EventsThe 6th International Electronic Conference on Applied Sciences
Published
This submission belongs to the session S4. Electrical, Electronics and Communications Engineering of the event The 6th International Electronic Conference on Applied Sciences
Published date
03 Dec, 2025
Academic Editor
author-avatarAlessandro Lo Schiavo
Citation
Grigorios Koulouras, Evangelos Nannos, Stylianos Katsoulis, Fotios Zantalis, Ioannis Chrysovalantis Panagou, Konstantinos Boukouras, Evaluating Thread, Zigbee and Z-Wave Against Common Criteria Cryptographic Requirements, in Proceedings of The 6th International Electronic Conference on Applied Sciences, 9 December–11 December 2025, MDPI: Basel, Switzerland
Share
Email
Facebook
Twitter
LinkedIn

Evaluating Thread, Zigbee and Z-Wave Against Common Criteria Cryptographic Requirements

image
image
1. TelSiP Research Laboratory, Department of Electrical and Electronic Engineering, School of Engineering, University of West Attica, Ancient Olive Grove Campus, 250 Thivon Str., GR-12241 Athens, Greece, Greece
2. Institute of Geodynamics, National Observatory of Athens, Thiseio, Athens, Greece
Abstract

The rapid expansion of the Internet of Things (IoT) has introduced a diverse set of devices operating in constrained environments, raising critical security concerns in domains such as smart homes, industrial automation, and healthcare. Many IoT ecosystems use lightweight wireless protocols for low-power, short-range communication. While these protocols embed security mechanisms, their alignment with formal cybersecurity assurance frameworks remains insufficiently studied. Drawing primarily on recent peer-reviewed journals and reputable conference proceedings, we evaluate Thread, Zigbee and Z-Wave against the Common Criteria (CC) Functional Requirements for Cryptography (FCS), as defined in CC:2022 and the European Union Cybersecurity Certification Scheme (EUCC). The assessment focuses on key CC components, including cryptographic key generation (FCS_CKM.1), distribution (FCS_CKM.2), agreement (FCS_CKM_EXT.7), operations (FCS_COP.1), and random bit generation (FCS_RBG.1). Our findings show that Thread demonstrates the strongest alignment with CC requirements, leveraging AES-CCM authenticated encryption and ECDH-based key exchange within a flexible, decentralized trust model. Zigbee provides comparable cryptographic strength but its reliance on a centralized Trust Center complicates compliance with key management lifecycle controls. Z-Wave has improved with the S2 Security framework, adopting ECDH exchanges, but still faces challenges due to proprietary constraints and limited transparency. This comparative analysis highlights that while all three protocols provide baseline security, only Thread is aligned with CC and EUCC certification schemes. Achieving compliance for Zigbee and Z-Wave will require protocol hardening and stricter cryptographic key lifecycle management. Aligning IoT protocols with CC is essential for building trust and resilience in critical connected systems.

Keywords
IoT Security
Thread Protocol
Zigbee
Z-Wave
Common Criteria (CC)
Cryptography
Wireless Protocols
European Union Cybersecurity Certification Scheme (EUCC)
Poster
ASEC2025-sciforum-150922_ver006_Final.pdf
IoT and AI-Driven Approaches for Energy Optimization in Off-Grid Solar Systems
Integration of Deep Learning Methods into the Design of Microwave Transceiver Components for 5G Mid-Band System