As Open Radio Access Network (O-RAN) deployments expand and adversaries adopt “store-now, decrypt-later” strategies, operators need empirical data on the cost of migrating critical control interfaces to post-quantum cryptography (PQC). This paper experimentally evaluates the impact of integrating a NIST-aligned Module-Lattice Key-Encapsulation Mechanism (ML-KEM) into IKEv2/IPsec, protecting the E2 interface between the 5G Node B (gNB) and the Near-Real-Time RAN Intelligent Controller (Near-RT RIC). Using an open-source testbed built from srsRAN, Open5GS, FlexRIC and strongSwan (with liboqs), we compare three configurations: no IPsec, classical Elliptic Curve Diffie–Hellman (ECDH)-based IPsec, and ML-KEM-based IPsec. This study focuses on IPsec tunnel-setup latency and the runtime behaviour of Near-RT RIC xApps under realistic signalling workloads. Results from repeated, automated runs show that ML-KEM integration adds a small overhead to tunnel establishment, which is approximately 2.7~4.7 ms in comparison to classical IPsec, while xApp operation and RIC control loops remain stable in our experiments. These findings, produced from an open, reproducible testbed, indicate that ML-KEM-based IPsec on the E2 interface is practically feasible and inform quantum-safe migration strategies for O-RAN deployments.
The evolution toward sixth generation (6G) wireless networks promises higher performance, greater flexibility, and enhanced intelligence. However, it also introduces a substantially enlarged attack surface driven by open, disaggregated, and multi-vendor Open RAN (O-RAN) architectures that will be utilised in 6G networks. This paper addresses the urgent need for a practical Zero Trust (ZT) deployment model tailored to O-RAN specification. To do so, we introduce a novel hybrid ZT deployment model that establishes the trusted foundation for AI/ML-driven security in O-RAN, integrating macro-level enclave segmentation with micro-level application sandboxing for xApps/rApps. In our model, the Policy Decision Point (PDP) centrally manages dynamic policies, while distributed Policy Enforcement Points (PEPs) reside in logical enclaves, agents, and gateways to enable per-session, least-privilege access control across all O-RAN interfaces. We demonstrate feasibility via a Proof of Concept (PoC) implemented with Kubernetes and Istio and based on the NIST Policy Machine (PM). The PoC illustrates how pods can represent enclaves and sidecar proxies can embody combined agent/gateway functions. Performance discussion indicates that enclave-based deployment adds 1–10 ms of additional per-connection latency while CPU/memory overhead from running a sidecar proxy per enclave is approximately 5–10% extra utilisation, with each proxy consuming roughly 100–200 MB of RAM.
This paper analyzes two crucial aspects towards the development of upcoming massive cellular Internet of Things (IoT) connections: Open Radio Access Network (O-RAN) and Energy Efficiency (EE). O-RAN offers flexibility, interoperability, multi-connectivity and an intelligent architecture. On the other hand, 80 % of the energy in mobile networks is consumed in the RAN. Therefore, in this paper we present a method to optimize the O-RAN energy efficiency. Specifically, we model the O-RAN energy consumption as an optimization problem and propose a traffic steering method for maximizing energy efficiency. The performance of the proposed method is analyzed by considering realistic parameters and device locations based on the deployments defined in the Liverpool 5G High Density Deployment (HDD) project. The proposed Algorithm 2 achieves 34.69 % higher energy efficiency as compared to Algorithm 1.
The wireless network data are a feasible way to understand the user behavior in a given environment and may be utilized for analysis, prediction and optimization. On the other hand, datasets from wireless service providers are not publicly available, and obtaining a dataset in real time is challenging. In this work, we present a 5G dense deployment dataset obtained from the Liverpool City Region High Density Demand (LCR HDD) project. The project involves network deployment and assessment at Salt Tar and the ACC Arena event venues located in the city of Liverpool. Digital twin technology is considered to generate the dataset, which is inputted to a system level simulator for data modeling and analysis. The data set consists of 3, 000 users in the Salt Tar venue and 12, 000 users in the ACC Arena venue with features including users’ position, traffic type, Radio Unit (RU) association, Signal to Interference and Noise Ratio (SINR), Physical Resource Blocks (PRB), throughput, Block Error Rate (BLER), and a total length of 10, 000 samples. The dataset is validated through experimental measurements and is released in a simple format for easy access.
