

de Recherche et d’Innovation
en Cybersécurité et Société
Mehrban, A.; Houda, Z. A. El; Moudoud, H.; Brik, B.; Khoukhi, L.
Securing O-RAN Equipment Using Blockchain-Based Supply Chain Verification Article d'actes
Dans: Int. Wirel. Commun. Mob. Comput. Conf., IWCMC, p. 1570–1575, Institute of Electrical and Electronics Engineers Inc., 2025, ISBN: 979-833150887-6 (ISBN), (Journal Abbreviation: Int. Wirel. Commun. Mob. Comput. Conf., IWCMC).
Résumé | Liens | BibTeX | Étiquettes: Access network equipment, Authentication, Block-chain, Blockchain, Cryptography, Denial-of-service attack, Firmware, Firmware authentication, Multi-vendor, Network architecture, Network security, O-RAN, Open radio access network, Radio access networks, Security, Security systems, Security vulnerabilities, Supply Chain Verification, Supply chains, Telecommunications networks
@inproceedings{mehrbanSecuringORANEquipment2025,
title = {Securing O-RAN Equipment Using Blockchain-Based Supply Chain Verification},
author = {A. Mehrban and Z. A. El Houda and H. Moudoud and B. Brik and L. Khoukhi},
url = {https://www.scopus.com/pages/publications/105011364438?origin=resultslist},
doi = {10.1109/IWCMC65282.2025.11059692},
isbn = {979-833150887-6 (ISBN)},
year = {2025},
date = {2025-01-01},
booktitle = {Int. Wirel. Commun. Mob. Comput. Conf., IWCMC},
pages = {1570–1575},
publisher = {Institute of Electrical and Electronics Engineers Inc.},
abstract = {The Open Radio Access Network (O-RAN) architecture has enabled the integration of multi-vendor equipment, yielding a significant enhancement in the flexibility and interoperability of telecommunications networks. However, this openness has also introduced new security vulnerabilities, particularly in supply chain integrity. Malicious actors may exploit weaknesses at various stages of production, distribution, or integration, leading to critical threats such as data tampering, unauthorized access, and denial-of-service (DOS) attacks. To address these challenges, this paper proposes a novel blockchain-based framework designed to secure the O-RAN supply chain. The proposed solution leverages a private permissioned blockchain ledger and cryptographic firmware authentication to ensure the integrity and authenticity of network equipment throughout its lifecycle. Specifically, the framework consists of: (1) a decentralized architecture integrating blockchain network components, equipment node validators, and secure firmware authentication mechanisms; and (2) a consensus-based verification model to enhance trust and transparency within the supply chain. To the best of our knowledge, this is one of the first approaches to use blockchain for O-RAN supply chain security, and also addressing emerging security threats in a scalable and tamper-resistant manner. Experimental validation and security assessments demonstrate the effectiveness of the proposed framework in mitigating supply chain risks, making it a promising solution for ensuring trust and robustness in next-generation O-RAN ecosystems. © 2025 IEEE.},
note = {Journal Abbreviation: Int. Wirel. Commun. Mob. Comput. Conf., IWCMC},
keywords = {Access network equipment, Authentication, Block-chain, Blockchain, Cryptography, Denial-of-service attack, Firmware, Firmware authentication, Multi-vendor, Network architecture, Network security, O-RAN, Open radio access network, Radio access networks, Security, Security systems, Security vulnerabilities, Supply Chain Verification, Supply chains, Telecommunications networks},
pubstate = {published},
tppubtype = {inproceedings}
}
Mehrban, A.; Houda, Z. Abou El; Moudoud, H.; Bao, L. Le
Integrating Zero Trust Architecture in O-RAN: A Comprehensive Survey and Analysis Article de journal
Dans: IEEE Open Journal of the Communications Society, vol. 6, p. 10465–10495, 2025, ISSN: 2644125X (ISSN).
