Logo
Nazad
Dalibor Zeman, Miralem Mehic, Miroslav Voznák
0 2026.

A Feasibility Analysis of Quantum-Safe 5G Roaming

The rapid advancement of quantum computing presents an urgent threat to 5G networks, particularly across sensitive roaming boundaries. While existing quantum-safe solutions typically require intrusive modifications to core network functions, this paper introduces a highly crypto-agile, non-intrusive proxy architecture to secure the N32 control-plane and N9 user-plane roaming interfaces. By deliberately isolating cryptographic operations within local, containerized proxies, our design avoids complex dependency upgrades on the running 5G core. To maximize practical deployability, we developed proof-of-concept prototypes based on OpenSSL 3.5.4 offering two distinct, highly configurable variants. The first enables immediate, software-only integration utilizing Post-Quantum Cryptography (PQC) suites (ML-KEM/ML-DSA, BIKE/Falcon). The second deploys autonomous agents in a custom Pre-Shared Key (PSK) configuration fed by out-of-band Quantum Key Distribution (QKD), enabling dynamically enforced cryptoperiods and seamless Public Key Infrastructure (PKI) fallback mechanism based on real-time key availability. We evaluate this architecture using a comprehensive open-source testbed combining Open5GS and QKDNetSim. To assess practical deployability, we measured control-plane registration times, cryptographic data volume, user-plane delay, and QKD key consumption against legacy HTTP(S) baselines. Experimental results demonstrate that these quantum-safe architectures perform comparably to, or better than, legacy security. The PQC proxies maintained competitive cold-start registration times (261–285 ms), successfully balancing computational and bandwidth trade-offs. Notably, the QKD-assisted PSK configuration achieved the highest efficiency, reducing median registration time to 258.2 ms (a 4.5% improvement over legacy HTTPS) and restricting handshake data volume to 12.3 kB by bypassing heavy asymmetric certificate authentication. Furthermore, all prototypes successfully secured the traditionally unencrypted GPRS Tunnelling Protocol user plane (GTP-U) traffic traversing the N9 interface with a practically negligible delay increase ( $\sim 300~\mu $ s). Finally, the study highlights critical transport-layer constraints, such as TCP-in-TCP congestion interference, underscoring the necessity of DTLS 1.3 to optimize practical, quantum-resilient telecommunications infrastructure.

Pretplatite se na novosti o BH Akademskom Imeniku

Ova stranica koristi kolačiće da bi vam pružila najbolje iskustvo

Saznaj više