LTE Attach and Default Bearer Setup Messaging



Similar documents
LTE X2 Handover Messaging

LTE RRC Connection Setup Messaging

Protocol Signaling Procedures in LTE

LTE Security. EventHelix.com. Encryption and Integrity Protection in LTE. telecommunication design systems engineering real-time and embedded systems

Voice over IP over LTE (VoLTE) Impacts on LTE access. EFORT

ETSI TS V8.0.0 ( ) Technical Specification

NTT DOCOMO Technical Journal. Core Network Infrastructure and Congestion Control Technology for M2M Communications

SAE and Evolved Packet Core

Long-Term Evolution. Mobile Telecommunications Networks WMNet Lab

Single Radio Voice Call Continuity. (SRVCC) with LTE. White Paper. Overview. By: Shwetha Vittal, Lead Engineer CONTENTS

Practical Security Testing for LTE Networks BlackHat Abu Dhabi December 2012 Martyn Ruks & Nils

Architecture Overview NCHU CSE LTE - 1

Diameter in the Evolved Packet Core

Security Testing 4G (LTE) Networks 44con 6th September 2012 Martyn Ruks & Nils

Performance validation for the mobile core

Design and Implementation of a Distributed Mobility Management Entity (MME) on OpenStack

Optimization Handoff in Mobility Management for the Integrated Macrocell - Femtocell LTE Network

The LTE Network Architecture

Delivery of Voice and Text Messages over LTE

Telesystem Innovations. LTE in a Nutshell: Protocol Architecture WHITE PAPER

3GPP LTE Packet Data Convergence Protocol (PDCP) Sub Layer

3GPP LTE Channels and MAC Layer

LTE Overview October 6, 2011

Priority, Pre-Emption, and Quality of Service

IP Multimedia System: general aspects and migration perspectives

Single Radio Voice Call Continuity (SRVCC) Testing Using Spirent CS8 Interactive Tester

Telecommunication Services Engineering (TSE) Lab. Chapter III 4G Long Term Evolution (LTE) and Evolved Packet Core (EPC)

UMTS/GPRS system overview from an IP addressing perspective. David Kessens Jonne Soininen

Public Safety Communications Research. LTE Demonstration Network Test Plan. Phase 3 Part 1: Network Interoperability & Drive Test. Version 2.

LTE Performance and Analysis using Atoll Simulation

3GPP Long Term Evolution: Architecture, Protocols and Interfaces

Security Analysis of LTE Access Network

Overview of the Evolved packet core network

ETSI TS V8.0.0 ( ) Technical Specification

GSM Network and Services

LTE Security How Good Is It?

How to deal with a thousand nodes: M2M communication over cellular networks. A. Maeder NEC Laboratories Europe andreas.maeder@neclab.

3GPP TS V8.0.0 ( )

Study of Long Term Evolution Network, its Architecture along with its Interfaces

Cisco ASR 5000 Mobility Management Entity Administration Guide

Triton Multi-purpose LTE wireless core networking testing tool

A Novel LIPA Scheme for LTE VoIP Services with Home enbs

Cisco ASR 5000 Series Mobility Management Entity Administration Guide

LTE CDMA Interworking

ETSI TS V ( )

Mobile Devices Security: Evolving Threat Profile of Mobile Networks

ETSI TS V9.0.0 ( ) Technical Specification

3GPP TS V7.0.0 ( )

ETSI TS V ( )

SERVICE DISCOVERY AND MOBILITY MANAGEMENT

End to End Delay Performance Evaluation for VoIP in the LTE Network

Long Term Evolution - LTE L10 Training Programs. Catalog of Course Descriptions

Advanced SIP Series: SIP and 3GPP Operations

LTE Solutions LE 5.0 Release Training Catalog

4G Mobile Networks At Risk

Network Optimization based on performance and capacity criteria

Wanderlust: Enabling roaming in the LTE era. Don Troshynski Vice President, Solutions Architecture

WiFi Direct and LTE D2D in Action

A Layer-2 Approach for Mobility and Transport in the Mobile Backhaul

Virtual Evolved Packet Core

LTE - Can SDN paradigm be applied?

Network Access Security in Mobile 4G LTE. Huang Zheng Xiong Jiaxi An Sihua

LTE transport network security Jason S. Boswell Head of Security Sales, NAM Nokia Siemens Networks

Long Term Evolution - LTE. A short overview

Contents. Preface. Acknowledgement. About the Author. Part I UMTS Networks

Introduction to Evolved Packet Core

MASTER THESIS. Luca Valtulina

Accelerating 4G Network Performance

Kamakshi Sridhar, PhD Distinguished Member of Technical Staff Director Wireless CTO organization

Architectural Overview of IP Multimedia Subsystem -IMS

Towards Software Defined Cellular Networks

3GPP Femtocells: Architecture and Protocols. by Gavin Horn

SOLUTIONS FOR ROAMING AND INTEROPERABILITY PROBLEMS BETWEEN LTE AND 2G OR 3G NETWORKS

EETS 8316 Wireless Networks Fall 2013

LTE Radio Layer 2, RRC and Radio Access Network Architecture

Mobility Management for All-IP Core Network

Migration to LTE: Infrastructure Impact. Maria E. Palamara Director CDMA-LTE Strategy Alcatel-Lucent January, 2009

How to secure an LTE-network: Just applying the 3GPP security standards and that's it?

