SlideShare a Scribd company logo
1 of 30
Aptilo Networks
 “We control Billing, User Services and Access in
 Wi-Fi, WiMAX and 3G / LTE networks worldwide”

       Why carrier Wi-Fi must go
       beyond the offloading aspect
                                  Reinaldo Medina
                                  Manager Sales Engineer
Why Build Wi-Fi ?

Stand out from
 competition          Large Wi-Fi Network         Drive to premium
                           = Loyalty              plans ($49 -> $59)
                                                                         Bundle with
                                                                        other services

       Reduce
        churn                                                       Wi-Fi-only devices
                                                                   become subscribers




    ”All” devices have
           Wi-Fi                                                   Offload up to 30%
                                                                        of traffic

   Users like Wi-Fi          Take control –
                           make Wi-Fi secure &                     Slow down CAPEX at
                               seamless             Lower cost          busy sites
         Some services only                      to produce data
          available in Wi-Fi


                                                                                         2
All Mobile Operators Need a Wi-Fi Strategy




                                             3
Offloading and 3GPP integration


              3GPP AAA for Trusted & Untrusted Authentications



                                                                           SWx
                                     HSS

                                                    PCRF               S6b




                          eNB
                                     SGW/               PDN                           Is it really that
                 LTE                 MME                GW
                 RAN                             S2a          S2b
                                                                                      “simple” ?
3GPP
                                                                           SWm
  +                                                      ePDG
Wi-Fi                            Wi-Fi to     Trusted         Un-Trusted
                                Mobile Core    WLAN           WLAN
                                                                           STa, SWa
                                                                           EAP-SIM
                                                    AG/WAG
                Wi-Fi
                RAN


        Traffic path
        Signalling path



                                                                                                          4
Carrier-Class Wi-Fi is so much more than just
        Offloading and 3GPP integration
                                                                                                                 Policy    SMS
                                                                                                 Charging        Look-up   OTP
                                                                                               OCS       OFCS      CRM     SMSC


               3GPP AAA for Trusted & Untrusted Authentications


                           ANDSF
                                                                                  SWx
                                           HSS
                                                                           S9
                                                           PCRF                 S6b



                                          SGW/                 PDN                                                          Carrier-Class Wi-Fi
                  LTE      eNB
                                          MME                  GW                                                          Service Management
                  RAN                                   S2a          S2b
3GPP
  +                                                             ePDG
                                                                                  SWm                           •  Wi-Fi AAA, Captive Portal & Hotspot
Wi-Fi                                 Wi-Fi to                                                                     Management for non-3GPP
                                                     Trusted         Un-Trusted
                                     Mobile Core      WLAN           WLAN                                       •  One-time-password via SMS
                                                                                  STa, SWa

                                                           AG/WAG
                                                                                  EAP-SIM
                                                                                                                           Innovative Integration
                 Wi-Fi                                                            Radius/WEB
Wi-Fi            RAN                                                                                                       For Policy & Charging
                                                                           Local Break-Out (non-SIM devices)
Only
                                       Wi-Fi to
                                                                                                                •  Policy Manager for Wi-Fi policies,
                                   Local Break-Out
                                                                                                                   can make lookups from PCRF,
         Traffic path
                                                                                                                   CRM or any database.
         Signalling path
                                                                                                                •  Charging & Billing aggregation

                                                                                                                                                        5
I am not building my own Wi-Fi footprint……
   Do I need a Wi-Fi Service Management system?
                           Temporary credentials for WISP login
                                                                                                    Mobile
                                                                                                     Core
                                                                                                        PCRF

                                                                                                        HLR
                                                                                                        HSS

        Wi-Fi                                          HTTPS            Mobile Operator
                                                 ing
                                            rward              Portal                                   OCS
        Service                   Sec ure fo
        Mgmt
                                  YES!
                                                                                                       OFCS
        System          Portal
                                                                                                        CRM
                                     •  Need a system to roam with WISPs
         Access
         Gateway
                                     •  Need a system for SIM authentication
                                     •  Need a system to handle secure logins
                   AP                      ‒  Use of so-called opaque login, user is securely forwarded to their
                                              home portal for login. Advanced Wi-Fi Service Management System
        Clients
                                              creates temporary credentials to login in the WISP’s network.
                                     •  Need a system for charging & billing aggregation
                                     •  Need a system to translate policies to what makes
                                        sense in each WISP’s Wi-Fi network
Wirless Internet ServiceProviders

                                                                                                               6
How To Build Coverage




Traditional Hotspots                 Small Cells (outdoor)               Residential/SMB
•    Hotels, restaurants, airports   •  Where high 3G traffic            •  Combined with DSL
•    Retail/shopping strong trend    •  Stadiums, High Streets,          •  All subs > 5 Mbps
•    Acquisition WISP network           Metro, Square, Parks, Beaches    •  Dual SSID
•    3GPP Core Integration           •  2016 90% of BS = Small Cells           One for public use
                                     •  Wi-Fi + Small Cell convergence         Utilize overcapacity
                                     •  Micro/Pico BS with Wi-Fi


                                                                              Utilize an
                                             "Normal"                         Existing
                                            RAN roll-out                      Network



                                                                                                  7
Common Wi-Fi Business Models

 •  Post/Prepaid subscription loyalty
    → Wi-Fi unlimited

 •  Post/Prepaid subscription bundle
    → Bundle Wi-Fi with e.g. 1:10 charging
 •  Group account subscriptions
    → One SIM, multiple devices (SIM/non-SIM)

 •  Pay per use
    → Multiple data plans (daypass, weekpass)
 •  Enterprise offers (B-to-B)
    → Guest Internet Access, Hospitality


                                                8
Why SIM authentication is so important for the
offloading business model




•  Very strong usage increase (10x users in 12 months)
    ‒  Similar statistics among several mobile operators
•  More frequent and shorter session
    ‒  Due to completely seamless transfer Wi-Fi/3G
•  Strong correlation to iOS5
    ‒  All Apple iOS devices can do EAP-SIM                •  Example from an airport
                                                           •  50% reduction HSPA traffic
                                                               ‒  In cells with good Wi-Fi coverage




