ENABLINGTHE IOTIN THE CLOUD
JAVIER GARCÍAPUGA
GLOBAL HEADOF IOT TECHNOLOGY
MAY 2018
• Positioned as “IoT leader” in Gartner’s magic quadrant for
4 years in a row
• Top 4 Telcos world-wide in IoT services
• +17 millions connected SIM Cards
• Very relevant customers: Nestlé, Visanet, Department of
Energy and Climate Change, Gocco, etc.
• +1.000 professionals world-wide focused on provide
best in class IoT solutions
• +500 partners & alliances, guaranteeing the best and
more innovative e2e IoT solutions
• +700 roaming agreements, providing global solutions
PARTNERS
TECHNOLOGY e2e SOLUTIONS
TEAM
Telefónica, a reference in the IoT Market
OUR VISION
LET INTERNET OF
THINGS HELP PEOPLE
TO CONNECT WITH THE
THINGS THAT REALLY
MATTER TO THEM
AND IT’S FOR REAL
There area set of challenges when deploying IoT Solutions:
• Security& credentialsmanagement
• Costefficient devices
• Service assurance
that can be resolved combining cellular network + IoT Connectivity platform
with Public Cloud Services
But…
Devices Managed Connectivity IoT Platform AnalyticsConnectivity Application
Cloud
Ready
GAP
Devices Managed Connectivity IoT PlatformLTE Network
LTE Cellular Security VPN encryption
(optional)
• Mutual authentication between device and network
• Strong OTA encryption (128 bits key AES-like in LTE)
and integrity assurance
• Temporary identity to avoid device tracking
• Trusted hardware (SIM)
• IPSec or MPLS VPNs
• Strong encryption
• Isolated from the Internet
Leveraging the cellular network
E2e security from device to cloud, without adding extra complexity to the device
Comprehensive inventory &
Lifecycle management
Remote trouble shooting
Real-time consumption control
Business rules and alerts
Geo-position
API integration
IoT Connectivity Platform
Managed Connectivity is a MUST when deploying massive and global IoT Solutions
REST API for
Customers
Security is YOY the main concern for everyone
“What barriers do companies see to investing in the IoT?”
39% execs chose “Security and privacy” as the main stopper
Business Intelligent report Dec 2014
“Are you fully confident that your connected devices are secure?”
Just 10% companies replied they are “fully confident”
AT&T State of IoT Security survey, 2015
“What is your main concern developing an IoT solution?”
39% developers named security as the main concern
Eclipse Foundation IoT Developer Trends Survey, 2018
39%
main
concern
#1
Barrier
90%
uncertain
Secure Comms
GGSNs
Virtual Private Gateway
Availability Zone
VPC Subnet
Router
VPN IPSec Connection
Private Customer APN
Private APN for devices connectivity to assure device isolation, complemented with IPSec or
MPLS communications with IoT PaaS in Cloud datacenter.
Secure Comms
GGSNs
Virtual Private Gateway
Availability Zone
VPC Subnet
Router
VPN IPSec Connection
Private Customer APN
AWS IoT
Direct ConnectMPLS Connection
(WAN2Cloud)
Public PaaS
Private APN for devices connectivity to assure device isolation, complemented with IPSec or
MPLS communications with IoT PaaS in Cloud datacenter.
• Asset monitoring
solution for a global
beverage machine
company.
• Solution built on top of
AWS IoT
• Problem: Unique
credentials
provisioning (X.509
certs.) in the device is
complex and increases
the cost of the device
manufacturing.
Monitoring solution for beverage machines
IoT Connectivity
Platform
IoT Device
IoT SolutionStep #4: MQTT connection using X.509 certificate
Data flows
Authentication flows
Step #1: Bootstrap
request under private APN
Credentials Manager
Step #2: Request to get AWS
IoT Certificates
Step #3: Certificate
delivered OTA to the SIM
Embedded
SW
AWS IoT Core
Device Integration with AWS IoT simplification: Credentials Manager
The customer’s device gets the AWS IoT Certificates with a secure network based
authentication API. This simplifies credentials provisioning into devices and avoids firmware
customization.
