SlideShare a Scribd company logo
1 of 14
Download to read offline
© 2022, Amazon Web Services, Inc. or its affiliates.
© 2023, Amazon Web Services, Inc. or its affiliates.
Enabling Supply Chain Flexibility
and IoT Scale with Zero Touch
Provisioning
S E S S I O N 1 . 2
© 2022, Amazon Web Services, Inc. or its affiliates.
Speakers
Ben Cooke
Partner Solutions Architect
IoT & Edge
Thomas Lorenser
Director GPC Compute Marketing
ARM
Marco Carrer
CTO
Eurotech
© 2022, Amazon Web Services, Inc. or its affiliates.
IoT Device Birth to Service Journey
Component
Supply Chain
Manufacturer Distributor Integrator Installer
Months to Years
A lot can change with a business in this time…
© 2022, Amazon Web Services, Inc. or its affiliates.
IoT Device Birth to Service Journey
Fleet
Operator
Device
Manufacturer
≠
© 2022, Amazon Web Services, Inc. or its affiliates.
IoT Device Life-Cycle Use Cases
2. Offline provisioning in the supply chain
1. Provisioning device at time of install
3. Factory refurbishment and migration
of previously fielded devices
4. Disaster recovery orchestration
© 2022, Amazon Web Services, Inc. or its affiliates.
The device identity “blob”
Device Identifier(s) – Serial Number, etc
Device Root
Identity Cert
Device Service Cert
Device Root
Pub/Priv Keys
Device Service
Pub/Priv Keys
Factory Meta Data – Default SW Version, config, etc
Cloud Meta Data – Groups, roles, account, etc
Device
Manufacturer
Fleet
Operator
Operational Meta Data – SW Version, config, etc
© 2022, Amazon Web Services, Inc. or its affiliates.
Secure Device Identities (DevIDs)
IEEE 802.1AR Secure Device Identity
§ Globally unique-per-device identity
§ Unique-per-device secret (private key)
§ Cryptographically bound to a device
§ Public X.509 certificate w/ certificate chain
Initial Device ID (IDevID)
§ Attests Supply-Chain and Device Platform Integrity
§ Installed by OEM and signed by OEM CA
§ Certificate w/ device serial number, SAN, and Certificate
Policy
§ Certificate never expires
Local Device ID (LDevID)
§ Attests Device Ownership
§ Signed by Device Owner
§ Installed by Device Owner or OEM/Distributor on behalf
of Device Owner
§ Certificate long-lived
Operational Device Identity (OpDevID)
§ Authentication Credentials for IoT Service Connectivity
§ Signed by Device Owner CA trusted by IoT Service
§ Enrolled by the device firmware
§ Certificate short-lived
© 2022, Amazon Web Services, Inc. or its affiliates.
Device Identities
EK EK TPM Endorsement Key
TPM Endorsement Certificate
Seeded at TPM manufacturing
Certificate managed by TPM manufacturer
IDevID IDevID signing and
attestation key
IDevID Certificate signed by
OEM
Seeded at Device Manufacturing
Certificate managed by OEM PKI
Certificate never expires
LDevID LDevID signing and
attestation key
LDevID Certificate signed by
customer CA
Seeded at Device Enrollment.
Certificate managed by Customer PKI
Certificate long-lived
OpDevID Operational Device Identity
(OpDevID) OpDevID
authentication key
OpDevID Certificate signed by
Customer CA used by the IoT
Service
Seeded at Device Provisioning.
Certificate managed by
Customer PKI
Certificate short-lived
TPM 2.0 Control Domains
Endorsement
Hierarchy
(EH)
Owned by TPM
Manufacturer and
OEM
Platform
Hierarchy
(PH)
Owned by OEM
Storage
Hierarchy
(SH)
Owned by the end-
customer
Secure Device Storage
© 2022, Amazon Web Services, Inc. or its affiliates.
Manufacturing Facility
OEM
IDevID
Seed IDevID Key
Enroll IDevID Certificate
with OEM PKI
Store IDevID Cert in TPM PH
Distributor Facility
Global Distributor
LDevID
Seed LDevID Key
Enroll LDevID Certificate
with Customer PKI
Store LDevID Cert in TPM SH
Customer Site
Local Distributor
Install AWS IoT Greengrass
Configure AWS IoT Endpoints
Configure Network Access
Configure Edge Application(s)
Installation Site
Field Installer
OpDevID
Seed OpDevID
Enroll OpDevID Certficate
with Customer PKI
AWS IoT Core Just-in-time
provisioning (JITP)
Create the AWS IoT Thing
Create policy for IoT Thing
Attach policy to OpDevID
Update AWS IoT Greengrass
Remote Updates
Repurposing
Decommissioning
Over-the-air updates
maintain the device secure
Device Certificates are
renewed by device firmware
with the corresponding PKI
through the EST protocol
Repurposing within an
organization restores the
post-enrollment device state
Decommissioning restores
the post-manufacturing state
Manufacturing Enrollment Commissioning Provisioning Management
IoT Thing IoT Shadow
AWS IoT
Greengrass
AWS IoT
Core
AWS IoT
Provisioning
Lambda
Device Life-Cycle
© 2022, Amazon Web Services, Inc. or its affiliates.
From this…
1. Download AWS IoT Greengrass
2. Install AWS IoT Greengrass
3. Follow link to instruction
4. Configure AWS IoT Greengrass nucleus
5. Create the AWS IoT Thing
6. Create the certificate from a private
key in an HSM
7. Create a CSR for the AWS IoT Thing
8. Create a Certificate for the AWS IoT Thing
9. Create policy for IoT Thing and attach it to
certificate
10. Import the AWS IoT Thing Certificate into the HSM
11. Update the AWS IoT Greengrass Core configuration
Demo
… to Zero-touch AWS IoT
Secure Provisioning
1.
Commission
2.
Provision
3.
Connect
Secure Zero-Touch Provisioning
© 2022, Amazon Web Services, Inc. or its affiliates.
Demo Architecture
Eurotech ESF and AWS IoT Greengrass
Standard PKI
Hardened Everyware Linux (based on Yocto)
Secure Hardware (Secure CPU, TPM 2.0)
Digital Twins
Wires
Secure Firmware (u-boot, ARM Trusted Firmware)
Updates
Diagnostics
IEC 62443-4-2
PSA Level 1
PARSEC
Log Analytics
Fieldbus
Protocols
Security Manager
Application
Services
Device
Management
Services
Connectivity
Services
EST Enrollment
AWS IoT Core
Connector
Everyware Software Framework
AWS IoT
Greengrass
AWS IoT Greengrass Nucleus
AWS IoT Core
AWS IoT
SiteWise
AWS IoT
Device
Defender
Client device auth
MQTT Bridge
MQTT Broker
AWS IoT Device
Defender
AWS IoT
Device
Shadows
Device Management
Remote Access
AWS IoT
Analytics
EST
MQTT
MQTT
REST
Any other device
and sensor
Meters
Motor
controllers
Breakers and
switches
© 2022, Amazon Web Services, Inc. or its affiliates.
Demo Video
© 2022, Amazon Web Services, Inc. or its affiliates.
Eurotech’s key activities
@Embedded World 2023
Eurotech & InoNet
[ hall 3 booth #153 ]
Robotic arm demo:
AI on the edge & digital twin
in the cloud
Show edge computing / AI vision and IoT
capabilities of our edge devices (real-time
detection on the edge and digital twin
creation and remote management
in the cloud).
arm booth
[ hall 3 booth #153 ]
AWS booth
[ hall 4 booth #550 ]
Eurotech AWS Ducati Live demo
Purpose: The demo shows how a Substation Bay Control
Unit can be easily connected to an IoT Gateway and be
remotely controlled and monitored with a few easy steps,
leveraging the power of the integration between ESF and
AWS IoT Greengrass. From Zero-Touch-Provisioning to a
fully functional web dashboard and upstream integrations,
using a ReliaGATE 10-14, ESF, EC, and AWS IoT Greengrass.
ABB AWS Live demo
The demo shows a remote monitoring application on ABB
Electrification devices. It employs a Eurotech gateway
(ReliaGATE 10-14) connected to one (or more) ABB devices.
The data from the ABB devices are collected by the gateway and
sent to the Cloud (integration with Eurotech Everyware cloud and
AWS services), where they are displayed on a dashboard.
© 2022, Amazon Web Services, Inc. or its affiliates.
Thank you!
© 2022, Amazon Web Services, Inc. or its affiliates.

