The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →EE Times’ “Building Trust in IoT, Plus Smart Buildings with KNX” is a 27-minute, 7-second episode published January 11, 2024. Its three interviews connect secure operating systems, hardware-rooted device identity and lifecycle management, and KNX IoT for IPv6-based building automation. The useful conclusion is not that one vendor or protocol solves trust: dependable IoT requires controls from silicon and boot software through provisioning, networking, updates, commissioning and retirement.
Episode at a glance
- Program: Embedded Edge with Nitin
- Publisher: EE Times
- Episode: “Building Trust in IoT, Plus Smart Buildings with KNX”
- Published: January 11, 2024
- Running time: 27:07
- Guests: executives from ProvenRun, Crypto Quantique and Cascoda
The episode is an archival set of company interviews, not an independent benchmark or security assessment. Statements about products, partnerships, certification and performance should therefore be read as claims or descriptions by the interviewees. The original episode and transcript are available at EE Times.
IoT trust is a lifecycle, not just encryption
Encryption protects data in transit or at rest, but it does not answer every trust question. A production device also needs an identity that a cloud service, gateway or building controller can authenticate; proof that its firmware is approved; authorization for the actions it may take; and a managed way to update, revoke and retire it.
- Identity: Which physical device is communicating?
- Authenticity: Is it genuine, rather than cloned?
- Software integrity: Did it boot approved code?
- Confidentiality and integrity: Can an attacker read or alter measurements, commands or updates?
- Lifecycle control: Can operators rotate credentials, revoke a device, recover it and document its history?
- Operational trust: Does it fail safely when a cloud service, gateway or network is unavailable?
A credible workflow usually generates or installs a unique key, keeps the private key non-exportable where possible, binds it to a certificate or equivalent identity, registers the device, verifies signed firmware before execution, supports rollback and recovery, and records manufacturing and fleet events. A physical unclonable function (PUF), secure element, TPM or one-time-programmable memory can strengthen key protection, but none is a complete lifecycle strategy by itself.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
ProvenRun: reducing the trusted software base
ProvenRun’s interview focuses on foundational software rather than cloud fleet operations. The company describes ProvenCore as a product family containing a microkernel operating system, a hypervisor and trusted applications for use cases including IoT, automotive, aerospace, defense and semiconductors. A small microkernel can reduce the amount of code that must be trusted and isolate components, although it can also increase integration and certification work compared with a conventional monolithic environment.
CEO Thierry Chesnais discussed the company’s claim that its operating system achieved Common Criteria Evaluation Assurance Level 7, the highest level in that scheme. Common Criteria applies to a defined evaluated product, configuration, security target and scope; it does not automatically certify every ProvenRun product, customer integration or later software change. The interview also described work involving Renault and STMicroelectronics, which should be treated as interviewee statements unless independently confirmed.
Chesnais said the certified code base had not changed since certification and characterized that as evidence of stability. The podcast does not independently audit that assertion, and it should not be restated as proof that the software has no bugs. Certification can support a regulated procurement decision, but secure application code, hardware design, manufacturing controls, patch governance and operational monitoring remain necessary.
Rank #2
Crypto Quantique: identifying and managing real devices
Crypto Quantique’s segment addresses the point at which a device becomes a known member of a fleet. The company discusses PUFs, which derive device-specific secrets from physical characteristics of silicon. The security outcome depends on implementation, enrollment, helper data, environmental stability, resistance to physical attack and integration with the rest of the system.
Its QuarkLink platform is positioned around provisioning, certificate management, secure boot, cloud onboarding and signed over-the-air updates. Current product material describes X.509 certificates, MQTT, AWS IoT, Azure IoT Hub, private-cloud options and hardware choices including PUFs, one-time programmable storage and secure elements. These are vendor-stated capabilities that need testing on the chosen MCU, RTOS, boot chain and deployment architecture.
A practical identity and update sequence
- Generate or install a unique device key during manufacturing or first controlled boot.
- Keep the private key non-exportable when the hardware permits it.
- Issue and bind a device certificate or another authenticated identity.
- Register the device with the gateway, cloud or building-management service.
- Require authenticated firmware before execution through secure boot.
- Sign update images, verify them on-device and enforce anti-rollback policy where appropriate.
- Provide staged rollout, rollback, recovery and revocation procedures.
- Retire credentials and preserve an audit record when the device leaves service.
The episode mentioned a free or “freemium” QuarkLink Ignite offering and an earlier claim of support for up to 50 devices. That historical limit should not be assumed to remain current. The present pricing page lists Ignite as free during early access and production tiers as annual, contact-sales plans.
Rank #3
- App-Guided Install: The Kasa or Tapo app guides you through step-by-step setup. Requires neutral wiring and 2.4 GHz Wi-Fi. Consulting an electrician is recommended if you’re unfamiliar with electrical wiring
- Control from Anywhere: Monitor your light status. Turn electronics on and off from anywhere with your smartphone using the Kasa app, whether you are at home, in the office or on vacation
- Voice Control: Enjoy the hands-free convenience of controlling the lights in your home with your voice via Amazon Alexa or Google Assistant; perfect for times when your hands are full or entering a dark room
- Scheduling: Use timer or countdown schedules to set your smart switch to automatically turn on and off while you're home or away. Enable ‘away mode’ to randomly switch on and off to trick potential intruders
- Trusted and reliable: Designed and developed in silicon valley, Kasa is trusted by over 4 million users. UL certified for safety use. System Requirements: Android 5.0 or higher, iOS 10 or higher
Cascoda: bringing KNX models to IPv6 networks
KNX is an established international building-automation ecosystem spanning media such as twisted pair, radio frequency and KNXnet/IP. Cascoda’s interview explains KNX IoT as an IPv6-based extension intended to preserve KNX functional models, datapoints and commissioning concepts while reaching IP networks. Thread is one possible transport in Cascoda’s implementation; IPv6 itself is the common network layer, not a guarantee of application compatibility.
Cascoda describes an open-source KNX IoT software stack, a Thread implementation and products including a KNX IoT development kit, KNX IoT Hub, Chili module and ChiliCuisine service. Its KNX IoT material references OSCORE (Object Security for Constrained RESTful Environments) to protect messages end to end even when proxies or other intermediaries are present. Actual security still depends on onboarding, credentials, firmware, gateway configuration and commissioning.
Free tools Windows power users keep installed
One-click scans. No signup required.
A representative architecture is:
Sensor or actuator ↓ Secure hardware identity and secure boot ↓ KNX IoT device stack ↓ Thread or another IPv6 transport ↓ Thread border router / KNX IoT gateway ↓ KNX tools and building-management system ↓ Local controls, enterprise systems and optional cloud services
This is a conceptual design, not a guaranteed configuration. Thread connectivity requires a border router and suitable IPv6 backhaul. A gateway bridging legacy KNX media and IP networks is also a high-value security and availability boundary.
Rank #4
- Voice Control with Alexa & Google: Hands-free control for your whole home — just say "Alexa, turn on bedroom lights" when your hands are full, or "Hey Google, turn off all lights" before bed. Perfect for dark rooms, cooking, or when you're cozy under the covers.
- Easy DIY Installation: No electrician needed — the GHome app walks you through step-by-step wiring and setup in minutes. Fits standard wall boxes, works with existing light fixtures (no need to replace bulbs). Neutral wire required, 2.4GHz Wi-Fi only.
- Remote Control & Schedules: Check if you left the lights on from anywhere, and turn them off with one tap. Set schedules to match your routine — porch light on at sunset, bedroom light off at 11pm, or Away Mode to simulate presence while traveling.
- Whole Home Smart Lighting: Replace every switch in your house — bedroom, living room, kitchen, hallway, garage. Group controls let you turn off the entire house with one command. — Smarter than smart bulbs.
- Safe & Reliable: UL & FCC certified for safety, built with flame-retardant material and overload protection. Backed by GHome's responsive support team. Works with all standard single-pole setups — Input and output: 120V/60Hz, 15A max, 1800W rating. The cover measures 4.73"*2.76"*0.35"(120*70*8.7mm), the internal dimensions without cover are 4.1"H*1.75"W*1.34"D (104*44*34mm).
KNX IoT compared with Matter, BACnet and proprietary systems
| Technology | Primary context | Application model and commissioning | Typical strength | Important limitation |
|---|---|---|---|---|
| KNX IoT | Professional building automation and KNX-connected residential projects | KNX functional models, datapoints and established installer workflows; IPv6 transports including Thread | Continuity with installed KNX concepts and tools | Requires correct KNX modeling, commissioning, gateways and product certification |
| Matter | Consumer smart-home ecosystems | Application-layer interoperability for supported device categories and controller platforms | Simpler multi-ecosystem consumer integration | Does not replace the full engineering and commissioning workflow of KNX buildings |
| BACnet | Commercial building-management systems, especially prevalent in North America | Building-control objects and BMS engineering practices | Deep installed base in commercial facilities | KNX and BACnet still need compatible models, gateways and security policies to interoperate |
| Proprietary platforms | Vendor-specific buildings or smart-home products | Vendor tools, APIs and cloud or controller workflows | Potentially integrated deployment from one supplier | Lock-in, migration risk and uncertain interoperability outside that ecosystem |
A building may contain KNX, BACnet, Modbus, DALI and proprietary controllers simultaneously. Cascoda’s interview mentions KNX/BACnet interoperability and a Siemens demonstration; that is evidence of a described integration, not a blanket assessment of every gateway or deployment. “IP-based” likewise does not mean that two systems share semantics, authorization, commissioning or fail-safe behavior.
