Edge-computing-based lightweight identity authentication and automated access control for distribution Internet of Things
Abstract
Distribution Internet of Things (DIoT) connects smart meters, feeder terminal units, distributed-energy controllers, charging facilities, and optical inspection nodes to edge gateways and automated control platforms. Conventional certificate-heavy authentication creates excessive latency for resource-constrained devices, whereas static access-control lists cannot respond to credential abuse or abnormal command behavior. This paper proposes Lightweight Identity Authentication and Access Management for Distribution Internet of Things (LIAM-DIoT), an edge-computing method for lightweight identity verification and automated risk-aware access control. Routine sessions use a rotating 96-bit pseudonym, a three-message BLAKE2s-based mutual-authentication exchange, a one-way key-evolution chain, and a 128-bit scoped capability token. A compact X25519 refresh is triggered only for step-up authentication, policy changes, or elevated risk, and the edge policy engine selects permit, step-up, or quarantine states without waiting for the cloud. A reproducible discrete-event evaluation with 10,000 logical devices and 250,000 sessions shows a device-side authentication time of 0.82 ms, 156 bytes of authentication traffic, and 0.061 mJ estimated energy per fast session. At 700 requests/s, the gateway 95th-percentile (p95) decision latency is 12.1 ms, while replay, impersonation, cloned-device, and flooding traces are detected with a mean true-positive rate of 98.7% and a 1.2% false-alarm rate. The method therefore provides a practical trust boundary for camera and light detection and ranging (LiDAR) event streams, fiber-connected gateways, and closed-loop distribution automation.