The Internet of Things (IoT) has been a major part of many use cases for 5G networks. From several of these use cases, it follows that 5G should be able to support at least one million devices per km2. In this paper, we explain that the 5G radio access schemes as used today cannot support such densities. This issue will have to be solved by 6G. However, this requires a fundamentally different approach to accessing the wireless medium compared to current generation networks: they are not designed to support many thousands of devices in each other’s vicinity, attempting to send/receive data simultaneously. In this paper, we present a 6G system architecture for trading wireless network resources in massive IoT scenarios, inspired by the concept of the sharing economy, and using the novel concept of spectrum programming. We simulated a truly massive IoT network and evaluated the scalability of the system when managed using our proposed 6G platform, compared to standard 5G deployments. The experiments showed how the proposed scheme can improve network resource allocation by up to 80%. This is accompanied by similarly significant improvements in interference and device energy consumption. Finally, we performed evaluations that demonstrate that the proposed platform can benefit all the stakeholders that decide to join the scheme.
Fifth-generation (5G) wireless networks have been a key enabler for information societies over the last few years [...]
Wi-Fi is still by far the most common and cheapest wireless technology to deliver Internet services to users and digital devices, which are dramatically increasing in terms of quantity and the quality of services they require. As a result, Wi-Fi networks are the most congested wireless technology. This issue incentivised many researchers to propose radio resource management solutions in unlicensed frequency bands to alleviate that problem. Nonetheless, these solutions lack coordination among the network operators who utilise wireless spectrum and hence, they do not efficiently solve the problem. In this work we propose a ‘win-win’ platform based on Software Defined Wireless Networking (SDWN) that facilitates a trusted and accountable Wi-Fi network access trading among networks operators, to solve the congestion problem in a collaborative manner that is beneficial for everyone. The platform enables Wi-Fi networks operators to both improve their users' satisfaction and earn incentives hence, achieving the ‘win-win’ equilibrium. Evaluation results in a dense Wi-Fi network environment show how the ‘win-win’ platform significantly improves satisfaction and achieved data rates for the cooperating networks operators' users in comparison to the standard approach.
Fifth-generation technologies have reached a stage where it is now feasible to consider deployments that extend beyond traditional public networks. Central to this process is the application of Fixed Wireless Access (FWA) in 5G Non-public Networks (NPNs) that can utilise a novel combination of radio technologies to deploy an infrastructure on top of 5G NR or entirely from scratch. However, the use of FWA backhaul faces many challenges in relation to the trade-offs for reduced costs and a relatively simple deployment. Specifically, the use of meshed deployments is critical as it provides resilience against a temporary loss of connectivity due to link errors. In this paper, we examine the use of meshing in a FWA backhaul to determine if an optimal trade-off exists between the deployment of more nodes/links to provide multiple paths to the nearest Point of Presence (POP) and the performance of the network. Using a real 5G NPN deployment as a basis, we have conducted a simulated analysis of increasing network densities to determine the optimal configuration. Our results show a clear advantage for meshing in general, but there is also a performance trade-off to consider between overall network throughput and stability.
This paper proposes a novel trust-based cooperative system to facilitate efficient Wi-Fi network access trading to solve the network congestion problem in a beneficial manner for both service providers and customers. The proposed system enables service providers to improve their users’ application performance through a novel cooperative Access Point (AP) association solution. The system is based on a Software-Defined Wireless Network (SDWN) controller, which has a global view of users’ devices, requirements, and APs. The SDWN controller is supported by Smart Contracts (SCs) as code of law, to liaise control among service providers according to the terms of their mutual agreements. Evaluation results in dense Wi-Fi network environments show how the system can significantly improve the overall performance for the cooperating network. Specifically, the results have been compared against the standard AP association approach and other centralised algorithms dealing with the same problem, in terms of the data bit rate provided to the users’ stations (STAs), Quality of Experience (QoE), bandwidth and energy consumed by the APs.
We propose a novel vision to trade and allocate wireless spectrum in 6G communication networks inspired by the concept of the sharing economy. We argue that such an approach will help ease the surge in demands for wireless spectrum that will characterise the 6G world. We also introduce HODNET (Heterogeneous on Demand NETwork resource negotiation), an open platform that is able to realise this new spectrum-sharing model. To demonstrate the benefits of spectrum trading and allocation in this new paradigm, we considered the use-case of massive Internet of Things (IoT) on a local scale. We simulated a large IoT deployment and evaluated the spectral efficiency of the system when managed using HODNET compared with a standard 5G deployment. Our experiments show that HODNET can indeed offer better allocation, based on our spectrum sharing model, of spectrum resources compared with standard allocation approaches.
