The InterPlanetary File System (IPFS) has been extensively promoted as a decentralized, censorship-resistant, and fault-tolerant storage protocol. This paper systematically dismantles these claims by demonstrating four critical and compounding vulnerability classes: (1) the structural dependency on centralized pinning services such as Pinata, Infura, and Web3.Storage, where compromising a single provider's dashboard or API effectively eliminates supposedly âimmutableâ content; (2) the futility of self-hosted pinning nodes as a mitigation strategy, given their susceptibility to targeted Distributed Denial-of-Service (DDoS) attacks capable of rendering them permanently unreachable; (3) the catastrophic implications of a cryptographic backdoor or collision discovery in SHA-256 or SHA-3 (Keccak), which would enable arbitrary content substitution while preserving valid Content Identifiers (CIDs), thereby destroying IPFS's fundamental integrity guarantees; and (4) the vulnerability of distributed pinning strategies to gossip-protocol-based reconnaissance attacks, wherein a state-level adversary (e.g., NSA, GCHQ, or equivalent) can enumerate all nodes hosting a target CID by compromising a single peer and leveraging protocol-level metadata propagation to systematically identify and neutralize every replica simultaneously. We formalize each attack vector with mathematical models, provide proof-of-concept algorithms, analyze the compounding effects of multi-vector attacks, and demonstrate that even the most sophisticated defense-in-depth strategies fail against a sufficiently resourced adversary. Our analysis conclusively establishes that IPFS, as deployed in practice, provides no meaningful censorship resistance and constitutes what we term Decentralization Theaterâa system that employs the aesthetics and terminology of decentralization while maintaining the vulnerability profile of traditional centralized architectures, augmented by a dangerous false sense of security.
With the deepening application of big data technology across various fields, data faces increasingly severe threats of privacy leakage and security risks throughout its entire processing lifecycle. Traditional protection mechanisms, which focus on static data or isolated stages, struggle to address the systemic risks arising from the continuity, dynamism, and complexity of big data processes. This paper aims to systematically investigate the collaborative mechanisms for privacy protection and data security within the big data processing pipeline. First, it analyzes the inherent vulnerabilities at each stage of data processing, as well as the limitations faced by key technologies such as anonymization, differential privacy, and secure multi-party computation when integrated into practical workflows. Next, it explores the evolution of process-oriented encryption strategies, including attribute-based encryption supporting dynamic policies, homomorphic encryption optimized for practical use, and verifiable computation and zero-knowledge proofs that ensure computational integrity. Finally, the paper constructs a dynamic balancing model for privacy, security, and utility, and proposes forward-looking systematic collaborative mechanisms such as distributed auditing based on trust chains and adaptive response. These contributions provide theoretical reference and technical pathways for building next-generation inherently secure big data processing architectures.
João Gião, Fernando Luis-Ferreira, Joao Sarraipa, Ricardo Jardim-Gonçalves
Nowadays, with the increased integration of cloud-computing, data integrity continues to be a problem in the current eHealth sector. This security principle is considered fundamental to ensure the accuracy and reliability of data by ensuring protection from unauthorized and illicit tampering. The present work aims to demonstrate the ability for the Distributed Ledger Technology (DLT) to provide trust and confidence in the healthcare infrastructure for patients, healthcare professionals and policy makers. The DLT has the potential to become one of the most reliable solutions for the many challenges facing the healthcare industry for its potential to enable more secure, transparent, and equitable data management. Although much documentation exists about applications in this domain, it is mostly presented in high-level conceptualization, without detailing the actual development or implementation. This document proposes a metadata-based approach to protect healthcare data integrity in compliance with GDPR, ensuring trustworthy data access for end-users, while demonstrating that the solution can be deployed on low-resource hardware with minimal adaptation effort and time constraints.
