← Latest papers
💻 computer science

Towards Quantum-Safe O-RAN -- Experimental Evaluation of ML-KEM-Based IPsec on the E2 Interface

This paper experimentally demonstrates that integrating NIST-aligned ML-KEM (CRYSTALS-Kyber) into IPsec for the O-RAN E2 interface introduces a negligible 3–5 ms overhead in tunnel establishment while maintaining stable Near-RT RIC xApp performance, thereby validating the practical feasibility of quantum-safe migration for 5G control planes.

Original authors: Mario Perera, Michael Mackay, Max Hashem Eiza, Alessandro RaschellÃ, Nathan Shone, Mukesh Kumar Maheshwari

Published 2026-02-13
📖 5 min read🧠 Deep dive

Original authors: Mario Perera, Michael Mackay, Max Hashem Eiza, Alessandro RaschellÃ, Nathan Shone, Mukesh Kumar Maheshwari

Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

The Big Picture: The "Quantum Time Bomb"

Imagine you are sending a secret letter to a friend today. You lock it in a strong box (encryption) that only you and your friend have the key to. You feel safe.

However, there is a villain in the future who is building a super-magic key (a Quantum Computer). This key can open any lock, even the ones you use today. The scary part? The villain doesn't need to open the letter now. They can just steal your locked letter, store it in a vault, and wait until they build their super-key to open it later. This is called "Store-Now, Decrypt-Later."

Our mobile networks (5G) are like a massive city of these secret letters. If we don't upgrade our locks now, all our current data could be read by future villains. We need new locks that even the super-magic key can't break. These are called Post-Quantum Cryptography (PQC) locks.

The Problem: The "Speed vs. Safety" Trade-off

The paper focuses on a specific part of the mobile network called the E2 Interface. Think of this as the high-speed control tower that tells the cell towers (where your phone connects) exactly what to do. It needs to be incredibly fast. If the control tower hesitates for even a fraction of a second, your video call might drop, or your self-driving car might hesitate.

The big question the researchers asked was: "If we swap our old, fast locks for these new, super-secure Quantum-Proof locks, will the control tower get too slow to do its job?"

The Experiment: The "Test Drive"

To answer this, the authors built a simulated mobile network in a lab. It wasn't a real city with real phones, but a digital "sandbox" that acted exactly like one. They used open-source software (like building blocks) to create:

  1. The Cell Tower (gNB).
  2. The Control Tower (RIC).
  3. The Security Guards (IPsec/IPsec tunnels).

They ran three different "test drives":

  1. No Security: Just driving fast with no locks (to see the baseline speed).
  2. Old Security: Using the current standard locks (ECDH).
  3. New Security: Using the new Quantum-Proof locks (ML-KEM).

The Results: A Tiny Speed Bump, No Crash!

Here is what they found, using some analogies:

1. The "Handshake" Delay (Setting up the tunnel)
Before two computers can talk securely, they have to shake hands and exchange keys.

  • The Old Way: The handshake took a certain amount of time.
  • The New Way: The Quantum-Proof handshake took a little longer because the math is more complex.
  • The Result: The new locks added about 3 to 5 milliseconds (that's 0.003 to 0.005 seconds) to the setup time.
    • Analogy: Imagine walking through a security checkpoint at an airport. The old scanner took 10 seconds. The new, super-secure scanner took 13 seconds. It's a tiny bit slower, but you still make your flight.

2. The "Driving" Speed (Running the network)
Once the handshake is done and the secure tunnel is open, the data starts flowing.

  • The Result: The new locks had zero impact on the actual speed of the data or the stability of the control tower. The "cars" (data packets) drove just as fast as before.
    • Analogy: Once you've passed the security checkpoint, the highway speed is exactly the same. The new lock doesn't make the car engine slower; it just took a tiny bit longer to get the key to start the engine.

Why This Matters

The paper concludes that we can upgrade our security without breaking the network.

  • Feasibility: It is possible to install these "Quantum-Proof" locks on the critical control parts of 5G networks.
  • Cost: The "cost" is just a tiny delay (3-5 ms) when the connection is first made. This is small enough that it won't ruin your video calls or game performance.
  • Future-Proofing: By doing this now, mobile operators can protect their data against future quantum computers without having to shut down their networks or slow them down significantly.

The Future: "Teamwork" for Security

The authors also mentioned a cool idea for the future: Federated Learning.

  • Analogy: Imagine every cell tower in the world is a detective. Instead of sending all their clues to a central police station (which might be slow or risky), they share their "lessons learned" with each other. If one tower spots a new type of quantum attack, it teaches the others instantly. This way, the whole network gets smarter and safer together, without sharing sensitive secrets.

Summary

The paper is a "proof of concept" that says: "Don't panic about quantum computers. We have tested the new locks, and they fit perfectly. They add a tiny, manageable delay to the setup, but once the network is running, it's business as usual." This gives mobile operators the green light to start upgrading their systems today.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →