* Cellular services and security
Now that mobile network services have become extensions of the corporate network, what should you expect your cellular carrier to contribute to your network security framework?
Part of the equation has to do with the operator’s own network infrastructure. Last week, for example, I mentioned that a peek under the hood at the operator’s own network topology can help you determine how effective a particular carrier might be in providing wireless disaster-recovery service. Similarly, the connectivity setup in the backbone of your provider’s network can have security implications.
Some providers, for example, will set up a dedicated link between their backbone and your corporate network. This removes the public Internet from your mobile-access equation, bypassing much of the Internet’s unpredictability and susceptibility to infection.
In a similar spirit, some operators will offer a server-to-server encrypted VPN connection from their own data center to yours across the Internet – an alternative method to the above configuration.
The standard GSM and CDMA-based digital airlink technologies have encryption built into them. Encryption, as well as end-user device authentication, is embodied in the network operator’s base stations and often in user handset subscriber identity modules (SIM), sometimes called removable user identity modules (R-UIM) or, most recently, universal subscriber identity modules (USIM). What they are called usually depends on the network technology/airlink protocol at play.
If this level of security is important to you, check to see that your operator is actually offering the encryption/authentication as part of its service. If you are running your own VPN, you may not need encryption and authentication services from the mobile operator, too. However, you may wish for your operator to work with you to tune your VPN settings – such as the packet-size settings in Windows clients – so that users experience optimum performance.
Cingular Wireless, for one, says it will do this, as well as bring in a middleware partner – such as Broadbeam, NetMotion Wireless and Padcom – to supply a business customer with all-in-one end-to-end encryption, behind-the-firewall compression, performance optimization and session management.
Meanwhile, at the CTIA Wireless 2005 in New Orleans last week, Sprint introduced a secure remote-access service, including a secure client, called Extended Workplace. The service is intended for businesses wishing to extend their corporate VPNs across Sprint’s IXRTT network, as well as Sprint Wi-Fi hot spot and dial services.




