Bug reproduction is becoming an important task in the security analysis of Solidity smart contracts. By simulating attacks, developers and auditors can better understand how a vulnerability is triggered in practice. To reproduce a bug, one often needs to define an attacker contract and a specific sequence of interactions that exploit the vulnerability. However, in smart contracts, there are rarely automated tools that can generate such contracts and sequences and validate their correctness. Existing security tools, such as formal verifiers, are effective at detecting bugs, but they are not designed for bug reproduction. They often omit execution traces or produce incomplete ones. Moreover, their reports rarely reflect the behaviour patterns of attacker contracts. This gap motivates our work. We propose VeriExploit, a framework that combines formal methods and large language models to automatically generate, validate, and refine reproduction contracts and execution steps. Given a vulnerable contract and its counterexample, VeriExploit produces a contract that re-triggers the same bug and outputs a concrete trace showing how the exploit works. Experiments show that VeriExploit is effective at automating bug reproduction, achieving a success rate of 85.60% on our benchmark dataset.
In recent years, many hash functions have been introduced to satisfy the pressing need of some zero-knowledge protocols for such primitives allowing a low degree verification of their round function when arithmetized over a large field.While this can be achieved by restricting their sub-components to low-degree functions (and their inverse), the newest primitives in this category also leverage the intricacies of some proof systems to use âSplit-and-Lookupâ non-linear functions that essentially apply a small S-box in parallel over the binary representation of a field element.Such components excel at hindering attacks relying on polynomial system solving, but they offer poor security against statistical attacks. On the other hand, low degree monomials offer the opposite guarantees, being strong against statistical attacks. Several primitives have recently been proposed that combine such components in different ways in order to get the best from both.In this paper, we target such primitives by relying on the low degree components to allow a low-cost polynomial solving step. The weakness of Split-and-Lookups against linear attacks is used to simplify these systems, and their weakness against differential attacks is then used to propagate across many rounds the differential patterns obtained during polynomial solving. We instantiate this general approach by attacking round-reduced Monolith, and providing a distinguisher on full-round Skyscraper. These result then shed some light on how to best combine the different types of components to achieve the highest security.
Investors may tend to turn to safe-haven assets to avoid high volatility in financial markets and protect themselves from risks during times of uncertainty created by crisis periods. In the study, haven, hedge and diversification characteristics of traditional and digital assets such as gold, silver, US dollar, euro, US 10-year bond, Brent oil, Bitcoin and Ethereum against BIST100, S&P500 and DAX indices were examined using EGARCH (1,1) and DCC-GARCH (1,1) models in seven different crisis periods that have a high impact on global markets, including geopolitical, financial and health crises, using 20-year daily data covering the period 01.01.2005â01.01.2025. The findings indicate that the US dollar has consistently demonstrated strong safe-haven characteristics against the BIST100, S&P 500, and DAX in various crises. The assets that exhibited significant haven characteristics only in one crisis period were gold against the S&P 500, Brent oil, and the Euro against the DAX. The 10-year US bond exhibited safe-haven properties relative to the S&P 500 and DAX during various crisis periods. While no significant results were achieved regarding silverâs haven or hedge characteristics, it was observed that the assets generally played a diversifying role in periods other than those yielding these results. According to EGARCH (1,1) results, Ethereum was identified as a haven candidate against DAX; however, DCC-GARCH (1,1) estimates did not confirm this result.
