Service Provider Wi-Fi Integration Dave Dukinfield
Cisco Confidential 2
Cisco Confidential 3
Cisco Confidential 4
Cisco Confidential 5
Cellular versus Wi-Fi (Public and Private) Domestic Cellular data has lost the battle with residential Wi-Fi Mobidia data indicates that Private Wi-Fi carrying over 4-times cellular domestic traffic Cellular roaming has lost the battle with Public Wi-Fi Mobidia data indicates that Public Wi-Fi carrying between 2- and 5-times cellular roaming traffic Domestic Cellular data is being challenged by Public Wi-Fi Mobidia data indicates that Public Wi-Fi carrying around 30% of all domestic cellular traffic Cisco Confidential 6
But surely Wi-Fi is all about best effort data what about voice? Pay monthly MOUs have fallen by nearly 20% in 5 years (in the UK) Why optimize architecture the future networks to support the past business model? Voice migrating to OTT - Skype app is among the top 10 downloads of all time for Windows Phone, ios and Android. In July 2013, Skype confirmed that its app had been downloaded over 100 million times by Android devices alone. Cisco Confidential 7
Integrate this (into your mission statement) 1. Wi-Fi already carrying the bulk of smartphone data 2. IEEE 802.11ac already delivering speeds in excess of LTE-Advanced 3. Carrier neutrality enables Wi-Fi to be supported by venue-centric value chains 4. Wi-Fi Calling and imessenger demonstrate how the most valuable cellular bytes can now be transported over Wi-Fi networks 5. Carrier Wi-Fi networks have already leapfrogged LTE in terms of dimensioning average per user sustained busy hour rates approaching 100 kbps in certain deployments 6. Overly complex cellular architecture is no longer needed in a good enough world Cisco Confidential 8
Your Relationship with WiFi Phase 1: Wi-Fi as the POOR relation Phase 2: Wi-Fi as the GOOD neighbor Phase 3: Wi-Fi as your BEST friend 1. Wi-Fi untrusted and unmanaged 2. OTT IPSec the only way to access carrier services 3. Separate parallel networks to deal with Wi-Fi 1. Wi-Fi trusted but still viewed as being deficient compared with LTE 2. LTE-LAA arguments include focus on guarantees (Coverage/ Capacity/QoS), policy/ management, service continuity 1. Wi-Fi delivering end-toend QoE for rich media support 2. Wi-Fi delivering scale beyond LTE 3. Wi-Fi delivering best in class visibility, for our customers and our customers customer Cisco Confidential 9
Voice Support Cisco Confidential 10
4 options for Wi-Fi Calling Integration MNO Wi-Fi Calling Application MNO Wi-Fi Calling Application MNO Wi-Fi Calling Application MNO Wi-Fi Calling Application No relationship Wi-Fi Calling Security GW addresses published to assist in FW rule configuration MNO Managed Identity (AKA/SIM) MNO Managed Identity (AKA/SIM) No Identity Management (Pre-shared keys) Enterprise Managed Identity (AD/LDAP) Baseline AAA roaming support for EAP-SIM/ EAP-AKA AAA based BBERF integration with Wi-Fi calling Unmanaged Wi-Fi Enterprise Managed Wi-Fi SP Managed Wi-Fi with AAA roaming identity support MNO Managed Wi-Fi with AAA support for dynamic QoS 1. Residential/Unmanaged 2. Enterprise Managed Wi-Fi 3. SP Managed roaming Wi-Fi 4. Integrated BBERF Cisco Confidential 11
Wi-Fi Calling Co-existence: It s a client issue SWu Client IMS-APN SWu Traffic Host: 10.10.1.1 Trusted/Non- Trusted Policy NSWO Policy 802.11 WLAN Access epdg NSWO-Traffic Native Client Cisco Confidential 12
Moving to Standard s Based Handover IKEv2 allocated 2610:8dba: 82e1:ffff::/64 Swu IKEv2 IMS-APN epdg Host: 10.10.1.1 S2b IMS APN UE Pool: 2610.8dba: 82e1:ffff::/48 IPv6 IMS based Wi-Fi Calling Service NSWO + Wi-Fi Calling Client NAS Allocated: 2610:8dba: 82e1:ffff::/64 LTE Uu: NAS IMS-APN enb S1 S-GW S5 IMS APN P-GW Seamless mobility between LTE and WiFi Node selection by the epdg ensures same PGW is selected IP address(es) are preserved PCRF, OCS, OFCS are updated with new RAT type But NW looses location, time zone and QoS on Wi-Fi Cisco Confidential 13
