How Open Horizon protects your Edge
Open Horizon is a deployment management system designed specifically to address a number of security challenges. We will discuss those capabilities now. However, it is also important to understand that Open Horizon does not intermediate your own application code or any communication it performs with other services in other nodes. You are responsible for ensuring your own code is adhering to good security practices.
Device attestation
As discussed in the Components of the Management Hub section of Chapter 4, Open Horizon supports the FIDO Device Onboard (FDO) system to enable zero-touch provisioning of the Open Horizon agent.
The core of FDO is built on the idea that device manufacturers will create a non-repudiable, secure token representing the authenticity of the individual device. The voucher, and the subsequent registration mechanism supported by Open Horizon, can be used to attest to the authenticity of the device. It is not subject...