An Integrated Architecture Combining Blockchain, Artificial Intelligence, and Machine Learning for Decentralised Identity Management in the Internet of Things
The identity-management challenge addressed in this study emerges after device enrolment, when an Internet of Things (IoT) device may continue to present valid credentials even though its software state, behavioural patterns, or operating conditions have changed. To address this limitation, the study proposes an integrated architecture that treats cryptographic identity and observed behaviour as complementary but distinct sources of trust evidence. A permissioned ledger anchors decentralised identifiers, credential states, policy versions, model attestations, and decision evidence, while behavioural analysis is performed close to the device and federated learning enables collaborative model development without centralising raw telemetry. At the authorisation stage, credential validity, behavioural risk, and request context are combined into a dynamic trust state, enabling graduated responses as evidence evolves. Low-level observation and temporary restrictions may be automated, whereas suspension is subject to review and permanent credential revocation requires human authorisation.
The study adopts a Design Science Research approach, treating the proposed architecture as an artefact evaluated through requirements-based assessment, threat-model analysis, and feasibility evidence derived from the underlying technological mechanisms. The evaluation identifies both design-level capabilities and unresolved dependencies related to secure key custody on legacy devices, federated coordination at scale, poisoning by credentialled participants, and regulatory conformity. The proposed architecture therefore extends decentralised identity management beyond static credential verification by integrating continuous behavioural assessment, auditable decision-making, and human oversight into a unified IoT trust-management framework.
Copyright: ©The Author(s) 2026. This article is distributed under the terms and conditions of the license Creative Commons Attribution (CC BY) license.
Article info: Received: 9 March, 2026 Revised: 30 March, 2026 Accepted: 19 May, 2026 Published: 22 May, 2026
Mihăilescu, M. I., Niță, S. L. & Mărăscu, V. (2026). An Integrated Architecture Combining Blockchain, Artificial Intelligence, and Machine Learning for Decentralised Identity Management in the Internet of Things. Journal of Emerging Technologies for Society, 1(1), 27-50. https://doi.org/10.57017/jets.v1.iss1.02
CRediT Authorship Contribution Statement: Mihăilescu, M. I.: Conceptualisation, methodology, visualisation, writing – original draft, supervision; Niță, S. L.: Literature review, formal analysis, validation, writing – review and editing; Mărăscu, V.: Methodology, formal analysis, validation, interpretation, writing – review and editing.
Acknowledgments/Funding: This research received no external funding.
Conflict of Interest Statement: The authors declare no commercial or financial conflicts of interest. Mihăilescu, M. I. is an Associate Editor of JETS, while Niță, S. L. and Mărăscu, V. are members of the International Advisory Board of JETS. All three authors were excluded from all editorial decisions related to this manuscript, which was handled independently in accordance with the journal’s peer-review and editorial procedures.
Data Availability Statement: No new data were created or analysed in this study. Data sharing is not applicable to this article.
Ethical Approval Statement: This study is based exclusively on the analysis of previously published literature. Therefore, ethical approval was not required.
Ali, S., Li, Q., & Yousafzai, A. (2024). Blockchain and federated learning-based intrusion detection approaches for edge-enabled industrial IoT networks: A survey. Ad Hoc Networks, 152(C), 103320. https://doi.org/10.1016/j.adhoc.2023.10332
Allen, C. (2016). The path to self-sovereign identity. Life With Alacrity. http://www.lifewithalacrity.com/2016/04/the-path-to-self-soverereign-identity.html
Belenguer, A., Pascual, J. A., & Navaridas, J. (2025). A review of federated learning applications in intrusion detection systems. Computer Networks, Volume 258, 111023. https://doi.org/10.1016/j.comnet.2024.111023
Buczak, A. L., & Guven, E. (2016). A survey of data mining and machine learning methods for cyber security intrusion detection. IEEE Communications Surveys & Tutorials, 18(2), 1153–1176. https://doi.org/10.1109/COMST.2015.2494502
