Skip to content
Open access

A Hardware-Rooted Blockchain Security Framework for IoT With PUF-Based Authentication

2026 · IEEE Access · Vol 14, pp. 112562-112576 · 0 citations · 31 references

TL;DR

By using PUF-generated responses as hardware-rooted seeds for mining and authentication, the framework removes the need for permanent secret storage and establishes a secure chain from device identity to consensus participation, making it suitable for practical deployment in industrial IoT, smart infrastructure, and other resource-constrained distributed systems.

Abstract

The integration of blockchain with the Internet of Things (IoT) can enable decentralized trust, secure data exchange, and tamper-resistant operation in distributed cyber-physical systems. However, the practical deployment of blockchain in resource-constrained IoT nodes remains limited by the high computational and energy cost of conventional Proof-of-Work (PoW) mechanisms and by the security risks associated with persistent cryptographic key storage. This paper presents a hardware–software co-design framework for secure and lightweight IoT blockchain implementation based on the joint use of Physically Unclonable Functions (PUFs) and a reconfigurable FPGA mining architecture. The proposed framework incorporates two FPGA-oriented PUF designs: a multi-mode delay PUF for device authentication in public blockchain settings and a glitch-enhanced memory PUF for secure key generation in private blockchain environments. Experimental evaluation shows that both designs achieve near-ideal uniqueness (above 49.95%) and high reliability (above 99.5%) over a temperature range of $-40^{\circ }\mathrm {C}$ to $80^{\circ }\mathrm {C}$ , while also improving resistance to modeling and physical attacks. To reduce mining overhead, a configurable linear feedback shift register (CLFSR)-based pseudo-random function is introduced as an alternative to conventional cryptographic hashing. Implemented on a Xilinx Artix-7 FPGA, the proposed mining module achieves 3.13 Mhash/s throughput with only 0.12 W power consumption, corresponding to a 93% reduction in power compared with conventional approaches. The CLFSR primitive is positioned as a lightweight pseudo-random mining function for permissioned and resource-constrained IoT blockchains rather than as a drop-in cryptographic-hash replacement for open, high-value public chains, and all reported throughput values (3.13 Mhash/s) correspond to post-place-and-route operation at 100 MHz on the same Artix-7 device. By using PUF-generated responses as hardware-rooted seeds for mining and authentication, the framework removes the need for permanent secret storage and establishes a secure chain from device identity to consensus participation. Experimental results confirm that the proposed architecture provides a favorable trade-off among security, hardware cost, and energy efficiency, making it suitable for practical deployment in industrial IoT, smart infrastructure, and other resource-constrained distributed systems.

Read PDF

Similar papers

Open access Jul 2026

A Blockchain-Based Lightweight Authentication Framework for Secure Communication in IoT Networks

A lightweight blockchain-based authentication framework for secure communication in Internet of Things (IoT) networks that integrates a permissioned blockchain with ECC-256 to provide mutual authentication, data integrity, and non-repudiation for resource-constrained IoT devices.

Ashraf A. Abu-Ein, Obaida M. Al-hazaimeh · 0 citations
Conference Jul 2026

A Hybrid Blockchain-Based Zero-Trust Architecture for Secure and Scalable IoT Systems

The growth of the Internet of Things (IoT) has introduced significant security challenges, mainly due to the resource constraints of devices and the limitations of centralized architectures. This paper proposes a blockchain-based Zero-Trust framework for secure and scalable IoT systems. The approach is architecture-agnostic and combines decentralized identity management, hybrid data storage, and edge-assisted computation. To optimize resource usage, raw data are stored off-chain while cryptographic hashes are anchored on the blockchain, ensuring integrity and immutability. A Merkle tree structure is employed to aggregate data efficiently, reducing communication overhead and blockchain transaction costs. Experimental results demonstrate that lightweight cryptographic mechanisms, combined with Merkle-based aggregation, provide strong security guarantees with low energy consumption. The proposed framework achieves improved scalability, robustness, and efficiency, making it suitable for resource-constrained IoT environments.

Florian Bonelli, Alexandre dos Santos Roque, E. P. de Freitas · 0 citations
Open access Aug 2026

OPAQUE-IoT: an optimization-driven PUF-Blockchain authenticated key agreement protocol with adaptive resource management for constrained IoT networks

Security in resource-constrained IoT deployments remains a persistent challenge: devices used in industrial control, smart healthcare, and transportation must authenticate quickly, consume minimal energy, and resist physical attacks — yet existing protocols rarely address all three requirements at once. To the best of current knowledge, no prior protocol jointly optimises security, energy, and latency within a single formally verified framework. This paper presents OPAQUE-IoT, an Optimization-driven PUF-Blockchain AKA Protocol for constrained IoT networks. The framework integrates PUF-based hardware identity verification, a permissioned blockchain for decentralized trust management, and the Adaptive Security-Energy Trade-off Optimizer (ASETO), which jointly minimizes authentication latency and energy consumption under formal security constraints. Convergence of ASETO is proven under Lipschitz-continuous objective functions. Formal security analysis under the Real-or-Random (RoR) model with explicit Random Oracle and ECDH hardness assumptions demonstrates resistance to replay, impersonation, man-in-the-middle, PUF modeling, insider, and side-channel attacks, with a security advantage bound of approximately 2^(-68). Simulation results across heterogeneous IoT topologies (N = 50 to 5000 devices) show 31.8% lower energy consumption, 30.2% reduced authentication latency, and 41.1% higher throughput compared to the best-performing blockchain-capable baseline, with O(log N) Merkle-indexed blockchain query complexity and O(T_max·N·P) per-epoch optimiser complexity.

Ibrahim Aqeel · 0 citations
Open access 2026

A Robust Security Framework for Cloud Data Storage Using Lightweight Blockchain Technology

The proposed framework outperforms existing blockchain-based models, achieving a 37.7% reduction in encryption/decryption time, a 51.3% decrease in transaction latency, and a 54.5% improvement in energy efficiency, and confirms that the proposed approach provides a practical balance between security assurance and performance optimization.

R. Bala, S. Gnanavel · 0 citations
Jul 2026

Blockchain-Based IOT Security Architecture for Secure, Scalable, and Trustworthy Next-Generation Internet of Things Ecosystems

A Blockchain-Based IoT Security Architecture that integrates distributed ledger technology, smart contracts, edge computing, and zero-trust authentication mechanisms to enhance security, privacy, and system reliability is proposed.

K. Venkatesh, Gorre Bharath, Jannu Subhas Chandra Boss · 0 citations
Open access Aug 2026

Blockchain-Assisted Lightweight Authentication Protocol for Resource-Constrained IoT Devices in 5G Smart Environments

The ubiquity of lightweight resource-constrained Internet-of-Things (IoT) devices in 5G smart environments necessitates authentication protocols with the conflicting goals of being lightweight, highly secure, and having a decentralised credential management structure. Existing schemes use trusted third-party key distributors or heavyweight cryptographic primitives infeasible to IoT embedded hardware; they also fail to anchor device credentials on a permissioned blockchain ledger for tamper-evident credential revocation. In this work, we introduce BLAP-IoT: a Blockchain-Assisted Lightweight Authentication Protocol over live Hyperledger Fabric 2.5.9 that leverages elliptic-curve Diffie–Hellman over P-256 curve, keyed MACs, and a three-message challenge-response protocol to provide injective mutual authentication with device key confirmation. Device credential commitments are stored on-chain to facilitate decentralised and efficient device revocation without revealing secrets on-chain. A formal security verification of the protocol in ProVerif 2.05 shows session-key secrecy, injective mutual authentication, and perfect forward secrecy in the presence of the Dolev-Yao attacker. The empirical evaluation of BLAP-IoT on measured P-256 primitives reports that the scheme achieves a total computation cost of 0.303 ms on constrained devices — up to 52% less than compared schemes, 1920-bit two-way communication overhead, and 0.218 mJ device energy consumption. The underlying blockchain layer sustains up to 277 transactions per second (TPS) in peak throughput, with end-to-end authentication latency less than 13 ms at 1000 concurrent devices.

Musaddak Maher, Abdul Zahra, Muhaned Al-Hashimi et al. · 0 citations