This paper proposes a method of emulation of \verb|OP_RAND| opcode on Bitcoin through a trustless interactive game between transaction counterparties. The game result is probabilistic and doesn't allow any party to cheat, increasing their chance of winning on any protocol step. The protocol can be organized in a way unrecognizable to any external party and doesn't require some specific scripts or Bitcoin protocol updates. We will show how the protocol works on the simple \textbf{Thimbles Game} and provide some initial thoughts about approaches and applications that can use the mentioned approach.
Ben Biedermann, Matthew Scerri, Victoria Kozlova, Joshua Ellul
Web3’s decentralised infrastructure has upended the standardised approach to digital identity established by protocols like OpenID Connect. Web2 and Web3 currently operate in silos, with Web2 leveraging selective disclosure JSON web tokens (SD-JWTs) and Web3 dApps being reliant on on-chain data and sometimes clinging to centralised system data. This fragmentation hinders user esxperience and the interconnectedness of the digital world. This article explores the integration of Web3 within the OpenID Connect framework, scrutinising established authentication protocols for their adaptability to decentralised identities. The research examines the interplay between OpenID Connect and decentralised identity concepts, the limitations of the existing protocols like OpenID Connect for verifiable credential issuance, OpenID Connect framework for verifiable presentations, and self-issued OpenID provider. As a result, a novel privacy-preserving digital identity bridge is proposed, which aims to answer the research question of whether authentication protocols should inherently support Web3 functionalities and the mechanisms for their integration. Through a Decentralised Autonomous Organisation (DAO) use case, the findings indicate that a privacy-centric bridge can mitigate the existing fragmentation by aggregating different identities to provide a better user experience. While the digital identity bridge demonstrates a possible approach to harmonise digital identity across platforms for their use in Web3, the bridging is unidirectional and limits root trust of credentials. The bridge’s dependence on centralised systems may further fuel the debate on (de)centralised identities.
This paper introduces 3MEthTaskforce (https://3meth.github.io), a multi-source, multi-level, and multi-token Ethereum dataset addressing the limitations of single-source datasets. Integrating over 300 million transaction records, 3,880 token profiles, global market indicators, and Reddit sentiment data from 2014-2024, it enables comprehensive studies on user behavior, market sentiment, and token performance. 3MEthTaskforce defines benchmarks for user behavior prediction and token price prediction tasks, using 6 dynamic graph networks and 19 time-series models to evaluate performance. Its multimodal design supports risk analysis and market fluctuation modeling, providing a valuable resource for advancing blockchain analytics and decentralized finance research.
The Federated Unified Secure Exchange (FUSE) algorithm represents a breakthrough in computer science and cybersecurity, building upon three foundational elements: Homomorphic Encryption, Zero-Knowledge Proofs, and Federated Learning. By deeply integrating these three pillars, FUSE not only guarantees data integrity and privacy in decentralized environments but also maintains high performance and remarkable scalability. This paper details the architecture, mathematical principles, and real-world applications of FUSE across Internet of Things (IoT), healthcare, finance, and supply chains. In addition, it compares FUSE with several “classic” algorithms that have dramatically changed the world—such as QuickSort, RSA, Dijkstra, PageRank, FFT, Backpropagation, SHA, Monte Carlo, Gradient Descent, and Blockchain—highlighting how FUSE addresses existing limitations in data protection and distributed computation.
This thesis presents novel techniques to improve the efficiency, scalability, and security of Data Confidence Fabrics (DCFs), a framework that ensures data authenticity and integrity in large scale, heterogeneous distributed systems by generating metadata at each point of data formation, processing, and transmission. Despite their strengths, DCFs face significant challenges, including excessive annotation and transactional overhead, which reduce scalability and efficiency, and metadata privacy risks, which compromise sensitive network information. To address these challenges, this research proposes methods that improve system scalability, enable efficient annotation retrieval, and protect sensitive network information, with a focus on the Alvarium Data Confidence Fabric, though the solutions are broadly applicable to other DCFs. A primary contribution of this work is addressing the efficiency and scalability challenges by reducing annotation overhead through compact annotation techniques, particularly annotation batching. By aggregating multiple annotations into a single ledger transaction, this approach minimizes redundancy, storage costs and ledger interactions. However, batching introduces complexity in retrieving individual annotations. To overcome this, two retrieval methods are proposed: Batch Keys, which use mapping tables to quickly locate individual annotations based on a Batch key, and Bloom Filters, which provide a low-overhead approach for efficiently verifying the presence of annotations. Another major focus of this work is mitigating metadata privacy risks, where adversaries could analyze annotations to infer network structures. To obscure network patterns, two privacy-preserving schemes, Hostname Mapping and Hostname Encryption, are introduced, with Hostname Encryption offering a more efficient and secure alternative. Additionally, the research highlights how timestamp metadata can be exploited to reconstruct network structures through clustering techniques. To mitigate this vulnerability, a timestamp obfuscation solution is proposed, introducing controlled randomness to disrupt predictable timing patterns and protect network confidentiality. In summary, the thesis introduces and evaluates methods that significantly enhance the efficiency, scalability, and security of DCFs. These contributions strengthen the practical deployment of DCFs in cloud-edge environments and provide a foundation for future research in secure and trustworthy data management across distributed systems.
