the [*CBRS*](#cbrs) band. In GXC deployments, the CBRS-NID is typically configured in APs and other [*CBSDs*](#cbsd) to associate them with the correct network instance, enabling [*SAS*](#sas) registration, policy enforcement, and operational segmentation.

#### &#xD;CBSD

**Citizens Broadband Radio Service Device** – A device authorized under [*FCC*](#fcc) rules to transmit in the CBRS band (3550–3700 MHz). In GXC networks, [*CBSDs*](#cbsd) include both [*BTS-CBSDs*](#bts-cbsd) (acting as fixed base stations) and [*CPE-CBSDs*](#cpe-cbsd) (fixed end-user devices). All CBSDs must register with the [*SAS*](#sas) and comply with dynamic frequency coordination requirements to prevent interference and ensure regulatory compliance.

#### CBSD Installation Parameters

The location, antenna, and deployment information required to register a [*CBSD*](#cbsd) with the [*SAS*](#sas).

#### CBSD Operational Parameters

Radio operating settings submitted to the [*SAS*](#sas), such as frequency range, bandwidth, and transmit power.

#### CBSD Registered State

A [*CBSD*](#cbsd) state indicating that registration with the [*SAS*](#sas) has been successfully completed.

#### CBSD Registration Request

A [*SAS*](#sas) request used to register a [*CBSD*](#cbsd) and establish its operational record.

#### Cell

A defined coverage area within a mobile network served by one or more [*RUs*](#ru). In GXC deployments, a cell may include multiple RUs operating under a single [*DU*](#du), especially in [*Shared Cell*](#shared-cell) configurations, enabling seamless coverage and mobility.

#### Cell ID

A unique identifier assigned to each [*Cell*](#cell) in a mobile network. [*UE*](#ue) use the Cell ID to distinguish between different cells for registration, handovers, and mobility management. In GXC’s [*Shared Cell*](#shared-cell) architecture, all [*RUs*](#ru) within a shared deployment share the same Cell ID to eliminate intra-site handovers.

#### Center Frequency

The frequency at the midpoint of a radio channel or spectrum allocation.

#### Channel

A defined range of radio frequencies used for wireless communication.

#### CLI

**Command-Line Interface** – A text-based interface used to configure, monitor, and manage the [*Onyx Edge*](#onyx-edge). Accessible via [*SSH*](#ssh), the CLI complements the GUI-based [*Onyx Portal*](#onyx-portal) and is used in scenarios requiring direct system access.

#### Client Certificate

A digital certificate used to authenticate a device or application when establishing a secure connection.

#### C-Plane

**Control Plane** – The signaling layer of the network that manages session establishment, mobility, handovers, and authentication between the Core and [*UE*](#ue). In GXC deployments, the C-Plane is handled by the [*CU*](#cu) and the core functions hosted on the [*Onyx Edge*](#onyx-edge), ensuring reliable network coordination and policy enforcement.

#### CPE

**Customer Premise Equipment** – On-site network equipment, such as routers and modems, that connect end users to the provider’s core or access network.

#### CPE-CBSD

Fixed [*CBSD*](#cbsd) that functions as a non-mobile [*UE*](#ue), typically with higher transmit power than standard end-user devices, exceeding EUD power limits.

#### CPI

**Certified Professional Installer** – A technician certified under [*FCC*](#fcc) requirements to register [*CBSDs*](#cbsd) with the [*SAS*](#sas). The CPI is responsible for providing accurate deployment data such as device location, antenna height, gain, and installation parameters to ensure regulatory compliance in [*CBRS*](#cbrs) networks. GXC deployments rely on CPI-verified installations for [*SAS*](#sas) approval and operation.

#### CPRI

**Common Public Radio Interface** – Legacy interface standard for connecting baseband units to [*RUs*](#ru). Largely replaced by [*eCPRI*](#ecpri) in 5G deployments for better bandwidth and latency performance.

#### CSV

**Comma-Separated Values** – A plain-text file format in which each line represents a data record with comma-separated values—widely used by [*Onyx Portal*](#onyx-portal) for data import/export.

#### CU

**Central Unit** – A higher-layer 5G RAN component that handles control and user plane functions such as [*RRC*](#rrc), mobility management, session control, and data forwarding. Integrated into the Onyx Edge, the CU works in tandem with the [*DU*](#du) to deliver scalable, low-latency private 5G services.

#### CU-CP

**Central Unit-Control Plane** – In 5G networks, the control plane component of the CU, responsible for managing [*RRC*](#rrc), signaling, handovers, mobility, and session establishment.

#### Customer

An end-user organization using a GXC Onyx Private Cellular Network for its enterprise connectivity needs. Customers can manage their network directly via the Onyx Portal or work with a GXC partner for managed services.

#### CU-UP

**Central Unit-User Plane** – In 5G networks, the user plane component of the CU responsible for forwarding user data traffic, packet routing, QoS enforcement, and buffering.

***

### D

#### DAS

**Distributed Antenna System** – A network of spatially separated antennas connected to a common signal source, designed to improve wireless coverage within large or complex environments. In GXC deployments, DAS supports both passive and active configurations, enabling shared infrastructure for public and private cellular services using filters, diplexers, and SAS-registered RUs.

#### Dashboard

A real-time display in the Onyx Portal that presents network-level metrics and operational status for traffic, equipment, and subscribers.

