Orchestrating Isolated Network Slices in 5G Networks

Ali Esmaeily,Katina Kralevska
DOI: https://doi.org/10.3390/electronics13081548
IF: 2.9
2024-04-19
Electronics
Abstract:Sharing resources through network slicing in a physical infrastructure facilitates service delivery to various sectors and industries. Nevertheless, ensuring security of the slices remains a significant hurdle. In this paper, we investigate the utilization of State-of-the-Art (SoA) Virtual Private Network (VPN) solutions in 5G networks to enhance security and performance when isolating slices. We deploy and orchestrate cloud-native network functions to create multiple scenarios that emulate real-life cellular networks. We evaluate the performance of the WireGuard, IPSec, and OpenVPN solutions while ensuring confidentiality and data protection within 5G network slices. The proposed architecture provides secure communication tunnels and performance isolation. Evaluation results demonstrate that WireGuard provides slice isolation in the control and data planes with higher throughput for enhanced Mobile Broadband (eMBB) and lower latency for Ultra-Reliable Low-Latency Communications (URLLC) slices compared to IPSec and OpenVPN. Our developments show the potential of implementing WireGuard isolation, as a promising solution, for providing secure and efficient network slicing, which fulfills the 5G key performance indicator values.
engineering, electrical & electronic,computer science, information systems,physics, applied
What problem does this paper attempt to address?
The paper aims to address the issues of security isolation and performance isolation in network slicing within 5G networks. Specifically: - **Research Background**: With the development of Network Function Virtualization (NFV), Software-Defined Networking (SDN), and Multi-access Edge Computing (MEC), 5G networks can provide diverse Quality of Service (QoS). However, ensuring security isolation between different slices in a shared infrastructure remains a significant challenge. - **Main Objectives**: The paper proposes an integrated XVPN-OSM architecture that utilizes the latest Virtual Private Network (VPN) solutions (such as WireGuard, IPSec, and OpenVPN) to create secure and efficient network slices in 5G networks. This architecture aims to achieve: - Security Isolation: Ensuring data security between Virtual Network Functions (VNFs) through encrypted communication tunnels; - Performance Isolation: Ensuring that the performance of different slices is not interfered with, for example, enhanced Mobile Broadband (eMBB) slices require high throughput, while Ultra-Reliable Low-Latency Communication (URLLC) slices require low latency. - **Specific Contributions**: - Proposing an XVPN-OSM architecture that provides both security isolation and performance isolation between slices; - Implementing point-to-point VPN solutions to meet tenants' needs for end-to-end data confidentiality; - Evaluating the performance of different VPN solutions in a 5G Standalone (SA) environment through Proof of Concept (PoC); - Using Open Source Management and Orchestration (OSM) to automatically deploy and manage network service instances and their slices, and establishing VPN tunnels between different VNFs; - Demonstrating that the proposed XVPN-OSM architecture can meet key performance indicators (KPIs), including high throughput for eMBB slices and low latency for URLLC slices. Through these measures, the paper aims to provide a secure and efficient network slicing isolation mechanism to meet the critical performance requirements of 5G networks.