Rojalina Priyadarshini, Rhishav Pandey, K C Ankit, Deepesh Bhandari · 7 authors
Verifying the legitimacy of original documents such as educational degree certificates is crucial. If these are found to be fraudulent, it can cause significant disruptions in the hiring process, resulting in substantial productivity losses. The researchers suggested several proposals to preserve these certificates. However, the challenge is still to have an integrated, tamper-proof and low-cost solution where the certificate issuer and the certificate itself are validated in a single platform. This paper proposes an integrated solution that uses a decentralized blockchain-based certificate verification and issuer validation system. In addition to this, it will protect the certificates from being tampered with. To search faster, hash function mapping has been employed. The proposed solution is experimentally validated by creating a blockchain network using Ethereum where each peer node represents an entity of a certificate verification system such as a validator, certificate issuer, certificate holder and the end-user of the client. The performance of the designed solution is measured by the execution and transaction cost in terms of gas consumption. A comparative analysis has been performed on similar types of tasks reported in the existing work performed on the same platform. It has been observed that the cost incurred for adding a certificate is minimal for the proposed approach. Furthermore, the searching time for the certificates is minimized by using a hash-based searching methodology. The results show that the search time has drastically gone down when certificates are not available.
Istiaque Ahmed, Kentaroh Toyoda, Tadashi Nakano, Thi Hong Tran
Traditional digital identity systems struggle with centralization, vulnerability to manipulation, and a lack of transparency. In distributed identity, different cryptographic methods are used for issuing credentials, that create challenges during presentation. It suffer from a fundamental interoperability barrier with heterogeneous digital-signature schemes, forcing each verifier either to implement every scheme or to trust a central translation gateway. We propose a signature-agnostic verification framework that eliminates this barrier. The core idea is to commit a salted root hash of credential claims to a distributed ledger and ensure the authenticity using a smart contract. A zero-knowledge proof (zk-SNARK) is used to prove a selected claim set without revealing actual information. The verification reduces to a single hash-consistency check, and the verifier never touches issuer-specific signatures. A pleasant side effect is that the same verifiable presentation (VP) can be reused across verifiers and sessions, since trust derives from the on-chain anchor rather than transient signatures. This research will advance the identification ecosystem, enabling applications such as eKYC across finance, healthcare, and other sectors. We implement our method on Ethereum Virtual Machine (EVM) using Groth16, benchmark gas cost, proof size, and latency, and show its feasibility and computational efficiency. The privacy and security analysis confirms that the proposed solution is resistant to various attacks.
Natalia Borgoñós García, María Hernández Padilla, Antonio Fernando Skarmeta Gómez
Abstract Data Spaces are ecosystems designed to allow multiple organizations or companies to share data in a secure manner. Despite the potential of these technologies, they encounter a number of challenges and privacy issues that limit their use. Privacy Preserving Enablers are mechanisms developed to tackle these difficulties, ensuring data integrity and access control. This paper aims to analyze the role of some Privacy Preserving Enablers and its integration with Connectors in the context of Data Spaces. The research will focus on key enablers, including a Self-Sovereign Identity with Zero-Knowledge Proof, which is a privacy preserving approach that allows users to verify their identity and attributes without the need to disclose underlying data, ensuring their privacy. Additionally, the usage of Sticky Policies instantiated through Attribute-Based Encryption attaches control policies into the encrypted data in order to have an attribute-based access control, enhancing its security. The application of Policies Enforcement assure the consistent application of policies and the maintenance of the security within the Data Space.
Secure personal data sharing remains a critical challenge in decentralized systems due to concerns over privacy, compliance, and trust. This paper presents the formal verification of a Blockchain-Based Security Model (BSM) designed to address these challenges through a multi-layered architecture. The proposed model integrates Chaincode-as-a-Service (CCaaS) on Hyperledger Fabric to ensure modular, maintainable, and scalable execution of smart contracts. A Flask-based API serves as the secure gateway for data operations and identity management. Sensitive data is stored off-chain using InterPlanetary File System (IPFS), preserving decentralization while minimizing on-chain bloat. Access control is enforced using efficient cryptographic techniques, while Intel SGX (or simulated enclaves) safeguards secure data processing and decryption within trusted execution environments. To further enhance privacy guarantees, Zero-Knowledge Proofs (ZKPs) are optionally integrated to enable verifiable claims without disclosing raw data. For assurance of correctness and security, the BSM is formally modeled using the Dolev-Yao attacker model and verified through ProVerif, focusing on key security properties such as confidentiality, integrity, authentication, and accountability. The findings confirm that the proposed model satisfies stringent security goals and is robust against symbolic adversaries. This work contributes a verifiable and extensible framework for privacy-preserving data sharing in sectors such as healthcare, finance, and government. To the best of our knowledge, this is among the first works to formally verify a blockchain-based security model that simultaneously integrates modular chaincode execution (CCaaS), trusted hardware enclaves (Intel SGX), decentralized off-chain storage (IPFS), and optional Zero-Knowledge Proofs (ZKPs) with a unified framework for personal data sharing.
Luigi Pavarini de Lima, Liliam Sayuri Sakamoto, Jair Minoro Abe, Jonatas Santos De Souza · 8 authors
The objective of this article is to propose a research structure to optimize this security of assets with NFT - Non- fungible Token with the use of DLP - Data Loss Prevention and Paraconsistent Logic for the identification not only preventively, but actively of the loss, theft, misuse and leakage of this type of assets during their use in the Metaverse. A bibliographic review was carried out on Metaverse, DLP, Paraconsistent Logic, Artificial Intelligence techniques [10][27][28], NFT [49][50], and Data Protection [4] with a focus on the LGPD (Brazilian Data Protection Law) [2][23], in conjunction with exploratory research. With a DLP and a database provided by the transport company with 200 articles analyzed. It was verified that a significant amount of data would be discarded in the first stage of the process (37%) since they do not present an active definition on the status of these assets. Considering the growing technological innovation with the use of the Metaverse, as an environment for educational, business and governmental interaction against the risk of cyber-attacks, there is an urgent need to strengthen its security, even more so when in this environment, where there is the possibility of moving assets with NFTs that are objects of great value acquired and traded in this medium. With the use of the Python program in the DLP, it was observed that it presented a 37% data loss in its analysis with this Artificial Intelligence [11] process only with the performance of the DLP, compared to the optimization of this analysis with the use of Paraconsistent Logic at 23%, that is, a use of more than 15% of the data.
Laura García, Carlos Cancimance, Rafael Asorey-Cacheda, Claudia Liliana Zúñiga Cañón · 6 authors
Data integrity and traceability are important challenges to provide security in the Internet of Things (IoT) networks, which are often vulnerable to data manipulation attacks due to their use of low-resource devices and wireless communication technologies. In this regard, blockchain is a promising solution to enhance IoT security, but the implementation of a conventional blockchain requires high computational and network connectivity resources that are not compatible with IoT networks. In this paper, we propose a lightweight blockchain for data integrity and traceability in IoT networks that adapts the Distributed Ledger Technology (DLT) feature of blockchain to the LoRaWAN wireless communication protocol. Our proposal offers data integrity without the need for complex consensus algorithms or cryptographic operations.We also have designed and implemented a logical LoRaWAN P2P topology that enables communication between the IoT nodes which comprise LoRaWAN’s characteristic star topology. Finally, we evaluate our proposal and demonstrate its feasibility and performance in terms of data traceability, and network overhead.
ABSTRACT An increasing number of knowledge resources are stored and disseminated in digital form, resulting in new challenges for Intellectual Property Rights (IPR) protection, including difficulty in establishing rights, difficulty in defending rights, and difficulty in incurring high costs. The proposed system in this paper aims to use Internet of Things (IoT) devices to collect knowledge resource data, store it in the Interplanetary File System (IPFS) network, and mint non‐fungible tokens (NFTs) in the blockchain, simplifying the process of IPR confirmation and protection while reducing costs. Additionally, blockchain transactions are delivered to the blockchain service network (BSN) to enhance network credibility. Experimental results show an average file storage time of 0.05 s, a 13% reduction in the average time for property rights registration, and a reduction in maintenance costs.
Mazharul Hasan, Mohammad Jabed Morshed Chowdhury, Kamanashis Biswas, Mahmudul Hasan · 5 authors
Non-Fungible Tokens (NFTs) have revolutionized the blockchain ecosystem by enabling the decentralized representation and ownership of unique digital assets. However, the NFT landscape is increasingly susceptible to security vulnerabilities and attack vectors, necessitating robust protection mechanisms. This research presents a comprehensive analysis and a structured framework to enhance the security of NFT transactions. The relevant studies were identified using a snowballing method as the paper searching approach, ensuring systematic and comprehensive coverage of the existing literature. Specifically, it examines critical security risks, including ownership duplication, duplicate token generation, unauthorized asset withdrawal, asset replication, and metadata manipulation. A key contribution of this study is the development of a detailed taxonomy of NFT-related threats and attacks, providing researchers and practitioners with a consolidated perspective on the evolving security landscape. Furthermore, we introduce and analyze attack vectors, demonstrating its implications and proposing an effective mitigation strategy.