                                                                                                9
Why additional authentication methods are needed

All devices do not support
SIM authentication.
                                                                                                  SIM-based
                                                                                                  WISPr 2.0
•  There are alternative methods                                 Automatic
                                                                               MAC-based
                                                                              authentication     WISPr Client
                                                                                                                SIM-based
                                                                                                                  802.1x
     ‒  Balance experience vs security                                                           OTP via SMS

•  Highest Security
     ‒  As secure as 3G/4G
                                                                                   Self-                        SIM-based
     ‒  Payload encrypted                                          Manual     registration via                  802.1x with
                                                                                SMS, then                        bill shock
                                                                  One-time
•  High Security                                                                MAC-based                       prevention*

     ‒  High security for authentication
     ‒  No encryption of payload
•  Standard Security                                                           Manual login       One-time-
                                                                     Manual    username /        password via
     ‒  Some security risk for                                                  password            SMS

        authentication
     ‒  No encryption of payload
                                                                              Standard             High         Highest
 * User is automatically authenticated but needs to accept an
 additional charge via the portal before gaining access to the Internet



                                                                                                                              10
Innovative combination of authentication methods

•  Case: Tier 1 mobile operator
    ‒  Wanted to combine the
       security and convenience of
       SIM authentication with the
       monetization of the service
       through a WEB portal.
•  Combines SIM + Portal
•  User just have to approve
   charge with a single click
•  Use of Aptilo’s innovative
   ServiceGlue
    ‒  Possible to add advanced
       logic to the authentication flow   1.  Retrieval of MAC address and IMSI
                                              •  During the SIM authentication, the user’s MAC address and IMSI is
                                                 retrieved and posted to the CRM system.
                                              •  Based on the IMSI - the user can be securely identified and the MAC
                                                 address tied to the correct MSISDN.
                                          2.  Re-direct to portal after SIM authentication
                                              •  The user’s MAC address is used to lookup the user’s MSISDN in
                                                 CRM system. The individual user is then presented with different
                                                 options based on his/her status, approve charge and click to connect
                                                 or top-up etc. MSISDN is used as charging identifier.


                                                                                                                        11
Hotspot 2.0 and the new 802.11u standard
•  Network discovery and selection
    ‒  Automatic discovery of suitable networks
       through the advertisement of access network     More
       type, roaming consortium support and venue      information
•  How Hotspot 2.0 works
    1.  802.11u-capable AP beacons with HS2.0
        support
    2.  The Passpoint certified device detects the                        AP Today
        HS 2.0 network
    3.  Device selects AP and performs ANQP
        request to determine what providers are
        supported, capabilities of the AP, etc.
    4.  AP responds to ANQP query with requested
        information
    5.  Device compiles provisioned profile
        information against HS2.0 data from APs
        and associates to the best SSID                               AP with 802.11u
•  Next Generation Hotspot (NGH)
    ‒    Extends the HS 2.0 initiative to include         Will take time before 802.11u
          •  Roaming/WRIX (roaming exchange) updates      support is widespread, ANDSF
          •  Accounting support                           will add policy-based network selection
          •  Legacy authentication methods


                                                                                               12
Hall 5
Thank You!   Booth 5G61




                      1
Carrier Wi-Fi
Authentication
Options
Tomás Lynch
Senior Solution Architect
Fixed Broadband and Convergence
Anywhere internet
24/7, please
                                                                                                                           95% of the
                                                                                                                           Smartphone users
                                                                                                                           want anywhere
                                                                                                                           access


                                                                                                          Smartphones make on-the-
                                                                                                          go laptop usage less
                                                                                                          frequent

                                                                                                          Smartphones complement
                                                                                                          rather than replaces laptops

                                                                                                          Tablets are likely to become
                                                                                                          a key on-the-go device




            Internet everywhere is a pre-requisite, not an option
                                                                                           Source: Ericsson Consumer Lab, Mobile Broadband business user study 2011
Carrier Wi-Fi Authentication Options | Public | © Ericsson AB 2013 | 2013-01-15 | Page 2
Authentication
Options
› Web Portal Authentication
       – An Access Gateway (ISG/BNG/PDG) will handle the subscriber
         session, providing IP addresses, authentication and policies.


› UAM/WISPr Authentication
       – The Access Points will redirect user traffic to a web portal and
         authenticate credentials against RADIUS.


› EAP Authentication
       – The Access Points will authenticate users credentials against
         RADIUS server before association.


Carrier Wi-Fi Authentication Options | Public | © Ericsson AB 2013 | 2013-01-15 | Page 3
Web Portal
Authentication
1. Open SSID
2. User gets connected and receives IP address from the
   Access Gateway
3. User Web Traffic is redirected to the login page
   (redirection enforced by the Access Gateway)
4. User and Pass are checked against AAA (RADIUS)
5. User is authenticated and proper policies are
   applied/enforced at the Access Gateway (rate limit,
   volume quota, etc…)
6. Traffic is allowed


Carrier Wi-Fi Authentication Options | Public | © Ericsson AB 2013 | 2013-01-15 | Page 4
Web Portal Flow
First Time Auth.

    User                                    AP                                 BNG                        AAA                Web Portal

                  Open SSID

                                   DHCP Request
                                                                                                                MAC
                                                                                           MAC Verification     Logged In!


                                    DHCP Answer

                                    Traffic to http                                                  Traffic is redirected

                                                                                                                  User/Password
                                                                   Access
                                                                   Granted                  CoA Message

                                                                        Traffic is allowed
Carrier Wi-Fi Authentication Options | Public | © Ericsson AB 2013 | 2013-01-15 | Page 5
Web Portal Flow
Second Time Auth.

    User                                    AP                                 BNG                        AAA   Web Portal

                  Open SSID

                                   DHCP Request
                                                                    Access
                                                                    Granted                MAC Verification

                                    DHCP Answer


                                                                        Traffic is allowed




Carrier Wi-Fi Authentication Options | Public | © Ericsson AB 2013 | 2013-01-15 | Page 6
UAM/WISPr
Authentication Options
› Three options:
       – DHCP and Redirection at the AP
       – DHCP and Redirection at the Controller
       – External DHCP and Redirection at the Controller


› All options may include NAT

› No roaming when DHCP or NAT at AP




Carrier Wi-Fi Authentication Options | Public | © Ericsson AB 2013 | 2013-01-15 | Page 7
UAM/WISPr
Authentication
1. Open SSID
2. User connects and receives IP address from the DHCP
   Server
       1. DHCP/NAT can be also applied by the AP
3. User Web Traffic is redirected to the login page
   (redirection enforced by the controller or AP)
4. User and Pass are checked against RADIUS
5. User is authenticated and proper policies are
   applied/enforced at the Access Point (rate limit, volume
   and /or time quota)


Carrier Wi-Fi Authentication Options | Public | © Ericsson AB 2013 | 2013-01-15 | Page 8
UAM/WISPr Flow
First Time Auth.

