Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

484 papersLast indexed Aug 31, 2026
Search papers

Paper index

484 results · page 2 of 21

Clear filters
Jun 30, 2026·Research Square
0 cites
Hardware-Assisted Zero-Knowledge Authentication Scheme for Resource-Constrained IoT Terminals: USBKEY Implementation and Evaluation Based on GSVOLE-2DLC

Jianxin Wang, Zifan Xu, Runze Zhou, Chaoen Xiao · 5 authors

Abstract When resource-constrained Internet of Things (IoT) terminals connect to industrial control, sensing, and edge systems, it is necessary to balance low-overhead authentication, credential privacy protection, and cross-platform deployment. Traditional password and USBKEY authentication methods rely on static credentials and certificate mechanisms, which are vulnerable to eavesdropping, replay, and forgery attacks, while simultaneously suffering from privacy leakage and high platform adaptation costs. To address these issues, this paper proposes a hardware-assisted zero-knowledge authentication scheme for resource-constrained terminals. It utilizes a USBKEY as the local trusted hardware carrier and introduces a quadratic constrained zero-knowledge proof protocol under the Generalized Subspace Vector Oblivious Linear Evaluation framework (GSVOLE-2DLC) to construct a session-bound dynamic authentication process. In the registration phase, the scheme binds protocol parameters with user credentials and writes them into the USBKEY. In the authentication phase, the server (acting as the verifier \((\mathcal{V})\)) generates a random challenge, and the USBKEY (acting as the prover \((\mathcal{P})\)) generates temporary proof parameters based on local witness information. Subsequently, the verifier \((\mathcal{V})\) completes the verification through constraint consistency and GSVOLE consistency, thereby avoiding the transmission of original identity credentials over the network. To adapt to terminals with varying computational capabilities, this paper further designs configurable finite field parameters and cross-platform modular arithmetic interfaces, which are implemented in a PowerPC-architecture USBKEY prototype and a host-side verification environment. Experimental results demonstrate that under the parameter configuration of a 64-bit prime field, \((n_C=4)\), \((k_C=3)\), \((d_C=3)\), \((\ell=2)\), and \((t=7)\), the total system authentication time is approximately 0.5476 s, and the verification time for the verifier \((\mathcal{V})\) is 0.0031 s. Protocol performance and functional tests indicate that the proposed scheme can correctly execute identity authentication under the assumed threat model, making it suitable for IoT edge scenarios requiring privacy protection and lightweight authentication.

Open access
Advanced Authentication Protocols Security
Cryptographic Implementations and Security
Security and Verification in Computing
Original source
Jun 27, 2026·Figshare
0 cites
dPoH: A Decentralized Proof of Humanity Protocol for Sybil-Resistant Blockchain Identity Systems

Emeka Iwuagwu

<b>Abstract</b>The rapid growth of decentralized technologies has intensified the need for secure, privacy-preserving, and Sybil-resistant identity systems capable of operating without centralized authorities. Existing blockchain identity mechanisms frequently depend on trusted intermediaries, invasive biometric verification, or token-based incentives that introduce privacy risks, centralization, or economic manipulation. This paper presents the Decentralized Proof of Humanity (dPoH) Protocol, a blockchain-native identity framework designed to establish unique human identities through decentralized verification while preserving user privacy and network scalability.The dPoH protocol combines decentralized attestations, cryptographic verification, reputation mechanisms, and consensus-driven validation to ensure that each participant corresponds to a unique human identity without exposing unnecessary personal information. By eliminating reliance on centralized identity providers, the protocol significantly reduces Sybil attacks while maintaining transparency, auditability, and interoperability across blockchain ecosystems.The proposed architecture is suitable for decentralized finance (DeFi), decentralized governance (DAO), voting systems, digital identity infrastructure, token distribution, and next-generation Web3 applications. The protocol contributes to the growing field of decentralized identity by providing a scalable framework for secure human verification in trustless environments.

Open access
2 source records
Blockchain Technology Applications and Security
Cryptography and Data Security
Advanced Authentication Protocols Security
Original source
Jun 25, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
Context-Aware Password Management For Multi-User IoT Environments: A Systematic Review Of Secure Key Rotation And Expiry Mechanisms

Vrutti Mistry, Yassir Farooqui, Amit Barve

The rapid proliferation of Internet of Things (IoT) devices across smart homes, healthcare systems, and industrial environments has intensified the need for robust and adaptive security mechanisms in multi-user settings. Traditional password management approaches remain widely deployed; however, they suffer from persistent vulnerabilities including weak password selection, credential reuse across services, and the absence of structured lifecycle management mechanisms. This paper presents a systematic review of existing authentication, password management, and key lifecycle strategies applicable to multi-user IoT ecosystems. The study follows a structured review methodology to analyze and synthesize contemporary research contributions in the areas of context-aware authentication, secure key rotation, password expiry mechanisms, and lightweight cryptographic implementations. A comparative evaluation of diverse security techniques—such as one-time passwords (OTPs), zero-knowledge proofs (ZKP), symmetric and public-key cryptographic schemes, and machine learning-based threat detection models—is conducted with particular attention to device resource constraints, scalability challenges, and operational efficiency. Conceptual models, analytical tables, and comparative charts are utilized to highlight trade-offs between security strength, computational overhead, and system performance. The review identifies significant research gaps in integrating dynamic key rotation and expiry mechanisms into holistic, context-aware security architectures tailored for multi-user IoT environments. Finally, the paper outlines future research directions aimed at developing scalable, resource-efficient, and adaptive password lifecycle management frameworks for next-generation IoT systems. management frameworks for next-generation IoT systems.

