This solution addresses the key issue #3.1: F1 interface security for IAB.
The control plane signalling between the IAB node and the IAB-donor node is confidentiality, integrity and replay protected in an end-to-end manner in the same way as the wireline fronthaul control (F1-C) protection using IPsec ESP and IKEv2 as specified in
TS 33.501. Alternatively, the F1-C interface could be protected using DTLS.
Figure 6.3.2-1 shows the protocol stack when IPsec is used for F1-C protection.
The user plane traffic between the IAB node and the IAB-donor node is confidentiality, integrity and replay protected in an end-to-end manner in the same way as the wireline fronthaul user plane (F1-U) protection specified in
TS 33.501. F1-U is used to transport traffic between UE and CU that is protected in PDCP layer as shown in
Figure 6.3.1.2-2.
The solution provides confidentiality and integrity protection of both control plane (i.e., F1-C) and user plane (i.e., F1-U) interfaces between the IAB node and IAB-donor, in an end-to-end manner. Therefore, the solution fulfils the potential security requirements of KI #3.1.
Furthermore, the solution allows to reuse the F1 security protocols for the wireline F1 interface as specified in
TS 33.501. This simplifies the handling of the security in an environment that supports both wireline F1 interface and wireless F1 interface as the same security protocol is used for both interfaces.