Untrusted Network Location Delivery via ePDG Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current 3GPP specifications do not provide a method for delivering specific location information for a UE connected to an untrusted non-3GPP access network, leading to potential inaccuracies in location determination, especially when the ePDG is located differently from the UE.

Innovation Solution

The apparatus and method involve checking and authenticating terminal access to a non-3GPP network, providing location information through an access-network-info attribute value pair, and ensuring that this information is delivered to the 3GPP AAA Server and PGW, even in untrusted networks, by reusing existing signaling mechanisms and expanding AVPs to include location information for various access types.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If ePDG is used for untrusted non-3GPP access, then network security is improved, but location information accuracy deteriorates

Engineering Contradiction:
Improvenetwork securityVSAvoidlocation information accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent introduces an intermediary mechanism (ePDG) that acts as a mediator between untrusted non-3GPP access networks and the 3GPP core network. This intermediary enables secure access while the invention further enhances location accuracy by introducing additional location determination mechanisms that work through this intermediary to overcome the location precision deterioration caused by the ePDG abstraction layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If location information is requested from HSS for untrusted access, then location service coverage is improved, but signaling complexity increases

Engineering Contradiction:
Improvelocation service coverageVSAvoidsignaling complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies universality by making the HSS serve multiple functions - it not only authenticates users but also determines and provides location information for both trusted and untrusted access types. The invention extends the existing HSS functionality to handle untrusted access scenarios, allowing a single network element to provide location services across different access types without requiring separate dedicated systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements preliminary action by having the HSS determine and store location information in advance during the authentication process. When location services are needed, the information is already available from prior authentication procedures, eliminating the need for separate location request-signaling exchanges and reducing overall signaling complexity.

Inventive Principle:
Principle #10Preliminary action

3Ease of manufacture

If ePDG location is used as UE location approximation, then implementation simplicity is improved, but location accuracy deteriorates

Engineering Contradiction:
Improveimplementation simplicityVSAvoidlocation accuracy
Core Design Contradiction:
Ease of manufactureVSMeasurement precision

Solution Approach 1:

The patent applies the copying principle by creating and using alternative location determination methods that copy or replicate the location information gathering capability from trusted access scenarios. Instead of relying solely on the crude ePDG location approximation, the invention implements mechanisms to obtain and use actual UE location information through the ePDG, effectively copying the location determination functionality that exists for trusted accesses.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11019486B2Location information for untrusted access
Publication Date: 2021.05.25 NOKIA SOLUTIONS & NETWORKS OY
  • US11019486B2 patent drawing
  • US11019486B2 patent drawing
  • US11019486B2 patent drawing

AI summary

It is provided a method, comprising monitoring if a tunnel to a terminal via an untrusted network is to be established, wherein the tunnel is set up only if the terminal is authenticated and authorized; requesting, if the tunnel is to be established, the authentication and authorization and an information on a location of the terminal; providing the information on the location received in response to the request to a gateway.