No Description
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

xep-0324.xml 346KB


  1. <?xml version='1.0' encoding='UTF-8'?>
  2. <!DOCTYPE xep SYSTEM 'xep.dtd' [
  3. <!ENTITY % ents SYSTEM 'xep.ent'>
  4. %ents;
  5. ]>
  6. <?xml-stylesheet type='text/xsl' href='xep.xsl'?>
  7. <xep>
  8. <header>
  9. <title>Internet of Things - Provisioning</title>
  10. <abstract>
  11. Note: This specification has been retracted by the author; new
  12. implementations are not recommended.
  13. This specification describes an architecture for efficient provisioning of
  14. services, access rights and user privileges in for the Internet of Things,
  15. where communication between Things is done using the XMPP protocol.
  16. </abstract>
  17. &LEGALNOTICE;
  18. <number>0324</number>
  19. <status>Retracted</status>
  20. <type>Standards Track</type>
  21. <sig>Standards</sig>
  22. <approver>Council</approver>
  23. <dependencies>
  24. <spec>XMPP Core</spec>
  25. <spec>XEP-0001</spec>
  26. <spec>XEP-0030</spec>
  27. <spec>XEP-0323</spec>
  28. <spec>XEP-0325</spec>
  29. </dependencies>
  30. <supersedes/>
  31. <supersededby/>
  32. <shortname>sensor-network-provisioning</shortname>
  33. &peterwaher;
  34. <revision>
  35. <version>0.5</version>
  36. <date>2017-05-20</date>
  37. <initials>XEP Editor: ssw</initials>
  38. <remark>Mark XEP as retracted by the author.</remark>
  39. </revision>
  40. <revision>
  41. <version>0.4</version>
  42. <date>2015-11-09</date>
  43. <initials>pw</initials>
  44. <remark>
  45. <p>Updated contact information.</p>
  46. <p>Updated example JIDs to example.org</p>
  47. </remark>
  48. </revision>
  49. <revision>
  50. <version>0.3</version>
  51. <date>2014-05-21</date>
  52. <initials>pw</initials>
  53. <remark>
  54. <p>Element renamed from <strong>Friend</strong> to <strong>friend</strong> when recommending friendships.</p>
  55. <p><strong>clearCache</strong> IQ stanzas now of type <strong>set</strong> instead of <strong>get</strong>.</p>
  56. <p>Corrected schema with regards to tokens.</p>
  57. <p>The <strong>getToken</strong> command now takes a base-64 encoded X.509 certificate (public part) instead of arbitrary string IDs.</p>
  58. <p>An additional challenge/response step has been added to make sure the sender of a certificate has access to the private part of the certificate.</p>
  59. <p>Named links to all sections in the document.</p>
  60. <p>Added reference to XEP-0347, for how things can find provisioning servers.</p>
  61. <p>Added method of finding provisioning server, if server hosted as a server component.</p>
  62. <p>Updated examples to reflect a provisioning server hosted as a server component, harmonizing with XEP-0347.</p>
  63. <p>Added a section about token challenges and token propagation.</p>
  64. <p>Added a security note regarding token challenges.</p>
  65. <p>Updated id-attributes in examples.</p>
  66. </remark>
  67. </revision>
  68. <revision>
  69. <version>0.2</version>
  70. <date>2014-03-10</date>
  71. <initials>pw</initials>
  72. <remark>
  73. <p>Corrected downloadPrivileges example.</p>
  74. <p>Made several corrections of the language.</p>
  75. <p>Expanded the introduction.</p>
  76. <p>Changes "Sensor Networks" to "Internet of Things".</p>
  77. <p>Fixed links to documents with new numbers.</p>
  78. <p>Changed namespace urn:xmpp:sn to urn:xmpp:iot</p>
  79. </remark>
  80. </revision>
  81. <revision>
  82. <version>0.1</version>
  83. <date>2013-04-16</date>
  84. <initials>psa</initials>
  85. <remark>
  86. <p>Initial published version approved by the XMPP Council.</p>
  87. </remark>
  88. </revision>
  89. <revision>
  90. <version>0.0.5</version>
  91. <date>2013-04-04</date>
  92. <initials>pw</initials>
  93. <remark>
  94. <p>Added control use cases.</p>
  95. <p>Grouped use cases.</p>
  96. </remark>
  97. </revision>
  98. <revision>
  99. <version>0.0.4</version>
  100. <date>2013-04-01</date>
  101. <initials>pw</initials>
  102. <remark>
  103. <p>Added altitude credentials.</p>
  104. <p>Added resource information of original called to their corresponding JIDs.</p>
  105. <p>Changed the return type of a rejected message.</p>
  106. <p>Made images inline.</p>
  107. <p>Converted the glossary into a definition list.</p>
  108. </remark>
  109. </revision>
  110. <revision>
  111. <version>0.0.3</version>
  112. <date>2013-03-18</date>
  113. <initials>pw</initials>
  114. <remark>
  115. <p>Added information about how to read sensors from large subsystems.</p>
  116. <p>Added friend recommendation message.</p>
  117. <p>Added client/device/service tokens.</p>
  118. </remark>
  119. </revision>
  120. <revision>
  121. <version>0.0.2</version>
  122. <date>2013-03-12</date>
  123. <initials>pw</initials>
  124. <remark>
  125. <p>Added use cases for service access rights and corresponding user privileges.</p>
  126. </remark>
  127. </revision>
  128. <revision>
  129. <version>0.0.1</version>
  130. <date>2013-03-11</date>
  131. <initials>pw</initials>
  132. <remark>
  133. <p>First draft.</p>
  134. </remark>
  135. </revision>
  136. </header>
  137. <section1 topic='Introduction' anchor='intro'>
  138. <p>
  139. This specification describes an architecture for efficient provisioning of services, access rights and user privileges in for the Internet of Things, where
  140. communication between Things is done using the XMPP protocol.
  141. </p>
  142. <p>
  143. Note has to be taken, that this XEP, and other Internet of Things-related XEP's, are designed for implementation in small devices, many of which have very limited
  144. amount of memory (both RAM and ROM) or resources (processing power). Therefore, simplicity is of utmost importance. Furthermore, Internet of Things networks can
  145. become huge, easily containing millions or billions of devices in peer-to-peer networks.
  146. </p>
  147. <p>
  148. An added complexity in the provisioning case is that Things (small sensors for example) often have very limited user interface options. Therefore, this document
  149. explains how provisioning can be done efficiently using a trusted third party with more power and options when it comes to user interface design and storage.
  150. </p>
  151. <p>
  152. This document defines the following important operations to allow for efficient provisioning of services in the Internet of Things, based on XMPP:
  153. </p>
  154. <ul>
  155. <li>What Things knows what Things</li>
  156. <li>What Things can read data from what Things, and what data.</li>
  157. <li>What Things can control what Things, and what parts.</li>
  158. <li>Control of Users in the network.</li>
  159. <li>Control of Services in the network.</li>
  160. <li>Control generic boolean User Privileges in the network.</li>
  161. </ul>
  162. <p>
  163. This XEP relies on &xep0323; and &xep0325; for sensor data readout and control interfaces. It relies on &xep0326; for bridging protocols and interfaing entities with multiple devices
  164. behind them. It also ties into &xep0347; for automatic discovery of provisioning servers by things.
  165. </p>
  166. <p>
  167. Internet of Things contain many different architectures and use cases. For this reason, the IoT standards have been divided into multiple XEPs according to the following table:
  168. </p>
  169. <table caption='Internet of Things XEPs'>
  170. <tr>
  171. <th>XEP</th>
  172. <th>Description</th>
  173. </tr>
  174. <tr>
  175. <td>xep-0000-IoT-BatteryPoweredSensors</td>
  176. <td>Defines how to handle the peculiars related to battery powered devices, and other devices intermittently available on the network.</td>
  177. </tr>
  178. <tr>
  179. <td>xep-0000-IoT-Events</td>
  180. <td>Defines how Things send events, how event subscription, hysteresis levels, etc., are configured.</td>
  181. </tr>
  182. <tr>
  183. <td>xep-0000-IoT-Interoperability</td>
  184. <td>Defines guidelines for how to achieve interoperability in Internet of Things, publishing interoperability interfaces for different types of devices.</td>
  185. </tr>
  186. <tr>
  187. <td>xep-0000-IoT-Multicast</td>
  188. <td>Defines how sensor data can be multicast in efficient ways.</td>
  189. </tr>
  190. <tr>
  191. <td>xep-0000-IoT-PubSub</td>
  192. <td>Defines how efficient publication of sensor data can be made in Internet of Things.</td>
  193. </tr>
  194. <tr>
  195. <td>xep-0000-IoT-Chat</td>
  196. <td>Defines how human-to-machine interfaces should be constructed using chat messages to be user friendly, automatable and consistent with other IoT extensions and possible underlying architecture.</td>
  197. </tr>
  198. <tr>
  199. <td>XEP-0322</td>
  200. <td>
  201. Defines how to EXI can be used in XMPP to achieve efficient compression of data. Albeit not an Internet of Things specific XEP, this XEP should be considered
  202. in all Internet of Things implementations where memory and packet size is an issue.
  203. </td>
  204. </tr>
  205. <tr>
  206. <td>XEP-0323</td>
  207. <td>
  208. Provides the underlying architecture, basic operations and data structures for sensor data communication over XMPP networks.
  209. It includes a hardware abstraction model, removing any technical detail implemented in underlying technologies. This XEP is used by all other
  210. Internet of Things XEPs.
  211. </td>
  212. </tr>
  213. <tr>
  214. <td>XEP-0324</td>
  215. <td>This specification. Defines how provisioning, the management of access privileges, etc., can be efficiently and easily implemented.</td>
  216. </tr>
  217. <tr>
  218. <td>XEP-0325</td>
  219. <td>Defines how to control actuators and other devices in Internet of Things.</td>
  220. </tr>
  221. <tr>
  222. <td>XEP-0326</td>
  223. <td>Defines how to handle architectures containing concentrators or servers handling multiple Things.</td>
  224. </tr>
  225. <tr>
  226. <td>XEP-0331</td>
  227. <td>Defines extensions for how color parameters can be handled, based on &xep0004;</td>
  228. </tr>
  229. <tr>
  230. <td>XEP-0336</td>
  231. <td>Defines extensions for how dynamic forms can be created, based on &xep0004;, &xep0122;, &xep0137; and &xep0141;.</td>
  232. </tr>
  233. <tr>
  234. <td>XEP-0347</td>
  235. <td>Defines the peculiars of sensor discovery in sensor networks. Apart from discovering sensors by JID, it also defines how to discover sensors based on location, etc.</td>
  236. </tr>
  237. </table>
  238. </section1>
  239. <section1 topic='Glossary' anchor='glossary'>
  240. <p>The following table lists common terms and corresponding descriptions.</p>
  241. <dl>
  242. <di>
  243. <dt>Actuator</dt>
  244. <dd>Device containing at least one configurable property or output that can and should be controlled by some other entity or device.</dd>
  245. </di>
  246. <di>
  247. <dt>Authority</dt>
  248. <dd>Used synonymously with Provisioning Server.</dd>
  249. </di>
  250. <di>
  251. <dt>Computed Value</dt>
  252. <dd>A value that is computed instead of measured.</dd>
  253. </di>
  254. <di>
  255. <dt>Concentrator</dt>
  256. <dd>Device managing a set of devices which it publishes on the XMPP network.</dd>
  257. </di>
  258. <di>
  259. <dt>Field</dt>
  260. <dd>
  261. One item of sensor data. Contains information about: Node, Field Name, Value, Precision, Unit, Value Type, Status, Timestamp, Localization information, etc.
