WiFi Roaming Gatekeeping via IP-Based Location Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cellular network operators face challenges in restricting the use of their resources by user equipment (UE) located in specific geographical regions when UE attempts to make calls via WiFi, as the internet's global reach makes it difficult to determine the UE's location, unlike traditional cellular connections.
Innovation Solution
Implementing a gatekeeping mechanism where a first wireless network node receives an authentication request from a second wireless network node, determines the UE's location based on its network address, and blocks the call if it is not permitted, ensuring that roaming UE's calls are restricted in prohibited regions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If WiFi calling is allowed without location verification, then UE can place calls from anywhere via internet, but cellular network resources may be abused by UEs in restricted geographical regions
Solution Approach 1:
The patent introduces an authentication server as an intermediary between the UE and the cellular network. This server receives authentication requests from the ePDG, determines UE location based on IP address, and decides whether to permit or block the call. This intermediary resolves the contradiction by enabling versatile call placement while preventing resource abuse through location-based authorization.
Solution Approach 2:
The patent implements preliminary location verification and authorization before allowing WiFi calls to use cellular network resources. The authentication server checks the UE's location and roaming permissions in advance, blocking unauthorized calls before they consume network resources. This preliminary action prevents resource abuse while maintaining call versatility for authorized users.
2Object-affected harmful factors
If location determination is implemented for WiFi callers, then resource protection is improved, but system complexity increases due to additional authentication mechanisms
Solution Approach 1:
The patent makes the authentication server multi-functional by having it perform both authentication and location determination tasks. Instead of adding separate dedicated systems, the existing authentication server is enhanced to also determine UE location based on IP address and make authorization decisions. This universality reduces overall system complexity while improving resource protection.
Solution Approach 2:
The patent implements a self-service mechanism where the authentication server automatically determines UE location from IP address and makes authorization decisions without requiring manual intervention or additional complex infrastructure. The system serves itself by using readily available IP address information to perform location-based authorization, reducing complexity while improving resource protection.
3Measurement precision
If IP address-based location determination is used, then location identification becomes possible, but measurement precision may be insufficient compared to cellular base station location
Solution Approach 1:
The patent applies partial action by using IP address-based location determination only when necessary for WiFi calls, rather than requiring precise location measurement in all cases. For cellular calls, traditional base station location methods are used. This partial application resolves the contradiction by providing sufficient location identification capability for resource protection without demanding excessive measurement precision that would be difficult to achieve.
Data Source
AI summary
Gatekeeping for roaming WiFi callers includes: receiving, by a first wireless network node, from a second wireless network node, an authentication request identifying a user equipment (UE) that is requesting a call over WiFi and identifying a network address of the UE; based on at least the network address of the UE, determining a location of the UE; based on at least the location of the UE, determining whether the call is permitted; based on at least determining that the call is not permitted for the UE, responding with a message that blocks the call. Solutions also include: receiving, by the second wireless network node, from a packet data gateway, a request for a call over WiFi; based on at least receiving the request, transmitting the authentication request to the first wireless network node, the authentication request identifying the network address of the UE.


