Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

448 papersLast indexed Aug 31, 2026
Search papers

Paper index

448 results · page 2 of 19

Clear filters
Feb 1, 2026·Proceedings on Privacy Enhancing Technologies
0 cites
The Masks We (Think We) Wear: Privacy Threats of Browser-Extension Wallets in the Web3 Ecosystem

Weihong Wang, Yana Dimova, Victor Vansteenkiste, Tom Van Goethem · 5 authors

Cryptocurrency wallets are the primary interface for managing pseudonymous blockchain addresses, viewing balances, and interacting with Web3 applications. Although users typically assume that their addresses remain independent of each other unless intentionally revealed, modern wallets routinely communicate with both blockchain infrastructure and decentralized applications (dApps), generating network-side and web-side signals that may undermine this assumption. In this paper, we identify and formalize five privacy threats that arise directly from wallets interacting with the network and the web browser. Using large-scale dynamic measurements of 85 of the most popular Chrome Web Store browser-extension wallets (representing 35.16 million users), we observe that routine remote procedure call (RPC) operations leak structural links between a user's addresses; that the majority of Ethereum wallets implement permission revocation inconsistently and continue to expose previously revoked addresses across sessions; and that many wallets inject their provider interfaces into cross-origin iframes, enabling passive cross-site tracking beyond dApps and potentially real-world identity deanonymization without user interaction. Taken together, our results show that these wallet behaviors leak sensitive information that can be used to link multiple addresses to the same user, track wallet users across sessions and sites, and connect their browsing activity to their on-chain wealth. We discuss practical mitigations and show that many of these threats can be substantially reduced through improved wallet implementation, stronger privacy considerations in ecosystem standards, and stricter controls over provider exposure. Our results highlight the need for standardized, privacy-preserving wallet architectures and provide actionable guidance for strengthening user privacy in the emerging Web3 ecosystem.

Open access
5 source records
Privacy, Security, and Data Protection
Advanced Malware Detection Techniques
Spam and Phishing Detection
Original source
Jan 1, 2026·SSRN Electronic Journal
0 cites
The Shield of Time: Anchoring IoT Trust in Non-Simulatable Physical Causality Against Generative AI Attacks

Yihang Wu

As Generative AI (AIGC) achieves pixel-level realism and real-time interaction; traditional digital authentication paradigms face an unprecedented "authenticity crisis". Software-level defenses and static biometrics are increasingly vulnerable to high-fidelity AI-generated threats. This paper proposes a novel Human-Source Authentication architecture, termed Testing, Inspection, and Certification (TIC), which shifts the verification focus from logical correctness to the real-time presence of a physical entity. At the core of TIC is the Pulse-Eye Handshake (PEH) protocol, which integrates hardware-level Physical Unclonable Functions (PUF) with the physiological dynamics of the human pupillary light reflex (PLR). By leveraging a "Hardware Trinity" comprising smart glasses, a smartwatch, and a smart ring, the protocol constructs a deterministic "Shield of Time". This shield exploits the significant latency gap between the computational overhead of AI inference (typically >300ms) and the intrinsic physical limits of the human autonomic nervous system (8.3-35ms). Furthermore, architecture employs recursive zero-knowledge proof (ZKP) based on the Nova protocol to ensure multi-modal verification without compromising user privacy. Security analysis demonstrates that the proposed system remains robust against sophisticated modeling attacks and AI-driven acceleration. Our work provides a foundational anchor for digital sovereignty and system resilience in the era of pervasive AI and Industry 5.0.

Open access
Physical Unclonable Functions (PUFs) and Hardware Security
User Authentication and Security Systems
Adversarial Robustness in Machine Learning
Original source
Jan 1, 2026·SSRN Electronic Journal
0 cites
Punycode, Unicode & Multilingual Digital Identities in Web3 through Handshake Domains

Sina Khoshtarkib zenoozi

The internet was architected on a 128-character encoding that systematically excluded billions of speakers of Arabic, Chinese, Persian, Turkish, Hindi, and every other non-Latin script. Two interlocking standards broke that constraint: Unicode — the universal map of every human character to a unique codepoint — and Punycode (RFC 3492), which translates Unicode into ASCII-compatible encodings the legacy Domain Name System can process. The emergence of Handshake (HNS), a decentralised proof-of-work naming blockchain, extends this capability into Web3 without any central gatekeeper. Handshake allows any individual to auction, own, and resolve top-level domains in any script — including emoji — through sovereign cryptographic ownership.