#### dBi

**Decibels Relative to Isotropic Radiator** – A unit of measurement for antenna gain relative to a theoretical isotropic radiator that radiates power equally in all directions. Higher dBi values indicate more directional antennas.

#### dBm

**Decibel-milliwatts** – Unit of power relative to 1 milliwatt. In wireless networks, dBm is used to express signal strength, transmit power, and receiver sensitivity. For example, a signal strength of -50 dBm is stronger than -80 dBm.

#### DC

**Dual Carrier** – An AP transmission mode in which an AP simultaneously transmits on two frequency carriers, improving throughput and reliability.

#### Default Network

The currently selected network instance in the Onyx Portal that determines which data is displayed across all Onyx Portal screens.

#### Default Network Selector

An interface element in the Onyx Portal that allows users to choose the default network to operate in.

#### DHE

**Diffie–Hellman Ephemeral** – A key exchange protocol using temporary keys for each session, ensuring forward secrecy in TLS communications.

#### DHCP

**Dynamic Host Configuration Protocol** – A network management protocol that automatically assigns IP addresses and other configuration parameters—such as subnet mask, gateway—to UE on a network, enabling them to communicate effectively.

#### DL

**Downlink** – Transmission from network to UE.

#### DNS

**Domain Name System** – Internet system that resolves domain names to IP addresses.

#### DP

**Domain Proxy** – An Onyx Portal module that handles communication with the [*SAS*](#sas) on behalf of [*CBSDs*](#cbsd) for dynamic frequency management.

#### DU

**Distributed Unit** – A lower-layer 5G [*RAN*](#ran) component responsible for real-time baseband processing functions including MAC and physical layer operations. Integrated into the [*Onyx Edge*](#onyx-edge), the DU connects to multiple [*RUs*](#ru) over the fronthaul interface. It works in tandem with the [*CU*](#cu) as part of GXC’s disaggregated RAN architecture.

***

### E

#### EARFCN

**E-UTRA Absolute Radio Frequency Channel Number** – Identifies LTE radio carriers with a specific frequency.

#### ECDHE

**Elliptic Curve Diffie–Hellman Ephemeral** – A key exchange method that provides forward secrecy for TLS sessions by generating temporary keys based on elliptic curve cryptography.

#### eCPRI

**Enhanced Common Public Radio Interface** – An improved version of [CPRI](#cpri) with better performance for 5G [fronthaul](#fronthaul).

#### EEA2

**EPS Encryption Algorithm 2** – A 4G LTE confidentiality algorithm based on [AES](#aes) in counter mode, used for [OTA](#ota) encryption.

#### EIA2

**EPS Integrity Algorithm 2** – A 4G LTE integrity algorithm based on [AES](#aes), used to ensure the authenticity of signaling messages.

#### EIRP

**Effective Isotropic Radiated Power** – The total radio power transmitted by an antenna, including antenna gain and accounting for transmission losses.

#### eNB / eNodeB

**Evolved Node B** – 4G LTE base station that connects [*UE*](#ue) to the [*EPC*](#epc).

#### EPC

**Evolved Packet Core** – The 4G LTE Core network architecture used to manage data, mobility, authentication, and session control. It includes the MME, SGW, PGW, and HSS functions. In GXC deployments, the EPC is integrated into the Onyx Edge as part of the LTE Core, enabling secure, localized, and scalable private LTE network operations.

#### ESC

**Environmental Sensing Capability** - A network of sensors used in the [*CBRS*](#cbrs) band to detect incumbent federal radar activity and notify the [*SAS*](#sas) when spectrum protection is required.

#### eSIM

**Embedded SIM** – A programmable SIM chip embedded directly into a UE, eliminating the need for a physical SIM card slot. It supports remote provisioning and simplifies UE deployment, particularly in IoT and enterprise environments.

#### eSync

**Edge Synchronization Module** – A GXC module that provides timing services such as GPS-based synchronization, [*PTP*](#ptp) Grandmaster functionality, and [*SyncE*](#synce) output. It ensures accurate time and phase alignment for 4G/5G networks when [*Onyx Edge*](#onyx-edge) or [*FHMs*](#fhm) require an external synchronization source.

#### Ethernet Backhaul&#xD;

A network connection that transports traffic between access network equipment and the core network using Ethernet.

#### EUTRA

**Evolved Universal Terrestrial Radio Access** – Radio access part of LTE, including eNodeB and UE.

#### Event

A system-recorded occurrence that reflects a change or activity within the network—such as an equipment status update, configuration change, or user action. Events provide an audit trail and operational visibility for diagnostics and historical review.

***

### F

#### F1

**F1 Interface** – In 5G networks, the F1 interface connects the [*DU*](#du) and [*CU*](#cu) within a [*gNodeB*](#gnb-gnodeb). In GXC deployments, both DU and CU functions are integrated within the Onyx Edge, and the F1 interface is implemented internally to support the split [*RAN*](#ran) architecture and efficient coordination between radio and control functions.

#### FCAPS

**Fault, Configuration, Accounting, Performance, Security** – A framework for network management functionality.

#### FCC

**Federal Communications Commission** – The U.S. regulatory authority that governs spectrum allocation, device certification, and telecommunications compliance, including rules for [*CBRS*](#cbrs) and private 5G deployments.

