SlideShare a Scribd company logo
© FIDO Alliance 2021
1
Introducing
FIDO Device Onboard (FDO)
May 7, 2021
© FIDO Alliance 2021
2
© FIDO Alliance 2021
Today’s Speakers
Giri Mandyam
Senior Director for Technology
Qualcomm
Co-Chair, IoT TWG
Andrew Shikiar
Executive Director & CMO
FIDO Alliance
Richard Kerslake
General Manager Industrial
Controls and Robotics, IOT
Business Unit,
Intel
Co-Chair, IoT TWG
© FIDO Alliance 2021
4
How the FIDO Alliance is
Solving the IoT Onboarding
Challenge
© FIDO Alliance 2021
The FIDO Alliance brings together the world’s leading
technology companies to develop and promote the adoption
of a standardized, simpler, and more secure online experience
that installs trust and confidence in a digital world.
5
© FIDO Alliance 2021
+ Sponsor members + Associate members + Liaison members
6
© FIDO Alliance 2021
Track record of successful collaboration
7
Growing Platform Support
Hello
3 Sets of Specs Released
Increasing Market Adoption
© FIDO Alliance 2021
8
How long does it take
to manually onboard1 10,000
Gateways, Devices, Sensors?
Answer:
Over 2-man years2
1. Assumes out-of-box to securely streaming data to an IoT Platform
2. Kaiser Associates Research and Analysis, IoT study, August 2017
© FIDO Alliance 2021
The Onboarding Challenge
9
• Wide variety of IOT devices – hardware and Operating Systems
• Most devices headless (i.e. don’t have displays)
• Different connectivity – wired / wireless
• Manual installation adds cost and time to IOT deployments, impacting program ROI
• Manual installation requires trusted and skilled staff
© FIDO Alliance 2021
Onboarding solutions exist today, but don’t fully meet the needs of the industry
• Manual onboarding
• Slow
• Insecure
• Expensive
• Proprietary ‘zero touch’
• Linked to one cloud/platform
• Only one silicon provider
• Require programming of target platform/cloud/user at manufacture
Onboarding solutions today
10
© FIDO Alliance 2021
The FIDO Alliance launched
the IoT Technical Working
Group (IoT TWG) in June
2019 - members include
leading Cloud Service
Providers, semiconductor
manufacturers, security
specialists and OEMs.
The IoT TWG analyzed
multiple use cases, target
architectures and
specifications to develop as
clear set of requirements.
Intel contributed their
Secure Device Onboard
specification, which served
as the starting point for
FIDO’s IoT work - the TWG
modified and extended the
initial specification to meet
the defined requirements.
FIDO’s Approach to Secure IoT
11
NEWS - The FIDO Device Onboard specification is now available:
https://fidoalliance.org/specs/FDO/fido-device-onboard-v1.0-ps-20210323/fido-device-onboard-v1.0-ps-20210323.html
© FIDO Alliance 2021
Fast, Scalable Device Provisioning, Onboarding &
Activation
12
Drop ship device to
installation location
Power-up & connect
to Network
Auto-provisions, Onboards
to Cloud
BENEFITS1
• Zero touch onboarding – integrates readily with existing zero touch solutions
• Fast & more secure1 – ~1 minute
• Hardware flexibility – any hardware (from ARM MCU to Intel® Xeon® processors)
• Any cloud – internet & on-premise
• Late binding - of device to cloud greatly reduces number of SKUs vs. other zero touch
offerings
• Open - LF-Edge SDO project up and running, code now on GitHub
12
1. No product or component can be absolutely secure
© FIDO Alliance 2021
FIDO Device Onboard: Late Binding in Supply Chain
13
IoT Device Supply Chain
Device SKU 2
Device SKU 2
Device SKU 2
Device SKU 2
Device SKU 2
Device SKU 2
Device SKU
Customer 1
Custom SKUs
Custom SKUs
Custom SKUs
FDO Late Binding
Device Identity
Build-to-order
Manufacturing
Infrastructure
Build-to-plan
Manufacturing
Infrastructure
Binding info
Binding info
Devices
Customer 2
Devices
Customer n
Devices
Customer 1
Devices
Customer 2
Devices
Customer n
Devices
Zero Touch without FDO
IoT device software and security
customization happens during
manufacturing
Result:
Complicated build-to-order
manufacturing infrastructure,
many SKUs, small lot sizes, long
lead times, higher cost
Zero Touch with FDO
IoT device software and
security customization
happens at the end of the
supply chain
Benefits:
Simplified build-to-plan
manufacturing infrastructure,
fewer SKUs, large lot sizes,
enable stocking distributors,
low customization cost
Result: Increased supply chain
volume and velocity
IoT Device Supply Chain
Single SKU
Late binding reduces costs & complexity in supply chain – a single device SKU for all customers
© FIDO Alliance 2021
Aligning FIDO IOT to Use Case and Ecosystem