Open access
User Authentication and Security Systems
Digital Communication and Language
Web Application Security Vulnerabilities
Original source
Dec 11, 2025·Zenodo (CERN European Organization for Nuclear Research)
0 cites
GuardIQ: A Post-Quantum Secure VIP Threat Detection and Monitoring Platform Using AI-Powered Intelligence and Biometric Authentication

Vanshika Joshi Sneha DL and Shruti M Jolad

ABSTRACT In the contemporary digital landscape, high-profile individuals including celebrities, executives, political leaders, and public officials face unprecedented threats from online impersonation, sophisticated misinformation campaigns, AI-generated deepfakes, and fraudulent social media profiles. The convergence of generative artificial intelligence technologies and social media platforms has dramatically expanded the attack surface, enabling malicious actors to create synthetic identities, manipulate multimedia content, and spread false narratives with alarming ease and speed. Existing security solutions remain fragmented, requiring extensive manual intervention and lacking the capability for real-time monitoring and automated threat response, thereby leaving critical gaps in digital protection for vulnerable public figures. This research paper presents GuardIQ, an integrated, fully automated, end-to-end VIP Threat Detection and Monitoring Platform that combines post-quantum cryptography, multi-factor biometric authentication, artificial intelligence-powered threat detection, and blockchain-based evidence preservation. The platform architecture is built upon seven core pillars: quantum-secure biometric registration utilizing Kyber Key Encapsulation Mechanism (KEM), real-time threat detection engine monitoring multiple social media platforms, AI-powered content verification distinguishing authentic media from AI-generated deepfakes, automated fake profile detection comparing discovered accounts against registered handles, live analyzer for instant authenticity verification, immutable evidence collection using Web3 technologies, and unified dashboard providing comprehensive threat intelligence visualization. GuardIQ employs CRYSTALS-Kyber post-quantum cryptographic algorithms (Kyber512 for lightweight mobile endpoints and Kyber768/1024 for enterprise deployments) combined with AES-256-GCM symmetric encryption to ensure quantum-resistant data protection. The biometric registration module captures facial recognition data, voice patterns, gesture signatures, and official social media handles, all protected through quantum-safe encryption. Large Language Models (LLMs) integrated within the threat detection engine perform real-time classification of suspicious content, achieving 92-97% accuracy in identifying impersonation attempts, misinformation campaigns, and image misuse across platforms including Twitter, Facebook, Instagram, and LinkedIn. The AI content detection module leverages advanced deep learning architectures including Convolutional Neural Networks (CNNs) for image analysis, Recurrent Neural Networks (RNNs) for sequential pattern detection, and transformer-based models for multimedia authenticity verification. Experimental results demonstrate the system's capability to distinguish AI-generated content from authentic material with confidence scores exceeding 94%, providing early detection of deepfakes and synthetic media targeting VIP credibility. The fake profile detection algorithm analyzes multiple parameters including account creation timestamps, username patterns, biographical information, follower-to-following ratios, engagement metrics, and posting behavior patterns to identify fraudulent accounts with 89% precision. Evidence collection is facilitated through Web3-based blockchain infrastructure ensuring tamper-proof, immutable storage of all flagged incidents, suspicious posts, and detected impersonations. This cryptographically verifiable evidence chain supports legal proceedings and investigative actions by providing irrefutable proof of malicious activities. The unified dashboard aggregates threat intelligence from all modules, presenting real-time alerts, authenticity scores, risk assessments, and recommended remediation actions through intuitive visualizations requiring minimal manual oversight. Performance evaluation reveals that post-quantum TLS handshakes introduce only 5-10 milliseconds additional latency compared to classical TLS implementations, demonstrating practical feasibility for production deployment. The automated threat detection pipeline reduces incident response time by 72% compared to manual monitoring approaches, while the quantum-resistant encryption framework ensures long-term security against emerging quantum computing threats. System architecture supports horizontal scalability through microservices deployment, containerization using Docker and Kubernetes orchestration, and cloud-native infrastructure compatible with AWS, Azure, and Google Cloud Platform. This research addresses the urgent need for comprehensive digital protection solutions in an era where AI-generated content, quantum computing capabilities, and sophisticated social engineering attacks converge to create unprecedented risks for public figures. GuardIQ represents a paradigm shift from reactive security measures to proactive, automated threat intelligence platforms capable of defending high-profile individuals against modern digital adversaries while maintaining usability, scalability, and legal compliance. Keywords : VIP Protection, Post-Quantum Cryptography, Kyber KEM, Deepfake Detection, AI Content Verification, Biometric Authentication, Threat Intelligence, Social Media Monitoring, Blockchain Evidence, Web3 Security, Impersonation Detection, Misinformation Prevention, Large Language Models, Zero- Trust Architecture, Quantum-Safe Encryption, Identity Verification, Automated Security Response, Digital Reputation Management

