1 Remote IP Access - Stage 2 Architecture proposal for adoption Peerapol Tinnakornsrisuphap Anand.

Slides:



Advertisements
Similar presentations
Dynamic HA Assignment for MIPv4 in WLAN Interworking Raymond Hsu, Qualcomm Inc., Wing C. Lau, Qualcomm Inc., Notice:
Advertisements

MIP6-HA-Local-Assignment-Capability indication to MS Contributors grant a free, irrevocable license to 3GPP2 and its Organization Partners.
HUAWEI TECHNOLOGIES CO., LTD. Huawei Technologies Co., Ltd. grant a free, irrevocable license to 3GPP2 and its Organizational Partners to.
1 DSMIP6 Support QUALCOMM Inc. Jun Wang, George Cherian, Masa Shirota Notice.
IP Connectivity for E911 in HRPD/PDS Networks Page 1 IP Connectivity for Emergency Calls in HRPD/PDS Networks 3GPP2 Meeting, 1/07 IP Connectivity for Emergency.
XHRPD Example Scenario for MSS Masa Shirota Qualcomm Inc. July 15, GPP2 Dalian Meeting Recommendation: FYI Notice QUALCOMM Incorporated grants a.
1 Notice Contributors grant a free, irrevocable license to 3GPP2 and its Organization Partners to incorporate text or other copyrightable material contained.
HRPD Femto Local IP Access: Overview Peerapol Tinnakornsrisuphap Qualcomm October 27 th, GPP2 Seoul,
1 IP Service Authorization Support and Mobility Selection for X.S0011-E Source: QUALCOMM Inc.: Masa Shirota, George Cherian, Jun Wang,
1 UATI-IP address mapping Peerapol Tinnakornsrisuphap David Ott Qualcomm.
1 Title: TDF support in cdma2000 1x and HRPD Networks Sources: China Telecom, ZTE, Huawei Contact: CT: Heng Nie ( ), Congjie Mao(
China Telecomm Peirong Xie ZTE Corporation Rajesh Bhalla Huawei Jixing Liu
1 May 14, 2007 Zhibi Wang, Simon Mizikovsky – Alcatel-Lucent Vidya Narayanan, Anand Palanigounder – QUALCOMM ABSTRACT: Access authentication architecture.
1 cdma2000® Data Service Transition to NULL Support Jun Wang Ravi Patwardhan June 5, 2003 Recommendation -
3GPP2 X xxx Title: SIP6 access and MIP6 Access Differentiation Sources: ZTE Contact: Rajesh Bhalla
Broadcast Area Based Management for BCMCS Quanzhong Gao Weidong Wu 04/05/2005.
Security Framework for (e)HRPD 1 S GPP2 TSG-S WG4 Source: QUALCOMM Incorporated Contact(s): Anand Palanigounder
1 IPsec-based MIP6 Security Qualcomm Inc. Starent Inc. Notice: Contributors grant free, irrevocable license to 3GPP2 and its Organization Partners to incorporate.
1 Title:Using group of artificial pilots to identify target femtocell during active hand-in Source:Peerapol Tinnakornsrisuphap, Ravindra Patwardhan QUALCOMM.
Authentication Profile for UICC- less eHRPD Terminals QUALCOMM Incorporated Contact(s): Anand Palanigounder Jun Wang.
1 Notice Contributors grant a free, irrevocable license to 3GPP2 and its Organization Partners to incorporate text or other copyrightable material contained.
QUALCOMM Incorporated 1 Protocol Options for BSN- BSMCS Controller Interface Jun Wang, Kirti Gupta 05/16/2005 Notice: Contributors grant a free, irrevocable.
