1. Introduction
The rapid digital transformation of the energy sector [
1] is reshaping the foundations, operations, and future trajectories of electrical systems worldwide. Traditional power infrastructures, once characterized by centralized generation, unidirectional flows, and limited observability, are increasingly giving way to a new paradigm defined by connectivity, automation, distributed intelligence, and pervasive sensing. At the heart of this shift lies the Internet of Things (IoT), a technological ecosystem enabling seamless interaction between physical electrical assets and digital systems [
2]. Networks of interconnected sensors, actuators, gateways, and intelligent platforms empower these systems to gather high-resolution data, interpret dynamic conditions, and respond autonomously to real-time events—overcoming the rigidity and inefficiencies of legacy infrastructures. This omnidirectional sensing ushers in a new era for smart grids, where heterogeneous sensor networks deliver comprehensive, real-time visibility across the energy infrastructure. Vibration and temperature sensors on electric motors, for instance, enable predictive maintenance by spotting early bearing wear or imbalance via spectral vibration analysis, averting costly downtime [
3]. Likewise, current leakage detectors, overload monitors, and thermal imaging tools provide vigilant oversight of hazards like ground faults, phase imbalances, short circuits, and overheating—triggering alarms and automated responses such as circuit breaker activation or load shedding to prevent fires, shocks, or cascading failures [
4]. This sensor-driven intelligence bolsters reliability while enabling proactive grid stewardship in IoT deployments.
This evolution toward IoT-based smart electrical systems stems from the mounting complexity of the energy landscape and the pressing need to weave in renewables, electrified mobility, storage, and demand-side flexibility. As decarbonization and resilience goals intensify, must embrace unprecedented decentralization and variability. Photovoltaic arrays, electric vehicles, home automation, industrial controls, building management, and advanced metering now fringe the grid [
5], bringing fresh capabilities alongside novel challenges [
6]. IoT serves as the vital substrate, harmonizing these elements through real-time monitoring, distributed control, and data-driven optimization across the energy value chain.
IoT adoption has since transcended early smart-home pilots permeating residential, commercial, industrial, and utility-scale realms [
7]. Smart homes harness interconnected devices for optimized consumption and comfort; smart buildings deploy sensor networks and predictive controls to cut costs and emissions [
8]. Industry 4.0/5.0 embeds IoT sensing into production for enhanced efficiency and sustainability. At grid level, IoT powers Smart Grids with bidirectional flows, adaptive control, and synergy among distributed resources [
9]. With billions of devices set to anchor electrical infrastructures, IoT stands as indispensable to sustainable, intelligent energy futures. This progression has unfolded temporally and geographically: the 1990s pioneered ICT remote monitoring, the 2000s birthed Smart Grids for DER integration, and post-2010 saw full-scale IoT/AI deployment—via regulatory frameworks in Europe/USA and ubiquitous sensors/UHV tech in Japan/China. A recent exemplar from the state of the art underscores how IoT convergence in critical systems amplifies cybersecurity risks, calling for sophisticated data-driven defenses. In autonomous vehicles, ML classifiers (KNN, XGBoost) tuned by modified PSO achieve over 89% accuracy in detecting CAN intrusions [
10]; similarly, hybrid deep models (CNN-DBN, Bi-LSTM-GRU) optimized via novel metaheuristics boost intrusion detection across IoT cyberattacks [
11]. Yet despite its promise, IoT integration into electrical systems poses pressing challenges. Device, platform, and protocol proliferation breeds interoperability hurdles, especially where IT meets entrenched OT standards—demanding middleware to bridge data formats and paradigms, lest deployments fragment into inefficiency.
No less urgent are security imperatives amid the expanding IoT attack surface. Resource-constrained devices struggle with robust cryptography, exposing them to eavesdropping, man-in-the-middle, DoS, botnets, and disruptive intrusions that imperil energy operations [
12]. As infrastructures digitize, safeguarding confidentiality, integrity, authenticity, and availability proves vital for reliability and public safety—yet nonuniform mechanisms across IoT technologies demand tailored, rigorous analysis for electrical contexts. Existing surveys on IoT-based smart electrical systems, while valuable, examine key dimensions—architectural models, communication protocols, standards, cybersecurity/privacy, data processing paradigms (edge/fog/cloud), energy management, and applications—in fragmented silos, obscuring cross-disciplinary optimization pathways. For instance, reviews focused on security [
5] or protocols [
13] neglect architectural shifts and interoperability, while energy-centric works [
14] overlook holistic IT/OT convergence. Quantitative analyses reveal that over 80% of recent surveys (2020–2025) address fewer than four dimensions, limiting their guidance for integrated deployments. This survey addresses these gaps through a systematic literature review detailed in
Section 2. Unlike prior narrative reviews, we introduce novel cross-layer taxonomies (e.g., linking edge latency reductions to OT protocol mappings and cybersecurity mitigations) that reveal previously underexplored synergies, such as unified V2G/EMS frameworks for real-world IoT ecosystems.
Section 9 quantifies our holistic scope against fragmented predecessors, positioning this work as the first comprehensive roadmap for practitioners and researchers navigating smart electrical transformations. This survey delivers exactly that across nine sections: state-of-the-art review (
Section 3, grounded in
Section 2’s PRISMA workflow), IoT-based Smart Electrical Systems (
Section 4), standards/protocols (
Section 5), technologies/interoperability (
Section 6), energy strategies (
Section 7), use cases (
Section 8), security (
Section 9), and findings/future directions (
Section 10)—weaving disparate threads previously siloed, unlike conventional reviews.
2. Research Methodology
To ensure a rigorous and comprehensive analysis of the state-of-the-art, this survey was conducted following a systematic literature review approach. The methodology employed for article selection and analysis is detailed below.
2.1. Database and Search Strategy
The systematic literature search and review process was conducted over a period of more than six months. The primary indexing engine utilized for this study was Google Scholar, chosen for its extensive coverage of academic literature across multiple disciplines. This allowed for the retrieval of documents from major authoritative repositories, including MDPI, IEEE Xplore and ScienceDirect, as well as other relevant academic sources.
