Untrusted Network Location Delivery via ePDG Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current 3GPP specifications do not provide a method for delivering specific location information for a UE connected to an untrusted non-3GPP access network, leading to potential inaccuracies in location determination, especially when the ePDG is located differently from the UE.
Innovation Solution
The apparatus and method involve checking and authenticating terminal access to a non-3GPP network, providing location information through an access-network-info attribute value pair, and ensuring that this information is delivered to the 3GPP AAA Server and PGW, even in untrusted networks, by reusing existing signaling mechanisms and expanding AVPs to include location information for various access types.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If ePDG is used for untrusted non-3GPP access, then network security is improved, but location information accuracy deteriorates
Solution Approach 1:
The patent introduces an intermediary mechanism (ePDG) that acts as a mediator between untrusted non-3GPP access networks and the 3GPP core network. This intermediary enables secure access while the invention further enhances location accuracy by introducing additional location determination mechanisms that work through this intermediary to overcome the location precision deterioration caused by the ePDG abstraction layer.
2Adaptability or versatility
If location information is requested from HSS for untrusted access, then location service coverage is improved, but signaling complexity increases
Solution Approach 1:
The patent applies universality by making the HSS serve multiple functions - it not only authenticates users but also determines and provides location information for both trusted and untrusted access types. The invention extends the existing HSS functionality to handle untrusted access scenarios, allowing a single network element to provide location services across different access types without requiring separate dedicated systems.
Solution Approach 2:
The patent implements preliminary action by having the HSS determine and store location information in advance during the authentication process. When location services are needed, the information is already available from prior authentication procedures, eliminating the need for separate location request-signaling exchanges and reducing overall signaling complexity.
3Ease of manufacture
If ePDG location is used as UE location approximation, then implementation simplicity is improved, but location accuracy deteriorates
Solution Approach 1:
The patent applies the copying principle by creating and using alternative location determination methods that copy or replicate the location information gathering capability from trusted access scenarios. Instead of relying solely on the crude ePDG location approximation, the invention implements mechanisms to obtain and use actual UE location information through the ePDG, effectively copying the location determination functionality that exists for trusted accesses.
Data Source
AI summary
It is provided a method, comprising monitoring if a tunnel to a terminal via an untrusted network is to be established, wherein the tunnel is set up only if the terminal is authenticated and authorized; requesting, if the tunnel is to be established, the authentication and authorization and an information on a location of the terminal; providing the information on the location received in response to the request to a gateway.


