IP Library Granted Patent US 12666255
Granted Patent B2
US 12666255 · App. 17/911,682 · Granted Jun 23, 2026

Selective user plane protection in 5G virtual RAN

Inventors: Stere Preda (Longueuil, CA); Daniel Migault (Montreal, CA); Amine Boukhtouta (Laval, CA); Xiaowen Yue (Herzogenrath, DE)
Assignee: Telefonaktiebolaget LM Ericsson (publ)
H04W12/033G06F21/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12666255
App. No.
17/911,682
Granted
Jun 23, 2026
Kind
B2
Abstract

Systems and methods for selective User Plane protection in a 5G virtual RAN are provided. A method performed by a gNB Central Unit (gNB-CU) for communicating with a gNB-Distributed Unit (gNB-DU) includes determining whether to selectively encrypt a PDU to be sent to the gNB-DU if the PDU is not otherwise encrypted. In response to determining to selectively encrypt, the method includes encrypting the PDU to be sent to the gNB-DU. In response to determining to not selectively encrypt, the method includes passing the PDU to be sent to the gNB-DU. In this way, additional security is provided while performance impact is minimized. In some embodiments, this provides a lower overhead on the gNB-CU-UP side compared to applying a generic protection of all PDUs. Additionally, the latency overhead is limited since a secure session establishment and handshake is confined to the gNB-CU-UP-SEG domain instead of gNB-CU-UP to gNB-DU.

Claims (68)

1 . A method performed by a gNB Central Unit, gNB-CU, for communicating with a gNB-Distributed Unit, gNB-DU, the method comprising:

determining, by the gNB-CU, whether to selectively encrypt a Protocol Data Unit, PDU, to be sent, by the gNB-CU, to the gNB-DU if the PDU is not otherwise encrypted;

in response to determining to selectively encrypt the PDU to be sent to the gNB-DU, encrypting, by the gNB-CU, the PDU to be sent to the gNB-DU;

in response to determining to not selectively encrypt the PDU to be sent to the gNB-DU, passing, by the gNB-CU, the PDU to be sent to the gNB-DU; and

transmitting, by the gNB-CU, the PDU to be sent to the gNB-DU;

wherein transmitting the PDU to be sent to the gNB-DU comprises:

transmitting the PDU to an Internet Protocol Security, IPsec, Security Gateway, SEG, for transmission to the gNB-DU.

2 . The method of claim 1 wherein:

the gNB-CU comprises a first multiplexer, MUX, and;

transmitting the PDU to the IPsec SEG comprises transmitting the PDU from the first MUX to a second MUX in the IPsec SEG.

3 . The method of claim 1 wherein:

determining whether to selectively encrypt the PDU to be sent to the gNB-DU comprises determining to selectively encrypt the PDU if one or more of the group consisting of:

the PDU comprises “type=0” and “User data existence flag=0”; and

the PDU comprises: “type=0”; “User data existence flag=1”; and the PDU is a Packet Data Convergence Protocol, PDCP, Control PDU.

4 . The method of claim 1 wherein:

determining whether a PDU received from the gNB-DU was selectively encrypted;

in response to determining the received PDU was selectively encrypted, decrypting the received PDU to be sent to the gNB-CU.

5 . The method of claim 1 wherein the received PDU is received from the IPsec SEG.

6 . The method of claim 5 wherein:

receiving the received PDU from the IPsec SEG comprises receiving the received PDU by the first MUX from the second MUX in the IPsec SEG.

7 . The method of claim 1 wherein a secure session is established between the gNB-CU and the IPsec SEG.

8 . The method of claim 7 wherein the secure session between the gNB-CU and the IPsec SEG is established when one of the group consisting of:

a first PDCP instance created in the gNB-CU;

on demand;

upon signaling from the gNB-CU;

upon setting up an interface between a gNB-CU User Plane (gNB-CU-UP) and a gNB-CU Control Plane (gNB-CU-CP), E1;

upon setting up an interface between the gNB-CU and the gNB-DU, F1; and

at creation of the gNB-CU-UP.

