Overview
ISO/IEC 24767-2:2009 - "Information technology - Home network security - Part 2: Internal security services - Secure Communication Protocol for Middleware (SCPM)" specifies a lightweight, network-layer security protocol for home-networked devices with limited IT capability. SCPM is media-independent and intended for middleware and devices that cannot support Internet security protocols (e.g., IPSec or SSL/TLS). The standard defines message formats, security services, information flows and processing rules required to implement SCPM within home networks.
Key topics
- Scope & design principles: security for constrained devices, minimization of resources, independence from communication media and cryptographic algorithms, and extensibility for variant usages.
- SCPM concept and placement: how SCPM operates at the network layer to protect middleware traffic without replacing existing protocol security.
- Secure message frame format: structure includes headers, secure header (SHD), source/destination addresses, sequence number field (SNF), byte counters, padding (PDG), block check code (BCC) and message data authentication signature (MDAS).
- Processing & algorithms: guidance on encryption and data-authentication processing, cipher-block-chaining (CBC) mode, initialization vectors (IV), and SNF initialization/verification. (The standard’s figures include an example using AES‑CBC.)
- Key management: initialization of user, service-provider and maker keys; master key update, synchronization and update flows; and key exchange methods (figures reference use of DH - Diffie‑Hellman - for controlled master key updates).
- Conformance & security considerations: threat categories (unsafe transmission, intentional misuse), and recommended combinations of security measures.
Applications
ISO/IEC 24767-2:2009 and SCPM are practical for:
- Device manufacturers producing smart appliances, set-top boxes, IoT endpoints and other home-networked hardware with limited CPU, memory or OS stack.
- Middleware and platform vendors who need a standardized, lightweight network-layer security method to protect inter-device communications.
- Home gateway and HES (Home Environment Server) designers implementing security for mixed-protocol networks where constrained devices cannot run full Internet security stacks.
- System integrators and security architects creating secure home-network deployments that require media-independent, interoperable protection and robust key management.
Related standards
- Other parts of the ISO/IEC 24767 series (home network security) provide complementary guidance; SCPM is intentionally not a replacement for Internet security standards (IPSec, TLS) but a supplement for constrained devices.
Keywords: ISO/IEC 24767-2:2009, SCPM, Secure Communication Protocol for Middleware, home network security, network layer security, key management, AES‑CBC, Diffie‑Hellman.