Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

486 papersLast indexed Aug 31, 2026
Search papers

Paper index

486 results · page 10 of 21

Clear filters
Sep 15, 2025·arXiv (Cornell University)
0 cites
Dstack: A Zero Trust Framework for Confidential Containers

Zhou, Shunfan, Wang, Kevin, Hang Yin

Web3 applications require execution platforms that maintain confidentiality and integrity without relying on centralized trust authorities. While Trusted Execution Environments (TEEs) offer promising capabilities for confidential computing, current implementations face significant limitations when applied to Web3 contexts, particularly in security reliability, censorship resistance, and vendor independence. This paper presents dstack, a comprehensive framework that transforms raw TEE technology into a true Zero Trust platform. We introduce three key innovations: (1) Portable Confidential Containers that enable seamless workload migration across heterogeneous TEE environments while maintaining security guarantees, (2) Decentralized Code Management that leverages smart contracts for transparent governance of TEE applications, and (3) Verifiable Domain Management that ensures secure and verifiable application identity without centralized authorities. These innovations are implemented through three core components: dstack-OS, dstack-KMS, and dstack-Gateway. Together, they demonstrate how to achieve both the performance advantages of VM-level TEE solutions and the trustless guarantees required by Web3 applications. Our evaluation shows that dstack provides comprehensive security guarantees while maintaining practical usability for real-world applications.

Open access
2 source records
Cloud Data Security Solutions
Security and Verification in Computing
Access Control and Trust
Original source
Sep 3, 2025·Proceedings of the 2025 International Conference on Information Technology for Social Good
0 cites
Requirements for Decentralized Consensus in E-Health Workflows: Towards Trustworthy Interorganizational Coordination

Aleksandr Kormiltsyn, Sowelu Avanzo, Vimal Dwivedi, Alex Norta · 5 authors

This paper explores conflict resolution in decentralized e-health prescription creation workflows, necessary for secure and efficient multi-stakeholder data sharing. Consensus mechanisms ensure consistency and enable trust across distributed systems. Decentralized Autonomous Organizations (DAOs) are adopted for decentralized decision-making in several domains but remain unexplored in e-healthcare. Current consensus mechanisms lack integration with governance models, limiting their adaptability to domain-specific requirements. Moreover, there is no existing consensus algorithm adapted for e-health, resulting in the lack of privacy, interoperability, and patient-centered data ownership. As a result, automatic conflict resolution in interorganizational e-health processes is complicated or almost impossible. To address this gap, we propose a domain-specific consensus algorithm adapted to the requirements of the e-health domain. The algorithm is embedded within a DAO-based governance framework, enabling transparency in decision-making among e-health stakeholders. Such integration enables automated, privacy-preserving conflict resolution in interorganizational e-health workflows. Following the Design Science methodology, the consensus algorithm for e-health DAO is based on stakeholder-driven requirements and evaluated using Colored Petri Nets (CPN). The evaluation shows the solution improves conflict resolution enabling fair, efficient, and privacy-aware collaboration in decentralized e-health.

Open access
Access Control and Trust
Business Process Modeling and Analysis
Blockchain Technology Applications and Security
Original source
Aug 19, 2025·arXiv (Cornell University)
0 cites
BetaWeb: Towards a Blockchain-enabled Trustworthy Agentic Web

Zihan Guo, Yuanjian Zhou, Chenyi Wang, Linlin You · 6 authors

The rapid development of large language models (LLMs) has significantly propelled the development of artificial intelligence (AI) agents, which are increasingly evolving into diverse autonomous entities, advancing the LLM-based multi-agent systems (LaMAS). However, current agentic ecosystems remain fragmented and closed. Establishing an interconnected and scalable paradigm for Agentic AI has become a critical prerequisite. Although Agentic Web proposes an open architecture to break the ecosystem barriers, its implementation still faces core challenges such as privacy protection, data management, and value measurement. Existing centralized or semi-centralized paradigms suffer from inherent limitations, making them inadequate for supporting large-scale, heterogeneous, and cross-domain autonomous interactions. To address these challenges, this paper introduces the blockchain-enabled trustworthy Agentic Web (BetaWeb). By leveraging the inherent strengths of blockchain, BetaWeb not only offers a trustworthy and scalable infrastructure for LaMAS but also has the potential to advance the Web paradigm from Web3 (centered on data ownership) towards Web3.5, which emphasizes ownership of agent capabilities and the monetization of intelligence. Beyond a systematic examination of the BetaWeb framework, this paper presents a five-stage evolutionary roadmap, outlining the path of LaMAS from passive execution to advanced collaboration and autonomous governance. We also conduct a comparative analysis of existing products and discuss key challenges of BetaWeb from multiple perspectives. Ultimately, we argue that deep integration between blockchain and LaMAS can lay the foundation for a resilient, trustworthy, and sustainably incentivized digital ecosystem. A summary of the enabling technologies for each stage is available at https://github.com/MatZaharia/BetaWeb.

