Do you recognize these challenges?
Whether the connected thing is a vehicle, a refrigerator, a toy, or a sensor, the manufacturing process
may pose security challenges:
- Issuance of birth certificates in a secure manufacturing network without Internet connectivity
- On-device key generation is time-consuming and a bottleneck in the manufacturing process
- Cumbersome administration and maintenance of multiple Certificate Authorities (CA)
- Uncontrolled code signing and multiple, insecurely stored signing keys
- OPC UA (IEC 62541) Global Discovery Service (GDS) certificate management
- Issuing Matter compliant Device Attestation Certificates (DAC) to Smart Home equipment
- CRA compliance
Code Signing for secure updates
Deploying firmware and software updates securely is essential for providers of connected devices to protect business value and to be compliant with regulations like the European Cyber Resilience Act (CRA). Signing is the de facto means of providing security when deploying code, enabling the receiving device to verify that the update is legitimate and preventing third parties from deploying malicious code.
Nexus PKI solution offers highly secure code signing functionality, providing controlled and traceable access with HSM-secured signing keys.
Nexus Identities for IoT
Become Matter-compliant
For the first time, industry giants such as Apple, Amazon, Google, Samsung, and others have come together to establish a common set of standards, governed by the Connectivity Standards Association (CSA).
This collaborative effort ensures secure and reliable interoperability across smart home devices, mobile apps, and cloud services.
How does it work?
A “Factory CA” issuing a “birth certificate” to the connected device when manufactured, ensures that the device can authenticate and securely communicate with an IoT application. It furthermore enables the device to authenticate for being onboarded to an IoT platform and/or become part of the operating environment. An “operational CA” can issue an operational certificate for the same device to be used for secure communication in this operating environment.
Nexus Smart ID IoT provides a factory CA where security requirements mandate an on-premise CA. Nexus GO IoT service, based on Nexus Smart ID IoT, can also provide PKI certificate lifecycle management throughout the devices’ lifetime. A “lifecycle CA” can augment the factory CA and provide revocation status service and renewal of certificates. Nexus Smart ID and the GO IoT service are based on mature, scalable, highly reliable, continuously tested and maintained products. The multi-CA solution helps you adapting the PKI hierarchy and request certificates via standard protocols. Nexus' solution offers administration, reporting and automation features and has a solid track record.
Achieve Zero Trust with Secure Device Identities
In an era where the Internet of Things (IoT) and Industrial Internet of Things (IIoT) dominate, securing connected devices is critical.
Read our white paper to learn how you can fortify IoT and IIoT ecosystems against cyber threats with PKI and achieve Zero Trust.
Start your FREE trial today to test our IoT services!
Why Nexus
The main advantages of Nexus PKI for IoT are: