Transport Security Considerations for the Open-RAN Fronthaul

Transport Security Considerations for the Open-RAN Fronthaul
复制标题

Open-RAN 前传的传输安全注意事项

DOI:
10.1109/5gwf52925.2021.00051
复制
发表时间:
2021
期刊:
2021 IEEE 4th 5G World Forum (5GWF)
影响因子:
--
通讯作者:
M. Berger
M. Berger
中科院分区:
--
文献类型:
--
作者:
Daniel Dik;M. Berger

文献摘要

被引文献

相似文献

Open-RAN前传受到严格的高性能要求的限制。它通过以太网在无线电单元和分布式单元之间传输非常敏感的数据,包括控制,用户,同步和管理数据包。基于前传接口中每个数据平面的各种漏洞,它可能会受到不同类型的威胁,这些威胁会危及网络及其服务的用户的操作。因此,迫切需要安全机制来保护基于四个安全支柱的Open-RAN前传:机密性,完整性,真实性和可用性。MACsec是一个标准的安全协议,它具有这四个安全特性。它在数据链路层中运行,因此与在更高层中运行的其他安全协议(如SSL)相比,它具有高性能优势。因此,本文提出MACsec是Open-RAN前传保护的一个有说服力的潜在解决方案。然而,其对保护前传中的每种分组类型的适用性需要进一步的独立分析,因为在Open-RAN前传中存在不同的性能要求和网络架构部署,这可能限制MACsec的使用。
The Open-RAN Fronthaul is constrained by strict high performance requirements. It transports very sensitive data over Ethernet between Radio Units and Distributed Units, including Control, User, Synchronization and Management packets. Based on the various vulnerabilities of each data plane in the fronthaul interface, it may be exposed to different types of threats that compromise the operation of the network and the users it serves. Therefore, there is an urgent need of security mechanisms to protect the Open-RAN Fronthaul based on the four pillars of security: Confidentiality, Integrity, Authenticity, and Availability. MACsec is a standard security protocol that possesses these four security features. It operates in the data-link layer and therefore provides high performance advantages over other security protocols that functions in higher layers, such as IPsec. For this reason, this paper proposes that MACsec is a persuasive potential solution for the Open-RAN Fronthaul protection. However, its applicability to secure each packet type in the fronthaul requires further independent analysis as there exists different performance requirements and network architectural deployments in the Open-RAN Fronthaul that could limit the use of MACsec.