Sim Dong-Hi, Shin Jongyoon, Kim Min Hyung
SK Telecom, Seoul 04539, Republic of Korea.
Entropy (Basel). 2023 Jun 15;25(6):943. doi: 10.3390/e25060943.
This paper demonstrates the use of software-defined networking (SDN) orchestration to integrate regionally separated networks in which different network parts use incompatible key management systems (KMSs) managed by different SDN controllers to ensure end-to-end QKD service provisioning to deliver the QKD keys between geographically different QKD networks. The study focuses on scenarios in which different parts of the network are managed separately by different SDN controllers, requiring an SDN orchestrator to coordinate and manage these controllers. In practical network deployments, operators often utilize multiple vendors for their network equipment. This practice also enables the expansion of the QKD network's coverage by interconnecting various QKD networks equipped with devices from different vendors. However, as coordinating different parts of the QKD network is a complex task, this paper proposes the implementation of an SDN orchestrator which acts as a central entity to manage multiple SDN controllers, ensuring end-to-end QKD service provisioning to address this challenge. For instance, when there are multiple border nodes to interconnect different networks, the SDN orchestrator calculates the path in advance for the end-to-end delivery of keys between initiating and target applications belonging to different networks. This path selection requires the SDN orchestrator to gather information from each SDN controller managing the respective parts of the QKD network. This work shows the practical implementation of SDN orchestration for interoperable KMS in commercial QKD networks in South Korea. By employing an SDN orchestrator, it becomes possible to coordinate multiple SDN controllers and ensure the efficient and secure delivery of QKD keys between different QKD networks with varying vendor equipment.
本文展示了如何使用软件定义网络(SDN)编排来集成区域分离的网络,其中不同的网络部分使用由不同SDN控制器管理的不兼容密钥管理系统(KMS),以确保提供端到端的量子密钥分发(QKD)服务,从而在地理上不同的QKD网络之间传递QKD密钥。该研究聚焦于网络的不同部分由不同SDN控制器单独管理的场景,这需要一个SDN编排器来协调和管理这些控制器。在实际的网络部署中,运营商通常会为其网络设备使用多个供应商。这种做法还能够通过互连配备不同供应商设备的各种QKD网络来扩大QKD网络的覆盖范围。然而,由于协调QKD网络的不同部分是一项复杂的任务,本文提出实施一个SDN编排器,它作为一个中央实体来管理多个SDN控制器,以确保提供端到端的QKD服务来应对这一挑战。例如,当有多个边界节点来互连不同网络时,SDN编排器会预先计算在属于不同网络的发起应用程序和目标应用程序之间进行密钥端到端传递的路径。这种路径选择要求SDN编排器从管理QKD网络各个部分的每个SDN控制器收集信息。这项工作展示了韩国商业QKD网络中用于可互操作KMS的SDN编排的实际实现。通过采用一个SDN编排器,可以协调多个SDN控制器,并确保在配备不同供应商设备的不同QKD网络之间高效且安全地传递QKD密钥。