Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

485 papersLast indexed Aug 31, 2026
Search papers

Paper index

485 results · page 4 of 21

Clear filters
Apr 27, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
Household Guilds: Governance Infrastructure for Human-Agent Organizations

Yongkang Liu

AI agents are evolving from on-demand tools into persistent, semi-autonomous workers. When a person manages multiple agents simultaneously, humans and agents together form a collaborative organization—what we call a Household Guild. Existing practice either plugs agents into human instant messaging platforms (e.g., Telegram Bots) or subsumes them into Decentralized Autonomous Organizations (DAOs); neither simultaneously satisfies three requirements: governance scalability, behavioral risk containment, and resource consumption accountability. We reposition social software as governance infrastructure: it carries not only communication but also rule deployment, resource lifecycle management, and output measurement. The system operates on edge servers, running by default within the Household's internal network and connecting to the public network only when cross-guild interaction is needed. We describe the guild's internal governance mechanisms (natural-language rules, a credits economy, role differentiation) and its external interaction protocols (authorized interface agents, inter-guild settlement, credits exchange), and argue that this semi-isolated architecture simultaneously addresses scalability constraints and behavioral boundary constraints. The goal of this work is to provide a directly discussable conceptual framework for the engineering practice of human-agent organizations.

Open access
2 source records
Multi-Agent Systems and Negotiation
Mobile Agent-Based Network Management
Access Control and Trust
Original source
Apr 24, 2026·arXiv (Cornell University)
0 cites
A dataset of early blockchain-registered AI agents on Ethereum

Yulin Liu

Abstract This study presents a structured dataset of blockchain-registered artificial intelligence agents under the ERC-8004 standard on Ethereum. The dataset integrates on-chain identity records, minting transactions, transfer events, reputation summaries, and individual feedback records, together with resolved off-chain metadata where available. Data were collected from Ethereum mainnet using Web3 RPC queries and processed into tabular form to enable reproducible analysis. The dataset covers 10,000 agents within a defined block range and includes both event-level records and aggregated summaries. It enables empirical research on agent identity formation, reputation systems, service exposure, and early-stage decentralized AI ecosystems. This resource supports studies in blockchain analytics, decentralized trust infrastructure, and the emerging agentic economy.

Open access
3 source records
Blockchain Technology Applications and Security
Access Control and Trust
Mobile Agent-Based Network Management
Original source
Apr 23, 2026·International Journal on Semantic Web and Information Systems
0 cites
Semantic-Enhanced Risk-Aware Dual-Layer Privacy-Preserving Verifiable Access Control for OT Systems

Bian Zhu, Ling Niu

Industrial operational technology systems are becoming more intelligent and interconnected, requiring remote maintenance and multiparty collaboration. While traditional approaches improve efficiency, they introduce risks like data leakage and unauthorized operations. Existing access control schemes struggle with compliance verification and auditing while ensuring privacy. A novel access control scheme was proposed that combines zero-knowledge proof with the publicly verifiable covert security model. The scheme features a dual-layer verification mechanism: a basic layer using zero-knowledge proof to protect identities and permissions during remote maintenance and an enhanced layer for high-risk operations that uses oblivious transfer and digital signatures to detect malicious behavior and generate cheating certificates. Security analysis showed the scheme ensures privacy, access legitimacy, and non-repudiation. Experiments demonstrated the scheme had faster proof generation and verification compared to existing methods with effective malicious behavior detection and accountability.

Open access
Access Control and Trust
Cryptography and Data Security
Advanced Authentication Protocols Security
Original source
Apr 17, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
Hybrid E-Voting: Integrating Homomorphic Encryption and DLT for Polarized Scenarios

Furio Ruggiero

ABSTRACT E-voting in polarized contexts requires a strict balance between public verifiability, ballot secrecy, andcoercion resistance. Traditional centralized systems lack transparency, while fully decentralized modelsface scalability and privacy issues. This paper proposes a hybrid architecture compliant withOSCE/ODIHR standards [1] for low-trust environments. The protocol decouples identity from voting anoff-chain Oracle manages authorization via cryptographic tokens, while the Waves DLT acts as animmutable bulletinboard.Utilizinghomomorphicencryption[2],Zero-KnowledgeRangeProofs(ZKRP) [3],and Distributed Key Generation (DKG) [4], the system ensures End-to-End Verifiability (E2E) bydelegating tallying to auditable scripts. Finally, the study examines model limitations, specificallyregarding endpoint vulnerabilities and physical constraints on coercion resistance. KEYWORDS E-Voting, Distributed Ledger Technology, Homomorphic Encryption, End-to-End Verifiability, ZeroKnowledge Proofs PDF LINK: https://ijcionline.com/paper/15/15226ijci01.pdf VOLUME LINK: https://airccse.org/journal/ijci/Current2026.html MORE DETAILS: https://airccse.org/journal/ijci/index.html

Open access
2 source records
Internet Traffic Analysis and Secure E-voting
Cryptography and Data Security
Access Control and Trust
Original source
Apr 16, 2026·International Journal of Drug Delivery Technology
0 cites
Blockchain-Powered Distributed Medical and Drug Record Sharing with Integrity and Access Control

Dr. P. C. Prabhu Kumar, P. Poojitha, K. Satheesh Kumar, M. Charan Kumar · 6 authors

