GEISA Specification 0.9.0-d117517¶
Contents:
- 1. Abstract
- 2. Contributors
- 3. License
- 4. Introduction
- 5. Glossary
- 6. Design Principles
- 7. Operations
- 7.1. Purpose and Scope
- 7.2. Roles and Authorities
- 7.3. End-to-End Operational Context
- 7.4. Operational Capability
- 7.5. Device Onboarding and Management Overview
- 7.6. Application Approval and Deployment Overview
- 7.7. Off-Device Communication Approval
- 7.8. Application Activation and Runtime Visibility
- 7.9. Operational Reporting and Visibility
- 7.10. Utility and Enterprise Interaction Points
- 7.11. Application Certification
- 7.12. Future Considerations
- 8. System Architecture
- 9. Conformance
- 10. Hardware Expectations
- 11. Application & Device Management
- 12. Linux Execution Environment
- 13. Virtual Execution Environment
- 14. Application Programming Interface (API)
- 14.1. API Architecture
- 14.2. API Catalog Reference
- 14.3. Platform Discovery
- 14.4. Platform and App Status
- 14.5. Common Response Status
- 14.6. Instantaneous Data
- 14.7. Billing Data
- 14.8. Waveform Data
- 14.9. References
- 14.10. Actuator Status & Control
- 14.11. Sensors
- 14.11.1. Scope
- 14.11.2. Sensor Discovery Model
- 14.11.3. Geolocation Metadata
- 14.11.4. Sensor Type Enumeration
- 14.11.5. Runtime Data Model
- 14.11.6. Sensor Value Model
- 14.11.7. Read Request and Response
- 14.11.8. MQTT Details
- 14.11.9. API Permissions
- 14.11.10. Transaction Data
- 14.11.11. Notes
- 14.11.12. References
- 14.12. Off-Device Communication
- 14.12.1. Message-based via LwM2M
- 14.12.2. IP socket based to local devices, private clouds, or public clouds
- 14.12.3. Interface Types
- 14.12.4. Destination Classes
- 14.12.5. Network State
- 14.12.6. Volume Limits
- 14.12.7. Security considerations
- 14.12.8. Connectivity
- 14.12.9. Policy Rules
- 14.12.10. DNS
- 14.12.11. Local Endpoint Considerations
- 14.13. App-to-App Communication
- 15. Security
- 15.1. Responsibilities
- 15.2. Threat Model
- 15.2.1. Software Provenance and Deployment Authorization
- 15.2.2. Lifecycle Trust Enforcement
- 15.2.3. Trust Revocation and Credential Lifecycle
- 15.2.4. Assets Requiring Protection
- 15.2.5. Trust Boundaries and External Interfaces
- 15.2.6. Threat Actors Considered
- 15.2.7. Representative Threat Scenarios
- 15.2.8. Unauthorized Use of Local Service Interfaces
- 15.2.9. Compromise of a Customer-Network Connected Device
- 15.2.10. Malicious or Altered Software Introduced During Update
- 15.2.11. Remote Exploitation of Exposed Services
- 15.2.12. Insider Abuse of Authorized Privileges
- 15.2.13. Coordinated Manipulation Across Multiple Devices
- 15.3. Interpretation of Conformance
- 15.4. Security Capability Expectations
- 15.5. Digital Signatures
- 15.6. Certificates
- 15.7. Network Security
- 15.8. GEISA API Security
- 16. Revision History
[LWM2M]
[LWM2M-Transport]
OMA Lightweight Machine to Machine Technical Specification: Transport Bindings 1.2.2
[NIST800-186]