intermediate 3 min answer

A consumer device sells 600,000 units in the fourth quarter and most of them are gifts. Roughly how many first-boot provisioning requests per second should the platform be sized for on the morning of 25 December, and what does the number rule out?

provisioningcapacitycertificatesactivationota
Show the full answer Hide the answer

The assumptions, stated

  • About 70% of the quarter's units are unopened until the holiday, so roughly 420,000 first boots fall in a three-day window.
  • Gift opening is concentrated: assume 25% of those activations land in a single hour, in one or two adjacent time zones.
  • Within that hour, arrivals are not flat. A peak-to-mean factor of 3 is the usual planning allowance for human-driven bursts.
  • Each activation is one certificate signing request, one registry write, one configuration fetch, and a firmware version check.

The arithmetic

105,000 activations in the peak hour is about 29 per second on average, so plan for roughly 90 per second at the peak minute, with a defensible range of 50 to 200 depending entirely on the concentration assumption.

The second number is the one that hurts. If 60% of those devices find themselves on firmware older than the current release and download it immediately, and the image is 8 MB, that is 63,000 × 8 MB in the hour, or about 500 GB, which is roughly 1.1 Gbit/s of sustained egress on top of the provisioning path.

Which assumption dominates the error

The share of activations in the peak hour, by a wide margin. Everything else moves the answer by tens of percent; that assumption can be wrong by a factor of five in either direction. Measure it once in a pilot and the estimate stops being a guess for every later product.

What the number rules in and out

  • Signing is not the constraint. 90 EC signatures per second is unremarkable even for a cloud HSM, which handles on the order of hundreds to low thousands per second per partition. Spend the design effort elsewhere.
  • Synchronous firmware update during activation is ruled out. It couples the slowest, largest operation to the one moment the customer is watching, and it is what turns a 90 per second path into a gigabit problem. Prefer deferring the first update by a random interval across 24 hours, which brings the gigabit down to about 50 Mbit/s.
  • A provisioning path that cannot start from cold is ruled out. This traffic arrives on the one day of the year when the service has been idle: empty caches, no warm connection pools, scale-to-zero functions, per-request HSM session setup. The failure is a thundering first minute against a cold tier, not steady-state capacity.
  • Queue the irreversible step. Accept the signing request, return a short retry instruction, and sign asynchronously. The device is already designed to retry; the customer is not watching a certificate.

When this is the wrong estimate

For an industrial product installed by technicians on weekdays, activations are nearly uniform and none of this applies, because the concentration factor is a property of how the product reaches people rather than of the fleet size. It is the only input worth arguing about in the design review.

Two cautions on the figures. Prices and platform behaviour move: the egress and HSM throughput ranges here are 2025 orders of magnitude, not quotes, and both should be re-derived from the current tariff before anyone commits capacity. And the estimate buys a decision rather than a number: it costs an afternoon, and it prevents a design where the irreversible step is synchronous and the largest transfer happens while the customer watches.