The search strategy relied on a combination of keywords aimed at covering the intersection of Internet of Things (IoT) technologies and electrical power systems. The search strings were constructed using Boolean operators (AND, OR) to combine the following core terms:
Core Domains: “Internet of Things” (IoT), “Smart Grid”, “Internet of Energy” (IoE), “Smart Electrical Systems”;
Enabling Technologies & Protocols: “Communication Protocols”, “Networks”, “5G/6G”, “Edge Computing”, “Cloud Computing”;
Applications & Management: “Smart Home”, “Smart Building”, “Energy Storage Systems”, “Energy Optimization”, “Energy Management Systems” (EMS), “Demand Response”;
Cross-cutting Issues: “Cyber Security”, “Privacy”, “Data Protection”, “Interoperability”, “Blockchain”.
2.2. Inclusion and Exclusion Criteria
To ensure the relevance and currency of the survey, the screening process was guided by the following criteria:
Language: only full-text articles written in English were considered.
Timeframe: a specific preference was given to articles published in the last 5 years (2020–2025) to capture the most recent technological advancements. However, foundational works and highly cited papers from the last 10 years (2015–2025) were also included to provide necessary context and theoretical background.
Source Reliability: priority was assigned to peer-reviewed journals and conference proceedings from recognized publishers (e.g., MDPI, IEEE, ScienceDirect). Grey literature and non-indexed sources were largely excluded unless representing official technical standards.
2.3. Selection Process (PRISMA)
The selection workflow adhered to the Preferred Reporting Items for Systematic Reviews and Meta-Analyses (PRISMA) guidelines. As illustrated in
Figure 1, the initial search yielded about 1200 records. After removing duplicates and screening titles and abstracts for relevance, 900 records were retained for closer inspection. A substantial number (750) were excluded at this stage due to being outside the scope (e.g., purely theoretical IoT without grid application) or outside the selected timeframe.
Subsequently, 150 full-text articles were assessed for eligibility. During this phase, 50 articles were excluded primarily due to insufficient technical depth, lack of peer review, or a generic focus on IoT not specific to electrical systems. This rigorous filtering process resulted in a final core set of 100 high-quality studies that form the basis of this survey.
3. State of the Art
Drawing from the systematic literature review outlined in
Section 2—which screened about 1200 records—this section synthesizes emergent trends in IoT-based smart electrical systems. Key findings reveal persistent silos in prior work: architectural shifts (e.g., edge computing), IT/OT interoperability challenges (e.g., middleware mapping ), and cybersecurity vulnerabilities (e.g., DDoS in expanded attack surfaces). These gaps underscore the need for a holistic, cross-dimensional analysis. The evolution of electrical systems represents a fundamental paradigm shift that has unfolded through distinct historical phases, marking the transition from traditional power grids to Smart Grids and, more recently, towards the Internet of Energy (IoE).
While the 1990s marked the first step towards automation with the introduction of ICT-based remote monitoring systems, the early 21st century saw the emergence of the Smart Grid concept, driven by the urgent need to integrate Distributed Energy Resources (DERs) to meet decarbonization goals. Since 2010, the sector has entered a new phase of “full deployment,” characterized by the deep integration of the Internet of Things (IoT), Big Data, and Artificial Intelligence. This transition has been geographically diversified: while Europe and the United States focused on regulatory frameworks for renewable integration and demand response markets, countries like Japan and China prioritized the deployment of ubiquitous smart sensors and Ultra-High Voltage (UHV) technologies [
15].
As illustrated in
Figure 2, this trajectory underscores the transition from a centralized model to a distributed and interconnected one. Traditionally, the electrical grid was characterized by a centralized and unidirectional structure. It was designed primarily to transmit energy from large power plants to end consumers, with limited real-time monitoring capabilities and minimal integration of renewable sources [
16]. However, the growing demand for energy, the need to reduce carbon emissions, and the integration of Distributed Energy Resources (DER) have necessitated the modernization of the infrastructure. The embedding of the Internet of Things (IoT) into power grids has transformed conventional infrastructures into Smart Grids, significantly improving efficiency, reliability, and sustainability through bidirectional monitoring and control [
5]. A crucial aspect of this evolution concerns the data processing architecture. While early Smart Grid implementations relied heavily on Cloud Computing for data analysis, the vast volume of data generated by IoT devices and the need for low latency have exposed the limitations of a purely centralized approach [
17].
Why is a shift from centralized Cloud to distributed Edge computing necessary? The primary driver is the need to handle the massive volume of data with the low latency required for grid stability.
Consequently, the architecture is shifting towards Edge and Fog Computing models. This decentralized approach allows data to be processed closer to the source (sensors and field devices), reducing latency and bandwidth consumption, and improving system resilience against network interruptions [
18].
Traditional cloud-centric Smart Grid models, prevalent in pre-2020 literature, face scalability limits due to IoT-generated data volumes exceeding 10 TB daily in urban grids, necessitating low-latency processing. Recent studies advocate edge/fog paradigms, reporting latency reductions of up to 50% in real-time fault detection [
19]. However, quantitative benchmarks remain sparse, with peer-reviewed validations limited to simulations rather than field deployments. This transition aligns with standards like IEC 61850 [
20], yet integration with lightweight IoT protocols demands further empirical scrutiny.
Regarding the interoperability challenges and IT/OT gaps, legacy OT protocols (e.g., DNP3, IEC 61850) prioritize real-time determinism, clashing with IT/IoT standards like MQTT, which favor flexibility but introduce overhead [
13]. Middleware and gateways offer mapping solutions (e.g., IEC 61850 to JSON/MQTT), enabling bidirectional flows in AMI/DSM; nonetheless, surveys indicate fragmented adoption, with <30% of studies addressing cross-layer validation. Authoritative frameworks such as NIST SP 800-213 highlight unresolved semantic mismatches, amplifying deployment inefficiencies [
20]. Moreover, concerning the security landscape, IoT proliferation expands the Smart Grid attack surface, with documented rises in DDoS, false data injection (FDI), and device tampering [
21]. Peer-reviewed analyses report detection accuracies >89% via ML hybrids (e.g., CNN-BiLSTM), but energy-constrained nodes limit cryptographic feasibility [
22]. Unlike siloed security reviews, holistic integration of physical-cyber defenses from design phases remains underexplored, per NIST guidelines.
