Overview
ISO/IEC 30118-13:2021 specifies the Onboarding Tool (OBT) behavior for the Open Connectivity Foundation (OCF) framework. It defines the mechanisms, security requirements and services an OBT must support to establish device ownership and provision devices into an OCF Security Domain. The standard contains normative security content for OBTs and informative references to the OCF Core and Security specifications. Key goals include secure, interoperable onboarding and credential provisioning for IP‑based IoT devices.
Key topics and technical requirements
- OBT role and purpose
- The OBT provides the foundation of trust for an OCF Security Domain, maintains the domain UUID, and provisions Devices with that UUID.
- OBTs require stronger security hardening than ordinary OCF devices to protect stored credentials.
- Primary OBT services
- DOTS (Device Ownership Transfer Service): establishes ownership and authenticates Devices during onboarding.
- CMS (Credential Management Service): issues and manages identity and role certificates.
- AMS (Access Management Service): manages device access and roles within the domain.
- Optional Mediator functionality for further configuration (e.g., Wi‑Fi, cloud access).
- Certificate and trust management
- Requirements for issuing identity and role certificates and provisioning Trust Anchor certificates.
- Ownership Transfer Methods
- Defines supported OTMs including Just Works, Random PIN / Shared Credential, Manufacturer Certificate Based, and Vendor‑Specific methods, with guidance on security considerations and bridging scenarios.
- Device onboarding states
- Addresses onboarding lifecycle (e.g., RESET, RFOTM) and access privileges during each state.
- Normative references
Applications and who uses it
ISO/IEC 30118-13 is intended for:
- IoT device manufacturers (appliances, door locks, cameras, sensors, actuators)
- Firmware and platform developers implementing OCF onboarding and security
- System integrators and smart‑home/cloud service providers
- Security architects and certification bodies validating secure onboarding and credential flows
Practical uses include secure first‑time device setup, transferring device ownership, provisioning device certificates and roles, and integrating devices into local or cloud OCF ecosystems.
Related standards
- ISO/IEC 30118‑1 - OCF Core Specification
- ISO/IEC 30118‑2 - OCF Security Specification
- Other parts of ISO/IEC 30118 series (bridging, resource mappings, cloud APIs)
- NIST SP 800‑90A - Random Number Generation guidance
Keywords: ISO/IEC 30118-13, OCF Onboarding Tool, OBT, IoT onboarding, device ownership transfer, DOTS, CMS, AMS, certificate management, OCF Security Domain.