Edge use cases need a 5G and beyond user plane

ericsson
Emerging virtual and hybrid private 5G solutions are enabling communication service providers (CSPs) to address a large number of new consumer and enterprise edge use cases. Each of these edge use cases will require a specific network deployment model and edge user plane connectivity. That’s why we’ve designed our 5G edge user plane to tackle five distinct key capabilities: support of flexible network deployments, 3GPP dual-mode support, integrated Gi LAN services, integrated probing with edge analytics and edge exposure enablement. Let’s dive into this blog post to learn how the powerful 5G edge user plane is unlocking new 5G edge use cases.

How technological innovation creates value and benefits society has always interested me, influencing my work as a mobile network technologist and sales professional. Since mobile data was introduced in late 90s, both mobile network technology and mobile consumer use cases have evolved enormously. Indeed, a rapid increase in connectivity speed and the introduction of smartphones have pushed the market to adopt mobile web and video and create thousands of new applications. However, sometimes ‘killer use cases’ require both business case and application ecosystem maturity. One example is video conferencing, one of the key services 3G was designed for but was only introduced when the over-the-top (OTT) vendors disrupted the content provider market and popularized social media. Creation of mobile technology has indeed its own innovation cycles and research feeds and therefore can't depend on market pull, but you can draw the conclusion that the time to value greatly benefits when the broad business and technology ecosystem in the value chain collaborate and co-create solutions.

Precisely, what’s really exciting about 5G is that it coincides with the maturity of other two disruptive technology enablers for end applications: artificial intelligence (AI) and cloud edge computing. It also comes at a moment when there’s both an urgent need and huge financial support to digitalize society and industry. In fact, more than ever, we are witnessing a close collaboration between technology and business ecosystems. Over the past few years, there have been a large number of public-private consortiums to feed service requirements into 5G standards, explore and validate the value of 5G technology. For example, just to name few, the 5G alliance for connected Industries and automation (5G-ACIA) or European 5G infrastructure Public Private Partnership (PPP) projects. For years, 3GPP standards have been preparing to define advanced 5G connectivity solutions for edge computing and vertical digitalization use cases. In addition, all sorts of consumer and enterprise edge applications are being developed at the same pace in many areas such advanced video processing, AI analytics, immersive gaming, smart grid applications, automated guided vehicles (AGVs) controls or industry automation.

The edge ecosystem is particularly complex and involves different players. One key pillar is the wireless connectivity service CSPs offer. 5G-ACIA introduced the concept of virtual private and hybrid private 5G solutions, two emerging solutions that CSPs are exploring to complement their private 5G network offerings. Such solutions allow CSPs to leverage their existing public networks and offer new services in an agile and cost-effective manner using new 5G capabilities such as network slicing. In order to address edge use cases, virtual and hybrid private 5G solutions need to bring the user plane connectivity to the edge by deploying 5G edge user plane functions.
The 5G edge user plane supports flexible network deployments        
One key learning from industry experimentation with 5G is that each use case brings a unique combination of connectivity requirements, in terms of end-to-end performance (uplink and downlink latency, jitter, packet loss and throughput), data privacy and security, robustness, wide vs local area coverage and mobility.

Latency and security requirements drive the selection of the edge location, which can be the enterprise premise, CSP access or regional data center or even the extended public edge such as content delivery networks (CDN) content provider or a hyper cloud provider’s (HCP) edge data center. For example, a mobile gaming application can be located in the CSP regional data center or HCP edge, whereas video processing and AI for a factory automation application is located on the factory premise.  Also edge distribution can be accounted by CSP for those use cases which produce significant amount of data such as fixed wireless access (FWA) to optimize backhaul costs.

Ericsson has a vast experience supporting and driving the ecosystem to realize time critical communication use cases at scale and has conducted detailed latency analysis for different type of deployments.  The RAN deployment needs to be carefully planned according to the specific use case performance characteristics. Some use cases can be achieved with existing macro RAN environment -4G or non-standalone 5G-, with macro RAN standalone 5G with or without dedicated quality of service (QoS) profiles or even may require network slicing to partition macro RAN. In contrast, some other use cases will need dedicated RAN deployments. In addition, most use cases will benefit from a dedicated edge user plane function, as it provides a higher level of performance and robustness.

In summary, the concrete edge use cases to be offered and CSP’s own solution preferences drive the type of network solution and deployment, which can be a private 5G network, a virtual or a hybrid 5G private network using existing macro or dedicated RAN, with or without network slicing.

The edge 5G user plane function should allow for such deployment flexibility and enable the different edge use cases characteristics. Ericsson Local Packet Gateway (LPG) addresses this by:

Supporting any access technology, radio deployment model and RAN vendor
Seamlessly integrating with Ericsson’s existing dual-mode 5G Core. which is prepared for slicing, efficient routing to edge (also called edge breakout) and advanced QOS and many other 5G edge features described in more detail in next section.
Supporting a fast time to service, deployment simplicity and a very low footprint enabling deployment at scale in any type of edge location, up to on enterprise premises. See our previous LPG 5G edge user plane: key requirements for success for details.
Providing a high level of robustness and failure resilience by means of a cloud native user plane application designed for high availability and fault resilience, support of geo-redundancy and support of 3GPP control plane and user plane split (CUPS) interface which can be deployed in full mesh with multiple control planes. User plane can also be deployed as a dedicated function within a slice to secure further characteristics and isolation or as a shared function for various slices.


5G edge user plane should enable transition from 4G to more sophisticated 5G connectivity
Most of CSPs are embracing edge opportunities. They are viewing the opportunities as an evolution of their existing offerings rather than a revolution, meaning existing 4G enterprise use cases will still need to be supported for some time as the ecosystem matures to support time-critical communications type of use cases. This means 5G edge user plane should be dual-mode and support such a wide breadth of technology.

5G edge user plane should support both 3GPP compliant serving/packet gateway user function (S/PGW-U) and user plane function (UPF) and evolve with advanced UPF features for time-critical communications, such as more stringent end to end QoS and transmission robustness for ultra-reliable low latency communications (URLLC) or Ethernet connectivity for advanced edge industrial use cases. It should also support 5G peak rates and do not degrade use cases performance characteristics.   It should also support dynamic edge routing solutions which are efficient, deployable by multipurpose terminals and mobility proof such as dynamic network slice selection which is preferrable to UPF as uplink classifier as starting solution until standardization evolves.

