Ouroboros Telecom
4G / LTE

A subscriber walks into a building with no coverage and connects to Wi-Fi. For calls and messaging to keep working, that untrusted Wi-Fi has to reach your EPC over a secure tunnel, and the subscriber's SIM has to be authenticated against the HSS. The ePDG terminates the tunnel; the AAA authenticates the SIM. Together they are how VoWiFi reaches your core.

AMTP · ePDG & AAA
ePDG interfacesSWu (IKEv2/IPsec to UE), S2b (to PGW), SWm (to AAA)
AAA interfacesSWm (to ePDG), SWx (Diameter to HSS)
TunnellingIKEv2 / IPsec ESP
AuthenticationEAP-AKA, Milenage
HandoverVoWiFi ↔ VoLTE session continuity
Availability99.999%
IKEv2
tunnel protocol
SWu
UE interface
3GPP
standards
EAP-AKA
authentication
00The problem

VoWiFi lets subscribers make calls and send messages over any Wi-Fi network: home broadband, a café, an airport. None of those networks are under operator control. They are, by definition, untrusted access.

The problem is bridging that untrusted access to the EPC and IMS core without exposing either. The Wi-Fi leg has to be encrypted end to end into the operator network, and the subscriber's identity has to be verified against the HSS using the SIM credentials — not a username and password. Without a gateway that terminates a secure tunnel and an authenticator that speaks SIM-based EAP, VoWiFi either does not work or is not safe to turn on.

For an MVNO there is a second problem, and it is financial. Every VoLTE call, video call, or SMS a subscriber makes is carried by the host MNO — national or roaming — and has to be compensated at that host's wholesale data rate. A session originated or terminated over VoWiFi never touches the host network, so that cost is zero. Every minute moved onto Wi-Fi is margin the MVNO keeps, and room to price against operators who own their own radio.

01How it works

ePDG & AAAcore
UE / Wi-FiSWu interface
PDN-GWS2b interface
AAA ServerSTa / SWd
HSSSWx interface
01 / 04

Two elements, one access path

The Ouroboros ePDG and AAA together form the access path for untrusted Wi-Fi into the mobile core.

02 / 04

The ePDG terminates the IPsec tunnel and connects the subscriber to the PGW over S2b

The ePDG (Evolved Packet Data Gateway) terminates an IPsec tunnel established by the handset over IKEv2. The subscriber's device builds an encrypted tunnel from the Wi-Fi network to the ePDG; all VoWiFi traffic rides inside it. The ePDG then connects to the PGW over the S2b interface, placing the subscriber's session into the same EPC bearer path used by LTE — so the IMS core sees a VoWiFi session the same way it sees a VoLTE one.

03 / 04

The AAA authenticates the SIM over EAP-AKA against the HSS — no separate password

The AAA (3GPP AAA Server) authenticates the subscriber during tunnel setup. The ePDG relays EAP-AKA authentication from the handset to the AAA over the SWm interface; the AAA fetches the authentication vectors and subscriber profile from the HSS over the SWx (Diameter) interface. EAP-AKA uses the SIM/USIM credentials, so there is no separate password — the same identity that authenticates the subscriber on LTE authenticates them on Wi-Fi.

04 / 04

Calls and messaging use the existing IMS core; handover between VoWiFi and VoLTE is supported

The result is a subscriber on untrusted Wi-Fi, securely tunnelled into the EPC, authenticated by their SIM, with calls and messaging carried by the existing IMS core. Handover between VoWiFi and VoLTE is supported so an active call survives the move between Wi-Fi and the cellular network.

Reference architecture
Untrusted Wi-Fi access into the evolved packet core. Two Wi-Fi access-point clusters reach the Ouroboros ePDG over SWu; the ePDG relays EAP-AKA to the Ouroboros AAA over SWm, and the AAA fetches authentication vectors from the HSS over SWx. The ePDG hands sessions to the P-GW/PCEF, which connects to a DHCP server, the OCS, the PCRF, and the IMS core over SGi.

ePDG · AAA — untrusted Wi-Fi access into the EPC

02Use cases

Coverage extension, Wi-Fi roaming, SIM-based auth, seamless handover — one access path for all VoWiFi scenarios.