More Related Content

What's hot

Quality engineering in DevOps... Why? How? (TestBusters Day&Night))
Quality engineering in DevOps... Why? How? (TestBusters Day&Night))Quality engineering in DevOps... Why? How? (TestBusters Day&Night))
Quality engineering in DevOps... Why? How? (TestBusters Day&Night))Rik Marselis
 
Software Testing Process, Testing Automation and Software Testing Trends
Software Testing Process, Testing Automation and Software Testing TrendsSoftware Testing Process, Testing Automation and Software Testing Trends
Software Testing Process, Testing Automation and Software Testing TrendsKMS Technology
 
DevOps: The Future of Software Development
DevOps: The Future of Software DevelopmentDevOps: The Future of Software Development
DevOps: The Future of Software DevelopmentOpsta
 
Continuous Delivery, Continuous Integration
Continuous Delivery, Continuous Integration Continuous Delivery, Continuous Integration
Continuous Delivery, Continuous Integration Amazon Web Services
 
Machine Learning for Self-Driving Cars
Machine Learning for Self-Driving CarsMachine Learning for Self-Driving Cars
Machine Learning for Self-Driving CarsJan Wiegelmann
 
Software test automation
Software test automationSoftware test automation
Software test automationOksana Demediuk
 
What is (tcoe) testing center of excellence
What is (tcoe) testing center of excellenceWhat is (tcoe) testing center of excellence
What is (tcoe) testing center of excellenceMaveric Systems
 
Automation testing strategy, approach & planning
Automation testing  strategy, approach & planningAutomation testing  strategy, approach & planning
Automation testing strategy, approach & planningSivaprasanthRentala1975
 
Selenium Tutorial For Beginners | What Is Selenium? | Selenium Automation Tes...
Selenium Tutorial For Beginners | What Is Selenium? | Selenium Automation Tes...Selenium Tutorial For Beginners | What Is Selenium? | Selenium Automation Tes...
Selenium Tutorial For Beginners | What Is Selenium? | Selenium Automation Tes...Edureka!
 
Chapter 2 - Fundamental Agile Testing Principle, Practices & Process
Chapter 2 - Fundamental Agile Testing Principle, Practices & ProcessChapter 2 - Fundamental Agile Testing Principle, Practices & Process
Chapter 2 - Fundamental Agile Testing Principle, Practices & ProcessNeeraj Kumar Singh
 
New trends in testing automation
New trends in testing automationNew trends in testing automation
New trends in testing automationEran Kinsbrunner
 
Ctfl at sample exam a v1.2 questions
Ctfl at sample exam a v1.2 questionsCtfl at sample exam a v1.2 questions
Ctfl at sample exam a v1.2 questionsNeeraj Kumar Singh
 
ISTQB Foundation Level Basic
ISTQB Foundation Level BasicISTQB Foundation Level Basic
ISTQB Foundation Level BasicErol Selitektay
 
Adaptive AUTOSAR - The New AUTOSAR Architecture
Adaptive AUTOSAR - The New AUTOSAR ArchitectureAdaptive AUTOSAR - The New AUTOSAR Architecture
Adaptive AUTOSAR - The New AUTOSAR ArchitectureAdaCore
 
Selenium with Cucumber
Selenium  with Cucumber Selenium  with Cucumber
Selenium with Cucumber Knoldus Inc.
 
