Zero-Trust SIM Connectivity via Cloud Edge Gateways

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need for efficient zero-trust connectivity solutions for Subscriber Identity Module (SIM) enabled equipment to securely forward traffic from devices to cloud-based systems, avoiding backhauling through corporate data centers and ensuring secure access to cloud services, especially in the context of growing remote work and IoT devices.

Innovation Solution

The implementation of cloud-based 5G security network architectures that integrate cloud-based security services within Multiaccess Edge Compute (MEC) systems, utilizing SIM cards, eSIM, or iSIM for intelligent steering and secure edge computing, enabling secure traffic forwarding and access control through cloud edge gateways and enforcement nodes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traffic is backhauled through corporate data centers, then centralized security control is maintained, but network latency increases and productivity decreases

Engineering Contradiction:
Improvesecurity controlVSAvoidnetwork efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the network architecture by deploying cloud-based security services at the edge (MEC nodes) rather than centralizing all security control in a remote data center. This allows traffic to be processed locally at the edge for faster response while maintaining centralized policy control through the cloud, resolving the contradiction between security control and network efficiency.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces cloud-based security services as an intermediary between edge devices and the corporate data center. These services act as a mediator that provides security functions at the edge while maintaining connectivity to the cloud for policy enforcement, eliminating the need for traffic backhauling while preserving security control.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If all traffic is forwarded to cloud-based system, then security coverage is improved, but device complexity and network overhead increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidnetwork configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service by allowing devices to automatically establish connections to cloud-based security services through standardized protocols. The cloud system automatically provisions security services, enforces policies, and manages traffic routing without requiring complex local configuration, thereby improving security coverage while minimizing device complexity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent creates a universal cloud-based security service platform that can serve multiple device types and network scenarios through a single standardized interface. This multi-functional approach allows diverse devices to access security services uniformly, reducing the complexity of configuring different security solutions for different devices.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If SIM cards are pre-provisioned with network routing, then connectivity is simplified, but adaptability to different networks is reduced

Engineering Contradiction:
Improveconnectivity setupVSAvoidnetwork flexibility
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamics by allowing SIM cards to be pre-provisioned with default routing to cloud-based security services, while maintaining the ability to dynamically adapt to different networks and scenarios. The cloud-based system can modify routing decisions based on real-time conditions, device location, and network availability, thereby preserving adaptability despite pre-provisioning.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS20240267783A1Zero-trust connectivity for Subscriber Identity Module (SIM) enabled equipment
Publication Date: 2024.08.08 ZSCALER INC
  • US20240267783A1 patent drawing
  • US20240267783A1 patent drawing
  • US20240267783A1 patent drawing

AI summary

Systems and methods for providing zero-trust connectivity for Subscriber Identity Module (SIM) enabled user equipment include responsive to a device having a SIM card equipped therein connecting to a cellular network, intercepting traffic associated with the device traversing the cellular network; forwarding the traffic through a cloud-based system; and processing the traffic from the device according to policy enforced by the cloud-based system.