Skip to Content
  • Proceeding Paper
  • Open Access

22 May 2026

Evaluating Thread, Zigbee and Z-Wave Against Common Criteria Cryptographic Requirements †

,
,
,
,
and
TelSiP Research Laboratory, Department of Electrical and Electronic Engineering, School of Engineering, University of West Attica, Ancient Olive Grove Campus, 250 Thivon Str., GR-12241 Athens, Greece
*
Author to whom correspondence should be addressed.
Presented at the 6th International Electronic Conference on Applied Sciences, 9–11 December 2025; Available online: https://sciforum.net/event/ASEC2025.

Abstract

The explosive growth of the Internet of Things (IoT) has brought an array of resource-constrained devices to domains such as smart homes, industrial automation, and healthcare, raising substantial cybersecurity challenges. Lightweight wireless protocols, such as Thread, Zigbee, and Z-Wave, are integral to IoT connectivity, but the degree to which their embedded cryptographic mechanisms satisfy formal cybersecurity certification schemes remains underexplored. This work draws primarily on recent peer-reviewed publications and major conference proceedings to rigorously evaluate Thread, Zigbee, and Z-Wave against the Common Criteria (CC) Functional Requirements for Cryptography (FCS) as specified in CC:2022 and the EU cybersecurity certification scheme on Common Criteria (EUCC). The assessment focuses on essential CC cryptographic components, including key generation (FCS_CKM.1), secure key distribution (FCS_CKM.2), agreement protocols (FCS_CKM_EXT.7), cryptographic operations (FCS_COP.1), and random bit generators (FCS_RBG.1). The analysis reveals that Thread demonstrates the strongest alignment with CC requirements by leveraging Advanced Encryption Standard—Counter with CBC-MAC mode (AES-CCM) authenticated encryption and Elliptic Curve Diffie-Hellman (ECDH)-based key exchange within a decentralized trust framework. Zigbee matches this cryptographic strength at the primitive level, but its dependency on a centralized Trust Center for key management complicates full compliance with key lifecycle and distribution controls. Z-Wave, especially through its S2 Security framework, improves by incorporating authenticated ECDH exchanges, though proprietary constraints and limited protocol transparency remain obstacles to independent assurance. This comparative study concludes that while all three protocols provide a baseline of robust cryptographic security, only Thread currently aligns with CC and EUCC certification schemes. Zigbee and Z-Wave will require additional protocol hardening and enhancement of cryptographic key lifecycle management to achieve comparable assurance levels. Ensuring conformance with formal cybersecurity standards is imperative for building trust and resilience across critical IoT infrastructures.

1. Introduction

The rapid expansion of the IoT has introduced a diverse range of resource-constrained devices into various sectors, including smart homes, industrial automation, and healthcare [1,2]. These deployments, while offering enhanced connectivity and automation, concurrently present substantial cybersecurity challenges [3,4]. Protecting IoT systems requires robust confidentiality, integrity, and authentication mechanisms [1]. Resource limitations observed in many IoT devices, such as limited processing capability, memory, and power supply, require the implementation of Lightweight Cryptographic (LWC) methods for information security [5,6].
Lightweight wireless protocols, including Thread, Zigbee, and Z-Wave, are fundamental to IoT connectivity [7]. However, the extent to which their embedded cryptographic mechanisms align with formal cybersecurity certification schemes remains an underexplored area [8,9]. Formal certifications, such as those derived from Common Criteria (CC) and the EU cybersecurity certification scheme on Common Criteria (EUCC), provide a standardized benchmark for evaluating security assurances [8,10]. Such evaluations are critical for establishing trust and ensuring the resilience of IoT infrastructures against evolving cyber threats [11].
This study assesses Thread, Zigbee, and Z-Wave against the CC Functional Requirements for Cryptography (FCS) [12] as specified in CC:2022 and the EUCC scheme [10], focusing on key cryptographic components such as Key generation (FCS_CKM.1), secure key distribution (FCS_CKM.2), agreement protocols (FCS_CKM_EXT.7), cryptographic operations (FCS_COP.1), and random bit generators (FCS_RBG.1) [12]. Following this introduction, the Section 2 details the evaluation framework based on standardized CC processes while the Literature Review contextualizes these protocols within current security standards and practices [13].