Chapter 1 - Fundamentals of Testing
Chapter 1 - Fundamentals of TestingChapter 1 - Fundamentals of Testing
Chapter 1 - Fundamentals of TestingNeeraj Kumar Singh
 

What's hot (20)

Quality engineering in DevOps... Why? How? (TestBusters Day&Night))
Quality engineering in DevOps... Why? How? (TestBusters Day&Night))Quality engineering in DevOps... Why? How? (TestBusters Day&Night))
Quality engineering in DevOps... Why? How? (TestBusters Day&Night))
 
Software Testing Process, Testing Automation and Software Testing Trends
Software Testing Process, Testing Automation and Software Testing TrendsSoftware Testing Process, Testing Automation and Software Testing Trends
Software Testing Process, Testing Automation and Software Testing Trends
 
DevOps: The Future of Software Development
DevOps: The Future of Software DevelopmentDevOps: The Future of Software Development
DevOps: The Future of Software Development
 
Continuous Delivery, Continuous Integration
Continuous Delivery, Continuous Integration Continuous Delivery, Continuous Integration
Continuous Delivery, Continuous Integration
 
Machine Learning for Self-Driving Cars
Machine Learning for Self-Driving CarsMachine Learning for Self-Driving Cars
Machine Learning for Self-Driving Cars
 
Software test automation
Software test automationSoftware test automation
Software test automation
 
What is (tcoe) testing center of excellence
What is (tcoe) testing center of excellenceWhat is (tcoe) testing center of excellence
What is (tcoe) testing center of excellence
 
Automation testing strategy, approach & planning
Automation testing  strategy, approach & planningAutomation testing  strategy, approach & planning
Automation testing strategy, approach & planning
 
Selenium Tutorial For Beginners | What Is Selenium? | Selenium Automation Tes...
Selenium Tutorial For Beginners | What Is Selenium? | Selenium Automation Tes...Selenium Tutorial For Beginners | What Is Selenium? | Selenium Automation Tes...
Selenium Tutorial For Beginners | What Is Selenium? | Selenium Automation Tes...
 
Static Testing
Static TestingStatic Testing
Static Testing
 
Chapter 2 - Fundamental Agile Testing Principle, Practices & Process
Chapter 2 - Fundamental Agile Testing Principle, Practices & ProcessChapter 2 - Fundamental Agile Testing Principle, Practices & Process
Chapter 2 - Fundamental Agile Testing Principle, Practices & Process
 
New trends in testing automation
New trends in testing automationNew trends in testing automation
New trends in testing automation
 
Ctfl at sample exam a v1.2 questions
Ctfl at sample exam a v1.2 questionsCtfl at sample exam a v1.2 questions
Ctfl at sample exam a v1.2 questions
 
ISTQB Foundation Level Basic
ISTQB Foundation Level BasicISTQB Foundation Level Basic
ISTQB Foundation Level Basic
 
ISO 26262: Automotive Functional Safety
ISO 26262: Automotive Functional SafetyISO 26262: Automotive Functional Safety
ISO 26262: Automotive Functional Safety
 
Test automation proposal
Test automation proposalTest automation proposal
Test automation proposal
 
Automotive Cybersecurity: The Gap Still Exists
Automotive Cybersecurity: The Gap Still ExistsAutomotive Cybersecurity: The Gap Still Exists
Automotive Cybersecurity: The Gap Still Exists
 
Adaptive AUTOSAR - The New AUTOSAR Architecture
Adaptive AUTOSAR - The New AUTOSAR ArchitectureAdaptive AUTOSAR - The New AUTOSAR Architecture
Adaptive AUTOSAR - The New AUTOSAR Architecture
 
Selenium with Cucumber
Selenium  with Cucumber Selenium  with Cucumber
Selenium with Cucumber
 
Chapter 1 - Fundamentals of Testing
Chapter 1 - Fundamentals of TestingChapter 1 - Fundamentals of Testing
Chapter 1 - Fundamentals of Testing
 

Similar to Enabling supply chain flexibility and IoT scale with zero touch provisioning

Can we build an Azure IoT controlled device in less than 40 minutes that cost...
Can we build an Azure IoT controlled device in less than 40 minutes that cost...Can we build an Azure IoT controlled device in less than 40 minutes that cost...
Can we build an Azure IoT controlled device in less than 40 minutes that cost...Codemotion Tel Aviv
 
AWS Summit Auckland- Developing Applications for IoT
AWS Summit Auckland-  Developing Applications for IoTAWS Summit Auckland-  Developing Applications for IoT
AWS Summit Auckland- Developing Applications for IoTAmazon Web Services
 
Developing Connected Applications with AWS IoT - Technical 301
Developing Connected Applications with AWS IoT - Technical 301Developing Connected Applications with AWS IoT - Technical 301
Developing Connected Applications with AWS IoT - Technical 301Amazon Web Services
 
IoT Day 2019 Naples - Microsoft Azure Shpere
IoT Day 2019 Naples - Microsoft Azure ShpereIoT Day 2019 Naples - Microsoft Azure Shpere
IoT Day 2019 Naples - Microsoft Azure ShpereMirco Vanini
 
Architecting IoT solutions with Microsoft Azure
Architecting IoT solutions with Microsoft AzureArchitecting IoT solutions with Microsoft Azure
Architecting IoT solutions with Microsoft AzureAlon Fliess
 
Augmate Capabilities Deck
Augmate Capabilities DeckAugmate Capabilities Deck
Augmate Capabilities DeckPete Wassell
 