Open access
2 source records
User Authentication and Security Systems
Face recognition and analysis
Biometric Identification and Security
Original source
Nov 30, 2025·International Journal For Multidisciplinary Research
0 cites
NEUROID:EEG-Based Brainwave Authentication System

Shreyas Wakhare, Eshaan Warade, Parth Yangandul, Shagufta Sheikh

This study introduces a functional EEG-based Multi-Factor Authentication (EEG-MFA) system engineered for accessibility and security utilizing affordable consumer hardware. Our version uses the BioAmp EXG Pill ( |3,000) with Arduino UNO, which is far cheaper than standard biometric systems that need expensive medical-grade equipment (|50,000–|500,000). It gets 86.7% authentication accuracy when the signal is good.The system uses three authentication factors: a password (knowledge), a pattern (behavior), and an EEG biometric (inherence). This makes it more secure. We utilize One-Class SVM with RBF kernel (nu=0.1) for user modeling, which means we don’t have to collect fake data, which is a big problem when using biometrics. The system learns brain patterns unique to each user using just 3–5 enrollment recordings (12 seconds each) and a simple electrode setup (3 electrodes: forehead + ears).Recent improvements in open-source EEG gear have made it much cheaper. With devices like the BioAmp EXG Pill (around 3,000 rupees), OpenBCI boards (100–500 dollars), and NeuroSky MindWave (100 dollars), students can do projects and small-scale research that weren’t possible before with medical-grade equipment. This lower price makes it possible to look into EEG authentication outside of established labs, utilizing real-world consumer technology that has its own problems. Some of the most important new features are: (1) an adaptive learning mechanism that lowers the False Rejection Rate from 20% to 0% over five sessions while keeping the False Acceptances at zero; (2) a tolerance margin system (10%) that makes up for differences in electrode placement; and (3) a complete end-to-end implementation with FastAPI backend, PostgreSQL database, and Next.js frontend.When we tested with real consumer hardware, we found that the most important performance aspect was signal quality (electrode preparation). With the right setup, we got an 80% genuine acceptance rate and a 0% imposter acceptance rate. The 10% Equal Error Rate (EER) is higher than medical-grade systems (¡5%), but it shows that it is possible to use it for specialized security applications, educational research, and proof-of-concept deployments where cost is more important than accuracy.

Open access
EEG and Brain-Computer Interfaces
ECG Monitoring and Analysis
User Authentication and Security Systems
Original source
Nov 29, 2025·Zenodo (CERN European Organization for Nuclear Research)
0 cites
The Future of Point-of-Sale User Experience in Ledger-Native Payments

CTAP

Ledger-native payment systems introduce a radically new interaction paradigm at the point of sale. Rather than relying on legacy card-based processing networks, these systems enable merchant devices and user devices to collaboratively perform the construction, authorization, signing, and broadcasting of a transaction directly to a digital ledger. Once biometric authentication is performed on the user’s device, the remaining steps of the payment flow may be distributed flexibly between the devices. This shift allows the point-of-sale environment to evolve into an expressive, adaptive, and deeply interactive interface layer. This white paper presents a comprehensive exploration of the experiential landscape surrounding ledger-native payments, mapping the full set of user-experience, sensory, identity, environmental, and data-driven capabilities that emerge once retail transactions operate directly on a cryptographic substrate. The document is fully self-contained and articulates the future UX domain rather than any specific implementation.

Open access
2 source records
Blockchain Technology Applications and Security
User Authentication and Security Systems
Digital Platforms and Economics
Original source
Oct 29, 2025·International Journal of Innovative Science and Research Technology
0 cites
Strengthening Web3 Data Confidentiality Through Blockchain-Enabled Multifactor Authentication: A Comparative Security Evaluation

Asheshemi Nelson Oghenekevwe, Okoro Akpohrobaro Daniel, Ayeh Blessing Elohor, Ayo Michael Ifioko · 6 authors

Developments of Web 3.0 technologies present vital problems regarding data confidentiality, authentication of users and their privacy in decentralised systems. The traditional multifactor authentication (MFA) systems have been effective when deployed in Web2 environments but have failed in protecting sensitive information in the decentralised environment because they use centralised servers and are also dependent on static security factors. The paper explores the concept of multifactor authentication that is based on blockchain technology as the effective method of improving the use of data confidentiality in Web3. A blockchain-augmented MFA infrastructure was created on the basis of an Ethereum smart contract, decentralised storage, and biometric data that were cryptographically encrypted. Simulation demonstrated significant increases in security relative to conventional MFA systems, a significant drop in the probability of breaching (0.0270 to 0.0040), an improvement in the entropies, a decrease in the likelihood of session hijacking, and limited mutual information leakage. Also, the blockchain-based system becomes more resistant to Man-in-the-Middle (MITM) and phishing attacks, mitigating them by about 60 per cent and 50 per cent success rates, respectively. Whereas the blockchain MFA made some minor sacrifices in latency and computation cost in the course of authentication, such a trade of costs is productive in the Web3 environment where security and data integrity remain of utmost importance. The study could be useful to developers, security practitioners and policymakers who intend to develop more secure, scalable, and user-centric authentication mechanisms in decentralised apps. As a potential improvement, it is suggested that future research should implement the aspect of consensus optimisation and Layer-2 to increase the efficiency and scalability further.

