The disaggregation that makes Open RAN attractive replaces the sealed base station with a multi-vendor software ecosystem, yet its security baseline still protects the boundary far more thoroughly than what happens inside it: once a third-party application is onboarded and a protected channel established, its subsequent actions on the RAN go essentially unchecked. Zero trust is the natural remedy, but it collides with the hard real-time budgets of the RAN control loop, and this collision has not been quantified. We identify four east-west attack paths that perimeter-oriented protection leaves open, and map the zero-trust primitives of workload identity, per-message authorization, and continuous attestation onto the O-RAN interfaces. Where prior work has measured the cost of encrypting O-RAN interfaces, we measure the cost of authorizing each action. On an O-RAN Software Community Near-RT RIC, authorization evaluated at a remote decision point inflates the 99th-percentile E2 loop latency to 14.2 ms and pushes 4% of transactions past the 10 ms deadline. Co-locating policy evaluation with the enforcement point and bounding decision staleness returns the 99th percentile to 7.5 ms while holding post-revocation exposure below 625 ms. The security-latency trade-off is therefore an operator-tunable parameter rather than an architectural absolute, and we close with guidelines for selecting an operating point.
Zero Trust Meets the Real-Time Loop: The Latency Price of Never Trusting Anything in the O-Cloud / Riggio, R.. - In: IEEE NETWORK. - ISSN 0890-8044. - (2026). [Epub ahead of print] [10.1109/mnet.2026.3732160]
Zero Trust Meets the Real-Time Loop: The Latency Price of Never Trusting Anything in the O-Cloud
Riggio, Roberto
2026-01-01
Abstract
The disaggregation that makes Open RAN attractive replaces the sealed base station with a multi-vendor software ecosystem, yet its security baseline still protects the boundary far more thoroughly than what happens inside it: once a third-party application is onboarded and a protected channel established, its subsequent actions on the RAN go essentially unchecked. Zero trust is the natural remedy, but it collides with the hard real-time budgets of the RAN control loop, and this collision has not been quantified. We identify four east-west attack paths that perimeter-oriented protection leaves open, and map the zero-trust primitives of workload identity, per-message authorization, and continuous attestation onto the O-RAN interfaces. Where prior work has measured the cost of encrypting O-RAN interfaces, we measure the cost of authorizing each action. On an O-RAN Software Community Near-RT RIC, authorization evaluated at a remote decision point inflates the 99th-percentile E2 loop latency to 14.2 ms and pushes 4% of transactions past the 10 ms deadline. Co-locating policy evaluation with the enforcement point and bounding decision staleness returns the 99th percentile to 7.5 ms while holding post-revocation exposure below 625 ms. The security-latency trade-off is therefore an operator-tunable parameter rather than an architectural absolute, and we close with guidelines for selecting an operating point.| File | Dimensione | Formato | |
|---|---|---|---|
|
_ACCEPTED___NETWORK__Zero_Trust_Meets_the_Real_Time_Loop.pdf
accesso aperto
Tipologia:
Documento in post-print (versione successiva alla peer review e accettata per la pubblicazione)
Licenza d'uso:
Licenza specifica dell'editore
Dimensione
190.68 kB
Formato
Adobe PDF
|
190.68 kB | Adobe PDF | Visualizza/Apri |
|
Riggio_Zero-Trust-Meets-Real-Time_2026.pdf
Solo gestori archivio
Tipologia:
Versione editoriale (versione pubblicata con il layout dell'editore)
Licenza d'uso:
Tutti i diritti riservati
Dimensione
373.92 kB
Formato
Adobe PDF
|
373.92 kB | Adobe PDF | Visualizza/Apri Richiedi una copia |
I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.