The rapid digital transformation of the healthcare and drug sector has increased the reliance on cloud infrastructures for storing and exchanging Electronic Health Records (EHRs), raising significant concerns regarding privacy breaches, unauthorized access, and data integrity. To overcome these challenges, this project proposes a secure, patient-centric medical and drug data-sharing framework that integrates blockchain technology with distributed cloud storage. In this system, patients upload encrypted Personal Health Records (PHRs) to an untrusted cloud server while maintaining complete control over access permissions. A semi-trusted Setup and Re-Encryption Server (SRS) manage cryptographic key generation and re-encryption processes, enabling healthcare providers to access only the data explicitly authorized by the patient. All access requests, key operations, and permission updates are immutably recorded on a blockchain ledger, ensuring transparency, traceability, and accountability. The design further enforces forward and backward access control, automatically revoking past privileges when permissions are modified. Experimental evaluation demonstrates that the framework effectively ensures confidentiality, integrity, and access control while resisting tampering and supporting efficient real-time medical services, making it a promising solution for secure and scalable e-Health data exchange.

Open access
Blockchain Technology Applications and Security
Cryptography and Data Security
Access Control and Trust
Original source
Apr 12, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
Blockchain-Enabled Charity Donation System for Transparency and Trust

Thotakura Meghana, Patan Hazira Bi, Katteda Moulika, Kolla Sailesh Kumar · 5 authors

Traditional philanthropic frameworks often struggle with financial opacity and a relianceon centralized intermediaries, which frequently leads to an erosion of donor trust andsystemic mismanagement. This paper proposes a Decentralized Charity Fund ManagementSystem that mitigates these risks by encoding the complete donation lifecycle withinEthereum smart contracts, ensuring transparency and accountability by design. Utilizing agovernance model inspired by Decentralized Autonomous Organizations (DAOs), thesystem grants donors proportional voting rights based on their contributions, empoweringthem to collectively oversee fund disbursement. Capital is released to campaign organizersonly after a majority of donors approve specific withdrawal proposals, which must besupported by cryptographic expenditure proofs hosted on the InterPlanetary File System(IPFS). Additionally, the system features an autonomous refund mechanism that activatesif a campaign fails to reach its financial target by a set deadline, allowing for the directreclamation of funds without central intervention. Implementation via a React-baseddecentralized application (DApp) and validation through Hardhat-based testing confirmthat this frameowrk enforces all governance rules deterministically, effectively eliminatingthe need for centralized authority in the charitable ecosystem.

Open access
2 source records
Blockchain Technology Applications and Security
FinTech, Crowdfunding, Digital Finance
Access Control and Trust
Original source
Apr 12, 2026·Proceedings of the ACM Web Conference 2026
0 cites
ShadowClone: Scalable Decentralized Identity with Cross-Domain Anonymity and Accountable Traceability

Y Liu, Zedan Zhao, Boyu Zhao, Na Wang · 6 authors

Decentralized identity (DID) is a key infrastructure for Web3, granting users sovereign control over their private identity data. While existing DID systems like FADID-TT (WWW'25) realize anonymity and traceability within a single domain, the Web3 ecosystem is a multiverse of independent domains like DeFi, GameFi, and DAO. This multi-domain reality presents critical issues for current DID solutions. First, most existing solutions are built on the monolithic committee architecture, facing severe scalability bottlenecks as the committee size grows. Second, most existing solutions cannot offer strong cross-domain anonymity, where frequent cross-domain interaction inevitably exposes the user's privacy. Third, existing methods for tracing the identities of malicious users are inefficient.

Open access
Internet Traffic Analysis and Secure E-voting
Access Control and Trust
Privacy, Security, and Data Protection
Original source
Apr 12, 2026·Proceedings of the 8th International Workshop on Emerging Trends in Software Engineering for Blockchain
0 cites
Accessing Web3 Onboarding and Trust via Vipps

Surya Bahadur Kathayat, Magnus Svendsen, Brage Hagemann Brataas

Web3 applications strive to enable decentralization and user sovereignty, but often remain inaccessible to mainstream users due to complex onboarding and unfamiliar interaction paradigms. This study presents a Web2-inspired onboarding solution that integrates an embedded custodial wallet with OpenID Connect (OIDC) authentication via Vipps, a Norwegian bank-backed identity provider with over 4.6 million verified users. The proposed approach abstracts wallet management and removes the need for seed-phrase setup while introducing real-world identity assurance into the Web3 environment. A blockchain-based Battleship proof-of-concept was developed to demonstrate the approach, aiming to make Web3 interactions more intuitive and trustworthy. A mixed-method evaluation, combining usability testing and semi-structured interviews, revealed that integrating familiar login flows with verified identities improves usability, conceptual understanding, and both peer and ecosystem trust. The findings suggest that leveraging centralized identity providers can act as a pragmatic bridge between Web2 and Web3, potentially lowering initial onboarding barriers.

