What Is the S2b Interface? A Complete Guide to the S2b Interface in VoWiFi (Wi-Fi Calling)
Voice over Wi-Fi (VoWiFi), commonly known as Wi-Fi Calling, has become an essential feature in modern mobile communication networks. It allows subscribers to make and receive voice calls, send SMS messages, and use IMS (IP Multimedia Subsystem) services over a Wi-Fi connection instead of relying solely on a cellular radio network. This technology is particularly valuable in locations where cellular coverage is weak or unavailable, such as underground parking garages, office buildings, shopping malls, airports, and residential areas with poor indoor signal strength.
One of the most important interfaces that enables Wi-Fi Calling is the S2b interface. Although it operates behind the scenes and is invisible to end users, the S2b interface is responsible for securely connecting users on untrusted Wi-Fi networks to the mobile operator’s Evolved Packet Core (EPC). Without the S2b interface, a subscriber connected through a home Wi-Fi router or public hotspot would not be able to access IMS services or maintain secure communication with the operator’s core network.
This article explains the S2b interface, how it works, its architecture, signaling procedures, protocols, security mechanisms, and why it plays a critical role in LTE and IMS-based Wi-Fi Calling services.
What Is the S2b Interface?
The S2b interface is a standardized interface defined by the 3rd Generation Partnership Project (3GPP) for secure access to the Evolved Packet Core (EPC) through an untrusted non-3GPP access network, such as Wi-Fi.
Its primary function is to connect the:
- ePDG (Evolved Packet Data Gateway)
to the:
- PGW (Packet Data Network Gateway)
through the EPC.
Unlike LTE radio access, where the User Equipment (UE) connects through an eNodeB, Wi-Fi Calling uses an untrusted wireless network. Since the operator cannot trust public or home Wi-Fi networks, additional security and authentication mechanisms are required before user traffic is allowed into the EPC.
The S2b interface provides this secure bridge between the ePDG and the PGW.
Why Is the S2b Interface Needed?
A Wi-Fi network belongs to someone else.
It may be:
- Home broadband
- Coffee shop Wi-Fi
- Airport hotspot
- Hotel network
- Public wireless network
Since these networks are outside the mobile operator’s control, they are considered untrusted access networks.
Without additional protection:
- User identity could be exposed.
- Traffic could be intercepted.
- Calls could be compromised.
- Unauthorized users might gain network access.
The S2b interface ensures that only authenticated subscribers receive secure access to the operator’s packet core.
Main Components Involved
Several network elements participate in establishing Wi-Fi Calling.
User Equipment (UE)
The UE is the subscriber’s smartphone or mobile device.
It supports:
- LTE
- IMS
- Wi-Fi Calling
- IPsec
- SIM authentication
The UE initiates the secure connection.
Wi-Fi Network
The Wi-Fi network provides internet connectivity.
Examples include:
- Home router
- Enterprise WLAN
- Airport Wi-Fi
- Hotel hotspot
This network only provides IP connectivity.
It does not authenticate subscribers into the mobile core.
ePDG (Evolved Packet Data Gateway)
The ePDG serves as the secure gateway between the untrusted Wi-Fi network and the EPC.
Its responsibilities include:
- Establishing IPsec tunnels
- Authenticating users
- Forwarding traffic
- Security enforcement
- Creating secure communication channels
The ePDG is often described as the “security guard” protecting the mobile operator’s network.
AAA Server / HSS
Before granting network access, the ePDG verifies subscriber credentials.
Authentication is performed using:
- AAA Server
- HSS (Home Subscriber Server)
These systems confirm:
- Subscriber identity
- Service authorization
- Subscription validity
Only authorized subscribers can continue.
PGW (Packet Data Network Gateway)
The Packet Data Network Gateway connects subscribers to external IP networks.
Its functions include:
- IP address allocation
- Bearer creation
- Traffic routing
- Quality of Service (QoS)
- Charging
The PGW provides the subscriber’s home-network IP address.
IMS (IP Multimedia Subsystem)
Once connectivity has been established, IMS delivers communication services including:
- Voice calls
- Video calls
- SMS over IP
- Multimedia communication
IMS is the service platform used for VoWiFi.
Overall Connection Flow
The Wi-Fi Calling connection proceeds in several stages.
The complete path is:
UE → Wi-Fi → ePDG → PGW → IMS Core
Each stage has a specific function.
Step 1: SWu Interface
The first connection occurs over the SWu interface.
The smartphone establishes an encrypted IPsec tunnel to the ePDG.
This tunnel protects all communication between the UE and the operator.
Information transmitted through the tunnel cannot be read by other users sharing the same Wi-Fi network.
The SWu interface therefore provides confidentiality, integrity, and authentication.
Step 2: User Authentication
Once the IPsec tunnel exists, the ePDG authenticates the subscriber.
Authentication typically uses:
- EAP-AKA
- EAP-AKA’
- SIM credentials
The ePDG communicates with:
- AAA Server
- HSS
to verify:
- IMSI
- Authentication vectors
- Subscriber permissions
If authentication succeeds, the subscriber proceeds to EPC access.
Step 3: Establishing the S2b Interface
Now the ePDG must establish connectivity with the Packet Data Network Gateway.
This occurs over the S2b interface.