  262. Fields should be unique within the triple (Node ID, Field Name, Timestamp).
  263. </dd>
  264. </di>
  265. <di>
  266. <dt>Field Name</dt>
  267. <dd>Name of a field of sensor data. Examples: Energy, Volume, Flow, Power, etc.</dd>
  268. </di>
  269. <di>
  270. <dt>Field Type</dt>
  271. <dd>What type of value the field represents. Examples: Momentary Value, Status Value, Identification Value, Calculated Value, Peak Value, Historical Value, etc.</dd>
  272. </di>
  273. <di>
  274. <dt>Historical Value</dt>
  275. <dd>A value stored in memory from a previous timestamp.</dd>
  276. </di>
  277. <di>
  278. <dt>Identification Value</dt>
  279. <dd>A value that can be used for identification. (Serial numbers, meter IDs, locations, names, etc.)</dd>
  280. </di>
  281. <di>
  282. <dt>Localization information</dt>
  283. <dd>Optional information for a field, allowing the sensor to control how the information should be presented to human viewers.</dd>
  284. </di>
  285. <di>
  286. <dt>Meter</dt>
  287. <dd>A device possible containing multiple sensors, used in metering applications. Examples: Electricity meter, Water Meter, Heat Meter, Cooling Meter, etc.</dd>
  288. </di>
  289. <di>
  290. <dt>Momentary Value</dt>
  291. <dd>A momentary value represents a value measured at the time of the read-out.</dd>
  292. </di>
  293. <di>
  294. <dt>Node</dt>
  295. <dd>
  296. Graphs contain nodes and edges between nodes. In Internet of Things, sensors, actuators, meters, devices, gateways, etc., are often depicted as nodes whereas links between sensors (friendships)
  297. are depicted as edges. In abstract terms, it's easier to talk about a Node, rather than list different possible node types (sensors, actuators, meters, devices, gateways, etc.).
  298. Each Node has a Node ID.
  299. </dd>
  300. </di>
  301. <di>
  302. <dt>Node ID</dt>
  303. <dd>
  304. An ID uniquely identifying a node within its corresponding context. If a globally unique ID is desired, an architecture should be used using a universally accepted
  305. ID scheme.
  306. </dd>
  307. </di>
  308. <di>
  309. <dt>Parameter</dt>
  310. <dd>
  311. Readable and/or writable property on a node/device. The XEP-0326 &xep0326; deals with reading and writing parameters
  312. on nodes/devices. Fields are not parameters, and parameters are not fields.
  313. </dd>
  314. </di>
  315. <di>
  316. <dt>Peak Value</dt>
  317. <dd>A maximum or minimum value during a given period.</dd>
  318. </di>
  319. <di>
  320. <dt>Provisioning Server</dt>
  321. <dd>An application that can configure a network and provide services to users or Things. In Internet of Things, a Provisioning Server knows who knows whom,
  322. what privileges users have, who can read what data and who can control what devices and what parts of these devices.</dd>
  323. </di>
  324. <di>
  325. <dt>Precision</dt>
  326. <dd>
  327. In physics, precision determines the number of digits of precision. In sensor networks however, this definition is not easily applicable. Instead, precision
  328. determines, for example, the number of decimals of precision, or power of precision. Example: 123.200 MWh contains 3 decimals of precision. All entities parsing and
  329. delivering field information in sensor networks should always retain the number of decimals in a message.
  330. </dd>
  331. </di>
  332. <di>
  333. <dt>Sensor</dt>
  334. <dd>
  335. Device measuring at least one digital value (0 or 1) or analog value (value with precision and physical unit). Examples: Temperature sensor, pressure sensor, etc.
  336. Sensor values are reported as fields during read-out. Each sensor has a unique Node ID.
  337. </dd>
  338. </di>
  339. <di>
  340. <dt>SN</dt>
  341. <dd>Sensor Network. A network consisting, but not limited to sensors, where transport and use of sensor data is of primary concern. A sensor network may contain actuators, network applications, monitors, services, etc.</dd>
  342. </di>
  343. <di>
  344. <dt>Status Value</dt>
  345. <dd>A value displaying status information about something.</dd>
  346. </di>
  347. <di>
  348. <dt>Timestamp</dt>
  349. <dd>Timestamp of value, when the value was sampled or recorded.</dd>
  350. </di>
  351. <di>
  352. <dt>Thing</dt>
  353. <dd>
  354. Internet of Things basically consists of Things connected to the Internet. Things can be any device, sensor, actuator etc., that can have an
  355. Internet connection.
  356. </dd>
  357. </di>
  358. <di>
  359. <dt>Thing Registry</dt>
  360. <dd>
  361. A registry where Things can register for simple and secure discovery by the owner of the Thing. The registry can also be used as a database for meta information
  362. about Things in the network.
  363. </dd>
  364. </di>
  365. <di>
  366. <dt>Token</dt>
  367. <dd>
  368. A client, device or user can get a token from a provisioning server. These tokens can be included in requests to other entities in the network, so these entities can validate
  369. access rights with the provisioning server.
  370. </dd>
  371. </di>
  372. <di>
  373. <dt>Unit</dt>
  374. <dd>Physical unit of value. Example: MWh, l/s, etc.</dd>
  375. </di>
  376. <di>
  377. <dt>Value</dt>
  378. <dd>A field value.</dd>
  379. </di>
  380. <di>
  381. <dt>Value Status</dt>
  382. <dd>Status of field value. Contains important status information for Quality of Service purposes. Examples: Ok, Error, Warning, Time Shifted, Missing, Signed, etc.</dd>
  383. </di>
  384. <di>
  385. <dt>Value Type</dt>
  386. <dd>Can be numeric, string, boolean, Date &amp; Time, Time Span or Enumeration.</dd>
  387. </di>
  388. <di>
  389. <dt>WSN</dt>
  390. <dd>Wireless Sensor Network, a sensor network including wireless devices.</dd>
  391. </di>
  392. <di>
  393. <dt>XMPP Client</dt>
  394. <dd>Application connected to an XMPP network, having a JID. Note that sensors, as well as applications requesting sensor data can be XMPP clients.</dd>
  395. </di>
  396. </dl>
  397. </section1>
  398. <section1 topic='Use Cases' anchor='usecases'>
  399. <p>
  400. The most basic use case in sensor networks is to read out sensor data from a sensor. However, since protecting end-user integrity and system security is vital, access
  401. rights and user privileges have to be imposed on the network.
  402. </p>
  403. <p>
  404. To store access rights in all sensors might be very impractical. Not only does it consume memory, it's difficult to maintain track of the current system status, make sure
  405. all devices have the latest configuration, distribute changes to the configuration, etc.
  406. </p>
  407. <p>
  408. Furthermore, most sensors and small devices have very limited possibility to provide a rich user interface. Perhaps all it can do is to provide a small LED and a button,
  409. useful perhaps for installing the sensor in the network, but not much more.
  410. </p>
  411. <p>
  412. As an added complexity, the sensor network operator might not even have access to the XMPP Servers used, and provisioning needs to lie outside of the XMPP Server domains.
  413. </p>
  414. <p>
  415. To solve this problem in an efficient manner, an architecture using distributed trusted third parties is proposed. Such third parties would:
  416. </p>
  417. <ul>
  418. <li>Provide a rich user interface and configurable options to end user or back end systems.</li>
  419. <li>Control friendships (who can communicate with whom).</li>
  420. <li>Control content available for different friends (what can be read by whom).</li>
  421. <li>Control operations accessible by different friends (what can be controlled/configured by whom).</li>
  422. <li>Provide additional interoperability services to nodes in the network (for instance, unit conversion).</li>
  423. </ul>
  424. <section2 topic='Delegating trust' anchor='delegatingtrust'>
  425. <section3 topic='Delegating original trust to a Provisioning Server' anchor='delegatingoriginaltrust'>
  426. <p>
  427. A provisioning server can be accessed either through a JID published by the provisioning server, or through a subdomain address, if hosted as a server component.
  428. This section will show how to delegate original trust to a Provisioning Server, in the case the server uses a JID to communicate with things.
  429. </p>
  430. <p>
  431. Trust is delegated to a provisioning server by a device, simply by befriending the provisioning server and asking it questions and complying with
  432. its answers. As an illustrative example, following is a short description of how such a trust relationship can be created in a scenario where the sensor only
  433. has a single LED and a single button.
  434. </p>
  435. <ul>
  436. <li>Somebody is installing the sensor, giving it a connection to an XMPP server and a JID, reachable from the provisioning server.</li>
  437. <li>The provisioning server is told to create a friendship request to the new sensor.</li>
  438. <li>The sensor flashes its LED for a given time (for example: 30 seconds).</li>
  439. <li>Viewing the LED, the person installing the sensor presses the button.</li>
  440. <li>Receiving the button press within the given time period, accepts the friendship request. Optionally, the device can give user feedback using the LED.</li>
  441. <li>The device performs a service discovery of the new friend, having been a manually added friend.</li>
  442. <li>If the new friend supports this provisioning extension, further responsibilities are delegated to this device.</li>
  443. <li>As the last step the device asks the provisioning server for a token. This device token is later used in calls to other devices and can be used to check access rights.</li>
  444. </ul>
  445. <p>
  446. The following diagram shows the general case:
  447. </p>
  448. <p>
  449. <img src=''/>
  450. </p>
  451. <p>
  452. The successful case can also be illustrated in a sequence diagram, as follows:
  453. </p>
  454. <p>
  455. <img src=''/>
  456. </p>
  457. <p>
  458. <strong>Note:</strong> In many cases, an address to a provisioning server might be preprogrammed during production of the
  459. device. In these cases, parts of the above procedure may not be necessary. All the client needs to do, if the provisioning server is not available
  460. in the roster of the device, is to send a subscription request to the provisioning server, to alert the server of the existence of the device,
  461. and possibly request a device token.
  462. </p>
  463. <p>
  464. <strong>Note 2:</strong> A certificate token has an undefined lifetime. It can be reused across sessions.
  465. </p>
  466. <p>
  467. The following use cases will assume such a trust relationship has been created between the corresponding device and the provisioning server.
  468. </p>
  469. </section3>
  470. <section3 topic='Provisioning Server as a server component' anchor='servercomponent'>
  471. <p>
  472. A provisioning server can also be hosted as a server component, and in these cases be addressed by using the component address, or sub-domain address of the component.
  473. In this case, the client searches through the components hosted by the server to see if one of them is a Provisioning Server. There are no friendship requests and
  474. presence subscriptions necessary, when communicating with a Provisioning Server hosted as a server component.
  475. </p>
  476. <p>
  477. To search for a Provisioning Server hosted as a component on an XMPP Server, you first request a list of available components, as follows:
  478. </p>
  479. <example caption="Checking if server supports components">
  480. <![CDATA[
  481. <iq from='device@example.org/device' to='example.org' type='get' id='1'>
  482. <query xmlns="http://jabber.org/protocol/disco#info"/>
  483. </iq>
  484. <iq type="result" id="1" from="example.org" to="device@example.org/device">
  485. <query xmlns="http://jabber.org/protocol/disco#info">
  486. ...
  487. <feature var="http://jabber.org/protocol/disco#items"/>
  488. ...
  489. </query>
  490. </iq>]]>
  491. </example>
  492. <p>
  493. If components (items) are supported, a request for available components is made:
  494. </p>
  495. <example caption="Requesting list of server components">
  496. <![CDATA[
  497. <iq from='device@example.org/device' to='example.org' type='get' id='2'>
  498. <query xmlns="http://jabber.org/protocol/disco#items"/>
  499. </iq>
  500. <iq type="result" id="2" from="example.org" to="995fab3dd759452ca9c370647323af0c@example.org/ebe2348e">
  501. <query xmlns="http://jabber.org/protocol/disco#items">
  502. ...
  503. <item jid="provisioning.example.org" name="Provisioning"/>
  504. ...
  505. </query>
  506. </iq>]]>
  507. </example>
  508. <p>
  509. The client then loops through all components (items) and checks what features they support, until a Provisioning Server is found:
  510. </p>
  511. <example caption="Service discovery information request made to each component">
  512. <![CDATA[
  513. <iq type='get'
  514. from='device@example.org/device'
  515. to='provisioning.example.org'
  516. id='3'>
  517. <query xmlns='http://jabber.org/protocol/disco#info'/>
  518. </iq>
  519. <iq type='result'
  520. from='provisioning.example.org'
  521. to='device@example.org/device'
  522. id='3'>
  523. <query xmlns='http://jabber.org/protocol/disco#info'>
  524. ...
  525. <feature var='urn:xmpp:iot:provisioning'/>
  526. ...
