4G/LTE - WiFi Offload

 

 

 

WiFi OffLoad : ePDG Discovery

 

How UE can figure out where it is supposed to get access for ePDG ? In other words, how a UE can figure out the IP address of ePDG ? You might have similar questions if you had experience of testing IMS.

ePDG Discovery method would be similar to IMS CSCF Discovery and I saw similar history of troubles related to this as I experienced from very early stage of ePDG implmentation (around 2 years ago) to relatively mature implementation as of now (as of Jun 2015).

I have seen several different implementation on UE of ePDG discovery and each method has its own advantage and headache. It is very important for you to know how your UE (DUT) implments the ePDG discover. Otherwise, you would get failed at the very first step of any ePDG related test. At the very early stage of ePDG implementation, I saw many of Case 1 which gaves me a lot of trouble because they just hardcoded and didn't provide information. And a while later, many UE start supporting Case 2. By the time when UE is about to be commericialized or to be tested in Carrier Lab, you would see many of Case 3 implementation.

3GPP calls this procedure ePDG selection. TS 23.402 clause 4.5.4 gives the stage 2 rules, TS 24.302 clause 7.2.1 gives the UE procedure, and TS 23.003 defines the domain names. Let's first look at the three cases and the DNS example, then at how the UE builds the name, and finally at how the UE chooses an ePDG at home and abroad.

What are the ways a UE finds the ePDG ?

The UE needs one thing from this step: an IP address to send IKE_SA_INIT to. The three cases below differ in where that address comes from, and each one needs a different check in the lab.

Case 1 : ePDG IP address is hardcoded in UE protocol stack.

Case 2 : UE provide some GUI or internal configuration file by which user can specify ePDG address manually.

Case 3 : UE send DNS query with ePDG and Network (Test Equipment) reply with ePDG IP address as shown in the following example.

Decoded message capture, DNS query for the ePDG FQDN. Field values are from a captured message, not from a specification.

Domain Name System (query)
    Transaction ID: 0x514d
    Flags: 0x0100 Standard query
        0... .... .... .... = Response: Message is a query
        .000 0... .... .... = Opcode: Standard query (0)
        .... ..0. .... .... = Truncated: Message is not truncated
        .... ...1 .... .... = Recursion desired: Do query recursively
        .... .... .0.. .... = Z: reserved (0)
        .... .... ...0 .... = Non-authenticated data: Unacceptable
    Questions: 1
    Answer RRs: 0
    Authority RRs: 0
    Additional RRs: 0
    Queries
        ss.epdg.epc.mncXYZ.mccABC.pub.3gppnetwork.org: type A, class IN
            Name: ss.epdg.epc.mnc260.mcc310.pub.3gppnetwork.org
            [Name Length: 45]
            [Label Count: 8]
            Type: A (Host Address) (1)
            Class: IN (0x0001)

Decoded message capture, DNS response with the ePDG address. Field values are from a captured message, not from a specification.

Domain Name System (response)
    Transaction ID: 0x514d
    Flags: 0x8180 Standard query response, No error
        1... .... .... .... = Response: Message is a response
        .000 0... .... .... = Opcode: Standard query (0)
        .... .0.. .... .... = Authoritative: Server is not an authority for domain
        .... ..0. .... .... = Truncated: Message is not truncated
        .... ...1 .... .... = Recursion desired: Do query recursively
        .... .... 1... .... = Recursion available: Server can do recursive queries
        .... .... .0.. .... = Z: reserved (0)
        .... .... ..0. .... = Answer authenticated: Answer/authority portion was not
                              authenticated by the server
        .... .... ...0 .... = Non-authenticated data: Unacceptable
        .... .... .... 0000 = Reply code: No error (0)
    Questions: 1
    Answer RRs: 1
    Authority RRs: 0
    Additional RRs: 0
    Queries
        ss.epdg.epc.mncXYZ.mccABC.pub.3gppnetwork.org: type A, class IN
            Name: ss.epdg.epc.mncXYZ.mccAB.pub.3gppnetwork.org
            [Name Length: 45]
            [Label Count: 8]
            Type: A (Host Address) (1)
            Class: IN (0x0001)
    Answers
        ss.epdg.epc.mncXYZ.mccABC.pub.3gppnetwork.org: type A, class IN, addr 192.168.0.254
            Name: ss.epdg.epc.mncXYZ.mccABC.pub.3gppnetwork.org
            Type: A (Host Address) (1)
            Class: IN (0x0001)
            Time to live: 86400
            Data length: 4
            Address: 192.168.0.254 (192.168.0.254) // This is IP address for ePDG

Let's read the two captures. The UE sends a standard query with Transaction ID 0x514d, and the response carries the same ID with the flags 0x8180, which means no error. The query type is A, a host address, so the UE asks for an IPv4 ePDG address. That fits a UE whose WLAN address is IPv4. The answer is 192.168.0.254 with a Time to live of 86400 seconds, so the UE can cache it for a day.

Now look at the name. Its first label is ss, followed by epdg.epc and the PLMN labels, and the capture counts 8 labels. The default Operator Identifier FQDN of TS 23.003 has exactly 7 labels and starts with epdg.epc. So this UE does not build the default name. It uses an FQDN that its home operator configured, which TS 23.402 allows, because a configured FQDN may have a different format. This is also Case 3 in practice: the name is configured, but the address still comes from DNS.

