Security Context Establishment for LTE User Plane Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In the LTE Hi architecture, user plane data transmitted over the Uu' interface lacks security protection, posing a security risk for user equipment (UE) data.

Innovation Solution

A method is implemented to establish a security context by acquiring and negotiating encryption algorithms and keys between the access node and the UE, enabling downlink encryption and uplink decryption, ensuring comprehensive security protection for user plane data transmitted over the Uu' interface.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security protection is enabled on the PCC interface, then security protection for control plane data is improved, but security protection for user plane data on the SCC interface deteriorates (remains unprotected)

Engineering Contradiction:
Improvesecurity protectionVSAvoidcomprehensive security coverage
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the security protection mechanism by introducing separate encryption keys for control plane data (K_RRCenc) and user plane data (K_UPenc). This allows independent security configuration for different data types and interfaces, enabling comprehensive security coverage across both PCC and SCC interfaces while maintaining the ability to adapt security settings to specific requirements.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different security qualities to different interfaces and data types. Specifically, it enables security protection on the SCC interface by deriving and applying K_UPenc for user plane data encryption, while maintaining K_RRCenc for control plane data. This local quality approach ensures that each interface receives appropriate security protection tailored to its specific needs, resolving the contradiction between partial and comprehensive security coverage.

Inventive Principle:
Principle #3Local quality

2Reliability

If encryption keys are derived and applied for SCC interface, then security protection for user plane data is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity protectionVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent performs preliminary action by deriving both K_RRCenc and K_UPenc from the root key K_eNB during the initial security context setup phase, before actual data transmission begins. This preliminary key derivation ensures that when data needs to be transmitted on the SCC interface, the appropriate encryption keys are already available, eliminating the need for complex real-time key generation and management during data transmission.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses a universal root key K_eNB that serves multiple functions: it is used to derive both control plane encryption keys (K_RRCenc) and user plane encryption keys (K_UPenc). This multi-functionality approach simplifies key management by having a single source key that can generate all necessary encryption keys, reducing the overall complexity of the key management system while providing comprehensive security protection.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3879867B1Method, apparatus, and system for establishing security context
Publication Date: 2024.10.30 HUAWEI TECH CO LTD
  • EP3879867B1 patent drawingFigure 1
  • EP3879867B1 patent drawingFigure 2
  • EP3879867B1 patent drawingFigure 3~4

AI summary

The present invention discloses a method, an apparatus, and a system for establishing a security context and relates to the communications field, so as to comprehensively protect UE data. The method includes: acquiring an encryption algorithm of an access node; acquiring a root key and deriving, according to the root key and the encryption algorithm, an encryption key of the access node; sending the encryption key and the encryption algorithm to the access node, so that the access node starts downlink encryption and uplink decryption; sending the encryption algorithm of the access node to the UE so as to negotiate the encryption algorithm with the UE; and instructing the access node to start downlink encryption and uplink decryption and instructing, during algorithm negotiation, the UE to start downlink decryption and uplink encryption. The present invention mainly applies to SCC security protection.