Terminal Security Negotiation for Separated CU-CP and CU-UP

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security negotiation mechanisms in wireless communications are inadequate for scenarios where the control-plane and user-plane function entities are separated, as they do not provide effective security negotiation solutions for such configurations.

Innovation Solution

A security negotiation method and apparatus that involves receiving security negotiation information from a CU-CP, determining whether to enable user-plane integrity protection or encryption protection based on indication identifiers, and generating corresponding keys for the terminal, allowing for secure communication even when the control-plane and user-plane entities are separated.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a current security negotiation mechanism (AS SMC process in LTE) is used, then authentication between terminal and base station is achieved, but it cannot be applied to scenarios where control-plane and user-plane entities are separated

Engineering Contradiction:
Improveapplicability to separated control-plane and user-plane entitiesVSAvoidcommunication security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the security negotiation process into two independent parts: control-plane security negotiation (between terminal and CU-CP) and user-plane security negotiation (between terminal and CU-UP). This allows each plane to have its own security context and protection mechanisms, enabling the system to adapt to separated control-plane and user-plane entities while maintaining security reliability through dedicated security procedures for each plane

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The CU-CP acts as an intermediary that receives security capability information from the terminal, determines the security protection mode, and then forwards appropriate security negotiation information to the CU-UP. This intermediary role enables coordination between control-plane and user-plane security while allowing independent security negotiation in the user-plane, resolving the contradiction between adaptability to separated entities and maintaining security reliability

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security protection is enabled for user-plane data, then communication security is improved, but device complexity and negotiation overhead increase

Engineering Contradiction:
Improveuser-plane security protectionVSAvoidsecurity negotiation mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The terminal performs preliminary security capability indication before actual user-plane data transmission. By indicating security capability in advance during connection establishment or reconfiguration, the network can determine the appropriate protection mode beforehand, avoiding complex real-time security negotiations and reducing device complexity during actual data transmission

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The security protection mode is made dynamic and configurable rather than fixed. The system can adaptively switch between different protection modes (integrity protection, encryption protection, or no protection) based on terminal capability indication and network policy, allowing simplified mechanisms for capable devices while maintaining security options for all scenarios, thus balancing security reliability with reduced complexity

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11765578B2Security negotiation method and apparatus
Publication Date: 2023.09.19 HUAWEI TECH CO LTD
  • US11765578B2 patent drawing
  • US11765578B2 patent drawing
  • US11765578B2 patent drawing

AI summary

A security negotiation method includes receiving, by a terminal, security negotiation information from a centralized unit control plane (CU-CP)/a centralized unit user plane (CU-UP), where the security negotiation information includes an integrity protection indication identifier of the CU-UP, and determining, by the terminal based on the integrity protection indication identifier, whether to enable user-plane integrity protection of the terminal.