#### FCC ID

A unique identifier assigned by the [*FCC*](#fcc) to certify that a wireless device complies with regulatory standards for radio frequency transmission and electromagnetic emissions.

#### FHM

**Fronthaul Multiplexer** – GXC 5G equipment that aggregates and synchronizes fronthaul signals between the Onyx Edge and multiple [*RUs*](#ru). It enables [*Shared Cell*](#shared-cell) functionality by virtualizing multiple RUs into a single cell, supporting extended coverage and efficient spectrum usage.

#### Fiber Uplink

A fiber-optic network connection used to provide high-speed connectivity between network devices.

#### Floor Plan Calibration

An [*Onyx Portal*](#onyx-portal) feature that allows you to map the latitude and longitude coordinates of each floor in a venue and visualize it on a map.

#### Fronthaul

In a split 5G architecture, the low-latency, time-sensitive link between the [*DU*](#du) and the [*RU*](#ru). GXC uses O-RAN 7.2x-compliant interfaces over fiber to transport radio data between these components.

#### FQDN

**Fully Qualified Domain Name** – Complete domain name including hostname and domain (e.g., *server.example.com*).

#### Free Running

A timing fallback mode used when an [*Onyx Edge*](#onyx-edge) or [*AP*](#ap) loses its primary synchronization source. In this mode, the equipment maintains its last known timing reference autonomously, which may lead to drift over time.

#### FSM

**Finite State Machine** – Indicates the current operational state of an [*AP*](#ap), helping administrators assess readiness, faults, or provisioning status.

#### FWA

**Fixed-Wireless Access** – Provides broadband internet using wireless connections instead of fiber or DSL.

***

### G

#### G100

GXC 4G indoor AP equipment.

#### G101

GXC 4G indoor AP equipment.

#### G105

GXC 5G indoor AP equipment.

#### G227

GXC 5G indoor AP equipment.

#### G229

GXC 4G indoor low-power AP equipment.

#### G238-n78H

GXC 5G outdoor high-power band n78 AP equipment.

#### G243-n48

GXC 5G outdoor band n48 AP equipment.

#### G243-n78H

GXC 5G outdoor high-power band n78 AP equipment.

#### G249

GXC 4G outdoor AP equipment.

#### G430

GXC 5G indoor AP equipment.

#### G443

GXC 5G outdoor AP equipment.

#### G501

GXC 4G outdoor high-power AP equipment.

#### G505

GXC 5G outdoor high-power AP equipment.

#### G509-n28

GXC 5G outdoor band n28 AP equipment.

#### G509-n41

GXC 5G outdoor band n41 AP equipment.

#### GAA

**General Authorized Access** - The lowest-priority [*CBRS*](#cbrs) access tier that permits shared use of available spectrum without acquiring a Priority Access License.

#### GCM

**Galois/Counter Mode** – An [*AES*](#aes) encryption mode that combines counter mode encryption with Galois field authentication, providing both confidentiality and integrity.

#### gNB / gNodeB

**Next Generation Node B** – The 5G base station that provides radio access to [*UE*](#ue), manages control signaling, and interfaces with the 5G Core network. In GXC deployments, the gNodeB includes the [*DU*](#du) and [*CU*](#cu), and operates in conjunction with the Onyx Edge platform.

#### GNSS

**Global Navigation Satellite System** - A satellite-based positioning system used to provide location and timing information.

#### GM01

GXC 4G GM01 Mesh Node equipment.

#### GM02

GXC 4G GM02 Mesh Node equipment.

#### GM03

GXC 5G GM03 Mesh Node equipment.

#### GPS

**Global Positioning System** – A satellite-based system used in GXC deployments to deliver precise timing and location information. GPS timing is critical for synchronizing [*TDD*](#tdd) operations, via components such as the [*Onyx Edge*](#onyx-edge) or [*FHM*](#fhm).

#### GPS Antenna

A receiver antenna that captures GPS satellite signals to provide accurate timing and location information. In GXC APs, it ensures synchronization for [*TDD*](#tdd) and ensures coordination across the [*RAN*](#ran).

#### Grant

An authorization issued by the [*SAS*](#sas) that permits a [*CBSD*](#cbsd) to transmit on specific frequencies under defined operating conditions.

#### Grant Request

A [*SAS*](#sas) request submitted by a [*CBSD*](#cbsd) or [*DP*](#dp) to obtain spectrum resources for transmission.

#### GXC Partner

An organization authorized to deploy, manage, or resell GXC’s private cellular solutions, often collaborating on implementation, support, and customer success.

#### GXC Root

The top-level administrative account used by GXC to manage the Onyx Portal.

***

### H

#### HA

**High Availability** – A redundancy architecture designed to ensure service continuity in [*Onyx Edge*](#onyx-edge) failure scenarios using [*Onyx Edge Pools*](#onyx-edge-pool).

#### HAAT

**Height Above Average Terrain** - The height of an antenna relative to the average elevation of the surrounding terrain.

#### Handover

The process of transferring an active session or connection from one cell to another as a [*UE*](#ue) moves.

#### Handover Hysteresis

The signal strength difference (in dB) that a neighboring cell must exceed over the current serving cell before initiating handover. Used to prevent rapid switching between cells when signal levels fluctuate, ensuring stable connections and reducing unnecessary network overhead.

#### Heartbeat

A periodic message exchanged with the [*SAS*](#sas) to maintain an active grant and authorization to transmit.

