Cradlepoint laid out its 5G security access service edge (SASE) strategy for cellular and Enterprise hybrid WAN security that continues the Ericsson subsidiary’s ongoing integration of its recently acquired Ericom assets.

Cradlepoint CMO Todd Krautkremer explained in an email to SDxCentral that Ericom provides the cloud-based security services edge (SSE) capabilities to the 5G SASE platform. Cradlepoint’s integrated work comes from its NetCloud Exchange 5G SD-WAN and zero-trust products, with the new platform’s network management and unified policy construct coming from NetCloud.

The initial 5G SASE product will be the Cradlepoint Cellular Intelligence platform that uses cellular network data like signal strength and data plan usage for SD-WAN traffic steering.

[ Related: SDxCentral Special Edition: How to Reframe SD-WANs for the Future: ]

Krautkremer explained that competing SD-WAN implementations “do not provide any traffic steering or prioritization based on cellular intelligence.” As an example, he noted that with the Cradlepoint product “a police cruiser can actually Switch carriers en route to an accident by using cellular telemetry for real-time signal strength measurement.”

This will eventually also tap into 5G standalone (SA) network deployments to support Cradlepoint’s network slicing efforts to allow operators to offer prioritization and slice-based isolation. KrautKremer said this exceeds current 5G slicing standards that depend on cellular networks pushing down configurations directly to the user endpoint.

“Additionally, these standards also include functionality for the user endpoint requesting a slice,” Krautkremer added. “These open the cellular network up to denial-of-service attacks if the user endpoint is compromised in any form. [Cradlepoint] has filed some [intellectual property] defining an API-based approach for endpoint slice NFV managment and network orchestration (MANO) that allows for a more secure method for network slicing.”

Network slicing is the capability to dedicate specific spectrum channels in a 5G network to a specific customer or use case. However, concerns have been raised that network slicing could open up attack vectors to private 5G network deployments if not properly instantiated and maintained.

Rodrigo Brito, head of cybersecurity for Nokia’s Cloud and Network Services business, recently told SDxCentral that network slicing deployments have been slow to materialize, but operators remain concerned over opening up a potential security attack vector. This concern is heightened by the recent push toward further opening up network APIs to allow operators to better monetize their 5G network investments.

Krautkremer noted that Cradlepoint’s 5G SASE also builds on embedded 5G network security by adding a zero-trust model on top of 5G security and cloaking all IP addresses from the Internet; uses the SIM management functionality to see and react when Enterprise SIMs are being removed and replaced; and the Cellular Intelligence product to provide visibility and control into SIMs, data plans, cell tower connectivity and 5G cellular routers.

This work builds on recent comments from Cradlepoint Marketing VP Donna Johnson as part of Ericsson’s rebranding of its own security products. This included renaming Ericsson’s ZTEdge SSE product as NetCloud Threat Defense Cloud to bring it in line with the Cradlepoint operations.

Johnson said this “full SASE stack” work is to “create a SASE stack that is optimized for companies that are embracing 5G.” She noted this includes companies with fixed locations, mobile locations, IoT use cases and supporting people working at a specific Enterprise location, at home or contractors that are roaming between “private networks, private cellular networks, private Wi-Fi networks and public networks.”

“It’s important to have a solution that allows us to identify users as they move among these different types of connectivity services, as they connect across different types of carriers and still provide consistent policies for both Application reliability and security,” Johnson added.

Cradlepoint’s ongoing Ericom 5G SASE integration efforts

Cradlepoint is also offering SIM-based security that uses SIM management and GPS tracking to secure physical devices and detect unauthorized movement of those devices. Cradlepoint noted it wants to work with operators for tighter SIM-based security using SIM for authentication.

In addition, the company offers a way to use zero trust in the 5G SASE to replace VPNs. This reduces the lateral attack surface by making any device that connects to a Cradlepoint Router “immediately dark to the outside world and other sites.” The vendor is working toward offering this feature via the cloud.

Cradlepoint is also providing Ericom’s SSE products through the cloud, which will allow for management from Cradlepoint’s NetCloud single pane of glass. This includes Ericom’s secure web gateway (SWG), Cloud Access Security Broker, remote browser isolation (RBI) and data leak prevention (DLP).

These updates feed into an increasingly complex and lucrative space.

ABI Research recently highlighted the need for cloud security platforms to be adaptable to specific needs of 5G network operators.

“Numerous existing solutions in the traditional cybersecurity market can secure 5G networks, data and devices. The critical success factor is to ensure that these technologies are adapted to the new context and can work with the architectural requirements defined by 5G standards,” wrote Michela Menting, telco cybersecurity research director at ABI Research.

The analyst firm predicts the 5G security software and services market will hit $8.6 billion in sales by 2027.

Ericsson’s Cradlepoint boost continues

The ongoing Ericom integration also continues what has been a significant push by Ericsson to bolster its Cradlepoint operations.

Ericsson closed on its $1.1 billion purchase of Idaho-based Cradlepoint in late 2020. The move was targeted at boosting Ericsson’s presence in the Enterprise market.

Cradlepoint has since launched several new products that have grown its presence in that market. This includes the launch late last year of network-slicing ready SD-WAN and zero-trust network access products.

Ericsson CEO Börje Ekholm told investors during the vendor’s first-quarter earnings call that it was still in investment mode when it came to its Enterprise efforts.

The executive explained that Cradlepoint’s current subscription model results in deferred profits reported on a monthly basis, which leads to an initial “negative impact” on earnings. As that business grows it will continue to “generate a loss for accounting reasons,” but long term Ekholm said it has a “very attractive profitability profile.”