Existing surveys on IoT-based smart electrical systems remain fragmented, addressing dimensions in isolation rather than through integrated frameworks—a limitation evident across recent peer-reviewed works. For instance, while refs. [
5,
22] offer valuable insights into cybersecurity and applications, they overlook architectures, protocols, and energy management, reducing their utility for cross-disciplinary deployments. Similarly, ref. [
13] excels in protocol-interoperability analysis but neglects security and application contexts, while ref. [
14] covers architectures and energy strategies yet ignores standards and holistic IT/OT convergence.
In contrast, this survey synthesizes nine interconnected dimensions—architectural models, communication protocols, reference standards, cybersecurity/privacy, data processing paradigms (edge/fog/cloud), energy management strategies, application scenarios, interoperability solutions, and future directions—via novel cross-layer taxonomies that explicitly link, for example, edge computing latencies to OT protocol mappings and security mitigations. Unlike prior works confined to silos (e.g., security-only in or protocol-focused in), our approach reveals optimization pathways obscured by fragmentation, such as unified V2G/EMS frameworks absent in 80% of reviewed studies. This comprehensive positioning equips researchers and practitioners with actionable intelligence for real-world IoT-driven electrical ecosystems.
5. Communication Standards and Protocols
In IoT systems, the balance between consumption, coverage, latency, and reliability is largely determined by the choice of communication protocol, which operates across the three-level architecture: the perception layer, including sensors and actuators for data collection; the transmission layer, responsible for data transfer via appropriate protocols and channels; and the application layer, which processes and delivers the data to users. In the specific context of the smart grid, this architecture facilitates the bidirectional flow of information necessary for Advanced Metering Infrastructure (AMI) and Demand Side Management (DSM), connecting power generation, distribution, and consumption points. Specifically for smart electrical systems, the perception layer handles the precise measurement of electrical parameters, while the transmission layer must ensure that critical grid events, such as sudden voltage drops or equipment failures, are communicated with minimal delay to prevent cascading effects [
28].
In the network layer, it is possible to distinguish short-range protocols such as Wi-Fi, Bluetooth, Zigbee, and Z-Wave, characterized by limited range but lower power consumption; and long-range protocols such as LoRaWAN, SigFox, and NB-IoT, which provide extended coverage up to kilometers while maintaining low energy demand. The former are therefore more suitable for domestic and industrial contexts, while the latter provide effective solutions for scenarios where device longevity and network scalability are important requirements [
29].
5.1. Short-Range Standards
The choice of the short-range standard depends on the balance between consumption, network capacity, and application requirements.
Wi-Fi (IEEE 802.11) is the most widely used technology, characterized by high throughput and direct IP connectivity. Given its high consumption (100–350 mA according to [
30]), it is suitable for applications requiring continuous power supply [
31]. In a smart grid context, its high data rate capability makes it suitable for specific applications such as linking smart meters to in-home displays or facilitating video monitoring in substations where power is readily available. Furthermore, it is leveraged for Home Energy Management Systems (HEMS) that require high-frequency sampling of power quality data.
ZigBee (IEEE 802.15.4) is optimized for low-power and low-data-rate communication and is widely used in IoT scenarios due to its scalability and support for large mesh networks. This technology is dominant in home area networks (HAN) of smart grids due to its ability to integrate with monitoring and home control systems. A key advantage for electrical systems is its ability to create self-healing mesh networks, which ensures that even if one smart appliance or meter fails, the energy consumption data can still reach the central gateway through alternative nodes [
32]. ZigBee is particularly effective for monitoring individual appliances and implementing demand response programs to reduce peak load.
Bluetooth (IEEE 802.15.1), particularly in the Low Energy (BLE) version, represents an intermediate option for personal and wearable devices. In a smart home environment, it enables the user to connect mobile devices to energy controllers for local monitoring of consumption data without requiring a complex network infrastructure [
28].
Z-Wave, operating in sub-GHz bands, provides a stable signal and low latency with greater signal penetration and reduced interference compared to the 2.4 GHz bands [
30]. For residential energy management, Z-Wave offers the advantage of not interfering with existing Wi-Fi networks while enabling reliable remote control of smart plugs and lighting, which is essential for automated energy-saving routines.
Table 2 compares the technical characteristics among the standards presented.
5.2. Long-Range Standards
Long-range technologies represent a fundamental solution for large-scale, low-power applications. These technologies support the Neighborhood Area Network (NAN), aggregating data from multiple smart meters to data collection points for transmission to the utility. According to [
28], approximately 86% of IoT devices connect using three LPWAN technologies: LoRaWAN, NB-IoT, and Sigfox.
Table 3 compares the technical characteristics among the long-range standards presented.
From an energy efficiency perspective, Sigfox is often reported as the most power-efficient LPWAN technology, followed by LoRaWAN, whereas NB-IoT tends to be less energy-efficient due to its reliance on cellular infrastructure and more complex signaling procedures [
31]. However, experimental data shows that while Sigfox is extremely energy-efficient, it can suffer from packet loss in dense urban environments due to its ultra-narrowband nature, which could be problematic for real-time grid monitoring [
33].
Among LPWAN technologies, LoRaWAN is frequently evaluated for smart grid communications because of its scalability, energy efficiency, and extended coverage [
28,
31]. Specific applications, such as outage detection or management, are typically studied at the network or AMI level rather than being protocol-specific [
28]. Conversely, NB-IoT is based on licensed frequencies and ensures greater reliability [
28,
31], making it highly suitable for utility metering in dense urban environments where interference is a major concern [
34].
Table 3.
Comparison of Long-Range Technologies for Smart Metering.
Table 3.
