Zigbee, Thread & Matter · Study deck

Zigbee Security

Imagine a new lamp asking to join a building network.

Radio Remi is your guide for this deck.

zigbeesecuritytrust-center
Radio Remi, the module guide, in a scene from this chapter.
iotclass.org

After studying this chapter

Learning objectives

You will be able to:

  • Explain: A single shared network key means one key exposure can affect the whole mesh, so the join step and key-custody record deserve direct evidence rather than a generic "encrypted network" note.
  • Explain: Trust Center custody evidence records who owns the coordinator or Trust Center role, how configuration is backed up, who can change join policy, and how replacement is approved.
  • Explain: The reviewer should be able to name the Trust Center, identify the link key or credential that protected each join, and explain who controls the shared network key.
  • Explain: Lost devices lose trust.
iotclass.org

Major section

In 60 Seconds

The safe question is not just whether it can join.

  • The question is who approved it, which key it received, and how the owner can remove it later.
  • Zigbee is a low-power mesh radio system.
  • A protocol is an agreed set of rules for how devices exchange data.
  • Encryption alone does not prove safe operation.

Key terms

protocol
protocol is an agreed set of rules for how devices exchange data.
gateway
gateway is the boundary device or service that links the mesh to another network.

Why it matters

A network is not secure because it names encryption or has a Trust Center.

iotclass.org

Major section

In 60 Seconds (continued)

A gateway is the boundary device or service that links the mesh to another network.

  • Practitioner records join, custody, removal, exceptions, and retest.
  • Those details may tighten the first claim.
  • They never turn a working join into proof that every later command is allowed.
  • Lost devices lose trust.
iotclass.org

Major section

In 60 Seconds (continued)

A network is not secure because it names encryption or has a Trust Center.

  • A changed owner starts a new review.
  • Zigbee security review asks whether joining, key transport, traffic protection, replay handling, and operations custody are proven for the deployment boundary.
  • This chapter keeps the focus on evidence.
iotclass.org

Major section

Evidence Families

Trust Center custody evidence records who owns the coordinator or Trust Center role, how configuration is backed up, who can change join policy, and how replacement is approved.

  • Key transport evidence records how the network key reaches a joining device and whether the join method depends on a shared default assumption or a device-specific credential.
  • Network-key custody evidence records where the shared network key is stored, who can access it, how backup is protected, and what happens after suspected exposure.
  • Application-security evidence records whether sensitive commands need pairwise or application-layer protection beyond mesh-layer encryption.
iotclass.org

Major section

Key Transport and Key Custody

Zigbee deployments commonly depend on a shared network key for mesh-layer protection.

  • The security review asks how that key was delivered, stored, backed up, and protected from unauthorized use.
  • The most important APS use is join-time network-key transport from the Trust Center to a newly authorized device.
  • That split makes the review sharper.

Why it matters

The riskiest instant in a Zigbee network's life is a device joining, because that is when the Trust Center transports the network key to the newcomer.

Zigbee security evidence boundary showing Trust Center custody, authorized join evidence, protected key transport, network traffic protection, application boundary review, operations visibility, decision, owner, and retest trigger.
Zigbee security evidence boundary showing Trust Center custody, authorized join evidence, protected key transport, network traffic protection, application boundary review, operations visibility, decision, owner, and retest trigger.
iotclass.org

Major section

Key Transport and Key Custody (continued)

The reviewer should be able to name the Trust Center, identify the link key or credential that protected each join, and explain who controls the shared network key.

  • A single shared network key means one key exposure can affect the whole mesh, so the join step and key-custody record deserve direct evidence rather than a generic "encrypted network" note.
  • The purpose is to separate an encrypted radio frame from the stronger claim that the right device joined, under an owned policy, for an approved application action.
  • Two approaches protect that transport very differently.
iotclass.org

Major section

Key Transport and Key Custody (continued)

The progression is the chapter's security argument in compact form: cryptography protects traffic, while identity, custody, application scope, and lifecycle evidence determine what that protection actually proves.

