About End-to-End LoRaWAN Security

The Things Stack secures LoRaWAN traffic from the device to your application. Every message is encrypted with AES-128 session keys, and every frame carries a Message Integrity Code (MIC) so the network can verify that it is authentic and has not been tampered with.

Key management and device authentication

Devices join the network through Over-The-Air Activation (OTAA) or Activation By Personalization (ABP). The Join Server derives and manages session keys, keeping root keys separate from the network and application servers. Gateways that connect with LoRa Basics™ Station or MQTT use TLS, so traffic between gateways and The Things Stack is protected as well.

Benefits of End-to-End LoRaWAN Security
  • Encrypted payloads: AES-128 encryption keeps application data private end to end.

  • Message integrity: MIC validation rejects altered or forged frames.

  • Secure key handling: Session keys are derived and stored by the Join Server, separated from other components.

  • Secure gateway links: TLS protects Basics Station and MQTT gateway connections.