Trending Tech: Digital Transformation: It's critical, but not all serious

eSIM-first IoT and why AI in the device changes the network

Trending Tech

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 27:30

In this episode of the Trending Tech podcast, host Jim Morrish, co-founder of Transforma Insights, is joined by Rony Cohen, co-founder of FLOLIVE and Loic Bonvarlet, senior VP of ecosystem and marketing at Kigen to explore how cellular IoT is evolving from remote monitoring into distributed infrastructure spanning device, edge, network and cloud.

As AI moves into the device, the rules change: models update continuously, decisions demand millisecond responses and data sovereignty determines where data can travel. So what should enterprises, MVNOs and manufacturers decide on day one to keep devices viable in the field for a decade or more?

Our guests discuss what SGP.32 really unlocks for eSIM-first deployments at scale, why the EU Cyber Resilience Act turns secure updates into a market access requirement, and why AI workloads need a network that comes to where the AI runs not the other way around.



Jim Morrish: [00:00:00] Okay. Hi, and welcome to this Trending Tech podcast, focusing on some of the key developments in today's cellular IoT markets, including how SGP.32 eSIM standards, Distributed AI and the evolving capabilities of support infrastructures for cellular IoT will reshape the concept of connectivity for IoT into something that could be better described almost as distributed infrastructure.

Yesterday's approaches for IoT were very much focused on remote monitoring and occasional data exchanges of status information or maybe control commands. But we're moving towards a world where AI-enabled IoT applications span multiple domains, and that's including the device, edge connectivity, cloud computing and more, and, of course, regulations intervene in this as well. We'll touch on some of the key emerging regulations in the space, not least of which the EU Cyber Resilience Act and more. So my name's Jim Morrish. I'm co-founder of [00:01:00] Transformer Insights, a firm of industry analysts focused on all things related to digital transformation, and for this episode of the podcast, I'm joined by Rony Cohen, who is co-founder of floLIVE

Rony Cohen: Hi, thank you for having me

Jim Morrish: And also Loic Bonvarlet, who is senior VP of ecosystem and marketing with Kigen

Loic Bonvarlet: Hi. Hi, Jim. Pleased to be here

Jim Morrish: Excellent. Great. It's great to have you here. I'm really looking forward to your views on these topics. So let's get stuck into the podcast.

Just starting off with a general question.

Loic Bonvarlet: Yes

Jim Morrish: Cellular IoT has been talked about for years. What's actually changed in the last couple of years that's making businesses, you know, rethink how they design and launch connected products?

And I'll ask you that question first, Loic, and I'll come to Rony, in a minute.

Rony Cohen: Thank you

Loic Bonvarlet: Yeah, sure. So I think, before in general, right, the telecom and connectivity integration in companies was quite difficult and complex. But now I think, the modern era, we are really into a stage where everything is connected, daily life is very connected, and it's really part of our daily business life. [00:02:00] So any company can think about, uh, really connecting their products for better intimacy with their end customers, for better life cycle for management, and also we come to that with security. There is a need now to really embed security and security life cycle out of the box. So, uh, we have also growth of, I would say, capability at the edge in terms of what a device can do, and companies are now able to embed more of their vertical knowledge directly into their devices, and process that data locally in the device. So it can really become a source of insights that will be pushed already pre-processed back to the HQ of the company and the HQ systems. So, overall, yeah, that makes security very central, and with EU CRA, secure product update really becoming essential, when you talk about any type connectivity and connected devices, and we stand ready to support that with Kigen products

Jim Morrish: Excellent. Thank you, and Rony, same kind of question to you. What do you think's really changed in the last [00:03:00] couple of years?

Rony Cohen: You've kind of said that cellular IoT has been talked about for years. And I think that finally we've arrived at a sort of straight line where the connectivity is streamlined and IoT connectivity is now finally available at a higher quality, but something's now changed or something's just about to change.

But we're seeing that now with the advancements in AI at the edge, and something that we just didn't have before. And we're seeing a massive growth on AI-enabled devices, and it could be from very unsophisticated machines, you know, from meters to a coffee machine or, you know, metering type of sort of applications to more sophisticated ones.

