Repository logo
 

A Comprehensive Analysis of Security Challenges in ZigBee 3.0 Networks

aut.relation.endpage4606
aut.relation.issue15
aut.relation.journalSensors
aut.relation.startpage4606
aut.relation.volume25
dc.contributor.authorGhobakhlou, Akbar
dc.contributor.authorAl-Hamid, Duaa Zuhair
dc.contributor.authorZandi, Sara
dc.contributor.authorCato, James
dc.date.accessioned2025-08-05T03:50:54Z
dc.date.available2025-08-05T03:50:54Z
dc.date.issued2025-07-25
dc.description.abstractZigBee, a wireless technology standard for the Internet of Things (IoT) devices based on IEEE 802.15.4, faces significant security challenges that threaten the confidentiality, integrity, and availability of its networks. Despite using 128-bit Advanced Encryption Standard (AES) with symmetric keys for node authentication and data confidentiality, ZigBee’s design constraints, such as low cost and low power, have allowed security issues to persist. While ZigBee 3.0 introduces enhanced security features such as install codes and trust centre link key updates, there remains a lack of empirical research evaluating their effectiveness in real-world deployments. This research addresses the gap by conducting a comprehensive, hardware-based analysis of ZigBee 3.0 networks using XBee 3 radio modules and ZigBee-compatible devices. We investigate the following three core security issues: (a) the security of symmetric keys, focusing on vulnerabilities that could allow attackers to obtain these keys; (b) the impact of compromised symmetric keys on network confidentiality; and (c) susceptibility to Denial-of-Service (DoS) attacks due to insufficient protection mechanisms. Our experiments simulate realistic attack scenarios under both Centralised and Distributed Security Models to assess the protocol’s resilience. The findings reveal that while ZigBee 3.0 improves upon earlier versions, certain vulnerabilities remain exploitable. We also propose practical security controls and best practices to mitigate these attacks and enhance network security. This work contributes novel insights into the operational security of ZigBee 3.0, offering guidance for secure IoT deployments and advancing the understanding of protocol-level defences in constrained environments.
dc.identifier.citationSensors, ISSN: 1424-8220 (Print); 1424-8220 (Online), MDPI AG, 25(15), 4606-4606. doi: 10.3390/s25154606
dc.identifier.doi10.3390/s25154606
dc.identifier.issn1424-8220
dc.identifier.issn1424-8220
dc.identifier.urihttp://hdl.handle.net/10292/19638
dc.languageen
dc.publisherMDPI AG
dc.relation.urihttps://www.mdpi.com/1424-8220/25/15/4606
dc.rights© 2025 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (https://creativecommons.org/licenses/by/4.0/).
dc.rights.accessrightsOpenAccess
dc.rights.urihttps://creativecommons.org/licenses/by/4.0/
dc.subject4605 Data Management and Data Science
dc.subject4606 Distributed Computing and Systems Software
dc.subject46 Information and Computing Sciences
dc.subject4604 Cybersecurity and Privacy
dc.subject0805 Distributed Computing
dc.subject0906 Electrical and Electronic Engineering
dc.titleA Comprehensive Analysis of Security Challenges in ZigBee 3.0 Networks
dc.typeJournal Article
pubs.elements-id622045

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
sensors-25-04606.pdf
Size:
13.11 MB
Format:
Adobe Portable Document Format
Description:
Journal article