#### HMAC

**Hash-Based Message Authentication Code** – A mechanism combining a cryptographic hash (e.g., SHA-256) with a secret key to verify data integrity and authenticity.

#### HSS

**Home Subscriber Server** – Stores subscriber profiles and performs authentication in LTE.

***

### I

#### ICCID

**Integrated Circuit Card Identifier** – A unique identifier assigned to each SIM card or eSIM profile, used primarily for inventory and provisioning management.

#### IdP

**Identity Provider** – A trusted third-party service that manages user authentication and identity. It validates credentials during [*SSO*](#sso) and provides user attributes to the [*Onyx Portal*](#onyx-portal) for [*RBAC*](#rbac).

#### IMEI

**International Mobile Equipment Identity** – A globally unique number used to identify a UE on a cellular network.

#### IMDSv2

**Instance Metadata Service version 2** – An updated version of [*AWS*](#aws) metadata service that enhances security by requiring session-oriented requests with tokens to access instance metadata. IMDSv2 mitigates common metadata-related attacks and protects sensitive data, such as IAM credentials, on cloud instances.

#### IMSI

**International Mobile Subscriber Identity** – A unique identifier assigned to a subscriber’s SIM or eSIM profile. It is used by the mobile network to authenticate the subscriber, manage sessions, and enforce access control for the associated UE.

#### Interference

Unwanted radio signals that degrade or disrupt wireless communications.

#### IoT

**Internet of Things** – Network of physical devices connected via the internet, enabling data exchange and automation.

#### IP

**Internet Protocol** – Network protocol for routing packets between devices.

#### IPSec

**IP Security** – Protocol suite for securing IP communications by authenticating and encrypting each IP packet in a communication session. In GXC’s 4G networks, APs and Onyx Edge can be configured to support IPSec for enhanced security.

#### ISO

**International Standards Organization** (ISO image) – Disk image file format used to install Onyx Edge software.

***

### K

#### KPI

**Key Performance Indicator** – A measurable metric used to evaluate the performance of networks, equipment, etc. against defined objectives.

***

### L

#### LAN

**Local Area Network** – A local network connecting computers and equipment.

#### LCI

**Local Configuration Interface** – The web interface hosted on AP equipment used for local configuration tasks including uploading certificates and enabling [IPSec](#ipsec), etc.

#### LTE

**Long Term Evolution** – 4G mobile communication standard developed by 3GPP. In GXC deployments, LTE supports OnGo-based private networks operating in the U.S. within the CBRS band (3550–3700 MHz).

#### LTE Core

GXC’s integrated 4G LTE Core, based on the EPC architecture, includes the MME, SGW, PGW, and HSS functions. It manages mobility, authentication, session handling, and traffic routing within GXC’s private LTE deployments. The LTE Core is embedded in the Onyx Edge, enabling secure and localized network operation.

***

### M

#### MAC Address

**Media Access Control Address** – Hardware address uniquely identifying a network interface.

#### MCC

**Mobile Country Code** – A three-digit numeric code used to identify the country of a mobile subscriber within cellular networks. It is part of the [*IMSI*](#imsi) and works in conjunction with [*MNC*](#mnc) to uniquely identify a mobile operator. MCC values are defined by ITU-T and are essential for roaming, network selection, and regulatory compliance.

#### Mesh

A GXC networking configuration where [*Mesh Nodes*](#mesh-node) wirelessly relay traffic between [*APs*](#ap) or between an AP and the [*Onyx Edge*](#onyx-edge). Mesh is used to extend coverage in areas without wired backhaul and provides resilient, self-healing connectivity in challenging environments.

#### Mesh Node

GXC equipment that wirelessly relays traffic between [*APs*](#ap) or to the [*Onyx Edge*](#onyx-edge), expanding network coverage in locations where cabling is impractical, such as remote or obstructed areas.

#### MFA

**Multi-Factor Authentication** – An [*Onyx Portal*](#onyx-portal) security feature that requires users to authenticate with two credentials, their Onyx Portal password and a [*TOTP*](#totp) generated by an authenticator app like the Google Authenticator or Microsoft Authenticator.

#### MFA Backup Code

Codes generated during [*MFA*](#mfa) setup that can be used instead of [*TOTPs*](#totp). Each code is single-use only and expires after it is used. MFA Backup Code are critical for access recovery.

#### MFA Secret

A cryptographic key stored in an authenticator app to generate [*TOTPs*](#totp). If a user loses access to their [MFA](#mfa) device or backup codes, the MFA secret must be reset to regain access to the [*Onyx Portal*](#onyx-portal).

#### MHz

**Megahertz** – Frequency unit equal to one million hertz.

#### MILENAGE

A set of cryptographic algorithms used within the SIM-based authentication process in mobile networks, supporting the [*AKA*](#aka) mechanism. MILENAGE defines functions for authentication, key generation, and data integrity checks, helping to ensure that SIM credentials are securely validated.

#### MIMO

**Multiple Input, Multiple Output** – A wireless technology that uses multiple antennas at both the transmitter and receiver to improve data throughput and signal reliability. GXC APs support MIMO for enhanced 4G/5G performance.

#### MME

**Mobility Management Entity** – The LTE Core function responsible for handling signaling related to mobility and security for UE.