Open access
2 source records
User Authentication and Security Systems
Advanced Authentication Protocols Security
Advanced Malware Detection Techniques
Original source
Jun 25, 2026·Cybersecurity Education Science Technique
0 cites
SECURE AUTHORIZATION OF BANKING TRANSACTIONS BASED ON THE SCHNORR SCHEME

Viktoriia Shlapak, S. A. Semenyuk

The method of secure authorization of banking transaction based on the Schnorr scheme represents a cryptographic approach to verifying user authenticity using Zero-Knowledge Proof (ZKP) protocols. The proposed approach is focused at minimizing the risks of compromising confidential data during the execution of transaction in open or partially trusted environments. The method is based on the Schnorr identification protocol, which relies on the computational hardness of the discrete logarithm problem and enables authentication without transmitting the user’s secret key. The authorization model includes the interaction process between three components of the transaction, namely the client, the transaction execution environment, and the banking side. The transaction execution environment is considered to be critical and untrusted component. The protocol consists of a sequence of stages: first, the initial parameters (p, g) are generated; then the public key value (y) is formed; based on it, a proof value (t) is created; on the bank`s side, a challenge (e) is generated followed by the computation of the parameter s, and subsequently the correctness of the verification relation is checked by the bank. A distinctive feature of the approach is the absence of private key transmission and the use of random values, which prevents the recovery of secret parameters even if part of the data is intercepted. Within the scope of the study, simulations of Man-in-the-Middle (MITM) and replay attacks were performed in older to evaluate the robustness of the proposed approach. In the case of a Man-in-the-Middle attack, it is shown that modification of the parameter t leads to a violation of the verification relation, making successful transaction authorization impossible. To counter replay attacks, a timestamp (TS) mechanism and transaction parameter uniqueness were integrated into the model, eliminating the possibility of reusing intercepted data. The constructed model is based on cryptographic strength, reduction of the impact of vulnerabilities in the transaction execution environment, and ensuring the fundamental principles of digital security, namely data integrity, confidentiality, and authenticity. The proposed method demonstrates its effectiveness in scenario with a high level of threats, such as in the financial sector, where transaction protection is a critical component

Open access
Advanced Authentication Protocols Security
Blockchain Technology Applications and Security
Cryptography and Data Security
Original source
Jun 25, 2026·Discover Internet of Things
0 cites
A scalable blockchain-based authentication framework for interoperable and regulatory-compliant cross-border transactions in IoT environments

Mohammad Ayoub Khan, Mohamed Chawki

Cross-border transactions with regulatory compliance have become conventional in the era of globalization. Transactions related to individuals, banking, technology, etc., are eased using Internet of Things (IoT) paradigms. Pervasive access and low interoperability due to improper administration of transaction terminals are significant problems in initiating and completing cross-border transactions. To address the problems, a novel Zero-knowledge proof Inter-Scalable Framework (ZISF) is proposed. This framework includes transaction authentication, Blockchain (BC), and a security generator to ensure security, scalability, and interoperability. The proposed framework consolidates these tasks to support diversified cross-border transactions with flexible regulatory compliance. The proposed ZISF framework achieved a 13.64% improvement in transaction throughput compared with CCMB under varying block-size and transaction-load conditions, while reducing processing latency by 13.79% relative to BETAC-IoT during miniature block scaling operations.

Open access
Blockchain Technology Applications and Security
Advanced Authentication Protocols Security
Cryptography and Data Security
Original source
Jun 25, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
Privacy-Preserving UPI Payment Tier Eligibility using Zero-Knowledge Proofs: A Multi-Predicate ZKProof-eKYC Framework for India's Payment Infrastructure

Tanishq Sahu, Puneet Bakshi, Pranali Nikam

India’s Unified Payments Interface (UPI) gates transaction limits behind Know Your Customer (KYC) compliance tiers mandated by the Reserve Bank of India (RBI) and National Payments Corporation of India (NPCI). Unlocking the Full KYC tier currently requires users to surrender sensitive identity documents (Aadhaar, PAN, income proofs) to Payment Service Providers (PSPs). This centralized storage creates severe breach vulnerabilities and systemically violates the data minimization principle of India’s Digital Personal Data Protection (DPDP) Act 2023, Section 8(3). We present ZKProof-eKYC, the first Zero-Knowledge Proof (ZKP) framework designed specifically for payment system tier access control. By reframing KYC eligibility as a cryptographic access token, a user’s device generates a 1.5 KB non-interactive Groth16 zk-SNARK proof asserting tier eligibility. The PSP receives only a boolean result, eliminating personal data transmission and achieving DPDP Act compliance mathematically. The primary contribution is a multi-predicate Circom 2.0 circuit (≈25,000 R1CS constraints) simultaneously enforcing eleven regulatory predicates (ϕage to ϕtier) mapped across six Indian statutes. The architecture introduces five key elements: (i) an 8-leaf depth-3 Poseidon Merkle credential tree; (ii) a dualdocument commitment scheme protecting the raw PAN (singlehash) and Aadhaar (double-hash) identifiers; (iii) an EdDSAPoseidon issuer signature; (iv) a depth-20 Sparse Merkle Tree (SMT) for real-time revocation; and (v) Poseidon nonce-binding against replay attacks. A novel branch-free finite-field formula calculates NPCI’s tier limits natively: tier = 2 · ⊮[FullKYC] + (1−⊮[FullKYC])·⊮[MinKYC]. We deploy a dual-circuit framework: UPIKYCTierProof for Full KYC and MinKYCTierProof for Min KYC. Functional correctness is validated against 12 adversarial test vectors. Performance profiling projects mobile WASM generation at <400 ms, with off-chain execution measured at ≈96 ms and on-chain verification at ≈242,000 gas. ZKProofeKYC establishes the first “one credential, multiple products” ZKP architecture for national payment infrastructure.

