Hashchain-based Authentication Framework Against Blended Attacks in Constrained IoT Networks
Many Internet of Things (IoT) deployments rely on multi-hop routing protocols designed for low-power and resource-constrained devices. These protocols are susceptible to routing attacks that degrade network reliability, compromise data integrity, and disrupt system operation. Existing countermeasures typically address limited attack classes or rely on cryptographic mechanisms that impose prohibitive overhead on constrained hardware. This paper presents a lightweight authentication framework to secure the IPv6 Routing Protocol for Low-Power and Lossy Networks (RPL) against combined Sybil and flooding attacks. The proposed approach constructs a global one-way hashchain and partitions it among provisioned nodes such that each index interval is associated with a specific node identity. This structure enables verifiable authentication of RPL control messages using only hash evaluations, eliminating the need for public-key operations during routine authentication. To maintain efficiency under adversarial load, the framework integrates probabilistic verification and per-node rate limiting to bound computational overhead during flooding attempts, while a Sybil pre-filter discards fabricated identities prior to full hashchain verification. For long-term deployments, credential renewal is protected using a Physical Unclonable Function (PUF)-gated mechanism that provides hardware-assisted identity verification before renewed credentials are distributed. The formal analysis demonstrates that the scheme provides message unforgeability, replay resistance, PUF-gated renewal security, Sybil resistance, and bounded verification cost under the stated cryptographic assumptions. A proof-of-concept implementation in Contiki-NG, evaluated on emulated Zolertia Z1 motes using Cooja, shows that the framework introduces 20 bytes of message overhead and less than 1% CPU utilization under benign conditions. Under the evaluated attack rates, the complete framework reduces radio duty cycle by 31–76% relative to unprotected RPL. Comparative analysis against symmetric MAC, ECC-based signing, ECC-voucher, and Merkle-hashchain approaches indicates that the proposed design provides a favorable balance of memory usage, latency, communication overhead, scalability, and attack resilience under the evaluated conditions.
Authors
- Baraq Ghaleb (ORCID: https://orcid.org/0000-0002-8361-0634)
- Mohammad Ahmed Alomari (ORCID: https://orcid.org/0000-0001-9403-5439)
- Ahmed Al‐Dubai (ORCID: https://orcid.org/0000-0001-9758-5540)
- Yahya Almurtadha (ORCID: https://orcid.org/0000-0003-2171-5470)
- Mukhtar Ghaleb (ORCID: https://orcid.org/0000-0002-6461-1818)
Institutions
- Cyber University (JP)
- Edinburgh Napier University (GB)
- Technical University of Malaysia Malacca (MY)
- University of Tabuk (SA)
Publication Details
- Journal
- ACM Transactions on Internet Technology
- Published
- 2026-09-18
- DOI
- https://doi.org/10.1145/3848517
- Primary Topic
- Security in Wireless Sensor Networks
- Type
- article
- Field-Weighted Citation Impact
- 0.00