Natalia Borgoñós García, María Hernández Padilla, Antonio Fernando Skarmeta Gómez
Abstract Data Spaces are ecosystems designed to allow multiple organizations or companies to share data in a secure manner. Despite the potential of these technologies, they encounter a number of challenges and privacy issues that limit their use. Privacy Preserving Enablers are mechanisms developed to tackle these difficulties, ensuring data integrity and access control. This paper aims to analyze the role of some Privacy Preserving Enablers and its integration with Connectors in the context of Data Spaces. The research will focus on key enablers, including a Self-Sovereign Identity with Zero-Knowledge Proof, which is a privacy preserving approach that allows users to verify their identity and attributes without the need to disclose underlying data, ensuring their privacy. Additionally, the usage of Sticky Policies instantiated through Attribute-Based Encryption attaches control policies into the encrypted data in order to have an attribute-based access control, enhancing its security. The application of Policies Enforcement assure the consistent application of policies and the maintenance of the security within the Data Space.
Senthil G. A, R. Prabha, R. Avudainayaki, Srinidhi Sundaram · 5 authors
Due to the rise of cryptocurrencies and blockchain technology, banking is changing forever through introducing transparent, secure, and decentralized solutions. They strongly rely on solid mathematics to ensure the security and functionality of these technologies. This paper explores the importance of mathematics in blockchain and cryptocurrency systems. In this article, we take a look at the properties of cryptographic hash functions which are necessary for tamper–evidence data integrity and blockchain records immutability. Next, we dive into public-key cryptography and digital signatures, which are core to the security of transactions and user authentication. These aspects are essential to maintaining secure communication and identity verification within the blockchain realm. So not PoW—because everyone knows PoW now—we go to another method of consensus such as a PoS, for example. With PoS, validation is dependent on ownership of bit coin rather than the vastly voracious computational power that PoW is reliant upon, thus making PoS more energy efficient and opening a wider net in terms of network participation. It discusses about the role of error-correcting codes in blockchain systems, and why they are needed to ensure that data is protected from unintentional corruption or deliberate attacks. These codes guarantee information saved on the blockchain has reliability and sustainability. These methods also include mathematical modeling and game theoretic applications to blockchain design that study participant behavior, promote cooperative behaviors, and deter malicious actions. In the world of cryptocurrency, these mathematical principles have particular applications; cryptographic techniques are used by consensus mechanisms and smart contracts to ensure privacy in decentralized and secure transactions. It is a powerful new area of mathematics that offers exciting possibilities for blockchain applications particularly for privacy-preserving transactions and computations. We provide a comprehensive overview of these essential mathematical concepts in order to provide developers, investors, and policymakers an insight into the underlying technology that sustains blockchain and cryptocurrency systems. All of which allows stakeholders to confidently orient themselves in this fast-emerging area. Lastly, we baptize some path-breaking directions for blockchain, including homomorphic encryption which enables evaluating expressions on ciphertexts.
Ensuring the reproducibility of scientific simulations is a persistent challenge, despite current best practices like version control and containerization. Factors such as floating-point arithmetic variations, hardware differences, and concurrency issues often prevent bit-for-bit replication of results. This paper investigates the techniques that distributed ledger technologies employ to achieve deterministic computations and application of these techniques to enhance the reproducibility, trustworthiness and verifiability of scientific simulations. We explore two primary approaches: executing simulations directly “on-chain” for complete transparency and deterministic replay, and performing computations “off-chain” while anchoring their integrity to a blockchain via cryptographic proofs, such as Zero-Knowledge Proofs (ZKPs) and Merkle trees.
