Multi-tiered authentication framework for enhanced security in cloud and IoT systems with blockchain
摘要
The combination of IoT and cloud computing has altered modern life by making services more efficient and accessible. Still, it also exposes IoT devices to security risks due to their dependency on public communication networks. To address these issues, this paper introduces SecureIoT-Auth, a multi-tiered authentication architecture intended to improve the security of IoT and cloud systems. The framework consists of two phases: registration and authentication, and it has two tiers to assure comprehensive security: one for IoT device authentication and another for IoT user authentication. In the first tier, IoT devices are authenticated utilizing location-based services (LBS), MAC address verification, and device fingerprinting based on the Trusted Platform Module (TPM). Furthermore, Blockchain technology validates devices through Proof of Authority and Reputation (PoAR), relying on their previous interactions and reputation within the network to verify legitimacy. The second tier focuses on user authentication, which begins with the registration of credentials such as a username, password, and biometric data (iris and fingerprint). During authentication, biometric features are extracted using the Log-Gabor filter and translated into binary keys, which are then compared using the Hamming distance for precise verification.