Open access
2 source records
Blockchain Technology Applications and Security
Access Control and Trust
Cloud Data Security Solutions
Original source
Aug 10, 2025·Qeios
0 cites
Truvry: Portable, Decentralized Trust Proofs for Inclusive Digital Participation and Democratic Decision-Making

Akhileshwar Pathak

Democratic institutions increasingly rely on verifiable digital trust to enable fair participation and evidence-based decisions. Truvry is a decentralized protocol that converts behaviour-based evidence (usage patterns, transaction integrity, peer attestations) into portable cryptographic proofs that remain independent of any single platform or identifier, allowing individuals to transfer trust capital across domains while preserving privacy. The current prototype is zero-knowledge–compatible; in this version we use hashed proof anchoring and field-level redaction (no zk-SNARK module is deployed), with configurable smart-contract verifiers. By decoupling trust from identity, Truvry widens citizen inclusion, mitigates gatekeeping bias, and supplies auditable inputs for AI-mediated governance. In prototype tests (n=112), end-to-end proof issuance averaged 3.7 s (fastest local 1.4 s), verifier parse+check averaged 1.8 s, and the current minimum anonymization entropy is 8.9 bits; gas costs for optional on-chain anchoring remained below US$0.02. All results are based on simulated user streams; a production pilot is planned.

Open access
Access Control and Trust
Blockchain Technology Applications and Security
Cryptography and Data Security
Original source
Aug 1, 2025·arXiv
1 cites
A Study on Privacy-Preserving Scholarship Evaluation Based on Decentralized Identity and Zero-Knowledge Proofs

Yi Chen, Bin Chen, Peichang Zhang, Da Che

Traditional centralized scholarship evaluation processes typically require students to submit detailed academic records and qualification information, which exposes them to risks of data leakage and misuse, making it difficult to simultaneously ensure privacy protection and transparent auditability. To address these challenges, this paper proposes a scholarship evaluation system based on Decentralized Identity (DID) and Zero-Knowledge Proofs (ZKP). The system aggregates multidimensional ZKPs off-chain, and smart contracts verify compliance with evaluation criteria without revealing raw scores or computational details. Experimental results demonstrate that the proposed solution not only automates the evaluation efficiently but also maximally preserves student privacy and data integrity, offering a practical and trustworthy technical paradigm for higher education scholarship programs.

Open access
2 source records
cs.CR
Privacy-Preserving Technologies in Data
Access Control and Trust
Original source
Aug 1, 2025·Open MIND
0 cites
Generic Agnostic AI and Distributed Ledger Enterprise System for Scalable Domain Adaptation: Architecture and Methodology for Vertical-Specific AI Deployment from a Unified Core Framework

Walter Kurz, Michel Malara, Velimir Dedić

The objective of this study is to define a compliance-first, conceptually generalisable architecture for a multi-agent artificial intelligence platform integrated with distributed ledger technology, designed to be domain-, deployment-, and vendor-agnostic. It addresses a persistent shortcoming in current AI deployments, where compliance is often treated as a secondary concern, applied retroactively through prompt engineering rather than embedded within the foundational design. The proposed model encodes regulatory, governance, and ESG requirements into an objective-under-constraints framework, ensuring that all specialised agents operate within legally admissible and verifiably auditable parameters prior to any domain-specific implementation. A DAG-based verification layer is incorporated to enable scalable, low-latency, and cost-efficient operation while preserving evidentiary integrity. The analysis evaluates the feasibility of this conceptual model to support sustainable, rapid-deployment vertical applications without inducing vendor lock-in, preserving operational neutrality, and ensuring environmental accountability. The findings suggest that integrating compliance, ESG metrics, and agent specialisation at the architectural level provides a transferable foundation for cross-domain AI-DLT infrastructures.

Open access
2 source records
Advanced Software Engineering Methodologies
Multi-Agent Systems and Negotiation
Access Control and Trust
Original source
Jul 10, 2025·arXiv (Cornell University)
0 cites
The Trust Fabric: Decentralized Interoperability and Economic Coordination for the Agentic Web

Sree Bhargavi Balija, Singal, Rekha, Ramesh Raskar, Erfan Darzi · 7 authors

The fragmentation of AI agent ecosystems has created urgent demands for interoperability, trust, and economic coordination that current protocols -- including MCP (Hou et al., 2025), A2A (Habler et al., 2025), ACP (Liu et al., 2025), and Cisco's AGP (Edwards, 2025) -- cannot address at scale. We present the Nanda Unified Architecture, a decentralized framework built around three core innovations: fast DID-based agent discovery through distributed registries, semantic agent cards with verifiable credentials and composability profiles, and a dynamic trust layer that integrates behavioral attestations with policy compliance. The system introduces X42/H42 micropayments for economic coordination and MAESTRO, a security framework incorporating Synergetics' patented AgentTalk protocol (US Patent 12,244,584 B1) and secure containerization. Real-world deployments demonstrate 99.9 percent compliance in healthcare applications and substantial monthly transaction volumes with strong privacy guarantees. By unifying MIT's trust research with production deployments from Cisco and Synergetics, we show how cryptographic proofs and policy-as-code transform agents into trust-anchored participants in a decentralized economy (Lakshmanan, 2025; Sha, 2025). The result enables a globally interoperable Internet of Agents where trust becomes the native currency of collaboration across both enterprise and Web3 ecosystems.

Open access
2 source records
Access Control and Trust
Blockchain Technology Applications and Security
Mobile Agent-Based Network Management
Original source
Jul 8, 2025·Figshare
0 cites
Dataset for Systematic Review of IAM Advancements : Insights into AI, Blockchain, and Zero Trust Architectures

Orchere Selorm (21608093)

<p dir="ltr"><b>Advances in Identity and Access Management (IAM): Systematic Insights into AI, Blockchain, and Zero Trust Architectures</b> <p dir="ltr">In an era of expanding digital infrastructure, cloud computing, and remote work, robust Identity and Access Management (IAM) systems are critical for securing sensitive data and ensuring regulatory compliance. This research paper provides a comprehensive systematic review of recent advancements in IAM technologies, addressing the limitations of traditional centralized systems, such as single points of failure and privacy concerns. Utilizing the PRISMA methodology, the study analyzes five peer-reviewed articles from a pool of 23 retrieved from Scopus, published between 2021 and 2025. Key innovations explored include passwordless authentication, AI-driven adaptive authentication, Zero Trust architectures, decentralized identity (DID), self-sovereign identity (SSI), and privacy-enhancing cryptographic techniques like zero-knowledge proofs. The review highlights their applications in multi-cloud, IoT, and hybrid environments, emphasizing enhanced security, user experience, and interoperability. Challenges such as standardization gaps, implementation costs, and privacy concerns are discussed, alongside future directions, including universal protocols and IoT integration. A publicly accessible dataset (DOI: 10.5281/zenodo.12345678) ensures reproducibility. This work serves as an essential resource for cybersecurity researchers and practitioners seeking to navigate the evolving landscape of IAM technologies.

Open access
Blockchain Technology Applications and Security
Access Control and Trust
Big Data and Digital Economy
Original source
Jul 8, 2025·arXiv (Cornell University)
0 cites
Programmable Governance for Group-Controlled Decentralized Identifiers

Carlo Segat, Sandro Rodriguez Garzon, Axel Küpper

Self-Sovereign Identity (SSI) is a paradigm for digital identity management that offers privacy and flexibility advantages. A key technology in SSI is Decentralized Identifiers (DIDs) and their associated metadata, DID Documents (DDOs). DDOs contain crucial verification material such as the public keys of the entity identified by the DID (i.e., the DID subject) and are often anchored on a distributed ledger to ensure security and availability. Long-lived DIDs must support updates (e.g., key rotation). Ideally, only the DID subject should authorize DDO updates. However, in practice, update capabilities may be shared or delegated. While the DID specification acknowledges such scenarios, it does not define how updates should be authorized when multiple entities jointly control a DID (i.e., group control). This article examines the implementation of an on-chain, trustless mechanism enabling DID controllers under group control to program their governance rules. The main research question is the following: Can a technical mechanism be developed to orchestrate on-chain group control of a DDO in a ledger-agnostic and adaptable manner?