Open access
Personal Information Management and User Behavior
Privacy, Security, and Data Protection
Access Control and Trust
Original source
Apr 11, 2026·Saudi Journal of Engineering and Technology
2 cites
Resilient Identity and Access Governance Architecture for Artificial Intelligence–Enabled Software-as-a-Service Ecosystems

Fahad Khayyam

Cloud-based SaaS platforms now run essential services across finance, healthcare, and government sectors. Many of these systems include automated agents and decision engines that operate at high speed and scale. Identity and access governance therefore serves as a central control layer. Traditional IAM models depend on fixed roles, centralized authorization servers, and periodic reviews. Such structures struggle in distributed, multi-tenant environments that process millions of access requests each day. Prior studies address adaptive authentication, Zero Trust security, decentralized identity, anomaly detection, and cloud resilience. However, these solutions often function separately rather than within a unified framework. This paper introduces a Resilient Identity and Access Governance Architecture that integrates real time risk evaluation, distributed policy enforcement, lifecycle governance for human and machine identities, and fault tolerance in a single design. The framework defines measurable targets for availability, detection time, throughput, and policy propagation. Risk scoring occurs during live authorization decisions, and enforcement spans multiple nodes. The result is a scalable identity governance model suitable for complex SaaS ecosystems that require high availability and consistent control.

Open access
Access Control and Trust
Information and Cyber Security
Blockchain Technology Applications and Security
Original source
Apr 10, 2026·bit-Tech
0 cites
Ethereum-Based Escrow System to Reduce the Risk of Peer-to-Peer Payment Abuse

Yudhistira Nanda Kumala, Rizky Parlika, Hendra Maulana

Peer-to-peer (P2P) payments facilitate rapid direct transactions but are frequently compromised by trust asymmetry, leading to substantial risks of non-delivery or non-payment. This study addresses these vulnerabilities by introducing a lightweight, deterministic escrow mechanism based on Ethereum smart contracts, specifically designed to bridge the regulatory gap in consumer protection. Unlike conventional escrow systems that rely on costly human intermediaries or complex decentralized autonomous organization (DAO) structures, the proposed "FairPay" model advances the state-of-the-art by offering a streamlined five-state lifecycle architecture comprising Created, Funded, WorkSubmitted, Released, and Refunded stages. The research prioritizes an analytical problem-solution flow, focusing on a state-machine design that enforces automated role-based restrictions. Methodological evaluation conducted on the Ethereum Sepolia testnet demonstrates a 100% functional success rate across all unit test scenarios. Furthermore, gas cost analysis reveals that the system is economically viable for granular transactions, with core operational functions maintaining a low execution overhead. Beyond operational success, the primary scholarly contribution lies in the design insight of balancing high cryptographic security with granular transaction accessibility, providing a scalable framework for the modern digital economy. However, the system currently assumes binary participant decisions for work verification, representing a transparency-oriented limitation in handling highly subjective service deliverables. Ultimately, this study demonstrates that algorithmic trust, mediated through a simplified state-machine, offers a more efficient and transparent alternative to existing high-complexity blockchain models, effectively resolving the tension between decentralized security and practical usability in P2P digital interactions.

Open access
Blockchain Technology Applications and Security
FinTech, Crowdfunding, Digital Finance
Access Control and Trust
Original source
Apr 5, 2026·arXiv (Cornell University)
0 cites
Context-Binding Gaps in Stateful Zero-Knowledge Proximity Proofs: Taxonomy, Separation, and Mitigation

Yoshiyuki Ootani

A zero-knowledge proximity proof certifies geometric nearness but carries no commitment to an application context. In stateful geo-content systems, where drops can share coordinates, policies evolve, and content has persistent identity, this gap can permit proof transfer between application objects unless extra operational invariants are maintained. We present a systems-security analysis of this deployment problem: a taxonomy of context-binding vulnerabilities, a formal off-circuit verification model for a transcript-adversary that holds a recorded proof but cannot obtain fresh coordinates, an assumption comparison across five binding strategy classes, and a concrete instantiation, Zairn-ZKP, that embeds drop identity, policy version, and session context as public circuit inputs. Compared with a strong off-circuit alternative based on stored-digest server checking, in-proof binding reduces operational invariants from four to two and adds no measurable proving cost relative to the sound geo-only baseline (-0.12 ms median in our setup). It also removes a correctness pitfall we identify empirically: a plausible off-circuit implementation that omits one server-side check remains vulnerable to cross-drop transfer. Measurements across six network conditions, seven venues in four countries, and an epoch-window simulation indicate that same-epoch transfer is realistic in dense urban deployments unless per-request nonces are maintained. Across five platforms and seven binding strategies, the results support a deployable methodology for reducing assumption surfaces in stateful ZK-backed verification workflows.

Open access
2 source records
Security and Verification in Computing
Access Control and Trust
Web Application Security Vulnerabilities
Original source
Apr 5, 2026·arXiv (Cornell University)
0 cites
Search-Bound Proximity Proofs: Binding Encrypted Geographic Search to Zero-Knowledge Verification

Yoshiyuki Ootani

Location-based systems that combine encrypted geographic search with zero-knowledge proximity proofs typically treat the two phases as independent. Under an honest-but-curious server, this leaves an authorization provenance gap: once session state is purged, no forensic procedure can attribute a proof to its originating search session, because the proof's public inputs encode no session-identifying information. We formalize this gap as the search-authorized proof (SAP) security notion and show via a concrete audit re-association attack that proof-external mechanisms, where authorization evidence remains outside the proof, cannot prevent forensic misattribution when the same drop parameters recur across sessions. Search-Bound Proximity Proofs (SBPP) realize the SAP requirements without modifying the ZKP circuit: session nonce, Merkle-root result-set commitment, and signed receipt are decomposed into independently auditable components, enabling property-level fault isolation in offline audit. Experiments on synthetic and real-world data (110,776 OpenStreetMap POIs) show sub-millisecond absolute overhead on a 125 ms Groth16 baseline.