2. Methodology

This work draws primarily on recent peer-reviewed publications and major conference proceedings to undertake a rigorous evaluation. The analysis concentrates on the FCS of CC, particularly those relevant to key management and data protection. The Common Criteria for Information Technology Security Evaluation (ISO/IEC 15408-2) [14] provides an internationally recognized framework for information security evaluation [10]. This framework enables third-party assessment and defines Evaluation Assurance Levels (EALs). The EUCC scheme directly utilizes aspects of CC, specifically its vulnerability assessment families, to ensure a well-informed choice of assurance levels [8,10]. The study focuses on specific FCS from CC:2022, which dictate precise security functions for cryptographic modules [15]. Thread, Zigbee, and Z-Wave were selected due to their widespread deployment in IoT ecosystems, particularly in constrained environments such as smart homes and industrial control systems [2,7]. The comparison approach involves dissecting each protocol’s cryptographic implementation against the five selected CC FCS components, highlighting compliance strengths and deficiencies in relation to formal certification requirements. It is important to establish that this study constitutes a formal theoretical analysis and structural mapping, rather than an empirical penetration testing or hardware exploitation exercise. Given that formal cybersecurity certification schemes operate on rigorous documentation and architectural alignment before physical evaluation, this paper’s primary academic contribution lies in the systematic, critical synthesis of the foundational specifications of Thread (1.4.0), Zigbee (R23.1), and Z-Wave (S2) [16,17,18]. By abstracting the highly technical, protocol-specific cryptographic mechanisms into the standardized regulatory language of the CC Functional Requirements for Cryptography (FCS), this research establishes a foundational theoretical baseline. This theoretical mapping is a necessary prerequisite for understanding compliance gaps prior to any empirical, laboratory-based certification efforts.

3. Literature Review

Lightweight wireless protocols are integral to the functionality of the IoT, enabling communication among resource-constrained devices [6]. These protocols must balance stringent resource limitations with the need for robust security [19,20]. However, traditional cryptographic approaches often require significant resource allocation, necessitating the development of lightweight cryptographic methods tailored for IoT devices with limited memory and processing power [5,21].
Previous research has extensively explored the security postures of IoT wireless protocols from various technical perspectives. For instance, Kambourakis et al. [7] provided a comprehensive review of mainstream IoT PAN protocols, highlighting broad architectural vulnerabilities, while Marksteiner et al. [2] focused on general wireless security within the smart home domain. Furthermore, numerous studies have evaluated the efficiency of lightweight cryptographic algorithms tailored for resource-constrained environments [3,5,20]. While these foundational works provide valuable empirical insights and general vulnerability assessments, they typically evaluate protocols in isolation or focus on broad cryptographic efficiency rather than regulatory compliance. A notable gap remains in the current literature regarding the systematic mapping of these specific protocols against standardized, internationally recognized certification frameworks. This study addresses this gap by moving beyond general vulnerability analysis, focusing specifically on how the cryptographic characteristics of Thread, Zigbee, and Z-Wave map to the strict, formalized parameters of the Common Criteria and the EUCC.
CC provides a framework for specifying and evaluating security functions and assurance requirements. The EUCC builds upon the CC, incorporating its vulnerability assessment components to provide a harmonized approach to cybersecurity certification across the EU [8,10]. Both schemes emphasize independent third-party evaluation, promoting transparency and trustworthiness in certified products, which is crucial for critical IoT infrastructures [22].
Thread employs robust cryptographic mechanisms, notably Advanced Encryption Standard in Counter with Cipher Block Chaining Message Authentication Code mode (AES-CCM) authenticated encryption and ECDH-based key exchange within a decentralized trust framework [2]. Zigbee utilizes AES-128 encryption, but often relies on a centralized Trust Center for key management [23,24]. Z-Wave, with its S2 Security framework, has incorporated authenticated ECDH exchanges to enhance key establishment [2].

4. Comparative Evaluation of Cryptographic Components

In this section, a detailed theoretical mapping is conducted. Instead of outlining protocol features, the analysis critically evaluates how the underlying architectural choices of each protocol—such as Thread’s decentralized mesh and Zigbee’s centralized Trust Center—either align with or challenge the systematic structural requirements of the Common Criteria cryptographic components.

4.1. Key Generation (FCS_CKM.1)

The Common Criteria requirement FCS_CKM.1 mandates that cryptographic keys must be generated with high entropy and unpredictability to ensure their strength and randomness, effectively preventing any form of predictability or compromise [15]. This process typically employs approved Deterministic Random Bit Generators (DRBGs) seeded by robust entropy sources for maintaining cryptographic security [15,25], while secure Key Derivation Functions (KDFs) are essential to produce cryptographic keys that meet stringent security requirements [15].
Thread leverages a decentralized trust framework, where devices can generate their own keys using strong cryptographic primitives [2]. The protocol specification implies the use of robust random number generation for key material, often relying on hardware-based True Random Number Generators (TRNGs) or Cryptographically Secure Pseudorandom Number Generators (CSPRNGs) [26]. This decentralized approach, coupled with explicit use of ECDH for key exchange, suggests a strong adherence to FCS_CKM.1 by promoting the generation of high-entropy ephemeral and long-term keys.
Zigbee networks use both network keys and link keys, which are 128-bit keys [24]. The specification explicitly states that devices generating random keys for distribution require a strong method of random number generation [16], which finally meet the FIPS 140-2 [27] standards for randomness and entropy, suggesting methods like basing numbers on random clocks, external events, or pre-seeded values [16].
Z-Wave, particularly with its S2 Security framework, incorporates authenticated ECDH exchanges, which inherently involve the generation of ephemeral key pairs [2]. While the S2 specification enhances security, the reliance on proprietary elements can pose challenges for independent verification against strict FCS_CKM.1 requirements.
Table 1 provides a comprehensive comparative overview of the key generation mechanisms alignment for all three protocols.
Table 1. Comparative analysis of key generation (FCS_CKM.1).

4.2. Secure Key Distribution (FCS_CKM.2)

FCS_CKM.2 specifies the secure distribution of cryptographic keys, ensuring their confidentiality and integrity during transit and prior to use [15]. This involves employing robust key exchange protocols, key wrapping, or encrypted channels for key protection. Additionally, secure channels like TLS or IKE are commonly utilized to safeguard key transport, while mechanisms including AES-128 CCM and AES-128 CMAC provide authenticated encryption and integrity verification during key distribution [15,17].
Thread employs Datagram Transport Layer Security (DTLS) and Transport Layer Security (TLS) protocols for key distribution, leveraging well-established cryptographic methods [18]. The use of ECDH key exchange establishes a secure channel for session key distribution, maintaining confidentiality and integrity throughout the process [28]. Thread’s decentralized mesh network design enhances robust key distribution in dynamic topologies, aligning strongly with the requirements as defined in FCS_CKM.2.
Zigbee secures communications using 128-bit network keys and link keys [24]. Key distribution typically relies on a pre-configured link key, shared between the Trust Center and joining devices for encrypted communications [16,24]. Although this aims to imporve security, its centralized operation introduces a single point of failure, complicating secure key management throughout the key lifecycle, especially if the Trust Center is compromised or insufficiently hardened [16,24].
Z-Wave’s S2 Security framework significantly enhances key distribution by using authenticated ECDH exchanges during device inclusion, for delivering secure session and network key transfer [7,17,29]. This process segments the network into three security classes: (i) S2 Access Control, (ii) S2 Authenticated, and (iii) S2 Unauthenticated, each with distinct AES-128 keys [7]. Although vulnerable “legacy” configurations may still exist, modern S2 implementations align closely with FCS_CKM.2 requirements for secure key management [2,7,17].
Table 2 provides a comprehensive comparative overview of the secure key distribution mechanisms alignment for all three protocols.
Table 2. Comparative analysis of key distribution (FCS_CKM.2).

