Trust in democratic institutions has waned in recent years, stemming from insufficient transparency and representation in public decision-making processes, expanding social and wealth disparities, and growing apprehensions surrounding mis/disinformation fueled by the emergence of highly persuasive AI-generated content such as ChatGPT. Decentralized Web3 technologies such as blockchain emerged as instruments for creating an alternative âtrustlessâ system that uses cryptography and decentralized consensus mechanisms to obviate the need for third party human intermediaries, but suffered significant setbacks due to massive frauds and speculations throughout the past decade of their evolution. Although it might appear counterintuitive to advocate for the potential benefits of these technologies in light of their evident failures, we assert that, before dismissing them, it is essential to differentiate the technological layer from the social layer in these instances and examine them with greater care and criticality. We argue that the recurrent failures of blockchain-based projects, as reported in the media and denounced by critics, are less indicative of the technologyâs inherent weakness, and more a consequence of malicious actors exploiting the social layer within the system. What is thus heavily lacking in the current Web3 landscape is the collaborative development and innovation in the social and institutional layer to build systems that genuinely enhance democracy and address the trust crisis society faces as a whole in a more sustainable way through leveraging the capabilities offered by decentralized technologies. As such, rather than perceiving these technologies as decentralized trust-replacing technologies, we consider them as âDecentralized Trust-Building Technologiesâ (DTTs). DTTs do not seek to replace trust, but instead serve to fortify trust through transparent and secure mechanisms combined with robust institutional designs. In this report, we investigate a variety of case studies that showcase emerging efforts to employ DTTs in the physical realities and the built environment of our social institutions. These empirical examples offer valuable insights â both inspirational and cautionary lessons â into the practical applications of DTTs in transforming our society and lived environments. From this empirical analysis, our goal is to establish a set of guidelines and best practices for current and future endeavors in fostering innovation within this space, ultimately paving ways for more resilient and sustainable lived ecosystems that harness the power of DTTs.
Saad Mutlaq Alluhaydan, Mohammed Obaid Alshammari, Yousef Jazaa Obaid Alshmilan, Ahmed Hamoud Alshammari · 12 authors
Background: The rise of AI health assistants and digital tools raises concerns about data security and consent management. Traditional systems are prone to failures and provide limited transparency in data sharing. Blockchain technology offers a decentralized, immutable, and secure solution to these issues. Aim: This narrative review critically examines the real-world implementations and security trade-offs of blockchain technology when applied specifically to health assistant audit trails and consent management, moving beyond theoretical propositions. Methods: A systematic search of peer-reviewed literature (2010-2024) was conducted across Scopus, IEEE Xplore, PubMed, and ACM Digital Library. Implementation case studies, prototypes, and theoretical frameworks were analyzed to assess technical architectures, performance metrics, and security evaluations. Results: Findings indicate an emerging landscape where blockchain proves useful for creating secure audit logs in AI decision-making and dynamic consent models using smart contracts. However, challenges persist, including performance and scalability issues, key management complexities, data linkage risks, and conflicts between immutability and regulatory requirements such as the GDPR's "right to be forgotten." Conclusion: Blockchain serves as a foundational layer to improve security and transparency in health assistant ecosystems. Its future potential relies on hybrid architectures, advanced cryptographic methods such as zero-knowledge proofs, and an awareness of the new security and operational challenges that arise. It is not merely a database but a comprehensive solution for integrity and control.
Identification, authentication, and authorization processes can be conducted in various ways. Particular attention is given to the processes implemented within the self-sovereign identity paradigm. This paper analyses the processes from a data leak perspective. A comparison is made between self-sovereign identity and a centralized identity provider scheme. An overview of the relevant implementations for these processes is provided: in both the self-sovereign and non-sovereign paradigms. It has been found that, from the data leaks perspective, the self-sovereign identity scheme could only provide superior security if zero-knowledge proof technology is applied.
