> For the complete documentation index, see [llms.txt](https://docs.gxc.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.gxc.io/docs/onyx-software/onyx-security-specification.md).

# Onyx Security Specification

GXC's Onyx solution is a fully integrated, cloud-orchestrated platform for deploying and managing secure, private 4G and 5G cellular networks. Designed for enterprise and industrial environments, Onyx delivers robust, multi-layered security across the radio, edge, core, and management planes, ensuring data sovereignty and enterprise control.

## Security Architecture

Cellular networks operate across three distinct planes that separate functions for optimal performance, scalability, and security:

* End-to-end encryption and segmentation across all network layers
* Zero trust enforcement with least-privilege access control
* Full enterprise control over user, control, and management plane data
* Secure device onboarding and identity protection with SIM-based and cryptographic mechanisms
* Scalable orchestration and monitoring through the centralized Onyx Portal

## Data Flow and Security

Cellular networks operate across three distinct planes that separate functions for optimal performance, scalability, and security:

* **User Plane (Data Plane)** – Transports all application-level traffic between user devices and enterprise application services or external destinations, including the actual data payloads.
* **Control Plane** – Manages signaling between user devices and the network to establish, manage, and secure sessions, authenticate devices, and enforce mobility and QoS policies.
* **Management Plane** – Handles configuration, monitoring, orchestration, authentication records, and logs. It supports administrative control and operational visibility across the network.

The Onyx platform implements layered security across all three planes, ensuring enterprise data sovereignty and compliance while maintaining seamless usability and scale.

### **(4G & 5G) On-Premises Deployments**&#x20;

In on-premises deployments, user and control plane traffic terminate locally, ensuring full enterprise data ownership. Only minimal operational metadata is sent to the cloud-based Orchestrator, preserving data sovereignty by keeping sensitive application and session data within enterprise boundaries.

<p align="center"><strong>Data Flow &#x26; Security in 4G &#x26; 5G On-Premises Deployments</strong></p>

<div data-with-frame="true"><figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FugUGmmbe9tyTWe1nBnRI%2Fimage.png?alt=media&amp;token=1d15d37f-baec-4618-8095-cbf05bea7aa0" alt=""><figcaption></figcaption></figure></div>

<p align="center"><strong>4G On-Premises Sequence Diagram</strong></p>

<div data-with-frame="true"><figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FygYC3wunT8nW8ndANX8t%2Fimage.png?alt=media&amp;token=fbafa964-48d3-424a-88d4-ce45a6cb65f2" alt=""><figcaption></figcaption></figure></div>

<p align="center"><strong>5G On-Premises Sequence Diagram</strong></p>

<div data-with-frame="true"><figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FOlequWlJYcaApC4e893n%2Fimage.png?alt=media&amp;token=eb7d1540-b62b-46cf-b4e2-add7e121e4cf" alt=""><figcaption></figcaption></figure></div>

### **(4G) Cloud Deployments**

In cloud deployments, all traffic is securely routed to a cloud-hosted Onyx Edge, enabling centralized orchestration without on-premises infrastructure. All communications are encrypted in transit, providing rapid scalability and simplified deployment while maintaining robust security controls.

<p align="center"><strong>Data Flow &#x26; Security in 4G Cloud Deployments</strong></p>

<div data-with-frame="true"><figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FiO39aSGwuWTU0DWrScEN%2Fimage.png?alt=media&amp;token=6ff0c578-103c-4be6-8f13-10a812c785d1" alt=""><figcaption></figcaption></figure></div>

<p align="center"><strong>4G Cloud Sequence Diagram</strong></p>

<div data-with-frame="true"><figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FZKe30kwqvmQOxCQsn1RF%2Fimage.png?alt=media&amp;token=7bf4935a-938b-4960-b97a-157d52a81b99" alt=""><figcaption></figcaption></figure></div>

## User Plane

<p align="center"><strong>User Plane in On-Premises Deployments</strong></p>

<div data-with-frame="true"><figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FRJLCpbcxjDII9vPG5cee%2Fimage.png?alt=media&amp;token=c3869e53-409d-4c2a-95b2-c1a09ae1f37c" alt=""><figcaption></figcaption></figure></div>

<p align="center"><strong>User Plane in Cloud Deployments</strong></p>

<div data-with-frame="true"><figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2F1uJFDMGDxowMTOD8lRI7%2Fimage.png?alt=media&amp;token=8dae9831-d0cb-4534-94e5-8b96142adc31" alt=""><figcaption></figcaption></figure></div>

