Disaggregated RAN CU-UP Security Isolation via Unique Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The disaggregated radio network architecture faces security challenges due to the potential compromise of security at one part of the network node affecting others, as the same security key is often shared across central unit user planes (CU-UPs), leading to a lack of isolation in case of a security breach.

Innovation Solution

Configuring multiple CU-UPs of a disaggregated radio network node to handle different data radio bearers with unique security keys, ensuring that each CU-UP operates within its own security domain by performing security processing based on distinct user plane security keys, which can be derived from parameters provided by the central unit control plane (CU-CP).

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the same security key is shared across multiple CU-UPs for simplified key management, then ease of operation is improved, but security reliability deteriorates because a compromise at one CU-UP affects all other CU-UPs

Engineering Contradiction:
Improvekey managementVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent divides the security domain by assigning unique security keys to each CU-UP instance. Instead of using a single shared security key across all CU-UPs, each CU-UP is segmented with its own dedicated security key, ensuring that a security compromise at one CU-UP does not affect other CU-UPs. This segmentation is implemented through the configuration of multiple security keys in the disaggregated radio network node.

Inventive Principle:
Principle #1Segmentation

2Reliability

If multiple CU-UPs use different security keys for security isolation, then security reliability is improved, but device complexity increases due to multiple key configurations

Engineering Contradiction:
ImprovesecurityVSAvoidkey configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal security key management mechanism that can handle both single-key and multi-key configurations through a unified architecture. The disaggregated radio network node is designed with multi-functionality to support configurable security key assignments, where the same system infrastructure can adapt to different security requirements without requiring separate management systems for each scenario.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If security processing is performed at each CU-UP with unique keys, then security isolation is improved, but processing overhead increases

Engineering Contradiction:
Improvesecurity isolationVSAvoidprocessing overhead
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent applies local quality by enabling security processing with unique keys only at the specific CU-UP instances that require enhanced security isolation. The security key configuration can be selectively applied to individual CU-UPs based on their specific security requirements and risk profiles, rather than uniformly applying to all CU-UPs. This allows the system to optimize security processing overhead by concentrating unique key management where most needed.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20230362635A1Radio Access Network Security
Publication Date: 2023.11.09 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US20230362635A1 patent drawing
  • US20230362635A1 patent drawing
  • US20230362635A1 patent drawing

AI summary

A network node (20) is configured for use in a wireless communication network (10). The network node (20) configures multiple central unit user planes, CU-UPs, (14-1UP) of a disaggregated radio network node (14) to handle different respective data radio bearers (16-1 . . . 16-N) of a wireless device (12) in multi-connectivity operation, with security processing of user plane traffic by different CU-UPs (14-1UP) being based on different respective security keys (18). In some embodiments, the network node (20) configures different distributed units, DUs, of the disaggregated radio network node (14) to serve different respective ones of the data radio bearers (16-1 . . . 16-N).