Industrial operators can automate IoT onboarding across Wi-Fi networks through a joint specification from the Wireless Broadband Alliance (WBA) and FIDO Alliance. The framework pairs the WBA’s federated OpenRoaming architecture with FIDO Device Onboard protocols.

Field technicians can spend hours manually configuring individual MAC addresses, Wi-Fi protected access keys, and administrative credentials across factory floors. This workflow eliminates that manual setup entirely. Devices authenticate at initial power-on, complete cryptographic handshakes, and migrate directly to designated enterprise segments with zero manual intervention.

Tiago Rodrigues, President and CEO of the WBA, said: “This work marks an important step, extending OpenRoaming further into IoT and edge device use cases. By combining OpenRoaming’s secure, interoperable connectivity with FIDO Device Onboard, we have shown how devices can establish a trusted first connection, begin automated onboarding and then transition to their designated operational network.

“It demonstrates the value of collaboration across the Wi-Fi, identity, manufacturing, and IoT ecosystems, while providing a standards-based foundation for further interoperability testing, product development and real-world trials that can help reduce deployment overhead and strengthen device security at scale.”


More

Inc.: 6 Expert Tips to Avoid Getting Hacked

In this article in Inc., one of the top ways to avoid getting hacked is…

Read More →

CSO: Vocal theft on the horizon

Executive Director Brett McDowell tells CSO that, while biometrics can be spoofed in some situations,…

Read More →

CIO: How to protect your Google and Facebook accounts with a security key

This CIO story explains how FIDO Authentication is easier to use while providing stronger authentication…

Read More →


Subscribe to the FIDO newsletter

Stay Connected, Stay Engaged

Receive the latest news, events, research and implementation guidance from the FIDO Alliance. Learn about digital identity and fast, phishing-resistant authentication with passkeys.