Four dominant radio access network (RAN) vendors passed the first round of a new security assessment program designed by the GSMA and 3GPP. Ericsson, Huawei, Nokia, and ZTE completed the first of many stages of appraisal aimed at ensuring the security of equipment makers’ product development and lifecycle processes.

The program, which is open to all network equipment vendors that support 3GPP defined functions, intends to confront and address concerns related to the security stature of RAN equipment on a global basis. 

However, it’s unclear how the Network Equipment Security Assurance Scheme (NESAS) might factor into network operators’ determinations or the extent to which the seal of industry approval could mitigate or challenge bans some countries have imposed on equipment from vendors.

Chinese Vendors Still Face Uphill Battle

Huawei and ZTE both applauded the development, but the Chinese vendors still face an uphill battle in reversing decisions that were based on a perceived security threat, largely due to their respective country of origin.

The U.S. government has mostly led the charge against Huawei and ZTE, effectively labeling the vendors as arms of the Chinese surveillance apparatus, but the companies and critics of those efforts claim politicians are unfairly blending national security and trade policies to blunt the rise of Chinese-backed technology. 

“Tying national security to trade policy makes for impossible security tradeoffs. Either this is a national security issue, in which case there are things we do and don’t do. Or this is a trade issue, in which case we negotiate on a variety of things. It cannot be both. It just doesn’t work,” Bruce Schneier, security technologist and researcher at Harvard Kennedy School, said during a panel earlier this year at the RSA Conference. 

While countries of origin, equipment, lifecycle management, assembly, shipping, and software programs are all genuine causes for alarm, the RAN industry is “deeply and irrevocably international in ways that make this impossible to solve,” he said. 

The U.S. government has taken steps against Huawei “for a very specific reason,” Katie Arrington, cyber information security officer at the U.S. Department of Defense, explained during the fiery debate at the event. 

Federal prosecutors earlier this year charged Huawei with acts of espionage and allegations of theft dating back to 2000. The widening battle has forced Huawei to abandon any near-term ambitions in the U.S. market. The United Kingdom government also last month reversed a previous decision and is now requiring all of Huawei’s equipment to be removed from its networks by 2027.

GSMA Plans More Security Tests

Meanwhile, the NESAS program is just getting underway and vendors will go another stage of review, including the submission of network equipment to be evaluated in a test laboratory, according to the GSMA. Security tests defined by 3GPP will further determine the security of each vendors’ lifecycle management processes and lead to a valuation report with detailed test results that can be made publicly available at each vendor’s discretion. 

“The GSMA recognizes the support and participation of Ericsson, Huawei, Nokia, and ZTE who have satisfied the scheme’s security requirements via an independent security audit and we congratulate them on achieving this important first step,” GSMA CTO Alex Sinclair said in a statement. 

“By committing to NESAS, vendors are helping network operators and other stakeholders make informed decisions about secure product development,” he added. “We look forward to others participating in the scheme, evidencing their commitment to good security practice by promoting a security-by-design culture within the industry.”

Samsung, a global RAN supplier, was noticeably absent from the initial wave of testing. A spokesperson for the company wasn’t immediately able to provide more information about its intent or plans to participate in the program. 

NESAS adheres to a series of 20 security requirements spanning development and product lifecycle processes, and a detailed assessment of network equipment security, according to the GSMA.