The EU has published a report on the cybersecurity of Open RAN, a 4G/5G (maybe even 2G?) network architecture the European Commission says will provide an alternative way of deploying the radio access part of 5G networks over the coming years, based on open interfaces. The EU noted that while Open RAN architectures create new opportunities in the marketplace, they also raise important security challenges, especially in the short term.
“It will be important for all participants to dedicate sufficient time and attention to mitigate such challenges, so that the promises of Open RAN can be realized,” the report said.
The report found that Open RAN could bring potential security opportunities, provided certain conditions are met. Namely, through greater interoperability among RAN components from different suppliers, Open RAN could allow greater diversification of suppliers within networks in the same geographic area. This could contribute to achieving the EU 5G Toolbox recommendation that each operator should have an appropriate multi-vendor strategy to avoid or limit any major dependency on a single supplier.
Open RAN could also help increase visibility of the network thanks to the use of open interfaces and standards, reduce human errors through greater automation, and increase flexibility through the use of virtualisation and cloud-based systems.
However, the Open RAN concept still lacks maturity, which means cybersecurity remains a significant challenge. Especially in the short term, by increasing the complexity of networks, Open RAN could exacerbate certain types of security risks, providing a larger attack surface and more entry points for malicious actors, giving rise to an increased risk of misconfiguration of networks and potential impacts on other network functions due to resource sharing.
The report added that technical specifications, such as those developed by the O-RAN Alliance, are not yet sufficiently secure by design. This means that Open RAN could lead to new or increased critical dependencies, for example in the area of components and cloud.
The EU recommended the use of regulatory powers to monitor large-scale Open RAN deployment plans from mobile operators and if needed, restrict, prohibit or impose specific requirements or conditions for the supply, large-scale deployment and operation of the Open RAN network equipment.
Technical controls such as authentication and authorization could be reinforced and a risk profile assessed for Open RAN providers, external service providers related to Open RAN, cloud service/infrastructure providers and system integrators. The EU added that including Open RAN components into the future 5G cybersecurity certification scheme, currently under development, should happen at the earliest possible stage.
Following up on the coordinated work already done at EU level to strengthen the security of 5G networks with the EU Toolbox on 5G Cybersecurity, Member States have analysed the security implications of Open RAN.
Margrethe Vestager, Executive Vice-President for a Europe Fit for the Digital Age, said: “Our common priority and responsibility is to ensure the timely deployment of 5G networks in Europe, while ensuring they are secure. Open RAN architectures create new opportunities in the marketplace, but this report shows they also raise important security challenges, especially in the short term. It will be important for all participants to dedicate sufficient time and attention to mitigate such challenges, so that the promises of Open RAN can be realised.”
Thierry Breton, Commissioner for the Internal Market, added: “With 5G network rollout across the EU, and our economies’ growing reliance on digital infrastructures, it is more important than ever to ensure a high level of security of our communication networks. That is what we did with the 5G cybersecurity toolbox. And that is what – together with the Member States – we do now on Open RAN with this new report. It is not up to public authorities to choose a technology. But it is our responsibility to assess the risks associated to individual technologies. This report shows that there are a number of opportunities with Open RAN but also significant security challenges that remain unaddressed and cannot be underestimated. Under no circumstances should the potential deployment in Europe’s 5G networks of Open RAN lead to new vulnerabilities.”
Guillaume Poupard, Director General of France’s National Cyber Security Agency (ANSSI), said: “After the EU Toolbox on 5G Cybersecurity, this report is another milestone in the NIS Cooperation Group’s effort to coordinate and mitigate the security risks of our 5G networks. This in-depth security analysis of Open RAN contributes to ensuring that our common approach keeps pace with new trends and related security challenges. We will continue our work to jointly address those challenges.”
Finally, a technology-neutral regulation to foster competition should be maintained., with EU and national funding for 5G and 6G research and innovation, so that EU players can compete on a level playing field.