CU-UP Security Key Management in Separated gNB Architecture

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The separation of CU-CP and CU-UP in NR systems poses a security challenge for the CU-UP, as existing methods do not effectively manage user plane security key generation and encryption, leading to potential vulnerabilities in data packet processing.

Innovation Solution

A method where the CU-CP generates and transmits a user plane security key and encryption algorithm to the CU-UP, enabling the CU-UP to derive and apply an encryption key for secure data packet processing, with embodiments detailing different responsibilities and communication steps between the CU-CP and CU-UP for key management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the CU is divided into CU-CP and CU-UP to solve fronthaul problems and enable cloud RAN, then system flexibility and cloud integration are improved, but security management complexity and vulnerabilities increase

Engineering Contradiction:
Improvecloud RAN integrationVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the security key management functions by introducing a dedicated security key management entity that operates independently from both CU-CP and CU-UP. This segmentation allows the security functions to be centralized and properly managed while maintaining the functional separation benefits of cloud RAN architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a security key management entity as an intermediary between CU-CP and CU-UP. This intermediary receives security parameters from CU-CP, generates appropriate security keys, and provides them to CU-UP, thereby resolving the security management challenges created by the functional separation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security key management is centralized in CU-CP, then security control is improved, but key transmission security and vulnerability to interception increase

Engineering Contradiction:
Improvesecurity controlVSAvoidkey interception vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The security key management entity acts as a secure intermediary that receives security parameters from CU-CP and generates actual security keys. This intermediary layer prevents direct exposure of security keys over the air interface, reducing interception vulnerability while maintaining centralized security control.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Instead of transmitting actual security keys directly from CU-CP to CU-UP, the system transmits security parameters that are then used to generate the actual keys. This copying approach maintains security control while eliminating the security risk of direct key transmission.

Inventive Principle:
Principle #26Copying

3Device complexity

If security parameters are transmitted directly from CU-CP to CU-UP, then key management simplicity is improved, but security vulnerability increases

Engineering Contradiction:
Improvekey management structureVSAvoidsecurity vulnerability
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a security key management entity as an intermediary between CU-CP and CU-UP. This intermediary receives security parameters from CU-CP, generates appropriate security keys, and provides them to CU-UP, thereby resolving the security management challenges created by the functional separation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Instead of transmitting actual security keys directly from CU-CP to CU-UP, the system transmits security parameters that are then used to generate the actual keys. This copying approach maintains security control while eliminating the security risk of direct key transmission.

Inventive Principle:
Principle #26Copying

Data Source

PatentEP3570577B1Method and apparatus for supporting security for separation of CU-CP and CU-up in wireless communication system
Publication Date: 2021.04.07 LG ELECTRONICS INC
  • EP3570577B1 patent drawingFigure 1
  • EP3570577B1 patent drawingFigure 2
  • EP3570577B1 patent drawingFigure 3

AI summary

Provided are a method and an apparatus for supporting security of user traffic when a central unit (CU)-control plane (CP) and a CU-user plane (UP) of a gNB are separated in a wireless communication system. According to an embodiment of the present invention, the CU-CP of the gNB selects an encryption algorithm, generates a user plane security key for the CU-UP on the basis of the encryption algorithm, and transmits the user plane security key for the CU-UP to the CU-CP. The CU-UP applies the received user plane security key. The CU-CP is a logical node constituting the gNB that hosts a radio resource control (RRC) and a packet data convergence protocol (PDCP)-C protocol, and the CU-UP is a logical node constituting the gNB that hosts a PDCP-U protocol.