3GPP Node Location Verification for Untrusted Network Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current 3GPP systems face challenges in providing accurate access authorization and roaming restrictions for Voice over WiFi services when using untrusted non-3GPP networks, as they lack the necessary location information to determine whether a user is within their home domain or roaming, leading to potential unauthorized access.
Innovation Solution
The method involves checking for available trusted 3GPP network location information and, if obsolete, deriving untrusted network location using the 3GPP AAA server or GeoIP database to determine if the UE is allowed to access services via untrusted non-3GPP networks, allowing operators to define access authorization and restrict Voice over WiFi services during roaming.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If trusted 3GPP network location information is used for access authorization, then access control accuracy is improved, but network complexity increases due to requiring updates from subscriber databases
Solution Approach 1:
The system performs preliminary actions by checking whether trusted 3GPP network location information is available from the subscriber database before attempting to access services. This advance check allows the system to prepare appropriate fallback mechanisms (using untrusted non-3GPP location information or deriving location from IP address) without requiring complex real-time updates to network settings or infrastructure.
2Adaptability or versatility
If untrusted non-3GPP network location information is used, then network compatibility is improved, but access control reliability deteriorates due to potential unauthorized access
Solution Approach 1:
The system introduces an intermediary verification mechanism by first attempting to obtain trusted location information from the subscriber database. Only when this intermediary source is unavailable or obsolete does the system resort to using untrusted non-3GPP network location information. This layered approach maintains reliability by preferring trusted sources while preserving compatibility with untrusted networks as a fallback option.
3Ease of manufacture
If location information is derived using GeoIP database, then implementation simplicity is improved, but measurement precision deteriorates compared to trusted network location
Solution Approach 1:
The system applies partial action by using GeoIP database derivation only as a fallback when trusted location information is unavailable. The solution does not exclusively rely on GeoIP but rather uses it partially to supplement or replace trusted location data when necessary. This approach balances implementation simplicity with acceptable location accuracy for access control decisions.
Data Source
AI summary
Embodiments herein relate to a 3rd Generation Partnership Project, 3GPP, infrastructure node, a method in the 3GPP infrastructure node, 3GPP Access, Authorization, and Accounting, AAA server, a method in the 3GPP AAA server, a Home Subscriber Server, HSS and a method in the HSS. More particularly the embodiments herein relate to handling a UE requesting access to a service via an untrusted non-3GPP network. According to a first aspect, a method performed by a 3GPP node for handling a UE, requesting access to a service via an untrusted non-3GPP network is provided. The method comprises checking if trusted 3GPP network location information associated with the UE is available to the 3GPP node from a subscriber database or if the available trusted 3GPP network location information is obsolete. If the trusted 3GPP network location information is unavailable or obsolete, the method comprises determining to use untrusted non-3GPP network location information previously received from the 3GPP AAA server or to derive the untrusted non-3GPP network location information at the 3GPP node. Still further, the method comprises determining if the UE is allowed or barred to access the service via the untrusted non-3GPP network based on the received or derived untrusted non-3GPP network location information. The embodiments herein, relate also to corresponding methods performed in an 3GPP Access, Authorization, and Accounting, AAA server, and a Home Subscriber Server, HSS, respectively. Further, the embodiments herein relate also to corresponding 3GPP infrastructure node, 3GPP AAA server, and HSS.


