Open RAN Security
Open RAN (O-RAN) disaggregates the Radio Access Network into vendor-neutral components connected over open, standardized interfaces. The architecture introduces the RAN Intelligent Controller (RIC), split into Non-Real-Time and Near-Real-Time tiers, together with xApps and rApps that run third-party logic against live RAN state. This expanded attack surface is governed by the O-RAN Alliance Working Group 11 (WG11) security specifications and inherits 3GPP SCAS and GSMA NESAS assurance requirements.
This hub aggregates Ultimate Guide coverage of Open RAN security: threats to the open interfaces (E2, A1, O1, O2, Open Fronthaul 7.2x), RIC and xApp/rApp trust boundaries, the Service Management and Orchestration (SMO) attack surface, supply-chain risks introduced by multi-vendor disaggregation, and the certificate, mutual-TLS, and zero-trust controls operators deploy to harden a production O-RAN deployment.
Frequently asked questions about open ran security
What are xApps and rApps in Open RAN and what security risks do they introduce?
xApps run on the Near-RT RIC (RAN Intelligent Controller) and act on second-scale radio-resource decisions; rApps run on the Non-RT RIC and drive minute-scale policies. Both can come from third-party vendors, which introduces a supply-chain attack surface unique to Open RAN: a malicious or compromised xApp/rApp can degrade service, bias resource allocation, or exfiltrate subscriber-linked data. O-RAN Alliance WG11 defines the security architecture (authentication, authorization, API hardening) that must be enforced on the RIC platforms.
What is Open RAN and what security implications does it have?
Open RAN disaggregates the traditional base station into open, interoperable components from multiple vendors. While it promotes competition and innovation, it expands the attack surface through additional interfaces (O1, A1, E2), introduces multi-vendor integration risks, and requires rigorous security testing of the RAN Intelligent Controller (RIC) and its applications (xApps/rApps). The O-RAN Alliance has published security specifications to address these concerns.
What is GSMA NESAS and how does it relate to SCAS?
NESAS (Network Equipment Security Assurance Scheme) is the GSMA-run vendor assurance scheme that audits telecom equipment vendors' development and product lifecycle processes against a defined baseline. SCAS (Security Assurance Specifications, 3GPP TS 33.117 and per-NF companion specs) defines the product-level test cases that a piece of network equipment must pass. Together, NESAS+SCAS give operators a defensible baseline for procurement: audited vendor + tested product. Adoption is now a de-facto requirement in many national tenders.
What are 3GPP Security Assurance Specifications (SCAS)?
3GPP SCAS define security test cases for specific network product classes (e.g., gNodeB, AMF, MME). They cover vulnerability testing, hardening requirements, and security functionality verification. SCAS test results feed into the GSMA NESAS evaluation process and provide operators with standardized security benchmarks for comparing equipment from different vendors.
Related glossary terms
- Non-RT RIC Non-Real-Time RAN Intelligent Controller
- RIC RAN Intelligent Controller
- Near-RT RIC Near-Real-Time RAN Intelligent Controller
- E2 Interface O-RAN Near-RT RIC to E2 Node Interface
- E2AP E2 Application Protocol
- A1 Interface Non-RT RIC to Near-RT RIC Interface
- Open RAN
- xApp
- rApp
- SMO Service Management and Orchestration
Related comparisons
More on Open Ran Security
Browse all topic hubs, the Ultimate Guide to Mobile Network Security and the TelcoSec Glossary.