Skip to content
Open access

BDLock: A blockchain-enabled two tier privacy-aware federated idam service platform using RBAC

Oct 2026 · International Journal of Electrical and Computer Engineering (IJECE) · 0 citations

Abstract

Centralized identity and access management (IDAM) systems suffer from sin-gle points of failure, lack of authorization transparency, and susceptibility to in-sider threats and privilege abuse. While role-based access control (RBAC) of-fers structured permission management, its enforcement through centralized pol-icy engines introduces auditability gaps unacceptable in modern distributed service delivery environments. This paper presents BDLock, a blockchain-enabled two-tier privacy-aware federated IDAM platform integrating OAuth 2.0, OpenID Connect (OIDC), and Hyperledger Fabric 2.4. The first tier validates JSON Web Tokens (JWT) issued by Keycloak against a Spring Boot resource server, the second tier enforces immutable scope-based RBAC rights on the Hyperledger Fabric ledger, ensuring every access decision is tamper-proof and auditable. Unlike prior approaches, BDLock uniquely bridges OAuth-authenticated off-chain identities to cryptographic on-chain Fabric wallet identities, satisfying all six STRIDE-modelled threats categories across both Web2 and Web3 identity models. Validated with up to 1,800 concurrent users, BDLock achieves a peak throughput of approximately 200 transactions per second using round-robin load balancing. At high concurrency, it outperforms single-peer fallback by up to 25%. Furthermore, it maintains uninterrupted access control during peer failures, eliminating the single point of failure found in all nine compared state-of-the-art systems.

Read PDF

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.