How Rakuten Mobile built a Secure Open RAN network

By Krishna Pramod Adharapurapu

It’s been six years since Rakuten launched a mobile revolution with the world’s first large-scale commercial Open RAN network. Just as personal computers have replaced mainframes and cloud computing has displaced on-premises data centers, our network has transformed the telecommunications industry – and contributed to a significant price reduction for Japanese consumers.

Just as importantly, Rakuten Mobile has also demonstrated that Open RAN can be deployed securely on our national Japanese network, contrary to critics’ claims. In 2022, Europe’s cybersecurity agency ENISA published a Threat Landscape for Open RAN that identified several risks and vulnerabilities associated with Open RAN deployments. Since then, the O-RAN ALLIANCE has worked to reduce these risks, implementing a series of new security requirements and controls. I am one of the new co-chairs of the O-RAN ALLIANCE Work Group 11, responsible for security.

We presented these improvements in Brussels at a workshop and again in Barcelona at the 2026 Mobile World Congress. It’s also encouraging to hear from Germany’s 1&1, which announced that it had successfully migrated all of its 12.5 million customers to an Open RAN network, which we helped build.

Our new security measures in Rakuten Mobile are far-reaching. We now enforce a lifecycle management process to verify third-party apps. New protocols protect data transmitted over the Open RAN network interfaces. Additional security controls protect the core radio units. Initial security requirements have been adopted for artificial intelligence/machine learning models. Vendors must now provide and attest to a Software Bill of Materials for supply chain security, and hardware devices must incorporate secure boot and other security assurances. A detailed explanation of the new security measures specified for Open RAN can be found here.

Let me acknowledge an obvious caveat: no security system is completely impenetrable. Vulnerabilities always remain. Breaches happen and security is a continuous process of identifying, assessing, and mitigating evolving threats rather than achieving absolute protection.

Even so, the results of our efforts are impressive. While hackers have exposed flaws in traditional networks, our platform was built with a security-first mindset to mitigate vulnerabilities. Traditionally, a few large vendors dominated mobile communications infrastructure, constructing expensive, vertical, top-down, proprietary systems in which they controlled both the software and hardware. Our Open RAN network is bottom-up, software-driven, running on commercial off-the-shelf servers, and powered via the cloud. It uses multiple vendors, mixing and matching them as needed.

While traditionalists equate the moniker Open with open to hackers, arguing that multiple vendors are inherently less secure than a single end-to-end vendor, our experience has shown that open technology can be as secure as – or more secure than – closed technology, provided it is deployed with robust security controls. Single-vendor deployments may introduce concentration risk, where the compromise of a widely deployed component or supplier can have broad operational consequences. As an example, the advanced cyber attackers like Salt Typhoon penetrated major US telecommunications companies – ultimately breaching no fewer than nine of the phone carriers and accessing Americans’ texts and calls in real time.

In contrast, open architecture allows operators to control what they put on their networks. No single vendor controls the system. With our Open RAN system, each vendor is responsible for securing their own components. Thanks to high transparency and component-level visibility, it is considerably easier for operators to identify, isolate, and remediate affected components. To guard against potential vulnerabilities across our diverse supplier ecosystem, we have adopted a Zero Trust architecture – grounded in the principle of “Never trust, always verify.” No component or vendor is inherently trusted; every interaction is authenticated and authorized.

Our supply chain is transparent – we work to ensure the integrity of all key components through Software Bills of Materials (SBOMs), secure boot, and cryptographic signing. This open architecture makes it significantly easier to resolve many issues than in traditional, proprietary systems, by switching out software or hardware. By eliminating proprietary ‘black boxes’, our open interfaces provide transparency into system components, enabling more effective security validation and lifecycle management. This should be music to the ears of security hawks – and reassure our over 10 million Japanese customers.


Krishna Pramod Adharapurapu is Rakuten Symphony’s Senior Director of Security Standards and Research, and co-chair of Work Group 11 of the O-RAN ALLIANCE

Tags
Show More
Back to top button