Conceptio › Archive › arXiv CS
arXiv CSopen access

RUN-O-RAN: An O-RAN-Native Architecture Enabling Cooperative Uplink Localization

· arxiv_cs
arXiv CS · Papers · License: Open Access
Open Source ↗Direct PDF ↓
distributed-systemsinternetnetworkingprotocols
networking, internet, protocols, distributed systems

1

RUN-O-RAN: An O-RAN-Native Architecture Enabling Cooperative Uplink Localization Viola Bernazzoli∗ , Alberto Ceresoli∗ , Ilario Filippini∗ ∗ Dipartimento di Elettronica, Informazione e Bioingegneria, (DEIB)

arXiv:2609.20640v1 [cs.NI] 17 Sep 2026

Politecnico di Milano, Milano, Italy 20133 Email: [email protected]

Abstract—Accurate positioning is increasingly required in indoor and dense urban environments; nonetheless, satellitebased systems are not always available, and standardized 5G localization solutions remain difficult to deploy with commercial devices. This paper presents RUN-O-RAN, an O-RAN-native framework that enables network-centric uplink localization using standard Sounding Reference Signal (SRS) transmissions from commercial 5G devices. RUN-O-RAN xApp coordinates serving and neighboring base stations, enabling non-serving base stations to retrieve SRS-based uplink timing measurements that would be unavailable in conventional RAN deployments, without modifying the UE or existing 3GPP signaling procedures. The framework combines cooperative SRS collection, first-path time-of-arrival estimation, timing-advance tracking, clock-drift compensation, and multi-anchor position estimation into a complete networkside localization service. Experimental evaluation over 150, 000 SRS transmissions validates the proposed framework, achieving meter-level localization under diverse propagation conditions while revealing the impact of anchor geometry and multipath on positioning accuracy. These findings demonstrate that cooperative SRS-based localization can be realized within the ORAN ecosystem without modifying commercial UEs, providing a practical foundation for future network-native Integrated Sensing and Communication (ISAC) positioning services.

I. I NTRODUCTION Accurate and reliable positioning is becoming an important requirement for mobile networks. Emerging applications, including emergency response, industrial automation, extended reality, asset tracking, and network-aware services, require location estimates in indoor and dense urban environments. However, Global Navigation Satellite Systems (GNSSs), which remain the main source of global positioning information, provide limited performance under poor satellite visibility. This limitation has motivated the integration of sensing and positioning capabilities into cellular systems. The broader vision of ISAC is to reuse communication infrastructure, spectrum, and waveforms to provide sensing and positioning services beyond data transmission [1], [2]. Within 5G, positioning has been standardized through the Location Management Function (LMF) and dedicated Reference Signal (RS) procedures. These mechanisms represent an important step toward network-integrated localization, but their practical deployment remains constrained. In particular, downlink positioning requires the User Equipment (UE) to perform measurements and report them to the network, making the service dependent on chipset support, device implementation

choices, and additional UE-side processing. For operators, this is a critical limitation: a localization service cannot be deployed entirely from the network side if its availability depends on whether each commercial device exposes the required measurement capabilities [3]. Uplink positioning offers a complementary opportunity. Commercial UEs already transmit Sounding Reference Signals (SRSs) for channel sounding, and these signals have correlation properties that make them suitable for timingbased ranging. If multiple geographically distributed 5G base stations (gNBs) could observe the same uplink transmission, the network could estimate the UE position without requiring additional localization functionality at the device. This would make positioning an infrastructure-side service: transparent to the UE, controlled by the operator, and configurable according to the accuracy, latency, and resource requirements of different applications. From a broader perspective, network-native location information could feed the Artificial Intelligence (AI) layer of future Open Radio Access Network (O-RAN)-based architectures, where AI-driven functions would exploit it to optimize Radio Access Network (RAN) operations. At the same time, controlled application interfaces could expose positioning services to external applications, enabling use cases such as industrial automation and context-aware edge services. The main limitation is that conventional RANs do not expose the information required for cooperative uplink processing. A serving gNB knows the scheduling decisions, resource allocations, and reference sequences associated with its UEs. A neighboring gNB may receive the same SRS, but it does not know when it is scheduled or which sequence must be used for coherent processing. Therefore, multiple receptions of the same uplink signal cannot directly be transformed into a set of cooperative ranging measurements. The O-RAN architecture provides the programmability required to address this problem. The O-RAN Alliance promotes disaggregating RANs components and using open, standardized interfaces [4]. In particular, the near-RT RIC enables software-based control and inference through network microservices implemented as xApps. A growing body of research has leveraged this openness to extend RAN functionalities beyond conventional signal processing. Previous works have used this architecture to detect and mitigate interference [5] and physical-layer attacks [6], to use spectrum unconventionally [7], as well as to support sensing infrastructures [8]. These studies show that O-RAN can extend RAN

2

•

We design and implement RUN-O-RAN, an O-RANnative localization framework that enables serving and neighboring gNBs to cooperate through a near-RT RIC

frame = 10 ms subframe = 1 ms slot

#0 - 0

#0 - 1

#1 - 0

#9 -0

#9 -1

RB subcarriers Nsc

RB − 1 k = NRB · Nsc

Resource Block

SCS

NRB

functionality beyond conventional communication operations, allowing the network to dynamically adapt its behavior. Based on these capabilities, we introduce RUN-O-RAN, an O-RAN-based 5G positioning micro-service that estimates the location of commercial UEs from standard uplink SRS transmissions. Unlike previous O-RAN positioning applications [9]–[12], RUN-O-RAN requires no additional hardware, positioning procedures, or computation at the UE, as the network performs the full localization process while the user equipment remains fully standards-compliant. Recent work has demonstrated that 3rd Generation Partnership Project (3GPP)-compliant Uplink (UL)-Time Difference of Arrival (TDoA) positioning can be integrated into practical open-source 5G implementations [13]. These solutions establish the feasibility of uplink timing-based localization, but they rely on the conventional LMF-based architecture, limiting the applicability to intra-Distributed Unit (DU) deployments, in which multiple Radio Units (RUs) are controlled by the same DU (O-RAN functional split 7-2x). Extending this approach across independent gNBs remains an open challenge because the standard RAN-Core Network (CN) architecture provides no general mechanism for distributing the scheduling information and reference signal configuration required for neighboring gNBs to process UL transmissions from nonassociated UEs. RUN-O-RAN addresses this limitation by introducing an xApp running in the near-Real Time Ran Intelligent Controller (near-RT RIC) that orchestrates cooperative uplink localization across multiple gNBs. To the best of our knowledge, this is the first fully network-based uplink positioning system integrated into the RAN and capable of coordinating independent gNBs to localize Commercial Off-the-Shelf (COTS) UEs, establishing network-controlled positioning as a native RAN capability and enabling a broad range of location-aware applications. Through the E2 interface, the xApp collects and distributes the information required to coordinate the serving and neighboring gNBs for positioning, including anchor identities and coordinates, negotiated SRS configurations, reference sequences, timing-advance updates, and received signal observations. This enables neighboring gNBs to process SRS transmissions from non-associated UEs and operate as localization anchors without requiring modifications to either the UE or the underlying 3GPP signaling procedures. Realizing cooperative uplink localization requires addressing three main challenges. First, the network must provide non-serving gNBs with the information required to process uplink SRSs. Second, the measured SRS delays must be corrected before they can be interpreted as geometric ranges, since synchronization offsets, clock drift, timing-advance updates, and multipath affect the estimated propagation time. Finally, the complete system must be validated under realistic yet controlled propagation conditions while preserving standardscompliant O-RAN operation. To address these challenges, this paper makes the following novel contributions:

k = 0 l = 0

l = Nsymb − 1

Fig. 1: Radio frame and resource grid with numerology µ = 1. In black, the resource elements occupied by the RUN-O-RAN configured SRS.

xApp. The framework provides network-side uplink trilateration without modifications to commercial UEs. • We develop an SRS-based localization pipeline that extracts Time of Arrival (ToA) measurements through crosscorrelation with the known SRS sequence, compensates for timing-advance and clock-drift components, and estimates the UE position using geometric and Kalman-based techniques. • We implement and evaluate RUN-O-RAN using a hybrid experimental testbed composed of a COTS 5G UE, OpenAirInterface, Open5GS, a USRP N310, a Keysight PROPSIM channel emulator, and O-RAN-compatible gNB instances. The evaluation includes 288,000 SRS transmissions collected in static and dynamic urban scenarios. The remainder of the paper is organized as follows. Section II introduces the physical-layer foundations of uplink positioning. Section III presents the RUN-O-RAN architecture and localization pipeline, while Section IV describes the experimental platform. Section V reports the evaluation results, and Section VI discusses limitations and future research directions. Finally, Section VII concludes the paper. II. 5G NR BACKGROUND FOR U PLINK P OSITIONING In this section, we provide an overview of 5G radio resources’ organization, synchronization procedures, and SRS configuration to understand the design choices we made to enable a reliable UL UE positioning. In this work, we focus on New Radio (NR) operating in the Frequency Range 1 (FR1). Although some parameter values differ for other frequency ranges, the overall scheme remains unchanged.

