IPsec based on Quantum Key Distribution: Adapting non-3GPP access to 5G Networks to the Quantum Era

πŸ“… 2026-03-25
πŸ“ˆ Citations: 0
✨ Influential: 0
πŸ“„ PDF
πŸ€– AI Summary
This work addresses the threat posed by quantum computing to conventional public-key cryptography and Diffie-Hellman key exchange by proposing and implementing a quantum-safe access mechanism for 5G non-3GPP access networks, such as Wi-Fi. The proposed scheme uniquely integrates keys generated via Quantum Key Distribution (QKD) into the IPsec Security Association establishment process, leveraging coordination between the Non-3GPP InterWorking Function (N3IWF) and an open-source 5G core network to construct an end-to-end information-theoretically secure heterogeneous access architecture. Experimental results demonstrate that, compared to traditional pre-shared key and certificate-based approaches, the method improves key agreement efficiency by 4.62% and 5.17%, respectively, while simultaneously ensuring information-theoretic security and significantly enhancing the quantum resistance of 5G non-3GPP access.

Technology Category

Application Category

πŸ“ Abstract
The advent of quantum computing will pose great challenges to the current communication systems, requiring essential changes in the establishment of security associations in traditional architectures. In this context, the multi-technological and heterogeneous nature of 5G networks makes it a challenging scenario for the introduction of quantum communications. Specifically, 5G networks support the unification of non-3GPP access technologies (i.e. Wi-Fi), which are secured through the IPsec protocol suite and the Non-3GPP Interworking Function (N3IWF) entity. These mechanisms leverage traditional public key cryptography and Diffie-Hellman key exchange mechanisms, which should be updated to quantum-safe standards. Therefore, in this paper we present the design and development of a Quantum Key Distribution (QKD) based non-3GPP access mechanism for 5G networks, integrating QKD keys with IPsec tunnel establishment. Besides, we also demonstrate the feasibility of the system by experimental validation in a testbed with commercial QKD equipment and an open-source 5G core implementation. Results show that the time required to complete the authentication and IPsec security association establishment is 4.62% faster than traditional cryptography PSK-based systems and 5.17% faster than the certificate-based system, while ensuring Information-Theoretic Security (ITS) of the QKD systems.
Problem

Research questions and friction points this paper is trying to address.

Quantum Key Distribution
IPsec
5G Networks
non-3GPP access
Quantum-Safe Security
Innovation

Methods, ideas, or system contributions that make the work stand out.

Quantum Key Distribution
IPsec
5G Non-3GPP Access
Information-Theoretic Security
N3IWF
πŸ”Ž Similar Papers
No similar papers found.
A
Asier Atutxa
Dept. of Communications Engineering, EHU Quantum Center, University of the Basque Country, Bilbao, Spain
A
Ane Sanz
Dept. of Communications Engineering, EHU Quantum Center, University of the Basque Country, Bilbao, Spain
E
Eire Salegi
Dept. of Communications Engineering, University of the Basque Country, Bilbao, Spain
G
Gaizka GonzΓ‘lez
Dept. of Communications Engineering, University of the Basque Country, Bilbao, Spain
Jasone Astorga
Jasone Astorga
University of the Basque Country UPV/EHU
cybersecurity5GNFV/SDN
Eduardo Jacob
Eduardo Jacob
University of the Basque Country
computer sciencecomputer networkssecuritysoftware defined networks