Open access
2 source records
Cryptography and Data Security
Cryptography and Residue Arithmetic
Advanced Authentication Protocols Security
Original source
Jun 24, 2026·International Journal of Computer Applications
0 cites
Securing Digital Services in Bangladesh: A Decentralized Identity Verification Framework Using Blockchain and Cryptography

Md Sakibul Islam Sheikh, Md Dipu, Maksudur Rahmand, Kazi Riadul Islam · 7 authors

In today's digital environment, secure and trustworthy identity management is critical as centralized systems remain vulnerable to data breaches, identity theft, and unauthorized access.This paper presents a blockchain-based decentralized identity verification framework that enhances data security, privacy, and user control by eliminating reliance on centralized authorities.The proposed system integrates smart contracts, decentralized identifiers (DIDs), and cryptographic security to enable tamper-resistant and transparent identity verification.Sensitive user documents are encrypted using AES-256-GCM and stored off-chain on IPFS, while only cryptographic hashes and verification records are recorded on the blockchain to preserve privacy and data integrity.Key management is strengthened through HKDF-based derivation, and users can selectively disclose identity attributes using privacy-preserving techniques.Experimental analysis indicates that the system significantly reduces identity fraud, improves verification accuracy, and enhances auditability and scalability.The solution is well-suited for applications in finance, healthcare, e-governance, and secure third-party authentication platforms.

Open access
Blockchain Technology Applications and Security
Cryptography and Data Security
Advanced Authentication Protocols Security
Original source
Jun 22, 2026·Computers
0 cites
dAuth: A Hybrid Smart Contract-Based Architecture for Decentralized Authentication with Institutional Attestation

Valerio Mandarino, Giuseppe Pappalardo, Emiliano Tramontana

Authentication is essential to hold users accountable across online services. Conventional authentication systems rely on centralized architectures or third-party identity providers, which, however, introduce single points of failure, privacy concerns, and limited user autonomy. Conversely, fully decentralized authentication frameworks often struggle to provide reliable identity attestation mechanisms. This makes them vulnerable to Sybil attacks and self-asserted claims, while limiting their interoperability with trust-based systems. This paper presents dAuth, a hybrid blockchain-based authentication architecture based on Ethereum smart contracts to provide cryptographic tokens that enable authentication to services. These tokens, anchored to the smart contract, are derived by users from institutionally certified base credentials issued by an accredited verifying authority and enable authentication to services without further involvement of the authority. Each token is cryptographically bound to a specific service, constrained in scope and duration, and verifiable off-chain through data and cryptographic commitments provided by the user. No plaintext personal information is published on-chain: identity attributes are committed as cryptographic digests, which anchor certified identity data on-chain while keeping the underlying personal information private and auditable. This design removes the verifying authority from the authentication process, as all authentication steps are assisted by the user-controlled smart contract. The verifying authority’s role is limited to initial identity certification and exceptional update procedures. The result is a privacy-preserving and verifiable hybrid authentication framework that leverages the cryptographic security properties of the underlying blockchain infrastructure and inherits its scalability characteristics. The proposed design has been implemented and experimentally evaluated on the Ethereum platform, addressing public blockchain-specific challenges such as scalability constraints and transaction costs to ensure practical deployment.

Open access
Advanced Authentication Protocols Security
Blockchain Technology Applications and Security
Cryptography and Data Security
Original source
Jun 20, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
BLOCKCHAIN-DRIVEN FRAMEWORK FOR SECURING ELECTRONIC HEALTH RECORDS

AMARESWARA RAO ADDANKI, Bharathi G, HARI BABU Dr.CHAVA, DINESH BABU DR.VUNNAVA · 6 authors

Academic research indicates an urgent need for safe, tamper-proof storage of sensitive medical information due to the rapid digitalization of healthcare data. Traditional systems are susceptible to both internal and external assaults because of their dependence on centralized servers. SEC-HEALTH implements a system for the secure storage of electronic health records (EHRs) by combining the immutable, distributed ledger technology of blockchain with the InterPlanetary File System (IPFS).This system use Solidity smart contracts to archive patient data and transaction records on the Ethereum blockchain. Comprehensive EHR files are preserved on IPFS and may be accessed via their blockchain hash addresses. The architecture guarantees data integrity, transparency, and safe access independent of trusted third parties.User modules include appointment scheduling, prescription management, patient and physician authentication, and platform registration. The graphics illustrate a fully operational web interface created in Python, implemented smart contracts, and the integration of blockchain with IPFS. The approach is resilient and decentralized, providing an alternative to traditional centralized health data management systems.

