IAB User Plane Key Derivation for Secure IPsec Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The challenge of establishing a secure IPsec connection between the user plane entity of an IAB donor central unit and the distributed unit of an IAB node in an integrated access and backhaul network architecture with separation of control and user planes is not adequately addressed.
Innovation Solution
A method for establishing a user plane secure transmission channel between the donor-CU-UP and IAB-DU using a first key derived from a root key, with key determination methods involving various network entities to ensure secure communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If a root key is used for establishing secure transmission channels in IAB networks with control-plane/user-plane separation, then key management simplicity is improved, but authentication errors occur between donor-CU-UP and IAB-DU
Solution Approach 1:
The patent segments the single root key into two distinct keys: a control plane key (Kc) for donor-CU-CP to IAB-DU communication and a user plane key (Ku) for donor-CU-UP to IAB-DU communication. This segmentation resolves the authentication error by ensuring each plane uses the appropriate key, while maintaining relatively simple key management through centralized key derivation at the donor-CU-CP.
2Reliability
If IPsec secure connections are established between donor-CU-UP and IAB-DU, then transmission security is improved, but authentication failures occur due to key mismatch
Solution Approach 1:
The donor-CU-CP acts as an intermediary that derives and distributes the appropriate user plane key (Ku) to both the donor-CU-UP and IAB-DU. This intermediary function ensures that both endpoints have the correct matching key for IPsec authentication, resolving the authentication failure while maintaining secure transmission through standardized IPsec protocols.
3Adaptability or versatility
If control plane and user plane are separated in IAB donor central unit, then functional flexibility is improved, but secure channel establishment between user plane entities becomes complex
Solution Approach 1:
The user plane key (Ku) is derived and distributed in advance by the donor-CU-CP before user plane data transmission begins. This preliminary key preparation simplifies the subsequent secure channel establishment between donor-CU-UP and IAB-DU, allowing them to directly use the pre-configured key without complex real-time key negotiation, thus maintaining functional flexibility while reducing establishment complexity.
Data Source
AI summary
This application provides a key determining method, and a communication apparatus. The method is applied to a donor node central unit which contains a control plane entity and a user plane entity, and the method includes: deriving a first key based on a root key, an internet protocol (IP) address of a distributed unit of an integrated access and backhaul node, and a first IP address of the user plane entity; and sending a first message to the user plane entity, wherein the first message comprises the first key. According to this application, a user plane secure transmission channel may be established between the user plane entity and the distributed unit based on the first key.