Open access
Security and Verification in Computing
Cloud Data Security Solutions
Physical Unclonable Functions (PUFs) and Hardware Security
Ensuring the reliable, auditable, and privacy-oriented distribution of donations in disaster logistics constitutes a critical challenge due to multi-stakeholder coordination difficulties and the risk of misuse. This study presents a modular architecture, named SecureRelief, operating on a permissioned Hyperledger Fabric platform. The architecture integrates authentication based on Self-Sovereign Identity (SSI), Decentralized Identifiers (DID), and WebAuthn, together with Attribute-Based Access Control (ABAC), and enables the verification of delivery evidence through privacy-preserving validation using zero-knowledge proofs (ZKP). Documents are stored off-chain on the InterPlanetary File System (IPFS), while only cryptographic summary (hash) values sufficient for integrity verification are maintained on-chain. In scenario-based laboratory experiments, the blockchain layer demonstrated low latency (p95 < 16 ms) and stable transaction throughput, confirming its scalability. While the API layer handled high burst request loads with a 0% error rate, the additional computational overhead introduced by the integrated privacy-preserving (ZKP) mechanisms kept the end-to-end transaction latency within acceptable limits for disaster management applications (3.5â4.5 s).
Edge-Cloud-Systeme ermöglichen Anwendungen, die auf Basis von Daten intelligenter Objekte und Infrastrukturen wirtschaftliche Mehrwerte schaffen und gesellschaftliche Herausforderungen adressieren. Dies bedarf hĂ€ufig eines Teilens von Daten mit Partnern in etablierten Wertschöpfungsnetzwerken oder entlang des Edge-Cloud-Kontinuums. Eine fundamentale Anforderung ist dabei die Sicherstellung des Schutzes sensibler betrieblicher und personenbezogener Informationen. WĂ€hrend die lokale Datenverarbeitung an der Edge ein grundlegendes MaĂ an Datenschutz und Informationssicherheit ermöglicht, reicht ein ausschlieĂlicher RĂŒckgriff auf diese MaĂnahme oftmals nicht aus, um diese Anforderungen bei gleichzeitiger Erzielung der Mehrwerte datengetriebener Anwendungen zu erfĂŒllen. Beispielsweise besteht hĂ€ufig die Notwendigkeit, schĂŒtzenswerte Daten an zentraler Stelle, beispielsweise der Cloud, zu aggregieren, um zu reichhaltigen Erkenntnissen zu gelangen oder die IntegritĂ€t der verwendeten Daten sicherzustellen. An dieser Stelle rĂŒcken Privacy-Enhancing-Technologies (PET) in den Fokus, die Mechanismen umfassen, um Datenschutz, Informationssicherheit und DatensouverĂ€nitĂ€t âby-Designâ in Systemarchitekturen zu integrieren. Bei PET handelt es sich um eine Klasse von individuellen Werkzeugen, die jeweils spezifische Informationssicherheitsanforderungen und -risiken in Edge-Cloud-Systemen adressieren können. FĂŒr Praktiker ergibt sich die Herausforderung, auf Basis der spezifischen Bedarfe ihrer Anwendungen und der verfĂŒgbaren PET-Werkzeuge passende PET-Strategien zu entwickeln, die eine Realisierung der Edge-Cloud-Anwendung unter BerĂŒcksichtigung der Anforderungen und Risiken fĂŒr die Informationssicherheit ermöglichen. Diese Orientierungshilfe unterstĂŒtzt Praktiker bei der