Selective user plane protection in 5G virtual RAN
Systems and methods for selective User Plane protection in a 5G virtual RAN are provided. A method performed by a gNB Central Unit (gNB-CU) for communicating with a gNB-Distributed Unit (gNB-DU) includes determining whether to selectively encrypt a PDU to be sent to the gNB-DU if the PDU is not otherwise encrypted. In response to determining to selectively encrypt, the method includes encrypting the PDU to be sent to the gNB-DU. In response to determining to not selectively encrypt, the method includes passing the PDU to be sent to the gNB-DU. In this way, additional security is provided while performance impact is minimized. In some embodiments, this provides a lower overhead on the gNB-CU-UP side compared to applying a generic protection of all PDUs. Additionally, the latency overhead is limited since a secure session establishment and handshake is confined to the gNB-CU-UP-SEG domain instead of gNB-CU-UP to gNB-DU.
1 . A method performed by a gNB Central Unit, gNB-CU, for communicating with a gNB-Distributed Unit, gNB-DU, the method comprising:
determining, by the gNB-CU, whether to selectively encrypt a Protocol Data Unit, PDU, to be sent, by the gNB-CU, to the gNB-DU if the PDU is not otherwise encrypted;
in response to determining to selectively encrypt the PDU to be sent to the gNB-DU, encrypting, by the gNB-CU, the PDU to be sent to the gNB-DU;
in response to determining to not selectively encrypt the PDU to be sent to the gNB-DU, passing, by the gNB-CU, the PDU to be sent to the gNB-DU; and
transmitting, by the gNB-CU, the PDU to be sent to the gNB-DU;
wherein transmitting the PDU to be sent to the gNB-DU comprises:
transmitting the PDU to an Internet Protocol Security, IPsec, Security Gateway, SEG, for transmission to the gNB-DU.
2 . The method of claim 1 wherein:
the gNB-CU comprises a first multiplexer, MUX, and;
transmitting the PDU to the IPsec SEG comprises transmitting the PDU from the first MUX to a second MUX in the IPsec SEG.
3 . The method of claim 1 wherein:
determining whether to selectively encrypt the PDU to be sent to the gNB-DU comprises determining to selectively encrypt the PDU if one or more of the group consisting of:
the PDU comprises “type=0” and “User data existence flag=0”; and
the PDU comprises: “type=0”; “User data existence flag=1”; and the PDU is a Packet Data Convergence Protocol, PDCP, Control PDU.
4 . The method of claim 1 wherein:
determining whether a PDU received from the gNB-DU was selectively encrypted;
in response to determining the received PDU was selectively encrypted, decrypting the received PDU to be sent to the gNB-CU.
5 . The method of claim 1 wherein the received PDU is received from the IPsec SEG.
6 . The method of claim 5 wherein:
receiving the received PDU from the IPsec SEG comprises receiving the received PDU by the first MUX from the second MUX in the IPsec SEG.
7 . The method of claim 1 wherein a secure session is established between the gNB-CU and the IPsec SEG.
8 . The method of claim 7 wherein the secure session between the gNB-CU and the IPsec SEG is established when one of the group consisting of:
a first PDCP instance created in the gNB-CU;
on demand;
upon signaling from the gNB-CU;
upon setting up an interface between a gNB-CU User Plane (gNB-CU-UP) and a gNB-CU Control Plane (gNB-CU-CP), E1;
upon setting up an interface between the gNB-CU and the gNB-DU, F1; and
at creation of the gNB-CU-UP.
9 . The method of claim 1 wherein encrypting the PDU to be sent to the gNB-DU comprises encrypting the PDU using a symmetric encryption key.
10 . The method of claim 4 wherein encrypting the PDU uses a first encryption key and decrypting the received PDU uses a second encryption key where the first encryption key is different than the second encryption key.
11 . The method of claim 1 wherein the gNB-CU operates in a first container.
12 . The method of claim 11 wherein the first MUX operates in the first container.
13 . The method of claim 12 wherein:
the first MUX operates in a second container; and
the first container and the second container operate in a same pod.
14 . A method performed by an Internet Protocol Security, IPsec, Security Gateway, SEG, for facilitating communication between a gNB-Distributed Unit, gNB-DU and a gNB Central Unit, gNB-CU, the method comprising:
determining, by the IPsec SEG, whether to selectively encrypt a Protocol Data Unit, PDU, to be sent to the gNB-CU from the gNB-DU if the PDU is not otherwise encrypted;
in response to determining to selectively encrypt the PDU to be sent to the gNB-CU, encrypting, by the IPsec SEG, the PDU to be sent to the gNB-CU;
in response to determining to not selectively encrypt the PDU to be sent to the gNB-CU, passing, by the IPsec SEG, the PDU to be sent to the gNB-CU; and
transmitting, by the IPsec SEG, the PDU to the gNB-CU.
15 . The method of claim 14 wherein:
the IPsec SEG comprises a first multiplexer, MUX, and;
transmitting the PDU to the gNB-CU comprises transmitting the PDU from the first MUX to a second MUX in the gNB-CU.
16 . The method of claim 14 wherein:
determining whether to selectively encrypt the PDU to be sent to the gNB-CU comprises determining to selectively encrypt the PDU if one or more of the group consisting of:
the PDU is a Radio Link Control, RLC,-to-Packet Data Convergence Protocol, PDCP, indication;
the PDU comprises “type=0” and “User data existence flag=0”;
the PDU comprises: “type=0”; “User data existence flag=1”; and the PDU is a PDCP Control PDU;
the PDU is a PDCP Control PDU;
the PDU is a Downlink, DL, Data Delivery Status indication; and
the PDU is an Assistance Information Data indication.
17 . The method of claim 14 wherein:
determining whether a PDU received from the gNB-CU was selectively encrypted;
in response to determining the received PDU was selectively encrypted, decrypting the received PDU to be sent to the gNB-DU.
18 . A processing node for implementing a gNB Central Unit, gNB-CU, for communicating with a gNB-Distributed Unit, gNB-DU, the processing node comprising:
one or more processors; and
memory comprising instructions to cause the processing node to:
determine, by the gNB-CU, whether to selectively encrypt a Protocol Data Unit, PDU, to be sent to the gNB-DU if the PDU is not otherwise encrypted;
in response to determining to selectively encrypt the PDU to be sent to the gNB-DU, encrypt, by the gNB-CU, the PDU to be sent to the gNB-DU;
in response to determining to not selectively encrypt the PDU to be sent to the gNB-DU, pass, by the gNB-CU, the PDU to be sent to the gNB-DU;
transmit, by the gNB-CU, the PDU to be sent to the gNB-DU.
19 . A processing node for implementing an Internet Protocol Security, IPsec, Security Gateway, SEG, for facilitating communication between a gNB-Distributed Unit, gNB-DU and a gNB Central Unit, gNB-CU, the processing node comprising:
one or more processors; and
memory comprising instructions to cause the processing node to:
determine, by the IPsec SEG, whether to selectively encrypt a Protocol Data Unit, PDU, to be sent to the gNB-CU from the gNB-DU if the PDU is not otherwise encrypted;
in response to determining to selectively encrypt the PDU to be sent to the gNB-CU, encrypt, by the IPsec SEG, the PDU to be sent to the gNB-CU;
in response to determining to not selectively encrypt the PDU to be sent to the gNB-CU, pass, by the IPsec SEG, the PDU to be sent to the gNB-CU; and
transmit, by the IPsec SEG, the PDU to the gNB-CU.