loading experience

Electronics & IoT

Secure IoT: device identity and firmware updates

The principles for designing connected devices that stay secure throughout their life in the field.

Secure IoT: device identity and firmware updates

An IoT device stays installed for years. Security is not added at the end: it is designed together with the hardware.

The device accepts only the manufacturer's firmware and can always roll back.
The device accepts only the manufacturer's firmware and can always roll back.

An identity for every device

Every device must have its own credentials, never shared with others, ideally stored in a dedicated secure element. If one device is compromised, only that one is revoked.

Encrypted communication

All communication goes over encrypted, authenticated channels, both to the platform and to configuration tools. No service ports left open in production.

Signed firmware updates

The device accepts only firmware signed by the manufacturer and keeps a working copy to fall back to if an update fails. Vulnerabilities discovered in the future can then be fixed without a site visit.

Only what is necessary

Every unnecessary function is attack surface. Disable debug interfaces, unused services and test accounts before production, and keep an inventory of the software components used in the firmware.

These principles also underpin the new European rules on the security of connected products: designing them in from the start costs far less than adapting later.

Comments (0)

No comments yet.

Leave a comment