A Lightweight Authentication Using Binary Fuse Filters in Resource Constrained IoT
Iain Baird, Isam Wadhaj, Baraq Ghaleb, Gordon Russell, Thomson, Craig · Edinburgh Napier Research Repository (Edinburgh Napier University)
The IPv6 Routing Protocol for Low-Power and Lossy Networks (RPL) remains highly vulnerable to control-plane abuse, particularly DIS flooding and Sybil attacks, which force repeated DIO transmissions , destabilise the topology and drain the limited energy reserves of IoT devices. This paper presents a lightweight defence that combines Binary Fuse Filters (BFFs) with hash-chain authentication to validate DIS messages efficiently on severely constrained motes. Unlike traditional cryptographic defences, the proposed mechanism performs efficient verification using compact fingerprints, avoiding asymmetric operations and reducing memory overhead.The framework is implemented in Contiki 3.0 and is evaluated on Sky motes within the Cooja simulator under sustained flooding and insider-forged hash scenarios. The results show that the scheme preserves routing stability while reducing network power consumption by up to 52% compared to unmitigated RPL, with a memory increase of only ≈ 6.8%.The system maintains near-baseline DIO activity and achieves very low false-positive rates (≤ 1.06% under worst-case insider conditions). These findings demonstrate that BFF-based authentication provides an effective and practical means of securing RPL control traffic in resource-constrained IoT deployments.