The Private Cellular market has largely struggled to make a dent against competing technologies. This blog was started because of my interest in Private Cellular and Private LTE has been around and available for a long time if you have access to spectrum. I was told this is one of the reasons I was invited to be a delegate to ask the right questions of OneLayer at Mobility Field Day 14.
That all changed in 2020 when the CBRS Band 48 of spectrum was release for public deployment of Private LTE networks.
Many people have said that Private Cellular was a solution looking for a problem, and to some degree that is how the technology has been rolled out. It’s an expensive solution looking for a problem that other technologies can tackle good enough.
Ultimately, there are places where Private Cellular absolutely makes a lot of sense and those industries are embracing it. That is where OneLayer comes into play.
What is OneLayer?
For several years, I’ve been dancing around the Private Cellular industry but never meeting with the OneLayer people. My original thoughts of what OneLayer does revolved around creating a single layer across networks.. because of the name. I was wrong. I thought it was similar to what Celona is doing with their Celona Edge solutions. That is not what OneLayer provides.

OneLayer says they close the visibility gap that is created because Cellular doesn’t care about the actual clients, unlike Wi-Fi. Cellular Security was built for Mobile Network Operators NOT for the requirements of Enterprises.

Using SIMs for authentication that doesn’t provide any view into the actual users behind the devices. The encryption and core pieces are similar to how Wi-Fi operates but the full end-to-end solution doesn’t fit the enterprise model.
Fingerprinting CPE and UE Devices
OneLayer makes Private Cellular more like other technologies that enterprises are use regularly, such as Wi-Fi. Transitioning Cellular for Enterprise usage, private networks need to provide views into the technology on the other side of the radio waves. Solving the Visibility and Observability Gap is where OneLayer fits.

Is OneLayer Just a Cellular NAC?
At Mobility Field Day 14, my fellow delegates were confused by the OneLayer presentation. Several delegates asked point blank if what was being demoed was just a NAC for Private 5G. The presenters said that it was more than just a Cellular NAC for Private 5G from a high level but didn’t really satisfy the question for the delegates.
There are some NAC like capabilities in the OneLayer product. When you want to Onboard clients, you use SIMs as the Authentication. SIMs can’t provide any visibility into the actual client because the technology doesn’t use MAC addresses.
Cellular lives in a world of IMEIs and IMSIs. With OneLayer, you can use Cellular technologies to build a solution that makes Cellular useful in the Enterprise.
OneLayer Onboarding, Segmentation, and Access
The onboarding process follows a lot like Wi-Fi.
- You start with a Staging APN which is similar to a Wi-Fi SSID, for onboarding clients until they get their configuration.
- OneLayer then checks the Security Posture of the device and verifies where it should connect. This involves verifying that it should connect to a certain core media gateway (MEC), or drop off box. This is like a VLAN in enterprise world. This provides segementation between services connected to the same radio just like different SSIDs or 802.1X can do in Wi-Fi.
- Once the security posture has been determined, a OneLayer profile is assigned just like 802.1X can do with a client. The SIM card is assigned a new APN that attaches it to the appropriate segment of the network like a VLAN.
- Then the network tells the client to Re-Attach to the cellular network using the new APN. All traffic is then routed through the new Media Gateway (MEC) or drop off box.

To do this manually can be time consuming. OneLayer reduces down this process into minutes and can integrate with lots of 3rd party technologies stacks. You can automate the process as a device moves around or as needed.

You can create policies and segment and allow or deny based on these policies for Palo Alto and other Firewalls; you can integrate into MDMs like Microsoft Intune; you can tie into private cellular systems like Cradlepoint Netcloud and Fortinet; and you can even tie directly into the Private and Public Cellular cores like HPE Athonet, Druid, Verizon, and AT&T.

OneLayer gives you a full stack control over your whole enterprise Private Cellular network through these integrations. You can automate how your cellular devices join your enterprise network or the carrier networks and what resources are available to those device.
Zero Trust.. More Than a Cellular NAC
This is all VERY NAC like and where my fellow delegates got stuck. So how is OneLayer more than a NAC?
This is where things get a little more difficult to distinguish OneLayer verse a Cellular NAC. Their sale pitch is all about how Private 5G is providing a better Zero Trust architecture than other technologies.

Since I first learned about Private Cellular, I was just finishing up a Masters degree in Cyber Security. Zero Trust was all the rage that I was still trying to grasp my head around. Private 5G has the ability to provide a better Zero Trust infrastructure than Wi-Fi because of how the technology is foundationally created.
Remember how Cellular technology does not care about the clients? This opens a world where traditional enterprise technologies have done the opposite.

Carriers live in a Zero Trust world. EVERYTHING their customers do has to be authenticated and access verified.
Just because you connect to Verizon with a SIM card doesn’t mean you’re automatically allowed on the network. The Cellular Core has mechanisms for billing and access. If you don’t pay your bill, your service is cut off.
There is no collision domain in Cellular either. You are not on the same Layer 2 network as all the other devices. There is no ability to attack a neighbor client on the same network over the air unless you do some downgrade to 2G and 3G that can be disabled in clients.
An improperly deployed Private Cellular network is just as insecure as an other network, but the pieces of Zero Trust are inherent in the technology. Unless you attach a SIM card to IMEI of a device, someone could remove the physical SIM and place it in another device without any controls. OneLayer provides a layer to handle these pieces at an enterprise level with automation.
5G Slicing is an additional layer to this Zero Trust model. Large organizations can purchase a slice from the carriers that can then be routed accordingly to your network. OneLayer can provide insights into that traffic as well and do Zero Trust against those devices.
With OneLayer, you can get insights and alerts to when devices get out of alignment with policies. You’ll get alerts if that SIM card is moved, but even better because you can easily lock the SIM card to IMEI through automation.
If you are building a Private Cellular network for your enterprise, I would definitely give OneLayer a hard consideration. OneLayer brings any cellular network and makes it Zero Trust Enterprise ready.
I recommend you go and watch the videos on Tech Field Day’s website for Mobility Field Day 14.