14
CSP & On-prem
Support
IoT Platform
ISV Suite
Silicon/device
Ecosystem
SI Ready
Connectivity
Support
Use cases where FIDO IOT delivers maximum value
• Industrial and Enterprise devices:
Gateways, servers, sensors, actuators, control systems, medical, etc.
• Multi-ecosystem applications and services:
not tied to specific cloud/platform framework
• Distributor sales:
deliver from stock, specify binding info after sale to customer
• Device resale / redeploy:
reset to factory conditions repeat onboarding process with new credentials
© FIDO Alliance 2021
How FDO Works
15
Build and Ship FDO
Enabled Devices
1
Register Ownership
to Target Platform
2
Register Device to
Rendezvous Service
3
Devices use FDO to
find owner location
4
Devices Authenticated
and Provisioned
5
Devices send sensor
data to IoT Platform
6
Device Recipient
3
Load Owner Voucher
at Procurement
Supply Chain
5
Late Binding Provisioning
1
Single SKU for Multiple
Target clouds
Registration
4
Target Cloud
(Device Management
System) with integrated
FDO Owner
Rendezvous
service
IoT Device
Device Manufacturer
2
6
© FIDO Alliance 2021
Processor
e.g. Intel, Arm
VARs
Distribution SI
Manufacturing Tool
(includes supply chain
tools)
Client for Arm, Intel,
other processors and
TPM
FDO Owner
(IoT Platform SDK)
Rendezvous server
(runs on Cloud or customer
premise)
FDO – Major Software Components
IOT Device
Reseller tool
IN
T
E
L
®
S
E
C
U
R
E
D
E
V
IC
E
O
N
B
O
A
R
D
FDO
Rendezvous
Server
Target Cloud
(Internet or on-premise)
2
1
5
3
4
© FIDO Alliance 2021
FDO/SDO: LF-Edge project & Open Source
17
The LF Edge Project is an open source implementation of the FDO
onboarding specification as a reference/gold implementation.
https://www.lfedge.org/projects/securedeviceonboard/
 Status
• LF Edge accepted Secure Device Onboard as a Phase 1 (At Large) project
• Project now active on LF-Edge web site.
• Code now Open Source https://github.com/secure-device-onboard
• Protocol testing release of FDO RD01; production release of FDO 1.0 2H21
© FIDO Alliance 2021
Drive industry adoption by building broad industry support across End
users, OEMs, ODMs, silicon partners, etc.
Launch FDO certification programs later this year.
• Functional certification testing
• Security certification testing
Continue work on v.next based on implementation feedback and to
address additional requirements
Goals for 2021
18
© FIDO Alliance 2021
o FIDO has an established security certification program for existing FIDO
authenticator specifications (UAF, U2F, FIDO 2.0/Webauthn)
o Levels that correspond to achievable security assurance
o L1 – Based on vendor questionnaire
o SW authenticators, e.g. from an app store
o L2 – Design documentation submitted by vendor and assessed by 3rd-party certification lab
o Authenticators developed in a trusted SW environment
o L3 – Sample device submitted to 3rd-party lab for verification of design and additional
penetration testing
o Authenticators instantiated in a secure element
Certification and Security
19
© FIDO Alliance 2021
o Multiple security certification levels also appropriate for IoT devices, given
large scope of achievable levels of security assurance
o Simple devices with
o Limited crypto capabilities
o No isolation of HW/SW required for security functionality
o More complex devices
o Advanced crypto capabilities (comparable to smartphones or PC’s)
o Isolation of security-impacting SW
o Special purpose HW for all secure operations related to onboarding
Certification (cont.)
20
© FIDO Alliance 2021
o FIDO is developing interoperability and security certification programs
o Anticipated rollout before end of year, 2021
o FIDO security certification will be assessed against regional regulatory
requirements
o Existing FIDO security certification leverages ‘companion’ programs
o e.g Common Criteria Protection Profiles
o FIDO expects to leverage existing IoT security certification programs as potential companion
programs
Certification (cont.)
21
© FIDO Alliance 2021
• The FIDO Alliance has a successful track record of bringing standards to market.
• FDO addresses the challenge of secure device onboarding – key to IoT growth
• FDO has been driven by Cloud, Semiconductor and Security leaders.
• FDO open-source software on LF-Edge; alpha code today, full release mid-21.
• You can download the specification and the software today to start using and
applying FDO.
• Interested in driving the evolution of FDO? Join FIDO Alliance today!
Summary
22
© FIDO Alliance 2021
Questions?
23

More Related Content

What's hot (20)

PDF
Dockerイメージ管理の内部構造
Etsuji Nakai
 
PPTX
コンテナネットワーキング(CNI)最前線
Motonori Shindo
 
PDF
OpenID Connect 入門 〜コンシューマーにおけるID連携のトレンド〜
Masaru Kurahayashi
 
PDF
LINE Login総復習
Naohiro Fujie
 
PPTX
KeycloakでAPI認可に入門する
Hitachi, Ltd. OSS Solution Center.
 
PDF
20231109_OpenID_TechNight_OpenID_Federation.pdf
OpenID Foundation Japan
 
PDF
Network Function Virtualization (NFV) using IOS-XR
Cisco Canada
 
PDF
What are Passkeys.pdf
Keiko Itakura
 
PPTX
Keycloakのステップアップ認証について
Hitachi, Ltd. OSS Solution Center.
 
PPTX
Process Monitor の使い方
彰 村地
 
PDF
より速く より運用しやすく 進化し続けるJVM(Java Developers Summit Online 2023 発表資料)
NTT DATA Technology & Innovation
 
PPTX
10分でわかるOpenAPI V3
Kazuchika Sekiya
 
PDF
"SRv6の現状と展望" ENOG53@上越
Kentaro Ebisawa
 
PPT
Javaバイトコード入門
Kota Mizushima
 
PDF
Qemu Introduction
Chiawei Wang
 
PDF
究極のゲーム用通信プロトコルを探せ!
Ryosuke Otsuya
 
PDF
JS7 JobScheduler プレビュー
OSSラボ株式会社
 
PDF
Open Liberty: オープンソースになったWebSphere Liberty
Takakiyo Tanaka
 
PDF
macOSの仮想化技術について ~Virtualization-rs Rust bindings for virtualization.framework ~
NTT Communications Technology Development
 
PDF
ネットワーク ゲームにおけるTCPとUDPの使い分け
モノビット エンジン
 
Dockerイメージ管理の内部構造
Etsuji Nakai
 
コンテナネットワーキング(CNI)最前線
Motonori Shindo
 
OpenID Connect 入門 〜コンシューマーにおけるID連携のトレンド〜
Masaru Kurahayashi
 
LINE Login総復習
Naohiro Fujie
 
KeycloakでAPI認可に入門する
Hitachi, Ltd. OSS Solution Center.
 
20231109_OpenID_TechNight_OpenID_Federation.pdf
OpenID Foundation Japan
 
Network Function Virtualization (NFV) using IOS-XR
Cisco Canada
 
What are Passkeys.pdf
Keiko Itakura
 
Keycloakのステップアップ認証について
Hitachi, Ltd. OSS Solution Center.
 
Process Monitor の使い方
彰 村地
 
より速く より運用しやすく 進化し続けるJVM(Java Developers Summit Online 2023 発表資料)
NTT DATA Technology & Innovation
 
10分でわかるOpenAPI V3
Kazuchika Sekiya
 
"SRv6の現状と展望" ENOG53@上越
Kentaro Ebisawa
 
Javaバイトコード入門
Kota Mizushima
 
Qemu Introduction
Chiawei Wang
 
究極のゲーム用通信プロトコルを探せ!
Ryosuke Otsuya
 
JS7 JobScheduler プレビュー
OSSラボ株式会社
 
Open Liberty: オープンソースになったWebSphere Liberty
Takakiyo Tanaka
 
macOSの仮想化技術について ~Virtualization-rs Rust bindings for virtualization.framework ~
NTT Communications Technology Development
 