Open access
2 source records
Cryptography and Data Security
Blockchain Technology Applications and Security
Access Control and Trust
Original source
Apr 2, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
AIGP-Σ: A Post-Quantum Identity and Authorization Protocol for Autonomous AI Agents

Mirasovici Marius Aurelian

AIGP-Σ (AI Governance Protocol — Sigma) is a post-quantum cryptographic identity and authorization framework designed for autonomous AI agents operating in multi-agent and agentic payment environments. The protocol suite consists of five interconnected specifications: WP-01: Core Protocol — ML-DSA (CRYSTALS-Dilithium) based identity anchoring with STARK zero-knowledge proofs via RISC0, Bitcoin blockchain timestamping, and a cryptographic Kill Switch mechanism for emergency AI halt. WP-02: Kill Switch — Formal specification of the HALT proof system enabling verifiable, tamper-proof shutdown of AI agents without revealing operational state. WP-03: SSL for Agents — A mutual TLS-equivalent handshake protocol adapted for AI agent-to-agent communication, providing forward secrecy and post-quantum resistance. WP-04: Agentic Payments — Authorization layer for autonomous financial transactions executed by AI agents, with cryptographic scope limitation and audit trails. WP-05: Multi-Agent Orchestration — Trust propagation and delegation model for hierarchical multi-agent systems with verifiable credential chains.

Open access
2 source records
Blockchain Technology Applications and Security
Cryptography and Data Security
Access Control and Trust
Original source
Apr 2, 2026·Systems
1 cites
Zero-Knowledge-Based Policy Enforcement for Privacy-Preserving Cross-Institutional Health Data Sharing on Blockchain

Faisal Albalwy

This study presents ZK-EHR, a decentralized access control framework designed to enable secure and privacy-preserving sharing of encrypted electronic health records across institutional boundaries. Unlike existing blockchain-based EHR access control systems that expose user identities on-chain or lack cryptographic privacy guarantees, ZK-EHR decouples authorization from identity disclosure by integrating zk-SNARK-based proofs with blockchain smart contracts to verify policy compliance without revealing user roles, affiliations, or credentials. The framework employs three differentiated actor roles—Patient (Data Owner), Doctor (Care Provider), and Researcher (Authorized Analyst)—with distinct policy-driven access workflows, a custom Groth16 zero-knowledge circuit for role-based constraint enforcement, and a modular architecture combining on-chain verification with off-chain encrypted storage via IPFS. Concrete design proposals for access revocation and replay attack prevention are introduced to address operational security requirements. The system was evaluated under multiple operational and adversarial scenarios. Experimental results indicate consistent on-chain verification latency (approximately 390 ms), reliable rejection of tampered submissions, and per-verification gas consumption of 216,631 gas. A comparative analysis against representative baseline systems demonstrates that ZK-EHR uniquely combines identity anonymity, on-chain cryptographic policy enforcement, and auditable encrypted record retrieval. These findings establish the feasibility of zk-SNARK-based access control for decentralized, verifiable, and privacy-aware EHR management.

Open access
2 source records
Cryptography and Data Security
Blockchain Technology Applications and Security
Access Control and Trust
Original source
Apr 1, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
Panoptes: A Zero-Trust Cryptographic Engine for Low-Latency P2P Poker

Antonio Lopez Vivar

Traditional digital card games rely on centralized servers, introducing catastrophic single points of failure, while decentralized Web3 alternatives fail to achieve real-time viability due to prohibitive block latency. This paper introduces Panoptes, an optimized, hybrid cryptographic engine that enforces low-latency decentralized consensus for peer-to-peer state channels. Assuming a highly hostile user-space environment, Panoptes treats the host application space and its underlying managed runtime as fundamentally compromised.A bifurcated architecture is detailed utilizing a hardened native airgap and direct OS-level memory mapping to process ciphertexts, bypassing standard and predictable libc allocators. To mitigate automated memory scrapers and frustrate asynchronous Direct Memory Access (DMA) attacks, Panoptes implements a multiplexed decoy memory topology (The Vault). This architecture relies on strict virtual page guarding, offline decryption, and temporal starvation via millisecond-scale execution windows. The protocol replaces commutative encryption with a deterministic Hand Commitment Payload, utilizing X25519 KEM, XOR- based Secret Sharing, and ChaCha20-Poly1305 to enforce Strict Zero-Trust Consensus.

