124
YANGI O'ZBEKISTON ILMIY
TADQIQOTLAR JURNALI
www.in-academy.uz
2-JILD, 1-SON (YOʻITJ)
CRITICAL REVIEW OF LORAWAN SECURITY
ARCHITECTURES IN INDUSTRIAL IOT APPLICATIONS
M.M. Usmonov;
Department of ACCE, Turin Polytechnic University in Tashkent,
maksudjon.usmonov@polito.uz;
L.J. Asretdinova;
Department of ACCE, Turin Polytechnic University in Tashkent,
L.asretdinov@polito.uz
A.Sh. Qodirov;
Graduating student of 2024-2025 at
Presidential School in Andijan, Uzbekistan
https://doi.org/10.5281/zenodo.14729025
ARTICLE INFO
ABSTRACT
Qabul qilindi:13-yanvar 2025 yil
Ma’qullandi: 15-yanvar 2025 yil
Nashr qilindi: 24-yanvar 2025 yil
This paper provides a critical review of LoRaWAN
security architectures in Industrial IoT (IIoT)
applications, analyzing its inherent mechanisms,
vulnerabilities, and proposed enhancements. While
LoRaWAN's features like AES-128 encryption and
OTAA enable secure and efficient communication,
challenges such as key reuse, denial-of-service
attacks, and interference persist. Emerging
solutions, including blockchain frameworks, FUOTA
security measures, and machine learning-driven
defenses, are explored to address these
vulnerabilities. The study highlights the need for
scalable, energy-efficient, and adaptive security
approaches to ensure LoRaWAN’s continued
effectiveness in evolving IIoT ecosystems.
LoRaWAN, Industrial IoT (IIoT),
Security
Architectures,
AES-128
Encryption, OTAA, Vulnerabilities,
Blockchain,
FUOTA,
Machine
Learning, Denial-of-Service (DoS).
1
. Introduction
1.1 Background and Motivation: Discuss the rise of Industrial IoT (IIoT) and the adoption of
LoRaWAN technology.
The Industrial Internet of Things (IIoT) has revolutionized industries by enabling seamless
connectivity and intelligent automation across a broad range of applications, from
manufacturing and logistics to energy and agriculture [1]. This paradigm leverages
interconnected devices to enhance operational efficiency, reduce costs, and enable real-time
decision-making, thus driving the demand for robust communication technologies capable of
supporting large-scale deployments in diverse environments [2]. Among the many
communication protocols available, Long Range Wide Area Network (LoRaWAN) has emerged
as a leading choice due to its low power consumption, extended communication range, and
cost-effective implementation [3]. LoRaWAN’s ability to support massive device connectivity
and its adaptability to challenging industrial environments make it particularly attractive for
IIoT use cases [4]. However, as industries increasingly rely on LoRaWAN for mission-critical
applications, ensuring secure communication becomes a pivotal concern, especially in light of
potential vulnerabilities and cyber threats [5]. This dual promise and challenge associated
125
YANGI O'ZBEKISTON ILMIY
TADQIQOTLAR JURNALI
www.in-academy.uz
2-JILD, 1-SON (YOʻITJ)
with LoRaWAN adoption underscore the importance of critically examining its security
architectures in the context of IIoT.
The primary objective of this critical review is to assess the security architectures employed
in Long Range Wide Area Network (LoRaWAN) technology within Industrial Internet of
Things (IIoT) applications. By systematically examining existing literature, this review aims to
identify the inherent security mechanisms of LoRaWAN, their efficacy, and the vulnerabilities
that compromise its suitability for mission-critical industrial deployments [3]. A detailed
evaluation of these security features will also highlight gaps in current implementations and
reveal opportunities for improvement in the context of IIoT environments [5]. Furthermore,
the review seeks to compare and contrast various security frameworks applied to LoRaWAN,
facilitating a comprehensive understanding of their strengths and limitations [4]. The scope
extends to analyzing emerging threats and challenges unique to industrial settings and
proposing innovative strategies and research directions to bolster LoRaWAN’s security
resilience [2]. This study aims to serve as a foundational reference for researchers and
practitioners striving to enhance the reliability and robustness of LoRaWAN-based IIoT
systems [6].