Open access
Blockchain Technology Applications and Security
Cloud Data Security Solutions
Physical Unclonable Functions (PUFs) and Hardware Security
Alejandro Hernán Son Romero, Nicolás Xavier Herrera Medina, Pablo Alberto Rojas Jaén
This article introduces a hybrid blockchain architecture to enhance Electronic Medical Record (EMR) management and interoperability. It integrates a permissioned public blockchain on Polkadot—managing roles and permissions—with a private blockchain on Hyperledger Fabric responsible for EMR storage. Text data are stored in CouchDB and medical images in IPFS as Non-Fungible Tokens (NFTs), following a patient-centric model. Stress tests yielded average latencies of 2050 ms for EMR creation and 2000 ms for sharing, with 65 % CPU and 170 MB memory usage, indicating system stability and efficiency. The proposed architecture provides a scalable, secure, and interoperable solution suitable for healthcare environments that demand data confidentiality and controlled access.
The rise of blockchain and Digital Ledger Technology (DLT) has gained wide traction. Instead of relying on a traditional centralized data authority, a blockchain system consists of digitally entangled block data shared across a distributed network. The specially designed chain data structure and its consensus mechanism protect blockchain data from being tampered by unauthorized adversaries. However, implementing a full-fledged blockchain system to protect a database can be technically cumbersome. In this work, we introduce an in-database design, named chain table, to protect data integrity without the need for a blockchain system. It features a succinct design without significant technology barriers or storage overhead. To realize rigorous data security, we also propose a set of data writing principles for the chain table. We prove that the chain table, together with the data writing principles, will guarantee flexible data integrity, named table-level data integrity (TDI).
Abstract The aim of this study is to design and implement a system that allows centralized blockchain institutions to prove their solvency. This system ensures that institutions do not misappropriate user assets and enhances trust between users and institutions. The article introduces the Groth‐16 zero‐knowledge proof algorithm from ZK‐SNARK (zero‐knowledge succinct non‐interactive argument of knowledge). The R1CS arithmetic circuit in the Groth‐16 algorithm effectively guarantees the authenticity and tamper‐resistance of the system's raw data sources. Additionally, it combines the use of Merkle Sum Trees and Sparse Merkle trees. The former enables users to perform distributed verification of solvency proofs, while the latter effectively hides the overall number of users. Finally, users verify the balances and the private key signatures of addresses in the institution's bulletin board. Together, these components form a comprehensive and distributed solvency proof solution. This solution is a pioneering solution in the field of blockchain solvency proofs and provides a secure, efficient, and privacy‐preserving method for centralized cryptocurrency service providers or Web3 enterprise custodians. It effectively addresses the challenge of proving an institution's possession of sufficient reserves to cover user assets without compromising user privacy or disclosing the institution's scale.
Identity management (IDM) systems in cloud computing struggle to securely manage user identities and access privileges in distributed environments. However, centralized IDM solutions come with high trust costs, single points of failure, and a need for appropriate security response. This paper proposes a novel decentralized IDM framework utilizing blockchain technology and automatic provisioning (AP) techniques to improve cloud computing’s security, scalability, and operational efficiency. The framework employs Ethereum smart contracts and role‐based access control (RBAC) to ensure secure, transparent, and automated management of user identities. Key features include support for single sign‐on (SSO), multifactor authentication (MFA), and delegated proof‐of‐stake (DPoS) consensus for secure transaction validation. Our proposed scheme utilizes the Ethereum blockchain and smart contracts for managing user access, ensuring transparent and immutable record‐keeping. The scheme introduces RBAC mechanisms to ensure precise privilege allocation and dynamic updates. The scheme also supports key IDM processes, including SSO, MFA, and lifecycle management of identities. The framework incorporates DPoS consensus to enhance security for efficient transaction validation and the prevention of fraud. To address fraudulent activities, the scheme uses machine learning to detect blockchain fraud with 99.1% accuracy, demonstrating robustness and efficiency for large‐scale cloud infrastructures.
