Lightweight Security for Private Networks: Real-World Evaluation of WireGuard
By: Hubert Djuitcheu , Andrew Sergeev , Khurshid Alam and more
Potential Business Impact:
Secures factory 5G networks with simpler, faster protection.
This paper explores WireGuard as a lightweight alternative to IPsec for securing the user plane as well as the control plane in an industrial Open RAN deployment at the Adtran Terafactory in Meiningen. We focus on a realistic scenario where external vendors access their hardware in our 5G factory network, posing recurrent security risks from untrusted gNBs and intermediate network elements. Unlike prior studies limited to lab setups, we implement a complete proof-of-concept in a factory environment and compare WireGuard with IPsec under industrial traffic conditions. Our approach successfully protects user data (N3 interface) against untrusted gNBs and man-in-the-middle attacks while enabling control plane (N2 interface) authentication between the access and mobility management functions (AMF) and gNB. Performance measurements show that WireGuard adds minimal overhead in throughput, latency, and Central Processing Unit (CPU) usage, achieving performance comparable to IPsec. These findings demonstrate that WireGuard offers competitive performance with significantly reduced configuration complexity, making it a strong candidate for broader adoption in O-RAN, providing a unified, lightweight security layer across multiple interfaces and components.
Similar Papers
Assessing the Latency of Network Layer Security in 5G Networks
Networking and Internet Architecture
Makes 5G internet super fast and safe.
A Light Weight Cryptographic Solution for 6LoWPAN Protocol Stack
Cryptography and Security
Makes small devices securely send messages.
Principle-Guided Verilog Optimization: IP-Safe Knowledge Transfer via Local-Cloud Collaboration
Cryptography and Security
Protects computer chip secrets while improving designs.