5G edge user plane should work in conjunction with the CSP’s dual-mode core system, which supports dynamic slicing orchestration, dynamic slice selection, ultra-reliable low latency communications and advanced 5G edge connectivity features such as different service continuity and user plane re-anchoring modes depending on mobility and application resilience needs. Ericsson’s dual-mode 5G Core with Local Packet Gateway provides such advanced 5G connectivity in a pre-verified manner. In fact, the Ericsson Local Packet Gateway Cloud Native Function (CNF) is based on the same software as the Ericsson Packet Core Gateway (PCG), the market leading cloud-native user plane, which is deployed in 5G live networks today.

Such deployment flexibility in edge user plane allows CSP to offer distinct use cases. For example, CSPs can offer mobile gaming service by deploying a cloud virtual reality (VR) gaming center application in their regional data centers. Connectivity with guaranteed low latency QoS can be provided by a dedicated 5G network slice with the dedicated Ericsson Local Packet Gateway, deployed close to the gaming application and connected to the CSP’s existing central core network. The mobile gaming application can use a portable device such as VR glasses or use a multi-purpose smartphone or tablet that supports dynamic slice selection. CSP can reuse their existing public network and macro 5G RAN. As another example, CSP can offer 5G edge connectivity to factories or logistic centers for augmented reality (AR) quality inspection. The AR application is deployed on the factory premise and needs an ultra-reliable and low-latency QoS connection to process in real time all the factory images. This is provided by a dedicated Ericsson Local Packet Gateway with ultra-reliable low latency QoS and redundant configuration being deployed on premises.

Edge use cases will require user plane services beyond 3GPP
There is a set of non-standardized user plane functions deployed in today’s networks (also called GI/N6 LAN functions) for mobile broadband service that would be also relevant for edge use cases.  These functions can be categorized as:

Traffic acceleration and optimization of access resources e.g., transport layer optimizers or advanced video traffic shapers
Network services e.g., carrier grade NAT devices or external load balancers
Service aware traffic monitoring and enforcements needed to realize customized CSP charging data plans or comply with some country regulatory such as content filters
Network security functions protecting CSP infrastructure and UEs of security attacks such as subscriber firewalls or distributed denial (DDoS) mitigation systems, and
Service chain policers and forwarders to chain and offload these GI/N6 LAN functions. Those can be integrated with operator policy framework to compose and program a unique data pipeline which addresses the specific connectivity needs of a given subscriber and application in the context of a certain use case

The current GI/N6 LAN market is very fragmented and addressed by many different vendor specific user plane functions. These functions are deployed as separate appliances or virtualized functions, each with their management system, policy integration and cloud orchestration system which significantly increases CSP’s total cost of ownership (TCO) when deploying and managing them. As CSPs start their edge journey they will need to bring some of these GI/N6 functions to the edge. A very simple and cost-efficient strategy to consolidate these functions in one single edge user plane function. This approach is being adopted by Ericsson Local Packet Gateway: it integrates these functions, including advanced integrated Packet Core Firewall, together with the UPF/S/PGW-U functions. This dramatically reduces the TCO and provides a single hop to the end application, which reduces further the latency. Ericsson Local Packet Gateway also allows to compose and tune the set user plane functions applied to a given traffic in one configuration click, which allows to customize the connectivity for each edge use case. 

Another consideration is that these GI/N6 functions were designed for legacy mobile broadband. This means they will need to evolve to support 5G peak user throughput rates and new 5G segment requirements, e.g., traffic optimizations should focus on optimizing the throughput of uplink transmissions and reducing the overall jitter and latency. Service aware charging models will evolve as 5G gets monetized, security for edge enterprise connectivity will keep evolving as well.  Technological innovation in this space is a must for any edge user plane vendor and should be holistic considering the entire ecosystem and end-to-end solution behavior. As one example, edge user plane can leverage 3GPP exposure interfaces for application detection, use collaborative solutions with content providers or RAN to optimize traffic delivery or even adapt traffic optimizations to new end to end rate adaptation mechanisms such as low latency low loss scalable throughput (L4S). Ericsson, as an end-to-end network provider and key contributor to 5G standardization, is working actively in this space.

Edge connectivity needs to be monitored and assured
CSPs need to monitor, troubleshoot, and assure the edge user plane connectivity. In many cases the CSP organizations dealing with enterprises services have their own analytic and management systems. Those systems need to evolve to provide visibility of the 5G encrypted communication, up to on enterprise premise and without compromising 5G security and provide advanced insights to meet the stringent service level agreements of edge use cases.  Example of user plane data feeds are traffic packet and patterns statistics, key performance indicators at transport level or service quality of experience estimates per application, area of interest, slice and subscriber type. CSP analytic use cases will also evolve, meaning network assurance and service experience management use cases will increasingly adopt AI/ML models with distinct and very demanding UP data sets running in parallel.

External probing solutions were not designed for these requirements. The cost of evolving and deploying such solutions to thousands of edges is unaffordable. Ericsson Local Packet Gateway addresses this challenge by supporting integrated dual-mode probing capabilities which includes rich, granular data with pre-processed data and advanced data collection profiles avoiding the need of deploying external taps, packet broker and probes at edge. Software probes are a unique Ericsson dual mode 5G Core feature – a feature that’s very popular with our customers for public network and enterprise solutions.

CSP will also introduce network data analytics function (NWDAF) function to enable 5G analytics for further 5G automation, new exposure APIs for verticals and data efficiency. An NWDAF can collect edge user plane and public network data to provide real time analytics which can be consumed by the network functions or by the end edge application to improve further the edge connectivity. Example of those analytics are user mobility, network congestion, quality of service, service experience or abnormal user behavior. Ideally, the NWDAF should be distributed at the edge and deployed co-located to the edge user plane for data efficiency, security and lower actuation latency.

Ericsson NWDAF  supports such distributed and co-located deployment and analytics and can collect pre-standard data from the Local Packet Gateway data until 3GPP rel-18 specifies UPF event exposure. 

Edge exposure for advanced edge connectivity
Exposure through APIs on the edge is becoming increasingly important for CSPs to enable new services, increase their relevance in the 5G ecosystem and become more attractive partners for hyperscale cloud providers, application ecosystems and other players.

