Device Provisioning
Getting identity and configuration onto hardware at manufacture or first boot.
4 to work through
-
intermediate
A consumer device sells 600,000 units in the fourth quarter and most of them are gifts. Roughly how many first-boot provisioning requests per second should the platform be sized for on the morning of 25 December, and what does the number rule out?
3 min answer -
intermediate
Devices are provisioned on a contract manufacturer's line: each unit boots, calls your cloud provisioning service, receives a unique certificate, and is boxed. At 02:00 on a Saturday your provisioning service becomes unreachable from that factory. The line runs three shifts and cannot stop. What happens next, and what should the design have been?
3 min answer -
advanced
A fleet of connected devices needs credentials. What does secure provisioning require, and what is the failure that ends the programme?
2 min answer -
advanced
Design provisioning for devices manufactured in volume and deployed by non-technical installers.
1 min answer
3 terms in this topic
Claim-Code Binding
Giving a device its cryptographic identity at manufacture but its owner at first use, so the factory line never depends on the cloud and ownership ca…
practiceDevice Provisioning
Giving a device a unique cryptographic identity and its initial configuration in a way that scales to millions and survives a hostile supply chain.
patternZero-Touch Provisioning
A device obtaining its identity, configuration and assignment automatically on first connection, so that installation requires no technical procedure…
Neighbouring topics
Edge, Mobile & IoT
General material on architecture beyond the data centre boundary.
Mobile App Architecture
Layering, navigation, background execution, and the platform rules you do not set.
Offline-First
Treating connectivity as an optimisation, with a local store as the source of truth.
Sync & Conflict Resolution
Two devices that both changed the same record while neither could see the other.
CRDTs
Data types that converge without coordination, and the semantics you must accept.
Mobile Release Strategy
Store review, staged rollout, and supporting versions you can never force off.
Push & Background Work
Delivery that is best-effort, and an operating system that will kill your process.
Device Identity
Identifying a thing rather than a person, and rotating a credential you cannot type.
Edge Compute Topologies
Regional, metro, on-premises and on-device, and what each tier is genuinely for.
Edge Functions
Short-lived compute at the CDN, its runtime limits, and what must stay at origin.
Edge Data Consistency
Replicated read state at hundreds of locations, and writes that still go to one.
IoT Ingest Architecture
Millions of small, unreliable, frequently duplicated messages arriving continuously.
Fleet Management
Inventory, health, configuration and grouping across devices you will never see.
OTA Updates
Updating firmware over a flaky link, with rollback, and without bricking the device.
Constrained Protocols
MQTT, CoAP and their kin, chosen for power, packet size and intermittent links.
Device Telemetry at Scale
Deciding what a device sends, how often, and what is aggregated before it leaves.
Digital Twin
A server-side model of a physical thing's reported and desired state.
Edge Security & Attestation
Secure boot, hardware roots of trust, and proving what is running on a device.
Physical-World Failure Modes
Power loss, tampering, clock drift, thermal limits, and a truck through the fibre.