Un Interface Data Protection for LTE Relay Nodes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The introduction of a relay node (RN) in the LTE-A system introduces new security requirements for data protection on the Un interface, particularly for user plane data, which are not adequately met by conventional LTE security mechanisms that lack fine-grained protection and only provide encryption for control plane data.

Innovation Solution

A method and apparatus for negotiating and implementing separate integrity protection and encryption algorithms for signaling data on SRB, s-DRB, and d-DRB over the Un interface, generating corresponding keys, and providing comprehensive security protection tailored to each type of radio bearer to meet the unique security requirements of S1/X2-AP and S1/X2-UP data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional LTE security mechanisms are used on the Un interface, then control plane data is protected with integrity protection and encryption, but user plane data lacks integrity protection and the security granularity is insufficient

Engineering Contradiction:
Improvedata security protectionVSAvoidsecurity protection granularity
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the Un interface data transmission into three distinct radio bearers (SRB, s-DRB, d-DRB), each with its own security protection configuration. This segmentation allows different security mechanisms to be applied to different data types, providing fine-grained security control. Specifically, SRB carries RRC signaling with integrity protection and encryption, s-DRB carries S1/X2-AP signaling with integrity protection and encryption, while d-DRB carries user data with encryption only, matching the legacy LTE security model for the UE-to-eNB interface.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different security protection qualities to different parts of the data transmission system. Control plane data (RRC signaling on SRB and S1/X2-AP signaling on s-DRB) receives both integrity protection and encryption, while user plane data (on d-DRB) receives only encryption. This local differentiation of security quality matches the security requirements of different data types while maintaining compatibility with legacy LTE security mechanisms.

Inventive Principle:
Principle #3Local quality

2Ease of manufacture

If the same encryption algorithm is selected for control plane data and user plane data, then implementation is simplified, but the security requirements for different data types cannot be differentiated

Engineering Contradiction:
Improvealgorithm selection simplicityVSAvoidsecurity algorithm flexibility
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent segments the algorithm selection process into separate negotiations for different radio bearers. The eNB and RN negotiate integrity protection algorithms and encryption algorithms independently for SRB, s-DRB, and d-DRB. This allows the system to maintain simplicity by using the same algorithm negotiation mechanism as legacy LTE, while simultaneously achieving flexibility by allowing different algorithms to be selected for different data types based on their specific security requirements.

Inventive Principle:
Principle #1Segmentation

3Reliability

If integrity protection is provided for all data types on the Un interface, then security is enhanced, but system complexity increases and legacy compatibility is reduced

Engineering Contradiction:
Improvecomprehensive security protectionVSAvoidsecurity mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies integrity protection selectively only where needed - specifically for control plane data (RRC signaling on SRB and S1/X2-AP signaling on s-DRB) - while omitting it for user plane data (d-DRB). This local application of integrity protection enhances security for critical signaling data without unnecessarily increasing system complexity for all data types, and maintains compatibility with legacy LTE where user plane data does not require integrity protection.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP2611227B1DATA PROTECTION ON AN Un INTERFACE
Publication Date: 2019.06.26 NOKIA TECHNOLOGIES OY
  • EP2611227B1 patent drawingFigure 1~2
  • EP2611227B1 patent drawingFigure 3~4
  • EP2611227B1 patent drawingFigure 5~6

AI summary

Methods and apparatus are provided for protecting data carried on an Un interface. The method includes: negotiating an integrity protection algorithm and an encryption algorithm for signaling data on a signaling radio bearer SRB over the Un interface, signaling data on a data radio bearer DRBs over the Un interface, and user data on a data radio bearer DRBd over the Un interface, respectively; and performing security protection for the signaling data on the SRB, the signaling data on the DRBs, and the user data on the DRBd with the respective integrity protection algorithm and encryption algorithm. According to the method and system in the embodiments, integrity protection algorithms and encryption algorithms are adopted for data on three classes of RBs over the Un interface are protected with respective integrity protection algorithm and encryption algorithm. Therefore, the security protection on the Un interface is more comprehensive, and the security protection requirements of data on different RBs can be met.