Yalan Wang, Liqun Chen, Long Meng, Christopher J. P. Newton
Concerns about how third parties manage personal information have led to the development of decentralized identities (DIDs) and verifiable credentials (VCs). The World Wide Web Consortium (W3C) working group has been developing standards for DIDs and VCs. In the W3C standards, a DID identifies an entity (a DID holder) and a VC confirms that this DID holder has some associated attributes. A DID holder can obtain many VCs and confirm any number of these VCs to others (verifiers) in verifiable presentations (VPs). In order to keep a holderâs identity and attributes private, it is necessary to achieve anonymous VPs that allows this information to be kept confidential. The W3C working group recommends using randomizable signatures to create VCs with zero-knowledge proofs for this purpose. However, the anonymous VPs provided by the this method are limited that in the real world, credentials in cross domains cannot be universally verified. To overcome this limitation, in this paper, we propose a new scheme, called Verifiable Credentials with anonymous DIDs (VCaDID), which aims to achieve anonymous VPs in cross-domain settings. The main technique in our VCaDID scheme is a ring signature with multiple attributes by hiding a holderâs public key among a ring of holders. In our scheme, we set private keys associated with the holderâs DID and attributes, which allow the holder to anonymously present these credentials in a verifiable way. We also prove that the proposed VCaDID scheme satisfies correctness, anonymity and unforgeability under security assumptions of discrete log and random oracle model. Finally, we implement our scheme to demonstrate its feasibility.
StanisĆaw BaraĆski, Ben Biedermann, Joshua Ellul
Voting is a cornerstone of collective participatory decision-making in contexts ranging from political elections to decentralized autonomous organizations (DAOs). Despite the proliferation of internet voting protocols promising enhanced accessibility and efficiency, their evaluation and comparison are complicated by a lack of standardized criteria and unified definitions of security and maturity. Furthermore, socio-technical requirements by decision makers are not structurally taken into consideration when comparing internet voting systems. This paper addresses this gap by introducing a trust-centric maturity scoring framework to quantify the security and maturity of seventeen internet voting systems. A comprehensive trust model analysis is conducted for selected internet voting protocols, examining their security properties, trust assumptions, technical complexity, and practical usability. In this paper we propose the Internet Voting Maturity Framework (IVMF) which supports nuanced assessment that reflects real-world deployment concerns and aids decision-makers in selecting appropriate systems tailored to their specific use-case requirements. The framework is general enough to be applied to other systems, where the aspects of decentralization, trust, and security are crucial, such as digital identity, Ethereum layer-two scaling solutions, and federated data infrastructures. Its objective is to provide an extendable toolkit for policy makers and technology experts alike that normalizes technical and non-technical requirements on a univariate scale.
Saravanan Muthaiyah, Lan Thi Phuong Nguyen, Yap Voon Choong, Thein Oak Kyaw Zaw
This study addresses the inherent risk management challenges in decentralized finance, particularly for peer-to-peer (P2P) lending platforms. We propose a novel framework that leverages a Multi-Agent System (MAS) to establish a collaborative network encompassing loan originators, investors, regulators, and service providers. This distributed approach facilitates federated risk management, where risk assessment and mitigation responsibilities are shared across these entities. The MAS employs a comprehensive nine-factor assessment (detailed in Table 5) to evaluate industry risk profiles, considering industry environment, competition, and internal capabilities. This data is further visualized using a color matrix (Tables 5 & 6) and utilized alongside state diagrams (Figure 2) to depict the workflow and manage tasks within the P2P lending process. Additionally, the MAS informs a novel Federated Risk-Based Access Control (FRkBAC) system that tailors access permissions (lending origination, disbursement, etc.) based on dynamic risk assessments of industry trends and individual borrower profiles. This data-driven approach fosters trust within the P2P ecosystem and represents a significant advancement in decentralized finance risk management compared to traditional methods. Doi: 10.28991/ESJ-2024-08-06-05 Full Text: PDF
The process of rendering authenticity to the Degree Certificate (DC) is known as Degree Attestation (DA). None of the prevailing works have focused on zero trust-based DA, verification, and traceability for secured DA. So, zero trust-based secured DA, verification, and traceability of degree credentials are presented in the paper. Primarily, to upload the DC of the student, the university registers and logs in to the Blockchain (BC). Subsequently, by utilizing radioactive decay-based elliptic curve cryptography (RD-ECC), the DC is secured. Next, by utilizing Glorot initialization-based Proof-of-Stake (GPoS), the data is stored in the BC. Further, to verify the traceability of the data, a Smart Contract (SC) is created. In the meantime, the student registers and logs in to the BC and gives attestation requests to the university. By utilizing rail fence cipher (RFC) RD-ECC hash-based message authentication code (RFCR-HMAC), the university authenticates the request. By utilizing a quadratic probing-based digital signature algorithm (QP-DSA), the university attests the DC after authentication. Lastly, by utilizing RD-ECC, the attested certificate is encrypted and sent to the student. Hence, the certificate is secured with an encryption time (ET) of 5971ms and DA is performed with a Signature Generation Time (SGT) of 6637ms.