Christos Karapapas, Iakovos Pittaras, George C. Polyzos, Constantinos Patsakis
The InterPlanetary File System~(IPFS) offers a decentralized approach to file storage and sharing, promising resilience and efficiency while also realizing the Web3 paradigm. Simultaneously, the offered anonymity raises significant questions about potential misuse. In this study, we explore methods that malicious actors can exploit IPFS to upload and disseminate harmful content while remaining anonymous. We evaluate the role of pinning services and public gateways, identifying their capabilities and limitations in maintaining content availability. Using scripts, we systematically test the behavior of these services by uploading malicious files. Our analysis reveals that pinning services and public gateways lack mechanisms to assess or restrict the propagation of malicious content.
This research explores the factors contributing to the failure of cryptocurrency exchanges by analyzing a sample of 845 exchanges. Using logit and probit models, it identifies key variables affecting cryptocurrency exchange defaults. The results show that cryptocurrency exchanges that are centralized, located in countries with high transparency indices, and offer fewer peer cryptocurrencies are more likely to default. Additionally, exchanges that impose high withdrawal fees and have no restrictions on clients from the United States are also positively associated with defaults. Moreover, the absence of referral schemes and having lower ratings each contributes marginally to defaults. Machine learning (ML) models including random forest, support vector machine, stacked ensemble confirm the robustness and high predictability of cryptocurrency exchange defaults. • This study uses statistical and ML models to predict cryptocurrency exchange default. • Centralized exchanges from high-transparency-index nations are more prone to default. • Limited coin listings, high fees, and U.S. client access increase the default risk. • Lacking referral programs and low ratings both marginally contribute to default.
The aim of this article is to examine the reasons why cryptocurrency volatility hinders its potential to replace fiat money as legal tender. We focus on Bitcoin and Ethereum for this analysis. By applying an augmented Dickey-Fuller stationarity test, we demonstrate that cryptocurrencies lack a long-term trend; instead, their movement is erratic and highly volatile. Furthermore, eGARCH models indicate that volatility tends to decrease and is expected to persist in this pattern. In summary, theoretical and empirical analysis suggests that, due to their nature based solely on supply and demand and their high volatility, cryptocurrencies are not suitable as primary investment instruments or stores of value.
Modern database systems are expected to handle dynamic data whose characteristics may evolve over time. Many popular database benchmarks are limited in their ability to evaluate this dynamic aspect of the database systems. Those that use synthetic data generators often fail to capture the complexity and unpredictable nature of real data, while most real-world datasets are static and difficult to create high-volume, realistic updates for. This paper introduces CrypQ, a database benchmark leveraging dynamic, public Ethereum blockchain data. CrypQ offers a high-volume, ever-evolving dataset reflecting the unpredictable nature of a real and active cryptocurrency market. We detail CrypQ's schema, procedures for creating data snapshots and update sequences, and a suite of relevant SQL queries. As an example, we demonstrate CrypQ's utility in evaluating cost-based query optimizers on complex, evolving data distributions with real-world skewness and dependencies.
The rise of Decentralized Finance (DeFi) has brought novel financial opportunities but also exposed serious security vulnerabilities, with flash loans frequently exploited for price manipulation attacks. These attacks, leveraging the atomic nature of flash loans, allow malicious actors to manipulate DeFi protocol oracles and pricing mechanisms within a single transaction, causing substantial financial losses. Traditional smart contract analysis tools address some security risks but often struggle to detect the complex, inter-contract dependencies that make flash loan attacks challenging to identify. In response, we introduce FlashDeFier, an advanced detection framework that enhances static taint analysis to target price manipulation vulnerabilities arising from flash loans. FlashDeFier expands the scope of taint sources and sinks, enabling comprehensive analysis of data flows across DeFi protocols. The framework constructs detailed inter-contract call graphs to capture sophisticated data flow patterns, significantly improving detection accuracy. Tested against a dataset of high-profile DeFi incidents, FlashDeFier identifies 76.4% of price manipulation vulnerabilities, marking a 30% improvement over DeFiTainter. These results highlight the importance of adaptive detection frameworks that evolve alongside DeFi threats, underscoring the need for hybrid approaches combining static, dynamic, and symbolic analysis methods for resilient DeFi security.
