The Wireless Broadband Alliance (WBA) has announced the publication of the ‘OpenRoaming for IoT Trials’ Report, developed in collaboration with the FIDO Alliance. The report demonstrates that a standards-based approach can address persistent challenges in large IoT deployments for manufacturers and enterprises, reducing the cost and complexity of deploying connected devices at scale.
Securely bringing hundreds or thousands of devices online can require significant manual intervention, particularly when equipment is installed across multiple locations, networks, and administrative domains. By combining OpenRoaming, Passpoint and FIDO Device Onboard (FDO), IoT, and Edge devices can establish secure connectivity at first power-on, begin ownership transfer and receive the credentials and configuration required for their operational environment, without technicians manually configuring each device.
Testing results from the trials report
The new report details how the approach tested by WBA and the FIDO Alliance creates a repeatable onboarding model that reduces credential handling and deployment complexity, while maintaining enterprise control over where devices ultimately connect.
Key achievements recorded in the trials included:
- Zero-touch IoT onboarding is technically feasible. A factory-based credentials mechanism can be used to enable a device to connect automatically to an OpenRoaming network without manual Wi-Fi configuration
- OpenRoaming helps provide the secure bootstrap connection. It gives the device trusted initial connectivity before it transitions to its final enterprise, industrial, or private network
- FDO helps manage secure ownership transfer and configuration. FIDO Device Onboard supports device identity, ownership transfer, and delivery of network credentials, policies, and application configuration
- Manufacturing becomes part of the trust framework. Device-bound certificates and credentials can be securely provisioned before shipment
- The model supports device redeployment. Devices can be reassigned and securely onboarded into new operational environments
How the model works
Under the model, manufacturers can provision devices with cryptographically bound credentials before shipment. When powered up within range of an OpenRoaming-enabled network, the device then authenticates automatically and uses that initial connection to reach its onboarding services.
OpenRoaming acts as a secure bootstrap layer rather than dictating the device’s final network placement. FDO manages device identity, ownership transfer and the delivery of operational credentials, policies, and configuration. The device can then leave the bootstrap connection and move onto its designated enterprise, industrial, private, or other operational network. This separation between initial access and final network placement enables organisations to automate onboarding without giving up control over local security policies and network access.
The trial team also described how this model could simplify the redeployment of connected products. Devices reassigned to a different site or owner can be securely re-onboarded into a new operational environment rather than requiring extensive manual reconfiguration.
A deeper look at the trial
The proof of concept was implemented by VinCSS using a Linux-based Raspberry Pi as a representative onboarding device and was designed to validate the first phase ‘End-user and Device Onboarding Flow’. Private keys were stored in a secure hardware element and were never exported. At first power-on, the device connected automatically to an available OpenRoaming network and initiated the FDO TO1 and TO2 ownership-transfer workflow. The trial successfully validated the initial FDO provisioning stage of the WBA OpenRoaming for IoT Model.
The report also identifies environments that require further technical work, including air-gapped or high-security networks, restricted network segments, and resource-constrained IoT devices that cannot run FDO or a Passpoint supplicant directly. For resource-constrained devices, the report explores a potential proxy model through which a helper device could execute the OpenRoaming and FDO protocols on their behalf. Solutions for air-gapped applications are already in definition and are expected to be part of a future WBA-FDO applications report.
An invitation to industry
The WBA and FIDO Alliance are inviting device manufacturers, enterprises, operators, infrastructure providers, and IoT solution developers to participate in the next phase of the work. Priorities include real-world, multi-vendor trials, industry-specific proofs of concept, certificate lifecycle testing, and further development for air-gapped and resource-constrained environments.
Tiago Rodrigues, President and CEO of the Wireless Broadband Alliance, said: “This work marks an important step, extending OpenRoaming further into IoT and Edge device use cases. By combining OpenRoaming’s secure, interoperable connectivity with FIDO Device Onboard, we have shown how devices can establish a trusted first connection, begin automated onboarding, and then transition to their designated operational network. It demonstrates the value of collaboration across the Wi-Fi, identity, manufacturing, and IoT ecosystems, while providing a standards-based foundation for further interoperability testing, product development, and real-world trials that can help reduce deployment overhead and strengthen device security at scale.”
