HADA: A Hybrid Authentication and Dynamic Attribute Access Control Mechanism for the Internet of Things Using Hyperledger Fabric Blockchain
Abstract
1. Introduction
- Implementing hashing and cryptographic algorithms with higher computational requirements unsuitable for resource-constrained IoT devices.
- Defining policies based on attributes for devices and users in a scalable manner is challenging.
- To implement a dynamic attribute selection framework that adapts to changing data patterns and user requirements in real time.
- To optimize system performance through parallel processing techniques in deep learning models, enabling efficient handling of large-scale attribute selection and access control decisions across distributed environments.
- To develop a robust authentication framework that combines traditional user security credentials with dynamic trust evaluation to enhance the security and reliability of access control systems in distributed environments.
- To design and implement a lightweight hashing mechanism within the HLF blockchain framework that optimizes resource utilization while maintaining security guarantees, with the aim of improving performance in resource-constrained environments.
1.1. Contributions of This Paper
- To prevent the participation of illegitimate data owners and users, a multi-level authentication framework is developed using identity verification, digital certificates, and Re-Physical Unclonable Function (PUF)–based device authentication, followed by trust validation. The authenticated data owner employs the lightweight SKINNY encryption algorithm to securely encrypt the data prior to cloud or network upload.
- To enhance the integrity and confidentiality of user and owner credentials, the lightweight SPONGENT hashing algorithm is integrated within the HLF blockchain environment, enabling secure and tamper-resistant storage of credential hashes.
- To support adaptive and context-aware attribute selection, a dynamic attribute-based access control (ABAC) mechanism is designed using a Bi-Fuzzy Q-Learning approach. As multiple users with varying requirements interact within the system, the model selects an optimal set of access attributes for each time period, ensuring flexible, fine-grained, and intelligent access management.
1.2. Organization of This Paper
2. Related Works
3. Problem Statement
- Trust value detection is based on false positive and false negative values. However, the node’s behavior and node communication are important for identifying whether a particular node is legitimate or malicious.
- In general, smart contracts are static and cannot be modified, so the trust calculation contracts developed cannot be the same for the devices at all times as the trust value of a device will be updated dynamically according to its behavior.
- The traditional algorithm SHA-256, used in the blockchain, requires multiple computations that slow the system when used continuously. It operates slower than lightweight hashing algorithms that increase latency.
- In previous research works on authentication, either credentials are validated or the trust value is estimated for validation. However, when the credentials are stored once the user is registered while the trust value is estimated dynamically according to activity, both are significant in authentication, an approach that has been unsuccessful in previous research.
- The attribute access control mechanisms consider a set of attributes which are always validated every time the user requests access; an increase in the number of attributes will increase time to validation.
4. Proposed HADA Control Mechanism
4.1. HADA System Model
4.2. DO and DU Registration and Authentication
4.2.1. Data Owner Registration
| Algorithm 1. Laplace Mechanism |
| add_laplace_noise(true_value, sensitivity, epsilon): |
| # Scale parameter is sensitivity/epsilon |
| scale = sensitivity/epsilon |
| # Generate noise from Laplace distribution |
| noise = np.random.laplace(0, scale) |
| # Return noisy value |
| return true_value + noise |
4.2.2. Data Owner Authentication
- (i)
- Add Round Key: In this step, the current state is combined with the round key using the bitwise exclusive-OR operator. Let the be the round key for this current round, which iswhere S is the current state matrix, is derived from the key-scheduling algorithm, and is the bitwise XOR operator. This step is significant independent of the secret key, and a single change in the key is reflected in the cipher text.
- (ii)
- Sub-Cells: In this step, a 4-bit substitution-box (S-box) is considered for each state which is non-linear:It maps each 4-bit input to the 4-bit output, facilitating resistance to differential and linear cryptanalysis. Let be the individual 4-bit cell, which is mathematically represented as follows:
- (iii)
- Shift Row: The diffusion is increased based on the performance of rotation on the row of state matrix.The state matrix is given asThe rows are shifted from one position to another; as a result, this operation distributes each byte across more than one column and enriches inter-column dependency.
- (iv)
- Mix Columns: The mix of columns on any single bit is reflected in the state of input. Maximum Distance Separable (MDS) matrix transformation is executed as follows:Finally, rounds are completed, and the output is cipher text, :
4.2.3. Data User Registration
4.2.4. Data User Authentication
4.3. Dynamic Attribute Selection and Attribute-Based Access Control
| Algorithm 2. Final Access Decision Rule |
| 1. Begin |
| 2. If argmax |
| { |
| It allows access |
| Else if argmax |
| { |
| It denies access |
| } |
| End if |
| } |
| 3. Stop |
4.4. Hyperledger Fabric Blockchain
- (i)
- S-Box Layer:
- (ii)
- Bit Permutation:
- (iiI)
- Mixing Layer: To enhance the cryptanalysis, an additional mixing function is performed that enables updates to the changes throughout all states.