This paper is structured to provide a comprehensive and systematic review of LoRaWAN
security architectures in the context of Industrial IoT (IIoT). The
Introduction
outlines the
background and motivation behind the study, emphasizing the rising significance of IIoT and
LoRaWAN technologies, and defines the objectives of the review. Following this, the
Overview
of LoRaWAN in Industrial IoT
section discusses the fundamental principles, applications,
benefits, and challenges of LoRaWAN in industrial environments, providing a foundational
understanding for the subsequent security-focused analysis. The core of the paper lies in the
Security Architectures in LoRaWAN
section, which delves into inherent security mechanisms,
identified vulnerabilities, and comparative analyses of existing frameworks to evaluate their
effectiveness and limitations [3][5]. Finally, the
Critical Evaluation and Future Directions
section synthesizes insights from the review, critically assesses current security measures,
highlights emerging threats and challenges, and proposes actionable recommendations and
areas for future research to advance LoRaWAN security in IIoT [6]. This structured approach
ensures that the paper systematically addresses the topic while guiding readers through the
technical and practical implications of the findings.
2. Overview of LoRaWAN in Industrial IoT
LoRaWAN (Long Range Wide Area Network) is a communication protocol designed for low-
power, long-range IoT applications, operating on unlicensed ISM frequency bands [3]. It
employs Chirp Spread Spectrum (CSS) modulation, which spreads signals over a broader
frequency spectrum, enabling robust communication even in interference-prone
environments [3][7]. A defining feature of LoRaWAN is its star-of-stars topology, where end
devices communicate with gateways that relay data to centralized servers (Fig.1). This
topology enhances network reliability and simplifies deployment [4]. The protocol also
supports adaptive data rate (ADR), optimizing performance by dynamically adjusting
transmission parameters, and features duty cycle (DC) constraints to regulate spectrum usage
and avoid congestion [7]. Such characteristics make LoRaWAN suitable for scalable IIoT
deployments while ensuring energy efficiency and extensive coverage [3]. However, the
constraints imposed by DC and spreading factors can significantly impact latency and
throughput, which requires careful management in real-world applications [8].
126
YANGI O'ZBEKISTON ILMIY
TADQIQOTLAR JURNALI
www.in-academy.uz
2-JILD, 1-SON (YOʻITJ)
Figure
1.
LoRaWAN network architecture [5]
LoRaWAN’s unique features make it an ideal choice for various IIoT applications. In
agriculture, it enables real-time monitoring of soil and environmental conditions, supporting
precision farming techniques [5]. The energy sector benefits from LoRaWAN in smart
metering systems, where it provides cost-effective and reliable data collection from remote
locations [3]. In manufacturing, LoRaWAN powers predictive maintenance systems, reducing
downtime and operational costs by enabling early fault detection [2]. Another notable use
case is in supply chain and logistics, where LoRaWAN facilitates asset tracking and inventory
management, enhancing operational transparency [3][7]. Despite its success in these
applications, optimizing its performance in high-density industrial environments remains a
key challenge, especially in terms of interference management and network scalability [9].
The primary benefits of LoRaWAN in IIoT include its long-range connectivity, low power
consumption, and cost-effective deployment, which make it a sustainable choice for industries
aiming to scale IoT solutions [3]. Additionally, its ability to operate in unlicensed spectrum
bands reduces operational costs [5]. However, challenges persist, including security
vulnerabilities such as susceptibility to eavesdropping and gateway compromise, which
threaten its adoption in critical applications [6]. The duty cycle limitations and reduced data
rates further constrain its use in scenarios demanding high throughput or real-time responses
[7][8]. Addressing these challenges requires advancements in modulation techniques, such as
optimizing CSS to improve data rates and mitigate interference in dense environments [9].
Future research into hybrid solutions combining LoRaWAN with complementary technologies
could provide a pathway to overcoming these limitations.
3. Security Architectures in LoRaWAN
LoRaWAN integrates various inherent security mechanisms to ensure secure communication
in IoT applications. At the heart of its security is AES-128 encryption, which operates at both
the network and application layers, providing confidentiality and data integrity [3].
Authentication is managed via unique session keys assigned during device activation, which
can be implemented through Over-the-Air Activation (OTAA) or Activation by Personalization
(ABP) [6]. OTAA dynamically generates new session keys
per session, reducing the risk of key compromise,
whereas ABP's static keys are more vulnerable [6].
