O-CU (O-RAN Centralized Unit)

Also known as: O-RAN Centralized Unit, O-RAN Central Unit, O-CU-CP, O-CU-UP

The O-CU is the O-RAN Alliance's disaggregated 5G gNB Centralized Unit, split into O-CU-CP (control plane, RRC/PDCP-C) and O-CU-UP (user plane, PDCP-U/SDAP). It terminates the F1 interface toward the O-DU and the E1 interface between CP and UP. In Open RAN deployments the O-CU typically runs as a cloud-native workload on O-Cloud, so its hardening (workload isolation, TLS on F1/E1, image supply chain) is a WG11 security concern.

Categories: Radio Access NetworkInternet and Routing

O-CU in context

The radio access network is where mobile devices attach to the operator's infrastructure. Attacks in this layer include IMSI catching, rogue base stations and downgrade attacks; defenses rest on mutual authentication, integrity-protected signaling and Open RAN supply-chain hygiene.

Telecom networks depend on Internet-style routing (BGP, DNS, MPLS) for interconnect. Route hijacks and DNS abuse can degrade or intercept signaling, which is why RPKI and DNSSEC are now standard hardening for carrier networks.

To place O-CU in the wider telecom-security picture, review A5/3, Broadband, BSS, CDMA, Core Network and CVE — each entry cross-references back to this page so you can walk the topic in either direction.

Related terms

More from the TelcoSec Glossary

Browse the full TelcoSec Glossary, the Ultimate Guide to Mobile Network Security, or the P1 Arsenal of telecom-security tools.