01

VoWiFi coverage extension

Subscribers in buildings, basements, or rural areas with poor cellular coverage place calls over home or venue Wi-Fi. The ePDG tunnels the session into the EPC and the AAA authenticates the SIM, so the call uses the operator's IMS core with no change to the subscriber experience.

02

Roaming over Wi-Fi

A subscriber abroad connects to local Wi-Fi and reaches the home IMS core through the ePDG, authenticated by the AAA against the home HSS. This offers calling and messaging without cellular roaming charges, using the home network's services.

03

SIM-based authentication, no passwords

Because the AAA runs EAP-AKA against the HSS, VoWiFi access uses the same SIM identity as LTE. There is no separate credential for the subscriber to manage and no password store for the operator to secure.

04

VoWiFi / VoLTE handover continuity

A subscriber on a VoWiFi call walks out of Wi-Fi range onto the cellular network. The session moves between the ePDG path and the LTE path without dropping the call.

Legos

We've selected Ouroboros because it was the best company capable of fulfilling our need for a scalable and virtualised full MVNO platform. Moreover, the Ouroboros team is pragmatic, flexible and responsive.

Pascal Prot

CEO-CTO · Legos

03Specifications

ePDG interfaces
SWu (IKEv2/IPsec to UE), S2b (to PGW), SWm (to AAA)
AAA interfaces
SWm (to ePDG), SWx (Diameter to HSS)
Tunnelling
IKEv2 / IPsec ESP
Authentication
EAP-AKA, Milenage
Handover
VoWiFi ↔ VoLTE session continuity
Standards
3GPP TS 23.402, TS 33.402, TS 29.273, RFC 4187 (EAP-AKA)
Protocols
IKEv2, IPsec, Diameter, EAP
Virtualisation
VMware, KVM, Docker
Availability
99.999%
Business model
OPEX rental · CAPEX licence
04Inside the platform

01

IPsec/IKEv2 tunnel termination

The ePDG terminates the encrypted tunnel the handset builds over any Wi-Fi network. Untrusted Wi-Fi reaches the operator core securely, with no trust placed in the access network.

02

EAP-AKA authentication against the HSS

The AAA authenticates the SIM/USIM over SWx to the HSS, with no separate password. The same identity that works on LTE works on Wi-Fi, and there is no credential store to breach.

03

S2b integration with the EPC

The ePDG connects to the PGW over S2b, placing the VoWiFi session in the standard bearer path. The IMS core treats VoWiFi like any other access, reusing existing voice and messaging services.

04

VoWiFi / VoLTE handover

An active session moves between the Wi-Fi and cellular paths without dropping. Subscribers keep their call when they walk in or out of Wi-Fi coverage.

05

EAP-AKA′ support

The AAA supports AKA′ key separation for access-network-bound keys. Authentication meets current 3GPP security requirements for non-3GPP access.

06

Carrier-grade availability

The ePDG and AAA run at 99.999% availability on virtualised infrastructure. VoWiFi is dependable enough to be a primary access path, not just a fallback.

05Why Ouroboros

VoWiFi turns every Wi-Fi network into coverage — but only if the untrusted access leg is secured and the subscriber is authenticated by their SIM. The ePDG and AAA are the two functions that make that safe and standards-compliant: one terminates the tunnel, the other authenticates against the HSS.

Delivered together as one access path, they reuse the existing EPC and IMS core rather than duplicating it — VoWiFi becomes another way into the same network, not a parallel stack. The OPEX rental model lets operators launch VoWiFi without capitalising new core infrastructure before the coverage benefit is proven.

Ouroboros Telecom

Tell us your EPC and HSS vendors and your VoWiFi plans, and we'll confirm how the ePDG and AAA fit between the Wi-Fi access leg and your existing core.