• Asset tracking solution
for a Cargo company
• Containers and reefers
location & temperature
monitoring
• Problem: GPS signal is
lost once containers
are loaded in the
vessel
Cargo container tracking
IoT Connectivity
Platform SIM & connectivity data is published as a
device ”shadow” in AWS IoT (SIM as a Sensor)
Device gathers data from its
sensors and publishes it in the
device “shadow” AWS IoT Core
Cloud Connector
Cloud Connector
Pushing network information automatically to AWS IoT allows a single point where to obtain
all the IoT data: business and operational data
 Cellular network location: Avoid GPS extra cost for apps which don’t need accuracy
 Connectivity status
 SIM current consumption
IoT Connectivity
Platform SIM & connectivity data is published as a
device ”shadow” in AWS IoT (SIM as a Sensor)
Device gathers data from its
sensors and publishes it in the
device “shadow” AWS IoT Core
Cloud Connector
Cloud Connector
… and this enables further use cases for Service Assurance, providing customers with better
visibility into the state of connectivity to control service quality and avoid downtime.
 Cellular network location
 Connectivity status
 SIM current consumption
Amazon
QuickSight
AWS IoT
Analytics
• Service Assurance
Detect service outages
due to connectivity status
and SIM current
consumption
• Better visibility of the
data consumption and
impact due to changes
in config.
Cloud Connector
Cloud Connector
• Service Assurance
• Combining SIM Lifecycle
and network registration
with AWS IoT Lifecycle
Events
• Security
Detect potential breaches
in the device
• SIM exchanged from
the device (IMEI-ICCID)
• Unusual
communications
patterns
Cloud Connector
Yourown use case
here
INTERNET OF THINGS

Enabling the IoT in the Cloud

  • 1.
    ENABLINGTHE IOTIN THECLOUD JAVIER GARCÍAPUGA GLOBAL HEADOF IOT TECHNOLOGY MAY 2018
  • 2.
    • Positioned as“IoT leader” in Gartner’s magic quadrant for 4 years in a row • Top 4 Telcos world-wide in IoT services • +17 millions connected SIM Cards • Very relevant customers: Nestlé, Visanet, Department of Energy and Climate Change, Gocco, etc. • +1.000 professionals world-wide focused on provide best in class IoT solutions • +500 partners & alliances, guaranteeing the best and more innovative e2e IoT solutions • +700 roaming agreements, providing global solutions PARTNERS TECHNOLOGY e2e SOLUTIONS TEAM Telefónica, a reference in the IoT Market
  • 3.
    OUR VISION LET INTERNETOF THINGS HELP PEOPLE TO CONNECT WITH THE THINGS THAT REALLY MATTER TO THEM
  • 5.
  • 6.
    There area setof challenges when deploying IoT Solutions: • Security& credentialsmanagement • Costefficient devices • Service assurance that can be resolved combining cellular network + IoT Connectivity platform with Public Cloud Services But… Devices Managed Connectivity IoT Platform AnalyticsConnectivity Application Cloud Ready GAP
  • 7.
    Devices Managed ConnectivityIoT PlatformLTE Network LTE Cellular Security VPN encryption (optional) • Mutual authentication between device and network • Strong OTA encryption (128 bits key AES-like in LTE) and integrity assurance • Temporary identity to avoid device tracking • Trusted hardware (SIM) • IPSec or MPLS VPNs • Strong encryption • Isolated from the Internet Leveraging the cellular network E2e security from device to cloud, without adding extra complexity to the device
  • 8.
    Comprehensive inventory & Lifecyclemanagement Remote trouble shooting Real-time consumption control Business rules and alerts Geo-position API integration IoT Connectivity Platform Managed Connectivity is a MUST when deploying massive and global IoT Solutions REST API for Customers
  • 9.
    Security is YOYthe main concern for everyone “What barriers do companies see to investing in the IoT?” 39% execs chose “Security and privacy” as the main stopper Business Intelligent report Dec 2014 “Are you fully confident that your connected devices are secure?” Just 10% companies replied they are “fully confident” AT&T State of IoT Security survey, 2015 “What is your main concern developing an IoT solution?” 39% developers named security as the main concern Eclipse Foundation IoT Developer Trends Survey, 2018 39% main concern #1 Barrier 90% uncertain
  • 10.
    Secure Comms GGSNs Virtual PrivateGateway Availability Zone VPC Subnet Router VPN IPSec Connection Private Customer APN Private APN for devices connectivity to assure device isolation, complemented with IPSec or MPLS communications with IoT PaaS in Cloud datacenter.
  • 11.