3

B. gNB-UE Synchronization

2τUE,gNB gNB

0

1

data

SSB 0

3

2

1

UE

4

data

TA 2

3

4

k

τUE,gNB

∆τTA

Fig. 2: Propagation delay and timing advance correction. The UE downlink timeline is delayed by the propagation time τ with respect to the gNB reference. After receiving the timing advance command, the UE advances its uplink transmission to align with the gNB timing.

A. Resource Configuration 5th generation (5G) has been designed with the unprecedented goal of unifying diverse verticals under a single, reconfigurable access network. To accommodate the broad spectrum of 5G applications, the radio interface introduces a highly flexible time–frequency structure defined by a set of configurations known as numerologies: µ = {0, 1, ..., 6}, which allow the network to adapt the physical layer to diverse latency and coverage needs. Low numerologies (e.g., µ = 0) with narrow subcarrier spacing are typically used for widearea, delay-tolerant services, while higher numerologies (e.g., µ ≥ 3) favor low-latency, high-throughput applications such as vehicular or industrial communications. In the time domain, each numerology corresponds to a specific radio frame configuration as defined by 3GPP specifications [14]. The radio frames have a fixed length of 10 ms, divided into 10 sub-frames of 1 ms each. The number of slots per sub-frame scales exponentially with the numerology, subframe following: Nslot (µ) = 2µ = {1, 2, 4, 8, 16, 32, 64}. Moreover, each slot comprises Nsymb = 14 Orthogonal Frequency Division Multiplexing (OFDM) symbols with a normal Cyclic Prefix (CPR) or Nsymb = 12 symbols with an extended CPR. In the frequency domain, the numerology determines the Subcarrier Spacing (SCS), defined as SCS = 2µ · 15 kHz. The maximum achievable bandwidth B that can be obtained for a given number of sub-carriers NSC is computed as B = NSC ·SCS = NSC ·(2µ ·15 kHz). This parameterization allows the network to finely balance spectral efficiency and coverage, adapting to the propagation conditions and service constraints of each deployment scenario. The Resource Grid (RG) is modeled and managed in both the time and frequency domains, subdivided into Resource Blocks (RBs), each comprising one OFDM symbol in the time domain and NscRB = 12 sub-carriers in the frequency domain, regardless of the CPR configuration. Thus, the Physical Resource Block (PRB) duration is T RB = 2−µ ms and its bandwidth is B RB = NscRB · SCS = 12 · 2µ · 15 kHz. The smallest allocable resource unit is the Resource Element (RE), corresponding to one OFDM symbol in the time domain and one sub-carrier in the frequency domain. Fig. 1 illustrates a RG, with the x-axis representing the time domain and the y-axis the frequency domain. As depicted, given a total bandwidth B, the total number of RBs is NRB = B/(NscRB ·SCS ).

When a UE attaches to a gNB, it aligns its internal time reference to the received Downlink (DL) Synchronization Signal Block (SSB). Due to the propagation delay τUE,gNB , a timing offset exists between the UE and gNB reference times. As a result, in the absence of compensation, UL transmissions would be received at the gNB with a total delay of 2 · τUE,gNB , accounting for both DL and UL propagation. For sufficiently large distances, this delay may cause UL signals to fall outside the intended time slot boundaries, leading to intersymbol interference. To prevent this effect, 3GPP specifies a closed-loop Timing Advance (TA) mechanism [14], [15], whereby the serving gNB periodically estimates the timing offset and commands the UE to adjust its transmission timing accordingly. In particular, the UL reception delay is periodically estimated and quantized in steps of 1024 · 2−µ · Tc , where Tc = 0.509 ns denotes the basic time unit [14]. At each k-th update cycle, a Timing Advance Command (TA-Command) with value TAk ∈ {0, 1, ..., 63} is reported to the UE. The UE is required to apply the corresponding timing adjustment within 6 slots by advancing or delaying its subsequent transmissions according to k ∆τTA = (TAk − 31) · 1024 · 2−µ · Tc ,

(1)

k denotes the incremental timing adjustment applied where ∆τTA at the k-th update, which depends on the received TAk value and the numerology index µ [16]. Since each TA-Command is computed relative to the previously adjusted time reference, the resulting timing control process is inherently cumulative. This iterative procedure forms a closed-loop timing adjustment that keeps the UL transmissions of each UE aligned with the gNB’s reference time. More precisely, after the k-th update, the cumulative timing advance is given by:

k 0 τTA = τTA +

k X

j ∆τTA ,

(2)

j=1 0 is the Random Access Response (RAR)-TA1 and where τTA k is the number of TA-Commands received by the UE from its cell attachment up to that time. At the k-th adjustment the gNB will therefore receive the UE’s UL transmissions with a k delay of 2 · τUE,gNB + τTA . In the context of UL-based positioning, any loss or corruption of TA-Commands invalidates the gNB knowledge of the UE time reference, making position estimation unfeasible. k Therefore, continuous tracking of ∆τTA , along with the detection and compensation of missed TA updates, is indispensable to the correct operation of the localization service.

C. Reference Signals In 5G NR, Reference Signals play a crucial role in ensuring efficient and reliable communication between the UE and the 1 RAR-TA is computed as (N TA,off + TA · 1024 · 2−µ ) · T with N TA,off c 0 being a fixed cell configuration parameter that is used to adapt the random access TA to the specific geometry of the cell ( [14], [17]).

4

gNB. They are responsible for channel estimation, synchronization, measurements for mobility, and beam management [14]. The configuration on the RG of these reference signals is customizable, depending on the deployment scenario and service requirements, offering flexibility in network resource allocation. Each RS is designed for a specific purpose. For highaccuracy localization, the Positioning RS (PRS) is the primary standardized option. PRS operates in the downlink and can achieve meter-level accuracy, on the order of a few meters with 100 MHz bandwidth [18]. However, it requires the UE to perform additional processing and to report positioning measurements or estimates back to the network, increasing both device complexity and signaling overhead. In this work, we instead target a seamless integration of localization within the network infrastructure. To this end, we avoid relying on PRS and focus on UL RSs, specifically the SRS. This choice is motivated by the favorable auto-correlation properties of SRS signals: in particular, SRS sequences are derived from Zadoff-Chu (ZC) sequences, which are complex-valued, constant-amplitude signals exhibiting ideal periodic autocorrelation, i.e., zero autocorrelation for all non-zero time shifts [19]. SRSs are primarily designed for UL channel quality estimation, enabling the gNB to perform efficient scheduling and link adaptation. Their configuration is determined by the gNB according to the UE’s capabilities and is conveyed via Radio Resource Control (RRC) setup or reconfiguration messages. Specifically, the SRS-Config and within that the SRS-Resource parameters define the allocation of SRSs within the RG. In the frequency domain, the SRS is transmitted starting from a given subcarrier k0 , extending for the upper mSRS,b PRBs, occupying one every KT C subcarriers of those PRBs. This results in a bandwidth occupation of BSRS = mSRS,b · SRS RB B RB kHz and a total of NSC = mSRS,b · NSC /KT C occupied subcarriers, each carrying an OFDM symbol. In the time domain, the signal’s transmission starts at a given OFDM symbol l0 = Nsymb − 1 − lof f set of the slot and continues for nr of symbols symbols. The black-filled squares of Fig. 1 depict an example of resource configuration for the SRS. In this case, the parameters are: KT C = 2 as the signal is sent every other subcarrier, lof f set = 4 as the signal is sent on the fourth-to-last symbol, and nr of symbols = 1 as it occupies only one OFDM symbol.

