IP Library › Granted Patent US 12,568,360
Granted Patent B2
US 12,568,360 · App. 18/427,313 · Granted Mar 3, 2026

Method for establishing secure transmission channel, key determining method, and communication apparatus

Inventors: Longhua Guo (Shanghai, CN); Yuanping Zhu (Shanghai, CN); Rong Wu (Shenzhen, CN)
Assignee: Huawei Technologies Co., Ltd.
H04W12/041H04W12/033H04W12/037H04W12/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,568,360
App. No.
18/427,313
Granted
Mar 3, 2026
Kind
B2
Abstract

This application provides a key determining method, and a communication apparatus. The method is applied to a donor node central unit which contains a control plane entity and a user plane entity, and the method includes: deriving a first key based on a root key, an internet protocol (IP) address of a distributed unit of an integrated access and backhaul node, and a first IP address of the user plane entity; and sending a first message to the user plane entity, wherein the first message comprises the first key. According to this application, a user plane secure transmission channel may be established between the user plane entity and the distributed unit based on the first key.

Claims (79)

1 . A key determining method applied to a donor node central unit containing a control plane entity and a user plane entity, the method comprising:

deriving, by the control plane entity, a first key based on a root key, an internet protocol (IP) address of a distributed unit of an integrated access and backhaul node, and a first IP address of the user plane entity,

wherein the first key is different from the root key, and

wherein the root key is a key obtained by the control plane entity from a network in a procedure in which the integrated access and backhaul node registers with the network; and

sending, by the control plane entity, a first message to the user plane entity,

wherein the first message comprises a one-to-one correspondence between the first key and the first IP address, and

wherein the first key and first IP address are for establishing a user plane secure transmission channel between the user plane entity and the distributed unit.

2 . The method according to claim 1 , further comprising:

sending, by the control plane entity, first indication information to the user plane entity; and

receiving, by the control plane entity, one or more IP addresses from the user plane entity,

wherein the one or more IP addresses comprise the first IP address.

3 . The method according to claim 2 , wherein the one or more IP addresses further comprises a second IP address, the method further comprises:

deriving, by the control plane entity, a second key based on the root key, the IP address of the distributed unit, and the second IP address,

wherein the first message comprises the one-to-one correspondence between the first key and the first IP address and a one-to-one correspondence between the second key and the second IP address.

4 . The method according to claim 1 , wherein the first key is KIAB, and the root key is KgNB.

5 . The method according to claim 1 further comprising:

deriving, by the control plane entity, a third key based on the root key, the IP address of the distributed unit, and an IP address of the control plane entity; and

establishing, by the control plane entity, a control plane secure transmission channel between the control plane entity and the distributed unit based on the third key.

6 . The method according to claim 1 further comprising:

receiving, by the user plane entity, the first message; and

establishing, by the user plane entity, a user plane secure transmission channel between the user plane entity and the distributed unit based on the first key and the first IP address.

7 . The method according to claim 6 , wherein the first message comprises a one-to-one correspondence between a plurality of IP addresses of the user plane entity and a plurality of keys, wherein the plurality of keys comprise the first key, and wherein the first key is corresponding to the first IP address; and the method further comprises:

determining, by the user plane entity, to establish the user plane secure transmission channel by using the first IP address; and

determining, by the user plane entity based on the one-to-one

correspondence that a key corresponding to the first IP address is the first key.

8 . The method according to claim 7 further comprising:

receiving, by the user plane entity, first indication information from the control plane entity; and

sending, by the user plane entity based on the first indication information, the plurality of IP addresses to the control plane entity.

9 . A system comprising a control plane entity of a donor node central unit and a user plane entity of the donor node central unit, wherein:

the control plane entity comprises at least one first processor and at least one first memory, and is configured to:

derive a first key based on a root key, an internet protocol (IP) address of a distributed unit of an integrated access and backhaul node, and a first IP address of the user plane entity,

wherein the first key is different from the root key, and

wherein the root key is a key obtained by the control plane entity from a network in a procedure in which the integrated access and backhaul node registers with the network;

send a first message to the user plane entity, wherein the first message comprises a one-to-one correspondence between the first key and the first IP address; and

the user plane entity comprises at least one second processor and at least one second memory, and is configured to:

receive the first message; and

establish a user plane secure transmission channel between the user plane entity and the distributed unit based on the first key and the first IP address.

