Disaggregated Base Station Security Contexts Across Multiple Domains
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In 5G communication systems with disaggregated base stations, managing security keys across multiple security domains is challenging due to the need for different encryption and integrity keys for various applications with varying quality-of-service and latency requirements, which can compromise privacy and security if the same keys are used across domains.
Innovation Solution
Implement a new security framework that generates distinct UP encryption and integrity keys for each security domain within a disaggregated base station by using a 'security domain counter' parameter to derive fresh keys, ensuring secure communication across different CU-UP instances.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If the same security keys are used across multiple security domains, then device complexity is reduced, but security and privacy are compromised
Solution Approach 1:
The patent divides the security key management into separate domains by introducing a security domain counter that identifies different security domains (e.g., first security domain for enhanced mobile broadband, second security domain for mission-critical services). Each domain receives distinct encryption and integrity keys derived from the base key combined with the domain counter, ensuring that keys are segmented and isolated across different service domains.
Solution Approach 2:
The patent applies local quality by providing different security key characteristics for different security domains. Each security domain receives keys tailored to its specific requirements (e.g., different integrity protection levels, different encryption strengths), allowing the security system to optimize key properties locally for each domain rather than using a uniform key approach across all domains.
2Reliability
If distinct security keys are generated for each security domain, then security and privacy are improved, but device complexity increases
Solution Approach 1:
The patent implements preliminary action by pre-defining the security domain counter and the key derivation methodology before actual security operations begin. The base key is established once, and the system is pre-configured to derive domain-specific keys by combining this base key with different counter values, eliminating the need for complex real-time key generation and reducing operational complexity during security operations.
Solution Approach 2:
The patent uses parameter changes by modifying a single parameter (the security domain counter value) to generate different security keys from the same base key. Instead of managing entirely separate key sets, the system changes the domain counter parameter to derive appropriate keys for each domain, significantly reducing the complexity of key management while maintaining distinct security properties across domains.
3Ease of operation
If a single security context is used for all applications, then ease of operation is improved, but adaptability to different quality-of-service requirements deteriorates
Solution Approach 1:
The patent implements universality by creating a multi-functional security context system where a single base key can serve multiple security domains through the domain counter mechanism. The same base key derivation process works universally across different domains (eMBB, URLLC, mMTC), providing ease of operation through a unified approach while adapting to different quality-of-service requirements through domain-specific key instances.
Solution Approach 2:
The patent applies dynamics by making the security context adaptable and flexible through the security domain counter. The system can dynamically select which domain counter value to use based on the specific application requirements, allowing the security context to change and adapt to different quality-of-service needs without requiring completely separate key management systems for each application type.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A reconfiguration message is received at user equipment in a communication system from a disaggregated base station with which the user equipment has a current security context established. The reconfiguration message comprises an instruction to compute a new security context based on a security domain counter value, wherein the security domain counter value represents a given security domain from a plurality of security domains supported by the disaggregated base station. The new security context is computed at the user equipment for the given security domain based on the security domain counter value. A set of security keys are derived from the new security context at the user equipment.