BISF-IoT: A Scalable Blockchain-Integrated Security Framework with Formal Guarantees

Authors

  • Shahid Imran Department of Computer Science & IT, University of Jhang, Jhang, Pakistan
  • Kalsoom Safdar Department of Computer Science & IT, University of Jhang, Jhang, Pakistan. Faculty of Intelligent Computing, Universiti Malaysia Perlis, 02600 Arau, Perlis, Malaysia.
  • Muhammad Usman Younus Department of Computer Science & IT, Baba Guru Nanak University, 39100 Nankana Sahib, Pakistan. Ecole Math´ematiques, Informatique, T´el´ecommunications de Toulouse, Universit´e de Toulouse, 31000 de Toulouse, France

DOI:

https://doi.org/10.33411/IJIST/1994

Keywords:

Blockchain, IoT, Decentralized, Authorization, Revocation, Auditable

Abstract

As IoT deployments rapidly expand, ensuring comprehensive end-to-end security across identity, authorization, communication, integrity, and auditability is critical. This paper presents BISF-IoT, a Blockchain-Integrated Security Framework that utilizes a permissioned ledger as a tamper-evident control plane while keeping high-volume telemetry and raw logs off-chain. BISF-IoT integrates decentralized identity (DID) management, capability-based authorization with explicit revocation under a freshness bound Δ, and secure-channel identity binding for MQTT/CoAP edge devices. Formal game-based proofs establish five core security properties: DID authenticity, authorization soundness, revocation safety, tamper-evident logging, and auditable anomaly alert non-repudiation. Performance evaluation through simulation with up to 10,000 devices demonstrates near-linear scalability, processing up to 160,000 transactions per day with a scaling efficiency of ~0.90–1.00. Authorization latency increases moderately from 120 ms at 100 devices to 650 ms at 10,000 devices. Therefore, it remains within practical operational limits. Blockchain storage grows steadily at approximately 37–42 MB/day by storing compact Merkle commitments and security artifacts while avoiding raw data bloat. Meanwhile Log verification time exhibits sub-linear growth, with verification cost per entry decreasing from 0.200 ms to 0.055 ms as log size increases from 100 to 10,000 entries, reflecting efficient Merkle inclusion proof mechanisms. These results confirm BISF-IoT’s capability to provide scalable, secure, and verifiable control-plane operations suitable for large-scale IoT environments.

References

D. Commey, B. Mai, S. G. Hounsinou, and G. V. Crosby, “Securing Blockchain-Based IoT Systems: A Review,” IEEE Access, vol. 12, pp. 98856–98881, 2024, doi: 10.1109/ACCESS.2024.3428490.

S. Almarri and A. Aljughaiman, “Blockchain Technology for IoT Security and Trust: A Comprehensive SLR,” Sustain. 2024, Vol. 16, Page 10177, vol. 16, no. 23, p. 10177, Nov. 2024, doi: 10.3390/SU162310177.

M. U. Younus, Y. Li, M. Shahbaz, R. Shafi, and H. He, “Robust security system for intruder detection and its weight estimation in controlled environment using Wi-Fi,” 2016 2nd IEEE Int. Conf. Comput. Commun. ICCC 2016 - Proc., pp. 985–990, May 2017, doi: 10.1109/CompComm.2016.7924852.

T. M. Fernández-Caramés and P. Fraga-Lamas, “A Review on the Use of Blockchain for the Internet of Things,” IEEE Access, vol. 6, pp. 32979–33001, May 2018, doi: 10.1109/ACCESS.2018.2842685.

Z. Ullah et al., “Blockchain-IoT: A revolutionary model for secure data storage and fine-grained access control in internet of things,” IET Commun., vol. 18, no. 19, pp. 1524–1540, Dec. 2024, doi: 10.1049/CMU2.12845;[6] A. Raj and S. Prakash, “A Secure Blockchain-Based Access Control Architecture for IoT-Healthcare Applications,” Natl. Acad. Sci. Lett. 2024 475, vol. 47, no. 5, pp. 529–537, Feb. 2024, doi: 10.1007/S40009-023-01383-Z.

