Work on RLOS service definition and requirements for unauthenticated UEs (PARLOS) driven primarily by US regulatory obligations to support manual roaming has been completed in [2], [3] and [4]. Meeting this US regulatory obligation add security risks and potential vulnerabilities to devices and networks supporting RLOS.
The ability to provide access to such local services has been available to U.S. operators on a proprietary basis on CS legacy networks. However, the wide deployment of LTE and corresponding introduction of VoLTE creates regulatory obligations on US operators for a standardized mechanism to allow a UE to access these services via LTE and NR (e.g., dialling a particular digit string, accessing a captive portal) without necessarily being successfully authenticated for access.
Manual roaming, an FCC obligation on US operators was first established in 1981, enhanced in 1994 and revisited without modification several times since. In summary, manual roaming is a requirement that US networks need to provide basic outbound only voice calling for users with a UE which is technically capable of connecting to a network's base stations (e.g. supporting the same bandclass), when there is no roaming agreement with the home network operator
In terms of the usage of this service in the US, some measure of the scale is over 23 million call attempts/month (276 million/year).
As a practical matter, while the US FCC regulations only applies to subscribers of US networks without domestic roaming agreements, it is currently not possible to distinguish other devices not covered by the regulation, manual roaming service is generally made available to all unauthenticated devices without distinction.
This service is also provided in Canada but the Canadian manual roaming regulatory framework has not been identified.
The following high-level flow describes the typical manual roaming service for most US networks' support of manual roaming.
-
The UE is unauthenticated and not registered in a US network, but is technically capable of connecting to the network's base station.
-
The user attempts to make a call.
-
The UE attempts to attach to a network as part of the call attempt but fails authentication.
-
The network verifies that the call is not an emergency call (911).
-
The network then forwards the call to the manual roaming service provider's IVR without further analysis of any signalling such as dialled digits.
-
The user interacts with the manual roaming service provider's IVR to provide financial payment information such as a prepaid account or a credit card.
-
After the financial information has been validated by the IVR, the call is placed to the desired number by the IVR (re-originated).
-
After the call is completed, the call is disconnected. If the user wants to make additional calls, the payment information needs to be re-entered.
Manual roaming only supports outbound calls, not inbound calls. This is the major difference between manual roaming and operator provided or operator supported pre-paid service.
The following list are specific aspects of manual roaming which apply to RLOS:
-
Only outbound initiated communication needs to be supported.
-
There is no need to send any 3GPP subscriber, user or device identities to the manual roaming service platform.
-
The service is on a per session or per call basis and needs to be re-established for subsequent sessions.
-
User interactions with manual roaming service IVR platform and manual roaming calling is outside the scope of RLOS. RLOS only provides the means to access the manual roaming service. In many cases the user interaction will be external to the 3GPP network.
-
Business or financial risks of providing manual roaming is outside the scope of RLOS. Rather these risks are handled by their manual roaming service platform.
Since manual roaming is a separate business and financial transaction separate from and not based on the user's subscription status with any operator, issues of IMEI blacklisting is only applicable based on RLOS operator implementation and home network operator service restrictions is not applicable. It should be noted as well, that manual roaming only provides outbound calling, a limited subset of voice services.