Entwicklung eigener PET-Strategien fĂŒr Edge-Cloud-Anwendungen. Sie bietet Hilfestellungen bei der Identifikation von Informationssicherheitsanforderungen und -risiken, der Auswahl passender PET-Werkzeuge und deren Integration in das Anwendungsdesign. Zentrales Element der Studie ist hierbei die Analyse von PET-Werkzeugen in Edge-Cloud-Anwendungskontexten. Die Orientierungshilfe zeigt, wie PET-Werkzeuge zur Umsetzung von Informationssicherheit beitragen können, welche Voraussetzungen fĂŒr ihren Einsatz in spezifischen Szenarien geschaffen werden mĂŒssen und welche Implikationen sich aus dem Praxiseinsatz der PET-Werkzeuge ergeben. Dazu beruft sich die Orientierungshilfe auf die Erkenntnisse der Early-Adopter von Edge-Cloud-Systemen und PET aus den Projekten des Technologieprogramms âEdge Datenwirtschaftâ des Bundesministeriums fĂŒr Forschung, Technologie und Raumfahrt (BMFTR). Die Inhalte dieser Orientierungshilfe adressieren insbesondere Systemarchitektinnen und -architekten und Datenschutzbeauftragte, die Datenverarbeitungsprozesse in Edge-Cloud-Systemen datenschutzkonform gestalten mĂŒssen. Ausgehend von der Darstellung möglicher Risiken wie physischen Angriffen und Cyberangriffen, unsicherer Datenhoheit, Insiderbedrohungen und Fehlkonfigurationen sowie Anforderungen wie Datenminimierung, IntegritĂ€t, Zweckbindung und die Verhinderung von DatenabflĂŒssen âby-Designâ in Edge-Cloud-Anwendungen analysiert diese Orientierungshilfe fĂŒnf konkrete PET-Werkzeuge in praxisnahen Anwendungsszenarien: § Hardware-SchlĂŒssel fĂŒr die sichere Authentifizierung ohne personenbezogene Daten in der Lebensmittelwirtschaft, § Federated-Learning fĂŒr kollaboratives KI-Training ohne Rohdatenweitergabe in der industriellen Fertigung, § Compute-to-Data zur AusfĂŒhrung von Analysen in der Umgebung des DateneigentĂŒmers in der industriellen Fertigung, § Zero-Knowledge-Proofs fĂŒr datenbasierte Nachweise ohne Offenlegung sensibler Daten in der Energiewirtschaft, § Trusted-Execution-Environments fĂŒr vertrauliche Berechnungen in isolierten Hardware-Umgebungen in der Energiewirtschaft. Zudem prĂ€sentiert die Studie vier Handlungsfelder und zugehörige Handlungsempfehlungen fĂŒr den erfolgreichen Einsatz von PET-Werkzeugen in Edge-Cloud-Anwendungen: 1) Aufbau vertrauenswĂŒrdiger Partnerökosysteme und Schaffung notwendiger Anreizmechanismen, 2) Schaffung betrieblicher Voraussetzungen fĂŒr den PET-Einsatz inklusive Schulung und Akzeptanzförderung, 3) Sicherstellung technischer ValiditĂ€t und IntegrationsfĂ€higkeit der PET in den Anwendungskontext, 4) GewĂ€hrleistung regulatorischer KonformitĂ€t der PET-gestĂŒtzten Edge-Cloud-Anwendung. Im Zuge der steigenden Relevanz von Edge-Cloud-Systemen und dem Teilen von Daten zur Generierung von Datenwertschöpfung bei mindestens gleichbleibenden Anforderungen an Datenschutz und Informationssicherheit wird der Einsatz von PET zu einem entscheidenden Erfolgsfaktor. PET ermöglichen nicht nur die Einhaltung regulatorischer Vorgaben, sondern schaffen die Grundlage fĂŒr vertrauensbasierte Kooperationen in komplexen Edge-Cloud-Ăkosystemen. Unternehmen, die zukĂŒnftig gemeinsam datengetriebene Wertschöpfung betreiben wollen, sollten sich aktiv mit PET beschĂ€ftigen.