5. Experimental Analysis
5.1. Simulation Setup
5.2. Comparative Analysis
5.2.1. Performance of Throughput
5.2.2. Latency Performance
5.2.3. Performance of Resource Utilization
5.2.4. Performance of Accuracy
5.3. Complexity Analysis
5.3.1. Analysis of SPONGENT Algorithm
5.3.2. Analysis of SKINNY Algorithm
5.4. Security Analysis
5.4.1. Confidentiality
5.4.2. Integrity
5.4.3. Trustworthiness
5.4.4. Non-Repudiation
5.4.5. Authorization
6. Conclusions
Funding
Institutional Review Board Statement
Informed Consent Statement
Data Availability Statement
Conflicts of Interest
References
- Choudhary, A. Internet of Things: A comprehensive overview, architectures, applications, simulation tools, challenges and future directions. Discov. Internet Things 2024, 4, 31. [Google Scholar] [CrossRef]
- Abbas, Z.; Ahmad, S.F.; Syed, M.H.; Anjum, A.; Rehman, S. Exploring Deep Federated Learning for the Internet of Things: A GDPR-Compliant Architecture. IEEE Access 2024, 12, 10548–10574. [Google Scholar] [CrossRef]
- He, Z.; Li, D. The Short Video Popularity Prediction Using Internet of Things and Deep Learning. IEEE Access 2024, 12, 47508–47517. [Google Scholar] [CrossRef]
- Sana, S.; Al-Qerem, M.A.; Alauthman, M.; Al-Mistarihi, M. Blockchain-IoT Healthcare Applications and Trends: A Review. IEEE Access 2024, 12, 4178–4197. [Google Scholar]
- Pakrooh, R.; Jabbari, A.; Fung, C. Deep Learning-Assisted Security and Privacy Provisioning in the Internet of Medical Things Systems: A Survey on Recent Advances. IEEE Access 2024, 12, 40610–40621. [Google Scholar] [CrossRef]
- Almarri, S.; Aljughaiman, A. Blockchain Technology for IoT Security and Trust: A Comprehensive SLR. Sustainability 2024, 16, 10177. [Google Scholar] [CrossRef]
- Villegas-Ch, W.; Gutierrez, R.; Sánchez-Salazar, I.; Mera-Navarrete, A. Adaptive Security Framework for the Internet of Things: Improving Threat Detection and Energy Optimization in Distributed Environments. IEEE Access 2024, 12, 157924–157944. [Google Scholar] [CrossRef]
- Obaidat, M.A.; Obeidat, S.; Holst, J.; Al Hayajneh, A.; Brown, J. A Comprehensive and Systematic Survey on the Internet of Things: Security and Privacy Challenges, Security Frameworks, Enabling Technologies, Threats, Vulnerabilities and Countermeasures. Computers 2020, 9, 44. [Google Scholar] [CrossRef]
- Hasan, M.K.; Weichen, Z.; Safie, N.; Ahmed, F.R.A.; Ghazal, T.M. A survey on key agreement and authentication protocol for Internet of Things application. IEEE Access 2024, 12, 61642–61666. [Google Scholar] [CrossRef]
- Dritsas, E.; Trigka, M. A Survey on Cybersecurity in IoT. Future Internet 2025, 17, 30. [Google Scholar] [CrossRef]
- Zhao, W.; Yang, S.; Luo, X. Blockchain-Facilitated Cybersecurity for Ubiquitous Internet of Things with Space–Air–Ground Integrated Networks: A Survey. Sensors 2025, 25, 383. [Google Scholar] [CrossRef]
- Alotaibi, B. A Survey on Industrial Internet of Things Security: Requirements, Attacks, AI-Based Solutions, and Edge Computing Opportunities. Sensors 2023, 23, 7470. [Google Scholar] [CrossRef] [PubMed]
- Wang, X.; Garg, S.; Lin, H.; Hu, J.; Kaddoum, G.; Piran, J.; Hossain, M.S. Toward Accurate Anomaly Detection in Industrial Internet of Things Using Hierarchical Federated Learning. IEEE Internet Things J. 2022, 9, 7110–7119. [Google Scholar]
- Zaidi, S.Y.A.; Shah, M.A.; Khattak, H.A.; Maple, C.; Rauf, H.T.; El-Sherbeeny, A.M.; El-Meligy, M.A. An Attribute-Based Access Control for IoT Using Blockchain and Smart Contracts. Sustainability 2021, 13, 10556. [Google Scholar] [CrossRef]
- Kalaria, R.; Kayes, A.S.M.; Rahayu, W.; Pardede, E.; Shahraki, A.S. Adaptive Context-Aware Access Control for IoT Environments Leveraging Fog Computing. Int. J. Inf. Secur. 2024, 23, 3089–3107. [Google Scholar] [CrossRef]