But what we now understand is that the rules of the AI means that the defining the data, location and the rules around the GDPR and the AI data sovereignty that each country has are sort of reshuffling, the field again. Which means that we no longer can just buy the connectivity. We now need to know where that data [00:04:00] resides, where is it moving between countries, and can we just send it all around the world and back.

And various subsectors, whether it's financial services or anything really that has user data, but also the AI models themselves, countries have their own data sovereignty rules. So now what's really changed is we have to think about the network, and it's something that we perhaps haven't thought about when we're thinking about traditional AIs with all the LLMs.

But when we're thinking about devices and we're thinking about, AI-enabled devices, we now have to think about the network and how do we bring that compute closer to the network with lower latency solutions. I think that's really what's changing in how the customers are rethinking this.

Jim Morrish: Okay. Thank you. I mean, definitely I see where you're coming from there. And what I'd like to do is take the conversation forward a little to focus on the two companies specifically, because these are two quite interesting companies, Kigen and floLIVE, with two quite complementary propositions.

So I'd like to drill into that a little and put that in context of some of these evolving dynamics that you've both outlined. [00:05:00] So starting with you, Loic, what does the combination of Kigen and floLIVE do to help customers achieve that might otherwise have taken them a lot longer?

Loic Bonvarlet: Right. So, we've shared with floLIVE a vision to facilitate this shift about adopting cellular IoT, and cellular IoT has long been perceived as complex because you have to, deal with contracts, you have to deal with SIM cards, et cetera. So we are really focused on trying to simplify that and have as much as possible a digital experience for the end customers.

So, we see mainly in this collaboration two big things from the Kigen side, which are the eSIM itself, right? eSIM enables the SIM functionality to be already part of the device itself. It's a component like any other, right? Where you will load and provision the right digital profile for the destination of the device, and to load that profile, we can do that into various moment of the provisioning flow, of the manufacturing flow. But essentially what we can use is in-factory profile provisioning, which is making sure that we [00:06:00] can load the right floLIVE profile into the device at the right point in the manufacturing flow.

And so here also when we pair that with floLIVE capability in terms of coverage of multiple IMSIs available that gives a global coverage, we can then have a very powerful out-of-the-box experience for the customer, which right away benefit from the entire coverage offered by floLIVE.

And if for a specific reason there is a need to enable other profile for regulation or some specific market like Turkey for example we did together, right? We are able to swap the profile via SGP.32 over-the-air, or again via a sideway means if we have these requirements, for example the device for whatever reason would go back into a provisioning centre at some point or repair centre, we would be able to also manage the life cycle of those profile at that stage.

So, that's the pieces around the key offering that we integrate there.

Jim Morrish: Thank you, and Rony, I thank you for outlining there how the SIM becomes much more part of the device, but [00:07:00] I think that the device actually becomes much better integrated to the network as well, doesn't it, Rony?

Rony Cohen: Yeah. I mean, the main part here really is that, you know, as Loic was saying about the SGP.32, on its own, it has to be downloaded, it has to be contracted between the network and the customer, whereas really the combination with Kigen is the floLIVE multi-IMSI running as a profile on the SIM with multiple operators, so multiple IMSIs, and floLIVE has more than 20 various IMSIs on its library. So we could get the multi-IMSI application that's running straight out of the box, and that sort of collapses that function that the customers require to contract and to download each specific one. So floLIVE has that. It can all be orchestrated via our connectivity management platform to create sort of business rules around which IMSIs need to be working first or by geographical area or first and secondary, you know, and as much of that is always to be close to the device as possible. So, [00:08:00] you know, using that low latency, which I've mentioned before.

Jim Morrish: Okay, thank you, and Loic, I do wanna come to you for a little clarification on SGP.32, 'cause SGP.32 is something that's come up in conversation a few times. You've both mentioned it, and it's being talked about in the wider industry as kind of a trigger that makes eSIM-first for IoT, you know, really work and practical at scale.

