X2 Switch for Secure 3GPP LTE Traffic Routing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Managing secure X2 interface traffic in 3GPP LTE networks becomes complex and costly as the number of eNBs increases, requiring each eNB to maintain multiple secure connections with others in a full mesh configuration.
Innovation Solution
Implementing an X2 switching network element (X2 switch) that maintains secured tunnels with each eNB, allowing eNBs to encrypt and tunnel packets through the X2 switch, reducing the need for direct secured connections between eNBs by using IPSec tunnels for secure communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If each eNB maintains secure connections with all other eNBs in a full mesh configuration, then secure communication is ensured between all eNBs, but the system complexity and cost increase significantly as the number of eNBs grows
Solution Approach 1:
The patent introduces a central controller as an intermediary that establishes secure connections with all eNBs instead of requiring direct secure connections between every pair of eNBs. The central controller acts as a trusted mediator that can securely route and manage X2 interface traffic between eNBs, thereby reducing the number of secure connections from O(N^2) in a full mesh to O(N) with the intermediary, while maintaining security through the central controller's authentication and encryption mechanisms.
2Reliability
If each eNB maintains secure connections with all other eNBs in a full mesh configuration, then secure communication is ensured between all eNBs, but the cost of maintaining multiple secure connections becomes very high
Solution Approach 1:
The patent merges the security management function into a single central controller that handles authentication, key management, and secure connection establishment for all eNBs. Instead of each eNB independently maintaining multiple secure connections, the security infrastructure is consolidated in the central controller, which can efficiently manage secure communications with multiple eNBs using shared security contexts and centralized key management, thereby reducing the overall cost of secure communication infrastructure.
3Reliability
If a full mesh configuration is used for secure X2 traffic, then direct secure communication between eNBs is achieved, but the configuration becomes complicated and difficult to manage as more eNBs are involved
Solution Approach 1:
The central controller serves as a managing intermediary that centralizes the configuration, monitoring, and control of all secure X2 connections. Instead of requiring operators to manually configure and manage O(N^2) direct connections between eNBs, the central controller provides a single point of management where all secure connections are established, configured, and monitored centrally. This dramatically simplifies operations and maintenance while maintaining the same security level.
Data Source
AI summary
A network element is configured to receive a first packet from a first eNodeB (eNB) of the packet network via a first secured X2 link. The network element decrypts the first packet to reveal a second packet encapsulated within the first packet. The network element determines a second secured X2 link associated with a second eNB as an intended recipient of the second packet. The network element encrypts the second packet to generate a third packet and transmits the third packet to the second eNB via the second secured X2 link. The network is coupled to various eNBs of the packet network via various secured X2 links, respectively.