ネットワーク ゲームにおけるTCPとUDPの使い分け
モノビット エンジン
 

Similar to Introducing FIDO Device Onboard (FDO) (20)

PPTX
Solving the IoT Challenge
FIDO Alliance
 
PDF
Introduction to FDO and How It works Applications _ Richard at FIDO Alliance.pdf
FIDO Alliance
 
PDF
The Value of Certifying Products for FDO _ Paul at FIDO Alliance.pdf
FIDO Alliance
 
PPTX
Webinar: Securing IoT with FIDO Authentication
FIDO Alliance
 
PPTX
FIDO: The Value of Certification
FIDO Alliance
 
PDF
Where to Learn More About FDO _ Richard at FIDO Alliance.pdf
FIDO Alliance
 
PPTX
FIDO Masterclass
FIDO Alliance
 
PPTX
Security Testing for IoT Systems
Security Innovation
 
PDF
Safety reliability and security lessons from defense for IoT
IoT613
 
PDF
Choosing the Right FDO Deployment Model for Your Application _ Geoffrey at In...
FIDO Alliance
 
PPTX
Removing Security Roadblocks to IoT Deployment Success
Microsoft Tech Community
 
PDF
FIDO Alliance Osaka Seminar: Overview.pdf
FIDO Alliance
 
PPTX
FIDO Munich Seminar FIDO Automotive Apps.pptx
FIDO Alliance
 
PPTX
Security for iot and cloud aug 25b 2017
Ulf Mattsson
 
PDF
The Future of Authentication for IoT
FIDO Alliance
 
PPTX
IoT Security: Debunking the "We Aren't THAT Connected" Myth
Security Innovation
 
PDF
ASRock Industrial FDO Solutions in Action for Industrial Edge AI _ Kenny at A...
FIDO Alliance
 
PPTX
Webinar: Catch Up with FIDO Plus AMA Session
FIDO Alliance
 
PPTX
FIDO Alliance Webinar: Catch Up WIth FIDO
FIDO Alliance
 
PPTX
Are we ready for IoT? VU Version 7
Jorge Sebastiao
 
Solving the IoT Challenge
FIDO Alliance
 
Introduction to FDO and How It works Applications _ Richard at FIDO Alliance.pdf
FIDO Alliance
 
The Value of Certifying Products for FDO _ Paul at FIDO Alliance.pdf
FIDO Alliance
 
Webinar: Securing IoT with FIDO Authentication
FIDO Alliance
 
FIDO: The Value of Certification
FIDO Alliance
 
Where to Learn More About FDO _ Richard at FIDO Alliance.pdf
FIDO Alliance
 
FIDO Masterclass
FIDO Alliance
 
Security Testing for IoT Systems
Security Innovation
 
Safety reliability and security lessons from defense for IoT
IoT613
 
Choosing the Right FDO Deployment Model for Your Application _ Geoffrey at In...
FIDO Alliance
 
Removing Security Roadblocks to IoT Deployment Success
Microsoft Tech Community
 
FIDO Alliance Osaka Seminar: Overview.pdf
FIDO Alliance
 
FIDO Munich Seminar FIDO Automotive Apps.pptx
FIDO Alliance
 
Security for iot and cloud aug 25b 2017
Ulf Mattsson
 
The Future of Authentication for IoT
FIDO Alliance
 
IoT Security: Debunking the "We Aren't THAT Connected" Myth
Security Innovation
 
ASRock Industrial FDO Solutions in Action for Industrial Edge AI _ Kenny at A...
FIDO Alliance
 
Webinar: Catch Up with FIDO Plus AMA Session
FIDO Alliance
 
FIDO Alliance Webinar: Catch Up WIth FIDO
FIDO Alliance
 
Are we ready for IoT? VU Version 7
Jorge Sebastiao
 
Ad

More from FIDO Alliance (20)

PPTX
Securing Account Lifecycles in the Age of Deepfakes.pptx
FIDO Alliance
 
PPTX
FIDO Seminar: Perspectives on Passkeys & Consumer Adoption.pptx
FIDO Alliance
 