From where you sit, what does it actually unlock for customers, and what does it still leave for them to solve another way?

Loic Bonvarlet: Yeah. So, um, really SGP.32 is, really learning from the previous generation of SGP, right? Two generation SGP.02 and 22. 02 was the M2M standard focused on automotive but with very complex network-to-network integration. We've eliminated that with 32, and the consumer infrastructure that was developed with SGP.22, brought the scale, and notably thanks to a few big OEMs like,, Apple and Samsung really democratised the use of eSIM in smartphones. The MNOs got equipped with what we call the SM-DP+, which is effectively the [00:09:00] foundation where you host your digital profile as an MNO or as a connectivity provider at large. So the standard didn't appear out of a vacuum, but really we were deeply involved in Kigen. We sent Said, our Head of Standards, into the building of the standard itself, and I would say from the management angle, we really pushed  Saïd to take as much as possible a pragmatic and implementable through steps approach rather than, you know, a full blank canvas, full standard and then say, "Okay, let's go implement that," right? So really learn from the past to build a standard that is usable, easily.

And so it does remove the SMS dependencies, which was a real problem in IoT, notably LPWAN, and it really brings the concept of what I would call 'Bring your own connectivity', right? That is, if you work with a connectivity provider such as floLIVE who has both the offer of classical SIMs but also digital profile. Then you get finally the freedom of separating the hardware [00:10:00] equation of your problem, inserting the right hardware on your device from the actual correct connectivity choices, and, for companies like floLIVE, it's really a way to be able to really demonstrate the true value of platform connectivity, profile pricing, the things that really matter for deploying a connected service. So, really we see more and more companies who are adopting the digitalisation of profile, making it available for IoT fleets, and we see adoption of that into smart meter, retail costs. So we see a real benefit there.

Now, practically in the field, sometimes there is the idea that it brings right away a difficult situation or position for connectivity player. And for IoT fleets, I don't think it's the case because you still have a lot of things to check and figure out to swap a large fleet of devices from coverage A to coverage B. This is a very important swap to do on a fleet of 100K, a million devices. You don't [00:11:00] do it lightly, right? So I think if the connectivity provider in place does a good job, is definitely here to stay, right? And I don't foresee in IoT fleet the concept of very frequent churn for, you know, just for pricing down, right? Because it's a very involved operation

Jim Morrish: Right. But sticking with you, Loic, let's take a slightly different perspective on that because I agree that it's going to be relatively unlikely or at least rare that huge fleets of kind of devices are gonna move from provider A to provider B. So churn probably won't be huge, but there is another perspective which is around the EU Cyber Resilience Act, and a requirement to keep products connected and up to date, and essentially, products updates move from being a nice to have thing to a market access requirement, and there are real, you know, penalties with real teeth if people don't update and maintain the SBOM or software bill of material of their devices, and there's a synergy in there, isn't there, between SGP.32 and maintaining, of that [00:12:00] connectivity to support the SBOM updates?

Loic Bonvarlet: Yeah. So as part of a, well, security-oriented component inside a product and also because we are delivering connected service, any device maker who brings a cellular IoT device will have to comply to EU CRA requirements, which start with SBOM declaration and ability to fix issues in the field if there is a problem in the full software stack related to security, right? And as such, the eSIM fall under that regulation as well. That is, you need to find ways to, be able to update the eSIM OS as an example. And, to date, the approach that was done in the consumer world was that, say, the big OEM such as Apple and Samsung designed their own system to be able to upgrade everything in their phone, right? But these are very capable with large means companies, and it's not necessarily the case of, you know, a smart meter or vertical company who is launching a connected device ideas, right? So, we try to make it [00:13:00] simple to update the eSIM OS and whatever is pertaining to the eSIM itself by leveraging the EIM and the SGP.32 infrastructure, and that's the path we took to deliver that. And in general, right, I think the awareness of end consumer and end user towards security is becoming more and more acute, not only because of EU CRA, because there is not a single day in everybody's digital life that you don't receive a spam or a phishing attempt or something of that kind, right?