Open access
3 source records
cs.NI
Access Control and Trust
Cryptography and Data Security
Original source
Jul 1, 2025·University of North Texas Libraries
0 cites
Scalable Distributed Ledger Paradigms for Secure IoT-Driven Data Management in Smart Cities

Musharraf N. Alruwaill

Blockchain has become a cornerstone of trustworthy, decentralised information governance. Consensus protocols and cryptographic linkages guarantee data integrity, immutability, and verifiable provenance, eliminating reliance on a single trusted authority and mitigating data fragmentation. Within smart‑healthcare ecosystems, these capabilities enable the shift from siloed, centralised repositories to distributed, patient‑centric infrastructures. Because clinical data are highly sensitive and strictly regulated, robust assurances of integrity, confidentiality, and fine‑grained authorisation are essential. Integrating blockchain and smart contracts with technologies such as distributed off‑chain storage and the Internet of Medical Things (IoMT) creates a resilient, scalable, and interoperable foundation for next‑generation healthcare data management. This research introduces hChain, a four‑generation family of distributed‑ledger frameworks that progressively strengthen security, intelligence, and scalability in smart‑healthcare environments. hChain 1.0 lays the groundwork with a blockchain architecture that safeguards patient data, supports real‑time clinical telemetry, and enables seamless inter‑institutional exchange. Building on this foundation, hChain 2.0 integrates InterPlanetary File System (IPFS) storage and smart‑contract enforcement to deliver tamper‑proof, fine‑grained access control. hChain 3.0 embeds on‑chain deep‑learning analytics, providing proactive, automated decision support across the care continuum while preserving data integrity. Finally, hChain 4.0 introduces a highly scalable, permissioned ledger augmented by an Attribute‑Based Access Control (ABAC) layer, ensuring dynamic, context‑aware authorisation in complex organisational settings. The results demonstrate practical solutions for transforming data infrastructures from centralised to decentralised architectures, providing techniques that facilitate seamless integration with existing systems while enhancing blockchain scalability and privacy.

Open access
Privacy-Preserving Technologies in Data
Cloud Data Security Solutions
Access Control and Trust
Original source
Jun 6, 2025·DOAJ (DOAJ: Directory of Open Access Journals)
0 cites
Threat Modeling a Health Web3 DApp

Gomes, Ricardo, Dinis, Daniela, Oliveira, João, Maximiano, Marisa · 8 authors

The healthcare sector increasingly explores Distributed Ledger Technology (DLT) and Health Web 3.0 Decentralized Applications (DApps) as promising solutions for patient-centric data management, data sovereignty, and privacy-preserving systems. Despite significant research at the intersection of blockchain and healthcare, current efforts predominantly address isolated technical challenges—focusing narrowly on specific mechanisms such as confidentiality, privacy, or individual smart contract vulnerabilities. Even cybersecurity assessments typically examine discrete attack vectors rather than comprehensive threat landscapes. This fragmented approach limits our ability to build trustworthy systems and delays real-world adoption, as stakeholders lack frameworks to holistically evaluate security posture. This study addresses this gap by conducting a comprehensive threat modeling analysis of Health Web 3.0 DApps, taking into account the complex and interconnected security challenges inherent in blockchain-based healthcare systems. We employ a multi-framework approach integrating LINDDUN threat modeling methodology, OWASP Top 10 Smart Contract Vulnerabilities catalog, and Threat Dragon analytical tool to systematically identify, categorize, and evaluate security risks across the entire application stack. Our analysis maps threats spanning smart contract design flaws, cross-chain interaction vulnerabilities, decentralized identity management weaknesses, unauthorized data access risks, and denial-of-service attack vectors. The primary contribution of this work is demonstrating the critical importance and practical value of holistic threat modeling in blockchain healthcare systems. Our findings reveal interdependencies between seemingly isolated vulnerabilities and show how comprehensive security assessment enhances data privacy protection, smart contract integrity, and overall application resilience. This research provides stakeholders with a systematic methodology for deriving trust in blockchain healthcare solutions, advancing both regulatory compliance and user confidence in decentralized medical data management systems.

Open access
Blockchain Technology Applications and Security
Information and Cyber Security
Access Control and Trust
Original source
May 15, 2025·World Journal of Advanced Engineering Technology and Sciences
0 cites
Decentralized trust frameworks for cross-enterprise integration

K. Muralidharan

Decentralized trust frameworks represent a fundamental transformation in cross-enterprise integration, addressing longstanding challenges in business-to-business interactions. These frameworks leverage Web3 technologies, specifically, Distributed Ledger Technology, Decentralized Identifiers, and Verifiable Credentials to establish inherent trust between organizations without relying on centralized intermediaries. Through cryptographic verification mechanisms, organizations gain enhanced security, verifiable data provenance, reduced reconciliation overhead, and improved operational resilience. The architectural components include a decentralized identity layer providing 99.98% authentication accuracy, credential exchange mechanisms enabling selective disclosure with 99.87% privacy preservation, shared ledger infrastructure ensuring immutable audit trails, and enterprise integration components bridging with existing systems. Implementation patterns such as credential-based API authorization, event-triggered credential issuance, ledger-anchored business processes, and credential-based data exchange deliver substantial improvements in security posture and operational efficiency. Despite significant benefits including 87.3% security enhancement and 73.4% reduction in reconciliation efforts, adoption challenges remain around technical complexity, standards maturity, legacy system integration, and governance frameworks. By addressing these challenges through phased implementation focusing on high-value integration points, organizations can gradually transform their integration landscape toward more secure, transparent, and resilient models that fundamentally change how trust is established in digital business ecosystems.

Open access
Access Control and Trust
Original source
May 8, 2025·2025 Crypto Valley Conference (CVC)
5 cites
SoK: A Taxonomy for Distributed-Ledger-Based Identity Management

Awid Vaziry, Sandro Rodriguez Garzon, Patrick Herbke, Carlo Segat · 5 authors

The intersection of blockchain (distributed ledger) and identity management lacks a comprehensive framework for classifying distributed-ledger-based identity solutions. This paper introduces a methodologically developed taxonomy derived from the analysis of 390 scientific papers and expert discussions. The resulting framework consists of 22 dimensions with 113 characteristics, organized into three groups: trust anchor implementations, identity architectures (identifiers and credentials), and ledger specifications. This taxonomy facilitates the systematic analysis, comparison, and design of distributed-ledger-based identity solutions, as demonstrated through its application to two distinct architectures. As the first methodology-driven taxonomy in this field, this work advances standardization and enhances understanding of distributed-ledger-based identity architectures. It provides researchers and practitioners with a structured framework for evaluating design decisions and implementation approaches.

Open access
2 source records
Blockchain Technology Applications and Security
Access Control and Trust
Privacy-Preserving Technologies in Data
Original source
Apr 28, 2025·arXiv (Cornell University)
0 cites
From Paper Trails to Trust on Tracks: Adding Public Transparency to Railways via zk-SNARKs

Tarek Galal, Valeria Tisch, Katja Assaf, Andreas Polze

Railways provide a critical service and operate under strict regulatory frameworks for implementing changes or upgrades. Despite their impact on the public, these frameworks do not define means or mechanisms for transparency towards the public, leading to reduced trust and complex tracking processes. We analyse the German guideline for railway-infrastructural modifications from proposal to approval, using the guideline as a motivating example for modelling decisions in processes using digital signatures and zero-knowledge proofs. Therein, a verifier can verify that a process was executed correctly by the involved parties and according to specification without learning confidential information such as trade secrets or identities of the participants. We validate our system by applying it to the railway process, demonstrating how it realises various rules, and we evaluate its scalability with increased process complexities. Our solution is not railway-specific but also applicable to other contexts, helping leverage zero-knowledge proofs for public transparency and trust.

Open access
3 source records
cs.CR
Safety Systems Engineering in Autonomy
Access Control and Trust
Original source
Apr 24, 2025·arXiv (Cornell University)
2 cites
Federated Learning: A Survey on Privacy-Preserving Collaborative Intelligence

Ratun Rahman

Federated Learning (FL) has emerged as a transformative paradigm in the field of distributed machine learning, enabling multiple clients such as mobile devices, edge nodes, or organizations to collaboratively train a shared global model without the need to centralize sensitive data. This decentralized approach addresses growing concerns around data privacy, security, and regulatory compliance, making it particularly attractive in domains such as healthcare, finance, and smart IoT systems. This survey provides a concise yet comprehensive overview of Federated Learning, beginning with its core architecture and communication protocol. We discuss the standard FL lifecycle, including local training, model aggregation, and global updates. A particular emphasis is placed on key technical challenges such as handling non-IID (non-independent and identically distributed) data, mitigating system and hardware heterogeneity, reducing communication overhead, and ensuring privacy through mechanisms like differential privacy and secure aggregation. Furthermore, we examine emerging trends in FL research, including personalized FL, cross-device versus cross-silo settings, and integration with other paradigms such as reinforcement learning and quantum computing. We also highlight real-world applications and summarize benchmark datasets and evaluation metrics commonly used in FL research. Finally, we outline open research problems and future directions to guide the development of scalable, efficient, and trustworthy FL systems.

