Hashchain-based Authentication Framework Against Blended Attacks in Constrained IoT Networks

Many Internet of Things (IoT) deployments rely on multi-hop routing protocols designed for low-power and resource-constrained devices. These protocols are susceptible to routing attacks that degrade network reliability, compromise data integrity, and disrupt system operation. Existing countermeasures typically address limited attack classes or rely on cryptographic mechanisms that impose prohibitive overhead on constrained hardware. This paper presents a lightweight authentication framework to secure the IPv6 Routing Protocol for Low-Power and Lossy Networks (RPL) against combined Sybil and flooding attacks. The proposed approach constructs a global one-way hashchain and partitions it among provisioned nodes such that each index interval is associated with a specific node identity. This structure enables verifiable authentication of RPL control messages using only hash evaluations, eliminating the need for public-key operations during routine authentication. To maintain efficiency under adversarial load, the framework integrates probabilistic verification and per-node rate limiting to bound computational overhead during flooding attempts, while a Sybil pre-filter discards fabricated identities prior to full hashchain verification. For long-term deployments, credential renewal is protected using a Physical Unclonable Function (PUF)-gated mechanism that provides hardware-assisted identity verification before renewed credentials are distributed. The formal analysis demonstrates that the scheme provides message unforgeability, replay resistance, PUF-gated renewal security, Sybil resistance, and bounded verification cost under the stated cryptographic assumptions. A proof-of-concept implementation in Contiki-NG, evaluated on emulated Zolertia Z1 motes using Cooja, shows that the framework introduces 20 bytes of message overhead and less than 1% CPU utilization under benign conditions. Under the evaluated attack rates, the complete framework reduces radio duty cycle by 31–76% relative to unprotected RPL. Comparative analysis against symmetric MAC, ECC-based signing, ECC-voucher, and Merkle-hashchain approaches indicates that the proposed design provides a favorable balance of memory usage, latency, communication overhead, scalability, and attack resilience under the evaluated conditions.

Authors

Institutions

Publication Details

Journal
ACM Transactions on Internet Technology
Published
2026-09-18
DOI
https://doi.org/10.1145/3848517
Primary Topic
Security in Wireless Sensor Networks
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

Hashchain-based Authentication Framework Against Blended Attacks in Constrained IoT Networks

Baraq Ghaleb, Mohammad Ahmed Alomari, Ahmed Al‐Dubai, Yahya Almurtadha et al.
ACM Transactions on Internet Technology
Security in Wireless Sensor Networks
article

Hashchain-based Authentication Framework Against Blended Attacks in Constrained IoT Networks

Baraq Ghaleb, Mohammad Ahmed Alomari, Ahmed Al‐Dubai, Yahya Almurtadha, Mukhtar Ghaleb
article en

Abstract

Many Internet of Things (IoT) deployments rely on multi-hop routing protocols designed for low-power and resource-constrained devices. These protocols are susceptible to routing attacks that degrade network reliability, compromise data integrity, and disrupt system operation. Existing countermeasures typically address limited attack classes or rely on cryptographic mechanisms that impose prohibitive overhead on constrained hardware. This paper presents a lightweight authentication framework to secure the IPv6 Routing Protocol for Low-Power and Lossy Networks (RPL) against combined Sybil and flooding attacks. The proposed approach constructs a global one-way hashchain and partitions it among provisioned nodes such that each index interval is associated with a specific node identity. This structure enables verifiable authentication of RPL control messages using only hash evaluations, eliminating the need for public-key operations during routine authentication. To maintain efficiency under adversarial load, the framework integrates probabilistic verification and per-node rate limiting to bound computational overhead during flooding attempts, while a Sybil pre-filter discards fabricated identities prior to full hashchain verification. For long-term deployments, credential renewal is protected using a Physical Unclonable Function (PUF)-gated mechanism that provides hardware-assisted identity verification before renewed credentials are distributed. The formal analysis demonstrates that the scheme provides message unforgeability, replay resistance, PUF-gated renewal security, Sybil resistance, and bounded verification cost under the stated cryptographic assumptions. A proof-of-concept implementation in Contiki-NG, evaluated on emulated Zolertia Z1 motes using Cooja, shows that the framework introduces 20 bytes of message overhead and less than 1% CPU utilization under benign conditions. Under the evaluated attack rates, the complete framework reduces radio duty cycle by 31–76% relative to unprotected RPL. Comparative analysis against symmetric MAC, ECC-based signing, ECC-voucher, and Merkle-hashchain approaches indicates that the proposed design provides a favorable balance of memory usage, latency, communication overhead, scalability, and attack resilience under the evaluated conditions.

ACM Transactions on Internet Technology
Cyber University (JP), Edinburgh Napier University (GB), Technical University of Malaysia Malacca (MY), University of Tabuk (SA)
Openalex Percentile: Top 9%
Security in Wireless Sensor Networks
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.