R. Priyadarshini, K. Reddy Geethika, V. Sravya, K. Pujitha · 6 authors
The increasing adoption of cloud computing has revolutionized data storage and accessibility, but it has also presented severe security and privacy issues, particularly in the context of developing quantum computing threats. Despite being effective against classical assaults, conventional encryption and password protection mechanisms are becoming more susceptible to quantum algorithms that can compromise current cryptographic systems. This paper presents QPause, a Password-Protected, Quantum-Resilient Data Offloading for Cloud Platforms forsafe cloud storage, in response to these new threats. To guarantee data confidentiality, integrity, and resilience against both classical and quantum adversaries, the suggested system combines sophisticated password-based authentication methods with post-quantum cryptography approaches. QPause uses zero-knowledge proof methods to enable secure verification without disclosing sensitive credentials, and it leverages lattice-based encryption to safeguard data that is outsourced. Additionally, the system integrates efficient key management and access control mechanisms to boost scalability and user confidence. QPause delivers strong resilience to quantum attacks while preserving low processing overhead and excellent usability for practical cloud applications, according to experimental evaluation. This framework offers a solid solution for secure and future-proof data outsourcing, bridging the gap between existing cloud services and the next generation of quantum-secure computing environments.
Ensuring the integrity and efficiency of academic record verification has become increasingly important for modern educational institutions. This study presents a blockchain-powered verification system specifically designed for confirming the credentials of graduated students from Mekelle University. By integrating Ethereum blockchain with GraphQL APIs, the system enhances transparency and reliability in the verification process. The universityâs existing system, built with Ruby on Rails, lacked automated verification, relied heavily on centralized control, and was prone to delays and potential data tampering. To overcome these issues, a decentralized application (DApp) was developed using various tools, including Ethers.js, Node.js, Ganache, Apollo Server, GraphQL, and React. This application enables the secure submission and retrieval of student records through Ethereum smart contracts. Data can be uploaded via CSV files or manually entered through forms, and each record is retrievable using a unique student ID, ensuring data immutability and public verifiability. Stakeholder feedback was gathered through interviews, and thematic analysis was used to assess the systemâs usability, scalability, and trustworthiness. Findings showed strong support for the blockchain-based system, with over 90% of participants agreeing that it improves transparency and reduces the risk of credential fraud. This research demonstrates a feasible bridge between traditional university information systems and decentralized technologies, highlighting both the practicality and institutional readiness for adopting blockchain in higher education.
Nacereddine Sitouah, Francesco Bruschi, Stefano De Cillis
The passing of the eIDAS amendment marks an important milestone for EU countries and changes how they must manage digital credentials for both public services and businesses. Italy has led in adopting eIDAS, first with CIE and SPID identity schemes, and now with the Italian Wallet (IO app) aligned to eIDAS 2.0. Self-Sovereign Identity (SSI) is a decentralized model born from the success of Distributed Ledgers, giving individuals full control over their digital identity. The current eIDAS 2.0 and its implementation acts diverge from SSI principles, rendering the European Digital Identity Wallet (EUDIW) centralized and merely user-centric, prioritizing security and legal protection over true self-sovereignty. This paper proposes an architecture that enables the use of IT Wallet credentials and services in an SSI-compliant environment through Trusted Execution Environments and Zero-Knowledge Proofs.
Student Information Management Systems (SIMS) are mission critical to higher learning institutions because they govern admissions, registration, fee status, assessment results, progression, graduation, and alumni verification. Yet conventional centralized SIMS architectures may face persistent challenges: record tampering risk, weak endâtoâend audit trails, fragmented reconciliation across units and campuses, slow and costly credential verification, and limited interoperability with external verifiers.This study develops a conceptual and technical framework for applying Distributed Ledger Technology (DLT) to strengthen SIMS at the Tanzania Institute of Accountancy (TIA). The framework positions DLT as a trust and interoperability layer rather than a replacement for SIMS. It proposes (i) an architecture that anchors cryptographic proofs onâchain while keeping personal data offâchain; (ii) standards based digital credentialing using W3C Verifiable Credentials and Decentralized Identifiers; (iii) governance and compliance controls aligned to Tanzanian data protection and cybercrime regimes; and (iv) an implementation roadmap and evaluation metrics grounded in established information systems theories. To make design tradeâoffs concrete, the study includes simulated calculations and figures for event volume, storage growth, verification turnaround time, and risk intensity across rollout phases. The framework provides a practical blueprint for a staged pilot at TIA starting with credential verification and assessment auditâtrail anchoring before scaling to additional workflows.