  527. </query>
  528. </iq>]]>
  529. </example>
  530. </section3>
  531. <section3 topic="Tokens and X.509 Certificates" anchor="tokenscertificats">
  532. <p>
  533. The provisioning server contains a set of rules defining what operation can take place and by whom, by participants in the network. Rules can be applied based on JIDs used,
  534. content affected, and also through device, service and user identities based on X.509 Certificates. In order for a service (for instance) to identify itself in the network, it
  535. uses an X.509 certificate. It sends the public part of this certificate to the provisioning server, and receives a token back in the form of a simple string. This token can then
  536. be used in requests and propagated through the network.
  537. </p>
  538. <p>
  539. To validate that the sender is allowed to use the certificate using its token, it encrypts a challenge using the public part of the certificate and sends it to the sender of the
  540. token, who in turn decrypts it using the private part of the certificate and returns it to the server. The provisioning server can also use the public part of the certificate to
  541. perform validation checks on the certificate itself. If the certificate becomes invalid, the provisioning server can invalidate any corresponding rules in the network. If the sender
  542. of a token cannot respond to a token challenge, the provisioning server can also refuse to allow the operation.
  543. </p>
  544. <p>
  545. In case of multiple units being part of an operation, a token can be propagated in the network. For example, a service can read data from U1, who reads data from U2. The service
  546. provides a token to U1, who propagates this token in the request to U2. When U2 asks the provisioning server if the operation should be allowed or not, the server knows what entity
  547. originated the request. If the provisioning server wants to challenge U2, concerning the token, U2 propagates the challenge to U1, who propagates it to the service, who can resolve
  548. the challenge, returns the response back to U1 who returns the response to U2 who in turn returns it to the provisioning server.
  549. </p>
  550. <p>
  551. <img src=''/>
  552. </p>
  553. <section4 topic='Requesting a token' anchor='requesttoken'>
  554. <p>
  555. The following example shows how a device or service can request a token from the provisioning server, by providing the base-64 encoded public part of an X.509 certificate.
  556. This step is optional, but can be used as a method to identify the device (or service), apart from the JID it is using. This might be useful if you want to assign a particular
  557. device or service privileges in the provisioning server, regardless of the JID it uses to perform the action.
  558. </p>
  559. <example caption='Requesting a token'>
  560. <![CDATA[
  561. <iq type='get'
  562. from='device@example.org/device'
  563. to='provisioning.example.org'
  564. id='4'>
  565. <getToken xmlns='urn:xmpp:iot:provisioning'>BASE-64 ENCODED PUBLIC X.509 CERTIFICATE</getToken>
  566. </iq>
  567. <iq type='result'
  568. from='provisioning.example.org'
  569. to='device@example.org/device'
  570. id='4'>
  571. <getTokenChallenge xmlns='urn:xmpp:iot:provisioning' seqnr='1'>BASE-64 ENCODED CHALLENGE</getTokenChallenge>
  572. </iq>
  573. <iq type='get'
  574. from='device@example.org/device'
  575. to='provisioning.example.org'
  576. id='5'>
  577. <getTokenChallengeResponse xmlns='urn:xmpp:iot:provisioning' seqnr='1'>BASE-64 ENCODED RESPONSE</getTokenChallengeResponse>
  578. </iq>
  579. <iq type='result'
  580. from='provisioning.example.org'
  581. to='device@example.org/device'
  582. id='5'>
  583. <getTokenResponse xmlns='urn:xmpp:iot:provisioning' token='TOKEN'/>
  584. </iq>]]>
  585. </example>
  586. <p>
  587. The <strong>getToken</strong> element contains the base-64 encoded public version of the certificate that is used to identify the device or service. The server
  588. responds with a challenge in a <strong>getTokenChallenge</strong> response. This challenge is also a base-64 encoded binary block of data, which corresponds to a random
  589. sequence of bytes that is then encrypted using the public certificate. Now, the device, or service, decrypts this challenge using the private part of the certificate, and
  590. returns the base-64 encoded decrypted version of the challenge back to the provisioning server using the <strong>getTokenChallengeResponse</strong> element. The provisioning
  591. server checks the response to the original random sequence of bytes. If equal, the provisioning server responds with a <strong>getTokenResponse</strong> result, containing
  592. the token (a string this time) that can be used when reference to the identity defined by the certificate has to be made. The provisioning server must not return tokens that
  593. contain white space characters.
  594. </p>
  595. <p>
  596. If the response to the challenge is wrong, the server returns a <strong>bad-request</strong> error result, as is shown below.
  597. </p>
  598. <example caption='Challenge reponse incorrect'>
  599. <![CDATA[
  600. <iq type='result'
  601. from='provisioning.example.org'
  602. to='device@example.org/device'
  603. id='5'>
  604. <error type='modify'>
  605. <bad-request xmlns='urn:ietf:params:xml:ns:xmpp-stanzas'/>
  606. </error>
  607. </iq>]]>
  608. </example>
  609. <p>
  610. If the sequence number identifying the challenge is not found on the server, the server returns a <strong>item-not-found</strong> error result, as is shown below.
  611. </p>
  612. <example caption='Challenge sequence number not found'>
  613. <![CDATA[
  614. <iq type='result'
  615. from='provisioning.example.org'
  616. to='device@example.org/device'
  617. id='5'>
  618. <error type='cancel'>
  619. <item-not-found xmlns='urn:ietf:params:xml:ns:xmpp-stanzas'/>
  620. </error>
  621. </iq>]]>
  622. </example>
  623. <p>
  624. The server must retain the challenge in memory for at least one minute before assuming the challenge will go unresponded.
  625. </p>
  626. </section4>
  627. <section4 topic='Provisioning Server challenging a token' anchor='tokenchallenge'>
  628. <p>
  629. For reasons the provisioning server determines, it can challenge the use of a token in any of the requests made to it. This is done by sending a
  630. iq get stanza with a <strong>tokenChallenge</strong> to the party sending the token. This element contains both the token being challenged, and a binary
  631. challenge. This challenge is made up of a random block of data that is encrypted using the public certificate referred to by the token.
  632. </p>
  633. <p>
  634. The receiver of the challenge, if it has access to the private certificate referenced, decrypts the challenge, and returns the decrypted binary block of data
  635. to the caller (i.e. the Provisioning Server in this case). If the decrypted block of data corresponds to the original random block of data encrypted, the sender
  636. of the token is considered to be allowed to use the token.
  637. </p>
  638. <p>
  639. If the received of the challenge does not have access to the private certificate referenced, but used the token in a propagated request made to it, it can propagate the
  640. request to the original sender of the token. When the response is returned, it returns the response in turn to the sender of the challenge.
  641. </p>
  642. <p>
  643. A challenge/response sequence can look as follows:
  644. </p>
  645. <example caption='Requesting a token'>
  646. <![CDATA[
  647. <iq type='get'
  648. from='provisioning.example.org'
  649. to='device@example.org/device'
  650. id='6'>
  651. <tokenChallenge xmlns='urn:xmpp:iot:provisioning' token='TOKEN'>BASE-64 encoded challenge</tokenChallenge>
  652. </iq>
  653. <iq type='result'
  654. from='device@example.org/device'
  655. to='provisioning.example.org'
  656. id='6'>
  657. <tokenChallengeResponse xmlns='urn:xmpp:iot:provisioning'>BASE-64 encoded response</tokenChallengeResponse>
  658. </iq>]]>
  659. </example>
  660. <p>
  661. <strong>Note:</strong> It is important that a unit only responds to a <strong>tokenChallenge</strong> request from a JID to which the corresponding token
  662. has been sent. If a token challenge is received from a JID to which the token has not been sent the last minute, the following error message must be returned:
  663. </p>
  664. <example caption='Invalid token challenge'>
  665. <![CDATA[
  666. <iq type='error'
  667. from='device@example.org/device'
  668. to='provisioning.example.org'
  669. id='6'>
  670. <error type='cancel'>
  671. <forbidden xmlns='urn:ietf:params:xml:ns:xmpp-stanzas'/>
  672. </error>
  673. </iq>]]>
  674. </example>
  675. </section4>
  676. </section3>
  677. <section3 topic='Delegating Secondary Trust' anchor='delegatingsecondarytrust'>
  678. <p>
  679. The <strong>isFriendResponse</strong> element returned by the provisioning server contains an attribute <strong>secondaryTrustAllowed</strong> that is by default
  680. set to false. If the provisioning server has no problem with allowing multiple trust to be delegated by devices in the network, it can choose to set this
  681. attribute to true in the response. If true, the device knows it has the right to add its own friends, or to add secondary trust relationships.
  682. </p>
  683. <p>
  684. The following diagram continues with the example given above, of how a sensor with a limited user interface, can allow to manually add new friends, including new
  685. trust relationships using a single LED and a button.
  686. </p>
  687. <p>
  688. <img src=''/>
  689. </p>
  690. </section3>
  691. <section3 topic='Multiple tokens' anchor='multipletokens'>
  692. <p>
  693. When multiple trust is used, the entity (client, user, service, etc.) has one token from each provisioning server. However, when sending a token to a third party,
  694. the sender does not know what provisioning server(s) the third party uses to check access rights and user privileges. Therefore, the client must send all tokens, separated
  695. by a space.
  696. </p>
  697. <p>
  698. When a provisioning server receives a request containing multiple tokens, the most forgiving response must be returned.
  699. </p>
  700. <example caption='Readout request using multiple tokens'>
  701. <![CDATA[
  702. <iq type='get'
  703. from='master@example.org/amr'
  704. to='device@example.org'
  705. id='7'>
  706. <req xmlns='urn:xmpp:iot:sensordata' momentary='true' serviceToken='SERVICETOKEN1 SERVICETOKEN2' userToken='USERTOKEN1' seqnr='4'/>
  707. </iq>
  708. <iq type='get'
  709. from='device@example.org/device'
  710. to='provisioning.example.org'
  711. id='8'>
  712. <canRead xmlns='urn:xmpp:iot:provisioning' jid='master@example.org' serviceToken='SERVICETOKEN1 SERVICETOKEN2' userToken='USERTOKEN1' momentary='true'/>
  713. </iq>
  714. <iq type='result'
  715. from='provisioning.example.org'
  716. to='device@example.org/device'
  717. id='8'>
  718. <canReadResponse xmlns='urn:xmpp:iot:provisioning' jid='master@example.org' momentary='true' result='true'/>
  719. </iq>
  720. <iq type='result'
  721. from='device@example.org'
  722. to='master@example.org/amr'
  723. id='7'>
  724. <accepted xmlns='urn:xmpp:iot:sensordata' seqnr='4'/>
  725. </iq>]]>
  726. </example>
  727. </section3>
  728. <p>
  729. <strong>Note:</strong> When a provisioning server wants to challenge multiple tokens, separate token challenges are sent, one for each token being challenged.
  730. </p>
  731. </section2>
  732. <section2 topic='Friendships' anchor='friendships'>
  733. <section3 topic='Friendship request accepted' anchor='friendshiprequestaccepted'>
  734. <p>
  735. The following diagram displays how a friendship request from an external party can be handled, delegating the responsibility to a trusted third party:
  736. </p>
  737. <p>
  738. <img src=''/>
  739. </p>
  740. <p>
  741. The communication between the XMPP Device and the Provisioning Server could be as follows:
  742. </p>
  743. <example caption='Friendship request accepted'>
  744. <![CDATA[
  745. <iq type='get'
  746. from='device@example.org/device'
  747. to='provisioning.example.org'
  748. id='9'>
  749. <isFriend xmlns='urn:xmpp:iot:provisioning' jid='client1@example.org'/>
  750. </iq>
  751. <iq type='result'
  752. from='provisioning.example.org'
  753. to='device@example.org/device'
  754. id='9'>
  755. <isFriendResponse xmlns='urn:xmpp:iot:provisioning' jid='client1@example.org' result='true'/>
  756. </iq>]]>
  757. </example>
  758. <p>
  759. <strong>Note:</strong> The provisioning server implicitly understands which two JIDs that are to be checked: The first one is the sender of the message, the second one
  760. is the JID available in the <strong>jid</strong> attribute in the request.
