Lightweight Security for Private Networks: Real-World Evaluation of WireGuard

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Djuitcheu, Hubert, Sergeev, Andrew, Alam, Khurshid, Santhosh, Danny, Autenrieth, Achim, Seitz, Jochen
Formato: Preprint
Publicado: 2025
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866915668158316544
author Djuitcheu, Hubert
Sergeev, Andrew
Alam, Khurshid
Santhosh, Danny
Autenrieth, Achim
Seitz, Jochen
author_facet Djuitcheu, Hubert
Sergeev, Andrew
Alam, Khurshid
Santhosh, Danny
Autenrieth, Achim
Seitz, Jochen
contents This paper explores WireGuard as a lightweight alternative to IPsec for securing the user plane as well as the control plane in an industrial Open RAN deployment at the Adtran Terafactory in Meiningen. We focus on a realistic scenario where external vendors access their hardware in our 5G factory network, posing recurrent security risks from untrusted gNBs and intermediate network elements. Unlike prior studies limited to lab setups, we implement a complete proof-of-concept in a factory environment and compare WireGuard with IPsec under industrial traffic conditions. Our approach successfully protects user data (N3 interface) against untrusted gNBs and man-in-the-middle attacks while enabling control plane (N2 interface) authentication between the access and mobility management functions (AMF) and gNB. Performance measurements show that WireGuard adds minimal overhead in throughput, latency, and Central Processing Unit (CPU) usage, achieving performance comparable to IPsec. These findings demonstrate that WireGuard offers competitive performance with significantly reduced configuration complexity, making it a strong candidate for broader adoption in O-RAN, providing a unified, lightweight security layer across multiple interfaces and components.
format Preprint
id arxiv_https___arxiv_org_abs_2512_10135
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Lightweight Security for Private Networks: Real-World Evaluation of WireGuard
Djuitcheu, Hubert
Sergeev, Andrew
Alam, Khurshid
Santhosh, Danny
Autenrieth, Achim
Seitz, Jochen
Cryptography and Security
Networking and Internet Architecture
High Energy Physics - Experiment
This paper explores WireGuard as a lightweight alternative to IPsec for securing the user plane as well as the control plane in an industrial Open RAN deployment at the Adtran Terafactory in Meiningen. We focus on a realistic scenario where external vendors access their hardware in our 5G factory network, posing recurrent security risks from untrusted gNBs and intermediate network elements. Unlike prior studies limited to lab setups, we implement a complete proof-of-concept in a factory environment and compare WireGuard with IPsec under industrial traffic conditions. Our approach successfully protects user data (N3 interface) against untrusted gNBs and man-in-the-middle attacks while enabling control plane (N2 interface) authentication between the access and mobility management functions (AMF) and gNB. Performance measurements show that WireGuard adds minimal overhead in throughput, latency, and Central Processing Unit (CPU) usage, achieving performance comparable to IPsec. These findings demonstrate that WireGuard offers competitive performance with significantly reduced configuration complexity, making it a strong candidate for broader adoption in O-RAN, providing a unified, lightweight security layer across multiple interfaces and components.
title Lightweight Security for Private Networks: Real-World Evaluation of WireGuard
topic Cryptography and Security
Networking and Internet Architecture
High Energy Physics - Experiment
url https://arxiv.org/abs/2512.10135