A framework for verifying the integrity of IoT logs and tracing tampering based on deterministic Merkle trees
Main Article Content
Abstract
In IoT scenarios such as industrial gateways, park security, vehicle terminals, and medical monitoring, logs are often the first materials retrieved for fault recovery and security evidence, but they are not naturally reliable. Device disconnection, gateway caching, platform script misoperation, and even intruders who obtain maintenance privileges may cause record loss, rewriting, disorder, or field rewriting. This article proposes an IoT log integrity verification and tamper tracing framework based on deterministic Merkle trees to address this issue. The framework first converts heterogeneous logs into recalcitrable canonical objects, and then establishes an evidence chain using leaf hashing, batch root hashing, external anchoring, and audit paths. The article further presents the collaborative process of devices, gateways, platforms, and audit nodes, discussing inclusion verification, consistency verification, anomaly localization, and responsibility boundary division. The research believes that this method does not need to publicly link all logs, which can improve the credibility of logs with lower storage and transmission costs, and provide an executable solution for the safe operation and post investigation of the Internet of Things.
Downloads
Article Details

This work is licensed under a Creative Commons Attribution 4.0 International License.
Authors who publish with this journal agree to the following terms:
- Authors retain copyright and grant the journal right of first publication with the work simultaneously licensed under a Creative Commons Attribution License that allows others to share the work with an acknowledgement of the work's authorship and initial publication in this journal.
- Authors are able to enter into separate, additional contractual arrangements for the non-exclusive distribution of the journal's published version of the work (e.g., post it to an institutional repository or publish it in a book), with an acknowledgement of its initial publication in this journal.
- Authors are permitted and encouraged to post their work online (e.g., in institutional repositories or on their website) prior to and during the submission process, as it can lead to productive exchanges, as well as earlier and greater citation of published work (See The Effect of Open Access).
References
B. Vrooman, “Optimizing Merkle Tree Operations in a High-performance Blockchain Virtual Machine: Architectural Approaches and Performance Analysis,” Asian Journal of Research in Computer Science, vol. 19, no. 4, pp. 165–176, 2026, doi: 10.9734/AJRCOS/2026/V19I4856.
O. Hammoud and A. I. Tarkhanov, “Correction: A scaling distributed access control model for blockchain-based file storage systems,” Frontiers in Blockchain, vol. 9, pp. 1806905–1806905, 2026, doi: 10.3389/FBLOC. 2026.1806905.
A. Corsi, A. Almenhali, and N. Laurenti, “Analysis of collision probability in Merkle trees in the random oracle model,” Journal of Mathematical Cryptology, vol. 20, no. 1, pp. 20250050–20250050, 2026, doi: 10.1515/JMC-2025-0050.
S. Arunadevi and P. Valarmathie, “Privacy-Preserving and Scalable Electronic Health Record Management Using Multi-Layer Merkle Trees and Zero-Knowledge Proofs,” International Journal of Pattern Recognition and Artificial Intelligence, vol. 40, no. 5, 2026, doi: 10.1142/S02180014255 90177.
M. Zheng, S. Huang, D. Kong, et al., “Logarithmic-Size Post-Quantum Linkable Ring Signatures Based on Aggregation Operations,” Entropy, vol. 28, no. 1, pp. 130–130, 2026, doi: 10.3390/E28010130.
M. A. M. M. Alsaedy, Z. A. Ghalwash, E. A. A. Yousif, et al., “E-AAPIV: Merkle Tree-Based Real-Time Android Manifest Integrity Verification for Mobile Payment Security,” Journal of Cyber Security, vol. 7, no. 1, pp. 653–674, 2025, doi: 10.32604/JCS.2025.073547.
S. Kodadi, K. Dondapati, D. P. D. Deevi, et al., “Optimizing Supply Chain Finance with XGBOOST and Merkle Tree Blockchain,” International Journal of Innovation and Technology Management, vol. 22, no. 7–08, 2025, doi: 10.1142/S0219877025400061.
R. Du, Z. Wang, and J. Shen, “Certificateless data integrity auditing with sparse Merkle trees for the cloud-edge environment,” Scientific Reports, vol. 15, no. 1, pp. 39202–39202, 2025, doi: 10.1038/S41598-025-14041-9.
M. S. Prabhu, N. Subramanyam, P. S. Krishnan, et al., “Decentralized digital currency system using Merkle hash trees,” Journal of Banking and Financial Technology, vol. 9, no. 2, pp. 1–31, 2025, doi: 10.1007/S42786-025-00059-0.
A. V. H. Le, N. D. Q. Nguyen, N. Tadashi, et al., “Blockchain-Based Decentralized Identity Management System with AI and Merkle Trees,” Computers, vol. 14, no. 7, pp. 289–289, 2025, doi: 10.3390/COMPUTER S14070289.
G. Liu, H. Lu, W. Wang, et al., “An efficient authentication scheme for vehicular networks based on Merkle tree,” Computer Networks, vol. 269, pp. 111429–111429, 2025, doi: 10.1016/J.COMNET.2025.111429.
P. Liu, D. Luo, J. Liu, et al., “CMT-YARN: an efficient security framework for yarn based on an improved merkle tree,” The Journal of Supercomput-ing, vol. 81, no. 10, pp. 1098–1098, 2025, doi: 10.1007/S11227-025-075 71-6.
S. Narla, S. Peddi, T. D. Valivarthi, et al., “FOG computing based energy efficient and secured iot data sharing using SGSOA and GMCC,” Sustainable Computing: Informatics and Systems, vol. 46, pp. 101109–101109, 2025, doi: 10.1016/J.SUSCOM.2025.101109.
Y. Wu, T. Feng, C. Su, et al., “MSAUPL: A multi-server authentication and key agreement protocol for industrial IoT based on user privacy level,” Journal of Information Security and Applications, vol. 89, pp. 103991– 103991, 2025, doi: 10.1016/J.JISA.2025.103991.
S. Liu, X. Zhou, A. X. Wang, et al., “A hash-based post-quantum ring signature scheme for the Internet of Vehicles,” Journal of Systems Architecture, vol. 160, pp. 103345–103345, 2025, doi: 10.1016/J.SYSARC.202 5.103345.
S. S. Fateminasab, D. Bahrepour, and K. R. S. Tabbakh, “A fair non-collateral consensus protocol based on Merkle tree for hierarchical IoT blockchain,” Scientific Reports, vol. 15, no. 1, pp. 3645–3645, 2025, doi: 10.1038/S41598-025-87025-4.
Y. Meng, B. Wang, Q. Xing, et al., “BBAD: Blockchain-based data assured deletion and access control system for IoT,” Peer-to-Peer Networking and Applications, vol. 18, no. 2, pp. 1–1, 2024, doi: 10.1007/S12083-024-018 81-X.
M. Nasreen and K. S. Singh, “BPMT: A hybrid model for secure and effective electronic medical record management system,” Journal of Computational Science, vol. 83, pp. 102457–102457, 2024, doi: 10.1016/J.JO CS.2024.102457.
E. Mollakuqe, H. Dag, and V. Dimitrova, “Mathematical Foundations and Implementation of CONIKS Key Transparency,” Applied Sciences, vol. 14, no. 21, pp. 9725–9725, 2024, doi: 10.3390/APP14219725.
A. Romero and R. Hernandez, “Blockchain-Driven Generalization of Policy Management for Multiproduct Insurance Companies,” Future Internet, vol. 16, no. 10, pp. 356–356, 2024, doi: 10.3390/FI16100356.