Centralized Security Parameter Configuration for LTE Base Stations
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security configurations in LTE networks, particularly for X2 and S1 interfaces, incur high overhead and performance consumption due to the need for IPSec tunnel management and key negotiation between eNodeBs, especially in scenarios involving third-party untrusted networks, which complicates data transmission and increases operational costs.
Innovation Solution
A method where a server configures and updates security parameters for a group of base stations, eliminating the need for key negotiation between them, thereby reducing performance consumption and simplifying IPSec tunnel management by using a centralized approach to distribute encryption policies and keys.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If IPSec tunnel and key management is implemented between eNodeBs for security protection, then data transmission security is improved, but performance consumption and overhead increase
Solution Approach 1:
The patent introduces a Key Distribution Center (KDC) as an intermediary authority that centrally manages security keys for eNodeBs. Instead of eNodeBs performing complex key negotiation with each other, the KDC acts as a mediator that distributes pre-configured security parameters, thereby reducing the performance consumption and computational overhead associated with direct key negotiation while maintaining security protection.
Solution Approach 2:
The patent implements preliminary configuration of security parameters where the KDC pre-configures encryption keys and security settings for eNodeBs before they need to communicate. This preliminary action eliminates the need for real-time key negotiation during data transmission, reducing performance consumption while ensuring security is established in advance.
2Adaptability or versatility
If key negotiation is performed between eNodeBs dynamically, then security parameter updates are improved, but performance consumption increases
Solution Approach 1:
The KDC serves as a centralized intermediary that handles dynamic security parameter updates for multiple eNodeBs simultaneously. Rather than each eNodeB performing individual key negotiation, the KDC mediates the update process, distributing new security parameters efficiently across the network, thereby reducing overall performance consumption while maintaining adaptability.
Solution Approach 2:
The KDC performs multiple functions including key generation, key distribution, and security parameter management for all eNodeBs in the network. This universal approach allows a single system to handle security updates for the entire network, improving efficiency and reducing the performance consumption that would result from multiple separate key negotiation processes.
3Reliability
If IPSec ESP is used for security protection, then data integrity and confidentiality are improved, but transport protocol overhead increases
Solution Approach 1:
The KDC acts as an intermediary that establishes secure communication channels before data transmission begins. By pre-establishing these channels through centralized key management, the patent reduces the need for repeated IPSec encapsulation and decapsulation operations during data transmission, thereby minimizing the transport protocol overhead while maintaining data integrity and confidentiality.
Solution Approach 2:
The patent implements preliminary establishment of security associations and encryption keys through the KDC before actual data transmission occurs. This preliminary action allows for more efficient data transmission with reduced IPSec overhead, as the security framework is already in place rather than being dynamically established for each transmission.
Data Source
AI summary
Methods, servers, base stations and communication systems for configuring security parameters are disclosed. Embodiments of the present invention provide a method for configuring security parameters in a network, the network comprising at least one base station and a server providing service for the at least one base station. The method comprises updating, by the server, security parameters for the base station and sending, by the server, the updated security parameters to the base station, so that base stations transmits data between each other according to the updated security parameters.


