US 12,245,036 B1
Global secure SIM clientless SASE architecture for cellular devices
Kallol Banerjee, San Jose, CA (US); Jonathan Bosanac, Ennis, MT (US); and Milind Gunjan, Olathe, KS (US)
Assigned to Netskope, Inc., Santa Clara, CA (US)
Filed by Netskope, Inc., Santa Clara, CA (US)
Filed on Jul. 10, 2024, as Appl. No. 18/769,302.
Int. Cl. H04W 12/088 (2021.01); H04W 8/20 (2009.01); H04W 12/72 (2021.01)
CPC H04W 12/088 (2021.01) [H04W 8/20 (2013.01); H04W 12/72 (2021.01)] 20 Claims
OG exemplary drawing
 
1. A clientless security system for securing a plurality of cellular devices across a cellular network in a cloud-based environment, the clientless security system comprises:
a tenant of a plurality of tenants using a plurality of cellular networks, the tenant includes the plurality of cellular devices;
a plurality of tunnels between a cellular device of the plurality of cellular devices and the cellular network, the plurality of tunnels is operable to:
transmit traffic from the cellular device of the plurality of cellular devices at the cellular network; and
identify traffic associated with a plurality of network identifiers;
a traffic steering module to route traffic towards a gateway of a plurality of gateways in the cloud-based environment, wherein the traffic steering module is operable to:
provision a Subscriber Identity Module (SIM) with the plurality of network identifiers;
configure the SIM with a custom network identifier;
create a device-to-IP mapping;
distribute the device-to-IP mapping to the plurality of gateways in real-time; and
route traffic to the gateway of the plurality of gateways using the custom network identifier;
the plurality of gateways to apply a plurality of policies based on a device profile in the cloud-based environment, wherein the plurality of gateways is operable to:
receive traffic from the traffic steering module at the cellular network;
perform a reverse lookup for the cellular device of the plurality of cellular devices using a source IP address;
determine a device identity corresponding to traffic from the cellular device of the plurality of cellular devices;
apply the plurality of policies based on the device profile; and
forward traffic to a destination in the cloud-based environment; and
an alert generator to notify the tenant for a remediation in case of detection of violation of a policy of the plurality of policies.