Blockchain bridges have become essential infrastructure for enabling interoperability across different blockchain networks, with more than $24B monthly bridge transaction volume. However, their growing adoption has been accompanied by a disproportionate rise in security breaches, making them the single largest source of financial loss in Web3. For cross-chain ecosystems to be robust and sustainable, it is essential to understand and address these vulnerabilities. In this study, we present a comprehensive systematization of blockchain bridge design and security. We define three bridge security priors, formalize the architectural structure of 13 prominent bridges, and identify 23 attack vectors grounded in real-world blockchain exploits. Using this foundation, we evaluate 43 representative attack scenarios and introduce a layered threat model that captures security failures across source chain, off-chain, and destination chain components. Our analysis at the static code and transaction network levels reveals recurring design flaws, particularly in access control, validator trust assumptions, and verification logic, and identifies key patterns in adversarial behavior based on transaction-level traces. To support future development, we propose a decision framework for bridge architecture design, along with defense mechanisms such as layered validation and circuit breakers. This work provides a data-driven foundation for evaluating bridge security and lays the groundwork for standardizing resilient cross-chain infrastructure.
Blockchain bridges have become essential infrastructure for enabling interoperability across different blockchain networks, with more than $24B monthly bridge transaction volume. However, their growing adoption has been accompanied by a disproportionate rise in security breaches, making them the single largest source of financial loss in Web3. For cross-chain ecosystems to be robust and sustainable, it is essential to understand and address these vulnerabilities. In this study, we present a comprehensive systematization of blockchain bridge design and security. We define three bridge security priors, formalize the architectural structure of 13 prominent bridges, and identify 23 attack vectors grounded in real-world blockchain exploits. Using this foundation, we evaluate 43 representative attack scenarios and introduce a layered threat model that captures security failures across source chain, off-chain, and destination chain components. Our analysis at the static code and transaction network levels reveals recurring design flaws, particularly in access control, validator trust assumptions, and verification logic, and identifies key patterns in adversarial behavior based on transaction-level traces. To support future development, we propose a decision framework for bridge architecture design, along with defense mechanisms such as layered validation and circuit breakers. This work provides a data-driven foundation for evaluating bridge security and lays the groundwork for standardizing resilient cross-chain infrastructure.
Ovaj rad prikazuje razvoj prototipa blockchain sustava za nadzor nad antidoping pos- tupcima u sportu. Sustav je osmišljen kako bi povećao transparentnost, sigurnost i nepromjenjivost podataka u procesima testiranja sportaša. Korištenjem Ethereum blockchaina, pametnih ugovora i tehnologija poput Reacta, Flask-a i Web3.py, im- plementirane su funkcionalnosti za tri glavne korisničke uloge: agenciju, laboratorij i sportaša. Agencija može inicirati zahtjeve za testiranjem, laboratorij upisivati rezul- tate, a sportaš pregledavati ishode. Evaluacijom su identificirane prednosti u odnosu na postojeće sustave, ali i ograničenja koja mogu biti predmet budućih poboljšanja, uključujući autentikaciju korisnika, veću skalabilnost i primjenu naprednih kripto- grafskih metoda.
Wallets are access points for the digital economys value creation. Wallets for blockchains store the end-users cryptographic keys for administrating their digital assets and enable access to blockchain Web3 systems. Web3 delivers new service opportunities. This chapter focuses on the Web3 enabled release of value through the lens of wallets. Wallets may be implemented as software apps on smartphones, web apps on desktops, or hardware devices. Wallet users request high security, ease of use, and access of relevance from their wallets. Increasing connectivity, functionality, autonomy, personal support, and offline capability make the wallet into the user's Universal Access Device for any digital asset. Through wallet based services, the owner obtains enhanced digital empowerment. The new Web3 solutionareas, Identity and Decentralisation, enable considerable societal effects, and wallets are an integral part of these. One example is self sovereign identity solutions combined with wallet borne AI for personalised support, empowering the enduser beyond anything previously known. Improved welfare is foreseen globally through enlarged markets with collaborative services with drastically lowered transaction costs compared to today, the expected vastly increased levels of automation in society necessitate enhanced enduser protection. As wallets are considered a weak spot for security, improving overall security through blockchains is essential.
