LAS VEGAS – T-Mobile US threw its operator hat into the secure access service edge (SASE) space with a unique hardware-based service that signals what could be the first of many by the operator in expanding its reach into the enterprise market.
The T-Mobile Secure Access Service Edge is being positioned as a network management and zero-trust network access (ZTNA) platform. It’s designed to support enterprise customers in securely connecting employees, systems and endpoints to remote networks, corporate applications and company resources.
The product’s unique take on the established SASE space is the work T-Mobile US did with Versa to create the T-SIMsecure platform that uses the International Mobile Subscriber Identity (IMSI) and International Mobile Equipment Identity (IMEI) specifications for clientless authentication. This results in devices connecting to T-Mobile’s network being automatically authorized through the SIM card, including nontraditional network devices like IoT devices and routers that are often difficult to protect.
Mishka Dehgan, SVP for strategy, product and solutions engineering at T-Mobile’s Business Group, told SDxCentral at this week’s MWC Las Vegas event that this hardware-based approach is key for simplifying security for overworked enterprise IT teams.
“There's nothing new about SASE,” Dehgan said. “This is something that we had been working on, but we wanted to make sure we bring something that's differentiated. … The fact that IT administrators do not have to worry about the authentication and it's happening organically through the SIM, that's a differentiation point, which we know is resonating with customers.”
The platform was launched through a partnership with Versa, which has gravitas in the SASE space, but T-Mobile US is interested in bringing along other vendors.
“[Versa’s] the first SASE partner that we are going to market with,” Dehgan said, adding “we are going to be augmenting our SASE portfolio working with other partners. Versa is just the first.”
And with those partnerships, T-Mobile US thinks it can maintain its unique position in the market in offering something that traditional SASE vendors can’t provide.
“Security is really top of mind, so that's why you really see a proliferation of companies delivering SASE solutions,” Dehgan said. “But all of them are traditional SASE and they're all software based. We wanted to make sure that we work with partners that understand and aligned with our approach on making it hardware based and really bringing that differentiation.”
5G network slicing security
That differentiation is also a target for nascent network-slicing services.
The carrier this week also launched its T-Mobile Security Slice as a way to use SASE to securely separate individual network slices enabled through its 5G standalone (SA) network capabilities. The security platform allows those slices to be isolated and customized to an enterprise’s needs.
“It's a single security slice where all of our SASE traffic is gonna go through,” Dehgan said of the service.
This angle confronts ongoing concerns that network slicing could open up attack vectors to private 5G network deployments if not properly instantiated and maintained.
Deloitte during a presentation at last year’s RSA Conference, walked through research that showed the potential to breach a device running in one network slice to see if they could then work laterally into breaching a device running in an adjacent network slice.
Abdul Rahman, associate VP at Deloitte, explained that the thought process was that an attacker could look for vulnerabilities in low-level devices running in one slice, providing examples of home automation tools or gaming devices that users are typically slow to update. That attacker would then navigate up that network slice and look for other potential vulnerable devices running in nearby network slices to conduct a horizontal attack.
“Five minutes on Google and you can get default passwords on a lot of these vendor devices and can then basically run scripts through the infrastructure in grey spaces to be able to find and exploit what parts of this attack surface are actually misconfigured,” Rahman said.
Once breached, an attacker can run different attack probes to gain a virtual picture, or attack graph, of that network architecture. This will then allow them to hunt for other potential misconfigurations or weak points further up the stack or slice.
This attack vector concern is being further heightened by the recent push toward further opening up network APIs to allow operators to better monetize their 5G network investments.
“When we expose the API‘s and with our strategy of enabling our customers to provide APIs to allow them to monetize the network data and enable applications, we provide security controls that need to be in place so that those APIs are provided on a safe way,” Rodrigo Brito, head of cybersecurity for Nokia’s Cloud and Network Services business, told SDxCentral in an interview earlier this year.
Dehgan noted that enterprises can work with T-Mobile US to tackle the API angle by providing developers using the operator’s DevEdge program with a secure SIM card for access. That DevEdge program this week was expanded to developers across the country and to those using Android devices.
Comments