Submitted:
20 July 2026
Posted:
20 July 2026
You are already at the latest version
Abstract
Keywords:
1. Introduction and Motivation
1.1. What This Framework Covers
- Layer 1 — O-RAN resource and placement foundation: Secure resource allocation, function placement, and service-sharing methods for AI-native 6G and O-RAN environments (Pillars 1–3).
- Layer 2 — Confidential edge intelligence: Federated learning, privacy-preserving AI, secure edge computing, and confidential processing built on top of the orchestration substrate (Pillars 4–6).
- Layer 3 — Network-wide orchestration, trust, and verification: A complete cross-domain orchestration framework focused on revenue-aware decision-making, trust management, auditability, resilience, and formal security verification (Pillars 7–9).
1.2. Why Now
1.3. Organisation of the Article
2. Background, Related Work, and the Gap
2.1. The AI-Native 6G Security Lifecycle
- L1: Intelligent device layer – devices with hardware-based identity and secure credentials.
- L2: 6G radio access layer – gNBs, O-RAN components, reconfigurable intelligent surfaces, and non-terrestrial network components.
- L3: Edge intelligence layer – MEC servers, learning aggregators, and AI inference nodes that support low-latency processing [11].
- L4: Trust and access-control layer – policy decision points, policy enforcement points, trust evaluation, and dynamic access decisions.
- L6: Cloud, digital-twin, and orchestration layer – cloud services, network digital twins, and cross-domain orchestration functions [2].

2.2. Where the Orchestration Literature Stands
2.3. Where the Security Literature Stands, and Its Limits
2.4. The Gap This Framework Fills
3. The Framework: Scope, Methodology, and the Nine Pillars
3.1. Overarching Goal
3.2. Specific Goals
- G1
- Establish an O-RAN resource-optimisation substrate—functional-split-aware placement, conflict-aware RIC control-loop scheduling, and dynamic PRB–compute slicing (Pillars 1–3)—on which every higher-layer decision is placed, scheduled, and resourced.
- G2
- Build a confidential and robust intelligence layer—trust-driven federated learning, attested edge inference, and trust-gated xApp sharing—on that substrate (Pillars 4–6).
- G3
- Close the loop with security-aware revenue-optimal orchestration, cross-domain zero-trust slice access, and a resilience-and-formal-verification capstone (Pillars 7–9).
- G4
- Throughout, treat security constraints as first-class terms in the placement and sharing optimisation, rather than as post-hoc filters.
3.3. A Common Methodological Template Across All Nine Pillars
- System (and threat) model A precise statement of entities, assumptions, latency and resource targets, and—for the security-facing pillars—the adversary set (external eavesdropper, malicious device, Sybil, compromised edge, honest-but-curious cloud, federated-learning attacker, AI adversary, DoS/jamming, quantum-capable). The optimisation-facing pillars instead state the workload, capacity, and SLA model.
- Problem formulation An explicit optimisation or protocol-design problem with objective, decision variables, and constraints. Where an NP-hardness or security-reduction argument is available, it is given.
- Solution approach A worked algorithmic strategy expressed as pseudocode (never full implementation), covering relaxation, decomposition, rounding, or the protocol message flow as appropriate.
- Analysis Security properties via ProVerif/Tamarin/AVISPA and game-based or UC proofs; performance via complexity analysis and simulation.
- Evaluation Benchmarks against the natural baselines (PKI, RBAC, FedAvg, TEE-only, OrchestRAN/JADES/OREO as relevant), on NS-3/Simu5G, SUMO+Veins, iFogSim/EdgeCloudSim, Flower, and a Colosseum-style O-RAN emulator.