Contemporary enterprises encounter substantial difficulties managing information dispersed across varied cloud infrastructures, geographically separated facilities, and specialized application environments. Traditional centralized frameworks, including consolidated data repositories and analytical warehouses, demonstrate limited capacity to deliver the required velocity, accuracy, and contextual intelligence necessary for sustained digital progression. Multi-Cloud Data Mesh constitutes a transformative architectural approach, advocating decentralized, domain-centric methodologies that systematically address intricate governance complexities and interoperability obstacles at the organizational scale. This framework establishes operational foundations through four fundamental tenets: Domain-Oriented Ownership, Data as a Product, Self-Serve Platform, and Federated Computational Governance. These architectural pillars collectively resolve decentralization imperatives, scalability prerequisites, interoperability complications, and sovereignty considerations inherent in modern enterprise ecosystems. Through ownership distribution to specialized domains, product-oriented information treatment, self-service platform provisioning, and federated governance implementation, organizations attain necessary scalability, operational flexibility, and contextual precision for continuous innovation across sophisticated multi-cloud landscapes
A sharing framework based on Zero-Knowledge Proof (ZKP) and Proxy Re-encryption (PRE) technologies offers a promising solution for sharing Student Electronic Academic Records (SEARs). As core credentials in the education sector, student records are characterized by strong identity binding, the need for long-term retention, frequent cross-institutional verification, and sensitive information. Compared with electronic health records and government archives, they face more complex security, privacy protection, and storage scalability challenges during sharing. These records not only contain sensitive data such as personal identity and academic performance but also serve as crucial evidence in key scenarios such as further education, employment, and professional title evaluation. Leakage or tampering could have irreversible impacts on a studentâs career development. Furthermore, traditional blockchain technology faces storage capacity limitations when storing massive academic records, and existing general electronic record sharing solutions struggle to meet the high-frequency verification demands of educational authorities, universities, and employers for academic data. This study proposes a dedicated sharing framework for studentsâ electronic academic records, leveraging PRE technology and the distributed ledger characteristics of blockchain to ensure transparency and immutability during sharing. By integrating the InterPlanetary File System (IPFS) with Ethereum Smart Contract (SC), it addresses blockchain storage bottlenecks, enabling secure storage and efficient sharing of academic records. Relying on optimized ZKP technology, it supports verifying the authenticity and integrity of records without revealing sensitive content. Furthermore, the introduction of gate circuit merging, constant folding techniques, Field-Programmable Gate Array (FPGA) hardware acceleration, and the efficient Bulletproofs algorithm alleviates the high computational complexity of ZKP, significantly reducing proof generation time. The experimental results demonstrate that the framework, while ensuring strong privacy protection, can meet the cross-scenario sharing needs of student records and significantly improve sharing efficiency and security. Therefore, this method exhibits superior security and performance in privacy-preserving scenarios. This framework can be applied to scenarios such as cross-institutional academic certification, employer background checks, and long-term management of academic records by educational authorities, providing secure and efficient technical support for the sharing of electronic academic credentials in the digital education ecosystem.
The spectacular development of information technology (IT) led to massive data proliferation. Management systems such as big servers and cloud computing failed to satisfy current requirements engendered by this tricky challenge. The most remarkable shortcomings concern bottlenecks that are the principal causes of security attacks (Denial of Service attacks, confidentiality, integrity, and availability harms) and resource constraints (scarce storage space and computational efficiency). The emergence of decentralized systems (blockchain and decentralized storage) opens new perspectives in handling security and privacy, scalability, and storage shortcomings. The aim of this paper is to conduct a review on works built by the cooperation of the distributed ledger and decentralized storage. After, we define the main concepts, present works made in this field, and analyze recent papers investigated. The discussion demonstrates the relevance of the emerging technology blockchain-based decentralized storage networks in enhancing security and privacy aspects of stored data. In order to sharpen this creative approach, future directions are explored.