So people start to also integrate what they live in their personal life into their own, I would say, business choices, right? And making sure that they can select components and solutions that deliver that software update ability and patch ability. I think that's really important, and yeah, we see that, more and more business leader actually understand this. This is becoming a real immediate thing to tackle.

Jim Morrish: Hmm. Thank you, and Rony, I'd like to bring you in here because we've been talking very much about, you know, [00:14:00] devices so far and security of those devices, but as the environment evolves, it's becoming about much more than devices. It's becoming about the devices and how they integrate into the network and that cohesive whole, and floLIVE has been talking about some of these things a fair amount recently. So specifically, you know, network for the AI age and so on. So in simple terms, what does that mean, and what does it need to look different from the connectivity that people have used in the last decade?

Rony Cohen: Well, I think really, I mean, what you need to kind of think about here is that it's completely changed. We're about to see a massive change in device behaviour. The devices right now, if you think about a device up until now, if we put it like, you know, what it was yesterday and what's it gonna be tomorrow.

So we'd be sending data out of the device, and it's usually some sort of metric data. It was sensor data, et cetera. Now, the device is running AI models, becoming more sophisticated. It's integrating with its own device management system. It's integrating with other [00:15:00] devices like that. It's learning from other devices, and it's creating, a richer environment for that product, and, that could be, you know, anything around the tracking. You know, if we see the asset management, all that's becoming a lot more richer, and it's gaining data from the model, running on the device. And so if we looked at yesterday, we were just sending out data, the speed, the accuracy, the temperature, where I am, have I delivered, have I not delivered.

Right now, for tomorrow, we're gonna need to talk to our AI model as well. So the device itself needs to update its AI model, and the AI model need to update the device. So if we're thinking about software updates, if we previously thought about software updates as devices, getting a software update for the hardware, we're now getting a software update for the AI model running on the device and the device updating its AI model, which means there's two separate streams of communications and the AI model running on the device, we're already seeing that with advanced customers in the automotive space and things like that, that you're calling, you know... The device calls the network and says, " [00:16:00] I need to create a secure, connection. I'm gonna run this amount of data for this amount of time, and it's gonna run through my specific model."

It no longer can just send it out, you know, to transverse the whole world via connectivity that's roaming somewhere else in the world. It needs to do it within its sort of data sovereignty, you know, limitations, and it'll say to the network, "I require you to give me connectivity for this amount of time. Open up a VPN for me for the next thirty seconds." And the network for AI means that it knows how to interact with that model. It knows to call the network, and the network knows how to create the infrastructure that it needs. So that's a very dynamic infrastructure.

The second thing is I would say about it is millisecond requirement responding. When you need to respond to a device, you know, some devices definitely don't need a millisecond response. But when they do need, the AI model needs to take a decision, whether it's gonna take a millisecond response or not. It could be a transactional. We're seeing more sophisticated, you know, financial services transactions. Am I going to take this transaction or [00:17:00] not? Am I going to authorise it or not? And all of that requires a millisecond type of response, and I think that's what we're seeing on the network and what, you know... Going back to what Loic was saying about security, we take that very seriously.

I think that because floLIVE runs its own core infrastructures around the world, pretty much most points around the world, you know, we have about 70 packet gateways around the world and 50 pack core networks. We are sitting on a massive amount of data infrastructure. We know where our devices are. They're authenticating on our core networks. We are the pipe out to the internet. We control all that data coming in and out. We have a lot of capabilities around security there. We're not reliant on a third party that's gaining that data, you know, API-ing that data out of our network and creating security. We're using that, so we're now thinking about, you know, baked into network security. So getting all those algorithms into the network and not sort of waiting for a third party to... Or, or throwing that on the customer, which up [00:18:00] until now, a lot of that was really the customer's problem. You know, get all that data out of the network, out of your device, and go and try and figure out your own security with third-party companies.

We realised that we have all that data, and there's no reason why we shouldn't sort of bake in all that security into the network, and that's definitely something we're working on.

