Abstract
The growing use of IoT devices in healthcare has increased medical data security challenges, as traditional access control models like role-based access control (RBAC), attribute-based access control (ABAC), and mandatory access control (MAC) lack flexibility and context awareness. The healthcare Internet of Things (IoT) faces challenges such as limited scalability, lack of dynamic access controls, and security risks from a centralized point of vulnerability. The research aims to develop a resilient, decentralized access control solution that provides secure, time-sensitive permissions in healthcare IoT systems. A hybrid RBAC-ABAC model, built on blockchain and integrated with interplanetary file system (IPFS), enables secure data sharing across healthcare IoT devices, outperforming current models in accuracy, latency, and scalability. A dual smart contract–IPFS mechanism enables adaptive access control. Results show 96.5% precision, 3.2 ms policy evaluation, 120 ms response time, 74 TPS, low cost (US$2.1), and 45–52 MB memory use. It outperforms ABAC, RBAC, and MAC, offering scalable, efficient security for healthcare IoT data sharing.
© 2026 Qi Jing, published by International Journal on Smart Sensing and Intelligent Systems
This work is licensed under the Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 License.