#### MNC

**Mobile Network Code** – A two- or three-digit code used in combination with the [MCC](#mcc) to uniquely identify a mobile network operator within a country. Together, MCC and [MNC](#mnc) form the [PLMN](#plmn) identifier, which is essential for network selection, roaming, and SIM provisioning.

#### MNO

**Mobile Network Operator** – Company providing wireless communications services.

#### M-Plane

**Management Plane** – Handles configuration, software updates, fault management, and monitoring for APs, RUs, and [DUs](#du). In GXC networks, the M-Plane operates through protocols like [TR-069](#tr-069) and O-RAN M-Plane interfaces, integrated into the Onyx Platform to support remote lifecycle management and diagnostics.

#### MSIN

**Mobile Subscriber Identifier** – Part of [IMSI](#imsi) that uniquely identifies a subscriber within a network.

#### mTLS

**Mutual Transport Layer Security** – An extension of [TLS](#tls) where both the client and server present and verify digital certificates to authenticate each other. mTLS provides strong, bidirectional authentication and encrypted communication, frequently used in securing APIs, service-to-service communications, and orchestrated deployments.

#### Multi-APN-VLAN Mode

A specialized Onyx Edge deployment mode allowing traffic separation using VLANs per APN. Enables fine-grained control over traffic segmentation across applications. Also referred to as the Bridge mode.

#### Multiplexing

A technique for sending multiple data streams over a single channel. In mobile networks, it includes time (TDM), frequency (FDM), and code (CDM) multiplexing.

#### Multi-Step Registration

A [*CBSD*](#cbsd) registration workflow in which installation parameters and operational parameters are submitted through separate systems before registration is completed.

***

### N

#### N6

**N6 Interface** – In 5G networks, the N6 interface connects the UPF on the Onyx Edge to external data networks, such as the internet or private enterprise LANs. It serves as the 5G equivalent of the [SGi](#sgi) interface in 4G, routing outbound user-plane traffic from the 5G Core to external destinations.

#### NaaS

**Network-as-a-Service** – GXC’s model of delivering private mobile networks as a service, including orchestration, monitoring, and lifecycle management.

#### NAS

**Non-Access Stratum** – In 4G and 5G networks, NAS is a signaling protocol layer between the UE and the core network (Onyx Edge). It handles key control plane functions such as authentication, mobility management, and session setup. In GXC deployments, NAS signaling is processed by the MME in 4G and AMF in 5G, both hosted on the Onyx Edge.

#### NAT

**Network Address Translation** – A method that maps private IP addresses to public IP addresses for outbound traffic. NAT enables multiple devices on a private network to share a single public IP, conserves address space, and enhances security by obscuring internal network details.

#### NAT Mode

A network configuration mode in which Onyx Edge performs NAT for user traffic. This allows UE to access external networks using the Onyx Edge’s IP address while preserving internal IP schemes. NAT mode simplifies integration into existing enterprise networks by avoiding routing conflicts and enabling secure, outbound-only communication without requiring external IPs for each device.

#### NEA1

**NR Encryption Algorithm 1** – A 5G confidentiality algorithm based on SNOW 3G, used for OTA encryption.

#### NEA2

**NR Encryption Algorithm 2** – A 5G confidentiality algorithm based on [AES](#aes) in counter mode, used for [OTA](#ota) encryption.

#### NEA3

**NR Encryption Algorithm 3** – A 5G confidentiality algorithm based on the ZUC stream cipher, used for [OTA](#ota) encryption.

#### Neighbor Cell Table

A table maintained by APs containing detailed information (cell ID, PCI, RSRP, etc.) about neighboring cells used for handover decisions.

#### Neighbor Frequency Table

A table maintained by APs listing frequencies UE should measure for detecting neighbor cells; populated based on [SAS](#sas) grants.

#### NETCONF

**Network Configuration Protocol** – Used in Onyx solution for secure management of 5G RUs and [FHMs](#fhm) via [M-Plane](#m-plane) interfaces.

#### Ng

**Ng Interface** – In GXC 5G networks, the Ng interface connects gNodeBs to the 5G Core hosted on the Onyx Edge. It includes both N2 (control plane) and N3 (user plane) interfaces for managing UE sessions, signaling, and data forwarding.

#### NIA3

**NR Integrity Algorithm 3** – A 5G integrity algorithm based on ZUC, ensuring the authenticity of signaling messages.

#### NOC

**Network Operations Center** – Centralized location for monitoring and managing networks.

#### Notifications Panel

Displays Onyx Portal broadcast announcements, such as planned downtime and scheduled upgrades. Accessible via the Notifications icon in the Onyx Portal header.

#### NR

**New Radio** – The radio access technology used in 5G networks. NR enables higher throughput, lower latency, and more efficient spectrum use compared to LTE, supporting a wide range of use cases from enhanced mobile broadband to ultra-reliable low-latency communication.

***

### O

#### Onyx Edge

A core component of the GXC solution that integrates core network and [*RAN*](#ran) functions to enable communication between [*APs*](#ap) and external networks. In 5G networks, it can be deployed in either [*Onyx Edge Core+NR*](#onyx-edge-corenr) (standard deployment) or [*Onyx Edge Core Only*](#onyx-edge-core-only) models.

