Choose your country and language
Language
The purpose of this lesson is to introduce you to some of the most important communication protocols used in IoT and highlight the importance of security when designing and implementing IoT systems.
This lesson provides an overview of key IoT protocols such as MQTT and RESTful APIs and emphasizes security best practices so you understand how to protect your devices and data in an increasingly connected world.
As you gain more experience with IoT, you will discover that communication and security become increasingly important. Your IoT project is part of a larger ecosystem where devices must communicate efficiently, reliably, and securely. Whether you are sending data between sensors and cloud servers or controlling devices remotely, choosing the right communication protocols and securing the system is essential.
This lesson introduces some of the most commonly used protocols in IoT and covers basic security measures that should be implemented to protect your system.
![]() |
AHT10 high-precision temperature and humidity sensor |
![]() |
TTGO T-Display ESP32 16MB with WiFi, Bluetooth and 1.1" color LCD screen |
![]() |
Dupont cables, 40 pcs |
IoT systems rely on communication protocols to exchange data between devices, cloud servers, and user interfaces. Two of the most widely used approaches in IoT are MQTT and RESTful APIs.
MQTT is a lightweight messaging protocol designed for IoT devices. It is optimized for networks with low bandwidth and high latency, making it ideal for resource-constrained devices such as your ESP32.
Publish/subscribe model: MQTT uses a publish/subscribe model where devices (called clients) either publish data to specific topics or subscribe to topics to receive data. This model is efficient and scalable — especially in systems with many devices that need to communicate.
Example: Imagine you have several sensors in different rooms. Each sensor can send data to a topic such as home/livingroom/temperature. Other devices or a cloud server can subscribe to this topic and receive real-time updates — without constant polling.
Broker: MQTT requires a central broker (such as Mosquitto), which handles message distribution between devices. The broker ensures that data published by one device is correctly forwarded to all subscribers.
MQTT is often used in smart homes, environmental monitoring, and industrial IoT applications because it is efficient and uses few resources.
RESTful APIs are a more traditional approach to communication in IoT systems, especially for devices interacting with web services.
Client/server model: In REST, devices (clients) send HTTP requests (GET, POST, PUT, DELETE) to a server, which then responds with data or an action. RESTful APIs are popular because they are stateless and use the familiar HTTP protocol, which is easy to implement and widely supported.
Example: For your IoT project, you can use a RESTful API to send data to a cloud service or retrieve information from a web-based database. For example, your ESP32 can send temperature and humidity data to a server that stores it and makes it available through a dashboard.
JSON format: RESTful APIs typically use JSON (JavaScript Object Notation) as their data format, which is lightweight and easy for both humans and machines to read.
Although RESTful APIs are flexible and powerful, they often require more bandwidth and resources than MQTT and are therefore not always ideal for low-power IoT devices.
Security is essential in IoT because connected devices often have access to sensitive data and control over physical systems. Without appropriate security measures, IoT devices are vulnerable to hacking, data leaks, and unauthorized control.
Here are some basic security practices to consider when developing and implementing IoT systems:
It is important to ensure that data sent between devices and servers is encrypted to prevent eavesdropping and unauthorized access.
TLS encryption: Use a supported version of Transport Layer Security (TLS) to encrypt data transferred over the internet. SSL is obsolete and must not be used. This is especially relevant for web servers and cloud services where sensitive data such as sensor values is transmitted. Always use HTTPS instead of HTTP to ensure that communication is encrypted.
To prevent unauthorized devices from accessing your IoT system, implement authentication and access control.
Username and password: Make sure your devices are protected by strong, unique passwords. Avoid factory settings or default passwords that can be easily guessed.
API keys and tokens: For communication with cloud services or REST APIs, API keys should be used to identify and authenticate devices and users. This ensures that only authorized devices can send or receive data.
The security of your IoT system also depends on the devices' software. It is important that devices run secure and up-to-date firmware.
Regular firmware updates: Devices should be updated regularly with security patches to close known vulnerabilities. Outdated firmware can be exploited by attackers.
Secure bootloaders: Some IoT systems use secure bootloaders that only allow verified firmware to be installed. This prevents malicious code from being installed.
It is also important to secure the network to which your IoT devices connect.
WiFi security: Use WPA3 (or at least WPA2) encryption on your WiFi network to prevent unauthorized access. Make sure the network password is strong and changed regularly.
Network segmentation: It is a good idea to separate your IoT devices from your primary network. For example, you can create a separate network just for IoT devices. This reduces the risk that a compromised device could provide access to important systems on your main network.
As you develop more advanced IoT systems, understanding communication protocols and implementing strong security measures will become increasingly important.
Both MQTT and RESTful APIs offer efficient ways for your devices to communicate — each with its own benefits depending on the use case.
Protecting your devices and data is just as important. By using secure communication channels, requiring authentication, keeping firmware updated, and securing your network, you can protect your system from a wide range of potential threats.
This lesson gives you a basic understanding of IoT protocols and security considerations. These concepts will become invaluable as you expand your projects, add new devices, and move into more complex and connected IoT environments.
About the measurements: The station in this series measures temperature and relative humidity using the AHT10. These are indoor climate readings, not direct measurements of CO2, VOCs, or particles. The series name “air quality monitoring” should be understood with this limitation.
Language