A final-year project with somewhere to go.

AspidIoT began as a question inside a final-year project: how can connected devices establish trust without carrying the weight of an enterprise stack? The answer became a working security framework—and then a product direction of its own.

We started with a constraint, not a feature list.

An FYP has a deadline, limited hardware, and no room for vague abstractions. That pressure gave AspidIoT its character: build the smallest trustworthy path from device identity to a secure session, then make every part understandable.

Can constrained devices earn trust?

The project began around a practical problem: connected devices need reliable identity and authentication, but they cannot afford unnecessary complexity or overhead.

Turn the research into a real exchange.

We shaped the idea around lightweight cryptography, device identity, and a four-step message flow that could be tested on the edge instead of only explained on paper.

Make the architecture visible.

Identity request, fresh challenge, proof response, and session confirmation became the spine of Auth-X: a sequence people can inspect, reason about, and build on.

Let the project grow beyond the submission.

The FYP became the starting point. AspidIoT is now being shaped as a product platform, with Auth-X as its first module and more focused security tools on the way.

Built for the lab. Recognized beyond it.

The project was not only designed and documented—it was demonstrated as a working system, then recognized by Habib University’s Computer Engineering program for the quality of its capstone design.

AspidIoT team receiving recognition for Best Capstone Design Project in Computer Engineering.
Academic validation

Best Capstone Design Project

Computer Engineering · Class of 2026 · Habib University

The recognition affirmed the engineering behind the work—and gave the project a stronger foundation to grow from a final-year submission into a product with a longer horizon.

The product grew. The principles stayed small.

AspidIoT is not trying to make connected systems feel heavier. It is about giving the edge the right security primitives, in a form that is focused enough to ship and clear enough to trust.

Edge efficiency

Lightweight by necessity

Every layer has to earn its place on a constrained device.

Session trust

Trust before traffic

Identity and freshness come before a session gets to move data.

Operational clarity

Built to be understood

Good security should be inspectable by the people who deploy it.

Auth-X is the first chapter, not the whole story.

The work is moving from a final-year milestone into a longer product journey: more modules, more experiments, and a clearer security foundation for the connected edge.