**Protection in Transit**

* (4G) OTA ciphering protects communication between UE and Onyx RAN using up to 128-EEA2 for encryption and 128-EIA2 for integrity protection
* (5G, On-Premises) OTA ciphering protects communication between UE and Onyx Edge using up to 128-NEA3 for encryption and 128-NIA3 for integrity protection
* (4G, Cloud) IPSec tunnels secure traffic between Onyx APs and the Onyx Edge using AES\_CBC-128 encryption cipher with HMAC-SHA2-256-128 integrity protection
* (On-Premises) APN-mapped VLANs isolate traffic by device group, enabling bridge networking mode, and limiting device exposure across VLAN segments. This supports enforcement of enterprise-managed segmentation and access policies at device group level.\
  VLAN IP domain segregation, combined with DHCP-based IP assignment, enables precise IP tracking and policy-driven access control. Enterprises can assign devices to specific subnets, monitor usage, and enforce local security controls across the enterprise LAN.
* (Cloud) Enterprise-managed firewall enforces traffic filtering and restricts malicious activity
* Enterprises can enforce end-to-end security protocols such as TLS or VPN between UE and enterprise application services to protect user traffic
* (On-Premises) Data is processed locally and handed over to the enterprise network, maintaining full enterprise control
* (Cloud) Data is securely routed to the Onyx Edge

**Protection at Rest**

* Data remains in volatile memory and is never stored persistently

## Control Plane

<p align="center"><strong>Control Plane in On-Premises Deployments</strong></p>

<div data-with-frame="true"><figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2F0s5dQ4JvPWuH8aF3BMaY%2Fimage.png?alt=media&amp;token=01a43e0e-aa75-48b0-845f-86e18ef33fee" alt=""><figcaption></figcaption></figure></div>

<p align="center"><strong>Control Plane in Cloud Deployments</strong></p>

<figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FRztSk4898u0oRfNJXCCH%2Fimage.png?alt=media&amp;token=3684e4be-f1c6-4aa9-91cf-403a1951f657" alt=""><figcaption></figcaption></figure>

**Protection in Transit**

* (4G, Cloud) IPSec tunnels secure traffic between Onyx APs and the Onyx Edge using AES\_CBC-128 encryption cipher with HMAC-SHA2-256-128 integrity protection
* Encrypted NAS signaling protects communication between UE and Onyx Edge using SNOW-3G and AES-CTR encryption across 4G (128-EEA1/EEA2) and 5G (128-NEA1/NEA2) networks
* 4G/5G AKA authenticates devices and establishes shared encryption keys
* Milenage performs SIM-based challenge-response authentication and key derivation
* (5G, On-Premises) SUCI encryption shields subscriber identifiers using AES-128 in CTR mode with HMAC-SHA-256 integrity protection (3GPP Profile A)
* IMSI Lock with IMEI binding restricts SIM/eSIM usage to authorized devices to prevent unauthorized SIM transfers, SIM swap attacks, and device impersonation
* (On-Premises) All signaling transactions terminate at the Onyx Edge
* (Cloud) Signaling is securely routed to the Onyx Edge
* (Cloud) Enterprise-managed firewall enforces traffic filtering and restricts malicious activity
* Enterprise network remains oblivious to control plane operations

**Protection at Rest**

* Minimal control plane data required for Orchestrator operations is encrypted in transit and securely stored on the Orchestrator using encryption at rest

## Management Plane

<p align="center"><strong>Management Plane in On-Premises Deployments</strong></p>

<figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FrSWMwoiswS1FJzEsns23%2Fimage.png?alt=media&amp;token=fa86ae93-02b6-4fb0-9d60-ddc69f82baca" alt=""><figcaption></figcaption></figure>

<p align="center"><strong>Management Plane in Cloud Deployments</strong></p>

<figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FSqVomNvWEmYgzVWDOuRA%2Fimage.png?alt=media&amp;token=e34f920c-4fe6-4359-b93a-6bc2d6da52b8" alt=""><figcaption></figcaption></figure>

**Protection in Transit**

* TLS encryption (TLS 1.2/1.3) secures management traffic across all components using TLS\_ECDHE\_RSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_DHE\_RSA\_WITH\_AES\_256\_GCM\_SHA384, TLS\_AES\_256\_GCM\_SHA384, and TLS\_AES\_128\_GCM\_SHA256 cipher suites
* (5G) Secure NETCONF interface enables authenticated, automated RAN setup and configuration
* Cryptographically signed OTA equipment software updates are securely delivered and verified to ensure integrity and authenticity
* SIM/eSIM credentials and authentication tokens are transmitted from the Orchestrator to the Onyx Edge over encrypted channels
* Integrated CBRS Domain Proxy enables compliant, interference-free shared spectrum operations through encrypted communication with the SAS
* Enterprise-managed firewall enforces traffic filtering and restricts malicious activity
* Minimal management metadata is securely sent to the Orchestrator
* Enterprise network remains oblivious to management operations

**Protection at Rest**

* Data is encrypted to ensure confidentiality and prevent unauthorized access
* AWS key management services and credential safeguards protect stored credentials and sensitive assets
* Backups of configuration and operational data are encrypted and stored with geographical redundancy
* AWS IMDSv2 strengthens instance-level metadata protection, securing credentials and sensitive metadata in cloud instances
* Cryptographically signed OTA update packages are verified before installation to ensure software integrity

## Device Access

Device access in the Onyx platform is secured through layered controls within the enterprise network. The Onyx Portal / Orchestrator securely manage SIM provisioning, access policies, and configuration, providing control and end-to-end visibility across the network.

