Selectable encryption for 5G open radio access network
Techniques for encrypting data within a 5G Open Radio Access Network (O-RAN) includes receiving, at a first module of the 5G O-RAN, a first set of one or more data packets encrypted using mathematical encryption. The method also includes determining, using a machine-learning model trained to detect cybersecurity threats, the existence of a cybersecurity threat associated with the voice or data transaction, and in response, determining to switch encryption from the mathematical encryption to quantum encryption. The method further includes encrypting the one or more data packets using a quantum encryption key to generate quantum-encrypted data packets, transmitting the quantum encryption key from the first module of the 5G O-RAN core to a second module of the 5G O-RAN over a quantum key distribution (QKD) channel, and transmitting the quantum-encrypted data packets from the first module of the 5G O-RAN to the second module of the 5G O-RAN.
1 . A method of encrypting data within a 5G Open Radio Access Network (O-RAN), the method comprising:
receiving, at a first module of the 5G O-RAN, a first set of one or more data packets pertaining to a voice or data transaction associated with the 5G O-RAN, the first set of one or more data packets being encrypted using mathematical encryption;
determining, based on the first set of one or more data packets and using a machine-learning model trained to detect cybersecurity threats, an existence of a cybersecurity threat associated with the voice or data transaction;
in response to determining the existence of the cybersecurity threat associated with the voice or data transaction based on the first set of one or more data packets, determining to switch encryption of the one or more data packets from the mathematical encryption to quantum encryption;
encrypting the one or more data packets using a quantum encryption key to generate quantum-encrypted data packets;
transmitting the quantum encryption key from the first module of the 5G O-RAN to a second module of the 5G O-RAN over a quantum key distribution (QKD) channel; and
transmitting the quantum-encrypted data packets from the first module of the 5G O-RAN to the second module of the 5G O-RAN.
2 . The method of claim 1 , comprising:
determining that the cybersecurity threat has been addressed; and
responsive to determining that the cybersecurity threat has been addressed, determining to switch from the quantum encryption to the mathematical encryption.
3 . The method of claim 1 , wherein the first module is a cloud-deployed module of the 5G O-RAN core.
4 . The method of claim 1 , wherein the first module is one of: an authentication server function (AUSF) module, a secure anchor function (SEAF) module, an access and mobility management function (AMF) module or a non-3GPP interworking function (N 3 IWF) module of a core of the 5G O-RAN.
5 . The method of claim 1 , wherein the second module is one of: a secure anchor function (SEAF) module, an access and mobility management function (AMF) module, a non-3GPP interworking function (N 3 IWF) module of a core of the 5G O-RAN, or a g-NodeB (gNB) of the 5G O-RAN.
6 . The method of claim 1 , wherein the machine-learning model is a deep learning model configured to detect cyber security threats based on data representing an input set of one or more data packets.
7 . The method of claim 1 , wherein the QKD channel is a fiber-optic channel.
8 . The method of claim 1 , wherein the quantum-encrypted data packets are transmitted from the first module of the 5G O-RAN to the second module of the 5G O-RAN over the QKD channel.
9 . The method of claim 1 , comprising:
decrypting the first set of one or more data packets using mathematical decryption, wherein encrypting the one or more data packets using the quantum encryption key to generate the quantum-encrypted data packets comprises:
encrypting a decrypted version of the one or more data packets after decrypting the first set of one or more data packets using mathematical decryption.
