Securing MB2-U Interface via Control Plane Negotiation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The MB2-U interface in LTE networks lacks authorization, allowing attackers to inject forged data, and existing solutions do not provide adequate security measures to ensure integrity protection.
Innovation Solution
Establishing a point-to-point security association between the Group Communication Service Enabler (GCS) Application Server and the Broadcast Multicast Service Center using protocols like IPsec and DTLS, with negotiation of security options via the MB2-C control interface to secure the MB2-U interface.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the MB2-U interface operates without authorization mechanisms, then the system maintains simplicity and ease of operation, but security is compromised allowing data injection and forgery attacks
Solution Approach 1:
The patent establishes security associations preliminarily through the MB2-C control interface before actual data transmission occurs on the MB2-U user plane. The BM-SC and GCS Application Server negotiate and configure security parameters (IP addresses, ports, cipher suites, key lengths) in advance, so that when user plane data flows are established, security protection is already in place without adding complexity to the data transmission path itself
Solution Approach 2:
The patent introduces the MB2-C control interface as an intermediary layer that handles security association establishment between the BM-SC and GCS Application Server. This mediator manages the complex security negotiation, authentication, and parameter configuration, isolating the security complexity from the user plane data transmission and allowing the MB2-U interface to focus on efficient data transfer while remaining protected
2Reliability
If security associations are established on the MB2-U interface, then data integrity and authentication are improved, but the complexity of connection establishment and parameter negotiation increases
Solution Approach 1:
The patent merges the security association establishment process with the existing MB2-C control plane procedures. Instead of creating separate security negotiation protocols, the security parameters and authentication are integrated into the control interface messages that already exist for bearer management and session control, thereby providing authorization protection without significantly increasing operational complexity
Solution Approach 2:
The BM-SC and GCS Application Server autonomously negotiate and configure their own security parameters through the MB2-C interface without requiring external intervention or manual configuration. The system entities themselves perform authentication, select cipher suites, determine key lengths, and establish security associations independently, reducing operational burden while maintaining strong security
Data Source
AI summary
Systems, methods, apparatuses, and computer program products for securing user plane (e.g., MB2-U) interface between a group communication service application server (GCS AS) and Broadcast Multicast Service Center (BM-SC) are provided. One method may include transmitting a message via a control plane, to an application server, indicating whether to establish a security association on a user plane in an interface between the GCS AS and the BM-SC. The method may also include providing, to the GCS AS, a target internet protocol (IP) address and possible port as a target for the security association.