In complex network systems, multiple Software Defined Networking (SDN) controllers are often deployed across different domains to manage diverse underlay technologies. This multi-controller environment introduces significant challenges in ensuring security and trust, as traditional secure methods such as Public Key Infrastructures (PKI), which rely on Certificate Authorities (CAs), often struggle to provide the necessary flexibility, transparency, and protection against tampering. Distributed Ledger Technologies (DLT) present a compelling solution by enabling decentralized management and the immutable recording of network configurations. This paper proposes an approach where SDN controllers from various domains act as valida-tor nodes within a DLT framework, utilizing Byzantine Fault Tolerance (BFT) as the consensus mechanism. This creates a distributed trust model that enhances collaborative network management by balancing trust among network controllers. By implementing a private, permissioned ledger, data integrity is enforced, and access is restricted to authorized stakeholders, thus maintaining consistency and trust among network configurations through a verifiable record of all transactions. The performance and operational efficiency of this DLT-based approach in multi-SDN controller environments are further evaluated. Experimental results demonstrate the practical benefits and viability of integrating DLT with SDN environments for collaborative network management.
BACKGROUND: As digital healthcare services handle increasingly more sensitive health data, robust access control methods are required. Especially in emergency conditions, where the patient's health situation is in peril, different healthcare providers associated with critical cases may need to be granted permission to acquire access to Electronic Health Records (EHRs) of patients. The research objective of this work is to develop a proactive access control method that can grant emergency clinicians access to sensitive health data, guaranteeing the integrity and security of the data, and generating trust without the need for a trusted third party. METHODS: A contextual and blockchain-based mechanism is proposed that allows access to sensitive EHRs by applying prognostic procedures where information based on context, is utilized to identify critical situations and grant access to medical data. Specifically, to enable proactivity, Long Short Term Memory (LSTM) Neural Networks (NNs) are applied that utilize patient's recent health history to prognose the next two-hour health metrics values. Fuzzy logic is used to evaluate the severity of the patient's health state. These techniques are incorporated in a private and permissioned Hyperledger-Fabric blockchain network, capable of securing patient's sensitive information in the blockchain network. RESULTS: The developed access control method provides secure access for emergency clinicians to sensitive information and simultaneously safeguards the patient's well-being. Integrating this predictive mechanism within the blockchain network proved to be a robust tool to enhance the performance of the access control mechanism. Furthermore, the blockchain network of this work can record the history of who and when had access to a specific patient's sensitive EHRs, guaranteeing the integrity and security of the data, as well as recording the latency of this mechanism, where three different access control cases are evaluated. This access control mechanism is to be enforced in a real-life scenario in hospitals. CONCLUSIONS: The proposed mechanism informs proactively the emergency team of professional clinicians about patients' critical situations by combining fuzzy and predictive machine learning techniques incorporated in the private and permissioned blockchain network, and it exploits the distributed data of the blockchain architecture, guaranteeing the integrity and security of the data, and thus, enhancing the users' trust to the access control mechanism.
