Separate Ciphering Keys for MeNB and SeNB U-Plane Traffic
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions do not adequately support separate ciphering at Master evolved Node B (MeNB) and Second eNB (SeNB) in Small Cell Enhancement (SCE) systems, which is required for secure U-Plane traffic transmission.
Innovation Solution
A radio base station is equipped with derivation and send means to derive and transmit keys for secure U-Plane traffic between MeNB and SeNB, ensuring separate ciphering by sharing keys between the base stations and User Equipment (UE), allowing for parallel traffic transmission.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If separate ciphering is implemented at MeNB and SeNB, then security is improved, but device complexity increases
Solution Approach 1:
The patent segments the ciphering function by implementing separate encryption keys and ciphering mechanisms at MeNB and SeNB. The MeNB uses a first key for encrypting user plane traffic, while the SeNB uses a second key for encrypting traffic, allowing independent security management at each node and resolving the contradiction between security improvement and device complexity.
Solution Approach 2:
The patent introduces a key management mechanism where the MeNB acts as an intermediary to provide the second key to the SeNB. This intermediary key management approach enables separate ciphering at both nodes while simplifying the overall system architecture by centralizing key distribution through the MeNB.
2Productivity
If parallel traffic transmission is enabled, then productivity is improved, but device complexity increases
Solution Approach 1:
The patent segments the user plane traffic into separate logical channels for MeNB and SeNB transmission. By implementing separate PDCP (Packet Data Convergence Protocol) entities and independent key management for each node, the system enables parallel traffic transmission while managing complexity through structured separation of functions.
3Reliability
If key management for separate ciphering is implemented, then security is improved, but loss of time increases
Solution Approach 1:
The patent implements preliminary key derivation and distribution mechanisms where the MeNB pre-calculates and prepares the second key for the SeNB before actual traffic transmission begins. This preliminary key management action eliminates time-consuming key exchange operations during data transmission, maintaining security while minimizing time loss.
Data Source
AI summary
In order for supporting separate ciphering at an MeNB (20) and an SeNB (30), the MeNB (20) derives separate first and second keys (KUPenc-M, KUPenc-S) from a third key (KeNB). The first key (KUPenc-M) is used for confidentially protecting first traffic transmitted over U-Plane between the MeNB (20) and a UE (10). The first key (KUPenc-M) may be the same as current KUPenc or a new key. The second key (KUPenc-S) is used for confidentially protecting second traffic transmitted over the U-Plane between the UE (10) and the SeNB (30). The MeNB (20) sends the second key (KUPenc-S) to the SeNB (30). The UE (10) negotiates with the MeNB (20), and derives the second key (KUPenc-S) based on a result of the negotiation.


