AI & Computingarticle2026-09-03

From Sealed to Anchored: What a Consortium Ledger Adds to HMAC-Sealed IoT Audit Logs in Ambient Assisted Living

Open access0 citations

Abstract

A symmetric integrity seal is worth exactly what its key is worth. Any party holding the keyed-hash (HMAC) key of an Internet of Things (IoT) audit trail can forge a record, re-seal a modified one, and leave no cryptographic trace, so an HMAC-sealed log establishes nothing to an external auditor or regulator beyond the honesty of the operator itself. This paper separates integrity from evidential strength and decomposes the latter into six properties—integrity, authenticity, non-repudiation of the anchored history, third-party verifiability, temporal upper-bounding, and bounded completeness—stating for each what a cryptographic mechanism can and cannot establish. It then presents the Ledger-Anchored Compliance Transformation Layer (LA-CTL), a two-tier architecture for Ambient Assisted Living (AAL) in which edge gateways seal each record with HMAC-SHA256 for operator-side verification and anchor RFC 6962 Merkle roots over sealed batches on a Byzantine fault-tolerant permissioned ledger shared with the auditor and the regulator. Records remain off-chain, preserving erasability under the General Data Protection Regulation. All cryptography is real; the consortium is evaluated both in a seeded network simulation and as four validator processes over sockets under LAN and emulated WAN conditions, at steady load and under the failure of a backup and of the primary. Anchoring is batch-priced rather than record-priced: on-chain state falls to 0.57 bytes per record at batch size 1024, while inclusion proofs grow logarithmically to at most 330 bytes. Holding the Merkle batching constant and varying only the publication substrate shows that most detection capability comes from the batching rather than from the ledger—a single-notary log matches the consortium on tampering, insider re-sealing, deletion and reordering—and that the quorum is distinguished on one attack: compromise of the publisher, which is the attack an operator-selected notary cannot withstand. The insider re-seal that the symmetric baseline accepts by construction is detected in all 10,000 trials. What the anchor does not give is stated with equal care: a commit bounds when the committed bytes existed, not when the event they describe occurred.

// Source

View paper (DOI)Open access versionOpenAlexApplied SciencesPublished 2026-09-03

Authors: Kunal Gawande, Vladimir Stantchev

Institutions: Heidelberg University, SRH Hochschule Heidelberg