Section 78 of 101
77. Device and Cartridge Authentication
Stable section ID: S05-CON-006-SECTION-78 · 34 content blocks
Device and Cartridge Authentication verifies that a connected entity possesses the identity and credentials associated with its registered record.
Authentication shall occur before a device or Cartridge receives protected network access, configuration authority, control permissions, or participation in a safety-relevant service.
Authentication may use:
hardware-backed device credentials;
manufacturer-issued certificates;
System05 registration credentials;
challenge-response protocols;
signed firmware identity;
secure physical provisioning;
supervised enrollment;
durable physical identity for passive components.
The authentication process shall verify:
Device or Cartridge Instance ID;
credential issuer;
credential validity;
revocation status;
Type and version consistency;
firmware or software integrity where required;
consistency with physical identification;
consistency with the assigned building location;
absence of duplicate active identity.
Authentication status shall be:
authenticated;
provisionally authenticated;
physically identified only;
expired;
revoked;
duplicated;
inconsistent;
unauthenticated.
Authentication does not establish compatibility, certification, health, or operational authorization. Those evaluations shall remain separate.
A passive Cartridge without electronic credentials may be authenticated through physical identification, installation evidence, supervised verification, and Registry comparison. Its authentication strength shall be appropriate to its criticality.
Failed authentication shall place the entity into a quarantined or restricted state. The BIOS may permit limited diagnostic communication without granting ordinary operational access.
Repeated authentication failure or identity duplication shall generate a security event and may trigger Interface isolation.