
Securely bringing hundreds or thousands of devices online can require significant manual intervention, particularly when equipment is installed across multiple locations, networks, and administrative domains. To address this task, the Wireless Broadband Alliance (WBA) announced the publication of the OpenRoaming for IoT Trials Report, developed in collaboration with the FIDO (Fast IDentity Online) Alliance.
The report aims to demonstrate that a standards-based approach can address persistent challenges in large IoT deployments for manufacturers and enterprises, reducing the cost and complexity of deploying connected devices at scale. By combining OpenRoaming, Passpoint, and FIDO Device Onboard (FDO), IoT and edge devices can establish secure connectivity at first power-on, begin ownership transfer, and receive the credentials and configuration required for their operational environment without technicians manually configuring each device.
The new report details how the approach tested by WBA and the FIDO Alliance creates a repeatable onboarding model that reduces credential handling and deployment complexity while maintaining enterprise control over where devices ultimately connect.
Key achievements recorded in the trials included:
Zero-touch IoT onboarding is technically feasible. A factory-provisioned credential mechanism can be used to enable a device to connect automatically to an OpenRoaming network without manual Wi-Fi configuration.
OpenRoaming helps provide the secure bootstrap connection. It gives the device trusted initial connectivity before it transitions to its final enterprise, industrial, or private network.
FDO helps manage secure ownership transfer and configuration. FIDO Device Onboard supports device identity, ownership transfer, and delivery of network credentials, policies, and application configuration.
Manufacturing becomes part of the trust framework. Device-bound certificates and credentials can be securely provisioned before shipment.
The model supports device redeployment. Devices can be reassigned and securely onboarded into new operational environments.
How the Model Works
Under the model, manufacturers can provision devices with cryptographically bound credentials before shipment. When powered up within range of an OpenRoaming-enabled network, the device then authenticates automatically and uses that initial connection to reach its onboarding services.
OpenRoaming acts as a secure bootstrap layer rather than dictating the device’s final network placement. FDO manages device identity, ownership transfer, and delivery of operational credentials, policies, and configuration. The device can then leave the bootstrap connection and move onto its designated enterprise, industrial, private, or other operational network. This separation between initial access and final network placement is designed to enable organizations to automate onboarding without giving up control over local security policies and network access.
The trial team also described how this model could simplify the redeployment of connected products. Devices reassigned to a different site or owner can be securely re-onboarded into a new operational environment rather than requiring extensive manual reconfiguration.
The report also identifies environments that require further technical work, including air-gapped or high-security networks, restricted network segments, and resource-constrained IoT devices that cannot run FDO or a Passpoint supplicant directly. For resource-constrained devices, the report explores a potential proxy model through which a helper device could execute the OpenRoaming and FDO protocols on their behalf. Solutions for air-gapped applications are already being defined and are expected to be part of a future WBA-FDO applications report.
An Invitation to Industry
The WBA and FIDO Alliance are inviting device manufacturers, enterprises, operators, infrastructure providers, and IoT solution developers to participate in the next phase of the work. Priorities include real-world, multi-vendor trials, industry-specific proofs of concept, certificate lifecycle testing, and further development for air-gapped and resource-constrained environments.
Learn more about the market for industrial network infrastructure.