Skip to content
Open access

OPAQUE-IoT: an optimization-driven PUF-Blockchain authenticated key agreement protocol with adaptive resource management for constrained IoT networks

Aug 2026 · Journal of King Saud University: Computer and Information Sciences · Vol 38 · 0 citations · 45 references

TL;DR

OPAQUE-IoT, an Optimization-driven PUF-Blockchain AKA Protocol for constrained IoT networks integrates PUF-based hardware identity verification, a permissioned blockchain for decentralized trust management, and the Adaptive Security-Energy Trade-off Optimizer (ASETO), which jointly minimizes authentication latency and energy consumption under formal security constraints.

Abstract

Security in resource-constrained IoT deployments remains a persistent challenge: devices used in industrial control, smart healthcare, and transportation must authenticate quickly, consume minimal energy, and resist physical attacks — yet existing protocols rarely address all three requirements at once. To the best of current knowledge, no prior protocol jointly optimises security, energy, and latency within a single formally verified framework. This paper presents OPAQUE-IoT, an Optimization-driven PUF-Blockchain AKA Protocol for constrained IoT networks. The framework integrates PUF-based hardware identity verification, a permissioned blockchain for decentralized trust management, and the Adaptive Security-Energy Trade-off Optimizer (ASETO), which jointly minimizes authentication latency and energy consumption under formal security constraints. Convergence of ASETO is proven under Lipschitz-continuous objective functions. Formal security analysis under the Real-or-Random (RoR) model with explicit Random Oracle and ECDH hardness assumptions demonstrates resistance to replay, impersonation, man-in-the-middle, PUF modeling, insider, and side-channel attacks, with a security advantage bound of approximately 2^(-68). Simulation results across heterogeneous IoT topologies (N = 50 to 5000 devices) show 31.8% lower energy consumption, 30.2% reduced authentication latency, and 41.1% higher throughput compared to the best-performing blockchain-capable baseline, with O(log N) Merkle-indexed blockchain query complexity and O(T_max·N·P) per-epoch optimiser complexity.

Read PDF

Similar papers

Open access 2026

A Hardware-Rooted Blockchain Security Framework for IoT With PUF-Based Authentication

By using PUF-generated responses as hardware-rooted seeds for mining and authentication, the framework removes the need for permanent secret storage and establishes a secure chain from device identity to consensus participation, making it suitable for practical deployment in industrial IoT, smart infrastructure, and other resource-constrained distributed systems.

B. Narayanapuram, J. Panda · 0 citations
Open access Jul 2026

EPoLBFT: A Blockchain Consensus Algorithm for Enhancing Privacy, Invulnerability and Trust in IoT System

Elastic Proof-of-Location Byzantine Fault Tolerance is proposed, a privacy-preserving and location-aware blockchain consensus framework for IoT systems that reduces communication overhead and improves consensus efficiency compared with conventional PBFT-based approaches while strengthening resilience against location-based and identity-based attacks.

Yunus Kareem, D. Djenouri, Essam Ghadafi · 0 citations
Open access Aug 2026

Blockchain-Assisted Lightweight Authentication Protocol for Resource-Constrained IoT Devices in 5G Smart Environments

BLAP-IoT is introduced: a Blockchain-Assisted Lightweight Authentication Protocol over live Hyperledger Fabric 2.5 that leverages elliptic-curve Diffie–Hellman over P-256 curve, keyed MACs, and a three-message challenge-response protocol to provide injective mutual authentication with device key confirmation.

Musadak Maher Abdul Zahra · 0 citations
Open access Jul 2026

A Blockchain-Based Lightweight Authentication Framework for Secure Communication in IoT Networks

A lightweight blockchain-based authentication framework for secure communication in Internet of Things (IoT) networks that integrates a permissioned blockchain with ECC-256 to provide mutual authentication, data integrity, and non-repudiation for resource-constrained IoT devices.

A. Abu-Ein, Obaida M. Al-hazaimeh · 0 citations
Open access Aug 2026

Blockchain-Assisted Authentication, Authorization, and Audit for MQTT-Based Smart-City IoT

Smart-city services increasingly rely on Internet of Things (IoT) deployments using lightweight Message Queuing Telemetry Transport (MQTT), yet weakly protected systems remain exposed to spoofing, unauthorized state changes, and limited accountability. This work evaluates blockchain and smart contracts as a complementary trust layer for MQTT-based smart-city IoT rather than as a replacement for transport-layer security. The proposed architecture provides owner-controlled device registration, per-sensor nonce management, replay-resistant Elliptic Curve Digital Signature Algorithm (ECDSA) authentication, authorization of state-changing operations, and tamper-evident event logging. MQTT confidentiality remains dependent on Transport Layer Security (TLS) or payload encryption. A prototype was implemented using ESP32 microcontrollers, a Raspberry Pi MQTT broker, Node-RED supervision, MongoDB storage, and Ethereum smart contracts deployed on Sepolia. The evaluation combines practical attack scenarios (unauthorized sensor modification, identity spoofing, and data manipulation) with measurements of blockchain latency, throughput, and gas consumption. Results show auditable nonce-bound signed updates, with mean transaction latency close to 12 s. Because the contract updates one sensor per transaction, costs are interpreted per confirmed write operation and scenario size. The findings position blockchain as an audit and policy-enforcement component for MQTT-based IoT.

Rida Lkhluf, David Santo Orcero, F. J. Cañete · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.