9 . The method of claim 1 wherein encrypting the PDU to be sent to the gNB-DU comprises encrypting the PDU using a symmetric encryption key.

10 . The method of claim 4 wherein encrypting the PDU uses a first encryption key and decrypting the received PDU uses a second encryption key where the first encryption key is different than the second encryption key.

11 . The method of claim 1 wherein the gNB-CU operates in a first container.

12 . The method of claim 11 wherein the first MUX operates in the first container.

13 . The method of claim 12 wherein:

the first MUX operates in a second container; and

the first container and the second container operate in a same pod.

14 . A method performed by an Internet Protocol Security, IPsec, Security Gateway, SEG, for facilitating communication between a gNB-Distributed Unit, gNB-DU and a gNB Central Unit, gNB-CU, the method comprising:

determining, by the IPsec SEG, whether to selectively encrypt a Protocol Data Unit, PDU, to be sent to the gNB-CU from the gNB-DU if the PDU is not otherwise encrypted;

in response to determining to selectively encrypt the PDU to be sent to the gNB-CU, encrypting, by the IPsec SEG, the PDU to be sent to the gNB-CU;

in response to determining to not selectively encrypt the PDU to be sent to the gNB-CU, passing, by the IPsec SEG, the PDU to be sent to the gNB-CU; and

transmitting, by the IPsec SEG, the PDU to the gNB-CU.

15 . The method of claim 14 wherein:

the IPsec SEG comprises a first multiplexer, MUX, and;

transmitting the PDU to the gNB-CU comprises transmitting the PDU from the first MUX to a second MUX in the gNB-CU.

16 . The method of claim 14 wherein:

determining whether to selectively encrypt the PDU to be sent to the gNB-CU comprises determining to selectively encrypt the PDU if one or more of the group consisting of:

the PDU is a Radio Link Control, RLC,-to-Packet Data Convergence Protocol, PDCP, indication;

the PDU comprises “type=0” and “User data existence flag=0”;

the PDU comprises: “type=0”; “User data existence flag=1”; and the PDU is a PDCP Control PDU;

the PDU is a PDCP Control PDU;

the PDU is a Downlink, DL, Data Delivery Status indication; and

the PDU is an Assistance Information Data indication.

17 . The method of claim 14 wherein:

determining whether a PDU received from the gNB-CU was selectively encrypted;

in response to determining the received PDU was selectively encrypted, decrypting the received PDU to be sent to the gNB-DU.

18 . A processing node for implementing a gNB Central Unit, gNB-CU, for communicating with a gNB-Distributed Unit, gNB-DU, the processing node comprising:

one or more processors; and

memory comprising instructions to cause the processing node to:

determine, by the gNB-CU, whether to selectively encrypt a Protocol Data Unit, PDU, to be sent to the gNB-DU if the PDU is not otherwise encrypted;

in response to determining to selectively encrypt the PDU to be sent to the gNB-DU, encrypt, by the gNB-CU, the PDU to be sent to the gNB-DU;

in response to determining to not selectively encrypt the PDU to be sent to the gNB-DU, pass, by the gNB-CU, the PDU to be sent to the gNB-DU;

transmit, by the gNB-CU, the PDU to be sent to the gNB-DU.

19 . A processing node for implementing an Internet Protocol Security, IPsec, Security Gateway, SEG, for facilitating communication between a gNB-Distributed Unit, gNB-DU and a gNB Central Unit, gNB-CU, the processing node comprising:

one or more processors; and

memory comprising instructions to cause the processing node to:

determine, by the IPsec SEG, whether to selectively encrypt a Protocol Data Unit, PDU, to be sent to the gNB-CU from the gNB-DU if the PDU is not otherwise encrypted;

in response to determining to selectively encrypt the PDU to be sent to the gNB-CU, encrypt, by the IPsec SEG, the PDU to be sent to the gNB-CU;

in response to determining to not selectively encrypt the PDU to be sent to the gNB-CU, pass, by the IPsec SEG, the PDU to be sent to the gNB-CU; and

transmit, by the IPsec SEG, the PDU to the gNB-CU.