How unit 5 is examined
Unit 5 covers IoT platforms, analytics, cloud and communication APIs, IoT attacks, and case studies; the marks sit in communication APIs and the home intrusion detection design.
IoT Platforms, Arduino, Raspberry Pi Board, Other IoT Platforms
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>
Definition. <mark>An IoT platform is the hardware and software base that connects devices, collects their data and runs applications on it.</mark>
Key points.
- Arduino is an open-source microcontroller board (ATmega328P on the Uno) that reads sensors and drives actuators, and it has no operating system.
- Raspberry Pi is a credit-card-sized Linux computer with a processor, RAM, USB, camera port, Wi-Fi and GPIO pins, so it can run Python, servers and a webcam.
- Arduino is programmed in C/C++ through the Arduino IDE, has analog inputs and digital pins, and suits simple real-time sensing.
- Other platforms are ESP8266/ESP32 (cheap Wi-Fi boards), BeagleBone and cloud platforms such as AWS IoT and ThingSpeak.
| Point | Arduino | Raspberry Pi |
|---|---|---|
| Type | Microcontroller board | Single-board computer |
| OS | None | Linux (Raspberry Pi OS) |
| Language | C/C++ | Python, C, Java |
| Networking | Needs a shield or module | Built-in Ethernet and Wi-Fi |
| Use | Simple sensing and control | Gateway, camera, servers |
Data Analytics for IoT, Cloud for IoT, Cloud storage models & communication APIs
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Low weight</span>
Definition. <mark>An IoT communication API is an interface through which devices, gateways and cloud applications exchange data using a defined protocol.</mark>
Key points.
- REST API is built on HTTP and treats each resource as a URL, using GET, POST, PUT and DELETE; it is stateless and follows the request-response model.
- WebSocket API keeps one full-duplex TCP connection open, so the server can push data instantly without repeated requests, which suits live dashboards.
- Request-response suits on-demand reads such as fetching a sensor value; publish-subscribe (MQTT) suits continuous telemetry, because devices publish to a broker and subscribers receive it.
- Data analytics for IoT turns raw sensor streams into decisions; it is descriptive (what happened), predictive (what will happen) and prescriptive (what to do), run at the edge for speed or in the cloud for scale.
- Cloud for IoT gives elastic storage, processing and dashboards, so devices need not store data locally; examples are AWS IoT, Azure IoT Hub and ThingSpeak.
- Cloud storage models are object storage (files and images), time-series or NoSQL databases (sensor readings) and relational databases (device records).
- Both APIs must be secured with HTTPS/TLS and tokens, since they expose devices to the internet.
| Point | REST | WebSocket |
|---|---|---|
| Connection | New HTTP request each time | One persistent connection |
| Direction | Client asks, server replies | Both sides send at any time |
| Overhead | Header on every request | Low after handshake |
| Best for | Occasional reads and commands | Live streaming data |
Diagram.
<figure class="ds-fig" style="margin:1.4rem 0;overflow-x:auto"><svg xmlns="http://www.w3.org/2000/svg" id="dsfig-u5-01" viewBox="0 0 424 80" width="424" height="80" role="img" aria-label="Publish-subscribe. Dev = IoT device, Brk = broker, App = subscribed application"><style>#dsfig-u5-01 .e{stroke:#454C5A;stroke-width:1.4;fill:none}#dsfig-u5-01 .e.hi{stroke:#2340B8;stroke-width:2.6}#dsfig-u5-01 .n{fill:#FFFFFF;stroke:#16181D;stroke-width:1.4}#dsfig-u5-01 .n.hi{fill:#E3E9FC;stroke:#2340B8;stroke-width:2.2}#dsfig-u5-01 .n.rb-b{fill:#16181D;stroke:#16181D}#dsfig-u5-01 .n.rb-r{fill:#BD3227;stroke:#BD3227}#dsfig-u5-01 text{font-family:"JetBrains Mono",ui-monospace,Menlo,Consolas,monospace;font-size:13px}#dsfig-u5-01 .t{fill:#16181D;font-weight:500}#dsfig-u5-01 .t.inv{fill:#FFFFFF;font-weight:700}#dsfig-u5-01 .kd{stroke:#16181D;stroke-width:1.2}#dsfig-u5-01 .dot{fill:#16181D}#dsfig-u5-01 .ann{fill:#2340B8;font-size:11px;font-weight:700}#dsfig-u5-01 .lbl{fill:#6F7787;font-family:system-ui,-apple-system,sans-serif;font-size:12px;font-weight:700}#dsfig-u5-01 .ptr{fill:#2340B8;font-size:12px;font-weight:700}#dsfig-u5-01 .ah{fill:#454C5A}#dsfig-u5-01 .ah.hi{fill:#2340B8}#dsfig-u5-01 .wl rect{fill:#FFFFFF;stroke:#DCE0E7}#dsfig-u5-01 .wl .t{font-size:12px;font-weight:700}#dsfig-u5-01 .wl.hi rect{fill:#2340B8;stroke:#2340B8}#dsfig-u5-01 .wl.hi .t{fill:#FFFFFF}html.dark #dsfig-u5-01 .e{stroke:#B1B7C3}html.dark #dsfig-u5-01 .e.hi{stroke:#8FA3FF}html.dark #dsfig-u5-01 .n{fill:#161920;stroke:#E6E8ED}html.dark #dsfig-u5-01 .n.hi{fill:#1E2748;stroke:#8FA3FF}html.dark #dsfig-u5-01 .n.rb-b{fill:#E6E8ED;stroke:#E6E8ED}html.dark #dsfig-u5-01 .n.rb-r{fill:#FF7E71;stroke:#FF7E71}html.dark #dsfig-u5-01 .t{fill:#E6E8ED}html.dark #dsfig-u5-01 .t.inv{fill:#0F1115}html.dark #dsfig-u5-01 .kd{stroke:#E6E8ED}html.dark #dsfig-u5-01 .dot{fill:#E6E8ED}html.dark #dsfig-u5-01 .ann{fill:#8FA3FF}html.dark #dsfig-u5-01 .lbl{fill:#858D9C}html.dark #dsfig-u5-01 .ptr{fill:#8FA3FF}html.dark #dsfig-u5-01 .ah{fill:#B1B7C3}html.dark #dsfig-u5-01 .ah.hi{fill:#8FA3FF}html.dark #dsfig-u5-01 .wl rect{fill:#161920;stroke:#2A2E37}html.dark #dsfig-u5-01 .wl.hi rect{fill:#8FA3FF;stroke:#8FA3FF}html.dark #dsfig-u5-01 .wl.hi .t{fill:#0F1115}</style><defs><marker id="ah5" viewBox="0 0 10 10" refX="9" refY="5" markerWidth="7" markerHeight="7" orient="auto-start-reverse"><path class="ah" d="M0,1 L9,5 L0,9 z"/></marker><marker id="ahh5" viewBox="0 0 10 10" refX="9" refY="5" markerWidth="7" markerHeight="7" orient="auto-start-reverse"><path class="ah hi" d="M0,1 L9,5 L0,9 z"/></marker></defs><path class="e" d="M59,40 L191,40" marker-end="url(#ah5)"/><path class="e" d="M231,40 L363,40" marker-end="url(#ah5)"/><g class="wl"><rect x="95.3" y="31" width="61.5" height="18" rx="9"/><text class="t" x="126" y="40" dy=".35em" text-anchor="middle">publish</text></g><g class="wl"><rect x="270.9" y="31" width="54.3" height="18" rx="9"/><text class="t" x="298" y="40" dy=".35em" text-anchor="middle">notify</text></g><circle class="n" cx="40" cy="40" r="18"/><text class="t" x="40" y="40" dy=".35em" text-anchor="middle">Dev</text><circle class="n" cx="212" cy="40" r="18"/><text class="t" x="212" y="40" dy=".35em" text-anchor="middle">Brk</text><circle class="n" cx="384" cy="40" r="18"/><text class="t" x="384" y="40" dy=".35em" text-anchor="middle">App</text></svg><figcaption style="font-size:.82em;opacity:.72;margin-top:.45rem">Publish-subscribe. Dev = IoT device, Brk = broker, App = subscribed application</figcaption></figure>
Answer frame. Open with the definition of an IoT communication API; draw the publish-subscribe figure; develop REST, then WebSocket, then the comparison table, then request-response versus publish-subscribe; close with one example, such as a phone using REST to read a temperature that the sensor publishes over MQTT.
Asked: [7 marks] (May 2023) Explain about IoT Communication APIs in detail.
Attacks in IoT system, vulnerability analysis in IoT
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>
Definition. <mark>An IoT attack exploits a weakness in a device, network or cloud to steal data or take control.</mark>
Key points.
- Common attacks are eavesdropping, man-in-the-middle, denial of service (Mirai botnet), device spoofing and physical tampering.
- Vulnerabilities come from default passwords, unencrypted traffic, unpatched firmware and weak authentication.
- Other attacks are replay attacks, firmware tampering, sinkhole and jamming attacks on wireless sensor networks, and side-channel attacks that read secrets from power use.
- Vulnerability analysis lists assets, scans for such weaknesses, rates the risk and fixes them with encryption, updates and strong authentication.
- Countermeasures include changing default passwords, TLS encryption, secure boot, signed firmware updates and network segmentation.
- Weak points sit at every layer: the sensing device, the network, the cloud and the mobile application.
IoT case studies: Smart Home, Smart framing etc.
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Low weight</span>
Definition. <mark>A home intrusion detection system senses movement, captures an image with a webcam and emails it as an alert.</mark>
Diagram.
<figure class="ds-fig" style="margin:1.4rem 0;overflow-x:auto"><svg xmlns="http://www.w3.org/2000/svg" id="dsfig-u5-02" viewBox="0 0 345 252" width="345" height="252" role="img" aria-label="PIR = motion sensor, Ctl = Raspberry Pi controller, Cam = webcam, Mail = SMTP email"><style>#dsfig-u5-02 .e{stroke:#454C5A;stroke-width:1.4;fill:none}#dsfig-u5-02 .e.hi{stroke:#2340B8;stroke-width:2.6}#dsfig-u5-02 .n{fill:#FFFFFF;stroke:#16181D;stroke-width:1.4}#dsfig-u5-02 .n.hi{fill:#E3E9FC;stroke:#2340B8;stroke-width:2.2}#dsfig-u5-02 .n.rb-b{fill:#16181D;stroke:#16181D}#dsfig-u5-02 .n.rb-r{fill:#BD3227;stroke:#BD3227}#dsfig-u5-02 text{font-family:"JetBrains Mono",ui-monospace,Menlo,Consolas,monospace;font-size:13px}#dsfig-u5-02 .t{fill:#16181D;font-weight:500}#dsfig-u5-02 .t.inv{fill:#FFFFFF;font-weight:700}#dsfig-u5-02 .kd{stroke:#16181D;stroke-width:1.2}#dsfig-u5-02 .dot{fill:#16181D}#dsfig-u5-02 .ann{fill:#2340B8;font-size:11px;font-weight:700}#dsfig-u5-02 .lbl{fill:#6F7787;font-family:system-ui,-apple-system,sans-serif;font-size:12px;font-weight:700}#dsfig-u5-02 .ptr{fill:#2340B8;font-size:12px;font-weight:700}#dsfig-u5-02 .ah{fill:#454C5A}#dsfig-u5-02 .ah.hi{fill:#2340B8}#dsfig-u5-02 .wl rect{fill:#FFFFFF;stroke:#DCE0E7}#dsfig-u5-02 .wl .t{font-size:12px;font-weight:700}#dsfig-u5-02 .wl.hi rect{fill:#2340B8;stroke:#2340B8}#dsfig-u5-02 .wl.hi .t{fill:#FFFFFF}html.dark #dsfig-u5-02 .e{stroke:#B1B7C3}html.dark #dsfig-u5-02 .e.hi{stroke:#8FA3FF}html.dark #dsfig-u5-02 .n{fill:#161920;stroke:#E6E8ED}html.dark #dsfig-u5-02 .n.hi{fill:#1E2748;stroke:#8FA3FF}html.dark #dsfig-u5-02 .n.rb-b{fill:#E6E8ED;stroke:#E6E8ED}html.dark #dsfig-u5-02 .n.rb-r{fill:#FF7E71;stroke:#FF7E71}html.dark #dsfig-u5-02 .t{fill:#E6E8ED}html.dark #dsfig-u5-02 .t.inv{fill:#0F1115}html.dark #dsfig-u5-02 .kd{stroke:#E6E8ED}html.dark #dsfig-u5-02 .dot{fill:#E6E8ED}html.dark #dsfig-u5-02 .ann{fill:#8FA3FF}html.dark #dsfig-u5-02 .lbl{fill:#858D9C}html.dark #dsfig-u5-02 .ptr{fill:#8FA3FF}html.dark #dsfig-u5-02 .ah{fill:#B1B7C3}html.dark #dsfig-u5-02 .ah.hi{fill:#8FA3FF}html.dark #dsfig-u5-02 .wl rect{fill:#161920;stroke:#2A2E37}html.dark #dsfig-u5-02 .wl.hi rect{fill:#8FA3FF;stroke:#8FA3FF}html.dark #dsfig-u5-02 .wl.hi .t{fill:#0F1115}</style><defs><marker id="ah6" viewBox="0 0 10 10" refX="9" refY="5" markerWidth="7" markerHeight="7" orient="auto-start-reverse"><path class="ah" d="M0,1 L9,5 L0,9 z"/></marker><marker id="ahh6" viewBox="0 0 10 10" refX="9" refY="5" markerWidth="7" markerHeight="7" orient="auto-start-reverse"><path class="ah hi" d="M0,1 L9,5 L0,9 z"/></marker></defs><path class="e" d="M59,126 L148,126" marker-end="url(#ah6)"/><path class="e" d="M184.8,115.5 L280.5,51.6" marker-end="url(#ah6)"/><path class="e" d="M184.8,136.5 L274.7,196.5" marker-end="url(#ah6)"/><path class="e" d="M298,59 L298,184" marker-end="url(#ah6)"/><circle class="n" cx="40" cy="126" r="18"/><text class="t" x="40" y="126" dy=".35em" text-anchor="middle">PIR</text><circle class="n" cx="169" cy="126" r="18"/><text class="t" x="169" y="126" dy=".35em" text-anchor="middle">Ctl</text><circle class="n" cx="298" cy="40" r="18"/><text class="t" x="298" y="40" dy=".35em" text-anchor="middle">Cam</text><rect class="n" x="273" y="197" width="50" height="30" rx="15"/><text class="t" x="298" y="212" dy=".35em" text-anchor="middle">Mail</text></svg><figcaption style="font-size:.82em;opacity:.72;margin-top:.45rem">PIR = motion sensor, Ctl = Raspberry Pi controller, Cam = webcam, Mail = SMTP email</figcaption></figure>
Key points.
- The PIR sensor detects movement by sensing infrared change and gives a HIGH signal on a GPIO pin.
- The controller (Raspberry Pi) polls this pin; a webcam on USB is used because Arduino cannot easily process images.
- On intrusion, the controller captures a frame, saves it as a JPEG and attaches it to the email.
- The email goes over SMTP with SSL to the owner, who sees the picture immediately; a buzzer can also be sounded.
- A GET on the controller's web page can also show a live view, so REST and the camera work together in a smart home.
- Other smart home uses are lights and thermostat control; smart farming uses soil moisture sensors to switch irrigation automatically.
Steps.
Step 1: Read the PIR sensor on a GPIO pin.
Step 2: If motion is detected, capture an image from the webcam.
Step 3: Build an email and attach the image.
Step 4: Send it through the SMTP server to the owner.
import cv2, smtplib
from email.message import EmailMessage
def alert():
ok, img = cv2.VideoCapture(0).read()
cv2.imwrite("intruder.jpg", img)
m = EmailMessage(); m["Subject"] = "Intrusion!"
m["From"] = "[email protected]"; m["To"] = "[email protected]"
m.add_attachment(open("intruder.jpg", "rb").read(),
maintype="image", subtype="jpeg", filename="intruder.jpg")
s = smtplib.SMTP_SSL("smtp.gmail.com", 465)
s.login("[email protected]", "app-password"); s.send_message(m)
Answer frame. Open with one line on the architecture (sensor, controller, webcam, email); draw the block diagram; list the four steps; write the alert function; close with the owner receiving the photo on the phone.
Asked: [7 marks] (May 2023) Design and implement the functionality of a home intrusion detection IoT system by interfacing a webcam. Implement the function in the controller to capture the image from webcam and send it as an attachment in the email alert when an intrusion is detected.
Last-minute revision
- REST is HTTP, stateless, request-response; WebSocket is one persistent full-duplex connection.
- MQTT publish-subscribe uses a broker between publishers and subscribers.
- Arduino has no OS; Raspberry Pi runs Linux.
- Mirai was a DoS botnet built from default-password devices.
- Intrusion alert: PIR, capture image, attach, SMTP send.
- Arduino is a microcontroller in C/C++; Raspberry Pi is a Linux computer with Wi-Fi.
- Analytics types are descriptive, predictive and prescriptive.
- IoT attacks include eavesdropping, man-in-the-middle, DoS, spoofing and tampering.
Memory hooks
- REST asks, WebSocket keeps talking, MQTT broadcasts.
- Arduino = brain only, Pi = tiny computer.
- PIR sees, camera shoots, SMTP shouts.
- DEMS: DoS, Eavesdrop, Man-in-the-middle, Spoof.
Coverage checklist
- IoT Platforms, Arduino, Raspberry Pi Board, Other IoT Platforms: no past questions.
- Data Analytics for IoT, Cloud for IoT, Cloud storage models & communication APIs: IoT communication APIs (May 2023).
- Attacks in IoT system, vulnerability analysis in IoT: no past questions.
- IoT case studies: Smart Home, Smart framing etc.: home intrusion detection (May 2023).