One of the main security challenges when federating separate Internet of Things (IoT) administrative domains is effective Identity and Access Management, which is required to establish trust and secure communication between federated IoT devices. The primary goal of the work is to develop a âlightweightâ protocol to enable authentication and authorization of IoT devices in federated environments and ensure the secure communication of IoT devices. We propose a novel Lightweight Authentication and Authorization Framework for Federated IoT (LAAFFI) which takes advantage of the unique fingerprint of IoT devices based on their configuration and additional hardware modules, such as Physical Unclonable Function, to provide flexible authentication and authorization based on Distributed Ledger technology. Moreover, LAAFFI supports IoT devices with limited computing resources and devices not equipped with secure storage space. We implemented a prototype of LAAFFI and evaluated its performance in the Hyperledger Fabric-based IoT framework. Three main metrics were evaluated: latency, throughput (number of operations or transactions per second), and network resource utilization rate (transmission overhead introduced by the LAAFFI protocol). The performance tests conducted confirmed the high efficiency and suitability of the protocol for federated IoT environments. Also, all LAAFFI components are scalable as confirmed by tests. We formally evaluated LAAFFI security using Verifpal as a formal verification tool. Based on the models developed for Verifpal, we validated their security properties, such as message secrecy, authenticity, and freshness. Our results show that the proposed solution can improve the security of federated IoT environments while providing zero-day interoperability and high scalability. Compared to existing solutions, LAAFFI is more efficient due to the use of symmetric cryptography and algorithms adapted for operations involving IoT devices. LAAFFI supports multiple authorization mechanisms, and since it also offers authentication and accountability, it meets the requirements of Authentication, Authorization and Accounting (AAA). It uses Distributed Ledger (DL) and smart contracts to ensure that the request complies with the policies agreed between the organizations. LAAFFI offers authentication of devices belonging to a single organization and different organizations, with the assurance that the encryption key will be shared with another device only if the appropriate security policy is met. The proposed protocol is particularly useful for ensuring the security of federated IoT environments created ad hoc for special missions, e.g., operations conducted by NATO countries and disaster relief operations Humanitarian Assistance and Disaster Relief (HADR) involving military forces and civilian services, where immediate interoperability is required.
The increasingly interconnected nature of modern network architectures demands advanced security and trust mechanisms, particularly in environments spanning multiple technology and stakeholder domains. Traditional approaches to network management systems, while effective in static settings, often lack the flexibility, security, and transparency required for dynamic and decentralized operations typical of multi-domain configurations. Distributed Ledger Technologies (DLT) offer a robust alternative by enabling decentralized management and immutable recording of network configurations, inherently increasing security against tampering and unauthorized changes. This paper introduces a DLT approach utilizing a private, permissioned ledger where topology changes are recorded as transactions. The setup enforces data integrity and restricts access to network topology information, ensuring only authorized stakeholders can make changes. Consequently, it enhances security, maintains data consistency, and builds trust among network components by keeping a verifiable record of all changes. Additionally, the paper examines the performance and operational efficiency of integrating DLT within network systems, using the ADRENALINE testbedâan advanced infrastructure for Beyond 5G and future 6G servicesâas the platform for analysis. Experimental results reveal the systemâs performance metrics, illustrating the practical viability of implementing DLT in network operations management.
Attribute Based Access Control (ABAC) is one the most efficient, scalable, and well used access control. Itâs based on attributes not on users, but even when the users want to get access to some resource, they must submit their attributes for the verification process which may reveal the privacy of the users. Many research papers suggest blockchain-based ABAC which provides an immutable and transparent access control system. However, the privacy of the system may be compromised depending on the nature of the attributes. A Zero-Knowledge Proof, Ethereum-Based Access Control (ZKâABAC) is proposed in this paper to simplify the management of access to the devices/objects and provide an efficient and immutable platform that keeps track of all actions and access management and preserve the privacy of the attributes. Our ZK-ABAC model utilizes smart contracts to facilitate access control management, Zero-Knowledge Succinct NonInteractive Argument of Knowledge (ZK-SNARK) protocol to add privacy to attributes, InterPlanetary File System (IPFS) network to provide distributed storage system, and Chainlink to manage communications and data between on/ off-chain systems. Comprehensive experiments and tests were conducted to evaluate the performance of our model, including the implementation of ZK-SNARK on the Ethereum blockchain. The results demonstrated the scalability challenges in the setup and proving phases, as well as the efficiency gains in the verification phase, particularly when scaled to higher numbers of users. These findings underscore the practical viability of our ZK-ABAC model for secure and privacy-preserving access control in decentralized environments.
