Embedded device security for the IoT industry using secure provisioning and constrained-device security techniques
Making tiny IoT devices securable — embedded security expertise for the smallest computers.
The Challenge
The Internet of Things runs on small, cheap, resource-constrained devices — sensors, controllers and smart-home products — that often lack the memory, processing power and user interfaces needed for conventional security. Many are “headless” (no screen or keyboard), which makes even basic tasks like secure provisioning and device association hard to do safely; the result is a rapidly growing installed base of poorly secured devices that manufacturers struggle to protect and consumers cannot manage.
The Solution
PicoSec directly addressed this challenge of securing the Internet of Things, with a focus on embedded security for small, constrained devices where security can be hard to implement. NquiringMinds, whose security expertise spans protocol design through to silicon implementation, positioned the project as a hub where embedded security experts could drive the innovations required to support the IoT industry, publishing practical guidance and analysis through the PicoSec.org platform.
Outcomes
The project produced public outputs on IoT security challenges — for example headless IoT device provisioning (how to set up secure and usable associations for devices with no visible user interface) and smart-home privacy — with contributions from mobile/IoT security specialists Copper Horse Solutions. The embedded-security groundwork fed NQM’s later secure-IoT portfolio, including PicoSense, ManySecured and SNbD.
TODO: capture formal outcomes, deliverables and follow-on work.

Features
Embedded security approaches for small, constrained ("pico") IoT devices where conventional security stacks do not fit.
Secure, usable association of devices with no user interface.
Smart-home privacy analysis and guidance.
A public hub for embedded security expertise supporting the IoT industry.
Security engineering aimed at the very smallest class of IoT devices, where the industry gap was largest.
Benefits
Public knowledge outputs (headless provisioning, smart-home privacy) made available to the IoT industry via PicoSec.org.
Established NQM's embedded/secure-IoT credentials, feeding the later DSTL PicoSense work and the ManySecured/SNbD secure-router programme.