    User                                    AP                            Controller                            AAA             Web Portal

                  Open SSID

                                   DHCP Request
                                                                                                                   MAC
                                                                                           MAC Verification        Logged In!

                                    DHCP Answer

                                    Traffic to http                                                     Traffic is redirected

                                                                                                                      User/Password

                                               Message including auth. Attributes embedded

                                   Allow Access                      Access
                                                                     Granted               Attr. Verification

                                                                        Traffic is allowed
Carrier Wi-Fi Authentication Options | Public | © Ericsson AB 2013 | 2013-01-15 | Page 9
UAM/WISPr Flow
Second Time Auth.

   User                                     AP                            Controller                       AAA   Web Portal

                  Open SSID

                                   DHCP Request
                                                                   Access
                                                                   Granted                  MAC Verification

                                    DHCP Answer

                                                                        Traffic is allowed




Carrier Wi-Fi Authentication Options | Public | © Ericsson AB 2013 | 2013-01-15 | Page 10
EAP Authentication

› Allows End-to-End Authentication
       – Direct from wireless device to AAA server.
       – AP acts as “dumb” L2-L3 relay
› WPA2/802.1x SSID
› User is authenticated on RADIUS (EAP) before associates
  to the AP
› Once associated, user receives IP address from the DHCP
  Server (PDG)
       – PDG is recommended by 3GPP




Carrier Wi-Fi Authentication Options | Public | © Ericsson AB 2013 | 2013-01-15 | Page 11
EAP Types

› TTLS (Tunneled Transport Layer Security)
       – Username/password inside secure tunnel
       – Very widely supported, simple with certificate-based security.
       – This is the most common form of EAP


› SIM
       – Use GSM SIM over EAP
       – Only works in SIM-based devices.
       – No configuration on device.
       – Requires connection to HLR associated with SIM card



Carrier Wi-Fi Authentication Options | Public | © Ericsson AB 2013 | 2013-01-15 | Page 12
EAP-TTLS Auth. Flow

   User                                     AP                                 PDG                        AAA          External AAA

                 802.1x
             Access Request                                                 EAP Request

                                                                                                 MAC
                                                                                                 Logged In!     EAP Proxy

                                                                         EAP Answer
                 802.1x
              Access Answer

                                    DHCP Request
                                                                    Access
                                                                    Granted                 MAC Address


                                    DHCP Answer

                                                                        Traffic is allowed
Carrier Wi-Fi Authentication Options | Public | © Ericsson AB 2013 | 2013-01-15 | Page 13
EAP-SIM Auth. Flow

   User                                     AP                                 PDG                        AAA             HLR

                 802.1x
             Access Request                                                 EAP Request

                                                                                                 MAC
                                                                                                 Logged In!     SS7 MAP

                                                                         EAP Answer
                 802.1x
              Access Answer

                                    DHCP Request
                                                                    Access
                                                                    Granted                 MAC Address


                                    DHCP Answer

                                                                        Traffic is allowed
Carrier Wi-Fi Authentication Options | Public | © Ericsson AB 2013 | 2013-01-15 | Page 14
Smartphones & EAP

› Blackberry supports 802.1X™  standard  and  EAP  
  authentication using EAP-FAST, EAP-SIM, EAP-TLS EAP-
  TTLS, LEAP, and PEAP

› Android phones support EAP-TTLS in several models.
  EAP-SIM is supported after applying a patch found in
  http://code.google.com/p/seek-for-android/wiki/EapSimAka

› iPhone supports EAP-SIM and a variety of other EAP
  methods


Carrier Wi-Fi Authentication Options | Public | © Ericsson AB 2013 | 2013-01-15 | Page 15
Authentication
Options Comparison
› Web Portal:
       – Useful when network already has a BNG for fixed broadband
       – Integration of fixed and mobile networks


› UAM/WISPr:
       – New deployments for companies not having a fixed broadband
         network
       – Useful to integrate third parties (e.g. coffee shops)


› EAP
       – Useful when a high percentage of smartphones supports EAP
       – Mobile network based companies
Carrier Wi-Fi Authentication Options | Public | © Ericsson AB 2013 | 2013-01-15 | Page 16
Telesemana webinar enero 22 2013

More Related Content

What's hot

SD-WAN's Role in the Multi-Cloud Digital Transformation
SD-WAN's Role in the Multi-Cloud Digital TransformationSD-WAN's Role in the Multi-Cloud Digital Transformation
SD-WAN's Role in the Multi-Cloud Digital TransformationRalph Santitoro
 
Carrier WiFi Architectures
Carrier WiFi ArchitecturesCarrier WiFi Architectures
Carrier WiFi ArchitecturesMarc Nader
 
Winhon Network Solution
Winhon Network SolutionWinhon Network Solution
Winhon Network SolutionJinzdm
 
Ключевые тенденции отрасли в последнее время
Ключевые тенденции отрасли в последнее времяКлючевые тенденции отрасли в последнее время
Ключевые тенденции отрасли в последнее времяSkillFactory
 
2015-02-16_HPN Sales Training
2015-02-16_HPN Sales Training2015-02-16_HPN Sales Training
2015-02-16_HPN Sales TrainingAloysius Erwin
 
201212 luceor-ports
201212 luceor-ports201212 luceor-ports
201212 luceor-portsN2Gr8LTD
 
Netaxess - Technical document for sify
Netaxess - Technical document for sifyNetaxess - Technical document for sify
Netaxess - Technical document for sifynavancnx200
 
Managing the Mobile Device Wave
Managing the Mobile Device WaveManaging the Mobile Device Wave
Managing the Mobile Device WaveCisco Canada
 
Preparing Your Network for Wave 2 of 802.11ac
Preparing Your Network for Wave 2 of 802.11acPreparing Your Network for Wave 2 of 802.11ac
Preparing Your Network for Wave 2 of 802.11acCisco Mobility
 
