Description
Inter-PLMN User Plane Security (IPUPS) is a 3GPP security mechanism designed to protect user plane data as it travels between two different Public Land Mobile Networks (PLMNs). Its primary focus is securing the N9 interface, which is the reference point between the User Plane Functions (UPFs) of two separate networks, a common scenario in roaming or when a user's data session is anchored in a home network while connected via a visited network. IPUPS ensures both confidentiality (preventing eavesdropping) and integrity (preventing tampering) of the user's IP packets.
The architecture of IPUPS involves security gateways (SEGs) or the UPFs themselves acting as security endpoints. These endpoints establish a secure tunnel, typically using IPsec, between the two PLMNs. The system utilizes the 3GPP-defined security protocol suite, Network Domain Security (NDS/IP), which specifies how to implement IPsec for 3GPP network interfaces. Key management is handled through the use of Internet Key Exchange protocol version 2 (IKEv2), often with certificate-based authentication to establish a trusted relationship between the operators' networks. The policies for which traffic requires protection (e.g., all roaming traffic, traffic for certain APNs) are configured within the network functions.
Operationally, when user plane data needs to be sent from the Visited PLMN (VPLMN) to the Home PLMN (HPLMN), the source UPF or SEG encapsulates the original GTP-U and user IP packets within an IPsec Encapsulating Security Payload (ESP) tunnel. The tunnel terminates at the peer entity in the other network, which decrypts and verifies the packet before forwarding it to the target UPF. This process is transparent to the end-user device. IPUPS is a critical component in the 5G security architecture, extending the 'security-by-design' principle to inter-operator links, which are potential points of vulnerability in a globally interconnected mobile ecosystem.
Purpose & Motivation
IPUPS was created to address a significant security gap in inter-operator connectivity. Historically, user plane traffic between different operators' networks (e.g., for roaming users) often traversed the public internet or private interconnects without mandatory encryption, relying on the security of the underlying transport network. This made the data vulnerable to interception, manipulation, or analysis by intermediaries. The increasing sensitivity of user data and the rise of regulatory requirements for data protection (like GDPR) necessitated a standardized, robust security solution.
The motivation for IPUPS stemmed from the 5G design principle of providing end-to-end security, which includes the 'network-to-network' segment. It solves the problem of securing user data once it leaves the relatively controlled environment of a single operator's network. By mandating or strongly recommending IPsec on the N9 interface, 3GPP ensures that user privacy is maintained even during roaming, and it protects against threats like man-in-the-middle attacks on inter-PLMN links. Its introduction in Release 16 aligns with the enhanced security requirements of 5G, supporting new use cases that demand higher trust, such as network slicing for enterprises and critical IoT communications.
Classification
Release Timeline
Detected Changes Across Releases
from 3GPP Change RequestsSpecific changes extracted from the „Change history“ tables of 3GPP specifications (5 CRs across 2 releases). Complements the general historical overview above with the evidence-based evolution of this function.
In Release 16, the Inter-PLMN User Plane Security (IPUPS) functionality was introduced, allowing operators to deploy UPFs at their network border to validate and filter invalid N9 interface traffic in home-routed roaming scenarios. The IPUPS functionality, controlled by the SMF via the N4 interface, terminates GTP-U N9 tunnels and forwards packets only for active, non-malformed PDU Sessions. It can be activated as an integrated part of a UPF or deployed as a separate, dedicated UPF inserted into the user plane path.
In Release 17, the new specification for the Inter-PLMN User Plane Security (IPUPS) function formally defined its deployment and control. It specified that UPFs supporting IPUPS, controlled by the SMF via the N4 interface, can be activated either integrated with other UP functionality in a single UPF or as a separate, dedicated UPF inserted into the user plane path. Furthermore, the release clarified that the IPUPS functionality forwards GTP-U packets on the N9 interface only for active PDU sessions and if they are not malformed, as per the security procedures.
- Resolving editor's note for IPUPS TS 29.244CR0627
Explore further
Broader topics and technologies where IPUPS plays a role.
Defining Specifications
3GPP specifications that define or reference IPUPS, with the latest known release. Sourced from the 3GPP document catalog — see methodology.
| Specification | Title | Release |
|---|---|---|
| TS 23.501 vk00 | 5G System Architecture Stage 2 | Rel-20 |
| TS 29.244 vj40 | PFCP Specification for Control/User Plane Separation | Rel-19 |
| TS 29.510 vj50 | NRF Service Based Interface Protocol | Rel-19 |
| TS 33.501 vk00 | 5G Security Architecture and Procedures | Rel-20 |