The ongoing deployment of 5G networks is seen as a key enabler for realizing upcoming interconnected services at scale, including the massive deployment of the Internet of Things, providing V2X communications to support autonomous vehicles, and the increase in smart homes, smart cities, and Industry 4 [...]
With the widespread deployment of 5G gaining pace, there is increasing interest in deploying this technology beyond traditional Mobile Network Operators (MNO) into private and community scenarios. These deployments leverage the flexibility of 5G itself to support private networks that sit alongside or even on top of existing public 5G. By utilizing a range of virtualisation and slicing techniques in the 5G Core (5GC) and heterogeneous Radio Access Networks (RAN) at the edge, a wide variety of use cases can be supported by 5G. However, these non-typical deployments may experience different performance characteristics as they adapt to their specific scenario. In this paper we present the results of our work to model and predict the performance of millimeter wave (mmWave) backhaul links that were deployed as part of the Liverpool 5G network. Based on the properties of the 802.11ad protocol and the physical characteristics of the environment, we simulate how each link will perform with different signal-to-noise ratio (SNR) and Packet Error Rate (PER) values and verify them against real-world deployed links. Our results show good convergence between simulated and real results and provide a solid foundation for further network planning and optimization.
This paper proposes an algorithm that enhances horizontal handover (HO) in dense wireless local area networks (WLANs), which is implemented in a software-defined wireless networking (SDWN)-based architecture. The algorithm considers the concept of user prioritisation, classifying the WLAN stations (STAs) into two categories representing high and low priorities respectively, and always attempts to guarantee the best quality of experience (QoE) to the high priority users. The architecture that implements the algorithm leverages the flexibility, programmability, and centralised nature of SDWN to efficiently manage the HO process. Moreover, the paper presents a performance evaluation campaign that demonstrates significant achievements against a state-of-the-art solution in terms of the provided QoE, throughput and delay. Finally, we discuss the importance of considering user prioritisation in a HO algorithm for dense WLAN s.
Cooperation to access wireless networks is a key approach towards optimizing the use of finite radio spectrum resources in overcrowded unlicensed bands and to help satisfy the expectations of wireless users in terms of high data rates and low latency. Although solutions that advocate this approach have been widely proposed in the literature, they still do not consider a number of aspects that can improve the performance of the users’ connections, such as the inclusion of (1) cooperation among network operators and (2) users’ quality requirements based on their applications. To fill this gap, in this paper we propose a centralized framework that is aimed at providing a “win-win” cooperation among Wi-Fi and cellular networks, which takes into account 5G technologies and users’ requirements in terms of Quality of Service (QoS). Moreover, the framework is supported by smart Radio Access Technology (RAT) selection mechanisms that orchestrate the connection of the clients to the networks. In particular, we discuss details on the design of the proposed framework, the motivation behind its implementation, the main novelties, its feasibility, and the main components. In order to demonstrate the benefits of our solution, we illustrate efficiency results achieved through the simulation of a smart RAT selection algorithm in a realistic scenario, which mimics the proposed “win-win” cooperation between Wi-Fi and cellular 5G networks, and we also discuss potential benefits for wireless and mobile network operators.
This paper explores a practical approach to securing large wireless networks by applying Physical Layer Security (PLS). To date, PLS has mostly been seen as an information theory concept with few practical implementations. We present an Access Point (AP) selection algorithm that uses PLS to find an AP that offers the highest secrecy capacity to a legitimate user. We then propose an implementation of this algorithm using the novel concept of spectrum programming which extends Software-Defined Networking to the physical and data-link layers and makes wireless network management and control more flexible and scalable than traditional platforms. Our Wi-Fi network evaluation results show that our approach outperforms conventional solutions in terms of security, but at the expense of communication capacity, thus identifying a trade-off between security and performance. These results encourage implementation and extension to further wireless technologies.
Current interference management solutions for dense IEEE 802.11 Wireless Local Area Networks (WLANs) rely on locally measuring the cumulative interference at the Acess Point (AP) in charge of adjusting the spectrum resources to its clients. These solutions often result in coarse-grained spectrum allocation that often leaves many wireless users unsatisfied and increases the spectrum congestion problem instead of easing it. In this paper, we present a centralized interference management algorithm that treats the network-wide interference impact of each channel individually and allows the controller to adjust the radio resource of each AP while it is utilised. This coordinated allocation takes into account the Quality of Service (QoS) requirements of downlink flows while minimizing its effect on neighbouring APs. Therefore, this paper proposes a novel approach for quantifying the interference impact of each employed channel and jointly addressing the user-side quality requirements and the network-side interference management. The algorithm is tailored for operator-agnostic Software-Defined Networking (SDN)-based Radio Resource Management (RRM) in dense Wireless Fidelity (Wi-Fi) networks and adopts a fine-grained per-flow approach. Simulation results show that our algorithm outperforms existing solutions in terms of reducing the overall interference, increasing the capacity of the wireless channel, and improving the users' satisfaction.
