By Phil Beecher, President/CEO Wi-SUN Alliance
Every smart meter, streetlight and environmental sensor connected to a city network creates another potential point of attack. As utilities and municipalities deploy millions of IoT devices, security is becoming just as important as coverage, battery life and cost. Here are five security capabilities organisations should demand from their IoT network infrastructure.
1. Strong device authentication
The first security consideration is how devices are added to a network. Currently, several IoT network technologies rely on pre-shared keys. Although this may sound secure, since in principle only the device vendor holds them, it creates a serious vulnerability. If a key falls into the wrong hands, whoever holds it can simply join the network. Instead, utilities and cities need true device authentication, the equivalent of a passport and a visa. Each device should carry its own “passport” (identity) and “visa” (permission to access the network). Organisations typically implement this using certificates and public key infrastructure (PKI), which also support firmware signing.
This becomes even more important as organisations deploy more applications at the Edge. Devices must be able to verify that any software running on them is authorised, helping maintain the integrity of the wider network.
Key Rotation
The second requirement is encrypting messages in transit. As with device authentication, any technology using a single pre-shared key is at risk. Any technology using a single pre-shared key is vulnerable if that key is compromised. Regular key rotation limits the amount of encrypted traffic exposed to any one key and reduces the opportunity for attackers to decrypt captured data.
2. Scalable security monitoring
Scalability and visibility are other critical aspects to consider when managing very large networks. Operators must be confident they can deploy millions of devices while maintaining full security oversight across the entire network. This means having clear visibility into network structure, device behaviour and anomalies, so that unusual activity stands out rather than getting lost in the noise of a large deployment. The reality is that for a network to be secure, if even a single device is compromised, operators need to detect it quickly, understand the nature of the issue, and remove or isolate that device from the network. As networks grow, monitoring, threat detection and remediation must all be automated to remain effective.
3. Secure OTA updates
Routine maintenance tasks, such as over-the-air (OTA) firmware upgrades, also need to be manageable at scale, with minimal per-device interaction. This matters beyond convenience. If engineers discover a vulnerability in a device or algorithm that affects multiple devices, organisations need to be able to fix it quickly across the whole fleet using an OTA update, without visiting each device individually.
Firmware signing ensures only authenticated software updates are accepted. Using the same certificate infrastructure that verifies device identity also enables organisations to verify firmware integrity before installation.
4. End-to-end application security
Another consideration is that having a security solution at the communications layer alone is not sufficient; you must also have application security.
Communications security alone is not enough; applications also need protection. Online banking is a good example. Regardless of whether you’re connected through your home Wi-Fi or a public hotspot, HTTPS keeps data encrypted between your device and the bank. IoT applications require the same principle, ensuring data remains protected throughout its journey rather than only across the local network.
This same scenario must exist in multi-service IoT networks, where multiple devices may run different applications that need to be securely segregated from each other. Imagine that you have gas and electric meters on the same network. If billing is handled by different companies, and a separate company manages the network and meters, then it’s a privacy breach if confidential data is viewed by an unauthorised entity.
IPv6 amplifies end-to-end security
IoT networks that run IPv6 across every device offer the potential for the highest level of IoT security, because every device is uniquely addressable and traffic can be routed directly through routers rather than gateways. This matters because gateways themselves are a security vulnerability: they need to decode the application layer to know where to direct a message, which means the message can’t remain sealed end-to-end. Routers, by contrast, only need the routing information in the packet. They never need to open the message itself.
This has two major benefits, but neither happens automatically; both depend on organisations actually deploying the right tools and practices on top of IPv6.
First, IPv6 to the Edge enables the use of the same intrusion detection tools used on enterprise networks. For example, AI-based tools that recognise traffic patterns and flag anomalous behaviour that might indicate an attack. Because every device is individually addressable and reachable, these tools can gain visibility into the activity of every single device, not just the traffic that happens to pass through a gateway.
IPv6 enables this level of visibility because every device is directly addressable, unlike proprietary gateway-based architectures.
Second, IPv6 to the Edge enables genuine end-to-end encryption, since all the routing information needed to deliver the packet is contained within the packet itself. This removes another vulnerability inherent to gateways, which, because they must read and act on the message to route it, creates a point at which messages must be decrypted or at least partially decoded.
To put this in simpler terms: using IPv6 end-to-end is like sealing a letter in an envelope with a tamper-evident seal, writing the address directly on the outside, and dropping it in the post. It arrives at the recipient address, and you can tell if anyone has opened it along the way. A gateway-based network, by contrast, is like tucking the envelope flap in rather than sealing it, with the actual address written on the letter inside, not on the envelope. Someone handling the envelope must partially open it just to see where it’s going. Once open, there’s nothing stopping them from reading further, and no way to tell afterward whether they did.
5. Open standards and future readiness
One of several benefits of using standards-based technologies is that, by definition, many interested parties rigorously scrutinise standards. It is well-recognized that security by obscurity doesn’t work and is easy to hack. Simply put, understanding the algorithms does not mean that anyone can decrypt the information. Open standards encourage interoperability without weakening security, because understanding an encryption algorithm does not mean an attacker can decrypt protected information.
The future of IoT security needs to be developed now
One evolving area of IoT security is that cyber-attacks are becoming more sophisticated, and the advent of post-quantum computing becomes even more important as computers become powerful enough to process messages more quickly than ever before. This means hackers can capture large amounts of data, process it, and uncover sensitive information, thereby breaching privacy and potentially leaving a network vulnerable to future attacks. Cities and utilities must therefore have a mechanism for anticipating how challenges will increase and design solutions into the network.
Whether the majority of IoT networking technologies are ready to process data at the Edge in quantum computing environments is another matter. They must use the right cybersecurity technology that enables migration to more advanced post-quantum algorithms as needed. Standards-based networking technologies that incorporate these capabilities will be better placed to support the long-term needs of smart cities and utilities.
Author biography:
Phil Beecher is President/CEO of Wi-SUN Alliance
