

de Recherche et d’Innovation
en Cybersécurité et Société
Mehrban, A.; Moudoud, H.; Brik, B.; Khoukhi, L.; Houda, Z. A. El
Game-Theoretic Security Orchestration for Cross-RIC Policy Conflicts in O-RAN Article d'actes
Dans: IEEE Int Conf Commun, Institute of Electrical and Electronics Engineers Inc., 2026, ISBN: 15503607 (ISSN); 979-831954209-0 (ISBN), (Journal Abbreviation: IEEE Int Conf Commun).
Résumé | Liens | BibTeX | Étiquettes: Computation theory, Computer system firewalls, Cryptography, Game theory, Game-theoretic, Multiple vendors, Network architecture, Network security, Networks security, Open radio access network, Open RAN, Policy conflict, Radio access networks, Security orchestration, Service management, Service orchestration, SMO, Xapp/rapp conflict, xApp/rApp conflicts
@inproceedings{mehrbanGameTheoreticSecurityOrchestration2026,
title = {Game-Theoretic Security Orchestration for Cross-RIC Policy Conflicts in O-RAN},
author = {A. Mehrban and H. Moudoud and B. Brik and L. Khoukhi and Z. A. El Houda},
url = {https://www.scopus.com/pages/publications/105045343135?origin=resultslist},
doi = {10.1109/ICC59461.2026.11587926},
isbn = {15503607 (ISSN); 979-831954209-0 (ISBN)},
year = {2026},
date = {2026-01-01},
booktitle = {IEEE Int Conf Commun},
publisher = {Institute of Electrical and Electronics Engineers Inc.},
abstract = {In Open Radio Access Network (Open RAN), disaggregated network components can interact through specialized xApps or rApps from multiple vendors. Despite the flexibility of operations and the dynamism of functions enabled by the open architecture, this openness can cause conflicts in security policy enforcement (e.g., encryption levels, key rotation, firewall restrictiveness), formally defined as thresholded divergences on shared or interdependent security parameters, where one app wants to set a stricter rule while another wants a more lenient policy simultaneously. The current solutions of "first-come"or "last-write"make the change one-sided for the benefit of a single app, while other apps may be harmed by the result, and at a network level, security and stability can be compromised. In this paper, we propose a novel Game-Theoretic Security Orchestrator (GTSO) that operates at the Service Management and Orchestration (SMO) layer, with cross-RIC scope, and is responsible for resolving parameter conflicts across xApps and rApps. GTSO treats xApps/rApps as strategic players and negotiates convergent solutions using game-theoretic models such as non-cooperative Nash games, cooperative bargaining, and leader-follower (Stackelberg) that guide competing control applications toward stable equilibrium points, while exchanging strategy summaries over secure channels to protect sensitive details and enhance overall network security. © 2026 IEEE.},
note = {Journal Abbreviation: IEEE Int Conf Commun},
keywords = {Computation theory, Computer system firewalls, Cryptography, Game theory, Game-theoretic, Multiple vendors, Network architecture, Network security, Networks security, Open radio access network, Open RAN, Policy conflict, Radio access networks, Security orchestration, Service management, Service orchestration, SMO, Xapp/rapp conflict, xApp/rApp conflicts},
pubstate = {published},
tppubtype = {inproceedings}
}
Mehrban, A.; Houda, Z. A. El; Moudoud, H.; Brik, B.; Khoukhi, L.
Securing O-RAN Equipment Using Blockchain-Based Supply Chain Verification Article d'actes
Dans: Int. Wirel. Commun. Mob. Comput. Conf., IWCMC, p. 1570–1575, Institute of Electrical and Electronics Engineers Inc., 2025, ISBN: 979-833150887-6 (ISBN), (Journal Abbreviation: Int. Wirel. Commun. Mob. Comput. Conf., IWCMC).