Edge applications will be able to consume network capabilities and data to provide advanced services and innovate. Data extracted from edge user plane function will be of high value. For example, to determine the exact UE sessions being anchored by a given edge user plane, the actual monitored QoS, etc.  Such exposure capabilities in edge user plane allows application to adapt the content delivery or reconfigure dynamically the connectivity, e.g., change dynamically the negotiated QoS or influence edge routing.  As mentioned previously, NWDAF user plane analytics can be also exposed for advanced edge use cases.

Ericsson is already working with our customers to create new edge use cases using Ericsson Local Packet Gateway and Edge Exposure Server. Stay tuned!

Summary:
In this blog post we’ve explained the different considerations that need to be taken into account when selecting the 5G edge user plane, and how it enables flexible virtual private and hybrid 4G private solution deployments and address the user experience idiosyncrasy of myriads of edge use cases. The 5G edge user plane has to be small, cost efficient, easy to deploy but still extremely powerful and advanced in terms of dual connectivity and added value features.

Ericsson Local Packet Gateway is designed with all these capabilities in mind and integrates seamlessly with existing CSP dual-mode 5G Core, delivering edge use cases was never that easy.

Spotlight

Lyme Computer Systems

LYME COMPUTER SYSTEMS is a full-service computer products reseller with a focus on networking, networking security and interconnectivity. Although our primary market is the U.S. Government, we also address the needs of state and local governments, government contractors, corporations, and academic institutions. We hold two GSA Federal Supply Schedules, giving government customers open market or GSA Schedule procurement options.

OTHER ARTICLES
Wireless, 5G

Can SD-WAN Help Businesses in Boosting ROI?

Article | May 18, 2023

We are surrounded by acronyms and buzzwords in technology. SD-WAN is one that is often used in the industry nowadays. Organizations embrace digital transformation to stay up with market developments, consumer needs, and competitiveness. Traditional network designs weren't meant to manage digital transformation workloads and complexity. Business-critical services are commonly spread over numerous clouds, compromising network performance, particularly at branch sites. Smart network operations teams opt for SD-WAN. SD-WAN reduces overhead and improves network performance. Routing and hardware expenses are saved through SD-WAN solutions while allowing multi-cloud access. SD-WAN also reduces overhead and supports new digital apps and services. This new technology streamlines WAN administration and operation and brings corporate advantages. Business Challenges that SD-WAN Addresses There has been a dramatic increase in the pressure on the network as a result of digitalization. Businesses must now rely on a stable and secure network, which conventional router-based network topologies are incapable of providing. An SD-WAN solution assists businesses in addressing use cases in order to expedite digital transformation efforts, lower cybersecurity risks, and increase revenue. Eases connectivity with far-flung factories and offices. Effectively deploys new sites and minimizes network equipment sprawl. Enhances the speed of file transfer and backups to disaster recovery facilities. Helps in moving applications to the cloud and protecting cloud app. data using Secure Access Service Edge (SASE). Safeguards IoT devices using a zero-trust network Helps in complying with the cybersecurity framework of the National Institute of Standards and Technology (NIST). Ways SD-WAN Can Help Businesses Boost their Bottom Line Boosts Security Digital transformation is a double-edged sword. It can increase consumer satisfaction and market reach, but can pose security threats. According to the U.S. State of Cybercrime study, 41% of respondents stated more cybersecurity occurrences in 2017. The good news is that many SD-WAN solutions provide built-in security. Most SD-WAN systems only offer basic firewall and VPN functionalities, requiring IT teams to add security to elastic and dynamic SD-WAN connections after the fact. SD-WAN solutions with NGFW, IPS, encryption, AV, and sandboxing can avoid data loss, downtime, regulatory violations, and legal liability. Enables Cloud Usage Cloud services are rapidly being used by businesses. The great news is that SD-WAN enables direct cloud access at the remote branch, removing backhauling traffic – which routes all cloud and branch office traffic through the data center – allowing workers to directly access cloud applications irrespective of location without burdening the core network with additional traffic to manage and secure. Furthermore, SD-WAN enhances cloud application performance by prioritizing vital business apps and allowing branches to interact directly with the Internet. Reduces Costs As businesses deploy a growing number of cloud-based services, the volume of data traveling across a WAN rises dramatically, driving up operational expenses. SD-WAN, thankfully, can minimize this cost by utilizing low-cost local Internet connectivity, offering direct cloud access, and lowering traffic via the backbone WAN. According to an IDC poll (prediction), over a quarter of survey respondents anticipate SD-WAN cost reductions of up to 39%, with the other two-thirds anticipating more modest savings of 5–19%. Improves performance Data transfer over a network isn't created equal. Fortunately, SD-WAN can be set up to prioritize business-critical traffic and real-time services such as Voice over Internet Protocol (VoIP) and then successfully guide it over the most efficient path. IT teams can help decrease packet loss and latency concerns by supporting important applications over dependable, high-performance connections, increasing employee productivity and morale. This is business-impacting performance. Closing Note Indeed, SD-WAN evolved and flourished in the data center over the first few years of development. However, the time has arrived to take it seriously as a tool for managing your wide area network. There are currently several vendors on the market, as well as several mature solutions to choose from. More significantly, the business cases for SD-WAN are expanding on a daily basis.

Read More
5G

What's New In 5G - June 2021

Article | May 25, 2022

The next-generation of wireless technologies – known as 5G – is here. Not only is it expected to offer network speeds that are up to 100 times faster than 4G LTE and reduce latency to nearly zero, it will allow networks to handle 100 times the number of connected devices, revolutionizing business and consumer connectivity and enabling the “Internet of Things.” Leading policymakers – federal regulators and legislators – are making it a top priority to ensure that the wireless industry has the tools it needs to maintain U.S. leadership in commercial 5G deployments. This blog provides monthly updates on FCC actions and Congressional efforts to win the race to 5G.

