IP Library Granted Patent US 12,507,060
Granted Patent B2
US 12,507,060 · App. 18/474,819 · Granted Dec 23, 2025

Identity-based policy enforcement for SIM devices

Inventors: Matthew Silverlock (Brooklyn, NY); Christian Ehrig (Munich, DE); Oliver Zi-gang Yu (Austin, TX); Nicholas Alexander Wondra (Savoy, IL); Catarina Pires Mota (Lisbon, PT)
Assignee: CLOUDFLARE, INC.
H04W8/26H04W8/183H04W12/08H04W12/72
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,507,060
App. No.
18/474,819
Granted
Dec 23, 2025
Kind
B2
Abstract

Traffic is received at a distributed cloud computing network. The traffic originates from a computing device using a mobile data connection. The traffic is associated with an identifier that identifies a SIM of the computing device. Using the SIM identifier, an identity for identity-based policy enforcement at the distributed cloud computing network is determined. The identity is uniquely associated with the SIM identifier. An identity-based policy that is applicable for the received traffic for the determined identity is determined. The identity-based policy is enforced.

Claims (92)

1 . A method, comprising:

receiving a domain name system (DNS) query at a distributed cloud computing network, wherein the DNS query originates from a computing device using a mobile data connection, wherein the DNS query is associated with an identifier of a subscriber identification module (SIM) of the computing device;

determining, using the SIM identifier, an identity for identity-based policy enforcement at the distributed cloud computing network;

determining a DNS policy that is applicable for the determined identity and DNS query;

enforcing the DNS policy to determine whether the DNS query is allowed to be resolved for the determined identity;

receiving, at the distributed cloud computing network, a request to access a private application, wherein the request to access the private application originates from the computing device using the mobile data connection, wherein the request to access the private application is associated with the SIM identifier of the computing device;

determining an access policy that is applicable for the determined identity and private application;

enforcing the access policy to determine whether the determined identity is allowed to access the private application;

receiving first IP traffic at the distributed cloud computing network that has a first IP destination, the first IP traffic originating from the computing device using the mobile data connection, wherein the first IP traffic is associated with the first SIM identifier of the computing device;

determining a first network policy that is applicable for the determined identity and first IP destination;

enforcing the first network policy to determine whether the first IP traffic is allowed to be transmitted to the first IP destination for the determined identity;

responsive to determining that the first IP traffic is not allowed to be transmitted to the first IP destination for the determined identity, blocking the first IP traffic from being transmitted to the first IP destination;

receiving second IP traffic at the distributed cloud computing network that has a second IP destination, the second IP traffic originating from the computing device using the mobile data connection, wherein the second IP traffic is associated with the first SIM identifier of the computing device;

determining a second network policy that is applicable for the determined identity and second IP destination;

enforcing the second network policy to determine whether the second IP traffic is allowed to be transmitted to the second IP destination for the determined identity;

responsive to determining that the second IP traffic is allowed to be transmitted to the second IP destination for the determined identity, causing the second IP traffic to be transmitted to the second IP destination;

receiving HTTP traffic at the distributed cloud computing network, the HTTP traffic originating from the computing device using the mobile data connection, wherein the HTTP traffic is associated with the SIM identifier of the computing device;

determining an HTTP policy that is applicable for the determined identity and HTTP traffic; and

enforcing the HTTP policy to determine whether HTTP traffic is allowed to be transmitted to its destination for the determined identity.

2 . The method of claim 1 , further comprising:

responsive to determining that the DNS query is allowed to be resolved, resolving the DNS query, and transmitting a DNS response to the computing device.

3 . The method of claim 1 , further comprising:

responsive to determining that the determined identity is not allowed to access the private application, blocking the requested access.

4 . The method of claim 1 , further comprising:

responsive to determining that the determined identity is allowed to access the private application, causing the request to access the private application to be transmitted to the private application.

5 . The method of claim 1 , further comprising:

responsive to determining that the HTTP traffic is not allowed to be transmitted to its destination for the determined identity, blocking the HTTP traffic from being transmitted.