Résumé | Liens | BibTeX | Étiquettes: Access network equipment, Authentication, Block-chain, Blockchain, Cryptography, Denial-of-service attack, Firmware, Firmware authentication, Multi-vendor, Network architecture, Network security, O-RAN, Open radio access network, Radio access networks, Security, Security systems, Security vulnerabilities, Supply Chain Verification, Supply chains, Telecommunications networks
@inproceedings{mehrbanSecuringORANEquipment2025,
title = {Securing O-RAN Equipment Using Blockchain-Based Supply Chain Verification},
author = {A. Mehrban and Z. A. El Houda and H. Moudoud and B. Brik and L. Khoukhi},
url = {https://www.scopus.com/pages/publications/105011364438?origin=resultslist},
doi = {10.1109/IWCMC65282.2025.11059692},
isbn = {979-833150887-6 (ISBN)},
year = {2025},
date = {2025-01-01},
booktitle = {Int. Wirel. Commun. Mob. Comput. Conf., IWCMC},
pages = {1570–1575},
publisher = {Institute of Electrical and Electronics Engineers Inc.},
abstract = {The Open Radio Access Network (O-RAN) architecture has enabled the integration of multi-vendor equipment, yielding a significant enhancement in the flexibility and interoperability of telecommunications networks. However, this openness has also introduced new security vulnerabilities, particularly in supply chain integrity. Malicious actors may exploit weaknesses at various stages of production, distribution, or integration, leading to critical threats such as data tampering, unauthorized access, and denial-of-service (DOS) attacks. To address these challenges, this paper proposes a novel blockchain-based framework designed to secure the O-RAN supply chain. The proposed solution leverages a private permissioned blockchain ledger and cryptographic firmware authentication to ensure the integrity and authenticity of network equipment throughout its lifecycle. Specifically, the framework consists of: (1) a decentralized architecture integrating blockchain network components, equipment node validators, and secure firmware authentication mechanisms; and (2) a consensus-based verification model to enhance trust and transparency within the supply chain. To the best of our knowledge, this is one of the first approaches to use blockchain for O-RAN supply chain security, and also addressing emerging security threats in a scalable and tamper-resistant manner. Experimental validation and security assessments demonstrate the effectiveness of the proposed framework in mitigating supply chain risks, making it a promising solution for ensuring trust and robustness in next-generation O-RAN ecosystems. © 2025 IEEE.},
note = {Journal Abbreviation: Int. Wirel. Commun. Mob. Comput. Conf., IWCMC},
keywords = {Access network equipment, Authentication, Block-chain, Blockchain, Cryptography, Denial-of-service attack, Firmware, Firmware authentication, Multi-vendor, Network architecture, Network security, O-RAN, Open radio access network, Radio access networks, Security, Security systems, Security vulnerabilities, Supply Chain Verification, Supply chains, Telecommunications networks},
pubstate = {published},
tppubtype = {inproceedings}
}
Moudoud, H.; Houda, Z. A. El; Brik, B.
Securing O-RAN with Zero Trust Architecture and Large Language Models Article d'actes
Dans: C., Iwendi; Z., Boulouard; N., Kryvinska (Ed.): Lect. Notes Networks Syst., p. 357–368, Springer Science and Business Media Deutschland GmbH, 2025, ISBN: 23673370 (ISSN); 978-303194619-6 (ISBN), (Journal Abbreviation: Lect. Notes Networks Syst.).
Résumé | Liens | BibTeX | Étiquettes: Access management, Access Management system, Architecture, Authentication, Block-chain, Blockchain, Computer architecture, Computer crime, Cryptography, Distributed computer systems, Intrusion Detection, Language model, Large language model, Management systems, Mobile security, Mobile telecommunication systems, Network architecture, Network security, O-RAN, Open radio access network, Radio access networks, Security systems, Security vulnerabilities, Trusted computing, Zero Trust
@inproceedings{moudoudSecuringORANZero2025,
title = {Securing O-RAN with Zero Trust Architecture and Large Language Models},
author = {H. Moudoud and Z. A. El Houda and B. Brik},
editor = {Iwendi C. and Boulouard Z. and Kryvinska N.},
url = {https://www.scopus.com/pages/publications/105011259647?origin=resultslist},
doi = {10.1007/978-3-031-94620-2_31},
isbn = {23673370 (ISSN); 978-303194619-6 (ISBN)},
year = {2025},
date = {2025-01-01},
booktitle = {Lect. Notes Networks Syst.},
volume = {1312 LNNS},
pages = {357–368},
publisher = {Springer Science and Business Media Deutschland GmbH},