The advent of Web3 technologies promises a paradigm shift toward decentralized and autonomous economic interactions enabled by blockchain and smart contracts. However, the lack of robust trust and reputation mechanisms hinders its evolution into a fully functional economic system. This paper introduces the Dmany Nexus Protocol, a decentralized reputation system that quantifies user trustworthiness through verified on-chain and off-chain actions. By integrating principles from information economics, game theory, and mechanism design, the protocol addresses issues of information asymmetry, moral hazard, and adverse selection inherent in decentralized networks. Leveraging the Dmany Quest Engine for decentralized task management and employing zero-knowledge proofs for privacy preservation, Dmany Nexus establishes a foundation for trust and cooperation in the Web3 ecosystem. The protocol enhances economic efficiency, mitigates security risks like Sybil attacks, and fosters mass adoption by enabling secure, privacy-preserving interactions among pseudonymous actors.
As digital interactions continue to shift toward decentralized platforms, the limitations of centralized identity systems such as data silos, lack of user control, and reliance on intermediaries have become increasingly apparent. This research introduces a structured, multi-layered framework to support the design and implementation of trustless digital identity systems aligned with the principles of Web3. The proposed model integrates five core components: standardized identity protocols, regulatory alignment, user-centric design, trusted institutional participation, and enterprise integration through middleware. Each layer addresses critical challenges such as legal recognition, interoperability, usability, and system scalability. By combining decentralized technologies with practical governance and user experience strategies, the framework aims to enable secure, verifiable, and portable identities that function across jurisdictions and platforms. This paper offers a foundational approach to advancing digital identity infrastructure in a way that is technically robust and socially inclusive
Data aggregation management is paramount in data-driven distributed systems. Conventional solutions premised on centralized networks grapple with security challenges concerning authenticity, confidentiality, integrity, and privacy. Recently, distributed ledger technology has gained popularity for its decentralized nature to facilitate overcoming these challenges. Nevertheless, insufficient identity management introduces risks like impersonation and unauthorized access. In this paper, we propose Degator, a data aggregation management framework that leverages self-sovereign identity and functions in decentralized networks to address security concerns and mitigate identity-related risks. We formulate fully decentralized aggregation protocols for data persistence and acquisition in Degator. Degator is compatible with existing data persistence methods, and supports cost-effective data acquisition minimizing dependency on distributed ledgers. We also conduct a formal analysis to elucidate the mechanism of Degator to tackle current security challenges in conventional data aggregation management. Furthermore, we showcase the applicability of Degator through its application in the management of decentralized neuroscience data aggregation and demonstrate its scalability via performance evaluation.
A. S. Santhosh Kumar, S. (Sarah) Thompson, N. (Noor) Al-Zubaidi
The rapid adoption of multi-cloud architectures enables organizations to balance cost, performance, and resilience by distributing workloads across different providers. However, this distributed environment introduces significant security and access control challenges, including inconsistent policies, fragmented identity management, and heightened risks of insider threats and data breaches. Traditional access control modelsâsuch as Role-Based Access Control (RBAC) and Attribute-Based Access Control (ABAC)âstruggle to provide unified enforcement across heterogeneous cloud platforms while ensuring transparency, auditability, and trust. This paper explores the potential of blockchain-based access control models to secure multi-cloud software systems by leveraging the immutability, decentralization, and consensus mechanisms of distributed ledger technology. Blockchain smart contracts can automate access control enforcement, eliminate reliance on centralized identity providers, and ensure tamper-proof audit trails of access decisions. Recent studies highlight that 80% of enterprises already operate in hybrid or multi-cloud environments (Flexera 2023), while 45% of cloud security incidents are linked to misconfigured or inconsistent access policies (IBM Cloud Security Report 2022)âunderscoring the urgency for innovative solutions. We analyze blockchain-enhanced RBAC and ABAC frameworks, discuss hybrid on-chain/off-chain policy enforcement, and evaluate the trade-offs of performance, scalability, and compliance. Case studies from healthcare and financial systems illustrate how blockchain access models improve accountability and regulatory alignment (e.g., HIPAA, GDPR, PCI DSS) in mission-critical workloads. Furthermore, we address key challenges such as transaction latency, interoperability across cloud providers, and privacy-preserving access control. The paper concludes that blockchain-based access control provides a paradigm shift in securing multi-cloud environments, offering organizations a path toward transparent, verifiable, and adaptive identity and access management. By integrating blockchain with AI-driven monitoring and zero trust architectures, the future of multi-cloud security will move toward autonomous, trustless, and regulation-compliant ecosystems capable of sustaining the demands of next-generation digital services.
