Connecting distributed applications across multiple cloud-native domains is growing in complexity. Applications have become containerized and fragmented across heterogeneous infrastructures, such as public clouds, edge nodes, and private data centers, including emerging IoT-driven environments. Existing networking solutions like CNI plugins and service meshes have proven insufficient for providing isolated, low-latency and secure multi-cluster communication. By combining SDN control with Kubernetes abstractions, we present L2S-CES, a Kubernetes-native solution for multi-cluster layer-2 network slicing that offers flexible isolated connectivity for microservices while maintaining performance and automation. In this work, we detail the design and implementation of L2S-CES, outlining its architecture and operational workflow. We experimentally validate against state-of-the-art alternatives and show superior isolation, reduced setup time, native support for broadcast and multicast, and minimal performance overhead. By addressing the current lack of native link-layer networking capabilities across multiple Kubernetes domains, L2S-CES provides a unified and practical foundation for deploying scalable, multi-tenant, and latency-sensitive cloud-native applications.
The rapid deployment of large-scale non-geostationary satellite orbit (NGSO) constellations has increased the need for tools that accurately evaluate their networking performance prior to deployment. However, existing solutions mainly rely on simulation techniques that fail to capture key characteristics of real NGSO systems, such as dynamic topology changes, realistic traffic behaviour, routing reconfigurations, and quality-of-service (QoS) constraints. This paper presents LOOM, a hybrid simulation–emulation framework specifically designed for the realistic evaluation of large-scale and hybrid NGSO constellations. LOOM integrates orbital propagation, dynamic network emulation, and interactive visualisation to enable the injection of realistic traffic patterns, on-demand topology updates, and the evaluation of routing and traffic engineering strategies under realistic operating conditions. The framework supports heterogeneous constellations, including multi-layer and hybrid low Earth orbit (LEO)–medium Earth orbit (MEO) architectures, while providing detailed performance metrics such as routing paths, link utilisation, and end-to-end (E2E) traffic characteristics. The capabilities of LOOM are validated through three representative use cases inspired by Iridium, Telesat, and IRIS2 constellations, demonstrating its scalability, flexibility, and effectiveness in capturing the dynamic behaviour of NGSO networks. LOOM serves as a practical tool for the design, validation, and optimisation of next-generation satellite networks.
The quantum era compromises current cryptography, motivating the development of Post-Quantum Cryptography (PQC) and Quantum Key Distribution (QKD) as complementary approaches to secure long-term communications. Satellite platforms are expected to extend QKD beyond terrestrial distance limits, yet their integration into broader network infrastructures introduces significant architectural and operational challenges. This work examines these challenges from a networking perspective and explores how PQC can assist early satellite-based QKD deployments. We introduce a control-plane model that combines satellite QKD for Earth-to-space key establishment with PQC-secured inter-satellite communication, enabling key delivery between ground stations when quantum keys are not yet available network-wide. A case study based on emulated keyexchange procedures using timing data derived from the Iridium constellation illustrates the feasibility of the approach.
The realization of a Quantum Internet is expected to transform communication networks by enabling intrinsically secure information exchange and distributed quantum applications. However, the experimental study of large-scale quantum networks remains limited by the high cost and operational constraints of quantum hardware. To address this challenge, this paper presents the design of a platform conceived to support research and experimentation in the field of quantum networking. The proposed system provides an emulation environment that mirrors the behavior of a real quantum network, enabling researchers to test protocols and mechanisms through a set of quantum operation instructions accessible via an Application Programming Interface (API). Emulated quantum nodes can be deployed across physically distributed locations, using physical or virtual machines or virtualization containers, allowing experiments to reproduce realistic network conditions and inter-node interactions. This approach enables applications to be executed over a persistent, configurable, and interactive environment that integrates both quantum and classical communication layers. To validate the feasibility of the proposed design, a prototype has been built and used to demonstrate its operation through a multi-hop quantum teleportation proof of concept. The results confirm the viability and flexibility of the architecture, laying the foundation for a distributed framework that facilitates the development and evaluation of quantum network architectures, control mechanisms, and experimental use cases.
Quantum Key Distribution (QKD) enables two parties to securely share encryption keys by leveraging the principles of quantum mechanics, offering protection against eavesdropping. In practical implementations, QKD systems often rely on a layered architecture where a key manager stores secret key material in a buffer and delivers it to higher communication layers as needed. However, this buffer can be depleted under high demand, requiring efficient replenishment strategies that minimize resource waste. Given the importance of optimizing time and resources in quantum cryptography protocols, we introduce a variable-length adaptation of the BB84 protocol designed to meet user-defined output key length constraints in non-ideal scenarios. We present a method for dynamically configuring the protocol's initial parameters to generate secret keys of a desired length. To validate our approach, we developed simulation tools to model general QKD networks and discrete-variable protocols. These tools were used to implement and evaluate our strategies, which were developed within the BB84 framework but can be extended to other QKD protocols under reasonable assumptions. The results highlight their usefulness in optimizing quantum resource usage and supporting key management, contributing to the long-term goal of scaling and strengthening secure quantum networks.