Gestire i devices con Azure IoT Hub e IoT Edge
Gestire i devices con Azure IoT Hub e IoT EdgeGestire i devices con Azure IoT Hub e IoT Edge
Gestire i devices con Azure IoT Hub e IoT EdgeMarco Parenzan
 
CCI2018 - Gestire devices per l'Internet of Things con Azure IoT Hub
CCI2018 - Gestire devices per l'Internet of Things con Azure IoT HubCCI2018 - Gestire devices per l'Internet of Things con Azure IoT Hub
CCI2018 - Gestire devices per l'Internet of Things con Azure IoT Hubwalk2talk srl
 
IoT: Connecting Devices and Manufacturing Equipment to the Cloud
IoT: Connecting Devices and Manufacturing Equipment to the CloudIoT: Connecting Devices and Manufacturing Equipment to the Cloud
IoT: Connecting Devices and Manufacturing Equipment to the CloudMichelle Devereux White
 
Improve operational excellence & reduce downtime for your IoT devices.pptx
Improve operational excellence & reduce downtime for your IoT devices.pptxImprove operational excellence & reduce downtime for your IoT devices.pptx
Improve operational excellence & reduce downtime for your IoT devices.pptxNeel688696
 
How to Easily and Securely Connect Devices to AWS IoT - AWS Online Tech Talks
How to Easily and Securely Connect Devices to AWS IoT - AWS Online Tech TalksHow to Easily and Securely Connect Devices to AWS IoT - AWS Online Tech Talks
How to Easily and Securely Connect Devices to AWS IoT - AWS Online Tech TalksAmazon Web Services
 
“Deploying Edge AI Solutions at Scale for the Internet of Things,” a Presenta...
“Deploying Edge AI Solutions at Scale for the Internet of Things,” a Presenta...“Deploying Edge AI Solutions at Scale for the Internet of Things,” a Presenta...
“Deploying Edge AI Solutions at Scale for the Internet of Things,” a Presenta...Edge AI and Vision Alliance
 
[NEW LAUNCH!] AWS IoT Device Tester: Enable Your Edge Devices for AWS IoT (IO...
[NEW LAUNCH!] AWS IoT Device Tester: Enable Your Edge Devices for AWS IoT (IO...[NEW LAUNCH!] AWS IoT Device Tester: Enable Your Edge Devices for AWS IoT (IO...
[NEW LAUNCH!] AWS IoT Device Tester: Enable Your Edge Devices for AWS IoT (IO...Amazon Web Services
 
Microsoft IoT Overview, Vision and Roadmap
Microsoft IoT Overview, Vision and RoadmapMicrosoft IoT Overview, Vision and Roadmap
Microsoft IoT Overview, Vision and RoadmapMicrosoft Tech Community
 
Solving the IoT Challenge
Solving the IoT ChallengeSolving the IoT Challenge
Solving the IoT ChallengeFIDO Alliance
 
Authenticate and authorize your IIoTdevices
Authenticate and authorize your IIoTdevicesAuthenticate and authorize your IIoTdevices
Authenticate and authorize your IIoTdevicesteam-WIBU
 
Introducing FIDO Device Onboard (FDO)
Introducing  FIDO Device Onboard (FDO)Introducing  FIDO Device Onboard (FDO)
Introducing FIDO Device Onboard (FDO)FIDO Alliance
 
PetNovations case study_architecting IoT systems - Olga Shpigel
PetNovations case study_architecting IoT systems - Olga ShpigelPetNovations case study_architecting IoT systems - Olga Shpigel
PetNovations case study_architecting IoT systems - Olga ShpigelGuy Vinograd ☁
 
Connecting low-power devices to the cloud with Amazon FreeRTOS BLE - SVC206 -...
Connecting low-power devices to the cloud with Amazon FreeRTOS BLE - SVC206 -...Connecting low-power devices to the cloud with Amazon FreeRTOS BLE - SVC206 -...
Connecting low-power devices to the cloud with Amazon FreeRTOS BLE - SVC206 -...Amazon Web Services
 

Similar to Enabling supply chain flexibility and IoT scale with zero touch provisioning (20)

Can we build an Azure IoT controlled device in less than 40 minutes that cost...
Can we build an Azure IoT controlled device in less than 40 minutes that cost...Can we build an Azure IoT controlled device in less than 40 minutes that cost...
Can we build an Azure IoT controlled device in less than 40 minutes that cost...
 
AWS Summit Auckland- Developing Applications for IoT
AWS Summit Auckland-  Developing Applications for IoTAWS Summit Auckland-  Developing Applications for IoT
AWS Summit Auckland- Developing Applications for IoT
 
Developing Connected Applications with AWS IoT - Technical 301
Developing Connected Applications with AWS IoT - Technical 301Developing Connected Applications with AWS IoT - Technical 301
Developing Connected Applications with AWS IoT - Technical 301
 
IoT Day 2019 Naples - Microsoft Azure Shpere
IoT Day 2019 Naples - Microsoft Azure ShpereIoT Day 2019 Naples - Microsoft Azure Shpere
IoT Day 2019 Naples - Microsoft Azure Shpere
 
Architecting IoT solutions with Microsoft Azure
Architecting IoT solutions with Microsoft AzureArchitecting IoT solutions with Microsoft Azure
Architecting IoT solutions with Microsoft Azure
 
Augmate Capabilities Deck
Augmate Capabilities DeckAugmate Capabilities Deck
Augmate Capabilities Deck
 
Gestire i devices con Azure IoT Hub e IoT Edge
Gestire i devices con Azure IoT Hub e IoT EdgeGestire i devices con Azure IoT Hub e IoT Edge
Gestire i devices con Azure IoT Hub e IoT Edge
 
