Skip to content
Open access

zk-Guard-R: Policy-Hidden and Replay-Safe zk-SNARK Access Control for IoT Sensor Data Stored on IPFS

Aug 2026 · Italian National Conference on Sensors · Vol 26, pp. 5045 · 0 citations · 24 references
Medicine

Abstract

IoT sensor deployments increasingly export measurement streams to edge gateways and content-addressed storage such as IPFS, but access control decisions must be enforced without disclosing sensor owner policies, requester attributes, or stale data versions. Existing blockchain, CP-ABE, and zero-knowledge approaches reduce parts of this leakage, yet they can still expose public policy structure, accept stale Merkle proofs after sensor stream updates, overload provers when policies grow, or leave IPFS gateways vulnerable to bandwidth abuse. This paper proposes zk-Guard-R, a policy-hidden and replay-safe zk-SNARK access control framework for privacy-preserving IoT sensor data sharing. zk-Guard-R replaces public sparse policy matrices with MiMC-Merkle policy commitments verified inside the proof, separates long-lived logical sensor policy roots from frequently updated physical IPFS data roots, binds every proof to an on-chain nonce, and decouples attribute possession from policy interpretation through a bounded stack-based policy interpreter. Numeric sensor-access predicates are represented through committed values and range check gadgets, while an off-chain verification gateway couples accepted proofs with payment channel vouchers before releasing encrypted IPFS chunks. The design contribution is separated from the measured prototype: the full protocol specifies a bounded policy interpreter, whereas the present gnark prototype evaluates the core committed policy, committed attribute, range check, data root, nonce, Solidity verifier, and gateway-metering mechanisms. We implement a gnark BN254/Groth16 research prototype and benchmark it against a matrix-public zk-Guard prototype, a blockchain ABAC baseline, an IoT token/HMAC baseline, and a CP-ABE-style cryptographic-work proxy. For 128 attributes, the zk-Guard-R prototype with MiMC-Merkle commitments uses 425,574 R1CS constraints, generates proofs in 3.12 s, verifies in 0.73 ms, and uses 641 MB peak Go heap allocation. A three-run repeat of the 128-attribute configuration gives a proof-generation mean of 2.80 s with a 0.54 s standard deviation on the same local host, illustrating the runtime variability of prover measurements. We also deploy the generated Solidity verifier on a local Anvil EVM and measure 241,942 gas for a successful verification transaction, and we evaluate a local Kubo/IPFS gateway under valid, replayed, and voucher-limited flood requests. The results show that zk-Guard-R shifts substantial but measurable work to the prover while improving policy confidentiality, freshness, and gateway metering for IPFS-backed IoT sensor data sharing.

Read PDF

Similar papers

Open access Sep 2026

Blockchain-Backed Revocation and Yang–Baxter Consistency Screening for Zero-Trust IoT Admission Control

IoT deployments handle credential hygiene reactively: cloned, replayed, or stale credentials are typically discovered only after misuse, and revocation state is often propagated through centralized lists whose integrity cannot be independently verified. This article introduces the Yang–Baxter IoT Consistency Gateway (Y...

Yair E. Rivera-Julio, Esmeide A. Leal-Narváez, Javier Prieto Tejedor · 0 citations
Open access Sep 2026

An Improved Secure Blockchain‐Based Remote Patient Monitoring System With Role‐Based Access Control Using IPFS

This work presents a privacy‐preserving remote healthcare system that integrates blockchain technology with a root seed‐based pseudonymization mechanism and lightweight cryptographic controls. Addressing the privacy risks of public ledgers and the limited computational resources of medical IoT devices, the proposed s...

Hoc Minh Le, Özgür Öksüz · 0 citations
Open access Aug 2026

OPAQUE-IoT: an optimization-driven PUF-Blockchain authenticated key agreement protocol with adaptive resource management for constrained IoT networks

OPAQUE-IoT, an Optimization-driven PUF-Blockchain AKA Protocol for constrained IoT networks integrates PUF-based hardware identity verification, a permissioned blockchain for decentralized trust management, and the Adaptive Security-Energy Trade-off Optimizer (ASETO), which jointly minimizes authentication latency and...

Ibrahim Aqeel · 0 citations
Open access Sep 2026

Task-Bound Authorization and Compliance Auditing with Quantum-Safe Task Passports for Privacy-Preserving Computation in Trusted Data Spaces

Trusted data spaces support privacy-preserving computation, but existing credentials leave an execution-time gap when task parameters or cumulative resources change. We present a task-bound lifecycle and state model instantiated by a quantum-safe task passport (QTP). Its signed schema binds purpose, scope, computation...

Si-Hang Qin, Yu-Rou Wu, Jie-Ling Wen et al. · 0 citations
Open access Aug 2026

Optimizing Zero-Knowledge Proofs For Soulbound Token-Based Academic Authentication On Resource-Constrained Devices

An academic authentication framework that integrates the ERC-5192 Soulbound Token standard with Groth16 zk-SNARKs implemented using Circom, SnarkJS, and client-side WebAssembly to support privacy-preserving credential verification and replay resistance is presented.

Dedy Sumarhadi, Sunardi, I. Riadi · 0 citations
Open access Aug 2026

Blockchain-Assisted Authentication, Authorization, and Audit for MQTT-Based Smart-City IoT

Smart-city services increasingly rely on Internet of Things (IoT) deployments using lightweight Message Queuing Telemetry Transport (MQTT), yet weakly protected systems remain exposed to spoofing, unauthorized state changes, and limited accountability. This work evaluates blockchain and smart contracts as a complementa...

Rida Lkhluf, David Santo Orcero, F. J. Cañete · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.