PDF Basket
Cars that talk to traffic lights and one another. Medical sensors that monitor patients at home. Factory machines that configure themselves on the go. As the internet of things (IoT) expands into everyday life, the challenge is no longer simply connecting devices, but ensuring those connections remain secure and private. Many devices are deployed with limited protection, leaving vulnerabilities across their entire life cycle.
The ERATOSTHENES project focused on the challenge of managing the trust, identity and security of connected devices. Additionally, the NIS Directive, GDPR and the EU Cybersecurity Act have set new expectations for risk management and data protection.
“We realised that trust is considered as a static given,” says project coordinator Konstantinos Loupos, R&D director at INLECOM INNOVATION. “But connected devices increase and change constantly. Their security needs to change with them from the design phase.”
Rather than chasing individual vulnerabilities, the team set out a holistic framework and network architecture to secure IoT systems from the moment a device is introduced into a network through to its eventual retirement.
A different approach to IoT security
At the heart of the project was a shift in perspective. Instead of adding security layers on top of existing systems, the team designed a framework where identity, trust and accountability are built in from the start. Devices can be securely registered, authenticated and updated as their role, software and ownership evolve, without relying on a single central authority.
That approach was as much about people as technology. Engineers had to accept that assumptions from traditional IT security do not hold in the IoT world, where devices are constrained by power, bandwidth and long lifespans, and are often deployed in places where maintenance is difficult or expensive.
“Some approaches that work well in conventional networks often prove not applicable in more dynamic settings,” Loupos adds. “You quickly learn that theoretical solutions fall apart when you try to apply them in real dynamic environments.”
Testing trust in the real world
To test whether its approach could work outside the lab, ERATOSTHENES validated its framework through three pilot scenarios.
In the connected vehicle pilot, the technology was integrated into in-vehicle and roadside systems, managing trust and identity as vehicles joined and left the network. In healthcare, the framework was tested with remote patient monitoring devices, securing sensitive data while allowing devices to be updated and managed safely over long periods. A third pilot focused on industrial IoT, where trust and identity mechanisms were deployed in production without disrupting existing operations.
Across all three demos, the deployment exposed challenges that rarely appear in design documents, forcing the team to refine both the technical architecture and their assumptions about how trust should be managed in operational settings.
Learning by working together
Collaboration was central to the project’s progress. Researchers, technology providers and end users worked side by side, combining development with hands-on testing. Various long staff exchanges placed researchers inside partner infrastructures, while expert visits and training sessions brought new equipment and experience to teams who had previously worked mainly in theory.
During the design stages of ERATOSTHENES, the project organised four project dedicated workshops and contributed to others, bringing in end users and experts to validate the system and challenge the design. Hackathons also supported real-life implementation and deployment of actual industrial challenges.
“Working together exposed the real benefits of the technology under industrial settings,” Loupos remarks. “That’s what allowed us to design the architecture as a reference in a meaningful way for the research and industry.”
The work produced tangible results, including dozens of scientific publications, early-stage prototypes and several EU-United States patent applications.
ERATOSTHENES concluded in 2025, but the momentum continues. Partners are building on the results through new research proposals and continued collaboration, while the identity and trust framework are now being reused in commercial applications, including electronic voting in Greece.