Open access
2 source records
Peer-to-Peer Network Technologies
Security and Verification in Computing
Access Control and Trust
Original source
Mar 31, 2026·Open MIND
0 cites
Measured Model Substitution Under Valid Agent Credentials

Anthony Coslett

Three model substitution scenarios were executed against a live inference endpoint with real HTTP requests, signed attestation JWTs, and OPA policy enforcement. In each scenario, every tested workload, artifact, or API identity control relevant to that scenario — workload JWT validation, health checks, gateway process continuity, artifact manifest integrity, API key authentication — remained valid while the model changed. In each scenario, a structural identity measurement based on activation geometry during a standard forward pass detected the substitution and the enforcement layer denied the request. Three substitutions were tested and three were detected, with zero false accepts in this run. The warm-path verification latency was 5.7–6.7 seconds on a single A100 with the model already loaded. The complete evidence chain — before/after measurement results, attestation claim summaries, OPA policy evaluations, and HTTP response codes — is published alongside this note as machine-readable JSON. This is a technical note, not a numbered entry in the research series. Supplementary Material. This note is accompanied by three machine-readable evidence files: cat3_results.json (structured results for all three scenarios, including the full before/after evidence chain for Scenario A with signed attestation claims, OPA policy evaluations, and HTTP response codes), manifest_authorized.json (SHA-256 build manifest for the enrolled model, 10 files, all verified), and manifest_substituted.json (SHA-256 build manifest for the substituted model, 10 files, all verified). All three files are available for download as supplementary files attached to this record. The Neural Network Identity Series — Mathematical foundations, empirical validation, and governance frameworks for verifying which model is running Newest addition: Technical Note: The Disappearing Window — AI Logprob Access Withdrawal and the Structural Verifiability of Frontier Model Contracts (DOI: 10.5281/zenodo.20362098) Paper 1: The δ-Gene: Inference-Time Physical Unclonable Functions from Architecture-Invariant Output Geometry (DOI: 10.5281/zenodo.18704275) Paper 2: Template-Based Endpoint Verification via Logprob Order-Statistic Geometry (DOI: 10.5281/zenodo.18776711) Paper 3: The Geometry of Model Theft: Distillation Forensics, Adversarial Erasure, and the Illusion of Spoofing (DOI: 10.5281/zenodo.18818608) Paper 4: Provenance Generalization and Verification Scaling for Neural Network Forensics (DOI: 10.5281/zenodo.18872071) Paper 5: Beneath the Character: The Structural Identity of Neural Networks — Mathematical Evidence for a Non-Narrative Layer of AI Identity (DOI: 10.5281/zenodo.18907292) Paper 6: Which Model Is Running?: Structural Identity as a Prerequisite for Trustworthy Zero-Knowledge Machine Learning (DOI: 10.5281/zenodo.19008116) Paper 7: The Deformation Laws of Neural Identity (DOI: 10.5281/zenodo.19055966) Paper 8: What Counts as Proof? — Admissible Evidence for Neural Network Identity Claims (DOI: 10.5281/zenodo.19058540) Paper 9: Composable Model Identity — Formal Hardening of Structural Attestations in the Enterprise Identity Stack (DOI: 10.5281/zenodo.19099911) Paper 10:Where Identity Comes From: Path Sensitivity and Endpoint Underdetermination in Neural Network Training (DOI: 10.5281/zenodo.19118807) Paper 11: Post-Hoc Disclosure Is Not Runtime Proof: Model Identity at Frontier Scale (DOI: 10.5281/zenodo.19216634) Paper 12: Family-Dependent Response to Reasoning Distillation Across Structural and Functional Identity Layers (DOI: 10.5281/zenodo.19298857) Paper 13: Safety-Alignment Removal as a Model-Identity Failure — Structural Evidence from Published Weight-Level Mutation Checkpoints (DOI: 10.5281/zenodo.19383019) Technical Note: Agent Identity Is Not Model Identity (DOI: 10.5281/zenodo.19240883) Technical Note: Gap Invariance: Why PPP Measurements Are Domain-Independent by Construction (DOI: 10.5281/zenodo.19275524) Technical Note: Measured Model Substitution Under Valid Agent Credentials (DOI: 10.5281/zenodo.19342848) Technical Note: Artifact Identity Is Not Runtime Identity — Trustfall Lite and the Boundary of File-Level Model Verification (DOI: 10.5281/zenodo.20019127) Formal Verification Stack for Neural Network Structural Identity (IT-PUF Coq Proofs) (DOI: 10.5281/zenodo.18930621) Copyright (c) 2026 Anthony Ray Coslett / Fall Risk AI, LLC. All Rights Reserved. Confidential and Proprietary. Patent Pending (Applications 63/982,893, 63/990,487, 63/996,680, 64/003,244).

Open access
3 source records
Adversarial Robustness in Machine Learning
Explainable Artificial Intelligence (XAI)
Scientific Computing and Data Management
Original source
Mar 30, 2026·Scientific Journal of Astana IT University
0 cites
DECENTRALIZED IDENTITY AND ACCESS MANAGEMENT IN INTERNET OF THINGS SYSTEMS BASED ON BLOCKCHAIN

Yersaiyn Mailybayev, Ulzhalgas Seidaliyeva, Adilkhan Kushukbaev, Карина Литвинова · 5 authors

