H(e)NB Secure Data Transmission via IPsec and TLS Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Insecure data transmission between Home Node-B (HNB) and Home Node-B Management System (HMS) or Home evolved Node-B (HeNB) and HeNB Management System (HeMS) poses threats due to lack of verification of configuration data and software updates, leading to potential deceptive software updates and attacks.

Innovation Solution

Implementing a secure data transmission method using IPsec and TLS tunnels to verify the integrity and confidentiality of data between HNB/HNB and HMS or HeNB/HeMS, discarding or retaining data if verification fails, and reporting errors to relevant network elements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If data is transmitted between HNB and HMS or HeNB and HeMS via broadband IP backhaul, then connectivity and accessibility are improved, but security and reliability deteriorate due to lack of verification

Engineering Contradiction:
ImproveconnectivityVSAvoiddata security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies preliminary action by establishing secure channels and verification mechanisms before data transmission occurs. The system performs mutual authentication between HNB and HMS/HeNB-HeMS before allowing data exchange, and verifies data integrity before processing, thereby preventing security breaches while maintaining connectivity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary security verification mechanism between the HNB/H(e)NB and HMS/HeMS. This intermediary layer includes authentication modules and data verification components that mediate all data transmissions, ensuring security without disrupting the existing broadband IP backhaul connectivity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If configuration data and software updates are downloaded without authentication, then ease of operation is improved, but harmful factors increase due to deceptive updates and attacks

Engineering Contradiction:
Improvedata downloadingVSAvoidsoftware attack
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary authentication and integrity verification before allowing configuration data and software updates to be downloaded and installed. The system verifies digital signatures and authentication tokens prior to data reception, preventing deceptive software updates while maintaining simple download operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent converts the potential harm of unverified data downloads into a benefit by implementing automatic verification mechanisms that detect and block malicious data while allowing legitimate updates to pass through seamlessly, thus protecting against attacks without complicating the update process.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

3Reliability

If data verification is implemented, then security is improved, but device complexity increases due to additional verification mechanisms

Engineering Contradiction:
Improvedata integrityVSAvoidverification system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by designing verification mechanisms that serve multiple functions: authentication, integrity checking, and security verification are integrated into existing HNB and HMS/HeNB-HeMS components. The same verification framework handles different data types (configuration data, software updates, signaling messages), reducing overall system complexity despite enhanced security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8606228B2Method, user network equipment and management system thereof for secure data transmission
Publication Date: 2013.12.10 ZTE CORP
  • US8606228B2 patent drawing
  • US8606228B2 patent drawing
  • US8606228B2 patent drawing

AI summary

A method for secure data transmission, and the method includes: after a Home (evolved) Node-B (H(e)NB) establishes a connection with a H(e)NB Management System (H(e)MS), data is transmitted between the H(e)NB and the H(e)MS via a secure path; when the H(e)NB or the H(e)MS receives data, verify the integrity and/or the confidentiality of said received data, and if the verification fails, retain or discard said received data. The present invention also provides user network equipment and a user network equipment management system for secure data transmission. The present invention removes various threats caused by the insecure data transmission and a variety of inconveniences caused by improperly handling downloaded data of the H(e)NB in practical applications.