Blockchain-Backed Revocation and Yang–Baxter Consistency Screening for Zero-Trust IoT Admission Control
IoT deployments handle credential hygiene reactively: cloned, replayed, or stale credentials are typically discovered only after misuse, and revocation state is often propagated through centralized lists whose integrity cannot be independently verified. This article introduces the Yang–Baxter IoT Consistency Gateway (YB-IoT-CG), a Zero-Trust admission-control framework that pushes an algebraic layer of credential screening to the edge and anchors security evidence on a modeled permissioned-ledger architecture. YB-IoT-CG operates after conventional secret-based authentication and Yang–Baxter equality is used as an execution-consistency invariant rather than as proof of device identity or message authenticity. Each authenticated message is hashed into a digest and reduced to an algebraic transcript that is verified over two Yang–Baxter traversal paths. Beyond equality checking, chain-proximity metrics inspired by time–memory trade-off analysis, nonce and timestamp freshness heuristics, and contextual risk scoring identify credentials that should be proactively challenged or revoked before telemetry is admitted. The proactive risk component is deterministic and policy-based rather than a learned predictive model. Decisions are batched into Merkle trees whose roots are represented through a permissioned-ledger model, credential revocation is propagated through a modeled on-chain registry, and device identities are bound to W3C Decentralized Identifiers (DIDs) with verifiable credentials. This design provides tamper-evident audit support while keeping ledger interaction off the packet decision path. Validation is based on a controlled Python 3.13.7 packet-level simulation and a parameterized ledger model, not on a physical IoT or live Hyperledger Fabric deployment. Across 60 seeded simulation runs, the complete post-authentication screening pipeline obtained a median incremental decision time of 7.8 μs, 99.4% aggregate decision accuracy for the modeled attack classes, a 0.43% false rejection rate, and a 31.4 ms amortized ledger service-time equivalent per decision for a batch size of 64. The 99.4% value is a property of the composed freshness/context/registry/YB policy and is not a YB-only detection rate; the YB-specific positive guarantee is limited to the isolated fault class of Proposition 7. These results provide simulation-based evidence supporting a lightweight, explainable, auditable, and proactive approach to credential hygiene at the edge.
Authors
- Yair Rivera Julio (ORCID: https://orcid.org/0000-0001-5622-6939)
- Javier Prieto (ORCID: https://orcid.org/0000-0001-8175-2201)
- Esmeide Leal (ORCID: https://orcid.org/0000-0003-2468-370X)
Institutions
- Universidad de Salamanca (ES)
- Corporación Universitaria Americana (CO)
- Universidad Autónoma del Caribe (CO)
Publication Details
- Journal
- Sensors
- Published
- 2026-09-20
- DOI
- https://doi.org/10.3390/s26185960
- Primary Topic
- Internet Traffic Analysis and Secure E-voting
- Type
- article
- Field-Weighted Citation Impact
- 0.00