Authenticated Rejected / impersonation blocked Compromised device
⚠ Couldn't load the 3D engineThree.js failed to load from the CDN. Check your connection and reload.

IoT Device Authentication: PSK vs Certificate vs TPM

A ring of IoT devices continuously authenticates against a central gateway using one of three real-world credential models — a shared pre-shared key, a software-held X.509 certificate, or a private key sealed inside a TPM / secure element. Triggering a simulated credential leak marks a subset of the fleet as compromised and reveals the actual security difference between the methods: PSK and software-certificate secrets keep authenticating successfully as an attacker until the next scheduled key rotation revokes them, while a TPM/SE-backed key never leaves its hardware in the first place, so a cloned device can never complete the handshake at all. Live readouts track authentication success rate, handshake latency and the countdown to the fleet's next key-rotation cycle.