4.3. Key Agreement Protocols (FCS_CKM.7)

FCS_CKM_EXT.7 delineates stringent requirements for cryptographic key agreement protocols, mandating that multiple entities securely establish a shared secret key without relying on pre-shared secrets [15,25]. These protocols must adhere to approved algorithms and parameters, which include Diffie-Hellman and RSA-based schemes with validated domain parameters [15,25]. Proper implementation involves key confirmation, key derivation, and validation of static and ephemeral keys [25].
Thread extensively employs ECDH as its primary key agreement protocol [2]. This choice of ECDH, enables devices to agree upon shared secret keys over an insecure channel, providing forward secrecy and resisting known attacks. The use of ECDH within its decentralized architecture strongly aligns Thread with the requirements of FCS_CKM_EXT.7.
Zigbee, while relying on AES-128 for symmetric encryption, traditionally manages keys through a centralized Trust Center [23,24]. Its primary model for key establishment is often based on pre-shared keys or keys distributed by the Trust Center [24]. Consequently, Zigbee’s original design does not inherently fulfill the FCS_CKM_EXT.7 requirement for dynamic key agreement between peers. While Zigbee 3.0 introduces advanced key establishment, the centralized Trust Center remains a potential weak point in its architecture.
Z-Wave’s S2 Security framework integrates authenticated ECDH exchanges for key agreement, which represents a significant enhancement over earlier Z-Wave security versions [2], for establishing a shared secret key through public-key cryptography and providing robust protection. The S2 framework’s explicit inclusion of ECDH directly addresses the requirements of FCS_CKM_EXT.7.
Table 3 provides a comprehensive comparative overview of the secure key agreement protocols alignment for all three protocols.
Table 3. Comparative analysis of key agreement protocols (FCS_CKM_EXT.7).

4.4. Cryptographic Operations (FCS_COP.1)

FCS_COP.1 requires that cryptographic operations performed by the target of evaluation utilize approved algorithms and modes of operation to ensure critical security objectives such as confidentiality, integrity, and authenticity [15]. This includes symmetric-key encryption modes like CBC, CTR, and XTS, Authenticated Encryption with Associated Data (AEAD) modes such as CCM and GCM, as well as hashing and digital signature algorithms [15]. Additionally, the generation of one-time values like nonces and IVs must adhere to strict randomness requirements as specified in FCS_OTV_EXT.1 to maintain cryptographic strength [15].
Thread utilizes AES-CCM for authenticated encryption [2]. AES-CCM is an approved cryptographic algorithm and mode that simultaneously provides confidentiality, data integrity, and data origin authentication, meeting the high standards required by FCS_COP.1.
Zigbee also employs AES-128 encryption [23]; however, the specific mode of operation used (e.g., CCM, CBC) might not always be consistently applied across all layers or device implementations [23]. While AES-128 itself satisfies the algorithm requirement, the comprehensive application of authenticated encryption modes, is crucial for full FCS_COP.1 compliance.
Z-Wave, particularly with S2 Security, also uses AES-128, often in an authenticated mode to provide both confidentiality and integrity [2]. The S2 framework is designed to protect against replay attacks and ensure message authenticity, indicating the use of a robust mode of operation such as AES-CCM or similar [7]. This application of AES-128 in a secure mode generally aligns Z-Wave with FCS_COP.1 requirements for cryptographic operations, particularly in newer S2-enabled devices.
Table 4 provides a comprehensive comparative overview of the secure cryptographic operations alignment for all three protocols.
Table 4. Comparative analysis of cryptographic operations (FCS_COP.1).

4.5. Random Bit Generation (FCS_RBG.1)

FCS_RBG.1 specifies requirements for the generation of random bits, crucial for cryptographic key generation and other security-critical functions, emphasizing unpredictability and sufficient entropy [26].
Thread relies on the underlying hardware and software to provide cryptographically secure random bit generation. Given its use of ECDH and AES-CCM, the implicit requirement for high-quality random numbers for nonces, ephemeral keys, and other cryptographic inputs is paramount [2]. While the specification does not detail the exact RBG implementation, its adherence to established security protocols like DTLS suggests the necessity of FIPS 140-2 compliant random number generators [18] that aligns Thread with FCS_RBG.1 requirements.
Zigbee specification explicitly mandates strong random number generation for creating random keys, requiring that these numbers are unpredictable and possess sufficient entropy to resist exhaustive search attacks. Methods proposed include using random clocks, external events, or pre-seeded values. The actual implementation’s quality depends on the IC manufacturers, which can lead to inconsistencies in meeting stringent FCS_RBG.1 standards across different devices [16].
Z-Wave’s S2 security framework necessitates high-quality random number generation for ephemeral ECDH key pairs and nonces used in authenticated encryption. Similar to other protocols, the underlying hardware implementation of the random bit generator is critical for meeting FCS_RBG.1 requirements [30]. While the S2 framework itself implies the need for strong randomness, the proprietary nature of some Z-Wave components might limit the transparency needed for a full, independent audit of its random bit generation capabilities against formal standards like FIPS 140-2.
Table 5 provides a comprehensive comparative overview of random bit generation alignment for all three protocols.
Table 5. Comparative analysis of random bit generation (FCS_RBG.1).

