Key Generation for Separated CU-UP Base Stations
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In future network architectures where a base station is divided into a centralized unit and a distributed unit, with the centralized unit further divided into a control plane entity and a user plane entity, the existing key architecture poses a security risk as different CU-UP entities share the same key.
Innovation Solution
A method for generating different user plane security keys for each user plane entity, where the control plane entity or user plane entity generates security keys based on a root key, identifiers, security algorithms, and other parameters to implement key isolation between user plane entities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the existing key architecture is used in future network with multiple CU-UP entities, then the system complexity is reduced and ease of operation is improved, but security reliability deteriorates due to shared keys
Solution Approach 1:
The patent segments the security key management by deriving separate user plane security keys (Kupenc, Kupint) for each CU-UP entity from a common base key (KeNB). This segmentation ensures that each CU-UP entity has its own dedicated security key, preventing security risks associated with shared keys while maintaining manageable system complexity through automated key derivation.
2Reliability
If separate security keys are generated for each CU-UP entity, then security reliability is improved, but device complexity and key management complexity increase
Solution Approach 1:
The patent applies preliminary action by pre-establishing the base key (KeNB) through authentication procedures before the network is operational. This base key is then used to derive all subsequent user plane security keys for different CU-UP entities, eliminating the need for separate key distribution procedures and reducing operational complexity.
Solution Approach 2:
The base key (KeNB) serves as an intermediary that bridges the authentication system and multiple CU-UP entities. Instead of directly managing separate keys for each entity, the system uses KeNB as a mediator to derive all necessary security keys, simplifying the overall key management architecture while ensuring security isolation.
Data Source
AI summary
Embodiments of this application provide a key generation method, applied to a scenario in which a base station is divided into a centralized unit and a distributed unit and a control plane and a user plane of the centralized unit are separated. And the control plane entity of the centralized unit obtains a root key, generates a user plane security key based on the root key, and sends the first user plane security key to the user plane entity of the first centralized unit. According to this application, key isolation between different user plane entities is implemented. Further, in an actual operation, the control plane entity or the user plane entity of the centralized unit may be flexibly selected to generate the user plane security key.