Purpose. The aim of the study is to develop a detailed role model for the implementation of smart contracts in the logistics processes of freight transportation, which will enable the automation of interaction between participants and increase the transparency of operations. Methodology. To achieve the stated goal, a systemic approach using context-role analysis was applied. The study involves a detailed decomposition of the stages of the logistics chain when applying smart contracts, identification of key participants, and definition of their functions, rights, and responsibilities. This approach makes it possible to clearly delineate areas of responsibility, reduce the risk of conflicts, and ensure the transparency of each participantâs actions. The developed UML diagram demonstrates the sequence of interactions between subjects, and the integration of smart contracts ensures the automation and immutability of operations. Findings. A comprehensive analysis of logistics processes using smart contracts was carried out, which made it possible to define the rights and responsibilities for seven basic roles of logistics operation participants. This approach provides a holistic view of the system and makes it possible to describe the logic of interactions between subjects. The developed model demonstrates the automation of contract conclusion and execution, which contributes to the reduction of document processing time, optimization of operations, and ensuring a high level of data security in the distributed ledger. Originality. An approach is proposed that enables the integration of formalized roles of freight transportation participants with smart contract technology. The detailed structuring of the functional responsibilities of each role makes it possible to implement the program logic of a decentralized system, which significantly expands the possibilities of automated logistics process management. The approach is universal and can be adapted to different types of logistics scenarios. Practical value. The developed role model creates favorable conditions for the implementation of blockchain solutions in the field of freight transportation, which makes it possible to digitalize logistics processes, increase trust between supply chain participants, and reduce operational costs. The obtained results have practical application for logistics operators, software developers, and consulting companies that seek to modernize existing transportation management systems. The model can also be useful for educational purposes in the fields of logistics, computer science, and management.
Ruba Islayem, Haya R. Hasan, Ahmad Musamih, Khaled Salah · 5 authors
The leather supply chain comprises numerous organizations and stakeholders, particularly when sustainability aspects are taken into account, making it a complex system. The complexity inherent in such systems can lead to inaccurate information, lack of transparency, and limited data provenance. Moreover, there has been a surge in the call for sustainable practices within leather production, propelled by growing environmental consciousness and ethical considerations. In this paper, we address these challenges by proposing a blockchain-based solution designed to ensure trusted and secure traceability and sustainability throughout the entire life cycle of leather products. By harnessing the inherent capabilities of Ethereum smart contracts and blockchain technology, such as decentralization, immutability, data integrity, and transparency, we guarantee the secure and reliable tracing of materials from the farm to the final consumer. Moreover, we provide proof of sustainability by which certification agencies monitor, audit, and approve the sustainable processes and practices carried out by the different stakeholders at all stages of production to ensure compliance with industry standards and regulations. The paper presents the blockchain-based system architecture, implementation, and validation of algorithms and smart contracts. It also evaluates the security measures and cost-effectiveness of the system to offer valuable insights into its robustness and efficiency. We have made the developed smart contracts code publicly available on GitHub.
Nopita Sari, Nurul Ain Safrizon, Basarudin Basarudin, Adam Idris
The increasing adoption of blockchain technology in Islamic finance has prompted growing interest in its application for smart contracts within murabahah financing structures. The digital transformation of financial transactions raises important questions regarding Sharia compliance, contractual validity, and legal enforceability in decentralized systems. This study aims to examine how blockchain-based smart contracts can enhance transparency, efficiency, and trust in murabahah financing while maintaining strict adherence to Islamic legal principles. A qualitative-doctrinal research method was employed, integrating analysis of classical fiqh al-muâ?mal?t with contemporary regulatory frameworks governing digital transactions and smart contract implementation. The study utilized comparative analysis of existing blockchain platforms and Islamic financial models to identify areas of alignment and potential conflict. The findings indicate that blockchain technology supports murabahah transactions by automating contract execution, eliminating asymmetrical information, and ensuring compliance with Sharia requirements for ownership transfer and cost disclosure. However, challenges remain in achieving legal recognition of decentralized contracts within conventional judicial systems. The study concludes that blockchain-based smart contracts can be considered Sharia-compliant when developed under proper legal supervision and governance mechanisms, offering a promising pathway for digital transformation in Islamic finance.