Open access
Privacy-Preserving Technologies in Data
Privacy, Security, and Data Protection
Access Control and Trust
Original source
Apr 21, 2025·Electronics
1 cites
RBFAC: A Redactable Blockchain Framework with Fine-Grained Access Control Based on Flexible Policy Chameleon Hash

Shunqing Wu, Lifei Wei, Sean M. Wu, Lei Zhang

While blockchain’s immutability ensures data integrity, it also poses significant challenges when dealing with illegal or erroneous data that require modification. The concept of redactable blockchain has emerged, utilizing Chameleon Hash (CH) and subsequent Policy-based Chameleon Hash (PCH) for controlled data editing. However, current redactable blockchain implementations exhibit significant limitations, particularly in their inability to separate data editing from policy modification and their insufficient support for decentralized management of diverse editing operations. To address these issues, this paper initially introduces the concept of Flexible Policy Chameleon Hash (FPCH), which integrates PCH with non-interactive zero-knowledge proofs to enable enhanced policy management flexibility. Moreover, this paper proposes a Redactable Blockchain Framework with Fine-grained Access Control (RBFAC) based on FPCH. The RBFAC framework employs a hybrid cryptographic approach to separate the right of data editing from policy modification. The framework also provides essential functionalities, including editing accountability, key tracking and revocation mechanisms, and policy privacy protection. Finally, experimental evaluations demonstrate that the RBFAC framework maintains acceptable performance overhead while delivering these advanced features. The results indicate that the proposed solution addresses the limitations of existing redactable blockchain systems, offering a more flexible and secure approach to controlled data editing in blockchain environments.

Open access
Access Control and Trust
Cryptography and Data Security
Cloud Data Security Solutions
Original source
Apr 15, 2025·International Journal on Advanced Electrical and Computer Engineering
0 cites
Distributed Ledger Technology for Decentralized Identity Management

Adam Bennett, Jennifer Clarke

The rapid advancement of digital services and online interactions has highlighted the need for secure, user-centric identity management systems. Traditional identity solutions, often centralized and dependent on trusted third parties, pose challenges related to privacy, security, and control over personal data. Distributed Ledger Technology (DLT), particularly blockchain, offers a promising solution for decentralized identity management by enabling self-sovereign identities (SSI). Through the use of decentralized identifiers (DIDs) and verifiable credentials (VCs), DLT allows individuals to maintain full control over their personal information, eliminating the need for intermediaries while ensuring data integrity and privacy. This paper explores the key principles of DLT-based decentralized identity management, discussing its potential to enhance privacy, security, and interoperability in digital ecosystems. We examine the various technical frameworks, challenges, and standards in the field, with a focus on the integration of DLT with emerging technologies such as zero-knowledge proofs (ZKPs) and secure multiparty computation (SMPC). Additionally, we evaluate real-world use cases, from financial services to healthcare, and the role of regulatory frameworks in shaping the future of decentralized identity systems. Ultimately, DLT presents a paradigm shift in identity management, offering scalable, transparent, and trusted solutions for the digital age.

Open access
Blockchain Technology Applications and Security
Cryptography and Data Security
Access Control and Trust
Original source
Mar 21, 2025·Crypto Valley Conference (CVC), 2025, pp. 44-55
3 cites
Governance of Ledger-Anchored Decentralized Identifiers

Sandro Rodriguez Garzon, Carlo Segat, Axel Küpper

A Decentralized Identifier (DID) empowers an entity to prove control over a unique and self-issued identifier without relying on any identity provider. The public key material for the proof is encoded into an associated DID document (DDO). This is preferable shared via a distributed ledger because it guarantees algorithmically that everyone has access to the latest state of any tamper-proof DDO but only the entities in control of a DID are able to update theirs. Yet, it is possible to grant deputies the authority to update the DDO on behalf of the DID owner. However, the DID specification leaves largely open on how authorizations over a DDO are managed and enforced among multiple deputies. This article investigates what it means to govern a DID and discusses various forms of how a DID can be controlled by potentially more than one entity. It also presents a prototype of a DID-conform identifier management system where a selected set of governance policies are deployed as Smart Contracts. The article highlights the critical role of governance for the trustworthy and flexible deployment of ledger-anchored DIDs across various domains.

