9
Affirmed Networks, Inc., 35 Nagog Park, Acton, MA 01720 USA SOLUTION BRIEF 1 How, When and Wi-Fi: Weaving Wi-Fi into Your Network Experience through Virtualization THE WI-FI OPPORTUNITY While 4G and LTE have captured much of the media attention, Wi-Fi has quietly become the wireless network of choice for many subscribers. Today, more than half of all mobile traffic (60%) is carried over Wi-Fi networks in homes, offices and public places from coffee shops to shopping malls. With the number of Wi-Fi hotspots expected to quadruple globally to 5.8 million over the next few years, analysts predict that soon as much as 80% of all mobile voice and data traffic will be Wi-Fi based. After years of building out their networks, fixed and mobile service providers now recognize the strategic necessity of bringing Wi-Fi access into their network experience. Extending their network coverage through Wi-Fi access enables today’s service providers to solve some of their most pressing challenges: § It enables network providers to monetize Wi-Fi communications through value-added services (e.g. security, quality, persistent identity); § It allows service providers to compete more effectively with over-the-top (OTT) providers such as Skype and WhatsApp; § It gives mobile providers a cost-effective alternative to extending their wireless network coverage into “difficult” areas (e.g., in-building coverage); § It provides an inexpensive backhaul solution to offload the growing amount of video and data traffic on the macrocellular network THE WI-FI CHALLENGE: SEAMLESS INTEGRATION The challenge for fixed and mobile service providers is to seamlessly integrate Wi-Fi voice and data communications into their networks and effectively monetize Wi-Fi access through value-added services that include better quality of experience and seamless session handoff between networks. There are four key areas in which service providers can provide value through network integration: 1. Security 2. Session continuity

How, When and Wi-Fi - affirmednetworks.comaffirmednetworks.com/wp-content/uploads/2017/12/Affirmed-Wifi... · § It provides an inexpensive backhaul solution to offload the growing

  • Upload
    haphuc

  • View
    221

  • Download
    0

Embed Size (px)

Citation preview

Page 1: How, When and Wi-Fi - affirmednetworks.comaffirmednetworks.com/wp-content/uploads/2017/12/Affirmed-Wifi... · § It provides an inexpensive backhaul solution to offload the growing

AffirmedNetworks,Inc.,35NagogPark,Acton,MA01720USA

SOLUTIONBRIEF

1

How,WhenandWi-Fi:WeavingWi-FiintoYourNetworkExperiencethroughVirtualizationTHEWI-FIOPPORTUNITYWhile4GandLTEhavecapturedmuchofthemediaattention,Wi-Fihasquietlybecomethewirelessnetworkofchoiceformanysubscribers.Today,morethanhalfofallmobiletraffic(60%)iscarriedoverWi-Finetworksinhomes,officesandpublicplacesfromcoffeeshopstoshoppingmalls.WiththenumberofWi-Fihotspotsexpectedtoquadruplegloballyto5.8millionoverthenextfewyears,analystspredictthatsoonasmuchas80%ofallmobilevoiceanddatatrafficwillbeWi-Fibased.

Afteryearsofbuildingouttheirnetworks,fixedandmobileserviceprovidersnowrecognizethestrategicnecessityofbringingWi-Fiaccessintotheirnetworkexperience.ExtendingtheirnetworkcoveragethroughWi-Fiaccessenablestoday’sserviceproviderstosolvesomeoftheirmostpressingchallenges:

§ ItenablesnetworkproviderstomonetizeWi-Ficommunicationsthroughvalue-addedservices(e.g.security,quality,persistentidentity);

§ Itallowsserviceproviderstocompetemoreeffectivelywithover-the-top(OTT)providerssuchasSkypeandWhatsApp;

§ Itgivesmobileprovidersacost-effectivealternativetoextendingtheirwirelessnetworkcoverageinto“difficult”areas(e.g.,in-buildingcoverage);

§ Itprovidesaninexpensivebackhaulsolutiontooffloadthegrowingamountofvideoanddatatrafficonthemacrocellularnetwork

THEWI-FICHALLENGE:SEAMLESSINTEGRATIONThechallengeforfixedandmobileserviceprovidersistoseamlesslyintegrateWi-FivoiceanddatacommunicationsintotheirnetworksandeffectivelymonetizeWi-Fiaccessthroughvalue-addedservicesthatincludebetterqualityofexperienceandseamlesssessionhandoffbetweennetworks.Therearefourkeyareasinwhichserviceproviderscanprovidevaluethroughnetworkintegration:

1. Security2. Sessioncontinuity

Page 2: How, When and Wi-Fi - affirmednetworks.comaffirmednetworks.com/wp-content/uploads/2017/12/Affirmed-Wifi... · § It provides an inexpensive backhaul solution to offload the growing

AffirmedNetworks,Inc.,35NagogPark,Acton,MA01720USA 2

3. Policy/qualityenforcement4. Servicessuchascontentfiltering,webandvideooptimization5. Accesstooperatorcontentie.video,musicetc

Tosupportthisintegration,thetelecommunicationsindustryhasdefinedtwonetworkelementstoserveasasecuregatewaybetweenaserviceprovider’scorenetwork—anevolvedpacketcore(EPC)inthecaseofmobileserviceproviders—andbothtrustedanduntrustedWi-Finetworks.ForaccesstotrustedWi-Finetworkssuchasthosedeployedbyorinpartnershipwiththeserviceprovider,theindustryhasdefinedtheTrustedWLANAccessGateway/Proxy(TWAG/TWAP)asthissecureentrypoint.ForaccesstountrustedWi-Finetworkssuchasthoseoperatedindependentlyorinconnectionwithanotherserviceprovider,theappropriatenetworkelementtosecureWi-FiaccesswouldbetheevolvedPacketDataGateway(ePDG).

Currently,serviceprovidershavetwooptionsfordeployingtheseelementsintheirnetwork:eitherasastandalone,hardware-basedlegacydevice(thetraditionalapproach)orasavirtualized,software-basedsolution.Networkfunctionsvirtualization(NFV)isfastbecomingthenewstandardfornetworkevolutionasserviceproviderslooktoscaletheirnetworksquicklywhilereducingcomplexityandcost.Tomeetthisnewdemand,manylegacynetworkgatewayvendorsarenowadaptingtheirhardware-basedsolutionsforvirtualizedenvironments.YetthesesolutionsrarelyofferthesamerobustperformanceandeconomicbenefitsthatnativelydevelopedNFVsolutionspresent.

FIGURE1:AFFIRMEDMOBILECONTENTCLOUD

Page 3: How, When and Wi-Fi - affirmednetworks.comaffirmednetworks.com/wp-content/uploads/2017/12/Affirmed-Wifi... · § It provides an inexpensive backhaul solution to offload the growing

AffirmedNetworks,Inc.,35NagogPark,Acton,MA01720USA 3

THEAFFIRMEDWI-FIGATEWAYSOLUTIONAsaleaderintheNFVnetworkevolution,AffirmedNetworksishelpingfixedandmobileserviceprovidersbuildthenext-generationofnetworksusingcarrier-class,nativelyvirtualizedsolutions.Affirmed’sgroundbreakingvirtualEPC(vEPC)solution,dubbedtheMobileContentCloud(MCC),iscurrentlydeployedinsomeoftheworld’slargestmobileserviceprovidernetworks.TheAffirmedWi-FigatewayhasbeendevelopedontopoftheMCCfromwhichitinheritsawiderangeofmobilegatewayfunctionssuchasGGSN,SAE-GW,SP/DPI/Heuristicsapplicationdetection,PCEFwithGxandGyinterfacesforQoSandoffline/onlinecharging,LawfulInterception,aswellasitsrichsetofcontentservicessuchasHTTP(S)Proxy,webandvideocontentoptimizationandadaptation,contentcaching,contentfiltering/parentalcontrol,subscriberfirewall,NAT/ALGandmore.TheAffirmedWi-FigatewaysolutionfeaturescompleteTWAG/TWAPandePDGfunctionsthatcanbedeployedoncommercialoff-the-shelf(COTS)serversorwithinthevEPConvirtuallymanagedhardware.

