Security · Engineering
Station tokens and plant isolation
A weight station should speak for itself. It should not speak for the whole factory.
The Smart Weight System sits on a factory floor. USB scales, thermal printers, Raspberry Pi boxes, a local service, and a central server. Bags get a weight and a QR identity. The network drops. Work continues. Later, events catch up.
That last part matters. Offline sync is useful. It is also a way to replay bad data if you do not know which station sent it.
One key for every box is a bad story
The easy design is a shared API key in every device image. Clone a Pi, you clone the plant. Steal one token, you write inventory as any station.
We used station tokens instead. A station proves it is that station. The server maps the token to a plant. One box cannot pretend to be another floor.
Isolation is a product rule
Plant-level isolation is not a slogan. Receiving, ledgers, and dispatch only make sense if plant A cannot see plant B’s bags. The token is the first filter. Authorization after that is boring on purpose: 401 if you are nobody, 403 if you are the wrong plant.
Offline does not mean sloppy
Local cache, retries, idempotency, and circuit breakers keep the line moving. They also stop a reconnect storm from double-counting a bag. Security here is operational integrity: the record is the bag that was weighed, once.
A device identity is a trust boundary. Treat it like one.
How I’d attack it
Thinking like the attacker is the useful test of the design:
- Clone a device. Copy a Pi’s SD card and the token comes with it. A token per station limits the damage to one station, and revoking it is a server-side switch.
- Steal a token off the wire. On a flat factory network, anything unencrypted can be sniffed. Transport security and short-lived credentials matter as much as the token format.
- Replay the sync queue. Resend yesterday’s events and hope inventory goes up twice. The event id in the data model is what turns the replay into a no-op.
- Cross the plant boundary. Use a valid token from plant A to write to plant B. That’s the 403 path, and it’s worth testing on purpose.
What I will not publish
Client internals, live endpoints, and exact token formats stay off this page. The useful part is the shape: station auth, plant isolation, offline resilience, and tests that gate deploy.
This is application and IoT engineering with security in the design. It is not a red-team report.