PRINS vs TLS-only on N32-f

On the N32-f interface between SEPPs, two protection profiles exist. TLS-only encrypts the transport but exposes every IE to any IPX in the middle. PRINS (Protocol for N32 Interconnect Security) adds JWE encryption of sensitive IEs and signed modification schemas.

AttributePRINSTLS-only on N32-f
Transport confidentialityYes (TLS)Yes (TLS)
IE-level confidentialitySensitive IEs JWE-encryptedNone
IPX modification modelSigned modification schemaTrusted intermediary
SUPI/key exposure to IPXHiddenVisible
Deployment complexityHigher — key mgmt across SEPPs and IPXLower

Verdict

TLS-only on N32-f is 5G roaming with an LTE trust model. It is a reasonable phase-1 deployment; it is not the target state. Any operator that keeps TLS-only for the long term is not benefiting from SEPP's core design.

Related terms

Related topics