gNB-CU-CP Security Configuration Selection for 5G Bearer Contexts
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In 5G wireless communication systems, the gNB-CU-UP entity does not support all ROHC profiles and ciphering/integrity algorithms, leading to issues when the gNB-CU-CP attempts to configure security configurations not supported by the gNB-CU-UP, potentially causing bearer context setup failures.
Innovation Solution
The gNB-CU-CP method involves obtaining information on supported security configurations from the gNB-CU-UP, selecting appropriate configurations or alternative gNB-CU-UPs that support the required algorithms/profiles, and configuring bearer contexts accordingly, ensuring compatibility and successful setup.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the gNB-CU-CP configures security configurations (ciphering/integrity algorithms, ROHC profiles) for bearer contexts, then the security protection and header compression are improved, but the system reliability deteriorates when the gNB-CU-UP does not support the configured algorithms
Solution Approach 1:
The gNB-CU-CP performs preliminary actions by obtaining capability information from the gNB-CU-UP before configuring bearer contexts. The CU-CP queries the CU-UP about supported ciphering algorithms, integrity protection algorithms, and ROHC profiles in advance, stores this capability information, and uses it to pre-select compatible security configurations before actual bearer setup, preventing configuration failures.
Solution Approach 2:
The system implements feedback mechanisms where the gNB-CU-UP provides capability information about supported security algorithms and ROHC profiles back to the gNB-CU-CP. The CU-CP uses this feedback to adjust its security configuration selections, ensuring that only supported algorithms are configured for bearer contexts, thereby maintaining reliability.
2Productivity
If the gNB-CU-CP selects security configurations without checking gNB-CU-UP support, then the configuration process is simplified and faster, but bearer context setup failures occur due to algorithm incompatibility
Solution Approach 1:
The gNB-CU-CP performs preliminary actions by obtaining capability information from the gNB-CU-UP before configuring bearer contexts. The CU-CP queries the CU-UP about supported ciphering algorithms, integrity protection algorithms, and ROHC profiles in advance, stores this capability information, and uses it to pre-select compatible security configurations before actual bearer setup, preventing configuration failures.
Solution Approach 2:
The system implements feedback mechanisms where the gNB-CU-UP provides capability information about supported security algorithms and ROHC profiles back to the gNB-CU-CP. The CU-CP uses this feedback to adjust its security configuration selections, ensuring that only supported algorithms are configured for bearer contexts, thereby maintaining reliability.
3Adaptability or versatility
If the gNB-CU-UP supports all possible ROHC profiles and security algorithms, then the adaptability and versatility are improved, but the device complexity and resource requirements increase
Solution Approach 1:
The gNB-CU-CP performs the universal function of selecting appropriate security configurations by maintaining a comprehensive view of both UE capabilities and CU-UP capabilities. Instead of requiring the CU-UP to support all algorithms universally, the CU-CP acts as the intelligent selector that matches UE requirements with CU-UP capabilities, achieving multi-functionality through the CP's coordination role.
Solution Approach 2:
The system dynamically changes the parameter of security algorithm selection based on the specific capability parameters of the CU-UP and UE. Rather than fixed support for all algorithms, the system adapts the selected algorithm parameters to match the actual capabilities of the involved entities, optimizing the balance between versatility and complexity.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A communication system is disclosed in which a distributed base station apparatus comprises a central unit for control plane signalling (CU-CP), at least one a central unit for user plane signalling (CU-UP), and at least one distributed unit. The CU-CP obtains information indicating whether a security configuration is supported by a CU-UP and selects a security configuration for an item of user equipment (UE) based on the obtained information.