10 . The system according to claim 9 , wherein the control plane entity is further configured to:

send first indication information to the user plane entity; and

receive one or more IP addresses of the user plane entity from the user plane entity, wherein the one or more IP addresses comprise the first IP address; and

the user plane entity is further configured to:

receive the first indication information from the control plane entity; and

send the one or more IP addresses to the control plane entity based on the first indication information.

11 . The system according to claim 10 , wherein the one or more IP addresses further comprises a second IP address, the control plane entity is further configured to derive a second key based on the root key, the IP address of the distributed unit, and the second IP address,

wherein the first message comprises the one-to-one correspondence between the first key and the first IP address and a one-to-one correspondence between the second key and the second IP address.

12 . The system according to claim 9 , wherein the control plane entity is further configured to:

derive a third key based on the root key, the IP address of the distributed unit, and an IP address of the control plane entity; and

establish a control plane secure transmission channel between the control plane entity and the distributed unit based on the third key.

13 . A control plane entity of a donor node central unit, wherein the donor node central unit further contains a user plane entity, and the control plane entity comprises:

a memory configured to store a computer program; and

a processor configured to invoke the computer program from the memory and run the computer program so as to enable the control plane entity to:

derive a first key based on a root key, an internet protocol (IP) address of a distributed unit of an integrated access and backhaul node, and a first IP address of the user plane entity,

wherein the first key is different from the root key, and

wherein the root key is a key obtained by the control plane entity from a network in a procedure in which the integrated access and backhaul node registers with the network; and

send a first message to the user plane entity,

wherein the first message comprises a one-to-one correspondence between the first key and the first IP address, and

wherein the first key and first IP address are for establishing a user plane secure transmission channel between the user plane entity and the distributed unit.

14 . The control plane entity according to claim 13 , wherein the processor is further configured to invoke the computer program from the memory and run the computer program to further enable the control plane entity to:

send first indication information to the user plane entity; and

receive one or more IP addresses from the user plane entity, wherein the one or more IP addresses comprise the first IP address.

15 . The control plane entity according to claim 14 , wherein the one or more IP addresses further comprises a second IP address, and the processor is further configured to invoke the computer program from the memory and run the computer program so as to further enable the control plane entity to derive a second key based on the root key, the IP address of the distributed unit, and the second IP address,

wherein the first message comprises the one-to-one correspondence between the first key and the first IP address and a one-to-one correspondence between the second key and the second IP address.

16 . The control plane entity according to claim 13 , wherein the processor is further configured to invoke the computer program from the memory and run the computer program to further enable the control plane entity to:

derive a third key based on the root key, the IP address of the distributed unit, and an IP address of the control plane entity; and

establish a control plane secure transmission channel between the control plane entity and the distributed unit based on the third key.

17 . A non-transitory computer-readable storage medium that stores a computer program and, based on the computer program run by a control plane entity of a donor node central unit, the control plane entity is enabled to:

derive a first key based on a root key, an internet protocol (IP) address of a distributed unit of an integrated access and backhaul node, and a first IP address of a user plane entity of the donor node central unit,

wherein the first key is different from the root key, and

wherein the root key is a key obtained from a network in a procedure in which the integrated access and backhaul node registers with the network; and

send a first message to the user plane entity,

wherein the first message comprises a one-to-one correspondence between the first key and the first IP address, and

wherein the first key and first IP address are for establishing a user plane secure transmission channel between the user plane entity and the distributed unit.

18 . The non-transitory computer-readable storage medium according to claim 17 , wherein upon the computer program being run by the control plane entity, the control plane entity is further enabled to:

send first indication information to the user plane entity; and

receive one or more IP addresses from the user plane entity, wherein the one or more IP addresses comprise the first IP address.

19 . The non-transitory computer-readable storage medium according to claim 17 , wherein the first key is KIAB, and the root key is KgNB.