  761. </p>
  762. <p>
  763. <strong>Note 2:</strong> Any resource information in the JID must be ignored by the provisioning server.
  764. </p>
  765. </section3>
  766. <section3 topic='Friendship request rejected' anchor='friendshiprequestrejected'>
  767. <p>
  768. The following diagram displays a friendship request from an external party being rejected as a result of the trusted third party negating the friendship:
  769. </p>
  770. <p>
  771. <img src=''/>
  772. </p>
  773. <p>
  774. The communication between the XMPP Device and the Provisioning Server could be as follows:
  775. </p>
  776. <example caption='Friendship request rejected'>
  777. <![CDATA[
  778. <iq type='get'
  779. from='device@example.org/device'
  780. to='provisioning.example.org'
  781. id='10'>
  782. <isFriend xmlns='urn:xmpp:iot:provisioning' jid='client2@example.org'/>
  783. </iq>
  784. <iq type='result'
  785. from='provisioning.example.org'
  786. to='device@example.org/device'
  787. id='10'>
  788. <isFriendResponse xmlns='urn:xmpp:iot:provisioning' jid='client2@example.org' result='false'/>
  789. </iq>]]>
  790. </example>
  791. </section3>
  792. <section3 topic='Unfriending existing friends' anchor='unfriendingexistingfriends'>
  793. <p>
  794. If the provisioning server decides that two friends in the network should no longer be friends and communicate with each other, it simply sends a message to
  795. at least one of the friends as follows:
  796. </p>
  797. <p>
  798. <img src=''/>
  799. </p>
  800. <p>
  801. The provisioning server should only send such messages to clients that have previously asked the provisioning server if friendship requests should be accepted or not.
  802. </p>
  803. <p>
  804. <strong>Note:</strong> The device should only honor such messages, if the sender is the trusted third party. Such messages received from other entities not trusted should
  805. be silently ignored.
  806. </p>
  807. <example caption='Unfriending existing friend'>
  808. <![CDATA[
  809. <message from='provisioning.example.org'
  810. to='device@example.org'>
  811. <unfriend xmlns='urn:xmpp:iot:provisioning' jid='client2@example.org'/>
  812. </message>]]>
  813. </example>
  814. </section3>
  815. <section3 topic='Recommending friendships' anchor='recommendingfriendships'>
  816. <p>
  817. The provisioning server can, apart from accepting new friendships and rejecting old friendships, also recommend new friendships. In this case, the provisioning server
  818. simply sends a message to one or both of the soon to be friends, as follows:
  819. </p>
  820. <p>
  821. <img src=''/>
  822. </p>
  823. <example caption='Recommending friendships'>
  824. <![CDATA[
  825. <message from='provisioning.example.org'
  826. to='device@example.org'>
  827. <friend xmlns='urn:xmpp:iot:provisioning' jid='client2@example.org'/>
  828. </message>]]>
  829. </example>
  830. <p>
  831. Note that the receptor can still ask the provisioning server if it can form a friendship with the suggested friend, using the <strong>isFriend</strong> command.
  832. </p>
  833. </section3>
  834. </section2>
  835. <section2 topic='Device Read-out' anchor='devicereadouts'>
  836. <section3 topic='Rejecting read-outs' anchor='rejectingreadouts'>
  837. <p>
  838. An important use case for provisioning in sensor networks is who gets to read out sensor data from which sensors. This use case details how communication with a
  839. provisioning server can help the device determine if a client has sufficient access rights to read the values of the device.
  840. </p>
  841. <p>
  842. <img src=''/>
  843. </p>
  844. <p>
  845. <strong>Note:</strong> This use case is an extension of the use case 'Read-out rejected' in the XEP-0323
  846. <link url='http://xmpp.org/extensions/xep-0323.html'>Internet of Things - Sensor Data</link>.
  847. </p>
  848. <p>
  849. The following example shows the communication first between the client and the device, then between the device and the provisioning server, and last between the device and the client:
  850. </p>
  851. <example caption='Rejecting read-outs'>
  852. <![CDATA[
  853. <iq type='get'
  854. from='master@example.org/amr'
  855. to='device@example.org'
  856. id='11'>
  857. <req xmlns='urn:xmpp:iot:sensordata' momentary='true' serviceToken='SERVICETOKEN1' userToken='USERTOKEN1' seqnr='1'/>
  858. </iq>
  859. <iq type='get'
  860. from='device@example.org/device'
  861. to='provisioning.example.org'
  862. id='12'>
  863. <canRead xmlns='urn:xmpp:iot:provisioning' jid='master@example.org' serviceToken='SERVICETOKEN1' userToken='USERTOKEN1' momentary='true'/>
  864. </iq>
  865. <iq type='result'
  866. from='provisioning.example.org'
  867. to='device@example.org/device'
  868. id='12'>
  869. <canReadResponse xmlns='urn:xmpp:iot:provisioning' jid='master@example.org' momentary='true' result='false'/>
  870. </iq>
  871. <iq type='error'
  872. from='device@example.org'
  873. to='master@example.org/amr'
  874. id='11'>
  875. <rejected xmlns='urn:xmpp:iot:sensordata' seqnr='1'>
  876. <error>Access denied.</error>
  877. </rejected>
  878. </iq>]]>
  879. </example>
  880. </section3>
  881. <section3 topic='Restricting nodes during read-out' anchor='restrictingnodes'>
  882. <p>
  883. In case the device handles multiple nodes that can be read, the provisioning server has the possibility to grant read-out, but to limit the nodes that can be read out.
  884. The provisioning server does this by returning the list of nodes that can be read.
  885. </p>
  886. <p>
  887. <img src=''/>
  888. </p>
  889. <p>
  890. <strong>Note:</strong> This use case is an extension of the use case 'Read-out of multiple devices' in the XEP-0323
  891. <link url='http://xmpp.org/extensions/xep-0323.html'>Internet of Things - Sensor Data</link>.
  892. </p>
  893. <p>
  894. <strong>Note 2:</strong> If the server responds, but without specifying a list of nodes, the device can assume that all nodes available in the original request are allowed
  895. to be read. If no nodes in the request are allowed to be read, the provisioning server must respond with a result='false', so the device can reject the read-out request.
  896. </p>
  897. <p>
  898. The following example shows the communication first between the client and the device, then between the device and the provisioning server, and last between the device and the client:
  899. </p>
  900. <example caption='Restricting nodes during read-out'>
  901. <![CDATA[
  902. <iq type='get'
  903. from='master@example.org/amr'
  904. to='device@example.org'
  905. id='13'>
  906. <req xmlns='urn:xmpp:iot:sensordata' momentary='true' serviceToken='SERVICETOKEN1' userToken='USERTOKEN1' seqnr='2'>
  907. <node nodeId='Device02'/>
  908. <node nodeId='Device03'/>
  909. </req>
  910. </iq>
  911. <iq type='get'
  912. from='device@example.org/device'
  913. to='provisioning.example.org'
  914. id='14'>
  915. <canRead xmlns='urn:xmpp:iot:provisioning' jid='master@example.org' momentary='true' serviceToken='SERVICETOKEN1' userToken='USERTOKEN1'>
  916. <node nodeId='Device02'/>
  917. <node nodeId='Device03'/>
  918. </canRead>
  919. </iq>
  920. <iq type='result'
  921. from='provisioning.example.org'
  922. to='device@example.org/device'
  923. id='14'>
  924. <canReadResponse xmlns='urn:xmpp:iot:provisioning' jid='master@example.org' momentary='true' result='true'>
  925. <node nodeId='Device02'/>
  926. </canReadResponse>
  927. </iq>
  928. <iq type='result'
  929. from='device@example.org'
  930. to='master@example.org/amr'
  931. id='13'>
  932. <accepted xmlns='urn:xmpp:iot:sensordata' seqnr='2'/>
  933. </iq>]]>
  934. </example>
  935. <p>
  936. Note that the provisioning server responds with a <strong>canReadResponse</strong> element, similar to the <strong>canRead</strong> element in the request, except
  937. only the nodes allowed to be read are read. The device must only permit read-out of nodes listed in the response from the provisioning server. Other nodes available
  938. in the request should be ignored.
  939. </p>
  940. </section3>
  941. <section3 topic='Restricting fields during read-out' anchor='restrictingfields'>
  942. <p>
  943. In case the provisioning server wants to limit the fields a device can send to a client, the provisioning server has the possibility to grant read-out, but
  944. list a set of fields the device is allowed to send to the corresponding client.
  945. </p>
  946. <p>
  947. <img src=''/>
  948. </p>
  949. <p>
  950. <strong>Note:</strong> If the server responds, but without specifying a list of field names, the device can assume that all fields available in the original request are allowed
  951. to be sent. If no fields in the request are allowed to be sent, the provisioning server must respond with a result='false', so the device can reject the read-out request.
  952. </p>
  953. <p>
  954. The following example shows the communication first between the client and the device, then between the device and the provisioning server, and last between the device and the client:
  955. </p>
  956. <example caption='Restricting fields during read-out'>
  957. <![CDATA[
  958. <iq type='get'
  959. from='master@example.org/amr'
  960. to='device@example.org'
  961. id='15'>
  962. <req xmlns='urn:xmpp:iot:sensordata' momentary='true' serviceToken='SERVICETOKEN1' userToken='USERTOKEN1' seqnr='3'/>
  963. </iq>
  964. <iq type='get'
  965. from='device@example.org/device'
  966. to='provisioning.example.org'
  967. id='16'>
  968. <canRead xmlns='urn:xmpp:iot:provisioning' jid='master@example.org' momentary='true' serviceToken='SERVICETOKEN1' userToken='USERTOKEN1'/>
  969. </iq>
  970. <iq type='result'
  971. from='provisioning.example.org'
  972. to='device@example.org/device'
  973. id='16'>
  974. <canReadResponse xmlns='urn:xmpp:iot:provisioning' jid='master@example.org' momentary='true' result='true'>
  975. <field name='Energy'/>
  976. <field name='Power'/>
  977. </canReadResponse>
  978. </iq>
  979. <iq type='result'
  980. from='device@example.org'
  981. to='master@example.org/amr'
  982. id='15'>
  983. <accepted xmlns='urn:xmpp:iot:sensordata' seqnr='3'/>
  984. </iq>]]>
  985. </example>
  986. <p>
  987. Note that the provisioning server responds with a <strong>canReadResponse</strong> element, similar to the <strong>canRead</strong> element in the request, except only
  988. the fields allowed to be sent are listed. The client must only send fields having field names in this list.
  989. </p>
  990. <p>
  991. Also note, that the provisioning server can return a list of both allowed nodes and allowed field names in the response. In this case, the device must only send allowed fields
  992. from allowed nodes, and ignore all other fields and/or nodes.
  993. </p>
  994. </section3>
  995. </section2>
  996. <section2 topic='Device Control' anchor='devicecontrol'>
  997. <section3 topic='Rejecting control actions' anchor='rejectingcontrolactions'>
  998. <p>
  999. An important use case for provisioning in sensor networks is who gets to control devices, and what they can control. This use case details how communication with a
  1000. provisioning server can help the device determine if a client has sufficient access rights to perform control actions on the device.
  1001. </p>
  1002. <p>
  1003. <img src=''/>
  1004. <!-- sensor-network-provisioning-15.png-->
  1005. </p>
  1006. <p>
  1007. The following example shows the communication first between the client and the device, then between the device and the provisioning server, and last between the device and the client:
  1008. </p>
  1009. <example caption='Rejecting control action'>
  1010. <![CDATA[
  1011. <iq type='set'
  1012. from='master@example.org/amr'
  1013. to='device@example.org'
  1014. id='17'>
  1015. <set xmlns='urn:xmpp:iot:control' xml:lang='en'>
  1016. <boolean name='Output' value='true'/>
  1017. </set>
  1018. </iq>
  1019. <iq type='get'
  1020. from='device@example.org/device'
  1021. to='provisioning.example.org'
  1022. id='18'>
  1023. <canControl xmlns='urn:xmpp:iot:provisioning' jid='master@example.org' serviceToken='SERVICETOKEN1' userToken='USERTOKEN1'>
  1024. <parameter name='Output'/>
  1025. </canControl>
  1026. </iq>
  1027. <iq type='result'
  1028. from='provisioning.example.org'
  1029. to='device@example.org/device'
  1030. id='18'>
  1031. <canControlResponse xmlns='urn:xmpp:iot:provisioning' jid='master@example.org' result='false'/>
  1032. </iq>
  1033. <iq type='error'
  1034. from='device@example.org'
  1035. to='master@example.org/amr'
  1036. id='17'>
  1037. <setResponse xmlns='urn:xmpp:iot:control' responseCode='InsufficientPrivileges'/>
  1038. </iq>]]>
  1039. </example>
  1040. </section3>
  1041. <section3 topic='Restricting nodes during control' anchor='restrictingnodescontrol'>
  1042. <p>
  1043. In case the device handles multiple nodes that can be read, the provisioning server has the possibility to grant control access, but to limit the nodes that can be controlled.
