Overview
ISO/IEC 30118-12:2021 - Information technology - Open Connectivity Foundation (OCF) Specification - Part 12: Cloud security specification - defines the security requirements and definitions for OCF devices and OCF cloud implementations. It is part of the ISO/IEC 30118 OCF series and focuses on protecting device-to-cloud interactions, device registration, credential handling, session management and the cloud-side REST resources that enable secure IoT operations.
This standard is directly relevant to secure IoT/cloud architectures and aligns OCF Cloud concepts with established Internet standards (for example OAuth 2.0 and CoAP over TLS/TCP). It is intended to ensure interoperable, scalable and secure device-cloud connectivity for smart home and commercial IoT deployments.
Key topics and technical requirements
- Device provisioning and registration: Defines processes and requirements for enrolling devices into an OCF Cloud, including Mediator-based provisioning options.
- Device authentication: Specifications for authenticating devices to the cloud, session semantics and secure connection patterns.
- Credentials and tokens: Defines the use and handling of Access Tokens, Authorization Providers and token refresh flows (references IETF RFC 6749 / RFC 6750).
- Message integrity and confidentiality: Session-level security guidance and recommendations for cipher suites and transport protection (see normative references such as RFC 8323 for transport considerations).
- Security resources (Cloud REST API): Resource Type definitions and REST behaviors for Account, Session and Token Refresh resources (Annex A provides OpenAPI/Swagger definitions and CRUDN behavior).
- Security hardening guidelines: Recommended practice to minimize attack surface and operational risk for OCF Cloud deployments.
- Normative references: Links to related OCF parts and Internet standards that implementations should follow.
Applications and who uses this standard
ISO/IEC 30118-12 is practical for:
- Device manufacturers needing a standardized approach for secure cloud connectivity and token handling.
- Cloud service providers / platform operators implementing OCF Cloud APIs, session management and token lifecycles.
- IoT solution architects and security engineers designing end-to-end secure device-cloud systems for smart homes, building automation and commercial IoT.
- Systems integrators and firmware developers implementing device-to-cloud workflows, resource types, and provisioning mediators.
Benefits include improved interoperability, repeatable security patterns, and alignment with OAuth-based authorization and CoAP/TLS transport options.
Related standards
- ISO/IEC 30118 series (Core, Security, Device-to-Cloud, Cloud API, Onboarding)
- ISO/IEC 30118-1 (Core specification) and 30118-2 (Security specification)
- IETF RFC 6749 (OAuth 2.0), RFC 6750 (Bearer Token Usage), RFC 8323 (CoAP over TCP/TLS/WebSockets)
- OpenAPI / Swagger (REST API definitions used in Annex A)
Adopting ISO/IEC 30118-12 helps organizations implement interoperable, secure cloud connectivity for OCF-compliant IoT devices while leveraging established web and IoT security standards.