A subscriber walks into a building with no coverage and connects to Wi-Fi. For calls and messaging to keep working, that untrusted Wi-Fi has to reach your EPC over a secure tunnel, and the subscriber's SIM has to be authenticated against the HSS. The ePDG terminates the tunnel; the AAA authenticates the SIM. Together they are how VoWiFi reaches your core.
VoWiFi lets subscribers make calls and send messages over any Wi-Fi network: home broadband, a café, an airport. None of those networks are under operator control. They are, by definition, untrusted access.
The problem is bridging that untrusted access to the EPC and IMS core without exposing either. The Wi-Fi leg has to be encrypted end to end into the operator network, and the subscriber's identity has to be verified against the HSS using the SIM credentials — not a username and password. Without a gateway that terminates a secure tunnel and an authenticator that speaks SIM-based EAP, VoWiFi either does not work or is not safe to turn on.
For an MVNO there is a second problem, and it is financial. Every VoLTE call, video call, or SMS a subscriber makes is carried by the host MNO — national or roaming — and has to be compensated at that host's wholesale data rate. A session originated or terminated over VoWiFi never touches the host network, so that cost is zero. Every minute moved onto Wi-Fi is margin the MVNO keeps, and room to price against operators who own their own radio.
Two elements, one access path
The Ouroboros ePDG and AAA together form the access path for untrusted Wi-Fi into the mobile core.
The ePDG terminates the IPsec tunnel and connects the subscriber to the PGW over S2b
The ePDG (Evolved Packet Data Gateway) terminates an IPsec tunnel established by the handset over IKEv2. The subscriber's device builds an encrypted tunnel from the Wi-Fi network to the ePDG; all VoWiFi traffic rides inside it. The ePDG then connects to the PGW over the S2b interface, placing the subscriber's session into the same EPC bearer path used by LTE — so the IMS core sees a VoWiFi session the same way it sees a VoLTE one.
The AAA authenticates the SIM over EAP-AKA against the HSS — no separate password
The AAA (3GPP AAA Server) authenticates the subscriber during tunnel setup. The ePDG relays EAP-AKA authentication from the handset to the AAA over the SWm interface; the AAA fetches the authentication vectors and subscriber profile from the HSS over the SWx (Diameter) interface. EAP-AKA uses the SIM/USIM credentials, so there is no separate password — the same identity that authenticates the subscriber on LTE authenticates them on Wi-Fi.
Calls and messaging use the existing IMS core; handover between VoWiFi and VoLTE is supported
The result is a subscriber on untrusted Wi-Fi, securely tunnelled into the EPC, authenticated by their SIM, with calls and messaging carried by the existing IMS core. Handover between VoWiFi and VoLTE is supported so an active call survives the move between Wi-Fi and the cellular network.
ePDG · AAA — untrusted Wi-Fi access into the EPC
Coverage extension, Wi-Fi roaming, SIM-based auth, seamless handover — one access path for all VoWiFi scenarios.
VoWiFi coverage extension
Subscribers in buildings, basements, or rural areas with poor cellular coverage place calls over home or venue Wi-Fi. The ePDG tunnels the session into the EPC and the AAA authenticates the SIM, so the call uses the operator's IMS core with no change to the subscriber experience.
Roaming over Wi-Fi
A subscriber abroad connects to local Wi-Fi and reaches the home IMS core through the ePDG, authenticated by the AAA against the home HSS. This offers calling and messaging without cellular roaming charges, using the home network's services.
SIM-based authentication, no passwords
Because the AAA runs EAP-AKA against the HSS, VoWiFi access uses the same SIM identity as LTE. There is no separate credential for the subscriber to manage and no password store for the operator to secure.
VoWiFi / VoLTE handover continuity
A subscriber on a VoWiFi call walks out of Wi-Fi range onto the cellular network. The session moves between the ePDG path and the LTE path without dropping the call.

We've selected Ouroboros because it was the best company capable of fulfilling our need for a scalable and virtualised full MVNO platform. Moreover, the Ouroboros team is pragmatic, flexible and responsive.
