开放前传上的滴答声:保障O-RAN中的同步安全
Tick-Tock on the Open Fronthaul: Securing Synchronization in O-RAN
- Purdue University(普渡大学)
- The University of Texas at Dallas(德克萨斯大学达拉斯分校)
机构由 AI 辅助整理,请以论文原文为准。
AI总结:
本文针对O-RAN开放前传中PTP同步缺乏认证的问题,提出轻量级保护机制PRTESLA-C,结合延迟密钥披露与ASCON认证,在保持亚微秒精度的同时抵御欺骗、重放和延迟操纵攻击。
AI中文摘要:
精确时间协议(PTP)为分解式开放无线接入网(O-RAN)提供所需的时间和相位同步。然而,在当前的开放前传部署中,PTP流量缺乏强制性的认证和完整性保护,使得同步易受欺骗、重放和延迟操纵攻击的影响,这些攻击可能降低无线接入性能。现有保护措施不适合此场景:它们要么增加过多延迟,要么无法高效支持组播分发,要么在部分可信的RU下无法控制密钥泄露。本文分析了未受保护的O-RAN PTP的安全风险,并为开放前传部署制定了威胁模型。随后,我们引入了PRTESLA-C,一种轻量级同步保护机制,该机制将每轮延迟密钥披露与基于ASCON的消息认证相结合。PRTESLA-C采用先应用后验证并纠正的范式:时间样本立即应用以保持实时控制,在密钥披露后进行验证,若认证失败则从持久同步状态中移除。该设计保持了亚微秒级的同步精度,提供了针对欺骗和重放的强保护,并以最小的计算和延迟开销限制了延迟操纵的影响。
英文摘要:
The Precision Time Protocol (PTP) provides the time and phase synchronization required by disaggregated Open Radio Access Networks (O-RAN). Yet, in current open fronthaul deployments, PTP traffic lacks mandatory authentication and integrity protection, leaving synchronization vulnerable to spoofing, replay, and delay manipulation attacks that can degrade radio access performance. Existing protections are poorly suited to this setting: they either add excessive latency, do not support multicast dissemination efficiently, or fail to contain key exposure under partially trusted RUs. This paper analyzes the security risks of unprotected O-RAN PTP and develops a threat model for open fronthaul deployments. We then introduce PRTESLA-C, a lightweight synchronization protection mechanism that combines per-round delayed key disclosure with ASCON-based message authentication. PRTESLA-C uses an apply-then-verify-and-correct paradigm: timing samples are applied immediately to preserve real-time control, verified after key disclosure, and removed from persistent synchronization state if authentication fails. This design maintains sub-microsecond synchronization accuracy, provides strong protection against spoofing and replay, and bounds the impact of delay manipulation with minimal computational and latency overhead.