CCI2018 - Gestire devices per l'Internet of Things con Azure IoT Hub
CCI2018 - Gestire devices per l'Internet of Things con Azure IoT HubCCI2018 - Gestire devices per l'Internet of Things con Azure IoT Hub
CCI2018 - Gestire devices per l'Internet of Things con Azure IoT Hub
 
IoT on azure
IoT on azureIoT on azure
IoT on azure
 
IoT: Connecting Devices and Manufacturing Equipment to the Cloud
IoT: Connecting Devices and Manufacturing Equipment to the CloudIoT: Connecting Devices and Manufacturing Equipment to the Cloud
IoT: Connecting Devices and Manufacturing Equipment to the Cloud
 
Improve operational excellence & reduce downtime for your IoT devices.pptx
Improve operational excellence & reduce downtime for your IoT devices.pptxImprove operational excellence & reduce downtime for your IoT devices.pptx
Improve operational excellence & reduce downtime for your IoT devices.pptx
 
How to Easily and Securely Connect Devices to AWS IoT - AWS Online Tech Talks
How to Easily and Securely Connect Devices to AWS IoT - AWS Online Tech TalksHow to Easily and Securely Connect Devices to AWS IoT - AWS Online Tech Talks
How to Easily and Securely Connect Devices to AWS IoT - AWS Online Tech Talks
 
“Deploying Edge AI Solutions at Scale for the Internet of Things,” a Presenta...
“Deploying Edge AI Solutions at Scale for the Internet of Things,” a Presenta...“Deploying Edge AI Solutions at Scale for the Internet of Things,” a Presenta...
“Deploying Edge AI Solutions at Scale for the Internet of Things,” a Presenta...
 
[NEW LAUNCH!] AWS IoT Device Tester: Enable Your Edge Devices for AWS IoT (IO...
[NEW LAUNCH!] AWS IoT Device Tester: Enable Your Edge Devices for AWS IoT (IO...[NEW LAUNCH!] AWS IoT Device Tester: Enable Your Edge Devices for AWS IoT (IO...
[NEW LAUNCH!] AWS IoT Device Tester: Enable Your Edge Devices for AWS IoT (IO...
 
Microsoft IoT Overview, Vision and Roadmap
Microsoft IoT Overview, Vision and RoadmapMicrosoft IoT Overview, Vision and Roadmap
Microsoft IoT Overview, Vision and Roadmap
 
Solving the IoT Challenge
Solving the IoT ChallengeSolving the IoT Challenge
Solving the IoT Challenge
 
Authenticate and authorize your IIoTdevices
Authenticate and authorize your IIoTdevicesAuthenticate and authorize your IIoTdevices
Authenticate and authorize your IIoTdevices
 
Introducing FIDO Device Onboard (FDO)
Introducing  FIDO Device Onboard (FDO)Introducing  FIDO Device Onboard (FDO)
Introducing FIDO Device Onboard (FDO)
 
PetNovations case study_architecting IoT systems - Olga Shpigel
PetNovations case study_architecting IoT systems - Olga ShpigelPetNovations case study_architecting IoT systems - Olga Shpigel
PetNovations case study_architecting IoT systems - Olga Shpigel
 
Connecting low-power devices to the cloud with Amazon FreeRTOS BLE - SVC206 -...
Connecting low-power devices to the cloud with Amazon FreeRTOS BLE - SVC206 -...Connecting low-power devices to the cloud with Amazon FreeRTOS BLE - SVC206 -...
Connecting low-power devices to the cloud with Amazon FreeRTOS BLE - SVC206 -...
 

More from Eurotech

Integrating electrical systems easily – accelerating the path towards sustain...
Integrating electrical systems easily – accelerating the path towards sustain...Integrating electrical systems easily – accelerating the path towards sustain...
Integrating electrical systems easily – accelerating the path towards sustain...Eurotech
 
Automatic People and Passenger Counters
Automatic People and Passenger CountersAutomatic People and Passenger Counters
Automatic People and Passenger CountersEurotech
 
Developing Interoperable Components for an Open IoT Foundation
Developing Interoperable Components for an Open IoT Foundation Developing Interoperable Components for an Open IoT Foundation
Developing Interoperable Components for an Open IoT Foundation Eurotech
 
IoT Solutions Made Simple with Everyware IoT
IoT Solutions Made Simple with Everyware IoTIoT Solutions Made Simple with Everyware IoT
IoT Solutions Made Simple with Everyware IoTEurotech
 
Intelligent IoT gateway: pushing analytics at the edge
Intelligent IoT gateway: pushing analytics at the edgeIntelligent IoT gateway: pushing analytics at the edge
Intelligent IoT gateway: pushing analytics at the edgeEurotech
 
Eclipse kura in industry 4.0 david woodard
Eclipse kura in industry 4.0   david woodardEclipse kura in industry 4.0   david woodard
Eclipse kura in industry 4.0 david woodardEurotech
 
Building IoT Mashups for Industry 4.0 with Eclipse Kura and Kura Wires
Building IoT Mashups for Industry 4.0 with Eclipse Kura and Kura WiresBuilding IoT Mashups for Industry 4.0 with Eclipse Kura and Kura Wires
Building IoT Mashups for Industry 4.0 with Eclipse Kura and Kura WiresEurotech
 
OSGi and Java in Industrial IoT
OSGi and Java in Industrial IoTOSGi and Java in Industrial IoT
OSGi and Java in Industrial IoTEurotech
 
IoT Solutions for Smart Energy Smart Grid and Smart Utility Applications
IoT Solutions for Smart Energy Smart Grid and Smart Utility ApplicationsIoT Solutions for Smart Energy Smart Grid and Smart Utility Applications
IoT Solutions for Smart Energy Smart Grid and Smart Utility ApplicationsEurotech
 