  1044. The provisioning server does this by returning the list of nodes that can be controlled.
  1045. </p>
  1046. <p>
  1047. <img src=''/>
  1048. <!-- sensor-network-provisioning-14.png-->
  1049. </p>
  1050. <p>
  1051. <strong>Note:</strong> If the server responds, but without specifying a list of nodes, the device can assume that all nodes available in the original request are allowed
  1052. to be controlled. If no nodes in the request are allowed to be controlled, the provisioning server must respond with a result='false', so the device can reject the read-out request.
  1053. The same is true for parameters: If the provisioning server does not specify parameters in the response, the caller can assume all parameters are allowed.
  1054. </p>
  1055. <p>
  1056. The following example shows the communication first between the client and the device, then between the device and the provisioning server, and last between the device and the client:
  1057. </p>
  1058. <example caption='Restricting nodes during control'>
  1059. <![CDATA[
  1060. <iq type='set'
  1061. from='master@example.org/amr'
  1062. to='concentrator@example.org'
  1063. id='19'>
  1064. <set xmlns='urn:xmpp:iot:control' xml:lang='en'>
  1065. <node nodeId='DigitalOutput1'/>
  1066. <node nodeId='DigitalOutput2'/>
  1067. <node nodeId='DigitalOutput3'/>
  1068. <node nodeId='DigitalOutput4'/>
  1069. <boolean name='Output' value='true'/>
  1070. </set>
  1071. </iq>
  1072. <iq type='get'
  1073. from='concentrator@example.org/plc'
  1074. to='provisioning.example.org'
  1075. id='20'>
  1076. <canControl xmlns='urn:xmpp:iot:provisioning' jid='master@example.org' serviceToken='SERVICETOKEN1' userToken='USERTOKEN1'>
  1077. <node nodeId='DigitalOutput1'/>
  1078. <node nodeId='DigitalOutput2'/>
  1079. <node nodeId='DigitalOutput3'/>
  1080. <node nodeId='DigitalOutput4'/>
  1081. <parameter name='Output'/>
  1082. </canControl>
  1083. </iq>
  1084. <iq type='result'
  1085. from='provisioning.example.org'
  1086. to='concentrator@example.org/plc'
  1087. id='20'>
  1088. <canControlResponse xmlns='urn:xmpp:iot:provisioning' jid='master@example.org' result='true'>
  1089. <node nodeId='DigitalOutput2'/>
  1090. <node nodeId='DigitalOutput3'/>
  1091. </canControlResponse>
  1092. </iq>
  1093. <iq type='result'
  1094. from='concentrator@example.org'
  1095. to='master@example.org/amr'
  1096. id='19'>
  1097. <setResponse xmlns='urn:xmpp:iot:control' responseCode='OK'>
  1098. <node nodeId='DigitalOutput2'/>
  1099. <node nodeId='DigitalOutput3'/>
  1100. </setResponse>
  1101. </iq>]]>
  1102. </example>
  1103. <p>
  1104. Note that the provisioning server responds with a <strong>canControlResponse</strong> element, similar to the <strong>canControl</strong> element in the request, except
  1105. only the nodes allowed to be controlled are included. The device must only permit control of nodes listed in the response from the provisioning server. Other nodes available
  1106. in the request should be ignored.
  1107. </p>
  1108. <p>
  1109. Also note, that the restricted set of nodes and/or parameters returned from the provisioning server must be returned to the original caller, so it can
  1110. act on the information that only a partial control action was allowed and taken.
  1111. </p>
  1112. </section3>
  1113. <section3 topic='Restricting parameters during control' anchor='restrictingparameterscontrol'>
  1114. <p>
  1115. In case the provisioning server wants to limit the control parameters a client can control in a device, the provisioning server has the possibility to grant
  1116. control access, but list a set of parameters the client is allowed to control in the corresponding device.
  1117. </p>
  1118. <p>
  1119. <img src=''/>
  1120. <!-- sensor-network-provisioning-14.png-->
  1121. </p>
  1122. <p>
  1123. <strong>Note:</strong> If the server responds, but without specifying a list of nodes, the device can assume that all nodes available in the original request are allowed
  1124. to be controlled. If no nodes in the request are allowed to be controlled, the provisioning server must respond with a result='false', so the device can reject the read-out request.
  1125. The same is true for parameters: If the provisioning server does not specify parameters in the response, the caller can assume all parameters are allowed.
  1126. </p>
  1127. <p>
  1128. The following example shows the communication first between the client and the device, then between the device and the provisioning server, and last between the device and the client:
  1129. </p>
  1130. <example caption='Restricting parameters during control'>
  1131. <![CDATA[
  1132. <iq type='set'
  1133. from='master@example.org/amr'
  1134. to='plc@example.org'
  1135. id='21'>
  1136. <set xmlns='urn:xmpp:iot:control' xml:lang='en'>
  1137. <boolean name='DigitalOutput1' value='true'/>
  1138. <boolean name='DigitalOutput2' value='true'/>
  1139. <boolean name='DigitalOutput3' value='true'/>
  1140. <boolean name='DigitalOutput4' value='true'/>
  1141. <int name='AnalogOutput1' value='65535'/>
  1142. <int name='AnalogOutput2' value='65535'/>
  1143. <int name='AnalogOutput3' value='65535'/>
  1144. <int name='AnalogOutput4' value='65535'/>
  1145. </set>
  1146. </iq>
  1147. <iq type='get'
  1148. from='plc@example.org/plc'
  1149. to='provisioning.example.org'
  1150. id='22'>
  1151. <canControl xmlns='urn:xmpp:iot:provisioning' jid='master@example.org' serviceToken='SERVICETOKEN1' userToken='user0001'>
  1152. <parameter name='DigitalOutput1'/>
  1153. <parameter name='DigitalOutput2'/>
  1154. <parameter name='DigitalOutput3'/>
  1155. <parameter name='DigitalOutput4'/>
  1156. <parameter name='AnalogOutput1'/>
  1157. <parameter name='AnalogOutput2'/>
  1158. <parameter name='AnalogOutput3'/>
  1159. <parameter name='AnalogOutput4'/>
  1160. </canControl>
  1161. </iq>
  1162. <iq type='result'
  1163. from='provisioning.example.org'
  1164. to='plc@example.org/plc'
  1165. id='22'>
  1166. <canControlResponse xmlns='urn:xmpp:iot:provisioning' jid='master@example.org' result='true'>
  1167. <parameter name='DigitalOutput1'/>
  1168. <parameter name='DigitalOutput2'/>
  1169. <parameter name='DigitalOutput3'/>
  1170. <parameter name='DigitalOutput4'/>
  1171. </canControlResponse>
  1172. </iq>
  1173. <iq type='result'
  1174. from='plc@example.org'
  1175. to='master@example.org/amr'
  1176. id='21'>
  1177. <setResponse xmlns='urn:xmpp:iot:control' responseCode='OK'>
  1178. <parameter name='DigitalOutput1'/>
  1179. <parameter name='DigitalOutput2'/>
  1180. <parameter name='DigitalOutput3'/>
  1181. <parameter name='DigitalOutput4'/>
  1182. </setResponse>
  1183. </iq>]]>
  1184. </example>
  1185. <p>
  1186. Note that the provisioning server responds with a <strong>canControlResponse</strong> element, similar to the <strong>canControl</strong> element in the request, except only
  1187. the parameters allowed to be sent are listed. The device must only control parameters included in this list.
  1188. </p>
  1189. <p>
  1190. Also note, that the provisioning server can return a list of both allowed nodes and allowed parameter names in the response back to the client, so it can
  1191. act on the information that only a partial control action was allowed and taken.
  1192. </p>
  1193. </section3>
  1194. </section2>
  1195. <section2 topic='Cache' anchor='cache'>
  1196. <section3 topic='Clear cache' anchor='clearcache'>
  1197. <p>
  1198. When the provisioning server updates access rights and user privileges in the system, it will send a <strong>clearCache</strong> command to corresponding devices.
  1199. If a device was offline during the change, the provisioning server must send the <strong>clearCache</strong> message when the device comes online again. To acknowledge
  1200. the receipt of the command, the client responds with a <strong>clearCacheResponse</strong> element. This response message does not contain any information on what was
  1201. done by the client. It simply acknowledges the receipt of the command, to make sure the provisioning server does not resend the clear cache command again.
  1202. </p>
  1203. <p>
  1204. <strong>Note:</strong> The <strong>clearCache</strong> command does not include information on what has been changed, so the device needs to clear the entire cache. This
  1205. to avoid complexities in making sure updates made to the provisioning rules works in all cases, and to minimize complexity in the implementation of the protocol on the sensor side.
  1206. It is also not deemed to decrease network performance, since changing provisioning rules for a device is an exceptional event and therefore does not affect performance during
  1207. normal operation.
  1208. </p>
  1209. <example caption='Clear cache'>
  1210. <![CDATA[
  1211. <iq type='set'
  1212. from='provisioning.example.org'
  1213. to='device@example.org'
  1214. id='23'>
  1215. <clearCache xmlns='urn:xmpp:iot:provisioning'/>
  1216. </iq>
  1217. <iq type='result'
  1218. from='device@example.org'
  1219. to='provisioning.example.org'
  1220. id='23'>
  1221. <clearCacheResponse xmlns='urn:xmpp:iot:provisioning'/>
  1222. </iq>]]>
  1223. </example>
  1224. </section3>
  1225. </section2>
  1226. <section2 topic='Services' anchor='services'>
  1227. <section3 topic='Getting a service token' anchor='servicetoken'>
  1228. <p>
  1229. A service requesting provisioning assistance, needs to retrieve a service token from the provisioning server, by providing a base-64 encoded X.509 certificate.
  1230. The following example shows how this can be done.
  1231. </p>
  1232. <example caption='Requesting a service token'>
  1233. <![CDATA[
  1234. <iq type='get'
  1235. from='device@example.org/device'
  1236. to='provisioning.example.org'
  1237. id='24'>
  1238. <getToken xmlns='urn:xmpp:iot:provisioning'>BASE-64 ENCODED PUBLIC X.509 CERTIFICATE</getToken>
  1239. </iq>
  1240. <iq type='result'
  1241. from='provisioning.example.org'
  1242. to='device@example.org/device'
  1243. id='24'>
  1244. <getTokenChallenge xmlns='urn:xmpp:iot:provisioning' seqnr='1'>BASE-64 ENCODED CHALLENGE</getTokenChallenge>
  1245. </iq>
  1246. <iq type='get'
  1247. from='device@example.org/device'
  1248. to='provisioning.example.org'
  1249. id='25'>
  1250. <getTokenChallengeResponse xmlns='urn:xmpp:iot:provisioning' seqnr='1'>BASE-64 ENCODED RESPONSE</getTokenChallengeResponse>
  1251. </iq>
  1252. <iq type='result'
  1253. from='provisioning.example.org'
  1254. to='device@example.org/device'
  1255. id='25'>
  1256. <getTokenResponse xmlns='urn:xmpp:iot:provisioning' token='TOKEN'/>
  1257. </iq>]]>
  1258. </example>
  1259. </section3>
  1260. <section3 topic='User access to service' anchor='usertoken'>
  1261. <p>
  1262. Provisioning in sensor networks also requires control of user access to different services in the network. This use case shows how service access rights are controlled using
  1263. a trusted provisioning server.