Broadcast/Multicast Priority List JUNHYUK SONG SAMSUNG Incorporated grants a free, irrevocable license to 3GPP2 and its Organization Partners to incorporate.
QUALCOMM PROPRIETARY 3GPP2 Network Evolution Architecture Dec. 04, 2006 Lucent Technologies Nortel Networks Qualcomm Inc. Hitachi, Ltd Huawei Technologies.
1 A13 Proxy for supporting HRPD Handout from femto AP to macro AN Peerapol Tinnakornsrisuphap David Ott
C August 24, 2004 Page 1 SMS Spam Control Nobuyuki Uchida QUALCOMM Incorporated Notice ©2004 QUALCOMM Incorporated. All rights reserved.
1 SeGW Certificate profile (Revised) 3GPP2 TSG-S WG4 /TSG-X WG5 (PDS) S X xx Source: QUALCOMM Incorporated Contact(s): Anand.
Page 1 January 16, 2008 Source: 3GPP2 TSG-S WG4 (Security) Contacts: Anand Palanigounder, Chair, TSG-S WG4 ( Zhibi Wang,
Proposed 1x Device Binding Solution Based on SX & SX GPP2 TSG-SX WG4 SX Source(s): Qualcomm Incorporated.
80-VXXX-X A July 2008 Page 1 QUALCOMM Confidential and Proprietary PCC Support for cdma2000 QUALCOMM Inc. Jun Wang, George Cherian, Masa Shirota
Proposed Solution for Device Binding 3GPP2 TSG-S WG4 S Source: Qualcomm Incorporated Contact(s): Anand Palanigounder,
May 12, 2008 Alcatel Lucent, Cisco, Motorola, Nortel, Verizon ABSTRACT: Proposed is additional key hierarchy and derivation for EPS access over eHRPD.
X xxx ZTE Discussion on cdma2000 Charging with PCC Title: Discussion on PCC Charging for cdma2000 1x and HRPD Sources: China Telecom, ZTE Contact:
Mobility Management in WLAN IW Inma Carrion, Vijay DevarapalliNokia Raymond HsuQualcomm Inc. Pete McCann, Frank AlfanoLucent Serge ManningSprint Notice:
1 Authentication and User Profile April 24, 2007 Jun Wang QUALCOMM Inc. Notice Contributors grant a free, irrevocable license to 3GPP2 and its Organization.
HRPD Connection Layer Protocols for Inter-technology Handoff March 31 st, 2008 Peerapol Tinnakornsrisuphap
Title: Placement of ROHC, Authenticator and Requirements for a robust Mobility Management Scheme Abstract: This contribution proposes a new architectural.
Jun Wang Anand Palanigounder Peerapol Tinnakornsrisuphap
User Notification Protocol Nikolai Leung, QUALCOMM Incorporated (703) Notice: QUALCOMM Incorporated grants.
Active Call Hand-in in cdma2000 1x Airvana Qualcomm October 27 th, GPP2 Seoul, Korea Notice ©2008. All rights reserved. The contributors grants a.
ABSTRACT: This contribution proposes the HRPD-WiMAX handoff solution. TITLE: HRPD-WiMAX Handoff TSG-A WG4 RECOMMENDATION: Review and Adopt Samsung Electronics.
Supporting Local Breakout in HRPD Femto Peerapol Tinnakornsrisuphap Qualcomm Doug Knisely
Jun Wang Anand Palanigounder Peerapol Tinnakornsrisuphap
Remote access to Local IP network via Femto Peerapol Tinnakornsrisuphap Anand Palanigounder
Title: Network Firewall Configuration and Control (NFCC): High Level Overview Trevor Plestid x4138 Dan Willey
10/27/2008X xx-0021 Femto Initialization Aspects: Femto AP Auto- configuration procedures Source: QUALCOMM Inc Chandru Sundarrman
