Back to Blog

Security · Engineering

Station tokens and plant isolation

A weight station should speak for itself. It should not speak for the whole factory.

The Smart Weight System sits on a factory floor. USB scales, thermal printers, Raspberry Pi boxes, a local service, and a central server. Bags get a weight and a QR identity. The network drops. Work continues. Later, events catch up.

That last part matters. Offline sync is useful. It is also a way to replay bad data if you do not know which station sent it.

One key for every box is a bad story

The easy design is a shared API key in every device image. Clone a Pi, you clone the plant. Steal one token, you write inventory as any station.

We used station tokens instead. A station proves it is that station. The server maps the token to a plant. One box cannot pretend to be another floor.

Isolation is a product rule

Plant-level isolation is not a slogan. Receiving, ledgers, and dispatch only make sense if plant A cannot see plant B’s bags. The token is the first filter. Authorization after that is boring on purpose: 401 if you are nobody, 403 if you are the wrong plant.

Offline does not mean sloppy

Local cache, retries, idempotency, and circuit breakers keep the line moving. They also stop a reconnect storm from double-counting a bag. Security here is operational integrity: the record is the bag that was weighed, once.

A device identity is a trust boundary. Treat it like one.

How I’d attack it

Thinking like the attacker is the useful test of the design:

What I will not publish

Client internals, live endpoints, and exact token formats stay off this page. The useful part is the shape: station auth, plant isolation, offline resilience, and tests that gate deploy.

This is application and IoT engineering with security in the design. It is not a red-team report.

Related

Introduction