Security and resilience in a KNX IoT deployment
- Authenticate devices and controllers during onboarding.
- Protect commands and measurements against eavesdropping, alteration, replay and impersonation.
- Use secure boot and signed firmware updates for sensors, actuators, hubs and border routers.
- Segment legacy KNX media, IP networks and enterprise systems appropriately.
- Define local behavior when cloud services or the backhaul fail.
- Document credential ownership, rotation, revocation and recovery.
- Test lighting, HVAC, access-control and other safety-relevant failure modes.
Neither IPv6 nor Thread automatically makes a building secure, and KNX IoT does not automatically inherit the security or reliability of every legacy KNX installation. Commissioning quality, physical access controls, gateway maintenance and long-term firmware support are as important as protocol selection.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What to evaluate before buying
Secure operating-system approach
- Does the required certification apply to the exact hardware, configuration and software version?
- Can the team meet real-time, debugging, isolation and Linux/RTOS integration requirements?
- Who maintains the evaluated configuration after patches and feature changes?
- What are the vendor-support, tooling and portability implications?
Identity and lifecycle platform
- Are keys generated on-device, injected in manufacturing or held by a secure element, PUF, OTP or TPM?
- Can private keys, certificates, metadata and fleet records be exported?
- How do secure boot, signing, staged rollout, rollback and recovery work on the target silicon?
- Are PKI, HSM, private-cloud, data-residency, audit and compliance requirements covered?
- What happens when the contract ends or a device must be revoked?
KNX IoT project
- Is there an existing KNX base to preserve, and is ETS or another commissioning route required?
- Which media, border routers, gateways and backhaul are needed?
- Are certified products, installers and long-term support available in the project region?
- How will KNX coexist with BACnet, Modbus, DALI, HVAC controllers and enterprise BMS software?
- What are the local-control, outage and recovery requirements?
Commercial tools mentioned in the episode’s technology context
QuarkLink
Crypto Quantique positions QuarkLink for provisioning, certificate lifecycle management, secure boot, onboarding and OTA operations. Review the provisioning and OTA pages against the exact hardware and cloud architecture. The current pricing page shows early-access Ignite and contact-sales production plans; no public production price is stated there.
Best Value
- Ground Fault Circuit Interrupters
Cascoda development kit and ChiliCuisine
The KNX IoT development kit is described as two development boards, a KNX IoT Hub, antenna, cables and power supply, with distribution handled through distributors. It is for prototyping, not proof that a finished product is certified for field deployment. ChiliCuisine accepts a JSON-described application and can generate device outputs, documentation, update manifests and a software bill of materials; pricing is available on request. Its convenience may also increase dependence on Cascoda hardware and service tooling. The KNX tutorial lists the practical workflow and prerequisites at KNX support.
ETS and certification costs
KNX’s ETS pricing section and its stack-fee reference are useful starting points. The surfaced fee schedule lists €600 for registration of a new stack on a particular MCU brand/type and €30 for one same-family case. Those amounts are not a complete estimate of engineering, testing, accredited-lab, membership, tooling or product-certification costs.
Bottom line
The EE Times episode’s durable lesson is architectural. Secure execution, hardware-backed identity, authenticated updates, IPv6 building networks and KNX semantics solve different parts of the trust problem. A trustworthy IoT or smart-building system connects them with disciplined manufacturing, commissioning, authorization, monitoring, recovery and retirement—and validates every vendor claim against the exact product configuration and operating environment.
Frequently Asked Questions
Is the EE Times episode a current product comparison?
No. It is a January 11, 2024 interview episode. It provides vendor perspectives and technical context, not independent benchmarks, vulnerability testing or total-cost comparisons.
Does KNX IoT replace Matter or BACnet?
No. KNX IoT extends KNX models and workflows over IPv6, while Matter targets supported consumer smart-home categories and BACnet remains deeply established in commercial building management. Gateways and integration layers may be needed.
Does a PUF by itself secure an IoT device?
No. A PUF can help derive a device-unique secret, but secure enrollment, key handling, secure boot, authorization, updates, revocation and operational monitoring are still required.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