The emerging Web3 has great potential to provide worldwide decentralized services powered by global-range data-driven networks in the future. To ensure the security of Web3 services among diverse user entities, a decentralized identity (DID) system is essential. Especially, a user's access request to Web3 services can be treated as a DID transaction within the blockchain, executed through a consensus mechanism. However, a critical implementation issue arises in the current Web3, i.e., how to deploy network nodes to serve users on a global scale. To address this issue, emerging Low Earth Orbit (LEO) satellite communication systems, such as Starlink, offer a promising solution. With their global coverage and high reliability, these communication satellites can complement terrestrial networks as Web3 deployment infrastructures. In this case, this paper develops three hybrid satellite-ground modes to deploy the blockchain-enabled DID system for Web3 users. Three modes integrate ground nodes and satellites to provide flexible and continuous DID services for worldwide users. Meanwhile, to evaluate the effectiveness of the present hybrid deployment modes, we analyze the complete DID consensus performance of blockchain on three hybrid satellite-ground modes. Moreover, we conduct numerical and simulation experiments to verify the effectiveness of three hybrid satellite-ground modes. The impacts of various system parameters are thoroughly analyzed, providing valuable insights for implementing the worldwide Web3 DID system in real-world network environments.
Integrating blockchain into healthcare devices offers potential for improved data control but faces significant usability and acceptance challenges. This study addresses this gap by evaluating CipherPal, an improved blockchain-enabled smart fidget toy prototype, using a multi-framework approach to understand the interplay between technology, design, and user experience. We combined insights from an expert review assessing adherence to Web3 Design Guidelines, a User Acceptance Toolkit assessment with professionals based on UTAUT2, and extended user testing over three days. Findings revealed that users valued CipherPal's satisfying tactile interaction and perceived benefits for well-being, such as stress relief. However, significant usability barriers emerged, primarily related to challenging device-application connectivity, data synchronization, and disruptive physical elements. While conceptually accepted, the blockchain integration mainly added interaction friction and complexity, overshadowing its potential benefits for users during the study. The multi-framework approach proved valuable, providing complementary insights and highlighting tensions between the device's core appeal and usability challenges. This research underscores the critical need for user-centered design in blockchain health applications, emphasizing seamless usability, abstracting technical complexity, and holistically considering physical and social factors.
Purpose: This article proposes and applies the 6V Framework to conceptualize and evaluate next-generation marketing channels in the digital economy.It aims to understand how emerging formats-such as voice commerce, immersive AR/VR environments, retail media networks, and Web3-based platforms-are reshaping customer engagement, brand experience, and value creation.Design/Methodology/Approach: Building on an extensive literature review and theoretical synthesis, the paper introduces the 6V Framework, consisting of six analytical dimensions: Value, Velocity, Visibility, Verifiability, Virtuality, and Vulnerability.The framework is applied to an in-depth case study of Nike .Swoosh, supported by a comparative evaluation of other leading platforms (e.g., Adidas, Gucci, Starbucks) to illustrate strategic patterns and innovation trajectories.Practical Implication: The article provides marketers, strategists, and digital transformation leaders with a practical framework for analyzing, designing, and governing complex marketing environments.It supports decision-making regarding channel investments, user experience design, and ethical risk management in data-rich, technology-driven contexts.Originality/Value: In contrast to legacy models focused on linear transactions and control, the 6V Framework captures the dynamic, participatory, and decentralized nature of modern marketing channels.It offers a novel conceptual lens for assessing strategic and operational implications of digital channel innovation.
