The Digital Product Passport (DPP) is a cross-sectoral framework for sharing data across value chains to promote circular economy practices such as repair, reuse, and recycling. A key challenge is ensuring trust and integrity in DPP data, which is often fragmented among multiple stakeholders. Distributed ledger technologies (DLTs) ofer a promising solution by enhancing data integrity, transparency, and reliability. However, a comprehensive understanding of how DLTs can support DPPs remains underexplored. This paper reviews academic and industrial initiatives using DLTs to build trustworthy DPP infrastructures. It identifies three core benefits of DLTs for DPPs: (1) tamper-proof data integrity for traceability, (2) peer-to-peer private data sharing without central authority, and (3) decentralized DPP lifecycle management, from creation to deactivation. Based on these findings, the paper proposes design guidelines to inform the development of DLT-based DPP systems that can support long-term trust and collaboration in circular economy ecosystems.
Kent Douglas Lambert, Tom Bradley, John M. Borky, Steve Simske · 6 authors
This research identifies a set of practical solutions to the uncontrolled growth of malicious cross-industry cybersecurity threats. Given the presence of the behaviors and negative effects of cyber threats, the research seeks to understand the effects of three eco-system-wide strategies for cyber defense: Defense-in-Depth (DiD), Zero-Trust Architectures (ZTA), and secure cryptographic key provisioning. These strategies are developed using the BlockFrame, Inc., Eco-Secure Provisioning™ (ESP™) Framework, blockchain-assisted digital logistics management and governance, and the application of Emergence Theory and Uniformity. The research addresses five specific questions to organize the approach, with practical translations of this research to selected industrial use cases.
Open access
Systems Engineering Methodologies and Applications
Infrastructure Resilience and Vulnerability Analysis
本文梳理分布式账本技术在金融交易中的前沿进展,分析其对支付结算、资产登记、监管审计和风险治理的影响。采用文献分析与比较研究方法,选取国内外标准化报告、国际组织研究、监管文件和典型项目材料,从技术架构、金融功能、资产形态、风险类型与治理要求五个维度进行归纳。结果:分布式账本技术已不再局限于加密资产记账,而是逐渐进入跨境支付、资产代币化、稳定币结算、供应链金融、证券登记清算、监管科技和央行数字货币相关基础设施等场景。本文进一步通过Project Agorá、mBridge、Project Guardian、Terra/Luna、数字人民币与BSN等代表性项目或案例进行横向比较,指出不同方案在开放性、可控性、结算最终性、资产确权、合规嵌入和治理责任方面存在明显差异。研究认为,DLT的金融价值主要体现为多主体共享可验证记录、缩短对账链条、支持可编程结算和提升监管可验证性,而不是简单替代金融中介。综上,DLT的大规模金融应用应在效率提升与风险控制之间取得平衡,重点完善隐私保护、法律确权、智能合约安全、跨链互操作、失败处置机制和跨境监管协同。This paper reviews recent developments in distributed ledger technology (DLT) for financial transactions and explains how these developments affect payment and settlement, asset registration, regulatory audit and risk governance. A literature-based and comparative research approach is adopted. The discussion is organised around five dimensions: technical architecture, financial function, asset form, risk type and governance requirement. This revised version adds representative comparisons of Project Agorá, mBridge, Project Guardian, Terra/Luna, e-CNY and BSN, and argues that DLT should be understood as an infrastructure for verifiable coordination rather than a simple substitute for financial intermediaries. Its large-scale adoption depends on technical performance, legal recognition, privacy protection, interoperability standards, smart contract security and cross-jurisdictional regulatory coordination.
The adoption of decentralized technologies in healthcare introduces new opportunities for secure, patient-centered data management but also brings significant privacy and security challenges. This paper presents a threat modeling approach applied to a Web3-based healthcare platform that integrates blockchain for access logging, a FHIR-compliant server for clinical data, and a backend for identity and access management. Using the LINDDUN privacy threat modeling framework and OWASP Threat Dragon, we identified and prioritized privacy risks based on system architecture and data flows. The results show that threat modeling can provide early insights into regulatory compliance, data exposure, and user privacy concerns. This process can be viewed as a foundational step in the development of digital health systems. While the analysis was focused on a specific use case, the methodology is adaptable to a wide range of applications handling sensitive personal data.
