mioty security works on two layers. The network layer is mandatory: every message between an end point and a base station is encrypted with AES-128 in counter mode and signed with a CMAC, using a network key that is registered and managed by the Service Center. On top of that, an application layer is optional: a second, independent AES-128 encryption using a separate application key that the network itself never holds, so payloads can stay unreadable to the network operator and only be decrypted in the customer’s Application Center. Both mechanisms are specified in the alliance’s dedicated security guideline and, for the application layer, in the Application Layer Specification, so certified products from different manufacturers apply the same protections.

