IoT Traffic Forwarding via SIM Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional approaches for forwarding traffic from Internet of Things (IoT) devices to the cloud are inefficient, as they often require user IDs, traditional network configurations, and complex software integrations, which are not feasible for diverse IoT devices operating outside corporate networks and lacking user identification.

Innovation Solution

A method utilizing a Subscriber Identity Module (SIM) card to authenticate and establish a secure tunnel to a cloud-based system, allowing traffic forwarding without user IDs, using Transport Layer Security (TLS), Secure Sockets Layer (SSL), or Datagram TLS (DTLS) over an Application-aware Networking (APN) network, enabling policy-based processing based on the SIM card's user and device type.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If conventional approaches (client connector applications, tunneling protocols, proxy configurations) are used for traffic forwarding, then traditional computing devices can forward traffic to the cloud, but IoT devices cannot be effectively supported due to lack of user IDs, mobility, and inability to execute client applications

Engineering Contradiction:
Improvedevice compatibilityVSAvoidsoftware integration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The SIM card serves as an intermediary authentication mechanism between IoT devices and the cloud-based system. Instead of requiring complex client applications or user IDs on the device, the SIM card's IMEI acts as a universal identifier that the cloud system can recognize and authenticate, enabling seamless traffic forwarding for diverse IoT devices without device-specific software integration

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The solution uses the SIM card's IMEI as a universal identifier that works across all IoT devices regardless of platform, operating system, or manufacturer. This single authentication mechanism replaces the need for device-specific client applications, user ID configurations, or platform-specific SDKs, providing universal compatibility across thousands of device variations

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If third-party software integration (SDK, library, code) is implemented in device code base to enable forwarding, then traffic forwarding can be achieved, but managing patches and versions for thousands of device variations becomes infeasible

Engineering Contradiction:
Improvetraffic forwarding reliabilityVSAvoiddeployment scalability
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The SIM card acts as a pre-configured intermediary that contains all necessary authentication credentials (IMEI) before the device is deployed. This eliminates the need for post-deployment software updates, patch management, or version control for thousands of device variations, as the authentication mechanism is already embedded in the SIM card

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The SIM card is pre-programmed with authentication credentials and configured to work with the cloud-based system before the IoT device is deployed. This preliminary configuration eliminates the need for ongoing software maintenance, updates, or version management, allowing scalable deployment across thousands of devices without requiring device-specific software integration

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If SIM card-based authentication and secure tunneling is implemented, then traffic forwarding can be achieved for all SIM-based devices without user IDs or client applications, but additional authentication and tunneling infrastructure is required

Engineering Contradiction:
Improvedevice coverageVSAvoidauthentication infrastructure
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The SIM card inherently provides its own identification through the IMEI, eliminating the need for separate user ID management, device registration processes, or client application installations. The device automatically presents its SIM card identity to the cloud system, which handles authentication and tunnel establishment, reducing the perceived complexity for device deployers

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11596027B2Mobile and IoT device forwarding to the cloud
Publication Date: 2023.02.28 ZSCALER INC
  • US11596027B2 patent drawing
  • US11596027B2 patent drawing
  • US11596027B2 patent drawing

AI summary

A method, implemented in a cloud-based system, includes, responsive to a client device having a Subscriber Identity Module (SIM) card therein connecting to a mobile network from a mobile network operator, receiving authentication of the client device based on the SIM card; receiving forwarded traffic from the client device; and processing the forwarded traffic according to policy, wherein the policy is determined based on one of a user of the client device and a type of the client device, each being determined based on the SIM card.