So that's really what, the AI network, you know, network for AI looks like.

Jim Morrish: Yeah, there are some extremely complex emerging architectures underpinning some of these new applications, with a lot more agility and different application components moving around between device and cloud and edge, and different locations in between, and something that you've described, Rony, in the past is an approach where floLIVE brings the network to where the customer wants to run their AI instead of forcing them to put their AI where the network goes.

Could you expand on that a little a- and maybe provide an example of what that looks like in a real deployment, one that spans multiple countries?

Rony Cohen: So I think the car industry was always something that we've discussed before. You know, we've got experience with that. I think that what we're seeing is [00:19:00] that if your cars are in a specific area in the world, you don't want to be sending that data across the borders, and that's the first thing. So when we say bring the connectivity towards the model is if you're running your car management system in your environment, there is no reason why we can't put our packet gateway in that same environment. If that's running on one of the public cloud providers, we could put that packet gateway or core network, adjacent to it and within, you know, that same environment. That brings down the latency and that definitely creates, you know, there's an element of security there. But bringing that data to bring that core network and packet gateway to where car management system lies is what we mean by that, and there is no reason for us not to do that.

We are, you know, agile in that respect. We've built it for cloud environments. We already run it on three different type environments today, and we could bring it closer and closer, and all of that is obviously, you know, there's one side of it, which is data sovereignty.

There's one side of [00:20:00] it, which is data sovereignty for AI, you know, for the AI era. But there's also the data, the GDPR element to it. Then there's a high-performance network. You know, that's where the performance comes in. So putting regulation to one side, there's also the performance side where... and there's no reason why we can't do that. You know, we did it by geography, we can now do it by the customer as well. You know, if it's a large enough, deployment, there's no reason why we wouldn't do that.

Jim Morrish: Okay so we have a complex application requirement and demand. We've got a very fast evolving technical infrastructure for supporting that. Let's think about this from the end user, from the adopter's perspective. You know, where do they start? So on day one, if somebody has a connected product that needs to work across multiple countries, so different operators, different regulators, different data residency rules, and if that device needs to stay in the field for many years, what are the choices that they need to make on day one?

I'll come to you first on that, Rony.

Rony Cohen: Well, first of all, I think if there's an AI element to it, they need to understand where their models are going to run, if that [00:21:00] device needs to live in the field. The models can run in the cloud, environments can be adapted over the years. It's not something that can't be changed. However, the elements that you need to think about is what happens in the network. Do you drop that data into your cloud environment today? Do you drop it into, you know, a server environment closer to the edge? And wherever that is, it really doesn't matter from our point of view. It's whatever suits that use case. If it's sort of a near edge environment or is it a public cloud, there's rules and regulations around various sub-sectors, from financial sector to transport, logistics, medical, you know. Each geography and each sub-sector has its own sort of regulations, and I think that is something that customers need to take into consideration while they're planning it, and I think most customers know that. You know, if you're in the sort of medical space and you're in a certain geography in the EU, you already know what's happening in that. You know, what's your limitations in that sector. And I think that we've built the network so flexible now that [00:22:00] really it's sort of a, you know, where do you drop the data? I need it closer here. You know, I need my AI environments to be talking to my models, and I need to do that on AWS or on Oracle Cloud or something. Although in some devices in certain areas in the world, I definitely need a packet gateway. For example, in Africa, I would like a packet gateway in Africa because I don't want for my latency to leave or there's also, you know, local GDPR requirements. All of these factors have to be taken in large scale deployments for sure, and where AI lives in there, in the device.

Jim Morrish: Okay and Loic, from your perspective, do you have any additional thoughts on things that end users and adopters and service providers, I guess, and even OEMs need to be thinking about on day one as they start to deploy solutions into this new and fast-evolving technical environment?