Netaxcess na 3 g-mpvn
Netaxcess na 3 g-mpvnNetaxcess na 3 g-mpvn
Netaxcess na 3 g-mpvnnavancnx200
 

What's hot (20)

SD-WAN's Role in the Multi-Cloud Digital Transformation
SD-WAN's Role in the Multi-Cloud Digital TransformationSD-WAN's Role in the Multi-Cloud Digital Transformation
SD-WAN's Role in the Multi-Cloud Digital Transformation
 
Carrier WiFi Architectures
Carrier WiFi ArchitecturesCarrier WiFi Architectures
Carrier WiFi Architectures
 
Apple Captive Network Assistant Bypass with ClearPass Guest
Apple Captive Network Assistant Bypass with ClearPass GuestApple Captive Network Assistant Bypass with ClearPass Guest
Apple Captive Network Assistant Bypass with ClearPass Guest
 
Voice over IP (VoIP) Deployment with Aruba Mobility Access Switch
Voice over IP (VoIP) Deployment with Aruba Mobility Access SwitchVoice over IP (VoIP) Deployment with Aruba Mobility Access Switch
Voice over IP (VoIP) Deployment with Aruba Mobility Access Switch
 
Aruba 802.11ac networks: Validated Reference Designs
Aruba 802.11ac networks: Validated Reference DesignsAruba 802.11ac networks: Validated Reference Designs
Aruba 802.11ac networks: Validated Reference Designs
 
Winhon Network Solution
Winhon Network SolutionWinhon Network Solution
Winhon Network Solution
 
Ключевые тенденции отрасли в последнее время
Ключевые тенденции отрасли в последнее времяКлючевые тенденции отрасли в последнее время
Ключевые тенденции отрасли в последнее время
 
2015-02-16_HPN Sales Training
2015-02-16_HPN Sales Training2015-02-16_HPN Sales Training
2015-02-16_HPN Sales Training
 
201212 luceor-ports
201212 luceor-ports201212 luceor-ports
201212 luceor-ports
 
Peplink presentation
Peplink presentationPeplink presentation
Peplink presentation
 
Netaxess - Technical document for sify
Netaxess - Technical document for sifyNetaxess - Technical document for sify
Netaxess - Technical document for sify
 
Meraki Datasheet MR12
Meraki Datasheet MR12Meraki Datasheet MR12
Meraki Datasheet MR12
 
Managing the Mobile Device Wave
Managing the Mobile Device WaveManaging the Mobile Device Wave
Managing the Mobile Device Wave
 
Tekelec Next Generation Msg & Mobile Adv - Bucharest Final
Tekelec Next Generation Msg & Mobile Adv  - Bucharest FinalTekelec Next Generation Msg & Mobile Adv  - Bucharest Final
Tekelec Next Generation Msg & Mobile Adv - Bucharest Final
 
Preparing Your Network for Wave 2 of 802.11ac
Preparing Your Network for Wave 2 of 802.11acPreparing Your Network for Wave 2 of 802.11ac
Preparing Your Network for Wave 2 of 802.11ac
 
Netaxcess na 3 g-mpvn
Netaxcess na 3 g-mpvnNetaxcess na 3 g-mpvn
Netaxcess na 3 g-mpvn
 
VRD-Indoor80211n 2012 05-31
VRD-Indoor80211n 2012 05-31VRD-Indoor80211n 2012 05-31
VRD-Indoor80211n 2012 05-31
 
Managing and Optimizing RF Spectrum for Aruba WLANs
Managing and Optimizing RF Spectrum for Aruba WLANsManaging and Optimizing RF Spectrum for Aruba WLANs
Managing and Optimizing RF Spectrum for Aruba WLANs
 
Cisco Mobile Innovations 2013
Cisco Mobile Innovations 2013Cisco Mobile Innovations 2013
Cisco Mobile Innovations 2013
 
Ready
ReadyReady
Ready
 

Similar to Telesemana webinar enero 22 2013

Brokerage 2007 presentation wireless
Brokerage 2007 presentation wirelessBrokerage 2007 presentation wireless
Brokerage 2007 presentation wirelessimec.archive
 
Overview lte
Overview lteOverview lte
Overview lteProcExpl
 
IPv6 in 3G Core Networks
IPv6 in 3G Core NetworksIPv6 in 3G Core Networks
IPv6 in 3G Core NetworksJohn Loughney
 
The Case for WiFi: Optimizing Your Network for Mobile Commerce
The Case for WiFi: Optimizing Your Network for Mobile CommerceThe Case for WiFi: Optimizing Your Network for Mobile Commerce
The Case for WiFi: Optimizing Your Network for Mobile CommerceCradlePoint
 
VoIP Connectivity Table
VoIP Connectivity TableVoIP Connectivity Table
VoIP Connectivity TableBraun Mincher
 
Top Global 3G Phoebus Wireless Router (MB6000) (Quantum-Wireless.com)
Top Global 3G Phoebus Wireless Router (MB6000) (Quantum-Wireless.com)Top Global 3G Phoebus Wireless Router (MB6000) (Quantum-Wireless.com)
Top Global 3G Phoebus Wireless Router (MB6000) (Quantum-Wireless.com)Ari Zoldan
 
VoWifi 03 - vowifi epdg aaa and architecture (pdf ppt)
VoWifi 03 - vowifi epdg aaa and architecture (pdf ppt)VoWifi 03 - vowifi epdg aaa and architecture (pdf ppt)
VoWifi 03 - vowifi epdg aaa and architecture (pdf ppt)Vikas Shokeen
 
TMA Brochure Telecom Software
TMA Brochure  Telecom SoftwareTMA Brochure  Telecom Software
TMA Brochure Telecom SoftwareTMA Solutions
 
IEEE 1588 Timing for Mobile Backhaul_Webinar
IEEE 1588 Timing for Mobile Backhaul_WebinarIEEE 1588 Timing for Mobile Backhaul_Webinar
IEEE 1588 Timing for Mobile Backhaul_WebinarSymmetricomSYMM
 
SG Security Switch Brochure
SG Security Switch BrochureSG Security Switch Brochure
SG Security Switch BrochureShotaro Kaida
 
Ready for the Evolution: LTE Session delivery requirements
Ready for the Evolution: LTE Session delivery requirementsReady for the Evolution: LTE Session delivery requirements
Ready for the Evolution: LTE Session delivery requirementsAcmePacket
 