System based on blockchain technology and smart contracts. The system aims to address the growing problem of managing and transferring digital assets such as cryptocurrency wallets, domains, cloud storage, NFTs, and gaming assets after the owner’s death. The proposed solution introduces a Dead Man’s Switch mechanism, where users are required to perform periodic check-ins. In case of prolonged inactivity, the system automatically triggers a smart contract that securely transfers access to designated heirs. The system leverages blockchain technology to ensure transparency, immutability, and security, while decentralized storage (IPFS) is used to protect sensitive data through encryption. The platform integrates modern technologies including Ethereum, Solidity, Web3.js, and decentralized storage solutions to provide a fully automated, secure, and trustless inheritance process without relying on centralized authorities or complex legal procedures. This work was conducted at Arab International University (AIU), Syria. The official website of the university is: https://www.aiu.edu.sy
This paper introduces DNET (Dual Network Exchange Technology), an interface architecture that unifies Settlement, Exchange, and Record generation into a single transaction structure for digital payments. Modern payment systems often treat exchange and settlement as separate backend processes, leading to fragmented identifiers, inconsistent idempotency behavior, and operational divergence across implementations. DNET resolves these issues by binding Payment Intent, Exchange Decision, and Settlement Outcome under a single TxID, enabling atomic SER‑coupling across Web2 and Web3 environments. The architecture provides a protocol‑level foundation for multi‑asset payments, ensuring traceability, auditability, and interoperability while reducing operational complexity. This work positions DNET as an OS‑layer interface for value transfer, offering a structural standard for future financial infrastructure.
O presente artigo formaliza o <i>Economic Centrifugal Dispersion Model</i> (ECDM) como uma estrutura analítica de alta fidelidade para a compreensão da propagação de capital e incentivos em ecossistemas de Web3 e finanças descentralizadas (DeFi). Fundamentado em uma convergência interdisciplinar entre a praxeologia da escola austríaca, a física estatística e a dinâmica de sistemas complexos, o modelo propõe que a injeção monetária em sistemas baseados em blockchain gera forças dispersivas análogas às forças centrífugas. A pesquisa detalha a aplicação do operador de Lyapunov para avaliar a estabilidade e a resiliência desses fluxos sob condições de volatilidade estocástica.<br>
The contemporary digital information ecosystem is suffering from a structural market failure analogous to George Akerlof’s "Market for Lemons." In an era of Generative AI, the marginal cost of producing misinformation has approached zero, while the cost of verifying truth remains high. This asymmetry has created a "Trust Deficit" where high-quality information cannot be reliably distinguished from algorithmic noise. Current remediation strategies are bifurcated between two flawed extremes: Centralized Web2 Platforms (which prioritize scalability at the expense of transparency and are prone to censorship) and Decentralized Web3 Networks (which prioritize immutability but suffer from the "Garbage In, Garbage Out" paradox - permanently recording unverified data). The Trust-Scalability Trilemma: This research posits that decentralized reputation systems face a "Trust-Scalability Trilemma," historically unable to simultaneously achieve Veracity (Accuracy), Scalability (Throughput), and Decentralization (Censorship Resistance). Traditional solutions, such as Token Curated Registries (TCRs), have failed because they rely on synchronous, on-chain voting for every data point, resulting in prohibitive latency and gas costs. The Solution: This paper introduces The Klyrox Protocol, a decentralized middleware designed to resolve this trilemma by decoupling Content Execution from Content Verification. The protocol introduces a novel consensus mechanism, "Proof-of-Klyrox," which combines Optimistic Machine Learning (opML) with Game Theoretic Integrity Bonds. Proof-of-Klyrox is not a blockchain consensus mechanism. It is a layered fraud-detection and incentive framework anchored to existing consensus networks. Scope Note: Protocol V1 focuses exclusively on objective, verifiable claims (e.g., market data, timestamped events, quantifiable metrics). Subjective content quality assessment (e.g., editorial judgment, artistic merit) is explicitly out of scope and scheduled for research in future iterations. The system operates on an "Optimistic" presumption of validity: Optimistic Execution: Content is verified instantly via off-chain AI Oracles, reducing verification costs by an estimated 85-95% compared to traditional on-chain governance