X2 Security Tunnel Establishment via Pre-configured Parameter Sets
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing LTE/SAE network system faces a data security issue during the establishment of an X2 link, as transmission information is often transmitted in plaintext, and the current security mechanisms, such as the 36.413 protocol, are incomplete, leading to negotiation failures and delays in establishing a security tunnel during handovers.
Innovation Solution
A method and system for establishing an X2 security tunnel by sending a notification message with a security parameter set including IP-Sec and IKE parameters, allowing the peer base station to select and respond with supported values, thereby reducing negotiation delays and failures, and ensuring secure data transmission.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If only IP-Sec transport layer address is added to X2 TNL Configuration Info message, then the security tunnel establishment process is simplified, but negotiation failures occur and security tunnel cannot be established
Solution Approach 1:
The patent applies preliminary action by pre-configuring a complete security parameter set (including IKE version, encryption algorithms, authentication algorithms, Diffie-Hellman groups, and IP-Sec parameters) in the source eNB before handover. This pre-prepared security configuration is included in the X2 TNL Configuration Info message, allowing the target eNB to directly use these parameters without extensive negotiation, thereby preventing negotiation failures while maintaining process simplicity.
2Reliability
If complete security parameter negotiation is performed between eNBs, then security tunnel can be established reliably, but negotiation delays occur during handover
Solution Approach 1:
The patent resolves this contradiction by performing the security parameter preparation in advance at the source eNB. The complete security parameter set is configured beforehand and transferred via the X2 TNL Configuration Info message during handover, eliminating the need for time-consuming real-time negotiation between eNBs while ensuring reliable security tunnel establishment.
Solution Approach 2:
The patent uses the MME and X2 TNL Configuration Info message as intermediaries to transfer pre-configured security parameters from the source eNB to the target eNB. This intermediary mechanism allows security parameters to be transferred efficiently without requiring direct real-time negotiation between eNBs, thus reducing handover time while maintaining security reliability.
3Speed
If security parameters are transmitted in plaintext during X2 link establishment, then transmission speed is fast, but data security is compromised
Solution Approach 1:
The patent applies parameter changes by transforming the security parameters (IKE version, encryption algorithms, authentication algorithms, Diffie-Hellman groups, IP-Sec parameters) into an encrypted format within the X2 TNL Configuration Info message. This encryption transformation maintains fast transmission speed while protecting data security, as the parameters are securely encrypted during transfer between eNBs through the MME.
Data Source
Figure 1~2
Figure 3~4
Figure 5~7
AI summary
A method, a system and a base station for establishing an X2 security tunnel are provided. When a user terminal is handed over from a cell covered by a base station to a cell covered by another base station, while sending a notification message to the another base station, the base station sends a security parameter set so that the another base station selects a security parameter value supported by the another base station, thereby sparing multiple times of negotiation, reducing problems caused by the negotiation, such as a delay or a failure to establish a security tunnel, and establishing an X2 security tunnel within a time tolerable for a communications handover. The method includes: sending, by a base station, a notification message to a peer base station, where the notification message includes a security parameter set; receiving a response message sent by the peer base station, where the response message includes a security parameter value selected by the peer base station from the security parameter set; and establishing an X2 security tunnel according to the response message.