Master gNodeB User Plane Integrity Protection Handling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In 5G systems, the lack of user plane integrity protection support in secondary nodes during dual connectivity scenarios leads to activation failures and network performance issues when the capabilities of master and secondary nodes differ, causing delays and network congestion.

Innovation Solution

A master gNodeB is designed to handle user plane security policies by receiving indications from the core network and establishing data radio bearers directly with user equipment, even if secondary base stations do not support user plane integrity protection, using a whitelist or blacklist of nodes that support integrity protection to ensure seamless security activation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If dual connectivity is implemented with secondary nodes that do not support user plane integrity protection, then network coverage and connectivity are improved, but security activation fails and network performance deteriorates

Engineering Contradiction:
Improvedual connectivity supportVSAvoidsecurity activation
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the security policy handling by creating separate whitelist and blacklist structures for secondary nodes. Nodes supporting user plane integrity protection are placed in the whitelist, while those that don't support it are placed in the blacklist. This segmentation allows the master gNodeB to selectively apply security policies based on node capabilities, resolving the contradiction between maintaining dual connectivity versatility and ensuring security activation reliability.

Inventive Principle:
Principle #1Segmentation

2Reliability

If the master gNodeB attempts to activate user plane integrity protection on all secondary nodes, then security policy compliance is improved, but activation failures increase and network congestion occurs

Engineering Contradiction:
Improvesecurity policy complianceVSAvoidactivation success rate
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements preliminary action by pre-categorizing secondary nodes into whitelist and blacklist based on their user plane integrity protection support capabilities before security activation attempts. The master gNodeB performs this classification in advance using capability indication information received from secondary nodes. When a data radio bearer needs to be established, the system already knows which nodes can support integrity protection, eliminating repeated activation failures and reducing network congestion caused by retry attempts.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If secondary nodes without integrity protection support are used for data offloading, then network capacity and throughput are improved, but security vulnerabilities are introduced

Engineering Contradiction:
Improvedata offloading capacityVSAvoidsecurity vulnerability
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by implementing differentiated security policies for different secondary nodes based on their capabilities. Nodes in the whitelist receive and enforce user plane integrity protection policies, while nodes in the blacklist are explicitly excluded from handling data radio bearers requiring integrity protection. This localized quality approach allows the network to maximize data offloading capacity to capable nodes while maintaining security, rather than applying a uniform security policy that would limit overall network productivity.

Inventive Principle:
Principle #3Local quality

4Reliability

If the system uses a whitelist approach to filter supported nodes, then security activation reliability is improved, but device complexity and signaling overhead increase

Engineering Contradiction:
Improvesecurity activation reliabilityVSAvoidnode management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements universality by designing the whitelist and blacklist mechanisms to serve multiple functions simultaneously. These structures not only manage security policy compliance but also optimize data radio bearer establishment, control signaling flow, and enable efficient node selection for data offloading. The same whitelist/blacklist infrastructure supports both security activation and overall network resource management, reducing the need for separate complex management systems and mitigating the increase in device complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11546765B2Master gNodeBs and method of operating master gNodeB
Publication Date: 2023.01.03 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US11546765B2 patent drawing
  • US11546765B2 patent drawing
  • US11546765B2 patent drawing

AI summary

A method of operating a Master gNodeB (MgNB) in a radio access network RAN is disclosed. An indication of a user plane security policy is received from a core network node, wherein the user plane security policy requires user plane integrity protection for a protocol data unit PDU session. Responsive to the user plane security policy requiring user plane integrity protection for the PDU session and responsive to determining that a secondary base station supporting the user plane security policy requiring user plane integrity protection is unavailable, a data radio bearer DRB of the PDU session is established directly between the MgNB and a user equipment UE. Related MgNBs are also discussed.