Secure Tunnel Establishment for Split RAN User Plane Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional Next Generation (NG) RAN architectures face challenges in efficiently securing user plane (UP) interfaces due to the need for manual configuration and the introduction of latency and backhaul traffic aggregation when using security gateways.
Innovation Solution
The solution involves establishing a secure tunnel directly between RAN nodes for user plane traffic, allowing for dynamic configuration and eliminating the need for a security gateway, thereby reducing latency and preserving security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a security gateway is used to secure UP interfaces, then security is preserved, but latency increases and backhaul resources are consumed
Solution Approach 1:
The patent extracts the security gateway from the UP interface path, removing it as a separate entity. Instead, security functions are integrated directly into the RAN nodes (gNBs), allowing encrypted tunnels to be established peer-to-peer between nodes without routing traffic through a centralized security gateway, thereby eliminating the latency and backhaul consumption associated with gateway mediation
Solution Approach 2:
The patent introduces an IPsec tunnel as an intermediary mechanism between RAN nodes. This tunnel provides encrypted communication directly between nodes, serving as a secure channel that eliminates the need for traffic to be routed through a security gateway, thus preserving security while reducing latency and backhaul resource usage
2Reliability
If a security gateway is used to secure UP interfaces, then security is preserved, but backhaul resources are aggregated and consumed
Solution Approach 1:
The patent extracts the security gateway from the architecture and removes its function of aggregating backhaul traffic. By implementing security directly at the RAN nodes through IPsec tunnels, user plane traffic flows directly between nodes without being aggregated and routed through a security gateway, thereby conserving backhaul resources
Solution Approach 2:
The patent segments the security function from the centralized security gateway and distributes it to individual RAN nodes. Each node establishes its own secure tunnels independently, allowing user plane traffic to flow directly between nodes without being consolidated through a single gateway, thus reducing backhaul aggregation and resource consumption
3Reliability
If manual configuration is used for IPsec connections, then security can be established, but the process requires heavy manual configuration and is not autonomous
Solution Approach 1:
The patent implements self-service by enabling RAN nodes to autonomously establish IPsec connections without manual configuration. Nodes automatically exchange necessary parameters (such as IP addresses and security credentials) and set up encrypted tunnels independently, eliminating the need for heavy manual configuration while maintaining security
Solution Approach 2:
The patent applies preliminary action by pre-configuring security parameters and credentials in the RAN nodes before operation. This allows nodes to automatically establish IPsec connections without requiring manual configuration at the time of connection setup, as the necessary security information is already in place for autonomous operation
4Loss of time
If secure tunnels are established before DRB setup, then DRB setup time is decreased, but the tunnel establishment process must be automated and dynamic
Solution Approach 1:
The patent applies preliminary action by establishing IPsec tunnels before Data Radio Bearer (DRB) setup. The secure tunnel infrastructure is prepared in advance, so when DRB establishment is needed, the security channel is already in place and DRBs can be set up rapidly over the pre-established tunnels, decreasing DRB setup time
Solution Approach 2:
The patent implements dynamics by making the tunnel establishment process automatic and adaptive. Nodes dynamically create and manage IPsec tunnels based on operational needs, with the ability to establish, modify, and tear down tunnels automatically without manual intervention, enabling the system to adapt to changing conditions while maintaining security
Data Source
AI summary
A network node (700) of a radio access network (RAN) of a wireless communication network (10) provides user plane security by establishing a secure tunnel between first and second tunnel endpoints (160, 180, 370, 195, 220, 230) that will handle respective protocol layers of a same protocol stack for a Data Radio Bearer (DRB) (330, 340, 350, 360) that is dedicated to user plane traffic and has yet to be established. Establishing the secure tunnel comprises exchanging an inner Internet Protocol (IP) address and an outer IP address of each of the endpoints (160, 180, 370, 195, 220, 230) between the endpoints (160, 180, 370, 195, 220, 230).