4G Mobile: Opportunities and Challenges in Indonesia
4G Mobile: Opportunities and Challenges in Indonesia4G Mobile: Opportunities and Challenges in Indonesia
4G Mobile: Opportunities and Challenges in IndonesiaArief Gunawan
 
Ruckus wp wifi-into-core
Ruckus wp wifi-into-coreRuckus wp wifi-into-core
Ruckus wp wifi-into-corewarchitect
 
Wi Max Network Architecture V0.1 Pdf Version
Wi Max Network Architecture V0.1 Pdf VersionWi Max Network Architecture V0.1 Pdf Version
Wi Max Network Architecture V0.1 Pdf VersionDeepak Sharma
 
Softbank Wifi
Softbank WifiSoftbank Wifi
Softbank WifiAPNIC
 
Zigbee wireless control made easy
Zigbee wireless control made easyZigbee wireless control made easy
Zigbee wireless control made easyrajrayala
 

Similar to Telesemana webinar enero 22 2013 (20)

Brokerage 2007 presentation wireless
Brokerage 2007 presentation wirelessBrokerage 2007 presentation wireless
Brokerage 2007 presentation wireless
 
Overview lte
Overview lteOverview lte
Overview lte
 
IPv6 in 3G Core Networks
IPv6 in 3G Core NetworksIPv6 in 3G Core Networks
IPv6 in 3G Core Networks
 
Radisys offloading 10412_final
Radisys offloading 10412_finalRadisys offloading 10412_final
Radisys offloading 10412_final
 
The Case for WiFi: Optimizing Your Network for Mobile Commerce
The Case for WiFi: Optimizing Your Network for Mobile CommerceThe Case for WiFi: Optimizing Your Network for Mobile Commerce
The Case for WiFi: Optimizing Your Network for Mobile Commerce
 
VoIP Connectivity Table
VoIP Connectivity TableVoIP Connectivity Table
VoIP Connectivity Table
 
Top Global 3G Phoebus Wireless Router (MB6000) (Quantum-Wireless.com)
Top Global 3G Phoebus Wireless Router (MB6000) (Quantum-Wireless.com)Top Global 3G Phoebus Wireless Router (MB6000) (Quantum-Wireless.com)
Top Global 3G Phoebus Wireless Router (MB6000) (Quantum-Wireless.com)
 
VoWifi 03 - vowifi epdg aaa and architecture (pdf ppt)
VoWifi 03 - vowifi epdg aaa and architecture (pdf ppt)VoWifi 03 - vowifi epdg aaa and architecture (pdf ppt)
VoWifi 03 - vowifi epdg aaa and architecture (pdf ppt)
 
TMA Brochure Telecom Software
TMA Brochure  Telecom SoftwareTMA Brochure  Telecom Software
TMA Brochure Telecom Software
 
IEEE 1588 Timing for Mobile Backhaul_Webinar
IEEE 1588 Timing for Mobile Backhaul_WebinarIEEE 1588 Timing for Mobile Backhaul_Webinar
IEEE 1588 Timing for Mobile Backhaul_Webinar
 
SG Security Switch Brochure
SG Security Switch BrochureSG Security Switch Brochure
SG Security Switch Brochure
 
Ready for the Evolution: LTE Session delivery requirements
Ready for the Evolution: LTE Session delivery requirementsReady for the Evolution: LTE Session delivery requirements
Ready for the Evolution: LTE Session delivery requirements
 
Anyfi.net Mobile™
Anyfi.net Mobile™Anyfi.net Mobile™
Anyfi.net Mobile™
 
4G Mobile: Opportunities and Challenges in Indonesia
4G Mobile: Opportunities and Challenges in Indonesia4G Mobile: Opportunities and Challenges in Indonesia
4G Mobile: Opportunities and Challenges in Indonesia
 
10 fn s01
10 fn s0110 fn s01
10 fn s01
 
10 fn s01
10 fn s0110 fn s01
10 fn s01
 
Ruckus wp wifi-into-core
Ruckus wp wifi-into-coreRuckus wp wifi-into-core
Ruckus wp wifi-into-core
 
Wi Max Network Architecture V0.1 Pdf Version
Wi Max Network Architecture V0.1 Pdf VersionWi Max Network Architecture V0.1 Pdf Version
Wi Max Network Architecture V0.1 Pdf Version
 
Softbank Wifi
Softbank WifiSoftbank Wifi
Softbank Wifi
 
Zigbee wireless control made easy
Zigbee wireless control made easyZigbee wireless control made easy
Zigbee wireless control made easy
 

More from Rafael Junquera

Colt sdn-strategy-telesemana-diciembre-2013-javier-benitez-colt-final
Colt sdn-strategy-telesemana-diciembre-2013-javier-benitez-colt-finalColt sdn-strategy-telesemana-diciembre-2013-javier-benitez-colt-final
Colt sdn-strategy-telesemana-diciembre-2013-javier-benitez-colt-finalRafael Junquera
 
Webinar 3-12-2013 Comptel, Analytics
Webinar 3-12-2013 Comptel, AnalyticsWebinar 3-12-2013 Comptel, Analytics
Webinar 3-12-2013 Comptel, AnalyticsRafael Junquera
 
Ims and rcs are fighting ott nov 8 2013 v1
Ims and rcs are fighting ott nov 8 2013 v1Ims and rcs are fighting ott nov 8 2013 v1
Ims and rcs are fighting ott nov 8 2013 v1Rafael Junquera
 
Webinar 26 de noviembre 2013
Webinar 26 de noviembre 2013Webinar 26 de noviembre 2013
Webinar 26 de noviembre 2013Rafael Junquera
 
Sdn en latinoamérica 5 11-13
Sdn en latinoamérica 5 11-13Sdn en latinoamérica 5 11-13
Sdn en latinoamérica 5 11-13Rafael Junquera
 
Workshop sdn nfv arg-ch juniper
Workshop sdn nfv arg-ch juniperWorkshop sdn nfv arg-ch juniper
Workshop sdn nfv arg-ch juniperRafael Junquera
 
Cant touch this hs es_la_no_mc_hv1
Cant touch this hs es_la_no_mc_hv1Cant touch this hs es_la_no_mc_hv1
Cant touch this hs es_la_no_mc_hv1Rafael Junquera
 
