Device Provisioning (Onboarding)
Device provisioning is the process of securely enrolling a new IoT or edge device into a system, giving it a trusted identity, credentials, network settings and configuration so that it can connect and be managed throughout its life.
Provisioning typically begins with a device identity established at manufacture, such as a unique X.509 certificate and private key stored in a secure element or Trusted Platform Module. When installed, the device proves this identity to a provisioning service, which registers it, issues or confirms operational credentials, assigns it to the correct network, broker, tenant or application and applies initial configuration. Zero-touch provisioning automates these steps so that installers need not enter credentials manually; the FIDO Device Onboard specification is one open approach.
Industrial deployments may involve thousands of sensors, gateways and edge devices across many sites. Consistent provisioning prevents shared default passwords, ensures each device can be individually authenticated and revoked, and links devices to their asset records and locations. Cloud IoT platforms, LwM2M bootstrap servers and LoRaWAN join procedures all provide provisioning mechanisms.
The security of provisioning depends on protecting manufacturing secrets, establishing trust between the device maker and the operator, and handling ownership transfer when devices are resold or repurposed. Certificate lifetimes, renewal and revocation must be planned from the start. Decommissioning, which removes credentials and data from retired devices, is part of the same life cycle, and IEC 62443-4-2 sets security requirements for industrial components, including identification and authentication.
Key points
- Securely enrols devices with identity, credentials and configuration
- Unique identities are often stored in secure elements or TPMs
- Zero-touch provisioning removes manual credential entry
- Avoids shared default passwords and enables per-device revocation
- Plan certificate renewal, revocation and decommissioning from the start
Where AiVibe comes in
AiAmbA IoT is AiVibe's edge protocol layer: it discovers devices and normalises industrial signals, with supported protocols including Siemens S7, Mitsubishi MC, Delta Modbus, OPC UA and MQTT, and driver availability confirmed per installation. Writes to machines are deny-by-default.
Related terms
- Over-the-Air (OTA) UpdateIndustrial IoT & Edge
- LwM2M (Lightweight M2M)Industrial IoT & Edge
- Industrial IoT GatewayIndustrial IoT & Edge
- IEC 62443 (ISA/IEC 62443)OT & Industrial Cybersecurity
- Zero Trust Architecture (ZTA)Cybersecurity & Compliance
- LoRaWANIndustrial IoT & Edge