- Zhang, J.; Yuan, L.; Xu, S. A lightweight blockchain-based access control scheme for integrated edge computing in the internet of things. arXiv 2021, arXiv:2111.06544. [Google Scholar] [CrossRef]
- Huang, Y.; Yen, I.-L.; Bastani, F. Collaborative Access Control for IoT—A Blockchain Approach. In Proceedings of the 2024 IEEE International Conference on Blockchain and Distributed Systems Security (ICBDS), Pune, India, 17–19 October 2024; pp. 1–6. [Google Scholar]
- Shammar, E.A.; Zahary, A.T.; Al-Shargabi, A.A. An Attribute-Based Access Control Model for Internet of Things Using Hyperledger Fabric Blockchain. Wirel. Commun. Mob. Comput. 2022, 2022, 6926408. [Google Scholar] [CrossRef]
- Ullah, S.S.; Oleshchuk, V.; Pussewalage, H.S.G. A survey on blockchain-envisioned attribute-based access control for Internet of Things: Overview, comparative analysis, and open research challenges. Comput. Netw. 2023, 235, 109994. [Google Scholar] [CrossRef]
- Han, J.; Li, Z.; Liu, J.; Wang, H.; Xian, M.; Zhang, Y.; Chen, Y. Attribute-Based Access Control Meets Blockchain-Enabled Searchable Encryption: A Flexible and Privacy-Preserving Framework for Multi-User Search. Electronics 2022, 11, 2536. [Google Scholar] [CrossRef]
- Yan, L.; Ge, L.; Wang, Z.; Zhang, G.; Xu, J.; Hu, Z. Access Control Scheme Based on Blockchain and Attribute-Based Searchable Encryption in Cloud Environment. J. Cloud Comput. 2023, 12, 61. [Google Scholar] [CrossRef]
- Chaudhary, D.; Santhi, P.; Durgarao, M.S.P.; Padmavathi, A.; Hassan, M.M.; Alkhamees, B.F. Module Lattice-Based Post Quantum Secure Blockchain Empowered Authentication Framework for Autonomous Truck Platooning. IEEE Access 2024, 12, 105219–105233. [Google Scholar] [CrossRef]
- Al Hwaitat, A.K.; Almaiah, M.A.; Ali, A.; Al-Otaibi, S.; Shishakly, R.; Lutfi, A.; Alrawad, M. A New Blockchain-Based Authentication Framework for Secure IoT Networks. Electronics 2023, 12, 3618. [Google Scholar] [CrossRef]
- McCabe, C.; Mohideen, A.I.C.; Singh, R. A Blockchain-Based Authentication Mechanism for Enhanced Security. Sensors 2024, 24, 5830. [Google Scholar] [CrossRef] [PubMed]
- Wu, M.; You, L.; Hu, G.; Li, L.; Cao, C. A blockchain-based hierarchical authentication scheme for multiserver architecture. Secur. Commun. Netw. 2021, 2021, 5592119. [Google Scholar] [CrossRef]
- Liu, H.; Han, D.; Li, D. Fabric-IoT: A Blockchain-Based Access Control System in IoT. IEEE Access 2020, 8, 18207–18218. [Google Scholar] [CrossRef]
- Jena, S.K.; Kumar, B.; Mohanty, B.; Singhal, A.; Barik, R.C. An Advanced Blockchain-Based Hyperledger Fabric Solution for Tracing Fraudulent Claims in the Healthcare Industry. Decis. Anal. J. 2023, 10, 100411. [Google Scholar] [CrossRef]
- Xie, B.; Zhou, Y.-P.; Yi, X.-Y.; Wang, C.-Y. An Improved Multi-Authority Attribute Access Control Scheme Base on Blockchain and Elliptic Curve for Efficient and Secure Data Sharing. Electronics 2023, 12, 1691. [Google Scholar] [CrossRef]
- Alabdulatif, A. Blockchain-Based Privacy-Preserving Authentication and Access Control Model for E-Health Users. Information 2025, 16, 219. [Google Scholar] [CrossRef]
- Nie, S.; Ren, J.; Wu, R.; Han, P.; Han, Z.; Wan, W. Zero-Trust Access Control Mechanism Based on Blockchain and Inner-Product Encryption in the Internet of Things in a 6G Environment. Sensors 2025, 25, 550. [Google Scholar] [CrossRef]
- Shih, D.-H.; Wu, T.-W.; Shih, M.-H.; Chen, G.-W.; Yen, D.C. Hyperledger Fabric Access Control for Industrial Internet of Things. Appl. Sci. 2022, 12, 3125. [Google Scholar] [CrossRef]