Cala workshop final chile
Cala workshop final   chileCala workshop final   chile
Cala workshop final chileRafael Junquera
 
Workshop sdn nfv arg-ch juniper
Workshop sdn nfv arg-ch juniperWorkshop sdn nfv arg-ch juniper
Workshop sdn nfv arg-ch juniperRafael Junquera
 
Revolucion movil telesemana
Revolucion movil telesemanaRevolucion movil telesemana
Revolucion movil telesemanaRafael Junquera
 
Packet network timing distribution webinar v0-3 hs-es_la
Packet network timing distribution   webinar v0-3 hs-es_laPacket network timing distribution   webinar v0-3 hs-es_la
Packet network timing distribution webinar v0-3 hs-es_laRafael Junquera
 
Webinar telesemana amdocs_toa_sep_2013v4
Webinar telesemana amdocs_toa_sep_2013v4Webinar telesemana amdocs_toa_sep_2013v4
Webinar telesemana amdocs_toa_sep_2013v4Rafael Junquera
 
Lte continuing the evolution of mobile broadband networks
Lte continuing the evolution of mobile broadband networksLte continuing the evolution of mobile broadband networks
Lte continuing the evolution of mobile broadband networksRafael Junquera
 
Content blocking telesemana_final 2
Content blocking telesemana_final 2Content blocking telesemana_final 2
Content blocking telesemana_final 2Rafael Junquera
 
Comptel social links_2.0_presentation v2
Comptel social links_2.0_presentation v2Comptel social links_2.0_presentation v2
Comptel social links_2.0_presentation v2Rafael Junquera
 
Telesemana webinar cos final
Telesemana webinar cos finalTelesemana webinar cos final
Telesemana webinar cos finalRafael Junquera
 

More from Rafael Junquera (20)

Colt sdn-strategy-telesemana-diciembre-2013-javier-benitez-colt-final
Colt sdn-strategy-telesemana-diciembre-2013-javier-benitez-colt-finalColt sdn-strategy-telesemana-diciembre-2013-javier-benitez-colt-final
Colt sdn-strategy-telesemana-diciembre-2013-javier-benitez-colt-final
 
4 gip webinar dic 2013
4 gip webinar dic 20134 gip webinar dic 2013
4 gip webinar dic 2013
 
Webinar 3-12-2013 Comptel, Analytics
Webinar 3-12-2013 Comptel, AnalyticsWebinar 3-12-2013 Comptel, Analytics
Webinar 3-12-2013 Comptel, Analytics
 
Ims and rcs are fighting ott nov 8 2013 v1
Ims and rcs are fighting ott nov 8 2013 v1Ims and rcs are fighting ott nov 8 2013 v1
Ims and rcs are fighting ott nov 8 2013 v1
 
Webinar 26 de noviembre 2013
Webinar 26 de noviembre 2013Webinar 26 de noviembre 2013
Webinar 26 de noviembre 2013
 
Sdn en latinoamérica 5 11-13
Sdn en latinoamérica 5 11-13Sdn en latinoamérica 5 11-13
Sdn en latinoamérica 5 11-13
 
Workshop sdn nfv arg-ch juniper
Workshop sdn nfv arg-ch juniperWorkshop sdn nfv arg-ch juniper
Workshop sdn nfv arg-ch juniper
 
Cant touch this hs es_la_no_mc_hv1
Cant touch this hs es_la_no_mc_hv1Cant touch this hs es_la_no_mc_hv1
Cant touch this hs es_la_no_mc_hv1
 
Sdn nf v_cala_slides
Sdn nf v_cala_slidesSdn nf v_cala_slides
Sdn nf v_cala_slides
 
Cala workshop final chile
Cala workshop final   chileCala workshop final   chile
Cala workshop final chile
 
Workshop sdn nfv arg-ch juniper
Workshop sdn nfv arg-ch juniperWorkshop sdn nfv arg-ch juniper
Workshop sdn nfv arg-ch juniper
 
Revolucion movil telesemana
Revolucion movil telesemanaRevolucion movil telesemana
Revolucion movil telesemana
 
Packet network timing distribution webinar v0-3 hs-es_la
Packet network timing distribution   webinar v0-3 hs-es_laPacket network timing distribution   webinar v0-3 hs-es_la
Packet network timing distribution webinar v0-3 hs-es_la
 
Webinar telesemana amdocs_toa_sep_2013v4
Webinar telesemana amdocs_toa_sep_2013v4Webinar telesemana amdocs_toa_sep_2013v4
Webinar telesemana amdocs_toa_sep_2013v4
 
Lte continuing the evolution of mobile broadband networks
Lte continuing the evolution of mobile broadband networksLte continuing the evolution of mobile broadband networks
Lte continuing the evolution of mobile broadband networks
 
Content blocking telesemana_final 2
Content blocking telesemana_final 2Content blocking telesemana_final 2
Content blocking telesemana_final 2
 
Comptel social links_2.0_presentation v2
Comptel social links_2.0_presentation v2Comptel social links_2.0_presentation v2
Comptel social links_2.0_presentation v2
 
Telco systems final
Telco systems finalTelco systems final
Telco systems final
 
Webinar telesemana lte
Webinar telesemana lteWebinar telesemana lte
Webinar telesemana lte
 
Telesemana webinar cos final
Telesemana webinar cos finalTelesemana webinar cos final
Telesemana webinar cos final
 

