Getting devices into service.
WHAT IDENTITY REQUIRES
A unique identifier per device Credentials proving it
WHAT CREDENTIALS SHOULD BE
Unique per device, never shared.
WHY THAT IS FUNDAMENTAL
A shared credential means compromising one device compromises the fleet.
WHAT TO PROVISION AT MANUFACTURE
A unique key or certificate, in secure storage where available.
WHAT JUST-IN-TIME PROVISIONING IS
A device registering itself on first connection, presenting a certificate from a trusted authority.
WHAT IT PROVIDES
No per-device configuration at manufacture beyond the certificate.
WHAT THE PROVISIONING FLOW MUST ESTABLISH
That the device is genuine Which customer or site it belongs to What configuration applies
WHAT CLAIMING IS
Associating a device with an owner.
HOW IT IS TYPICALLY DONE
A code on the device, entered by the owner Scanning a code Proximity pairing
WHAT TO PREVENT
Someone claiming a device that is not theirs.
WHAT TO RECORD
Every device, its identity, its owner, its location and its status.
WHY
An unrecorded device cannot be managed, secured or recovered.
WHAT TO PLAN
Decommissioning, including credential revocation.