- Alniamy, A.; Taylor, B.D. Attribute-Based Access Control of Data Sharing Based on Hyperledger Blockchain. In Proceedings of the 2020 International Conference on Blockchain Technology, Association for Computing Machinery; Association for Computing Machinery: New York, NY, USA, 2020; pp. 135–139. [Google Scholar]
- Karankar, N.; Seth, A. An IoT System for Access Control Using Blockchain and Message Queuing System. EURASIP J. Inf. Secur. 2025, 2025, 31. [Google Scholar] [CrossRef]
- Javanmardi, S.; Scarpa, M.; Shojafar, M.; Distefano, S.; Merlino, G. Mutable Blockchains in IoT-Driven Sustainable Urban Planning: Challenges, and Analytical Modeling. In 2025 IEEE International Conference on Smart Computing (SMARTCOMP); IEEE: Piscataway, NJ, USA, 2025; pp. 408–413. [Google Scholar]
- Shi, G.; Qi, M.; Zhong, Q.; Li, N.; Gao, W.; Zhang, L.; Gao, L. MedAccessX: A Blockchain-Enabled Dynamic Access Control Framework for IoMT Networks. Sensors 2025, 25, 1857. [Google Scholar] [CrossRef]
- Wang, C.; Wu, W.; Chen, F.; Shu, H.; Zhang, J.; Zhang, Y.; Wang, T.; Xie, D.; Zhao, C. A Blockchain-Based Trustworthy Access Control Scheme for Medical Data Sharing. IET Inf. Secur. 2024, 1, 5559522. [Google Scholar] [CrossRef]
- Pathak, A.; Al-Anbagi, I.; Hamilton, H.J. TABI: Trust-Based ABAC Mechanism for Edge-IoT Using Blockchain Technology. IEEE Access. 2023, 11, 36379–36398. [Google Scholar] [CrossRef]
- Gong, Q.; Zhang, J.; Wei, Z.; Wang, X.; Zhang, X.; Yan, X.; Liu, Y.; Dong, L. SDACS: Blockchain-Based Secure and Dynamic Access Control Scheme for Internet of Things. Sensors 2024, 24, 2267. [Google Scholar] [CrossRef] [PubMed]
- Gupta, H.; Vahid Dastjerdi, A.; Ghosh, S.K.; Buyya, R. iFogSim: A toolkit for modeling and simulation of resource management techniques in the Internet of Things, Edge and Fog computing environments. Softw. Pract. Exp. 2017, 47, 1275–1296. [Google Scholar] [CrossRef]












| Challenge | Response |
|---|---|
| Challenge | Response | Status |
|---|---|---|
| Valid Challenge | Valid Response | Success |
| Invalid Challenge | Error Response | Failure |
| Repeated Challenge | Consistent Response | Verified |
| Modified Challenge | New Response | Valid |
| Corrupted Challenge | No Response | Error |
| Model Parameters | Count |
| Number of DO | 2 |
| Number of DU | 6 |
| Number of CA | 1 |
| Cloud Service Provider | 1 |
| Hardware and Software | Version |
| Java Development Kit | 23.0.2 |
| Netbeans IDE | 24 |
| Wamp Server | 3.2.6 |
| MySQL | 5.7.36 |
| RAM | 16.0 |
| Processor | 11th Gen Inter (R) Core (TM) i5 |
| System Type | 64-bit |
| HLF Blockchain Specs | |
| Block size | 1–2 MB |
| Block generation time | 0.5–2 s |
| Number of channels | 1 or more |
| Number of peer nodes | 2 to 4 |
| Endorsement Execution time | 5–20 ms |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the author. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Alshehri, S. HADA: A Hybrid Authentication and Dynamic Attribute Access Control Mechanism for the Internet of Things Using Hyperledger Fabric Blockchain. Sensors 2026, 26, 2531. https://doi.org/10.3390/s26082531
Alshehri S. HADA: A Hybrid Authentication and Dynamic Attribute Access Control Mechanism for the Internet of Things Using Hyperledger Fabric Blockchain. Sensors. 2026; 26(8):2531. https://doi.org/10.3390/s26082531
Chicago/Turabian StyleAlshehri, Suhair. 2026. "HADA: A Hybrid Authentication and Dynamic Attribute Access Control Mechanism for the Internet of Things Using Hyperledger Fabric Blockchain" Sensors 26, no. 8: 2531. https://doi.org/10.3390/s26082531
APA StyleAlshehri, S. (2026). HADA: A Hybrid Authentication and Dynamic Attribute Access Control Mechanism for the Internet of Things Using Hyperledger Fabric Blockchain. Sensors, 26(8), 2531. https://doi.org/10.3390/s26082531