Dorri, A., Kanhere, S. S., Jurdak, R., & Gauravaram, P. (2017). Blockchain for IoT security and privacy: The case study of a smart home. In 2017 IEEE International Conference on Pervasive Computing and Communications Workshops (PerCom Workshops) (pp. 618–623). IEEE. https://doi.org/10.1109/PERCOMW.2017.7917634
Hernandez-Ramos, J. L., Karopoulos, G., Chatzoglou, E., Kouliaridis, V., Marmol, E., Gonzalez-Vidal, A., & Kambourakis, G. (2025). Intrusion detection based on federated learning: A systematic review. ACM Computing Surveys, 57(12), 1–65. https://doi.org/10.1145/3731596
Hussain, F., Hussain, R., Hassan, S. A., & Hossain, E. (2020). Machine learning in IoT security: Current solutions and future challenges. IEEE Communications Surveys & Tutorials, 22(3), 1686–1721. https://doi.org/10.1109/COMST.2020.2986444
Khacha, A., Aliouat, Z., Harbi, Y., Gherbi, C., Saadouni, R., & Harous, S. (2024). Landscape of learning techniques for intrusion detection system in IoT: A systematic literature review. Computers and Electrical Engineering, 120, 109725. https://doi.org/10.1016/j.compeleceng.2024.109725
Khan, M. A., & Salah, K. (2018). IoT security: Review, blockchain solutions, and open challenges. Future Generation Computer Systems, 82, 395–411. https://doi.org/10.1016/j.future.2017.11.022
McMahan, B., Moore, E., Ramage, D., Hampson, S., & Agüera y Arcas, B. (2017). Communication-efficient learning of deep networks from decentralized data. In Proceedings of AISTATS (pp. 1273–1282). PMLR. https://proceedings.mlr.press/v54/mcmahan17a/mcmahan17a.pdf
Mühle, A., Grüner, A., Gayvoronskaya, T., & Meinel, C. (2018). A survey on essential components of a self-sovereign identity. Computer Science Review, 30, 80–86. https://doi.org/10.1016/j.cosrev.2018.10.002
Sicari, S., Rizzardi, A., Grieco, L. A., & Coen-Porisini, A. (2015). Security, privacy and trust in Internet of Things: The road ahead. Computer Networks, 76, 146–164. https://doi.org/10.1016/j.comnet.2014.11.008
Androulaki, E., Barger, A., Bortnikov, V., Cachin, C., Christidis, K., De Caro, A., Enyeart, D., Ferris, C., Laventman, G., Manevich, Y., Muralidharan, S., Murthy, C., Nguyen, B., Sethi, M., Singh, G., Smith, K., Sorniotti, A., Stathakopoulou, C., Vukolić, M., Cocco, S. W., & Yellick, J. (2018). Hyperledger Fabric: A distributed operating system for permissioned blockchains. In Proceedings of the Thirteenth EuroSys Conference (Article 30, pp. 1–15). ACM. https://doi.org/10.1145/3190508.3190538
Antonakakis, M., April, T., Bailey, M., Bernhard, M., Bursztein, E., Cochran, J., Durumeric, Z., Halderman, J. A., Invernizzi, L., Kallitsis, M., Kumar, D., Lever, C., Ma, Z., Mason, J., Menscher, D., Seaman, C., Sullivan, N., Thomas, K., & Zhou, Y. (2017). Understanding the Mirai botnet. In Proceedings of the 26th USENIX Security Symposium (pp. 1093–1110). USENIX Association. https://www.usenix.org/conference/usenixsecurity17/ technical-sessions/presentation/antonakakis
Bagdasaryan, E., Veit, A., Hua, Y., Estrin, D., & Shmatikov, V. (2020). How to backdoor federated learning. In Proceedings of the 23rd International Conference on Artificial Intelligence and Statistics, Proceedings of Machine Learning Research, 108, 2938–2948. https://proceedings.mlr.press/v108/bagdasaryan20a.html
Blanchard, P., El Mhamdi, E. M., Guerraoui, R., & Stainer, J. (2017). Machine learning with adversaries: Byzantine tolerant gradient descent. In Advances in Neural Information Processing Systems, 30, 119–129. https://papers.nips.cc/paper_files/paper/2017/file/f4b9ec30ad9f68f89b29639786cb62ef-Paper.pdf
Bonawitz, K., Ivanov, V., Kreuter, B., Marcedone, A., McMahan, H. B., Patel, S., Ramage, D., Segal, A., & Seth, K. (2017). Practical secure aggregation for privacy-preserving machine learning. In Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security (pp. 1175–1191). ACM. https://doi.org/10.1145/3133956.3133982
Douceur, J. R. (2002). The Sybil attacks. In P. Druschel, F. Kaashoek, & A. Rowstron (Eds.), Peer-to-Peer Systems. Lecture Notes in Computer Science, Vol. 2429, 251–260. Springer. https://doi.org/10.1007/3-540-45748-8_24
ETSI. (2020). Cyber security for consumer Internet of Things: Baseline requirements (ETSI EN 303 645 V2.1.1). European Telecommunications Standards Institute. https://cdn.standards.iteh.ai/samples/57991/ dfada3bbc3e94fa1844b1c1b0e8477be/ETSI-EN-303-645-V2-1-1-2020-06-.pdf
