Disaggregated RAN CU-UP Security Isolation via Unique Keys
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The disaggregated radio network architecture faces security challenges due to the potential compromise of security at one part of the network node affecting others, as the same security key is often shared across central unit user planes (CU-UPs), leading to a lack of isolation in case of a security breach.
Innovation Solution
Configuring multiple CU-UPs of a disaggregated radio network node to handle different data radio bearers with unique security keys, ensuring that each CU-UP operates within its own security domain by performing security processing based on distinct user plane security keys, which can be derived from parameters provided by the central unit control plane (CU-CP).
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the same security key is shared across multiple CU-UPs for simplified key management, then ease of operation is improved, but security reliability deteriorates because a compromise at one CU-UP affects all other CU-UPs
Solution Approach 1:
The patent divides the security domain by assigning unique security keys to each CU-UP instance. Instead of using a single shared security key across all CU-UPs, each CU-UP is segmented with its own dedicated security key, ensuring that a security compromise at one CU-UP does not affect other CU-UPs. This segmentation is implemented through the configuration of multiple security keys in the disaggregated radio network node.
2Reliability
If multiple CU-UPs use different security keys for security isolation, then security reliability is improved, but device complexity increases due to multiple key configurations
Solution Approach 1:
The patent implements a universal security key management mechanism that can handle both single-key and multi-key configurations through a unified architecture. The disaggregated radio network node is designed with multi-functionality to support configurable security key assignments, where the same system infrastructure can adapt to different security requirements without requiring separate management systems for each scenario.
3Reliability
If security processing is performed at each CU-UP with unique keys, then security isolation is improved, but processing overhead increases
Solution Approach 1:
The patent applies local quality by enabling security processing with unique keys only at the specific CU-UP instances that require enhanced security isolation. The security key configuration can be selectively applied to individual CU-UPs based on their specific security requirements and risk profiles, rather than uniformly applying to all CU-UPs. This allows the system to optimize security processing overhead by concentrating unique key management where most needed.
Data Source
AI summary
A network node (20) is configured for use in a wireless communication network (10). The network node (20) configures multiple central unit user planes, CU-UPs, (14-1UP) of a disaggregated radio network node (14) to handle different respective data radio bearers (16-1 . . . 16-N) of a wireless device (12) in multi-connectivity operation, with security processing of user plane traffic by different CU-UPs (14-1UP) being based on different respective security keys (18). In some embodiments, the network node (20) configures different distributed units, DUs, of the disaggregated radio network node (14) to serve different respective ones of the data radio bearers (16-1 . . . 16-N).