PPTX
FIDO Seminar: Evolving Landscape of Post-Quantum Cryptography.pptx
FIDO Alliance
 
PPTX
FIDO Seminar: Targeting Trust: The Future of Identity in the Workforce.pptx
FIDO Alliance
 
PPTX
FIDO Seminar: New Data: Passkey Adoption in the Workforce.pptx
FIDO Alliance
 
PPTX
FIDO Seminar: Authentication for a Billion Consumers - Amazon.pptx
FIDO Alliance
 
PPTX
FIDO Alliance Seminar State of Passkeys.pptx
FIDO Alliance
 
PPTX
FIDO Munich Seminar: FIDO Tech Principles.pptx
FIDO Alliance
 
PPTX
FIDO Munich Seminar: Securing Smart Car.pptx
FIDO Alliance
 
PPTX
FIDO Munich Seminar: Strong Workforce Authn Push & Pull Factors.pptx
FIDO Alliance
 
PPTX
FIDO Munich Seminar: Biometrics and Passkeys for In-Vehicle Apps.pptx
FIDO Alliance
 
PPTX
FIDO Munich Seminar Workforce Authentication Case Study.pptx
FIDO Alliance
 
PPTX
FIDO Munich Seminar In-Vehicle Payment Trends.pptx
FIDO Alliance
 
PPTX
FIDO Munich Seminar Blueprint for In-Vehicle Payment Standard.pptx
FIDO Alliance
 
PPTX
FIDO Munich Seminar Introduction to FIDO.pptx
FIDO Alliance
 
PPTX
UX Webinar Series: Essentials for Adopting Passkeys as the Foundation of your...
FIDO Alliance
 
PPTX
UX Webinar Series: Drive Revenue and Decrease Costs with Passkeys for Consume...
FIDO Alliance
 
PPTX
UX Webinar Series: Aligning Authentication Experiences with Business Goals
FIDO Alliance
 
PDF
FIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdf
FIDO Alliance
 
PDF
FIDO Alliance Osaka Seminar: LY-DOCOMO-KDDI-Mercari Panel.pdf
FIDO Alliance
 
Securing Account Lifecycles in the Age of Deepfakes.pptx
FIDO Alliance
 
FIDO Seminar: Perspectives on Passkeys & Consumer Adoption.pptx
FIDO Alliance
 
FIDO Seminar: Evolving Landscape of Post-Quantum Cryptography.pptx
FIDO Alliance
 
FIDO Seminar: Targeting Trust: The Future of Identity in the Workforce.pptx
FIDO Alliance
 
FIDO Seminar: New Data: Passkey Adoption in the Workforce.pptx
FIDO Alliance
 
FIDO Seminar: Authentication for a Billion Consumers - Amazon.pptx
FIDO Alliance
 
FIDO Alliance Seminar State of Passkeys.pptx
FIDO Alliance
 
FIDO Munich Seminar: FIDO Tech Principles.pptx
FIDO Alliance
 
FIDO Munich Seminar: Securing Smart Car.pptx
FIDO Alliance
 
FIDO Munich Seminar: Strong Workforce Authn Push & Pull Factors.pptx
FIDO Alliance
 
FIDO Munich Seminar: Biometrics and Passkeys for In-Vehicle Apps.pptx
FIDO Alliance
 
FIDO Munich Seminar Workforce Authentication Case Study.pptx
FIDO Alliance
 
FIDO Munich Seminar In-Vehicle Payment Trends.pptx
FIDO Alliance
 
FIDO Munich Seminar Blueprint for In-Vehicle Payment Standard.pptx
FIDO Alliance
 
FIDO Munich Seminar Introduction to FIDO.pptx
FIDO Alliance
 
UX Webinar Series: Essentials for Adopting Passkeys as the Foundation of your...
FIDO Alliance
 
UX Webinar Series: Drive Revenue and Decrease Costs with Passkeys for Consume...
FIDO Alliance
 
UX Webinar Series: Aligning Authentication Experiences with Business Goals
FIDO Alliance
 
FIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdf
FIDO Alliance
 
FIDO Alliance Osaka Seminar: LY-DOCOMO-KDDI-Mercari Panel.pdf
FIDO Alliance
 
Ad

Recently uploaded (20)

