The rapid growth of the Internet of Things is transforming industries ranging from manufacturing and healthcare to smart cities and energy. However, every connected device also represents a potential entry point for cyberattacks. While much attention is given to securing devices during operation, one of the most critical security challenges actually occurs much earlier—when a device connects to a network for the very first time.
This initial deployment phase, often referred to as the “First Mile”, is where devices are traditionally configured, assigned credentials and integrated into operational environments. Manual installation procedures, insecure default settings and inconsistent provisioning practices can introduce vulnerabilities that remain throughout the entire lifecycle of a product.
To address this challenge, the DOSS Secure Onboarding Platform introduces a secure-by-design approach that automates trust establishment from the very first connection. Instead of relying on manual configuration, the platform enables devices to authenticate themselves, securely join the network and receive their operational security policies automatically.
Figure 1 illustrates the overall architecture of the DOSS Secure Onboarding Platform, showing how the Manufacturer, the DOSS Platform, and the Operator collaborate to establish trust and securely onboard IoT devices.

Figure 1 – Onboarding Platform Architecture
Eliminating Manual Configuration
Traditional onboarding processes often require installers to configure devices individually, creating opportunities for human error and making large-scale deployments both expensive and difficult to manage.
The DOSS platform replaces this approach with Zero-Touch Onboarding, built on the FIDO Device Onboard (FDO) standard. Devices leave the factory with secure onboarding credentials but without being tied to a specific customer or deployment environment. When the device is powered on, it automatically discovers its designated owner, establishes a secure encrypted connection and completes the ownership transfer without requiring local configuration.
Figure 2 illustrates how trust is securely transferred from the manufacturer to the device owner. Through an automated sequence of authentication, ownership transfer and credential exchange, devices can be provisioned and integrated into their operational environment without manual configuration, enabling secure and scalable Zero-Touch Onboarding.

Figure 2 – FDO Ownership flow
This concept of late binding allows manufacturers to produce standard devices while enabling operators to securely determine the final deployment environment only when installation takes place. As a result, secure onboarding becomes both scalable and flexible without compromising security.
Extending Trust with the Device Security Passport
One of the distinguishing features of the DOSS Secure Onboarding Platform is its integration with the Device Security Passport (DSP).
Rather than serving only as a digital identity, the Device Security Passport acts as a trusted, machine-readable repository containing security information about each device throughout its lifecycle. It stores references to security artefacts such as Bills of Materials, Manufacturer Usage Descriptions (MUD), firmware information and onboarding metadata.
During onboarding, the platform automatically retrieves the Device Security Passport after the device has successfully authenticated. This allows the operator not only to verify the identity of the device but also to understand its security characteristics before it becomes operational.
By combining device identity with trusted security metadata, the platform creates a continuous Supply Trust Chain between manufacturers, operators and deployed devices.
Automatically Applying Security Policies
Authenticating a device is only the first step. Equally important is ensuring that it behaves exactly as intended once it joins the network.
The DOSS platform achieves this through the use of Manufacturer Usage Description (MUD) files. These describe the network communications that are appropriate for a particular device.
After retrieving the Device Security Passport, the platform automatically locates the corresponding MUD file and translates it into concrete security policies that can be enforced by the local infrastructure. This means devices immediately receive only the network permissions required for their intended purpose, implementing the principle of least privilege and significantly reducing the attack surface.
This entire process happens automatically, without requiring network administrators to manually configure firewall rules or access control policies.
Security Beyond Deployment
Cybersecurity does not stop once onboarding has been completed. Devices must continue to receive security updates and respond to newly discovered vulnerabilities throughout their operational lifetime.
Figure 3 provides a trusted firmware update workflow, ensuring that software updates are authenticated, integrity-protected and securely delivered throughout the device lifecycle. By validating firmware before installation and maintaining a trusted update process, the platform helps protect IoT devices against unauthorized or malicious software modifications.

Figure 3 – Device Firmware update
To support this, the DOSS Secure Onboarding Platform incorporates a Secure Update Manager that verifies firmware authenticity before installation and ensures that every update is cryptographically validated and securely logged. This protects devices against unauthorized software modifications while maintaining a complete audit trail of update activities.
The platform also supports hardware-based security technologies such as Trusted Platform Modules (TPMs) and Secure Elements, providing stronger protection for cryptographic keys and device identities than software-based storage alone.
Simplifying Security Management
Managing thousands of connected devices requires more than automation — it also requires visibility.
For this reason, the DOSS platform includes a web-based graphical interface that enables operators to manage device inventories, inspect Device Security Passports, create and apply security policies, monitor policy enforcement, manage firmware updates and respond to security incidents from a single interface.
This unified approach reduces operational complexity while allowing organizations to maintain consistent security policies across large IoT deployments.
A Foundation for Secure-by-Design IoT
The DOSS Secure Onboarding Platform demonstrates that secure onboarding is much more than connecting a device to a network. By combining Zero-Touch Onboarding, FIDO Device Onboard, the Device Security Passport, automated policy enforcement and secure lifecycle management, the platform establishes trust before devices begin operating and maintains that trust throughout their entire lifecycle.
As IoT ecosystems continue to grow and cybersecurity regulations become more demanding, automated onboarding will become an essential component of secure-by-design development. The DOSS platform provides a practical demonstration of how standardized technologies, automation and continuous trust management can make IoT deployments both more secure and easier to manage.
You can find out more about the Secure Onboarding Platform in the DOSS Deliverable D3.3.