Read More
5G

Cisco SD-WAN – the easiest way to connect private links to the cloud from your data center or even branches

Article | September 28, 2023

Applications and workloads have been moving to the cloud for some time. This transition has been putting a lot of pressure on IT organizations to support the trend by extending their networks to support cloud connectivity. Cisco SD-WAN enables your hybrid connectivity to the cloud We at Cisco have innovated on multiple fronts to help our customers with this transition by providing a deep level of integration with many of the leading cloud service providers (CSPs), including Amazon Web Services (AWS), Microsoft Azure, and Google Cloud. Here, we highlight one key aspect of this innovation that allows private cloud links to be available as part of the SD-WAN network, enabling hybrid connectivity to the cloud and multicloud. Now our customers can benefit from all the rich features that our Cisco SD-WAN solution offers including application-aware routing, intent-based path selection, and security policy enforcement. Private direct cloud connectivity to CSPs such as AWS Direct Cloud Connect, Google Cloud Interconnect, and Azure ExpressRoute are becoming popular lately, as they provide customers with optimal connectivity similar to what MPLS did in the past, but in a more agile and on-demand fashion. The only problem is those services are normally acquired separately and customers must determine how to manage them as part of a larger WAN solution including configuration, monitoring, and so on. The on-demand nature of these circuits provides customers with major savings, but also turns automation into a key requirement for management. Enter Cisco SD-WAN release 20.6 Beginning with Cisco SD-WAN release 20.6, a Cisco SD-WAN customer may use Cloud OnRamp for Mutlicloud to automate and simplify cloud connectivity across private and public transports. What is great is this task, that used to require hours and days to setup, now only takes minutes as outlined by the following integration documents for AWS, Azure and Google Cloud respectively: Configure AWS Direct Connect as a Transport with SD-WAN in a Click Configure Azure Express Route as Transport with SD-WAN in a Click Configure Google Cloud Interconnect as a Transport with Cisco SD-WAN in a Click Once a customer implements such connectivity, they will have the ability to steer any type of traffic through it with a customizable and flexible SD-WAN policy. This solution also allows customers to eliminate some limitations imposed on them by the CSPs, such as restricting the number of prefixes advertised via BGP over private links, thus providing better scalability and control. For customers who already use Cisco SD-WAN Cloud Interconnect at middle-mile POPs, such as with Equinix or Megaport, rolling out this solution as a test can be extremely simple given the automation discussed above. The best way to find out how easy this solution is, is to try it.

Read More
Data Center Networking

Enhancing Network Resilience in the Healthcare Sector to Prevent Downtime and Unusable Uptime

Article | July 5, 2023

Your patients have grown to trust your expertise and recommendations in matters regarding their healthcare. As the sector transitions into a more digital playing field, uninterrupted network connectivity is more than just a bonus; it’s a necessity. While there are many different challenges to completely integrating your practice into the digital world, internet outages are the costliest. Downtime can be caused by various factors, which can compromise patient safety, the faith your team instills in you, and your practice’s reputation and revenue. However, investing in the means to maintain a resilient network lets you maximize your network uptime to optimize resources. We'll look at four different strategies and their benefits for your infrastructure so you can focus on what you do best: providing healthcare excellence to your patients. Strengthening Network Infrastructure The traditional way of doing things may be great for your remedies and techniques. Still, with a growing number of patients and their contextually relevant demands, your network needs to be able to accommodate many different booking requests, increase user activity on your server, and store sensitive patient information. High-speed internet connections enhance your network performance and let you, your team, and your patients make the most of your uninterrupted uptime. Fiber-optic networks, when combined with load balancing and proper segmentation, can diffuse and direct network traffic efficiency and prevent congestion, which prevents downtime due to overload. Implementing Network Monitoring and Management Tools Much like your patients visit your practice to ensure everything is all right with the current state of their health, your network must also receive the same treatment. Identifying and pre-emptively resolving potential issues and vulnerabilities will prevent much more destructive or expensive problems from occurring. Use real-time tools to monitor your bandwidth usage and gain visibility of potential bottlenecks. Tools that offer risk monitoring deliver alerts about critical events that pose a threat to your business continuity. Your IT team will be better equipped to troubleshoot issues promptly and optimize performance. Conducting Regular Network Assessments and Audits Once you have the proper monitoring tools to manage your network topology better, proactive troubleshooting is a great way to spot-check whether your current solution is working as it should. A network audit is much like proactive troubleshooting; you are looking to see if anything could harm the overall system and catch it before it can develop. When auditing a network, the primary focus should be security measures. If patient and confidential data is not secure, the smooth operations of your business are the least of your worries. When conducting an audit, consulting with a network service provider will help identify issues with your protocols, data encryption, and firewall configuration. Establishing Redundancy and Disaster Recovery Plans Backing up private and confidential data is crucial to ensuring that sensitive information is not lost or exposed. Minimizing network downtime can often be achieved by having backup systems that will keep running in the event of an attack or outage. For example, a dedicated Cloud Access Network, power supplies, and switches will go a long way. When creating an internet contingency plan, outline steps and protocols with your team that you will take in the event of a complete failure, including things such as brand reputation management, customer service, and data loss prevention. Looking Forward As the lines between in-person and digital are blurred, navigating the complexities of implementing a robust network is paramount to your business. Strengthening your infrastructure, integrating redundant systems, and conducting regular audits and assessments with the proper monitoring and management tools will help you maximize uptime usage and minimize network downtime. Although overwhelming, working with a reputable network service provider can help you embrace your network topology to remain competitive.

Read More

Spotlight

Lyme Computer Systems

LYME COMPUTER SYSTEMS is a full-service computer products reseller with a focus on networking, networking security and interconnectivity. Although our primary market is the U.S. Government, we also address the needs of state and local governments, government contractors, corporations, and academic institutions. We hold two GSA Federal Supply Schedules, giving government customers open market or GSA Schedule procurement options.

Related News

Network Security

Ampliphae, HPE Athonet and Arqit deliver Quantum-Safe Private 5G using Symmetric Key Agreement