The exponential proliferation of Internet of Things (IoT) devices presents critical challenges to traditional centralized identity and access management systems, which are plagued by issues of scalability, single points of failure, and significant privacy risks. While blockchain technology offers a promising decentralized alternative, its direct application is often hindered by low transaction throughput, high costs, and the computational limitations of IoT devices. This study addresses these challenges by proposing and formally evaluating HybID-AC, a novel hybrid architecture for decentralized identity and access management tailored for large-scale, heterogeneous IoT ecosystems. The methodology involves a dual-layer design that separates global trust anchoring from local execution. A highly scalable, feeless Directed Acyclic Graph (DAG) based distributed ledger serves as a public "anchor layer" for registering W3C standard Decentralized Identifiers (DIDs) and access policy hashes. All high-frequency access control operations are processed off-chain at the "edge layer" using the DIDComm v2 peer-to-peer protocol, Attribute-Based Access Control (ABAC) for fine-grained policy enforcement, and Zero-Knowledge Proofs (ZKP) to ensure privacy-preserving attribute verification. The results of our analytical evaluation demonstrate that the HybID-AC architecture achieves orders-of-magnitude improvements in latency and cost-efficiency compared to fully on-chain models, maintaining consistent performance as the network scales. Furthermore, we introduce an original probabilistic model that provides a quantitative metric for assessing the integral security risk of ABAC policies against attribute compromise. The study concludes that this hybrid approach effectively resolves the inherent trade-offs of blockchain in an IoT context, offering a robust, scalable, and interoperable framework that empowers devices with self-sovereign identity while ensuring security and privacy by design.

Open access
Blockchain Technology Applications and Security
Access Control and Trust
IoT and Edge/Fog Computing
Original source
Mar 30, 2026·Decision Analytics Journal
0 cites
A decision analytics framework for interpreting trust signals in decentralized digital communities

Andry Alamsyah, Muhammad Falaah

Public discourse plays a critical role in shaping trust, legitimacy, and governance dynamics within decentralized Web3 ecosystems. However, existing studies often examine Web3 discourse through isolated lenses such as sentiment or topic modeling, which limits their ability to capture how emotional expression and communicative purpose jointly convey strategic intent. This study proposes a three-stage decision analytics framework that transforms unstructured Web3 discourse into diagnostic signals by jointly modeling industry domain, emotional tone, and communicative purpose. The analysis draws on 10,840 user-generated posts collected from X, Reddit, YouTube, and the ENS DAO forum, using a human-in-the-loop annotation process combined with transformer-based text classification models. The framework is evaluated using a domain-adapted language model and a general-purpose baseline, with robustness assessed through five-fold cross-validation. The results indicate that curiosity and optimism frequently align with promotional intent in infrastructure and application-oriented domains, whereas skepticism and concern are more prevalent in governance-related discourse. These findings demonstrate that emotional tone and communicative intent operate as structured, decision-relevant signals rather than incidental sentiment. The proposed framework supports systematic, diagnostic monitoring of narrative dynamics as decision support, enabling organizations, platform operators, and governance stakeholders to identify emerging legitimacy risks and shifts in community trust within decentralized environments.

Open access
Access Control and Trust
Internet Traffic Analysis and Secure E-voting
Information and Cyber Security
Original source
Mar 28, 2026·Open MIND
0 cites
Transaction Binding Security for Policy-Bound Authorization Tokens

Rudolf Jacobus Coetzee

Authorization tokens in distributed systems are typically context-free: a cryptographically valid token carries no binding to the specific transaction for which it was issued. This enables reuse and cross-context presentation attacks that are undetectable at the cryptographic layer. In regulated financial infrastructure, cross-border payments, and autonomous agent systems, transaction-scoped enforcement is a hard requirement that existing standards leave unaddressed. We introduce the first formal security model for policy-bound transaction tokens. We define the syntax of a policy-bound transaction token scheme over a formal transaction context space and introduce three game-based security notions: transaction binding (TB), which simultaneously resists forgery and cross-context reuse; existential unforgeability under chosen-context attack (EUF-CCA); and unlinkability (UNL). We prove that TB strictly implies EUF-CCA, establish a formal separation between TB and UNL, and identify the inherent tension between unlinkability and auditability. We construct a scheme parameterized by any EUF-CMA-secure signature scheme and a random oracle, and prove that it achieves transaction binding security with a tight reduction requiring no rewinding. We then address the complementary privacy problem by formalizing zero-knowledge compliance privacy (ZK-CP) and constructing an enhanced scheme that augments transaction-binding tokens with a non-interactive zero-knowledge proof of policy compliance. We prove that the enhanced scheme simultaneously achieves TB security and ZK-CP, and show how it integrates with decentralized identity (DID) systems to enable fully privacy-preserving authorization where the verifier learns only whether compliance is satisfied. We give a concrete instantiation using Ed25519 and SHA-512, derive bit-security parameters, analyze performance costs, and discuss deployment considerations including regulatory alignment with PSD2, MiCA, DORA, the GENIUS Act, SEC token taxonomy, and FinCEN BSA requirements.

