Thread and Matter
- Thread and Matter
Why this matters
Thread and Matter are the industry’s answer to everything on the Zigbee and Z-Wave pages, and — unusually for this course — the answer is mostly good. Matter is the first consumer IoT standard to mandate a password-authenticated key exchange, per-device certificates, and mutually authenticated operational sessions. If you have spent the term finding hardcoded keys and unauthenticated downgrades, it is a genuine change of posture.
So the interesting question is no longer “is the crypto broken” but “what did this not fix, and where did the vendor implement it badly.” Those are the two things worth your attention, and they are both still substantial.
Keep the layering straight, because almost all confusion about these two technologies comes from conflating them:
| Thread | Matter | |
|---|---|---|
| What it is | An IPv6 mesh network | An application layer |
| Runs on | IEEE 802.15.4 | Thread, WiFi, or Ethernet |
| Provides | Routing, addressing, link security | Device types, commands, identity |
| Steward | Thread Group | Connectivity Standards Alliance |
Matter does not require Thread. Thread does not require Matter. Most smart-home devices you meet use both, which is why they are one page.
The radio layer
Thread uses IEEE 802.15.4 — the same PHY and MAC as Zigbee, so everything in Zigbee’s radio section applies unchanged: 2.4 GHz, channels 11–26, 2 MHz wide, O-QPSK with DSSS at 250 kb/s, no frequency hopping.
This means your Zigbee capture hardware works on Thread, which is a genuinely useful fact. A CC2531, a CC2652 LaunchPad or an nRF52840 dongle sniffs both; Wireshark dissects 802.15.4 underneath either stack. What changes is everything above the MAC header.
Matter over WiFi is a different matter entirely — it is ordinary IP traffic on an ordinary WLAN, so see WiFi for capture, and expect to be looking at TLS you cannot read.
⚠️ BLE is part of this story too. Matter uses Bluetooth LE as the commissioning bearer: a factory-fresh device advertises over BLE so a phone can find it and hand it network credentials. That advertising is observable with anything from the Bluetooth page, and it tells you a device is in commissioning mode — which is exactly when it is most interesting.
Thread: an IPv6 mesh
Thread replaces Zigbee’s bespoke network layer with 6LoWPAN — IPv6 with header compression tuned for 127-byte 802.15.4 frames. Every node gets real IPv6 addresses and real IP semantics.
| Role | Function |
|---|---|
| Leader | Assigns router IDs; elected, and replaceable |
| Router | Forwards for the mesh; mains-powered |
| REED | Router-eligible end device; promotes itself if needed |
| End Device | Sleepy or minimal; does not forward |
| Border Router | Bridges the mesh to WiFi/Ethernet, does service discovery |
Architecturally this is better than Zigbee in one important way: there is no coordinator whose loss kills the network. The Leader is elected and another node takes over. Zigbee’s coordinator is a single point of failure and a single point of compromise; Thread has neither.
The Border Router is what replaces it as the interesting target. It sits on both networks, holds the credentials, and runs a full OS. More on that below.
Thread’s link security
MAC-layer frames are encrypted with AES-CCM under a shared 128-bit Network Key, with frame counters for replay protection and a key sequence counter for rotation.
Note that honestly: Thread, like Zigbee, has one network key shared by every node. Compromising any device yields mesh-wide decryption. The improvement over Zigbee is not in this layer — it is in how a device gets the key, and in the fact that Matter adds a second, genuinely per-device layer above it.
Commissioning with a PAKE
To join, a device performs a DTLS 1.2 handshake using EC-JPAKE, keyed by a commissioning credential (the PSKd) printed on the device. J-PAKE is a password-authenticated key exchange: an eavesdropper who captures the entire exchange cannot mount an offline dictionary attack against the credential. Each guess costs an online attempt, which the device rate-limits.
That is the same property WPA3’s SAE provides, and it is precisely what S0 Z-Wave and legacy Zigbee lacked. There is no constant in the specification to know.