FIGURE2:AFFIRMEDWI-FIGATEWAY

Recommended Partner or 3rd Party

User Experience Content

3G/4G

3G/4G

3G/4GAccess

3G/4GRoaming

Trusted WiFi

Trusted

Untrusted

SGSN/SGW

SGSN/SGW

HLR/HSS AAA OCS PCRF

Untrusted WiFi

Page 4: How, When and Wi-Fi - affirmednetworks.comaffirmednetworks.com/wp-content/uploads/2017/12/Affirmed-Wifi... · § It provides an inexpensive backhaul solution to offload the growing

AffirmedNetworks,Inc.,35NagogPark,Acton,MA01720USA 4

Affirmed’sWi-Figatewaysolutionisdesignedtoprovidethemostrobust,reliableandflexiblesolutiononthemarkettoday,featuring:

§ Ultra-highperformanceoncommercialx86serversandblades;§ OpensupportforpopularhypervisorsfromVMware,KVMandOpenStack;§ FullcompliancewithETSINFVstandards;§ EasyintegrationwiththeAffirmedvEPCorthird-partyEPCsolutions;§ AuniquelyengineeredvirtualePDGthatdelivers5Glevelsofperformanceforhighvolumesof

encryptedtraffic;§ Seamlessdeliveryofcorenetworkservicesincludingpolicy/charging,packetinspection,value-added

service/contentoptimizationandworkfloworchestration.

TheWi-FiGatewayinAction:FourExamplesThereareseveralwaysthatserviceproviderscanleverageWi-Fiaccesstoenhancetheirservicesandimprovenetworkperformance.TheseincludeoffloadingtrafficontotrustedWi-Finetworks,extendingcorenetworkservicesthroughtrusted(anduntrusted)Wi-FinetworksandprovidingVoWiFiorWiFicallingserviceswhichincludesseamlesssessionhandoffbetweenWi-Fiandmacrocellularnetworks.We’lltakealookateachofthesecasesbelowandexplainhowtheAffirmedWi-Figatewaysolutionthenecessaryintegrationtosupporttheseservices.OffloadingTrafficontoTrustedWi-FiNetworksUsingWi-Finetworkstoextendnetworkcoverageandreducetrafficonthemacrocellularnetworkhasclearcostadvantagesforserviceproviders.AtrustedWi-Finetworkcanbeeitherahotspotthattheserviceprovidermaintains(e.g.,ahostedhotspotatanairport)oronedeployedinpartnershipwiththeprovider.Theserviceproviderinthiscasemaybeamobileorafixednetworkoperator.CableproviderComcast,forexample,currentlyoffersbothwirelessvoiceanddataservicesthroughthousandsofwirelesshotspotsthatithasdeployedintheU.S.Byatrustednetwork,wemeanoneinwhichtheserviceprovidercanverifybasicuserinformationandexertsomelevelofcontrolovertheaccesspoint.Intheexampleabove,Wi-Fiuserswouldbeauthenticatedbytheserviceprovider’sAuthentication,AuthorizationandAccounting(AAA)systemviatheTWAP,whilethevoice/datatrafficitselfwouldpassthroughtheTWAGanbeoffloadedontothedatanetworkforbackhaul.AnaddedvaluethatAffirmed’ssolutionbringstothisscenarioistheabilitytoapplyGiservicestothesubscriber.Theseservicesinclude:Policyenforcement(includingQoSpolicies),contentfiltering,web/videooptimizationandsecurityservicessuchasNAT,FirewallandIPS.

Page 5: How, When and Wi-Fi - affirmednetworks.comaffirmednetworks.com/wp-content/uploads/2017/12/Affirmed-Wifi... · § It provides an inexpensive backhaul solution to offload the growing

AffirmedNetworks,Inc.,35NagogPark,Acton,MA01720USA 5

FIGURE3:TRUSTEDOFFLOADTrustedWi-FiAccessIntegrationtoEPCExtendingthesubscriber’snetworkexperience—includingvalue-addedservicesandseamlesssessionhandoff—totrustedWi-Finetworksrequirestightintegrationwiththeserviceprovider’scorenetwork.AnexampleoftrustedWi-Fiaccesswouldbewirelessroamingatalargeshoppingmall,wheremobilesubscriberswouldseamlesslymovefromthemacrocellularnetworkoutsidethemalltothewirelessLAN(WLAN)onceinsidethemall.Insuchascenario,subscriberswouldenjoybetterwirelessreceptionindoorswithoutrequiringthemtologontothenetworkorinterruptexistingsessions.Asintheexampleabove,theTWAPwouldsecurecommunicationswiththeAAAserverforauthentication/authorization,whiletheTWAGwouldoffloadvoice/datatraffic(andenforcepoliciesonthattraffic)ontothepacketdatanetwork.However,notalltrafficmayberouteddirectlytotheInternetdirectly.CertaintrafficmayberoutedthroughtheTWAGtothepacketcorenetwork.Operatorswoulddothisiftheywanttoserveuphostedcontentsuchasvideoormusic.TheAffirmedTWAGsupportstheindustry-standardS2ainterface,whichenablestheTWAGtocommunicatedirectlywithanyindustry-standardEPCgateway,whetherit’spartofAffirmed’svirtualEPCsolutionoranexistingthird-partyEPCsolution.