Résumé | Liens | BibTeX | Étiquettes: 6g network, 6G networks, Access control, Data flow analysis, Intelligent controllers, Interoperability, Mobile telecommunication systems, Multi-vendor, Network architecture, Network components, Network security, New approaches, Open radio access network, open radio access network (O-RAN), Radio access networks, RAN intelligent controller, RAN intelligent controller (RIC), Smart contract, Survey and analysis, Trusted computing, Vendor interoperability, Zero trust architecture, Zero trust architecture (ZTA)
@article{mehrbanIntegratingZeroTrust2025,
title = {Integrating Zero Trust Architecture in O-RAN: A Comprehensive Survey and Analysis},
author = {A. Mehrban and Z. Abou El Houda and H. Moudoud and L. Le Bao},
url = {https://www.scopus.com/pages/publications/105025432034?origin=resultslist},
doi = {10.1109/OJCOMS.2025.3644132},
issn = {2644125X (ISSN)},
year = {2025},
date = {2025-01-01},
journal = {IEEE Open Journal of the Communications Society},
volume = {6},
pages = {10465–10495},
publisher = {Institute of Electrical and Electronics Engineers Inc.},
abstract = {Open Radio Access Network (O-RAN) is a new approach to mobile networks that disaggregates the network architecture into multi-vendor interoperable physical and software-defined network components connected through standardized open interfaces. This architecture enables deploying solutions on cloud-native platforms and boosting Artificial Intelligence(AI)-driven automation for network optimization. Despite the benefits of O-RAN’s heterogeneous and multi-vendor architecture, this approach inevitably enlarges the attack surface and introduces additional trust boundaries, which imminently threaten the uniformity of network performance. This also justifies the necessity of Zero Trust Architecture (ZTA) principles as a countermeasure, securing all network components, interfaces, and data flows. This survey shows how ZTA tenets can be integrated into O-RAN settings, contributing in three key areas: (1) a novel ZTA-to-O-RAN mapping model that explicitly places Policy Engine (PE), Policy Administrator (PA), and Policy Enforcement Points (PEPs) across RIC layers (Non-RT/Near-RT RIC), standardized interfaces (A1/E2/O1/O2), and disaggregated RAN functions (O-DU/O-CU/O-RU); (2) a Risk-Adaptive Access Control (RAdAC) framework that dynamically modulates verification depth based on contextual risk; and (3) integration of blockchain-based decentralized identity management with smart-contract-driven authorization for xApp/rApp lifecycle security. © 2020 IEEE.},
keywords = {6g network, 6G networks, Access control, Data flow analysis, Intelligent controllers, Interoperability, Mobile telecommunication systems, Multi-vendor, Network architecture, Network components, Network security, New approaches, Open radio access network, open radio access network (O-RAN), Radio access networks, RAN intelligent controller, RAN intelligent controller (RIC), Smart contract, Survey and analysis, Trusted computing, Vendor interoperability, Zero trust architecture, Zero trust architecture (ZTA)},
pubstate = {published},
tppubtype = {article}
}
Mehrban, A.; Moudoud, H.; Houda, Z. A. El
Zta-Driven Hierarchical Byzantine Consensus for Scalable O-Ran Supply Chain Security Article d'actes
Dans: Int. Congr. Smart Agric. Sustain. Syst., SmartAgri SuSY, Institute of Electrical and Electronics Engineers Inc., 2025, ISBN: 979-833157801-5 (ISBN), (Journal Abbreviation: Int. Congr. Smart Agric. Sustain. Syst., SmartAgri SuSY).
Résumé | Liens | BibTeX | Étiquettes: Block-chain, Blockchain, Byzantine consensus, Firmware, Hierarchical Byzantine consensus, Multi-vendor, Network architecture, Network security, Open RAN, Open RAN (O-RAN), Permissioned blockchain, Supply chain security, Supply chains, Supply-chain attestation, Vendor interoperability, Zero-trust architecture, Zero-Trust Architecture (ZTA)
@inproceedings{mehrbanZtaDrivenHierarchicalByzantine2025,
title = {Zta-Driven Hierarchical Byzantine Consensus for Scalable O-Ran Supply Chain Security},
author = {A. Mehrban and H. Moudoud and Z. A. El Houda},
url = {https://www.scopus.com/pages/publications/105037585759?origin=resultslist},
doi = {10.1109/SmartAgriSuSY68475.2025.11466868},
isbn = {979-833157801-5 (ISBN)},
year = {2025},
date = {2025-01-01},
booktitle = {Int. Congr. Smart Agric. Sustain. Syst., SmartAgri SuSY},
publisher = {Institute of Electrical and Electronics Engineers Inc.},
abstract = {Open RAN (O-RAN) multi-vendor interoperability continues to grow at a rapid pace, bringing flexibility and innovation but also increasing the attack surface. This makes O-RAN deployments vulnerable to supply chain infiltration and firmware tampering. Blockchain has emerged as a promising solution to provide an immutable and verifiable audit trail of equipment firmware hashes from manufacturing through deployment. However, conventional blockchain designs rely on all-to-all validator communication, which introduces scalability challenges and increases verification latency. To alleviate this issue, in this paper, we propose a scalable, efficient, and lightweight blockchain-enabled consensus framework, called H-BFT, to ensure supply chain security and attestation in O-RAN environments. H-BFT consists of three modules. The first module is a hierarchical consensus and attestation module that maps ZeroTrust Architecture (ZTA) microsegments (i.e., RU/DU/CU zones, near-real-time RIC clusters, and SMO domains) to validator committees. These committees verify local attestation events and produce concise summaries. The second module is a lightweight leader checkpointing module that periodically aggregates crosssegment digests, so that only compact validations become global, reducing communication and latency overhead. The third module is a blockchain-based audit and integrity enforcement module, where segment-level contracts enforce onboarding and integrity guarantees, and a checkpoint manager maintains consistency across the entire network. © 2025 IEEE.},
note = {Journal Abbreviation: Int. Congr. Smart Agric. Sustain. Syst., SmartAgri SuSY},
keywords = {Block-chain, Blockchain, Byzantine consensus, Firmware, Hierarchical Byzantine consensus, Multi-vendor, Network architecture, Network security, Open RAN, Open RAN (O-RAN), Permissioned blockchain, Supply chain security, Supply chains, Supply-chain attestation, Vendor interoperability, Zero-trust architecture, Zero-Trust Architecture (ZTA)},
pubstate = {published},
tppubtype = {inproceedings}
}



