X2 Security Tunnel Establishment via Pre-configured Parameter Sets

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing LTE/SAE network system faces a data security issue during the establishment of an X2 link, as transmission information is often transmitted in plaintext, and the current security mechanisms, such as the 36.413 protocol, are incomplete, leading to negotiation failures and delays in establishing a security tunnel during handovers.

Innovation Solution

A method and system for establishing an X2 security tunnel by sending a notification message with a security parameter set including IP-Sec and IKE parameters, allowing the peer base station to select and respond with supported values, thereby reducing negotiation delays and failures, and ensuring secure data transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If only IP-Sec transport layer address is added to X2 TNL Configuration Info message, then the security tunnel establishment process is simplified, but negotiation failures occur and security tunnel cannot be established

Engineering Contradiction:
Improvesecurity tunnel establishment processVSAvoidsecurity tunnel establishment success rate
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent applies preliminary action by pre-configuring a complete security parameter set (including IKE version, encryption algorithms, authentication algorithms, Diffie-Hellman groups, and IP-Sec parameters) in the source eNB before handover. This pre-prepared security configuration is included in the X2 TNL Configuration Info message, allowing the target eNB to directly use these parameters without extensive negotiation, thereby preventing negotiation failures while maintaining process simplicity.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If complete security parameter negotiation is performed between eNBs, then security tunnel can be established reliably, but negotiation delays occur during handover

Engineering Contradiction:
Improvesecurity tunnel establishment success rateVSAvoidhandover time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent resolves this contradiction by performing the security parameter preparation in advance at the source eNB. The complete security parameter set is configured beforehand and transferred via the X2 TNL Configuration Info message during handover, eliminating the need for time-consuming real-time negotiation between eNBs while ensuring reliable security tunnel establishment.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses the MME and X2 TNL Configuration Info message as intermediaries to transfer pre-configured security parameters from the source eNB to the target eNB. This intermediary mechanism allows security parameters to be transferred efficiently without requiring direct real-time negotiation between eNBs, thus reducing handover time while maintaining security reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Speed

If security parameters are transmitted in plaintext during X2 link establishment, then transmission speed is fast, but data security is compromised

Engineering Contradiction:
Improvetransmission speedVSAvoiddata security risk
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The patent applies parameter changes by transforming the security parameters (IKE version, encryption algorithms, authentication algorithms, Diffie-Hellman groups, IP-Sec parameters) into an encrypted format within the X2 TNL Configuration Info message. This encryption transformation maintains fast transmission speed while protecting data security, as the parameters are securely encrypted during transfer between eNBs through the MME.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP2770778B1Method, system, and enb for establishing secure x2 channel
Publication Date: 2018.08.01 HUAWEI TECH CO LTD
  • EP2770778B1 patent drawingFigure 1~2
  • EP2770778B1 patent drawingFigure 3~4
  • EP2770778B1 patent drawingFigure 5~7

AI summary

A method, a system and a base station for establishing an X2 security tunnel are provided. When a user terminal is handed over from a cell covered by a base station to a cell covered by another base station, while sending a notification message to the another base station, the base station sends a security parameter set so that the another base station selects a security parameter value supported by the another base station, thereby sparing multiple times of negotiation, reducing problems caused by the negotiation, such as a delay or a failure to establish a security tunnel, and establishing an X2 security tunnel within a time tolerable for a communications handover. The method includes: sending, by a base station, a notification message to a peer base station, where the notification message includes a security parameter set; receiving a response message sent by the peer base station, where the response message includes a security parameter value selected by the peer base station from the security parameter set; and establishing an X2 security tunnel according to the response message.