3GPP2 X xxx Title: Subscriber QoS Profile Support in eHRPD System Sources: China Telecom, ZTE Contact: CT: Peirong Li Wenyi.
Comment to Limited Idle Mode Nortel Networksgrants a free, irrevocable license to 3GPP2 and its Organizational Partners to incorporate text or other copyrightable.
Mobile Sensing Measurement Report for supporting 1x Active Hand-in Peerapol Tinnakornsrisuphap Chirag Patel
1 Discussion on Handoffs for 1x/HRPD Femtos Peerapol Tinnakornsrisuphap David Ott
Jun Wang Anand Palanigounder Peerapol Tinnakornsrisuphap
EHRPD-LTE Inter Technology Spectrum Optimization Source: Qualcomm Incorporated Contact: Jun Wang/George Cherian September 9, 2013 Notice ©2013. All rights.
EAP over HRPD Comments Qualcomm, Inc. Vidya Narayanan, Dondeti, Lakshminath, Jun Wang, Pete Barany Notice: QUALCOMM Incorporated grants a free, irrevocable.
Tunneling Protocol Structures for UMB to HRPD Interworking Linhai He Peerapol Tinnakornsrisuphap
1 MAPSUP in eHRPD: Data forwarding Tunnel Sources: ZTE Contact: Bi YiFeng Rajesh Bhalla
X xx CT+ZTE PCC for cdma2000 MS Init Call Flows 1 1 Title: PCC for cdma2000 – MS-Init Call Flow Example Sources: CTC, ZTE Contact: CHINA TELECOM.
1 HRPD Fast Handoff Jun Wang and Raymond Hsu Qualcomm Inc Notice: QUALCOMM Incorporated grants a free, irrevocable license to 3GPP2 and its Organization.
1 SAMSUNG BCMCS Security Architecture and Key Management JUNHYUK SONG SAMSUNG Incorporated grants a free, irrevocable license to 3GPP2 and its Organization.
1 PPP Free Operation Mobility Management January 16, 2006 Jun Wang, Pete Barany, Raymond Hsu Qualcomm Inc Notice: Contributors grant free, irrevocable.
1 On 3GPP2 Femto Security Anand Palanigounder Qualcomm Inc. Notice: Contributors grant a free, irrevocable license to 3GPP2 and its Organization.
Signaling Packet Routing for Layer 3 approach in UMB-HRPD/1x interworking KDDI Corporation, Tsunehiko Chiba, Osamu.
HUAWEI TECHNOLOGIES CO., LTD. HUAWEI TECHNOLOGIES Co., Ltd. Page 1 Zhiming Li 18 Feb Notice.
C August 19, 2003 Page 1 SMS Push Teleservice Nobuyuki Uchida QUALCOMM Incorporated Notice ©2003 QUALCOMM Incorporated. All rights reserved.QUALCOMM.
1 MSI (Multiple Service Instances) Ravindra Patwardhan QUALCOMM Incorporated Review and approve for D Notice QUALCOMM.
WLAN IW Enhancement for Multiple Authentications Support QUALCOMM Inc.: Raymond Hsu, QUALCOMM Inc.: Masa Shirota,
Clarifications on Work Split among TSG-X/A for 3GPP2 Network Evolution March 26, 2007 Airvana/Alcatel-Lucent/CTC/Fujitsu/ Hitachi/KDDI/NEC/Qualcomm/ZTE.
1 IP Service Authorization Support and Mobility Selection Source: QUALCOMM Inc.: Masa Shirota, George Cherian, Jun Wang,
1 Notice Contributors grant a free, irrevocable license to 3GPP2 and its Organization Partners to incorporate text or other copyrightable material contained.
Source: Qualcomm Incorporated Contact: Jun Wang, George Cherian March 1, 2010 Page 1 3GPP2 Femtocell Phase II Femto Access Control Enhancement Notice ©
E-UTRAN - HRPD rev B Interworking
Presentation transcript:

