IAB User Plane Key Derivation for Secure IPsec Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The challenge of establishing a secure IPsec connection between the user plane entity of an IAB donor central unit and the distributed unit of an IAB node in an integrated access and backhaul network architecture with separation of control and user planes is not adequately addressed.

Innovation Solution

A method for establishing a user plane secure transmission channel between the donor-CU-UP and IAB-DU using a first key derived from a root key, with key determination methods involving various network entities to ensure secure communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a root key is used for establishing secure transmission channels in IAB networks with control-plane/user-plane separation, then key management simplicity is improved, but authentication errors occur between donor-CU-UP and IAB-DU

Engineering Contradiction:
Improvekey management complexityVSAvoidauthentication reliability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the single root key into two distinct keys: a control plane key (Kc) for donor-CU-CP to IAB-DU communication and a user plane key (Ku) for donor-CU-UP to IAB-DU communication. This segmentation resolves the authentication error by ensuring each plane uses the appropriate key, while maintaining relatively simple key management through centralized key derivation at the donor-CU-CP.

Inventive Principle:
Principle #1Segmentation

2Reliability

If IPsec secure connections are established between donor-CU-UP and IAB-DU, then transmission security is improved, but authentication failures occur due to key mismatch

Engineering Contradiction:
Improvetransmission securityVSAvoidauthentication success
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The donor-CU-CP acts as an intermediary that derives and distributes the appropriate user plane key (Ku) to both the donor-CU-UP and IAB-DU. This intermediary function ensures that both endpoints have the correct matching key for IPsec authentication, resolving the authentication failure while maintaining secure transmission through standardized IPsec protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If control plane and user plane are separated in IAB donor central unit, then functional flexibility is improved, but secure channel establishment between user plane entities becomes complex

Engineering Contradiction:
Improvefunctional flexibilityVSAvoidsecure channel establishment complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The user plane key (Ku) is derived and distributed in advance by the donor-CU-CP before user plane data transmission begins. This preliminary key preparation simplifies the subsequent secure channel establishment between donor-CU-UP and IAB-DU, allowing them to directly use the pre-configured key without complex real-time key negotiation, thus maintaining functional flexibility while reducing establishment complexity.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12568360B2Method for establishing secure transmission channel, key determining method, and communication apparatus
Publication Date: 2026.03.03 HUAWEI TECH CO LTD
  • US12568360B2 patent drawing
  • US12568360B2 patent drawing
  • US12568360B2 patent drawing

AI summary

This application provides a key determining method, and a communication apparatus. The method is applied to a donor node central unit which contains a control plane entity and a user plane entity, and the method includes: deriving a first key based on a root key, an internet protocol (IP) address of a distributed unit of an integrated access and backhaul node, and a first IP address of the user plane entity; and sending a first message to the user plane entity, wherein the first message comprises the first key. According to this application, a user plane secure transmission channel may be established between the user plane entity and the distributed unit based on the first key.