  1264. </p>
  1265. <p>
  1266. <img src=''/>
  1267. </p>
  1268. <p>
  1269. First, the user connects to the service in some way. This can be done using XMPP, HTTP, HTTPS or some other means. The service need to extract some form of identifying
  1270. credentials from the user, and provide that to the provisioning server. The provisioning server determines if the client has access rights to the service based on these
  1271. credentials, and also provides the service with a <strong>userToken</strong> that the service can use in further communication with the provisioning server regarding
  1272. the user and its privileges.
  1273. </p>
  1274. <p>
  1275. The following table lists some different types of credentials that the service can extract from the client:
  1276. </p>
  1277. <table caption='User Credentials'>
  1278. <tr>
  1279. <th>Type</th>
  1280. <th>Protocols</th>
  1281. <th>Description</th>
  1282. </tr>
  1283. <tr>
  1284. <td>JID</td>
  1285. <td>XMPP</td>
  1286. <td>Allows provisioning to be done on the JID the user has.</td>
  1287. </tr>
  1288. <tr>
  1289. <td>IP Address</td>
  1290. <td>HTTP, HTTPS</td>
  1291. <td>Allows provisioning to be done on IP address or IP-ranges for instance.</td>
  1292. </tr>
  1293. <tr>
  1294. <td>Host Name</td>
  1295. <td>HTTP, HTTPS with DNS</td>
  1296. <td>If the service has access to the client host name, for instance in an intra network, this can be used for provisioning.</td>
  1297. </tr>
  1298. <tr>
  1299. <td>X.509 Certificate</td>
  1300. <td>HTTPS</td>
  1301. <td>If the client provides a client certificate, such a certificate can be used to provide provisioning.</td>
  1302. </tr>
  1303. <tr>
  1304. <td>X.509 Certificate Thumbprint</td>
  1305. <td>HTTPS</td>
  1306. <td>
  1307. The client can also choose to validate the certificate itself and only send the certificate thumbprint to the provisioning server. Even though this
  1308. provides somewhat lesser security than providing the entire certificate, it might be an option to distribute certificate validation checks across the network
  1309. to lower the work load on the provisioning server.
  1310. </td>
  1311. </tr>
  1312. <tr>
  1313. <td>User Name</td>
  1314. <td>HTTP, HTTPS, XMPP</td>
  1315. <td>
  1316. If authenticated HTTP(S) access is implemented, the service can provide the user name as credentials. XMPP based clients can use
  1317. information in the roster to provide user name information to the provisioning server.
  1318. </td>
  1319. </tr>
  1320. <tr>
  1321. <td>Geolocation</td>
  1322. <td>HTML5 over HTTP(S), XMPP</td>
  1323. <td>
  1324. If the geographic location (longitude, latitude and possibly altitude) of the user client is known, it can be used. HTML 5 provides mechanism whereby the location
  1325. of the client can be fetched. &xep0080; provides a mechanism whereby client location can be obtained over XMPP.
  1326. </td>
  1327. </tr>
  1328. <tr>
  1329. <td>SSO Token</td>
  1330. <td>Intranet</td>
  1331. <td>If a single sign on token is available, such a token could be provided as credentials.</td>
  1332. </tr>
  1333. <tr>
  1334. <td>Protocol</td>
  1335. <td>Any</td>
  1336. <td>Connection protocol used to connect to the service.</td>
  1337. </tr>
  1338. </table>
  1339. <p>
  1340. The provisioning server receives these credentials, and decides if the user should have access to the service or not, based on rules configured in the provisioning service.
  1341. If the user is granted access, a <strong>userToken</strong> is generated and returned to the service.
  1342. </p>
  1343. <p>
  1344. Now, the service can determine if this access grant is sufficient or not. It can require the user to login into the service first. If so, the service should provide the provisioning
  1345. server with the user name used during login, when logged in.
  1346. </p>
  1347. <example caption='User access to service'>
  1348. <![CDATA[
  1349. <!-- user connects to service -->
  1350. <iq type='get'
  1351. from='service@example.org/service'
  1352. to='provisioning.example.org'
  1353. id='26'>
  1354. <canAccess xmlns='urn:xmpp:iot:provisioning' serviceToken='SERVICETOKEN1'>
  1355. <credentials type='IpAddress' value='10.0.0.1'/>
  1356. <credentials type='Longitude' value='123.45'/>
  1357. <credentials type='Latitude' value='67.89'/>
  1358. </canAccess>
  1359. </iq>
  1360. <iq type='result'
  1361. from='provisioning.example.org'
  1362. to='service@example.org/service'
  1363. id='26'>
  1364. <canAccessResponse xmlns='urn:xmpp:iot:provisioning' userToken='USERTOKEN1' result='true'/>
  1365. </iq>
  1366. <!-- user performs login into service -->
  1367. <message from='service@example.org/service'
  1368. to='provisioning.example.org'>
  1369. <userLoggedIn xmlns='urn:xmpp:iot:provisioning' serviceToken='SERVICETOKEN1' userToken='USERTOKEN1' userName='Kermit' />
  1370. </message>
  1371. <!-- user continues interacting with service -->]]>
  1372. </example>
  1373. </section3>
  1374. </section2>
  1375. <section2 topic='User privileges' anchor='userprivileges'>
  1376. <section3 topic='User privileges in service' anchor='userpriviliegesservices'>
  1377. <p>
  1378. When a user has been given access to a service, and properly been identified, the service can ask the provisioning service for detailed user privileges to control
  1379. different aspects of the service. This can be done using the <strong>hasPrivilege</strong> command. Here, the service sends its <strong>serviceToken</strong> and
  1380. the <strong>userToken</strong> earlier received when being granted access to the service. Furthermore a <strong>privilegeId</strong> has to be provided.
  1381. </p>
  1382. <p>
  1383. A <strong>Privilege ID</strong> is a string composed of one or a sequence of parts, delimited by period characters. The Privilege IDs form a tree of privileges,
  1384. using an invisible, but common, root privilege.
  1385. </p>
  1386. <p>
  1387. The following table suggests some examples of Privilege IDs, with suggestive descriptions. (Only used as an example.)
  1388. </p>
  1389. <table caption='Privilege ID examples'>
  1390. <tr>
  1391. <th>Privilege ID</th>
  1392. <th>Description</th>
  1393. </tr>
  1394. <tr>
  1395. <td>Databases.Energy.Select</td>
  1396. <td>Gives the user the rights to select data from the Energy database.</td>
  1397. </tr>
  1398. <tr>
  1399. <td>Databases.Energy.Insert</td>
  1400. <td>Gives the user the rights to insert data into the Energy database.</td>
  1401. </tr>
  1402. <tr>
  1403. <td>Databases.Energy.Delete</td>
  1404. <td>Gives the user the rights to delete data from the Energy database.</td>
  1405. </tr>
  1406. </table>
  1407. <p>
  1408. <strong>Note:</strong> Note that privilege IDs are local to the service. Different services are allowed to use similar or same Privilege IDs, in different contexts and
  1409. with different meanings. The provisioning server must separate Privilege IDs from different services.
  1410. </p>
  1411. <p>
  1412. The client must always provide full Privilege IDs to the provisioning server. The provisioning server however, can grant partial privilege IDs, pointing to parent
  1413. privilege nodes to a user or a role object, granting a user a specific role. If granting a parent privilege ID to a user or role, this is interpreted as
  1414. giving the corresponding user or role the privileges of the entire sub-tree defined by the parent privilege ID.
  1415. </p>
  1416. <p>
  1417. If additional control over privileges is desired, negative privileges can be assigned to the user or role. Granted or explicitly rejected privileges are specified in a
  1418. sequential list of full or partial privilege IDs. This list is then processed sequentially to determine if a privilege is granted or not.
  1419. </p>
  1420. <p>
  1421. Example: Consider the privileges above. Give a user or its corresponding role the following privileges in a sequential list:
  1422. </p>
  1423. <ul>
  1424. <li>Exclude: Databases.Energy.Delete</li>
  1425. <li>Include: Databases.Energy</li>
  1426. </ul>
  1427. <p>
  1428. This would give the user rights to select and insert data, but not to delete data from the Energy database.
  1429. </p>
  1430. <p>
  1431. <strong>Note:</strong> Care should be taken when constructing Privilege IDs, so they do not include variable data that potentially can create an infinite amount of
  1432. privilege IDs. For example: Do not include user names, sensor IDs, etc., in privilege IDs, as the number of such entities cannot be estimated or is scalable beforehand.
  1433. </p>
  1434. <p>
  1435. The following diagram shows an example of how a service asks permission from a provisioning server before an action is taken:
  1436. </p>
  1437. <p>
  1438. <img src=''/>
  1439. </p>
  1440. <example caption='User privileges in service'>
  1441. <![CDATA[
  1442. <!-- user wants to perform action -->
  1443. <iq type='get'
  1444. from='service@example.org/service'
  1445. to='provisioning.example.org'
  1446. id='27'>
  1447. <hasPrivilege xmlns='urn:xmpp:iot:provisioning' serviceToken='SERVICETOKEN1' userToken='USERTOKEN1' privilegeId='Sensors.View'/>
  1448. </iq>
  1449. <iq type='result'
  1450. from='provisioning.example.org'
  1451. to='service@example.org/service'
  1452. id='27'>
  1453. <hasPrivilegeResponse xmlns='urn:xmpp:iot:provisioning' result='true'/>
  1454. </iq>
  1455. <!-- user performs action -->]]>
  1456. </example>
  1457. </section3>
  1458. <section3 topic='Download all user privileges' anchor='downloadall'>
  1459. <p>
  1460. To improve performance, services can download the entire set of user privileges, and perform privilege checks internally. The following diagram displays
  1461. how the above two use cases could be handled in such a case:
  1462. </p>
  1463. <p>
  1464. <img src=''/>
  1465. </p>
  1466. <p>
  1467. <strong>Note:</strong> When downloading privileges using this command, a sequential list of full or partial privilege IDs will be returned together with the
  1468. corresponding include or exclude flags. The above mentioned algorithm of determining user privileges must be implemented by the service, if this method is
  1469. to be used.
  1470. </p>
  1471. <example caption='Download all user privileges'>
  1472. <![CDATA[
  1473. <!-- user connects to service -->
  1474. <iq type='get'
  1475. from='service@example.org/service'
  1476. to='provisioning.example.org'
  1477. id='28'>
  1478. <canAccess xmlns='urn:xmpp:iot:provisioning' serviceToken='SERVICETOKEN1'>
  1479. <credentials type='IpAddress' value='10.0.0.1'/>
  1480. <credentials type='Longitude' value='123.45'/>
  1481. <credentials type='Latitude' value='67.89'/>
  1482. </canAccess>
  1483. </iq>
  1484. <iq type='result'
  1485. from='provisioning.example.org'
  1486. to='service@example.org/service'
  1487. id='28'>
  1488. <canAccessResponse xmlns='urn:xmpp:iot:provisioning' userToken='USERTOKEN1' result='true'/>
  1489. </iq>
  1490. <!-- user performs login into service -->
  1491. <message from='service@example.org/service'
  1492. to='provisioning.example.org'>
  1493. <userLoggedIn xmlns='urn:xmpp:iot:provisioning' serviceToken='SERVICETOKEN1' userToken='USERTOKEN1' userName='Kermit' />
  1494. </message>
  1495. <iq type='get'
  1496. from='service@example.org/service'
  1497. to='provisioning.example.org'
  1498. id='29'>
  1499. <downloadPrivileges xmlns='urn:xmpp:iot:provisioning' serviceToken='SERVICETOKEN1' userToken='USERTOKEN1'/>
  1500. </iq>
  1501. <iq type='result'
  1502. from='provisioning.example.org'
  1503. to='service@example.org/service'
  1504. id='29'>
  1505. <downloadPrivilegesResponse>
  1506. <exclude id='Sensors.Delete'/>
  1507. <include id='Sensors'/>
  1508. </downloadPrivilegesResponse>
  1509. </iq>
  1510. <!-- user performs actions without interaction with the provisioning server -->]]>
  1511. </example>
  1512. <p>
  1513. <strong>Note:</strong> If the user or service has not been correctly identified, logged in, etc., the resulting list must only include privileges
  1514. that default users that are not logged in can have. This list can be empty.