This research analyzes the impact of blockchain technology in the field of electronic evidence. It starts from a hypothesis of assuming that blockchain technology will have a significant impact on both public administrations and society in general, which will mean changing the way personal electronic information is managed by putting control in the hands of individual citizens rather than centralized servers or platforms. The article also analyzes regulatory efforts in the European Union to adapt to the changing landscape of electronic evidence, including the proposed eIDAS 2 regulation, which seeks to establish autonomous digital identities based on blockchain technology and then focuses on the procedural treatment of blockchain as a means and source of evidence and differentiates between this technology as a means of storing electronic evidence and as a mechanism to preserve and secure this type of evidence. Likewise, the text concludes by emphasizing the potential of blockchain technology in the context of Web3, where decentralized and interoperable systems are expected to play a fundamental role in the Spanish and European administration of justice.
Оксана Гладченко, T. V. Ratushnyak, І. Д. Погорєловська, А. Р. Коротун · 5 authors
У статті розглянуто вплив комп’ютерних технологій, зокрема блокчейн-рішень, ІТ-інфраструктури та суміжних цифрових інструментів, на формування й розвиток криптовалют. Висвітлено історичну еволюцію ІТ-технологій у контексті ключових етапів розвитку криптовалютного середовища – від перших концепцій цифрових гро- шей у 1970-х роках до сучасної високотехнологічної екосистеми. Окреслено, як розвиток персональних комп’ютерів, глобального інтернету, криптографії, peer-to-peer мереж, хмарних обчислень, смартконтрактів і Web3-платформ сприяв можливості створення, функціонування та масштабування цифрових активів. На основі історичного та статистичного аналізу показано, що зростання інвестицій у блокчейн-технології тісно пов’язане з динамікою капіталізації криптовалютного ринку. Проведений регресійний аналіз продемонстрував високий рівень кореляції між ринками блокчейну та криптовалют, а також між ІТ-сектором і криптовалютами, що вказує на їхнє визначальне значення у цифровій економіці. У статті схарактеризовано модель формування криптовалюти, починаючи з концептуального етапу та завершуючи її інтеграцією в платформи обміну, зберігання та реального використання. Особливу увагу приділено ролі смартконтрактів, мережевих архітектур, тестових середовищ, безпекових протоколів та адаптації до регуляторних вимог. Зазначено, що комп’ютерні технології є системоутворюючим елементом сучасної криптовалютної економіки, а блокчейн відіграє роль ядра довіри, прозорості та безпеки в цифровому середовищі. У результаті визначено, що комп’ютерні технології є базовим структурним елементом у побудові функціональної криптовалютної екосистеми, а блокчейн виступає не просто інструментом обліку, а технологічним ядром для забезпечення довіри, децентралізації та безпеки. Таким чином, криптовалюта не є ізольованим цифровим активом, а є результатом системної взаємодії програмного забезпечення, мережевих інфраструктур, безпеки, ринкового середовища та технологічної інноваційності.
True democracy, strong trust of people in the government and legal transfer of power in the country are possible only when elections are held honestly and correctly. Modern information technologies contribute to innovative restructuring of electoral processes, ensuring optimization of the voting process, minimizing human errors, increasing accessibility for voters. At the same time, the introduction of digital technologies creates significant problems with information security, in particular, possible changes in voting results, manipulation, threats to integrity, availability, confidentiality and anonymity. One of the effective solutions for ensuring information security in electronic voting (e-voting) is blockchain technology. This study is devoted to the problem of developing a website for electronic voting using blockchain technology. Based on the study of scientific literature, the essence, principles, advantages and disadvantages of this technology are revealed. A comparative analysis of the best practices for implementing blockchain technology in the e-voting process is presented. As an example, the process of developing a website for electronic voting using blockchain technology is described: functional requirements for this system are established, the architecture of the software application is described, and a use case diagram is modeled. TypeScript was used as the main programming language for the backend development, Nest.js as a framework, PostgreSQL for data management, and Web3.js for implementing the backend functionality. The frontend was implemented using the TypeScript programming language, the React framework, and Tailwind CSS for interface design. The developed electronic voting platform demonstrates high flexibility and can be implemented for various electoral procedures. Its functionality covers both elections of officials (for example, the rector of the university) and local votes (for example, the election of the head of an academic group), as well as referendums to evaluate the activities of structural units. The data identified during the study can enrich educational materials for students of the 12th Information Technology branch.
