论文标题
5G网络用QKD和Quantum-SAFE安全性切片
5G Network Slicing with QKD and Quantum-Safe Security
论文作者
论文摘要
我们演示了如何扩展5G网络切片模型以满足数据安全要求。在这项工作中,我们演示了两种不同的切片配置,具有不同的加密要求,代表了两个用于5G网络的不同用例:即,一个托管在地铁网络站点的企业应用程序和内容交付网络。我们创建了一个修改的软件定义网络(SDN)编排器,该编排器根据要求计算和规定网络切片,包括由量子密钥分布(QKD)或其他方法支持的加密。通过SDN编排网络资源,可以自动提供切片,从而允许选择加密的链接,包括使用标准Diffie-Hellman密钥交易所,QKD和QUAN-nastum抗量子算法(QRAS)的链接,以及根本没有加密。我们表明,网络切片的设置和拆除时间为1-2分钟,这比当今手动配置链接的数量级改进。
We demonstrate how the 5G network slicing model can be extended to address data security requirements. In this work we demonstrate two different slice configurations, with different encryption requirements, representing two diverse use-cases for 5G networking: namely, an enterprise application hosted at a metro network site, and a content delivery network. We create a modified software-defined networking (SDN) orchestrator which calculates and provisions network slices according to the requirements, including encryption backed by quantum key distribution (QKD), or other methods. Slices are automatically provisioned by SDN orchestration of network resources, allowing selection of encrypted links as appropriate, including those which use standard Diffie-Hellman key exchange, QKD and quantum-resistant algorithms (QRAs), as well as no encryption at all. We show that the set-up and tear-down times of the network slices takes of the order of 1-2 minutes, which is an order of magnitude improvement over manually provisioning a link today.