models. Cryptoeconomic Security: Users must stake financial collateral (Integrity Bonds) to publish. This creates a "Pay-to-Truth" incentive structure where the cost of generating misinformation strictly exceeds the potential profit. Sybil Resistance: The protocol implements a proprietary Time-Decayed Stake-Weighted (TDSW) algorithm. This scoring engine ensures that influence scales logarithmically with capital (preventing plutocratic capture) and decays exponentially over time (preventing the entrenchment of dormant actors). By financializing reputation into a portable, quantifiable asset class defined as "Epistemic Capital," The Klyrox Protocol offers a scalable blueprint for a self-regulating "Market for Truth." It transforms trust from a subjective social sentiment into an objective, verifiable economic product, providing the necessary infrastructure for the next generation of decentralized media, prediction markets, and AI safety layers. Author's Note: This whitepaper outlines the technical architecture and game-theoretic mechanisms underpinning the concept of "Epistemic Capital," as explored in The Algorithmic Monographs series by Ali Sadhik Shaik (The Algorithmic Invisible Hand, The Republic of Code, The Market for Truth, The Heavy Metal Intelligence and The Synthetic C-Cuite).
There have been various attempts at token standards on numerous blockchain platforms today to fundamentally change the way assets are traded in the traditional capital markets, but there is a lack of research and resolution on regulatory issues that become the common foundation for interoperability and reusable standards. Our proposal, Regulatory Compliance Protocol (RCP), is based on the regulations and reports of 15 global financial institutions and standardizes recommendations and guidelines involving the overall asset tokenization of TradFi and DeFi into five regulatory groups: Traceability, Privacy, Enforceability, Finality and Tokenizability, compiling them into 31 items and presenting a benchmark for technology and standards as an underlying protocol. To review the legality and effectiveness of RCP, it was validated based on three tokenization and trading scenarios, and by benchmarking existing asset-tokenization standards (ERC-20, ERC-7943, ERC-1400, and ERC-3643) against RCP, it makes explicit which regulatory requirements each standard addresses at the token level and which remain inherently off-chain.
Reentrancy remains one of the most critical vulnerabilities affecting Ethereum smart contracts. While many existing analysis tools focus on detecting classical single-function reentrancy, more complex forms such as cross-function reentrancy are harder to identify because they depend on execution semantics and interactions between multiple functions. In this work, we study reentrancy at the level of Ethereum Virtual Machine (EVM) execution traces. We extend the TxSpector framework with new Datalog-based detection rules designed to capture cross-function reentrancy patterns. To support this analysis, we also modernize the trace extraction component by adapting it to recent versions of the Ethereum client and updated EVM instructions. The proposed approach is evaluated on real Ethereum on-chain transaction traces. The results show that our method is able to detect cross-function reentrancy behaviors that are not captured by the original TxSpector rules, demonstrating the effectiveness of pattern-based logic detection at the EVM execution level.
Public distributed ledgers enforce integrity through radical transparency, creating tension with data minimization principles required for regulatory compliance. While Zero-Knowledge Proofs (ZKPs) offer a theoretical privacy solution, existing constructions often overlook adversarial constraints in smart contract environments. Specifically, the asynchronous decoupling of off-chain proof generation from on-chain submission introduces front-running and proof-reuse risks in public mempools. In this work, we formalize Selective Disclosure Authorization Schemes (SDAS), a cryptographic primitive for granular and revocable compliance checks on public ledgers without revealing the underlying witness. We define a security model for SDAS, introducing Ledger-Bound Attribute Unlinkability and Context-Aware Sender Binding to capture how valid proofs remain bound to their intended authorization context. To validate sender binding, we present ZK-Compliance, an Ethereum-based instantiation that operationalizes a user-controlled "Grant, Verify, Revoke" lifecycle. We implement the sender-binding component using a 14-constraint Circom circuit that anchors the zero-knowledge proof to the executing on-chain sender address. Our Sepolia evaluation confirms practical viability: browser-based proof generation executes in under 200 ms, and on-chain verification costs 240,512 gas, neutralizing proof reuse by different callers while preserving strict attribute privacy.
