BDLock: A blockchain-enabled two-tier privacy-aware federated IDAM service platform using RBAC
Authors/Creators
- 1. University of Dhaka
- 2. Jashore University of Science and Technology (JUST)
Description
Centralized identity and access management (IDAM) systems suffer from single points of failure, lack of authorization transparency, and susceptibility to in-sider threats and privilege abuse. While role-based access control (RBAC) offers structured permission management, its enforcement through centralized policy engines introduces auditability gaps unacceptable in modern distributed service delivery environments. This paper presents BDLock, a blockchain-enabled two-tier privacy-aware federated IDAM platform integrating OAuth 2.0, OpenID Connect (OIDC), and Hyperledger Fabric 2.4. The first tier validates JSON Web Tokens (JWT) issued by Keycloak against a Spring Boot resource server, the second tier enforces immutable scope-based RBAC rights on the Hyperledger Fabric ledger, ensuring every access decision is tamper-proof and auditable. Unlike prior approaches, BDLock uniquely bridges OAuth-authenticated off-chain identities to cryptographic on-chain Fabric wallet identities, satisfying all six STRIDE-modelled threats categories across both Web2 and Web3 identity models. Validated with up to 1,800 concurrent users, BDLock achieves a peak throughput of approximately 200 transactions per second using round- robin load balancing. At high concurrency, it outperforms single-peer fallback by up to 25%. Furthermore, it maintains uninterrupted access control during peer failures, eliminating the single point of failure found in all nine compared state-of-the-art systems.
Files
41956 IJECE 7% faizah.pdf
Files
(758.2 kB)
| Name | Size | Download all |
|---|---|---|
|
md5:38d5054d474d6324476607df24d85c5d
|
758.2 kB | Preview Download |