Module Overview

Architecture, threat modelling, and authenticated encryption for CPS/IoT systems

The module brought together strategic and engineering perspectives on securing complex systems-of-systems. Strategic work mapped CIA priorities to the ABCDE characteristics (Autonomy, Belonging, Connectivity, Diversity, Emergence) for blockchain-integrated CPS/IoT platforms, while engineering work produced a Python simulation of AES-GCM authenticated encryption with realistic loss, latency, and adversarial conditions.

Standards and frameworks referenced across the artefacts include ISO 27001, the NIST Cybersecurity Framework, GDPR, and the CIA triad. Threat modelling used Attack-Defence Trees with quantitative DREAD/DSS scoring to justify mitigation sequencing, and assurance was driven by Bandit, Flake8, and Pytest with coverage tracking.

Module Learning Outcomes

Core competencies developed through the module

🏛️

Architectural Alignment

Design secure CPS/IoT architectures by aligning CIA priorities with ABCDE characteristics and SoS constraints.

📊

Quantitative Threat Modelling

Prioritise threats through AD-Trees and quantitative scoring (DREAD/DSS) to justify the sequencing of mitigations.

🔐

Secure Communications Engineering

Implement authenticated encryption with sound object-oriented design, integrating replay protection and resilience to loss.

Testing & Quality Gates

Integrate automated testing, coverage targets, and security tooling to assure reliability under adverse conditions.

🗣️

Evidence-led Communication

Communicate architectural decisions, trade-offs, and testing results to technical and non-technical audiences with supporting evidence.

Key Artefacts

Deliverables with tutor commentary and growth actions

🧱

Development Team Project — Design Document

UNIT 3

Architecture for a blockchain-integrated CPS/IoT system-of-systems identified key vulnerabilities and mapped mitigations via AD-Trees (client node, controller/hub, overall SoS). Controls included multi-factor authentication, Zero Trust patterns, and layered detection aligned to quantified DREAD/DSS scores.

💻

Development Individual Project — Code Development

UNIT 6

Built a modular Python simulation of secure IoT communication focused on confidentiality within the ABCDE model. Async components (controller, device, network, packet) used AES-GCM with unique nonces, injected loss and delay, and surfaced metrics. Bandit, Flake8, and Pytest underpinned quality assurance, with documentation detailing experiments and results.

📝

Individual Reflective Submission

UNIT 6

Captured lessons on secure architecture for blockchain-enabled CPS/IoT deployments, translating tutor feedback into an action plan for automated testing, AD-Tree enhancements, and tighter ABCDE linkage. Reflections examined team collaboration, delegation, and growth areas.

Action Plan (next 6–8 weeks)

Prioritised improvements driven by feedback and observed gaps

What will be done Evidence of completion
ABCDE linkage & visuals Map each vulnerability to ABCDE attributes, regenerate AD-Trees via Graphviz or diagram tooling, remove placeholder artefacts, and standardise figure styling. Appendix table (vulnerability → ABCDE) and refreshed diagram set in the design document. Week 2
Trade-off analysis Add quantified discussion on blockchain scalability, latency, and mitigation costs, including sensitivity analysis of DREAD/DSS inputs. New trade-off subsection plus revised scores with sensitivity commentary. Week 3
Comms hardening Introduce replay detection (sequence numbers), periodic key rotation, and X25519-based session key agreement layered on AES-GCM. Passing automated tests, code diffs, and updated README crypto notes. Week 4
Reliability testing Extend chaos scenarios (duplication, reordering, burst loss) and add Hypothesis property tests plus coverage targets. CI badge, ≥85% coverage reports, and chaos test execution logs or screenshots. Week 4
CI & quality gates Implement pre-commit hooks (Black, Flake8, Bandit, Pytest) and GitHub Actions with artefact capture and metric trending. Committed pre-commit config, CI pipeline history, and trend chart exports. Week 3
Documentation polish Produce updated architecture and sequence diagrams, operating runbook, and Cite-Them-Right references with consistent styling. Updated README/design document and alphabetised reference list. Week 3
Reflection updates Add concrete collaboration examples, measurable impacts, and broadened perspectives backed by recent citations. Revised reflective submission with in-text citations and word count noted. Week 2

Professional Skills Matrix (snapshot)

Current strengths with planned improvements aligned to feedback

Current level Evidence Planned improvement
Systems architecture (CPS/IoT, SoS) Proficient
Coherent SoS design with CIA + ABCDE framing and comprehensive vulnerability analysis. Explicit vulnerability-to-ABCDE mapping, polished diagrams, and deeper scalability trade-offs.
Threat modelling & quantification Proficient
AD-Trees for client, hub, and SoS layers with DREAD/DSS prioritisation. Regenerate original figures, add sensitivity analysis, and clarify risk acceptance criteria.
Secure comms engineering (Python) Proficient
Modular asyncio/websockets simulation with AES-GCM and resilient packet abstraction. Add replay protection, key rotation with forward secrecy, and extended chaos scenarios.
Testing & assurance Proficient
Bandit, Flake8, Pytest, and scenario testing under packet loss and latency. CI with quality gates, property-based tests, and ≥85% coverage tracking.
Documentation & academic practice Proficient
Clear README and design rationale with referenced sources. Standardise diagram styles, apply Cite-Them-Right, and expand trade-off exposition.
Collaboration & reflective practice Proficient
Reflection linked theory to practice with actionable responses to feedback. Include specific outcome metrics, cite impacts on delivery quality, and broaden perspectives.

Reflection Highlights

Key takeaways from the module

The module underscored the importance of connecting architectural artefacts with quantifiable risk arguments. Tutor feedback highlighted the need for better diagram polish and clearer ABCDE traceability, which now drive specific improvements in modelling collateral.

Implementing authenticated encryption with measurable chaos testing reinforced the value of automation and telemetry in CPS/IoT environments. The next iteration will emphasise forward secrecy, evidence-backed trade-off narratives, and showcasing the measurable impact of collaborative changes.

References

ISO/IEC (2022) ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection — Information security management systems — Requirements. Geneva: International Organization for Standardization.

Council of the European Union (2016) Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data (General Data Protection Regulation). Brussels.

Shostack, A. (2014) Threat Modeling: Designing for Security. Indianapolis: Wiley.

National Institute of Standards and Technology (2007) NIST SP 800-38D Recommendation for Block Cipher Modes of Operation: Galois/Counter Mode (GCM) and GMAC. Gaithersburg: NIST.

Howard, M. and LeBlanc, D. (2003) Writing Secure Code. 2nd edn. Redmond: Microsoft Press.