5G Network Slice Isolation with WireGuard and Open Source MANO: A VPNaaS Proof-of-Concept

Simen Haga, A. Esmaeily, Katina Kralevska, D. Gligoroski
{"title":"5G Network Slice Isolation with WireGuard and Open Source MANO: A VPNaaS Proof-of-Concept","authors":"Simen Haga, A. Esmaeily, Katina Kralevska, D. Gligoroski","doi":"10.1109/NFV-SDN50289.2020.9289900","DOIUrl":null,"url":null,"abstract":"The fifth-generation (5G) mobile networks aim to host different types of services on the same physical infrastructure. Network slicing is considered as the key enabler for achieving this goal. Although there is some progress in applying and implementing network slicing in the context of 5G, the security and performance of network slicing still have many open research questions. In this paper, we propose the first OSM-WireGuard framework and its lifecycle. We implement the WireGuard secure network tunneling protocol in a 5G network to provide a VPN-as-a-Service (VPNaaS) functionality for virtualized network functions. We demonstrate that OSM instantiates WireGuard-enabled services up and running in 4 min 26 sec, with potential the initialization time to go down to 2 min 44 sec if the operator prepares images with a pre-installed and up-to-date version of WireGuard before the on-boarding process. We also show that the OSM-WireGuard framework provides considerable enhancement of up to 5.3 times higher network throughput and up to 41% lower latency compared to OpenVPN. The reported results show that the proposed framework is a promising solution for providing traffic isolation with strict latency and throughput requirements.","PeriodicalId":283280,"journal":{"name":"2020 IEEE Conference on Network Function Virtualization and Software Defined Networks (NFV-SDN)","volume":"85 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2020-10-08","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"8","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2020 IEEE Conference on Network Function Virtualization and Software Defined Networks (NFV-SDN)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/NFV-SDN50289.2020.9289900","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 8

Abstract

The fifth-generation (5G) mobile networks aim to host different types of services on the same physical infrastructure. Network slicing is considered as the key enabler for achieving this goal. Although there is some progress in applying and implementing network slicing in the context of 5G, the security and performance of network slicing still have many open research questions. In this paper, we propose the first OSM-WireGuard framework and its lifecycle. We implement the WireGuard secure network tunneling protocol in a 5G network to provide a VPN-as-a-Service (VPNaaS) functionality for virtualized network functions. We demonstrate that OSM instantiates WireGuard-enabled services up and running in 4 min 26 sec, with potential the initialization time to go down to 2 min 44 sec if the operator prepares images with a pre-installed and up-to-date version of WireGuard before the on-boarding process. We also show that the OSM-WireGuard framework provides considerable enhancement of up to 5.3 times higher network throughput and up to 41% lower latency compared to OpenVPN. The reported results show that the proposed framework is a promising solution for providing traffic isolation with strict latency and throughput requirements.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
使用WireGuard和开源MANO的5G网络切片隔离:VPNaaS概念验证
第五代(5G)移动网络旨在在相同的物理基础设施上托管不同类型的服务。网络切片被认为是实现这一目标的关键推动者。虽然在5G背景下网络切片的应用和实现取得了一定的进展,但网络切片的安全性和性能仍有许多有待研究的问题。在本文中,我们提出了第一个OSM-WireGuard框架及其生命周期。我们在5G网络中实现了WireGuard安全网络隧道协议,为虚拟化网络功能提供vpn即服务(VPNaaS)功能。我们证明,OSM在4分26秒内启动并运行了支持WireGuard的服务,如果作业者在启动过程之前使用预安装的最新版本的WireGuard准备图像,则初始化时间可能会降低到2分44秒。我们还表明,与OpenVPN相比,OSM-WireGuard框架提供了相当大的增强,网络吞吐量提高了5.3倍,延迟降低了41%。报告的结果表明,所提出的框架是提供具有严格延迟和吞吐量要求的流量隔离的有希望的解决方案。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Enhancing Performance, Security, and Management in Network Function Virtualization Incremental Deployment of Hybrid IP/SDN Network with Optimized Traffic Engineering PSVShare: A Priority-based SFC placement with VNF Sharing On the Design of Fast and Scalable Network Applications Through Data Stream Processing Policy Controlled Multi-domain cloud-network Slice Orchestration Strategy based on Reinforcement Learning
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1