Radius

Radius/ Diameter

Gx Gy

SGi

GRE

UE Connected

via WiFi

AAA PCRF OCS

TWAG/ Gi Svcs

Trusted WiFi

Trusted AP/AC

Packet Data Network

Extending services from trusted networksAuthen!ca!on done locally or through TWAP to AAATransparent to the UENo IPSec or client required on the UEGRE tunnel from Trusted WiFi as opposed to UEValue-add of applying Gi Services to traffic i.e. policy, Qos, Service differen!a!on

- - ----

Capabili!es

Page 6: How, When and Wi-Fi - affirmednetworks.comaffirmednetworks.com/wp-content/uploads/2017/12/Affirmed-Wifi... · § It provides an inexpensive backhaul solution to offload the growing

AffirmedNetworks,Inc.,35NagogPark,Acton,MA01720USA 6

FIGURE4:TRUSTEDvEPCINTEGRATIONUntrustedWi-FiAccessIntegrationInaworldwithmillionsofWi-Fiaccesspoints,untrustedWi-Finetworksareacommonoccurrence.Byanuntrustednetwork,wemeanoneinwhichtheserviceprovidercannotauthenticateusersorcontroltheflowoftrafficoverthenetwork.AnexampleofanuntrustednetworkcouldbeaWi-Finetworkinacoffeeshoporonehostedbyacompetitiveprovider.InordertosafelybringuntrustedWi-Finetworksintothecorenetwork,serviceprovidersmustdeployadifferentelement:anevolvedPacketDataGateway(ePDG).CommunicationsoveruntrustednetworksrequireanaddedlevelofsecurityknownasIPsecencryption.IndustrystandardsmandatethatallmobiledevicesmustfeatureanIPsecclientonthedevice.Inthiscase,voiceanddatasessionspasssecurelythroughanIPsectunnel.Thesetunnelsoftenneedtoremainopeninanticipationofincomingoroutgoingcalls,sothatatanygiventimemillionsofIPsectunnelsmayneedtoremainopeninthenetwork.Hardware-basedePDGsaredesignedtohandlethishighdemandforopenIPsectunnels,butthesesamehighencryptionrequirementshavehistoricallyprovenproblematicforvirtualizedePDGinstances.TheAffirmedePDGistheexceptiontothatrule:aremarkablyrobustvirtualePDGthatcandeliver5GlevelsofIPsec-encryptedcommunicationsonasingleserver.

Radius

Radius/ Diameter Gx Gy

SGi

SGi

GRE

S2a

S5

UE Connected

via WiFi

AAA PCRF OCS

TWAG/ Gi Svcs

TWAG/ Gi Svcs

Trusted WiFi

Trusted AP/AC

UE Connected via 3G/4G

3G/4G

SGW

Packet Data Network

Affirmed or 3rd party PGW/GGSN

Select traffic routed through TWAG and then to the packet core for addi"onal operator specific services i.e. music, video, etc.Seamless 3G/4G - WiFi mobilityIntegra"on with Affirmed Gateway and 3rd party Gateway

-

--

Capabili!es

Page 7: How, When and Wi-Fi - affirmednetworks.comaffirmednetworks.com/wp-content/uploads/2017/12/Affirmed-Wifi... · § It provides an inexpensive backhaul solution to offload the growing

