Security Challenges and Mitigation Strategies for Open RAN A1 Interface
摘要
As mobile networks evolve toward openness, interoperability, and intelligence, Open Radio Access Network (Open RAN) has emerged as a transformative architecture supporting vendor-neutral deployments. However, the modular structure of Open RAN introduces new security challenges. This paper proposes stage-based threat scenarios targeting privilege-related vulnerabilities in the A1 interface, a critical component for policy and model exchange between the Non-RT RIC and Near-RT RIC. The scenarios include malicious policy injection, privilege escalation, and exploitation of Enrichment Information (EI) pathways. To address these threats, we present countermeasures aligned with O-RAN Alliance WG11 specifications, including multi-layered authentication (mTLS, IPsec), OAuth 2.0-based access control, schema validation, rate limiting, and continuous monitoring. Our findings offer practical insights into securing A1 communications and contribute to the development of a more trustworthy Open RAN ecosystem for 5G and beyond.