Hybrid Conventional and Quantum Security for Software Defined and Virtualized Networks

被引:36
作者
Aguado, Alejandro [1 ]
Lopez, Victor [2 ]
Martinez-Mateo, Jesus [1 ]
Szyrkowiec, Thomas [3 ]
Autenrieth, Achim [3 ]
Peev, Momtchil [4 ]
Lopez, Diego [2 ]
Martin, Vicente [1 ]
机构
[1] Univ Politecn Madrid, Ctr Computat Simulat, Campus Montegancedo, E-28660 Madrid, Spain
[2] Telefon GCTO, Ronda Comunicac S-N, Madrid 28050, Spain
[3] ADVA Opt Networking, D-82152 Munich, Germany
[4] Huawei Technol Duesseldorf GmbH, Riesstr 25, D-80992 Munich, Germany
基金
欧盟地平线“2020”;
关键词
Network functions virtualization; Quantum key distribution; Software-defined networks; KEY DISTRIBUTION; QKD;
D O I
10.1364/JOCN.9.000819
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Today's networks are quickly evolving toward more dynamic and flexible infrastructures and architectures. This software-based evolution has seen its peak with the development of the software-defined networking (SDN) and network functions virtualization (NFV) paradigms. These new concepts allow operators to automate the setup of services, thus reducing costs in deploying and operating the required infrastructure. On the other hand, these novel paradigms expose new vulnerabilities, as critical information travels through the infrastructure from central offices, down to remote data centers and network devices. Quantum key distribution (QKD) is a state-of-the-art technology that can be seen as a source of symmetric keys in two separated domains. It is immune to any algorithmic cryptanalysis and is thus suitable for long-term security. This technology is based on the laws of physics, which forbids us from copying the quantum states exchanged between two endpoints from which a secret key can be extracted. Thus, even though it has some limitations, a correct implementation can deliver keys of the highest security. In this paper, we propose the integration of QKD systems with well-known protocols and methodologies to secure the network's control plane in an SDN and NFV environment. Furthermore, we experimentally demonstrate a workflow where QKD keys are used together with classically generated keys to encrypt communications between cloud and SDN platforms for setting up a service via secure shell, while showcasing the applicability to other cryptographic protocols.
引用
收藏
页码:819 / 825
页数:7
相关论文
共 22 条
  • [1] Secure NFV Orchestration Over an SDN-Controlled Optical Network With Time-Shared Quantum Key Distribution Resources
    Aguado, Alejandro
    Hugues-Salas, Emilio
    Haigh, Paul Anthony
    Marhuenda, Jaume
    Price, Alasdair B.
    Sibson, Philip
    Kennard, Jake E.
    Erven, Chris
    Rarity, John G.
    Thompson, Mark Gerard
    Lord, Andrew
    Nejabati, Reza
    Simeonidou, Dimitra
    [J]. JOURNAL OF LIGHTWAVE TECHNOLOGY, 2017, 35 (08) : 1357 - 1362
  • [2] ABNO: A Feasible SDN Approach for Multivendor IP and Optical Networks
    Aguado, Alejandro
    Lopez, Victor
    Marhuenda, Jaume
    Gonzalez de Dios, Oscar
    Pedro Fernandez-Palacios, Juan
    [J]. JOURNAL OF OPTICAL COMMUNICATIONS AND NETWORKING, 2015, 7 (02) : A356 - A362
  • [3] Ben-Or M, 2005, LECT NOTES COMPUT SC, V3378, P386
  • [4] Cramer R, 1998, LECT NOTES COMPUT SC, V1462, P13, DOI 10.1007/BFb0055717
  • [5] Secure Optical Networks Based on Quantum Key Distribution and Weakly Trusted Repeaters
    Elkouss, David
    Martinez-Mateo, Jesus
    Ciurana, Alex
    Martin, Vicente
    [J]. JOURNAL OF OPTICAL COMMUNICATIONS AND NETWORKING, 2013, 5 (04) : 316 - 328
  • [6] Quantum cryptography
    Gisin, N
    Ribordy, GG
    Tittel, W
    Zbinden, H
    [J]. REVIEWS OF MODERN PHYSICS, 2002, 74 (01) : 145 - 195
  • [7] Github, GITH DOCKERNET TOOL
  • [8] Network Function Virtualization: Challenges and Opportunities for Innovations
    Han, Bo
    Gopalakrishnan, Vijay
    Ji, Lusheng
    Lee, Seungjoon
    [J]. IEEE COMMUNICATIONS MAGAZINE, 2015, 53 (02) : 90 - 97
  • [9] Jimenez T., 2017, OPT FIB COMM C OFC
  • [10] Kurosawa K, 2004, LECT NOTES COMPUT SC, V3152, P426