The exponential growth of the electric vehicle (EV) industry, driven by decarbonization goals and energy transition policies, has intensified the need for sustainable and transparent supply chains. Lithium-ion batteries (LIBs), the cornerstone of EVs, pose complex life cycle challenges related to ethical sourcing, environmental degradation, traceability gaps, and inefficient end-of-life (EOL) management. Addressing these multifaceted issues requires an integrated technological approach. This study proposes a unified framework leveraging Digital Product Passports (DPPs) and blockchain technology to enable real-time, tamper-proof tracking of battery materials, components, and performance metrics throughout their lifecycle.The paper further integrates machine learning, with a focus on reinforcement learning (RL), to optimize logistics and predictive maintenance based on dynamic supply chain data. To ensure privacy and regulatory compliance in data sharing, the framework incorporates zkSNARKsâa zero-knowledge proof system that preserves confidentiality while maintaining verifiability across distributed networks. This triadic approach promotes lifecycle transparency, supports circular economy goals through efficient material reuse and recycling, and reduces the total cost of ownership (TCO) for EV stakeholders.The proposed solution addresses critical industry challengesâsuch as counterfeit components, low recycling efficiency, and supply chain opacityâwhile offering scalable applications in adjacent sectors like consumer electronics and renewable energy. The integration of DPPs, blockchain, and AI-based optimization establishes a resilient, interoperable infrastructure that enables enhanced sourcing, sustainability, and collaborative innovation in the evolving EV ecosystem.
In response to the escalating plastic pollution crisis, the development of high-performance biodegradable materials is critical. Poly(butylene succinate) (PBS) is an important biodegradable polymer as it possesses excellent biodegradability and processability. But it suffers from limitations such as low mechanical strength, poor thermal stability, and high production costs. In this study, taxus residue (TF), a waste by-product, was utilized as a reinforcing filler to reduce PBS costs while enhancing its overall performance. To address the interfacial incompatibility between TF and PBS, branched PBS (T-PBS) was introduced as a compatibilizer. The TF was surface-modified via alkali treatment and silane coupling (KH550), and a series of PBS/TF/T-PBS composites with varying T-PBS viscosity grades were prepared by melt blending. The compatibilization mechanism of T-PBS and its influence on the composite structure, crystallization behavior, thermal stability, rheological, and mechanical properties were systematically investigated. Results show that the branched structure significantly enhanced T-PBS melt strength and reactivity. The introduction of T-PBS effectively improved interfacial compatibility between TF and PBS matrix, reducing phase separation and interfacial defects. Compared to uncompatibilized PBS/TF composites, those with appropriately viscous T-PBS exhibited improved tensile strength (increased by 19.7%) and elongation at break (increased by 78.8%), while flexural strength was also maintained at an enhanced level. The branched points acted as nucleating agents, increasing the onset temperature and degree of crystallinity. In the high-temperature region, the synergistic barrier effect from TF and char residue improved thermal stability (T85% reached 408.19 °C). Rheological analysis revealed enhanced viscosity and elasticity of the system. This study provides a promising strategy and theoretical foundation for the high-value utilization of taxus waste and the development of high-performance biodegradable PBS-based composites.
Abstract Cryptocurrency speculation involves investing in assets with highly volatile price movements in which large sums can be gained or lost in short periods. Although fear of missing out (FOMO) has been positively linked to this type of activity, less is known about the role of regret, such as how people react to actions taken (acts of commission) or not taken (acts of omission). Anticipated regret was investigated in a study involving 403 investors ( M = 325, F = 73, Other = 5) recruited from an online panel and presented with meme coin scenarios that manipulated omission (not buying) or commission (sold early) while also examining the roles of social comparison and temporal framing. Scenarios were arranged in a 2 Ă 2 Ă 2 factorial design with FOMO, risk tolerance, impulsivity, financial literacy and problem gambling included as covariates to control for potential individual differences. Acts of commission were associated with greater regret and negative emotion but not with FOMO-based investment decisions. No effects were found for temporal distance or social comparison. At-risk and problem-gambling investors were also found to be more vulnerable to negative emotions and risky intention decision-making than non-risk gamblers. FOMO and risk tolerance were related to making decisions based on FOMO, whereas cryptocurrency literacy appeared to mitigate this tendency. These findings underscore the potential value of consumer education in raising awareness of psychological biases that are likely to lead to riskier speculative decisions.
