Integration – Can MTG IoT PKI be integrated into existing manufacturing processes?
Yes, MTG IoT PKI is designed for integration into existing production and testing environments. It can be integrated into processes such as pre-personalization, firmware flashing, calibration, and serial number assignment. This allows the digital device identity to become an integral part of the existing manufacturing process and to be automatically provisioned to the respective device.
Licensing Model – How is MTG IoT PKI licensed?
MTG IoT PKI licensing is based on the number of certificates issued within a calendar year and therefore on the actual annual production volume. Certificates issued in previous years that remain active do not result in cumulative licensing across multiple years. This is particularly relevant for long-lived IoT devices whose certificates may continue to require […]
Security – Why is a PKI important for IoT devices?
An IoT PKI creates unique and cryptographically secured device identities. This allows systems to verify whether a device is authentic and authorized to communicate. MTG IoT PKI therefore provides a foundation for secure authentication, encrypted communication, and protection against manipulation or the substitution of unauthorized devices and components. It supports the creation of secure and […]
Renewal – How are device certificates renewed during operation?
During operation, new certificates can be provisioned through a Device Management system and an appropriate Corporate PKI. Standardized interfaces such as EST or CMP can be used to automate certificate requests and renewals. In combination with MTG Corporate PKI, MTG supports automated certificate renewal through EST, for example. In LwM2M-based environments, the EST mechanisms defined […]
Certificate Lifecycle – How long are the initial certificates valid?
The validity period of the initial device certificates can be defined according to the security requirements and intended use of the devices. For production certificates, MTG recommends validity periods of approximately two to seven years as a best practice. The initial certificates are intended to provide a secure device identity during production, delivery, and commissioning. […]
Automation – Can certificate provisioning in production be automated?
Yes, certificate issuance and provisioning can be fully automated and integrated into existing manufacturing processes. MTG IoT PKI is designed for high volumes and short cycle times, making it particularly suitable for series and mass production. Automated certificate provisioning reduces manual process steps and makes it possible to reliably equip large numbers of devices with […]
Production Certificates – How do devices receive their digital identity?
During the manufacturing process, the device generates its own unique key pair and creates a certificate request from it. The request is transferred to MTG IoT PKI and validated there. MTG IoT PKI then issues the initial device certificate, which is installed directly on the device. This gives each device a unique cryptographic identity before […]
IoT PKI – What is MTG IoT PKI?
MTG IoT PKI enables the secure and scalable creation of digital device identities directly during the manufacturing process. Each device receives a unique, cryptographically secured identity and can therefore be reliably authenticated before it leaves the factory. The solution is specifically designed for industrial series and mass production and supports high production volumes with short […]