20 . The non-transitory computer-readable storage medium according to claim 17 , wherein upon the computer program being run by the control plane entity, the control plane entity is further enabled to:

derive a third key based on the root key, the IP address of the distributed unit, and an IP address of the control plane entity; and

establish a control plane secure transmission channel between the control plane entity and the distributed unit based on the third key.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 8, 2025
From: GUO, LONGHUA; ZHU, YUANPING; WU, RONG
To: HUAWEI TECHNOLOGIES CO., LTD.
Reel/Frame 072179/0306 →
Priority Claims (1)
CN 202110877235.9 · Jul 31, 2021 · national
Continuity (2)
Continuation PCTCN2022108633 · Jul 28, 2022
Related Publication 20240171970A1 · May 23, 2024
References Cited (30)
US 10172042B2 · Zhang · 2019 [cited by examiner]
US 10455414B2 · Lee · 2019 [cited by examiner]
US 11523277B2 · Rajadurai · 2022 [cited by examiner]
US 12075243B2 · Rajadurai · 2024 [cited by examiner]
US 20130028139A1 · Sanneck · 2013 [cited by examiner]
US 20140160977A1 · Serbest · 2014 [cited by examiner]
US 20160127897A1 · Lee · 2016 [cited by examiner]
US 20200100102A1 · Xu · 2020 [cited by examiner]
US 20200120725A1 · Mildh · 2020 [cited by examiner]
US 20200396611A1 · Rajadurai · 2020 [cited by examiner]
US 20210058771A1 · Wu · 2021 [cited by examiner]
US 20210105622A1 · Rajadurai · 2021 [cited by applicant]
US 20230354023A1 · Rajadurai · 2023 [cited by examiner]
US 20240106705A1 · Pauliac · 2024 [cited by examiner]
CN 106375992A · 2017 [cited by applicant]
CN 110365470A · 2019 [cited by applicant]
CN 112399409A · 2021 [cited by applicant]
EP 3751817A1 · 2020 [cited by applicant]
WO 2020164506A1 · 2020 [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study on Security for NR Integrated Access and Backhaul; (Release 17),” 3GPP TR 33.824 V0.9.0, total 21 pages, 3rd Generati… [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Security architecture and procedures for 5G system (Release 16),” 3GPP TS 33.501 V16.7.1, total 255 pages, 3rd Generation P… [cited by applicant]
Huawei, Hisilicon, “Security for CU-CP and CU-UP split,” 3GPP TSG SA WG3 (Security) Meeting #90Bis, San Diego, USA, S3-180839, total 3 pages, 3rd Generation Partnership Project, Valbonne, France (Feb. 26-Mar. 2, 2018). [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Radio Access Network; Evolved Universal Terrestrial Radio Access Network(E-UTRAN); X2 application protocol (X2AP) (Release 16),” 3GPP TS 36.423 V16.5.0,… [cited by applicant]
CATT, “Discussion on Security of Multi-CU-UP connectivity,” 3GPP TSG-SA WG3 Meeting #97, Reno (US), S3-194138 revision of S3-19xabc, total 4 pages, 3rd Generation Partnership Project, Valbonne, France (Nov. 18-22, 2019). [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Radio Access Network; NG-RAN; Architecture description (Release 16),” 3GPP TS 38.401 V16.5.0, total 79 pages, 3rd Generation Partnership Project, Valbon… [cited by applicant]
Ericsson, “CU-UPs supported by DC,” 3GPP TSG-SA3 Meeting #100bis-e, e-meeting, S3-202592 Revision of S3-20xxxx, total 2 pages, 3rd Generation Partnership Project, Valbonne, France (Oct. 12-16, 2020). [cited by applicant]
Huawei, “Discussions on Security handling for CP-UP separation of IAB-donor,” 3GPP TSG-RAN WG3 Meeting #113-e, E-Meeting, R3-21xxxx, total 3 pages, 3rd Generation Partnership Project, Valbonne, France (Aug. 2021). [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study on Security for NR Integrated Access and Backhaul; (Release 17),” 3GPP Standard; Technical Report; 3GPP TR 33.824 V0.… [cited by applicant]
Huawei et al., “Security for CU-CP and CU-UP split,” 3GPP TSG WG3 (Security) Meeting #90Bis, S3-180839 Security-for-CU-CP-and-CU -UP-Split, 3rd Generation Partnership Project, Mobile Competence Centre; 650, Route Des Lu… [cited by applicant]
CATT, “Discussion on Security of Multi-CU-UP connectivity,” 3GPP TSG-SA WG3 Meeting #97, S3-194138, 3rd Generation Partnership Project, Mobile Competence Centre; 650, Route Deslucioles; F-06921 Sophia-Antipolis Cedex; F… [cited by applicant]