O-RAN WG11 Security Specification
O-RAN Interface Security

O-RAN WG11 Security Specification 2: O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul

Secure O-RAN open interfaces per O-RAN Alliance WG11 Security Requirements Specifications covering E2 (Near-RT RIC to E2 Node) + A1 (Non-RT RIC to Near-RT RIC) + O1 (SMO to managed function) + O2 (SMO to O-Cloud) + Open Fronthaul (O-DU to O-RU). Interface security requirements per WG11 must address (a) authentication of all interface peers with mutual TLS (mTLS) + certificate-based + or equivalent strong authentication, (b) confidentiality via TLS 1.2/1.3 + IPsec + or equivalent for management and control traffic + with cryptographic suites per O-RAN WG11 cryptographic requirements, (c) integrity protection of interface messages and parameters, (d) replay protection via nonce + sequence numbers + or equivalent, (e) authorisation enforcement appropriate to interface (role-based access + scope tokens + OAuth2 for application-layer interfaces + 3GPP-style network function authorisation where applicable), (f) traffic separation between control + management + user planes with appropriate cryptographic isolation. Open Fronthaul-specific requirements must address (a) M-Plane authentication via NETCONF over SSH or TLS, (b) C-Plane + U-Plane confidentiality where required by deployment risk profile, (c) timing synchronisation security per PTP + Sync-E + GPS/GNSS protection. Implement and verify interface security continuously across multi-vendor deployments.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.