Comparison of Long-Range Technologies for Smart Metering.
| Standard | Energy Efficiency | Latency | Reliability in Smart Grids |
|---|
| LoRaWAN | Ultra-low consumption [30,31] | NAN-compliant (1–15 s) [28] | High interference robustness (CSS modulation) [31,34] |
| NB-IoT | Coverage-dependent efficiency [31] | Fast response, near real-time [28,31] | Carrier-grade reliability (licensed spectrum) [31] |
| Sigfox | IoT energy benchmark [31] | Optimized for periodic, non-critical transmissions [28,31] | Congestion-sensitive in dense urban areas [34] |
5.3. Application Layer Protocols
Application layer protocols manage IoT device communication, directly influencing efficiency. Message Queuing Telemetry Transport (MQTT) is a TCP-based publish/subscribe protocol designed for remote monitoring over fragile networks. In a smart grid scenario, smart meters act as publishers sending consumption data to the broker, which then routes information to utility billing systems [
35]. MQTT’s Quality of Service (QoS) levels are essential for control commands (e.g., disconnecting a load), where losing a packet is not an option [
36].
In contrast, the Constrained Application Protocol (CoAP) is a UDP-based protocol designed to reduce overhead and energy consumption [
36]. Technical evaluations show that CoAP reduces significantly the communication overhead compared to HTTP, allowing utilities to collect more frequent data points without draining the batteries of remote sensors.
From an energy perspective, transport is crucial: TCP (used by MQTT) requires persistent connections and delivery acknowledgments, increasing consumption. UDP (used by CoAP) allows lighter communications. However, security implementation remains a challenge; studies indicate that encryption (TLS for MQTT or DTLS for CoAP) can increase energy consumption, a factor that grid operators must consider when planning the 10–15 year lifecycle of smart meters.
In the case of MQTT-SN (the UDP-based version), clients can enter “sleep” mode, enabling significant energy savings. Total consumption between MQTT-SN and CoAP is very similar, with MQTT-SN being slightly more efficient due to lower client complexity [
35]. Ultimately, the integration of these protocols enables the transition to smart grids, supporting advanced functions like outage management, fraud detection, and the integration of distributed renewable energy resources.
The technical specifications and the differences between these solutions are summarized in
Table 4.
After discussing short-range, long-range, and application-layer communication protocols, it is useful to summarize their characteristics in a single comparative overview.
Table 5 presents a synthesis of the key protocols, highlighting their trade-offs in energy efficiency, latency, and typical use cases in Smart Electrical Systems. This allows for a quick comparison and aids in selecting the most suitable protocol for specific IoT applications.
6. Technologies, Platforms, and Interoperability
The IoT ecosystem for energy management and building automation relies on a diverse array of platforms, protocols, and standards that facilitate integration and communication among heterogeneous devices [
37,
38]. These platforms constitute the critical infrastructure for Smart Homes, Smart Buildings, and Smart Grids, providing essential tools for consumption monitoring, automated management, and data security. Two primary architectural paradigms can be distinguished: commercial platforms, prioritizing high usability and vertical integration, and open-source or DIY (Do-It-Yourself) platforms, which emphasize flexibility, interoperability, and local data sovereignty. A taxonomy of these ecosystems, categorized by their architectural approach and target user base, is illustrated in
Figure 5.
6.1. Commercial Platforms
Commercial IoT platforms currently dominate the market for smart device integration in both residential and professional settings. Predominantly cloud-centric, these architectures prioritize user experience by offering “turnkey” environments where sensors, actuators, and digital services operate cohesively. Current market solutions fall into two distinct categories: general-purpose consumer ecosystems and specialized platforms for advanced automation and energy control. The first group includes widely adopted ecosystems such as Apple (HomeKit), Amazon (Alexa), Google (Home), and Samsung (SmartThings).
Functioning as centralized hubs, these systems enable device management via mobile applications or voice assistants. Their primary advantage lies in deep cloud service integration and the capability to execute automated routines that optimize comfort, safety, and energy efficiency [
39]. However, from a research perspective, these ecosystems can operate effectively as ’black boxes.’ They often restrict direct access to raw, granular sensor data, which may constrain their applicability in scenarios requiring precise demand-response mechanisms.
Despite their prevalence, these platforms face inherent structural constraints. Since device coordination occurs primarily on remote servers, they introduce challenges related to privacy, latency, and operational resilience, alongside the risk of vendor lock-in. While this closed model ensures stability, it limits the integration of third-party devices. Beyond consumer-grade solutions, the market includes professional platforms tailored for installers and advanced users. Solutions such as Shelly, Control4, Crestron, HomeSeer, Hubitat, Hornbach Smart Home, Cozify, Symcon, and Telldus offer a modular, configurable approach, frequently targeting HVAC, lighting, and energy control. Many of these systems support multiple communication protocols—including Zigbee, Z-Wave, Thread, Wi-Fi, and Bluetooth Low Energy (BLE)—and allow integration with third-party systems through APIs or dedicated gateways. While generally offering superior stability, their architectural structure can present challenges regarding scalability. The complexity of retrofitting and a tendency toward rigid configurations may render them comparatively less adaptable to the dynamic requirements of emerging Smart Grid standards.
In recent years, regional and multi-platform ecosystems such as a wide range of proprietary and vertical ecosystems has emerged, including Tuya Smart, Aqara Home, Bosch Smart Home, Philips Hue, Netatmo, Hive Home, Eve Systems, and IKEA Dirigera. These solutions are characterized by the adoption of interoperable protocols (Zigbee, Thread, Matter) and an increasing focus on energy efficiency and data security. The introduction of the Matter protocol has represented a major step forward toward the standardization of interoperability among heterogeneous ecosystems. Matter, together with the Thread network technology, enables secure and local communication between devices from different manufacturers (Apple, Google, Amazon, Samsung, IKEA), reducing market fragmentation and simplifying the user experience [
40].
6.2. Open-Source and DIY Platforms
Conversely, open-source and DIY (Do-It-Yourself) platforms offer a flexible alternative for managing IoT systems. Driven by collaborative developer communities and open architectures, these solutions empower users to integrate multi-vendor devices and design highly personalized automations. Prominent platforms include Home Assistant, OpenHAB, Homey, Domoticz, ioBroker, Node-RED, Nymea, Homebridge, and ESPHome, which enable the creation of interoperable ecosystems based on open protocols such as MQTT, REST API, Modbus TCP, and CoAP [
41].
