Simple and Flexible Onboarding Framework for IoT Devices Based on OAuth 2.0 Standards
Toshio Ito · IEICE Transactions on Information and Systems · 2025
In typical Internet of Things (IoT) scenarios, devices with sensors and actuators connect to servers on cloud platforms over the Internet. To maintain the security of the whole system, the devices and servers need to be configured to securely communicate with each other. This configuration process is called onboarding. As an increasing number of IoT devices is deployed, the cost and time of onboarding become overwhelming. To solve this problem, we propose a semi-automated onboarding framework for IoT devices. Unlike other frameworks such as FIDO Device Onboard, the framework we developed does not require pre-registered device ownership. This simplifies the system because there is no requirement on the supply chain of devices. To determine the device owner, our framework uses OAuth 2.0 Device Authorization Grant. We evaluated the time needed to onboard devices in an experiment where human operators onboarded five devices with a prototype of the framework. The results indicated that the proposed framework was sufficiently fast for small-scale applications. We analyzed the security aspects of our framework based on the specifications and drafts of the OAuth 2.0 framework. We also analyzed an alternative method for Device Authorization Grant that uses FIDO2 standards. Based on the analysis, we evaluated the trade-off between security, simplicity, flexibility, and efficiency of the proposed onboarding framework.