Terminal Security Negotiation for Separated CU-CP and CU-UP
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security negotiation mechanisms in wireless communications are inadequate for scenarios where the control-plane and user-plane function entities are separated, as they do not provide effective security negotiation solutions for such configurations.
Innovation Solution
A security negotiation method and apparatus that involves receiving security negotiation information from a CU-CP, determining whether to enable user-plane integrity protection or encryption protection based on indication identifiers, and generating corresponding keys for the terminal, allowing for secure communication even when the control-plane and user-plane entities are separated.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a current security negotiation mechanism (AS SMC process in LTE) is used, then authentication between terminal and base station is achieved, but it cannot be applied to scenarios where control-plane and user-plane entities are separated
Solution Approach 1:
The patent segments the security negotiation process into two independent parts: control-plane security negotiation (between terminal and CU-CP) and user-plane security negotiation (between terminal and CU-UP). This allows each plane to have its own security context and protection mechanisms, enabling the system to adapt to separated control-plane and user-plane entities while maintaining security reliability through dedicated security procedures for each plane
Solution Approach 2:
The CU-CP acts as an intermediary that receives security capability information from the terminal, determines the security protection mode, and then forwards appropriate security negotiation information to the CU-UP. This intermediary role enables coordination between control-plane and user-plane security while allowing independent security negotiation in the user-plane, resolving the contradiction between adaptability to separated entities and maintaining security reliability
2Reliability
If security protection is enabled for user-plane data, then communication security is improved, but device complexity and negotiation overhead increase
Solution Approach 1:
The terminal performs preliminary security capability indication before actual user-plane data transmission. By indicating security capability in advance during connection establishment or reconfiguration, the network can determine the appropriate protection mode beforehand, avoiding complex real-time security negotiations and reducing device complexity during actual data transmission
Solution Approach 2:
The security protection mode is made dynamic and configurable rather than fixed. The system can adaptively switch between different protection modes (integrity protection, encryption protection, or no protection) based on terminal capability indication and network policy, allowing simplified mechanisms for capable devices while maintaining security options for all scenarios, thus balancing security reliability with reduced complexity
Data Source
AI summary
A security negotiation method includes receiving, by a terminal, security negotiation information from a centralized unit control plane (CU-CP)/a centralized unit user plane (CU-UP), where the security negotiation information includes an integrity protection indication identifier of the CU-UP, and determining, by the terminal based on the integrity protection indication identifier, whether to enable user-plane integrity protection of the terminal.


