X2 Switch for Secure 3GPP LTE Traffic Routing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing secure X2 interface traffic in 3GPP LTE networks becomes complex and costly as the number of eNBs increases, requiring each eNB to maintain multiple secure connections with others in a full mesh configuration.

Innovation Solution

Implementing an X2 switching network element (X2 switch) that maintains secured tunnels with each eNB, allowing eNBs to encrypt and tunnel packets through the X2 switch, reducing the need for direct secured connections between eNBs by using IPSec tunnels for secure communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If each eNB maintains secure connections with all other eNBs in a full mesh configuration, then secure communication is ensured between all eNBs, but the system complexity and cost increase significantly as the number of eNBs grows

Engineering Contradiction:
Improvesecure communicationVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a central controller as an intermediary that establishes secure connections with all eNBs instead of requiring direct secure connections between every pair of eNBs. The central controller acts as a trusted mediator that can securely route and manage X2 interface traffic between eNBs, thereby reducing the number of secure connections from O(N^2) in a full mesh to O(N) with the intermediary, while maintaining security through the central controller's authentication and encryption mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If each eNB maintains secure connections with all other eNBs in a full mesh configuration, then secure communication is ensured between all eNBs, but the cost of maintaining multiple secure connections becomes very high

Engineering Contradiction:
Improvesecure communicationVSAvoidcost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent merges the security management function into a single central controller that handles authentication, key management, and secure connection establishment for all eNBs. Instead of each eNB independently maintaining multiple secure connections, the security infrastructure is consolidated in the central controller, which can efficiently manage secure communications with multiple eNBs using shared security contexts and centralized key management, thereby reducing the overall cost of secure communication infrastructure.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If a full mesh configuration is used for secure X2 traffic, then direct secure communication between eNBs is achieved, but the configuration becomes complicated and difficult to manage as more eNBs are involved

Engineering Contradiction:
Improvesecure communicationVSAvoidmanageability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The central controller serves as a managing intermediary that centralizes the configuration, monitoring, and control of all secure X2 connections. Instead of requiring operators to manually configure and manage O(N^2) direct connections between eNBs, the central controller provides a single point of management where all secure connections are established, configured, and monitored centrally. This dramatically simplifies operations and maintenance while maintaining the same security level.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8837365B2Method and system for securely routing traffic on X2 interface in a 3GPP network
Publication Date: 2014.09.16 MAVENIR US INC
  • US8837365B2 patent drawing
  • US8837365B2 patent drawing
  • US8837365B2 patent drawing

AI summary

A network element is configured to receive a first packet from a first eNodeB (eNB) of the packet network via a first secured X2 link. The network element decrypts the first packet to reveal a second packet encapsulated within the first packet. The network element determines a second secured X2 link associated with a second eNB as an intended recipient of the second packet. The network element encrypts the second packet to generate a third packet and transmits the third packet to the second eNB via the second secured X2 link. The network is coupled to various eNBs of the packet network via various secured X2 links, respectively.