Evaluation of FIDO Device Onboard (FDO) for Industrial Bootstrapping

Evaluation of FIDO Device Onboard (FDO) for Industrial Bootstrapping

Supervisor(s): Sebastian Peters, Adrian Reuter
Status: finished
Topic: Others
Author: Patricia Horvath
Submission: 2026-04-08
Type of Thesis: Masterthesis
Thesis topic in co-operation with the Fraunhofer Institute for Applied and Integrated Security AISEC, Garching

Description

Devices deployed in Operational Technology (OT) environments are increasingly inter-
connected, exposing them to threats such as unauthorized access that were previously
mitigated by physical isolation. This trend demands strong device identity and authen-
tication mechanisms based on cryptographic trust anchors to ensure only authorized
devices can join an OT system, making secure bootstrapping a security-critical process
that directly influences the integrity, availability, and safety of these systems. In order to
prevent risks and reduce costs associated with manual commissioning practices, several
zero-touch bootstrapping protocols have been developed. We evaluate the suitability of
FIDO Device Onboard (FDO) for industrial bootstrapping by systematically analyzing
to which degree the controls listed in the established OT security guideline NIST
SP 800-82r3 can be fulfilled by FDO and compare our findings to another bootstrapping
protocol, Secure Zero Touch Provisioning (SZTP), to provide a comparative baseline. We
further examine whether FDO can be deployed in typical OT system architectures. We
find that FDO is suitable for OT systems, provided that certain conditions pertaining to
device capability, manufacturing integrity, organizational processes, and infrastructure
integration are met by the deploying organization.