Open access
3 source records
Privacy-Preserving Technologies in Data
Access Control and Trust
Cryptography and Data Security
Original source
Mar 20, 2025·Electronics
0 cites
Performance Modeling of Distributed Ledger-Based Authentication in Cyber–Physical Systems Using Colored Petri Nets

Michał Jarosz, Konrad Wrona, Zbigniew Zieliński

Federated cyber–physical systems (CPSs) present unique security challenges due to their distributed nature and the need for secure communication between components from different administrative domains. Distributed ledger technology (DLT) offers a promising approach to implementing a resilient authentication and authorization mechanism and an immutable record of CPS identities and transactions in federated environments. However, using Distributed Ledger (DL) within a CPS raises some important questions regarding scalability, throughput, latency, and potential bottlenecks, which require effective modeling of DL performance. This paper proposes a novel approach to modeling distributed ledgers using Colored Timed Petri Nets (CPNs). We focus on the performance modeling of Hyperledger Fabric (HLF), a permissioned distributed ledger technology which provides a backbone for a Lightweight Authentication and Authorization Framework for Federated IoT (LAAFFI), a novel framework for secure communication between CPS devices. We implement our model using CPN Tools, a widely adopted CPN modeling software that provides advanced simulation, analysis, and performance monitoring features. Our model offers a robust framework for studying distributed ledger systems’ synchronization, throughput, and response time. It supports flexibility in modeling transaction validation and consensus algorithms, which provides an opportunity for adapting the model to future changes in HLF and modeling other DLs. We successfully validate our CPN model by comparing simulation results with experimental measurements obtained from a LAAFFI prototype.

Open access
Smart Grid Security and Resilience
Petri Nets in System Modeling
Access Control and Trust
Original source
Mar 12, 2025·arXiv (Cornell University)
1 cites
RaceTEE: Enabling Interoperability of Confidential Smart Contracts

Keyu Zhang, Andrew Martin

Decentralized smart contracts enable trustless collaboration but suffer from limited privacy and scalability, which hinders broader adoption. Trusted Execution Environment (TEE) based off-chain execution frameworks offer a promising solution to both issues. Although TEE-based frameworks have made significant progress, prior work has yet to fully explore contract interoperability, a critical foundation for building complex real-world decentralized applications. This paper identifies the key challenges impeding such interoperability and presents practical solutions. Based on these insights, we introduce RaceTEE, a novel framework that leverages off-chain TEE-enabled nodes to efficiently execute confidential, long-lived smart contracts with interactions of arbitrary complexity among contracts. We implement a RaceTEE prototype using Intel SGX, integrate it with Ethereum, and release it as open source. Evaluation across diverse use cases demonstrates its practicality and effectiveness.

Open access
4 source records
cs.CR
Blockchain Technology Applications and Security
FinTech, Crowdfunding, Digital Finance
Original source
Mar 11, 2025·Electronics
1 cites
Embedding Security Awareness into a Blockchain-Based Dynamic Access Control Framework for the Zero Trust Model in Distributed Systems

Avoy Mohajan, Sharmin Jahan

The Zero Trust (ZT) model is pivotal in enhancing the security of distributed systems by emphasizing rigorous identity verification, granular access control (AC), and continuous monitoring. To address the complexity and scalability challenges of modern distributed systems, we propose a blockchain-based dynamic access control scheme (DACS) as a practical solution for implementing ZT principles. This framework dynamically manages access control lists (ACLs) and enforces policies through smart contracts. In the DACS framework, each blockchain node maintains an object list specifying access permissions within its ACL and incorporates a minimum trust metric (TM) threshold to evaluate access requests. The TM assigned to each node reflects its trustworthiness. To further enhance security, the framework includes security awareness, enabling the dynamic assessment of the risk factor (RF), which reflects the operational risk level. The TM of access-requesting nodes is updated at runtime based on their behavior, with penalties imposed for malicious actions according to the prevailing RF. Access control policies are dynamically adjusted, mitigating risks posed by potentially untrustworthy users with valid credentials. Implemented and tested on the Ethereum blockchain, the proposed DACS framework demonstrates its efficiency and effectiveness in securing distributed systems.

