UX Design · Study deck

Device Pairing: Trust and Recovery

A shared door lock must find the right device and bind the right owner.

UX Uma is your guide for this deck.

device-discoverypairing-flowcommissioning
UX Uma, the module guide, in a scene from this chapter.
iotclass.org

After studying this chapter

Learning objectives

You will be able to:

  • Trace discovery and pairing review path across its components and failure boundaries.
  • Validate field gateway commissioning with a concrete scenario and pass criteria.
  • trace discovery and pairing review path across its components and failure boundaries
  • validate field gateway commissioning with a concrete scenario and pass criteria
iotclass.org

Major section

Discovery And Pairing Review Path

Proof of possession: evidence that the person pairing has physical or administrative control.

  • Change condition: firmware, app, hub, identity label, account policy, installation context, or support evidence changes.
Pairing is a chain of trust from bounded discovery and physical identification through proof of possession, credential binding, permission assignment, recovery, and the condition that reopens review.
Pairing is a chain of trust from bounded discovery and physical identification through proof of possession, credential binding, permission assignment, recovery, and the condition that reopens review.
iotclass.org

Major section

Candidate Identity

A candidate device must be identifiable enough for a user or installer to select the correct physical object.

  • Identity evidence should match the deployment.
  • A consumer setup flow may rely on a QR label and blinking LED.
  • An industrial setup may require asset tag, work order, cabinet location, installer role, and commissioning log.
iotclass.org

Major section

Pairing Proof

Pairing proof shows that the person pairing the device is allowed to do so.

  • Button press: physical access is proved by pressing a device button during a short pairing window.
  • Account transfer: previous ownership is released, delegated, or revoked before a new owner can bind the device.
  • A temporary button press may be enough for a low-risk sensor in a private room.
iotclass.org

Major section

Discovery And Pairing Record

Decision and change condition: accepted tradeoff, owner, known limit, open issue, and change condition.

  • The record should remain short enough to update whenever the setup flow, account policy, firmware, hub behavior, label, installation workflow, or support tooling changes.
Device discovery and pairing review record.
Device discovery and pairing review record.
iotclass.org

Major section

Worked Review: Shared Door Lock Setup

A shared building uses connected locks for residents, guests, maintenance, and property managers.

  • Shared locks need individual credentials, role boundaries, revocation, transfer, and support evidence.
  • Moment: a lock is already paired to a previous owner or old hub, and residents, guests, maintenance, and property managers all need their own access.
iotclass.org

Major section

Common Findings

The app says "device not found" when the real issue is permission, ownership, sleep state, or unsupported firmware.

  • Factory reset is the first recovery step instead of a last resort.
  • A device can be paired by someone nearby without enough ownership proof.
  • Setup grants owner permission when installer or guest permission would be enough.
iotclass.org

Major section

Common Findings (continued)

QR codes, labels, or buttons are unreachable after installation.

  • Transfer between owners preserves old access or destroys needed service history.
  • The record lacks an owner, known limit, open issue, or change condition.
  • Moment: the app says “device not found” when the real issue is permission, ownership, sleep state, or unsupported firmware.
iotclass.org

Deck summary

Key takeaways

Proof of possession: evidence that the person pairing has physical or administrative control.

  • A candidate device must be identifiable enough for a user or installer to select the correct physical object.
  • Pairing proof shows that the person pairing the device is allowed to do so.
  • Decision and change condition: accepted tradeoff, owner, known limit, open issue, and change condition.
  • A shared building uses connected locks for residents, guests, maintenance, and property managers.
iotclass.org

Retrieval practice

Recall check

UX Uma says: answer from memory, then check your reasoning.

Q1A setup app lists six identical sensors found nearby. The user selects one at random, but the wrong room is added to the account. What is the strongest review response?

AAccept the flow because discovery found the sensors successfully
BHold until it adds physical confirmation, duplicate handling, and wrong-device recovery
CHide all device identity details to simplify the setup screen
DRequire factory reset whenever the wrong device is selected or recovery feels uncertain
Show answer

Answer: B Discovery is incomplete until the user can identify the correct physical device, prove authority, bind credentials, and recover from wrong or partial setup.

iotclass.org

Print reference

Answers

Answer key.

  1. B · Discovery is incomplete until the user can identify the correct physical device, prove authority, bind credentials, and recover from wrong or partial setup.
iotclass.org