Securing MB2-U Interface via Control Plane Negotiation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The MB2-U interface in LTE networks lacks authorization, allowing attackers to inject forged data, and existing solutions do not provide adequate security measures to ensure integrity protection.

Innovation Solution

Establishing a point-to-point security association between the Group Communication Service Enabler (GCS) Application Server and the Broadcast Multicast Service Center using protocols like IPsec and DTLS, with negotiation of security options via the MB2-C control interface to secure the MB2-U interface.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the MB2-U interface operates without authorization mechanisms, then the system maintains simplicity and ease of operation, but security is compromised allowing data injection and forgery attacks

Engineering Contradiction:
Improvedata integrityVSAvoidsecurity association establishment
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent establishes security associations preliminarily through the MB2-C control interface before actual data transmission occurs on the MB2-U user plane. The BM-SC and GCS Application Server negotiate and configure security parameters (IP addresses, ports, cipher suites, key lengths) in advance, so that when user plane data flows are established, security protection is already in place without adding complexity to the data transmission path itself

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces the MB2-C control interface as an intermediary layer that handles security association establishment between the BM-SC and GCS Application Server. This mediator manages the complex security negotiation, authentication, and parameter configuration, isolating the security complexity from the user plane data transmission and allowing the MB2-U interface to focus on efficient data transfer while remaining protected

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security associations are established on the MB2-U interface, then data integrity and authentication are improved, but the complexity of connection establishment and parameter negotiation increases

Engineering Contradiction:
Improveauthorization protectionVSAvoidconnection establishment
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent merges the security association establishment process with the existing MB2-C control plane procedures. Instead of creating separate security negotiation protocols, the security parameters and authentication are integrated into the control interface messages that already exist for bearer management and session control, thereby providing authorization protection without significantly increasing operational complexity

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The BM-SC and GCS Application Server autonomously negotiate and configure their own security parameters through the MB2-C interface without requiring external intervention or manual configuration. The system entities themselves perform authentication, select cipher suites, determine key lengths, and establish security associations independently, reducing operational burden while maintaining strong security

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11212321B2Group communication service enabler security
Publication Date: 2021.12.28 NOKIA SOLUTIONS & NETWORKS OY
  • US11212321B2 patent drawing
  • US11212321B2 patent drawing
  • US11212321B2 patent drawing

AI summary

Systems, methods, apparatuses, and computer program products for securing user plane (e.g., MB2-U) interface between a group communication service application server (GCS AS) and Broadcast Multicast Service Center (BM-SC) are provided. One method may include transmitting a message via a control plane, to an application server, indicating whether to establish a security association on a user plane in an interface between the GCS AS and the BM-SC. The method may also include providing, to the GCS AS, a target internet protocol (IP) address and possible port as a target for the security association.