Skip to content

Login  |  Sign Up

Ask the Quexperts: What are the biggest security challenges in SoC-based IoT devices, and how are they mitigated?

System-on-chip (SoC)-based IoT devices face a growing array of security challenges, all of which have a significant impact on the safety, performance, and reliability of connected devices and services. As the number of IoT devices in operation has grown to tens of billions, the potential for IoT security vulnerabilities has widened, while those IoT devices have also incorporated richer features and capabilities, raising the stakes. SoCs now combine computing, connectivity, and OS functionality, so security should not be an afterthought. It must be designed into the hardware and software from the very beginning to create the defense-in-depth that our connected world depends upon.

The larger volume of IoT devices in deployment has resulted in more entry points across cellular, Wi-Fi, Bluetooth, and GNSS as well as USB, camera, and display interfaces. In addition, the adoption of Android and Linux-based SoCs, modules, and smart devices that can run complex software stacks has increased potential vulnerabilities because expanded on-device capabilities allow malicious actors to cause more damage.

While greater on-device functionality can create expanded vulnerability, modern approaches to device design are eliminating traditional points of weakness. Intelligent industrial edge devices, for example, can utilize smart modules to reduce the number of integrations between different components that can create vulnerabilities. Having fewer components enables simpler security management in comparison to stitching together security across multiple hardware platforms.

Another challenge is unauthorized firmware and malware. Attackers routinely attempt to replace firmware or boot malicious software. Once compromised, this gives them full device control. In a smart payment terminal, this can result in payment information being hacked by criminals. This can be prevented with Secure Boot, which verifies firmware authenticity before executing a task, establishing a trusted boot chain with a hardware root of trust, and preventing unauthorized firmware from loading.

Secure wireless communication

Interception of data is increasingly seeing sensitive telemetry, video, commands, and credentials being accessed, and a growing number of man-in-the-middle attacks. These can be mitigated with devices that support secure wireless communication such as TLS and secure communication protocols, usage of modern Wi-Fi security such as WPA2 and WPA3, and accelerated hardware encryption.

It’s not only the device and connectivity that are under threat. Vulnerable applications are introducing unsecured APIs, excessive permissions, third-party libraries, and Android and Linux applications, bringing new vulnerabilities to address. In medical devices, for example, sensitive patient data might become accessible because of one of these weaknesses. What’s needed are stable smart module platforms that support secure application development. In addition, developers and engineers should continue to focus on implementing secure coding practices.

Relevant resources

The pace at which IoT is developing is also being mirrored by bad actors and with many IoT devices expected to be in operation for many years, it’s essential to address security for the entire device lifecycle. Inevitably, new vulnerabilities will emerge after devices are deployed, so updates are needed. A fleet management terminal is likely to be embedded in a vehicle for its operational life, so new threats will emerge throughout its lifespan. These threats can be guarded against by updates to secure firmware, provision of security patches throughout the product lifecycle, and sustained collaboration with ecosystem partners on vulnerability management.

The supply chain is also a source of vulnerabilities with counterfeit hardware, third-party weaknesses and compromised software dependencies, all posing significant threats. Developers should put in place secure hardware and software supply chain processes, ensure component traceability and trusted manufacturing are enabled, and close the loop with a strong vulnerability disclosure process.

Quectel, for example, has partnered with US-based cybersecurity firm Finite State, a leader in product security and software supply chain risk management, improved visibility and comprehensive software risk management. The partnership helps ensure Quectel’s product suite is compliant and secure, with emphasis on transparency, regulatory compliance, and maintaining industry-leading standards of security.

Compliance is a welcome challenge

A further challenge that should be welcomed is the growing volume of security-related regulations, such as the EU Cyber Resilience Act (CRA) and the NIST Cybersecurity Framework 2.0 in the USA. Although these and other regulations present a burden in the form of increased global cybersecurity regulations, secure-by-design requirements, and device lifecycle management, they help enhance security. Designers should ensure their security capabilities support compliance efforts. Security should be designed-in to module platforms, and this should be backed up with documentation and engineering support.

Quectel has ensured its product portfolio is ready for the CRA ahead of the September 2026 deadline. Quectel’s best-practice product security ensures customers can meet the Act’s mandatory requirements across security by design, secure bill of materials (SBOM) availability, and vulnerability disclosure and incident reporting. The company has again worked with Finite State to support its CRA readiness and product security transparency.

Relevant resources

One of the largest threats is misconfiguration. Devices that offer effective security features are left weakened because features are never enabled. Default passwords are left in place, there is poor certificate management, and unused services are left inactive, thereby providing opportunities for vulnerabilities to be exploited. These issues can be mitigated with technical documentation, application notes, engineering support, and guidance on how to implement security features correctly.

Defense-in-depth

Apart from the regulatory environment, technical and operational support for security is maturing rapidly. IoT devices are no longer going into deployment unarmed, but to achieve this, a defense-in-depth strategy is essential to meet the shared responsibility of end-to-end security in IoT. Smart modules can provide the foundational security capabilities OEMs need, so they can build better pervasive security spanning across hardware, firmware, operating systems, applications, communications, updates, and cloud infrastructure.