A particularly notable example is Home Assistant, which allows local device management, energy monitoring, and the creation of complex automation scenarios through graphical interfaces or scripting. Similarly, OpenHAB and ioBroker offer modular architectures based on extensible components, facilitating the integration of Zigbee, Wi-Fi, and Modbus systems. Node-RED, developed by IBM, represents a low-code solution for automation flow creation, making it accessible even to non-expert users.
More recent open-source platforms adopt edge or fog-based architectures, moving part of the data processing closer to the devices to reduce latency, increase resilience, and improve privacy by design. This decentralized model allows greater data control and reduces dependency on cloud infrastructures, enhancing local interoperability and responsiveness in heterogeneous IoT environments [
38]. A detailed synthesis of these architectural approaches, highlighting the key differences in interoperability and operational trade-offs between commercial and open-source models, is provided in
Table 6.
At the research level, European initiatives such as INTER-IoT have proposed multi-layer interoperability frameworks—physical, syntactic, semantic, and organizational—to connect heterogeneous platforms in industrial and civil scenarios [
42]. These frameworks represent a key step toward achieving technical convergence among diverse ecosystems and realizing a truly unified IoT infrastructure.
6.3. Strategies for Interoperability and Large-Scale Integration
To overcome interoperability limitations and enable large-scale IoT deployments across heterogeneous devices and vendors, compatibility must be addressed at multiple architectural levels. Rather than relying on a single technological choice, effective interoperability emerges from the coordinated adoption of communication standards, abstraction mechanisms, semantic alignment, and ecosystem-level governance.
Adoption of Standardized Communication Protocols.
The adoption of standardized communication protocols represents the first and most fundamental step toward reducing system integration complexity. Widely accepted protocols such as MQTT, CoAP, RESTful APIs, OPC UA, and AMQP provide common communication primitives that are independent of specific vendors or hardware implementations [
43]. By converging toward shared standards, heterogeneous devices can exchange data using well-defined interaction models, potentially reducing integration effort by promoting shared interaction patterns and vendor-independent interfaces, although the realized benefit depends on legacy constraints, data-model alignment, and deployment scale [
44]. In large-scale deployments, interoperability is further enhanced when manufacturers are encouraged to support at least one standardized protocol in parallel with proprietary solutions, or when protocol translation gateways are provided to ensure backward compatibility.
Middleware and Integration Platforms.
Middleware platforms play a central role in abstracting protocol heterogeneity by acting as intermediaries between devices and applications [
45]. Through message brokers, integration frameworks, or cloud-based IoT platforms, middleware solutions decouple device-level communication from application logic, enabling devices to operate using their native protocols while exposing normalized interfaces to higher layers. This architectural separation can reduce tight coupling and simplify system evolution, enabling large-scale deployments to integrate heterogeneous devices without requiring changes at the application level.
Data Format Standardization.
Beyond communication protocols, interoperability critically depends on the standardization of data representations. Even when devices successfully exchange messages, inconsistent data formats can hinder effective integration and interpretation. The adoption of common data serialization formats such as JSON, Protocol Buffers, Apache Avro, or XML enables consistent data parsing and processing across platforms [
46]. Defining canonical data models that capture shared semantics ensures that heterogeneous data sources can be interpreted uniformly, regardless of the originating device or protocol, thereby facilitating scalable analytics and control applications.
API Gateway Architecture.
API gateways provide a unifying architectural layer that consolidates access to heterogeneous IoT resources. By supporting protocol translation, data transformation, authentication, authorization, and rate limiting, API gateways can enable a consistent interaction model for applications operating over diverse device ecosystems [
47]. This approach allows backend services to remain agnostic to device-specific protocols while enforcing centralized security and lifecycle management policies. As systems evolve, API versioning mechanisms further support long-term compatibility without disrupting existing integrations.
Digital Twin Framework.
Digital twin frameworks address interoperability by introducing a virtual abstraction of physical devices. Each physical asset is represented by a standardized digital counterpart that exposes uniform interfaces and behaviors, regardless of the underlying hardware or communication protocol [
48]. Applications interact exclusively with digital twins rather than directly with devices, effectively isolating them from protocol heterogeneity. This abstraction not only simplifies integration but also enhances scalability, maintainability, and the ability to perform simulation, monitoring, and predictive analysis across large fleets of devices.
Edge Computing and Protocol Converters.
Edge computing architectures contribute to interoperability by localizing protocol conversion and data normalization close to the data source. Edge gateways collect information from devices using native protocols, translate it into standardized representations, and perform preprocessing before forwarding data to central systems [
44]. This approach can reduce latency and bandwidth usage and improve resilience, particularly in geographically distributed deployments. Moreover, edge-based interoperability enables continued operation under limited or intermittent connectivity conditions.
Semantic Interoperability.
While syntactic compatibility ensures that data can be exchanged, semantic interoperability ensures that data is correctly understood. Semantic frameworks based on shared ontologies, standardized vocabularies, and metadata models enable consistent interpretation of data meaning across heterogeneous systems [
48]. The use of schema registries and standardized units of measurement, timestamps, and naming conventions further reduces ambiguity. This semantic alignment is particularly critical in large-scale applications, where data from diverse sources must be aggregated and analyzed coherently.
Vendor Partnership and Certification Programs. Finally, interoperability at scale cannot be achieved solely through technical solutions but also requires organizational coordination. Vendor partnership and certification programs play a crucial role in fostering ecosystem-level compatibility by defining interoperability requirements, testing procedures, and compliance criteria. Certification schemes incentivize manufacturers to adopt common standards and provide assurance to system integrators regarding device compatibility. Industry consortiums and reference implementations further accelerate convergence toward interoperable solutions, reducing fragmentation and supporting sustainable large-scale adoption.