Microservice-based platforms such as Kubernetes have experienced a rise in popularity for the deployment of network services. However, existing solutions do not fully address the requirements of these environments, as network services demand a finer degree of control over communication behaviour and network management. Therefore, any solution aiming at deploying such services should combine flexible traffic isolation with comprehensive communication security to address the security needs of microservice-based platforms. This paper presents a layered secure communication architecture that enables protected data exchange in microservice environments by integrating isolation mechanisms with multi-scope protection strategies. In particular, the proposed solution combines virtual network segmentation with complementary security mechanisms operating at different levels, including infrastructure-level protection and service-level end-to-end encryption. In addition, optional post-quantum secure key establishment can be incorporated to enhance long-term security guarantees. An experimental evaluation analyses the performance impact of each protection layer in terms of throughput and jitter. Results show that, although layered protection introduces measurable overhead, the system maintains sufficient performance to support common microservice-based workloads while providing enhanced security across multiple communication scopes.
The growing adoption of NFV across federated and heterogeneous infrastructures raises important security concerns, particularly regarding the trustworthiness of virtual links connecting Virtual Network Functions (VNFs). In this context, this article introduces a decentralized security solution that enables link-level protection directly at the VNF layer, independently of the underlying infrastructure. Building on ETSI principles, the proposed approach complements existing NFV security and management capabilities by allowing neighboring VNFs to negotiate and enforce protection mechanisms in a decentralized manner over shared virtual links. A prototype implementation and validation on a hybrid Kubernetes/Open- Stack NFV testbed demonstrate the portability of the solution, its scalability, and its negligible impact on service instantiation and runtime overhead.
Monitoring mechanisms are essential in modern telecommunications networks, ensuring reliability, performance, and security by continuously tracking network health and status. These mechanisms enable real-time anomaly detection and response, allowing for fast intervention and dynamic optimization of network resources. To advance Quantum Key Distribution (QKD) networks toward becoming a mainstream service within current telecommunication infrastructures, comprehensive monitoring mechanisms must be available. This paper explores the integration of such a monitoring approach for QKD. Leveraging a recently proposed model that utilizes virtualization to create an abstraction layer over the highly heterogeneous array of quantum and classical hardware, this monitoring mechanism offers significant advantages. These include the continuous provisioning of real-time data and traffic statistics on network segments, as well as the detection of potential attacks or failures on critical network elements, enabling dynamic, data-driven routing, operations, and management. The proposed monitoring strategy, which incorporates both passive and active measurements, enables proactive and immediate actions when any network irregularity is detected. Beyond detailing the monitoring mechanism, we demonstrate its feasibility through a virtual environment test, validating its effectiveness in a controlled setting.
Quantum Key Distribution (QKD) offers information-theoretic security by leveraging quantum mechanics, yet the cost and complexity of dedicated hardware and fiber infrastructure have so far limited large-scale deployment and experimentation. In this paper, we introduce Quditto, an automated open-access emulation platform that combines high-fidelity quantum-channel modeling with a standardized key-delivery API, enabling users to interact with the emulated network exactly as they would with real QKD hardware. Quditto modular design supports pluggable protocol implementations, complex key management schemes and detailed channel models, including variable attenuation and decoherence. We validate Quditto by deploying networks of various sizes and demonstrate its flexibility through two proof-of-concept scenarios featuring eavesdropper attacks and heterogeneous channel conditions.
The advent of softwarization and disaggregated architectures has transformed modern communication networks, sparking innovation by separating network functionalities from the underlying hardware. Following this trend, in future quantum networks, the virtualization and softwarization of critical components will be essential to achieve global interoperability and enhance adaptability. Virtualization allows for the abstraction of hardware resources, making it easier to manage and scale networks dynamically, while softwarization promotes flexibility, reconfigurability, and interoperability by enabling the use of standardized, software-defined protocols that can be easily updated and modified to work across diverse and evolving network environments. In this paper, we introduce and examine an operational model for QKD networks that leverages the virtualization of control and key management functionalities. We detail its elements and procedures to optimize QKD services. The design paves the way for the integration of quantum network with functions already established in modern mobile networks while adhering to established QKD network standards. The proposed operational model has been validated at the 5G Telefonica Open Network Innovation Centre (5TONIC) using an environment that deploys digital twins of QKD networks.