AffirmedNetworks,Inc.,35NagogPark,Acton,MA01720USA 7

FIGURE5:UNTRUSTEDWI-FIvEPCINTEGRATIONVoiceOverWi-FiMuchlikeVoiceoverLTE(VoLTE),VoiceoverWi-Fi(VoWiFi)seekstocreateseamlesshandoffbetweennetworksduringalivevoicecall.Considerourearlierexampleoftheshoppingmall;inthiscase,serviceproviderswouldbeconcernedwithmovingthesessionfromthemacrocellularnetworkoutsidethemalltotheWi-Finetworkinsidethemallwithoutdroppingthesessionorrequiringtheusertologintoadifferentnetwork.Infact,thegoalwithVoWiFi(aswithVoLTE)istomakethistransitioncompletelyinvisibletousers.Althoughrelativelynew,VoWiFiisexpectedtogaintractioninthecomingyearsasmobileserviceproviderslooktoaddressoneoftheirgreatestchallenges:weakin-buildingcoverage.Theaddition,forthefirsttime,ofbuilt-inVoWiFifeaturesintothenewAppleiPhone6isexpectedtoacceleratetheadoptionofVoWiFi.TheePDGprovidesthenecessarysupportforencryptedVoWiFicallswhilebringingthesessionintotheIMS/LTEcoreforpersistentsessioncontrolandpolicyenforcement.Hereagain,theAffirmedePDGprovidesasuperiorlevelofperformanceonencryptedcommunicationsinascalable,flexiblevirtualizedplatform.

IPSec

Radius/ Diameter

Gx Gy Gz

SGi

SGi

S2b

S5

UE Connected

via WiFi

AAA PCRF OCS OFCS

ePDG

GGSN/ PGW/Gi

Untrusted WiFi

UE Connected via 3G/4G

3G/4G SGW

Packet Data Network

High performance ePDGAllows WiFi access to the Operator’s servicesTransparent to the Untrusted WiFi OperatorNo arrangement with WiFi operator requiredNo interworking with the AP/ACLocal breakout or integrated with PGW for seamless mobility

------

Capabili!es

Client

Page 8: How, When and Wi-Fi - affirmednetworks.comaffirmednetworks.com/wp-content/uploads/2017/12/Affirmed-Wifi... · § It provides an inexpensive backhaul solution to offload the growing

AffirmedNetworks,Inc.,35NagogPark,Acton,MA01720USA 8

FIGURE6:VOICEOVERWIFIMakingtheWi-FiFutureaRealityTodayWi-Fiaccessiscriticallyimportanttothefutureoffixedandmobileserviceproviders—asimportantasradioaccessnetworksandpotentiallymoreimportantthanVoLTE.YetserviceprovidersneedtosolidifytheirWi-Fiaccessstrategiessoon,asthekeymarketplayersarealreadyjockeyingforpositioninthisnewmarket,asevidencedbyearlyWi-FiservicerolloutsfromT-MobileandComcast.Networkfunctionsvirtualizationprovidesthequickestandmostcost-effectivepathforthistransformation,providedthatthesolutiondeliverscarrier-classsecurity,seamlesssessionhandoffandtightintegrationwithcoresubscribersservicessuchaspolicyenforcement,identityandaccounting.VirtualizationandWi-Fiaccesspresentthenextgenerationofnetworkedcommunications.Bybringingthetwotechnologiestogetherinarobustandhighlyscalablesolution,Affirmedenablesserviceproviderstodeliverabettercommunicationsexperiencefortheirsubscribersthroughinnovationandsmarterefficiency.

IPSec

Radius/ Diameter

Gx Gy Gz

SGi

SGi

S2b

S5

UE Connected

via WiFi

AAA PCRF OCS OFCS

ePDG

GGSN/ PGW/Gi

Untrusted WiFi

UE Connected via 3G/4G

3G/4G SGW

Packet Data Network

Be!er in building coverage and voice experienceTraffic offload to help with RAN capacity constraintsCapitalize on exis$ng WiFiCompete with OTT and reduce churnSupport of SIM and non-SIM devices

-----

Capabili!es

Client

IMS

Page 9: How, When and Wi-Fi - affirmednetworks.comaffirmednetworks.com/wp-content/uploads/2017/12/Affirmed-Wifi... · § It provides an inexpensive backhaul solution to offload the growing

AffirmedNetworks,Inc.,35NagogPark,Acton,MA01720USA 9

APPENDIXWi-FiInterfaces

LI GW

GyGx

vWAG / vWAP / vePDG

SPR

UE

Untrusted AC/AP

Trusted AC/AP

PCRF OCSOFCS

AAAAAA Proxy

GGSN

EMS

PGW