RUN-O-RAN removes this barrier through a centralized xApp deployed in the near-RT RIC. The xApp agrees upon the SRS configuration with the serving anchor, distributes the parameters required for SRS retrieval to the secondary anchors, and collects their signal observations through the E2 interface. The resulting control and telemetry workflow enables multiple gNBs to derive cooperative ranging measurements from the same uplink transmission. Since the entire procedure relies on standard SRS signaling and is executed within the network, no modification of the chipset or protocol stack on the COTS UE is required. The framework separates the localization problem into three functional layers. The first layer is architectural: O-RAN provides the control and telemetry path required to coordinate serving and secondary gNBs. The second layer is signalprocessing oriented: cooperative SRS reception, correlationbased ToA extraction, TA compensation, and drift-correction transform uplink reference signals into corrected range estimates. The third layer is algorithmic: trilateration and temporal filtering convert these ranges into a continuous estimate of the UE position. The separation between the second and third layers makes RUN-O-RAN extensible, as improvements in anchor selection or tracking can be introduced without changing the underlying coordination mechanism. Figure 3 shows the considered system model. A UE is connected to the master, denoted by gNBm , and lies within the reception range of at least two secondary anchors, labeled as gNBs . More generally, any participating anchor is denoted by gNBi , independently of whether it serves the UE. A. O-RAN-Enabled Cooperative Localization Architecture Figure 4 shows the O-RAN architecture deployed by RUNO-RAN. Following the O-RAN paradigm, the gNB is disaggregated into the RU, DU, and Central Unit (CU). This disaggregation is complemented by a programmable control loop that enables interoperable vendor-agnostic control of the RAN [4]: the near-RT RIC, which operates within [10, 1000) ms and supports near-real-time control via xApps. This makes the near-RT RIC the natural location for the RUNO-RAN control logic. Communication between the near-RT RIC and the underlying RAN is enabled by the E2 interface. E2 abstracts implementation-specific details and exposes standardized telemetry and control primitives to xApps. Through this

III. RUN-O-RAN F RAMEWORK RUN-O-RAN turns standard uplink SRSs transmissions into cooperative localization measurements by allowing serving and non-serving gNBs to process the same UE waveform. The key obstacle is architectural. In a conventional RAN, only the serving gNB has access to the scheduling decision, resource allocation, and reference sequence associated with a given UE. A neighboring gNB may physically receive the same SRS, but it cannot identify the relevant resource elements or perform coherent correlation without this information. This architectural limitation prevents cooperative uplink localization in legacy deployments.

gNBs2 UE gNBm

gNBs1

Fig. 3: Trilateration geometry used for UE localization. The UE is connected to the serving base station gNBm and is simultaneously listened by two neighboring anchors gNBs1 and gNBs2 .

5

gNBm

E2

E2 Agent

emulated PHY

O-RU

RUN-O-RAN DATAs1

gNBs2

DATAs2

O-DU

E2 Agent

O-CU

emulated PHY

O-RU

controller

gN Bs secondary

C{SRSconf } Sreq {UE}

RA E2

E2 Term

O-DU

xApp

master

nRT -RIC

gNBs1 O-CU

gN Bm

Startup

O-RU

E2

Ranging

Trilateration

MSG1 MSG2 MSG3 MSG4

Parameter Negotiation

emulated PHY

UE target

Ires {UE} UEID , SRSconf , TARA

C{SRSparam }

Sreq {SRS}

Sreq {SRS}

Ires {SRS}

Ires {SRS}

other xApps...

Fig. 4: RUN-O-RAN validation architecture. Synchronized traces collected

sgen Calibration

DATA m

O-DU

E2 Agent

O-CU

sgen

TA Compensation. ...Clock drift est.... ..Position update...

for the serving anchor (gNBm ) and the secondary anchors (gNBs1 , gNBs2 ) are injected into the emulated PHY layers of three O-RAN-compatible gNB instances. Each node reports its measurements to the near-RT RIC through E2, where the RUN-O-RAN xApp performs ranging and trilateration.

sgen

Ires {SRS}

Ires {SRS}

sgen

..Position update... sgen

SRSconf : reproduces the 3GPP standard SRS-Resource as described in II-C. • SRSparam contains the subset of SRSconf parameters required by neighbouring gNBs to identify the time– frequency resources on which the target UE transmits its uplink SRSs. • SRS: efficiently encodes the received baseband SRS samples together with the hashed Cell Radio Network Temporary Identifier of the associated UE (UEID ), the reception timestamp, and the measured Signal-to-Noise•

Ires {SRS}

sgen

..Position update... TA TA Eval. TA

interface, xApps can collect measurements, process networkstate information, and issue control actions to distributed RAN nodes while remaining independent of the specific vendor implementation. The E2 interface operation is based on the E2 Application Potocol (E2AP), and a set of E2 Service Models (E2SMs). E2AP manages the association between the RIC and the E2 nodes, whereas E2SMs define the semantics and data structures associated with specific monitoring and control functions. At the time of deployment, standardized E2SMs did not expose all the information required for cooperative uplink positioning. We therefore introduce a dedicated localizationoriented Service Model (SM) that extends the E2 interface, a fundamental step in the proof-of-concept development of new xApps [20]. The proposed SM introduces semantics that, when extended, pave the way toward ISAC functionalities within O-RAN, laying the foundation for a new generation of 6Goriented O-RAN applications. The SM has been defined and implemented using Protocol Buffers, a language-agnostic, platform-independent format developed by Google LLC to efficiently serialize structured data [21]. In particular, RUN-O-RAN SM defines the payload of the messages exchanged between gNBs and the xApp shown in Fig. 5:

Ires {SRS}

TA Command TA Apply

Ires {TAk } TA Compensation.

Fig. 5: Exchange of messages between UE, gNB master, xApp, and secondary gNBs. Notation: E2AP RIC Control Message (C{·}), E2AP RIC Subscrption Request (Sreq {·}), E2AP RIC Indication Response (Ires {·}).

Ratio (SNR). TAk : conveys the TA-Command value measured by the master gNB, together with the corresponding UEID and timestamp. The reader can find further details on GitHub2 , where the RUN-O-RAN SM and a patch implementing the required E2node extensions were made publicly available. •

B. RUN-O-RAN Workflow To convert a standard uplink reference-signal transmission into a cooperative multi-anchor localization system, we designed a sequence of control and indication messages exchanged between the xApp and the participating gNBs, as depicted in Fig. 5. The proposed workflow builds on the E2 procedures and service-model abstractions defined by ORAN [22]–[24]. For clarity, the figure omits the E2 association establishment, which follows the standard procedures [22], [23], and we omit the onboarding, deployment, and registration of the xApp, which are also standard-compliant. The startup 2 https://github.com/viola-bernazzoli/RUN-O-RAN