  • Second, do not treat a successful join as proof that the correct device joined for the correct reason.
  • The legacy method uses a well-known default global link key, the ZigBeeAlliance09 value.
  • Because it is public, anyone who sniffs a join secured only by that default can recover the network key and, with it, the whole mesh.
iotclass.org

Major section

Frame Counter and Replay Review

Frame counters and message freshness checks help reject replayed traffic, but they still need review at lifecycle boundaries.

  • Every secured Zigbee frame carries a monotonically increasing frame counter.
  • A receiver rejects a secured frame when its counter is not greater than the last counter accepted from that sender.
  • If devices stop being accepted after a power cycle, suspect frame-counter state before assuming the keys are wrong.
iotclass.org

Major section

Green Power and Constrained Device Boundaries

Some Zigbee deployments include constrained or energy-harvesting devices that use simplified security behavior.

  • The review question is not whether those devices are "secure enough" in general.
  • The question is whether their limits are acceptable for the specific action they trigger.
  • Green Power serves ultra-constrained, energy-harvesting devices, such as a battery-less light switch, that cannot run the full Zigbee stack.
iotclass.org

Major section

Security Review Record

Traffic Boundary then states what mesh protection and replay evidence cover.

  • Decision narrows, revises, rejects, or accepts the claim with an owner and retest trigger.
  • That order carries protocol behaviour into accountable approval without hiding a lifecycle gap.

Why it matters

It prevents a successful join or an AES label from becoming a blanket approval when the deployment boundary, exceptions, or ownership are still unknown.

Zigbee security review record showing claim, boundary, Trust Center owner, join evidence, key custody, traffic boundary, exception, decision, owner, and retest trigger.
Zigbee security review record showing claim, boundary, Trust Center owner, join evidence, key custody, traffic boundary, exception, decision, owner, and retest trigger.
iotclass.org

Major section

Concept Relationships

Trust Center and join policy: the Trust Center controls who can join, while the review record proves whether the approved join policy was followed.

  • Network key and application boundary: mesh-layer protection can protect network traffic, but high-impact application actions may need additional evidence.
  • Frame counters and lifecycle events: replay assumptions need retest after reset, rejoin, replacement, restore, or firmware changes.
  • Backup and operations: coordinator recovery is useful only when backup access, restore behavior, and ownership are controlled.
iotclass.org

Deck summary

Key takeaways

The safe question is not just whether it can join.

  • A gateway is the boundary device or service that links the mesh to another network.
  • A network is not secure because it names encryption or has a Trust Center.
  • Trust Center custody evidence records who owns the coordinator or Trust Center role, how configuration is backed up, who can change join policy, and how replacement is approved.
  • Zigbee deployments commonly depend on a shared network key for mesh-layer protection.
iotclass.org

Retrieval practice

Recall check 1 of 6

Radio Remi says: answer from memory, then check your reasoning.

Q1Why is 'we have a Trust Center and encryption' not enough to call a Zigbee network secure?

ASecurity needs proven join path, key custody, removal behavior, and retest evidence
BBecause Trust Centers are optional extras that most real Zigbee deployments simply leave out
CBecause AES encryption slows mesh traffic so much that networks disable it in practice
DBecause a Trust Center can only protect the mains-powered devices in the network
Show answer

Answer: A A Zigbee network is reviewable only when join path, key custody, removal behavior, and retests are evidenced, not just naming encryption.

iotclass.org

Retrieval practice

Recall check 2 of 6

Radio Remi says: answer from memory, then check your reasoning.

Q2What is the difference between the Zigbee network key and a link key?