Mobile Assurance. Centralized Roaming Management System (CRMS) Brochure.

Mobile IPv6 deployment opportunities in next generation 3GPP networks. I. Guardini E. Demaria M. La Monaca

Implementing ATCA Serving Gateways for LTE Networks

CS Fallback Function for Combined LTE and 3G Circuit Switched Services

Alcatel-Lucent Evolved Packet Core Solution:

LTE Pwnage: Hacking HLR/HSS and MME Core Network Elements. P1 Security

Implementing LTE International Data Roaming

New Control Plane in 3GPP LTE/EPC Architecture for On-Demand Connectivity Service

Comparison of LTE and WiMAX on the Basis of Qualities

ETSI TS V ( ) Technical Specification

Mobility Management. Sara Modarres Razavi

Nationwide Interoperability Framework

What is going on in Mobile Broadband Networks?

Voice over LTE Telephony on the National Public Safety Broadband Network

Whitepaper. 10 Metrics to Monitor in the LTE Network. blog.sevone.com

Voice and SMS in LTE White Paper

Get the best performance from your LTE Network with MOBIPASS

LTE Control Plane on Intel Architecture

Transcription:

LTE Attach and Default Bearer Setup Messaging 2012 Inc. All Rights Reserved

LTE Attach Message Sequence Chart enodeb MME SGW HSS Initial UE Message Update Location Update Location Answer Create Session Create Session Response Initial Context Setup + Attach Accept + Activate Default Bearer Initial Context Setup Response Attach Complete + Activate Default Bearer Accept Modify Bearer 2012 Inc. 2

S1AP Initial UE Message S1AP: enodeb MME S1AP Initial UE Message Id: enb UE S1AP ID Initial UE Message is the first message sent to the MME to establish a connection Tracking Area Id Tracking Area Code Cell Id The enode uses the enb-ue-s1ap- ID to uniquely identify the UE EPS attach type may be: EPS Attach: UE is attaching only to the 4G LTE network Combined EPS/IMSI Attach: The UE identity is specified is: IMSI: If the UE has is not registered with the network Old GUTI: Subsequent attach requests identify the UE with the Old GUTI Attach EPS attach type Identity EPS Encryption Algorithm Supported EPS Integrity Algorithm Supported EPS Attach Combined EPS/IMSI Attach IMSI Old GUTI PDN Type: IPV4 Connection Type: Initial Attach 2012 Inc. 3

Diameter Update Location S6A: MME HSS Diameter Update Location MME updates the UE location with the HSS Origin and Destination are specified as Host and Realm (domain) The user name in the request is set to IMSI The Radio Access Technology is specified in the RAT Type It will be set to EUTRAN for LTE access The Visited PLMN is also included in the message Command Code Application Id Origin Destination User Name Update Location S6a interface application Host Realm Host Realm IMSI RAT Type EUTRAN MCC Visited PLMN Id MNC 2012 Inc. 4

Diameter Update Location Answer S6A: MME HSS Diameter Update Location Answer The HSS accesses the database and responds with user information to the MME The Aggregate Maximum Bit Rate (AMBR) occurs twice in the message: The first occurrence specifies the maximum bit rate for the default PDP context Result Code: Success Subscriber Status: Service Granted Aggregate Maximum Bit Rate Access Restriction Data MSISDN Maximum ed Bandwidth Uplink Maximum ed Bandwidth Downlink Called Station Id PDN Type IPV4 The second occurrence specifies the data maximum data limit via the APN. These limits are specified by the PDN APN configuration also includes: IP address of the PDN Gateway. This address is used to determine the default route for the traffic towards the Internet APN Configuration Profile PDN GW Address PDN GW Name QoS Class Identifier QCI specifies BER, Priority, GBR IP address assigned to the UE (Served Party IP Address) Served Party IP Address 3GPP Charging Characteristics Aggregate Maximum Bit Rate Maximum ed Bandwidth Uplink Maximum ed Bandwidth Downlink 2012 Inc. 5

Default Bearer Establishment MME SGW: Create Session SGW PGW: Create Session The SGW asks the PGW to establish the bearer SGW PGW: Create Session Response The PGW establishes the bearer and responds back to the SGW MME SGW: Create Session Response The SGW responds back to the MME 2012 Inc. 6

GTP Create Session S11: MME SGW GTP Create Session IMSI RAT Type EUTRAN TEID MME initiates the default route establishment by asking the SGW to create a GTP tunnel Sender F-TEID for Control Plane MME IP Address EPS Bearer Id The source is identified by the fully qualified endpoint identifier with the Tunnel Endpoint Identifier (TEID) and the MME IP Address The IP Address assigned to the UE is also included along with the downlink and uplink maximum data rates allowed at the APN level PDN Type Bearer Context MSISDN TAI IPV4 OR IPV6 ARP QCI MCC, MNC, TAC QCI specifies BER, Priority, GBR The TAI and ECGI (E-UTRAN Cell Group Identifier) information identify the current location of the user ECGI Contents PGW S5/S9 Address for Control MCC, MNC, ECI TEID PGW IP Address PDN IP Address APN PDN Address Allocation IP Address Assigned to UE Aggregate Max Bit Rate APN Limit Downlink and Uplink 2012 Inc. 7

