CU-UP Security Key Management in Separated gNB Architecture
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The separation of CU-CP and CU-UP in NR systems poses a security challenge for the CU-UP, as existing methods do not effectively manage user plane security key generation and encryption, leading to potential vulnerabilities in data packet processing.
Innovation Solution
A method where the CU-CP generates and transmits a user plane security key and encryption algorithm to the CU-UP, enabling the CU-UP to derive and apply an encryption key for secure data packet processing, with embodiments detailing different responsibilities and communication steps between the CU-CP and CU-UP for key management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the CU is divided into CU-CP and CU-UP to solve fronthaul problems and enable cloud RAN, then system flexibility and cloud integration are improved, but security management complexity and vulnerabilities increase
Solution Approach 1:
The patent segments the security key management functions by introducing a dedicated security key management entity that operates independently from both CU-CP and CU-UP. This segmentation allows the security functions to be centralized and properly managed while maintaining the functional separation benefits of cloud RAN architecture.
Solution Approach 2:
The patent introduces a security key management entity as an intermediary between CU-CP and CU-UP. This intermediary receives security parameters from CU-CP, generates appropriate security keys, and provides them to CU-UP, thereby resolving the security management challenges created by the functional separation.
2Reliability
If security key management is centralized in CU-CP, then security control is improved, but key transmission security and vulnerability to interception increase
Solution Approach 1:
The security key management entity acts as a secure intermediary that receives security parameters from CU-CP and generates actual security keys. This intermediary layer prevents direct exposure of security keys over the air interface, reducing interception vulnerability while maintaining centralized security control.
Solution Approach 2:
Instead of transmitting actual security keys directly from CU-CP to CU-UP, the system transmits security parameters that are then used to generate the actual keys. This copying approach maintains security control while eliminating the security risk of direct key transmission.
3Device complexity
If security parameters are transmitted directly from CU-CP to CU-UP, then key management simplicity is improved, but security vulnerability increases
Solution Approach 1:
The patent introduces a security key management entity as an intermediary between CU-CP and CU-UP. This intermediary receives security parameters from CU-CP, generates appropriate security keys, and provides them to CU-UP, thereby resolving the security management challenges created by the functional separation.
Solution Approach 2:
Instead of transmitting actual security keys directly from CU-CP to CU-UP, the system transmits security parameters that are then used to generate the actual keys. This copying approach maintains security control while eliminating the security risk of direct key transmission.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Provided are a method and an apparatus for supporting security of user traffic when a central unit (CU)-control plane (CP) and a CU-user plane (UP) of a gNB are separated in a wireless communication system. According to an embodiment of the present invention, the CU-CP of the gNB selects an encryption algorithm, generates a user plane security key for the CU-UP on the basis of the encryption algorithm, and transmits the user plane security key for the CU-UP to the CU-CP. The CU-UP applies the received user plane security key. The CU-CP is a logical node constituting the gNB that hosts a radio resource control (RRC) and a packet data convergence protocol (PDCP)-C protocol, and the CU-UP is a logical node constituting the gNB that hosts a PDCP-U protocol.