Towards a Zero-Trust Supply-Chain Assurance Rubric for ORAN RIC Applications
Chun Yin Chiu

TL;DR
This paper proposes a comprehensive zero-trust supply-chain assurance rubric for O-RAN RIC applications, integrating threat modeling, security controls, and onboarding assurance levels to enhance security in open RAN environments.
Contribution
It introduces an app-centric threat model, a threat-control-evidence mapping aligned with security standards, and an operator-facing assurance profile for incremental onboarding.
Findings
Case-study walkthroughs demonstrate rubric application.
Workflow supports explicit decision-making during app onboarding.
Evaluation focuses on applicability, not deployment-scale performance.
Abstract
Open RAN enables third-party xApps and rApps to be onboarded and updated at operational cadence, creating a software supply chain that spans developers, CI systems, registries, onboarding pipelines, and runtime enforcement points. This preprint proposes a zero-trust supply-chain assurance rubric for O-RAN RIC applications. It makes three contributions: first, an app-centric lifecycle threat model for RIC applications across build, signing, publication, onboarding, runtime, and update or rollback stages; second, a WG11-aligned threat-control-evidence mapping that relates lifecycle threats to O-RAN security baselines and complementary supply-chain evidence; and third, an operator-facing assurance profile that combines secure software development practices, SBOM transparency, and SLSA-style provenance into incremental onboarding levels. Analytical case-study walkthroughs and a minimal…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
