Secure Blockchain-Based Identity Authentication Mechanism for Edge-IoT Networks
Abstract
Identity authentication in Internet of Things (IoT) networks is challenging due to limited device resources, decentralized architectures, and the need for secure, fast, and energy-efficient communication. Traditional methods, such as Public Key Infrastructure (PKI), often fall short due to high latency and central points of failure, whereas existing blockchain-based approaches lack continual identity verification and dynamic trust management. To address these limitations, this paper proposes the Secure Blockchain-based Identity Authentication (SBIA) mechanism for edge-IoT networks. SBIA builds on standard SM9 identity-based cryptography and introduces four methods enforcing the zero-trust principle of “never trust, always verify.” The proposed four methods are 1) Device-Attribute Identity Binding (DAIB), which binds attested device attributes to a permanent cryptographic identity as a versioned on-chain record, so that spoofing is mitigated without the identity breaking when attributes legitimately change; 2) Lightweight Single-Round Authorization (LSRA), which combines identity, nonce, and ephemeral-key verification in an authenticated exchange to reduce initial-access latency. 3) Continual Verification Token Generation (CVTG), which periodically re-verifies IoT devices with time-bound, single-use tokens, and 4) Threshold-based Credential Revocation (TCR), which revokes IoT devices’ credentials after repeated verification failures. In addition, a two-layer blockchain architecture supports the mechanism: the main blockchain records authoritative registration and revocation decisions, and base-station sidechains maintain synchronized credential state for local credential and signature verification. Cross-chain smart contracts propagate finalized credential-state updates without relaying live authentication messages. SBIA derives session keys from authenticated ephemeral values rather than public nonces alone and never transmits session keys in plaintext. Experimental evaluations demonstrate that SBIA reduces authentication delay by 39% (22.7 ms) and energy consumption by 40% (13.22 mJ) on average compared to existing mechanisms. A formal security analysis, a BAN logic derivation, and ProVerif-based verification establish the security of the mechanism, while BAN-based and experimental ablation studies confirm the necessity of each proposed method for achieving continual identity verification.