Skip to content
English
  • There are no suggestions because the search field is empty.

DevNonce issue

KONA Core: Device cannot join or reconnect due to repeated DevNonce values

Overview

A device may initially connect to KONA Core successfully but later become unable to join the network again. Other devices on the same server may continue working normally.

One possible cause is the device repeatedly using the same DevNonce values in its join requests. This article explains that specific issue and how to resolve it.

What causes this?

When a LoRaWAN device requests to join the network, it sends a security value called a DevNonce. LoRaWAN treats a repeated DevNonce as a replay attempt and requires the network to refuse it. KONA Core keeps a record of the DevNonce values each device has recently used and rejects a join request that repeats one of them. A rejected join request gets no Join Accept, so the device keeps sending join requests and no uplinks follow.

For example, an affected device may repeatedly cycle through the values 0, 1, 2, 3 and 4. Once those values have been used, subsequent attempts repeat a previously used value, and KONA Core rejects the request.

When repeated DevNonce values are confirmed as the cause, KONA Core is enforcing the expected security requirement. The underlying problem is the device’s handling of these values, rather than the KONA Core installation.

Permanent resolution

Contact the device manufacturer for a firmware update that corrects how the device generates and stores its DevNonce values.

The firmware must prevent values from being reused, including after the device restarts or loses power. For devices using an incrementing DevNonce counter, this means saving the counter and continuing from its previous value rather than resetting it to zero. For devices that generate a random DevNonce, the value must be chosen from the full 16-bit range (0 to 65535), not from a small set of values.

Temporary workaround

For a device affected by this issue, deleting it from KONA Core and adding it again can allow it to connect again.

  1. Before deleting the device, securely save its provisioning details, including its device identifiers, activation keys and configuration settings.

  2. Delete the affected device from KONA Core, then add it again using the original provisioning details.

  3. Initiate a new join attempt according to the device manufacturer’s instructions.

This is a temporary recovery step, not a permanent fix. The device may become unable to connect again when it repeats the same values. A firmware correction from the device manufacturer is still required.

Need assistance?

Contact TEKTELIC Support to confirm whether repeated DevNonce values are causing the connection failure. Include the device model, firmware version and device identifier (DevEUI).