PDF
Responsible AI and AI Ethics - By Sylvester Ebhonu
Sylvester Ebhonu
 
PPTX
OA presentation.pptx OA presentation.pptx
pateldhruv002338
 
PDF
TrustArc Webinar - Navigating Data Privacy in LATAM: Laws, Trends, and Compli...
TrustArc
 
PPTX
cloud computing vai.pptx for the project
vaibhavdobariyal79
 
PPTX
AI Code Generation Risks (Ramkumar Dilli, CIO, Myridius)
Priyanka Aash
 
PPTX
Dev Dives: Automate, test, and deploy in one place—with Unified Developer Exp...
AndreeaTom
 
PDF
How Open Source Changed My Career by abdelrahman ismail
a0m0rajab1
 
PDF
The Future of Artificial Intelligence (AI)
Mukul
 
PDF
Make GenAI investments go further with the Dell AI Factory
Principled Technologies
 
PDF
introduction to computer hardware and sofeware
chauhanshraddha2007
 
PDF
Market Insight : ETH Dominance Returns
CIFDAQ
 
PPTX
Agentic AI in Healthcare Driving the Next Wave of Digital Transformation
danielle hunter
 
PDF
Trying to figure out MCP by actually building an app from scratch with open s...
Julien SIMON
 
PDF
Per Axbom: The spectacular lies of maps
Nexer Digital
 
PPTX
Applied-Statistics-Mastering-Data-Driven-Decisions.pptx
parmaryashparmaryash
 
PDF
Tea4chat - another LLM Project by Kerem Atam
a0m0rajab1
 
PDF
Google I/O Extended 2025 Baku - all ppts
HusseinMalikMammadli
 
PDF
OFFOFFBOX™ – A New Era for African Film | Startup Presentation
ambaicciwalkerbrian
 
PDF
State-Dependent Conformal Perception Bounds for Neuro-Symbolic Verification
Ivan Ruchkin
 
PDF
RAT Builders - How to Catch Them All [DeepSec 2024]
malmoeb
 
Responsible AI and AI Ethics - By Sylvester Ebhonu
Sylvester Ebhonu
 
OA presentation.pptx OA presentation.pptx
pateldhruv002338
 
TrustArc Webinar - Navigating Data Privacy in LATAM: Laws, Trends, and Compli...
TrustArc
 
cloud computing vai.pptx for the project
vaibhavdobariyal79
 
AI Code Generation Risks (Ramkumar Dilli, CIO, Myridius)
Priyanka Aash
 
Dev Dives: Automate, test, and deploy in one place—with Unified Developer Exp...
AndreeaTom
 
How Open Source Changed My Career by abdelrahman ismail
a0m0rajab1
 
The Future of Artificial Intelligence (AI)
Mukul
 
Make GenAI investments go further with the Dell AI Factory
Principled Technologies
 
introduction to computer hardware and sofeware
chauhanshraddha2007
 
Market Insight : ETH Dominance Returns
CIFDAQ
 
Agentic AI in Healthcare Driving the Next Wave of Digital Transformation
danielle hunter
 
Trying to figure out MCP by actually building an app from scratch with open s...
Julien SIMON
 
Per Axbom: The spectacular lies of maps
Nexer Digital
 
Applied-Statistics-Mastering-Data-Driven-Decisions.pptx
parmaryashparmaryash
 
Tea4chat - another LLM Project by Kerem Atam
a0m0rajab1
 
Google I/O Extended 2025 Baku - all ppts
HusseinMalikMammadli
 
OFFOFFBOX™ – A New Era for African Film | Startup Presentation
ambaicciwalkerbrian
 
State-Dependent Conformal Perception Bounds for Neuro-Symbolic Verification
Ivan Ruchkin
 
RAT Builders - How to Catch Them All [DeepSec 2024]
malmoeb
 

Introducing FIDO Device Onboard (FDO)

