LAS VEGAS – T-Mobile US has launched several enterprise security options for its 5G-based network, including a SIM card-based secure access service edge (SASE) system powered by Versa Networks and a network-slice security platform designed to defend network slicing-based services from cyberattacks.

The SIM card-based service, called T-Mobile Secure Access Service Edge, is being positioned as a network management and zero-trust network access (ZTNA) platform. It’s designed to support enterprise customers in securely connecting employees, systems and endpoints to remote networks, corporate applications and company resources.

T-Mobile is working with Versa to create the T-SIMsecure platform that uses the International Mobile Subscriber Identity (IMSI) and International Mobile Equipment Identity (IMEI) specifications for clientless authentication. This results in devices connecting to T-Mobile's network being automatically authorized through the SIM card, including nontraditional network devices like IoT devices and routers that are often difficult to protect.

Devices that cannot accept a SIM card can be protected using a downloadable SASE device client that can secure connections regardless of network connectivity.

"This SASE offering for enterprise customers will allow them to enforce cloud-based security policies consistently and persistently to any of the T-Mobile devices anywhere on their network without the hassle of installing a device client," John Saw, EVP and CTO at T-Mobile US, said during a keynote speech at this week's MWC Las Vegas event.

The carrier explained that the hardware-based offering is superior to traditional software-based SASE that “only offers protection when client software is downloaded into devices and configured. This is a heavy administrative lift for IT departments and can potentially leave some devices vulnerable, such as IoT hardware and routers.”

The T-Mobile SASE platform also provides a Private Access service, which uses ZTNA for a VPN to provide secure, direct and least-privileged access to devices. There is also a Secure Internet Access service that includes web filtering using secure web gateway (SWG), a cloud access security broker (CASB) for software-as-a-service (SaaS) application protection and next-gen firewall IT network security.

The Versa partnership provides solid backing to the effort.

The vendor scored a top position in Forrester Research’s most recent ranking of zero-trust edge providers, alongside rivals Palo Alto Networks, Cato Networks and Fortinet.

Versa was praised for having a unified SASE offering and a large number of global points of presence (PoP) sites with granular control services throughout the WAN. However, it was dinged for an unrefined SASE roadmap and challenges in encouraging customers to use its security capabilities due to internal divisions between networking and security teams.

Gartner is not quite as high on Versa, listing the vendor as a “challenger” in its most recent ranking of single-vendor SASE providers.

5G network slicing security

T-Mobile is also targeting security services for the nascent 5G network slicing space.

The carrier’s T-Mobile Security Slice provides a way to securely separate individual network slices enabled through its 5G standalone (SA) network capabilities. The security platform allows those slices to be isolated and customized to an enterprise’s needs.

Network slicing is viewed as one of the key architectural features of a 5G SA deployment. It allows an operator to basically set up siloed virtual networks that act as independent, scalable networks and can support revenue-generating premium services.

Saw noted T-Mobile's implementation of Security Slice would provide customers with improved latency, faster network speeds and an increased layer of network security.

The new security offerings are scheduled to be available by year-end.