5. Discussion

Alignment with CC and EUCC Requirements: Thread aligns most closely with CC and EUCC standards by using decentralized, standardized primitives like AES-CCM and ECDH [2,10]. Zigbee’s reliance on a centralized Trust Center complicates compliance with distributed key lifecycle requirements [24]. Z-Wave S2 improves alignment via authenticated ECDH, though its proprietary history may limit the transparency needed for full certification [2].
Protocol-Specific Strengths and Limitations: Thread leverages open standards and a decentralized mesh to avoid single points of failure, though managing this complexity is a challenge [2]. Zigbee offers mature AES-128 encryption but remains vulnerable to Trust Center compromises [23,24]. Z-Wave S2 provides robust key agreement, yet its legacy of proprietary constraints still hinders independent assurance [2].
Obstacles to Independent Assurance and Transparency: Independent assurance is hindered by Zigbee’s manufacturer-dependent implementations and Z-Wave’s restricted specification access [2,24]. Even Thread’s open-standard approach faces scrutiny regarding specific hardware-level variations during certification.
Implications for IoT Trust and Infrastructure Resilience: Comprehensive alignment with CC/EUCC, currently led by Thread, is essential for critical infrastructure resilience [22]. Failing to meet these cryptographic standards creates systemic vulnerabilities in key management and bit generation, undermining trust in IoT ecosystems [26,31].

6. Conclusions

This comparative evaluation of Thread, Zigbee, and Z-Wave against Common Criteria cryptographic functional requirements reveals distinct security postures as illustrated in Table 6. Thread demonstrates the strongest alignment with CC and EUCC due to its use of AES-CCM authenticated encryption and ECDH-based key exchange within a decentralized trust framework, providing robust key generation, distribution, and agreement [2]. Zigbee offers strong cryptographic primitives (AES-128) but faces challenges in meeting comprehensive key lifecycle and distribution controls due to its reliance on a centralized Trust Center [24]. Z-Wave’s S2 Security, with its authenticated ECDH exchanges, significantly enhances its cryptographic capabilities, though proprietary elements and transparency issues persist [2].
Table 6. Synthesis of key protocol characteristics.
The ongoing evolution of IoT connectivity standards demands a stronger emphasis on achieving formal cybersecurity certifications to ensure robust security and user trust [32]. Future efforts should prioritize the development of open, auditable cryptographic implementations that are lightweight yet resilient, fostering transparency in protocol specifications and encouraging independent security evaluations across all IoT layers. Additionally, advancing research into quantum-resistant cryptography is vital to safeguard IoT networks against emerging threats. Establishing unified certification and standardization frameworks is imperative to build enduring trust and resilience in the expanding IoT ecosystem [32,33].

Author Contributions

Conceptualization, E.N., S.K., F.Z., I.C.P., K.B. and G.K.; methodology, E.N., S.K., F.Z., I.C.P., K.B. and G.K.; software, E.N., S.K., F.Z., I.C.P., K.B. and G.K.; validation, E.N., S.K., F.Z., I.C.P., K.B. and G.K.; formal analysis, E.N., S.K., F.Z., I.C.P., K.B. and G.K.; investigation, E.N., S.K., F.Z., I.C.P., K.B. and G.K.; resources, E.N., S.K., F.Z., I.C.P., K.B. and G.K.; data curation, E.N., S.K., F.Z., I.C.P., K.B. and G.K.; writing original draft preparation, E.N., S.K., F.Z., I.C.P., K.B. and G.K.; writing—review and editing, E.N., S.K., F.Z., I.C.P., K.B. and G.K.; visualization, E.N., S.K., F.Z., I.C.P., K.B. and G.K.; supervision, G.K.; project administration, G.K. All authors have read and agreed to the published version of the manuscript.

