Skip to content

Author

Rida Lkhluf

1 paper indexed here

We haven’t gathered this author’s papers yet. Follow them and we’ll fetch their work.

Not the right person? Other researchers publish under this name.

Open access Aug 2026

Blockchain-Assisted Authentication, Authorization, and Audit for MQTT-Based Smart-City IoT

Smart-city services increasingly rely on Internet of Things (IoT) deployments using lightweight Message Queuing Telemetry Transport (MQTT), yet weakly protected systems remain exposed to spoofing, unauthorized state changes, and limited accountability. This work evaluates blockchain and smart contracts as a complementary trust layer for MQTT-based smart-city IoT rather than as a replacement for transport-layer security. The proposed architecture provides owner-controlled device registration, per-sensor nonce management, replay-resistant Elliptic Curve Digital Signature Algorithm (ECDSA) authentication, authorization of state-changing operations, and tamper-evident event logging. MQTT confidentiality remains dependent on Transport Layer Security (TLS) or payload encryption. A prototype was implemented using ESP32 microcontrollers, a Raspberry Pi MQTT broker, Node-RED supervision, MongoDB storage, and Ethereum smart contracts deployed on Sepolia. The evaluation combines practical attack scenarios (unauthorized sensor modification, identity spoofing, and data manipulation) with measurements of blockchain latency, throughput, and gas consumption. Results show auditable nonce-bound signed updates, with mean transaction latency close to 12 s. Because the contract updates one sensor per transaction, costs are interpreted per confirmed write operation and scenario size. The findings position blockchain as an audit and policy-enforcement component for MQTT-based IoT.

Rida Lkhluf, David Santo Orcero, F. J. Cañete · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.