Decentralized exchanges (DEXs) form a cornerstone of the decentralized finance (DeFi) ecosystem, processing token trades worth billions of dollars daily. Yet, a significant fraction of these trades are suboptimal: alternative routing paths could yield more target tokens. Addressing this inefficiency is both practically urgent and theoretically compelling. Building on the linear line-graph-based routing method of Zhang et al. (2025), we propose three key extensions that better capture real-world trading complexity. First, we introduce a breadth-first search (BFS) link iteration rule that reduces computational cost and average execution time without sacrificing profitability. Second, we design a route-splitting strategy that divides large trades into smaller ones, alleviating price slippage and increasing average trader profits, albeit at the cost of higher computational overhead. Third, we generalize the method beyond a single DEX to a multi-DEX aggregator setting, reflecting actual trading environments. Using empirical data from Uniswap V2 and Sushiswap V2, we demonstrate that these extensions substantially improve both computational efficiency and profitability, establishing a foundation for future routing enhancements.
The COVID-19 pandemic has accelerated the adoption of digital health solutions such as telemedicine, Internet of Medical Things (IoMT), and AI-based diagnostics, enabling remote monitoring and contactless consultations. While IoMT devicesâincluding wearable sensors and implantablesâhave enhanced continuous healthcare delivery, they have also introduced challenges related to security, privacy, interoperability, and latency. Traditional blockchain frameworks, though effective in ensuring decentralized trust and immutability, are resource-intensive and unsuitable for constrained IoMT environments. To address these limitations, this study proposes a Lightweight BlockchainâIoMT framework tailored for secure remote healthcare in the post-pandemic era. The proposed architecture follows a three-tier design: (i) the IoMT Device Layer for real-time physiological data collection, (ii) the Fog/Edge Layer functioning as blockchain gateways for authentication and pre-processing, and (iii) the Cloud Layer for storage, analytics, and decision support. By incorporating lightweight consensus mechanisms such as Proof-of-Authentication (PoAh) or Delegated Proof-of-Stake (DPoS), the system minimizes latency and energy consumption compared to Proof-of-Work. Security is reinforced through elliptic curve cryptography (ECC) and smart contracts, ensuring data confidentiality, integrity, and controlled access, while complying with global standards such as HIPAA and GDPR. Experimental analysis demonstrates that the lightweight blockchainâIoMT framework outperforms conventional blockchain models in transaction throughput, scalability, and energy efficiency. Moreover, the integration of machine learning within the cloud layer supports predictive analytics and personalized care.
The transition to post-quantum cryptography poses an unprecedented challenge for Bitcoin and Ethereum, as it involves implementing a defensive downgrade that imposes immediate, severe costs with no tangible benefits. While quantum computers capable of breaking secp256k1 require between 523â2,500 logical qubits, with the author deriving 523 logical qubits as an algorithmic lower bound (not inclusive of arithmetic and ancilla qubits) for a canonical Shor/phase-estimation circuit using the formula QL = 2âlog2(n)â + 2 + âlog2(2 + 1/(2Δ))â for Δ = 0.001, and conservative estimates ranging up to 2,500 logical qubits based on comprehensive resource modelsâsignificantly less than the 2,100â2,400 logical qubits es- timated for general elliptic curvesâcurrent systems achieve only âŒ100 logical qubits. IBMâs quantum roadmap projects 500â1,000 logical qubits by 2029, placing the critical threshold within 4â10 years depending on which estimate proves accurate. This timeline collides with the reality that convincing decentralized communities to accept 50% capacity loss and 2â 3Ă fee increases may take 10â15 years in themselves, based on historical governance patterns where even beneficial upgrades required 2â5+ years. Current testnet implementations on per- missioned systems show measurable performance degradation. Critically, this data comes from fundamentally different architectures than permissionless networks, which will likely experience 30â50% additional performance degradation due to global verification requirements, heterogeneous hardware, and compounding propagation delays. This methodological limitationâextrapolating from permissioned to permissionless systemsârepresents a critical infrastructure failure that introduces massive uncertainty into