  1515. </p>
  1516. </section3>
  1517. </section2>
  1518. </section1>
  1519. <section1 topic='Determining Support' anchor='support'>
  1520. <p>
  1521. If an entity is a Provisioning Server and supports the protocol specified herein, it MUST advertise that fact by returning a feature of "urn:xmpp:iot:provisioning"
  1522. in response to &xep0030; information requests.
  1523. </p>
  1524. <example caption="Service discovery information request">
  1525. <![CDATA[
  1526. <iq type='get'
  1527. from='device@example.org/device'
  1528. to='provisioning.example.org'
  1529. id='disco1'>
  1530. <query xmlns='http://jabber.org/protocol/disco#info'/>
  1531. </iq>]]>
  1532. </example>
  1533. <example caption="Service discovery information response">
  1534. <![CDATA[
  1535. <iq type='result'
  1536. from='provisioning.example.org'
  1537. to='device@example.org/device'
  1538. id='disco1'>
  1539. <query xmlns='http://jabber.org/protocol/disco#info'>
  1540. ...
  1541. <feature var='urn:xmpp:iot:provisioning'/>
  1542. ...
  1543. </query>
  1544. </iq>]]>
  1545. </example>
  1546. <p>
  1547. In order for an application to determine whether an entity supports this protocol, where possible it SHOULD use the dynamic, presence-based profile of service discovery defined
  1548. in &xep0115;. However, if an application has not received entity capabilities information from an entity, it SHOULD use explicit service discovery instead.
  1549. </p>
  1550. </section1>
  1551. <section1 topic='Implementation Notes' anchor='impl'>
  1552. <section2 topic='JID vs Component Provisioning Servers' anchor='jidvscomponent'>
  1553. <p>
  1554. A client must treat the connection between a Provisioning Server differently if it is hosted as a client, having a JID, or if it is hosted as a Jabber Server Component.
  1555. If it is hosted as a server component, there's no need for the thing to become friends with the Provisioning Server. Messages and requests can be made directly to the
  1556. server component without having to add it to the roster or request presence subscriptions. If the Provisioning Server is hosted as a client, having a JID (@ in the address),
  1557. the Provisioning Server must be added to the roster of the client before the client can communicate with the Provisioning Server.
  1558. </p>
  1559. </section2>
  1560. <section2 topic='Caching and cache time' anchor='cache'>
  1561. <p>
  1562. To minimize network traffic, and optimize response time, devices should cache access rights and user privileges provided by the provisioning server. If memory is limited,
  1563. items in the cache should be ordered by last access, and items with the oldest last access timestamp should be removed first. A safety valve can optionally be implemented as well,
  1564. removing unused cache items after a certain age, even if memory is available.
  1565. </p>
  1566. <p>
  1567. The device can assume that access rights and user privileges on the provisioning server do not change over time, unless the provisioning server says so.
  1568. </p>
  1569. <p>
  1570. The provisioning server on the other hand, must keep track of when a device is online and offline, and clear the cache of the device if changes are made that affects the device.
  1571. If the device was offline when those changes occurred, the provisioning server must send the clear cache command as soon as the device comes online again.
  1572. </p>
  1573. <p>
  1574. When creating a new trust relationship, the device should always clear its cache, if it contains information from before.
  1575. </p>
  1576. <p>
  1577. To minimize stress of the provisioning server during synchronous sensor start up, for instance after a power failure, all clients should aim to persist its cache if possible. Clients
  1578. not persisting its cache may produce too much stress on the provisioning server on start-up, practically removing it from the network.
  1579. </p>
  1580. </section2>
  1581. <section2 topic='Working with multiple provisioning servers' anchor='multipleprovisioningservers'>
  1582. <p>
  1583. When working with multiple provisioning servers, there are some things that should be considered:
  1584. </p>
  1585. <ul>
  1586. <li>
  1587. When a device requests information from the provisioning servers, this can be done in a parallel fashion. Even though the provisioning servers
  1588. were added in a sequential fashion, there is no order or priority between the servers.
  1589. </li>
  1590. <li>
  1591. When receiving different responses from different servers, with regards to access rights, privileges, relationships, etc.,
  1592. the union of rights, or the most forgiving or most accepting response should be used. If one of the servers grant a privilege, the privilege is assumed
  1593. to exist. If one of the servers grant a friendship request, the friendship request should be granted, etc. Most probably, different servers will manage
  1594. different subsets of entities on the network, and when they receive questions about unrecognized devices, they will simply deny access.
  1595. </li>
  1596. <li>
  1597. If a provisioning server requires total control of the network, it should not allow secondary trust relationships. However, if such a server enters a network
  1598. and there exist previous provisioning servers (i.e. they accept secondary trust relationships), more trust relationships are assumed to be acceptable.
  1599. </li>
  1600. <li>
  1601. Even though examples in this document only list a secondary trust relationship, there is no such limit. There may exist many different trust relationships in a network
  1602. or for a given device.
  1603. </li>
  1604. </ul>
  1605. </section2>
  1606. <section2 topic='Automatic aggregation of services, users and privileges' anchor='aggregationservices'>
  1607. <p>
  1608. One important design consideration when implementing a provisioning server is how to handle new services, users and privileges. One option might be to automatically
  1609. ignore anything not recognized. Another option might be to dynamically add new services, user names and privileges to internal data sources, making it easier to manage
  1610. new types of services dynamically. However, adding such items automatically might also make such data sources grow beyond control.
  1611. </p>
  1612. </section2>
  1613. <section2 topic='Reading devices from large subsystems' anchor='largesubsystems'>
  1614. <p>
  1615. All examples in this document have been simplified examples where a few devices containing a few fields have been read. However, in many cases large subsystems with
  1616. very many sensors containing many fields have to be read, as is documented in <link url='http://xmpp.org/extensions/xep-0326.html'>Internet of Things - Concentrators</link>
  1617. <link url='http://xmpp.org/extensions/xep-0326.html'>Internet of Things - Concentrators</link>. In such cases, a node may have to be specified using two or perhaps
  1618. even three ID's: a <strong>sourceId</strong> identifying the data source controlling the device, a possible <strong>cacheType</strong> narrowing down the search to
  1619. a specific kind of node, and the common <strong>nodeId</strong>. For more information about this, see
  1620. <link url='http://xmpp.org/extensions/xep-0326.html'>Internet of Things - Concentrators</link>.
  1621. </p>
  1622. <p>
  1623. <strong>Note:</strong> For cases where the <strong>nodeId</strong> is sufficient to uniquely identify the node, it is sufficient to provide this attribute in the request.
  1624. If there is ambiguity in the request, the receptor must treat the request as a request with a set of nodes, all with the corresponding <strong>nodeId</strong> as requested.
  1625. </p>
  1626. </section2>
  1627. <section2 topic='Different types of tokens' anchor='tokentypes'>
  1628. <p>
  1629. A small note regarding the use of different tokens. A service can get a <strong>Service Token</strong>, a device a <strong>Device Token</strong> and a user
  1630. a <strong>User Token</strong>. When delegating these tokens to third parties, a service sends its <strong>Service Token</strong>. But, if the service does this
  1631. within the context of a user action, the service sends both its <strong>Service Token</strong> and the users <strong>User Token</strong>. The same with a device.
  1632. If a device delegates its token to a third party, it sends its <strong>Device Token</strong>. But if the device performs the action in the context of a user action,
  1633. the device sends both its <strong>Device Token</strong> as well as its <strong>User Token</strong>.
  1634. </p>
  1635. </section2>
  1636. </section1>
  1637. <section1 topic='Security Considerations' anchor='security'>
  1638. <section2 topic='Trust Delegation' anchor='sectrustdelegation'>
  1639. <p>
  1640. Delegating trust to a third party may create a weak link in the overall security of a sensor network. Therefore, it's vitally important that the following be adhered to:
  1641. </p>
  1642. <ul>
  1643. <li>
  1644. Trust should only be delegated in a secure way. Once delegated, it should be able to lock this trust so it cannot be changed without reverting the device to
  1645. factory default settings. Such a locked delegation mode can be likened with a production mode, where vital configuration parameters should not be able to be changed.
  1646. </li>
  1647. <li>
  1648. If allowing installation using a LED, as above, make sure the LED does not light up for a long time, limiting the window of access where the sensor can be linked to a
  1649. provisioning server.
  1650. </li>
  1651. <li>
  1652. Provisioning servers should be monitored during operation, since it provides a vital link in the operation of the network.
  1653. </li>
  1654. <li>
  1655. Multiple provisioning servers could be allowed, for redundancy or for scalability. This specification does not limit the number of provisioning servers used in a network,
  1656. not used by a device. Examples in this specification use only one provisioning server for simplicity.
  1657. </li>
  1658. <li>
  1659. Generally, take care what kind of provisioning servers you allow in a network.
  1660. </li>
  1661. </ul>
  1662. </section2>
  1663. <section2 topic='Token Challenges' anchor='sectokenchallenges'>
  1664. <p>
  1665. When receiving token challenges from somebody, make sure you've sent the corresponding token to the corresponding party less than a minute before receiving the token
  1666. challenge. If not, the token challenge might represent a malicious attempt by somebody else to use the token to gain privileges in the network otherwise not enjoyed.
  1667. </p>
  1668. </section2>
  1669. </section1>
  1670. <section1 topic='IANA Considerations' anchor='iana'>
  1671. <p>This document requires no interaction with &IANA;.</p>
  1672. </section1>
  1673. <section1 topic='XMPP Registrar Considerations' anchor='registrar'>
  1674. <p>
  1675. The <link url="#schema">protocol schema</link> needs to be added to the list of <link url="http://xmpp.org/resources/schemas/">XMPP protocol schemas</link>.