3.4. The Nine Pillars at a Glance
4. The Orchestration Substrate: Pillars 1–3 (L2–L3, L6)
4.1. Pillar 1 — Functional-Split-Aware Placement of Virtualized O-RAN Functions with Joint O-Cloud Resource Allocation
| Algorithm 1 Split-Aware Placement with Benders Decomposition and Rounding |
|

4.2. Pillar 2 — Joint xApp/rApp Placement and Conflict-Aware Control-Loop Scheduling
| Algorithm 2 Conflict-Aware xApp/rApp Placement and Scheduling |
|

4.3. Pillar 3 — Dynamic RAN Slicing: Joint PRB and O-Cloud Compute Co-Allocation Under SLA
| Algorithm 3 Online PRB–Compute Co-Allocation (drift-plus-penalty) |
|

5. Confidential and Robust Intelligence: Pillars 4–6 (L3–L4, L6)
5.1. Pillar 4 — Trust-Weighted Robust Federated Learning for the 6G Edge
| Algorithm 4 Trust-Weighted Robust Secure Aggregation (round t) |
|

5.2. Pillar 5 — Attested, Verifiable Confidential Edge Inference
| Algorithm 5 Attested Confidential Edge Inference (device i, edge ) |
|

5.3. Pillar 6 — Security-Aware xApp Sharing and Placement
| Algorithm 6 Security-Aware xApp Sharing and Placement |
|

6. Network-Wide Orchestration, Cross-Domain Trust, and Assurance: Pillars 7–9 (L4–L6)
6.1. Pillar 7 — Revenue-Optimal Secure Service Orchestration
| Algorithm 7 Security-Aware Revenue-Optimal Orchestration (SA-JADES) |
|

6.2. Pillar 8 — Cross-Domain Zero-Trust Slice Access
| Algorithm 8 Cross-Domain Zero-Trust Continuous Authorisation |
|

6.3. Pillar 9 — Resilience, Auditability, and End-to-End Formal Assurance (Capstone)
| Algorithm 9 End-to-End Assurance and Resilience Evaluation |
|

7. How the Nine Pillars Fit Together
- The
- placement–sharing thread The O-Cloud placement and resource model built in P1, extended by P2’s control-app deployment model and P3’s slice model, is exactly the structure that P6 makes security-aware and P7 turns revenue-optimal. The optimisation spine of this framework runs unbroken from Pillar 1 to Pillar 7, in the JADES/OREO lineage.
- The
- trust thread A single trust score is defined where it is first needed (P4, for federated-learning eligibility and weighting) and then reused unchanged: it decides orchestration eligibility (P7) and drives cross-domain authorisation (P8). One definition, many consumers—this is what prevents the “each mechanism in isolation” failure mode.
- The
- post-quantum thread The hybrid ECC + ML-KEM session construction is designed in P5 (where attested confidential offload first needs it) and reused by P4 and P8, so the confidential-intelligence and cross-domain layers inherit quantum resilience from a single well-analysed primitive rather than re-inventing it per pillar.
- The
- audit thread The append-only, hash-only ledger discipline (model hashes, attestation outcomes, revocation, cross-domain evidence—never raw data) is set in P4/P5 and honoured by P7 and P8, so that P9 can prove auditability by construction.
