Open Radio Access Networks

Open Wireless Networks Face New Quantum Security Gap, Researchers Warn

Open Radio Access Networks, the increasingly popular wireless architecture prized for letting operators mix equipment from different vendors, carry security weaknesses that quantum computers could soon make worse, according to a new academic study.

The paper, published on the arXiv preprint server by researchers at Middlesex University London, Shiv Nadar University in India and VinUniversity in Vietnam, lays out what the the team calls the first comprehensive framework for defending Open Radio Access Networks, or O-RAN, against both current cyberattacks and the looming threat posed by quantum computers capable of breaking today’s encryption.

O-RAN is a design standard that breaks a cell tower’s functions into separate, interchangeable software and hardware components built by different companies, rather than relying on one vendor’s closed system. Telecom operators have embraced the approach because it lowers costs and avoids being locked into a single supplier. But that same openness creates more places for hackers to break in, the researchers wrote, and conventional encryption safeguarding those connections may not survive the arrival of powerful quantum computers.

A Widening Attack Surface

The study identifies three categories of vulnerabilities specific to O-RAN’s disaggregated design. The first involves authentication weaknesses, in which attackers exploit exposed management interfaces or software flaws to gain unauthorized access to network equipment or escalate their own permissions once inside. The second covers attacks on data privacy, accuracy and network uptime, including so-called man-in-the-middle attacks in which an intruder secretly intercepts and alters communications between network components. The third concerns the artificial intelligence systems that increasingly run O-RAN networks, which researchers say are susceptible to data poisoning attacks that corrupt an AI model’s training data to make it behave in ways an attacker wants.

Compounding these risks is the threat quantum computers pose to the mathematical encryption that protects nearly all internet traffic today, including the signals coursing through O-RAN equipment. Machines powerful enough to break that encryption do not yet exist.

But researchers and government agencies have grown increasingly concerned about a strategy known as “harvest now, decrypt later,” in which adversaries intercept and store encrypted data today with the expectation that a future quantum computer will be able to unlock it. Because telecommunications infrastructure often stays in service for many years, the researchers write that O-RAN operators face pressure to prepare now, even though a code-breaking quantum computer may be a decade or more away.

Mapping Defenses to Threats on Networks

Rather than treating quantum defenses as a single fix, the study proposes folding them into a broader security model called Zero Trust, in which no device, application or vendor is automatically trusted, and every request for access is continuously verified.

Within that structure, the researchers map specific O-RAN threats to specific quantum and quantum-resistant countermeasures, compiled in a reference table meant to guide network operators.

The defense of these networks is focused on post-quantum cryptography, a category of encryption methods that run on ordinary computer hardware but rely on mathematical problems believed to be too difficult for even a quantum computer to solve. The National Institute of Standards and Technology finalized the first three of these standards in August 2024, and the study recommends O-RAN operators prioritize rolling them out on the network’s management and policy channels first, since those carry long-lived configuration data and credentials that are prime targets for harvest-now-decrypt-later attacks.

According to the researchers, software, firmware and the AI applications that run inside O-RAN’s controllers also need updated digital signatures early because those components can remain deployed for years without being replaced.

Beyond that near-term fix, the study explores several more experimental quantum technologies that could help secure these networks. Quantum key distribution, which uses the physical properties of light particles to detect eavesdropping rather than relying on math that could theoretically be broken, is described as a complement to post-quantum cryptography for a small number of high-value fiber-optic connections, rather than a network-wide replacement. The researchers also examine quantum identity authentication and quantum digital signatures, newer concepts that would use quantum properties to verify who is on a network and confirm messages have not been tampered with, and quantum secret sharing, which could let multiple companies jointly control a sensitive cryptographic key without any single vendor holding the whole thing.

The team writes that all of these approaches require specialized hardware that is far less mature than standardized post-quantum cryptography and remain largely confined to research and pilot projects.

The study also proposes using quantum machine learning to detect intrusions and unusual network activity, and quantum optimization techniques to help network defenses respond to attacks such as signaling storms, in which a flood of fraudulent requests overwhelms network equipment.

However, the researchers stress that any claimed advantage from these quantum computing methods must be proven against conventional software before being adopted, rather than assumed.

Two Ways to Deploy

The researchers outline two practical ways telecom companies could build quantum defenses into an O-RAN network. One approach folds quantum security functions into xApps and rApps, the modular software applications that already run inside O-RAN’s controllers, making them easier for outside vendors to develop and deploy. The other adds entirely separate, dedicated quantum hardware alongside the existing network, which the study suggests will offer tighter security but requires more effort to integrate and monitor.

To help operators sequence the work, the study lays out a three-phase timeline. In the near term, spanning roughly the next one to three years, companies should catalog where vulnerable encryption already exists across their systems, begin testing hybrid encryption that combines old and new methods, and update the way software and AI models are digitally signed. In a medium-term phase, quantum key distribution could be layered onto a handful of the most sensitive fiber connections once industry technical standards mature. Widespread use of the more experimental quantum authentication and quantum computing-driven security tools, the study says, likely remains seven years or more away and depends on hardware that does not yet exist at commercial scale.

Next Steps to Secure Open Wireless Networks

The researchers list a few limitations in their study. For example, the framework is a conceptual proposal rather than a network that has been built and tested, and many of the quantum technologies it describes have not been proven to outperform existing, non-quantum defenses in real-world conditions. The researchers note that claims of quantum advantage in areas like machine learning-based threat detection require validation against classical systems before operators should rely on them. They also flag that quantum hardware suitable for authentication and secure key-sharing remains early-stage and is not yet ready for broad commercial deployment.

The paper calls for further research into scalable quantum hardware, standardized interfaces between quantum and classical network components, and testing that pits quantum defenses directly against conventional cybersecurity tools to determine which upgrades are worth the cost.

Leave a Comment

Your email address will not be published. Required fields are marked *