German telecom giant Deutsche Telekom and vendor partner Ericsson report that they have created a secure 5G network slicing that can tie directly into a private cloud, a move that attempts to bridge enterprise concerns over adopting edge use cases supported by evolving 5G technology standards.

Network slicing is viewed as one of the key architectural features of a 5G SA deployment. It allows an operator to basically set up siloed virtual networks that act as independent networks and can support revenue-generating premium services.

The self-titled proof-of-concept (PoC) was conducted on a 5G standalone (SA) testbed within DT’s lab using an enterprise smartphone connecting to a “predefined set of private cloud applications.” Ericsson provided the 5G core, radio access network (RAN) and end-to-end orchestration.

The test used mobile device management (MDM) and user equipment route selection policy (URSP) to test and validate an application-level configuration of a device. It also exposed TM Forum-based APIs to integrate third-party management interfaces that allows external management systems to incorporate slice ordering and management.

The companies said the validated service provides a single management interface for “automated configuration, provisioning and end-to-end orchestration of the enterprise slicing service order” and “is enabled without the need for any additional configuration by the user on their enterprise devices.”

“Enterprise employees can then access private cloud-based applications on their enterprise smartphone device via a secure network slice over the public network,” they stated. “The enterprise administrator can also make use of a variety of analytics services in the integrated solution to monitor and analyze the use of the customized network slice.”

The latest PoC builds on past work between DT and Ericsson, including a trial in mid-2021 that used Ericsson’s 5G SA core and a Samsung smartphone to support a mobile gaming service.

Network slicing benefits

Analyst firms have for years been touting the financial benefita of commercial network-slicing capabilities, especially tied to penetrating different market verticals.

ABI Research as far back as 2018 predicted 5G network slicing would generate “$66 billion in value for enterprise verticals including manufacturing, logistics and transportation by 2026.” The research firm more recently noted that operators need to pay “attention to 5G slice-as-a-service and other ‘value-add services,’ which are critical to monetization.”

Ericsson last year worked with Spain-based telecom operator Telefónica and Google to demonstrate an end-to-end automated network slicing concept in a 5G SA environment, including lifecycle support and radio resource portioning.

More recently, Samsung and Japanese operator KDDI generated multiple network slices using Samsung’s RAN intelligent controller (RIC) running on a live commercial 5G SA network in Tokyo. Those slices were able to meet service level agreements (SLAs) for low latency and throughput for each application tested.

“Network slicing will help us activate a wide range of services that require high performance and low latency, benefiting both consumers and businesses,” Toshikazu Yokai, managing executive officer and GM of KDDI’s Mobile Network Technical Development Division, noted in a statement on that trial.

Network slicing security challenges

However, as the DT and Ericsson PoC highlighted, security remains an ongoing concern.

Rodrigo Brito, head of cybersecurity for Nokia’s Cloud and Network Services business, told SDxCentral in a recent interview that network slicing deployments have been slow to materialize as operators remain concerned over opening up a potential security attack vector. This concern is heightened by the recent push toward further opening up network APIs to allow operators to better monetize their 5G network investments.

Deloitte during a presentation at last year’s RSA Conference walked through research that showed the potential to breach a device running in one network slice to see if they could then work laterally into breaching a device running in an adjacent network slice.

Abdul Rahman, associate VP at Deloitte, explained that the thought process was that an attacker could look for vulnerabilities in low-level devices running in one slice, providing examples of home automation tools or gaming devices that users are typically slow to update. That attacker would then navigate up that network slice and look for other potential vulnerable devices running in nearby network slices to conduct a horizontal attack.

“Five minutes on Google and you can get default passwords on a lot of these vendor devices and can then basically run scripts through the infrastructure in grey spaces to be able to find and exploit what parts of this attack surface are actually misconfigured,” Rahman said.

Once breached, an attacker can run different attack probes to gain a virtual picture, or attack graph, of that network architecture. This will then allow them to hunt for other potential misconfigurations or weak points further up the stack or slice.

Raham explained that it’s important to know the location of an organization’s “crown jewels” within network slices. These are labeled as the essential target a hacker would be looking to go after and that it’s important to know which hosts are within a hop or two of where those crown jewels are located.

“If there’s a host that has an exploit that’s connected to a crown jewel that might be an easier target, especially if they’re no defenses,” Raham said. “There may be a lot of rules associated with protecting crown jewels and you may have a lot of challenges going after this, but hosts that are connected to it might make for a softer attack surface and easier angle of approach.”