Jadwal Sholat

Memuat jadwal sholatโ€ฆ

Ilmu Komputer & AI editorial

Open AccessOA2026

rApp/xApp Attestation: A New Security Use Case for O-RAN

Runtime integrity verification for the RIC ecosystem through attestation modules, agents, and SMO-driven policy coordination
Hamed Alimohammadi; Burcu ลžahin; Arda Akman; Chuan Heng Foh; Periklis Chatzimisios; Mohammad Shojafarยท 2026ยท DOI 10.48550/arXiv.2609.24296

The core problem

The Open Radio Access Network (O-RAN) architecture introduces disaggregation and softwarization that enable multi-vendor innovation but simultaneously expose the RAN Intelligent Controller (RIC) ecosystem to new runtime security risks. Existing O-RAN specifications define strong safeguards for onboarding, authentication, identity management, and secure communication. However, they do not provide a concrete mechanism for verifying whether deployed rApps and xApps remain in their intended, untampered state during operation.

This paper addresses that gap by introducing rApp/xApp attestation as a RIC-native O-RAN security use case for runtime integrity verification. Rather than proposing a new cryptographic protocol, the work defines how existing integrity verification techniques can be integrated into O-RAN through attestation modules, attestation agents, RIC application interfaces, and SMO-driven policy coordination. The authors map the use case to relevant O-RAN Alliance working groups, identify required standardization extensions, and demonstrate feasibility through a lightweight hash-based prototype implemented on the Near-RT RIC platform.

The core research question is: how can

Innovation

Experimental results show attestation latencies below 40 ms across multiple cryptographic hash functions. This indicates that runtime attestation can be performed without disrupting time-sensitive RIC operations when appropriately scheduled.

The prototype was implemented on the Near-RT RIC platform, which typically operates with control loops on the order of 10 ms to 1 s. The sub-40 ms attestation latency therefore fits within the scheduling slack of many Near-RT RIC use cases, provided that attestation is not performed during critical control loop execution.

Key quantitative findings include:

- Attestation latency ms for all tested hash functions.
- The latency is dominated by and , with contributing a smaller fraction.
- Scheduling attestation outside critical control loops prevents disruption of time-sensitive operations.

The results suggest that a hash-based attestation mechanism is feasible for runtime integrity verification in O-RAN. However, the authors note that the prototype is lightweight and does not yet address scalability across many rApps/xApps or the establishment of trusted known-good runtime states.

The Open Radio Access Network (O-RAN) architecture introduces disaggregation and softwarization that enable multi-vendor innovation but simultaneously expose the RAN Intelligent Controller (RIC) ecosystem to new runtime security risks. Existing O-RAN specifications define strong safeguards for onboarding, authentication, identity management, and secure communication. However, they do not provide a concrete mechanism for verifying whether deployed rApps and xApps remain in their intended, untampered state during operation.
This paper addresses that gap by introducing rApp/xApp attestation as a RIC-native O-RAN security use case for runtime integrity verification. Rather than proposing a new cryptographic protocol, the work defines how existing integrity verification techniques can be integrated into O-RAN through attestation modules, attestation agents, RIC application interfaces, and SMO-driven policy coordination. The authors map the use case to relevant O-RAN Alliance working groups, identify required standardization extensions, and demonstrate feasibility through a lightweight hash-based prototype implemented on the Near-RT RIC platform.

Why it matters

The paper discusses remaining technical and standardization challenges. These include:

- **Trusted verification**: How can the attestation module itself be trusted? A compromised attestation module could report false integrity results.
- **Known-good runtime states**: Attestation requires a reference measurement (known-good state). Defining and updating these states for multi-vendor rApps/xApps is non-trivial.
- **Scalability**: Attesting many applications frequently may strain RIC resources. Scheduling and batching strategies are needed.
- **Mitigation policies**: What actions should be taken when attestation fails? The SMO must define policies for quarantine, rollback, or alerting.
- **Future hybrid attestation mechanisms**: Combining hash-based attestation with hardware-based roots of trust (e.g., TPM, TEE) could strengthen guarantees.

The authors map the use case to O-RAN Alliance working groups, suggesting that standardization efforts should focus on defining attestation interfaces, report formats, and policy coordination between the RIC and SMO.

The paper concludes that rApp/xApp attestation is a promising RIC-native security use case that can be integrated into O-RAN without new cryptographic protocols, but further standardization and scalability work is required.

Who should read this

CS practitioners and researchers

Opening member contentโ€ฆ