AThe network key is shared PAN-wide and secures NWK-layer frames
BThe network key is per-device and the link key is shared by everyone.
CBoth keys are identical and interchangeable.
DThe link key encrypts radio frequencies, not data.
Show answer

Answer: A Network key means PAN-wide NWK security; link key means pairwise or legacy global APS security, including join-time network-key transport.

iotclass.org

Retrieval practice

Recall check 3 of 6

Radio Remi says: answer from memory, then check your reasoning.

Q3Why does install-code-based joining protect a Zigbee network better than the default global link key?

AThe install code yields a unique per-device link key known only to that device and the Trust Center.
BInstall codes upgrade the join to a stronger cipher than the AES-128 CCM* used elsewhere in the network.
CInstall codes remove the shared network key, giving every device its own key for all mesh traffic.
DInstall codes let a device compute the network key locally, so it is never transmitted over the air.
Show answer

Answer: A A default global link key is public; install codes derive unique per-device link keys for safer network-key transport.

iotclass.org

Retrieval practice

Recall check 4 of 6

Radio Remi says: answer from memory, then check your reasoning.

Q4What attack does the monotonically increasing frame counter on each secured Zigbee frame primarily defeat?

AReplay attacks, because a captured frame re-sent later has a counter that is not greater than the last accepted.
BBrute-force key recovery, because each frame counter adds entropy that strengthens the AES-128 key.
CRadio jamming, because the counter lets receivers filter out the attacker's channel noise.
DAddress-table exhaustion, because tracking a sender’s frame sequence helps detect repeated traffic that could consume receiver state.
Show answer

Answer: A Monotonic frame counters reject replayed secured frames; resets and rollover need operational retest or key action.

iotclass.org

Retrieval practice

Recall check 5 of 6

Radio Remi says: answer from memory, then check your reasoning.

Q5A Zigbee gateway shows that a new sensor joined successfully, but the review record does not show the expected device identity, the authorization method, or whether joining was closed afterward. What is the strongest review decision?

AApprove the join, because a successful join proves the Trust Center authorized the expected device under policy.
BApprove the join once the sensor starts sending normal telemetry, since working data flow confirms that a legitimate device joined.
CRequire revision or retest before approval, recording expected-device evidence, authorization method, and join-policy closure.
DReject the site's Zigbee security claim outright, because one incomplete join record invalidates the deployment.
Show answer

Answer: C Join review approves only the authorization and policy behavior that the evidence supports — with the owner and retest trigger recorded.

iotclass.org

Retrieval practice

Recall check 6 of 6

Radio Remi says: answer from memory, then check your reasoning.

Q6A Zigbee deployment record names the Trust Center and shows encrypted traffic, but it does not document key custody, coordinator backup access, device removal behavior, or retest after gateway restore. What should the reviewer do?

AApprove the deployment, because observed encrypted traffic demonstrates that the whole security architecture works end to end.
BRequire revision or retest before approval, focusing on key custody, backup access, removal behavior, and restore evidence.
CApprove after confirming a common vendor and firmware baseline, because that simplifies the key-management and restore procedures to review.
DRemove coordinator backups before approval, because reducing stored copies of network keys lowers the chance of exposure.
Show answer

Answer: B Security readiness needs evidence for both cryptographic behavior and operational custody, plus a named owner and retest trigger.

iotclass.org

Print reference

Answers 1 of 2

Answer key.

  1. A · A Zigbee network is reviewable only when join path, key custody, removal behavior, and retests are evidenced, not just naming encryption.
  2. A · Network key means PAN-wide NWK security; link key means pairwise or legacy global APS security, including join-time network-key transport.
  3. A · A default global link key is public; install codes derive unique per-device link keys for safer network-key transport.
  4. A · Monotonic frame counters reject replayed secured frames; resets and rollover need operational retest or key action.
iotclass.org

Print reference

Answers 2 of 2

Answer key.

  1. C · Join review approves only the authorization and policy behavior that the evidence supports — with the owner and retest trigger recorded.
  2. B · Security readiness needs evidence for both cryptographic behavior and operational custody, plus a named owner and retest trigger.
iotclass.org