Context-Based Security for O-RAN Interfaces

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Next Generation RAN (NG-RAN) and Open Radio Access Network (O-RAN) architectures in mobile networks are vulnerable to new security threats, particularly over interfaces like Xn-U and F1-U, where self-driving cars and industrial IoT devices can potentially attack or infect other devices, necessitating improved security techniques for monitoring and applying context-based security policies.

Innovation Solution

A security platform is configured to inspect XnAP and GTP-U traffic over specific interfaces, providing stateful inspection and layer 7 security capabilities to correlate contextual information with user plane traffic, enabling context-based security policies for NG-RAN and O-RAN environments, utilizing Next Generation Firewall technologies to enforce security policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional firewall rules are applied to NG-RAN and O-RAN interfaces, then basic network security is provided, but context-based security threats from self-driving cars and industrial IoT devices cannot be effectively detected or prevented

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidsecurity platform complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security platform performs preliminary actions by inspecting F1AP traffic and extracting contextual information before user plane traffic flows through the network. This proactive approach allows the system to establish security contexts and policies in advance, enabling effective detection and prevention of threats from self-driving cars and industrial IoT devices before they can execute malicious actions.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The security platform acts as an intermediary between the control plane and user plane in NG-RAN and O-RAN architectures. It intercepts and inspects F1AP traffic between O-DU and O-CU-CP, extracts contextual information, and uses this information to enforce security policies on user plane traffic. This intermediary position enables the platform to correlate control plane context with data plane traffic for comprehensive threat detection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security functions are implemented closer to users in NG-RAN and O-RAN environments, then selective industry vertical security and protection for sensitive locations is enhanced, but implementation complexity and resource requirements increase

Engineering Contradiction:
Improvesecurity protection for sensitive locationsVSAvoidsecurity platform implementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security platform implements local quality by providing customized security policies for different industry verticals and sensitive locations. It extracts contextual information from F1AP traffic and applies location-aware, application-aware, and user-aware security policies tailored to specific network segments. This allows enhanced security for government networks, power plants, and other sensitive locations while maintaining standard security elsewhere.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The security platform segments security enforcement into distinct functional modules: F1AP traffic inspection, context information extraction, security policy decision-making, and user plane traffic enforcement. This segmentation allows the system to handle different security requirements for different industry verticals and locations independently, reducing overall implementation complexity through modular design.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11943620B2Context-based security over interfaces in O-RAN environments in mobile networks
Publication Date: 2024.03.26 PALO ALTO NETWORKS INC
  • US11943620B2 patent drawing
  • US11943620B2 patent drawing
  • US11943620B2 patent drawing

AI summary

Techniques for applying context-based security over interfaces in O-RAN environments in mobile networks are disclosed. In some embodiments, a system/process/computer program product for applying context-based security over interfaces in O-RAN environments in mobile networks includes monitoring network traffic on a mobile network at a security platform to identify a GTP-U tunnel session setup message associated with a new session; extracting a plurality of parameters from the GTP-U tunnel session setup message and from F1AP traffic to extract contextual information at the security platform; and enforcing a security policy at the security platform on the new session based on one or more of the plurality of parameters to apply context-based security to the network traffic transported between O-RAN Distributed Unit (O-DU) and O-RAN Centralized Unit Control Plane (O-CU-CP) nodes in an O-RAN environment in the mobile network.