SVI-SEPP SECURITY EDGE PROTECTION PROXY
Advanced core network security with 5G Edge Protection Proxy
5G Security Edge Protection Proxy SEPP
From the edge of the 5G SA core network, the Security Edge Protection Proxy enables secure exchange of the authentication, authorisation, and subscriber policy. Unlike 4G, security is built into 5G through the 3GPP standards regarding N32-c and N32-f interfaces and SEPPs.
The 5G SVI-SEPP enables topology hiding, message normalisation and filtering, DOS and DDOS protection, load balancing and congestion control functionality for 5G PLMNs (Public Land Mobile Networks) transmissions.

Security Edge Protection Proxy
Deploying the advanced 5G SVI-SEPP provides tighter security and normalisation as part of the 5G HTTP/2 Signalling Controller:

Topology Hiding
Application-level concealing of HTTP/2 message identity information leaving a local realm.Security
The 5G SVI-SEPP provides topology hiding, DoS and DDoS protection while delivering load balancing and congestion control.Message Filtering
5G SVI-SEPP message screening scans all traffic to determine what enters the network and from where.Admission Control
Full configuration in terms of protocol compliance and custom policy setup, filtering, comparison to deny/allow listing, throttling and message manipulation.DoS, DDoS Protection
The SEPP protects HTTP/2 servers and networks from overload and signalling storms brought on by DoS and DDoS attacks.Transport over TLS IPSec
IPSec and Transport Layer Security allows for intra-realm security providing advanced encryption between endpoints.Onboard Firewall
Networks and subscribers are protected from privacy leaks and denial of service attacks by the Security Edge Protection Proxy’s onboard HTTP/2 firewall.Overload Protection
Optimise management of 5G SA core networks with advanced load balancing and throttling.Message Normalisation
Ensure message normalisation across 5G SA core networks with SEPP-based mediation.
The N32 interface, the backbone of inter-operator 5G SA roaming, is divided into two logical components. It defines the standardised, seamless communication path between SEPPs in different operator networks.
N32-c handles control-plane functions such as capability negotiation and security establishment.
N32-f manages the forwarding of signalling traffic between networks.
N32 ensures that subscriber authentication data, mobility management information, policy rules, and session management signalling can be exchanged consistently and securely across global roaming ecosystems.

High Availability
Carrier-grade reliability is supplied through a comprehensive range of high-availability options.

Specifications
Supporting multiple interface types, including support for HTTP/2, 5G SA core, IMS / 4G / LTE and legacy SS7 TDM, and NGN IP SIGTRAN.

OA&M
A comprehensive web-based management system delivers on-board configuration, monitoring and debugging.
Commercial Off The Shelf
Supplied on standard Dell servers.
Virtual or Cloud Deployment
Virtual Machine deployed on industry-standard servers in a data centre environment using a hypervisor, i.e. VMware, or Virtual Network Function (VNF) in AWS, Azure, OpenStack, Nokia, Oracle Cloud and Google Cloud infrastructure.
Enhanced Network Functions
Network functions are faster with network function virtualisation architectures and containerisation.
Trusted by Customers Worldwide
Squire Technologies solutions enable over 30 billion transactions per second and 11 trillion transactions per year. We have deployments in over 6 continents, in 150+ countries and with 400+ customers.
30
Transactions per second
11
Transactions per year
400
Telecom Operators
150
Countries
Further Information

Service Communication Proxy
The SVI-SCP provides scalable, seamless routing and comprehensive carrier-grade traffic management of 5GNR core networks.

