Network slicing enables the provision of services for different verticals over a shared infrastructure. Nevertheless, security is still one of the main challenges when sharing resources. In this paper, we study how WireGuard can provide an encrypted Virtual Private Network (VPN) tunnel as a service between network functions in 5G setting. The open source management and orchestration entity deploys and orchestrates the network functions into network services and slices. We create multiple scenarios emulating a real-life cellular network deploying VPN-as-a-Service between the different network functions to secure and isolate network slices. The performance measurements demonstrate from 0.8 Gbps to 2.5 Gbps throughput and below 1ms delay between network functions using WireGuard. The performance evaluation results are aligned with 5G key performance indicators, making WireGuard suited to provide security in slice isolation in future generations of cellular networks.
翻译:网络剪切使得能够在共享的基础设施上为不同垂直提供各种服务。然而,安全仍然是共享资源的主要挑战之一。在本文中,我们研究了WireGuard如何提供加密虚拟私人网络隧道,作为5G环境中网络功能之间的一种服务。开放源管理和管弦实体将网络功能部署到网络服务和切片,并将网络功能划为网络服务和切片。我们创造了多种假想,模拟在不同的网络功能之间部署VPN-as-a-service的实时移动电话网络,以保障和隔离网络切片。绩效测量显示,使用WireGuard的网络功能之间从0.8Gbps到2.5Gbps的流量和低于1ms的延迟。绩效评估结果与5G关键性能指标一致,使WireGuard适合在未来几代移动电话网络中提供切片安全。