Real-world asset (RWA) tokenization has emerged as a prominent application of blockchain technology, enabling off-chain financial and non-financial assets to be represented through blockchain-based instruments. However, deployed RWA systems remain difficult to compare because legal claims, custody arrangements, token mechanics, verification processes, and on-chain integrations are often described separately. This paper develops a systems-level taxonomy of RWA tokenization to classify how off-chain assets are legally, economically, and technically represented on-chain. Following an iterative taxonomy-development method, we organize twenty-three dimensions into five components: governance, asset structure, token properties, distributed ledger technology, and economy. We apply the taxonomy to twenty major RWA systems selected by market capitalization and compare their design choices across asset classes and implementation models. The classification shows that current RWA tokenization is predominantly implemented through hybrid architectures: blockchain tokens support representation, transfer control, redemption workflows, pricing, and composability, while core legal guarantees remain anchored in off-chain legal wrappers, custodial arrangements, compliance processes, and verification mechanisms. The analysis also reveals recurring documentation gaps concerning voting rights, dispute forums, burn mechanics, supply constraints, and reserve verification. Overall, the taxonomy provides a structured basis for comparing RWA systems, identifying design patterns and limitations, and supporting future research on blockchain-based financial infrastructure.
Generative search engines are reshaping information access by replacing traditional ranked lists with synthesized answers and references. In parallel, with the growth of Web3 platforms, incentive-driven creator ecosystems have become an essential part of how enterprises build visibility and community by rewarding creators for contributing to shared narratives. However, the extent to which exposure in generative search engine citations is shaped by external attention markets remains uncertain. In this study, we audit the exposure for 44 Web3 enterprises. First, we show that the creator community around each enterprise is persistent over time. Second, enterprise-specific queries reveal that more popular voices systematically receive greater citation exposure than others. Third, we find that larger follower bases and enterprises with more concentrated creator cores are associated with higher-ranked exposure. Together, these results show that generative search engine citations exhibit exposure bias toward already prominent voices, which risks entrenching incumbents and narrowing viewpoint diversity.
The expansion of Decentralized Finance (DeFi) and Anonymity-Enhancing Technologies (AETs) has complicated the tracking of illicit financial flows. This article analyzes three distinct AETs—Tornado Cash, Monero, and Zcash—to assess how specific protocol mechanisms degrade transaction‑graph attribution and obstruct compliance. Synthesizing technical literature, AML/CFT frameworks, and recent judicial documentation, the study traces how design choices translate into investigative challenges. The analysis yields three key findings. First, “decentralization” rarely eliminates control; instead, it shifts choke points to infrastructure layers such as bridges and RPC providers. Second, while AETs significantly raise attribution costs, their effectiveness is often conditional and dependent on usage patterns. Third, the Tornado Cash enforcement saga illustrates the limitations of applying traditional sanctions to autonomous code. The paper concludes by proposing a mitigation agenda focused on measurable risk reduction at entry/exit points without compromising legitimate privacy.
Phishing attacks pose significant risks to the Ethereum ecosystem, comprising over 50% of Ethereum-related cybercrimes, leading to the emergence of many machine learningbased defenses.This paper introduces a comprehensive framework aimed at enhancing machine learning-based phishing detection in Ethereum transactions.The framework addresses critical aspects such as feature selection, class imbalance, model robustness, and algorithm optimization.By systematically evaluating the strengths and limitations of existing approaches, we highlight gaps in current practices, particularly in feature manipulation and unsustainable performance outcomes.Through both analytical and experimental assessments, we demonstrate the framework's ability to streamline detection techniques, improving generalization and model effectiveness.Our findings emphasize the importance of refining detection strategies to meet the evolving challenges posed by sophisticated phishing schemes in the blockchain space.