CU-DU Access Control for 5G Closed Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In the 5G architecture with separated CU and DU, there is a challenge in ensuring that users belonging to a closed access group (CAG) or a standalone non-public network (SNPN) can access the corresponding CAG cell or SNPN cell while preventing unauthorized access.
Innovation Solution
A method is proposed that involves a series of message exchanges and decision rules between the UE, base stations, and the core network to determine and enforce access permissions to CAG cells and SNPN cells, ensuring that only authorized users can access these closed networks during network access, handover, and RRC reestablishment processes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the base station is divided into separated CU and DU with centralized deployment, then network performance and user experience are improved, but access control complexity and security management difficulty increase
Solution Approach 1:
The base station is segmented into CU and DU with distinct functional responsibilities. The CU handles high-layer protocols (RRC, PDCP) and access control decisions, while the DU handles physical layer functions. This segmentation allows centralized deployment of control functions while maintaining distributed radio access, resolving the contradiction between improved network performance and increased access control complexity.
Solution Approach 2:
The F1 interface acts as an intermediary between CU and DU, enabling standardized communication and control. This intermediary mechanism allows the CU to enforce access control policies on the DU without direct complex interactions, simplifying security management while maintaining the benefits of separation.
2Reliability
If closed access group (CAG) and standalone non-public network (SNPN) support is added to the separated CU-DU architecture, then network security and access control capabilities are improved, but system complexity and implementation difficulty increase
Solution Approach 1:
The CU is designed to handle multiple access control scenarios (CAG, SNPN, public network access) through a unified RRC connection management framework. This multi-functional design allows the system to support diverse network types without proportionally increasing complexity, as the same CU infrastructure serves multiple security and access control purposes.
Solution Approach 2:
Access control parameters and security policies are pre-configured in the CU before UE connection attempts. The CU maintains pre-established rules for CAG membership verification and SNPN authorization, enabling rapid access decisions without real-time complex computations, thus improving security while managing system complexity.
3Reliability
If strict access control mechanisms are implemented for CAG and SNPN cells, then unauthorized access prevention is improved, but legitimate user access delay and connection establishment time increase
Solution Approach 1:
The CU pre-loads and caches access control lists, CAG membership information, and SNPN authorization data before access requests arrive. When a UE attempts to connect, the CU performs rapid lookups in these pre-prepared data structures rather than performing complex real-time verification, significantly reducing access delay while maintaining strict security controls.
Solution Approach 2:
The system implements feedback mechanisms where successful access patterns are learned and cached for future rapid processing. The CU tracks and memorizes authorized UE-CAG and UE-SNPN associations, enabling subsequent access decisions to be made faster while maintaining the same security rigor.
Data Source
AI summary
A method for supporting non-public network (NPN), by a first central unit (CU) of a first base station, in a wireless communication system, the method comprising: receiving, from a first distributed unit (DU) of the first base station, an F1 setup request comprising at least one of a first closed access network (CAG) identifier list or a first network identifier (NID) list, transmitting, to an access and mobility management function (AMF), an NG setup request comprising at least one of the first CAG identifier list or the first NID list, receiving, from the AMF, an NG setup response, and transmitting, to the first DU, an F1 setup response.


