Context-Based Security for O-RAN Interfaces
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Next Generation RAN (NG-RAN) and Open Radio Access Network (O-RAN) architectures in mobile networks are vulnerable to new security threats, particularly over interfaces like Xn-U and F1-U, where self-driving cars and industrial IoT devices can potentially attack or infect other devices, necessitating improved security techniques for monitoring and applying context-based security policies.
Innovation Solution
A security platform is configured to inspect XnAP and GTP-U traffic over specific interfaces, providing stateful inspection and layer 7 security capabilities to correlate contextual information with user plane traffic, enabling context-based security policies for NG-RAN and O-RAN environments, utilizing Next Generation Firewall technologies to enforce security policies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional firewall rules are applied to NG-RAN and O-RAN interfaces, then basic network security is provided, but context-based security threats from self-driving cars and industrial IoT devices cannot be effectively detected or prevented
Solution Approach 1:
The security platform performs preliminary actions by inspecting F1AP traffic and extracting contextual information before user plane traffic flows through the network. This proactive approach allows the system to establish security contexts and policies in advance, enabling effective detection and prevention of threats from self-driving cars and industrial IoT devices before they can execute malicious actions.
Solution Approach 2:
The security platform acts as an intermediary between the control plane and user plane in NG-RAN and O-RAN architectures. It intercepts and inspects F1AP traffic between O-DU and O-CU-CP, extracts contextual information, and uses this information to enforce security policies on user plane traffic. This intermediary position enables the platform to correlate control plane context with data plane traffic for comprehensive threat detection.
2Reliability
If security functions are implemented closer to users in NG-RAN and O-RAN environments, then selective industry vertical security and protection for sensitive locations is enhanced, but implementation complexity and resource requirements increase
Solution Approach 1:
The security platform implements local quality by providing customized security policies for different industry verticals and sensitive locations. It extracts contextual information from F1AP traffic and applies location-aware, application-aware, and user-aware security policies tailored to specific network segments. This allows enhanced security for government networks, power plants, and other sensitive locations while maintaining standard security elsewhere.
Solution Approach 2:
The security platform segments security enforcement into distinct functional modules: F1AP traffic inspection, context information extraction, security policy decision-making, and user plane traffic enforcement. This segmentation allows the system to handle different security requirements for different industry verticals and locations independently, reducing overall implementation complexity through modular design.
Data Source
AI summary
Techniques for applying context-based security over interfaces in O-RAN environments in mobile networks are disclosed. In some embodiments, a system/process/computer program product for applying context-based security over interfaces in O-RAN environments in mobile networks includes monitoring network traffic on a mobile network at a security platform to identify a GTP-U tunnel session setup message associated with a new session; extracting a plurality of parameters from the GTP-U tunnel session setup message and from F1AP traffic to extract contextual information at the security platform; and enforcing a security policy at the security platform on the new session based on one or more of the plurality of parameters to apply context-based security to the network traffic transported between O-RAN Distributed Unit (O-DU) and O-RAN Centralized Unit Control Plane (O-CU-CP) nodes in an O-RAN environment in the mobile network.