Worked example: the border router hands over everything
The Thread credential set is called the Operational Dataset, and it contains the network key. Anyone with shell access to a border router has the whole mesh:
$ sudo ot-ctl dataset active
Active Timestamp: 1
Channel: 15
Channel Mask: 0x07fff800
Ext PAN ID: dead00beef00cafe
Mesh Local Prefix: fd11:22:0:0::/64
Network Key: 00112233445566778899aabbccddeeff
Network Name: OpenThreadDemo
PAN ID: 0x1234
PSKc: c23a76e98f1a6483639b1ac1271e2e27
Security Policy: 672 onrc 0
Done
Feed that Network Key to Wireshark’s 802.15.4 decryption and the mesh is readable. Confirm the topology from the same shell:
$ sudo ot-ctl state
leader
Done
$ sudo ot-ctl router table
| ID | RLOC16 | Next Hop | Path Cost | LQI In | LQI Out | Age | Extended MAC |
+----+--------+----------+-----------+--------+---------+-----+------------------+
| 22 | 0x5800 | 63 | 0 | 3 | 3 | 0 | 0a1b2c3d4e5f6071 |
| 44 | 0xb000 | 22 | 1 | 3 | 3 | 23 | 7a8b9c0d1e2f3041 |
This is the practical Thread attack path, and it is not cryptographic. It is: find the border router, get a shell on it, read the dataset. Border routers run Linux — a Raspberry Pi running OpenThread Border Router, a hub, a smart speaker, an eero. All the ordinary host-security questions from Attacks apply, and they are far easier than attacking J-PAKE.
Matter: identity, properly
Matter’s contribution is that every device has a cryptographic identity, and so does every controller. Three mechanisms carry it.
Device attestation
Every certified device ships with a Device Attestation Certificate (DAC) and its private key, burned in at manufacture:
PAA (Product Attestation Authority — root, published in the DCL)
└── PAI (Product Attestation Intermediate — per vendor/product line)
└── DAC (Device Attestation Certificate — per device)
During commissioning the controller challenges the device to sign a nonce with the DAC key and validates the chain against the Distributed Compliance Ledger, the CSA’s public registry of certified products. A counterfeit device cannot produce a valid chain.
This is a real supply-chain control and nothing earlier in this course has an equivalent.
⚠️ The DAC private key is a key stored on a device you can open. If it lives in unprotected flash rather than in a secure element or a locked region, it can be extracted with the techniques from Dumping flash — and then a device’s certified identity can be cloned. Attestation moves the problem from “is the protocol sound” to “is the key storage sound,” which is a hardware question. That is a legitimate and productive thing to test.
Commissioning: PASE
Commissioning uses SPAKE2+, an augmented PAKE, keyed by the device’s setup passcode — the 8-digit number in the QR code on the label.
Eight digits is 10⁸, which would be feeble against offline guessing. SPAKE2+ means there is no offline guessing: each attempt requires an online exchange, the device rate-limits them, and the commissioning window is normally closed. The entropy is adequate precisely because the protocol denies the attacker parallelism.
The exposure that remains is physical and social: the passcode is printed on the device and frequently on the box. A photograph of the label is commissioning capability, if the device is in a commissioning window. Ask during an assessment: can the window be opened remotely? What triggers a factory reset? Is the QR code visible through a window?
Operational sessions: CASE
Once commissioned, the controller issues the device a Node Operational Certificate (NOC) signed by the fabric’s root CA. Ongoing communication uses CASE — mutual certificate authentication with ephemeral ECDH, which gives forward secrecy. Recovering keys later does not decrypt earlier captures.
Compare that to Zigbee and Thread’s shared network key, where it very much does.
Fabrics and multi-admin
A Matter device can belong to several fabrics at once — Apple Home, Google Home, Amazon, Home Assistant — each with its own root CA, its own NOC for the device, and its own access-control list.
This is a genuine usability advance and it enlarges the trust base: the device is now only as trustworthy as the least careful of its administrators, and each fabric can grant access independently. “How many fabrics is this device joined to, and who controls them” is a question worth asking.
Worked example: commissioning with chip-tool
chip-tool is the reference controller from the Matter SDK and the right way
to see the machinery directly:
$ chip-tool pairing ble-thread 0x11 hex:0e080000000000010000000300000f35060004001fffe0 \
20202021 3840
[1718] CHIP:CTL: Starting commissioning discovery over BLE
[1719] CHIP:CTL: Establishing PASE session
[1722] CHIP:CTL: Received Attestation Information from the device
[1722] CHIP:CTL: Verifying attestation information
[1723] CHIP:CTL: Sending operational certificate to the device
[1725] CHIP:CTL: Successfully finished commissioning step 'SendNOC'
[1731] CHIP:TOO: Device commissioning completed with success
Every stage is visible: PASE with the passcode 20202021, attestation
verification against the DCL, then NOC issuance. Read a cluster afterwards over
CASE:
$ chip-tool onoff read on-off 0x11 1
[1744] CHIP:TOO: OnOff: FALSE
⚠️
--bypass-attestation-verification trueexists, and you will find it in vendor documentation and forum answers because development boards use test certificates. A production controller that ships with it set has silently discarded the entire attestation guarantee. Look for it.
