Zigbee, Thread & Matter · Study deck
Zigbee Security
Imagine a new lamp asking to join a building network.
Radio Remi is your guide for this deck.

After studying this chapter
Learning objectives
You will be able to:
- Explain: A single shared network key means one key exposure can affect the whole mesh, so the join step and key-custody record deserve direct evidence rather than a generic "encrypted network" note.
- Explain: Trust Center custody evidence records who owns the coordinator or Trust Center role, how configuration is backed up, who can change join policy, and how replacement is approved.
- Explain: The reviewer should be able to name the Trust Center, identify the link key or credential that protected each join, and explain who controls the shared network key.
- Explain: Lost devices lose trust.
Major section
In 60 Seconds
The safe question is not just whether it can join.
- The question is who approved it, which key it received, and how the owner can remove it later.
- Zigbee is a low-power mesh radio system.
- A protocol is an agreed set of rules for how devices exchange data.
- Encryption alone does not prove safe operation.
Major section
In 60 Seconds (continued)
A gateway is the boundary device or service that links the mesh to another network.
- Practitioner records join, custody, removal, exceptions, and retest.
- Those details may tighten the first claim.
- They never turn a working join into proof that every later command is allowed.
- Lost devices lose trust.
Major section
In 60 Seconds (continued)
A network is not secure because it names encryption or has a Trust Center.
- A changed owner starts a new review.
- Zigbee security review asks whether joining, key transport, traffic protection, replay handling, and operations custody are proven for the deployment boundary.
- This chapter keeps the focus on evidence.
Major section
Evidence Families
Trust Center custody evidence records who owns the coordinator or Trust Center role, how configuration is backed up, who can change join policy, and how replacement is approved.
- Key transport evidence records how the network key reaches a joining device and whether the join method depends on a shared default assumption or a device-specific credential.
- Network-key custody evidence records where the shared network key is stored, who can access it, how backup is protected, and what happens after suspected exposure.
- Application-security evidence records whether sensitive commands need pairwise or application-layer protection beyond mesh-layer encryption.
Major section
Key Transport and Key Custody
Zigbee deployments commonly depend on a shared network key for mesh-layer protection.
- The security review asks how that key was delivered, stored, backed up, and protected from unauthorized use.
- The most important APS use is join-time network-key transport from the Trust Center to a newly authorized device.
- That split makes the review sharper.
Major section
Key Transport and Key Custody (continued)
The reviewer should be able to name the Trust Center, identify the link key or credential that protected each join, and explain who controls the shared network key.
- A single shared network key means one key exposure can affect the whole mesh, so the join step and key-custody record deserve direct evidence rather than a generic "encrypted network" note.
- The purpose is to separate an encrypted radio frame from the stronger claim that the right device joined, under an owned policy, for an approved application action.
- Two approaches protect that transport very differently.
Major section
Key Transport and Key Custody (continued)
The progression is the chapter's security argument in compact form: cryptography protects traffic, while identity, custody, application scope, and lifecycle evidence determine what that protection actually proves.
- Second, do not treat a successful join as proof that the correct device joined for the correct reason.
- The legacy method uses a well-known default global link key, the ZigBeeAlliance09 value.
- Because it is public, anyone who sniffs a join secured only by that default can recover the network key and, with it, the whole mesh.
Major section
Frame Counter and Replay Review
Frame counters and message freshness checks help reject replayed traffic, but they still need review at lifecycle boundaries.
- Every secured Zigbee frame carries a monotonically increasing frame counter.
- A receiver rejects a secured frame when its counter is not greater than the last counter accepted from that sender.
- If devices stop being accepted after a power cycle, suspect frame-counter state before assuming the keys are wrong.
Major section
Green Power and Constrained Device Boundaries
Some Zigbee deployments include constrained or energy-harvesting devices that use simplified security behavior.
- The review question is not whether those devices are "secure enough" in general.
- The question is whether their limits are acceptable for the specific action they trigger.
- Green Power serves ultra-constrained, energy-harvesting devices, such as a battery-less light switch, that cannot run the full Zigbee stack.
Major section
Security Review Record
Traffic Boundary then states what mesh protection and replay evidence cover.
- Decision narrows, revises, rejects, or accepts the claim with an owner and retest trigger.
- That order carries protocol behaviour into accountable approval without hiding a lifecycle gap.
Major section
Concept Relationships
Trust Center and join policy: the Trust Center controls who can join, while the review record proves whether the approved join policy was followed.
- Network key and application boundary: mesh-layer protection can protect network traffic, but high-impact application actions may need additional evidence.
- Frame counters and lifecycle events: replay assumptions need retest after reset, rejoin, replacement, restore, or firmware changes.
- Backup and operations: coordinator recovery is useful only when backup access, restore behavior, and ownership are controlled.
Deck summary
Key takeaways
The safe question is not just whether it can join.
- A gateway is the boundary device or service that links the mesh to another network.
- A network is not secure because it names encryption or has a Trust Center.
- Trust Center custody evidence records who owns the coordinator or Trust Center role, how configuration is backed up, who can change join policy, and how replacement is approved.
- Zigbee deployments commonly depend on a shared network key for mesh-layer protection.
Retrieval practice
Recall check 1 of 6