Funding

This research received no external funding.

Data Availability Statement

No new data were created or analyzed in this study. Data sharing is not applicable to this article.

Acknowledgments

During manuscript preparation, the authors used the Gemini 3.0 assistant solely for basic editorial support. The tool was used to check grammar, sentence structure, spelling, and formatting consistency. The authors have reviewed and edited the output and take full responsibility for the content of this publication.

Conflicts of Interest

The authors declare no conflicts of interest.

Abbreviations

The following abbreviations are used in this manuscript:
AEADAuthenticated Encryption with Associated Data
AES-128Advanced Encryption Standard using a 128-bit key
AES-CCMAdvanced Encryption Standard—Counter with CBC-MAC mode
CCCommon Criteria
CSPRNGsCryptographically Secure Pseudorandom Number Generators
DRBGsDeterministic Random Bit Generators
DTLSDatagram Transport Layer Security
EALsEvaluation Assurance Levels
ECDHElliptic Curve Diffie-Hellman
EUCCEU cybersecurity certification scheme on Common Criteria
FCSFunctional Requirements for Cryptography
FIPSFederal Information Processing Standard
IECInternational Electrotechnical Commission
IoTInternet of Things
ISOInternational Organization for Standardization
KDFsKey Derivation Functions
LWCLightweight Cryptography
TRNGsTrue Random Number Generators

