[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"detail-sidebar-cat-1-en-105":3,"doc-seo-253326-105":53,"doc-detail-253326-en":126},{"code":4,"msg":5,"data":6},0,"success",[7,14,19,24,29,34,39,44,49],{"id":8,"doc_module":9,"doc_module_name":10,"category_name":11,"show_sort_weight":12,"slug":13},11,1,"Template","Presentations",90,"presentations",{"id":15,"doc_module":9,"doc_module_name":10,"category_name":16,"show_sort_weight":17,"slug":18},12,"Resumes",80,"resumes",{"id":20,"doc_module":9,"doc_module_name":10,"category_name":21,"show_sort_weight":22,"slug":23},14,"Invoices",70,"invoices",{"id":25,"doc_module":9,"doc_module_name":10,"category_name":26,"show_sort_weight":27,"slug":28},15,"Posters",60,"posters",{"id":30,"doc_module":9,"doc_module_name":10,"category_name":31,"show_sort_weight":32,"slug":33},16,"Social Media",50,"social-media",{"id":35,"doc_module":9,"doc_module_name":10,"category_name":36,"show_sort_weight":37,"slug":38},17,"Forms",40,"forms",{"id":40,"doc_module":9,"doc_module_name":10,"category_name":41,"show_sort_weight":42,"slug":43},18,"Letters",30,"letters",{"id":45,"doc_module":9,"doc_module_name":10,"category_name":46,"show_sort_weight":47,"slug":48},21,"Paper Templates",5,"papers-templates",{"id":50,"doc_module":9,"doc_module_name":10,"category_name":51,"show_sort_weight":4,"slug":52},158,"General","general-158",{"code":4,"msg":54,"data":55},"ok",{"site_id":56,"language":57,"slug":58,"title":59,"keywords":60,"description":61,"schema_data":62,"social_meta":119,"head_meta":121,"extra_data":123,"updated_unix":125},105,"en","security-assessment-report-security-2-command-class-protocol-review-executive-summary","Security Assessment Report - Security 2 Command Class Protocol Review - Executive Summary","","Security Assessment Report documents an independent security evaluation of Sigma Designs’ Security 2 Command Class protocol framework conducted in June 2017. The assessment verifies whether previously identified replay-attack risks were effectively mitigated, whether introduced security controls perform effectively in physical implementations, and whether protocol-level risks remain at an acceptable level. Results are designed to feed a broader risk management process and are explicitly treated as a point-in-time review for the tested system and environment.",{"@graph":63,"@context":118},[64,80,101],{"@type":65,"itemListElement":66},"BreadcrumbList",[67,71,74,77],{"item":68,"name":69,"@type":70,"position":9},"https://docshare.wps.com","Home","ListItem",{"item":72,"name":10,"@type":70,"position":73},"https://docshare.wps.com/template/",2,{"item":75,"name":51,"@type":70,"position":76},"https://docshare.wps.com/template/general/",3,{"item":78,"name":59,"@type":70,"position":79},"https://docshare.wps.com/template/security-assessment-report-security-2-command-class-protocol-review-executive-summary/253326/",4,{"url":78,"name":59,"@type":81,"image":82,"author":87,"headline":59,"publisher":90,"fileFormat":93,"inLanguage":57,"description":61,"dateModified":94,"datePublished":95,"encodingFormat":93,"isAccessibleForFree":96,"interactionStatistic":97},"DigitalDocument",{"url":83,"@type":84,"width":85,"height":86},"https://docshare.wps.com/thumbnails/security-assessment-report-security-2-command-class-protocol-review-executive-summary/253326.png","ImageObject",442,249,{"name":88,"@type":89},"Emma Wilson","Person",{"url":68,"name":91,"@type":92},"DocShare","Organization","application/pdf","2026-09-20","2026-09-13",true,{"@type":98,"interactionType":99,"userInteractionCount":79},"InteractionCounter",{"@type":100},"ViewAction",{"@type":102,"mainEntity":103},"FAQPage",[104,110,114],{"name":105,"@type":106,"acceptedAnswer":107},"When was the Security 2 Command Class security assessment conducted?","Question",{"text":108,"@type":109},"The assessment started on 19 June 2017 and concluded on 21 June 2017.","Answer",{"name":111,"@type":106,"acceptedAnswer":112},"What was the purpose of conducting the security review for Sigma Designs?",{"text":113,"@type":109},"Sigma Designs aimed to verify the security of its newly developed S2 security framework through third-party independent verification in addition to internal testing.",{"name":115,"@type":106,"acceptedAnswer":116},"How is the overall risk rating described in the report?",{"text":117,"@type":109},"The overall information security risk rating is stated as “Informational,” based on the highest criticality finding and supporting risk statistics shown in the risk summary table.","https://schema.org",{"og:url":78,"og:type":120,"og:title":59,"og:site_name":91,"og:description":61},"article",{"robots":122,"canonical":78},"index,follow",{"doc_id":124,"site_id":56},253326,1789265363,{"code":4,"msg":5,"data":127},{"doc_id":124,"user_id":128,"nickname":88,"user_avatar":129,"doc_module":9,"category_id":50,"category_name":51,"doc_title":59,"doc_description":61,"doc_content":130,"file_id":131,"file_url":132,"file_type":133,"file_size":134,"view_count":79,"is_deleted":4,"is_public":9,"is_downloadable":9,"audit_status":9,"page_count":135,"language":136,"language_code":57,"site_id":56,"html_lang":57,"table_of_contents":137,"faqs":138,"seo_title":139,"seo_description":61,"update_tm":125,"read_time":140},3848291630094,"https://eur-avatar.wpscdn.com/davatar_085a072bc5b1113ac321206ff7593b45","Security Assessment Report  \n\n| Client | Sigma Designs |\n| --- | --- |\n| Project Name | Security 2 Command Class Protocol Review |\n| Project Code | SP02508 |\n| Date | 2017-08-18 |\n\nTABLE OF CONTENTS  \n1.1 Assessment Overview .............................................................................................................................. 