The APN attribute is acquired based on the existing information in the packet header such as 5-tuple (might be 2-tuple in an encrypted environment) and QinQ (S-VLAN and C-VLAN) at the edge devices of the APN domain, added to the data packets along with the tunnel encapsulation. This means that APN does not need to rely on the encrypted payload of the packet. Moreover, in this draft https://datatracker.ietf.org/doc/html/draft-li-apn-framework-04#section-5.1, we have also listed the APN Attribute Conveying Requirements, the [REQ 1d] is that “APN ID MUST be acquired from the existing available information of the packet header without interference into the payload.”