Open access
2 source records
Blockchain Technology Applications and Security
Advanced Authentication Protocols Security
IoT and Edge/Fog Computing
Original source
Jun 20, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
Privacy-Preserving Authentication — Cryptography, Key Management, Post-Quantum, Sovereign AI, and Post-Cloud Architecture (Mf+So)

Lois-Kleinner Alpasan

This paper presents a comprehensive analysis of privacy-preserving authentication mechanisms within the MF+SO sovereign identity vault, focusing on the protocol's implementation of zero-knowledge identity proofs, anonymous credentials, blind signatures, and data minimization techniques. Traditional authentication protocols require the user to disclose their identity to each service provider, creating a centralized record of the user's activities across services. MF+SO's privacy architecture inverts this model: users authenticate to services without revealing their MF+SO identifier, using cryptographic techniques that provide the verifier with assurance of the user's authorization status while revealing minimal information about the user's identity. We examine three canonical privacy-preserving authentication mechanisms implemented in MF+SO: (1) zero-knowledge identity proofs using the Groth16 zk-SNARK construction, enabling users to prove possession of valid credentials without revealing which credentials they hold; (2) anonymous credentials based on the Camenisch-Lysyanskaya (CL) signature scheme, providing multi-show unlinkability where the same credential can be presented multiple times without the presentations being correlatable; and (3) blind signature-based tokens for email cloaking, where the MF+SO service issues a blind signature on a user's email address for use with third-party services without learning the email address. The paper provides a formal security analysis of the unlinkability guarantees of each mechanism, proving that under the decisional Diffie-Hellman (DDH) assumption, CL-based anonymous credential presentations are computationally unlinkable. We present benchmark data for each mechanism on mobile platforms: CL credential issuance (120 ms), CL credential presentation (85 ms), blind RSA signature issuance (45 ms), and zk-SNARK-based verification (2.3 ms). The implementation details include the MF+SO privacy layer architecture, the credential ... Part of The Anticloud research corpus by Lois-Kleinner Alpasan (ORCID: 0009-0009-2233-6107). This work explores cryptography, key management in the context of sovereign AI infrastructure, post-cloud computing architectures, and transparent, blackbox-free systems.

Open access
2 source records
Cryptography and Data Security
Advanced Authentication Protocols Security
Blockchain Technology Applications and Security
Original source
Jun 20, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
Zero-Knowledge Proofs in Identity Management — Cryptography, Key Management, Post-Quantum, Sovereign AI, and Post-Cloud Architecture (Mf+So)

Lois-Kleinner Alpasan

This paper presents a comprehensive analysis of zero-knowledge proof (ZKP) systems and their application to privacy-preserving identity management within the MF+SO sovereign identity vault. Zero-knowledge proofs, introduced by Goldwasser, Micali, and Rackoff (1985), enable a prover to convince a verifier of the truth of a statement without revealing any information beyond the statement's validity. We examine three families of ZKP systems in the context of MF+SO's identity assertions: zk-SNARKs (Zero-Knowledge Succinct Non-Interactive Arguments of Knowledge), zk-STARKs (Zero-Knowledge Scalable Transparent Arguments of Knowledge), and Bulletproofs. For each family, we analyze the setup assumptions (trusted setup vs. transparent), proof size, verification complexity, prover computation, and post-quantum security. The paper identifies three canonical use cases within MF+SO: (1) age verification without date of birth disclosure, where the user proves that their age exceeds a threshold without revealing their exact birth date; (2) credential possession proof, where the user proves they hold a valid credential for a resource without revealing which credential among a set they hold; and (3) membership in an allowlist without position disclosure, where the user proves their identifier appears in a list without revealing their position in the list. We present benchmark data for each use case using the Groth16 zk-SNARK (prover time: 1.2 seconds, proof size: 192 bytes, verification: 2.3 ms) and the STARK-based approach using the Winterfell library (prover time: 4.8 seconds, proof size: 48 KB, verification: 8.1 ms). The implementation complexity analysis demonstrates that zk-SNARKs require trusted setup ceremonies but provide the most compact proofs, while zk-STARKs eliminate the trusted setup requirement at the cost of larger proofs. The paper concludes with an analysis of the protocol integration requirements, including circuit compilation for the MF+SO identity predicate lang... Part of The Anticloud research corpus by Lois-Kleinner Alpasan (ORCID: 0009-0009-2233-6107). This work explores cryptography, key management in the context of sovereign AI infrastructure, post-cloud computing architectures, and transparent, blackbox-free systems.