Open access
Blockchain Technology Applications and Security
Internet Traffic Analysis and Secure E-voting
Advanced Steganography and Watermarking Techniques
Guy Goren, Andrew Hariri, Timothy D. R. Hartley, Ravi Kappiyoor · 6 authors
Existing decentralized storage protocols fall short of the service required by real-world applications. Their throughput, latency, cost-effectiveness, and availability are insufficient for demanding workloads such as video streaming, large-scale data analytics, or AI training. As a result, Web3 data-intensive applications are predominantly dependent on centralized infrastructure. Shelby is a high-performance decentralized storage protocol designed to meet demanding needs. It achieves fast, reliable access to large volumes of data while preserving decentralization guarantees. The architecture reflects lessons from Web2 systems: it separates control and data planes, uses erasure coding with low replication overhead and minimal repair bandwidth, and operates over a dedicated backbone connecting RPC and storage nodes. Reads are paid, which incentivizes good performance. Shelby also introduces a novel auditing protocol that provides strong cryptoeconomic guarantees without compromising performance, a common limitation of other decentralized solutions. The result is a decentralized system that brings Web2-grade performance to production-scale, read-intensive Web3 applications.
Blockchain has been widely recognized as a trusted computing paradigm underpinning Decentralized Applications (DApps). However, low performance and poor scalability of the existing mainstream blockchain designs and implementations render their prospects unattainable, so-called trilemma . Directed Acyclic Graph (DAG) emerged as an alternative blockchain architecture to address the performance and scalability issue. However, the capacity and feasibility of DAG-based blockchain systems still remain of concern, due to a lack of open source implementations and convincing published experimental results. In this article, we propose a DAG-based blockchain, named 3D-DAG , to greatly improve the scalability and performance without compromising security. The system addresses the trilemma of decentralization, scalability, and security. Technically, our 3D-DAG consists of two layers of chains: DAGchain and mainchain . The DAGchain organizes the transactions in DAG topology, without having to solve the forks. They select a small group of validators from a large number of miners to make up the committee for consensus procedures. The design of DAGchain improves scalability by enabling parallel transaction processing. Based on that, the mainchain plays the role of checkpoint, periodically packaging and recording received transactions from DAGchain for finality. We also provide a prototype implementation with detailed evaluations. Experimental results show our 3D-DAG can meet the performance (a peak value of \(9.82\times 10^{4}\) TPS) that is expected by DApps in the context of Web3.
Initially introduced to Ethereum via Flashbots' MEV-boost, Proposer-Builder Separation allows proposers to auction off blockspace to a market of transaction orderers, known as builders. PBS is currently available to validators through the aforementioned MEV-boost, but its unregulated and relay-dependent nature has much of the Ethereum community calling for its enshrinement. Providing a protocol-integrated PBS marketspace and communication channel for payload outsourcing is termed PBS enshrinement. Although ePBS potentially introduces native MEV mitigation mechanisms and reduces validator operation costs, fears of multiparty collusion and chain stagnation are all too real. In addition to mitigating these potential drawbacks, PBS research pursues many tenets revered by Web3 enthusiasts, including but not limited to, censorship resistance, validator reward equity, and deflationary finance. The subsequent SoK will identify current PBS mechanisms, the need for enshrinement, additions to the ePBS upgrade, and the existing or potential on-chain socioeconomic implications of each.
