
© 2022 Elemental Machines - 771-00027 rev 01 Element U, EU2 User Manual elementalmachines.com7/8
Element-U User Manual
Model EU2
Positioning the Tablet Gateway
Tablet Gateways collect data from the Elements, collating it and
transmitting it across the internet to Elemental Machines’ Cloud.
The tablet Gateways’ default is to transmit by Wi-Fi; for added
reliability they fall back to Cellular connection when Wi-Fi connec-
tion drops out. There is a danger of data delay or even loss if all
connection is lost, so tablet Gateways should be positioned where
they are getting good Wi-Fi and Cellular connection.
The strength of the Wi-Fi and Cellular connection are displayed by
the Wi-Fi icon using Cellular bar icons. These icons are displayed
5: There is no way for outside users to get into the user's network
6: We do not listen to any ports; this is the case even if the user
opens ports 80, 123, or 443 for receipt
Tablet Gateways opens connections through port 80, 123, and 443
of a customer's firewall, opening only outbound connections.
Elemental Gateways require the following outbound TCP connec-
tions to be open on your firewall for the system to work:
• *.elementalmachines.io:443, TCP – for sending data to the
dashboard
• s3.amazonaws.com:[80|443], TCP – various files
• *.awmdm.com:443, TCP – device management
• play.google.com:443, TCP – provisioning
• android.googleapis.com:443, TCP – provisioning
• android.clients.google.com:80, TCP – app management
• time.windows.com:123, UDP – time synchronization
• *.pubnub.com:443, TCP – secure IoT device messaging
• *.pubnub.net:443, TCP – secure IoT device messaging
• *.pndsn.com:443, TCP – secure IoT device messaging
• *.papertrailapp.com:443, TCP – log management
Gateway-2’s open connections through ports 80, 123, and 443 of a
customer's firewall, opening only outbound connections.
Gateway-2’s require the following outbound TCP and/or UDP
connections to be open on your firewall for the system to work:
1. *.elementalmachines.io:443, TCP – for sending data to the
Elemental Machines Insights Dashboard™
2. s3.amazonaws.com:[80|443], TCP – various files
3. *.balena-cloud.com:443, TCP – for device management
4. *.docker.com:443, TCP – for verified operating system images
5. *.docker.io:443, TCP – for verified operating system images
6. time.elementalmachines.io:123, UDP – for time synchronization
7. 8.8.8.8:443, TCP – for DNS resolution
Elemental Machines Sensory Network Secu-
rity Overview
The Elemental Machines Sensory Network is designed to operate
securely on our customers’ networks. The system includes
Elements, wireless devices that monitor critical equipment and/or
the ambient environment, Elemental Gateways, which gather data
from Elements, and the Elemental Machines Insights Dashboard™.
Local Communication
Individual Elements communicate to a local Gateway via a low
power 2.4GHz wireless communication protocol, typically 8 dBm or
lower power. Only whitelisted devices can connect with the
Gateway; the whitelist is populated prior to shipping and adjusted
with any subsequent additions to the network.
Communication through Customer Wi-Fi:
The system uses established communication and security
standards to protect data transmitted between Gateways and the
Elemental Machines Insights Dashboard™ .
• TLS, the web standard for protecting sensitive data including
usernames, passwords, credit card, and banking information.
• Asymmetric Cryptography is used to encrypt the data transmit-
ted. The keys for this symmetric encryption are generated
uniquely for each connection and are based on a shared secret
negotiated at the start of the session.
The Elemental Machines’ Sensory Network external communica-
tion is designed to work even in the strictest environments. The
communication uses an adaptive transport mechanism that is
designed to work well when confronted with proxy authorities,
firewalls, and antivirus software.
No inbound ports need to be opened. Security vulnerability using
the above configuration is prevented as follows:
1: Internet Communication over port 80, 123, and 443
2: Device must be able to transmit outward to the Internet on 443
3: Clients do not open inbound ports
4: There is no need to open the firewall to receive on port 80, 123,
or 443
on the tablet Gateway to the left of the battery percentage.
• 4 or more bars for both Wi-Fi and cell indicate good
connectivity
• 2 bars for both Wi-Fi and cell runs an increased risk of some
data delay or loss
• <2 bars for cell or Wi-Fi carry a danger of significant data delay
or loss