#### Onyx Edge Core Only

A 5G deployment model in which the [*Onyx Edge*](#onyx-edge) functions exclusively as the 5G Core, while the [*gNodeB*](#gnb-gnodeb) ([*DU*](#du) and [*CU*](#cu)) is hosted externally by a third-party vendor. This mode is primarily intended for integration with non-GXC RAN components and is offered with limited support.

#### Onyx Edge Core+NR

The standard 5G deployment model in which a single [*Onyx Edge*](#onyx-edge) hosts both the 5G Core and the gNodeB (comprising [*DU*](#du) and [*CU*](#cu)). It enables end-to-end control, ultra-low latency, and local breakout—ideal for standalone, high-performance private networks in enterprise environments.

#### Onyx Edge On-Premises

A 4G and 5G deployment mode where the [*Onyx Edge*](#onyx-edge) runs locally at the enterprise site. This mode ensures low latency, localized data processing, and supports mission-critical applications that require high reliability and data sovereignty.

#### Onyx Edge Pool

A logical grouping of [*Onyx Edge*](#onyx-edge) in a network for redundancy and scalability. Pools simplify management and load balancing across Onyx Edge.

#### Onyx ES2

GXC 4G ONYX-ES2 Ruggedized Onyx Edge server.

#### Onyx ES4

GXC 4G ONYX-ES4 Onyx Edge server.

#### Onyx ES7

GXC 5G ONYX-ES7 Onyx Edge server.

#### Onyx ES8

GXC 5G ONYX-ES8 Outdoor Onyx Edge server.

#### Onyx Orchestrator

GXC’s centralized platform for lifecycle management and automation of equipment. It enables remote provisioning, software upgrades, configuration management, performance monitoring, and fault management across multiple deployments, ensuring scalable and consistent operations.

#### Onyx Portal

A cloud-native, GUI-based interface used by GXC, GXC partners, and customers to monitor and manage GXC-deployed private cellular networks.

#### Onyx Platform

The GXC private cellular networking platform, consisting of the Onyx Portal, Onyx Edge, radio access components, and supporting services.

#### O-RAN

**Open Radio Access Network** – Industry standard promoting interoperable and virtualized RAN architecture.

#### OTA

**Over-the-Air** – Refers to wireless communication between UE and the network. In GXC deployments, OTA commonly describes encryption and integrity protection of 4G/5G signaling and user traffic.

***

### P

#### PAL

**Priority Access License** – A licensed [*CBRS*](#cbrs) spectrum access tier that provides priority rights to specific frequency channels within a geographic area.

#### PCI

**Physical Cell Identity** – A unique identifier used by LTE and 5G [*Cells*](#cell) to distinguish neighboring cells during radio operations.

#### PDN

**Packet Data Network** – An external network (e.g., internet or corporate LAN) that UE connect to.

#### PGW

**PDN Gateway / Packet Data Network Gateway** – The LTE Core function that routes user traffic to external data networks.

#### PKI

**Public Key Infrastructure** – Framework used to manage digital certificates and encryption keys.

#### PLMN

**Public Land Mobile Network Identifier** – A unique identifier for a mobile network operator, composed of an [MCC](#mcc) and an [MNC](#mnc). The PLMN identifies the network that a subscriber is connected to and is used for network selection, roaming, and authentication in both public and private cellular deployments (e.g., GXC-assigned PLMN IDs).

#### PoE

**Power over Ethernet** - A technology that delivers electrical power and network connectivity over a single Ethernet cable.

#### POI

**Point of Interface** – Connection point between RU/base station and DAS infrastructure.

#### PRB

**Physical Resource Block** – The smallest unit of resource allocation in 4G/5G radio scheduling, representing a specific time-frequency slot that the network assigns to a subscriber/UE for uplink or downlink transmission.

#### Private 4G / Private 5G

A cellular network deployed for exclusive use by an enterprise or organization. Built on 3GPP 4G or 5G technology it uses licensed or shared spectrum (such as [*CBRS*](#cbrs)) to deliver secure, high-performance connectivity.

#### Provisioning Server

A backend service in GXC’s architecture responsible for initializing and configuring Onyx Edge and Mesh Node equipment during onboarding. It automates tasks such as device registration to ensure secure and consistent deployment across GXC networks.

#### PSD

**Power Spectral Density** - The amount of transmitted power distributed across a unit of bandwidth, typically expressed in dBm/MHz.

#### PSS

**Primary Synchronization Signal** - A synchronization signal used by UE to detect and synchronize with a cellular network.

#### PTP

**Precision Time Protocol** – IEEE 1588 protocol for time synchronization over networks.

***

### Q

#### QAM

**Quadrature Amplitude Modulation** – A modulation method that encodes data by varying signal amplitude and phase. In GXC’s networks, higher-order QAM (e.g., 64-QAM, 256-QAM) improves spectral efficiency and data throughput, enabling faster wireless performance under good signal conditions.

#### QoS

**Quality of Service** – Network mechanisms to manage traffic performance and prioritization based on application or subscriber.

***

### R

#### RAN

**Radio Access Network** – The radio portion of the mobile network that connects UE to the core.

#### RBAC

**Role-Based Access Control** – A security model that restricts system access based on user roles. In the Onyx Portal, RBAC ensures that administrators, partners, and customers only access functions and data appropriate to their assigned role.

#### reCAPTCHA

A Google security service that helps prevent automated brute-force login attempts while allowing access for real users. It appears on the Onyx Portal login screen only after a failed login attempt.