Vivere del Cambiamento: tracciare la rotta verso l'industria 4.0
Vivere del Cambiamento: tracciare la rotta verso l'industria 4.0Vivere del Cambiamento: tracciare la rotta verso l'industria 4.0
Vivere del Cambiamento: tracciare la rotta verso l'industria 4.0Eurotech
 
Real World IoT Architectures and Projects with Eclipse IoT
Real World IoT Architectures and Projects with Eclipse IoTReal World IoT Architectures and Projects with Eclipse IoT
Real World IoT Architectures and Projects with Eclipse IoTEurotech
 
L’IoT industriale e i vantaggi competitivi della trasformazione digitale
L’IoT  industriale e i vantaggi competitivi della trasformazione digitale L’IoT  industriale e i vantaggi competitivi della trasformazione digitale
L’IoT industriale e i vantaggi competitivi della trasformazione digitale Eurotech
 
Reshaping Business Through IoT: Key Technology Factors to Consider
Reshaping Business Through IoT: Key Technology Factors to ConsiderReshaping Business Through IoT: Key Technology Factors to Consider
Reshaping Business Through IoT: Key Technology Factors to ConsiderEurotech
 
Industrial IoT Mayhem? Java IoT Gateways to the Rescue
Industrial IoT Mayhem? Java IoT Gateways to the RescueIndustrial IoT Mayhem? Java IoT Gateways to the Rescue
Industrial IoT Mayhem? Java IoT Gateways to the RescueEurotech
 
Eurotech and Red Hat collaboration simplifies Internet of Things integration ...
Eurotech and Red Hat collaboration simplifies Internet of Things integration ...Eurotech and Red Hat collaboration simplifies Internet of Things integration ...
Eurotech and Red Hat collaboration simplifies Internet of Things integration ...Eurotech
 
Real World IoT Architecture Use Cases
Real World IoT Architecture Use CasesReal World IoT Architecture Use Cases
Real World IoT Architecture Use CasesEurotech
 
Simplify Internet of Things with an Intelligent Gateway
Simplify Internet of Things with an Intelligent GatewaySimplify Internet of Things with an Intelligent Gateway
Simplify Internet of Things with an Intelligent GatewayEurotech
 
Internet of Things: a reality check
Internet of Things: a reality check Internet of Things: a reality check
Internet of Things: a reality check Eurotech
 
IoT the driver of Business Innovation: better products, new services and...
IoT the driver of  Business Innovation: better products, new  services  and...IoT the driver of  Business Innovation: better products, new  services  and...
IoT the driver of Business Innovation: better products, new services and...Eurotech
 
HPC the new normal
HPC the new normalHPC the new normal
HPC the new normalEurotech
 

More from Eurotech (20)

Integrating electrical systems easily – accelerating the path towards sustain...
Integrating electrical systems easily – accelerating the path towards sustain...Integrating electrical systems easily – accelerating the path towards sustain...
Integrating electrical systems easily – accelerating the path towards sustain...
 
Automatic People and Passenger Counters
Automatic People and Passenger CountersAutomatic People and Passenger Counters
Automatic People and Passenger Counters
 
Developing Interoperable Components for an Open IoT Foundation
Developing Interoperable Components for an Open IoT Foundation Developing Interoperable Components for an Open IoT Foundation
Developing Interoperable Components for an Open IoT Foundation
 
IoT Solutions Made Simple with Everyware IoT
IoT Solutions Made Simple with Everyware IoTIoT Solutions Made Simple with Everyware IoT
IoT Solutions Made Simple with Everyware IoT
 
Intelligent IoT gateway: pushing analytics at the edge
Intelligent IoT gateway: pushing analytics at the edgeIntelligent IoT gateway: pushing analytics at the edge
Intelligent IoT gateway: pushing analytics at the edge
 
Eclipse kura in industry 4.0 david woodard
Eclipse kura in industry 4.0   david woodardEclipse kura in industry 4.0   david woodard
Eclipse kura in industry 4.0 david woodard
 
Building IoT Mashups for Industry 4.0 with Eclipse Kura and Kura Wires
Building IoT Mashups for Industry 4.0 with Eclipse Kura and Kura WiresBuilding IoT Mashups for Industry 4.0 with Eclipse Kura and Kura Wires
Building IoT Mashups for Industry 4.0 with Eclipse Kura and Kura Wires
 
OSGi and Java in Industrial IoT
OSGi and Java in Industrial IoTOSGi and Java in Industrial IoT
OSGi and Java in Industrial IoT
 
IoT Solutions for Smart Energy Smart Grid and Smart Utility Applications
IoT Solutions for Smart Energy Smart Grid and Smart Utility ApplicationsIoT Solutions for Smart Energy Smart Grid and Smart Utility Applications
IoT Solutions for Smart Energy Smart Grid and Smart Utility Applications
 
Vivere del Cambiamento: tracciare la rotta verso l'industria 4.0
Vivere del Cambiamento: tracciare la rotta verso l'industria 4.0Vivere del Cambiamento: tracciare la rotta verso l'industria 4.0
Vivere del Cambiamento: tracciare la rotta verso l'industria 4.0
 
Real World IoT Architectures and Projects with Eclipse IoT
Real World IoT Architectures and Projects with Eclipse IoTReal World IoT Architectures and Projects with Eclipse IoT
Real World IoT Architectures and Projects with Eclipse IoT
 
L’IoT industriale e i vantaggi competitivi della trasformazione digitale
L’IoT  industriale e i vantaggi competitivi della trasformazione digitale L’IoT  industriale e i vantaggi competitivi della trasformazione digitale
L’IoT industriale e i vantaggi competitivi della trasformazione digitale
 
Reshaping Business Through IoT: Key Technology Factors to Consider
Reshaping Business Through IoT: Key Technology Factors to ConsiderReshaping Business Through IoT: Key Technology Factors to Consider
Reshaping Business Through IoT: Key Technology Factors to Consider
 
Industrial IoT Mayhem? Java IoT Gateways to the Rescue
Industrial IoT Mayhem? Java IoT Gateways to the RescueIndustrial IoT Mayhem? Java IoT Gateways to the Rescue
Industrial IoT Mayhem? Java IoT Gateways to the Rescue
 
Eurotech and Red Hat collaboration simplifies Internet of Things integration ...
Eurotech and Red Hat collaboration simplifies Internet of Things integration ...Eurotech and Red Hat collaboration simplifies Internet of Things integration ...
Eurotech and Red Hat collaboration simplifies Internet of Things integration ...
 
