3GPP Node Location Verification for Untrusted Network Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current 3GPP systems face challenges in providing accurate access authorization and roaming restrictions for Voice over WiFi services when using untrusted non-3GPP networks, as they lack the necessary location information to determine whether a user is within their home domain or roaming, leading to potential unauthorized access.

Innovation Solution

The method involves checking for available trusted 3GPP network location information and, if obsolete, deriving untrusted network location using the 3GPP AAA server or GeoIP database to determine if the UE is allowed to access services via untrusted non-3GPP networks, allowing operators to define access authorization and restrict Voice over WiFi services during roaming.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If trusted 3GPP network location information is used for access authorization, then access control accuracy is improved, but network complexity increases due to requiring updates from subscriber databases

Engineering Contradiction:
Improvelocation information accuracyVSAvoidnetwork complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by checking whether trusted 3GPP network location information is available from the subscriber database before attempting to access services. This advance check allows the system to prepare appropriate fallback mechanisms (using untrusted non-3GPP location information or deriving location from IP address) without requiring complex real-time updates to network settings or infrastructure.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If untrusted non-3GPP network location information is used, then network compatibility is improved, but access control reliability deteriorates due to potential unauthorized access

Engineering Contradiction:
Improvenetwork compatibilityVSAvoidaccess control reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system introduces an intermediary verification mechanism by first attempting to obtain trusted location information from the subscriber database. Only when this intermediary source is unavailable or obsolete does the system resort to using untrusted non-3GPP network location information. This layered approach maintains reliability by preferring trusted sources while preserving compatibility with untrusted networks as a fallback option.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of manufacture

If location information is derived using GeoIP database, then implementation simplicity is improved, but measurement precision deteriorates compared to trusted network location

Engineering Contradiction:
Improveimplementation simplicityVSAvoidlocation information accuracy
Core Design Contradiction:
Ease of manufactureVSMeasurement precision

Solution Approach 1:

The system applies partial action by using GeoIP database derivation only as a fallback when trusted location information is unavailable. The solution does not exclusively rely on GeoIP but rather uses it partially to supplement or replace trusted location data when necessary. This approach balances implementation simplicity with acceptable location accuracy for access control decisions.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10182053B2Methods and nodes for handling access to a service via an untrusted non-3GPP network
Publication Date: 2019.01.15 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US10182053B2 patent drawing
  • US10182053B2 patent drawing
  • US10182053B2 patent drawing

AI summary

Embodiments herein relate to a 3rd Generation Partnership Project, 3GPP, infrastructure node, a method in the 3GPP infrastructure node, 3GPP Access, Authorization, and Accounting, AAA server, a method in the 3GPP AAA server, a Home Subscriber Server, HSS and a method in the HSS. More particularly the embodiments herein relate to handling a UE requesting access to a service via an untrusted non-3GPP network. According to a first aspect, a method performed by a 3GPP node for handling a UE, requesting access to a service via an untrusted non-3GPP network is provided. The method comprises checking if trusted 3GPP network location information associated with the UE is available to the 3GPP node from a subscriber database or if the available trusted 3GPP network location information is obsolete. If the trusted 3GPP network location information is unavailable or obsolete, the method comprises determining to use untrusted non-3GPP network location information previously received from the 3GPP AAA server or to derive the untrusted non-3GPP network location information at the 3GPP node. Still further, the method comprises determining if the UE is allowed or barred to access the service via the untrusted non-3GPP network based on the received or derived untrusted non-3GPP network location information. The embodiments herein, relate also to corresponding methods performed in an 3GPP Access, Authorization, and Accounting, AAA server, and a Home Subscriber Server, HSS, respectively. Further, the embodiments herein relate also to corresponding 3GPP infrastructure node, 3GPP AAA server, and HSS.