European Parliament and Council of the European Union. (2016). Regulation (EU) 2016/679 of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation). OJ L 119, 4.5.2016, 1–88. https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng
European Parliament and Council of the European Union. (2024a). Regulation (EU) 2024/1183 of 11 April 2024 amending Regulation (EU) No 910/2014 as regards establishing the European Digital Identity Framework. OJ L, 2024/1183, 30.4.2024. https://eur-lex.europa.eu/eli/reg/2024/1183/oj/eng
European Parliament and Council of the European Union. (2024b). Regulation (EU) 2024/1689 of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act). OJ L, 2024/1689, 12.7.2024. https://artificialintelligenceact.eu/the-act/
European Parliament and Council of the European Union. (2024c). Regulation (EU) 2024/2847 of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements (Cyber Resilience Act). OJ L, 2024/2847, 20.11.2024. https://eur-lex.europa.eu/EN/legal-content/summary/horizontal-cybersecurity-requirements-for-products-with-digital-elements-cyber-resilience-act.html
Ferdous, M. S., Chowdhury, F., & Alassafi, M. O. (2019). In search of self-sovereign identity leveraging blockchain technology. IEEE Access, 7, 103059–103079. https://doi.org/10.1109/ACCESS.2019.2931173
Fung, C., Yoon, C. J. M., & Beschastnikh, I. (2020). The limitations of federated learning in Sybil settings. In 23rd International Symposium on Research in Attacks, Intrusions and Defenses (RAID 2020) (pp. 301–316). USENIX Association. https://www.usenix.org/conference/raid2020/presentation/fung
Herder, C., Yu, M.-D., Koushanfar, F., & Devadas, S. (2014). Physical unclonable functions and applications: A tutorial. Proceedings of the IEEE, 102(8), 1126–1141. https://doi.org/10.1109/JPROC.2014.2320516
Hevner, A. R., March, S. T., Park, J., & Ram, S. (2004). Design science in information systems research. MIS Quarterly, 28(1), 75–105. https://doi.org/10.2307/25148625
Kairouz, P., McMahan, H. B., Avent, B., Bellet, A., Bennis, M., Bhagoji, A. N., Bonawitz, K., Charles, Z., Cormode, G., Cummings, R., D'Oliveira, R. G. L., Eichner, H., El Rouayheb, S., Evans, D., Gardner, J., Garrett, Z., Gascón, A., Ghazi, B., Gibbons, P. B., … Zhao, S. (2021). Advances and open problems in federated learning. Foundations and Trends in Machine Learning, 14(1–2), 1–210. https://doi.org/10.1561/2200000083
Kolias, C., Kambourakis, G., Stavrou, A., & Voas, J. (2017). DDoS in the IoT: Mirai and other botnets. Computer, 50(7), 80–84. https://doi.org/10.1109/MC.2017.20
Lear, E., Droms, R., & Romascanu, D. (2019). Manufacturer usage description specification (RFC 8520). Internet Engineering Task Force. https://doi.org/10.17487/RFC8520
Meidan, Y., Bohadana, M., Mathov, Y., Mirsky, Y., Shabtai, A., Breitenbacher, D., & Elovici, Y. (2018). N-BaIoT: Network-based detection of IoT botnet attacks using deep autoencoders. IEEE Pervasive Computing, 17(3), 12–22. https://doi.org/10.1109/MPRV.2018.0336773
Nguyen, T. D., Marchal, S., Miettinen, M., Fereidooni, H., Asokan, N., & Sadeghi, A.-R. (2019). DÏoT: A federated self-learning anomaly detection system for IoT. In 2019 IEEE 39th International Conference on Distributed Computing Systems (ICDCS) (pp. 756–767). https://doi.org/10.1109/ICDCS.2019.00080
Peffers, K., Tuunanen, T., Rothenberger, M. A., & Chatterjee, S. (2007). A design science research methodology for information systems research. Journal of Management Information Systems, 24(3), 45–77. https://doi.org/10.2753/MIS0742-1222240302
Rose, S., Borchert, O., Mitchell, S., & Connelly, S. (2020). Zero trust architecture (NIST Special Publication 800-207). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-207
Sporny, M., Longley, D., Sabadello, M., Reed, D., Steele, O., & Allen, C. (2022). Decentralized identifiers (DIDs) v1.0 (W3C Recommendation, 19 July 2022). World Wide Web Consortium. https://www.w3.org/TR/did-core/
Sporny, M., Longley, D., Chadwick, D., & Herman, I. (2025). Verifiable credentials data model v2.0 (W3C Recommendation, 15 May 2025). World Wide Web Consortium. https://www.w3.org/TR/vc-data-model-2.0/
Yin, D., Chen, Y., Kannan, R., & Bartlett, P. (2018). Byzantine-robust distributed learning: Towards optimal statistical rates. In Proceedings of the 35th International Conference on Machine Learning (Proceedings of Machine Learning Research, Vol. 80, pp. 5650–5659). PMLR. https://proceedings.mlr.press/v80/yin18a.html