Radio Remi says: answer from memory, then check your reasoning.
Q1Why is 'we have a Trust Center and encryption' not enough to call a Zigbee network secure?
Show answer
Answer: A A Zigbee network is reviewable only when join path, key custody, removal behavior, and retests are evidenced, not just naming encryption.
Retrieval practice
Recall check 2 of 6

Radio Remi says: answer from memory, then check your reasoning.
Q2What is the difference between the Zigbee network key and a link key?
Show answer
Answer: A Network key means PAN-wide NWK security; link key means pairwise or legacy global APS security, including join-time network-key transport.
Retrieval practice
Recall check 3 of 6

Radio Remi says: answer from memory, then check your reasoning.
Q3Why does install-code-based joining protect a Zigbee network better than the default global link key?
Show answer
Answer: A A default global link key is public; install codes derive unique per-device link keys for safer network-key transport.
Retrieval practice
Recall check 4 of 6

Radio Remi says: answer from memory, then check your reasoning.
Q4What attack does the monotonically increasing frame counter on each secured Zigbee frame primarily defeat?
Show answer
Answer: A Monotonic frame counters reject replayed secured frames; resets and rollover need operational retest or key action.
Retrieval practice
Recall check 5 of 6

Radio Remi says: answer from memory, then check your reasoning.
Q5A Zigbee gateway shows that a new sensor joined successfully, but the review record does not show the expected device identity, the authorization method, or whether joining was closed afterward. What is the strongest review decision?
Show answer
Answer: C Join review approves only the authorization and policy behavior that the evidence supports — with the owner and retest trigger recorded.
Retrieval practice
Recall check 6 of 6

Radio Remi says: answer from memory, then check your reasoning.
Q6A Zigbee deployment record names the Trust Center and shows encrypted traffic, but it does not document key custody, coordinator backup access, device removal behavior, or retest after gateway restore. What should the reviewer do?
Show answer
Answer: B Security readiness needs evidence for both cryptographic behavior and operational custody, plus a named owner and retest trigger.
Print reference
Answers 1 of 2
Answer key.
- A · A Zigbee network is reviewable only when join path, key custody, removal behavior, and retests are evidenced, not just naming encryption.
- A · Network key means PAN-wide NWK security; link key means pairwise or legacy global APS security, including join-time network-key transport.
- A · A default global link key is public; install codes derive unique per-device link keys for safer network-key transport.
- A · Monotonic frame counters reject replayed secured frames; resets and rollover need operational retest or key action.
Print reference
Answers 2 of 2
Answer key.
- C · Join review approves only the authorization and policy behavior that the evidence supports — with the owner and retest trigger recorded.
- B · Security readiness needs evidence for both cryptographic behavior and operational custody, plus a named owner and retest trigger.