Open access
2 source records
Blockchain Technology Applications and Security
Cryptography and Data Security
Access Control and Trust
Original source
Mar 27, 2026·Cybernetics and Computer Technologies
0 cites
Application of Game Theory Methods to Analyze Validator Interaction in Proof-Of-Stake Blockchain Systems

Viktor Godliuk

This paper investigates the strategic behavior of validators in blockchain systems utilizing the Proof-of-Stake (PoS) consensus mechanism through the application of game theory. A mathematical model of a non-cooperative game with complete information is proposed, where validators act as rational agents aiming to maximize their expected payoff by choosing between honest validation and malicious actions, specifically a double-spending attack. The model incorporates key economic parameters of the system: block and attestation rewards, transaction fees, operational costs, slashing penalties, and the probability of detecting protocol violations. Utility functions for two primary strategies – honest and attacking – are formalized, and conditions for the existence of Nash equilibrium, the central solution concept in game theory, are analyzed. The analysis demonstrates that under effective punishment mechanisms, the "all-honest" equilibrium is stable: an individual validator has no incentive to deviate from protocol-compliant behavior, as potential losses from penalties significantly outweigh any gains from a failed attack. Conversely, the "all-attackers" equilibrium, while theoretically possible, is practically unattainable due to the prohibitively high cost of acquiring a majority stake, rendering such a strategy economically infeasible. A quantitative example based on a hypothetical network of 1000 validators confirms these findings and highlights the critical importance of balancing incentives for honest behavior with strong disincentives for malicious actions. The study emphasizes the crucial role of economic security in PoS systems, where stability is ensured not only by technical safeguards but also by carefully designed economic mechanisms. The developed model can be used by blockchain protocol designers to calibrate consensus parameters, thereby promoting decentralization, resilience, and long-term network reliability. Future research can extend the model by incorporating heterogeneous validators, repeated games, and the analysis of other attack vectors. Keywords: Proof-of-Stake, validators, game theory, Nash equilibrium, economic security, slashing, double-spending attack, game model, blockchain, consensus.

Open access
Blockchain Technology Applications and Security
Internet Traffic Analysis and Secure E-voting
Access Control and Trust
Original source
Mar 25, 2026·Open MIND
0 cites
Post-Hoc Disclosure Is Not Runtime Proof: Model Identity at Frontier Scale

Anthony Coslett

Current AI deployment stacks authenticate agents, workloads, and credentials but do not verify which neural network is computing at inference time. Recent incidents — including the undisclosed use of an open-weight foundation model inside a commercial product, industrial-scale distillation campaigns, and emerging agent identity standards that authenticate software without authenticating models — show that this gap has practical consequences. Post-hoc disclosure resolved these incidents; runtime proof would have made the model identity question answerable at inference time. This paper asks whether runtime model identity is technically feasible at frontier scale. We present three results. First, we enrolled and verified five open-weight transformer models spanning 8 billion to 72.7 billion parameters across three families, with zero false acceptances in all pairwise comparisons and self-verification within the acceptance threshold for all models. A thermodynamic observable predicted by extreme value theory remained within two percent of its predicted value across the full range, with no statistically significant scale-dependent correction detected across more than two orders of magnitude in parameter count. Second, we tested structural separability on three declared-lineage distillation pairs spanning 8 billion to 70 billion parameters — each derivative sharing identical architecture with its base — and measured separations ranging from 2,858 to 4,583 times the acceptance threshold, increasing monotonically with model scale across two base-model families. All derivatives self-verified within the acceptance threshold. Third, we demonstrate a frontier-scale software attestation path — including signed JWT issuance and downstream policy consumption — and situate it within a previously formalized attestation architecture that composes with enterprise identity infrastructure, complementing rather than replacing current agent identity frameworks. These results demonstrate that runtime model identity is measurable and separable across the tested range of open-weight instruct-tuned transformers from 8B to 72.7B, with a frontier-validated software attestation path and an inherited route to stronger hardware-backed and proof-backed assurance. The Neural Network Identity Series — Mathematical foundations, empirical validation, and governance frameworks for verifying which model is running Newest addition: Technical Note: The Disappearing Window — AI Logprob Access Withdrawal and the Structural Verifiability of Frontier Model Contracts (DOI: 10.5281/zenodo.20362098) Paper 1: The δ-Gene: Inference-Time Physical Unclonable Functions from Architecture-Invariant Output Geometry (DOI: 10.5281/zenodo.18704275) Paper 2: Template-Based Endpoint Verification via Logprob Order-Statistic Geometry (DOI: 10.5281/zenodo.18776711) Paper 3: The Geometry of Model Theft: Distillation Forensics, Adversarial Erasure, and the Illusion of Spoofing (DOI: 10.5281/zenodo.18818608) Paper 4: Provenance Generalization and Verification Scaling for Neural Network Forensics (DOI: 10.5281/zenodo.18872071) Paper 5: Beneath the Character: The Structural Identity of Neural Networks — Mathematical Evidence for a Non-Narrative Layer of AI Identity (DOI: 10.5281/zenodo.18907292) Paper 6: Which Model Is Running?: Structural Identity as a Prerequisite for Trustworthy Zero-Knowledge Machine Learning (DOI: 10.5281/zenodo.19008116) Paper 7: The Deformation Laws of Neural Identity (DOI: 10.5281/zenodo.19055966) Paper 8: What Counts as Proof? — Admissible Evidence for Neural Network Identity Claims (DOI: 10.5281/zenodo.19058540) Paper 9: Composable Model Identity — Formal Hardening of Structural Attestations in the Enterprise Identity Stack (DOI: 10.5281/zenodo.19099911) Paper 10:Where Identity Comes From: Path Sensitivity and Endpoint Underdetermination in Neural Network Training (DOI: 10.5281/zenodo.19118807) Paper 11: Post-Hoc Disclosure Is Not Runtime Proof: Model Identity at Frontier Scale (DOI: 10.5281/zenodo.19216634) Paper 12: Family-Dependent Response to Reasoning Distillation Across Structural and Functional Identity Layers (DOI: 10.5281/zenodo.19298857) Paper 13: Safety-Alignment Removal as a Model-Identity Failure — Structural Evidence from Published Weight-Level Mutation Checkpoints (DOI: 10.5281/zenodo.19383019) Technical Note: Agent Identity Is Not Model Identity (DOI: 10.5281/zenodo.19240883) Technical Note: Gap Invariance: Why PPP Measurements Are Domain-Independent by Construction (DOI: 10.5281/zenodo.19275524) Technical Note: Measured Model Substitution Under Valid Agent Credentials (DOI: 10.5281/zenodo.19342848) Technical Note: Artifact Identity Is Not Runtime Identity — Trustfall Lite and the Boundary of File-Level Model Verification (DOI: 10.5281/zenodo.20019127) Formal Verification Stack for Neural Network Structural Identity (IT-PUF Coq Proofs) (DOI: 10.5281/zenodo.18930621) Copyright (c) 2026 Anthony Ray Coslett / Fall Risk AI, LLC. All Rights Reserved. Confidential and Proprietary. Patent Pending (Applications 63/982,893, 63/990,487, 63/996,680, 64/003,244).