This article addresses critical health data integrity by proposing an HF (Hyperledger Fabric)-based architecture with integration into the global health data architecture based on distributed content-addressable storage networks.
With the rapid spread of the use of Internet of Things devices, it has become an important situation for these devices to be provided with critical infrastructure, integrated into daily life and the creation of robust security mechanisms. The attribute-based access control (ABAC) method has emerged as a promising approach to manage access of IoT resources based on users' attributes. However, current ABAC models lack adequate privacy protections and do not address specific vulnerabilities, especially in scenarios where sensitive data is involved. The research includes a comprehensive review of the ABAC models that stand out in the context of IoT security, including the limitations and vulnerabilities that they carry. In this work, a new framework has been proposed that integrates zero-knowledge proofs (ZKP) with homomorphic encryption into the ABAC model, providing stronger security guarantees and privacy protection. While ZKPs allow users to prove that they have certain attributes or access rights without disclosing sensitive information, homomorphic encryption allows calculations to be performed on encrypted data without decryption. The proposed framework has been evaluated by theoretical analysis and simulation studies. The findings of this research are expected to contribute significantly to the field of IoT security by providing a more robust and privacy-protecting access control mechanism for IoT environments. The proposed framework has the potential to mitigate various security threats, including unauthorized access, data and privacy violations
Secure data exchange has become a critical requirement for modern intelligent systems that operate across distributed and heterogeneous environments. As artificial intelligence applications increasingly rely on collaborative data sharing among organizations, devices, and platforms, ensuring trust, integrity, and privacy in the exchanged information becomes a fundamental challenge. Traditional centralized security mechanisms often fail to provide sufficient transparency and tamper resistance, especially when multiple stakeholders with varying trust levels are involved. Blockchain technology, with its decentralized ledger architecture and cryptographic validation mechanisms, offers a promising solution to address these issues. This research proposes a trust-aware intelligent systems framework that leverages blockchain technology to facilitate secure and reliable data exchange across distributed intelligent environments. The framework integrates trust evaluation models with blockchain-based distributed ledgers to ensure that data transactions are verified, immutable, and traceable.
The rapid adoption of intelligent systems across domains such as finance, healthcare, transportation, and smart infrastructure has created new opportunities for automation, efficiency, and data-driven decision making. However, these systems often operate in complex digital ecosystems where transparency, trust, and data integrity remain significant concerns. Traditional centralized governance frameworks struggle to provide verifiable accountability and secure collaboration among multiple stakeholders. Blockchain technology, with its decentralized ledger structure and cryptographic validation mechanisms, offers a promising solution to these challenges by enabling transparent and tamper-resistant governance models for intelligent systems. This study proposes a blockchain-based governance architecture designed to enhance the transparency, reliability, and security of intelligent systems operating in distributed environments. The framework integrates decentralized consensus mechanisms, smart contract-based policy enforcement, and secure data sharing protocols to establish trustworthy governance across autonomous agents and data providers.
