Q-RAN: Quantum-Resilient O-RAN Architecture
Vipin Rathi, Lakshya Chopra, Madhav Agarwal, Nitin Rajput, Kriish Sharma, Sushant Mundepi, Shivam Gangwar, Rudraksh Rawal, Jishan
TL;DR
Q-RAN proposes a practical, end-to-end plan to harden Open RAN against quantum threats by integrating NIST-standardized PQC (notably ML-KEM and ML-DSA) with Quantum Random Number Generators. The framework replaces legacy PKI, TLS/DTLS, IPsec, and OAuth 2.0 with hybrid and quantum-resistant variants, anchored by a centralized PQ Certificate Authority within the SMO, and enables crypto-agile deployment across gNodeB, SMO, and RIC components. Key contributions include detailed implementation guidance, a complete migration roadmap, and concrete deployment examples using open-source stacks like OpenRAN/OAI, strongSwan, and OpenSSL with the OQS provider, plus practical notes on QRNG integration and performance considerations. The work demonstrates that lattice-based PQC can meet 5G-disaggregate network requirements while outlining hardware acceleration and standardization needs to realize large-scale adoption.
Abstract
The telecommunications industry faces a dual transformation: the architectural shift toward Open Radio Access Networks (O-RAN) and the emerging threat from quantum computing. O-RAN disaggregated, multi-vendor architecture creates a larger attack surface vulnerable to crypt-analytically relevant quantum computers(CRQCs) that will break current public key cryptography. The Harvest Now, Decrypt Later (HNDL) attack strategy makes this threat immediate, as adversaries can intercept encrypted data today for future decryption. This paper presents Q-RAN, a comprehensive quantum-resistant security framework for O-RAN networks using NIST-standardized Post-Quantum Cryptography (PQC). We detail the implementation of ML-KEM (FIPS 203) and ML-DSA (FIPS 204), integrated with Quantum Random Number Generators (QRNG) for cryptographic entropy. The solution deploys PQ-IPsec, PQ-DTLS, and PQ-mTLS protocols across all O-RAN interfaces, anchored by a centralized Post-Quantum Certificate Authority (PQ-CA) within the SMO framework. This work provides a complete roadmap for securing disaggregated O-RAN ecosystems against quantum adversaries.