  1676. </p>
  1677. </section1>
  1678. <section1 topic='XML Schema' anchor='schema'>
  1679. <code>
  1680. <![CDATA[
  1681. <?xml version='1.0' encoding='UTF-8'?>
  1682. <xs:schema
  1683. xmlns:xs='http://www.w3.org/2001/XMLSchema'
  1684. targetNamespace='urn:xmpp:iot:provisioning'
  1685. xmlns='urn:xmpp:iot:provisioning'
  1686. xmlns:sn='urn:xmpp:iot:sensordata'
  1687. elementFormDefault='qualified'>
  1688. <xs:import namespace='urn:xmpp:iot:sensordata'/>
  1689. <xs:element name='getToken' type='xs:base64Binary'/>
  1690. <xs:element name='getTokenChallenge' type='GetTokenChallengeResponse'/>
  1691. <xs:element name='getTokenChallengeResponse' type='GetTokenChallengeResponse'/>
  1692. <xs:element name='getTokenResponse' type='GetTokenResponse'/>
  1693. <xs:element name='tokenChallenge' type='TokenChallenge'/>
  1694. <xs:element name='tokenChallengeResponse' type='xs:base64Binary'/>
  1695. <xs:element name='isFriend' type='Friend'/>
  1696. <xs:element name='isFriendResponse' type='FriendResponse'/>
  1697. <xs:element name='unfriend' type='Friend'/>
  1698. <xs:element name='friend' type='Friend'/>
  1699. <xs:element name='canRead' type='CanRead'/>
  1700. <xs:element name='canReadResponse' type='CanReadResponse'/>
  1701. <xs:element name='canControl' type='CanControl'/>
  1702. <xs:element name='canControlResponse' type='CanControlResponse'/>
  1703. <xs:element name='clearCache'>
  1704. <xs:complexType/>
  1705. </xs:element>
  1706. <xs:element name='clearCacheResponse'>
  1707. <xs:complexType/>
  1708. </xs:element>
  1709. <xs:element name='canAccess'>
  1710. <xs:complexType>
  1711. <xs:choice minOccurs='0' maxOccurs='unbounded'>
  1712. <xs:element name='jid' type='JidCredential'/>
  1713. <xs:element name='ip4' type='Ip4Credential'/>
  1714. <xs:element name='ip6' type='Ip6Credential'/>
  1715. <xs:element name='hostName' type='HostNameCredential'/>
  1716. <xs:element name='x509Certificate' type='X509CertificateCredential'/>
  1717. <xs:element name='x509CertificateThumbprint' type='X509CertificateThumbprintCredential'/>
  1718. <xs:element name='userName' type='UserNameCredential'/>
  1719. <xs:element name='longitude' type='LongitudeCredential'/>
  1720. <xs:element name='latitude' type='LatitudeCredential'/>
  1721. <xs:element name='altitude' type='AltitudeCredential'/>
  1722. <xs:element name='sso' type='SsoCredential'/>
  1723. <xs:element name='protocol' type='ProtocolCredential'/>
  1724. </xs:choice>
  1725. <xs:attribute name='serviceToken' type='xs:string' use='required'/>
  1726. </xs:complexType>
  1727. </xs:element>
  1728. <xs:element name='canAccessResponse'>
  1729. <xs:complexType>
  1730. <xs:attribute name='result' type='xs:boolean' use='required'/>
  1731. <xs:attribute name='userToken' type='xs:string' use='optional'/>
  1732. </xs:complexType>
  1733. </xs:element>
  1734. <xs:element name='userLoggedIn'>
  1735. <xs:complexType>
  1736. <xs:attribute name='serviceToken' type='xs:string' use='required'/>
  1737. <xs:attribute name='userToken' type='xs:string' use='required'/>
  1738. <xs:attribute name='userName' type='xs:string' use='required'/>
  1739. </xs:complexType>
  1740. </xs:element>
  1741. <xs:element name='hasPrivilege'>
  1742. <xs:complexType>
  1743. <xs:attribute name='serviceToken' type='xs:string' use='required'/>
  1744. <xs:attribute name='userToken' type='xs:string' use='required'/>
  1745. <xs:attribute name='privilegeId' type='PrivilegeId' use='required'/>
  1746. </xs:complexType>
  1747. </xs:element>
  1748. <xs:element name='hasPrivilegeResponse'>
  1749. <xs:complexType>
  1750. <xs:attribute name='result' type='xs:boolean' use='required'/>
  1751. </xs:complexType>
  1752. </xs:element>
  1753. <xs:element name='downloadPrivileges'>
  1754. <xs:complexType>
  1755. <xs:attribute name='serviceToken' type='xs:string' use='required'/>
  1756. <xs:attribute name='userToken' type='xs:string' use='required'/>
  1757. </xs:complexType>
  1758. </xs:element>
  1759. <xs:element name='downloadPrivilegesResponse'>
  1760. <xs:complexType>
  1761. <xs:choice minOccurs='0' maxOccurs='unbounded'>
  1762. <xs:element name='include' type='Privilege'/>
  1763. <xs:element name='exclude' type='Privilege'/>
  1764. </xs:choice>
  1765. </xs:complexType>
  1766. </xs:element>
  1767. <xs:complexType name='GetTokenResponse'>
  1768. <xs:attribute name='token' type='xs:string' use='required'/>
  1769. </xs:complexType>
  1770. <xs:complexType name='GetTokenChallengeResponse'>
  1771. <xs:simpleContent>
  1772. <xs:extension base='xs:base64Binary'>
  1773. <xs:attribute name='seqnr' type='xs:int' use='required'/>
  1774. </xs:extension>
  1775. </xs:simpleContent>
  1776. </xs:complexType>
  1777. <xs:complexType name='TokenChallenge'>
  1778. <xs:simpleContent>
  1779. <xs:extension base='xs:base64Binary'>
  1780. <xs:attribute name='token' type='xs:string' use='required'/>
  1781. </xs:extension>
  1782. </xs:simpleContent>
  1783. </xs:complexType>
  1784. <xs:complexType name='Friend'>
  1785. <xs:attribute name='jid' type='xs:string' use='required'/>
  1786. </xs:complexType>
  1787. <xs:complexType name='FriendResponse'>
  1788. <xs:complexContent>
  1789. <xs:extension base='Friend'>
  1790. <xs:attribute name='result' type='xs:boolean' use='required'/>
  1791. <xs:attribute name='secondaryTrustAllowed' type='xs:boolean' use='optional' default='false'/>
  1792. </xs:extension>
  1793. </xs:complexContent>
  1794. </xs:complexType>
  1795. <xs:complexType name='CanReadBase' abstract='true'>
  1796. <xs:choice minOccurs='0' maxOccurs='unbounded'>
  1797. <xs:element name='node'>
  1798. <xs:complexType>
  1799. <xs:attribute name='nodeId' type='xs:string' use='required'/>
  1800. <xs:attribute name='sourceId' type='xs:string' use='optional'/>
  1801. <xs:attribute name='cacheType' type='xs:string' use='optional'/>
  1802. </xs:complexType>
  1803. </xs:element>
  1804. <xs:element name='field'>
  1805. <xs:complexType>
  1806. <xs:attribute name='name' type='xs:string' use='required'/>
  1807. </xs:complexType>
  1808. </xs:element>
  1809. </xs:choice>
  1810. <xs:attributeGroup ref='sn:fieldTypes'/>
  1811. <xs:attribute name='all' type='xs:boolean' use='optional' default='false'/>
  1812. <xs:attribute name='historical' type='xs:boolean' use='optional' default='false'/>
  1813. <xs:attribute name='jid' type='xs:string' use='required'/>
  1814. </xs:complexType>
  1815. <xs:complexType name='CanRead'>
  1816. <xs:complexContent>
  1817. <xs:extension base='CanReadBase'>
  1818. <xs:attributeGroup ref='tokens'/>
  1819. </xs:extension>
  1820. </xs:complexContent>
  1821. </xs:complexType>
  1822. <xs:attributeGroup name='tokens'>
  1823. <xs:attribute name='serviceToken' type='xs:string' use='optional'/>
  1824. <xs:attribute name='userToken' type='xs:string' use='optional'/>
  1825. <xs:attribute name='deviceToken' type='xs:string' use='optional'/>
  1826. </xs:attributeGroup>
  1827. <xs:complexType name='CanReadResponse'>
  1828. <xs:complexContent>
  1829. <xs:extension base='CanReadBase'>
  1830. <xs:attribute name='result' type='xs:boolean' use='required'/>
  1831. </xs:extension>
  1832. </xs:complexContent>
  1833. </xs:complexType>
  1834. <xs:complexType name='CanControlBase' abstract='true'>
  1835. <xs:choice minOccurs='0' maxOccurs='unbounded'>
  1836. <xs:element name='node'>
  1837. <xs:complexType>
  1838. <xs:attribute name='nodeId' type='xs:string' use='required'/>
  1839. <xs:attribute name='sourceId' type='xs:string' use='optional'/>
  1840. <xs:attribute name='cacheType' type='xs:string' use='optional'/>
  1841. </xs:complexType>
  1842. </xs:element>
  1843. <xs:element name='parameter'>
  1844. <xs:complexType>
  1845. <xs:attribute name='name' type='xs:string' use='required'/>
  1846. </xs:complexType>
  1847. </xs:element>
  1848. </xs:choice>
  1849. <xs:attribute name='jid' type='xs:string' use='required'/>
  1850. </xs:complexType>
  1851. <xs:complexType name='CanControl'>
  1852. <xs:complexContent>
  1853. <xs:extension base='CanControlBase'>
  1854. <xs:attributeGroup ref='tokens'/>
  1855. </xs:extension>
  1856. </xs:complexContent>
  1857. </xs:complexType>
  1858. <xs:complexType name='CanControlResponse'>
  1859. <xs:complexContent>
  1860. <xs:extension base='CanControlBase'>
  1861. <xs:attribute name='result' type='xs:boolean' use='required'/>
  1862. </xs:extension>
  1863. </xs:complexContent>
  1864. </xs:complexType>
  1865. <xs:complexType name='JidCredential'>
  1866. <xs:attribute name='value' type='xs:string' use='required'/>
  1867. </xs:complexType>
  1868. <xs:complexType name='Ip4Credential'>
  1869. <xs:attribute name='value' type='xs:string' use='required'/>
  1870. </xs:complexType>
  1871. <xs:complexType name='Ip6Credential'>
  1872. <xs:attribute name='value' type='xs:string' use='required'/>
  1873. </xs:complexType>
  1874. <xs:complexType name='HostNameCredential'>
  1875. <xs:attribute name='value' type='xs:string' use='required'/>
  1876. </xs:complexType>
  1877. <xs:complexType name='X509CertificateCredential'>
  1878. <xs:attribute name='base64' type='xs:string' use='required'/>
  1879. </xs:complexType>
  1880. <xs:complexType name='X509CertificateThumbprintCredential'>
  1881. <xs:attribute name='base64' type='xs:string' use='required'/>
  1882. </xs:complexType>
  1883. <xs:complexType name='UserNameCredential'>
  1884. <xs:attribute name='value' type='xs:string' use='required'/>
  1885. </xs:complexType>
  1886. <xs:complexType name='LongitudeCredential'>
  1887. <xs:attribute name='value' type='xs:double' use='required'/>
  1888. </xs:complexType>
  1889. <xs:complexType name='LatitudeCredential'>
  1890. <xs:attribute name='value' type='xs:double' use='required'/>
  1891. </xs:complexType>
  1892. <xs:complexType name='AltitudeCredential'>
  1893. <xs:attribute name='value' type='xs:double' use='required'/>
  1894. </xs:complexType>
  1895. <xs:complexType name='SsoCredential'>
  1896. <xs:attribute name='value' type='xs:string' use='required'/>
  1897. </xs:complexType>
  1898. <xs:complexType name='ProtocolCredential'>
  1899. <xs:attribute name='value' type='ProtocolName' use='required'/>
  1900. </xs:complexType>
  1901. <xs:complexType name='Privilege'>
  1902. <xs:attribute name='id' type='PrivilegeId' use='required'/>
  1903. </xs:complexType>
  1904. <xs:simpleType name='ProtocolName'>
  1905. <xs:restriction base='xs:string'>
  1906. <xs:enumeration value='XMPP'/>
  1907. <xs:enumeration value='HTTP'/>
  1908. <xs:enumeration value='HTTPS'/>
  1909. <xs:enumeration value='TcpSocket'/>
  1910. <xs:enumeration value='UdpSocket'/>
  1911. <xs:enumeration value='Queue'/>
  1912. <xs:enumeration value='Internal'/>
  1913. <xs:enumeration value='Other'/>
  1914. </xs:restriction>
  1915. </xs:simpleType>
  1916. <xs:simpleType name='PrivilegeId'>
  1917. <xs:restriction base='xs:string'>
  1918. <xs:pattern value='^[^.]+([.][^.]+)*$'/>
  1919. </xs:restriction>
  1920. </xs:simpleType>
  1921. </xs:schema>]]>
  1922. </code>
  1923. </section1>
  1924. <section1 topic='For more information' anchor='moreinfo'>
  1925. <p>
  1926. For more information, please see the following resources:
  1927. </p>
  1928. <ul>
  1929. <li>
  1930. <p>
  1931. The <link url='http://wiki.xmpp.org/web/Tech_pages/SensorNetworks'>Sensor Network section of the XMPP Wiki</link> contains further information about the
  1932. use of the sensor network XEPs, links to implementations, discussions, etc.
  1933. </p>
  1934. </li>
  1935. <li>
  1936. <p>
  1937. The XEP's and related projects are also available on <link url='https://github.com/joachimlindborg/'>github</link>, thanks to Joachim Lindborg.
  1938. </p>
  1939. </li>
  1940. <li>
  1941. <p>
  1942. A presentation giving an overview of all extensions related to Internet of Things can be found here:
  1943. <link url='http://prezi.com/esosntqhewhs/iot-xmpp/'>http://prezi.com/esosntqhewhs/iot-xmpp/</link>.
  1944. </p>
  1945. </li>
  1946. </ul>
  1947. </section1>
  1948. <section1 topic='Acknowledgements' anchor='ack'>
  1949. <p>Thanks to Joachim Lindborg, Karin Forsell, Tina Beckman and Teemu Väisänen for all valuable feedback.</p>
  1950. </section1>
  1951. </xep>