• Become a member
  • Log In
The Institution of Electronics
  • Home
  • About us
    • Our Objectives
    • Our History
    • Governance of the Institution
  • The Electron Magazine
    • 2024
      • 2024 – Winter
      • 2024 – Spring
      • 2024 – Summer
      • 2024 – Autumn
    • 2025
      • 2025 – Winter
      • 2025 – Spring
      • 2025 – Summer
      • 2025 – Autumn
    • 2026
      • 2026 – Winter
  • Members
    • Membership Grades and Fees
    • Members’ Resources
      • The Electron Newsletter
      • The Archives
  • Education and Projects
    • National Electronics Competition
    • Student Members’ Projects
    • Arkwright Engineering Scholarships
  • News
  • Contact Us
  • Menu Menu
Uncategorised

Navigating IoT security in a connected world

Today, billions of smart devices are connected to each other through the Internet and can communicate real-time data without human interaction. A garage door can be opened or closed remotely via an application on a smartphone, a baby can be remotely monitored through cameras or sensors, and even watches and vehicles are connected to the Internet of Things (IoT).

It’s estimated that by 2030, more than 25 billion smart, connected devices will be in use. However, security threats increase as more of these smart devices become integrated into everyday life. So, it’s more essential now than ever to secure IoT devices against these security threats and vulnerabilities.

Moreover, governments, private businesses, and regulatory bodies have recognized that small, incremental changes to cybersecurity defense will not provide the ample security needed for future cyber protection.

 

Cybersecurity regulation initiatives

This urgency toward improving IoT security is being seen globally. In the European Union, Radio Equipment Directive Security Requirements (RED) requires RF manufacturers in the EU to ensure protection from fraud, protection of networks, and protection of personal and private data. Any device that is considered to be connected to the IoT must comply with these regulations by the deadline of August 1, 2024.

Next, Singapore has established its Cybersecurity Labeling Scheme in an effort to improve the security of IoT devices and encourage manufacturers to focus on product security.

Figure 1 Governments around the world are launching cybersecurity initiatives to protect IoT users. Source: Silicon Labs

The United States White House has also recognized the importance of ensuring security for the future of the IoT. Regulation timelines for cybersecurity are accelerating and should be in full force within the next one to two years.

A significant cybersecurity update necessary for future IoT development was signed into action in May 2021 when President Biden signed Executive Order (EO) 14028 “Improving the Nation’s Cybersecurity.” The order aimed to strengthen cybersecurity across the federal government while recognizing the crucial aspect of collaboration with the private sector. EO 14028 emphasizes key aspects needed for enhanced security, such as updating cybersecurity practices, developing security standards for infrastructure, and an incident response plan.

However, most recently, the Biden administration proposed a few key developments needed for cybersecurity that will impact the future of the IoT, especially for consumers. As a part of EO 14028, the administration included the need for producers to provide consumers with a “Software Bill of Materials,” which gives the records for the supply chain relationships or components used when building the software product.

This must be communicated in the form of either a Software Package Data eXchange (SPDX)12, CycloneDX13, or Software Identification (SWID) tags14. If there are known and unknown sources of materials, those must be identified. As a result, this bill improves transparency for consumers, so they understand the possible vulnerabilities in software as well as reduces the risk of hidden security threats.

Additionally, EO 14028 addressed the need for an IoT cybersecurity labeling program for the consumer, derived from the Consumer Security IoT Profile (NIST IR 8425). This IoT labeling program, called the U.S. Cyber Trust Mark, gives consumers clear information about their smart gadgets and IoT devices.

Figure 2 IoT labelling provides users with information about any security breaches or the latest security. Source: Silicon Labs

With the IoT labeling program, devices such as smart refrigerators, fitness tracking devices, baby monitors, or even smart doorbells that meet the government’s cybersecurity requirements can attain a Cyber Crest label. Through a “living label” featured on a product’s packaging, which can manifest as a barcode or QR code, consumers can conveniently scan the label with their smartphone to access vital information, including any security breaches or the latest security threats associated with the product.

This kind of transparency into the IoT will not only help consumers make the best decisions for themselves but will help them to develop trust in the IoT, and as an extension, the product manufacturers.

Overcoming IoT security challenges

Securing these requirements for the IoT is critical for continued development. However, there are ongoing challenges and potential long-term effects that innovators need to consider. Some of these factors include the availability of resources, the price of production and devices, the environmental impact, and the security for sustainable development.

Silicon vendors can help with these challenges through hardware security products offering features that exceed the requirements necessary for the IoT’s current consumer labeling program and protect against local and remote software attacks, local hardware attacks, and have been strategically tested in third-party labs for security functions.