abstract = {The Open Radio Access Network (O-RAN) architecture is critical for the development of 6G networks, offering flexibility and interoperability through disaggregated components. However, this openness exposes O-RAN to new security vulnerabilities, including unauthorized access, data breaches, and malicious xApp deployments. To address these challenges, we propose DistillORAN, a novel Zero-Trust architecture designed specifically for O-RAN. DistillORAN features two core components: (1) a blockchain-based decentralized trust management system for secure verification, authentication, and dynamic access control of xApps, and (2) a lightweight intrusion detection module powered by DistilBERT, a transformer-based model optimized for resource-constrained environments. DistilBERT’s ability to analyze network activities and detect anomalies in real-time allows it to identify complex security threats and multi-step attack scenarios within the O-RAN ecosystem. Its lightweight nature makes it ideal for O-RAN’s distributed infrastructure, where computational resources may be limited. By combining blockchain technology for trust management with DistilBERT’s powerful pattern recognition for intrusion detection, DistillORAN enforces a Zero-Trust security model, ensuring continuous monitoring and verification of all network components. This comprehensive solution enhances the security and resilience of O-RAN networks, aligning with the dynamic needs of next-generation mobile infrastructures. © The Author(s), under exclusive license to Springer Nature Switzerland AG 2025.},
note = {Journal Abbreviation: Lect. Notes Networks Syst.},
keywords = {Access management, Access Management system, Architecture, Authentication, Block-chain, Blockchain, Computer architecture, Computer crime, Cryptography, Distributed computer systems, Intrusion Detection, Language model, Large language model, Management systems, Mobile security, Mobile telecommunication systems, Network architecture, Network security, O-RAN, Open radio access network, Radio access networks, Security systems, Security vulnerabilities, Trusted computing, Zero Trust},
pubstate = {published},
tppubtype = {inproceedings}
}
Mehrban, A.; Houda, Z. Abou El; Moudoud, H.; Bao, L. Le
Integrating Zero Trust Architecture in O-RAN: A Comprehensive Survey and Analysis Article de journal
Dans: IEEE Open Journal of the Communications Society, vol. 6, p. 10465–10495, 2025, ISSN: 2644125X (ISSN).
Résumé | Liens | BibTeX | Étiquettes: 6g network, 6G networks, Access control, Data flow analysis, Intelligent controllers, Interoperability, Mobile telecommunication systems, Multi-vendor, Network architecture, Network components, Network security, New approaches, Open radio access network, open radio access network (O-RAN), Radio access networks, RAN intelligent controller, RAN intelligent controller (RIC), Smart contract, Survey and analysis, Trusted computing, Vendor interoperability, Zero trust architecture, Zero trust architecture (ZTA)
@article{mehrbanIntegratingZeroTrust2025,
title = {Integrating Zero Trust Architecture in O-RAN: A Comprehensive Survey and Analysis},
author = {A. Mehrban and Z. Abou El Houda and H. Moudoud and L. Le Bao},
url = {https://www.scopus.com/pages/publications/105025432034?origin=resultslist},
doi = {10.1109/OJCOMS.2025.3644132},
issn = {2644125X (ISSN)},
year = {2025},
date = {2025-01-01},
journal = {IEEE Open Journal of the Communications Society},
volume = {6},
pages = {10465–10495},
publisher = {Institute of Electrical and Electronics Engineers Inc.},
abstract = {Open Radio Access Network (O-RAN) is a new approach to mobile networks that disaggregates the network architecture into multi-vendor interoperable physical and software-defined network components connected through standardized open interfaces. This architecture enables deploying solutions on cloud-native platforms and boosting Artificial Intelligence(AI)-driven automation for network optimization. Despite the benefits of O-RAN’s heterogeneous and multi-vendor architecture, this approach inevitably enlarges the attack surface and introduces additional trust boundaries, which imminently threaten the uniformity of network performance. This also justifies the necessity of Zero Trust Architecture (ZTA) principles as a countermeasure, securing all network components, interfaces, and data flows. This survey shows how ZTA tenets can be integrated into O-RAN settings, contributing in three key areas: (1) a novel ZTA-to-O-RAN mapping model that explicitly places Policy Engine (PE), Policy Administrator (PA), and Policy Enforcement Points (PEPs) across RIC layers (Non-RT/Near-RT RIC), standardized interfaces (A1/E2/O1/O2), and disaggregated RAN functions (O-DU/O-CU/O-RU); (2) a Risk-Adaptive Access Control (RAdAC) framework that dynamically modulates verification depth based on contextual risk; and (3) integration of blockchain-based decentralized identity management with smart-contract-driven authorization for xApp/rApp lifecycle security. © 2020 IEEE.},
keywords = {6g network, 6G networks, Access control, Data flow analysis, Intelligent controllers, Interoperability, Mobile telecommunication systems, Multi-vendor, Network architecture, Network components, Network security, New approaches, Open radio access network, open radio access network (O-RAN), Radio access networks, RAN intelligent controller, RAN intelligent controller (RIC), Smart contract, Survey and analysis, Trusted computing, Vendor interoperability, Zero trust architecture, Zero trust architecture (ZTA)},
pubstate = {published},
tppubtype = {article}
}
Mehrban, A.; Houda, Z. A. El; Moudoud, H.; Brik, B.; Khoukhi, L.
