USER MANUAL V1.0
© 2016 EnOcean | www.enocean.com
F-710-017, V1.0
PTM 535Z User Manual | v1.0 | March 2016 | Page 18/38
PTM 535Z – 2.4 GHZ PUSHBUTTON TRANSMITTER MODULE
2.9
Security modes
PTM 535Z can operate in two security modes:
Secure mode (default, R2 not populated)
PTM 535Z operates in secure mode by default using AES128 security for data telegrams.
Security is based on a random, device-unique security key which is generated during the
production of the device.
Standard mode (if R2 is populated)
PTM 535Z can operate in standard mode for applications requiring shorter payloads and
without the need for an AES128 signature.
2.9.1
Selecting the security mode
The default operation mode is secure mode. Standard mode can be selected by populating
configuration resistor R2.
2.9.2
Security parameters
PTM 535Z transmits data is secured based on a 4 byte sequence counter, an out of the box
device-unique key and a 4 byte signature calculated based on the AES128 encryption using
CBC mode.
The current status of the sequence counter together with the device-unique key are trans-
mitted during commissioning and have to be stored by the device where PTM 535Z is
learned in. These parameters are subsequently used to authenticate received telegrams.
EnOcean can provide references for the implementation of the required routines for key
exchange and message validation upon request.