Telesemana webinar enero 22 2013

  • 1. Aptilo Networks “We control Billing, User Services and Access in Wi-Fi, WiMAX and 3G / LTE networks worldwide” Why carrier Wi-Fi must go beyond the offloading aspect Reinaldo Medina Manager Sales Engineer
  • 2. Why Build Wi-Fi ? Stand out from competition Large Wi-Fi Network Drive to premium = Loyalty plans ($49 -> $59) Bundle with other services Reduce churn Wi-Fi-only devices become subscribers ”All” devices have Wi-Fi Offload up to 30% of traffic Users like Wi-Fi Take control – make Wi-Fi secure & Slow down CAPEX at seamless Lower cost busy sites Some services only to produce data available in Wi-Fi 2
  • 3. All Mobile Operators Need a Wi-Fi Strategy 3
  • 4. Offloading and 3GPP integration 3GPP AAA for Trusted & Untrusted Authentications SWx HSS PCRF S6b eNB SGW/ PDN Is it really that LTE MME GW RAN S2a S2b “simple” ? 3GPP SWm + ePDG Wi-Fi Wi-Fi to Trusted Un-Trusted Mobile Core WLAN WLAN STa, SWa EAP-SIM AG/WAG Wi-Fi RAN Traffic path Signalling path 4
  • 5. Carrier-Class Wi-Fi is so much more than just Offloading and 3GPP integration Policy SMS Charging Look-up OTP OCS OFCS CRM SMSC 3GPP AAA for Trusted & Untrusted Authentications ANDSF SWx HSS S9 PCRF S6b SGW/ PDN Carrier-Class Wi-Fi LTE eNB MME GW Service Management RAN S2a S2b 3GPP + ePDG SWm •  Wi-Fi AAA, Captive Portal & Hotspot Wi-Fi Wi-Fi to Management for non-3GPP Trusted Un-Trusted Mobile Core WLAN WLAN •  One-time-password via SMS STa, SWa AG/WAG EAP-SIM Innovative Integration Wi-Fi Radius/WEB Wi-Fi RAN For Policy & Charging Local Break-Out (non-SIM devices) Only Wi-Fi to •  Policy Manager for Wi-Fi policies, Local Break-Out can make lookups from PCRF, Traffic path CRM or any database. Signalling path •  Charging & Billing aggregation 5
  • 6. I am not building my own Wi-Fi footprint…… Do I need a Wi-Fi Service Management system? Temporary credentials for WISP login Mobile Core PCRF HLR HSS Wi-Fi HTTPS Mobile Operator ing rward Portal OCS Service Sec ure fo Mgmt YES! OFCS System Portal CRM •  Need a system to roam with WISPs Access Gateway •  Need a system for SIM authentication •  Need a system to handle secure logins AP ‒  Use of so-called opaque login, user is securely forwarded to their home portal for login. Advanced Wi-Fi Service Management System Clients creates temporary credentials to login in the WISP’s network. •  Need a system for charging & billing aggregation •  Need a system to translate policies to what makes sense in each WISP’s Wi-Fi network Wirless Internet ServiceProviders 6
  • 7. How To Build Coverage Traditional Hotspots Small Cells (outdoor) Residential/SMB •  Hotels, restaurants, airports •  Where high 3G traffic •  Combined with DSL •  Retail/shopping strong trend •  Stadiums, High Streets, •  All subs > 5 Mbps •  Acquisition WISP network Metro, Square, Parks, Beaches •  Dual SSID •  3GPP Core Integration •  2016 90% of BS = Small Cells   One for public use •  Wi-Fi + Small Cell convergence   Utilize overcapacity •  Micro/Pico BS with Wi-Fi Utilize an "Normal" Existing RAN roll-out Network 7
  • 8. Common Wi-Fi Business Models •  Post/Prepaid subscription loyalty → Wi-Fi unlimited •  Post/Prepaid subscription bundle → Bundle Wi-Fi with e.g. 1:10 charging •  Group account subscriptions → One SIM, multiple devices (SIM/non-SIM) •  Pay per use → Multiple data plans (daypass, weekpass) •  Enterprise offers (B-to-B) → Guest Internet Access, Hospitality 8
  • 9. Why SIM authentication is so important for the offloading business model •  Very strong usage increase (10x users in 12 months) ‒  Similar statistics among several mobile operators •  More frequent and shorter session ‒  Due to completely seamless transfer Wi-Fi/3G •  Strong correlation to iOS5 ‒  All Apple iOS devices can do EAP-SIM •  Example from an airport •  50% reduction HSPA traffic ‒  In cells with good Wi-Fi coverage 9
  • 10. Why additional authentication methods are needed All devices do not support SIM authentication. SIM-based WISPr 2.0 •  There are alternative methods Automatic MAC-based authentication WISPr Client SIM-based 802.1x ‒  Balance experience vs security OTP via SMS •  Highest Security ‒  As secure as 3G/4G Self- SIM-based ‒  Payload encrypted Manual registration via 802.1x with SMS, then bill shock One-time •  High Security MAC-based prevention* ‒  High security for authentication ‒  No encryption of payload •  Standard Security Manual login One-time- Manual username / password via ‒  Some security risk for password SMS authentication ‒  No encryption of payload Standard High Highest * User is automatically authenticated but needs to accept an additional charge via the portal before gaining access to the Internet 10
  • 11. Innovative combination of authentication methods •  Case: Tier 1 mobile operator ‒  Wanted to combine the security and convenience of SIM authentication with the monetization of the service through a WEB portal. •  Combines SIM + Portal •  User just have to approve charge with a single click •  Use of Aptilo’s innovative ServiceGlue ‒  Possible to add advanced logic to the authentication flow 1.  Retrieval of MAC address and IMSI •  During the SIM authentication, the user’s MAC address and IMSI is retrieved and posted to the CRM system. •  Based on the IMSI - the user can be securely identified and the MAC address tied to the correct MSISDN. 2.  Re-direct to portal after SIM authentication •  The user’s MAC address is used to lookup the user’s MSISDN in CRM system. The individual user is then presented with different options based on his/her status, approve charge and click to connect or top-up etc. MSISDN is used as charging identifier. 11
  • 12. Hotspot 2.0 and the new 802.11u standard •  Network discovery and selection ‒  Automatic discovery of suitable networks through the advertisement of access network More type, roaming consortium support and venue information •  How Hotspot 2.0 works 1.  802.11u-capable AP beacons with HS2.0 support 2.  The Passpoint certified device detects the AP Today HS 2.0 network 3.  Device selects AP and performs ANQP request to determine what providers are supported, capabilities of the AP, etc. 4.  AP responds to ANQP query with requested information 5.  Device compiles provisioned profile information against HS2.0 data from APs and associates to the best SSID AP with 802.11u •  Next Generation Hotspot (NGH) ‒  Extends the HS 2.0 initiative to include Will take time before 802.11u •  Roaming/WRIX (roaming exchange) updates support is widespread, ANDSF •  Accounting support will add policy-based network selection •  Legacy authentication methods 12