Open access
Web Application Security Vulnerabilities
Blockchain Technology Applications and Security
User Authentication and Security Systems
Original source
Oct 9, 2025·Internet of Things
3 cites
DIDAuth-IoTFW: Decentralized firmware authentication for smart home IoT devices using verifiable credentials

W. M. A. B. Wijesundara, Joong-Sun Lee, Eleni Aloupogianni, Dara Tith · 6 authors

Rapid proliferation of smart home IoT devices has intensified the demand for secure, scalable, and autonomous firmware authentication mechanisms. Traditional centralized solutions face challenges related to privacy concerns, limited scalability, and vulnerability to single point of failure. In this paper, we propose DIDAuth-IoTFW, a novel decentralized identity and firmware authentication framework that uniquely integrates Ethereum Layer-2 Arbitrum, InterPlanetary File System (IPFS), and W3C-compliant Decentralized Identifiers (DIDs) and Verifiable Credentials (VCs). DIDAuth-IoTFW provides a complete firmware authentication life cycle, from decentralized identity registration to real-time, on-chain verifiable revocation. While enabling autonomous, cryptographic verification directly on resource-constrained IoT devices and ensuring reliable performance even when gateways are compromised or unavailable. Our proof-of-concept implementation on ESP32 and Raspberry Pi achieved complete resistance to replay, forgery, and revocation threats with verification consistently under 1.2 s. Compared to prior work, DIDAuth-IoTFW uniquely combines firmware–VC hash binding, contract binding that prevents cross-registry replay, and device-side enforcement resilient to gateway compromise. Experimental results indicate a robust, privacy-preserving, and scalable alternative to centralized firmware-update pipelines for smart-home IoT.

Open access
User Authentication and Security Systems
Advanced Authentication Protocols Security
Blockchain Technology Applications and Security
Original source
Oct 9, 2025·Array
3 cites
Hybrid and adaptive framework for secure and scalable authentication in healthcare IoT

Razi Iqbal, Muhammad Afzaal, Geetanjali Rathee

The rapid adoption of Internet of Things (IoT) in Healthcare has significantly enhanced real-time patient monitoring and decision making. However, security and privacy still remain the major concern due to sensitive medical data of patients especially on low-power IoT devices. Traditional authentication schemes like Zero Knowledge Proof (ZKP) and Elliptic Curve Cryptography (ECC) often struggle with efficiency in resource-constraint environments due to their computational overhead. In order to address these challenges, we propose a Neural-Based Hybrid and Adaptive Framework that combines Schnorr ZKP with Kyber-based key encapsulation, using a neural network to dynamically select Kyber variants (512, 768, 1024) based on device parameters (type, authentication time, transmission time) to balance security and efficiency for low-power IoT devices. Extensive experiments validated robust security against replay and spoofing attacks, achieving authentication success for legitimate clients and zero attack successes. Furthermore, our proposed framework outperforms traditional Kyber1024 and ZKP/ECC based authentication schemes in terms of authentication time and computational overhead making it robust and scalable solution for sensitive and resource-limited environments like HealthCare IoT systems. • Design a novel hybrid authentication framework that integrates ZKP and Kyber PQC (Post Quantum Cryptography) to ensure secure and efficient authentication for IoT healthcare devices. • Utilize Neural Network to intelligently select the most appropriate Kyber variant based on threat level and computational efficiency. • Provide comprehensive experimental analysis comparing the proposed hybrid and adaptive framework with traditional ZKP, ECC and static Kyber implementations.

Open access
User Authentication and Security Systems
Advanced Authentication Protocols Security
Biometric Identification and Security
Original source
Oct 7, 2025·The Journal of Supercomputing
6 cites
Anonymous authentication based on blockchain and zero-knowledge proof for vehicular ad hoc networks

Xingxing Chen, Xiaohong Zhang, Shaojiang Zhong, Shuling Liu

Vehicular Ad Hoc Networks (VANETs) are now a pivotal component of Intelligent Transportation Systems. However, ensuring secure vehicle identity authentication and protecting user privacy remain two challenging issues in VANETs. Addressing these challenges, this paper seamlessly integrates blockchain technology with the InterPlanetary File System to realize a fully decentralized storage solution for identity verification information. Simultaneously, it employs zk-SNARK and elliptic curve cryptography to allow vehicle users to anonymously complete identity verification. Additionally, the lightweight identity authentication proof obtained after successful verification maintains credibility while reducing the computational and communication costs for both roadside units and vehicles. The security and performance analysis of the system show that the proposed scheme has significant advantages in both communication and computation compared with similar research, while also offering superior security and a broader range of functional attributes compared to existing competitive approaches.

