Secure Tunnel Establishment for Split RAN User Plane Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional Next Generation (NG) RAN architectures face challenges in efficiently securing user plane (UP) interfaces due to the need for manual configuration and the introduction of latency and backhaul traffic aggregation when using security gateways.

Innovation Solution

The solution involves establishing a secure tunnel directly between RAN nodes for user plane traffic, allowing for dynamic configuration and eliminating the need for a security gateway, thereby reducing latency and preserving security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a security gateway is used to secure UP interfaces, then security is preserved, but latency increases and backhaul resources are consumed

Engineering Contradiction:
ImprovesecurityVSAvoidlatency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent extracts the security gateway from the UP interface path, removing it as a separate entity. Instead, security functions are integrated directly into the RAN nodes (gNBs), allowing encrypted tunnels to be established peer-to-peer between nodes without routing traffic through a centralized security gateway, thereby eliminating the latency and backhaul consumption associated with gateway mediation

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an IPsec tunnel as an intermediary mechanism between RAN nodes. This tunnel provides encrypted communication directly between nodes, serving as a secure channel that eliminates the need for traffic to be routed through a security gateway, thus preserving security while reducing latency and backhaul resource usage

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a security gateway is used to secure UP interfaces, then security is preserved, but backhaul resources are aggregated and consumed

Engineering Contradiction:
ImprovesecurityVSAvoidbackhaul resources
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent extracts the security gateway from the architecture and removes its function of aggregating backhaul traffic. By implementing security directly at the RAN nodes through IPsec tunnels, user plane traffic flows directly between nodes without being aggregated and routed through a security gateway, thereby conserving backhaul resources

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments the security function from the centralized security gateway and distributes it to individual RAN nodes. Each node establishes its own secure tunnels independently, allowing user plane traffic to flow directly between nodes without being consolidated through a single gateway, thus reducing backhaul aggregation and resource consumption

Inventive Principle:
Principle #1Segmentation

3Reliability

If manual configuration is used for IPsec connections, then security can be established, but the process requires heavy manual configuration and is not autonomous

Engineering Contradiction:
ImprovesecurityVSAvoidautonomous setup
Core Design Contradiction:
ReliabilityVSExtent of automation

Solution Approach 1:

The patent implements self-service by enabling RAN nodes to autonomously establish IPsec connections without manual configuration. Nodes automatically exchange necessary parameters (such as IP addresses and security credentials) and set up encrypted tunnels independently, eliminating the need for heavy manual configuration while maintaining security

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent applies preliminary action by pre-configuring security parameters and credentials in the RAN nodes before operation. This allows nodes to automatically establish IPsec connections without requiring manual configuration at the time of connection setup, as the necessary security information is already in place for autonomous operation

Inventive Principle:
Principle #10Preliminary action

4Loss of time

If secure tunnels are established before DRB setup, then DRB setup time is decreased, but the tunnel establishment process must be automated and dynamic

Engineering Contradiction:
ImproveDRB setup timeVSAvoiddynamic configuration
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by establishing IPsec tunnels before Data Radio Bearer (DRB) setup. The secure tunnel infrastructure is prepared in advance, so when DRB establishment is needed, the security channel is already in place and DRBs can be set up rapidly over the pre-established tunnels, decreasing DRB setup time

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements dynamics by making the tunnel establishment process automatic and adaptive. Nodes dynamically create and manage IPsec tunnels based on operational needs, with the ability to establish, modify, and tear down tunnels automatically without manual intervention, enabling the system to adapt to changing conditions while maintaining security

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12225379B2User plane security in split RAN architectures
Publication Date: 2025.02.11 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US12225379B2 patent drawing
  • US12225379B2 patent drawing
  • US12225379B2 patent drawing

AI summary

A network node (700) of a radio access network (RAN) of a wireless communication network (10) provides user plane security by establishing a secure tunnel between first and second tunnel endpoints (160, 180, 370, 195, 220, 230) that will handle respective protocol layers of a same protocol stack for a Data Radio Bearer (DRB) (330, 340, 350, 360) that is dedicated to user plane traffic and has yet to be established. Establishing the secure tunnel comprises exchanging an inner Internet Protocol (IP) address and an outer IP address of each of the endpoints (160, 180, 370, 195, 220, 230) between the endpoints (160, 180, 370, 195, 220, 230).