Telecoms, Datacoms, Wireless, IoT


The five pillars of secure IoT design

19 April 2017 Telecoms, Datacoms, Wireless, IoT

For any industrial Internet of Things (IoT) application, ensuring signal integrity is crucial for safety and operational reliability. However, even the most robust system has many attack surfaces that are vulnerable to would-be ­hackers intent on compromising a system. This is unacceptable for high-reliability systems in general, but as more contextual information gets added, including time and position, the level of compromise increases dramatically, so gaps in security must be identified and closed at every opportunity.

In the case of an IoT sensor, a chain of trust must be established from the sensor to the microcontroller and wireless module, and all the way through to the end application. In industrial applications for the IoT, every attack surface must be secured in order to establish a chain of trust. u-blox refers to this as its five pillars of secure IoT design:

• Device firmware and Secure Boot.

• Communications to the server.

• Interface security.

• Enforcing API control.

• Robustness that includes handling spoofing/jamming.

Secure Boot ensures that a device is executing the intended firmware by authenticating at each stage before booting the next process. Also, while over-the-air updates are useful for mass uploads of many widely deployed IoT devices, they create an attack surface that can be vulnerable, so all firmware must first be validated before being installed. A good implementation will include a backup of a previously authenticated image to allow backtracking if there is a problem.

At the communications or transport layer, a device needs to be able to authenticate itself with the server and all exchanged data should be encrypted, with no possibility of a ‘man in the middle’ attack. Secure key management will allow for this, even on a per-session basis.

The defined APIs that provide access to device functionality are also a vulnerability that must be addressed, though they are often overlooked. This is particularly insidious as hackers usually have a lot of time to look for open APIs and explore their relationship to device functionality and features, which sometimes might include access to paid services. Also, developers often use undocumented APIs for their own test and configuration purposes, so these must be protected too, using the same formal authentication and authorisation processes as used for all APIs.

The fifth link in securing IoT devices involves ensuring robustness, such as when facing jamming or spoofing attempts that might undermine the device’s ability to get accurate position data from a GNSS. The design must be able to detect that the reported information is not accurate and report the situation to the user or IoT network operator.

For more information contact Andrew Hutton, RF Design, +27 (0)21 555 8400, [email protected], www.rfdesign.co.za



Credit(s)



Share this article:
Share via emailShare via LinkedInPrint this page

Further reading:

Scalable and secure IoT device onboarding and management
Telecoms, Datacoms, Wireless, IoT
EasyPass is an enhancement within Cambium’s cnMaestro platform, aimed at providing local businesses with secure, efficient, and scalable device management making it ideal for high-demand environments such as educational institutions, retail spaces, and corporate campuses.

Read more...
Industrial-grade Ethernet switches
Vepac Electronics Telecoms, Datacoms, Wireless, IoT
Covering PoE-powered series and certified models like PROFINET, DNV, and Railway, these products offer reliable networking solutions for diverse industrial applications.

Read more...
Non-reflective SPDT RF switch
RS South Africa Telecoms, Datacoms, Wireless, IoT
The ADRF5019 from Analog Devices is a non-reflective, single pole, double throw RF switch that operates from 100 MHz to 13 GHz.

Read more...
Ultrawideband Low Noise Amplifier
Altron Arrow Telecoms, Datacoms, Wireless, IoT
The ADL8101 is an ultrawideband, low noise amplifier that operates from 10 kHz to 22 GHz with typical gain and noise figure of 14 dB and 3,5 dB respectively.

Read more...
Data Centre trends 2025
Telecoms, Datacoms, Wireless, IoT
Innovation in powering and cooling AI racks, management of energy consumption and emissions all to be a focus in 2025.

Read more...
Air temperature and humidity transmitter
Mimic Components Telecoms, Datacoms, Wireless, IoT
The RHT air temperature and humidity transmitter is a fully wireless solution designed for seamless measurement of temperature and humidity over long distances.

Read more...
Module combines 5G and NTN support
Quectel Wireless Solutions Telecoms, Datacoms, Wireless, IoT
Quectel Wireless Solutions announced the launch of its BG770A-SN ultra-compact 5G-ready satellite communication module, compliant with 3GPP releases 13, 14 and 17.

Read more...
3,75 GHz RF inductor
RF Design Passive Components
The ceramic chip wire wound inductor from Coilcraft features a DC resistance of 1 O, a DC current of 175 mA, and a self-resonant frequency of 3,75 GHz.

Read more...
SIMCom’s A7673X series
Otto Wireless Solutions Telecoms, Datacoms, Wireless, IoT
SIMCom’s A7673X series is a Cat 1 bis module that supports LTE-FDD, with a maximum downlink rate of 10 Mbps and an uplink rate of 5 Mbps.

Read more...
Non-terrestrial network module
Altron Arrow Telecoms, Datacoms, Wireless, IoT
Fibocom unveiled its MA510-GL (NTN), a non-terrestrial networks module which is compliant with 3GPP Release 17 standard.

Read more...