3  \n1.2 Motivation for conducting security review......................................................................................3  \n1.3 About Sense Post ........................................................................................................................................ 3  \n1.4 Risk Summary..............................................................................................................................................4  \n1.5 Conclusion & Recommendations........................................................................................................4  \n2.1 Z-Wave Network Security ...................................................................................................................... 5  \n3.1 Summary ....................................................................................................................................................... 6  \n3.2 Z-Wave Controller Components .........................................................................................................6  \n3.3 Decryption and Replay Attacks ............................................................................................................6  \n4.1 Results Summary .......................................................................................................................................7  \n4.2 Z-Wave Device Assessment...................................................................................................................7  \n5.1 Z Wave Device Assessment ...................................................................................................................9  \n5.1.1 Data Encryption.................................................................................................................................9  \n1 EXECUTIVE SUMMARY   \n1.1 Assessment Overview  \nThe assessment of Sigma Designs' Security 2 Command Class commenced on the 19th of June 2017 and concluded on the 21st of June 2017. This assessment was the culmination of several previous projects – both on a documentation review level as well as a technical assessment of the protocol implemented on hardware provided by Sigma Designs. This final project was requested by Sigma Systems in order to identify any final concerns prior to the standard being finalised and published.  \nSigma Designs engaged the services of SensePost in order to:  \n􀁸 Evaluate whether the risk of replay attacks identified during previous projects had been effectively mitigated.  \n􀁸 Evaluate whether the security controls introduced in the Security 2 Command Class were effective when physically implemented.  \n􀁸 Gauge whether the risk identified within the protocol was at a level acceptable and that such risk would not have a significant impact on the delivery of the service, expose clients to harm or loss or other such consequences.  \nThe results provided are the output of the security assessment performed and should be used as input into a larger risk management process.  \nThese results are a point in time assessment of the system and environment as they werepresented for testing. Any changes could yield a different set of results.  \n1.2 Motivation for conducting security review  \nSigma Designs wanted to verify the security of their newly developed S2 security framework. Third party independent verification from a qualified security analyst chosen in addition to inhouse testing. From experience, this greatly improves the analysis coverage and number offlaws found. Analysts from SensePost had previously demonstrated knowledge and skills needed to uncover flaws in older Z-Wave dev","cbCaikpDwdRFkk9o","https://ap.wps.com/l/cbCaikpDwdRFkk9o","pdf",1291844,22,"English","# Assessment Overview\n## Motivation for conducting security review\n## About SensePost\n## Risk Summary\n## Conclusion & Recommendations\n# Z-Wave Network Security\n## Results Summary\n## Z-Wave Device Assessment","[{\"question\":\"When was the Security 2 Command Class security assessment conducted?\",\"answer\":\"The assessment started on 19 June 2017 and concluded on 21 June 2017.\"},{\"question\":\"What was the purpose of conducting the security review for Sigma Designs?\",\"answer\":\"Sigma Designs aimed to verify the security of its newly developed S2 security framework through third-party independent verification in addition to internal testing.\"},{\"question\":\"How is the overall risk rating described in the report?\",\"answer\":\"The overall information security risk rating is stated as “Informational,” based on the highest criticality finding and supporting risk statistics shown in the risk summary table.\"}]","Security Assessment Report - Security 2 Command Class Protocol Review - Executive Summary | PDF",8]