Initial Context / Attach Accept/ Default Bearer S1AP: enodeb MME S1AP Initial Context Setup NAS Attach Accept Activate Default Bearer The next message from the MME is really a three-in-one. The message contains: SIAP Initial Context Setup A request to establish a context between the MME and enodeb The message contains SGW tunneling information NAS Attach Accept This message acknowledges the successful Attach to the UE. The enodeb will pass this message to the UE Activate Default Bearer The message initiates the default bearer setup on the UE The enodeb will pass this message to the UE S1AP PDU EPS mobility management messages EPS session management messages S1AP Initial Context Setup NAS Attach Accept Activate Default Bearer 2012 Inc. 8

SIAP Initial Context Setup S1AP: enodeb MME S1AP Initial Context Setup The MME responds with MME UE S1AP ID that was received from the enodeb in the initial UE message The message also contains the MME UE S1AP ID The message contains the maximum aggregate bit rate information. The message also contains the information about the default erab. QCI to assign session priority The maximum bit rate for the erab Guaranteed bit rate for the erab Transport Layer Address assigns the IP Address for the user plane entity on the S-GW GTP TE ID identifies the S-GW end of the user plane tunnel The security capabilities specify the encryption and integrity protection algorithm to be used for the UE session MME UE S1AP ID ENB UE S1AP ID Aggregate Max Bitrate (AMBR) erabs to Setup UE Security Capability Security Key Downlink Uplink erab ID Encryption Algorithm Integrity Protection Algorithm QCI erab Max Bit Rate Downlink erab Max Bit Rate Uplink RAB Guaranteed Bit Rate Downlink RAB Guaranteed Bit Rate Uplink Transport Layer Address GTP TE ID 2012 Inc. 9

NAS Attach Accept enodeb MME UE enodeb NAS Attach Accept The Attach Accept is carried as NAS payload in the Initial Context Setup The message specifies that the attach has been successful. The terminal is attached to the EPS only (i.e. LTE only, no SGSN registration) The T3412 timer specifies the maximum time between tracking area updates from the terminal The TAI list in the message specifies the PLMN and the Tracking Area Codes for all the registered tracking areas The message contains GUTI. GUTI uniquely identifies the UE with PLMN, MME Group, MMC code and the M-TMSI Finally, the GPRS Ready timer is included in the message. The UE will be transitioned to IDLE if no activity is detected for this period EPS Attach Result T3412 TAI List GUTI GPRS Ready Timer EPS Only Type Partial TAI List MCC MNC MME Group Id MME Code M-TMSI One PLMN PLMN TAC List 2012 Inc. 10

Activate Default Bearer enodeb MME UE enodeb Activate Default Bearer The Attach Accept is carried as NAS payload in the Initial Context Setup The EPS Bearer id identifies the bearer that needs to be activated The EPS QoS carries quality of service information: QCI to assign session priority The maximum bit rate for the bearer Guaranteed bit rate for the bearer The Access Point Name (APN) is included in the message The PDN IP address assigned by the HSS is passed to the UE EPS Bearer Id EPS QoS Access Point Name PDN Address QCI erab Max Bit Rate Downlink erab Max Bit Rate Uplink RAB Guaranteed Bit Rate Downlink RAB Guaranteed Bit Rate Uplink 2012 Inc. 11

S1AP Initial Context Setup Response enodeb MME Initial Context Setup Response The enodeb sends the Initial Context Setup Response message to the MME. The message confirms the establishment of the GTP tunnel on the S1-U interface MME UE S1AP ID The message contains information about the RABs that are being established at startup. The following information is present for each RAB enb UE S1AP ID E-RAB Setup List E-RAB Setup Item E-RAB ID Transport Layer Address The E-RAB ID The transport layer IP address on the enodeb. GTP TEID The enodeb GTP Tunneling ID (TEID) for the enodeb side. 2012 Inc. 12

Completing the Attach and Default Bearer Activation enodeb MME: Attach Complete + Activate Default Bearer Accept enodeb transports Attach Complete and Activate Default Bearer Accept The message was received from the UE MME SGW: Modify Bearer Inform SGW about the enodeb s user plane IP address and GTP TEID 2012 Inc. 13

Thank You Thank you for visiting. The following links provide more information about telecom design tools and techniques: Links EventStudio System Designer VisualEther Protocol Analyzer Telecom Call Flows TCP/IP Sequence Diagrams Telecom Networking Software Description Sequence diagram based systems engineering tool. Wireshark based visual protocol analysis and system design reverse engineering tool. GSM, SIP, H.323, ISUP, LTE and IMS call flows. TCP/IP explained with sequence diagrams. Real-time and embedded systems, call flows and object oriented design articles. 2012 Inc. 14