joanie_wexler
Writer

Is patching cellular gaps with Wi-Fi secure?

Opinion
Jan 28, 20113 mins

Carriers, vendors make progress but enterprises need convincing

The ambitious goals President Obama expressed for next-generation mobile broadband during his recent State of the Union address could get a shot in the arm if mobile operators use Wi-Fi to patch 3G/4G coverage holes and ensure that cellular-to-Wi-Fi network handovers are secure.

One popular option for beating the notorious spectrum capacity crunch is for mobile network operators to supplement their licensed spectrum with pockets of unlicensed Wi-Fi. That’s a leap for most carriers, who are accustomed to “owning” their network footprint (or at least licensing it from the federal government and controlling it).

RULING: FCC opens up ‘white spaces’ spectrum to mobile devices

Despite the lack of control carriers have over equal-access, unlicensed airwaves, they have grown friendlier toward the idea of using every available wireless tool in the arsenal to keep subscribers connected. And that includes transparently switching subscribers to the “best” network available (strongest signal, fastest, least expensive) without them being cognizant of the handover and having to fiddle with settings.

A number of Wi-Fi vendors, such as Motorola, Proxim and Ruckus Wireless, have broadened their portfolios with carrier-grade equipment for offload applications. And recently, Towerstream, a U.S. WiMAX last-mile service provider, announced it was getting into the wholesale Wi-Fi business. The company has piloted the offload service in New York City for the past year and said earlier this month that it will build more hot zones in Chicago, San Francisco and possibly elsewhere in 2011.

What has some networks managers worried is how security translates from one wireless technology platform to another. They’re concerned that if cellular users unknowingly move on and off Wi-Fi networks, they might be vulnerable during the transition and not even know it, given that in Wi-Fi networking the initial part of a client-to-AP authentication process is in the clear (unencrypted).

I chatted with Ruckus Wireless about this issue last fall. At that time, Steven Glapa, senior director of field marketing, indicated that the 802.1x security framework, paired with EAP-SIM wireless authentication protocols for GSM-based networks, would be the approach to take. The idea would be to integrate the back-end handshake destinations for Wi-Fi and 3G (or 4G) in the carrier NOC.

This process “requires two touches of [the user’s] finger the very first time a user connects to send phone configuration data, SSID and specification as to which authentication protocol your phone should use on that SSID.” After that, he said, your SSID would be promulgated across the carrier’s entire Wi-Fi footprint and would happen automatically.

The back-end integration will likely require some sort of gateway gizmo that would ship subscriber Wi-Fi data to the carrier’s back-end 3G/4G architecture. Anyone want to bet we see a series of such announcements in the coming months?

joanie_wexler
Writer

Joanie Wexler is an independent writer and editor who has spent 20+ years writing about computer networking technologies, their business potential, and implementation considerations. She serves clients at technology companies and industry publications writing educational materials on all aspects of IT.

More from this author