6

phase is executed once when RUN-O-RAN is instantiated. The subsequent procedures are executed for each newly attached UE, whereas the TA-update phase is repeated whenever the TA-Command procedure is triggered. 1) Startup: During startup, RUN-O-RAN is deployed in the near-RT RIC and requests the identifiers, coordinates, and neighbor relations of the E2-connected gNBs. This information defines the set and geometry of the candidate localization anchors. Depending on the deployment, anchor coordinates may be obtained from a network topology database or reported by the gNBs through E2 indications. Once the infrastructure information has been retrieved, RUN-O-RAN sends control messages C{SRSconf } to the participating gNBs to configure the SRS parameters required by the localization service. This configuration must balance positioning accuracy and radio-resource occupancy. Widerbandwidth SRS transmissions and lower periodicity value improve the temporal and spatial resolution of the range estimates, but they also consume more physical resources3 . RUN-O-RAN then subscribes to notifications associated with newly attached UEs with Sreq {UE}. The gNB reporting the attachment is selected as gNBm , while candidate nonserving anchors are obtained from the serving cell’s neighbor relations and from the E2-connected nodes capable of monitoring the target carrier. RUN-O-RAN then retains only the candidates that successfully detect the target UE’s SRS. 2) UE Parameter Negotiation: When a UE attaches to the network, gNBm retrieves the UE capability information and negotiates an SRS configuration that is both compatible with the device and suitable for localization. The selected parameters follow the recommendation issued by RUN-ORAN whenever they are supported by the UE; otherwise, gNBm selects the closest feasible configuration. After each successful random access, represented by the Random Access (RA) block in Fig. 5, gNBm sends an indication message Ires {UE} to RUN-O-RAN containing: a confidentiality-preserving UE identifier UEID , obtained by hashing the Cell Radio Network Temporary Identifier; the negotiated SRS configuration SRSconf , which may differ from the requested configuration depending on UE capabilities; and the TARA , namely the first TA-Command issued by gNBm , later used for timing compensation. These elements identify the time–frequency resources assigned to the SRS and provide the parameters required to reconstruct the corresponding reference sequence. RUN-O-RAN then distributes the scheduling and resourceallocation information to the selected non-serving anchors trough a control message C{SRSparam }. Each anchor monitors the assigned resource elements and reports the corresponding received samples to the xApp, which subscribed to the information through Sreq {SRS}. The xApp obtains the 3 To expose this trade-off to the operator, we define an accuracy–occupancy parameter ρao ∈ [0, 1]. The parameter reflects the amount of REs occupied by the SRS in 180 ms by a single UE, and is normalized by the UE capabilities. ρao = 0 and ρao = 1 represent minimum and maximum occupancy respectively.

sequence-generation information from gNBm and processes the observations collected by all participating anchors. 3) UE Calibration: The calibration phase is executed for each newly attached UE. Its purpose is to initialize the ranging process and estimate the device-dependent clockdrift components, as described in Sec. III-C3. In commercial devices, the uplink transmission timing is affected by oscillator drift, chipset-specific corrections, and internal timing-control mechanisms. These effects introduce slowly varying biases in the measured propagation delays and, consequently, systematic errors in the estimated ranges. Since their behavior depends on the UE hardware and operating state, the calibration cannot be reused across different devices, but can be reused for different attachment sessions. During this phase, each participating gNBi reports the received uplink SRS sequence sgen to the xApp through E2 indications. The xApp centrally estimates the UE–gNBi ranges according to Sec. III-C1 and compensates for timing realignments introduced by TA updates, as described in Sec. III-C2. Once the drift parameters have been estimated, RUN-ORAN computes the initial UE position through trilateration and enters tracking mode. Subsequent SRS observations are collected by the participating anchors and processed by the xApp to update the position estimate over time. C. Positioning Pipeline The cooperative reception procedure provides each participating anchor with a copy of the SRS transmitted by the target UE. However, the delay extracted from this signal cannot be used directly as a geometric range. It contains not only the propagation time between the UE and the receiving anchor, but also the effects of uplink synchronization, timingadvance updates, residual inter-gNB clock offsets, and chipsetdependent timing corrections. The purpose of the RUN-ORAN positioning pipeline is therefore to transform raw correlation delays into a corrected distance estimate suitable for trilateration. 1) Signal Model and ToA Extraction: Upon reception of the first SRS sequence from each anchor, the positioning pipeline is initialized. Since the UE uplink timing is aligned with the serving gNBm , the delay observed at the master anchor corresponds to a round-trip propagation term proportional to 2dUE,m /c, where dUE,i is the distance between the UE and the i-th anchor, and c is the signal propagation speed. At a secondary anchor, instead, the downlink timing reference is still determined by gNBm , whereas the uplink signal is received by gNBs . Therefore, the measured delay contains the composite propagation term (dUE,m + dUE,s )/c. Let sgen denote the generated SRS sequence, known by the UE, gNBm , and RUN-O-RAN after the attachment. Let si,rx be the sequence received at the i-th anchor and sampled at frequency fs . We assume that all participating anchors operate over the same SRS bandwidth and therefore use the same sampling frequency. The received signal can be modeled as si,rx [n] = αi [n]sgen [n − m e i ] + ηi [n],

SRS n ∈ [0, NSC ], (3)

7

where n is the sample index, αi [n] is the channel attenuation term between the UE and gNBi , m e i is the discrete recepSRS tion delay, ηi [n] is additive noise, and NSC = mSRS,b · RB Nsc /KT C is the length of the SRS sequence. RUN-O-RAN estimates the discrete channel impulse response by cross-correlating the received signal with the known reference: ĥi [n] = Rsi,rx ,sgen [n], (4) where R denotes the cross-correlation operator. Under the correlation properties of SRS sequences, ĥi [n] approximates a scaled and shifted version of the autocorrelation of the transmitted waveform. Peaks of ĥi [n] therefore correspond to sampled propagation paths between the UE and the receiving anchor. In many ranging systems, the ToA is estimated by selecting the strongest correlation peak. This criterion is reliable only when the strongest path also corresponds to the first arriving path. In multipath environments, however, the highest-power component may be a reflected path and may therefore arrive later than the direct or shortest path. To mitigate this effect, RUN-O-RAN first identifies the set of significant peaks and the delay estimate is then obtained as the earliest significant peak: m̂i = arg min n, n∈Pi

for Pi = {n : |ĥi [n]|2 ≥ γi },

(5)

where γi is a detection threshold selected according to the noise floor and correlation sidelobe level; this choice favors the first detectable path and therefore estimates the true Lineof-Sight (LOS) delay in LOS multipath scenarios, while minimizing positive bias in Non-Line-of-Sight (NLOS) conditions. The corresponding distance estimate is obtained after compensating for the master-anchor reference delay. For the i-th anchor, the raw range estimate can be written as   c 1 ˆ , (6) dUE,i = ∆d m̂i − m̂m , ∆d = 2 nFFT · SCS where m̂m is the delay index estimated at the master gNBm , and ∆d is the distance resolution of the correlation domain. This resolution is determined by the SRS bandwidth and sampling configuration, where nFFT is the Fourier-transform size used to discretize the SRS in the frequency domain, and SCS is the subcarrier spacing. Increasing the SRS bandwidth improves the granularity of the correlation space and therefore the achievable ranging accuracy, at the cost of higher radioresource consumption. The same procedure is repeated independently for all participating anchors. The resulting raw measurements are then passed to the TA and drift compensation stages described below. 2) Timing Advance Compensation: As discussed in Sec. II-B, uplink transmissions are periodically realigned to the resource grid of gNBm through the TA mechanism. Accurate tracking of TA-Commands is therefore essential, since each TA update modifies the effective transmission timing of the UE. RUN-O-RAN subscribes to these updates during the

parameter-negotiation phase. Whenever gNBm sends a TACommand to the tracked UE, it also forwards the corresponding information to the xApp. This allows RUN-O-RAN to maintain an updated record of the cumulative timing advance applied to the UE and to compensate for its effect on the estimated ranges. The TAcorrected distance is computed as: k

c · τTA TA-Corr. , dˆUE,i = dˆUE,i − 2

(7)

k where τUE is derived with eq. 2. Figure 6a shows the effect of TA compensation on the range estimate. While the uncorrected estimate dˆUE,m exhibits large deviations following TATA-Corr. Command updates, the corrected estimate dˆUE,m remains close to the ground-truth distance. A practical difficulty arises from the absence of an explicit TA-Command feedback mechanism. As a result, we have no UE reception confirmation. If a TA-Command is lost or corrupted, the xApp’s estimate of the UE transmission timing becomes inconsistent with the actual device behavior, which can invalidate both range and position estimates. RUN-ORAN therefore detects missed TA commands by checking the plausibility of consecutive range updates. If a corrected range variation implies a physically unrealistic apparent speed, k for example for µ = 1 the threshold thr = ∆τUE · TAk =32 c/srs periodicity ≈ 139 m/s, the corresponding TA-Command is flagged as potentially unacknowledged, and the cumulative timing-advance record is adjusted accordingly. An example is shown in Fig. 6b, where the red marker denotes a TACommand observed by the xApp but not by the UE. Including this missed command in the cumulative TA introduces a . Once detected by RUN-O-RUN, persistent bias in dˆ,TA-Corr. UE,m however, the timing-advance record is corrected, yielding the orange estimate.

