A Blockchain-based Dual Identity Management and Authentication Framework for IoT Networks
Dana Haj Hussein, Ethan Houlahan, Alexandre Janelle-Goode, Thomas Lumsden, Mohamed A. Ibnkahla · 2024
The widespread adoption of Internet of Things (IoT) devices has introduced an era of unparalleled connectivity and data-driven innovation. Nevertheless, this rapid proliferation introduced significant security challenges. The limited computational capabilities of IoT devices impose constraints on the implementation of robust security mechanisms, rendering them susceptible to malicious attacks. Additionally, the dynamic nature of IoT systems which allows multiple administrators to add or remove IoT devices, necessitates the establishment of an identity management system. This system is crucial for managing both devices and system users, ensuring the traceability of device registration activities, and maintaining accountability of system users. Furthermore, traditional centralized authentication systems encounter scalability issues and high costs associated with centralized servers. To address these challenges, this paper proposes a Dual Identity Management and Authentication (DIMA) framework, leveraging blockchain technology. The proposed framework addresses two primary issues. Firstly, it assigns dual identities to each IoT node, facilitating a secure authentication process and regulating network access. Secondly, it supports the traceability of system device registration activities, enabling accountability for system users and ensuring a secure administrator-in-the-loop device identification process. Moreover, experimental testing and security analysis are undertaken to validate the usability and ascertain the critical security strengths of the DIMA framework.