Emerging crypto economies still hemorrhage digital assets because legacy wallets leak private keys at almost every layer of the software stack, from user-space libraries to kernel memory dumps. This paper solves that twin crisis of security and interoperability by re-imagining key management as a platform-level service anchored in ARM TrustZone through OP-TEE. Our architecture fractures the traditional monolithic Trusted Application into per-chain modules housed in a multi-tenant TA store, finally breaking OP-TEE's single-binary ceiling. A cryptographically sealed firmware-over-the-air pipeline welds each TA set to an Android system image, enabling hot-swap updates while Verified Boot enforces rollback protection. Every package carries a chained signature developer first, registry second so even a compromised supply chain cannot smuggle malicious code past the Secure World's RSA-PSS gatekeeper. Inside the TEE, strict inter-TA isolation, cache partitioning, and GP-compliant crypto APIs ensure secrets never bleed across trust boundaries or timing domains. The Rich Execution Environment can interact only via hardware-mediated Secure Monitor Calls, collapsing the surface exposed to malware in Android space. End-users enjoy a single polished interface yet can install or retire Bitcoin, Ethereum, Solana, or tomorrow's chain with one tap, shrinking both storage footprint and audit scope. For auditors, the composition model slashes duplicated verification effort by quarantining blockchain logic inside narrowly scoped modules that share formally specified interfaces. Our threat analysis spans six adversary layers and shows how the design neutralizes REE malware sniffing, OTA injection, and cross-module side channels without exotic hardware. A reference implementation on AOSP exports a Wallet Manager HAL, custom SELinux domains, and a CI/CD pipeline that vet community modules before release. The result is not merely another hardware wallet but a programmable substrate that can evolve at the velocity of the blockchain ecosystem. By welding radical extensibility to hardware-anchored assurance, the platform closes the security-usability gap that has long stymied mass-market self-custody. We posit that modular TEEs are the missing OS primitive for Web3, much as virtual memory unlocked multi-tasking in classical computing. Together, these contributions sketch a blueprint for multi-chain asset management that is auditable, resilient, and poised for global deployment.
The article presents a comprehensive analysis of the transition from traditional centralized digital identity models to an innovative decentralized paradigm based on block-chain technologies and zero-knowledge proofs (ZKP). It highlights the fundamental problems of existing systems that rely on centralized registries, passwords, and social logins. Such approaches create significant vulnerabilities, including risks of data breaches, mass surveillance, and manipulation, as centralized intermediaries act as sole controllers of personal information, depriving users of control over their data. In response to these challenges, the article discusses the concept of Decentralized Identity (DID). This model enables individuals to own, store, and control their digital credentials independently, without involving intermediaries. The key technological components of this ecosystem include Verifiable Credentials (VC), Digital ID Wallets, and Decentralized Identifiers (DID), which are typically stored on a block-chain to ensure immutability and security. A triadic trust model involving the Issuer, Holder, and Verifier is described, allowing data verification without direct contact with the issuing organization. Special attention is given to the concept of Self-Sovereign Identity (SSI) as a specific philosophy within DID that emphasizes user autonomy, data minimization, and privacy by design. Unlike the broader DID concept, in the SSI model, the user makes the final decision regarding the disclosure of their data. A central technology ensuring privacy in decentralized systems is zero-knowledge proofs (ZKP). ZKP allow the validation of the truthfulness of a statement without revealing the underlying information. The article provides a detailed analysis of the benefits of using ZKP in the context of DID, including selective attribute disclosure (e.g., proving legal age without revealing the date of birth), minimizing the amount of shared data, preventing correlation and user activity tracking, as well as creating reputation systems that preserve anonymity. Practical application scenarios such as private electronic voting and confidential medical data protection are examined. The paper also addresses standardization, which is key to ensuring compatibility and widespread adoption of DID solutions. Leading initiatives such as W3C Verifiable Credentials, the Decentralized Identity Foundation (DIF), and projects like Hyperledger Indy and Aries are mentioned. Examples of advanced implementations already in use are provided: Polygon’s zkKYC for private verification in DeFi, the Sismo protocol for creating anonymous reputation badges in Web3, and Evernym’s SSI platform based on Hyperledger Indy. In conclusion, it is emphasized that the combination of DID and ZKP forms a new paradigm for digital identity management focused on security and user autonomy. Despite challenges related to usability complexity, key loss risk, and legal uncertainty, the technology is actively evolving and moving from conceptual to practical application, which may eventually become the foundation for a global sovereign digital identity.