migration planning. Com- pounding this challenge, secp256k1 is not officially approved by NIST under FIPS 186-5 or SP 800-186, creating additional regulatory vulnerabilities. Beyond transient impacts, PQC creates permanent state bloat, with quantum-resistant accounts requiring 59 times more storage (1,952 bytes / 33 bytes = 59.2Ă for ML-DSA-65), thereby accelerating centralization- tion. This paper presents a comprehensive framework acknowledging these harsh realities. While we propose specific BIP/EIP implementations and optimization strategies that might achieve 50â60% capacity retention, we recognize that the quantum threat timeline may now be shorter than even the minimum viable migration period. Unlike beneficial upgrades like SegWit (which took 20 months for activation and 5+ years for 50% adoption despite offering improvements), PQC migration is a purely defensive measure imposing only costs. The stark reality: blockchain communities must choose between accepting immediate emergency action or facing quantum vulnerability by 2029.
Decentralized resource markets are Web 3.0 applications that build open-access platforms for trading digital resources among users without any central management. They promise cost reduction, transparency, and flexible service provision. However, these markets usually have large workload that must be processed in a timely manner, leading to serious scalability problems. Despite the large amount of work on blockchain scalability, existing solutions are ineffective as they do not account for these markets' work models and traffic patterns. We introduce chainScale, a secure hybrid sidechain-sharding solution that aims to boost throughput of decentralized resource markets and reduce their latency and storage footprint. At its core, chainScale leverages dependent sidechains and functionality-oriented workload splitting to parallelize traffic processing by having each market module assigned to a sidechain. Different from sharding, chainScale does not incur any cross-sidechain transactions that tend to be costly. chainScale introduces several techniques, including hierarchical workload sharing that further sub-divides overloaded modules, and weighted miner assignment that assigns miners with vested interest in the system to critical modules' sidechains. Furthermore, chainScale employs sidechain syncing to maintain the mainchain as the single truth of system state, and pruning to discard stale records. Beside analyzing security, we build a proof-of-concept implementation for a distributed file storage market as a use case. Our experiments show that, compared to a single sidechain-based prior solution, chainScale boosts throughput by 4x and reduces confirmation latency by 5x. Also, they show that chainScale outperforms sharding by 2.5x in throughput and 3.5x in latency.
Ensuring the integrity of business processes without disclosing confidential business information is a major challenge in inter-organizational processes. This paper introduces a zero-knowledge proof (ZKP)-based approach for the verifiable execution of business processes while preserving confidentiality. We integrate ZK virtual machines (zkVMs) into business process management engines through a comprehensive system architecture and a prototypical implementation. Our approach supports chained verifiable computations through proof compositions. On the example of product carbon footprinting, we model sequential footprinting activities and demonstrate how organizations can prove and verify the integrity of verifiable processes without exposing sensitive information. We assess different ZKP proving variants within process models for their efficiency in proving and verifying, and discuss the practical integration of ZKPs throughout the Business Process Management (BPM) lifecycle. Our experiment-driven evaluation demonstrates the automation of process verification under given confidentiality constraints.
Rules of origin are a core element of any free trade agreement, but their complexity can present significant challenges for efficient and compliant use. This paper discusses the challenges and opportunities in automating origin calculations for businesses involved in cross-border trade. It focuses on the role of Enterprise Resource Planning (ERP) systems, customs software and Long-Term Supplier Declarations (LTSDs) in simplifying compliance with preferential origin rules. Focusing on the United Kingdomâs trade, the paper outlines key factors businesses must consider to effectively automate origin management, such as rules interpretation, data quality, legal documentation and supplier cooperation. The potential roles of distributed ledger technology (DLT) and automation within customs declarations software are also explored.
