PRINS vs TLS-only on N32-f
On the N32-f interface between SEPPs, two protection profiles exist. TLS-only encrypts the transport but exposes every IE to any IPX in the middle. PRINS (Protocol for N32 Interconnect Security) adds JWE encryption of sensitive IEs and signed modification schemas.
| Attribute | PRINS | TLS-only on N32-f |
|---|---|---|
| Transport confidentiality | Yes (TLS) | Yes (TLS) |
| IE-level confidentiality | Sensitive IEs JWE-encrypted | None |
| IPX modification model | Signed modification schema | Trusted intermediary |
| SUPI/key exposure to IPX | Hidden | Visible |
| Deployment complexity | Higher — key mgmt across SEPPs and IPX | Lower |
Verdict
TLS-only on N32-f is 5G roaming with an LTE trust model. It is a reasonable phase-1 deployment; it is not the target state. Any operator that keeps TLS-only for the long term is not benefiting from SEPP's core design.