Blockchain technology has produced effective solutions and provides security by using cryptographic tools for various applications, attracting attention from the academic community. Therefore, researchers have taken advantage of the features of blockchain technology to increase the security of the ecosystem. Recently, as the existence of quantum computers has been felt, researchers have started to benefit from post-quantum cryptography to increase privacy and security. There has been an increase in data and asset protection in post-quantum blockchain-based solutions. To the best of our knowledge, there is no comprehensive review or taxonomy that provides a complete picture of post-quantum secure structures with privacy-preserving techniques that have the potential to be used in blockchain. This paper aims to close this gap by systematically examining these approaches and revealing the deficiencies in the existing literature and the development potential in these areas. The taxonomy examines the role of blockchain technology in post-quantum cryptography and emphasizes the potential of technologies such as zero-knowledge proof to ensure privacy in post-quantum blockchain-based systems. We also review the existing literature on addressing the performance overhead, interoperability, scalability, and security challenges in implementing post-quantum cryptography in zero-knowledge proof-enabled blockchain architectures that protect against quantum computing threats. The studies are collected from journal papers in widely used academic databases between 2018 and 2024. The studies are subjected to certain elimination criteria, and 13 studies are reviewed in detail. Our approach will facilitate discussions on future research directions by proposing the accessibility of post-quantum cryptography against quantum threats to blockchain systems and solutions to the challenges that arise in the integration phase.
With the growing integration of cloud computing and the increasing adoption of Internet-of-Things (IoT) devices, ensuring the integrity and privacy of data has become critical in digital systems. Data integrity is fundamental to maintain the completeness and reliability of data throughout the data lifecycle. Its importance is particularly evident in domains such as healthcare, where accurate diagnoses rely on trustworthy data. However, as systems evolve and become more complex, traditional centralised solutions often lack transparency and resilience, while resource-constrained devices make it more difficult to guarantee security and privacy. This thesis addresses these challenges by proposing a framework that integrates Distributed Ledger Technology (DLT) to support privacy-preserving data sharing and strengthen trust among system stakeholders. Based on this framework, an architecture was designed with three main modules: a middleware integrator for service interoperability, an authorisation manager for fine-grained access control, and a data integrity validator leveraging metadata anchored on a distributed ledger to ensure compliance with the General Data Protection Regulation. A proof of concept was designed and implemented using IoT devices, healthcare data, and low-resource hardware. Experimental results demonstrate that the proposed solution enables efficient data sharing and integrity validation with minimal overhead on the system. The DLT layer validated the integrity of shared data through a metadata model while preserving user privacy. Furthermore, the access control mechanism supported scalable and granular authorisation policies, and the middleware facilitated interoperability across heterogeneous stakeholders. This work contributes to new insights into the security of digital systems and provides responsible entities with a trustworthy approach for sharing data among diverse entities.
Sabbir M. Saleh, Nazim H. Madhavji, John Steinbacher
Security is becoming a pivotal point in cloud platforms. Several divisions, such as business organisations, health care, government, etc., have experienced cyber-attacks on their infrastructures. This research focuses on security issues within Continuous Integration and Deployment (CI/CD) pipelines in a cloud platform as a reaction to recent cyber breaches. This research proposes a blockchain-based solution to enhance CI/CD pipeline security. This research aims to develop a framework that leverages blockchain's distributed ledger technology and tamper-resistant features to improve CI/CD pipeline security. The goal is to emphasise secure software deployment by integrating threat modelling frameworks and adherence to coding standards. It also aims to employ tools to automate security testing to detect publicly disclosed vulnerabilities and flaws, such as an outdated version of Java Spring Framework, a JavaScript library from an unverified source, or a database library that allows SQL injection attacks in the deployed software through the framework.
This research introduced a new novel “Unified Quantum-Resilient Blockchain-Zero-Knowledge Proofs Privacy Authentication Framework (QBC-ZKPAF)” to upgrade the IoT environments with greater security. To enable privacy-preserving authentication, access control, and secure communication, the framework integrates blockchain technology with Zero Trust Architecture (ZTA) and post-quantum cryptography. A hybrid Reinforcement-Lattice Blockchain KeyGen for quantum-resilient key generation, Deep Q-Network Multi-Factor Secure Key (DQN-MFSK) for dynamic selection of keys, and Zero-Knowledge Proof for privacy-preserving signatures are employed to achieve secure IoT settings. This architecture entails data privacy and confidentiality, auditability and traceability, and withstanding evolving threats, including potential threats in terms of quantum attacks. It then uses blockchain technology for recording unalterable data of identity and access management while Zero-Knowledge Proofs (ZKP) ensures authentication and verification without revealing sensitive information. By decentralizing identity management and enabling multi-factor authentication, QBC-ZKPAF provides robust security and privacy solutions for IoT networks. The experimental results demonstrate the model’s effectiveness with 98% privacy preservation, 700 TPS throughput, 0.7 J energy consumption, 0.98 quantum resilience, and 96% access control effectiveness, making it highly suitable for modern IoT and blockchain applications.
