REFERENCE SCENARIO · IMPLEMENTATION-GRADERS-07 — Connected-device onboarding and runtime attestation
This scenario connects a user action to state, authority, policy, evidence and integration boundaries. It is a reference model; legal or regulatory decisions remain with the authoritative party for each data domain.
Actors / systemsDevice / Thing Operator; Device Operations Console; device PKI/attestation verifier; policy engine; connected device.PreconditionsDevice identity/certificate enrolment path exists and selected assurance level is appropriate to risk and device capability.TriggerA device is enrolled, reconnects or is challenged for runtime trust.
End-to-end flowResolve device/thing → verify certificate status → collect attestation evidence where L3 is required → appraise claims against policy → produce runtime trust decision → record evidence → enforce allow/restrict/quarantine independently of ownership.State modelCertificate Valid/Revoked is one state domain; Runtime Trust Trusted/Degraded/Denied is another. Ownership/custody is separate again.Authority boundaryDevice CA/PKI is authoritative for certificate status; the runtime policy/appraisal service is authoritative for the deployment-specific runtime trust decision.
Policy / disclosureAssurance level L0–L3, device class, firmware/secure-boot claims, freshness, nonce/challenge, risk and enforcement policy.EvidenceCertificate check reference, challenge/attestation evidence, appraisal result, policy version, enforcement action and audit.API / event / connectorDevice attestation API; certificate/status integration; evidence API; device events; operations policy/enforcement APIs.
Failure / retry / reconciliation
Stale attestation → challenge again; revoked certificate → deny according to policy; unsupported capability → fall back only to an explicitly permitted lower assurance level, never silently upgrade trust.
Architecture
P03 · P05 · P06
Actor → Experience → Action → Business Object → Authority → Policy → State → Evidence → API/Connector → Architecture → Standard.
Standards / profiles
IEEE 802.1AR / RATS-family concepts where applicable; deployment-specific PKI and attestation profiles.
REFERENCE ARCHITECTURE
Product UI statusUI/UX BASELINE — *_final.png is embedded only when the approved source binary and provenance are available; no screenshot is fabricated to fill a missing source.