Overview
ISO/IEC 30118-2:2021 - Information technology - Open Connectivity Foundation (OCF) Specification - Part 2: Security specification - defines the normative security content for OCF-based IoT devices and platforms. It complements ISO/IEC 30118-1 (OCF base layer) by specifying security objectives, mechanisms, resources and lifecycle behaviors that affect device onboarding, provisioning, authentication, access control and message protection. This standard targets secure interoperability across OCF ecosystems and provides prescriptive security resources and profiles for implementers.
Key technical topics and requirements
The standard covers a broad set of security functions and requirements, including:
- Security overview and philosophy - access control models, onboarding concepts, provisioning flows and secure resource management (SRM).
- Device onboarding & ownership transfer (OTM) - defined OTM methods (Just‑Works, PIN, Manufacturer Certificate, etc.), owner establishment and state transitions for onboarding.
- Credentials & lifecycle management - credential types (symmetric keys, asymmetric keys, certificates, passwords), creation, refresh, revocation and provisioning.
- Certificate-based key management and PKI - X.509 certificate profiles, certificate provisioning, trust store and path validation.
- Device authentication - authentication methods using symmetric keys, raw asymmetric keys and certificates, and role assertions.
- Message integrity & confidentiality - session protection (e.g., DTLS), cipher suite guidance and session semantics.
- Access control (ACL) - ACL generation, evaluation, wildcard and role matching, and ACL resource models.
- Security resources & APIs - standardized security resource definitions (Credential, ACL, CSR, Provisioning Status, Auditable Events, Roles, Security Domain Information, SVRs).
- Event logging & auditing - auditable event lists and security logging expectations.
- Execution environment security - secure storage, secure execution engine considerations and hardening guidance.
Practical applications
ISO/IEC 30118-2 is applied to:
- Secure onboarding and provisioning of consumer and industrial IoT devices.
- Implementing standardized ACLs and role-based access for smart home, building automation and industrial gateways.
- Designing device firmware and platform security modules (SRM, credential stores, PKI).
- Building test plans for product certification and OCF compliance management.
Who should use this standard
- IoT device manufacturers and firmware engineers
- Security architects and integrators implementing OCF stacks
- Test labs, certification bodies and compliance managers
- Platform and cloud teams integrating OCF-compliant endpoints
Related standards
- ISO/IEC 30118-1 (OCF base specification) - informative base layer referenced by 30118-2
- Standards and technologies referenced in the document: X.509, DTLS, PKI concepts
Keywords: ISO/IEC 30118-2, OCF Security Specification, IoT security, device onboarding, access control, credential management, DTLS, X.509, PKI.