Disaggregated RAN User Plane Key Change Coordination

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In a disaggregated radio access network (RAN) node with geographically dispersed control plane (CP) and user plane (UP) components, there are delays in communicating cryptographic key changes, leading to disruptions in wireless communication due to suspended transmission during key renegotiation, affecting the quality of service (QoS).

Innovation Solution

A method and apparatus for coordinating cryptographic key changes by transmitting a key change indicator in protocol data units (PDUs) between the RAN node and wireless devices, allowing seamless transition to new key sets without suspending transmission, with the UP component autonomously managing key changes based on keying material received from the CP component.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic key changes are coordinated through CP entity in disaggregated RAN node, then security is maintained, but transmission delays increase and QoS deteriorates

Engineering Contradiction:
Improvecryptographic securityVSAvoidkey renegotiation delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The RAN node is segmented into CP entity and UP entity located in different physical network elements. The UP entity is empowered to autonomously manage cryptographic key changes using keying material received from CP, separating the security management function from the control plane signaling path. This allows cryptographic operations to proceed independently without waiting for CP coordination delays.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The CP entity sends keying material to the UP entity in advance before transmission suspensions occur. The UP entity prepares new cryptographic keys beforehand and can immediately activate them when needed, avoiding delays during actual key renegotiation. This preliminary preparation eliminates the need to suspend transmissions during key changes.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If UP entity autonomously manages key changes, then transmission continuity is maintained, but coordination complexity increases

Engineering Contradiction:
Improvetransmission continuityVSAvoidkey management coordination
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The cryptographic key management function is extracted from the CP entity and placed in the UP entity. The UP entity now autonomously handles key changes using keying material received from CP, removing the need for complex real-time coordination between CP and UP during key transitions. This extraction simplifies the coordination mechanism while maintaining transmission continuity.

Inventive Principle:
Principle #2Taking out (Extraction)

3Loss of time

If key change indicator is transmitted in PDUs, then synchronization is achieved without suspending transmission, but protocol overhead increases

Engineering Contradiction:
Improvetransmission suspension timeVSAvoidprotocol data units
Core Design Contradiction:
Loss of timeVSQuantity of substance

Solution Approach 1:

Existing PDU structures are used to carry key change indicators, making the PDUs multi-functional. The same PDU format that carries user data or control information is also used to convey cryptographic key change indications. This approach avoids creating separate signaling messages, thereby minimizing protocol overhead while achieving synchronization without transmission suspensions.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11039309B2User plane security for disaggregated RAN nodes
Publication Date: 2021.06.15 HUAWEI TECH CO LTD
  • US11039309B2 patent drawing
  • US11039309B2 patent drawing
  • US11039309B2 patent drawing

AI summary

A method of coordinating a change in cryptographic key sets from a first cryptographic key set to a second cryptographic key set between a radio access network (RAN) node and a wireless device (WD) served by the RAN node. The RAN node includes a user plane (UP) component and a control plane (CP) component. The method includes transmitting, from the UP component to the wireless device (WD), a key change indicator indicative of changeover to the second cryptographic key set, the key change indicator included in one of a data protocol data unit (PDU) and a control PDU; and subsequently cryptographically encoding PDUs for transmission to the WD and cryptographically decoding PDUs received from the WD in accordance with the second cryptographic key set.