Open access
2 source records
Cryptography and Data Security
Advanced Authentication Protocols Security
Cloud Data Security Solutions
Original source
Jun 18, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
A Hybrid Zero-Knowledge Proof and Human Interaction Proof Protocol for Secure Authentication and the Prevention of Automated Brute-Force Attacks

Sancaktar Pelin, Necla Kırcalı Gürsoy, Arif Gürsoy

Modern authentication architectures contain structural vulnerabilities against automated credential stuffing and server-side data breaches. Traditional solutions rely on the transmission of raw or hashed passwords over the network; for bot defense, they position third-party Completely Automated Public Turing test to tell Computers and Humans Apart (CAPTCHA) services, which may violate user privacy and create institutional dependencies, as an illusion of two-factor authentication (2FA). This situation raises a critical research question in cybersecurity: How can an integrated cryptographic shield be constructed that is independent of user-privacy-invasive mechanisms and external data authorities, while preventing autonomous bots from targeting the identity and human-verification layers separately?In response to this question, this paper presents a zero-dependency, original, and hybrid protocol that integrates a Zero-Knowledge Proof (ZKP) based on the Schnorr authentication scheme with a local Human Interaction Proof (HIP) mechanism. The main advantage of the proposed architecture is that it mathematically seals the user’s secret credential together with a dynamically generated one-time CAPTCHA token on the client side using the SHA-256 function, thereby transforming the verification process into an indivisible atomic “Hybrid Secret.” In this way, the transmission of password hashes over the network is completely eliminated, and the server evaluates only the mathematical validity of the proof under the Discrete Logarithm Problem (DLP) assumption.Experimental results obtained through Selenium-based automated brute-force attack simulation engines demonstrate that the system provides complete blocking against automated threat vectors. Dynamic one-time nonce mutation immediately invalidates the derived client response, even in extreme scenarios where an attacking bot obtains the correct password string and solves the CAPTCHA image, thereby mathematically defeating brute-force and replay attacks. Furthermore, the autonomous structure of the proposed protocol, with no dependency on third-party analytics services, opens the way for a highly secure and local authentication architecture for internet-isolated critical infrastructures.In this study, the theoretical and mathematical foundations of the proposed protocol are presented, the stages constituting its life cycle are methodologically explained, and Selenium-based experimental simulation results together with telemetry log analyses are detailed.

Open access
2 source records
User Authentication and Security Systems
Advanced Authentication Protocols Security
Security in Wireless Sensor Networks
Original source
Jun 6, 2026·arXiv (Cornell University)
0 cites
LPOR: A Layered Proof of Reserves Framework for Usable and Publicly Auditable Solvency Verification

Donggoo Kim, Rajesh Upadhayaya, Milosz Bator, Tao Le

Proof of Reserves (PoR) enables centralized crypto exchanges to demonstrate that on-chain reserves are sufficient to cover customer liabilities. However, existing approaches, including Merkle-tree-based proofs and zero-knowledge PoR systems, remain difficult for everyday users to verify in practice, resulting in limited participation and weakened transparency. We introduce LPOR, a layered, usability-focused PoR framework that separates lightweight user-side checks from auditor-level cryptographic verification, enabling non-technical users to verify inclusion and publicly recompute total liabilities with minimal friction. By lowering verification barriers, LPOR increases user participation and substantially improves the probability of detecting omitted liabilities. We evaluate its scalability and omission detectability at a multi-million-user scale.

Open access
2 source records
Cryptography and Data Security
Advanced Authentication Protocols Security
Blockchain Technology Applications and Security
Original source
Jun 5, 2026·International Journal of Drug Delivery Technology
0 cites
Securing E-Commerce Payments using Decentralized Crypto Escrow

S. Praveena, T. Arasulingam, M. Dineshkumar, P. Puvirajan · 7 authors

The rapid expansion of digital commerce has brought forward new challenges in payment security and transactional trust. Buyers and sellers engaging in online platforms face persistent threats such as payment fraud, unauthorized fund diversions, delayed settlements, and an overreliance on centralized financial intermediaries. Traditional mechanisms, which route payments through banks and payment gateway providers, often introduce additional costs while creating points of vulnerability that undermine consumer confidence. This paper proposes a blockchain-driven decentralized crypto escrow payment framework designed to address these shortcomings in a fundamental way. Rather than routing buyer payments directly to merchant accounts, the system temporarily secures those funds within a smart contract-governed escrow until all agreed-upon transaction conditions have been satisfied — including verified order fulfilment and successful product delivery. In the event of a dispute or transaction failure, the system enforces pre-coded refund protocols without requiring manual intervention. The proposed framework is expected to strengthen the relationship between buyers and sellers, meaningfully raise the bar for payment security, and deliver a transparent, auditable transaction environment through the principles of decentralized finance.

Open access
Blockchain Technology Applications and Security
Cryptography and Data Security
Advanced Authentication Protocols Security
Original source
Jun 2, 2026·arXiv (Cornell University)
0 cites
Reserve Depletion and Security Runway in Proof-of-Stake Systems

Paolo Penna, Manvir Schneider

Many proof-of-stake protocols finance validator rewards from two sources: transaction fees and a finite reserve of tokens. This creates a dynamic hand-off problem. Early in the life of the system, fees may be too small to fund the target level of security; later, fees may become sufficient. The central question is whether the reserve provides enough runway for the protocol to remain secure until this fee-only region is reached. We study this problem in a discrete-time stochastic model of validator participation. Token price and transaction demand fluctuate over time, while validators choose participation strategically. We solve the validator entry game and derive an exact state-dependent reserve threshold, i.e., the minimal reserve stock necessary and sufficient to sustain a target security level. This threshold separates three regions: infeasibility, reserve-dependent security, and fee-only security. Security fails if the reserve first falls below the state-dependent threshold, and a successful hand-off occurs exactly if the fee-only region is reached before that failure time. We derive stress-test guarantees that convert lower confidence bands for token price and demand into reserve requirements, and obtain explicit failure-probability and expected hand-off-time bounds. Finally, we extend the model to forward-looking validators and derive the Markov participation condition that captures how current participation affects future reserve-funded rewards. The main implication is that reserve policy should not be evaluated by nominal depletion dates or steady-state reward ratios alone. A protocol can have a large nominal reserve and still be close to security failure after adverse price or demand shocks. Conversely, once demand crosses the fee-only threshold, the reserve becomes redundant for security. This paper provides a tractable equilibrium framework for stress-testing this transition.