U. Roy and N. Ghosh, “BloAC: A blockchain-based secure access control management for the Internet of Things,” J. Inf. Secur. Appl., vol. 87, p. 103897, Dec. 2024, doi: 10.1016/J.JISA.2024.103897.

J. Wang and J. Li, “Blockchain and Access Control Encryption-Empowered IoT Knowledge Sharing for Cloud-Edge Orchestrated Personalized Privacy-Preserving Federated Learning,” Appl. Sci. 2024, Vol. 14, Page 1743, vol. 14, no. 5, p. 1743, Feb. 2024, doi: 10.3390/APP14051743.

B. Li, H. Zhong, J. Zhang, Q. Zhang, J. Li, and J. Cui, “Achieving Fair and Efficient Revocable Access Control for IIoT Data Sharing: A Blockchain-Enabled Approach,” IEEE Internet Things J., vol. 12, no. 17, pp. 36634–36647, 2025, doi: 10.1109/JIOT.2025.3583317.

Y. Zhang, L. Chen, Y. Zhu, and X. Kong, “Privacy-Enhanced Role-Based Access Control for IoT Systems,” IEEE Internet Things J., vol. 12, no. 14, pp. 27269–27279, 2025, doi: 10.1109/JIOT.2025.3562155.

Y. Wu, Y. Matsubara, and S. Kasahara, “Enhancing Account Information Anonymity in Blockchain-Based IoT Access Control Using Zero-Knowledge Proofs,” Electron. 2025, Vol. 14, Page 2772, vol. 14, no. 14, p. 2772, Jul. 2025, doi: 10.3390/ELECTRONICS14142772.

P. S. Bangare and K. P. Patil, “Enhancing MQTT security for internet of things: Lightweight two-way authorization and authentication with advanced security measures,” Meas. Sensors, vol. 33, p. 101212, Jun. 2024, doi: 10.1016/J.MEASEN.2024.101212.

S. H. Gopalan, A. Manikandan, N. P. Dharani, and G. Sujatha, “Enhancing IoT Security: A Blockchain-Based Mitigation Framework for Deauthentication Attacks,” Int. J. Networked Distrib. Comput. 2024 122, vol. 12, no. 2, pp. 237–249, May 2024, doi: 10.1007/S44227-024-00029-W.

Y. Shin and S. Jeon, “MQTree: Secure OTA Protocol Using MQTT and MerkleTree,” Sensors 2024, Vol. 24, Page 1447, vol. 24, no. 5, p. 1447, Feb. 2024, doi: 10.3390/S24051447.

L. Duan et al., “Secure and Fine-Grained Data Sharing in Internet of Things: Integration of Interplanetary File System and Cross-Blockchain for Access Control,” IEEE Internet Things J., vol. 12, no. 18, pp. 37301–37308, 2025, doi: 10.1109/JIOT.2025.3583969.

M. Alashwal et al., “Trust Aware and Explainable Access Control for Internet of Medical Things: A Lightweight Hybrid Blockchain Approach,” IEEE Internet Things J., vol. 13, no. 12, pp. 27843–27861, Jun. 2026, doi: 10.1109/JIOT.2026.3680091.

N. Karankar and A. Seth, “An IoT system for access control using blockchain and message queuing system,” EURASIP J. Inf. Secur. 2025 20251, vol. 2025, no. 1, pp. 31-, Oct. 2025, doi: 10.1186/S13635-025-00208-4.

M. Wen, M. Xiao, W. Li, and B. Xiao, “A Sanitizable and Bilateral Access Control Scheme Based on Blockchain,” IEEE Internet Things J., vol. 12, no. 24, pp. 53900–53913, 2025, doi: 10.1109/JIOT.2025.3619544.

Downloads

Published

2026-08-16
CITATION
Published: 2026-08-16
Crossref Citation Count: Loading...

How to Cite

Imran, S., Safdar, K., & Younus, M. U. (2026). BISF-IoT: A Scalable Blockchain-Integrated Security Framework with Formal Guarantees. International Journal of Innovations in Science & Technology, 8(5), 1966–1994. https://doi.org/10.33411/IJIST/1994