CoAP & LwM2M — REST and device management for constrained devices

iot · memo

In one line: CoAP (RFC 7252) is REST over UDP: GET/POST/PUT/DELETE and HTTP-like codes in a 4-byte binary header, reliability by confirmable messages with exponential backoff, push by Observe, big bodies by block-wise, security by DTLS or OSCORE. LwM2M (OMA SpecWorks) is device management on top of CoAP: a standard object/instance/resource tree (/3/0/3 = firmware version) plus bootstrap, registration, management and reporting interfaces.

Download PDF Print view LaTeX source

CoAP & LwM2M — REST and device management for constrained devices — figure 1

CoAP — how it works

  • UDP port 5683, DTLS 5684; TCP/TLS/WebSocket binding exists (RFC 8323) but UDP is the design point: no connection state, no head-of-line blocking.
  • Two layers: message layer (type + 16-bit Message ID: dedup, ACK matching) and request/response layer (Token, 0–8 bytes: matches responses and notifications to a request). Response = piggybacked in the ACK, or separate (empty ACK now, CON response later).
  • Reliability: CON waits for ACK; timeout random in 2–3 s (ACK_TIMEOUT 2 s × factor 1.5), doubled each time, 4 retransmits max. NON = fire-and-forget telemetry. RST = “I can’t handle this”.
  • Options are delta-encoded numbers: Uri-Path, Uri-Query, Content-Format (0 text, 50 JSON, 60 CBOR), Max-Age, ETag.
  • Observe: best-effort push of the latest state (intermediate states may be skipped), sequence numbers reorder, at least one CON per 24 h checks the observer is alive.
  • Block-wise (RFC 7959): Block2 = response body, Block1 = request body; NUM + More + size 2SZX+4 = 16…1024 B — firmware, fits 6LoWPAN MTUs.
  • Discovery: GET /.well-known/core → CoRE Link Format (</temp>;rt="temperature";if="sensor").
  • Security: DTLS with PSK, raw public key or X.509 (handshake RAM + round trips hurt); OSCORE (RFC 8613) protects the CoAP message itself end-to-end, through proxies.

CoAP vs MQTT vs HTTP

CoAPMQTTHTTP/1.1
TransportUDP (+DTLS)TCP (+TLS)TCP (+TLS)
Patternrequest/response + Observepub/sub via brokerrequest/response
Topologyclient ↔ device, no brokerstar around brokerclient → server
Header4 B binary2 B mintext, 100s of B
Sleepy / NATno session; NAT binding expires → server can’t reach devicekeepalive holds TCPpoll
Best atRESTful device mgmt, NB-IoT, 6LoWPANfan-out telemetry, many consumersphones, web, cloud APIs

LwM2M — the model

  • Path /Object/Instance/Resource: 0 Security · 1 Server · 2 Access Control · 3 Device · 4 Connectivity Monitoring · 5 Firmware Update · 6 Location; IPSO objects (3303 Temperature). Standard IDs = interoperable servers.
  • Resources are R, W or E (execute: POST /3/0/4 reboots). Formats: TLV, SenML JSON/CBOR, plain text.
  • Roles are inverted: the device is a CoAP client to register, and a CoAP server for its object tree.

The four interfaces

Bootstrapfactory-known bootstrap server writes /0 (server URI + DTLS keys) and /1 (lifetime, binding)
RegistrationPOST /rd?ep=<name>&lt=86400 + link list (</3/0>,</5/0>) → 2.01 + Location; Update before lt expires; DELETE = de-register
Device mgmt & service enablementRead (GET) · Write (PUT/POST) · Execute (POST) · Create · Delete · Discover · Write-Attributes
Information reportingObserve / Notify / Cancel; pmin/pmax attributes bound the notify rate

Firmware update with Object 5

Write /5/0/1 Package URI → device downloads (Block2) → State /5/0/3: 0 Idle → 1 Downloading → 2 Downloaded → server Executes /5/0/2 → 3 Updating → reboot → Update Result /5/0/5. Queue mode: a sleeping device’s requests wait until its next Update.

Interview traps

  • “CoAP runs over TCP” — UDP is the whole point.
  • Message ID ≠ Token: dedup/ACK vs request matching.
  • Observe is not a reliable stream — design for skipped notifications.
  • “LwM2M replaces MQTT” — management vs data; they coexist.

Remember

CON waits, NON flies · MID for the message, token for the request · Observe = latest · LwM2M = /object/instance/resource.

Likely questions

  1. Constrained sensor: CoAP or MQTT? — CoAP for sleepy UDP/NB-IoT and REST mgmt; MQTT for fan-out through a broker.
  2. Big payload over CoAP? — block-wise, never IP fragmentation.
  3. Where does the phone fit? — behind a gateway/proxy speaking HTTP/MQTT.