Pascal Prot
CEO-CTO · Legos
IPsec/IKEv2 tunnel termination
The ePDG terminates the encrypted tunnel the handset builds over any Wi-Fi network. Untrusted Wi-Fi reaches the operator core securely, with no trust placed in the access network.
EAP-AKA authentication against the HSS
The AAA authenticates the SIM/USIM over SWx to the HSS, with no separate password. The same identity that works on LTE works on Wi-Fi, and there is no credential store to breach.
S2b integration with the EPC
The ePDG connects to the PGW over S2b, placing the VoWiFi session in the standard bearer path. The IMS core treats VoWiFi like any other access, reusing existing voice and messaging services.
VoWiFi / VoLTE handover
An active session moves between the Wi-Fi and cellular paths without dropping. Subscribers keep their call when they walk in or out of Wi-Fi coverage.
EAP-AKA′ support
The AAA supports AKA′ key separation for access-network-bound keys. Authentication meets current 3GPP security requirements for non-3GPP access.
Carrier-grade availability
The ePDG and AAA run at 99.999% availability on virtualised infrastructure. VoWiFi is dependable enough to be a primary access path, not just a fallback.
VoWiFi turns every Wi-Fi network into coverage — but only if the untrusted access leg is secured and the subscriber is authenticated by their SIM. The ePDG and AAA are the two functions that make that safe and standards-compliant: one terminates the tunnel, the other authenticates against the HSS.
Delivered together as one access path, they reuse the existing EPC and IMS core rather than duplicating it — VoWiFi becomes another way into the same network, not a parallel stack. The OPEX rental model lets operators launch VoWiFi without capitalising new core infrastructure before the coverage benefit is proven.
Tell us your EPC and HSS vendors and your VoWiFi plans, and we'll confirm how the ePDG and AAA fit between the Wi-Fi access leg and your existing core.
4G / LTE · 4G/LTE
ePDG & AAA — VoWiFi Access Gateway
A subscriber walks into a building with no coverage and connects to Wi-Fi. For calls and messaging to keep working, that untrusted Wi-Fi has to reach your EPC over a secure tunnel, and the subscriber's SIM has to be authenticated against the HSS. The ePDG terminates the tunnel; the AAA authenticates the SIM. Together they are how VoWiFi reaches your core.
In production since 2004 · 148M+ subscribers · OPEX rental available
Untrusted access on one side, wholesale cost on the other
VoWiFi lets subscribers make calls and send messages over any Wi-Fi network: home broadband, a café, an airport. None of those networks are under operator control. They are, by definition, untrusted access.
The problem is bridging that untrusted access to the EPC and IMS core without exposing either. The Wi-Fi leg has to be encrypted end to end into the operator network, and the subscriber's identity has to be verified against the HSS using the SIM credentials — not a username and password. Without a gateway that terminates a secure tunnel and an authenticator that speaks SIM-based EAP, VoWiFi either does not work or is not safe to turn on.
For an MVNO there is a second problem, and it is financial. Every VoLTE call, video call, or SMS a subscriber makes is carried by the host MNO — national or roaming — and has to be compensated at that host's wholesale data rate. A session originated or terminated over VoWiFi never touches the host network, so that cost is zero. Every minute moved onto Wi-Fi is margin the MVNO keeps, and room to price against operators who own their own radio.
Untrusted Wi-Fi, securely tunnelled into the EPC.
Two elements, one access path
The Ouroboros ePDG and AAA together form the access path for untrusted Wi-Fi into the mobile core.
The ePDG terminates the IPsec tunnel and connects the subscriber to the PGW over S2b
The ePDG (Evolved Packet Data Gateway) terminates an IPsec tunnel established by the handset over IKEv2. The subscriber's device builds an encrypted tunnel from the Wi-Fi network to the ePDG; all VoWiFi traffic rides inside it. The ePDG then connects to the PGW over the S2b interface, placing the subscriber's session into the same EPC bearer path used by LTE — so the IMS core sees a VoWiFi session the same way it sees a VoLTE one.
The AAA authenticates the SIM over EAP-AKA against the HSS — no separate password
The AAA (3GPP AAA Server) authenticates the subscriber during tunnel setup. The ePDG relays EAP-AKA authentication from the handset to the AAA over the SWm interface; the AAA fetches the authentication vectors and subscriber profile from the HSS over the SWx (Diameter) interface. EAP-AKA uses the SIM/USIM credentials, so there is no separate password — the same identity that authenticates the subscriber on LTE authenticates them on Wi-Fi.
Calls and messaging use the existing IMS core; handover between VoWiFi and VoLTE is supported
The result is a subscriber on untrusted Wi-Fi, securely tunnelled into the EPC, authenticated by their SIM, with calls and messaging carried by the existing IMS core. Handover between VoWiFi and VoLTE is supported so an active call survives the move between Wi-Fi and the cellular network.
ePDG · AAA — untrusted Wi-Fi access into the EPC
How operators use it.
Coverage extension, Wi-Fi roaming, SIM-based auth, seamless handover — one access path for all VoWiFi scenarios.
VoWiFi coverage extension
Subscribers in buildings, basements, or rural areas with poor cellular coverage place calls over home or venue Wi-Fi. The ePDG tunnels the session into the EPC and the AAA authenticates the SIM, so the call uses the operator's IMS core with no change to the subscriber experience.
Roaming over Wi-Fi
A subscriber abroad connects to local Wi-Fi and reaches the home IMS core through the ePDG, authenticated by the AAA against the home HSS. This offers calling and messaging without cellular roaming charges, using the home network's services.
SIM-based authentication, no passwords
Because the AAA runs EAP-AKA against the HSS, VoWiFi access uses the same SIM identity as LTE. There is no separate credential for the subscriber to manage and no password store for the operator to secure.
VoWiFi / VoLTE handover continuity
A subscriber on a VoWiFi call walks out of Wi-Fi range onto the cellular network. The session moves between the ePDG path and the LTE path without dropping the call.
Specifications.
Inside the platform.
IPsec/IKEv2 tunnel termination
The ePDG terminates the encrypted tunnel the handset builds over any Wi-Fi network. Untrusted Wi-Fi reaches the operator core securely, with no trust placed in the access network.
EAP-AKA authentication against the HSS
The AAA authenticates the SIM/USIM over SWx to the HSS, with no separate password. The same identity that works on LTE works on Wi-Fi, and there is no credential store to breach.
S2b integration with the EPC
The ePDG connects to the PGW over S2b, placing the VoWiFi session in the standard bearer path. The IMS core treats VoWiFi like any other access, reusing existing voice and messaging services.
VoWiFi / VoLTE handover
An active session moves between the Wi-Fi and cellular paths without dropping. Subscribers keep their call when they walk in or out of Wi-Fi coverage.
EAP-AKA′ support
The AAA supports AKA′ key separation for access-network-bound keys. Authentication meets current 3GPP security requirements for non-3GPP access.
Carrier-grade availability
The ePDG and AAA run at 99.999% availability on virtualised infrastructure. VoWiFi is dependable enough to be a primary access path, not just a fallback.
VoWiFi turns every Wi-Fi network into coverage — but only if the untrusted access leg is secured and the subscriber is authenticated by their SIM. The ePDG and AAA are the two functions that make that safe and standards-compliant: one terminates the tunnel, the other authenticates against the HSS.
Delivered together as one access path, they reuse the existing EPC and IMS core rather than duplicating it — VoWiFi becomes another way into the same network, not a parallel stack. The OPEX rental model lets operators launch VoWiFi without capitalising new core infrastructure before the coverage benefit is proven.
HSS
The AAA authenticates VoWiFi subscribers against the HSS over SWx. The same subscriber profile drives LTE and VoWiFi access.
vEPC
The ePDG connects to the PGW over S2b. VoWiFi sessions ride the same EPC bearer path as LTE.
Messaging Center (SMSC)
VoWiFi subscribers send and receive messages through the same IMS messaging path the SMSC serves.
Next step
Launching VoWiFi and need untrusted Wi-Fi access into your core?
Tell us your EPC and HSS vendors and your VoWiFi plans, and we'll confirm how the ePDG and AAA fit between the Wi-Fi access leg and your existing core.