Scalable Security and Migration-Aware SFC Provisioning in LEO Satellite Networks

2026-07-01Emerging Technologies

Emerging Technologies
AI summary

The authors study how to securely share computing functions on satellites in low Earth orbit that support multiple users (tenants) for future 6G networks. Since satellites have limited resources, users must share these functions, which risks security due to potential side-channel attacks between users. The authors create a mathematical model to place these functions in a way that minimizes security risks and the need to move functions around as satellites orbit. They also develop methods to solve this complex problem efficiently and show through simulations that their approach improves security and performance compared to previous methods.

Low Earth Orbit (LEO)6G ConnectivityVirtual Network Functions (VNFs)Side-channel riskService Function Chain (SFC)Mixed-Integer Linear Programming (MILP)VNF MigrationAlternating Direction Method of Multipliers (ADMM)Walker-Delta Satellite ConstellationCo-location risk
Authors
Mohammed Mahyoub, Wael Jaafar, Sami Muhaidat, Halim Yanikomeroglu
Abstract
Low Earth orbit (LEO) satellite constellations are emerging as a backbone for global 6G connectivity, where independent tenant slices share orbital infrastructure, each requiring an ordered chain of security virtual network functions (VNFs). Because onboard computation and networking are scarce, slices cannot be given dedicated VNFs. They must share instances on the same satellites, enlarging the attack surface and exposing tenants to cross-slice side-channel risk. This exposure shifts continually as visibility, orbital motion, and the inter-satellite topology change in time (epochs), making VNF migration a structural necessity that couples resource efficiency, service continuity, and security isolation into a single problem. We formulate this security- and migration-aware security function chain (SFC) placement as a multi-slice mixed-integer linear programming (MILP) whose core is a co-location risk model, grounded in ISO/NIST principles and supported by analytic bounds, in which we separate avoidable migrations from those forced by orbital motion. Because the joint program scales quadratically with the cross-slice co-location terms, we develop an alternating direction method of multipliers (ADMM)-inspired penalized per-slice best response decomposition that recasts the coupling as a linear per-slice penalty, yielding independent subproblems through sequential (S-ADMM) and parallel, collision-repaired (P-ADMM) schedules. Simulations over a Walker-Delta satellite constellation show that the proposed framework eliminates co-location risk, reduces SFC migrations, and sustains full delay compliance, while remaining feasible within the per-epoch budget for slice counts where the monolithic security-aware MILP is intractable.