论文标题

通过切片隔离和钢线固定服务实施

Secure Service Implementation with Slice Isolation and WireGuard

论文作者

Kielland, Sondre, Esmaeily, Ali, Kralevska, Katina, Gligoroski, Danilo

论文摘要

网络切片可以在共享基础架构上为不同的垂直领域提供服务。然而,安全仍然是共享资源时的主要挑战之一。在本文中,我们研究了VireGuard如何提供加密的虚拟专用网络(VPN)隧道作为5G设置中网络功能之间的服务。开源管理和编排实体将网络功能部署并安排在网络服务和切片中。我们创建了多种场景,模仿了真实的蜂窝网络,在不同的网络函数之间部署VPN-AS-AS-Service以保护和隔离网络切片。性能测量结果从0.8 Gbps到2.5 Gbps吞吐量,使用VireGuard在网络函数之间延迟1ms。绩效评估结果与5G关键性能指标对齐,这使得线索适合在后代的蜂窝网络中提供切片隔离的安全性。

Network slicing enables the provision of services for different verticals over a shared infrastructure. Nevertheless, security is still one of the main challenges when sharing resources. In this paper, we study how WireGuard can provide an encrypted Virtual Private Network (VPN) tunnel as a service between network functions in 5G setting. The open source management and orchestration entity deploys and orchestrates the network functions into network services and slices. We create multiple scenarios emulating a real-life cellular network deploying VPN-as-a-Service between the different network functions to secure and isolate network slices. The performance measurements demonstrate from 0.8 Gbps to 2.5 Gbps throughput and below 1ms delay between network functions using WireGuard. The performance evaluation results are aligned with 5G key performance indicators, making WireGuard suited to provide security in slice isolation in future generations of cellular networks.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源