rApp/xApp 证明:O-RAN 的一个新安全用例
rApp/xApp Attestation: A New Security Use Case for O-RAN
浏览论文内容
中文总结 AI 辅助
针对O-RAN中rApp/xApp运行时完整性验证缺失的问题,提出RIC原生的证明用例,集成现有完整性验证技术,原型实验显示延迟低于40毫秒,不影响时敏操作。
中文摘要 AI 辅助
开放无线接入网(O-RAN)架构引入的分解化和软件化实现了多供应商创新,但也使RAN智能控制器(RIC)生态系统面临新的运行时安全风险。现有的O-RAN规范为接入、认证、身份管理和安全通信定义了强有力的保障措施;然而,它们并未提供具体机制来验证已部署的rApp和xApp在运行期间是否保持其预期的、未被篡改的状态。本文提出将rApp/xApp证明作为RIC原生的O-RAN安全用例,用于运行时完整性验证。该工作并非提出新的密码学协议,而是定义了如何通过证明模块、证明代理、RIC应用接口和SMO驱动的策略协调,将现有的完整性验证技术集成到O-RAN中。我们将该用例映射到相关的O-RAN联盟工作组,识别所需的标准扩展,并通过在Near-RT RIC平台上实现的轻量级基于哈希的原型展示其可行性。实验结果表明,在多种密码学哈希函数下,证明延迟低于40毫秒,表明在适当调度下,运行时证明可以在不干扰对时间敏感的RIC操作的情况下执行。最后,我们讨论了剩余的技术和标准化挑战,包括可信验证、已知良好运行时状态、可扩展性、缓解策略以及未来的混合证明机制。
英文摘要
The disaggregation and softwarization introduced by the Open Radio Access Network (O-RAN) architecture enable multi-vendor innovation but also expose the RAN Intelligent Controller (RIC) ecosystem to new runtime security risks. Existing O-RAN specifications define strong safeguards for onboarding, authentication, identity management, and secure communication; however, they do not provide a concrete mechanism for verifying whether deployed rApps and xApps remain in their intended, untampered state during operation. This paper introduces rApp/xApp attestation as a RIC-native O-RAN security use case for runtime integrity verification. Rather than proposing a new cryptographic protocol, the work defines how existing integrity verification techniques can be integrated into O-RAN through attestation modules, attestation agents, RIC application interfaces, and SMO-driven policy coordination. We map the use case to relevant O-RAN Alliance working groups, identify required standardization extensions, and demonstrate feasibility through a lightweight hash-based prototype implemented on the Near-RT RIC platform. Experimental results show attestation latencies below 40 ms across multiple cryptographic hash functions, indicating that runtime attestation can be performed without disrupting time-sensitive RIC operations when appropriately scheduled. Finally, we discuss remaining technical and standardization challenges, including trusted verification, known-good runtime states, scalability, mitigation policies, and future hybrid attestation mechanisms.
发表机构
- GIC, Institute for Communication Systems (ICS), University of Surrey(萨里大学通信系统研究所)
- Nokia(诺基亚)
- Department of Information and Electronic Engineering, International Hellenic University(国际赫尔基克大学信息与电子工程系)
机构由 AI 辅助整理,请以论文原文为准。