Real World IoT Architecture Use Cases
Real World IoT Architecture Use CasesReal World IoT Architecture Use Cases
Real World IoT Architecture Use Cases
 
Simplify Internet of Things with an Intelligent Gateway
Simplify Internet of Things with an Intelligent GatewaySimplify Internet of Things with an Intelligent Gateway
Simplify Internet of Things with an Intelligent Gateway
 
Internet of Things: a reality check
Internet of Things: a reality check Internet of Things: a reality check
Internet of Things: a reality check
 
IoT the driver of Business Innovation: better products, new services and...
IoT the driver of  Business Innovation: better products, new  services  and...IoT the driver of  Business Innovation: better products, new  services  and...
IoT the driver of Business Innovation: better products, new services and...
 
HPC the new normal
HPC the new normalHPC the new normal
HPC the new normal
 

Recently uploaded

Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Mattias Andersson
 
Dev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebDev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebUiPathCommunity
 
SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024Scott Keck-Warren
 
"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii SoldatenkoFwdays
 
Powerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time ClashPowerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time Clashcharlottematthew16
 
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 3652toLead Limited
 
SAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxSAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxNavinnSomaal
 
Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Scott Keck-Warren
 
Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfAddepto
 
My Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationMy Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationRidwan Fadjar
 
APIForce Zurich 5 April Automation LPDG
APIForce Zurich 5 April  Automation LPDGAPIForce Zurich 5 April  Automation LPDG
APIForce Zurich 5 April Automation LPDGMarianaLemus7
 
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks..."LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...Fwdays
 
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek SchlawackFwdays
 
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
"Federated learning: out of reach no matter how close",Oleksandr LapshynFwdays
 
Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Commit University
 
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticsKotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticscarlostorres15106
 
DevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsDevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsSergiu Bodiu
 
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...shyamraj55
 

Recently uploaded (20)

Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?
 
Hot Sexy call girls in Panjabi Bagh 🔝 9953056974 🔝 Delhi escort Service
Hot Sexy call girls in Panjabi Bagh 🔝 9953056974 🔝 Delhi escort ServiceHot Sexy call girls in Panjabi Bagh 🔝 9953056974 🔝 Delhi escort Service
Hot Sexy call girls in Panjabi Bagh 🔝 9953056974 🔝 Delhi escort Service
 
Dev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebDev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio Web
 
SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024
 
DMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special EditionDMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special Edition
 
"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko
 
Powerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time ClashPowerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time Clash
 
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
 
SAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxSAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptx
 
Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024
 
Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdf
 
My Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationMy Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 Presentation
 
APIForce Zurich 5 April Automation LPDG
APIForce Zurich 5 April  Automation LPDGAPIForce Zurich 5 April  Automation LPDG
APIForce Zurich 5 April Automation LPDG
 
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks..."LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
 
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
 
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
 
Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!
 
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticsKotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
 
DevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsDevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platforms
 