3) Clock-Drift Calibration and Correction: Even after TA compensation, accurate localization requires tracking residual timing bias. In commercial devices, the UE transmission timing is affected by clock drift, chipset-dependent corrections, and internal timing-control mechanisms. These effects introduce slowly varying biases that appear as systematic errors in the measured ranges. According to 3GPP specifications, the maximum UE transmission timing error Temax must remain below the TA discretization step [25]. To satisfy this requirement, the UE continuously estimates its timing error Te using downlink reference signals. When the error exceeds the allowed bound, the UE gradually adjusts its transmission timing through small consecutive corrections. Empirical observations show that this behavior produces a repeatable sawtooth timing-drift pattern [26]. The pattern alternates between coasting phases, during which clock bias accumulates approximately linearly, and corrective phases, during which the UE progressively compensates the accumulated error, as the blue line shows in Fig. 6c. For a given UE model, the slopes of these phases are sufficiently consistent across experiments to be learned and later compensated. RUNO-RAN exploits this regularity by estimating the characteristic

8

(a) TA-corrected

(b) lost-TA-corrected

(c) Drift-corrected

Fig. 6: Correction steps of RUN-O-RAN. The red line represents the ground truth, and the azure and orange ones represent dˆU E before and after the correction, respectively. drift slopes during a calibration stage and subtracting their contribution from subsequent range estimates. Timing-bias calibration. When a UE attaches to gNBm , RUN-O-RAN initiates a one-time calibration procedure before enabling reliable tracking. A lightweight Kalman Filter (KF), evolving according to a random-walk model, jointly tracks the apparent distance, timing bias, and bias derivative. By analyzing the variance of the second derivative of the bias estimate, the xApp identifies intervals in which the UE can be considered static. During these intervals, RUN-O-RAN estimates two characteristic slopes: a positive slope δ̂+ associated with the coasting phase, and a negative slope δ̂− associated with the corrective phase. Timing-bias correction. Once calibration is complete, RUNO-RAN compensates timing drift in real time. The xApp identifies the beginning of each coasting or corrective phase by monitoring the sign and evolution of the first and second derivatives of the estimated timing bias. Depending on the current phase, it selects either δ̂+ or δ̂− and applies the corresponding correction to each anchor-specific range: d˜UE,i = dˆTA-Corr. − cδ̂+/− ∆tsync , UE,i

(8)

where δ̂+/− denotes the active drift slope, selected according to the current sawtooth phase, and ∆tsync is the time elapsed since the beginning of the current coasting or corrective interval. This correction removes the dominant deterministic timing bias, leaving only residual stochastic fluctuations to be handled by the final position estimator. D. Position Estimation Once the ranging pipeline has produced the corrected anchor-wise measurements, localization can be cast as a geometric estimation problem. At SRS instant k, RUN-O-RAN observes the mixed measurement vector h iT k k k k k zk = d˜UE,m , (9) d˜UE,s1 − d˜UE,m d˜UE,s2 − d˜UE,m

corrected differential ranges of the two secondary anchors with respect to the master reference. Let pk = [xk , yk ]T denote the UE position and let ui = [xi , yi ]T be the known position of anchor i. Using the master anchor m and the two secondaries s1 and s2 , the corresponding nonlinear measurement model is   ∥p − um ∥2 h(p) = ∥p − us1 ∥2 − ∥p − um ∥2  . (10) ∥p − us2 ∥2 − ∥p − um ∥2 Measurement reliability is encoded by  2 R = diag σm , σt2 , σt2 , W = R−1/2 ,

(11)

where σm and σt are the standard deviations assigned to the master absolute range and to the secondary anchors’ differential measurements, respectively. This common formulation is used by both estimators below. 1) Weighted Nonlinear Least Squares: the algorithm computes the position independently at each SRS instant by minimizing the weighted residual between the observation vector in (9) and the model in (10):   2 p̂NLS = arg min2 ρ W zk − h(p) 2 , (12) k p∈R

where ρ(·) is a robust penalty, such as soft-L1 , used to reduce the influence of isolated outliers. In practice, the solver is initialized with the previous estimate p̂NLS k−1 when available, and with the anchor centroid otherwise. This yields a compact geometric estimate at each SRS occasion without introducing an explicit mobility model. 2) Extended Kalman-Based Tracking: To exploit temporal continuity, the tracker uses the same measurement geometry within a constant-velocity Extended Kalman Filter (EKF). The state is described by  T  T vkT = xk yk ẋk ẏk , xk = pT (13) k with transition model

k where d˜UE,m is the corrected absolute range from the master k k k k anchor, and d˜UE,s1 − d˜UE,m and d˜UE,s2 − d˜UE,m are the

 xk|k−1 = Fk xk−1|k−1 ,

Fk =

I2 02

 ∆tk I2 . I2

(14)

9

The measurement function is still given by (10), so the linearized measurement matrix results in: " # ∂h Hk = 03×2 . (16) ∂p p=p̂k|k−1

.csv Positions

Sionna ray-tracer

Channel converter .asc PROPSIM F8800A

2

3

4

5

6

7

4-way combiner

8

nrt-RIC xApp

1

xApp

UE

xApp

Assuming white acceleration noise with standard deviation σa , the process covariance is  4  ∆tk /4 0 ∆t3k /2 0  0 ∆t4k /4 0 ∆t3k /2 . (15) Qk = σa2  2 ∆t3k /2 0 ∆tk 0  0 ∆t3k /2 0 ∆t2k

General Purpose Hardware

E2

N310

gNB

CN

The EKF is then updated as standard. The two estimators therefore differ only in their temporal structure: p̂NLS uses the current measurement only, whereas k x̂EKF combines the same measurement geometry with a k constant-velocity prior. IV. E XPERIMENTAL S ETUP We validate RUN-O-RAN in real time through the experimental architecture shown in Fig. 4, which was designed to execute the complete RUN-O-RAN workflow under controlled and reproducible propagation conditions. The testbed uses three OpenAirInterface (OAI) gNBs instances [27] connected to an Open5GS CN [28]. We rely on open-source implementations that are easy to enhance by introducing new capabilities. Indeed, we extended the DU by integrating the RUN-O-RAN E2SM and exposing the configuration and measurement information required for cooperative uplink processing III-A. The three anchors establish independent E2 connections with the O-RAN Software Community (SC) near-RT RIC, where RUN-O-RAN is deployed. A physical deployment with three independent SDR-based gNBs would require tight, potentially expensive, inter-node time and frequency synchronization, as commercial RANs typically provide. Depending on the synchronization system implemented, residual inter-gNB clock offsets would directly affect the measured arrival times. To isolate the localization framework from these external dependencies, we developed an emulated physical layer (e-PHY). The e-PHY is integrated into OAI and replaces only the acquisition of PHY-layer samples. Instead of reading samples from an RF front end, each instance replays a previously recorded baseband trace in real time. The e-PHY is transparent to the upper layers. Each gNB processes the replayed samples as if they had been acquired from a physical radio unit. At the same time, RUN-O-RAN receives the resulting information from the DU through the same E2 control and telemetry path. The xApp does not access the trace files directly; from its perspective, the three nodes behave as independent gNBs observing the same uplink transmission through distinct propagation channels. The three e-PHY instances replay three synchronized real traces DATAm , DATAs1 , and DATAs2 according to the original transmission timing, thereby allowing the system to operate in real time. This approach allows the same signal observations to be replayed across multiple experiments. Different ranging, correction, and localization algorithms can therefore be

Fig. 7: Experimental setup used to collect the traces replayed by the e-PHY. Sionna-rt generates the propagation scenario, whose channel realizations are instantiated by the channel emulator. A COTS 5G UE is connected to an OAI gNB and transmits standard uplink SRS waveforms, which are simultaneously recorded through three independently configured propagation paths.

compared using identical waveforms, hardware impairments, anchor geometries, and propagation conditions. For each scenario, we generate the channel realizations using the Sionna ray-tracing framework [29]. We convert each uplink path to .asc format and feed it to a Keysight PROPSIM channel emulator [30] with the propagation delay, attenuation, multipath components, and fading profile. The traces replayed by the e-PHY are collected using the testbed shown in Fig. 7. The gNB is an OAI instance attached to an Ettus Research USRP N310 software-defined radio [31], operating in band n77 with a 60 M Hz channel bandwidth and numerology µ = 1 (30 kHz SCS). The radio front end is configured through PROPSIM with one DL and three UL paths. The DL provides master-UE connectivity, while the ULs simultaneously capture the UE SRS transmission after it has propagated through independently configured channels. The resulting baseband signals represent the observations available at the three anchors in a geographically distributed arbitrary deployment.