Figure 3 Secure Vault providing IoT device security has earned Arm PSA Certified Level 2 security certification as well as IoXt Alliance SmartCert IoT security. Source: Silicon Labs

Take, for instance, Arm’s Platform Security Architecture (PSA/SESIP certification Level 3). Here, PSA Level 3 builds upon the already stringent security measures of PSA Level 2, including secure boot processes, secure debug ports, secure software updates, and powerful encryption for data and secret keys. It also provides a “hardware root of trust” to protect against software and hardware attacks, as well as physical tampering with hardware and data.

Next, the National Institute of Standards and Technology (NIST) Interagency Report (IR) 8425, developed from NIST IR 8259A and B, forms the basis for the U.S. Consumer IoT Labeling program. Under this report, IoT developers must include security documentation for a way for consumers and companies to communicate vulnerabilities to each other. When security vulnerabilities and bugs occur, reports can be submitted to and handled promptly by providers’ Product Security Incident Response Teams (PSIRT), a highly valued line of support in the industry.

Securing IoT for real-world solutions

With further development necessary for the IoT, it’s crucial to look at the latest IoT practices and trends, their security challenges, and current security practices in these areas where innovators are working to improve security:

Healthcare

Manual care can increase the likelihood for human bias and error. On the other hand, the precision of the IoT can provide real-time tracking for portable health devices, assist in staff workflow, as well as allow for remote patient monitoring. It can also aid in other healthcare areas such as assisted living facilities, self-healthcare, and proactive healthcare.

Supply chain

With the increased demand for products associated with the IoT, partnering with suppliers to manage products from development to consumer delivery will be crucial, and it’s a challenge for innovators to consider for the future. A partnership will support unexpected surges in supply chain demand and ensure security from development to deployment.

Companies can benefit from hardware security services to ensure unique identification of components and secure device provisioning. These services can help products withstand security attacks that may happen during their lifecycle. Take the example of Custom Parts Manufacturing Services (CPMS) offered by Silicon Labs. It simplifies programming, making secure IoT implementation cost-efficient and quick without requiring third-party involvement or significant investments.

AI/machine learning (ML)

As intelligence moves closer to “the edge,” security increases because the information is stored closely to the source of the data. This change helps to reduce possible cyberattacks. Here, AI and ML have the potential to enhance security measures for the IoT.

Navigating the future of IoT

Despite security challenges, the IoT has almost unlimited potential through its ability to connect everyday objects with technology. By 2030, the McKinsey IoT 2021 report estimates that the IoT could “enable $5.5 trillion to $12.6 trillion in value globally.” With this in mind, we should expect the IoT to further integrate into everyday life, into our homes, offices, and medical settings.

As developers work together to solve IoT problems, enhanced security measures become mission critical. Are they ready to tackle security challenges to build a safer, more secure, and connected world?

Rohit Ravichandran is product manager at Silicon Labs.

Related Content

PUF up your IoT security
IoT security: hardware vs software
IoT Security – Physical and hardware security
Hardware-Based Design Approach for Smart-Home IoT Security
What’s Driving the Shift from Software to Hardware in IoT Security?
<!–

VIDEO AD

–><!–

div-gpt-ad-inread

–>

<!–
googletag.cmd.push(function() { googletag.display(‘div-gpt-ad-native’); });
–>

The post Navigating IoT security in a connected world appeared first on EDN.

29 November 2023
http://institutionofelectronics.ac.uk/wp-content/uploads/2022/12/IOE_LOGO.png 0 0 http://institutionofelectronics.ac.uk/wp-content/uploads/2022/12/IOE_LOGO.png 2023-11-29 07:26:442023-11-29 07:26:44Navigating IoT security in a connected world

Latest news

  • Radon: Level detection, risk determination, and as-needed mitigation13 August 2026 - 13:16
  • TI a first mover in CAN XL transceivers13 August 2026 - 10:13
  • Four-channel USB-UART IC boosts server management13 August 2026 - 05:08
  • eFuse speeds overcurrent detection13 August 2026 - 05:08
  • Memory platform tackles AI bottlenecks13 August 2026 - 05:08
  • 6.5-kV SiC MOSFET reaches 8-kV blocking13 August 2026 - 05:08
  • Made by Google 2026: This limited silicon-supply situation really sucks13 August 2026 - 05:08
  • Cheap and cheerful LMC555 RC PWM pulse generator12 August 2026 - 13:56
  • Record high wafer shipments. Can fabs keep pace?12 August 2026 - 07:51
  • Analog uncertainty-aware design: How it replaces Monte Carlo with certifiable yield intelligence11 August 2026 - 16:31
IOE LOGO 2

Become a member

click here

Become a member

click here

Become a subscriber

click here

Become a sponsor

click here

© Copyright - The Institution of Electronics | Website by WHD Solutions
  • Link to LinkedIn
  • Link to Facebook
  • Link to X
Link to: Squashed triangles: sines, but with teeth? Link to: Squashed triangles: sines, but with teeth? Squashed triangles: sines, but with teeth? Link to: Root mean square versus root sum square Link to: Root mean square versus root sum square Root mean square versus root sum square
Scroll to top Scroll to top Scroll to top