LOGBOOK

HELP

SIOT

Secure IoT

Knowledge and practical skills for secure IoT systems. IoT security threats, attack vectors, technologies, testing tools, security architectures with cloud.

About this sector

Secure Internet of Things. What changes when a computer is the size of a coin, runs off a battery for years, sits in a field or a wall, and still has to be trustworthy. The module builds the picture from both ends: first the architecture — the IoT technology stack from device connection up to human value, the device → gateway → cloud pipeline, and the software architectures for each of those three tiers — and then the security, which on constrained hardware is a different discipline from enterprise IT security rather than a smaller version of it.

Then it gets hands-on. The boards range from Linux-capable Raspberry Pis down to an Arduino with 2 KB of RAM, with the ESP32 and Azure Sphere in between. Sensors reach them over I2C, SPI and UART, and the electronics basics (breadboards, LEDs, resistors, Ohm's law) are what wire them up. The software side is the real-time operating system: preemptive scheduling, task states, semaphores and mutexes, and priority inversion, ending in a FreeRTOS task that blinks an LED on an ESP32.

The recurring constraint is resources. A device with kilobytes of RAM and an energy budget may need to limit connection state, handshake costs and cryptographic code size. Designs can use CoAP over UDP/DTLS, MQTT over TCP/TLS, and IPv6 adapted by 6LoWPAN over IEEE 802.15.4. Firmware authentication may use conventional or hash-based signatures according to the device budget. The recurring lesson is that security has to be designed in from the start: a deployed device with no UI, no physical access and no reinstall path cannot be patched into safety later. Real-world cases carry the argument — the ZigBee worm that jumped between Philips Hue lamps by proximity alone, the DVR and IP-camera botnets that took down half the web's front page, the remotely braked Jeep, ultrasonic commands that voice assistants hear and people do not — and the countermeasures close it: private/authentic/secure channels, signed over-the-air firmware updates, and a secure boot chain that verifies every stage before it runs.

Launch All Sectors