Seguridad y vulnerabilidades de dispositivos IOT LORAWAN frente a interferencias y ataques de radiofrecuencia con FLIPPER ZERO
Files
Date
2026-01
Authors
Journal Title
Journal ISSN
Volume Title
Publisher
Universidad Técnica de Ambato. Facultad de Ingeniería en Sistemas Electrónica e Industrial. Carrera de Telecomunicaciones
Abstract
This thesis conducts a comprehensive analysis of security in an IoT environment using LoRa and LoRaWAN technology, applied to a real system consisting of IoT nodes, a LoRaWAN gateway, and a backend infrastructure developed with ChirpStack. The analysis seeks to detect vulnerabilities related to cryptographic management, access control, wireless communication, and interface exposure, taking into account the threats inherent in LPWAN networks and the guidelines established by OWASP IoT Top 10.
The methodology used consists of four stages: designing and implementing a controlled test environment, which includes setting up a LoRaWAN server on a Linux virtual machine, integrating nodes, and configuring an operational gateway; conducting communication tests, validating RF parameters, and functionally analyzing the IoT system; employing methods to evaluate security using techniques such as sniffing, replay, interference, and passive analysis with Flipper Zero and SDR equipment; classifying the risk and devising measures to mitigate it based on telecommunications standards and engineering best practices.
The findings show that there are serious vulnerabilities in unencrypted LoRa links, that LoRaWAN metadata is exposed, that there are fingerprinting risks, weaknesses in key management, and susceptibility to RF attacks such as replay and jamming. Based on these findings, a technical mitigation guide is developed with the aim of strengthening the confidentiality, integrity, and availability of the IoT system. To this end, suggestions are made regarding encryption, authentication, physical control, firmware hardening, and spectrum monitoring.
This study helps to understand and strengthen security in Internet of Things solutions based on LPWAN technologies.
Description
Este trabajo de titulación realiza un análisis exhaustivo de la seguridad en un entorno IoT que utiliza tecnología LoRa y LoRaWAN, aplicado a un sistema auténtico que consta de nodos IoT, una puerta de enlace LoRaWAN y una infraestructura backend desarrollada con ChirpStack. El análisis busca detectar vulnerabilidades relacionadas con la gestión criptográfica, el control de acceso, la comunicación inalámbrica y la exposición de interfaces, tomando en cuenta las amenazas propias de las redes LPWAN y las pautas establecidas por OWASP IoT Top 10.
La metodología utilizada consta de cuatro etapas: el diseño y la puesta en marcha de un entorno de pruebas controlado, que incluye establecer un servidor LoRaWAN en una máquina virtual Linux, integrar nodos y configurar un gateway operativo; llevar a cabo pruebas de comunicación, validar parámetros RF y analizar funcionalmente el sistema IoT; emplear métodos para evaluar la seguridad mediante técnicas como sniffing, replay, interferencia y análisis pasivo con equipos Flipper Zero y SDR; clasificar el riesgo e idear medidas para mitigarlo basándose en estándares de telecomunicaciones y buenas prácticas ingenieriles.
Los hallazgos muestran que existen vulnerabilidades serias en los enlaces LoRa sin cifrar, que la metadata de LoRaWAN está expuesta, que hay peligros de fingerprinting, debilidades en la administración de claves y una susceptibilidad a ataques RF como el replay y el jamming. Basándose en estos descubrimientos, se elabora una guía técnica de mitigación con el objetivo de reforzar la confidencialidad, integridad y disponibilidad del sistema IoT. Para ello, se dan sugerencias sobre el cifrado, la autenticación, el control físico, el endurecimiento del firmware y la supervisión del espectro.
Keywords
LORAWAN, SEGURIDAD IOT, VULNERABILIDAD, RF, FLIPPER ZERO