References

  1. Yalli, J.S.; Hilmi Hasan, M.; Tang Jung, L.; Ibrahim Yerima, A.; Adamu Aliyu, D.; Danjuma Maiwada, U.; Mahmood Al-Selwi, S.; Ur Rehman Shaikh, M. A Systematic Review for Evaluating IoT Security: A Focus on Authentication, Protocols and Enabling Technologies. IEEE Internet Things J. 2025, 12, 18908–18928. [Google Scholar] [CrossRef] [Scilit]
  2. Marksteiner, S.; Exposito Jimenez, V.J.; Valiant, H.; Zeiner, H. An Overview of Wireless IoT Protocol Security in the Smart Home Domain. In Proceedings of the IEEE CTTE 2017; IEEE: Piscataway, NJ, USA, 2017; pp. 1–8. [Google Scholar] [CrossRef] [Scilit]
  3. Hasan, M.K.; Shafiq, M.; Islam, S.; Pandey, B.; Baker El-Ebiary, Y.A.; Nafi, N.S.; Ciro Rodriguez, R.; Vargas, D.E. Lightweight Cryptographic Algorithms for Guessing Attack Protection in Complex Internet of Things Applications. Complexity 2021, 2021, 5540296. [Google Scholar] [CrossRef] [Scilit]
  4. Shahzad, A.; Lee, M.; Lee, Y.K.; Kim, S.; Xiong, N.; Choi, J.Y.; Cho, Y. Real Time MODBUS Transmissions and Cryptography Security Designs and Enhancements of Protocol Sensitive Information. Symmetry 2015, 7, 1176–1210. [Google Scholar] [CrossRef] [Scilit]
  5. Parvathy, K.; Nataraj, B.; Rajalakshmi, S.; Duraisamy, P. A Review on Lightweight Cryptographic Algorithms in Internet of Things. In Proceedings of the 2023 5th International Conference on Inventive Research in Computing Applications (ICIRCA), Coimbatore, India, 3–5 August 2023; pp. 1448–1451. [Google Scholar] [CrossRef] [Scilit]
  6. Gupta, S.; Saxena, S. Lightweight Cryptographic Techniques and Protocols for IoT; Transactions on Computer Systems and Networks; Springer Nature: Singapore, 2022; pp. 55–77. [Google Scholar] [CrossRef] [Scilit]
  7. Kambourakis, G.; Kolias, C.; Geneiatakis, D.; Karopoulos, G.; Makrakis, G.M.; Kounelis, I. A State-of-the-Art Review on the Security of Mainstream IoT Wireless PAN Protocol Stacks. Symmetry 2020, 12, 579. [Google Scholar] [CrossRef] [Scilit]
  8. Matheu, S.N.; Hernández-Ramos, J.L.; Skarmeta, A.F.; Baldini, G. A Survey of Cybersecurity Certification for the Internet of Things. ACM Comput. Surv. 2020, 53, 115. [Google Scholar] [CrossRef] [Scilit]
  9. Matheu, S.N.; Hernandez-Ramos, J.L.; Skarmeta, A.F. Toward a Cybersecurity Certification Framework for the Internet of Things. IEEE Secur. Priv. 2019, 17, 66–76. [Google Scholar] [CrossRef]
  10. Official Journal of the European Union—European Commission. Commission Implementing Regulation (EU) 2024/482 of 31 January 2024 Laying down Rules for the Application of Regulation (EU) 2019/881 of the European Parliament and of the Council as Regards the Adoption of the European Common Criteria-Based Cybersecurity Certification Scheme (EUCC). Available online: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202400482 (accessed on 24 January 2026).
  11. Irshad, R.R.; Hussain, S.; Hussain, I.; Nasir, J.A.; Zeb, A.; Alalayah, K.M.; Alattab, A.A.; Yousif, A.; Alwayle, I.M. IoT-Enabled Secure and Scalable Cloud Architecture for Multi-User Systems: A Hybrid Post-Quantum Cryptographic and Blockchain-Based Approach Toward a Trustworthy Cloud Computing. IEEE Access 2023, 11, 105479–105498. [Google Scholar] [CrossRef] [Scilit]
  12. Sun, N.; Li, C.T.; Chan, H.; Dung Le, B.; Islam, M.Z.; Zhang, L.Y.; Islam, M.R.; Armstrong, W. Defining Security Requirements With the Common Criteria: Applications, Adoptions, and Challenges. IEEE Access 2022, 10, 44756–44777. [Google Scholar] [CrossRef] [Scilit]
  13. Holguin, I.; Errapotu, S.M. Smart Home IoT Communication Protocols and Advances in Their Security and Interoperability. In Proceedings of the IEEE CSNet 2023; IEEE: Piscataway, NJ, USA, 2023; pp. 208–211. [Google Scholar] [CrossRef] [Scilit]
  14. ISO/IEC 15408-2; Information Security, Cybersecurity and Privacy Protection—Evaluation Criteria for IT Security—Part 2: Security Functional Components. ISO: Geneva, Switzerland, 2022. Available online: https://www.iso.org/standard/72892.html (accessed on 24 January 2026).
  15. Common Criteria Development Board. Common Criteria Specification of Functional Requirements for Cryptography, January 2025. Version: 1.0. 2/62. Available online: https://www.commoncriteriaportal.org/files/ccfiles/CCDB-018-v1.0-2025-Jan-31-Final-Specification_of_Functional_Requirements_for_Cryptography.pdf (accessed on 24 January 2026).