#### RF

**Radio Frequency** – The range of electromagnetic frequencies used for wireless communication and signal transmission.

#### RRC

**Radio Resource Control** – A protocol in the RAN that manages connection setup, mobility, and resource allocation between UE and the network.

#### RRH

**Remote Radio Head** – A radio transmitter unit used in [DAS](#das) systems.

#### RSA

**Rivest–Shamir–Adleman** – An asymmetric encryption algorithm used for secure key exchange, digital signatures, and TLS certificate authentication in GXC networks.

#### RSRP

**Reference Signal Received Power** – Measures the power level of LTE reference signals.

#### RSRQ

**Reference Signal Received Quality** – Measures LTE signal quality including interference and signal strength.

#### RSSI

**Received Signal Strength Indicator** – Measures total received power including signal and interference.

#### RU

**Radio Unit** – In 5G networks, the RU handles RF functions as part of a disaggregated RAN architecture—e.g., GXC G505. In GXC documentation, RU may also be referred to as AP.

***

### S

#### S1

**S1 Interface** – In GXC 4G networks, the S1 interface connects APs to the LTE Core hosted on the Onyx Edge. It includes S1-MME (control plane) and S1-U (user plane) sub-interfaces for forwarding user data, enabling complete connectivity between UE and the core network.

#### SA

**Standalone** – A 5G network deployment model where 5G radios operate alongside a native 5G Core, without relying on legacy 4G infrastructure. GXC’s 5G deployments use the SA model to enable advanced features such as ultra-low latency, network slicing, and full control plane/user plane separation.

#### SAS

**Spectrum Access System** – A cloud-based service that dynamically manages spectrum assignments in the [*CBRS*](#cbrs) band, ensuring interference protection and regulatory compliance.

#### SAS User ID

A unique identifier assigned by a [*SAS*](#sas) provider to an organization or deployment owner for [*CBRS*](#cbrs) operations.

#### SC

**Single Carrier** – An AP transmission mode in which an AP uses a single frequency carrier to transmit data. It is typically used in simpler or lower-throughput deployments and is supported in both 4G and 5G networks.

#### Sector

A coverage area served by a directional antenna or radio cell.

#### SFP

**Small Form-factor Pluggable**&#x20;\- A compact, hot-swappable transceiver module used for network connectivity over fiber or copper media.

#### SFP+

**Enhanced Small Form-factor Pluggable** - A higher-speed version of the [*SFP*](#sfp) transceiver module commonly used for 10 Gbps network connections.

#### SGi

**SGi Interface** – In 4G networks, the SGi interface connects the PGW (hosted on the Onyx Edge) to external IP networks such as the internet or enterprise LAN. It carries outbound user plane traffic from the LTE Core and is typically mapped to a physical interface (e.g., eth0).

#### SGW

**Serving Gateway** – The LTE Core function that routes and forwards user data packets between the eNodeB and PGW.

#### Shared Cell

A 5G deployment model in which multiple RUs operate under a single [DU](#du) with a unified cell ID. In GXC’s architecture, this eliminates intra-site handovers, reduces signaling overhead, and ensures seamless mobility and consistent performance across large or complex environments such as warehouses and factories.

#### SIM

**Subscriber Identifier Module** – A physical smart card inserted into a UE to authenticate and identify the UE/subscriber on a mobile network. It stores credentials such as the [IMSI](#imsi) and encryption keys used during network access. Also, see [eSIM](#esim).

#### SLO

**Single Log Out** – When users log out from the Onyx Portal using [SSO](#sso), they are simultaneously logged out from all other integrated applications within their organization’s SSO environment.

#### SLA

**Service Level Agreement** – Contract defining performance metrics between a service provider and customer.

#### Slot Pattern

A time-domain configuration in 5G [TDD](#tdd) that defines the arrangement of downlink, uplink, and flexible symbols within a slot. Similar to [SSF](#ssf) in LTE, slot patterns impact latency, throughput, and UL/DL switching behavior.

#### SMA Connector

**SubMiniature Version A Connector** – A threaded RF connector used to attach external antennas (e.g., GPS or LTE) to network equipment. Common in GXC APs and timing modules.

#### SMF

**Session Management Function** – The 5G Core function handling session establishment, modification, and teardown.

#### SNOW

A 3GPP stream cipher algorithm used in LTE for confidentiality and integrity protection of signaling and user data.

#### SOC 2

A compliance framework developed by the American Institute of Certified Public Accountants (AICPA) that verifies an organization’s security, availability, processing integrity, confidentiality, and privacy controls.

SOC 2 Type I certification confirms that GXC’s security controls are properly designed and implemented at a specific point in time, demonstrating our commitment to protecting customer data.

#### Spectrum Analyzer

An [*Onyx Portal*](#onyx-portal) feature that visualizes uplink and downlink RF power characteristics for monitoring and troubleshooting radio performance.

#### Spectrum Inquiry

A [*SAS*](#sas) request used to determine available frequencies and spectrum resources at a [*CBSD*](#cbsd) location.

#### S-Plane

**Synchronization Plane** – Provides timing and synchronization across distributed RAN components to maintain aligned transmissions. GXC supports synchronization through [PTP](#ptp) and other timing mechanisms critical for interference-free operations, especially in shared and adjacent cell deployments.