10

For every SRS occasion, the setup records the three baseband traces. Because we used a COTS device to generate the waveforms (a Sierra Wireless [32] with a Qualcomm Snapdragon X60 5G Modem-RF system and a programmable SIM), the traces include oscillator behavior, transmissiontiming adjustments, chipset-dependent effects, and other hardware imperfections. The testbed combines commercial-device realism with controlled and repeatable propagation conditions, enabling performance evaluation under arbitrarily varying system parameters. Any experiment is fully determined by the recorded UE waveforms. The same traces can therefore be reused across multiple runs, ensuring that all evaluated algorithms operate on the same uplink observations.

(a) ECDF of the ranging error after each correction step: raw peak detection, TA correction, lost-TA correction, and drift correction.

V. R ESULTS We evaluate RUN-O-RAN over an experimental dataset of 150,000 SRS transmissions, using both Nonlinear Least Squares (NLS) and EKF estimators. The dataset includes opensquare and narrow-street urban scenarios, under both static and dynamic UE conditions. We selected these scenarios to stress the three factors that most directly affect uplink trilateration: anchor geometry, multipath-induced ranging bias, and SRS signal quality. The static e-PHY dataset consists of eight measurement campaigns generated with the Sionna ray-tracing framework, using a detailed 3D model of the city of Munich. In the six static campaigns, the UE is positioned in an open urban square, and the three anchors are placed on surrounding buildings at distances of 100 m and 200 m to evaluate the effect of multipath in LOS and NLOS. Unless otherwise stated, the anchors are arranged at the vertices of an equilateral triangle centered on the UE, so that the impact of propagation can be studied independently of Geometric Dilution of Precision (GDOP). The last two campaigns then assess RUN-O-RAN under realistic dynamic scenarios, moving the UE along a trajectory in the square and in a narrower street with an asymmetric anchor disposition. Fig. 12 depicts an example scenario. This section aims not only to report localization accuracy, but also to identify where the error originates. We therefore organize the evaluation around four questions. (A) How does the system behave under noisy SRS? (B) Does RUN-O-RAN behave consistently with the geometry of trilateration? (C) How does multipath affect the corrected range estimates and the final position? (D) How do anchor-wise ranging errors propagate into localization error?

(b) Impact of SRS SNR on ranging accuracy. Samples are grouped into 5 dB SNR bins.

Fig. 8: Impact of the correction pipeline and of SRS SNR on ranging accuracy in static conditions.

estimate achieves a 90th-percentile error of 4.22 m, nearly an order of magnitude lower than the uncorrected case. We then evaluate the relationship between the SNR of the received SRS and the ranging error. Lower SNR increases the uncertainty of the estimated Channel Impulse Response (CIR) and makes the detection of the earliest significant peak less reliable. Unlike NLOS multipath, however, low SNR primarily increases measurement variance rather than introducing a persistent geometric bias. Fig. 8b reports the ranging error of the previously analyzed scenarios, grouped into 5 dB SNR bins. As expected, lowSNR samples exhibit larger dispersion, reflecting the increased difficulty of detecting the first arrival path in noisy channel conditions. Nevertheless, most estimates remain within a few meters as long as the UE remains attached to its master. This result indicates that SNR is not the primary source of error for positioning applications; however, an SNR-based rejection or reweighting rule may improve robustness against noisy samples.

A. Noisy Ranging

B. Impact of Anchor Geometry

To give the reader an idea of the impact of the filters described in Sec. III-C, we show in Fig. 8a the Empirical Cumulative Distribution Function (ECDF) of the ranging error in static conditions after the sequence of correction steps: TA correction, lost-TA correction, and drift correction. The raw peak detection and TA-corrected estimates are dominated by residual TA missed updates, while the final drift-corrected

In this analysis, we aim to isolate the effect of anchor geometry; therefore, we conducted the experimental campaign in a square in Munich, with all anchors in the UE’s LOS. In the scenario, the UE is the centroid of a triangular configuration, where the centroid-vertex distance is fixed at 100 m, shown in Fig. 9 above. The gNBs are the vertices of the triangle and move along the circumference centered on the UE and

11

gNBs2

UE θ gNBm

gNBs1

Fig. 9: Impact of anchor geometry on positioning error. The localization error increases as the anchor layout moves from a well-conditioned triangular configuration towards the degenerate aligned case.

of radius 100 m to change the geometry of the setup. We conducted the experiments by varying the widest angle at the centroid from 120◦ to 180◦ in 5◦ increments. The 120◦ case corresponds to an equilateral triangle, whereas the 180◦ case corresponds to the degenerate configuration in which the anchors are aligned. Fig. 9 on the left confirms the expected behavior of a trilateration system. Both the NLS and EKF estimators produce comparable error distributions. Since the UE is static, the EKF’s temporal filtering provides little additional information over the memoryless NLS estimate. The estimators achieve their lowest error when the anchors surround the target with a wellconditioned geometry. As the triangle becomes increasingly obtuse, the same ranging uncertainty is amplified into a larger position error. The error peaks near the aligned configuration, where trilateration becomes ill-conditioned. This result validates RUN-O-RAN’s geometric consistency. The framework introduces no unexpected behavior: when the anchor layout degenerates, positioning error increases regardless of the estimator.

We generate three levels of multipath richness: MP0, where only the direct path contributes to each UE–gNB channel; MP3, where we add up to three reflections; and MP5, where we add up to five reflections. We do not consider higherorder reflections because their peak amplitudes fall below the emulator’s noise floor and are indistinguishable from zero. Fig. 10 reports the ECDF of the localization error for the EKF (Fig. 10a) and NLS (Fig. 10b) estimators, comparing the three multipath levels in LOS (100 m) against NLOS (200 m) scenario. Both Fig. 10a and Fig. 10b show that, already at 100 m, increasing multipath richness clearly degrades the position estimate: the 90-th percentile grows from a few centimeters at MP0 to several tens of centimeters at MP5. As expected, the NLOS campaign yields the worst ECDF among all the configurations considered. This follows from how RUN-ORAN mitigates multipath: it selects the earliest significant peak of the estimated CIR, rather than the strongest, assuming the first arrival is the direct path. In LOS, this assumption holds, and the range estimate closely matches the true distance. In NLOS, the direct path is blocked, so even the earliest detected component is a reflection. This residual excess length manifests as a positive bias in the range estimate and, consequently, in the localization error.

(a) EKF: LOS (100 m) vs. NLOS (200 m).

C. Impact of Multipath Multipath is a major radio impairment affecting SRS-based ranging in urban environments. We evaluate its impact on RUN-O-RAN under two propagation conditions, LOS and NLOS. Channel realizations are generated with Sionna-rt in an urban square in Munich, with the UE placed at the center and the three gNBs at the vertices of an equilateral triangle centered on the UE; this symmetric layout keeps the GDOP constant across scenarios, so that any difference in localization error can be attributed to multipath rather than to anchor geometry. The gNBs are placed on the buildings surrounding the UE, at a distance of 100 m for the LOS case and, to complete the study, at 200 m for a NLOS feasibility campaign, where surrounding buildings obstruct the direct UE-gNB path.

(b) NLS: LOS (100 m) vs. NLOS (200 m).

Fig. 10: ECDF of the localization error under increasing multipath richness. MP0, MP3, and MP5 denote scenarios with zero, three, and five reflections, respectively.

D. Propagation of Ranging Errors We investigate how anchor-wise ranging errors propagate into the final position estimate. We restrict this analysis to the

12

(a) Square scene.