8. Expected Impact and Concluding Remarks
8.1. Scientific Impact
8.2. Practical and Societal Impact
8.3. Concluding Remarks
References
- Saad, W.; Bennis, M.; Chen, M. A Vision of 6G Wireless Systems: Applications, Trends, Technologies, and Open Research Problems. IEEE Netw. 2020, 34, 134–142. [Google Scholar]
- Kukliński, S.; Tomaszewski, L.; Kołakowski, R. On O-RAN, MEC, SON and Network Slicing Integration. In Proceedings of the Proc. IEEE Globecom Workshops (GC Wkshps), 2020; pp. 1–6. [Google Scholar]
- Klement, F.; et al. Toward Securing the 6G Transition: A Comprehensive Empirical Method to Analyze Threats in O-RAN Environments. IEEE J. Sel. Areas Commun. 2024, 42, 420–431. [Google Scholar] [CrossRef]
- Liyanage, M.; Braeken, A.; Shahabuddin, S.; Ranaweera, P. Open RAN Security: Challenges and Opportunities. J. Netw. Comput. Appl. 2023, 214, 103621. [Google Scholar] [CrossRef]
- Cui, J.; Wu, D.; Zhang, J.; Xu, Y.; Zhong, H. An Efficient Authentication Scheme Based on Semi-Trusted Authority in VANETs. IEEE Trans. Veh. Technol. 2019, 68, 2972–2986. [Google Scholar] [CrossRef]
- Ranaweera, P.; Jurcut, A.D.; Liyanage, M. Survey on Multi-Access Edge Computing Security and Privacy. IEEE Commun. Surv. Tutor. 2021, 23, 1078–1124. [Google Scholar] [CrossRef]
- Guo, Y.; Tütüncüoğlu, F.; Javeed, A.; Dán, G. Revenue Optimal Orchestration of ML-Based Services With Dependencies Under Delay and Quality Constraints in Beyond 5G RAN. IEEE/ACM Trans. Netw. 2026, 34, 4403–4415. [Google Scholar] [CrossRef]
- Mungari, F.; Puligheddu, C.; Garcia-Saavedra, A.; Chiasserini, C.F. O-RAN Intelligence Orchestration Framework for Quality-Driven xApp Deployment and Sharing. IEEE Trans. Mob. Comput. 2025, 24, 4811–4828. [Google Scholar] [CrossRef]
- Polese, M.; Bonati, L.; D’Oro, S.; Basagni, S.; Melodia, T. Understanding O-RAN: Architecture, Interfaces, Algorithms, Security, and Research Challenges. IEEE Commun. Surv. Tutor. 2023, 25, 1376–1411. [Google Scholar] [CrossRef]
- Abdalla, A.S.; Upadhyaya, P.S.; Shah, V.K.; Marojevic, V. Toward Next Generation Open Radio Access Networks: What O-RAN Can and Cannot Do! IEEE Netw. 2022, 36, 206–213. [Google Scholar] [CrossRef]
- Liu, Y.; Peng, M.; Shou, G.; Chen, Y.; Chen, S. Toward Edge Intelligence: Multiaccess Edge Computing for 5G and Internet of Things. IEEE Internet Things J. 2020, 7, 6722–6747. [Google Scholar] [CrossRef]
- Xu, H.; Klaine, P.V.; Onireti, O.; Cao, B.; Imran, M.; Zhang, L. Blockchain-Enabled Resource Management and Sharing for 6G Communications. Digit. Commun. Netw. 2020, 6, 261–269. [Google Scholar] [CrossRef]
- Maksymyuk, T.; Gazda, J.; Volosin, M.; Bugar, G.; Horvath, D.; Klymash, M.; Dohler, M. Blockchain-Empowered Framework for Decentralized Network Management in 6G. IEEE Commun. Mag. 2020, 58, 86–92. [Google Scholar] [CrossRef]
- Bonati, L.; Polese, M.; D’Oro, S.; Basagni, S.; Melodia, T. Open, Programmable, and Virtualized 5G Networks: State-of-the-Art and the Road Ahead. Comput. Netw. 2020, 182, 107516. [Google Scholar] [CrossRef]
