Embedded SystemUnit 99 min read

IoT Systems: Architecture, Protocols, Applications & Security

Unit 9 of Embedded System explores the Internet of Things (IoT) ecosystem, covering its layered architecture, communication protocols (MQTT, CoAP, LoRaWAN), cloud-edge-fog computing trade-offs, security challenges (encryption, DDoS), and real-world deployments like smart cities, industrial automation, and healthcare mo

Key Concepts and IoT Architecture

1. Definition and Core Components

IoT (Internet of Things) refers to a network of physical objects ("things") embedded with sensors, software, and connectivity to collect and exchange data. The three core components are:

  • Sensing Layer: Devices with sensors/actuators (e.g., temperature sensors, motion detectors).
  • Networking Layer: Protocols and gateways (e.g., Wi-Fi, Bluetooth, cellular).
  • Processing Layer: Cloud/edge servers for data storage and analytics.
graph TD
    A["Sensing Layer\n(Sensors/Actuators)"] --> B["Networking Layer\n(Protocols/Gateways)"]
    B --> C["Processing Layer\n(Cloud/Edge/Fog)"]
    C --> D["Application Layer\n(Dashboards/ML Models)"]
    D -->|"Feedback"| A

2. IoT Communication Protocols

Protocols determine how devices communicate. Compare the most common ones:

Protocol Use Case Data Rate Power Consumption Range Example Use in Nepal
MQTT Lightweight messaging (cloud) Low Very Low LAN/WAN eSewa’s smart meter readings
CoAP Constrained devices (RESTful) Low Low LAN Home automation (e.g., Philips Hue)
LoRaWAN Long-range, low-power (LPWAN) Very Low Extremely Low 10+ km NTC’s smart grid monitoring
Zigbee Mesh networking (home/office) Medium Low 10–100 m Smart lighting in hotels
NB-IoT Cellular-based (low bandwidth) Low Medium National Ncell’s asset tracking

Worked Example: MQTT in a Smart Farm A farmer in Chitwan uses an Arduino-based soil moisture sensor connected to an MQTT broker (e.g., Mosquitto). When soil moisture drops below 30%, the sensor publishes a message:

{
  "topic": "farm/soil_moisture",
  "payload": {"location": "field_A", "value": 25, "timestamp": "2024-05-20T14:30:00"}
}

The broker forwards this to a cloud dashboard, triggering an automated irrigation system via a relay module.


3. Cloud vs. Edge vs. Fog Computing

IoT systems often use a mix of these paradigms to balance latency, bandwidth, and cost.

Feature Cloud Computing Edge Computing Fog Computing
Location Remote data centers Device/nearby gateway Intermediate (e.g., routers)
Latency High (ms–s) Ultra-low (µs–ms) Low (ms)
Bandwidth High Minimal Moderate
Use Case Large-scale analytics Real-time control (e.g., drones) Local processing (e.g., traffic lights)

Real-World Tie-In: Pathao’s Ride-Hailing Pathao uses edge computing to process driver location and passenger requests locally on smartphones. This reduces latency for real-time route optimization, even in Kathmandu’s congested traffic. The system offloads only aggregated data (e.g., heatmaps of demand) to the cloud for analytics.


4. IoT Security Challenges

Security is critical due to IoT’s distributed nature. Key threats and mitigations:

A. Common Vulnerabilities

  1. Weak Authentication: Default passwords (e.g., "admin/admin").
  2. Unencrypted Data: Sensitive data transmitted in plaintext.
  3. DDoS Attacks: Botnets of compromised devices (e.g., Mirai malware).
  4. Physical Tampering: Unauthorized access to sensors/actuators.

B. Security Layers

Layer Security Measure Example in Nepal
Device Hardware root of trust (HRoT), secure boot Ncell’s eSIM authentication
Network TLS/SSL, VPNs Khalti’s encrypted transactions
Cloud Zero-trust architecture, IAM policies Daraz’s warehouse inventory DB
Application Input validation, rate limiting NEPSE’s stock trading API

Worked Example: Securing a Smart Grid NTC deploys LoRaWAN for smart meters but faces risks of signal jamming. To mitigate:

  • Encryption: AES-128 for meter-to-gateway communication.
  • Authentication: Pre-shared keys (PSK) for devices.
  • Anomaly Detection: Edge nodes flag sudden power draw spikes (e.g., theft).

5. IoT Applications in Nepal

A. Smart Cities

Project: Kathmandu’s Smart Traffic Management System

  • Technology: IoT sensors (inductive loops, cameras) + edge computing.
  • How It Works:
    1. Sensors detect vehicle density at intersections.
    2. Edge gateways (Raspberry Pi clusters) adjust traffic light timings in real-time.
    3. Cloud analytics predict congestion hotspots.
  • Impact: Reduced travel time by 20% in Thapathali during peak hours.