Open access
Vehicular Ad Hoc Networks (VANETs)
User Authentication and Security Systems
Autonomous Vehicle Technology and Safety
Original source
Aug 31, 2025·Journal of Computers Mechanical and Management
8 cites
Blockchain-Based Framework for Secure Communication in Smart IoT Systems

Chetan Chauhan, Pradeep Laxkar, Ram Kumar Solanki, S. R. Parihar · 6 authors

Blockchain technology has emerged as a promising paradigm for addressing the inherent vulnerabilities of Internet of Things (IoT) networks. Conventional IoT systems rely on centralized architectures that are prone to single points of failure, data breaches, and unauthorized access. This paper presents a blockchain-enabled secure communication framework for smart IoT systems that integrates symmetric encryption, distributed ledger validation, and smart-contract–driven access control. The proposed model is formalized through mathematical definitions of encryption, hashing, and contract execution, and validated using simulation tools such as NS-3 and Ethereum-based test environments. Comparative results demonstrate that the framework significantly improves communication security, data integrity, and resistance to cyberattacks while reducing latency and energy consumption relative to traditional models. The findings suggest that blockchain integration provides a scalable, resilient, and efficient foundation for trustworthy IoT communication in smart environments.

Open access
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
User Authentication and Security Systems
Original source
Aug 10, 2025·arXiv (Cornell University)
0 cites
Understanding NFTs from EIP Standards

Minfeng Qi, Qin Wang, Guangsheng Yu, Ruiqiang Li · 6 authors

We argue that the technical foundations of non-fungible tokens (NFTs) remain inadequately understood. Prior research has focused on market dynamics, user behavior, and isolated security incidents, yet systematic analysis of the standards underpinning NFT functionality is largely absent. We present the first study of NFTs through the lens of Ethereum Improvement Proposals (EIPs). We conduct a large-scale empirical analysis of 191 NFT-related EIPs and 10K+ Ethereum Magicians discussions (as of July, 2025). We integrate multi-dimensional analyses including the automated parsing of Solidity interfaces, graph-based modeling of inheritance structures, contributor profiling, and mining of community discussion data. We distinguish foundational from emerging standards, expose poor cross-version interoperability, and show that growing functional complexity heightens security risks.

Open access
2 source records
cs.CR
cs.ET
User Authentication and Security Systems
Original source
Jul 30, 2025·Blockchain Research and Applications
1 cites
SmartBLock: a smart lock protocol over the Bitcoin blockchain

Mohsen Rahmanikivi, Cristina Pérez‐Solà, Víctor Garcia-Font

This paper introduces “SmartBLock”, a novel protocol that integrates smart lock management with the Bitcoin blockchain. By employing blockchain technology, the SmartBLock protocol eliminates the need for centralized databases (reducing the risk of data breaches) and ensures accountability for all access events. Authentication is accomplished through Bitcoin's cryptographic signature scheme. Additionally, SmartBLock is an open and manufacturer-agnostic protocol, relying on the open and permissionless Bitcoin blockchain rather than proprietary tools or protocols. Given the limited computational capabilities of Internet of Things (IoT) devices, achieving this integration presents a significant challenge. This paper provides a comprehensive review of the state of the art in smart lock protocols, details the design of the SmartBLock protocol, presents a proof-of-concept prototype to validate its feasibility, and offers a meticulous analysis of its security, privacy, and traceability features. • Literature review on blockchain-integrated smart locks. • Propose a smart lock protocol on Bitcoin for immutable and transparent management. • Provide a demonstration that the protocol is secure, private, and transparent. • Build a PoC for the proposal on an IoT device and gather evidence of its feasibility.