PR Newswire | January 19, 2024

Arqit Quantum Inc, a leader in quantum-safe encryption, and Ampliphae Ltd (Ampliphae), a leader in network cyber security solutions, have today announced successful completion of a project that will deliver enhanced quantum-safe security for Private 5G networks. The Security Enhanced Virtualised Networking for 5G (SEViN-5G) project, funded by Innovate UK, the UK Government’s innovation agency, leveraged Ampliphae’s network security analytics technology and Arqit’s Symmetric Key Agreement Platform to deliver a quantum-secure Private 5G testbed that can protect against both current and future cyber threats. Athonet, a Hewlett Packard Enterprise acquisition, provided the Radio Access Network (RAN) equipment for the project with a cloud core hosted on AWS. Private enterprise networks based on 5G cellular technology are accelerating digital transformation across industries including manufacturing, healthcare, defence and smart cities. Private 5G gives enterprises access to high-speed, massively scalable, and ultra-reliable wireless connectivity, allowing them to implement innovative IoT and mobile solutions that enhance productivity, drive automation and improve customer engagement. The security of these networks will be paramount as they will support safety-critical infrastructure and carry highly sensitive data. But like any new technology, 5G comes with potential new threats and security risks including the threat from quantum computing. The project finished in December 2023 and customer engagement has already begun. David Williams, Arqit Founder, Chairman and CEO said: “Enterprises want to deploy Private 5G networks with complete confidence that they will be safe from both current and future cyber threats including from quantum computers. Working alongside Ampliphae, we have shown that a quantum-safe Private 5G network is deliverable using Arqit’s unique encryption technology.” Trevor Graham, Ampliphae CEO said: “Private 5G can be hosted partly or completely in the Cloud, giving enterprises the opportunity to rapidly set up their own cellular networks customised to support their operations. With Ampliphae and Arqit they can now be certain that those Private 5G networks are monitored and secure against eavesdropping and disruption.” Nanda Menon, Senior Advisor Hewlett Packard Enterprise said: “In an era where security is paramount, the completion of the SEViN-5G project is a significant milestone. The delivery of a quantum-secure Private 5G testbed, achieved where Athonet have combined the Athonet core with CableFree radios, underscores the commitment to innovation and reinforces the confidence enterprises can have in deploying networks that are both cutting-edge and secure from both present and future threats.” About Arqit Arqit Quantum Inc. (Nasdaq: ARQQ, ARQQW) (Arqit) supplies a unique encryption Platform as a Service which makes the communications links of any networked device, cloud machine or data at rest secure against both current and future forms of attack on encryption – even from a quantum computer. Compliant with NSA standards, Arqit’s Symmetric Key Agreement Platform delivers a lightweight software agent that allows devices to create encryption keys locally in partnership with any number of other devices. The keys are computationally secure and operate over zero trust networks. It can create limitless volumes of keys with any group size and refresh rate and can regulate the secure entrance and exit of a device in a group. The agent is lightweight and will thus run on the smallest of end point devices. The Product sits within a growing portfolio of granted patents. It also works in a standards compliant manner which does not oblige customers to make a disruptive rip and replace of their technology. Recognised for groundbreaking innovation at the Institution of Engineering and Technology awards in 2023, Arqit has also won the Innovation in Cyber Award at the National Cyber Awards and Cyber Security Software Company of the Year Award at the Cyber Security Awards. Arqit is ISO 27001 Standard certified. www.arqit.uk About Ampliphae Ampliphae’s distributed network analytics technology provides insight into how networks are used to support enterprise operations at every level. A graduate of the prestigious LORCA cyber accelerator in London, and the AWS European Defence Accelerator, Ampliphae’s technology is already used by enterprises across multiple verticals to discover, analyse and secure the network traffic that supports their key applications and business processes. Ampliphae’s Encryption Intelligence product operates at enterprise scale to discover devices and applications that use cryptography, analysing their encryption capabilities to detect risks, including assets that are vulnerable to future quantum computer attack. Using Encryption Intelligence, the organisation can gather effective operational intelligence about their encryption landscape, both within and outside the organisation, and build an effective mitigation program to address current and future vulnerabilities.

Read More

Network Security

Cato Networks Introduces World's First SASE-based XDR

PR Newswire | January 25, 2024

Cato Networks, the leader in SASE, announced the expansion of the Cato SASE Cloud platform into threat detection and incident response with Cato XDR, the world's first SASE-based, extended detection and response (XDR) solution. Available immediately, Cato XDR utilizes the functional and operational capabilities of the Cato SASE Cloud to overcome the protracted deployment times, limited data quality, and inadequate investigation and response experience too often associated with legacy XDR solutions. Cato also introduced Cato EPP, the first SASE-managed endpoint protection platform (EPP/EDR). Together, Cato XDR and Cato EPP mark the first expansion beyond the original SASE scope pioneered by Cato in 2016 and defined by industry analysts in 2019. SASE's security capabilities encompassed threat prevention and data protection in a common, easy-to-manage, and easy-to-adopt global platform. With today's announcement, Cato is expanding SASE into threat detection, incident response, and endpoint protection without compromising on the architectural elegance captured by the original SASE definition. "Cato SASE continues to be the antidote to security complexity," says Shlomo Kramer, CEO and co-founder of Cato Networks. "Today, we extend our one-of-a-kind SASE platform beyond threat prevention and into threat detection and response. Only Cato and our simple, automated, and elegant platform can streamline security this way." An early adopter of Cato XDR is Redner's Markets, an employee-owned supermarket chain headquartered in Reading, Pennsylvania, with 75 locations. Redner's Markets' vice president of IT and Infrastructure, Nick Hidalgo, said, "The Cato platform gave us better visibility, saved time on incident response, resolved application issues, and improved network performance ten-fold." (Read more about Redner's Markets and Cato in this blog. "The convergence of XDR and EPP into SASE is not just another product; it's a game-changer for the industry," said Art Nichols, CTO of Windstream Enterprise, a Cato partner. "The innovative integration of these capabilities brings together advanced threat detection, response capabilities, and endpoint security within a unified, cloud-native architecture—revolutionizing the way enterprises protect their networks and data against increasingly sophisticated cyber threats." (Read more about what Cato partners are saying about today's news in this blog.) Platform vs. Product: The Difference Matters Cato XDR takes full advantage of the enormous benefits of the Cato SASE Cloud platform, the first platform built from the ground up to enable enterprises to connect, secure, and manage sites, users, and cloud resources anywhere in the world. Unlike disjointed point solutions and security appliances, Cato capabilities are instantly on, always available at scale, and fully converged, giving IT teams a single, shared context worldwide to understand their networks, prevent threats, and resolve problems. As an autonomous platform, Cato SASE Cloud sustains its evolution, resiliency, optimal performance, and security posture, saving enterprises the operational overhead of maintaining enterprise infrastructure. Enterprises simply subscribe to Cato to meet their business needs. Cato's cloud-native model revolutionized security and networking operations when it was introduced in 2016, a fact validated three years later in 2019 when the Cato approach was formally recognized by the industry as SASE. Breach Times Still Too Long; Limitations of Legacy XDR Cato is again revolutionizing cybersecurity with the first SASE platform to expand into threat detection, empowering security teams to become smarter and remediate incidents faster. The flood of security alerts triggered by network sensors, such as firewalls and IPS, complicates threat identification. In 2023, enterprises required 204 days on average to identify breaches.1 XDR tools help security analysts close this gap by ingesting, correlating, and contextualizing threat intelligence information with the data from native and third-party sensors. However, legacy XDR tools suffer from numerous problems relating to data quality. Sensor deployment extends the time-to-value as IT must not only install the sensors but also develop a baseline of specific organizational activity for accurate assessments. Data quality is also compromised when importing and normalizing third-party sensor data, complicating threat identification and incident response. Security analysts waste time sorting through incident stories to identify the ones most critical for immediate remediation. Once determined, incident remediation is often hampered by missing information, requiring analysts to master and switch between disparate tools. No wonder in 2023, average breach containment required more than two months.1 Cato XDR and Cato EPP Expands the Meaning of SASE Cato XDR addresses legacy XDR's limitations. Instantly activated globally, Cato XDR provides enterprises with immediate insights into threats on their networks. Incident detection is accurate due to Cato's many native sensors – NGFW, advanced threat prevention (IPS, NGAM, and DNS Security), SWG, CASB, DLP, ZTNA, RBI, and now EPP/EDR. Powered by Bitdefender's world-leading malware prevention technology, Cato EPP protects endpoints from attack – in the Cato way. Endpoint threat and user data are stored in the same converged Cato data lake as the rest of the customer's network data, simplifying cross-domain event correlation. The result is incredibly high-quality data that improves the incident identification and remediation process. Cato AI uses the data to accurately identify and rank incidents, empowering analysts to focus critical resources on an organization's most important remediation cases. Cato AI is battle-tested and proven across years of threat hunting and remediation handling by Cato MDR service agents. Remediation times reduce as detected incident stories contain the relevant information for in-depth investigation. Cato's tools sit in the same console as the native engines, enabling security analysts to view everything in one place -- the current security policy and the reviewed story. Finally, incident reporting is simplified with generative AI. Purpose-built for investigations, this natural language engine provides human-readable explanations of incident stories. Analysts save time sharing incident information with other teams and reporting to their managers.

