Air Interface Security Mechanism for Relay Node Key Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The introduction of a relay node in LTE systems creates significant hidden security risks in air interface links, making the data transmitted vulnerable to attacks due to compromised key management and security associations.
Innovation Solution
A method and device for establishing a security mechanism that involves performing security processing on shared keys between a relay node and a mobility management entity, enabling the relay node to obtain and derive security keys for both the user plane and control plane, while ensuring the same security keys are used for communication between the user equipment and the relay node and between the user equipment and the eNodeB.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a relay node is introduced to segment the air interface link, then network coverage and service diversity are improved, but security risks increase due to vulnerable data transmission and compromised key management
Solution Approach 1:
The air interface link is segmented into an access link between UE and RN, and a relay link between RN and eNB. Each segment has independent security association establishment, allowing security to be maintained at each hop while enabling network coverage extension through the relay node
Solution Approach 2:
The relay node acts as an intermediary that establishes separate security associations with both the UE and the eNB. It derives keys from a shared key received from the eNB and uses these derived keys to secure communications with the UE, thereby mediating security across the segmented link
2Device complexity
If centralized security control is used with direct security association between UE and eNB, then key management is simplified, but the relay node cannot participate in security association establishment
Solution Approach 1:
The security control mechanism dynamically adapts to the presence of a relay node. When an RN is detected, the system transitions from direct centralized security association to distributed security association where the RN participates in key derivation and security key management for both access and relay links
3Reliability
If distributed security control is used with relay node participation, then security coverage is extended, but key derivation and distribution processes become more complex
Solution Approach 1:
The eNB performs preliminary key derivation by deriving a first security key from the shared key before transmitting it to the RN. This preliminary action prepares the security infrastructure in advance, allowing the RN to subsequently derive access link security keys without requiring complex real-time key negotiation with the UE
Solution Approach 2:
The relay node receives a copy of the shared key from the eNB and uses this copy to derive security keys for the access link. This copying mechanism allows the RN to participate in security association establishment while maintaining key management simplicity, as the RN replicates the key derivation process using the received shared key
Data Source
AI summary
A method, a device, and a system for establishing a security mechanism for an air interface are provided in embodiments of the present invention. The method includes: performing security processing for a shared key of an access link according to a shared key between a relay node and a mobility management entity; and sending the shared key of the access link after the security processing to the relay node to enable the relay node to obtain the shared key of the access link based on the shared key between the relay node and the mobility management entity. The present invention reduces the possibility at which the air interface link is hacked, thereby improving the security of the air interface link.


