1. Device Identity advanced

    Design identity for devices that must authenticate to a platform for years, without a human present.

    1 min answer device-identitycertificatesrotationprovisioning
  2. Device Identity advanced

    How should device identity be established and maintained for a fleet, and what fails when it is done casually?

    2 min answer iotidentityprovisioningattestation
  3. Device Identity intermediate

    Review this design. A delivery-partner app on low-end Android phones reads a device identifier from the operating system at launch and uses it as the primary key of a devices table. The row holds the partner's current shift, an offline cash ledger and a per-device fraud limit. The identifier is Android SSAID or iOS identifierForVendor depending on platform. What would you remove, what would you change, and what would you leave alone?

    3 min answer device-identityandroidiosfraud
  4. Device Identity advanced

    You inherit an IoT fleet of 80,000 devices whose client certificates all expire in fourteen months. What do you do?

    2 min answer iotcertificatesrotationrisk
  5. Device Provisioning intermediate

    A consumer device sells 600,000 units in the fourth quarter and most of them are gifts. Roughly how many first-boot provisioning requests per second should the platform be sized for on the morning of 25 December, and what does the number rule out?

    3 min answer provisioningcapacitycertificatesactivation
  6. Device Provisioning advanced Multiple choice

    A fleet of 180000 building controllers all authenticate to the platform with one shared enrolment secret compiled into the firmware. That secret has just appeared in a public teardown writeup. The devices are on cellular links, about 6% are offline at any moment, and a failed credential change means a site visit costing more than the controller. Which migration sequence do you run?

    4 min answer device-provisioningcredential-rotationsecure-elementmigration
  7. Device Provisioning advanced

    A fleet of connected devices needs credentials. What does secure provisioning require, and what is the failure that ends the programme?

    2 min answer atheridentityprovisioningrotation
  8. Device Provisioning advanced

    Design provisioning for devices manufactured in volume and deployed by non-technical installers.

    1 min answer provisioningbootstrapsupply-chainidentity
  9. Device Provisioning intermediate

    Devices are provisioned on a contract manufacturer's line: each unit boots, calls your cloud provisioning service, receives a unique certificate, and is boxed. At 02:00 on a Saturday your provisioning service becomes unreachable from that factory. The line runs three shifts and cannot stop. What happens next, and what should the design have been?

    3 min answer provisioningmanufacturingavailabilitycertificates
  10. Device Telemetry at Scale advanced

    A fleet platform emits 25 metric series per device, tagged with device id, for 400,000 devices. The observability bill is now larger than the compute bill for the platform itself. The team proposes dropping the device id tag and keeping per-model and per-region aggregates. What does that buy, what does it give up, and when does the bill arrive?

    3 min answer cardinalitytelemetrycostdiagnosis
  11. Device Telemetry at Scale advanced

    A logistics platform receives location updates from a large fleet every few seconds. Where should volume be reduced, and what is the ordering of leverage?

    2 min answer delhiveryportertelemetryfiltering
  12. Device Telemetry at Scale advanced

    A ride-hailing platform receives location updates from hundreds of thousands of active drivers every few seconds. Design the ingest and serving path.

    2 min answer ubergeospatialingestionreal-time