While several interoperability solutions are already mature and widely adopted at the protocol, middleware, and architectural levels, a fully uniform and seamless interoperability across heterogeneous IoT ecosystems remains challenging, particularly at scale. This limitation is not solely technical in nature, but also reflects the absence of a widely recognized and authoritative standardization body capable of coordinating and enforcing interoperability across multiple layers, including data models, semantics, and certification procedures. As a result, current solutions often remain fragmented, with partial standardization confined to specific domains, platforms, or vendor-driven ecosystems. Future research and industrial efforts should therefore focus not only on advancing semantic alignment and certification frameworks, but also on fostering stronger cross-industry governance mechanisms that can promote convergence toward truly interoperable, vendor-agnostic, and scalable IoT systems.
The above mentioned strategies summarized in
Table 7 outline a comprehensive approach to mitigating protocol fragmentation and facilitating scalable integration.
9. Security Challenges and Countermeasures
The Internet of Things ecosystem presents a complex landscape of security vulnerabilities that emerge across multiple architectural layers: at the perception layer, devices face threats from physical tampering and manipulation; the network layer is prone to routing attacks and interception, while the application layer struggles with authentication and data integrity challenges [
84]. In the specific context of Smart Grids (SG), these vulnerabilities are amplified by the critical nature of the infrastructure, where cyber-attacks can lead to physical damage, blackouts, or energy theft [
22].
9.1. Vulnerabilities and Threats
The diversity of IoT devices complicates security, since heterogeneity obstructs the adoption of unified protection strategies and creates weaknesses [
85]. To better understand the risks in smart electrical systems, it is essential to categorize attacks based on their target and impact within the SG architecture [
22]:
Attacks on Availability: Denial of Service (DoS) and Distributed Denial of Service (DDoS) represent critical risks. In a Smart Grid, these can target communication links between Smart Meters and the Control Center, preventing the transmission of critical data and causing grid instability [
22]. DDoS attacks are easy to deploy and particularly effective because IoT devices have limited computational and energy resources. From an energy perspective, there are ghost attacks on ZigBee nodes that deplete batteries without compromising security credentials, paving the way for subsequent DoS attempts. Closely linked are botnets, which exploit insecure devices to orchestrate large-scale disruptions. In healthcare environments, such events can have severe consequences [
84].
Attacks on Integrity: False Data Injection (FDI) attacks are specifically dangerous for electrical systems. Adversaries can manipulate meter readings or price signals, leading to incorrect state estimation by the grid operator and potentially causing physical overflows or financial fraud [
22].
Attacks on Confidentiality: Among common threats, eavesdropping remains one of the most fundamental. Since a large portion of IoT traffic remains unencrypted, attackers can intercept sensitive information. In particular, Palo Alto Networks reported in 2020 that up to 98% of overall IoT traffic was transmitted without encryption, exposing personal and confidential data on the Internet [
86]. In Smart Grids, this can reveal energy consumption patterns, compromising user privacy [
22]. Even with encryption, metadata leakage may reveal user behaviors; for instance, fitness trackers can disclose activity levels simply through traffic analysis [
87].
Another major risk is the Man-in-the-Middle (MitM) attack, which exploits weak authentication mechanisms and often goes undetected by existing intrusion detection systems [
85]. The cross-technology nature of IoT systems further increases the attack surface: WiFi devices can emulate ZigBee signals to launch effective protocol-based intrusions [
88]. The scale of the problem is amplified by the rapid growth of IoT infrastructures. Fereidouni et al. [
85] report that 16.6 billion IoT devices were connected globally in 2023, with forecasts suggesting that this number could exceed 40 billion by 2030.
Protocol-specific weaknesses also emerge. For example, in ZigBee, touchlink commissioning can be abused to reset devices and extract network keys. Bluetooth Low Energy (BLE) versions up to 4.1 rely on weak pairing, exposing them to eavesdropping and MitM attacks unless out-of-band pairing is used. In 6LoWPAN, routing exploits such as sinkhole attacks allow adversaries to manipulate large volumes of traffic [
87]. In SG environments, these routing attacks can isolate entire sections of the grid from the monitoring system [
22].
More sophisticated adversaries may resort to advanced persistent threats (APTs). MitM itself is often considered an APT due to its persistence [
85]. An illustrative example is the fingerprint and timing-based snooping (FATS) attack, described in [
89], where attackers infer user activities by analyzing encrypted smart home traffic patterns. Finally, several threats explicitly target energy availability. Battery depletion attacks accelerate energy loss; sleep deprivation attacks prevent low-power modes; and exhaustion attacks repeatedly drain network resources [
84].
9.2. Security Protocols and Countermeasures
Securing IoT communications requires robust mechanisms to ensure confidentiality, integrity, and authentication despite device limitations. For Smart Grids, the National Institute of Standards and Technology (NIST) framework suggests a multi-layered defense strategy:
Prevention: Use of robust encryption like AES and secure protocols (TLS/DTLS). To counter FDI attacks, message authentication codes (MAC) and digital signatures are vital for ensuring data source authenticity [
22].
Detection: Intrusion Detection Systems (IDS) must be adapted for SG traffic. Machine learning-based IDS are increasingly used to identify anomalies in energy consumption or communication flow that signal an ongoing attack [
22].
Mitigation and Recovery: Implementing automated response systems that can isolate compromised grid segments to prevent cascading failures [
22].
The alignment between security goals, the specific threats faced by smart grids, and the corresponding countermeasures defined in the NIST framework is summarized in
Table 11.
There are Virtual Private Networks (VPNs) and encryption frameworks such as TLS/SSL (and DTLS in constrained environments) that provide essential protections against interception and manipulation [
91]. However, performance and energy costs vary. WireGuard offers much lower latency (52.44 ms) than OpenVPN (827.93 ms), making it attractive for latency-sensitive deployments, though it still faces DoS risks [
90].
At the application layer, MQTT generally outperforms CoAP in energy-constrained scenarios. Several studies report that MQTT can achieve lower energy consumption and better reliability than CoAP in lossy network conditions, as well as higher efficiency during firmware update processes [
87].
