Zigbee, Thread & Matter · Study deck
Matter Fabric Security
Matter fabric security is the trust layer that lets a device participate in one or more Matter administrative domains without sharing one global household credential.
Radio Remi is your guide for this deck.

After studying this chapter
Learning objectives
You will be able to:
- Review Matter fabric security using fabric, certificate, session, ACL, and interaction records.
- Distinguish PASE commissioning evidence from CASE operational-session evidence.
- Explain how multi-admin control preserves separate trust domains rather than sharing one credential pool.
- Identify fabric-capacity, stale-credential, wrong-fabric, and overbroad-ACL failures before approving a deployment.
Major section
Start With the Trust Boundary
Adding a second controller must not grant every person the same rights or leave an old controller trusted after the tenancy ends.
- Matter is a shared application model for connected devices.
- A fabric is one managed trust group with its own identity and keys.
- Encrypted reachability does not prove that a person should be allowed to act.
Major section
Start With the Trust Boundary (continued)
The start-simple move is to follow one device from discovery through approval to ordinary traffic.
- Membership also does not prove sensor truth, safe physical behavior, or correct account ownership.
- Practitioner builds the access and change record.
- Once that path is visible, the deeper material can test replay protection, credential custody, fabric scope, and operational exceptions.
Major section
In 60 Seconds · Fabric Security Review Claim · Fabric Evidence Path
A Matter fabric is an administrative trust domain with its own root of trust, fabric identity, operational certificates, and access-control records.
- Multi-admin means one device can be commissioned into multiple fabrics, but each fabric keeps its own credentials and permissions.
- A Node Operational Certificate is not just a label.
Major section
Evidence Families · What a Fabric Proves · Multi-Admin Boundaries
Matter fabric security review needs several evidence families.
- A missing family usually means the decision should stay open.
- This framing keeps multi-admin evidence honest.
- A device may have one fabric for a resident controller, another for a building operator, and another for a service workflow.
- Multi-admin is not credential sharing.
Major section
Certificate and Fabric Identity · PASE and CASE Evidence · Access Control Lists
Matter operational identity is fabric-scoped.
- The reviewer should confirm that the node identity presented during operation chains to the expected fabric trust anchor and that the device stores the corresponding fabric entry.
- The credential must match the fabric and operation being reviewed.
- ACL review connects identity to allowed action.
Major section
Encrypted Interaction Evidence · Network Evidence That Still Matters
After secure session establishment, the interaction should be protected and authorized.
- The reviewer should preserve the interaction type and outcome with the security record.
- Rejections are useful evidence when the request is intentionally out of scope.
- Security evidence is strongest when successful operations and expected denials are both tested.
Major section
Commissioning and Failure Evidence · Worked Review: Adding a Second Fabric
Commissioning is a lifecycle event.
- It should leave a record that explains how the device entered the fabric and what administrative authority was created.
- Fabric capacity is especially easy to misreview.
- The evidence should show the fabric table state and the administrative action used to remove or retain each fabric.
Major section
Worked Review: Wrong-Fabric Controller · Worked Review: Overbroad Voice Assistant ACL
The app reports that the device is unavailable.
- Evidence: network reachability is present, but the CASE evidence shows the presented identity does not chain to the expected fabric.
- The device rejects the session before any authorized interaction occurs.
- The issue is not Thread or Wi-Fi reachability.
Major section
Common Mistakes · Matter Fabric Security Checklist
Mixing fabrics: A credential from one fabric should not be used as proof for another fabric.
- Multi-admin means separate trust domains.
- Approving from one toggle: One successful Invoke command does not prove Read, Subscribe, Write, Timed, administrator actions, or another endpoint.
- Fabric cleanup should be part of commissioning review.
Major section
Fabric as the Unit of Trust · Certificates, Sessions, and Multi-Fabric Records
A fabric is a security domain of nodes that share a common root of trust, usually represented by a fabric Certificate Authority.
- Every node admitted to a fabric receives a Node Operational Certificate issued under that fabric authority, which becomes the node's verifiable identity inside that fabric.
Major section
Passcode Bootstrap, Certificate Operation · Summary
At commissioning there is no shared fabric identity yet, so Matter uses PASE: a password-authenticated key exchange based on SPAKE2+ and the device setup passcode.
- The exchange establishes a protected channel by proving passcode knowledge without sending the passcode itself.
- After commissioning, the passcode is not the normal operational identity.
- The safest decision is bounded.
Major section
Key Takeaway · Concept Relationships
Matter Fabric Security Evidence should connect fabrics, certificates, access control, operational credentials, rotation, recovery, and deployment evidence.
- Matter Interactions explains the operations that ACLs authorize.
- Matter Protocol Stack and Data Model explains endpoints, clusters, commands, and attributes protected by Matter security.
- Thread Security and Matter separates Thread network security from Matter fabric security.
Deck summary
Key takeaways
Adding a second controller must not grant every person the same rights or leave an old controller trusted after the tenancy ends.
- The start-simple move is to follow one device from discovery through approval to ordinary traffic.
- A Matter fabric is an administrative trust domain with its own root of trust, fabric identity, operational certificates, and access-control records.
- Matter fabric security review needs several evidence families.
- Matter operational identity is fabric-scoped.
Retrieval practice
Recall check 1 of 6