    Secure Comms GGSNs Virtual PrivateGateway Availability Zone VPC Subnet Router VPN IPSec Connection Private Customer APN AWS IoT Direct ConnectMPLS Connection (WAN2Cloud) Public PaaS Private APN for devices connectivity to assure device isolation, complemented with IPSec or MPLS communications with IoT PaaS in Cloud datacenter.
  • 12.
    • Asset monitoring solutionfor a global beverage machine company. • Solution built on top of AWS IoT • Problem: Unique credentials provisioning (X.509 certs.) in the device is complex and increases the cost of the device manufacturing. Monitoring solution for beverage machines
  • 13.
    IoT Connectivity Platform IoT Device IoTSolutionStep #4: MQTT connection using X.509 certificate Data flows Authentication flows Step #1: Bootstrap request under private APN Credentials Manager Step #2: Request to get AWS IoT Certificates Step #3: Certificate delivered OTA to the SIM Embedded SW AWS IoT Core Device Integration with AWS IoT simplification: Credentials Manager The customer’s device gets the AWS IoT Certificates with a secure network based authentication API. This simplifies credentials provisioning into devices and avoids firmware customization.
  • 14.
    • Asset trackingsolution for a Cargo company • Containers and reefers location & temperature monitoring • Problem: GPS signal is lost once containers are loaded in the vessel Cargo container tracking
  • 15.
    IoT Connectivity Platform SIM& connectivity data is published as a device ”shadow” in AWS IoT (SIM as a Sensor) Device gathers data from its sensors and publishes it in the device “shadow” AWS IoT Core Cloud Connector Cloud Connector Pushing network information automatically to AWS IoT allows a single point where to obtain all the IoT data: business and operational data  Cellular network location: Avoid GPS extra cost for apps which don’t need accuracy  Connectivity status  SIM current consumption
  • 16.
    IoT Connectivity Platform SIM& connectivity data is published as a device ”shadow” in AWS IoT (SIM as a Sensor) Device gathers data from its sensors and publishes it in the device “shadow” AWS IoT Core Cloud Connector Cloud Connector … and this enables further use cases for Service Assurance, providing customers with better visibility into the state of connectivity to control service quality and avoid downtime.  Cellular network location  Connectivity status  SIM current consumption Amazon QuickSight AWS IoT Analytics
  • 17.
    • Service Assurance Detectservice outages due to connectivity status and SIM current consumption • Better visibility of the data consumption and impact due to changes in config. Cloud Connector
  • 18.
    Cloud Connector • ServiceAssurance • Combining SIM Lifecycle and network registration with AWS IoT Lifecycle Events
  • 19.
    • Security Detect potentialbreaches in the device • SIM exchanged from the device (IMEI-ICCID) • Unusual communications patterns Cloud Connector
  • 20.
  • 21.

Editor's Notes

  • #4 Nuestra visión en Telefónica IoT es conectar a las personas con las cosas que les importan. Para que podamos conectar con lo que verdaderamente nos importa.
  • #5 VÍDEO CORPORATIVO.
  • #6 IOT es ya una realidad. Lo es para nosotros, en Telefónica, y lo es para nuestros clientes. Quienes más y mejor nos ayudan a derribar barreras son precisamente los clientes más comprometidos con su progreso. Os he traído unos ejemplos de cómo avanzamos junto a ellos en el camino de IOT.
  • #7 Gracias a nuestros activos los podemos resolver La red y nuestras plataformas de conetividad Telefónica IoT Connectivity “AWS Ready”
  • #13 https://www.pexels.com/photo/beverage-business-cafeteria-caffeine-302894/
  • #15  Cargo shipping container tracking voy a empezar por un buen ejemplo de creación conjunta: una de las principales compañías globales de transporte marítimo. Nos pidieron una solución que diera más seguridad al transporte de mercancías refrigeradas de más de mil barcos y 150 mil contenedores en tiempo real, durante toda la travesía. Imaginaos monitorizar cada contenedor en cada punto del océano, y ver en tiempo real su estado, si necesita una reparación, o si la mercancía pierde refrigeración… Os puedo decir que nuestra competencia no lo había conseguido de un modo eficiente. Colocarle una sim a cada container no era una solución asequible. Colaborando con la compañía llegamos a una solución que es la que se está implantando: una combinación de conectividad interna dentro del barco, y otra externa, vía satélite para que el cliente tenga la información de manera inmediata en cualquier dispositivo.
  • #22 Gracias.