Open access
3 source records
Advanced Authentication Protocols Security
Wireless Communication Security Techniques
Cryptography and Data Security
Original source
Jun 1, 2026·Archivo Digital UPM (Universidad Politécnica de Madrid)
0 cites
Análisis criptográfico de la criptomoneda Monero

Analía Olivero Betancor

Este Trabajo Fin de Grado presenta un análisis criptográfico y matemático de la arquitectura de Monero, una criptomoneda diseñada con la privacidad como propiedad fundamental de su protocolo. El estudio comienza con la formalización de los fundamentos algebraicos que conforman el sistema, como las curvas de Edwards retorcidas y la completitud de su ley de grupo, característica que contribuye a mitigar vulnerabilidades asociadas a ataques de canal lateral. Sobre esta base se estudia el protocolo Ring Confidential Transactions (RingCT), núcleo de los mecanismos de privacidad de la red. En particular, se analizan las direcciones sigilosas (stealth addresses), que garantizan la no vinculabilidad de los receptores mediante intercambios Diffie–Hellman sobre curvas elípticas; las firmas de anillo CLSAG y las imágenes de clave, que proporcionan anonimato al emisor y previenen el doble gasto; y los compromisos de Pedersen, utilizados para ocultar las cantidades transferidas. Asimismo, se estudian las pruebas de rango Bulletproofs+, destacando su función en la reducción del tamaño de las transacciones mediante argumentos de producto interno. Finalmente, se examinan diversas vulnerabilidades históricas y técnicas de análisis de trazabilidad aplicadas a Monero, evaluando el grado de resistencia que ofrece el protocolo frente a distintos ataques. Los resultados ponen de manifiesto cómo la integración de herramientas avanzadas de criptografía de clave pública, pruebas de conocimiento cero y estructuras algebraicas sobre curvas elípticas permite construir un sistema financiero con garantías de privacidad, seguridad y fungibilidad. ABSTRACT This Bachelor’s Thesis presents a cryptographic and mathematical analysis of the architecture of Monero, a cryptocurrency designed with privacy as a fundamental property of its protocol. The study begins with the formalization of the algebraic foundations underlying the system, including twisted Edwards curves and the completeness of their group law, a feature that helps mitigate vulnerabilities associated with side-channel attacks. Building upon this mathematical framework, the Ring Confidential Transactions (RingCT) protocol, which forms the core of Monero’s privacy mechanisms, is examined. In particular, the thesis analyzes stealth addresses, which ensure receiver unlinkability through Diffie–Hellman key exchanges over elliptic curves; CLSAG ring signatures and key images, which provide sender anonymity and prevent double-spending; and Pedersen commitments, which are used to conceal transferred amounts. Furthermore, Bulletproofs+ range proofs are studied, highlighting their role in reducing transaction size through efficient inner-product arguments. Finally, several historical vulnerabilities and traceability analysis techniques applied to Monero are reviewed in order to evaluate the protocol’s resistance against different types of attacks. The results demonstrate how the integration of advanced public-key cryptography, zero-knowledge proofs, and algebraic structures based on elliptic curves makes it possible to build a financial system with strong guarantees of privacy, security, and fungibility.

Open access
Advanced Authentication Protocols Security
Cryptography and Data Security
Security in Wireless Sensor Networks
Original source
Jun 1, 2026·arXiv (Cornell University)
0 cites
I-(OT)^2: A Client-optimal Oblivious Transfer Protocol for IoT Devices

E. Onofri, Andrea Ciccotelli, Roberto Di Pietro

Oblivious Transfer (OT) is a fundamental cryptographic primitive enabling privacy-preserving computation and constitutes a core building block for secure multi-party computation while supporting a wide range of security-sensitive applications: private information retrieval, zero-knowledge proofs, and password-authenticated key exchange, to cite a few. While recent advances in OT extension have significantly reduced amortised costs, their reliance on batches of random base OTs and substantial pre-computation phases limits their practicality in scenarios where the number of transfers is modest or where communication latency and client-side computation are critical constraints. In such settings, efficient base OT protocols remain both relevant and necessary. In this work, we introduce $I$-$(OT)^2$, a novel base 1-out-of-2 OT protocol grounded in the quadratic residuosity problem, specifically designed to minimise receiver-side computation and interaction. Our construction is particularly appealing on client--server architectures in which the receiver operates on low-power hardware, such as Internet of Things (IoT) devices. Through a lightweight offline pre-computation phase, $I$-$(OT)^2$ shifts the on-transfer computational burden almost entirely to the Sender, while reducing online communication to only six messages and four digests exchanged. We provide a detailed description of the protocol, accompanied by a formal proof of its security. Moreover, to demonstrate the viability of $I$-$(OT)^2$, we also present an open-source proof-of-concept implementation (in C language) evaluated on real IoT hardware. Results are staggering: for 128-bit security using a 3072-bit RSA modulus, the receiver incurs an average online cost per OT as low as 2.80 μs on desktop platforms and 39.90 μs on IoT devices, more than 10$\times$ faster than the well known SimplestOT.