- D’Oro, S.; Bonati, L.; Polese, M.; Melodia, T. OrchestRAN: Orchestrating Network Intelligence in the Open RAN. IEEE Trans. Mob. Comput. 2024, 23, 7952–7968. [Google Scholar] [CrossRef]
- Maxenti, S.; D’Oro, S.; Bonati, L.; Polese, M.; Capone, A.; Melodia, T. ScalO-RAN: Energy-Aware Network Intelligence Scaling in Open RAN. In Proceedings of the Proc. IEEE INFOCOM, 2024; pp. 891–900. [Google Scholar]
- Bonati, L.; D’Oro, S.; Polese, M.; Basagni, S.; Melodia, T. Intelligence and Learning in O-RAN for Data-Driven NextG Cellular Networks. IEEE Commun. Mag. 2021, 59, 21–27. [Google Scholar] [CrossRef]
- Padmanabhan, M.R.; Zhu, Y.; Basu, S.; Pavan, A. Maximizing Submodular Functions Under Submodular Constraints. In Proceedings of the Proc. Uncertainty in Artificial Intelligence (UAI), 2023; pp. 1618–1627. [Google Scholar]
- Nesterov, Y.; Nemirovskii, A. Interior-Point Polynomial Algorithms in Convex Programming; SIAM: Philadelphia, PA, USA, 1994. [Google Scholar]
- Lyu, L.; Yu, H.; Ma, X.; Chen, C.; Sun, L.; Zhao, J.; Yang, Q.; Yu, P.S. Privacy and Robustness in Federated Learning: Attacks and Defenses. IEEE Trans. Neural Netw. Learn. Syst. 2024, 35, 8726–8746. [Google Scholar] [CrossRef] [PubMed]
- Larsen, L.M.P.; Checko, A.; Christiansen, H.L. A Survey of the Functional Splits Proposed for 5G Mobile Crosshaul Networks. IEEE Commun. Surv. Tutor. 2019, 21, 146–172. [Google Scholar] [CrossRef]
- Kazemifard, N.; Shah-Mansouri, V. Minimum Delay Function Placement and Resource Allocation for Open RAN (O-RAN) 5G Networks. Comput. Netw. 2021, 188. [Google Scholar] [CrossRef]
- Matoussi, S.; Fajjari, I.; Costanzo, S.; Aitsaadi, N.; Langar, R. 5G RAN: Functional Split Orchestration Optimization. IEEE J. Sel. Areas Commun. 2020, 38, 1448–1463. [Google Scholar] [CrossRef]
- Murti, F.W.; Ali, S.; Latva-aho, M. Constrained Deep Reinforcement Based Functional Split Optimization in Virtualized RANs. IEEE Trans. Wirel. Commun. 2022, 21, 9850–9864. [Google Scholar] [CrossRef]
- Pamuklu, T.; Erol-Kantarci, M.; Ersoy, C. Reinforcement Learning Based Dynamic Function Splitting in Disaggregated Green Open RANs. In Proceedings of the Proc. IEEE International Conference on Communications (ICC), 2021; pp. 1–6. [Google Scholar]
- Ojaghi, B.; Adelantado, F.; Verikoukis, C. SO-RAN: Dynamic RAN Slicing via Joint Functional Splitting and MEC Placement. IEEE Trans. Veh. Technol. 2023, 72, 1925–1939. [Google Scholar] [CrossRef]
- Lacava, A.; Polese, M.; Sivaraj, R.; Soundrarajan, R.; Bhati, B.S.; Singh, T.; Zugno, T.; Cuomo, F.; Melodia, T. Programmable and Customized Intelligence for Traffic Steering in 5G Networks Using Open RAN Architectures. IEEE Trans. Mob. Comput. 2024, 23, 2882–2897. [Google Scholar] [CrossRef]
- Adamczyk, C.; Kliks, A. Conflict Mitigation Framework and Conflict Detection in O-RAN Near-RT RIC. IEEE Commun. Mag. 2023, 61, 199–205. [Google Scholar] [CrossRef]
- Wadud, A.; Golpayegani, F.; Afraz, N. QACM: QoS-Aware xApp Conflict Mitigation in Open RAN. IEEE Trans. Green Commun. Netw. 2024, 8, 978–993. [Google Scholar] [CrossRef]