Read More

Network Infrastructure

DISH Wireless Awarded $50 Million NTIA Grant for 5G Open RAN Integration and Deployment Center

PR Newswire | January 16, 2024

DISH Wireless, a subsidiary of EchoStar, was awarded a historic $50 million grant from the U.S. Department of Commerce's National Telecommunications and Information Administration (NTIA) to establish the Open RAN Center for Integration & Deployment (ORCID). ORCID will allow participants to test and validate their hardware and software solutions (RU, DU and CU) against a complete commercial-grade Open RAN network deployed by DISH. "The Open RAN Center for Integration and Deployment (ORCID) will serve a critical role in strengthening the global Open RAN ecosystem and building the next generation of wireless networks," said Charlie Ergen, co-founder and chairman, EchoStar. "By leveraging DISH's experience deploying the world's first standalone Open RAN 5G network, ORCID will be uniquely positioned to test and evaluate Open RAN interoperability, performance and security from domestic and international vendors. We appreciate NTIA's recognition of DISH and ORCID's role in driving Open RAN innovation and the Administration's ongoing commitment to U.S. leadership in wireless connectivity." To date, this grant represents NTIA's largest award under the Public Wireless Supply Chain Innovation Fund (Innovation Fund). ORCID will be housed in DISH's secure Cheyenne, Wyoming campus and will be supported by consortium partners Fujitsu, Mavenir and VMware by Broadcom and technology partners Analog Devices, ARM, Cisco, Dell Technologies, Intel, JMA Wireless, NVIDIA, Qualcomm and Samsung. NTIA Administrator Alan Davidson and Innovation Fund Director Amanda Toman will join EchoStar Co-Founder and Chairman Charlie Ergen, EchoStar CEO Hamid Akhavan, EVP and Chief Network Officer Marc Rouanne and other stakeholders to announce the grant and tour a DISH 5G Open RAN cell site later today in Las Vegas. During this event, DISH will outline ORCID's unique advantages, including that it will leverage DISH's experience as the only operator in the United States to commercially deploy a standalone Open RAN 5G network. DISH and its industry partners have validated Open RAN technology at scale across the country; today DISH's network covers over 246 million Americans nationwide. At ORCID, participants will be able to test and evaluate individual or multiple network elements to ensure Open RAN interoperability, performance and security, and contribute to the development, deployment and adoption of open and interoperable standards-based radio access networks. ORCID's "living laboratory" will drive the Open RAN ecosystem — from lab testing to commercial deployment. Below are highlights of ORCID: ORCID will combine both lab and field testing and evaluation activities. ORCID will be able to test elements brought by any qualified vendor against DISH's live, complete and commercial-grade Open RAN stack. ORCID will use DISH's spectrum holdings, a combination of low-, mid- and high-band frequencies, enabling field testing and evaluation. ORCID will evaluate Open RAN elements through mixing and matching with those of other vendors, rather than validating a single vendor's stack. DISH's experience in a multi-vendor environment will give ORCID unique insights about the integration of Open RAN into brownfield networks. ORCID's multi-tenant lab and field testing will occur in DISH's secure Cheyenne, Wyoming facility, which is already compliant with stringent security protocols in light of its satellite functions. About DISH Wireless DISH Wireless, a subsidiary of EchoStar Corporation (NASDAQ: SATS), is changing the way the world communicates with the Boost Wireless Network. In 2020, the company became a nationwide U.S. wireless carrier through the acquisition of Boost Mobile. The company continues to innovate in wireless, building the nation's first virtualized, Open RAN 5G broadband network, and is inclusive of the Boost Infinite, Boost Mobile and Gen Mobile wireless brands.

