EN
.
33
12.2.
Z-Wave Security
Luxy Smart Switch supports the latest Security 2 feature. Security S2 is handled by the Strong
AES 128 Encryption protocol, which means that the S2 makes Z-Wave the most secure IoT
(Internet of Things) security platform out there. To fully utilize the product and its SECURITY 2
feature, a Security Enabled Z-Wave gateway (hub) must be used.
Authenticated Control
•
Out-Of-Band Device Specific Key for inclusion
•
May be used by most implementations
Also supports: Security S2 Unauthenticated, Security S0 and Unsecure inclusion.
IMPORTANT
: When adding the Luxy Smart Switch to a Z-Wave network with a controller
supporting Security 2 (S2), the PIN code of the Z-Wave Device Specific Key (DSK) is required.
The unique DSK code is printed on the product label and a copy is inserted in the packaging,
which must not be lost. Do not remove the DSK from the product. As a backup measure, use
the label in the packaging.
The first five digits of the key are highlighted or underlined to help the
user identify the PIN code portion of the DSK text.
The DSK is additionally represented with a QR Code as shown here.
DSK label and QR code (example)
A joining node requesting to join the S2 Access Control Class or the S2 Authenticated Class will
obfuscate its Public Key by setting the bytes 1..2 to zeros (0x00) before transferring its key via
RF.
A joining node requesting to join only the S2 Unauthenticated Class will send the its full Public
Key when transferring the key via RF as the including node has no access to the DSK.
The DSK may be used for out-of-band (OOB) authentication.
•
The including gateway (hub) may use QR code scanning device to read the entire DSK off
the joining device and match it with the obfuscated public key received via RF from the
joining device.
SmartStart enabled products can be added into a Z-Wave network by scanning the Z-Wave QR
Code present on the product with a controller providing SmartStart inclusion. No further action
is required and the SmartStart product will be added automatically within 10 minutes of being
switched on in the network vicinity.