Open access
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
User Authentication and Security Systems
Original source
Jul 25, 2025·Frontiers in Blockchain
4 cites
A man–vehicle e-passport system using biometric blockchain for automated border control

Bing Xu, Ahmed Bouridane, Qiang Ni, Richard Jiang

Since the mid-1990s, the evolution of internet technologies has significantly transformed global connectivity and digital interaction. Today, advances in computing and networking continue to support the development of emerging paradigms such as the metaverse and digital twins—concepts that aspire to bridge physical and digital experiences. Parallel to this, blockchain technology is reshaping traditional notions of trust by enabling immutable transaction records and smart contract automation, thereby fostering the rise of decentralized autonomous organizations (DAOs). Building on these foundations, this study presents a biometric blockchain-based e-passport system designed to improve the operational efficiency of automated border control (ABC) systems. At the core of our approach is the concept of a DAO-inspired framework for border control wherein identity verification and management tasks are executed through atomic smart contracts and recorded immutably on the blockchain. Our system incorporates biometric authentication and decentralized identity features to digitize border documentation and automate verification processes. This creates a secure, verifiable digital representation of an individual’s identity that can interact with ABC workflows. Performance evaluations conducted using Hyperledger Caliper demonstrate the potential of the proposed system, showing a 3.5-fold improvement in processing efficiency compared to traditional ABC setups.

Open access
Blockchain Technology Applications and Security
User Authentication and Security Systems
Original source
Jul 23, 2025·Journal of King Saud University - Computer and Information Sciences
10 cites
A quantum-resilient lattice-based security framework for internet of medical things in healthcare systems

Zeyad Ghaleb Al-Mekhlaf, Murtaja Ali Saare, Jalal Mohammed Hachim Altmemi, ‪Mahmood A. Al-Shareeda‬‏ · 9 authors

The rapid adoption of Internet of Medical Things (IoMT) devices enables real-time patient monitoring and remote diagnostics and has revolutionized healthcare delivery. Traditional cryptographic schemes like RSA and ECC, which rely on meaningful mathematical challenges, are under great threat from quantum computing, threatening sensitive medical data confidentiality and integrity. This paper proposes a quantum-resistant healthcare security framework based on lattice-based cryptographic primitives such as Learning With Errors (LWE), Ring-LWE (RLWE), and Short Integer Solution (SIS). To this end, we design a five-phase IoMT-friendly framework—Initialization, Registration, Authentication, Data Exchange, and Treatment—where each phase is backed up by lightweight cryptography primitives that can be easily implemented on the low-resource IoMT devices. Relative to the state-of-the-art lattice- and hash-based constructions, our framework involves 50-75% smaller ciphertext sizes, up to a 50% reduction of the communication overhead, and nearly 60% less in computational cost. Furthermore, the solution relies on zero-knowledge proofs, homomorphic encryption as well and attribute-based access control to guarantee strong security and privacy. Using the AVISPA tool, the framework is formally verified, showing its resistance against classical and quantum adversaries. Focusing on tangible healthcare threats, including data tampering and unlicensed access to patient diagnostics, this research paves the way for scalable, efficient, and quantum-resistant medical data protection. Our results pave the way for future investigations into secure post-quantum healthcare and IoT applications.

Open access
User Authentication and Security Systems
Advanced Authentication Protocols Security
Cryptography and Data Security
Original source
Jul 2, 2025·Distributed Ledger Technologies Research and Practice
2 cites
Implementation of Privacy-Preserving Identifiers for the Secure Storage of Electronic Health Records on the Ethereum Blockchain

Swati Kumari, Hitesh Tewari

Patients and healthcare authorities frequently lack confidence in one another when it comes to the security of their medical records in healthcare settings. Particularly when it comes to patient data management, hospitals are infamous for having inadequate security and have long been the target of cyberattacks. Using blockchain technology to store medical records has drawbacks, including an excessive dependence on centralised cloud servers for key storage, privacy concerns and the potential for attackers to deduce personal information about patients based on their blockchain activity. A system where patients have autonomy over their medical records and who can view them is a promising scenario. This article provides a framework for indexing and securing a user’s medical records, with emphasis placed on the healthcare setting using an Ethereum blockchain. The records are secured using biometric authentication and the patient’s Personal Identifiable Information (PII). The patient can grant and revoke access to their records to individual healthcare authorities, and the Interplanetary Name System (IPNS) is used for off-chain record storage. The framework is modular and can be adapted for use in other environments, such as proof of ownership of tickets, and storing travel documents for verification by border control. A smart contract is used to store the hashes of the patient’s iris scans on an Ethereum Virtual Machine (EVM) compatible blockchain. Privacy-preserving identifiers are used to anonymise the patient and where their records are stored on the blockchain. Our approach is to the best of our knowledge the only one that simultaneously offers encryption, anonymity, unlinkability and efficient off-chain storage. Additionally, our approach is the only approach we are aware of that provides record revocability.