The adoption of the Computing Continuum is characterised by the seamless integration of diverse computing environments and devices. In this dynamic landscape, sharing resources across the continuum is becoming a reality and security must move an step forward, specially in terms of authentication and authorisation for such a distributed and heterogeneous environments. The need for robust identity management is paramount and, in this regard, Decentralised Identity Management (DIM) emerges as a promising solution. It leverages decentralised technologies to secure and facilitate identity interactions across the Computing Continuum. Particularly, to enhance security and privacy, it would be desirable to apply the principles of Self-Sovereign Identity (SSI). In this paradigm, users have full ownership and control of their digital identities that empowers individuals to manage and share their identity data on a need-to-know basis. These mechanisms could contribute to improve security properties during continuum resource management operations. In this context, this paper presents the design, workflows and implementation of a solution that provides authentication/authorisation features to distributed zero-trust based infrastructures across the continuum, enhancing security in resource sharing and resource acquisition stages. To this aim, the solution relies on key aspects like decentralisation, interoperability, trust management and privacy-enhancing capabilities. The decentralisation leverages distributed ledger technologies, such as blockchain, to establish a decentralised identity ecosystem. The solution prioritises interoperability, enabling nodes to seamlessly access and share their identities across different domains and environments. Trustworthiness is at the core of DIM, and privacy is also considered, incorporating privacy-preserving techniques that individuals to selectively disclose identity attributes while safeguarding sensitive information. The implementation includes different operations for allowing continuum frameworks to be enhanced with decentralised authentication and authorisation features. The performance has been evaluated measuring the impact for the adoption of the solution. The most expensive task, the self-identity generation, takes only a few seconds (in our deployment) and it is only executed once. Authorisation tasks operate in the millisecond range, which is a totally invaluable time if incorporated into resource acquisition processes in frameworks such as Liqo, used in the scope of FLUIDOS project.
Mohammed Alghazwi, Tariq Bontekoe, Leon Visscher, Fatih TĂŒrkmen
Abstract Non-interactive zero-knowledge (NIZK) proofs of knowledge have proven to be highly relevant for securely realizing a wide array of applications that rely on both privacy and correctness . They enable a prover to convince any party of the correctness of a public statement for a secret witness . However, most NIZKs do not natively support proving knowledge of a secret witness that is distributed over multiple provers. Previously, collaborative proofs [54] have been proposed to overcome this limitation. We investigate the notion of composability in this setting, following the Commit-and-Prove design of LegoSNARK [19]. Composability allows users to combine different, specialized NIZKs (e.g., one for arithmetic circuits, one for boolean circuits, and one for range proofs) with the aim of reducing the proof generation time. Moreover, it opens the door to efficient realizations of many applications in the collaborative setting such as mutually exclusive prover groups, combining collaborative and single-party proofs and efficiently implementing publicly auditable secure multiparty computing (PA-MPC). We present the first, general definition for collaborative commitand- prove NIZK (CP-NIZK) proofs of knowledge and construct MPC protocols to enable their realization. We implement our protocols for two commonly used NIZKs, Groth16 and Bulletproofs, and evaluate their practicality in a variety of computational settings. Our findings indicate that composability adds only minor overhead, especially for large circuits. We also evaluated our construction in two application settings, one of which shows 18â $$55\times $$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mrow> <mml:mn>55</mml:mn> <mml:mo>Ă</mml:mo> </mml:mrow> </mml:math> runtime reduction when compared to prior works while requiring only a fraction ( $$0.2\%$$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mrow> <mml:mn>0.2</mml:mn> <mml:mo>%</mml:mo> </mml:mrow> </mml:math> ) of the communication.
Caleb Geren, Amanda Board, Gaby G. Dagher, Tim Andersen · 5 authors
With the growing development and deployment of large language models (LLMs) in both industrial and academic fields, their security and safety concerns have become increasingly critical. However, recent studies indicate that LLMs face numerous vulnerabilities, including data poisoning, prompt injections, and unauthorized data exposure, which conventional methods have struggled to address fully. In parallel, blockchain technology, known for its data immutability and decentralized structure, offers a promising foundation for safeguarding LLMs. In this survey, we aim to comprehensively assess how to leverage blockchain technology to enhance LLMs' security and safety. Besides, we propose a new taxonomy of blockchain for large language models (BC4LLMs) to systematically categorize related works in this emerging field. Our analysis includes novel frameworks and definitions to delineate security and safety in the context of BC4LLMs, highlighting potential research directions and challenges at this intersection. Through this study, we aim to stimulate targeted advancements in blockchain-integrated LLM security.