Web3 technologies have experienced unprecedented growth in the last decade, achieving widespread adoption. As various blockchain networks continue to evolve, we are on the cusp of a paradigm shift in which they could provide services traditionally offered by the Internet, but in a decentralized manner, marking the emergence of the Internet of Blockchains. While significant progress has been achieved in enabling interoperability between blockchain networks, existing solutions often assume that networks are already mutually aware. This reveals a critical gap: the initial discovery of blockchain networks remains largely unaddressed. This paper proposes a decentralized architecture for blockchain network discovery that operates independently of any centralized authority. We also introduce a mechanism for discovering assets and services within a blockchain from external networks. Given the decentralized nature of the proposed discovery architecture, we design an incentive mechanism to encourage nodes to actively participate in maintaining the discovery network. The proposed architecture implemented and evaluated, using the Substrate framework, demonstrates its resilience and scalability, effectively handling up to 130,000 concurrent requests under the tested network configurations, with a median response time of 5.5 milliseconds, demonstrating the ability to scale its processing capacity further by increasing its network size.
Abstract—File storage platforms face inherent challenges such as censorship, limited transparency, vulnerability to single points of failure, and restricted user control over data. To address these limitations, this paper proposes a decentralized file-sharing system that integrates the Ethereum blockchain with the InterPlanetary File System (IPFS). Our design leverages smart contracts to securely manage file metadata and enforce access controls, providing an immutable and tamper-resistant record of data ownership and permissions. IPFS is utilized for efficient, distributed file storage, enhancing scalability and availability. User authentication is handled through wallet-based cryptographic verification, eliminating reliance on centralized identity providers. Additionally, the system supports micropayment- based monetization via smart contracts, enabling direct and transparent transactions between content creators and consumers. The proposed platform delivers a secure, censorship-resistant, and user-empowered file-sharing environment consistent with the principles of Web3. Keywords- Blockchain, IPFS, Smart Contracts,
Web3 applications, such as on-chain games, NFT minting, and leader elections necessitate access to unbiased, unpredictable, and publicly verifiable randomness. Despite its broad use cases and huge demand, there is a notable absence of comprehensive treatments of on-chain verifiable randomness services. To bridge this, we offer an extensive formal analysis of on-chain verifiable randomness services. We present the first formalization of on-chain verifiable randomness in the blockchain setting by introducing the notion of Verifiable Randomness as a Service (VRaaS). We formally define VRaaS using an ideal functionality$\mathcal{F}\text{VRaaS}$in the Universal Composability model. Our definition not only captures the core features of randomness services, such as unbiasability, unpredictability, and public verifiability, but also accounts for many other crucial nuances pertaining to different entities involved, such as smart contracts. Within our framework we study a generic design of Verifiable Random Function (VRF)-based randomness service - where the randomness requester provides an input on which the randomness is evaluated as VRF output. We show that it does satisfy our formal VRaaS definition. Furthermore, we show that the generic protocol captures many real-world randomness services like Chainlink VRF and Supra dVRF. Moreover, we investigate the minimalism of the frame-work. Towards that, first we show that, the two transactions in-built in our framework are actually necessary for any randomness service to support the essential qualities. We also discover practical vulnerabilities in other designs such as Algorand beacon, Pyth VRF and Band VRF, captured within our framework.