This article proposes a novel connectivity orchestration service for multidomain network functions virtualization ecosystems to address current limitations. The service automatically provides connectivity to remote virtual functions using software-defined networking technologies.
Containerization technologies have risen in popularity for deploying microservices applications in cloud-native environments, offering the benefits of traditional virtualization with reduced overhead. However, existing container networking solutions lack support for applications requiring isolated link-layer communications among containers in different clusters. These communications are fundamental to enable the seamless integration of cloud-native solutions in 5G and beyond networks. Accordingly, we present an SDN-enabled networking solution that supports the creation of isolated link-layer virtual networks between containers across different Kubernetes clusters by building virtual circuits that dynamically adapt to changes in the topology. In this article, we introduce our solution, highlighting its advantages over existing alternatives, and provide a comprehensive design overview. Additionally, we validate it through an experiment, offering a deeper understanding of its functionality. Our work fills an existing gap for applications with inter-cluster link-layer networking access requirements in the cloud-native ecosystem.
Softwarization and disaggregated architectures have transformed traditional communication networks by separating network control functions from the hardware, catalyzing innovation, and dramatically reducing deployment and operation costs. This paper extends these concepts to Quantum Key Distribution (QKD) networks, emphasizing the importance of virtualizing key management functions with advanced cloud-native technologies for enhanced global interoperability and flexibility. Our approach advocates for a fully disaggregated key management plane supported by softwarization and virtualization technologies, without losing sight of the established standards. The proposed model unlocks multiple benefits, including the facilitation of tailored access control mechanisms for QKD network administrators, the ability to apply real-time performance monitoring and base the control and management of the network on the gathered data, as well as conducting different key generation Quality of Service (QoS) admission control mechanisms on the QKD network. Moreover, a disaggregated model of the key management functions facilitates the implementation of different strategies for cross-domain collaboration between QKD network providers, as well as continuous key provisioning even in the midst of quantum infrastructure outages. The model has been validated through experiments in a virtualized environment, leveraging software tools to create customizable digital twins of QKD networks.
Quantum technologies promise major advances in different areas. From computation to sensing or telecommunications, quantum implementations could bring significant improvements to these fields, arousing the interest of researchers, companies, and governments. In particular, the deployment of Quantum Key Distribution (QKD) networks, which enable the secure dissemination of cryptographic keys to remote application entities following Quantum Mechanics Principles, appears to be one of the most attractive and relevant use cases. Quantum devices and equipment are still in a development phase, making their availability low and their price high, hindering the deployment of physical QKD networks and, therefore, the research and experimentation activities related to this field. In this context, this paper focuses on providing research stakeholders with an open-access testbed where it is feasible to emulate the deployment of QKD networks, thus enabling the execution of experiments and trials, where even potential network attacks can be analyzed, without the quantum physical equipment requirement, nor compromising the integrity of an already built QKD network. The designed solution allows users to automatically deploy, configure, and run a digital twin environment of a QKD network, offering cost-effectiveness and great flexibility in the study of the integration of quantum communications in the current network infrastructures. This solution is aligned with the European Telecommunications Standard Institute (ETSI) standardized application interface for QKD, and is built upon open-source technologies. The feasibility of this solution has been validated throughout several functional trials carried out in the 5G Telefónica Open Network Innovation Centre (5TONIC), verifying the service performance in terms of speed and discarded qubits when generating the quantum keys.
Network Functions Virtualization (NFV) is a fundamental enabler in 5G networks, automating service deployment through softwarization and virtualization. However, challenges remain in providing network connectivity to service components, commonly referred to as Virtual Network Functions (VNFs), deployed on different domains. A usual approach to enable such connectivity is to rely on layer-3 routing from Internet service providers. However, this approach presents limitations to preserve isolation among remote VNFs, and may require undesirable network configurations. This paper proposes a novel connectivity orchestration service for multi-domain NFV ecosystems to address these limitations. The service is based on a set of interconnected software components that are deployed on every NFV domain. Connectivity is automatically provided to remote VNFs over the overlay network formed by these components using Software-Defined Network (SDN) technologies. The service has been prototyped using open-source software, being validated on a real NFV ecosystem.