Francesco D’Amato, Roberto Saltini, Thuy-An Tran, Luca Zanolini
Gasper, the consensus protocol currently employed by Ethereum, typically requires 64 to 95 slots -- the units of time during which a new chain extending the previous one by one block is proposed and voted -- to finalize. This means that under ideal conditions -- where the network is synchronous, and all chain proposers, along with more than two-thirds of the validators, behave as dictated by the protocol -- proposers construct blocks on a non-finalized chain that extends at least 64 blocks. This exposes a significant portion of the blockchain to potential reorganizations during changes in network conditions, such as periods of asynchrony. Specifically, this finalization delay heightens the network's exposure to Maximum Extractable Value (MEV) exploits, which could undermine the network's integrity. Furthermore, the extended finalization period forces users to balance the trade-off between economic security and transaction speed. To address these issues and speed up finality, we introduce a partially synchronous finality gadget, which we combine with two dynamically available consensus protocols -- synchronous protocols that ensure safety and liveness even with fluctuating validator participation levels. This integration results in secure ebb-and-flow protocols [SP 2021], achieving finality within three slots after a proposal and realizing 3-slot finality.
This paper presents a comprehensive analysis of storage proofs in the Ethereum ecosystem, examining their role in addressing historical and cross-chain state access challenges. We systematically review existing approaches to historical state verification, comparing Merkle Mountain Range (MMR) and Merkle-Patricia trie (MPT) architectures. An analysis involves their respective performance characteristics within zero-knowledge contexts, where performance challenges related to Keccak-256 are explored. The paper also examines the cross-chain verification, particularly focusing on the interactions between Ethereum and Layer 2 networks. Through careful analysis of storage proof patterns across different network configurations, we identify and formalize three architectures for cross-chain verification. By organizing this complex technical landscape, this analysis provides a structured framework for understanding storage proof implementations in the Ethereum ecosystem, offering insights into their practical applications and limitations.
Penelitian ini mengembangkan aplikasi terdesentralisasi (DApp) untuk manajemen sertifikat digital menggunakan Non-Fungible Token (NFT) berbasis standar ERC-721 di jaringan Ethereum. Aplikasi ini dirancang untuk meningkatkan keamanan, dan transparansi dalam pembuatan, pengelolaan, serta verifikasi sertifikat digital. Hasil penelitian menunjukan bahwa penggunaan teknologi blockchain memberikan jaminan bahwa setiap sertifikat yang diterbitkan tidak hanya dapat dilacak dan diverifikasi secara publik, tetapi juga tidak dapat diubah atau dimanipulasi setelah diterbitkan. Hal ini membuat sistem lebih aman dibandingkan dengan metode tradisional. Implementasi standar ERC-721 memungkinkan setiap sertifikat digital yang diterbitkan dalam bentuk NFT memiliki identitas unik yang tidak dapat diduplikasi atau dipalsukan. Selain itu, teknologi ini juga memungkinkan pemilik sertifikat untuk memiliki bukti kepemilikan yang aman dan dapat diverifikasi oleh pihak ketiga. Pengembangan dan pengujian smart contract yang ditulis dalam bahasa pemrograman Solidity pada platform Ethereum juga berhasil membuktikan bahwa smart contract yang dibuat berfungsi dengan baik dalam berbagai aspek seperti penciptaan, transfer, verifikasi, dan penghapusan sertifikat. Smart contract ini menunjukkan keamanan sesuai dengan spesifikasi yang diharapkan, menjadikannya solusi inovatif untuk manajemen sertifikat digital. Kata Kunci - Blockchain, Ethereum, DApp, Sertifikat Digital, NFT, ERC-721.
Nima Shiri Harzevili, Mohammad Mahdi Mohajer, Jiho Shin, Moshi Wei · 11 authors
Checker bugs in Deep Learning (DL) libraries are critical yet not well-explored. These bugs are often concealed in the input validation and error-checking code of DL libraries and can lead to silent failures, incorrect results, or unexpected program behavior in DL applications. Despite their potential to significantly impact the reliability and performance of DL-enabled systems built with these libraries, checker bugs have received limited attention. We present the first comprehensive study of DL checker bugs in two widely-used DL libraries, i.e., TensorFlow and PyTorch. Initially, we automatically collected a dataset of 2,418 commits from TensorFlow and PyTorch repositories on GitHub from Sept. 2016 to Dec. 2023 using specific keywords related to checker bugs. Through manual inspection, we identified 527 DL checker bugs. Subsequently, we analyzed these bugs from three perspectives, i.e., root causes, symptoms, and fixing patterns. Using the knowledge gained via root cause analysis of checker bugs, we further propose TensorGuard, a proof-of-concept RAG-based LLM-based tool to detect and fix checker bugs in DL libraries via prompt engineering a series of ChatGPT prompts. We evaluated TensorGuard's performance on a test dataset that includes 92 buggy and 135 clean checker-related changes in TensorFlow and PyTorch from January 2024 to July 2024. Our results demonstrate that TensorGuard has high average recall (94.51\%) using Chain of Thought prompting, a balanced performance between precision and recall using Zero-Shot prompting and Few-Shot prompting strategies. In terms of patch generation, TensorGuard achieves an accuracy of 11.1\%, which outperforms the state-of-the-art bug repair baseline by 2\%. We have also applied TensorGuard on the latest six months' checker-related changes (493 changes) of the JAX library from Google, which resulted in the detection of 64 new checker bugs.
