polito.it
Politecnico di Torino (logo)

Enhancing O-RAN Fronthaul Synchronization Security: TESLA and ASCON as a MACsec Alternative

Enrico Pisanti

Enhancing O-RAN Fronthaul Synchronization Security: TESLA and ASCON as a MACsec Alternative.

Rel. Antonio Lioy, Elisa Bertino. Politecnico di Torino, Corso di laurea magistrale in Ingegneria Informatica (Computer Engineering), 2025

[img] PDF (Tesi_di_laurea) - Tesi
Accesso riservato a: Solo utenti staff fino al 11 Aprile 2026 (data di embargo).
Licenza: Creative Commons Attribution Non-commercial No Derivatives.

Download (2MB)
Abstract:

Ensuring synchronization in the O-RAN Fronhaul S-Plane is crucial to accurately align timing between network elements and enable latency-sensitive features such as time division duplexing and carrier aggregation. The Precision Time Protocol (PTP) plays a key role in this context, but any vulnerability that compromises synchronization can cause serious impacts on network efficiency and quality of user experience. Although traditional solutions such as MACsec offer link-level encryption and authentication, they introduce a processing overhead that is potentially incompatible with the stringent requirements of O-RAN fronthaul. As an alternative, this work proposes an authentication-based security mechanism that combines the Timed Efficient Stream Loss-Tolerant Authentication (TESLA) protocol with ASCON, a lightweight cryptographic algorithm optimized for integrity. With its delayed key disclosure mechanism, TESLA reduces the risks of spoofing, replay attacks by allowing only legitimate parties to authenticate messages on the fronthaul. In addition, the use of ASCON as an authentication function provides high throughput with minimal computational impact. Authenticated encryption with associated data as implemented in ASCON, ensures that synchronization messages remain readable while still being protected from unauthorized modifications. The results show that the combination of TESLA and ASCON offers a comparable or higher level of security to MACsec, with lower overhead and better compatibility with real-time synchronization constraints, making it a scalable and efficient model for protecting O-RAN fronthaul synchronization.

Relatori: Antonio Lioy, Elisa Bertino
Anno accademico: 2024/25
Tipo di pubblicazione: Elettronica
Numero di pagine: 64
Soggetti:
Corso di laurea: Corso di laurea magistrale in Ingegneria Informatica (Computer Engineering)
Classe di laurea: Nuovo ordinamento > Laurea magistrale > LM-32 - INGEGNERIA INFORMATICA
Ente in cotutela: Purdue University (STATI UNITI D'AMERICA)
Aziende collaboratrici: Purdue University
URI: http://webthesis.biblio.polito.it/id/eprint/35310
Modifica (riservato agli operatori) Modifica (riservato agli operatori)