Authenticated Rejected / impersonation blocked Compromised device
drag to rotate · scroll to zoom

IoT Device Authentication 2D: PSK vs Certificate vs TPM

A ring of IoT devices continuously authenticates against a central gateway using one of three real-world credential models — a shared pre-shared key, a software-held X.509 certificate, or a private key sealed inside a TPM / secure element. Triggering a simulated credential leak marks a subset of the fleet as compromised and reveals the actual security difference between the methods: PSK and software-certificate secrets keep authenticating successfully as an attacker until the next scheduled key rotation revokes them, while a TPM/SE-backed key never leaves its hardware in the first place, so a cloned device can never complete the handshake at all. This 2D rendition adds a rotatable, zoomable flat ring diagram plus a live rolling success-rate and latency timeline strip beneath it.