End-to-End Quantum Secured Inter-Domain 5G Service Orchestration Over Dynamically Switched Flex-Grid Optical Networks Enabled by a q-ROADM

End-to-End Quantum Secured Inter-Domain 5G Service Orchestration Over Dynamically Switched Flex-Grid Optical Networks Enabled by a q-ROADM
复制标题

DOI:
10.1109/jlt.2019.2949864
复制
发表时间:
2019-09
影响因子:
4.7
通讯作者:
Rui Wang;Qibing Wang;G. Kanellos;R. Nejabati;D. Simeonidou;R. S. Tessinari;E. Hugues-Salas;A. Bravalheri;N. Uniyal;A. Muqaddas;R. Guimaraes;T. Diallo;Shadi Moazzeni
Rui Wang;Qibing Wang;G. Kanellos;R. Nejabati;D. Simeonidou;R. S. Tessinari;E. Hugues-Salas;A. Bravalheri;N. Uniyal;A. Muqaddas;R. Guimaraes;T. Diallo;Shadi Moazzeni
中科院分区:
工程技术2区
文献类型:
--
作者:
Rui Wang;Qibing Wang;G. Kanellos;R. Nejabati;D. Simeonidou;R. S. Tessinari;E. Hugues-Salas;A. Bravalheri;N. Uniyal;A. Muqaddas;R. Guimaraes;T. Diallo;Shadi Moazzeni

文献摘要

被引文献

相似文献

通过网络功能虚拟化(NFV)和软件定义网络(SDN)实现的虚拟化和软件化相结合的动态和灵活的光网络是支持新兴5G网络服务的动态性、带宽和延迟要求的关键技术推动因素。为了实现5G的端到端连接目标,网络服务(NS)必须经常透明地部署在多个管理和技术领域。这种情况通常会带来安全风险,因为典型的NS 11网络服务是为实现所需网络功能而创建的多个虚拟和物理网络功能的组合。可以包括网络功能链,每个网络功能在不同的远程位置执行,并且在网络基础设施内的篡改可以损害它们的通信。为了避免这种威胁,量子密钥分发(QKD)已经被确定并提出作为一种未来证明的方法,不受任何基于基本量子物理机制的算法密码分析的影响,以分发对称密钥。QKD的成熟使得量子网络的研究和开发能够与使用电信级电信设备的经典光网络逐渐共存。这使得QKD技术成为分布式和虚拟化网络服务安全的合适候选者。在本文中,我们首次提出了一种动态量子安全光网络,用于支持通过链接虚拟网络功能(VNF)22动态创建的网络服务。硬件网络功能在软件中实现并部署为VM或容器时称为VNF。在多个网络域上。这项工作包括一个新的灵活网格量子交换可重构光分插复用器(q-ROADM),扩展到SDN启用的光控制平面,并扩展到NFV编排,以实现量子感知,按需链接的VNF。实验结果验证了在共享光纤链路上单独和动态路由量子和经典数据通道的能力。此外,5G网络中VNF的量子安全链接通过使用5GUK Exchange编排平台通过q-ROADM与八个光通道同时互连四个自治5G岛进行实验演示。实验场景和结果证实了所提出的数据平面架构和控制/管理平面框架的益处。
Dynamic and flexible optical networking combined with virtualization and softwarisation enabled by network function virtualization (NFV) and software defined networking (SDN) are the key technology enablers for supporting the dynamicity, bandwidth, and latency requirements of emerging 5G network services. To achieve the end-to-end connectivity objective of 5G, network services (NSes) must be often deployed transparently over multiple administrative and technological domains. Such scenario often presents security risks since a typical NS11Network service is a combination of multiple virtual and physical network functions created to realise a desired network functionality. may comprise a chain of network functions, each executed in different remote locations, and tampering within the network infrastructure may compromise their communication. To avoid such threats, quantum key distribution (QKD) has been identified and proposed as a future-proof method immune to any algorithmic cryptanalysis based on fundamental quantum-physics mechanisms to distribute symmetric keys. The maturity of QKD has enabled the research and development of quantum networks with gradual coexistence with classical optical networks using carrier-grade telecom equipment. This makes the QKD technology a suitable candidate for security of distributed and virtualised network services. In this article, for the first time, we propose a dynamic quantum-secured optical network for supporting network services that are dynamically created by chaining virtual network functions (VNFs)22Hardware network functions when implemented in software and deployed as VMs or containers are called VNFs. over multiple network domains. This work includes a new flex-grid quantum-switched reconfigurable optical add drop multiplexer (q-ROADM), extensions to SDN-enabled optical control plane, and extensions to NFV orchestration to achieve quantum-aware, on-demand chaining of VNFs. The experimental results verify the capability of routing quantum and classical data channels both individually and dynamically over shared fibre links. Moreover, quantum secured chaining of VNFs in 5G networks is experimentally demonstrated via interconnecting four autonomous 5G islands simultaneously through the q-ROADM with eight optical channels using the 5GUK Exchange orchestration platform. The experimental scenarios and results confirm the benefit of the proposed data plane architecture and control/management plane framework.