rApp/xApp Attestation: A New Security Use Case for O-RAN
Researchers propose runtime rApp and xApp attestation for O-RAN, with a prototype under 40 milliseconds.
The paper argues that O-RAN onboarding and authentication controls do not verify that deployed rApps and xApps stay untampered at runtime. It defines rApp/xApp attestation as a RIC-native use case that reuses existing integrity checks through attestation modules, agents, RIC interfaces, and SMO policy, and maps needed O-RAN Alliance extensions. A lightweight hash-based prototype on the Near-RT RIC completed attestation in under 40 ms across several hash functions. Remaining gaps include trusted verification, known-good runtime states, scalability, and mitigation policy.
- O-RAN specs lack runtime integrity checks for deployed rApps and xApps.
- The paper maps attestation into RIC interfaces and SMO policy coordination.
- A hash-based Near-RT RIC prototype attested apps in under 40 milliseconds.
- Open issues include trusted verification, known-good states, and mitigation policy.
Full article194 words · extracted from arxiv.org · click to collapse
The disaggregation and softwarization introduced by the Open Radio Access Network (O-RAN) architecture enable multi-vendor innovation but also expose the RAN Intelligent Controller (RIC) ecosystem to new runtime security risks. Existing O-RAN specifications define strong safeguards for onboarding, authentication, identity management, and secure communication; however, they do not provide a concrete mechanism for verifying whether deployed rApps and xApps remain in their intended, untampered state during operation. This paper introduces rApp/xApp attestation as a RIC-native O-RAN security use case for runtime integrity verification. Rather than proposing a new cryptographic protocol, the work defines how existing integrity verification techniques can be integrated into O-RAN through attestation modules, attestation agents, RIC application interfaces, and SMO-driven policy coordination. We map the use case to relevant O-RAN Alliance working groups, identify required standardization extensions, and demonstrate feasibility through a lightweight hash-based prototype implemented on the Near-RT RIC platform. Experimental results show attestation latencies below 40 ms across multiple cryptographic hash functions, indicating that runtime attestation can be performed without disrupting time-sensitive RIC operations when appropriately scheduled. Finally, we discuss remaining technical and standardization challenges, including trusted verification, known-good runtime states, scalability, mitigation policies, and future hybrid attestation mechanisms.
Text extracted automatically; images, tables and formatting may be missing. Original: https://arxiv.org/abs/2609.24296