6 . The method of claim 1 , further comprising:

responsive to determining that the HTTP traffic is allowed to be transmitted to its destination for the determined identity, causing the HTTP traffic to be transmitted to its destination.

7 . The method of claim 1 , wherein the SIM is on a removable Universal Integrated Circuit Card (UICC) or on an Embedded Universal Integrated Circuit Card (EUICC).

8 . A non-transitory machine-readable storage medium that provides instructions that, when executed by a processor causes operations to be performed including:

receiving a domain name system (DNS) query at a distributed cloud computing network, wherein the DNS query originates from a computing device using a mobile data connection, wherein the DNS query is associated with an identifier of a subscriber identification module (SIM) of the computing device;

determining, using the SIM identifier, an identity for identity-based policy enforcement at the distributed cloud computing network;

determining a DNS policy that is applicable for the determined identity and DNS query;

enforcing the DNS policy to determine whether the DNS query is allowed to be resolved for the determined identity;

receiving, at the distributed cloud computing network, a request to access a private application, wherein the request to access the private application originates from the computing device using the mobile data connection, wherein the request to access the private application is associated with the SIM identifier of the computing device;

determining an access policy that is applicable for the determined identity and private application;

enforcing the access policy to determine whether the determined identity is allowed to access the private application;

receiving first IP traffic at the distributed cloud computing network that has a first IP destination, the first IP traffic originating from the computing device using the mobile data connection, wherein the first IP traffic is associated with the first SIM identifier of the computing device;

determining a first network policy that is applicable for the determined identity and first IP destination;

enforcing the first network policy to determine whether the first IP traffic is allowed to be transmitted to the first IP destination for the determined identity;

responsive to determining that the first IP traffic is not allowed to be transmitted to the first IP destination for the determined identity, blocking the first IP traffic from being transmitted to the first IP destination;

receiving second IP traffic at the distributed cloud computing network that has a second IP destination, the second IP traffic originating from the computing device using the mobile data connection, wherein the second IP traffic is associated with the first SIM identifier of the computing device;

determining a second network policy that is applicable for the determined identity and second IP destination;

enforcing the second network policy to determine whether the second IP traffic is allowed to be transmitted to the second IP destination for the determined identity;

responsive to determining that the second IP traffic is allowed to be transmitted to the second IP destination for the determined identity, causing the second IP traffic to be transmitted to the second IP destination;

receiving HTTP traffic at the distributed cloud computing network, the HTTP traffic originating from the computing device using the mobile data connection, wherein the HTTP traffic is associated with the SIM identifier of the computing device;

determining an HTTP policy that is applicable for the determined identity and HTTP traffic; and

enforcing the HTTP policy to determine whether HTTP traffic is allowed to be transmitted to its destination for the determined identity.

9 . The non-transitory machine-readable storage medium of claim 8 , wherein the operations further include:

responsive to determining that the DNS query is allowed to be resolved, resolving the DNS query, and transmitting a DNS response to the computing device.

10 . The non-transitory machine-readable storage medium of claim 8 , wherein the operations further include:

responsive to determining that the determined identity is not allowed to access the private application, blocking the requested access.

11 . The non-transitory machine-readable storage medium of claim 8 , wherein the operations further include:

responsive to determining that the determined identity is allowed to access the private application, causing the request to access the private application to be transmitted to the private application.

12 . The non-transitory machine-readable storage medium of claim 8 , wherein the operations further include:

responsive to determining that the HTTP traffic is not allowed to be transmitted to its destination for the determined identity, blocking the HTTP traffic from being transmitted.

13 . The non-transitory machine-readable storage medium of claim 8 , wherein the operations further include:

responsive to determining that the HTTP traffic is allowed to be transmitted to its destination for the determined identity, causing the HTTP traffic to be transmitted to its destination.

14 . The non-transitory machine-readable storage medium of claim 8 , wherein the SIM is on a removable Universal Integrated Circuit Card (UICC) or on an Embedded Universal Integrated Circuit Card (EUICC).