Radio Remi says: answer from memory, then check your reasoning.
Q1In Matter fabric security, when is PASE used versus CASE?
Show answer
Answer: A PASE protects commissioning before operational credentials exist; CASE authenticates operational sessions afterward.
Retrieval practice
Recall check 2 of 6

Radio Remi says: answer from memory, then check your reasoning.
Q2A controller establishes a CASE session with a Matter device, but its command to change the device ACL is rejected. What is the best review interpretation?
Show answer
Answer: B CASE and ACLs answer different questions.
Retrieval practice
Recall check 3 of 6

Radio Remi says: answer from memory, then check your reasoning.
Q3A device can be controlled from fabric A, but a controller from fabric B cannot establish an operational session. What evidence should be checked first?
Show answer
Answer: B Start with fabric identity and credential-chain evidence for fabric B; once the credentials check out, then verify whether fabric B ACL entries authorize the operation.
Retrieval practice
Recall check 4 of 6

Radio Remi says: answer from memory, then check your reasoning.
Q4What is a Matter fabric?
Show answer
Answer: A A Matter fabric is a security domain of nodes sharing a trust root, with each node holding a fabric-scoped Node Operational Certificate.
Retrieval practice
Recall check 5 of 6

Radio Remi says: answer from memory, then check your reasoning.
Q5How does a commissioned Matter node prove its identity to a controller during normal operation?
Show answer
Answer: A Operational Matter sessions use CASE, authenticated by each node's Node Operational Certificate from the reviewed fabric.
Retrieval practice
Recall check 6 of 6

Radio Remi says: answer from memory, then check your reasoning.
Q6Why does Matter use PASE for commissioning but CASE for operation?
Show answer
Answer: A PASE bootstraps a protected commissioning channel from the passcode; CASE authenticates operational sessions with fabric certificates.
Print reference
Answers 1 of 2
Answer key.
- A · PASE protects commissioning before operational credentials exist; CASE authenticates operational sessions afterward.
- B · CASE and ACLs answer different questions.
- B · Start with fabric identity and credential-chain evidence for fabric B; once the credentials check out, then verify whether fabric B ACL entries authorize the operation.
- A · A Matter fabric is a security domain of nodes sharing a trust root, with each node holding a fabric-scoped Node Operational Certificate.
Print reference
Answers 2 of 2
Answer key.
- A · Operational Matter sessions use CASE, authenticated by each node's Node Operational Certificate from the reviewed fabric.
- A · PASE bootstraps a protected commissioning channel from the passcode; CASE authenticates operational sessions with fabric certificates.