(b) Street scene.

Fig. 11: Propagation of anchor-wise ranging errors into the NLS positioning error. Each axis represents the ranging error associated with one gNB; color intensity encodes the resulting localization error.

(c) ECDF.

NLS estimator, whose output depends solely on the current set of range measurements. In contrast, the EKF estimate is also conditioned on previous filter states, which combines the contribution of the current measurement with that of the estimator’s memory and precludes a clean attribution of error to a specific anchor. We characterize this propagation using all our experimental campaigns. To isolate the secondary anchors’ contribution to the trilateration outcome, we built a controlled post-processing dataset: we retain RUN-O-RAN’s range estimates for both secondary gNBs, while replacing the master’s range with its ground-truth value. This construction also supports peranchor analysis, isolating cases where only one secondary is significantly biased from cases where both are. Fig. 11 maps the ranging error of each secondary anchor onto the resulting localization error. Each axis corresponds to one secondary anchor’s ranging error, while the color of each scattered point encodes the associated localization error. The scatter is denser below the y = x diagonal, indicating that gNB1 ’s ranging error typically exceeds gNB2 ’s. Along the diagonal, where both anchors are biased by comparable amounts, the localization error remains limited: same-sign errors largely cancel in the trilateration solution, leaving the estimated position close to the true UE location. Moving toward the anti-diagonal, where the two errors carry opposite signs, the localization error grows sharply, as the equilateral anchor geometry amplifies the mismatch and displaces the estimate well beyond the true one. This representation makes clear that localization degradation is not uniformly distributed across anchors: a single biased gNB can dominate the resulting position error, while bias on both anchors compounds it. Beyond characterizing this asymmetry, the plot is diagnostic in practice, as it can identify which anchor contributes most to the localization error in a given deployment. E. Dynamic Scenarios Finally, we evaluate RUN-O-RAN under UE mobility. The dynamic dataset includes two pedestrian-like trajectories in the

Fig. 12: Dynamic scenarios: square and street. Fig. 12a– 12b show in red the ground truth, in white the estimated trace, and in green the three anchors. Fig. 12c shows the localization error for the dynamic scenarios. Horizontal lines mark the 67th and 90th percentiles.

Munich environment: a UE crossing an open square, and a UE moving through a narrow urban canyon. The open-square scenarios preserve a favorable anchor geometry, whereas the urban-canyon scenario combines stronger multipath with a less favorable layout. As expected, in dynamic conditions, the difference between the two estimators becomes more visible. The NLS estimator processes each SRS instant independently and therefore reflects the instantaneous quality of the current range estimates. The EKF uses the same geometric measurement model but adds a constant-velocity prior, thereby suppressing isolated outliers and producing smoother trajectories. The experimental results confirm this behavior. Fig. 12c shows the resulting ECDFs for both estimators and both scenes: in open-square trajectories, where the geometry is favorable and LOS propagation is more likely, both estimators provide stable localization, with the EKF reducing abrupt fluctuations caused by transient ranging errors. In the urbancanyon trajectory, performance degrades because NLOS propagation introduces persistent range bias, and the corresponding curves in Fig. 12c are shifted well to the right of the squarescene curves. In this case, the EKF smooths the trajectory but cannot fully remove the systematic displacement caused by biased measurements. This distinction is essential. Temporal filtering improves stability when errors are sporadic, but it cannot compensate for persistent NLOS bias without additional information. Therefore, the dynamic experiments confirm the feasibility of realtime RUN-O-RAN tracking while highlighting a key direction for further improvements: detecting and mitigating NLOSinduced range errors through anchor selection or propagationaware models based on environment digital twins.

13

VI. D ISCUSSION : S YNCHRONIZATION AND A NCHOR R ELIABILITY RUN-O-RAN demonstrates that cooperative uplink localization can be implemented as an O-RAN-native service. Building on these results, we discuss two aspects that are key to extending its applicability to broader deployment scenarios: inter-gNB synchronization and multi-anchor availability. A. Inter-gNB Synchronization Operational cellular networks already rely on synchronization mechanisms such as GNSS-based timing, SyncE, and IEEE 1588 PTP, especially in TDD deployments [33]–[35]. For localization, however, residual relative timing error among the anchors can introduce noise into the estimates. In this section, we highlight the impact of three different synchronization errors across gNBs: 1) timing offset, 2) phase noise, and 3) frequency drift.

(a) EKF phase noise correction.

1) Timing Offset: A constant bias bi,m between the local clocks of anchor i and the master m shifts the estimated differential delay by a fixed, time-invariant amount:

(b) SMA phase noise correction.

∆τ̂i,m (t) = ∆τi,m (t) + bi,m .

Fig. 13: Phase noise affecting gNBs in ranging estimation, corrected through

(17)

Since bi,m does not evolve over the observation window, it is therefore fully absorbed by the existing calibration procedure for hardware asymmetries III-B3 and requires no dedicated compensation logic. 2) Phase Noise: Residual oscillator phase noise introduces a random, zero-mean fluctuation to the distance estimation:   ϕi,m (t) ∼ E[ϕi,m (t)] = 0, σϕ2 i,m = E[ϕ2i,m (t)] . (18) The standard deviation σϕi,m is set to 33 m; this value represents an upper bound on the phase-noise-induced ranging error observed in real 5G deployments [36]. This error is stationary and, to first approximation, uncorrelated across measurement epochs, so it does not accumulate over time. Its contribution to the range estimate can be reduced by applying the EKF or by applying a Simple Moving Average (SMA) over W independent samples, which reduces √ the impact to σϕi,m/ W . Fig. 13 shows the estimated ranging distance for a secondary anchor i with respect to the master m: the raw ranging (light blue) fluctuates around the ground truth (red), while both SMA and EKF (orange) suppress this fluctuation, with the EKF tracking the ground truth more tightly. 3) Frequency Drift: Clock drift is the most critical because it introduces a time-varying error that accumulates across consecutive measurements. The current implementation compensates for timing impairments associated with the UE and the serving-cell timing process. Extending the same principle to inter-gNB drift is a natural continuation. For a static UE, the corrected differential delay between two anchors should remain constant once propagation and TA effects have been removed. A systematic variation observed in the slave anchors therefore indicates residual relative clock drift: d δ̂i,m = ∆τ̂i,m (t), (19) dt

EKF and moving average.

where ∆τ̂i,j (t) is the differential delay between anchors i and the master. In ideal conditions, δ̂i,m = 0. When this is not the case, the same drift-estimation logic used in Sec. III-C3 can be applied to estimate δ̂i,j and compensate for the corresponding accumulating range error. In this case, Eq. 20 would become: TA-Corr. d˜UE,i = dˆUE,i − cδ̂+/− ∆tsync − cδ̂i,m ∆ti,m sync .

(20)

This extension is beyond the scope of the present evaluation, but RUN-O-RAN enables it directly, as the xApp observes the same uplink transmission from multiple anchors. B. Multi-Cell Visibility and Anchor Availability RUN-O-RAN assumes that the target UE is observable by at least three anchors with compatible radio configurations. This condition is plausible in dense small-cell deployments, private 5G networks, industrial campuses, and indoor distributed deployments, but it is not guaranteed in sparse or frequencyfragmented networks. In those cases, fewer than three gNBs may be able to receive and process the same SRS transmission. This limitation defines the operating region of pure trilateration, but it does not limit the broader RUN-O-RAN architecture. When three anchors are unavailable, the framework can be extended by combining range measurements with angular or beam measurements. A multi-antenna gNB, for example, can in principle fuse ToA-based ranging with Angle of Arrival (AoA) estimation [37]; with two anchors, range and angle constraints can reduce the remaining ambiguity. This points toward hybrid ToA/AoA localization within the same O-RAN control framework. More generally, RUN-O-RAN should be interpreted as a programmable infrastructure for network-side localization, rather than as a fixed three-anchor trilateration pipeline. Future