Loic Bonvarlet: So I think, yeah, the multi-country, multi-operators really bring the complexity of supply chain, right? So and if you work with, say, multiple MNOs, in some cases because of regulation, you've experienced directly already the pain of, " Oh, I need [00:23:00] to integrate all the SIM supply from the different vendors, and this is not uniform. They don't behave the same way," et cetera. So our belief is that, for this large scale, multi-country, multi-network, you need an eSIM certified product. You can guarantee the availability of the hardware through one source or multiple source, but you know exactly what you're buying hardware and capability-wise. And then on that solid basis, you are able to load the profiles you and especially if the device are long-lived. Typically, connectivity contracts don't last, say, 10 years or 15 or 20 years in some market, for example, for metering. To have the capability to manage the profile over the lifecycle of the device is a key aspect.

So, this day one decision on your design or if you're doing a refresh of your design have a big, big impact on the TCO of your device if you don't pay attention or if you lock yourself into some type of solutions. Yeah. And really, they correlate connectivity profile [00:24:00] and eSIM hardware, I think for large is really something interesting that SGP.32 brings.

Jim Morrish: Okay. Thank you. And just to sort of draw this podcast to a close and shifting away from that day one perspective and kind of going to the other end, if we look two or three years ahead, and you've described, you know, an evolving approach to supporting connected devices, if everything works in the way that you described in this podcast, how does the way that businesses buy and design connectivity actually change? And what's the one thing you'd want folks listening in to take away? Uh, Loic, I'll ask you that question first.

Loic Bonvarlet: Yeah. So we would say in two, three years, every connected product launching, for example, in Europe have to meet the EU CRA requirements, the secure by design and eSIM-first, we think will be the default, not a differentiator because, yeah, it embeds the software capabilities updates. It embeds the flexibility of choosing your own connectivity, and we believe that from that perspective, SGP.32 is a solid standard that really learned from [00:25:00] the past, and it will be the standard for IoT, because it really allows this vision of digital connectivity delivery to your devices while ensuring security life cycle

Jim Morrish: Okay, thank you. And Rony, your thoughts on what the future might look like?

Rony Cohen: I think as I said, you know, we believe that there's an explosion of sort of AI-based devices or enhanced with AI. So I think, first of all, from the electronics industry, I think that we're gonna see a mass amount of new deployments or existing devices getting revamped with the AI.

I think that buying AI inference will be distributed across dozens of regional clouds. Connectivity, you know, is going to follow that cloud path and the network plan and the device plan will be one conversation. It's the same as sort of buying, are you gonna buy cloud and connectivity? I think they'll be very much a single conversation, where you set the rules, and the network adapts really to the rules around the cloud and the data path.

I think that connectivity's moved from procurement to strategic foundation and the platform that sort of [00:26:00] turns device data into sort of business impact and lets business move faster than their competitors. I think that's really where it's all going. You know, we're all trying to create much better devices and the market's moving so quickly with AI. And I think it's the devices, we know who will come just slightly afterwards. It's first happening in the middle on the application side.

But definitely, the customers need to be sort of future ready for this if they wanna stay ahead.

Jim Morrish: Okay. Well, thank you both for an extremely interesting discussion. I mean, there's many things we've touched on there. You know, everything is connected, and those connected devices very much are part of life. There's a lot more AI at the edge and pre-processing, and that's making security much more central.

There's AI in the network, in the cloud. It's pervading all sorts of aspects. And I tend to agree, the whole industry and the whole space is moving away from a procurement of connectivity towards a strategic decision about the capabilities that you need as an end user or OEM to support your proposition.

So yeah, Rony and Luke, it's been extremely interesting [00:27:00] discussion, and thank you for joining me.

Rony Cohen: Thank you very much. Thanks for your time

Loic Bonvarlet: Thank you for having us

Jim Morrish: And with that, I think we should draw this podcast to a close. And just a reminder that you can subscribe to the Trending Tech Podcast wherever you found us today, and indeed, thank you for joining us, and we're delighted to have you listening in as part of our growing audience. We'll be back soon, I'm sure, with another edition of Trending Tech Podcast.

So please do keep tuned for that, and we'll talk more about digital transformation then. Thanks again for joining, and bye for now 

Rony Cohen: Great. Thank you, Jim 

Loic Bonvarlet: Bye-bye