Paper 2025/1268
What’s the Matter? An In-Depth Security Analysis of the Matter Protocol
Abstract
The Matter protocol has emerged as the leading standard for secure IoT interoperability, backed by major vendors such as Apple, Google, Amazon, Samsung, and others. With millions of Matter devices already deployed, its security guarantees are critical to the safety of modern IoT ecosystems. This paper presents the first in-depth analysis of Matter's key establishment protocols: Passcode-Authenticated Session Establishment (PASE) and Certificate-Authenticated Session Establishment (CASE), which are based on the well-studied SPAKE2+ and SIGMA, respectively. We first perform a specification-level security analysis of PASE and CASE, comparing Matter's design choices against the original SPAKE2+ and SIGMA protocols. This reveals weaknesses such as low-entropy setup passcodes, static per-device salts, and weak PBKDF2 parameters. Next, to assess how such weaknesses manifest in practice, we analyse a certified Matter codebase and find that critical safeguards such as limiting failed pairing attempts are not enforced. All identified vulnerabilities were responsibly disclosed and have been patched. We then complement our analysis by formally verifying PASE, CASE, CASE Resumption, and the original SPAKE2+ and SIGMA protocols. In particular, we reduce the security of Matter's lightweight session re-establishment mechanism (CASE Resumption) to that of an ephemeral key generated by an IoT device. Building on all three stages, we construct proof-of-concept attacks and evaluate their feasibility under Matter's own threat model. Our results invalidate several countermeasures specified in Matter's threat model, including protections for threats classified as "High Risk". Overall, our work shows that strong cryptographic building blocks alone are insufficient unless the surrounding protocol and deployment rules are equally rigorously specified and tested at the standard level.
Metadata
- Available format(s)
-
PDF
- Category
- Cryptographic protocols
- Publication info
- Preprint.
- Keywords
- MatterIoTProtocol AnalysisProVerif
- Contact author(s)
-
sayon duttagupta @ esat kuleuven be
arman @ kolozyan com
georgio nicolas @ esat kuleuven be
bart preneel @ esat kuleuven be
dave singelee @ esat kuleuven be - History
- 2026-06-12: last of 6 revisions
- 2025-07-10: received
- See all versions
- Short URL
- https://ia.cr/2025/1268
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2025/1268,
author = {Sayon Duttagupta and Arman Kolozyan and Georgio Nicolas and Bart Preneel and Dave Singelee},
title = {What’s the Matter? An In-Depth Security Analysis of the Matter Protocol},
howpublished = {Cryptology {ePrint} Archive, Paper 2025/1268},
year = {2025},
url = {https://eprint.iacr.org/2025/1268}
}