Open access
3 source records
cs.CR
Cryptography and Data Security
Advanced Authentication Protocols Security
Original source
May 24, 2026·arXiv (Cornell University)
0 cites
Decoupling Reentrancy Protection from Smart Contract Implementation Logic

Shashank Joshi, Wojciech Golab

Reentrancy attacks remain a persistent threat to decentralized applications (DApps), with malicious actors siphoning around 80M USD from the DApp ecosystem last year by exploiting EVM's inter-contract message-passing semantics. Existing research focuses primarily on detection, relying on known attack patterns, and fails to provide deployable solutions that eliminate the vulnerability. Traditional reentrancy guards are similarly limited, offering incomplete coverage across attack variations and lacking robustness against complex DApp interactions. In this paper, we introduce Sentinel, a novel proxy-based approach that mitigates reentrancy vulnerabilities in a type-agnostic way by integrating reentrancy logic directly into the proxy layer, intercepting all calls to the underlying implementation contract. Key features include a dual-mode operational system offering both a gas-optimized internal guard and a high-security external lock registry for cross-contract reentrancy prevention. The proxy also intelligently handles static calls, enabling safe view-function execution while protecting against Read-Only Reentrancy (ROR) attacks. Through rigorous evaluation on a dataset of 70 vulnerable smart contracts, Sentinel achieves 100% security coverage across four major reentrancy attack categories, outperforming existing solutions by over 40%

Open access
3 source records
cs.CR
cs.ET
Security and Verification in Computing
Original source
May 21, 2026·Studies in health technology and informatics
0 cites
A Web3-Based Patient-Centric Health Data Management System

Dongjae Shin, Minseon Park, Hyung‐Jin Yoon

This paper presents a Web3-based healthcare system integrated with the Republic of Korea's MyHealthWay platform for secure and user-controlled management of personal health data. The system combines decentralized identifiers, smart contracts, distributed storage, and the HL7 FHIR standard to support decentralized authentication, access control, and interoperability. A conceptual demonstrator, HealthCube, validates feasibility by enabling privacy-preserving health data processing through computation on encrypted data without exposing original information.

Open access
Innovation in Digital Healthcare Systems
Advanced Authentication Protocols Security
Digital Rights Management and Security
Original source
May 16, 2026·arXiv (Cornell University)
0 cites
A Lightweight QR-assisted Zero-knowledge Identification Protocol For Secure Authentication

Hüseyin Bodur

This study proposes a lightweight Zero-Knowledge authentication model supported by QR codes. The approach is based on the Schnorr authentication protocol and provides an additional security layer against replay attacks through nonce and timestamp mechanisms. The proof data generated by the prover is embedded within a QR code and transmitted to the verifier. Thus, the system enables verification of knowledge of the secret key without revealing it. Simulation results show that proof generation and verification times under a 256-bit security level are in the millisecond range. Additionally, the proof size remains constant at approximately 0.5 KB, making it suitable for practical applications in terms of QR code capacity. The findings indicate that the proposed model is applicable in mobile and low-resource systems in terms of both security and performance.

Open access
2 source records
QR Code Applications and Technologies
Advanced Authentication Protocols Security
RFID technology advancements
Original source
May 11, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
ChitraVault: A Chitrakavi-Inspired Multi-Modal Authentication Framework for Password Vault Security

Arvind Vijayakumar

ChitraVault is an exploratory conceptual authentication architecture that investigates whether geometric visual traversal patterns, drawn from the Chitrakavi (சித்திரக்கவி) classical Tamil literary tradition, can augment password vault security by adding a spatial-behavioral dimension to cryptographic key derivation. This paper proposes the Visual Pattern Key Derivation Function (VP-KDF), which combines a user-drawn Chitrakavi geometric pattern, a text passphrase, and a hardware-bound device fingerprint as inputs to Argon2id key stretching. The framework maps four classical Chitrakavi patterns — Chakra Bandha (wheel), Naga Bandha (serpent), Gomutrika (zigzag), and Thiruezhukkootrirukkai (triangle) — onto distinct cryptographic roles within a zero-knowledge password vault architecture. This work is framed as an exploratory research program, not a finished cryptographic system. All security arguments are bounded by stated assumptions and require empirical and cryptanalytic validation. Future work includes controlled user studies, formal security proofs, and prototype evaluation. Author: Arvind VijayakumarIndependent ResearcherMay 2026

Open access
2 source records
User Authentication and Security Systems
Biometric Identification and Security
Advanced Authentication Protocols Security
Original source
May 10, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
SecureAttend: A Privacy-Preserving Cloud-Based Attendance Management Framework Integrating Zero-Knowledge Proof Authentication and Biometric Verification