- Brach del Prever, P.; D’Oro, S.; Bonati, L.; Polese, M.; Tsampazi, M.; Lehmann, H.; Melodia, T. PACIFISTA: Conflict Evaluation and Management in Open RAN. IEEE Trans. Mob. Comput. 2025, 24, 10590–10605. [Google Scholar] [CrossRef]
- Adamuz-Hinojosa, O.; Zanzi, L.; Sciancalepore, V.; Costa-Pérez, X. MAREA: A Delay-Aware Multi-Time-Scale Radio Resource Orchestrator for 6G O-RAN. IEEE Transactions on Communications, 2025. [Google Scholar]
- Filali, A.; Mlika, Z.; Cherkaoui, S.; Kobbane, A. Dynamic SDN-Based Radio Access Network Slicing With Deep Reinforcement Learning for URLLC and eMBB Services. IEEE Trans. Netw. Sci. Eng. 2022, 9, 2174–2187. [Google Scholar] [CrossRef]
- Sun, Y.; Peng, M.; Zhou, Y.; Huang, Y.; Mao, S. Application of Machine Learning in Wireless Networks: Key Techniques and Open Issues. IEEE Commun. Surv. Tutor. 2019, 21, 3072–3108. [Google Scholar] [CrossRef]
- Neely, M.J. Stochastic Network Optimization with Application to Communication and Queueing Systems; Morgan & Claypool, 2010. [Google Scholar]
- Mothukuri, V.; Parizi, R.M.; Pouriyeh, S.; Huang, Y.; Dehghantanha, A.; Srivastava, G. A Survey on Security and Privacy of Federated Learning. Future Gener. Comput. Syst. 2021, 115, 619–640. [Google Scholar] [CrossRef]
- Blanco-Justicia, A.; Domingo-Ferrer, J.; Martínez, S.; Sánchez, D.; Flanagan, A.; Tan, K.E. Achieving Security and Privacy in Federated Learning Systems: Survey, Research Challenges and Future Directions. Eng. Appl. Artif. Intell. 2021, 106, 104468. [Google Scholar] [CrossRef]
- Bonawitz, K.; Ivanov, V.; Kreuter, B.; Marcedone, A.; McMahan, H.B.; Patel, S.; Ramage, D.; Segal, A.; Seth, K. Practical Secure Aggregation for Privacy-Preserving Machine Learning. In Proceedings of the Proc. ACM SIGSAC Conf. Computer and Communications Security (CCS), 2017; pp. 1175–1191. [Google Scholar]
- Blanchard, P.; El Mhamdi, E.M.; Guerraoui, R.; Stainer, J. Machine Learning with Adversaries: Byzantine Tolerant Gradient Descent. In Proceedings of the Proc. Advances in Neural Information Processing Systems (NeurIPS), 2017; pp. 119–129. [Google Scholar]
- Jauernig, P.; Sadeghi, A.R.; Stapf, E. Trusted Execution Environments: Properties, Applications, and Challenges. IEEE Secur. Priv. 2020, 18, 56–60. [Google Scholar] [CrossRef]
- Mo, F.; Tarkhani, Z.; Haddadi, H. Machine Learning with Confidential Computing: A Systematization of Knowledge. ACM Comput. Surv. 2024, 56. [Google Scholar] [CrossRef]
- National Institute of Standards and Technology. Module-Lattice-Based Key-Encapsulation Mechanism Standard. Technical Report FIPS 203, 2024. [Google Scholar]
- Stebila, D.; Fluhrer, S.; Gueron, S. Hybrid Key Exchange in TLS 1.3. Technical Report Internet-Draft draft-ietf-tls-hybrid-design; Internet Engineering Task Force, 2023. [Google Scholar]
- Mimran, D.; Bitton, R.; Kfir, Y.; Klevansky, E.; Brodt, O.; Lehmann, H.; Elovici, Y.; Shabtai, A. Security of Open Radio Access Networks. Comput. Secur. 2022, 122, 102890. [Google Scholar] [CrossRef]
- Rose, S.; Borchert, O.; Mitchell, S.; Connelly, S. Technical Report NIST Special Publication 800-207; Zero Trust Architecture. National Institute of Standards and Technology, 2020.