14

xApps can select the best available subset of anchors according to geometry, SNR, NLOS presence, multipath likelihood, antenna configuration, resource availability, and synchronization quality [38]. This would let the localization service adapt to the deployment instead of assuming every scenario provides the same anchor set. VII. C ONCLUSION This paper presented RUN-O-RAN, an O-RAN-native framework that enables cooperative UL localization from standard SRS transmissions generated by commercial UEs. By exploiting O-RAN-enabled network programmability, RUNO-RAN overcomes a fundamental limitation of conventional RAN deployments by enabling neighboring gNBs to cooperatively process UL transmissions through standard ORAN interfaces, without requiring modifications to the UE or existing 3GPP procedures. RUN-O-RAN integrates cooperative SRS collection, timing-advance compensation, clockdrift correction, and multi-anchor positioning into a complete network-side localization service. The experimental evaluation, comprising 288,000 SRS transmissions collected using commercial hardware and an O-RAN-compatible testbed, demonstrates meter-level localization accuracy under diverse anchor geometries and multipath conditions. The experiments show feasibility in static and dynamic scenarios, demonstrating that temporal filtering improves trajectory stability. While RUN-O-RAN mitigates NLOS-induced ranging errors by selecting the shortest path, it can be further improved by advanced anchor-selection techniques. Overall, these results demonstrate the architectural feasibility of cooperative uplink localization as an O-RAN-native framework that will help develop ISAC services for future cellular networks. R EFERENCES [1] Gonzalez-Prelcic and et al., “The integrated sensing and communication revolution for 6g: Vision, techniques, and applications,” Proceedings of the IEEE, vol. 112, no. 7, pp. 676–723, 2024. [2] ETSI, “Integrated Sensing And Communications (ISAC); Use Cases and Deployment Scenarios,” European Telecommunications Standards Institute, ETSI Group Report ETSI GR ISC 001 V1.1.1, 2025. [3] Zanini and et al., “Towards end-to-end implementation of 5g positioning with off-the-shelf devices,” in 2024 IEEE 100th Vehicular Technology Conference (VTC2024-Fall), 2024, pp. 1–6. [4] Polese and et al., “Understanding O-RAN: Architecture, interfaces, algorithms, security, and research challenges,” IEEE Communications Surveys & Tutorials, vol. 25, no. 2, pp. 1376–1411, 2023. [5] Reus-Muns and et al., “Senseoran: O-RAN based radar detection in the cbrs band,” JSAC, 2023. [6] Wen and et al., “5G-spector: An O-RAN compliant layer-3 cellular attack detection service,” in Proceedings of NDSS, 2024. [7] Lizarribar and et al., “ORAN-sense: Localizing non-cooperative transmitters with spectrum sensing and 5G O-RAN,” in INFOCOM, 2024. [8] Q. P. et al., “On nextg open ran as a sensing infrastructure,” in Proceedings of the 26th International Workshop on Mobile Computing Systems and Applications (HotMobile). ACM, 2025. [9] Zeng and et al., “New “5g+ beidou” integrated positioning based on openran architecture,” in CSNC. Springer, 2022, pp. 602–611. [10] Ko and et al., “Beamforming-based location management under an o-ran architecture using spark streaming,” in Proceedings of IEEE Vehicular Technology Conference, 2021. [11] Lizarribar and et al., “Oran-sense: Localizing non-cooperative transmitters with spectrum sensing and 5g o-ran,” in Proceedings of IEEE Conference, 2024.

[12] Jonnavithula and et al., “Mimo-ric: Ran intelligent controller for mimo xapps,” in Proceedings of the 30th Annual International Conference on Mobile Computing and Networking (MobiCom). ACM, 2024. [13] Malik and et al., “From concept to reality: 5g positioning with opensource implementation of ul-tdoa in openairinterface,” in Proceedings of IEEE Conference, 2025. [14] ETSI, “5G; NR; Physical Channels and Modulation (3GPP TS 38.211 version 16.10.0 Release 16),” European Telecommunications Standards Institute, Tech. Rep., Jul. 2022. [Online]. Available: http://www.etsi.org/standards-search [15] ——, “5G; NR; physical layer procedures for control,” European Telecommunications Standards Institute, Technical Specification (TS) ETSI TS 38.213 v. 16.2.0, 2020. [16] 3GPP, “NR; Medium Access Control (MAC) Protocol Specification,” ETSI, 3GPP Technical Specification TS 38.321, Apr. 2025. [17] ETSI, “5G; NR; requirements for support of radio resource management,” European Telecommunications Standards Institute, Tech. Rep., 2020. [18] Palamà and et al., “5G positioning with software-defined radios,” Computer Networks, p. 110595, 2024. [19] Hua and et al., “Analysis of the frequency offset effect on zadoff-chu sequence timing performance,” IEEE Transactions on Communications, vol. 62, no. 11, pp. 4024–4039, 2014. [20] Moro and et al., “An open RAN framework for the dynamic control of 5G service level agreements,” in NFV-SDN. IEEE, 2023, pp. 141–146. [21] Currier and et al., “Protocol buffers,” in Mobile Forensics–The File Format Handbook: Common File Formats and File Systems Used in Mobile Devices. Springer, 2022, pp. 223–260. [22] O-RAN Alliance, “E2 Interface: General Aspects and Principles,” ETSI, Technical Specification ETSI TS 104 038, Oct. 2024. [23] ——, “E2 Interface: Application Protocol,” ETSI, Technical Specification ETSI TS 104 039, Oct. 2024. [24] ——, “E2 Interface: Service Model,” ETSI, Technical Specification ETSI TS 104 040, Oct. 2024. [25] 3GPP, “NR; user equipment (UE) conformance specification; radio resource management (RRM),” 3rd Generation Partnership Project (3GPP), Technical Specification TS 38.533 V15.0.0, 2019. [26] Mundlamuri and et al., “Novel round trip time estimation in 5G NR,” 2024. [Online]. Available: https://arxiv.org/abs/2404.19618 [27] OpenAirInterface Software Alliance, “OpenAirInterface,” https://openairinterface.org/, 2026. [28] Open5GS Project, “Open5GS: Open Source 5G Core and EPC,” https: //open5gs.org/, 2026. [29] NVIDIA, “Sionna: An Open-Source Library for Next-Generation Physical Layer Research,” https://nvlabs.github.io/sionna/, 2026. [30] Keysight Technologies, “PROPSIM F32, F8, and FS8 RF Channel Emulators,” https://www.keysight.com/us/en/products/ channel-emulators/propsim-f32-f8-fs8-rf-channel-emulators.html, 2026. [31] Ettus Research, National Instruments, “NI Ettus USRP X410 Software Defined Radio,” https://www.ettus.com/all-products/usrp-x410/, 2026. [32] Sierra Wireless, “Sierra Wireless 5G Modules and Routers,” https: //www.sierrawireless.com/, 2026. [33] Ericsson, “5G Synchronization Requirements and Solutions,” Ericsson Technology Review, 2021. [Online]. Available: https: //www.ericsson.com/en/reports-and-papers/ericsson-technology-review/ articles/5g-synchronization-requirements-and-solutions [34] ——, “5G Transport Network Synchronization Solutions,” Ericsson Reports and Papers, 2021. [Online]. Available: https://www.ericsson.com/en/reports-and-papers/further-insights/ synchronization-in-5g-transport-network [35] Microchip Technology Inc., “Synchronizing 5G Networks with Timing Design and Management: Part Two,” Microchip Technology Blog, 2023. [Online]. Available: https://www.microchip.com/en-us/about/media-center/blog/2023/ synchronizing-5g-networks-with-timing-design-and-management-two [36] Xu and et al., “Experimental validation of 5g positioning with inter-cell clock bias correction,” IEEE Access, vol. 14, pp. 75 525–75 534, 2026. [37] Ceresoli and et al., “Aoa services in 5g networks: A framework for real-world implementation and systematic testing,” in 2026 IEEE International Conference on Communications Workshops (ICC Workshops), 2026, pp. 1–6. [38] Xhafa and et al., “Evaluation of 5g positioning performance based on utdoa, aoa and base-station selective exclusion,” Sensors, vol. 22, no. 1, 2022.

Record · ID 978379 · SHA-256 f8237f9073c4eee4
Retrieved via Conceptio — every document is proof-bundled with source, license, and retrieval metadata.