Access Stratum Security Segmentation for Ultra-Dense Small Cells

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The conventional cellular radio network struggles to provide high-quality, high-speed, low-latency mobile services, especially in indoor environments due to its wide coverage and uniform signal distribution, which cannot meet the demand for large data capacity and is insecure when communication data is transmitted through multiple air interfaces in ultra-dense networks.

Innovation Solution

Implementing end-to-end access stratum security between user equipment and gateway nodes, and between user equipment and initial access nodes or macro base stations, using encryption and integrity protection mechanisms to ensure secure data transmission across multiple air interfaces, while improving mobility performance and transmission continuity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If small radio access nodes are densely deployed to increase network capacity, then network capacity is improved, but security of data transmission through multiple air interfaces deteriorates

Engineering Contradiction:
Improvenetwork capacityVSAvoidsecurity of data transmission
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the security protection scope into two distinct parts: user plane data security protected end-to-end from UE to gateway node, and control plane signaling security protected from UE to serving access node. This segmentation allows each plane to have optimized security mechanisms appropriate to its requirements, enabling secure operation in ultra-dense networks with multiple air interfaces.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The gateway node acts as an intermediary that terminates the user plane security context and forwards data to the core network. By positioning the gateway node as the security termination point for user plane data, the system enables end-to-end security protection across multiple access nodes and air interfaces without requiring security contexts at each intermediate node.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If end-to-end security is implemented between UE and gateway node, then user plane security is improved, but control plane security delays increase

Engineering Contradiction:
Improveuser plane securityVSAvoidcontrol plane security delays
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent divides security processing into two separate segments: user plane security handled end-to-end between UE and gateway node, and control plane security handled locally between UE and serving access node. This segmentation eliminates control plane security processing delays by keeping control plane security local, while user plane security is handled independently in the data path without affecting control plane timing.

Inventive Principle:
Principle #1Segmentation

3Area of stationary object

If conventional cellular network architecture is used, then wide coverage is achieved, but indoor signal quality and data capacity deteriorate

Engineering Contradiction:
Improvecoverage areaVSAvoidindoor signal quality
Core Design Contradiction:
Area of stationary objectVSReliability

Solution Approach 1:

The patent segments the network into macro base stations providing wide area coverage and small radio access nodes providing localized high-capacity access points. This segmentation allows the system to simultaneously achieve both wide coverage through macro cells and high indoor signal quality through strategically placed small nodes that penetrate building structures.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a new spatial dimension by deploying small radio access nodes in three-dimensional space (indoor, rooftop, aerial) rather than relying solely on two-dimensional ground-based macro cell coverage. This dimensional expansion enables signal delivery to indoor environments through multiple paths and reduces dependency on macro cell penetration.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS10136325B2Method for implementing access stratum security, user equipment, and small radio access network node
Publication Date: 2018.11.20 ZTE CORP
  • US10136325B2 patent drawing
  • US10136325B2 patent drawing
  • US10136325B2 patent drawing

AI summary

A method for implementing access stratum security is provided. The method includes: performing end-to-end user plane access stratum security between a UE and a gateway node; and performing end-to-end control plane access stratum security between the UE and an initial access node when the UE only has a micro communication path; when the UE has the micro communication path and a macro communication path, performing end-to-end control plane access stratum security between the UE and a macro base station in the macro communication path. The micro communication path is a communication path in which the UE accesses a small radio access node via a radio access link and then accesses a core network finally. The macro communication path is a communication path in which the UE accesses the macro base station via the radio access link and then accesses the core network finally.