Traditional digital trust architectures suffer from the âLibrary Problemâ: dependency on pre-compiled, static lookup tables or binaries that must be trusted blindly, creating supply-chain vulnerabilities. This paper proposes a paradigm shift to Intrinsic Trust, where encoding infrastructure is mathematically regenerated at runtime rather than distributed. We introduce the 0MXI Calculus, a deterministic lattice system anchored on universal transcendental constants:the golden ratio Ί â 1.618033988749895 and Ï â 3.141592653589793, with a contraction ratio λ â 0.339949771344778. Operations on a quantized F15 lattice ensure cross-platform determinism, bounded by a Prime Boundary Horizon (N = 23) that guarantees injective reversibility (Theorems 1 and 2).This framework underpins TreeOS, an operating system that bootstraps from a âMath Root-of-Trustâ via autogenesis, regenerating a bijective Tick Table for byte encoding without stored dependencies. TreeBABEL, the verifiable data transport protocol, packages data as JSON artifacts with mathematical manifests for independent receiver validation. Extending this, the VMEM Node Architecture transforms online repositories into externalized memory banks, enabling AI models to scrape and derive OS state on demand, eliminating internal weight bloat and static knowledge cutoffs.We demonstrate adaptability to constrained ledgers (e.g., 280-character limits) for efficient chunking. Through rigorous proofs and a Python reference implementation, we show that trust can be calculated, not stored, decoupling systems from physical hardware and fostering entropy-neutral, zero-trust computation.
Modern web applications permanently process large quantities of sensitive information such as personal records, financial information, confidential documents. Typical centralized architectures for web systems are highly susceptible to data breaches, unauthorized access and single-point failures. These limitations pose severe problems in preserving user privacy and data integrity in distributed environment . Block chain technology offers a decentralized and tamperproof framework for secure storage and controlled access of digital information without being based on a single trusted authority. By combining cryptographic hashing, distributed ledger mechanisms and permission-based access control, blockchain can do a lot to improve privacy preservation for web applications. This paper presents the idea of a blockchain enabled privacy preservation system for web applications that provides security of data storage, transparency of accessing verification, and against unauthorized modification.
The dynamic service conditions, the lack of centralised control in the distributed and federated services, and the growing sophistication of the malicious behaviours are the key challenges to trust management in the distributed and federated services. Standard trust models, based on fixed credentials, central authorities, or aggregation of reputation over the whole world, are no longer suitable to serve high-rate changing contexts in services, and have very high communication and coordination costs. In an effort to curb these issues, this paper puts forward a proposal of adaptive trust evaluation framework that has distributed verification in highly dynamic service-oriented architectures. The suggested model represents trust as a context-based, multi-dimensional digit that conservatively adapts to the context changes in service conduct, workload, and environmental state. To satisfy the decentralized nature of trust updates, a lightweight peer-based verification system is presented and does not need any centralized sources of trust but instead, trust updates are validated through decentralized means without depending upon a full blockchain consensus system. The framework constitutes adaptive weighting of trust, decay of trust and enforcement policies to reliably detect malicious or unreliable services in changing situations. Between the two widely used approaches, the widespread performance analysis of the suggested approach demonstrates that it has a better accuracy in trust, faster in detecting malicious service and with a much lower communication overhead than state of art centralised, reputation-based and ledger-driven approaches to trust. The findings affirm the viability, scalability, as well as viability of the suggested solution to secure trust execution in the next-generation distributed cloud and edge service surroundings.