  • 13. Hall 5 Thank You! Booth 5G61 1
  • 14. Carrier Wi-Fi Authentication Options Tomás Lynch Senior Solution Architect Fixed Broadband and Convergence
  • 15. Anywhere internet 24/7, please 95% of the Smartphone users want anywhere access Smartphones make on-the- go laptop usage less frequent Smartphones complement rather than replaces laptops Tablets are likely to become a key on-the-go device Internet everywhere is a pre-requisite, not an option Source: Ericsson Consumer Lab, Mobile Broadband business user study 2011 Carrier Wi-Fi Authentication Options | Public | © Ericsson AB 2013 | 2013-01-15 | Page 2
  • 16. Authentication Options › Web Portal Authentication – An Access Gateway (ISG/BNG/PDG) will handle the subscriber session, providing IP addresses, authentication and policies. › UAM/WISPr Authentication – The Access Points will redirect user traffic to a web portal and authenticate credentials against RADIUS. › EAP Authentication – The Access Points will authenticate users credentials against RADIUS server before association. Carrier Wi-Fi Authentication Options | Public | © Ericsson AB 2013 | 2013-01-15 | Page 3
  • 17. Web Portal Authentication 1. Open SSID 2. User gets connected and receives IP address from the Access Gateway 3. User Web Traffic is redirected to the login page (redirection enforced by the Access Gateway) 4. User and Pass are checked against AAA (RADIUS) 5. User is authenticated and proper policies are applied/enforced at the Access Gateway (rate limit, volume quota, etc…) 6. Traffic is allowed Carrier Wi-Fi Authentication Options | Public | © Ericsson AB 2013 | 2013-01-15 | Page 4
  • 18. Web Portal Flow First Time Auth. User AP BNG AAA Web Portal Open SSID DHCP Request MAC MAC Verification Logged In! DHCP Answer Traffic to http Traffic is redirected User/Password Access Granted CoA Message Traffic is allowed Carrier Wi-Fi Authentication Options | Public | © Ericsson AB 2013 | 2013-01-15 | Page 5
  • 19. Web Portal Flow Second Time Auth. User AP BNG AAA Web Portal Open SSID DHCP Request Access Granted MAC Verification DHCP Answer Traffic is allowed Carrier Wi-Fi Authentication Options | Public | © Ericsson AB 2013 | 2013-01-15 | Page 6
  • 20. UAM/WISPr Authentication Options › Three options: – DHCP and Redirection at the AP – DHCP and Redirection at the Controller – External DHCP and Redirection at the Controller › All options may include NAT › No roaming when DHCP or NAT at AP Carrier Wi-Fi Authentication Options | Public | © Ericsson AB 2013 | 2013-01-15 | Page 7
  • 21. UAM/WISPr Authentication 1. Open SSID 2. User connects and receives IP address from the DHCP Server 1. DHCP/NAT can be also applied by the AP 3. User Web Traffic is redirected to the login page (redirection enforced by the controller or AP) 4. User and Pass are checked against RADIUS 5. User is authenticated and proper policies are applied/enforced at the Access Point (rate limit, volume and /or time quota) Carrier Wi-Fi Authentication Options | Public | © Ericsson AB 2013 | 2013-01-15 | Page 8
  • 22. UAM/WISPr Flow First Time Auth. User AP Controller AAA Web Portal Open SSID DHCP Request MAC MAC Verification Logged In! DHCP Answer Traffic to http Traffic is redirected User/Password Message including auth. Attributes embedded Allow Access Access Granted Attr. Verification Traffic is allowed Carrier Wi-Fi Authentication Options | Public | © Ericsson AB 2013 | 2013-01-15 | Page 9
  • 23. UAM/WISPr Flow Second Time Auth. User AP Controller AAA Web Portal Open SSID DHCP Request Access Granted MAC Verification DHCP Answer Traffic is allowed Carrier Wi-Fi Authentication Options | Public | © Ericsson AB 2013 | 2013-01-15 | Page 10
  • 24. EAP Authentication › Allows End-to-End Authentication – Direct from wireless device to AAA server. – AP acts as “dumb” L2-L3 relay › WPA2/802.1x SSID › User is authenticated on RADIUS (EAP) before associates to the AP › Once associated, user receives IP address from the DHCP Server (PDG) – PDG is recommended by 3GPP Carrier Wi-Fi Authentication Options | Public | © Ericsson AB 2013 | 2013-01-15 | Page 11
  • 25. EAP Types › TTLS (Tunneled Transport Layer Security) – Username/password inside secure tunnel – Very widely supported, simple with certificate-based security. – This is the most common form of EAP › SIM – Use GSM SIM over EAP – Only works in SIM-based devices. – No configuration on device. – Requires connection to HLR associated with SIM card Carrier Wi-Fi Authentication Options | Public | © Ericsson AB 2013 | 2013-01-15 | Page 12
  • 26. EAP-TTLS Auth. Flow User AP PDG AAA External AAA 802.1x Access Request EAP Request MAC Logged In! EAP Proxy EAP Answer 802.1x Access Answer DHCP Request Access Granted MAC Address DHCP Answer Traffic is allowed Carrier Wi-Fi Authentication Options | Public | © Ericsson AB 2013 | 2013-01-15 | Page 13
  • 27. EAP-SIM Auth. Flow User AP PDG AAA HLR 802.1x Access Request EAP Request MAC Logged In! SS7 MAP EAP Answer 802.1x Access Answer DHCP Request Access Granted MAC Address DHCP Answer Traffic is allowed Carrier Wi-Fi Authentication Options | Public | © Ericsson AB 2013 | 2013-01-15 | Page 14
  • 28. Smartphones & EAP › Blackberry supports 802.1X™  standard  and  EAP   authentication using EAP-FAST, EAP-SIM, EAP-TLS EAP- TTLS, LEAP, and PEAP › Android phones support EAP-TTLS in several models. EAP-SIM is supported after applying a patch found in http://code.google.com/p/seek-for-android/wiki/EapSimAka › iPhone supports EAP-SIM and a variety of other EAP methods Carrier Wi-Fi Authentication Options | Public | © Ericsson AB 2013 | 2013-01-15 | Page 15
  • 29. Authentication Options Comparison › Web Portal: – Useful when network already has a BNG for fixed broadband – Integration of fixed and mobile networks › UAM/WISPr: – New deployments for companies not having a fixed broadband network – Useful to integrate third parties (e.g. coffee shops) › EAP – Useful when a high percentage of smartphones supports EAP – Mobile network based companies Carrier Wi-Fi Authentication Options | Public | © Ericsson AB 2013 | 2013-01-15 | Page 16