Engineering Blog

IoT Security & Device PKI

Practical engineering articles on certificate infrastructure, firmware signing, device attestation, and IoT security from the ErlySign team.

All articles

device identity PKI IoT security

What Is Device Identity and Why It Matters for IoT Security

As IoT deployments scale to billions of devices, the question of 'who is this device?' becomes a foundational security requirement. We break down the core concepts of device identity, PKI, and why certificate-based authentication is the only scalable answer.

Shubhendra Singh Thakur 7 min read
Matter smart home PKI

Matter Protocol & PKI: What Device Makers Need to Know

The Matter standard mandates per-device certificates issued by a CSA-approved PAA. We walk through the certificate hierarchy, attestation flow, and what OEMs need to implement before their first device ships.

Arjun Mehta 9 min read
firmware signing secure boot OTA

Firmware Signing and Secure Boot: A Practical Guide

Unsigned firmware is the most common attack surface in deployed IoT devices. This guide covers the key concepts: code signing keys, secure boot chain verification, OTA update signing, and rollback prevention.

Priya Nair 11 min read
IEC 62443 industrial OT compliance

IEC 62443 for IoT Manufacturers: What You Need to Build In

IEC 62443 is the global standard for industrial cybersecurity. For IoT device manufacturers supplying into ICS environments, it defines specific requirements for device identity and secure communications.

Shubhendra Singh Thakur 10 min read
certificate lifecycle OCSP scale

Managing Certificate Lifecycles Across Millions of Devices

When you have 100,000 devices in the field, certificate expiry becomes an operational risk. We walk through the architecture patterns for automated certificate renewal, revocation lists, OCSP stapling, and operational tooling.

Arjun Mehta 12 min read
TPM secure element hardware security

TPM vs Secure Element: Choosing the Right Hardware Root of Trust

Hardware root of trust options — discrete TPM, integrated TPM, secure element, or software-only — each have different cost, integration, and security tradeoffs. A decision framework for embedded engineers.

Priya Nair 10 min read
automotive V2X UN R155

Automotive V2X Certificate Management: An Engineering Overview

Vehicle-to-everything communication requires pseudonym certificates that rotate frequently to protect driver privacy while maintaining vehicle authentication. We cover SCMS architecture and IEEE 1609.2 format.

Rahul Desai 13 min read

Ready to implement device identity?

ErlySign pilot: 100 devices, no cost, direct engineering onboarding.