Open access
Blockchain Technology Applications and Security
Access Control and Trust
Security and Verification in Computing
Original source
Feb 22, 2025·Future Generation Computer Systems
2 cites
A Trust-Aware and Cost-Optimized Blockchain Oracle Selection Model with Deep Reinforcement Learning

H.C. Zhang, Shike Li, Shike Li, Hang Bao · 6 authors

The rapid development of blockchain technology has driven the widespread application of decentralized applications (DApps) across various fields. However, DApps cannot directly access external data and rely on oracles to interact with off-chain data. As a bridge between blockchain and external data sources, oracles pose potential risks of malicious behavior, which may inject incorrect or harmful data, leading to trust and security issues. Additionally, with the surge in data requests, the disparity in oracle trustworthiness and costs has increased, making the dynamic selection of the most suitable oracle for each request a critical challenge. To address these issues, this paper proposes a Trust-Aware and Cost-Optimized Blockchain Oracle Selection Model with Deep Reinforcement Learning (TCO-DRL). The model incorporates a comprehensive trust management mechanism to evaluate oracle reputation from multiple dimensions and employs an improved sliding time window to monitor reputation changes in real time, enhancing resistance to malicious attacks. Moreover, TCO-DRL uses deep reinforcement learning algorithms to dynamically adapt to fluctuations in oracle reputation, ensuring the selection of high-reputation oracles while optimizing node selection, thereby reducing costs without compromising data quality. We implemented and validated TCO- DRL on Ethereum. Experimental results show that, compared to existing methods, TCO-DRL reduces the allocation rate to malicious oracles by more than 39.10% and saves over 12.00% in costs. Furthermore, simulated experiments on various malicious attacks further validate the robustness and effectiveness of TCO-DRL

Open access
3 source records
cs.CE
cs.ET
Blockchain Technology Applications and Security
Original source
Feb 10, 2025·arXiv
5 cites
Generating Privacy-Preserving Personalized Advice with Zero-Knowledge Proofs and LLMs

Hiroki Watanabe, Motonobu Uchikoshi

Large language models (LLMs) are increasingly utilized in domains such as finance, healthcare, and interpersonal relationships to provide advice tailored to user traits and contexts. However, this personalization often relies on sensitive data, raising critical privacy concerns and necessitating data minimization. To address these challenges, we propose a framework that integrates zero-knowledge proof (ZKP) technology, specifically zkVM, with LLM-based chatbots. This integration enables privacy-preserving data sharing by verifying user traits without disclosing sensitive information. Our research introduces both an architecture and a prompting strategy for this approach. Through empirical evaluation, we clarify the current constraints and performance limitations of both zkVM and the proposed prompting strategy, thereby demonstrating their practical feasibility in real-world scenarios.

Open access
2 source records
Privacy-Preserving Technologies in Data
Cryptography and Data Security
Access Control and Trust
Original source
Feb 10, 2025·IEEE Transactions on Services Computing
2 cites
AiRacleX: Automated Detection of Price Oracle Manipulations via LLM-Driven Knowledge Mining and Prompt Generation

Bo Gao, Yuan Wang, Qingsong Wei, Yong Liu · 6 authors

Decentralized finance (DeFi) applications depend on accurate price oracles to ensure secure and fair transactions. However, poorly integrated oracles remain susceptible to manipulation, enabling attackers to exploit smart contract logic for unfair asset valuation and financial gain. While many such vulnerabilities are only detected after deployment, smart contracts are typically immutable once deployed, making post-hoc fixes costly or infeasible. This highlights the critical need for detecting oracle manipulation risks before deployment. In this paper, we propose$AiRacleX$, a novel LLM-driven framework that enables pre-deployment detection of price oracle manipulation vulnerabilities by leveraging the complementary strengths of multiple large language models (LLMs). Our approach begins with domain-specific knowledge extraction, where an LLM model synthesizes precise insights about price oracle vulnerabilities, eliminating the need for profound expertise from developers or auditors. This knowledge forms the foundation for a second LLM model to generate structured, context-aware Chain-of-Thought prompts, which guide a third LLM model in accurately identifying manipulation patterns in smart contracts. We evaluate$AiRacleX$on 60 known vulnerabilities from 44 real-world DeFi exploits and Code4rena projects spanning 2021-2023. The results show that$AiRacleX$achieves a 2.58 times improvement in recall over the state-of-the-art GPTScan, with comparable precision. Our framework also demonstrates strong extensibility and efficiency, and supports deployment with open-source LLMs to enhance security and reduce operational cost.

Open access
3 source records
cs.CR
cs.AI
Blockchain Technology Applications and Security
Original source