10 . A system of encrypting data within a 5G Open Radio Access Network (O-RAN), the system comprising:
memory encoded with machine-readable instructions; and
one or more processors coupled to the memory, and configured to execute the machine-readable instructions, which when executed, cause the one or more processors to execute operations comprising:
receiving, at a first module of the 5G O-RAN, a first set of one or more data packets pertaining to a voice or data transaction associated with the 5G O-RAN, the first set of one or more data packets being encrypted using mathematical encryption,
determining, based on the first set of one or more data packets and using a machine-learning model trained to detect cybersecurity threats, an existence of a cybersecurity threat associated with the voice or data transaction,
in response to determining the existence of the cybersecurity threat associated with the voice or data transaction based on the first set of one or more data packets, determining to switch encryption of the one or more data packets from the mathematical encryption to quantum encryption,
encrypting the one or more data packets using a quantum encryption key to generate quantum-encrypted data packets,
transmitting the quantum encryption key from the first module of the 5G O-RAN to a second module of the 5G O-RAN over a quantum key distribution (QKD) channel, and
transmitting the quantum-encrypted data packets from the first module of the 5G O-RAN to the second module of the 5G O-RAN.
11 . The system of claim 10 , wherein the operations comprise:
determining that the cybersecurity threat has been addressed; and
responsive to determining that the cybersecurity threat has been addressed, determining to switch from the quantum encryption to the mathematical encryption.
12 . The system of claim 10 , wherein the first module is a cloud-deployed module of a core of the 5G O-RAN.
13 . The system of claim 10 , wherein the first module is one of: an authentication server function (AUSF) module, a secure anchor function (SEAF) module, an access and mobility management function (AMF) module or a non-3GPP interworking function (N3IWF) module of a core of the 5G O-RAN.
14 . The system of claim 10 , wherein the second module is one of: a secure anchor function (SEAF) module, an access and mobility management function (AMF) module, a non-3GPP interworking function (N 3 IWF) module of the 5G O-RAN core, or a g-NodeB (gNB) of the 5G O-RAN.
15 . The system of claim 10 , wherein the machine-learning model is a deep learning model configured to detect cyber security threats based on data representing an input set of one or more data packets.
16 . The system of claim 10 , wherein the quantum-encrypted data packets are transmitted from the first module of the 5G O-RAN to the second module of the 5G O-RAN over the QKD channel.
17 . At least one non-transitory machine-readable storage device encoded with machine-readable instructions, which when executed, cause one or more processing devices to execute operations comprising:
receiving, at a first module of a 5G Open Radio Access Network (O-RAN), a first set of one or more data packets pertaining to a voice or data transaction associated with the 5G O-RAN, the first set of one or more data packets being encrypted using mathematical encryption,
determining, based on the first set of one or more data packets and using a machine-learning model trained to detect cybersecurity threats, an existence of a cybersecurity threat associated with the voice or data transaction,
in response to determining the existence of the cybersecurity threat associated with the voice or data transaction based on the first set of one or more data packets, determining to switch encryption of the one or more data packets from the mathematical encryption to quantum encryption,
encrypting the one or more data packets using a quantum encryption key to generate quantum-encrypted data packets,
transmitting the quantum encryption key from the first module of the 5G O-RAN to a second module of the 5G O-RAN over a quantum key distribution (QKD) channel, and
transmitting the quantum-encrypted data packets from the first module of the 5G O-RAN to the second module of the 5G O-RAN.
18 . The non-transitory machine-readable storage device of claim 17 , wherein the operations comprise:
determining that the cybersecurity threat has been addressed; and
responsive to determining that the cybersecurity threat has been addressed, determining to switch from the quantum encryption to the mathematical encryption.
19 . The non-transitory machine-readable storage device of claim 17 , wherein the first module is one of: an authentication server function (AUSF) module, a secure anchor function (SEAF) module, an access and mobility management function (AMF) module or a non-3GPP interworking function (N3IWF) module of a core of the 5G O-RAN, and the second module is one of: a secure anchor function (SEAF) module, an access and mobility management function (AMF) module, a non-3GPP interworking function (N3IWF) module of a core of the 5G O-RAN, or a g-NodeB (gNB) of the 5G O-RAN.
20 . The non-transitory machine-readable storage device of claim 17 , wherein the quantum-encrypted data packets are transmitted from the first module of the 5G O-RAN to the second module of the 5G O-RAN over the QKD channel.