A Comprehensive Analysis of Security Challenges in ZigBee 3.0 Networks
| aut.relation.endpage | 4606 | |
| aut.relation.issue | 15 | |
| aut.relation.journal | Sensors | |
| aut.relation.startpage | 4606 | |
| aut.relation.volume | 25 | |
| dc.contributor.author | Ghobakhlou, Akbar | |
| dc.contributor.author | Al-Hamid, Duaa Zuhair | |
| dc.contributor.author | Zandi, Sara | |
| dc.contributor.author | Cato, James | |
| dc.date.accessioned | 2025-08-05T03:50:54Z | |
| dc.date.available | 2025-08-05T03:50:54Z | |
| dc.date.issued | 2025-07-25 | |
| dc.description.abstract | ZigBee, a wireless technology standard for the Internet of Things (IoT) devices based on IEEE 802.15.4, faces significant security challenges that threaten the confidentiality, integrity, and availability of its networks. Despite using 128-bit Advanced Encryption Standard (AES) with symmetric keys for node authentication and data confidentiality, ZigBee’s design constraints, such as low cost and low power, have allowed security issues to persist. While ZigBee 3.0 introduces enhanced security features such as install codes and trust centre link key updates, there remains a lack of empirical research evaluating their effectiveness in real-world deployments. This research addresses the gap by conducting a comprehensive, hardware-based analysis of ZigBee 3.0 networks using XBee 3 radio modules and ZigBee-compatible devices. We investigate the following three core security issues: (a) the security of symmetric keys, focusing on vulnerabilities that could allow attackers to obtain these keys; (b) the impact of compromised symmetric keys on network confidentiality; and (c) susceptibility to Denial-of-Service (DoS) attacks due to insufficient protection mechanisms. Our experiments simulate realistic attack scenarios under both Centralised and Distributed Security Models to assess the protocol’s resilience. The findings reveal that while ZigBee 3.0 improves upon earlier versions, certain vulnerabilities remain exploitable. We also propose practical security controls and best practices to mitigate these attacks and enhance network security. This work contributes novel insights into the operational security of ZigBee 3.0, offering guidance for secure IoT deployments and advancing the understanding of protocol-level defences in constrained environments. | |
| dc.identifier.citation | Sensors, ISSN: 1424-8220 (Print); 1424-8220 (Online), MDPI AG, 25(15), 4606-4606. doi: 10.3390/s25154606 | |
| dc.identifier.doi | 10.3390/s25154606 | |
| dc.identifier.issn | 1424-8220 | |
| dc.identifier.issn | 1424-8220 | |
| dc.identifier.uri | http://hdl.handle.net/10292/19638 | |
| dc.language | en | |
| dc.publisher | MDPI AG | |
| dc.relation.uri | https://www.mdpi.com/1424-8220/25/15/4606 | |
| dc.rights | © 2025 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (https://creativecommons.org/licenses/by/4.0/). | |
| dc.rights.accessrights | OpenAccess | |
| dc.rights.uri | https://creativecommons.org/licenses/by/4.0/ | |
| dc.subject | 4605 Data Management and Data Science | |
| dc.subject | 4606 Distributed Computing and Systems Software | |
| dc.subject | 46 Information and Computing Sciences | |
| dc.subject | 4604 Cybersecurity and Privacy | |
| dc.subject | 0805 Distributed Computing | |
| dc.subject | 0906 Electrical and Electronic Engineering | |
| dc.title | A Comprehensive Analysis of Security Challenges in ZigBee 3.0 Networks | |
| dc.type | Journal Article | |
| pubs.elements-id | 622045 |
Files
Original bundle
1 - 1 of 1
Loading...
- Name:
- sensors-25-04606.pdf
- Size:
- 13.11 MB
- Format:
- Adobe Portable Document Format
- Description:
- Journal article
