Ciphering Key Forwarding for UMTS RRC Deciphering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In UMTS networks, encrypted Radio Resource Control (RRC) packets cannot be analyzed due to the unavailability of Ciphering Keys (CK) on the same interfaces as the packets, and network monitoring equipment is often distributed, making it difficult to forward CKs to deciphering applications in a timely manner.

Innovation Solution

A system and method for capturing CKs from UMTS networks and forwarding them to deciphering applications, involving the identification of network nodes and monitors, and establishing communication links between monitors to ensure CKs are delivered to the appropriate deciphering applications, even if they are located separately, using IuCS, IuPS, Iub, and Iur interfaces.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Area of stationary object

If network monitoring equipment is distributed to monitor different parts of the UMTS network, then the monitoring coverage is improved, but the difficulty of forwarding ciphering keys between monitors increases

Engineering Contradiction:
Improvemonitoring coverageVSAvoidkey forwarding complexity
Core Design Contradiction:
Area of stationary objectVSDevice complexity

Solution Approach 1:

The patent introduces a key forwarding mechanism that acts as an intermediary between monitors capturing ciphering keys and monitors requiring them for decryption. The system identifies the responsible monitor for each network node and establishes communication links to forward keys across distributed monitoring equipment, resolving the complexity of key distribution in a distributed monitoring architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The monitoring system implements a universal key forwarding framework that can operate across any distributed monitor configuration. The system identifies network nodes, determines responsible monitors, and establishes communication paths dynamically, making the key forwarding mechanism adaptable to various distributed monitoring topologies without requiring dedicated key distribution infrastructure for each monitor pair.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If ciphering keys are captured from core network interfaces, then the key availability for decryption is improved, but the difficulty of delivering keys to the correct monitor increases

Engineering Contradiction:
Improvekey availabilityVSAvoidkey delivery difficulty
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The system implements a feedback mechanism where the monitor capturing the ciphering key identifies the network node and determines which monitor is responsible for processing messages from that node. This feedback loop ensures the key is forwarded to the correct monitor that has the corresponding encrypted messages, preventing key delivery errors in distributed monitoring environments.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent establishes communication links between monitors in advance, before ciphering keys need to be forwarded. The system pre-identifies responsible monitors for each network node and sets up the key forwarding infrastructure proactively, so when a key is captured, the delivery path is already established, reducing delivery difficulty and latency.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If monitors are located separately to monitor different interfaces, then the monitoring flexibility is improved, but the timeliness of key delivery to deciphering applications deteriorates

Engineering Contradiction:
Improvemonitoring flexibilityVSAvoidkey delivery time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system establishes continuous communication links between monitors that capture ciphering keys and monitors that require them for decryption. Once a communication path is established, the key forwarding operates continuously and efficiently, minimizing delivery time while maintaining the flexibility of distributed monitor locations. The system ensures keys are forwarded as soon as they are captured, maintaining continuous decryption capability.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS8254573B2System and method for ciphering key forwarding and RRC packet deciphering in a UMTS monitoring system
Publication Date: 2012.08.28 NETSCOUT SYSTEMS TEXAS LLC
  • US8254573B2 patent drawing
  • US8254573B2 patent drawing
  • US8254573B2 patent drawing

AI summary

System and method for forwarding a ciphering key to a decipher application comprising capturing a first message carrying the ciphering key from a first network interface, identifying a network node associated with the first network interface, identifying a monitor responsible for processing messages captured from interfaces coupled to the network node, and forwarding the ciphering key to the monitor. In an alternative embodiment, the method may further comprise capturing second messages carrying encrypted messages from a second network interface, and deciphering the second messages using the ciphering key. The method may also comprise identifying user equipment associated with the first messages, and selecting a deciphering application running on the monitor using a user equipment identity.