#### SSF

**Special Subframe Configuration** – A timing pattern used in [TDD](#tdd) LTE systems to define the guard period between uplink and downlink slots. It affects latency and throughput performance.

#### SSH

**Secure Shell** – Protocol for secure remote access to the Onyx Edge.

#### SSO

**Single Sign-On** – An authentication method that allows users to log in once and gain access to multiple applications in their organization’s SSO environment, including the Onyx Portal, without needing to re-authenticate. GXC supports SSO via integration with customer [IdPs](#idp).

#### SUCI

**Subscription Concealed Identifier** – A privacy-enhancing identifier used in 5G networks to protect the [SUPI](#supi) when transmitted over the air. The SUCI is a cryptographically generated, temporary identifier derived from the SUPI, preventing interception and tracking by unauthorized parties.

#### SUPI

**Subscription Permanent Identifier** – A unique, permanent identifier assigned to a mobile subscriber, typically based on the IMSI. In 5G, the SUPI remains protected and is never directly transmitted in clear text; instead, it is concealed using [SUCI](#suci).

#### Subscriber

An end user/UE authorized to access the network using a GXC-issued SIM or eSIM. Subscribers are managed through the Onyx Portal and associated with policies and identities for secure connectivity.

#### SyncE

**Synchronous Ethernet** – A timing protocol used in mobile networks to distribute frequency synchronization over Ethernet links. In GXC systems, SyncE helps maintain precise timing between Onyx Edge and connected RUs, supporting [TDD](#tdd) alignment and fronthaul stability.

#### Synchronization Source

The source used by network equipment to obtain timing and frequency synchronization.

***

### T

#### TAC

**Tracking Area Code** – Identifies a specific tracking area within a network.

#### TAI

**Tracking Area Identifier / Identity** – Uniquely identifies a tracking area used in mobility management.

#### TAU

**Tracking Area Update** – Procedure for updating UE’s location within a new tracking area.

#### TDD

**Time Division Duplex** – A transmission method that separates uplink and downlink signals by allocating them alternating time slots on the same frequency channel.

#### TFT

**Traffic Flow Template** – Defines filters for bearer traffic matching.

#### Timing Reference

A clock or synchronization signal used to maintain accurate network timing.

#### TLS

**Transport Layer Security** – In 4G and 5G networks, TLS secures communication channels between GXC components by encrypting and authenticating management and signaling traffic. It is used across interfaces such as those between the Onyx Portal, Onyx Edge, and APs to ensure secure configuration, control, and data integrity.

#### TOTP

**Time-Based One-Time Password** – A temporary, automatically generated numeric password used for MFA, generated via apps like Google Authenticator or Microsoft Authenticator.

#### TR-069

**Technical Report 069** – A broadband device management protocol that enables remote configuration, monitoring, and firmware updates of CPE. In GXC networks, TR-069 is used to manage 4G APs, simplifying provisioning and lifecycle operations through secure, centralized control.

#### TTT

**Time to Trigger** – The duration that a qualifying signal condition must persist before initiating a handover, preventing unnecessary switching due to brief fluctuations.

#### Transport Layer

The time-synchronized, high-speed communication infrastructure that connects the Onyx Edge to distributed RUs. Built on protocols such as IEEE 1588v2 PTP and SyncE, the transport layer enables deterministic performance and precise coordination in 4G/5G fronthaul networks.

***

### U

#### UDM

**Unified Data Management** – The 5G Core function managing subscriber profiles.

#### UE

**User Equipment** – An end-user device authorized to access the network using a SIM or eSIM, such as a smartphone, tablet, or IoT sensor.

#### Upgrade Group

A logical grouping of Onyx Edge, AP, or Mesh Node equipment at the network level, used to manage coordinated software upgrades or rollbacks.

#### UL

**Uplink** – Data transmission direction from UE to network.

#### UPF

**User Plane Function** – The 5G Core function managing data forwarding, packet inspection, and QoS enforcement.

#### Upstream IdP User

An Onyx Portal user authenticated via an external IdP. A corresponding user account is created within the Onyx Portal to provide fallback access in cases where the IdP fails to release required SSO attributes.

#### U-Plane

**User Plane** – The data layer of the network responsible for carrying user traffic (e.g., application data and internet access). Managed by the UPF in 5G or by SGW/PGW in LTE, the User Plane in GXC systems is optimized for low-latency, high-throughput delivery and is embedded within the Onyx Edge for localized traffic handling.

#### Uu

**Uu Interface** – In 4G and 5G networks, the Uu interface is the radio interface between the UE and the base station (eNodeB in 4G or gNodeB in 5G). It carries both control and user plane traffic over the air and is the primary link for access connectivity.

***

### V

#### Venue

A logical location in the Onyx Portal representing a real-world location (e.g., warehouse, factory) where APs are deployed. A venue can be assigned floor plans and used for floor calibration.

#### VLAN

**Virtual LAN** – Logical segmentation of a physical network into multiple broadcast domains. Also, see Multi-APN-VLAN Mode.

***

### W

#### WAF

**Web Application Firewall** – A security solution that protects web applications by filtering and monitoring HTTP/HTTPS traffic between a web application and the internet. WAFs help block common attacks such as cross-site scripting (XSS), SQL injection, and other OWASP Top 10 vulnerabilities.

***


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.gxc.io/glossary.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