Regarding encryption algorithms, AES-CCM8 has been observed to provide slightly better energy efficiency compared to other AES modes in IoT environments. Lightweight authentication mechanisms, such as asynchronous OTP combined with pre-shared keys, also exhibit significantly lower processing overhead than traditional security protocols such as DTLS with large key sizes.
Cryptographic choices further impact gateway performance. In particular, elliptic curve cryptography (ECC) has been shown to outperform RSA in terms of energy consumption and computational efficiency, making it especially suitable for resource-constrained IoT gateways. Consequently, ECC is often recommended for Smart Meter applications, where limited processing power restricts the feasibility of complex cryptographic operations [
22].
Finally, while TLS/DTLS remains central, their handshake procedures can be energy intensive. Pre-shared key (PSK) methods offer more efficient alternatives than certificate-based schemes, though elliptic-curve Diffie–Hellman (ECDHE) remains preferable when asymmetric security is unavoidable [
90].
9.3. Privacy and Data Protection
Privacy protection in IoT systems extends beyond technical safeguards to include legal compliance design. The Privacy by Design principle requires integrating data protection at the earliest stages, shaping both system architecture and energy usage [
92]. In smart electrical systems, privacy is a major concern as high-frequency meter data can reveal a resident’s daily routine, used appliances, and even socio-economic status [
22]. Compliance with regulations such as GDPR imposes technical and organizational measures that, while necessary, also increase computational and energy costs [
86].
Technical solutions include differential privacy, which introduces noise for statistical anonymity at moderate energy cost; homomorphic encryption, which enables computation on encrypted data but with high overhead; and secure multi-party computation [
93]. Furthermore, the use of blockchain technology is emerging as a solution for decentralized and tamper-proof energy trading, enhancing both security and privacy in peer-to-peer energy markets [
22]. Emerging quantum technologies could theoretically transform IoT privacy protection [
94], though their specialized hardware and energy requirements raise new concerns.
Privacy-preserving machine learning also represents a growing trend. Federated learning and secure aggregation allow model training without raw data exposure, but require additional computation and communication, increasing energy consumption. Recent approaches attempt to mitigate this by separating sensitive from non-sensitive data, applying heavier protections only where necessary with the aim to strike a balance between energy and privacy.
The reviewed sources shown in
Table 12 provide a robust foundation for IoT privacy discourse, yet exhibit notable complementarities and limitations when contextualized within SES. Achaal et al. [
22] and Anedda et al. [
86] offer the strongest SES-specific contributions, with the former delivering a systematic analysis of privacy breaches via high-frequency metering data and the latter operationalizing GDPR-compliant architectures with quantified energy overheads. However, their cybersecurity orientation often subsumes privacy under broader threat models, lacking granular treatment of Privacy by Design principles. Shahid et al. [
92] extends technical depth through differential privacy and homomorphic encryption analyses, but its healthcare provenance limits direct applicability to electrical metering profiles. Coiduras-Sanagustín et al. [
93] contributes valuable user-centric design perspectives via systematic literature review, though its qualitative nature and erroneous DOI necessitate caution. Sharma et al. [
94], while innovative in quantum-blockchain integration, remains exploratory, with immature technologies ill-suited for resource-constrained SES deployment. The corpus demonstrates source overlap on blockchain-enabled P2P energy trading and insufficient empirical benchmarking of privacy mechanisms’ energy costs—a critical SES concern given constrained edge devices. Post-GDPR regulatory evolution (EU AI Act [
95]) and NIST post-quantum cryptography standards remain unaddressed, representing temporal gaps given the manuscript’s 2026 timeframe.
Despite advances in privacy-enhancing technologies (PETs), to the best of our knowledge, five substantive gaps persist for scalable SES deployment:
Zero-Knowledge Proofs (ZKP) Maturity: while theoretically optimal for privacy-preserving energy trading (verifiable consumption without raw data exposure), ZKP implementations exhibit 3-5x computational overhead on typical ARM Cortex-M edge processors, lacking SES-specific benchmarks [
96].
Homomorphic Encryption Optimization: recent Cheon-Kim-Kim-Song (CKKS) schemes [
97] reduce multiplicative depth overhead by 50% versus Paillier [
98], yet no standardized SES profiles exist for AMI Advanced Metering Infrastructure (AMI) data structures, hindering practical adoption.
Regulatory Harmonization: the EU AI Act [
95] mandates risk classification for grid analytics AI models, requiring privacy impact assessments absent from current SES literature. Integration with NIS2 Directive for critical infrastructure adds compliance complexity.
Edge-Centric Privacy: TinyML frameworks enable on-device anomaly detection (leakage/short-circuit) without cloud exfiltration, but remain vulnerable to side-channel attacks and lack formal energy-privacy trade-off models for 10–15 year smart meter lifecycles.
Quantum-Resistant Migration: NIST PQC standardization (2024) mandates Kyber/Dilithium adoption for long-term SES data at rest, yet IoT hardware acceleration trails by 2–3 years, creating a deployment window vulnerability.
A a research imperative, SES privacy frameworks mus prioritize hybrid PETs (ZKP + lightweight HE) with standardized energy-privacy metrics, validated through real-world AMI testbeds. User-centric dynamic consent mechanisms for prosumers, enabled via self-sovereign identity (SSI) on blockchain, represent the next architectural frontier absent from current literature.
10. Conclusions and Future Directions
This survey provides an integrated view of IoT technologies applied to smart electrical systems, highlighting how digitalization is deeply transforming the energy infrastructure. The analysis shows that:
Evolution towards Smart Grid and Internet of Energy: the spread of sensors, actuators, distributed control platforms, and edge/fog computing enables real-time monitoring, automation, and optimization of energy flows [
2,
18].
Communication Standards: both short-range technologies (Wi-Fi, ZigBee, BLE, Z-Wave) and long-range ones (LoRaWAN, NB-IoT, Sigfox) offer different trade-offs between power consumption, coverage, latency, and reliability [
29,
31]. No single standard is universally superior: the choice depends on the specific application context [
32,
99].
