180
F. Firouzi and B. Farahani
Identity
Token
Device
Manufacturer
Registration
service
Enrolment list
Authorization
service
Protected
resources in
cloud
Request to register (ID)
Store identity
Store identity
Create digital twin
Digital twin
Verify ID
Authorization grant
Access token
Request (access token)
Is token valid?
Token is valid
Response
Fig. 4.3 A typical device provisioning and registration flow
storage. The manufacturer also inserts the device registration information on the
Cloud enrollment list.
2. A device makes contact with the registration service and provides the credentials
and registration information to confirm its identity.
3. The device’s identity is confirmed by the registration service by validating the
registration information in comparison to the enrollment list.
4. The device is then registered in the Cloud and a digital representation (i.e.,
shadow, manifesto, or device twin) of the actual device is created in the Cloud.
The Cloud typically stores a common set of device characteristics and state
information such as software details and hardware specifications. It should be
noted that usually document-based NoSQL databases, such as MongoDB, are
used to store heterogeneous device description in the Cloud.
5. Next, the registration service sends an authorization grant to the device.
6. Using the authorization grant, the device can contact the authorization service to
be able to obtain an access token. This token is then utilized by the device when
communicating with any resource in the Cloud.
7. The device connects with the Cloud and provides the access token for each
request.
8. When a request is received from a device, the access token should be reviewed
in the Cloud by authorization service to confirm the validity and to determine if
the device has a suitable right and permission to access a resource/service. If it is
accessible, the Cloud then processes the device’s request.
It should be noted that when the device registration process is finished, users,
applications, organizations, and groups can then be associated with the device.
F. Firouzi and B. Farahani
Identity
Token
Device
Manufacturer
Registration
service
Enrolment list
Authorization
service
Protected
resources in
cloud
Request to register (ID)
Store identity
Store identity
Create digital twin
Digital twin
Verify ID
Authorization grant
Access token
Request (access token)
Is token valid?
Token is valid
Response
Fig. 4.3 A typical device provisioning and registration flow
storage. The manufacturer also inserts the device registration information on the
Cloud enrollment list.
2. A device makes contact with the registration service and provides the credentials
and registration information to confirm its identity.
3. The device’s identity is confirmed by the registration service by validating the
registration information in comparison to the enrollment list.
4. The device is then registered in the Cloud and a digital representation (i.e.,
shadow, manifesto, or device twin) of the actual device is created in the Cloud.
The Cloud typically stores a common set of device characteristics and state
information such as software details and hardware specifications. It should be
noted that usually document-based NoSQL databases, such as MongoDB, are
used to store heterogeneous device description in the Cloud.
5. Next, the registration service sends an authorization grant to the device.
6. Using the authorization grant, the device can contact the authorization service to
be able to obtain an access token. This token is then utilized by the device when
communicating with any resource in the Cloud.
7. The device connects with the Cloud and provides the access token for each
request.
8. When a request is received from a device, the access token should be reviewed
in the Cloud by authorization service to confirm the validity and to determine if
the device has a suitable right and permission to access a resource/service. If it is
accessible, the Cloud then processes the device’s request.
It should be noted that when the device registration process is finished, users,
applications, organizations, and groups can then be associated with the device.