Rajesh Bose, Shrabani Sutradhar, Arfat Ahmad Khan, Sandip Roy · 7 authors
ABSTRACT The promise of blockchain applications is transformative in terms of certificate verification and managing digital identities in the various fields, such as education, healthcare and land records. Nevertheless, current blockchainâbased certificate solutions have serious shortcomings: most are based on simple cryptography protection with no privacyâpreserving systems, have low throughput (16.67 TPS in typical Ethereumâbased systems), have unpredictable response times under varying loads, are not standardised across industries and are expensive to operate due to gas fees. Besides, the current implementations are mostly either theoretical or without performance tests in practice. This paper fills these gaps by suggesting a Plonkâbased system that incorporates zeroâknowledge proofs, digital signatures and trusted identity verification to improve the efficiency, security, and privacy of the verifiable credential digital identity verification and management systems (VC DIVMS). It was implemented at JIS University, India, with 50 transactions per minute (an improvement of 200% over Ethereum), an error rate of 244â1277ms in response times under load conditions (24â33 faster than Ethereum) and highâlevel privacy through ZKP. Contrary to currently used models that are sectorâspecific, the offered Plonk framework offers a single, scalable, privacyâfocused model that can be applied in areas of education, healthcare, or credit verification. Intense testing ensured both resilience, scalability and compatibility with a demanding environment, making Plonk a strong and secure substitute to decentralised identity verification and credential management that is resistant to tampering.
Zhang Dayong, Nur Haliza Abdul Wahab, Juniardi Fadila, Arafat Al-Dhaqm · 8 authors
Practical Byzantine Fault Tolerance (PBFT) serves as a cornerstone consensus protocol for distributed systems. However, its inherent limitations, including quadratic communication complexity, scalability bottlenecks, and insufficient privacy protection, hinder its applicability in large-scale and privacy-sensitive environments. This study presents a systematic and comprehensive review of cryptographic advancements aimed at addressing these challenges. By analyzing peer-reviewed literature from 2015 to 2025, we demonstrate that the integration of Verifiable Random Function (VRF) and BonehâLynnâShacham (BLS) aggregate signatures effectively reduces PBFT's communication complexity from O(NÂČ) to O(N) or even O(logN), significantly enhancing scalability and reducing consensus latency. Moreover, advanced cryptographic schemes such as zero-knowledge proofs, homomorphic encryption, group signatures, ring signatures, hash ring, threshold signatures, attribute-based Encryption and lattice-based cryptography are shown to substantially strengthen consensus efficiency, privacy preservation and node security. Despite these improvements, trade-offs arise in terms of computational overhead and system complexity. The findings provide critical insights into the synergetic application of cryptography within PBFT-based systems and offer future directions for constructing scalable, secure, and privacy-preserving distributed architectures, particularly in Internet of Things and other resource-constrained scenarios.
Saha Reno, Koushik Roy, G M Abdullah Al Kafi, Khandakar Md Shafin
ABSTRACT The simultaneous achievement of scalability, security and decentralisation remains an open problem for distributed ledger technologies. This paper introduces InternxtChain, a novel framework leveraging Internxt's decentralised storage infrastructure with zeroâknowledge proofs (ZKPs) and sharded proofâofâstorage (SPoS) consensus. Specifically, erasureâcoded sharding ensures data availability and fault tolerance by splitting files into encoded fragments distributed across nodes; BLSâ381 aggregated signatures enable efficient consensus by compressing multiple signatures into a single short proof; and zkâSNARK audits provide tamperâevident storage verification without revealing user data. InternxtChain addresses this challenge through three synergistic mechanisms: (i) erasureâcoded sharding with (6,3) ReedâSolomon encoding, (ii) zkâSNARKs for storage auditability and (iii) an SPoS consensus based on BLSâ381 aggregated signatures. Experimental evaluation on a testbed of 2048 nodes across 16 geographic regions shows that InternxtChain processes 2800 transactions per second (TPS) with a median latency of 420 ms, while maintaining 99.9% data integrity under up to 30% Byzantine nodes. These results establish a practical path toward harmonising Web3 principles with realâworld throughput, cost and General Data Protection Regulation (GDPR) auditability requirements.