Umar . Abubakar, Hamza Itopa Sanni, Abdulsalam Aliyu

Conventional attendance management approaches in academic and organisational settings face persistent challenges that include susceptibility to proxy attendance, inadequate protection of biometric credentials, and the absence of privacy-preserving verification mechanisms in cloud-hosted deployments. This paper presents SecureAttend, a cloud-based attendance management framework that addresses these deficiencies through the integration of Zero-Knowledge Proof (ZKP) cryptographic authentication with biometric capture via a ZKTeco K40 Pro fingerprint terminal. The proposed framework employs a challenge-response ZKP protocol that enables users to demonstrate possession of valid authentication credentials without disclosing underlying private keys or biometric templates to the server. Attendance records are encrypted using AES-256 prior to storage in a MongoDB cloud database, while SHA-256 hashing provides tamper-evidence for each record. Session integrity is maintained through JWT-based token management, and access boundaries are enforced via a Role-Based Access Control (RBAC) policy. Functional evaluation across eighteen test scenarios confirmed complete compliance with stated requirements. Security assessment validated correct operation of cryptographic mechanisms, access controls, and audit logging subsystems. Performance benchmarks recorded average API response latencies of approximately 85 milliseconds for authentication requests and 120 milliseconds for attendance marking operations. The results demonstrate that ZKP authentication can be deployed effectively in real-world attendance management contexts, offering measurable improvements in privacy, integrity, and resistance to credential-based attacks compared with conventional approaches.

Open access
2 source records
Cryptography and Data Security
Advanced Authentication Protocols Security
Cloud Data Security Solutions
Original source
May 8, 2026·Open MIND
0 cites
The Role of Cryptography in Network Security: A Systematic Review and Emerging Trends

Daniel Makolo, Obafemi Babatunde Desmond, Dauda Shaibu Anibe, Ejiga Timothy Ikoojo · 7 authors

Cryptography is the backbone of modern network security, providing confidentiality, integrity, authentication, and non-repudiation for digital communication. However, the rapid evolution of cyber threats, particularly the looming arrival of large-scale quantum computers, poses serious challenges to the cryptographic algorithms that protect today's networks. This paper presents a systematic review of cryptography in network security, following the PRISMA 2020 guidelines. A total of 68 studies published between 2016 and 2025 were selected from five major academic databases: IEEE Xplore, ACM Digital Library, Scopus, Web of Science, and ScienceDirect. The review covers classical symmetric and asymmetric algorithms, widely deployed cryptographic protocols such as TLS 1.3, IPsec, and SSH, and the growing body of work on post-quantum cryptography (PQC). Key findings include the following: NIST finalized three post-quantum cryptographic standards (FIPS 203, 204, and 205) in August 2024; lightweight cryptography standards for IoT devices were published in 2025 with the selection of ASCON; and real-world deployment of hybrid classical/post-quantum schemes has already begun in major web browsers and messaging applications. This paper also examines emerging trends in homomorphic encryption, zero-knowledge proofs, and AI-driven cryptanalysis. Based on the findings, this review identifies critical gaps in PQC migration strategies, IoT security, and the integration of cryptography with artificial intelligence, and proposes directions for future research.

Open access
2 source records
Cryptography and Data Security
Chaos-based Image/Signal Encryption
Advanced Authentication Protocols Security
Original source
May 4, 2026·IACR Communications in Cryptology
3 cites
Anonymous Credentials from ECDSA

Matteo Frigo, abhi shelat

Anonymous digital credentials allow a user to prove possession of an attribute that has been asserted by an identity issuer without the user revealing any extra information about themselves. For example, a user who has received a digital passport credential can prove their “age is <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mrow> <mml:mo>&gt;</mml:mo> <mml:mn>18</mml:mn> </mml:mrow> </mml:math> ” without revealing any other attributes such as their name or date of birth. Despite their clear application to privacy-preserving authentication, anonymous credential schemes have been difficult to deploy at scale. Part of the difficulty arises because schemes in the literature, such as BBS+, use new cryptographic primitives that require system-wide changes to existing issuer infrastructure. In addition, issuers often require digital identity credentials to be device-bound by incorporating the device’s secure element into the presentation flow. As a result, schemes like BBS+ require updates to the hardware on every user's device. We propose new ZK techniques which enable the construction of an anonymous credential scheme for the legacy Elliptic Curve Digital Signature Algorithm (ECDSA) signature scheme. By adding efficient ZK arguments for statements about SHA-256 and document parsing for ISO-standardized identity formats, we construct the first ZK proof of posession of a credential that can be deployed without changing any issuer processes, without changes to mobile devices, and without requiring non-standard cryptographic assumptions. Furthermore, our proof system itself only relies on SHA-256 as its complexity assumption. Producing ZK proofs about ECDSA signatures has been a bottleneck for other ZK proof systems because standardized curves such as P256 use finite fields which do not support efficient number theoretic transforms. We overcome this bottleneck by designing a ZK proof system around sumcheck and the Ligero argument system, by designing efficient methods for Reed-Solomon encoding over the required fields, and by designing specialized circuits for ECDSA. Our proofs for ECDSA can be generated in as little as <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mrow> <mml:mo>≈</mml:mo> <mml:mn>20</mml:mn> </mml:mrow> </mml:math> ms. When incorporated into a fully standardized identity protocol such as the ISO MDOC standard, our system can generate a zero-knowledge proof for the MDOC presentation flow in a few hundred ms on mobile devices. These advantages make our scheme a promising candidate for privacy-preserving digital identity applications.

Open access
Cryptography and Data Security
Cryptography and Residue Arithmetic
Advanced Authentication Protocols Security
Original source