B. Healthcare: Remote Patient Monitoring

Example: eSewa’s Telemedicine Partnerships

  • Device: Wearable ECG sensor (e.g., Zephyr BioHarness) transmits data via Bluetooth Low Energy (BLE) to a smartphone.
  • Protocol: MQTT for lightweight messaging to a hospital server.
  • Use Case: A patient in Pokhara with hypertension monitors vitals; alerts are sent to a cardiologist in Kathmandu if BP exceeds 160/100 mmHg.

C. Agriculture: Precision Farming

Example: FarmLogs (Nepal)

  • Sensors: Soil moisture (FC-28), temperature (DS18B20), humidity (DHT22).
  • Actuators: Automated irrigation valves.
  • Protocol: LoRaWAN for long-range farm coverage.
  • Worked Trace:
    1. Sensor detects soil moisture = 15% (dry).
    2. Arduino publishes MQTT message to cloud.
    3. Cloud triggers relay to open valve for 10 minutes.

6. Designing an IoT System: Step-by-Step

Use this checklist to design a robust IoT solution:

  1. Define Requirements

    • What data to collect? (e.g., temperature, motion)
    • Latency tolerance? (e.g., <100ms for drones)
    • Power constraints? (e.g., battery vs. mains)
  2. Select Hardware

    • Microcontroller: ESP32 (Wi-Fi/BLE), STM32 (low power).
    • Sensors: DHT11 (humidity), MPU6050 (motion).
    • Actuators: Relays, servo motors.
  3. Choose Protocols

    • Short-range: BLE (low power), Zigbee (mesh).
    • Long-range: LoRaWAN (smart cities), NB-IoT (asset tracking).
  4. Security Hardening

    • Disable unused services on MCUs.
    • Use TLS 1.3 for cloud communication.
    • Implement OTA updates for firmware patches.
  5. Deploy and Monitor

    • Edge: Process data locally (e.g., anomaly detection).
    • Cloud: Store historical data (e.g., InfluxDB).
    • Alerts: SMS/email for critical events (e.g., fire alarm).

Mermaid Diagram: IoT System Design Flow

flowchart TD
    A["1. Define Requirements"] --> B["2. Select Hardware\n(MCU, Sensors, Actuators)"]
    B --> C["3. Choose Protocols\n(MQTT, LoRaWAN, etc.)"]
    C --> D["4. Security Hardening\n(Encryption, Auth)"]
    D --> E["5. Deploy\n(Edge/Cloud)"]
    E --> F["6. Monitor & Maintain\n(Logs, Alerts)"]
    F -->|"Feedback Loop"| A

In the Real World

  1. eSewa’s IoT Integration

    • Idea Used: MQTT + Cloud Analytics
    • How: eSewa partners with smart meters to publish electricity usage data every 15 minutes. The MQTT broker aggregates this to predict peak demand, enabling dynamic pricing (e.g., lower rates at night).
  2. NTC’s Smart Grid Pilot

    • Idea Used: LoRaWAN + Edge Processing
    • How: In Butwal, NTC deploys LoRaWAN-enabled transformers to detect faults. Edge nodes (Raspberry Pi) analyze voltage spikes locally, reducing cloud dependency and latency.
  3. Pathao’s Driver Safety

    • Idea Used: GPS + Cellular IoT (NB-IoT)
    • How: Pathao’s app uses NB-IoT to transmit driver location and speed to a central server. If speed exceeds 80 km/h, the system flags the driver and notifies dispatch for retraining.

Exam Tip

  1. Architecture Questions

    • Always draw the 4-layer IoT stack (sensing → networking → processing → application) with arrows for data flow.
    • Compare MQTT vs. CoAP vs. LoRaWAN in a table (use the one above as a template).
  2. Protocol Selection

    • Low power? → LoRaWAN/NB-IoT.
    • Real-time control? → MQTT or Zigbee.
    • High bandwidth? → Wi-Fi or cellular.
  3. Security

    • Weakest link: Often the device layer (default passwords, unpatched firmware).
    • Mitigation: Always mention encryption (AES/TLS), authentication (PSK/X.509), and secure boot.
  4. Worked Examples

    • For MQTT, show a JSON payload with topic, payload, and timestamp.
    • For edge computing, explain how data is processed before sending to the cloud (e.g., filtering noise from sensor data).
  5. Nepal-Specific Applications

    • Smart grid: NTC’s LoRaWAN meters.
    • Healthcare: eSewa’s telemedicine wearables.
    • Agriculture: FarmLogs’ precision farming.
    • Traffic: Kathmandu’s IoT-enabled traffic lights.

Common Pitfalls to Avoid

  • Forgetting to mention power constraints in IoT design (e.g., battery life for sensors).
  • Ignoring latency in real-time systems (e.g., drones require edge processing).
  • Overlooking security—examiners love questions on DDoS, weak auth, and unencrypted data.

Based on the PU BE Computer (PU) syllabus for Embedded System (ELX320), unit 9.

Discussion

Loading…