M Y Khan, Shaik Rehan, Mohammed Abdullah, Marwan Ali
In the rapidly evolving world of digital finance,there remains a growing need to bridge the gapbetween decentralized crypto assets and traditionalfiat currency systems. RupXpay is a robust andsecure payment application designed to meet thisdemand by enabling users to convert their cryptocurrency into Indian Rupees (INR) and alsoperform direct INR transfers through their bankaccounts. The app begins by allowing users toconnect any Web3 wallet of their choice (such asMeta Mask, Trust Wallet, etc.). Upon successfulconnection, RupXpay displays the user’s real-timewallet balance, providing full visibility andtransparency. When a user wants to convert theircrypto holdings into INR, they simply enter thedesired amount, select the block chain network,choose the crypto currency, and the preferredpayment method. To initiate the transaction, theuser must provide a digital wallet signature, whichnot only authorizes the transaction but alsotriggers a temporary wallet lock for five minutes.This lock mechanism ensures the transaction dataremains secure and unaltered during theverification process, significantly reducing the riskof fraud. The system calculates applicable gas feesbased on the selected network and applies a fixed1% fee for network processing and a 2% service feecharged by RupXpay for conversion services. Onceverified, the INR amount is credited to the user’slinked bank account. In addition to crypto-basedconversions, RupXpay supports traditional bankto-bank INR transfers. By linking their bankaccount within the app, users can send moneydirectly to other users without involving cryptocurrency, making RupXpay a complete, dual-modepayment solution. By combiningblock chain technology with traditional financialinfrastructure, RupXpay provides users with areliable, efficient, and secure platform to makecrypto spendable in everyday life. It is a futurereadyfinancial tool that redefines how digitalassets are used in the real economy.
Résilience à la collusion dans les mécanismes de places de marché décentralisées Les places de marché décentralisées dans le Web3 cherchent à protéger leurs utilisateurs contre la censure, les biais et les points de défaillance uniques qui peuvent exister dans leurs homologues centralisés. Pourtant, certains mécanismes ont tendance à rester centralisés, par exemple le moteur de recherche permettant de découvrir de nouvelles ressources sur le marché. De telles vulnérabilités ont été exploitées sur des places de marché décentralisées ces dernières années : il est d'autant plus essentiel de fournir des mécanismes de protection. Dans cette thèse, nous proposons des protocoles pour assurer la fiabilité et l'équité des mécanismes des places de marché, notamment par la résilience à la collusion d'acteurs malveillants. Tout d'abord, pour traiter la sélection décentralisée d'un sous-ensemble de participants parmi une population comprenant des acteurs malveillant, nous proposons un protocole basé sur la blockchain pour éviter que les acteurs malveillants n'influencent la sélection à leur avantage. Ensuite, en considérant des ensembles de participants sélectionnés qui travailleront ensemble sur des tâches dans une place de marché décentralisée de ressources cloud, dans un environnement sans accès à des informations fiables ou non confidentielles, nous présentons un mécanisme d'incitation qui punit ou récompense collectivement les participants aux tâches en fonction du résultat de leurs tâches. Nous décrivons et évaluons également la manière d'atteindre un taux de réussite cible des tâches de la place de marché : l'algorithme que nous proposons est capable d'atteindre les objectifs définis et de réduire par 5 à 10 fois le taux d'échec par rapport à un système sans protection. Par ailleurs, nous montrons comment les fournisseurs du moteur de recherche d'une place de marché décentralisée peuvent favoriser un sous-ensemble d'utilisateurs du moteur de recherche. Nous protégeons ces moteurs de recherche avec notre protocole COoL-TEE, qui permet aux utilisateurs honnêtes d'éviter les fournisseurs malveillants de ce moteur de recherche, qui retardent de manière sélective les réponses au profit des utilisateurs qui les soudoient. Les utilisateurs honnêtes collaborent avec des environnements d'exécution de confiance (Trusted Execution Environment, TEE) au sein des machines hôtes des fournisseurs du moteur de recherche, afin de sélectionner des fournisseurs proches, rapides et honnêtes. A partir de simulations d'utilisateurs envoyant des requêtes depuis le monde entier à des fournisseurs géo-distribués hébergés dans des centres de données, nous illustrons comment COoL-TEE réduit l'avantage des utilisateurs malveillants à un niveau proche d'un scénario sans attaques. Enfin, de nombreux protocoles traditionnels et basés sur les TEEs requièrent des mesures temporelles fiables pour leur logique d'exécution, y compris COoL-TEE. Cependant, des attaquants qui contrôlent le système d'exploitation sont capables d'attaquer la perception du temps du TEE et, par conséquent, de manipuler les protocoles utilisant les mesures temporelles fournies. Nous contribuons une implémentation publique du protocole d'état-de-l'art Triad, dont le code source est fermé, et nous menons des attaques sur celui-ci de manière empirique. Sa calibration peut être manipulée pour affecter la vitesse d'horloge perçue par le TEE. En outre, les attaques sur une machine compromise peuvent se propager aux machines honnêtes participant au protocole de temps de confiance de Triad. Nous discutons comment atténuer ces vulnérabilités afin d'améliorer la résilience contre de telles attaques.