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
 

Enabling supply chain flexibility and IoT scale with zero touch provisioning

  • 1. © 2022, Amazon Web Services, Inc. or its affiliates. © 2023, Amazon Web Services, Inc. or its affiliates. Enabling Supply Chain Flexibility and IoT Scale with Zero Touch Provisioning S E S S I O N 1 . 2
  • 2. © 2022, Amazon Web Services, Inc. or its affiliates. Speakers Ben Cooke Partner Solutions Architect IoT & Edge Thomas Lorenser Director GPC Compute Marketing ARM Marco Carrer CTO Eurotech
  • 3. © 2022, Amazon Web Services, Inc. or its affiliates. IoT Device Birth to Service Journey Component Supply Chain Manufacturer Distributor Integrator Installer Months to Years A lot can change with a business in this time…
  • 4. © 2022, Amazon Web Services, Inc. or its affiliates. IoT Device Birth to Service Journey Fleet Operator Device Manufacturer ≠
  • 5. © 2022, Amazon Web Services, Inc. or its affiliates. IoT Device Life-Cycle Use Cases 2. Offline provisioning in the supply chain 1. Provisioning device at time of install 3. Factory refurbishment and migration of previously fielded devices 4. Disaster recovery orchestration
  • 6. © 2022, Amazon Web Services, Inc. or its affiliates. The device identity “blob” Device Identifier(s) – Serial Number, etc Device Root Identity Cert Device Service Cert Device Root Pub/Priv Keys Device Service Pub/Priv Keys Factory Meta Data – Default SW Version, config, etc Cloud Meta Data – Groups, roles, account, etc Device Manufacturer Fleet Operator Operational Meta Data – SW Version, config, etc
  • 7. © 2022, Amazon Web Services, Inc. or its affiliates. Secure Device Identities (DevIDs) IEEE 802.1AR Secure Device Identity § Globally unique-per-device identity § Unique-per-device secret (private key) § Cryptographically bound to a device § Public X.509 certificate w/ certificate chain Initial Device ID (IDevID) § Attests Supply-Chain and Device Platform Integrity § Installed by OEM and signed by OEM CA § Certificate w/ device serial number, SAN, and Certificate Policy § Certificate never expires Local Device ID (LDevID) § Attests Device Ownership § Signed by Device Owner § Installed by Device Owner or OEM/Distributor on behalf of Device Owner § Certificate long-lived Operational Device Identity (OpDevID) § Authentication Credentials for IoT Service Connectivity § Signed by Device Owner CA trusted by IoT Service § Enrolled by the device firmware § Certificate short-lived
  • 8. © 2022, Amazon Web Services, Inc. or its affiliates. Device Identities EK EK TPM Endorsement Key TPM Endorsement Certificate Seeded at TPM manufacturing Certificate managed by TPM manufacturer IDevID IDevID signing and attestation key IDevID Certificate signed by OEM Seeded at Device Manufacturing Certificate managed by OEM PKI Certificate never expires LDevID LDevID signing and attestation key LDevID Certificate signed by customer CA Seeded at Device Enrollment. Certificate managed by Customer PKI Certificate long-lived OpDevID Operational Device Identity (OpDevID) OpDevID authentication key OpDevID Certificate signed by Customer CA used by the IoT Service Seeded at Device Provisioning. Certificate managed by Customer PKI Certificate short-lived TPM 2.0 Control Domains Endorsement Hierarchy (EH) Owned by TPM Manufacturer and OEM Platform Hierarchy (PH) Owned by OEM Storage Hierarchy (SH) Owned by the end- customer Secure Device Storage
  • 9. © 2022, Amazon Web Services, Inc. or its affiliates. Manufacturing Facility OEM IDevID Seed IDevID Key Enroll IDevID Certificate with OEM PKI Store IDevID Cert in TPM PH Distributor Facility Global Distributor LDevID Seed LDevID Key Enroll LDevID Certificate with Customer PKI Store LDevID Cert in TPM SH Customer Site Local Distributor Install AWS IoT Greengrass Configure AWS IoT Endpoints Configure Network Access Configure Edge Application(s) Installation Site Field Installer OpDevID Seed OpDevID Enroll OpDevID Certficate with Customer PKI AWS IoT Core Just-in-time provisioning (JITP) Create the AWS IoT Thing Create policy for IoT Thing Attach policy to OpDevID Update AWS IoT Greengrass Remote Updates Repurposing Decommissioning Over-the-air updates maintain the device secure Device Certificates are renewed by device firmware with the corresponding PKI through the EST protocol Repurposing within an organization restores the post-enrollment device state Decommissioning restores the post-manufacturing state Manufacturing Enrollment Commissioning Provisioning Management IoT Thing IoT Shadow AWS IoT Greengrass AWS IoT Core AWS IoT Provisioning Lambda Device Life-Cycle
  • 10. © 2022, Amazon Web Services, Inc. or its affiliates. From this… 1. Download AWS IoT Greengrass 2. Install AWS IoT Greengrass 3. Follow link to instruction 4. Configure AWS IoT Greengrass nucleus 5. Create the AWS IoT Thing 6. Create the certificate from a private key in an HSM 7. Create a CSR for the AWS IoT Thing 8. Create a Certificate for the AWS IoT Thing 9. Create policy for IoT Thing and attach it to certificate 10. Import the AWS IoT Thing Certificate into the HSM 11. Update the AWS IoT Greengrass Core configuration Demo … to Zero-touch AWS IoT Secure Provisioning 1. Commission 2. Provision 3. Connect Secure Zero-Touch Provisioning
  • 11. © 2022, Amazon Web Services, Inc. or its affiliates. Demo Architecture Eurotech ESF and AWS IoT Greengrass Standard PKI Hardened Everyware Linux (based on Yocto) Secure Hardware (Secure CPU, TPM 2.0) Digital Twins Wires Secure Firmware (u-boot, ARM Trusted Firmware) Updates Diagnostics IEC 62443-4-2 PSA Level 1 PARSEC Log Analytics Fieldbus Protocols Security Manager Application Services Device Management Services Connectivity Services EST Enrollment AWS IoT Core Connector Everyware Software Framework AWS IoT Greengrass AWS IoT Greengrass Nucleus AWS IoT Core AWS IoT SiteWise AWS IoT Device Defender Client device auth MQTT Bridge MQTT Broker AWS IoT Device Defender AWS IoT Device Shadows Device Management Remote Access AWS IoT Analytics EST MQTT MQTT REST Any other device and sensor Meters Motor controllers Breakers and switches
  • 12. © 2022, Amazon Web Services, Inc. or its affiliates. Demo Video
  • 13. © 2022, Amazon Web Services, Inc. or its affiliates. Eurotech’s key activities @Embedded World 2023 Eurotech & InoNet [ hall 3 booth #153 ] Robotic arm demo: AI on the edge & digital twin in the cloud Show edge computing / AI vision and IoT capabilities of our edge devices (real-time detection on the edge and digital twin creation and remote management in the cloud). arm booth [ hall 3 booth #153 ] AWS booth [ hall 4 booth #550 ] Eurotech AWS Ducati Live demo Purpose: The demo shows how a Substation Bay Control Unit can be easily connected to an IoT Gateway and be remotely controlled and monitored with a few easy steps, leveraging the power of the integration between ESF and AWS IoT Greengrass. From Zero-Touch-Provisioning to a fully functional web dashboard and upstream integrations, using a ReliaGATE 10-14, ESF, EC, and AWS IoT Greengrass. ABB AWS Live demo The demo shows a remote monitoring application on ABB Electrification devices. It employs a Eurotech gateway (ReliaGATE 10-14) connected to one (or more) ABB devices. The data from the ABB devices are collected by the gateway and sent to the Cloud (integration with Eurotech Everyware cloud and AWS services), where they are displayed on a dashboard.
  • 14. © 2022, Amazon Web Services, Inc. or its affiliates. Thank you! © 2022, Amazon Web Services, Inc. or its affiliates.