Our High-Performing Core Network

Fully virtualizable on VMware, K8S, Docker and OpenStack containers

Security Edge Protection Proxy(SEPP)

SEPP (Security Edge Protection Proxy) is a key element in 5G core networks, enabling secure and trusted communication across operator boundaries. It plays a vital role in supporting 5G roaming and inter-PLMN interoperability by safeguarding control-plane signaling between networks.

Positioned at the edge of the operator’s core network, SEPP filters, mediates, and protects signaling messages exchanged with partner operators. Through the standardized N32 interface, SEPP applies encryption, integrity protection, and policy enforcement to ensure signaling confidentiality and trust.

Key Benefits

380cf5e734

A fully software-based solution by design

67d1c6a00b

Centralized and standardized IT integration

8e82b3364f

Easy to operate with standardized processes across domains

ce24ac166d

Centralized and standardized utilization of common network functions

ee115ca98e

Single capacity license with flexible traffic allocation across supported protocols

773702f2c1

Built-in support for interworking and interoperability

IPLOOK's SEPP For MNO roaming between standalone 5G cores (5GC)

  • The IPLOOK SEPP enables operators to achieve end-to-end confidentiality and integrity for designated message elements between the source and destination networks. It offers unique flexibility through an extensive, integrated set of routing and service creation capabilities. It supports the relevant standards as well as HTTP/2-based signaling scenarios.
  • The IPLOOK SEPP is a purpose-built, single-engine software product – not an afterthought, project, or patchwork solution. It enables operators to consolidate network functions, operations, management, and licenses.

Features

Support for the N32-f and N32-c interfaces

On-board session database key negotiation

Support for Transport Layer Security (TLS)

Support for security key management and lookup

Supports message modification instruction inclusion via the JSON PATCH method

Support for remote SEPP authorization and authentication

Support for topology hiding

Support for load balancing

Support for egress/ingress limitation

Optional (on-board) support for:

On-board non-volatile database for key repository and storage

Powerful any-to-any interworking across all supported protocols (including SS7, Diameter, RADIUS, HTTP, LDAP, ENUM, etc.)

Single-view reporting, GUI-based management, and provisioning

Flexible licensing across all supported protocols, not just HTTP/2

Support for PRINS (Protocol for N32 Interconnect Security, JWE/JWS) – ongoing standardization developments in progress

Support for malformed N32 message detection

Support for anti-spoofing mechanisms

Support for high-availability and geo-redundant deployment models

Full GUI-based signaling orchestration and system management with configurable service logic – no scripting or development needed

Related Products

Get Your Product Brochure

Please fill in your name and email to access the product PDF.