Open RAN vs vRAN
vRAN (virtualized RAN) runs traditional RAN functions on general-purpose compute. Open RAN adds standardized open interfaces (O1, O2, E2, Open Fronthaul) so components from different vendors interoperate. Open RAN is always vRAN; vRAN is not always Open RAN.
| Attribute | Open RAN | vRAN |
|---|---|---|
| Virtualization | Yes | Yes |
| Open interfaces | Yes (O-RAN Alliance) | Vendor-defined |
| Multi-vendor | By design | Rare in practice |
| RIC / xApps / rApps | Yes | No |
| Attack surface | Every open interface + RIC apps | Cloud + orchestration layer |
| Reference threat model | O-RAN WG11 | 3GPP + operator-specific |
Verdict
Open RAN expands the attack surface deliberately in exchange for supply-chain flexibility. WG11's threat model is now mature enough to plan against — but the RIC and third-party xApp/rApp channels are the piece most deployments underestimate.