Decentralized marketplaces in Web3 aim to protect against censorship, bias, and single points of failure that may exist in their centralized counterparts. Still, some mechanisms tend to remain centralized, for example the search mechanism that enables discovery of new assets in the market. Such vulnerabilities have been exploited in live marketplaces in recent years: it is all the more essential to provide protection mechanisms. In this thesis, we propose protocols to uphold the reliability and fairness of marketplace mechanisms, notably through resilience against colluding malicious actors. First, to address decentralized selection of a subset of participants among a population comprising malicious actors, we contribute a blockchain-based protocol to avoid malicious actors swaying selection to their benefit. Then, considering selected sets of participants that will work together on tasks in a decentralized computing marketplace, in an environment with no access to trustworthy or non-confidential monitoring information, we present an incentive mechanism that collectively punishes or rewards task participants based on the outcome of their tasks. We also describe and evaluate how to meet a target success rate for the marketplace's tasks: our proposed algorithm is able to meet such targets and to reduce the failure rate by 5 to 10 times compared to an unprotected system. Additionally, we show how providers of a marketplace's search mechanism can favor a subset of search consumers, granting them an unfair advantage in accessing information about the most recent state of the market. We protect decentralized marketplaces' search with our protocol COoL-TEE, which enables honest search consumers to avoid malicious search providers, who selectively delay responses to benefit colluding consumers. Honest consumers collaborate with Trusted Execution Environments (TEEs) inside the host providers, in order to select close, fast, and honest providers. Using simulations of consumers sending search requests from around the globe to geo-distributed providers hosted in datacenters, we illustrate how COoL-TEE reduces malicious advantage close to a scenario without attacks. Finally, many TEE and traditional protocols rely on trustworthy time measurements for their execution logic, including COoL-TEE. However, attackers controlling the operating system are capable of attacking the TEE's time perception and, in turn, of manipulating the protocols depending on the timestamps. We contribute a public implementation of the state-of-the-art but closed-source protocol Triad and empirically showcase attacks. Calibration can be manipulated to affect the TEE's perceived clock speed. Furthermore, attacks on a compromised machine could propagate to honest machines participating in Triad's trusted time protocol. We discuss mitigations to these vulnerabilities for higher resilience against such attacks.
Purpose: The paper discusses the intersection of financial literacy and digital asset education as an inherent determinant of the emergence of a new wave of self-made millionaires in America. As conventional means to wealth creation become ever more tenuous, especially for Millennials and Gen Z, advances in digital technology, including cryptocurrency, decentralized finance (DeFi), non-fungible tokens (NFTs), and e-business present unparalleled opportunities. The article investigates the key role played by financial literacy in empowering individuals to access these new avenues. Materials and Methods: A mixed-method research design was employed in this study. The paper employs current data published by Pew Research, Chainalysis, Fidelity, and the Global Financial Literacy Excellence Center. The research also employs qualitative interviews and public case profiles of investors and digital entrepreneurs. Findings: The most successful lasting success factor among the new digital millionaires is not inherited wealth or high income, but rather high financial and digital literacy levels. Case studies of individuals who have utilized cryptocurrency investing, digital enterprises, and online learning to attain prosperity prove the trend. Furthermore, this paper presents a comparative review of traditional and digital wealth creation models. Implications to Theory, Practice, and Policy: The study proposes a redefinition of financial literacy to include blockchain, tokenomics, and platform-based earnings. Practically, it summons schools, governments, and financial institutions to incorporate digital financial literacy into education and advisory services. Policy implications are public funding for Web3 education, support for digital entrepreneurship, and the decentralization of access to wealth-building.