The PLMN labels in the capture are not consistent. Most lines use the placeholders mncXYZ and mccABC, one Name line of the response shows mccAB, and the Name line of the query shows mnc260 and mcc310. The capture is left as it was recorded. When you set up a test DNS server, though, it has to answer the exact name that the UE sends, character by character.

How do the three cases map to the specifications? Case 1 and Case 2 are both a configured ePDG identifier, an IP address or an FQDN in the UE. TS 24.302 lets the home operator provide that configuration through H-ANDSF or the USIM, and implementation specific means apply only when neither is present. Case 3 is DNS resolution of either a configured FQDN or an FQDN that the UE constructs itself.

  • The query type follows the local address : TS 24.302 makes the UE pick an ePDG address with the same IP version as its local IP address.
  • A configured FQDN can look different : the ss prefix here is not an error, because a home operator can configure its own format.
  • Hardcoding has a standard form : a fixed ePDG address in the UE corresponds to the configured ePDG identifier of TS 23.402.

How does the UE build the ePDG FQDN ?

When no FQDN is configured, the UE constructs one from a PLMN ID. TS 23.402 defines two formats for this, and TS 23.003 defines how each one is written. The choice between them decides whether the operator can select an ePDG by location.

The first format is the Operator Identifier FQDN. It identifies only the PLMN, and it has seven labels: epdg.epc.mnc<MNC>.mcc<MCC>.pub.3gppnetwork.org. The MNC and the MCC always have 3 digits. If the MNC has only 2 digits, the UE inserts a 0 on the left. So MCC 345 with MNC 12 becomes epdg.epc.mnc012.mcc345.pub.3gppnetwork.org.

The second format is the Tracking/Location Area Identity FQDN. It adds the area of the UE in front of the operator part, for example tac-lb<TAC-low-byte>.tac-hb<TAC-high-byte>.tac.epdg.epc.mnc<MNC>.mcc<MCC>.pub.3gppnetwork.org for a 2 octet TAC, or lac<LAC>.epdg.epc... for a Location Area. TS 23.003 also defines a 5GS variant for a 3 octet TAC. With this format, the operator's DNS can return an ePDG close to the UE.

The UE uses the Tracking/Location Area Identity FQDN only when two conditions hold. First, the ePDG selection information tells the UE to use this format for the registered PLMN. Second, the UE knows its current TAI or LAI, for example from the last Attach or TAU. Otherwise the UE builds the Operator Identifier FQDN. The UE also falls back to the Operator Identifier FQDN if DNS cannot resolve the area-based name.

Two more names appear in special cases. For emergency bearer services, TS 23.003 adds the label sos in front, as in sos.epdg.epc.mnc<MNC>.mcc<MCC>.pub.3gppnetwork.org. For roaming, the Visited Country FQDN epdg.epc.mcc<MCC>.visited-country.pub.3gppnetwork.org is used in a DNS NAPTR query, which the next section explains.

  • MNC and MCC are always 3 digits : a 2 digit MNC gets a leading 0 in the FQDN.
  • The area-based name enables location-specific selection : and the UE falls back to the Operator Identifier FQDN if it fails.
  • sos marks the emergency ePDG : an emergency session uses its own FQDN and selection procedure.

Which ePDG does the UE select at home and abroad ?

The FQDN format is only half of the question. The UE also has to decide in which PLMN to look for an ePDG, and that depends on the country it is in and on what the home operator configured.

The home operator can configure two things. The first is the ePDG identifier, an FQDN or an IP address of an ePDG in the HPLMN. The second is the ePDG selection information, a prioritized list of PLMNs for ePDG selection. For each PLMN, the list also says which FQDN format to use, and it may include an any PLMN entry. The UE uses these in a fixed order of precedence. Configuration from the ANDSF server comes first, then the UICC, and then the pre-configuration on the ME.

First, the UE determines the country it is located in. TS 24.302 leaves the method to the UE, and if the UE cannot tell, it stops the ePDG selection. In the home country, the UE selects an ePDG in the HPLMN. If the selection information lists the HPLMN, the UE builds the FQDN in the listed format. Otherwise it uses the configured ePDG identifier, and without one it builds the Operator Identifier FQDN from the HPLMN ID on the USIM.

In a visited country, the UE first checks the PLMN it is registered in via 3GPP access. If that PLMN is in the selection information, the UE selects an ePDG there. In all other cases, the UE sends a DNS NAPTR query with the Visited Country FQDN. An empty answer means the country does not require a local ePDG, and the UE can use a listed PLMN in that country or fall back to the HPLMN. One or more records mean the country requires one of the returned PLMNs. If no DNS response comes back at all, the UE stops the selection.

After selection, two more rules apply. The UE uses one ePDG for all its PDN connections. Also, if an ePDG address does not answer IKE_SA_INIT, the UE repeats the selection without that ePDG. The waiting time before the retry is implementation specific. A UE that supports the 5GS procedure of TS 24.502 follows that specification instead.

  • The country decides the procedure : at home the UE always uses the HPLMN, and abroad it may have to use a local PLMN.
  • ANDSF beats USIM, and USIM beats the ME : the same ePDG configuration can exist in three places, with this order of precedence.
  • No answer to IKE_SA_INIT restarts the selection : the UE excludes the silent ePDG and tries again.

Reference

  • TS 23.003 v20.0.0 : Numbering, addressing and identification
  • TS 23.402 v19.0.0 : Architecture enhancements for non-3GPP accesses
  • TS 24.302 v19.0.0 : Access to the 3GPP Evolved Packet Core via non-3GPP access networks, Stage 3