Solutions · IoT Security

PKI that scales from ten devices to ten million.

Constrained hardware, spotty networks, decade-long service lifetimes — IoT breaks conventional certificate management. TigerTrust delivers automated provisioning, rotation, and revocation designed for the fleet, not the datacentre.

The problem

Shared secrets don't scale. Neither does the field engineer.

IoT projects start with hand-configured pilots and die trying to onboard the millionth device. Certificate lifetimes measured in years mean weak crypto stays in the field for a decade — until the first breach makes the front page.

Without IoT-grade PKI
  • Manual keying per device — economics break above a few thousand
  • Shared keys make one compromised device a fleet-wide incident
  • No rotation strategy for devices that live 10+ years in the field
  • Constrained-device protocols (CoAP, MQTT) leak because TLS wasn't automated
  • Compromised units keep signing until humans notice
With TigerTrust IoT PKI
  • Zero-touch provisioning from factory-installed IDevID (IEEE 802.1AR)
  • Per-device unique keys — no shared secrets, ever
  • Scheduled rotation with algorithm-agile issuance for the long tail
  • Lightweight enrolment via EST, SCEP, or Matter DAC/PAI hierarchy
  • Continuous attestation + auto-revocation on drift or tamper
Zero-touch onboarding

From factory floor to field, no field engineer

Devices ship with an IDevID burned in at manufacture. On first connect, TigerTrust rotates to a short-lived LDevID and enrols the device into its fleet in seconds.

How it works
  • IEEE 802.1AR two-tier identity (IDevID → LDevID)
  • FIDO Device Onboard support
  • Matter DAC / PAI hierarchy
  • One-line agent installer
IoT devices being onboarded on a factory line
Scale

Provision at fleet speed, not one at a time

Batch issuance across PKI Core replicas; backpressure-aware queues; no per-cert rate limits. Push ten thousand devices in an hour without breaking a sweat.

How it works
  • Millions of certificates per hour
  • Parallel issuance across replicas
  • Backpressure-aware enrolment queue
  • Regional CAs for global fleets
Large-scale IoT sensor deployment
Constrained protocols

Lightweight enrolment for tiny endpoints

EST, SCEP, and CoAP-based enrolment for devices that can't afford a full TLS handshake stack. Certificate size, algorithm, and issuance flow tuned per device class.

How it works
  • EST (RFC 7030) and SCEP support
  • CoAP / LwM2M-based enrolment
  • ECDSA P-256 profiles for constrained radios
  • Cert size optimised (< 500 bytes achievable)
Low-power connected sensors in a distributed deployment
Continuous trust

Re-attest, revoke, replace — automatically

Devices re-attest on your policy interval. Stale attestation, PCR drift, or tamper flags trigger revocation and re-provisioning without an operator opening a ticket.

How it works
  • Configurable attestation sweep
  • CRL + OCSP + agent push
  • Sub-minute revocation propagation
  • Auto-quarantine on tamper detection
Fleet operations dashboard tracking device health
IoT-first design

Everything a device fleet needs. Nothing it can't afford.

Every capability optimised for constrained hardware and long service lives.

TPM & secure element
Hardware-bound identities across Intel PTT, Infineon, STMicro, Nuvoton.
  • TPM 2.0 attestation
  • ATECC / SE050 support
  • Key non-exportability
Per-device keys
No shared secrets, ever. Compromise stays local.
  • Unique per unit
  • Non-exportable
  • Auto-quarantine
High-throughput issuance
Millions of certs per hour across regional CAs.
  • Parallel workers
  • Backpressure aware
  • No per-cert rate limits
Continuous attestation
TPM2_Quote-based re-verification on schedule.
  • PCR drift detection
  • Auto-revocation
  • Full audit trail
Constrained protocols
EST, SCEP, CoAP for radios that can&apos;t do full TLS.
  • RFC 7030 EST
  • LwM2M enrolment
  • Cert size optimisation
Zero-touch
IDevID → LDevID with no field engineer.
  • IEEE 802.1AR
  • FIDO Device Onboard
  • Matter DAC/PAI

From IoT deployments in production

180K+
Devices in production
<2s
End-to-end enrolment
<60s
Fleet-wide revocation
10 yrs
Field lifecycle supported
Case study
Industrial IoT · Manufacturing

180,000 gateways in the field — no field engineer visits.

Our previous approach broke past 5,000 devices. TigerTrust let us ship the next 175,000 without adding a single provisioning engineer.
VP of Product Security
180K+
Devices in production
<2s
End-to-end enrolment
<60s
Fleet-wide revocation
Integrations

Fits your existing stack

TPM vendors, secure elements, Linux distributions, and IoT cloud platforms the connected-device stack runs on.

Intel PTT
TPM
Infineon SLB
TPM
STMicro ST33
TPM
Microchip ATECC
Secure Element
NXP SE050
Secure Element
Yocto
Embedded Linux
Ubuntu Core
Embedded Linux
Zephyr RTOS
RTOS
AWS IoT Core
IoT Cloud
Azure IoT Hub
IoT Cloud
Matter DAC/PAI
Protocol
FIDO Device Onboard
Protocol
FAQ

Frequently asked questions

Devices are burned at manufacture with an IEEE 802.1AR IDevID — a manufacturer-anchored identity in the TPM or secure element. On first connect the TigerTrust agent presents the IDevID, TigerTrust validates against the manufacturer EK root, and rotates to a short-lived LDevID scoped to your fleet. The device is enrolled in seconds, with no field engineer, and the IDevID stays as a fallback for re-enrolment scenarios.
Yes. Secure elements like Microchip ATECC and NXP SE050 provide hardware-rooted identity and non-exportable keys without a full TPM. TigerTrust supports IDevID / LDevID enrolment on these devices via EST or SCEP. You lose PCR-based attestation but keep per-device unique keys and hardware key custody — a meaningful upgrade from shared secrets.
EST (RFC 7030), SCEP, and CoAP-based enrolment cover the constrained end. Certificate profiles are tuned per device class — ECDSA P-256 keys, minimised extensions, and CBOR-encoded formats. Cert size can go under 500 bytes for devices where every octet on the LoRaWAN uplink matters.
PKI Core replicas scale horizontally. In production we have measured over 1 million certificates per hour on an 8-node cluster with an HSM signer pool. The bottleneck is typically the HSM sign rate. TigerTrust queues requests with backpressure so factory-line bursts never drop enrolments.
Two patterns. First, short-lived leaf certificates with automatic rotation over the management channel — appropriate for connected devices with reliable networks. Second, longer-lived leaves with more frequent trust-anchor rotation — appropriate for intermittently-connected devices. Both are supported per device class, and crypto-agility means algorithm upgrades happen on renewal without firmware changes.
The device is quarantined immediately — its certificate is revoked, CRL propagates within a minute, and OCSP responders serve the revocation. Continuous attestation catches many compromises before an operator notices: PCR drift, tamper flags, and stale attestation all trigger auto-revocation. The device can re-enrol from its IDevID once remediated, so recovery does not require a truck roll.

Ship a fleet with identity built in.