论文标题

5G网络切片隔离与线虫和开源Mano:VPNAAS概念证明

5G Network Slice Isolation with WireGuard and Open Source MANO: A VPNaaS Proof-of-Concept

论文作者

Haga, Simen, Esmaeily, Ali, Kralevska, Katina, Gligoroski, Danilo

论文摘要

第五代(5G)移动网络旨在在同一物理基础架构上托管不同类型的服务。网络切片被认为是实现此目标的关键推动力。尽管在5G的上下文应用和实施网络切片方面取得了一些进展,但是网络切片的安全性和性能仍然有许多开放的研究问题。在本文中,我们提出了第一个OSM-WireGuard框架及其生命周期。我们在5G网络中实现了WireGuard安全网络隧道协议,以为虚拟化网络函数提供VPN-AS-AS-Service(VPNAAS)功能。我们证明,OSM在4分钟26秒内启动并运行OSM,如果操作员在板载过程之前使用预装的预装和最新版本的Winegueard的图像准备图像,则可能会降至2分钟44秒的初始化时间。我们还表明,与OpenVPN相比,OSM-WireGuard框架可提供高达5.3倍的网络吞吐量和低41%的延迟。报告的结果表明,提出的框架是提供严格延迟和吞吐量要求的流量隔离的有前途的解决方案。

The fifth-generation (5G) mobile networks aim to host different types of services on the same physical infrastructure. Network slicing is considered as the key enabler for achieving this goal. Although there is some progress in applying and implementing network slicing in the context of 5G, the security and performance of network slicing still have many open research questions. In this paper, we propose the first OSM-WireGuard framework and its lifecycle. We implement the WireGuard secure network tunneling protocol in a 5G network to provide a VPN-as-a-Service (VPNaaS) functionality for virtualized network functions. We demonstrate that OSM instantiates WireGuard-enabled services up and running in 4 min 26 sec, with potential the initialization time to go down to 2 min 44 sec if the operator prepares images with a pre-installed and up-to-date version of WireGuard before the on-boarding process. We also show that the OSM-WireGuard framework provides considerable enhancement of up to 5.3 times higher network throughput and up to 41% lower latency compared to OpenVPN. The reported results show that the proposed framework is a promising solution for providing traffic isolation with strict latency and throughput requirements.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源