Lightweight Security for Private Networks: Real-World Evaluation of WireGuard
Hubert Djuitcheu, Andrew Sergeev, Khurshid Alam, Danny Santhosh, Achim Autenrieth, Jochen Seitz

TL;DR
This study evaluates WireGuard as a lightweight, efficient security solution for industrial 5G networks, demonstrating its practical deployment, comparable performance to IPsec, and enhanced security in real-world factory conditions.
Contribution
It provides the first real-world implementation and comparison of WireGuard with IPsec in an industrial 5G environment, highlighting its practicality and performance benefits.
Findings
WireGuard effectively secures user data against untrusted network elements.
Performance of WireGuard is comparable to IPsec in throughput, latency, and CPU usage.
WireGuard offers reduced configuration complexity, facilitating broader adoption in industrial networks.
Abstract
This paper explores WireGuard as a lightweight alternative to IPsec for securing the user plane as well as the control plane in an industrial Open RAN deployment at the Adtran Terafactory in Meiningen. We focus on a realistic scenario where external vendors access their hardware in our 5G factory network, posing recurrent security risks from untrusted gNBs and intermediate network elements. Unlike prior studies limited to lab setups, we implement a complete proof-of-concept in a factory environment and compare WireGuard with IPsec under industrial traffic conditions. Our approach successfully protects user data (N3 interface) against untrusted gNBs and man-in-the-middle attacks while enabling control plane (N2 interface) authentication between the access and mobility management functions (AMF) and gNB. Performance measurements show that WireGuard adds minimal overhead in throughput,…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsSoftware-Defined Networks and 5G · IPv6, Mobility, Handover, Networks, Security · Wireless Communication Security Techniques
