TS 23.402**): Non-Roaming Reference Architecture for non-3GPP Accesses HSS Wx* **) Colouring of non3GPP accesses and red arrows (incl. text in red) added for this presentation 2G/3G SGSN S6a S4 PCRF S3 MME Rx+ S7 S11 SGi S1-MME S10 EUTRAN S1-U Serving SAE Gateway PDN SAE Gateway S5 Operator’s IP Services (e.g. IMS, PSS etc.) S6c S2b S2c S2a 3GPP AAA Server Wn* HPLMN Trusted/Untrusted* Non-3GPP IP Access or 3GPP Access Trusted Non-3GPP IP Access UE * Untrusted non3GPP access requires ePDG in the data path Wm* ePDG Handovers (Discovery and Selection of non-3GPP Access is needed before) Untrusted Non-3GPP IP Access Non3GPP Networks Wa* Ta* 1 Key Issue NW Discovery & Selection (NW-DS) (Excerpt from TR 23.882) It is necessary to optimize NW-DS procedures for frequent mobility events. It is desirable that the concept for NW-DS in SAE supports effective means for minimizing processing. Looking at the currently defined NW-DS principles for I-WLAN in TS 23.234 it becomes clear that they cannot be extended for time critical handovers and for other RATs, due to complexity and latency: per available WLAN access NW a scan/probe has to be performed if a WLAN AN is connected to more than one 3GPP NW this is only detected after L2 association and trying authentication. It is therefore necessary to develop or adopt new, more efficient mechanisms, for both idle and active mode (where this differentiation is applicable). Solutions may be based on concepts developed in other fora (e.g. IEEE 802.11u, IEEE 802.21, IETF) or based on concepts defined by 3GPP (e.g. provision of specific databases). Further mechanisms are FFS. When selecting solutions, the amount of signalling, size of stored and transferred data, especially over the radio interface, and terminal power consumption shall be taken into account. 2 Example of HO Message Flow (from informative annex of TS 23.402) Untrusted Untrusted Non-3GPP non-3GPP Access IPIPAccess UE EUTRAN Serving GW MME - PDN GW ePDG HSS/ AAA PCRF 1. GTP/PMIPv6 Tunnel 2. UE discovers the 2. UE discovers the untrusted untrusted non-3GPP non-3GPP access system and initiates HO access system and initiates HO 3. Access Auth 3. Access Authentication 4. ePDG Discovery 5. IKEv2/Ipsec SA setup (CoA config) 5. AAA Auth/ Authz 6. AAA Auth/ 6. IKEv2/Ipsec SA setup Authz 7. BU/BA (IP Addr) 8. DSMIPv6 Tunnel Ipsec Tunnel 3