Read More

Network Security

Ampliphae, HPE Athonet and Arqit deliver Quantum-Safe Private 5G using Symmetric Key Agreement

PR Newswire | January 19, 2024

Arqit Quantum Inc, a leader in quantum-safe encryption, and Ampliphae Ltd (Ampliphae), a leader in network cyber security solutions, have today announced successful completion of a project that will deliver enhanced quantum-safe security for Private 5G networks. The Security Enhanced Virtualised Networking for 5G (SEViN-5G) project, funded by Innovate UK, the UK Government’s innovation agency, leveraged Ampliphae’s network security analytics technology and Arqit’s Symmetric Key Agreement Platform to deliver a quantum-secure Private 5G testbed that can protect against both current and future cyber threats. Athonet, a Hewlett Packard Enterprise acquisition, provided the Radio Access Network (RAN) equipment for the project with a cloud core hosted on AWS. Private enterprise networks based on 5G cellular technology are accelerating digital transformation across industries including manufacturing, healthcare, defence and smart cities. Private 5G gives enterprises access to high-speed, massively scalable, and ultra-reliable wireless connectivity, allowing them to implement innovative IoT and mobile solutions that enhance productivity, drive automation and improve customer engagement. The security of these networks will be paramount as they will support safety-critical infrastructure and carry highly sensitive data. But like any new technology, 5G comes with potential new threats and security risks including the threat from quantum computing. The project finished in December 2023 and customer engagement has already begun. David Williams, Arqit Founder, Chairman and CEO said: “Enterprises want to deploy Private 5G networks with complete confidence that they will be safe from both current and future cyber threats including from quantum computers. Working alongside Ampliphae, we have shown that a quantum-safe Private 5G network is deliverable using Arqit’s unique encryption technology.” Trevor Graham, Ampliphae CEO said: “Private 5G can be hosted partly or completely in the Cloud, giving enterprises the opportunity to rapidly set up their own cellular networks customised to support their operations. With Ampliphae and Arqit they can now be certain that those Private 5G networks are monitored and secure against eavesdropping and disruption.” Nanda Menon, Senior Advisor Hewlett Packard Enterprise said: “In an era where security is paramount, the completion of the SEViN-5G project is a significant milestone. The delivery of a quantum-secure Private 5G testbed, achieved where Athonet have combined the Athonet core with CableFree radios, underscores the commitment to innovation and reinforces the confidence enterprises can have in deploying networks that are both cutting-edge and secure from both present and future threats.” About Arqit Arqit Quantum Inc. (Nasdaq: ARQQ, ARQQW) (Arqit) supplies a unique encryption Platform as a Service which makes the communications links of any networked device, cloud machine or data at rest secure against both current and future forms of attack on encryption – even from a quantum computer. Compliant with NSA standards, Arqit’s Symmetric Key Agreement Platform delivers a lightweight software agent that allows devices to create encryption keys locally in partnership with any number of other devices. The keys are computationally secure and operate over zero trust networks. It can create limitless volumes of keys with any group size and refresh rate and can regulate the secure entrance and exit of a device in a group. The agent is lightweight and will thus run on the smallest of end point devices. The Product sits within a growing portfolio of granted patents. It also works in a standards compliant manner which does not oblige customers to make a disruptive rip and replace of their technology. Recognised for groundbreaking innovation at the Institution of Engineering and Technology awards in 2023, Arqit has also won the Innovation in Cyber Award at the National Cyber Awards and Cyber Security Software Company of the Year Award at the Cyber Security Awards. Arqit is ISO 27001 Standard certified. www.arqit.uk About Ampliphae Ampliphae’s distributed network analytics technology provides insight into how networks are used to support enterprise operations at every level. A graduate of the prestigious LORCA cyber accelerator in London, and the AWS European Defence Accelerator, Ampliphae’s technology is already used by enterprises across multiple verticals to discover, analyse and secure the network traffic that supports their key applications and business processes. Ampliphae’s Encryption Intelligence product operates at enterprise scale to discover devices and applications that use cryptography, analysing their encryption capabilities to detect risks, including assets that are vulnerable to future quantum computer attack. Using Encryption Intelligence, the organisation can gather effective operational intelligence about their encryption landscape, both within and outside the organisation, and build an effective mitigation program to address current and future vulnerabilities.

