Ericsson threw a bucket of cold water on open radio access network (RAN) architecture this week, citing a series of unresolved security challenges and shortcomings.

The Swedish vendor, in trying to balance a tempered acceptance of open RAN principles while buttressing its primary revenue stream tied to traditional RAN equipment, claims that increased virtualization in the cloud will introduce new security risks. While this approach enables better use of hardware resources between different applications, “isolation between applications are only ‘logical’ in software without physical isolation across hardware resources,” Jason Boswell, head of security on Ericsson’s network products, wrote in a blog post.

“Recently discovered vulnerabilities like Meltdown and Spectre reveal that there can be increased security risks when sharing hardware resources,” he warned. 

Establishing a secure communication channel between two endpoints requires authentication on both ends with a unique identifier and credentials kept under lock and key, according to Bosell. “The authentication process is the base for establishing a secure communication channel, but it must trust the layers underneath to attest that the node, layer, or data set has not been compromised,” he added. 

Standardized interfaces and APIs for hardware security functions must be coupled with transparency into how each layer uses and provides security functions throughout the chain, according to Boswell.

The vendor also claims that early open RAN deployments fall short in delivering baseline features of 5G.

Ericsson Details Open RAN Shortcomings

“Today’s open RAN networks run virtualization for low data rates, so less than 100 Mb/s, low bandwidth, say [20 megahertz]” and “that’s insufficient for 5G needs today where multiple bands, hundreds of megahertz of bandwidth, delivering gigabits of service, requires higher-processing power, software optimization, and hardware accelerators,” Paul Challoner, VP of network products at Ericsson in North America, said in a corresponding video.

Ericsson claims that custom silicon basebands will continue to outperform server-based systems for many years, and maintains that hardware accelerators are required to address high capacity and complex computation.

Virtualization in the RAN is a long journey, Challoner said, noting that it’s taken about 10 years to virtualize 60% of core network functions. Moreover, achieving high performance on virtualization remains a challenge, he said. 

While open RAN, which aims to move hardware processing out of the radio and into software, reduces costs of the radio, it also sacrifices performance and necessitates the need for more open RAN sites compared to traditional RAN, particularly in greenfield networks, according to Challoner. 

“Security really is something that needs to be built in and not bolted on,” he said, adding that the O-RAN Alliance didn’t begin formally addressing security until March 2020. 

Ericsson outlined a series of recommendations to bolster the security posture of open RAN, including protection of the expanded threat surface, risk limitation on near real-time radio intelligent controller (RIC) interfaces. It also advocated for management interfaces to be secured via transport security layer (TSL) and digital signing, and heightened levels of due diligence in securing open source code and DevOps practices.

“With any nascent technology, including open RAN, security cannot be an afterthought and should be built upon a security-by-design approach,” Boswell wrote. “Ericsson will continue to drive standards that give suppliers and carriers a common, transparent, and well-established technical foundation of interoperability and security.”