A Blockchain-Enabled Multi-Layered Zero-Trust Security Framework for O-RAN Article d'actes
Dans: Int. Wirel. Commun. Mob. Comput. Conf., IWCMC, p. 1564–1569, Institute of Electrical and Electronics Engineers Inc., 2025, ISBN: 979-833150887-6 (ISBN), (Journal Abbreviation: Int. Wirel. Commun. Mob. Comput. Conf., IWCMC).
Résumé | Liens | BibTeX | Étiquettes: Access control, Block-chain, Blockchain, Data privacy, Federated learning, federated learning (FL), Internet of thing, Internet of things, Internet of Things (IoT), Interoperability, Learning systems, Mobile telecommunication systems, Multi-layered, Network architecture, Network security, Open access, Open radio access network, open radio access network (O-RAN), Radio, Radio access networks, Radio access technologies, Radio communication, Secure communication, Security, Security frameworks, Security risks, Transfer learning, Trusted computing
@inproceedings{mehrbanBlockchainEnabledMultiLayeredZeroTrust2025,
title = {A Blockchain-Enabled Multi-Layered Zero-Trust Security Framework for O-RAN},
author = {A. Mehrban and Z. A. El Houda and H. Moudoud and B. Brik and L. Khoukhi},
url = {https://www.scopus.com/pages/publications/105011345211?origin=resultslist},
doi = {10.1109/IWCMC65282.2025.11059720},
isbn = {979-833150887-6 (ISBN)},
year = {2025},
date = {2025-01-01},
booktitle = {Int. Wirel. Commun. Mob. Comput. Conf., IWCMC},
pages = {1564–1569},
publisher = {Institute of Electrical and Electronics Engineers Inc.},
abstract = {O-RAN (Open Radio Access Network) is a set of open and interoperable radio access technologies, guided by the O-RAN Alliance, that, despite an open ecosystem, introduces significant security risks, expanding the threat surface in 6G networks. Traditional perimeter-based security approaches are inadequate for O-RAN's highly distributed, multi-vendor environments, where Zero Trust Architecture (ZTA) becomes essential for robust security. To address these challenges, we propose a novel blockchain-based, decentralized Zero-Trust Framework specifically designed for O-RAN security. Our proposed framework comprises two key layers: the first layer utilizes Federated Learning (FL) and Transfer Learning (TL) for advanced attack detection, enabling distributed, privacy-preserving threat analysis across O-RAN nodes. The second layer enforces Zero Trust access control through a blockchain-based identity management system, ensuring tamper-resistant, real-time policy updates. This multi-layered framework provides adaptive threat detection and resilient access control, validated through simulations demonstrating high detection accuracy and robust access management with minimal impact on network performance, offering a scalable security solution for next-generation O-RAN deployments. © 2025 IEEE.},
note = {Journal Abbreviation: Int. Wirel. Commun. Mob. Comput. Conf., IWCMC},
keywords = {Access control, Block-chain, Blockchain, Data privacy, Federated learning, federated learning (FL), Internet of thing, Internet of things, Internet of Things (IoT), Interoperability, Learning systems, Mobile telecommunication systems, Multi-layered, Network architecture, Network security, Open access, Open radio access network, open radio access network (O-RAN), Radio, Radio access networks, Radio access technologies, Radio communication, Secure communication, Security, Security frameworks, Security risks, Transfer learning, Trusted computing},
pubstate = {published},
tppubtype = {inproceedings}
}