Interoperability: the coexistence of IT/IoT and OT protocols requires the use of middleware and intelligent gateways. These tools must translate heterogeneous data models (e.g., from IEC 61850 to MQTT) and ensure consistent integration between devices, platforms, and applications [
20,
40]. In this context, this survey specifically addressed the technical gap between IT and OT, analyzing middleware solutions capable of bridging legacy industrial protocols with modern IoT standards.
Security and Privacy: the proliferation of IoT devices increases the attack surface, exposing the network to risks like DDoS and false data injection [
21]. The limited computing resources of nodes make it difficult to implement advanced encryption protocols. Techniques such as lightweight cryptography, DTLS/TLS, differential privacy, federated learning, and quantum-resistant algorithms are promising but come with significant energy costs [
94,
100].
Smart Applications: smart homes, smart buildings, Industry 4.0/5.0, and smart grids show measurable improvements in energy efficiency, automation, and resilience. The literature reports energy savings across a variety of residential and industrial deployments, although the magnitude of these gains is highly scenario-dependent and varies with baseline conditions, controllable load share, and operational constraints [
68,
77].
Energy Management Systems (EMS): supported by advanced Artificial Intelligence techniques (such as Deep Reinforcement Learning), EMS act as the brain of smart energy systems, orchestrating heterogeneous resources like photovoltaics, storage systems, home loads, and electric vehicles [
52,
61].
The following
Table 13 summarizes the comparison of the proposed work with existing surveys, highlighting the unique contributions and overlapping areas of study in the context of IoT-based smart electrical systems.
As summarized in
Table 13, the related literature often examines IoT-based smart electrical systems through partially disconnected perspectives. Foundational IoT surveys such as [
14,
23] consolidate generic architectures and enabling paradigms, but they are not tailored to the constraints of critical electrical infrastructures, where long device lifecycles, safety-critical requirements, and OT-driven standardization strongly influence design choices. Conversely, several domain-specific surveys provide in-depth coverage of individual functional layers: Refs. [
3,
13] emphasize communication requirements, QoS, and protocol-level considerations; Ref. [
45] focuses on middleware/platform capabilities and adoption challenges; and security-oriented surveys such as [
12,
49,
100] prioritize threats and countermeasures (and, in some cases, privacy aspects), often without a systematic cross-layer mapping to architectural and standardization and integration decisions. Although broader smart-grid/energy-domain surveys such as [
2,
5,
6,
80] cover a wider spectrum of technologies and applications, they often present standards, protocols, architectures, and use cases as parallel “silos”, leaving key functional dependencies among these dimensions largely implicit. In contrast, our survey introduces a cross-layer synthesis that connects architectural/reference models, standards and communication protocols, IT/OT interoperability mechanisms (including gateway/middleware-based translation across heterogeneous stacks), security and privacy requirements, edge–fog–cloud computing choices, and data/AI pipelines, thereby enabling readers to trace design decisions across layers toward implementable energy-management strategies and smart electrical applications.
Overall, the survey shows that IoT is now an essential element for building smart electrical systems. However, it also highlights that interoperability, security, and complexity management remain key challenges to address for creating truly scalable, reliable, and sustainable solutions.
The evolution of IoT-based smart electrical systems is expected to accelerate in the coming years, driven by the increasing penetration of distributed energy resources, electric vehicles, and data-intensive applications. One of the most prominent trends concerns the growing adoption of edge and fog computing paradigms, which aim to reduce latency, enhance scalability, and improve resilience by enabling localized data processing and control closer to the physical infrastructure. In parallel, the integration of artificial intelligence and machine learning techniques, including deep learning and reinforcement learning, is anticipated to play a central role in predictive maintenance, adaptive energy management, and demand response optimization.
Addressing challenges such as data management, trustworthiness, AI explainability, and regulatory compliance will require multidisciplinary research efforts, combining advances in communication technologies, artificial intelligence, cybersecurity, and energy systems engineering, ultimately paving the way toward resilient, secure, and sustainable IoT-enabled smart electrical systems.
Beyond the general challenges outlined above, a more detailed analysis reveals a set of structural limitations that continue to hinder the large-scale deployment of IoT-based smart electrical systems. In accordance with current research trends and technological trajectories, the following open research gaps are identified in a concise form, highlighting critical weaknesses of existing solutions and outlining promising directions for future investigation:
Scalable IT/OT Security
- ∘
Problem: Existing security frameworks, including NIST-based guidelines and ECC-based cryptographic schemes [
22], as well as VPN-based architectures [
90], were not conceived to scale across the billions of heterogeneous devices expected by 2030 [
85].
- ∘
Research Gap: Absence of autonomous and zero-touch security mechanisms capable of dynamically managing trust and mitigating threats in massive-scale, heterogeneous IT/OT ecosystems.
Real-time AI at the Edge
- ∘
Problem: Advanced Artificial Intelligence and Deep Reinforcement Learning (DRL) models for energy management [
61] frequently exceed the computational, memory, and energy constraints of most IoT nodes [
90,
100].
- ∘
Research Gap: Lack of ultra-lightweight, edge-native AI models (e.g., TinyML) capable of supporting real-time decision-making under stringent latency, energy, and privacy constraints.
Standard Harmonization
- ∘
Problem: Emerging protocols such as Matter and MQTT [
40] improve interoperability at the communication level but fail to address integration at the semantic and information-model levels.
- ∘
Research Gap: Absence of a unified semantic framework or a universal ontology [
48] enabling true cross-vendor and cross-domain interoperability in large-scale IoE ecosystems.
As shown in
Table 14, despite these advancements, several open challenges remain. Interoperability across heterogeneous devices, platforms, and standards continues to represent a critical issue, particularly in large-scale deployments involving multiple vendors and legacy systems. While international standards provide partial solutions, achieving seamless integration between IT and operational technology OT domains remains an open research problem. Security and privacy also constitute major concerns, as the increased attack surface introduced by IoT devices exposes smart electrical systems to cyber–physical threats, data breaches, and service disruptions. Developing lightweight yet robust security mechanisms that can operate under the resource constraints of IoT nodes is still a challenging task.