  • 1. © FIDO Alliance 2021 1 Introducing FIDO Device Onboard (FDO) May 7, 2021
  • 3. © FIDO Alliance 2021 Today’s Speakers Giri Mandyam Senior Director for Technology Qualcomm Co-Chair, IoT TWG Andrew Shikiar Executive Director & CMO FIDO Alliance Richard Kerslake General Manager Industrial Controls and Robotics, IOT Business Unit, Intel Co-Chair, IoT TWG
  • 4. © FIDO Alliance 2021 4 How the FIDO Alliance is Solving the IoT Onboarding Challenge
  • 5. © FIDO Alliance 2021 The FIDO Alliance brings together the world’s leading technology companies to develop and promote the adoption of a standardized, simpler, and more secure online experience that installs trust and confidence in a digital world. 5
  • 6. © FIDO Alliance 2021 + Sponsor members + Associate members + Liaison members 6
  • 7. © FIDO Alliance 2021 Track record of successful collaboration 7 Growing Platform Support Hello 3 Sets of Specs Released Increasing Market Adoption
  • 8. © FIDO Alliance 2021 8 How long does it take to manually onboard1 10,000 Gateways, Devices, Sensors? Answer: Over 2-man years2 1. Assumes out-of-box to securely streaming data to an IoT Platform 2. Kaiser Associates Research and Analysis, IoT study, August 2017
  • 9. © FIDO Alliance 2021 The Onboarding Challenge 9 • Wide variety of IOT devices – hardware and Operating Systems • Most devices headless (i.e. don’t have displays) • Different connectivity – wired / wireless • Manual installation adds cost and time to IOT deployments, impacting program ROI • Manual installation requires trusted and skilled staff
  • 10. © FIDO Alliance 2021 Onboarding solutions exist today, but don’t fully meet the needs of the industry • Manual onboarding • Slow • Insecure • Expensive • Proprietary ‘zero touch’ • Linked to one cloud/platform • Only one silicon provider • Require programming of target platform/cloud/user at manufacture Onboarding solutions today 10
  • 11. © FIDO Alliance 2021 The FIDO Alliance launched the IoT Technical Working Group (IoT TWG) in June 2019 - members include leading Cloud Service Providers, semiconductor manufacturers, security specialists and OEMs. The IoT TWG analyzed multiple use cases, target architectures and specifications to develop as clear set of requirements. Intel contributed their Secure Device Onboard specification, which served as the starting point for FIDO’s IoT work - the TWG modified and extended the initial specification to meet the defined requirements. FIDO’s Approach to Secure IoT 11 NEWS - The FIDO Device Onboard specification is now available: https://fidoalliance.org/specs/FDO/fido-device-onboard-v1.0-ps-20210323/fido-device-onboard-v1.0-ps-20210323.html
  • 12. © FIDO Alliance 2021 Fast, Scalable Device Provisioning, Onboarding & Activation 12 Drop ship device to installation location Power-up & connect to Network Auto-provisions, Onboards to Cloud BENEFITS1 • Zero touch onboarding – integrates readily with existing zero touch solutions • Fast & more secure1 – ~1 minute • Hardware flexibility – any hardware (from ARM MCU to Intel® Xeon® processors) • Any cloud – internet & on-premise • Late binding - of device to cloud greatly reduces number of SKUs vs. other zero touch offerings • Open - LF-Edge SDO project up and running, code now on GitHub 12 1. No product or component can be absolutely secure
  • 13. © FIDO Alliance 2021 FIDO Device Onboard: Late Binding in Supply Chain 13 IoT Device Supply Chain Device SKU 2 Device SKU 2 Device SKU 2 Device SKU 2 Device SKU 2 Device SKU 2 Device SKU Customer 1 Custom SKUs Custom SKUs Custom SKUs FDO Late Binding Device Identity Build-to-order Manufacturing Infrastructure Build-to-plan Manufacturing Infrastructure Binding info Binding info Devices Customer 2 Devices Customer n Devices Customer 1 Devices Customer 2 Devices Customer n Devices Zero Touch without FDO IoT device software and security customization happens during manufacturing Result: Complicated build-to-order manufacturing infrastructure, many SKUs, small lot sizes, long lead times, higher cost Zero Touch with FDO IoT device software and security customization happens at the end of the supply chain Benefits: Simplified build-to-plan manufacturing infrastructure, fewer SKUs, large lot sizes, enable stocking distributors, low customization cost Result: Increased supply chain volume and velocity IoT Device Supply Chain Single SKU Late binding reduces costs & complexity in supply chain – a single device SKU for all customers