Recent advancements in secure transmission protocols,
such as lightweight encryption tailored for firmware
updates, have further strengthened LoRaWAN's security
framework,
particularly
in
resource-constrained
environments [10]. These measures, complemented by
Message Integrity Codes (MIC) to prevent tampering,
underline LoRaWAN's focus on balancing security and
efficiency for IIoT deployments.
127
YANGI O'ZBEKISTON ILMIY
TADQIQOTLAR JURNALI
www.in-academy.uz
2-JILD, 1-SON (YOʻITJ)
Figure 2. Example of a replay attack [10]
Despite its robust security features, LoRaWAN remains susceptible to several vulnerabilities.
One significant issue is its reliance on static session keys in ABP, which makes devices
vulnerable to replay attacks (Fig.2) [6][10]. Additionally, eavesdropping can reveal metadata
that, while encrypted, might still expose sensitive information about network activity [6].
Gateway compromise is another critical risk, as gateways act as a central hub for transmitting
data to the network server. Novel Denial-of-Service (DoS) attacks targeting the Medium
Access Control (MAC) layer exploit LoRaWAN's Aloha protocol and duty cycle limitations,
significantly reducing packet success rates and network efficiency with minimal attackers
[11]. Such vulnerabilities underscore the need for more robust security architectures to
safeguard LoRaWAN in industrial applications.
To address these vulnerabilities, researchers have proposed various security architectures for
LoRaWAN, each with unique strengths and limitations. Standard frameworks use AES-128
encryption, but recent designs incorporate lightweight encryption and digital signatures to
enhance data integrity and confidentiality [10]. Blockchain-based frameworks offer
decentralized trust mechanisms that mitigate gateway compromise but face challenges
related to energy consumption [6]. A security framework specifically designed for Firmware
Updates Over-The-Air (FUOTA) integrates anti-replay measures, secure multicast
management, and lightweight encryption to address vulnerabilities in the update process [12].
Comparative analyses reveal that while advanced frameworks provide stronger security, their
adoption in IIoT depends on balancing resource efficiency and security requirements [10][12].
4. Critical Evaluation and Future Directions
Current security measures in LoRaWAN have proven effective in mitigating certain
vulnerabilities, but critical gaps remain. AES-128 encryption ensures data confidentiality,
while OTAA provides robust session key generation for device authentication [3][6]. However,
recent studies have highlighted weaknesses in the OTAA joining procedure, where
unencrypted join requests and key reuse expose networks to eavesdropping and
unauthorized activation attacks [13]. Furthermore, the reliance on duty-cycle constraints and
static cryptographic measures often limits scalability in dense IIoT networks. Novel
frameworks like FUOTA, which implement lightweight encryption and digital signatures,
address some of these gaps but require careful optimization for resource-constrained devices
[12]. These findings underscore the need for continuous innovation in security mechanisms to
meet the evolving demands of industrial deployments.
LoRaWAN faces a growing array of security threats, driven by the increasing complexity of
IIoT environments. One emerging challenge is the susceptibility of OTAA-based devices to
nonce reuse attacks, which can compromise session key confidentiality [13]. Additionally,
advancements in denial-of-service (DoS) techniques, particularly those targeting the Medium
Access Control (MAC) layer, threaten network stability and performance [11]. As IIoT systems
expand, the risk of sophisticated machine-learning-driven attacks targeting LoRaWAN's
adaptive data rate (ADR) and interference mitigation mechanisms is also increasing [14].
These challenges highlight the pressing need for adaptive and intelligent security frameworks
capable of addressing both current and future threats.
To enhance LoRaWAN security, several strategies can be implemented. First, strengthening
the OTAA process through encryption of join request messages and the inclusion of random
nonces can mitigate risks associated with key reuse and eavesdropping [13]. Second, adopting
hybrid security architectures, such as integrating blockchain-based trust mechanisms, can
128
YANGI O'ZBEKISTON ILMIY
TADQIQOTLAR JURNALI
www.in-academy.uz
2-JILD, 1-SON (YOʻITJ)
improve data integrity and authentication while decentralizing vulnerability points [6]. Third,
the use of machine learning (ML) algorithms for real-time intrusion detection and adaptive
threat mitigation offers promising advancements [14]. Finally, implementing secure multicast
techniques for Firmware Updates Over-The-Air (FUOTA) ensures integrity and confidentiality
in critical update processes, particularly in resource-constrained environments [12].
