DRB Configuration for S1AP/X2AP Signaling Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In the LTE-Advanced scheme, relay nodes and radio base stations face challenges in identifying the Data Radio Bearer (DRB) that requires integrity protection for S1AP/X2AP layer signaling, leading to inadequate security in the Un radio space without Network Domain Security (NDS)/IP.
Innovation Solution
The method involves setting and notifying the Data Radio Bearer during the attach process of the relay node, ensuring that the DRB for S1AP/X2AP layer signaling is explicitly identified and protected, with notifications exchanged between the relay node and the radio base station to determine which bearers require integrity protection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If integrity protection is performed for all DRBs in the Un radio space, then security for S1AP/X2AP layer signaling is strengthened, but device complexity increases and unnecessary processing is applied to bearers that do not require protection
Solution Approach 1:
The invention applies preliminary action by setting and notifying the DRB configuration during the attach process of the relay node, before actual data transmission begins. The radio base station determines which DRBs require integrity protection and notifies both the relay node and itself of this configuration in advance, allowing the system to prepare security parameters before they are needed, thus avoiding complex real-time identification during data transmission
Solution Approach 2:
The invention uses the attach process as an intermediary mechanism to establish the DRB configuration for integrity protection. During this intermediate phase between relay node connection and full data transmission, the system exchanges and stores the necessary configuration information, serving as a mediator that resolves the complexity of direct real-time identification by pre-establishing the protection scope
2Device complexity
If integrity protection is not performed, then device complexity is reduced, but security for S1AP/X2AP layer signaling becomes insufficient
Solution Approach 1:
The invention applies local quality by providing integrity protection only to specific DRBs that require it, rather than uniformly protecting all bearers. The radio base station determines on a per-bearer basis which DRBs need integrity protection and configures this selectively, allowing the system to maintain simplicity for bearers that don't require protection while ensuring security for those that do
Solution Approach 2:
The invention uses parameter changes by modifying the DRB configuration parameters during the attach process to indicate which bearers require integrity protection. The system changes the state of the DRB from unprotected to protected based on the S1AP/X2AP layer signaling requirements, allowing dynamic adaptation of security parameters without complex ongoing management
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The present invention relates to a mobile communication method that sends and receives the signaling of an S1AP/X2AP layer on DRB established between a radio base station DeNB and a relay node RN, the mobile communication method including: a step of setting the above DBR in an attach process of the relay node RN; and a step of notifying the above DRB to the relay node RN and the radio base station DeNB in an attach process of the relay node RN.