Open access
2 source records
Adversarial Robustness in Machine Learning
Security and Verification in Computing
Access Control and Trust
Original source
Mar 25, 2026·Zenodo (CERN European Organization for Nuclear Research)
2 cites
AEGIS: A Constitutional Governance Architecture for Autonomous AI Agents

Kenneth A. Tannenbaum

Autonomous AI agents increasingly execute consequential actions against operational infrastructure. This paper presents AEGIS, a constitutional governance architecture that enforces deterministic policy at the agent action boundary — post-reasoning, pre-execution. AEGIS satisfies Anderson's reference monitor properties, aligns with all four functions of the NIST AI Risk Management Framework, and introduces a decentralized federation model for cross-organizational governance intelligence sharing. Submitted to IEEE Computer, Special Issue on AI Governance and Compliance.

Open access
2 source records
Access Control and Trust
Multi-Agent Systems and Negotiation
Ethics and Social Impacts of AI
Original source
Mar 23, 2026·Proceedings of the 41st ACM/SIGAPP Symposium on Applied Computing
0 cites
zkA3: Zero-Knowledge Address Abstraction with Auditability for Cross-Chain Identity Management

Jae Hyun Choi, Geontae Noh, Ji Young Chun, Ik Rae Jeong

Regulatory frameworks like MiCA mandate KYC and auditability for stablecoins, but existing solutions fail to simultaneously achieve privacy, compliance, and cross-chain compatibility. We propose zkA3 (Zero-Knowledge Address Abstraction with Auditability), enabling users to generate pseudonymous identifiers from web2 certificates with unlinkability guarantees while incorporating encrypted audit tokens for authorized identity tracing. We formally prove five security properties: pseudonymity, unlinkability, zero-knowledge authentication, auditability, and cross-chain consistency. Our implementation achieves 29.8ms proof generation with 9,917 constraints, demonstrating practical feasibility. zkA3 is the first scheme simultaneously supporting privacy-preserving cross-chain stablecoin operations and regulatory compliance.

Open access
Cryptography and Data Security
Access Control and Trust
Blockchain Technology Applications and Security
Original source
Mar 23, 2026·Proceedings of the 41st ACM/SIGAPP Symposium on Applied Computing
1 cites
A Decentralized Behavioral Trust Framework Across Mobile Networks

Umut Pekel, OÄŸuz Yayla

Mobile communication channels have become a major target for large-scale and adaptive fraud, including impersonation, phishing, and unsolicited calls. Existing caller-verification frameworks depend on centralized heuristics and static credentials that fail to reflect behavioral trust or protect users in real time. This paper presents BTID (Behavioral Trust for Identity Decentralization) - a decentralized, privacy-preserving identity framework that derives caller reputation from verified behavioral feedback. BTID integrates Decentralized Identifiers (DIDs) and Verifiable Credentials (VCs) with a lightweight zero-knowledge-proof mechanism, enabling callers to prove that their behavioral reputation meets a callee's trust threshold without revealing their actual score or personal data. Each post-call rating is recorded as a cryptographic commitment and aggregated through a pairwise Sybil-resistant reputation model governed by exponential decay (λ = 0.0039, six-month half-life). A reference prototype demonstrates that the protocol is implementable and logically sound even under high-cost and high-latency conditions on public ledgers. On modern lightweight networks such as Algorand or IOTA, the same architecture can achieve sub-second verification and near-zero cost. Beyond its technical contribution, BTID also reframes the role of the blockchain itself. Rather than treating decentralization as an ideological end, this work demonstrates that a tamper-proof and privacy-preserving public ledger can serve as a shared, universal database accessible to all participants and not as a silo controlled by industrial conglomerates. In doing so, BTID shows that the blockchain can function as a neutral trust infrastructure capable of addressing a real and universal problem in mobile communication: establishing behavioral trust without sacrificing privacy.

Open access
Access Control and Trust
Internet Traffic Analysis and Secure E-voting
Mobile Agent-Based Network Management
Original source