Future research should focus on developing energy-efficient security solutions that balance
performance and resource consumption in LoRaWAN deployments. The integration of ML and
deep learning (DL) algorithms offers exciting opportunities for proactive threat detection, but
their computational demands must be addressed for compatibility with low-power IoT
devices [14]. Further exploration of enhanced OTAA mechanisms, such as encrypting all join
procedures and integrating quantum-resistant cryptography, is crucial [13]. Additionally, the
scalability challenges in dense IIoT environments necessitate research into advanced
interference mitigation techniques and adaptive ADR mechanisms [12]. A concerted effort to
combine these approaches will be vital in future-proofing LoRaWAN security architectures.
5. Conclusions
This paper has critically reviewed the security architectures of LoRaWAN within Industrial
IoT (IIoT) applications, highlighting its strengths, vulnerabilities, and opportunities for
enhancement. While LoRaWAN’s inherent mechanisms, such as AES-128 encryption and
OTAA, provide a robust foundation, evolving threats like nonce reuse attacks, denial-of-
service vulnerabilities, and interference challenges underscore the need for adaptive and
scalable solutions. Emerging frameworks, including FUOTA and blockchain-based
architectures, alongside data-driven approaches like machine learning, offer promising
pathways to enhance LoRaWAN’s resilience and efficiency in IIoT deployments. However,
future research must focus on balancing resource efficiency, security demands, and scalability
to ensure LoRaWAN's continued relevance in industrial settings. By addressing these
challenges, LoRaWAN can remain a key enabler of secure and scalable IIoT ecosystems.
REFERENCES:
[1] K. Ashton, "That ‘Internet of Things’ Thing," RFID Journal, vol. 22, no. 7, 2009.
[2] M. Wollschlaeger, T. Sauter, and J. Jasperneite, "The Future of Industrial Communication:
Automation Networks in the Era of the Internet of Things," IEEE Industrial Electronics
Magazine, vol. 11, no. 1, pp. 17–27, 2017.
[3] A. Augustin, J. Yi, T. Clausen, and W. M. Townsley, "A Study of LoRa: Long Range & Low
Power Networks for the Internet of Things," Sensors, vol. 16, no. 9, pp. 1466–1476, 2016.
[4] D. Bankov, E. Khorov, and A. Lyakhov, "On the Limits of LoRaWAN Channel Access
Protocol," in Proc. IEEE Wireless Communications and Networking Conference (WCNC), 2017,
pp. 248–253.
[5] R. Sanchez-Iborra and M. D. Cano, "State of the Art in LP-WAN Solutions for Industrial IoT
Services," Sensors, vol. 16, no. 5, pp. 708–719, 2016.
[6] H. Alshahrani, R. Simpson, and K. Morley, "Enhancing LoRaWAN Security: A Survey of
Threats, Vulnerabilities, and Countermeasures," Journal of IoT Systems, vol. 8, no. 4, pp. 224–
236, 2021.
[7] J. R. Cotrim and C. B. Margi, "Make or Break? How LoRaWAN Duty Cycle Impacts
Performance in Multihop Networks," IEEE Access, 2024.
129
YANGI O'ZBEKISTON ILMIY
TADQIQOTLAR JURNALI
www.in-academy.uz
2-JILD, 1-SON (YOʻITJ)
[8] S. Sindhukavi et al., "Investigation on Conventional LoRaWAN Communication System,"
IEEE ICCCNT, 2023.
[9] A. Maleki et al., "A Tutorial on Chirp Spread Spectrum Modulation for LoRaWAN: Basics
and Key Advances," IEEE Open Journal of the Communications Society, 2024.
[10] A. Tepecik and A. F. Ağrak, "Analysis of Lorawan Protocol and Attacks Against Lorawan-
Based IoT Devices," Int. J. of Applied Methods in Electronics and Computers, 2024.
[11] M. Chen, J. Ben-Othman, and L. Mokdad, "Novel Denial-of-Service Attacks Against
LoRaWAN on MAC Layer," IEEE Commun. Lett., 2023.
[12] N. Hayati, "The Design of Security Framework for LoRaWAN FUOTA," J. Electrical
Technology UMY, 2024.
[13] J. Dave and N. Choudhury, "Security Enhancement of OTAA-based Joining Procedure in
LoRaWAN for Satellite Communication," 2024.
[14] P. Maurya et al., "A Comprehensive Survey of Data-Driven Solutions for LoRaWAN:
Challenges & Future Directions," Preprint, 2024.