Open access
Biometric Identification and Security
User Authentication and Security Systems
Blockchain Technology Applications and Security
Original source
Jun 24, 2025·arXiv (Cornell University)
0 cites
ZK-SERIES: Privacy-Preserving Authentication using Temporal Biometric Data

Daniël Reijsbergen, Eyasu Getahun Chekole, Howard Halim, Jianying Zhou

Biometric authentication relies on physiological or behavioral traits that are inherent to a user, making them difficult to lose, forge or forget. Biometric data with a temporal component enable the following authentication protocol: recent readings of the underlying biometrics are encoded as time series and compared to a set of base readings. If the distance between the new readings and the base readings falls within an acceptable threshold, then the user is successfully authenticated. Various methods exist for comparing time series data, such as Dynamic Time Warping (DTW) and the Time Warp Edit Distance (TWED), each offering advantages and drawbacks depending on the context. Moreover, many of these techniques do not inherently preserve privacy, which is a critical consideration in biometric authentication due to the complexity of resetting biometric credentials. In this work, we propose ZK-SERIES to provide privacy and efficiency to a broad spectrum of time series-based authentication protocols. ZK-SERIES uses the same building blocks, i.e., zero-knowledge multiplication proofs and efficiently batched range proofs, to ensure consistency across all protocols. Furthermore, it is optimized for compatibility with low-capacity devices such as smartphones. To assess the effectiveness of our proposed technique, we primarily focus on two case studies for biometric authentication: shake-based and blow-based authentication. To demonstrate ZK-SERIES's practical applicability even in older and less powerful smartphones, we conduct experiments on a 5-year-old low-spec smartphone using real data for two case studies alongside scalability assessments using artificial data. Our experimental results indicate that the privacy-preserving authentication protocol can be completed within 1.3 seconds on older devices.

Open access
Biometric Identification and Security
User Authentication and Security Systems
Original source
Jun 17, 2025·PLoS ONE
0 cites
A ZKP-based anonymous biometric authentication scheme for the E-health systems

Xuechun Mao, Xiaqing Zhou, Xiaoming Zhao, Ying Chen

The widespread adoption of e-health systems raises critical concerns regarding data privacy and network security. Ensuring secure and reliable data sharing between patients and healthcare professionals remains a significant challenge. To address this, we propose a novel anonymous authentication scheme tailored for e-health environments, integrating zero-knowledge proof (ZKP) with multimodal biometrics. Our key contributions are as follows: (1) applying the Pedersen vector commitment algorithm to construct a biometric-based ZKP scheme, thereby ensuring enhanced security and privacy-preserving authentication; (2) utilizing multimodal cancelable biometrics generate (MCBG) technology, integrating fingerprint, face, and iris modalities to strengthen the security of the verification process; and (3) providing a detailed security analysis that demonstrates our scheme meets essential security requirements, including anonymity, authenticity, unlinkability, forward security, and resistance to replay attacks. Experimental results demonstrate stable proving and verification time of approximately 78 ms and 140 ms, respectively, regardless of the proof range, validating its efficiency and practicality for secure authentication in e-health systems.

Open access
Biometric Identification and Security
User Authentication and Security Systems
Advanced Authentication Protocols Security
Original source
Jun 7, 2025·DOAJ (DOAJ: Directory of Open Access Journals)
0 cites
Integration of Citizen’s Card Digital Authentication in Hyperledger

Machado Antunes, Carlos, Maximiano, Marisa, Távora, Vítor, Gomes, Ricardo · 6 authors

This study investigates the integration of the Portuguese Citizen’s Card authentication with Hyperledger Fabric blockchain technology, addressing the challenge of bridging traditional government-issued digital identities with blockchain-based systems, particularly focusing on reducing barriers to Web3 adoption for users unfamiliar with decentralized technologies. The proposed solution leverages the Autenticação.gov Software Development Kit (SDK), developed by the Portuguese Agency for Administrative Modernization (AMA) to create a secure bridge between the Citizen’s Card authentication system and Hyperledger Fabric's permissioned blockchain framework. The study examines how this approach can facilitate the development of transparent, tamper-proof authentication systems suitable for critical applications such as e-voting and digital government services, and also feasible for on-premises systems. The findings suggest that integrating existing digital identity systems with blockchain technology can promote wider acceptance of decentralized solutions while maintaining security, privacy, and accessibility standards required for public sector applications.

Open access
Blockchain Technology Applications and Security
User Authentication and Security Systems
Privacy, Security, and Data Protection
Original source
Jun 5, 2025·Scientific Reports
36 cites
A lightweight scalable hybrid authentication framework for Internet of Medical Things (IoMT) using blockchain hyperledger consortium network with edge computing

Abdullah Ayub Khan, Asif Ali Laghari, Roobaea Alroobaea, Abdullah M. Baqasah · 7 authors