15 . A server, comprising:

a processor; and

a non-transitory machine-readable storage medium that provides instructions that, when executed by the processor causes operations to be performed including:

receiving a domain name system (DNS) query at a distributed cloud computing network, wherein the DNS query originates from a computing device using a mobile data connection, wherein the DNS query is associated with an identifier of a subscriber identification module (SIM) of the computing device;

determining, using the SIM identifier, an identity for identity-based policy enforcement at the distributed cloud computing network;

determining a DNS policy that is applicable for the determined identity and DNS query;

enforcing the DNS policy to determine whether the DNS query is allowed to be resolved for the determined identity;

receiving, at the distributed cloud computing network, a request to access a private application, wherein the request to access the private application originates from the computing device using the mobile data connection, wherein the request to access the private application is associated with the SIM identifier of the computing device;

determining an access policy that is applicable for the determined identity and private application;

enforcing the access policy to determine whether the determined identity is allowed to access the private application;

receiving first IP traffic at the distributed cloud computing network that has a first IP destination, the first IP traffic originating from the computing device using the mobile data connection, wherein the first IP traffic is associated with the first SIM identifier of the computing device;

determining a first network policy that is applicable for the determined identity and first IP destination;

enforcing the first network policy to determine whether the first IP traffic is allowed to be transmitted to the first IP destination for the determined identity;

responsive to determining that the first IP traffic is not allowed to be transmitted to the first IP destination for the determined identity, blocking the first IP traffic from being transmitted to the first IP destination;

receiving second IP traffic at the distributed cloud computing network that has a second IP destination, the second IP traffic originating from the computing device using the mobile data connection, wherein the second IP traffic is associated with the first SIM identifier of the computing device;

determining a second network policy that is applicable for the determined identity and second IP destination;

enforcing the second network policy to determine whether the second IP traffic is allowed to be transmitted to the second IP destination for the determined identity;

responsive to determining that the second IP traffic is allowed to be transmitted to the second IP destination for the determined identity, causing the second IP traffic to be transmitted to the second IP destination;

receiving HTTP traffic at the distributed cloud computing network, the HTTP traffic originating from the computing device using the mobile data connection, wherein the HTTP traffic is associated with the SIM identifier of the computing device;

determining an HTTP policy that is applicable for the determined identity and HTTP traffic; and

enforcing the HTTP policy to determine whether HTTP traffic is allowed to be transmitted to its destination for the determined identity.

16 . The server of claim 15 , wherein the operations further include:

responsive to determining that the DNS query is allowed to be resolved, resolving the DNS query, and transmitting a DNS response to the computing device.

17 . The server of claim 15 , wherein the operations further include:

responsive to determining that the determined identity is not allowed to access the private application, blocking the requested access.

18 . The server of claim 15 , wherein the operations further include:

responsive to determining that the determined identity is allowed to access the private application, causing the request to access the private application to be transmitted to the private application.

19 . The server of claim 15 , wherein the operations further include:

responsive to determining that the HTTP traffic is not allowed to be transmitted to its destination for the determined identity, blocking the HTTP traffic from being transmitted.

20 . The server of claim 15 , wherein the operations further include:

responsive to determining that the HTTP traffic is allowed to be transmitted to its destination for the determined identity, causing the HTTP traffic to be transmitted to its destination.

21 . The server of claim 15 , wherein the SIM is on a removable Universal Integrated Circuit Card (UICC) or on an Embedded Universal Integrated Circuit Card (EUICC).

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 25, 2025
From: SILVERLOCK, MATTHEW; EHRIG, CHRISTIAN; YU, OLIVER ZI-GANG; WONDRA, NICHOLAS ALEXANDER; MOTA, CATARINA PIRES
To: CLOUDFLARE, INC.
Reel/Frame 073036/0754 →
SECURITY INTEREST Recorded May 20, 2024
From: CLOUDFLARE, INC.
To: CITIBANK, N.A.
Reel/Frame 067472/0246 →
Continuity (2)
Provisional Application 63377189 · Sep 26, 2022
Related Publication 20240107294A1 · Mar 28, 2024
References Cited (2)
US 20220117015A1 · DeFoy · 2022 [cited by examiner]
US 20240267783A1 · Howe · 2024 [cited by examiner]