- Syed, N.F.; Shah, S.W.; Shaghaghi, A.; Anwar, A.; Baig, Z.; Doss, R. Zero Trust Architecture (ZTA): A Comprehensive Survey. IEEE Access 2022, 10, 57143–57179. [Google Scholar] [CrossRef]
- Ramezanpour, K.; Jagannath, J. Intelligent Zero Trust Architecture for 5G/6G Networks: Principles, Challenges, and the Role of Machine Learning in the Context of O-RAN. Comput. Netw. 2022, 217, 109358. [Google Scholar] [CrossRef]
- Blanchet, B. Modeling and Verifying Security Protocols with the Applied Pi Calculus and ProVerif. Found. Trends Priv. Secur. 2016, 1, 1–135. [Google Scholar] [CrossRef]
- Meier, S.; Schmidt, B.; Cremers, C.; Basin, D. The TAMARIN Prover for the Symbolic Analysis of Security Protocols. In Proceedings of the Proc. Int. Conf. Computer Aided Verification (CAV), 2013; pp. 696–701. [Google Scholar]
- Nguyen, D.C.; Ding, M.; Pathirana, P.N.; Seneviratne, A.; Li, J.; Niyato, D.; Dobre, O.; Poor, H.V. 6G Internet of Things: A Comprehensive Survey. IEEE Internet Things J. 2022, 9, 359–383. [Google Scholar] [CrossRef]
| # | Pillar (short title) | Layer (L1–L6) | Core techniques |
|---|---|---|---|
| Layer 1 — O-RAN orchestration substrate | |||
| P1 | Split-aware O-RAN function placement & O-Cloud alloc. | L2–L3, L6 | MINLP, Benders decomposition, rounding |
| P2 | Conflict-aware xApp/rApp placement & scheduling | L3, L6 | Lagrangian relaxation, max-weight independent set, EDF |
| P3 | Dynamic slicing: PRB–compute co-allocation | L2–L3 | Lyapunov drift-plus-penalty, online rounding |
| Layer 2 — Confidential intelligence | |||
| P4 | Trust-weighted robust federated learning | L3, L4 | Secure aggregation, robust filtering, trust dynamics |
| P5 | Attested, verifiable confidential edge inference | L3 | TEE attestation, hybrid ECC + ML-KEM sessions |
| P6 | Security-aware xApp sharing & placement | L3, L6 | Legality-constrained MILP, sharing-graph pruning |
| Layer 3 — Orchestration & assurance | |||
| P7 | Revenue-optimal secure service orchestration | L6 | SA-JADES relaxation, block coordinate descent |
| P8 | Cross-domain zero-trust slice access | L4, L5, L6 | Continuous authorisation, privacy-preserving attestations |
| P9 | Resilience, audit & end-to-end formal capstone | L5 (all) | ProVerif/Tamarin, UC composition, resilience frontier |
| # | Consumes (input from) | Produces (used by) |
|---|---|---|
| P1 | — (foundational) | O-Cloud placement & resource model → P2, P6, P7 |
| P2 | P1 placement model | xApp/rApp deployment & scheduling model → P6, P7 |
| P3 | P1 resource model | SLA-driven slice & revenue model → P7 |
| P4 | P3 slice/workload model, secure sessions (P5) | Trust score & robust FL dynamics → P7 (eligibility), P8, P9 |
| P5 | secure sessions, attestation | Hybrid-PQ session + confidential-compute cost → P4, P6, P7, P8 |
| P6 | P1/P2 placement models, P5 attestation classes | Legal-sharing constraint → P7 |
| P7 | P1–P3 resource/slice models, P4–P6 costs & constraints | Security-aware revenue placement → P8, P9 |
| P8 | P4 trust, P5 PQ sessions, P7 placement | Cross-domain trust attestations → P9 |
| P9 | all of P1–P8 | End-to-end proof & resilience frontier |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (http://creativecommons.org/licenses/by/4.0/).