The Internet of Things (IoMT) has revolutionized the global landscape by enabling the hierarchy of interconnectivity between medical devices, sensors, and healthcare applications. Significant limitations in terms of scalability, privacy, and security are associated with this connection. This study presents a scalable, lightweight hybrid authentication system that integrates blockchain and edge computing within a Hyperledger Consortium network to address such real-time problems, particularly the use of Hyperledger Indy. For secure authentication, Hyperledger ensures a permissioned, decentralized, and impenetrable environment, while edge computing lowers latency by processing data closer to IoMT devices. The proposed framework balances security and computing performance by utilizing a hybrid cryptographic technique, like NuCypher Threshold Proxy Re-Encryption. Applicational activities are now appropriate for IoMT devices with limited resources thanks to this integration. By facilitating cooperation between numerous stakeholders with restricted access, the consortium network improves scalability and data governance. Comparing the proposed framework to the state-of-the-art techniques, experimental evaluation shows that it reduces latency by 2.93% and increases authentication efficiency by 98.33%. Therefore, in contrast to current solutions, guarantee data integrity and transparency between patients, consultants, and hospitals. The development of dependable, scalable, and secure IoMT applications is facilitated by this work, enabling next-generation medical applications.

Open access
Blockchain Technology Applications and Security
User Authentication and Security Systems
Advanced Authentication Protocols Security
Original source
May 23, 2025·Journal of Computational Science
2 cites
Resilient authentication protocol for electronic healthcare enabled wireless body area networks using distributed ledger

Munir Hussain, Amjad Mehmood, Muhammad Altaf Khan, Jaime Lloret · 5 authors

The recent developments in telecommunication technologies and monitoring devices have brought many changes in modern electronic healthcare systems (EHSs) by improving quality and decreasing healthcare expenses. Despite the benefits, they have privacy and security issues because the communication between patients and service providers takes place generally over public channels. Several user authentication protocols using distributed ledger technology (DLT) have recently been proposed to address these issues in EHSs. However, many are still vulnerable to a single point of failure (SPoF), privacy, and security attacks. Besides, they suffered from high communication and computational costs. Therefore, in this paper, we proposed a user authentication protocol using DLT to avoid these issues. A Burrows-Abadi-Needham (BAN) logic proof method has been used to check the security of the proposed protocol and ensure it achieves the desired security goals. In addition, an informal security analysis has been conducted to verify its important security requirements. A formal security analysis has been performed via the Automated Validation of Internet Security Protocols and Applications (AVISPA) tool and Real-or-Random (ROR) model for further security strength. The results demonstrate that the proposed user authentication protocol is SAFE against all types of Man-in-the-Middle (MitM) attacks, impersonation, replay, and forgery attacks . Finally, performance analysis has been performed and results show that it achieves better performance by consuming 29.63 % and 13.21 % less communication and computational overheads as compared to existing related user authentication protocols. The security and performance analysis make it a more appropriate choice for the EHSs.

Open access
Advanced Authentication Protocols Security
User Authentication and Security Systems
Wireless Body Area Networks
Original source
May 10, 2025·Ain Shams Engineering Journal
16 cites
Privacy-preserving authentication for 5G healthcare with HBZKP: Hierarchical blockchain-based zero knowledge proof for secure edge devices

V. Maheshwari, M. Prasanna

Objective: The combination of 5G connectivity and edge computing known as 5G Edge, lifts the limitations of the Internet of Medical Things (IoMT) and enables a plethora of authentic healthcare services, including access to medical information and diagnosis. Additionally, there is a chance that malicious insiders using the 5G Edge platform could compromise the security and confidentiality of IoMT data. As a result, end users cannot trust 5G Edge data. Materials and methods: This paper imagines a new hierarchical blockchain edge of things (HBEoT) architecture that would facilitate healthcare applications managed by blockchain at the network edge. Additionally, the article delves into how HBEoT can offer security services such as authenticating users, protecting data, detecting attacks, and managing trust. First, the consensus method PoS generates a block for healthcare data, and its hash values are kept in the blockchain. The Zero Knowledge Proof (ZKP) protocol stores secret information in the blockchain, authenticating healthcare systems for enhanced privacy and security. Results: To ensure immutable data storage, the suggested architecture incorporates 5G Edge servers into a blockchain platform. It prevents unauthorised users from accessing healthcare services by acting as an anonymous authenticator. We assessing the proposed methods efficiency in terms of latency, throughput, communication cost, energy consumption cost and the validation between ZKP prover and verifier. Conclusion: We conduct multiple experiments to evaluate the effectiveness of the suggested framework. To further investigate the quality measures, such as authenticate latency, throughput rate was examined. To fulfil the requirements for a 5G-enabled healthcare system, the research shows that the suggested HBEoT-ZKP performs a decrease in latency of around 1.16 s and an improvement in throughput of approximately 339 tps. Communication and energy cost is evaluated and compared with other conventional methods.

Open access
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
User Authentication and Security Systems
Original source