IoT Device Authentication 2D: PSK vs Certificate vs TPM
Interactive 2D diagram of IoT fleet authentication: watch pre-shared keys, X.509 certificates and TPM/secure-element keys handshake against a gateway, trigger a credential-leak attack, and see scheduled key rotation revoke stolen secrets in real time on a rotatable ring view with a live success-rate timeline.
A ring of IoT devices continuously authenticates against a central gateway using one of three real-world credential models — a shared pre-shared key, a software-held X.509 certificate, or a private key sealed inside a TPM / secure element. Triggering a simulated credential leak marks a subset of the fleet as compromised and reveals the actual security difference between the methods: PSK and software-certificate secrets keep authenticating successfully as an attacker until the next scheduled key rotation revokes them, while a TPM/SE-backed key never leaves its hardware in the first place, so a cloned device can never complete the handshake at all. This 2D rendition adds a rotatable, zoomable flat ring diagram plus a live rolling success-rate and latency timeline strip beneath it.
Interactive 2D diagram of an IoT device fleet authenticating against a gateway with pre-shared keys, X.509 certificates or TPM/secure-element-backed keys, showing how a simulated credential leak stays exploitable until scheduled key rotation revokes it — except for TPM-sealed keys, which are never exposed at all. A rotatable, zoomable ring view sits above a live rolling success-rate and latency timeline.
2D · HTML5 Canvas 2D · 60 FPS target · runs fully client-side, no install