论文标题
使用可扩展的授权框架来确保5G OpenRan的XAPPS
Securing 5G OpenRAN with a Scalable Authorization Framework for xApps
论文作者
论文摘要
移动网络从专有物理网络框到虚拟化功能和部署模型的持续转换导致了更具可扩展和灵活的网络体系结构,能够适应特定的用例。作为该机芯的推动者,OpenRAN倡议促进了标准化,从而允许使用Open API建立供应商中性无线电访问网络。此外,O-Ran联盟已开始符合Openran的定义的规范工作。这包括近实时RAN智能控制器(RIC)监督一组可扩展应用程序(XAPPS)。这些潜在不受信任的第三方应用程序的使用为移动网络平面引入了新的攻击表面,其基本安全性和系统设计要求尚待解决。为了保护5G O-RAN XAPP模型,我们介绍了XAPP存储库功能(XRF)框架,该框架实现了XAPP的可扩展身份验证,授权和发现。我们首先介绍该框架的系统设计和实施细节,然后在生产级集装箱环境中进行操作基准。评估结果以主动处理和操作时间为中心,表明我们提出的框架可以在多线程的Kubernetes微服务环境中有效地扩展,并支持大量具有最小开销的客户。
The ongoing transformation of mobile networks from proprietary physical network boxes to virtualized functions and deployment models has led to more scalable and flexible network architectures capable of adapting to specific use cases. As an enabler of this movement, the OpenRAN initiative promotes standardization allowing for a vendor-neutral radio access network with open APIs. Moreover, the O-RAN Alliance has begun specification efforts conforming to OpenRAN's definitions. This includes the near-real-time RAN Intelligent Controller (RIC) overseeing a group of extensible applications (xApps). The use of these potentially untrusted third-party applications introduces a new attack surface to the mobile network plane with fundamental security and system design requirements that are yet to be addressed. To secure the 5G O-RAN xApp model, we introduce the xApp Repository Function (XRF) framework, which implements scalable authentication, authorization, and discovery for xApps. We first present the framework's system design and implementation details, followed by operational benchmarks in a production-grade containerized environment. The evaluation results, centered on active processing and operation times, show that our proposed framework can scale efficiently in a multi-threaded Kubernetes microservice environment and support a large number of clients with minimal overhead.