  16. Connectivity Standards Alliance. Zigbee R23.1 Specifications. Available online: https://csa-iot.org/developer-resource/specifications-download-request/ (accessed on 24 January 2026).
  17. Z-Wave Alliance, Inc. Z-Wave Specifications, Release 2025B. Available online: https://sdomembers.z-wavealliance.org/DesktopModules/Inventures_Document/FileDownload.aspx?ContentID=3841 (accessed on 24 January 2026).
  18. Thread Group, Inc. Thread 1.4.0 Specifications, Release 2024. Available online: https://www.threadgroup.org/ThreadSpec (accessed on 24 January 2026).
  19. Kaur, B.; Rakhra, M.; Singh, D.; Singh, A.; Shruti. Advancements in Lightweight Cryptography: Secure Solutions for Resource-Constrained Environments in IoT, WSNs, and CPS. In Proceedings of the 2024 11th International Conference on Reliability, Infocom Technologies and Optimization (Trends and Future Directions) (ICRITO), Noida, India, 14–15 March 2024; pp. 1–7. [Google Scholar] [CrossRef] [Scilit]
  20. Radhakrishnan, I.; Jadon, S.; Honnavalli, P.B. Efficiency and Security Evaluation of Lightweight Cryptographic Algorithms for Resource-Constrained IoT Devices. Sensors 2024, 24, 4008. [Google Scholar] [CrossRef] [Scilit] [PubMed]
  21. Makarenko, I.; Semushin, S.; Suhai, S.; Ahsan Kazmi, S.M.; Oracevic, A.; Hussain, R. A Comparative Analysis of Cryptographic Algorithms in the Internet of Things. In Proceedings of the 2020 International Scientific and Technical Conference Modern Computer Network Technologies (MoNeTeC), Online, 27–29 October 2020; pp. 1–8. [Google Scholar] [CrossRef] [Scilit]
  22. Pradhan, M.; Noll, J. Security, Privacy, and Dependability Evaluation in Verification and Validation Life Cycles for Military IoT Systems. IEEE Commun. Mag. 2020, 58, 14–20. [Google Scholar] [CrossRef] [Scilit]
  23. Kumar, M.; Yadav, V.; Yadav, S.P. Advance Comprehensive Analysis for Zigbee Network-Based IoT System Security. Discov. Comput. 2024, 27, 22. [Google Scholar] [CrossRef] [Scilit]
  24. Fan, X.; Susan, F.; Long, W.; Li, S. Security Analysis of ZigBee. MWR Info Security. Available online: https://courses.csail.mit.edu/6.857/2017/project/17.pdf (accessed on 24 January 2026).
  25. Barker, E.; Chen, L.; Roginsky, A.; Vassilev, A.; Davis, R. Recommendation for Pair-Wise Key-Establishment Schemes Using Discrete Logarithm Cryptography; Technical Report; National Institute of Standards and Technology: Gaithersburg, MD, USA, 2018. [CrossRef] [Scilit]
  26. Kietzmann, P.; Schmidt, T.C.; Wählisch, M. A Guideline on Pseudorandom Number Generation (PRNG) in the IoT. ACM Comput. Surv. 2021, 54, 112. [Google Scholar] [CrossRef] [Scilit]
  27. National Institute of Standards and Technology. FIPS PUB 140-2: Security Requirements for Cryptographic Modules; NIST: Gaithersburg, MD, USA, 2001. Available online: https://csrc.nist.gov/pubs/fips/140-2/upd2/final (accessed on 24 January 2026).
  28. Liu, Y.; Pang, Z.; Dan, G.; Lan, D.; Gong, S. A Taxonomy for the Security Assessment of IP-Based Building Automation Systems: The Case of Thread. IEEE Trans. Ind. Inform. 2018, 14, 4113–4123. [Google Scholar] [CrossRef] [Scilit]
  29. Du, J.Z.; Liu, J.W.; Feng, T.; Yuan, Z.T. Formal Analysis and Improvement of Z-Wave Protocol. J. Comput. 2023, 34, 25–39. [Google Scholar] [CrossRef] [Scilit]
  30. Park, K.; Park, S.; Choi, B.G.; Kang, T.; Kim, J.; Kim, Y.; Jin, H. A Lightweight True Random Number Generator Using Beta Radiation for IoT Applications. ETRI J. 2020, 42, 951–964. [Google Scholar] [CrossRef] [Scilit]
  31. Boke, A.K.; Nakhate, S.; Rajawat, A. Efficient Key Generation Techniques for Securing IoT Communication Protocols. IETE Tech. Rev. 2020, 38, 282–293. [Google Scholar] [CrossRef] [Scilit]
  32. Hennessy, H. Consumer IoT Device Cybersecurity Standards, Policies, and Certification Schemes 2025 Update. Omdia Consulting. Available online: https://csa-iot.org/wp-content/uploads/2025/06/Consumer-IoT-Device-Cybersecurity-Standards-Policies-and-Certification-Schemes-2025-_FINAL.pdf (accessed on 24 January 2026).
  33. Khurshid, A.; Alsaaidi, R.; Aslam, M.; Raza, S. EU Cybersecurity Act and IoT Certification: Landscape, Perspective and a Proposed Template Scheme. IEEE Access 2022, 10, 129932–129948. [Google Scholar] [CrossRef] [Scilit]
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content.

Article Metrics

Citations

Article Access Statistics

Multiple requests from the same IP address are counted as one view.