3GPP 23.501 v20.2.0 — the document's own text
6.2.17 SEPP
Taught in 4. What each network function does (The 5G system architecture, in depth), 18. Being served by somebody else's network (The 5G system architecture, in depth), 2. Who does what in the core (The 5G system architecture, overview).
The Security Edge Protection Proxy (SEPP) is a non-transparent proxy and supports the following functionality:
- Message filtering and policing on inter-PLMN control plane interfaces.
NOTE: The SEPP protects the connection between Service Consumers and Service Producers from a security perspective, i.e. the SEPP does not duplicate the Service Authorization applied by the Service Producers as specified in clause 7.1.4.
- Topology hiding.
Detailed functionality of SEPP, related flows and the N32 reference point, are specified in TS 33.501 [29].
The SEPP applies the above functionality to every Control Plane message in inter-PLMN signalling, acting as a service relay between the actual Service Producer and the actual Service Consumer. For both Service Producer and Consumer, the result of the service relaying is equivalent to a direct service interaction. Every Control Plane message in inter-PLMN signalling between the SEPPs may pass via IPX entities. More details on SEPPs and the IPX entities are described in TS 29.500 [49] and TS 33.501 [29].