Visualising complex data facilitates a more comprehensive stage for conveying knowledge. Within the medical data domain, there is an increasing requirement for valuable and accurate information. Patients need to be confident that their data is being stored safely and securely. As such, it is now becoming necessary to visualise data patterns and trends in real-time to identify erratic and anomalous network access behaviours. In this paper, an investigation into modelling data flow within healthcare infrastructures is presented; where a dataset from a Liverpool-based (UK) hospital is employed for the case study. Specifically, a visualisation of transmission control protocol (TCP) socket connections is put forward, as an investigation into the data complexity and user interaction events within healthcare networks. In addition, a filtering algorithm is proposed for noise reduction in the TCP dataset. Positive results from using this algorithm are apparent on visual inspection, where noise is reduced by up to 89.84%.
This research concerns the detection of unauthorised access within hospital networks through the real-time analysis of audit logs. Privacy is a primary concern amongst patients due to the rising adoption of Electronic Patient Record (EPR) systems. There is growing evidence to suggest that patients may withhold information from healthcare providers due to lack of Trust in the security of EPRs. Yet, patient record data must be available to healthcare providers at the point of care. Ensuring privacy and confidentiality of that data is challenging. Roles within healthcare organisations are dynamic and relying on access control is not sufficient. Through proactive monitoring of audit logs, unauthorised accesses can be detected and presented to an analyst for review. Advanced data analytics and visualisation techniques can be used to aid the analysis of big data within EPR audit logs to identify and highlight pertinent data points. Employing a human-in-the-loop model ensures that suspicious activity is appropriately investigated and the data analytics is continuously improving. This paper presents a system that employs a Human-in-the-Loop Machine Learning (HILML) algorithm, in addition to a density-based local outlier detection model. The system is able to detect 145 anomalous behaviours in an unlabelled dataset of 1,007,727 audit logs. This equates to 0.014% of the EPR accesses being labelled as anomalous in a specialist Liverpool (UK) hospital.
The rising demand for health and social care, and around the clock monitoring services, is increasing and are unsustainable under current care provisions. Consequently, a safe and independent living environment is hard to achieve; yet the detection of sudden or worsening changes in a patient?s condition is vital for early intervention. The use of smart technologies in primary care delivery is increasing significantly. However, substantial research gaps remain in non-invasive and cost effective monitoring technologies. The inability to learn the unique characteristics of patients and their conditions seriously limits the effectiveness of most current solutions. The smart metering infrastructure provides new possibilities for a variety of applications that are unachievable using the traditional energy grid. By 2020, UK energy suppliers will install 50 million smart meters, therefore, providing access to a highly accurate sensing network. Each smart meter records the electrical load for a given property at 30 minute intervals. This granular data captures detailed habits and routines through the occupant?s interactions with electrical devices, enabling the detection and identification of alterations in behaviour. The research presented in this paper explores how this data could be used to achieve a safe living environment for people living with progressive neurodegenerative disorders.
This work introduces an innovative Access Point (AP) allocation algorithm for dense Wi-Fi networks, which relies on a centralised potential game developed in a Software-Defined Wireless Networking (SDWN)-based framework. The proposed strategy optimises the allocation of the Wi-Fi stations (STAs) to APs and allows their dynamic reallocation according to possible changes in the capacity of the Wi-Fi network. This paper illustrates the design of the proposed framework based on SDWN and the implementation of the potential game-based algorithm, which includes two possible strategies. The main novel contribution of this work is that the algorithm allows us to efficiently reallocate the STAs by considering external interference, which can negatively affect the capacities of the APs handled by the SDWN controller. Moreover, the paper provides a detailed performance analysis of the algorithm, which describes the significant improvements achieved with respect to the state of the art. Specifically, the results have been compared against the AP selection considered by the IEEE 802.11 standards and another centralised algorithm dealing with the same problem, in terms of the data bit rate provided to the STAs, their dissatisfaction and Quality of Experience (QoE). Finally, the paper analyses the trade-off between efficient performance and the computational complexity achieved by the strategies implemented in the proposed algorithm.