Read More

Network Security

Cato Networks Introduces World's First SASE-based XDR

PR Newswire | January 25, 2024

Cato Networks, the leader in SASE, announced the expansion of the Cato SASE Cloud platform into threat detection and incident response with Cato XDR, the world's first SASE-based, extended detection and response (XDR) solution. Available immediately, Cato XDR utilizes the functional and operational capabilities of the Cato SASE Cloud to overcome the protracted deployment times, limited data quality, and inadequate investigation and response experience too often associated with legacy XDR solutions. Cato also introduced Cato EPP, the first SASE-managed endpoint protection platform (EPP/EDR). Together, Cato XDR and Cato EPP mark the first expansion beyond the original SASE scope pioneered by Cato in 2016 and defined by industry analysts in 2019. SASE's security capabilities encompassed threat prevention and data protection in a common, easy-to-manage, and easy-to-adopt global platform. With today's announcement, Cato is expanding SASE into threat detection, incident response, and endpoint protection without compromising on the architectural elegance captured by the original SASE definition. "Cato SASE continues to be the antidote to security complexity," says Shlomo Kramer, CEO and co-founder of Cato Networks. "Today, we extend our one-of-a-kind SASE platform beyond threat prevention and into threat detection and response. Only Cato and our simple, automated, and elegant platform can streamline security this way." An early adopter of Cato XDR is Redner's Markets, an employee-owned supermarket chain headquartered in Reading, Pennsylvania, with 75 locations. Redner's Markets' vice president of IT and Infrastructure, Nick Hidalgo, said, "The Cato platform gave us better visibility, saved time on incident response, resolved application issues, and improved network performance ten-fold." (Read more about Redner's Markets and Cato in this blog. "The convergence of XDR and EPP into SASE is not just another product; it's a game-changer for the industry," said Art Nichols, CTO of Windstream Enterprise, a Cato partner. "The innovative integration of these capabilities brings together advanced threat detection, response capabilities, and endpoint security within a unified, cloud-native architecture—revolutionizing the way enterprises protect their networks and data against increasingly sophisticated cyber threats." (Read more about what Cato partners are saying about today's news in this blog.) Platform vs. Product: The Difference Matters Cato XDR takes full advantage of the enormous benefits of the Cato SASE Cloud platform, the first platform built from the ground up to enable enterprises to connect, secure, and manage sites, users, and cloud resources anywhere in the world. Unlike disjointed point solutions and security appliances, Cato capabilities are instantly on, always available at scale, and fully converged, giving IT teams a single, shared context worldwide to understand their networks, prevent threats, and resolve problems. As an autonomous platform, Cato SASE Cloud sustains its evolution, resiliency, optimal performance, and security posture, saving enterprises the operational overhead of maintaining enterprise infrastructure. Enterprises simply subscribe to Cato to meet their business needs. Cato's cloud-native model revolutionized security and networking operations when it was introduced in 2016, a fact validated three years later in 2019 when the Cato approach was formally recognized by the industry as SASE. Breach Times Still Too Long; Limitations of Legacy XDR Cato is again revolutionizing cybersecurity with the first SASE platform to expand into threat detection, empowering security teams to become smarter and remediate incidents faster. The flood of security alerts triggered by network sensors, such as firewalls and IPS, complicates threat identification. In 2023, enterprises required 204 days on average to identify breaches.1 XDR tools help security analysts close this gap by ingesting, correlating, and contextualizing threat intelligence information with the data from native and third-party sensors. However, legacy XDR tools suffer from numerous problems relating to data quality. Sensor deployment extends the time-to-value as IT must not only install the sensors but also develop a baseline of specific organizational activity for accurate assessments. Data quality is also compromised when importing and normalizing third-party sensor data, complicating threat identification and incident response. Security analysts waste time sorting through incident stories to identify the ones most critical for immediate remediation. Once determined, incident remediation is often hampered by missing information, requiring analysts to master and switch between disparate tools. No wonder in 2023, average breach containment required more than two months.1 Cato XDR and Cato EPP Expands the Meaning of SASE Cato XDR addresses legacy XDR's limitations. Instantly activated globally, Cato XDR provides enterprises with immediate insights into threats on their networks. Incident detection is accurate due to Cato's many native sensors – NGFW, advanced threat prevention (IPS, NGAM, and DNS Security), SWG, CASB, DLP, ZTNA, RBI, and now EPP/EDR. Powered by Bitdefender's world-leading malware prevention technology, Cato EPP protects endpoints from attack – in the Cato way. Endpoint threat and user data are stored in the same converged Cato data lake as the rest of the customer's network data, simplifying cross-domain event correlation. The result is incredibly high-quality data that improves the incident identification and remediation process. Cato AI uses the data to accurately identify and rank incidents, empowering analysts to focus critical resources on an organization's most important remediation cases. Cato AI is battle-tested and proven across years of threat hunting and remediation handling by Cato MDR service agents. Remediation times reduce as detected incident stories contain the relevant information for in-depth investigation. Cato's tools sit in the same console as the native engines, enabling security analysts to view everything in one place -- the current security policy and the reviewed story. Finally, incident reporting is simplified with generative AI. Purpose-built for investigations, this natural language engine provides human-readable explanations of incident stories. Analysts save time sharing incident information with other teams and reporting to their managers.

Read More

Network Infrastructure

DISH Wireless Awarded $50 Million NTIA Grant for 5G Open RAN Integration and Deployment Center

PR Newswire | January 16, 2024

DISH Wireless, a subsidiary of EchoStar, was awarded a historic $50 million grant from the U.S. Department of Commerce's National Telecommunications and Information Administration (NTIA) to establish the Open RAN Center for Integration & Deployment (ORCID). ORCID will allow participants to test and validate their hardware and software solutions (RU, DU and CU) against a complete commercial-grade Open RAN network deployed by DISH. "The Open RAN Center for Integration and Deployment (ORCID) will serve a critical role in strengthening the global Open RAN ecosystem and building the next generation of wireless networks," said Charlie Ergen, co-founder and chairman, EchoStar. "By leveraging DISH's experience deploying the world's first standalone Open RAN 5G network, ORCID will be uniquely positioned to test and evaluate Open RAN interoperability, performance and security from domestic and international vendors. We appreciate NTIA's recognition of DISH and ORCID's role in driving Open RAN innovation and the Administration's ongoing commitment to U.S. leadership in wireless connectivity." To date, this grant represents NTIA's largest award under the Public Wireless Supply Chain Innovation Fund (Innovation Fund). ORCID will be housed in DISH's secure Cheyenne, Wyoming campus and will be supported by consortium partners Fujitsu, Mavenir and VMware by Broadcom and technology partners Analog Devices, ARM, Cisco, Dell Technologies, Intel, JMA Wireless, NVIDIA, Qualcomm and Samsung. NTIA Administrator Alan Davidson and Innovation Fund Director Amanda Toman will join EchoStar Co-Founder and Chairman Charlie Ergen, EchoStar CEO Hamid Akhavan, EVP and Chief Network Officer Marc Rouanne and other stakeholders to announce the grant and tour a DISH 5G Open RAN cell site later today in Las Vegas. During this event, DISH will outline ORCID's unique advantages, including that it will leverage DISH's experience as the only operator in the United States to commercially deploy a standalone Open RAN 5G network. DISH and its industry partners have validated Open RAN technology at scale across the country; today DISH's network covers over 246 million Americans nationwide. At ORCID, participants will be able to test and evaluate individual or multiple network elements to ensure Open RAN interoperability, performance and security, and contribute to the development, deployment and adoption of open and interoperable standards-based radio access networks. ORCID's "living laboratory" will drive the Open RAN ecosystem — from lab testing to commercial deployment. Below are highlights of ORCID: ORCID will combine both lab and field testing and evaluation activities. ORCID will be able to test elements brought by any qualified vendor against DISH's live, complete and commercial-grade Open RAN stack. ORCID will use DISH's spectrum holdings, a combination of low-, mid- and high-band frequencies, enabling field testing and evaluation. ORCID will evaluate Open RAN elements through mixing and matching with those of other vendors, rather than validating a single vendor's stack. DISH's experience in a multi-vendor environment will give ORCID unique insights about the integration of Open RAN into brownfield networks. ORCID's multi-tenant lab and field testing will occur in DISH's secure Cheyenne, Wyoming facility, which is already compliant with stringent security protocols in light of its satellite functions. About DISH Wireless DISH Wireless, a subsidiary of EchoStar Corporation (NASDAQ: SATS), is changing the way the world communicates with the Boost Wireless Network. In 2020, the company became a nationwide U.S. wireless carrier through the acquisition of Boost Mobile. The company continues to innovate in wireless, building the nation's first virtualized, Open RAN 5G broadband network, and is inclusive of the Boost Infinite, Boost Mobile and Gen Mobile wireless brands.

Read More

Events