On the cybersecurity of LoRaWAN-based system: a Smart-Lighting case study
Florian Hofer, Barbara Russo
TL;DR
This paper tackles cybersecurity in a LoRaWAN-based Smart-Lighting Architecture by performing iterative in-vitro and on-site experiments with multiple gateways. It systematically tests vulnerability classes (interference, exhaustion, protocol misconfigurations) and shows that most attacks are ineffective, though near-field jamming and misconfigurations can degrade performance. A key insight is that gateway redundancy and careful data-rate control markedly enhance resilience, while ABP join floods and protocol violations remain practical concerns. The study suggests practical hardening measures and future work to scale to 1000+ nodes and apply AI-driven parameter optimization to sustain security and performance in dense LoRaWAN deployments.
Abstract
Cyber-physical systems and the Internet of Things (IoT) are key technologies in the Industry 4.0 vision. They incorporate sensors and actuators to interact with the physical environment. However, when creating and interconnecting components to form a heterogeneous smart systems architecture, these face challenges in cybersecurity. This paper presents an experimental investigation of architectural configurations for a LoRaWAN-based Smart-Lighting project, aimed at verifying and improving the system's robustness against attacks. We assess the system's robustness in a series of iterative experiments conducted both in-vitro and on-site. The results show that most attacks on a LoRaWAN network are unsuccessful, also highlighting unresolved issues with the installed products. The most successful attacks are high-power jamming attacks within a few meters of the target, which, in the case of gateways, can be mitigated through gateway redundancy.
