Key Generation for Separated CU-UP Base Stations

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In future network architectures where a base station is divided into a centralized unit and a distributed unit, with the centralized unit further divided into a control plane entity and a user plane entity, the existing key architecture poses a security risk as different CU-UP entities share the same key.

Innovation Solution

A method for generating different user plane security keys for each user plane entity, where the control plane entity or user plane entity generates security keys based on a root key, identifiers, security algorithms, and other parameters to implement key isolation between user plane entities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the existing key architecture is used in future network with multiple CU-UP entities, then the system complexity is reduced and ease of operation is improved, but security reliability deteriorates due to shared keys

Engineering Contradiction:
Improveease of operationVSAvoidsecurity reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the security key management by deriving separate user plane security keys (Kupenc, Kupint) for each CU-UP entity from a common base key (KeNB). This segmentation ensures that each CU-UP entity has its own dedicated security key, preventing security risks associated with shared keys while maintaining manageable system complexity through automated key derivation.

Inventive Principle:
Principle #1Segmentation

2Reliability

If separate security keys are generated for each CU-UP entity, then security reliability is improved, but device complexity and key management complexity increase

Engineering Contradiction:
Improvesecurity reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-establishing the base key (KeNB) through authentication procedures before the network is operational. This base key is then used to derive all subsequent user plane security keys for different CU-UP entities, eliminating the need for separate key distribution procedures and reducing operational complexity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The base key (KeNB) serves as an intermediary that bridges the authentication system and multiple CU-UP entities. Instead of directly managing separate keys for each entity, the system uses KeNB as a mediator to derive all necessary security keys, simplifying the overall key management architecture while ensuring security isolation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11533610B2Key generation method and related apparatus
Publication Date: 2022.12.20 HUAWEI TECH CO LTD
  • US11533610B2 patent drawing
  • US11533610B2 patent drawing
  • US11533610B2 patent drawing

AI summary

Embodiments of this application provide a key generation method, applied to a scenario in which a base station is divided into a centralized unit and a distributed unit and a control plane and a user plane of the centralized unit are separated. And the control plane entity of the centralized unit obtains a root key, generates a user plane security key based on the root key, and sends the first user plane security key to the user plane entity of the first centralized unit. According to this application, key isolation between different user plane entities is implemented. Further, in an actual operation, the control plane entity or the user plane entity of the centralized unit may be flexibly selected to generate the user plane security key.