1 Remote IP Access - Stage 2 Architecture proposal for adoption Peerapol Tinnakornsrisuphap Anand Palanigounder Jun Wang Douglas Knisely Rajesh Bhalla ), Mar 30th, 2009 Notice ©2009. All rights reserved. The contributors grants a free, irrevocable license to 3GPP2 and its Organizational Partners to incorporate text or other copyrightable material contained in the contribution and any modifications thereof in the creation of 3GPP2 publications; to copyright and sell in Organizational Partner’s name any Organizational Partner’s standards publication even though it may include all or portions of this contribution; and at the Organizational Partner’s sole discretion to permit others to reproduce in whole or in part such contribution or the resulting Organizational Partner’s standards publication. The contributors are also willing to grant licenses under such contributor copyrights to third parties on reasonable, non-discriminatory terms and conditions for purpose of practicing an Organizational Partner’s standard which incorporates this contribution. This document has been prepared by the contributors to assist the development of specifications by 3GPP2. It is proposed to the Committee as a basis for discussion and is not to be construed as a binding proposal on the contributors. The contributors specifically reserves the right to amend or modify the material contained herein and nothing herein shall be construed as conferring or offering licenses or rights with respect to any intellectual property of the contributors other than provided in the copyright statement above.

Background Remote IP access: Allow AT to reach local IP network or server in the same domain as the Femto AP even when the AT is not connected over-the-air with the Femto AP We submitted High-level architecture to Feb 3GPP2 meeting in X In this contribution we provide further design details (e.g., architectural assumptions, security etc) for adoption at concept level at this meeting 2

Architectural Assumptions Operator offers Remote IP Access as an add-on service on a subscription basis Capabilities such as DCHP/ARP are available at the Femto AP to support Remote IP Access Femto APs that can be reached by a given AT, configured as part of the AT (subscription) profile at the Home AAA Femto APs can be identified by FEID or by realm (useful for group of femtos in enterprise deployment) User invokes the service on demand at the AT (e.g., by clicking “My Home”) 3

Proposed Architecture 4 Femto Gateway actsas VPN gatewayfor IPsec tunnel with ATFGW forwards any packetsreceived from AT to Femto APIPsec tunnelAT authentication is perfomedwith Home AAA using IKEv2EAP-AKA or IKEv2 PSK (reusingexisting AT’s IP subscriptioncredentials)Femto is DHCP server fromwhich FGW will request a localIP address and assign it to the ATas part of IKEv2FGW forwards selected packetsfrom Femto AP to AT (e.g., basedon target address)Femto Gateway needs to bereachable via AT’s macro IPaddress NOTE: The AT can use any available IP connectivity for Remote IP Access

5 Packet from AT in macro network to Home

6 Packet from Home to AT in macro network

Femto GW discovery by AT 7 Femto GW publicly reachable (e.g., Femto APs) AT must discover & connect to the same FGW that is being used by the FAP at the target network AT assumed to be pre-configured with the FGW that is used by target FAP –Other possible FGW discovery procedures are FFS

AT Authentication using IKEv2 EAP-AKA inside IKEv2 – EAP-AKA between the AT and Home AAA –Used if both the network and the AT support AKA Use IKEv2 in PSK mode –PSK derived by AT & AAA for each IKEv2 session –Root keys for PSK derivation: EMSK, MN-AAA & CHAP SS NAI indicates Remote IP Access service –e.g., where the “username” is the username part of the AT’s regular IP service –If there are multiple FAPs (e.g., two different homes) then the FAP identity can be included by the AT in the NAI e.g., –If there are multiple remote IP network realms (e.g., enterprise scenario), the AT realm is indicated E.g., 8

Auth method selection AT support for EAP or PSK indicated by absence/presence of AUTH payload during IKE_AUTH exchange; method chosen is as follows: –AT must always prefer either EAP-AKA or IKEv2 PSK with EMSK over other PSK modes –If neither of the above two feasibile, then MN-AAA must be preferred before CHAP-SS for PSK derivation This is similar to IKEv2 PSK/EAP authentication adopted by 3GPP2 for MIPv6 enhancement and HRPD-WiMax interworking AAA enforces auth method selection in order to avoid bidding down attacks 9

Authorization For each AT (subscription), AAA maintains FAP(s) that can be accessed as part of the AT subscription profile Based on the received NAI during authentication, the AAA returns one or more FAPs to the FGW –If multiple FAPs are returned, the FGW selects a FEID (e.g., based on availability of IPSec tunnel to the FAP, etc) –AT subscription profile determines whether the user is authorized to use the selected FAP(s) Authorized femto identifier(s) returned to the FGW via AAA message after successful AT authentication 10

Routing at FGW Based on the FEID(s) received from the AAA, the FGW checks to ensure that there is already pre-setup IPSec tunnel to FAP –If no tunnel exists for the authorized FAP, then FGW rejects the request from AT request with appropriate error code using IKEv2 FGW assigns an IPSec IP address to the AT and creates a routing entry bridging AT’s IPSec tunnel with the FAP’s IPSec tunnel 11

Proposal Adopt the proposal 12