  • 14. © FIDO Alliance 2021 Aligning FIDO IOT to Use Case and Ecosystem 14 CSP & On-prem Support IoT Platform ISV Suite Silicon/device Ecosystem SI Ready Connectivity Support Use cases where FIDO IOT delivers maximum value • Industrial and Enterprise devices: Gateways, servers, sensors, actuators, control systems, medical, etc. • Multi-ecosystem applications and services: not tied to specific cloud/platform framework • Distributor sales: deliver from stock, specify binding info after sale to customer • Device resale / redeploy: reset to factory conditions repeat onboarding process with new credentials
  • 15. © FIDO Alliance 2021 How FDO Works 15 Build and Ship FDO Enabled Devices 1 Register Ownership to Target Platform 2 Register Device to Rendezvous Service 3 Devices use FDO to find owner location 4 Devices Authenticated and Provisioned 5 Devices send sensor data to IoT Platform 6 Device Recipient 3 Load Owner Voucher at Procurement Supply Chain 5 Late Binding Provisioning 1 Single SKU for Multiple Target clouds Registration 4 Target Cloud (Device Management System) with integrated FDO Owner Rendezvous service IoT Device Device Manufacturer 2 6
  • 16. © FIDO Alliance 2021 Processor e.g. Intel, Arm VARs Distribution SI Manufacturing Tool (includes supply chain tools) Client for Arm, Intel, other processors and TPM FDO Owner (IoT Platform SDK) Rendezvous server (runs on Cloud or customer premise) FDO – Major Software Components IOT Device Reseller tool IN T E L ® S E C U R E D E V IC E O N B O A R D FDO Rendezvous Server Target Cloud (Internet or on-premise) 2 1 5 3 4
  • 17. © FIDO Alliance 2021 FDO/SDO: LF-Edge project & Open Source 17 The LF Edge Project is an open source implementation of the FDO onboarding specification as a reference/gold implementation. https://www.lfedge.org/projects/securedeviceonboard/  Status • LF Edge accepted Secure Device Onboard as a Phase 1 (At Large) project • Project now active on LF-Edge web site. • Code now Open Source https://github.com/secure-device-onboard • Protocol testing release of FDO RD01; production release of FDO 1.0 2H21
  • 18. © FIDO Alliance 2021 Drive industry adoption by building broad industry support across End users, OEMs, ODMs, silicon partners, etc. Launch FDO certification programs later this year. • Functional certification testing • Security certification testing Continue work on v.next based on implementation feedback and to address additional requirements Goals for 2021 18
  • 19. © FIDO Alliance 2021 o FIDO has an established security certification program for existing FIDO authenticator specifications (UAF, U2F, FIDO 2.0/Webauthn) o Levels that correspond to achievable security assurance o L1 – Based on vendor questionnaire o SW authenticators, e.g. from an app store o L2 – Design documentation submitted by vendor and assessed by 3rd-party certification lab o Authenticators developed in a trusted SW environment o L3 – Sample device submitted to 3rd-party lab for verification of design and additional penetration testing o Authenticators instantiated in a secure element Certification and Security 19
  • 20. © FIDO Alliance 2021 o Multiple security certification levels also appropriate for IoT devices, given large scope of achievable levels of security assurance o Simple devices with o Limited crypto capabilities o No isolation of HW/SW required for security functionality o More complex devices o Advanced crypto capabilities (comparable to smartphones or PC’s) o Isolation of security-impacting SW o Special purpose HW for all secure operations related to onboarding Certification (cont.) 20
  • 21. © FIDO Alliance 2021 o FIDO is developing interoperability and security certification programs o Anticipated rollout before end of year, 2021 o FIDO security certification will be assessed against regional regulatory requirements o Existing FIDO security certification leverages ‘companion’ programs o e.g Common Criteria Protection Profiles o FIDO expects to leverage existing IoT security certification programs as potential companion programs Certification (cont.) 21
  • 22. © FIDO Alliance 2021 • The FIDO Alliance has a successful track record of bringing standards to market. • FDO addresses the challenge of secure device onboarding – key to IoT growth • FDO has been driven by Cloud, Semiconductor and Security leaders. • FDO open-source software on LF-Edge; alpha code today, full release mid-21. • You can download the specification and the software today to start using and applying FDO. • Interested in driving the evolution of FDO? Join FIDO Alliance today! Summary 22
  • 23. © FIDO Alliance 2021 Questions? 23