Air Interface Security Mechanism for Relay Node Key Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The introduction of a relay node in LTE systems creates significant hidden security risks in air interface links, making the data transmitted vulnerable to attacks due to compromised key management and security associations.

Innovation Solution

A method and device for establishing a security mechanism that involves performing security processing on shared keys between a relay node and a mobility management entity, enabling the relay node to obtain and derive security keys for both the user plane and control plane, while ensuring the same security keys are used for communication between the user equipment and the relay node and between the user equipment and the eNodeB.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a relay node is introduced to segment the air interface link, then network coverage and service diversity are improved, but security risks increase due to vulnerable data transmission and compromised key management

Engineering Contradiction:
Improvenetwork coverageVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The air interface link is segmented into an access link between UE and RN, and a relay link between RN and eNB. Each segment has independent security association establishment, allowing security to be maintained at each hop while enabling network coverage extension through the relay node

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The relay node acts as an intermediary that establishes separate security associations with both the UE and the eNB. It derives keys from a shared key received from the eNB and uses these derived keys to secure communications with the UE, thereby mediating security across the segmented link

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If centralized security control is used with direct security association between UE and eNB, then key management is simplified, but the relay node cannot participate in security association establishment

Engineering Contradiction:
Improvekey managementVSAvoidrelay node participation
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The security control mechanism dynamically adapts to the presence of a relay node. When an RN is detected, the system transitions from direct centralized security association to distributed security association where the RN participates in key derivation and security key management for both access and relay links

Inventive Principle:
Principle #15Dynamics

3Reliability

If distributed security control is used with relay node participation, then security coverage is extended, but key derivation and distribution processes become more complex

Engineering Contradiction:
Improvesecurity coverageVSAvoidkey derivation process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The eNB performs preliminary key derivation by deriving a first security key from the shared key before transmitting it to the RN. This preliminary action prepares the security infrastructure in advance, allowing the RN to subsequently derive access link security keys without requiring complex real-time key negotiation with the UE

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The relay node receives a copy of the shared key from the eNB and uses this copy to derive security keys for the access link. This copying mechanism allows the RN to participate in security association establishment while maintaining key management simplicity, as the RN replicates the key derivation process using the received shared key

Inventive Principle:
Principle #26Copying

Data Source

PatentUS9060270B2Method and device for establishing a security mechanism for an air interface link
Publication Date: 2015.06.16 HUAWEI TECH CO LTD
  • US9060270B2 patent drawing
  • US9060270B2 patent drawing
  • US9060270B2 patent drawing

AI summary

A method, a device, and a system for establishing a security mechanism for an air interface are provided in embodiments of the present invention. The method includes: performing security processing for a shared key of an access link according to a shared key between a relay node and a mobility management entity; and sending the shared key of the access link after the security processing to the relay node to enable the relay node to obtain the shared key of the access link based on the shared key between the relay node and the mobility management entity. The present invention reduces the possibility at which the air interface link is hacked, thereby improving the security of the air interface link.