Viktor Valaštín, Dušan Morháč, Kristián Košťál, Ivan Kotuliak
Liquidity is critical for a healthy and thriving blockchain ecosystem, enabling value exchange between participants. However, achieving unified liquidity across heterogeneous blockchain platforms remains challenging due to disparities in architecture, virtual machines, and asset management logic. These disparities force assets to be wrapped into other formats to ensure compatibility with underlying systems, thus fragmenting liquidity into multiple pools. This paper proposes LiquiSpell, a novel protocol that aims to unify liquidity across multiple parachains within the Polkadot ecosystem. By leveraging the cross-chain message passing (XCMP), LiquiSpell introduces the concept of a universal transaction that can be constructed to be compatible with any parachain, regardless of its underlying architecture or asset management pallet. This approach overcomes the obstacles posed by the diverse nature of parachains, enabling seamless asset sharing and enhancing cross-chain interoperability. The proposed solution mitigates liquidity fragmentation within the Polkadot ecosystem. It presents a framework that can be extended to other multichain environments outside Polkadot. Ultimately, LiquiSpell aims to foster a thriving ecosystem by facilitating the introduction of new assets and increasing overall liquidity, thereby driving innovation and adoption within the decentralized finance (DeFi) landscape.
Open access
Advanced Data Storage Technologies
Innovative Microfluidic and Catalytic Techniques Innovation
Abstract The adoption of digital assets and distributed ledger technology in finance is rapidly increasing. This adoption introduces new types of risks, currently not adequately covered in conventional risk management frameworks. This paper identifies, reviews, and categorises these risks. It draws on a systematic review of literature and classifies the vulnerabilities by layer—network layer, consensus layer, protocol layer, and enablement layer.
William Fernando Martínez Luna, Ana María Moreno Ballesteros, Edgar José Ruiz Dorantes
NFTs (non-fungible tokens) enable the commercialization of goods and services through blockchain technology, enhancing the security, transparency, and speed of transactions. The primary challenge NFTs face is their connection to the underlying asset, ensuring that transferring the token also means transferring the linked asset. This interdisciplinary article examines the technical and legal challenges of creating and linking a digital asset to an NFT. To explain the binding process, an NFT associated with a digital artwork was created, and relevant internal and uniform legal regulations were analyzed.
Juseong Jeon, Sejin Park, Deokwoo Lee, Juncheol Ahn
The blockchain market has been experiencing rapid growth recently. Alongside this, Web3 services based on blockchain technology are expanding and gaining attention. These services can support not only encompass gaming and financial services but also leverage the numerous nodes existing in the network to distribute tasks, thereby supporting parallel computing. However, there is no way to directly access web3 services in the current network topology, which limits the expansion of services. Therefore, the current Web3 relies on centralized web servers as access points for services, resulting in the inevitable loss of benefits associated with decentralization, such as the shift in data sovereignty.
In this study, a new data-sharing method is proposed that uses a private InterPlanetary File System—a decentralized storage system operated within a closed network—to distribute data to external entities while making its authenticity verifiable. Among the two operational modes of IPFS, public and private, this study focuses on the method for using private IPFS. Private IPFS is not open to the general public; although it poses a risk of data tampering when distributing data to external parties, the proposed method ensures the authenticity of the received data. In particular, this method applies a type of zero-knowledge proof, namely, the Groth16 protocol of zk-SNARKs, to ensure that the data corresponds to the content identifier in a private IPFS. Moreover, the recipient’s name is embedded into the distributed data to prevent unauthorized secondary distribution. Experiments confirmed the effectiveness of the proposed method for an image data size of up to 120 × 120 pixels. In future studies, the proposed method will be applied to larger and more diverse data types.