Rui Han, Bin Yuan, Weizhong Qiang, Deqing Zou · 5 authors
The widespread use of IoT devices in the accommodation and hospitality sectors has created demand for temporary device-permission sharing and transfer. Prior work has largely focused on security issues in device permission sharing, with far less attention devoted to device permission transfer. However, inappropriate access control management during device permission transfer can also lead to violations of the users' expectations of control over their devices. For example, a malicious host retaining or regaining access to a camera after its permission has been transferred to a tenant. In this paper, we present the first systematic study on understanding and enhancing the security of device permission transfer in IoT leasing. To this end, we propose Forseti, a new authorization framework that leverages zero-knowledge proof and a decentralized ledger to ensure that the rights of both hosts and tenants are not violated. Our evaluation demonstrates that Forseti is effective, efficient, scalable, and compatible with existing IoT platforms.
Federated Learning (FL) offers a promising paradigm for privacy-preserving collaborative training, yet it remains highly vulnerable to adversarial behaviors, client unreliability, and challenges associated with non-independent and identically distributed (non-IID) data. Existing secure aggregation techniques, while preserving confidentiality, fail to guarantee the integrity and trustworthiness of model updates, leaving FL deployments exposed to poisoning and consistency attacks. This work introduces FL-SMPC++, a robust and privacy-preserving FL framework designed to address these challenges. The primary objective is to develop a scalable solution that ensures verifiable, privacy-preserving aggregation while mitigating malicious client behaviors, dropouts, and data heterogeneity. Our approach integrates Secure Multi-Party Computation (SMPC), Pedersen commitments, and zero-knowledge proofs (ZKPs) to cryptographically bind clients' submitted updates to their validation outcomes without revealing private data. We propose a dynamic client selection strategy based on shared validation performance, a dropout-tolerant threshold aggregation protocol, and a warm-up initialization phase to counteract non-IID distributions. Comprehensive experiments on MNIST, CIFAR-10, FEMNIST, and UCI Heart Disease show that FL-SMPC++ consistently outperforms FedAvg, FedProx, and FedNova. For example, under a label-flipping attack with 30% malicious clients on CIFAR-10 (non-IID), FL-SMPC++ achieves 78.9% accuracy compared to 67.4% for FedAvg, representing an absolute gain of 11.5%. Across datasets, the framework limits accuracy degradation to 6â8% under attack, while baselines suffer 13â20% losses. These results demonstrate that FL-SMPC++ achieves strong cryptographic privacy guarantees together with empirically validated resilience and convergence, offering a scalable and practical blueprint for trustworthy FL in adversarial and resource-constrained environments. âą A novel FL framework combines SMPC, commitments, and zero-knowledge proofs. âą Ensures submitted model updates match validated ones without revealing them. âą Uses dynamic validation for secure and fair client selection. âą Tolerates client dropouts using a threshold-based aggregation mechanism. âą Outperforms baseline FL methods under adversarial and non-IID conditions.
Abstract This study provides a comprehensive bibliometric analysis of FinTech research spanning from 1968 to 2025, using 2760 articles indexed in the Web of Science database. It aims to uncover major publication trends, core theoretical frameworks, emerging topics, and the intellectual structure of FinTech scholarship. Employing VOSviewer and Harzingâs Publish or Perish software, this study maps co-occurrence networks, citation structures, and thematic clusters. It analyzes document types, source distribution, geographical contributions, keyword evolution, and the top 10 most cited papers in FinTech literature. The analysis reveals a significant surge in FinTech research since 1968, driven by the growing impact of digital finance innovations. The top three countries contributing to FinTech publications are the USA, England, and China. Dominant publication outlets include the International Journal of Bank Marketing and the Journal of Financial Services Marketing. Key research themes have evolved across three distinct periods: early banking and innovation (1968â1999), customer satisfaction and trust (2000â2011), and bank performance and digital adoption (2012â2025). Emerging topics include blockchain, mobile banking, crowdfunding, and Internet banking. The Technology Acceptance Model (TAM), along with its extended versions (TAM2, TAM3, UTAUT), is identified as the foundational theoretical framework in this field. The co-citation and keyword cluster analysis confirm the centrality of trust, risk, satisfaction, and performance in shaping FinTech outcomes. These findings not only synthesize FinTechâs academic development but also inform future research by identifying intellectual gaps and high-impact trends. The study highlights the growing integration between FinTech and consumer behavior and calls for deeper exploration into regulatory, ethical, and cybersecurity issues affecting FinTech adoption. Beyond the banking sector, the thematic patterns uncovered particularly in areas such as blockchain-based supply chain finance, crowdfunding ecosystems, and AI-enabled embedded financial services signal substantial strategic implications for non-financial firms. These include enhanced liquidity management, decentralized capital access, and data-driven business model innovation across diverse industries such as manufacturing, retail, and digital commerce.
Code reuse is a common practice in software engineering. Developers of smart contracts pervasively reuse subcontracts to improve development efficiency. Like any program language, such subcontract reuse may unexpectedly include, or introduce vulnerabilities to the end-point smart contract. Indeed, prior empirical studies have identified a number of issues caused by code reuse in smart contracts. Unfortunately, automatically detecting such issues poses several unique challenges. Particularly, in most cases, smart contracts are compiled as bytecode, whose class-level information (e.g., inheritance, virtual function table), and even semantics (e.g., control flow and data flow) are fully obscured as a single smart contract after compilation. Therefore, it is rather difficult to identify the reused parts of subcontract from a given smart contract, not to mention finding potential vulnerabilities caused by subcontract misuse.In this paper, we propose Satellite, a new bytecode-level static analysis framework for subcontract misuse vulnerability (SMV) detection in smart contracts. Satellite incorporates a series of novel designs to enhance its overall effectiveness.. Particularly, Satellite utilizes a transfer learning method to recover the inherited methods, which are critical for identifying subcontract reuse in smart contracts. Further, Satellite extracts a set of fine-grained method-level features and performs a method-level comparison, for identifying the reuse part of subcontract in smart contracts. Finally, Satellite summarizes a set of SMV indicators according to their types, and hence effectively identifies SMVs. To evaluate Satellite, we construct a dataset consisting of 58 SMVs derived from real-world attacks and collect additional 56 SMV patterns from SOTA studies. Experiment results indicate that Satellite exhibits good performance in identifying SMV, with a precision rate of 84.68% and a recall rate of 92.11%. In addition, Satellite successfully identifies 14 new/unknown SMV over 10,011 realworld smart contracts, affecting a total amount of digital assets worth 201,358 USD.
Abstract Health Care Information Systems leverage Body Area Networks (BANs) to provide real-time monitoring and automated medical interventions, significantly enhancing patient care. However, security and privacy concerns present significant barriers to widespread adoption, with broken access control being a considerable risk. This research proposes an authorization framework to secure BANs, addressing critical issues such as unauthorized access and policy enforcement failures in electronic health records (EHRs). Our study introduces a Multi-Modular System Architecture that enhances access control, incorporating a Spatio-Temporal Attribute-Based Access Control (STABAC) model to enforce dynamic location and time constraints for secure data access. We introduce the Spatio-Temporal Zone (STZone) concept, simplifying policy enforcement by integrating time and location attributes. To ensure policy integrity and security, we employ Time Colored Petri Nets (TCPN) for formal policy analysis, detecting violations, and ensuring compliance with real-time constraints. Additionally, blockchain technology is leveraged to maintain policy integrity, preventing unauthorized modifications. Experimental validation demonstrates the effectiveness of the proposed framework in enforcing secure access control while maintaining system usability. The findings highlight the frameworkâs potential in securing BANs, offering a scalable and adaptable approach to mitigating emerging security threats in healthcare information systems.