<p align="center"><strong>Device Access in On-Premises Deployments</strong></p>

<figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FkKMWA2f2LRYGDoImlGAc%2Fimage.png?alt=media&amp;token=c9adc0c7-d636-43c8-b415-17bbff59a045" alt=""><figcaption></figcaption></figure>

<p align="center"><strong>Device Access in Cloud Deployments</strong></p>

<figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2Fg8oqCn14CPjxc0GZU264%2Fimage.png?alt=media&amp;token=09131b5a-d0da-4a5f-892d-f48ca4179b84" alt=""><figcaption></figcaption></figure>

* (4G) OTA ciphering protects communication between UE and Onyx RAN using up to 128-EEA2 for encryption and 128-EIA2 for integrity protection
* (5G, On-Premises) OTA ciphering protects communication between UE and Onyx Edge using up to 128-NEA3 for encryption and 128-NIA3 for integrity protection
* (4G, Cloud) IPSec tunnels secure traffic between Onyx APs and the Onyx Edge using AES\_CBC-128 encryption cipher with HMAC-SHA2-256-128 integrity protection
* Encrypted NAS signaling protects communication between UE and Onyx Edge using SNOW-3G and AES-CTR encryption across 4G (128-EEA1/EEA2) and 5G (128-NEA1/NEA2) networks
* 4G/5G AKA authenticates devices and establishes shared encryption keys
* Milenage performs SIM-based challenge-response authentication and key derivation
* (5G, On-Premises) SUCI encryption shields subscriber identifiers using AES-128 in CTR mode with HMAC-SHA-256 integrity protection (3GPP Profile A)
* IMSI Lock with IMEI binding restricts SIM/eSIM usage to authorized devices to prevent unauthorized SIM transfers, SIM swap attacks, and device impersonation
* (On-Premises) APN-mapped VLANs isolate traffic by device group, enabling bridge networking mode, and limiting device exposure across VLAN segments. This supports enforcement of enterprise-managed segmentation and access policies at device group level.\
  VLAN IP domain segregation, combined with DHCP-based IP assignment, enables precise IP tracking and policy-driven access control. Enterprises can assign devices to specific subnets, monitor usage, and enforce local security controls across the enterprise LAN.
* (Cloud) Enterprise-managed firewall enforces traffic filtering and restricts malicious activity
* Enterprises can enforce end-to-end security protocols such as TLS or VPN between UE and enterprise application services to protect user traffic

## **GXC Equipment Access**

**Onyx Edge**

* Supports key-based SSH and local console access for the “agw\_user” account, enabling customers to log on to collect basic debug information, restart services, reboot the system, etc.
* Onyx Portal users have RBAC-restricted access to a limited set of diagnostic commands and troubleshooting features; all operations are audit logged
* GXC Engineering has direct login and key-based SSH access for troubleshooting operations
* Network port exposure is limited by design to minimize the attack surface
* All user operations and administrative actions are audit logged

**Onyx AP**

* GXC Engineering has secure, authenticated access for troubleshooting operations
* Configuration and updates are delivered via the Onyx Edge; all changes are audit logged
* Onyx APs are generally isolated from the enterprise network, preventing direct network access

**Mesh Node**

* Managed via the Onyx Edge with no direct network access
* Configuration and updates are delivered via the Onyx Edge; all changes are audit logged

**(5G) FHM**

* Managed via the Onyx Edge with no direct network access
* Configuration and updates are delivered via the Onyx Edge; all changes are audit logged

## Onyx Portal User Access & Third-Party Integrations

**Onyx Portal User Access**

* Logically isolated environments for each GXC partner and customer tenant enforce administrative separation and secure access boundaries, preventing cross-tenant data exposure
* SSO with MFA strengthens user authentication for Onyx Portal access
* CAPTCHA mechanisms, including reCAPTCHA, prevent automated credential abuse by bots
* Bcrypt-hashed user credentials mitigate brute-force and rainbow table attacks
* RBAC enforces least-privilege access for all Onyx Portal functions
* Flexible integration with enterprise IdPs enables seamless alignment with existing authentication frameworks and security policies
* Comprehensive audit logging tracks all access, configuration, and authentication events, with 60 days log retention
* AWS WAF protects Onyx Portal web interface against common attack vectors
* AWS GuardDuty continuously detects infrastructure threats and anomalies

**Third-Party API Integrations**

* API integrations allowing enterprises to export telemetry and logs to third-party applications are entirely optional and controlled by enterprise policy
* All API integrations use tokenized, tightly scoped connections with short-lived tokens
* Continuous validation and strict token-scoped permissions ensure secure access
* Comprehensive audit logging tracks all third-party API access and activities with 60 days log retention

## Compliance & Certifications

* FCC-certified for Part 96 compliance, supporting shared CBRS spectrum use in the United States
* SOC 2 Type I certification affirms GXC's internal controls to safeguard customer data

\* Specifications are subject to change without prior notice.

\* For definitions of acronyms and abbreviations used in this spec sheet, refer to the *GXC Glossary*.

## Contact GXC

To get in touch with GXC, please visit <https://gxc.io/contact-us/>.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.gxc.io/docs/onyx-software/onyx-security-specification.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
