SecurityBrief UK - Technology news for CISOs & cybersecurity decision-makers
United Kingdom
Wireless Broadband Alliance backs zero-touch IoT onboarding

Wireless Broadband Alliance backs zero-touch IoT onboarding

Wed, 7th Oct 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

The Wireless Broadband Alliance has published a report on OpenRoaming for IoT trials, developed with the FIDO Alliance. It sets out findings from a proof of concept for automated Wi-Fi onboarding of connected devices.

The project tested a model combining OpenRoaming, Passpoint and FIDO Device Onboard to let IoT and edge devices connect at first power-on, begin ownership transfer, and receive credentials and configuration without manual setup for each unit.

The aim was to address a recurring problem in large device deployments: the operational effort required to bring hundreds or thousands of devices online across different sites, networks and administrative domains.

VinCSS implemented the trial using a Linux-based Raspberry Pi as a representative onboarding device. Private keys were stored in a secure hardware element and were not exported during the process.

At first power-on, the device connected automatically to an available OpenRoaming network and initiated the FDO TO1 and TO2 ownership-transfer workflow. This validated the initial FDO provisioning stage of the Wireless Broadband Alliance's OpenRoaming for IoT model.

Under the approach described, manufacturers provision devices with cryptographically bound credentials before shipment. Once switched on within range of an OpenRoaming-enabled network, a device authenticates automatically, reaches its onboarding services, and receives the information needed to move to its designated operational network.

The model separates the first connection from the device's final network placement. OpenRoaming acts as a bootstrap layer, while FIDO Device Onboard handles identity, ownership transfer, and delivery of operational credentials, policies and configuration.

This structure is intended to let organisations automate onboarding while retaining control over local security policies and where devices ultimately connect. It could also support redeployment, allowing devices moved to another site or owner to be re-onboarded without extensive manual reconfiguration.

Trial findings

Among the main findings was that zero-touch IoT onboarding is technically feasible through a factory-based credentials mechanism that lets a device connect automatically to an OpenRoaming network without manual Wi-Fi configuration. The report also found that OpenRoaming can provide the initial trusted connection before a device transitions to its final enterprise, industrial or private network.

FIDO Device Onboard can manage device identity, ownership transfer, and delivery of network credentials, policies and application configuration. The report also found that manufacturing can become part of the trust framework through secure provisioning of device-bound certificates and credentials before shipment.

Another conclusion was that the approach could support reassignment of devices between sites or owners. That matters in sectors where equipment is moved between operational environments and would otherwise need to be reset and configured again.

Limits identified

The report also identified areas where further technical work is needed. These include air-gapped or high-security networks, restricted network segments, and resource-constrained IoT devices that cannot run FDO or a Passpoint supplicant directly.

For smaller or less capable devices, the document explores a proxy model in which a helper device would execute OpenRoaming and FDO protocols on their behalf. It also notes that solutions for air-gapped applications are already being defined.

Tiago Rodrigues, President and Chief Executive Officer of the Wireless Broadband Alliance, said: "This work marks an important step, extending OpenRoaming further into IoT and edge device use cases. By combining OpenRoaming's secure, interoperable connectivity with FIDO Device Onboard, we have shown how devices can establish a trusted first connection, begin automated onboarding and then transition to their designated operational network. It demonstrates the value of collaboration across the Wi-Fi, identity, manufacturing and IoT ecosystems, while providing a standards-based foundation for further interoperability testing, product development and real-world trials that can help reduce deployment overhead and strengthen device security at scale."

The project also drew comment from companies involved in networking and device standards, with Cisco and Intel backing the approach in statements included alongside the report.

"Setting up large numbers of connected devices manually is a major hurdle for businesses today. This work empowers the manufacturing and enterprise industries to automatically connect and secure devices right out of the box, helping companies grow their networks more simply and securely," said Mark Grayson.

Richard Kerslake, Market Development, Connected Standards, FIDO Alliance, said: "Enterprises no longer have to choose between speed and security. By pairing FIDO Device Onboard with OpenRoaming, devices can now authenticate, locate their network, and configure themselves automatically - with zero manual setup and zero risk of tampering. It's the secure, friction-free blueprint that IoT and Edge applications need to scale in the real world."

"As IoT deployments continue to scale, the industry needs a simpler and more secure way to bring devices online from first power-on. By combining trusted device identity established during manufacturing with OpenRoaming(r) and FIDO Device Onboard, this work demonstrates a practical path towards automated onboarding across diverse network environments. It is an important step towards making secure, zero-touch deployment easier to implement at scale," said Dr. Necati Canpolat.