The S2b interface carries signaling between:
- ePDG
- PGW
using GTPv2-C (GPRS Tunneling Protocol Version 2 – Control Plane).
Create Session Request
The first major signaling message is:
Create Session Request
The ePDG sends this request to the PGW.
The request contains information such as:
- Subscriber identity
- APN
- QoS parameters
- Tunnel identifiers
- Bearer information
The PGW uses this information to establish the subscriber session.
IP Address Allocation
After receiving the Create Session Request, the PGW performs several important tasks.
It:
- Creates the subscriber session
- Allocates an IP address
- Creates the default bearer
- Installs QoS policies
- Prepares charging information
The assigned IP address belongs to the operator’s mobile network rather than the local Wi-Fi network.
This allows IMS services to function correctly.
Create Session Response
The PGW replies with a:
Create Session Response
The response includes:
- Assigned IP address
- Tunnel identifiers
- Bearer information
- QoS parameters
The subscriber session is now active.
Tunnel Binding
The ePDG now performs tunnel binding.
It links:
Outer Tunnel:
IPsec Tunnel
to
Inner Tunnel:
GTP Tunnel
This mapping allows secure user traffic arriving through IPsec to be forwarded correctly into the EPC.
Likewise, traffic returning from the PGW is encrypted before being transmitted across the Wi-Fi network.
User Plane Communication
Once setup is complete:
Voice packets travel as:
UE
↓
IPsec Tunnel
↓
ePDG
↓
GTP Tunnel (S2b)
↓
PGW
↓
IMS Core
↓
VoLTE/VoWiFi Services
All communication remains encrypted across the untrusted network.
Protocols Used
Several protocols operate together during Wi-Fi Calling.
IPsec
Provides:
- Encryption
- Authentication
- Integrity protection
Used between:
UE ↔ ePDG
GTPv2-C
Used over:
S2b Interface
Responsible for:
- Session management
- Bearer creation
- Mobility procedures
GTP-U
Carries user traffic after session establishment.
Examples include:
- Voice packets
- IMS signaling
- SMS over IP
Diameter
Used between:
ePDG
AAA
HSS
for authentication and authorization.
Security Features
The S2b interface contributes significantly to network security.
Key protections include:
Subscriber Authentication
Only valid SIM subscribers receive network access.
Traffic Encryption
The IPsec tunnel protects data traveling across public Wi-Fi.
Integrity Protection
Packets cannot be modified without detection.
Secure Mobility
Users can safely move between different Wi-Fi networks while maintaining secure sessions.
Advantages of the S2b Interface
The S2b interface offers numerous operational benefits.
Improved Indoor Coverage
Subscribers can place calls in areas where LTE signals are weak.
Better Customer Experience
Users enjoy seamless voice services through Wi-Fi.
Reduced Cellular Congestion
Traffic is offloaded from LTE radio resources.
Enhanced Security
IPsec encryption protects communication over untrusted networks.
Standardized Architecture
S2b is standardized by 3GPP, ensuring interoperability among equipment vendors.
Practical Example
Imagine a subscriber entering a shopping mall where LTE coverage is weak.
The smartphone automatically connects to the mall’s Wi-Fi network.
The following sequence occurs:
- Wi-Fi connection established.
- UE creates an IPsec tunnel to the ePDG using the SWu interface.
- The ePDG authenticates the subscriber through the AAA server and HSS.
- The ePDG sends a Create Session Request to the PGW over the S2b interface.
- The PGW allocates an IP address and creates the default bearer.
- A Create Session Response is returned.
- The ePDG binds the IPsec tunnel to the GTP tunnel.
- IMS registration begins.
- The subscriber makes a crystal-clear voice call over Wi-Fi.
Throughout this process, the user experiences a normal phone call without needing to understand the complex signaling occurring within the EPC.
Troubleshooting S2b Issues
If Wi-Fi Calling fails, engineers often investigate the S2b interface.
Common problems include:
- GTP tunnel establishment failure
- Authentication errors
- AAA communication failure
- PGW unreachable
- Incorrect APN configuration
- IP address allocation failure
- Diameter signaling issues
- IPsec tunnel problems
- Firewall blocking GTP traffic
Monitoring GTP signaling and EPC logs helps identify these issues.
Conclusion
The S2b interface is a fundamental component of Voice over Wi-Fi (VoWiFi) architecture, enabling secure communication between the ePDG (Evolved Packet Data Gateway) and the PGW (Packet Data Network Gateway) across the Evolved Packet Core (EPC). It allows subscribers connected through untrusted Wi-Fi networks to access mobile operator services safely by combining strong user authentication, encrypted IPsec tunnels, and GTPv2-C session management. During Wi-Fi Calling, the user first establishes a secure SWu interface connection to the ePDG, after which the ePDG authenticates the subscriber through the AAA server or HSS. The ePDG then initiates a Create Session Request over the S2b interface, allowing the PGW to allocate an IP address, establish bearer channels, and return a Create Session Response. Finally, the ePDG binds the secure IPsec tunnel to the newly created GTP tunnel, enabling encrypted user traffic to reach the IMS core for voice, video, and messaging services. By providing a secure bridge between untrusted Wi-Fi access and the mobile core network, the S2b interface plays a vital role in delivering reliable, secure, and seamless Wi-Fi Calling experiences for millions of subscribers worldwide.