This poster showcases an industry-academia collaboration between Telefónica and Universidad Carlos III de Madrid, aiming to establish a testbed to support research and experimentation with novel IoT, edge, and cloud computing technologies. The testbed has been deployed at the 5G Telefonica Open Network Innovation Centre (5TONIC), and enables the seamless integration of IoT/Edge/Cloud infrastructure domains using virtual and hardware components that can be made available both within 5TONIC and external premises. The design of the testbed is based on key enabling technologies in 5G/6G networking, including Network Function Virtualization (NFV), Software Defined Networking (SDN), and cloud-native computing, as well as on a Secure Infrastructure Abstraction (SIA) that facilitates automation and secure network communications.
Network performance monitoring is a crucial aspect in order to maintain reliable and efficient communications between different hosts and clusters. This is becoming more relevant as companies are progressively moving towards cloud-native environments, where hyperconnected islands are deployed. While monitoring for individual clusters and components is widely deployed, inter-domain metrics have not been yet added to present solutions. In this paper, we present MONCHi, an open-source based custom monitoring tool designed to collect and analyse traditional and custom metrics for network links within and among Kubernetes clusters. MONCHi consists on the flexible design and implementation on top of a conventional monitoring tool –Prometheus in this case– of several custom scripts that run in separate containers within a single pod and continuously collect and store metrics. These metrics are then exposed and visualised in an analysis tool, allowing for easy monitoring of network performance in clusters and for scalable multi-domain deployments based on multiple Prometheus instances. We also discuss the modification of Prometheus configuration to support the new endpoint for MONCHi. Finally, we present the results of several performance tests, focusing mainly on Round-Trip Time (RTT) and bandwidth, conducted to validate the effectiveness of MONCHi to accurately collect and analyse network performance metrics. Overall, MONCHi provides an effective and easy to customise solution for monitoring cloud-native multi-domain environments.
Federated Learning (FL) is a distributed Machine Learning paradigm that allows multiple clients to collaboratively train a model under the control of a central server while keeping data locally in edge devices. To simplify workload management in FL ecosystems, cloud computing and container-based approaches such as Kubernetes (K8s) have been proposed for scalable deployment. Nonetheless, K8s can violate fundamental FL privacy principles, e.g., the inherent flat networking approach in K8s can potentially allow FL clients to access other client or domain resources. The latter poses an open research problem and gap in the literature because serious privacy risks can arise from attackers gaining access to any client in the FL setup. To address this problem, this paper presents a networking approach via network isolation at the link layer level, and authentication and data packet encryption at the network layer level. The former allows to create secure resource sharing, and the latter is used to protect in-transit data. For this purpose, we use a K8s networking operator and a secure network protocol suite. The above combination facilitates on-demand link-layer connectivity, per-link data source authentication, and confidentiality between FL actors. We tested our approach on a network testbed composed of different geo-located nodes where FL clients are deployed. Our promising results showcase the feasibility of the solution for privacy preservation at the network level in K8s-based FL.
Microservices have become promising candidates for the deployment of network and vertical functions in the fifth generation of mobile networks. However, microservice platforms like Kubernetes use a flat networking approach towards the connectivity of virtualised workloads, which prevents the deployment of network functions on isolated network segments (for example, the components of an IP Telephony system or a content distribution network). This paper presents L2S-M, a solution that enables the connectivity of Kubernetes microservices over isolated link-layer virtual networks, regardless of the compute nodes where workloads are actually deployed. L2S-M uses software-defined networking (SDN) to fulfil this purpose. Furthermore, the L2S-M design is flexible to support the connectivity of Kubernetes workloads across different Kubernetes clusters. We validate the functional behaviour of our solution in a moderately complex Smart Campus scenario, where L2S-M is used to deploy a content distribution network, showing its potential for the deployment of network services in distributed and heterogeneous environments.
The revolution of Remotely Piloted Aircraft Systems (RPASs), both in the commercial and the research field, has accelerated the arrival of innovative and complex services to the civilian environment within non-segregated airspace. The extensive deployment of these services will still require solving relevant challenges in several topics, such as regulation, security, or diverse technical defiance. In particular, the services to be provided increasingly demand network resources and performance improvements. This scenario will be strongly exacerbated by the upcoming resources provided by the 5G/6G architectures, where Remotely Piloted Aircrafts (RPAs) will likely support multiple communication interfaces and will be able to establish multi-hop network connectivity with numerous devices leading to an unprecedented hyper-connected RPA environment. In addition, future RPASs will have to enhance the management of their connectivity capabilities to comply with the latest regulations, which demand an uninterrupted link for the Control and Non-Payload Communications (CNPC). This article presents a flexible Communication Infrastructure Manager (CIM) based on Software-Defined Networking (SDN) and virtualization technologies capable of handling the complexity inherent to this ecosystem and being adapted to different operation requirements to cope with all these communication challenges. Finally, the article shows several validation experiences to demonstrate the potential of the CIM versus the standard approach.