SEPP (Security Edge Protection Proxy)

The Security Edge Protection Proxy is the 5G network function placed at the edge of every PLMN to terminate the N32 interface used for inter-operator signalling. It enforces application-layer protection (PRINS) that authenticates and integrity-protects each JSON message, optionally encrypting sensitive information elements end-to-end across IPX intermediaries. SEPP closes the inter-PLMN trust gap that plagued SS7 and Diameter, and is mandatory for any 5G operator offering or consuming roaming.

Categories: Core NetworkSignalingRoaming and Interconnect

SEPP in context

The mobile core carries subscriber sessions, mobility and policy. In 4G it is the EPC (MME, HSS, S/PGW); in 5G it is the Service-Based Architecture with AMF, SMF, UPF, AUSF, UDM and the NRF.

Signaling protocols carry the control-plane messages that set up calls, register subscribers and route SMS. SS7, Diameter, GTP-C and SIP are the four dominant families, and interconnect exposure of any of them is treated by GSMA as top-tier telecom risk.

To place SEPP in the wider telecom-security picture, review GTP Firewall, HLR, I-CSCF, Signaling Firewall, MSSP and Lateral Movement (Telecom): each entry cross-references back to this page so you can walk the topic in either direction.

Related terms

Related topic hubs

  • Roaming Security IPX/GRX interconnect risk, home-routed vs local-breakout, SEPP.
  • 5G Security 5G SBA, SEPP, SUCI, 5G-AKA, N32 and service-based interface security.
  • SEPP Security N32-c/N32-f, PRINS, JWE and OAuth 2.0 at the 5G roaming edge.
  • Signaling Firewall Unified SS7/Diameter/GTP/SMS signaling firewall framework.

More from the TelcoSec Glossary

Browse the full TelcoSec Glossary, the Ultimate Guide to Mobile Network Security, or the P1 Arsenal of telecom-security tools.