Device Identity
Identifying a thing rather than a person, and rotating a credential you cannot type.
5 to work through
-
intermediate
Review this design. A delivery-partner app on low-end Android phones reads a device identifier from the operating system at launch and uses it as the primary key of a devices table. The row holds the partner's current shift, an offline cash ledger and a per-device fraud limit. The identifier is Android SSAID or iOS identifierForVendor depending on platform. What would you remove, what would you change, and what would you leave alone?
3 min answer -
advanced
A fleet of devices has certificates expiring in two years. What must be true today for that not to be an incident?
2 min answer -
advanced
Design identity for devices that must authenticate to a platform for years, without a human present.
1 min answer -
advanced
How should device identity be established and maintained for a fleet, and what fails when it is done casually?
2 min answer -
advanced
You inherit an IoT fleet of 80,000 devices whose client certificates all expire in fourteen months. What do you do?
2 min answer
2 terms in this topic
Device Identity
Establishing and maintaining a trustworthy identity for each device in a fleet — including the parts that must work for a decade without physical access.
conceptHardware Backed Credential
A private key generated inside a secure element and unable to leave it, so device identity cannot be copied off the device.
Neighbouring topics
Edge, Mobile & IoT
General material on architecture beyond the data centre boundary.
Mobile App Architecture
Layering, navigation, background execution, and the platform rules you do not set.
Offline-First
Treating connectivity as an optimisation, with a local store as the source of truth.
Sync & Conflict Resolution
Two devices that both changed the same record while neither could see the other.
CRDTs
Data types that converge without coordination, and the semantics you must accept.
Mobile Release Strategy
Store review, staged rollout, and supporting versions you can never force off.
Push & Background Work
Delivery that is best-effort, and an operating system that will kill your process.
Edge Compute Topologies
Regional, metro, on-premises and on-device, and what each tier is genuinely for.
Edge Functions
Short-lived compute at the CDN, its runtime limits, and what must stay at origin.
Edge Data Consistency
Replicated read state at hundreds of locations, and writes that still go to one.
IoT Ingest Architecture
Millions of small, unreliable, frequently duplicated messages arriving continuously.
Device Provisioning
Getting identity and configuration onto hardware at manufacture or first boot.
Fleet Management
Inventory, health, configuration and grouping across devices you will never see.
OTA Updates
Updating firmware over a flaky link, with rollback, and without bricking the device.
Constrained Protocols
MQTT, CoAP and their kin, chosen for power, packet size and intermittent links.
Device Telemetry at Scale
Deciding what a device sends, how often, and what is aggregated before it leaves.
Digital Twin
A server-side model of a physical thing's reported and desired state.
Edge Security & Attestation
Secure boot, hardware roots of trust, and proving what is running on a device.
Physical-World Failure Modes
Power loss, tampering, clock drift, thermal limits, and a truck through the fibre.