Untrusted Access Cisco Confidential 14
3GPP epdg Functional Architecture Home HLR AAA SWx P-GW IP services Packet Core DHCP SWm S2b PMIPv6 GTPv2 WiFi access epdg SWu Untrusted network (e.g. home Wi-Fi) SWu IPSec Cisco Confidential 15
VoWi-Fi Network Architecture Internet VoWifi Architecture requires: epdg 3GPP AAA HSS/HLR PGW PCRF TAS IMS Core PGW with s2b support PCRF IMS Core infrastructure TAS AAA S5/S8 Gi VoWifi capable UEs HSS VoWifi capable UE pre-loaded with operator profile SWm S2b PMIPv6 GTPv2 MME/ SGW SGSN MSC UE discovers the epdg using DNS lookup for epdg FQDN Statically or dynamically configured in Operator File epdg Wi-Fi access 3GPP access UE establishes IPSEC tunnel to epdg SWn RNC epdg sets up a PDN session to PGW on behalf of UE PGW allocates IP address and manages P-CSCF discovery provides P-CSCF details to UE Untrusted network (e.g. home/ent) UE SIP registers with SBC/PCSCF SWu UE makes/receives call via IMS/TAS P-CSCF discovery over IKE or operator profile IMS/VoLTE IPSec enodeb NodeB Cisco Confidential 16
epdg Main Functions User Authentication and Authorization IKEv2 based on EAP-AKA (Extensible Auth Protocol - Authentication and Key Agreement) De-capsulation/Encapsulation of packets for IPSec Tunnel authentication and authorization APN authorization to HSS via AAA PGW Selection DNS queries for dynamic PGW selection Selects PGW if instructed to perform static selection Retrieves PGW address from AAA during inter system Hos Tunnel and QoS mapping between S2b bearers and AN Mapping of S2b bearer(s) to SWu (IPSec) sessions DSCP marking/tagging for QoS Enforcement of QoS policies based on information received over S2b CP (GTPC) Several other features DOS protection Inter-RAT HO Provision of Roaming info Overload protection Cisco Confidential 17
Trusted Access Cisco Confidential 18
SaMOG GW Trusted WiFi Integration into MPC/EPC TWAP: Trusted WLAN AAA Proxy Subscriber authentication and authorization based on EPC credentials EAP-AKA, EAP-AKA and EAP-SIM over Radius 3GPP Diameter STa interface support Radius interface towards Trusted WLAN (WLC, AP) Subscriber session management (attach, detach and accounting triggers) UE session establishment upon EAP success UE session teardown based on Radius message from Trusted WLAN Radius accounting message support TWAG: Trusted WLAN Access Gateway Datapath connectivity to EPC for Tunnel Switching and packet forwarding S2a interface to the PGW (3GPP TR 23.852 ) GTPv2-C (control), GTP-U (for data) Bearer management support Cisco Confidential 19
SaMOG GW (LTE) Home SWx HSS AAA P-GW SGi Gi internet Packet Core WiFi access TWAP intercepts EAP-SIM messages to trigger session Web Portal Non EAP-SIM Cisco-WLC STa (Diameter) Radius EAP-SIM TWAP PMIPv6 DHCP TWAG S2a GTPv2 EoGRE Local Breakout Non-Cisco WLC Cisco Confidential 20
Thank you.
epdg as defined in Standards epdg is part of the 3GPP LTE SAE defined in 3GPP TS 23.402 PGW information updated in case of IRAT mobility Required for UE Authentication and Service Authorization HSS SWx epdg is responsible for interworking between the EPC and un-trusted non-3gpp networks, such as WiFi access networks. epdg terminates IPSec tunnels established/initiated by UEs via un-trusted WiFi network for secure access to the EPC. HPLMN Non-3GPP Networks 3GPP Access S6a Serving Gateway S5 Non-3GPP Gxc S2a PDN Gateway S2b Gx Trusted Non-3GPP IP Access Gxa epdg PCRF SWu Gxb SWn SGi Rx S6b SWm Untrusted Non-3GPP IP Access UE Operator's IP Services (e.g. IMS, PSS etc.) SWa 3GPP AAA Server STa WiFi Un-trusted Cisco Confidential 22