What Matter did not change
Worth stating plainly, because the marketing does not:
- The device still runs firmware in a flash chip you can read. Every technique in Dumping flash and Software RE is unaffected.
- Attestation proves provenance, not correctness. A genuine, certified device with a buffer overflow in its cluster handler is still a genuine, certified device.
- Thread’s shared network key is still shared. Matter’s per-device identity sits above a mesh layer that does not have one.
- Local network trust. Matter over WiFi is on the same LAN as everything else, with all the lateral-movement questions that implies.
- The border router and the hub are ordinary computers, and are the softest target on the network.
Where the specifications are now
Matter ships roughly annually with maintenance releases between: 1.4 (November 2024) added the Home Router and Access Point device type and improved multi-admin; 1.4.1 and 1.4.2 (2025) focused on security, testing and certification tooling; 1.5 (November 2025) added cameras, closures and soil sensors, and extended energy management.
Thread 1.4 (September 2024) added cross-vendor credential sharing between border routers, and has been required for newly certified border routers since January 2026.
Key takeaways
- Thread is an IPv6 mesh; Matter is an application layer. They are usually used together and are constantly confused.
- Thread runs on the same 802.15.4 radio as Zigbee, so the same sniffer hardware works and the same channel plan applies.
- Thread has no coordinator — the Leader is elected and replaceable — which is a real improvement on Zigbee’s single point of failure.
- Thread still uses one shared network key for MAC-layer security; the improvement is in commissioning, which uses the EC-JPAKE PAKE.
- The Thread operational dataset contains the network key, and the border router will print it. Attack the border router, not the cryptography.
- Matter mandates device attestation via a DAC/PAI/PAA chain validated against the public DCL — the first real supply-chain control in consumer IoT.
- SPAKE2+ commissioning makes the 8-digit passcode adequate by removing offline guessing; the residual risk is that the passcode is printed on the device.
- CASE sessions give mutual authentication and forward secrecy, which Zigbee, Z-Wave and Thread link security do not.
- The DAC private key is stored on a device you can physically open; if it is not in a secure element, attestation is only as strong as the flash.
--bypass-attestation-verificationin a shipping controller voids the whole model.
References
- Connectivity Standards Alliance, Matter — https://csa-iot.org/all-solutions/matter/
- Matter specifications and the Distributed Compliance Ledger — https://csa-iot.org/developer-resource/specifications-download-request/
- CSA, Matter 1.5 announcement — https://csa-iot.org/newsroom/matter-1-5-introduces-cameras-closures-and-enhanced-energy-management-capabilities/
- CSA, Matter 1.4.2 announcement — https://csa-iot.org/newsroom/matter-1-4-2-enhancing-security-and-scalability-for-smart-homes/
- Thread Group, specifications and white papers — https://www.threadgroup.org/support
- OpenThread — https://openthread.io/
- OpenThread Border Router — https://openthread.io/guides/border-router
- connectedhomeip (Matter SDK) and
chip-tool— https://github.com/project-chip/connectedhomeip - Hao & Ryan, J-PAKE: Authenticated Key Exchange Without PKI — https://eprint.iacr.org/2010/190.pdf
- Taubert & Wood, RFC 9383, SPAKE2+, an Augmented PAKE — https://www.rfc-editor.org/rfc/rfc9383.html
- RFC 4944 / RFC 6282, IPv6 over IEEE 802.15.4 (6LoWPAN) — https://www.rfc-editor.org/rfc/rfc6282.html
Related course pages: Radio Protocols · Zigbee · Z-Wave · Bluetooth · WiFi · Dumping flash · Attacks
🛠️ Maintenance note: this is the fastest-moving page in the set. Matter has shipped 1.4, 1.4.1, 1.4.2 and 1.5 since late 2024 and the cadence has not slowed — re-check the version paragraph and the CSA newsroom every offering, and treat any specific version claim here as stale until confirmed. Thread’s border-router certification requirement changed in January 2026.
chip-toolis developer tooling with no stability guarantee: its subcommands and log format change between SDK releases, so re-run the commissioning transcript before using it in lab.