William Villegas-Ch, Rommel Gutierrez, Alexandra Maldonado Navarro, Aracely Mera-Navarrete
The Internet of Things (IoT) expansion has exposed connected devices to significant security vulnerabilities, particularly in terms of authentication and authorization. Traditional solutions, such as centralized servers or Proof of Work (PoW)–based blockchain, are unfeasible due to the resource limitations of IoT devices, such as their low processing capacity and dependence on batteries. This study proposes a lightweight blockchain system based on a simplified Proof of Stake (PoS) consensus mechanism designed to optimize energy consumption and improve resilience to attacks in IoT networks. The system implements a hierarchical network topology that improves data propagation and transmission times, significantly reducing latency compared to distributed topologies. In addition, it uses lightweight cryptographic algorithms such as ECDSA for authentication and AES-128 for authorization, ensuring transaction security without compromising the efficiency of IoT devices. The results show that the system reduces energy consumption by 54% compared to PoW solutions in high-load scenarios while maintaining an average latency below 30 ms. Furthermore, the system achieved a 92.5% attack detection rate under low malicious load, demonstrating its effectiveness in high-threat environments. This work offers a scalable and efficient solution that optimizes security and performance in IoT networks, opening new possibilities for its application in critical infrastructures and real-time sensor networks.
Healthcare systems face challenges in ensuring robust security, achieving scalable operations, and maintaining optimal efficiency, mainly attributable to the inherent constraints of conventional centralized architectural frameworks. These traditional systems have limitations that compromise healthcare delivery, affecting patient care quality, data integrity, and operational effectiveness. This research proposes a hybrid blockchain framework that integrates Hyperledger Fabric, Ethereum, and the Interplanetary File System (IPFS) to enable secure, scalable, and interoperable healthcare data management. Testing with simulated healthcare data across three institutional nodes demonstrated a significant 64% reduction in data retrieval time compared to traditional systems while maintaining exceptional 99.8% uptime reliability. Chainlink oracles serve as sophisticated bridges for cross-chain communication, securely transmitting data between blockchain networks while preserving complete data integrity. The framework ensures HIPAA and GDPR compliance through advanced AES-256 encryption protocols, immutable audit trails, and patient-controlled access mechanisms. The implementation results conclusively demonstrate that the hybrid model improves data security and interoperability while reducing operational costs by approximately 37% compared to current centralized solutions. This research establishes the transformative potential of hybrid blockchain frameworks in revolutionizing healthcare data environments by providing technically viable and economically efficient solutions to manage sensitive medical information.
Lyudmila Kovalchuk, M. Yu. Kuznetsov, A. A. Shumskaya
The splitting attack is one of the most important attacks on the blockchain, first of all for Proof-of-Work and Proof-of-Stake consensus protocols. Currently, there are no explicit analytical formulas for evaluating its success probability, which causes some distrust in blockchain technologies. In this paper, for a simplified (but still not simple) model of a splitting attack, the recurrent formulas allowing the evaluation of the exact values of the probability that an attacker will be able to build a branch of a given length are obtained. The correctness of these formulas is verified through numerical examples using the Monte Carlo method by constructing estimates with a specified confidence level and relative error. Keywords: blockchain, Proof-of-Stake, splitting attack, stakeholder, timeslot, slotleader, recursive formulas, Monte Carlo method.
As blockchain technology evolves to support a wide range of Web3 services, seamless interoperability between heterogeneous blockchain platforms has emerged as a key technical challenge. Existing studies mainly address interoperability in homogeneous environments, often neglecting critical platform-specific factors such as consensus mechanisms, asset models, and block generation parameters. Additionally, current standards by ISO and ITU-T define architectural frameworks but fall short in offering practical guidance for real-world implementation. This paper introduces a practical gateway-based interoperability framework designed to support dynamic and policy-driven interactions across diverse blockchain networks. The proposed architecture decouples interoperability logic from blockchain-specific interfaces, enabling modular scalability and flexible integration. Interoperability policies are defined with respect to consensus trust levels, transaction types, and asset compatibility to ensure atomicity and consistency in cross-chain operations. To validate the approach, we implemented a cross-chain asset transfer scenario between Hyperledger Fabric and Hyperledger Besu (Private Ethereum). The case study demonstrates high success rates, low latency, and consistent data integrity, confirming the framework’s practical applicability in Web3 environments. Future work will explore enhanced support for asynchronous execution, trust-based transaction control, and regulatory compliance in cross-jurisdiction blockchain interactions.