Ericsson, Microsoft and French multinational Thales have partnered with a trio of 5G telecommunication providers for a new platform that uses secure access service edge (SASE) (SASE)-embedded SIM cards to support secure remote provisioning of enterprise devices. The operators include T-Mobile US, Japan’s SoftBank and Telia Sweden.
The sextet is working through the Ericsson Virtual Cellular Network (EVCN) program, which is a new program designed to automate digital SIM (eSIM) profile management. This allows an enterprise to activate and manage eSIM-based device access.
The initial work targeted the use of this control over 5G-enabled devices running Microsoft’s Windows 11 operating system (OS). Once engaged, the platform can automatically connect to a 5G network and use zero-touch provisioning to establish enterprise policies.
A service trial was able to activate eSIM profile groups with local 5G connectivity provisioned according to an employee’s demographic and data usage. The devices were able to successfully connect to Telia’s network in Stockholm, T-Mobile’s network in New York and Seattle, and SoftBank’s network in Tokyo.
Ericsson was also able to automate eSIM management through a private 5G network set up at its D-15 facility in Santa Clara, California. This used Thales’ eSIM-as-a-service to automatically switch between private and public 5G networks as the device moved between service coverage.
Analyst firms have noted the advantage of using eSIM technology to help bolster a device’s security posture. IoT Analytics explained that the “technology incorporates embedded secure elements, providing advanced security features compared to traditional SIM cards. The secure element acts as a hardware root of trust for asymmetric encryption, ensuring secure end-to-end communication.”
T-Mobile US targets SASE angleT-Mobile specified that its work in the group will also allow it to provide its recently launched T-SIMsecure platform. This uses the international mobile subscriber identity (IMSI) and international mobile equipment identity (IMEI) specifications for clientless authentication, which allows devices connecting to T-Mobile’s network to be automatically authorized through the SIM card, including nontraditional network devices like IoT devices and routers that are often difficult to protect.
The T-SIMsecure platform, in turn, can support the SIM card-based T-Mobile SASE Edge, which is a network management and zero-trust network access (ZTNA) platform. It’s designed to use SASE technology to support enterprise customers in securely connecting employees, systems and endpoints to remote networks, corporate applications and company resources.
“This SASE offering for enterprise customers will allow them to enforce cloud-based security policies consistently and persistently to any of the T-Mobile devices anywhere on their network without the hassle of installing a device client,” John Saw, EVP and CTO at T-Mobile US, said during a keynote speech at last fall’s MWC Las Vegas event.
The carrier explained that the hardware-based offering is superior to traditional software-based SASE that “only offers protection when client software is downloaded into devices and configured. This is a heavy administrative lift for IT departments and can potentially leave some devices vulnerable, such as IoT hardware and routers.”
T-Mobile initially tapped Versa Networks to create the T-SIMsecure platform, though the carrier has stated plans to involve other SASE vendors.
“[Versa’s] the first SASE partner that we are going to market with,” Mishka Dehgan, SVP for strategy, product and solutions engineering at T-Mobile’s Business Group, told SDxCentral at the MWC Las Vegas event, adding “we are going to be augmenting our SASE portfolio working with other partners. Versa is just the first.”
Versa last week unveiled its own branded version of the product.
Comments