Wireless Relay Node Security Association Architecture

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current 3GPP LTE systems do not define security associations or key distribution procedures between relay nodes and base stations, leading to security gaps in data and control signal transmission.

Innovation Solution

Establishing multiple security associations between user equipment, relay nodes, and base stations through authentication and key agreement processes, allowing relay nodes to transparently transfer data and control signals without encryption/decryption, and using key derivation functions to generate ciphering and integrity keys for secure communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Area of stationary object

If relay nodes are added to extend coverage, then network coverage is improved, but security associations and key distribution procedures are not defined leading to security gaps

Engineering Contradiction:
Improvenetwork coverageVSAvoidsecurity assurance
Core Design Contradiction:
Area of stationary objectVSReliability

Solution Approach 1:

The patent introduces a relay node as an intermediary between the user equipment and base station. The relay node establishes separate security associations with both the user equipment (first security association) and the base station (second security association), acting as a secure mediator that forwards data and control signals while maintaining security boundaries between different network segments.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the security architecture into distinct security associations: a first security association between user equipment and relay node, and a second security association between relay node and base station. This segmentation allows independent key management and security procedures for each link, addressing the security gaps introduced by relay nodes.

Inventive Principle:
Principle #1Segmentation

2Reliability

If relay nodes perform encryption/decryption operations, then security is improved, but hardware cost and design complexity increase

Engineering Contradiction:
ImprovesecurityVSAvoidhardware cost and design complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The relay node serves as a transparent intermediary that forwards encrypted data and control signals between user equipment and base station without performing encryption or decryption operations. The relay node maintains security associations and manages key distribution but acts as a pass-through for actual data encryption, thereby reducing hardware requirements and design complexity while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If multiple security associations are established, then security coverage is improved, but key management complexity increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service mechanisms where each node (user equipment, relay node, base station) autonomously generates and manages its own security keys and associations. The relay node independently establishes its first security association with user equipment and second security association with base station using standardized authentication and key agreement procedures, reducing the need for complex centralized key management.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8605904B2Security method in wireless communication system having relay node
Publication Date: 2013.12.10 IND TECH RES INST
  • US8605904B2 patent drawing
  • US8605904B2 patent drawing
  • US8605904B2 patent drawing

AI summary

A security method in a wireless communication system is provided, which is used for providing a plurality of security associations between a user equipment, a relay node, and a base station node in a wireless communication system. The user equipment authenticates with a serving gateway in the wireless communication system through the relay node, such that a security association between the user equipment and the relay node is established correspondingly. The relay node establishes a second security association between the relay node and the base station node through the base station node.