The growth of decentralized data ecosystems has increased the need for transparent and traceable contract agreements between organizations. Although the Eclipse Dataspace Components offer a flexible, open-source framework for sovereign data exchange, they present limitations in terms of end-to-end transparency and traceability of these agreements. This thesis explores how blockchain technologies, specifically smart contracts and tokenized assets, can enhance the Eclipse Dataspace Components to address these limitations. We introduce a model in which contract agreements are represented as non-fungible tokens. These tokens represent uniquely identifiable off-chain contracts whose state changes are immutably recorded on the blockchain. This allows for contract life-cycle monitoring and tamper-proof traceability across dataspace participants. The implementation includes a custom ERC-721 smart contract deployed on the Sepolia Testnet, as well as a decentralized application that connects its functionality to the Eclipse Dataspace Components. The evaluation is conducted using a Minimum Viable Dataspace hosted on two separate servers, representing one data provider and one data consumer. The evaluation demonstrates that agreements based on smart contracts significantly improve transparency and traceability while maintaining data sovereignty. Overall, the results show that blockchain-based contract agreements build trust without modifying the existing workflows of the Eclipse Dataspace Components. This provides a viable path toward the management of trustworthy and sovereign contracts in future dataspaces.
The rapid increase in fraudulent reproduction and misuse of digital certificates has become a critical concern for organizations and institutions worldwide. Fake or tampered certificates are often used to obtain employment in domains where individuals lack the required qualifications, thereby compromising organizational credibility and posing significant risks, particularly in sensitive sectors such as healthcare. With the proliferation of online learning platforms, certificates are issued digitally, making them vulnerable to unauthorized access, duplication, and identity forgery. To address these challenges, this paper proposes a secure and sustainable framework for proof of ownership of valuable educational assets using blockchain technology. Leveraging the capabilities of non-fungible tokens (NFTs), the proposed system ensures that each certificate is uniquely identifiable, tamper-proof, and verifiable. Unlike fungible digital assets, NFTs represent immutable and distinct records on the blockchain, enabling transparent and decentralized ownership verification. The proposed approach not only enhances trust and authenticity in educational credentials but also demonstrates applicability across multiple domains, including healthcare, supply chain, and digital asset management
cloud computing environments and multi agent systems has presented huge difficulties in creating a trust system, verifying securely and largely being transparent amongst the heterogeneous entities. The traditional centralized methods continue to become unsuitable with their vulnerability to the single point of failure, breach of data and unimpeccable auditability. The decentralized and immutable nature of blockchain technology has become a promising solution, but the currently operational blockchain-based systems still present severe constraints which are associated with scalability, high computation cost, disturbing latency as well as absence of adaptive trust mechanism.The current paper suggests a set of new conceptual frameworks on the use of an efficient and secure blockchain-based trust and verification system adapted to the distributed environment. The model uses a hybrid design that combines on-chain and off-chain processing to make the performance efficient and do not compromise security. An active screening system of trust is presented to determine the trustworthiness of each of the participating nodes on the basis of transaction history, behavioral patterns as well as their success rate of validation. Also, it includes a featherweight hybrid consensus which is based on Proof of Stake (PoS) and Practical Byzantine Fault Tolerance (PBFT) to ensure that it uses less energy to execute and also enhance the speed of transactions verification.The framework also includes smart contracts to verify and control access and use of data array of cryptography methods to guarantee the integrity of data and authentication. The proposed model offers a practical and flexible solution to the current distributed system since it tackles major challenge related to the system, namely scalability, efficiency and security. The framework is applicable to various areas which have been showcased in the IoT networks, management of supply chains, data sharing in healthcare, and e-governance. Future research possibilities include incorporating the element of artificial intelligence in the adaptive trust and quantum-resistant cryptographic research.
The exponential growth of cloud computing has enabled large-scale data outsourcing but has simultaneously introduced critical challenges related to data confidentiality, integrity, and trust. Traditional cryptographic and blockchain-based cloud security solutions often suffer from high computational overhead, latency, and scalability limitations, which hinder their practical adoption. To address these issues, this study proposes a robust and lightweight blockchain-based security framework for secure cloud data storage. The framework integrates hybrid AESâECC encryption, smart contractâdriven access control, and a lightweight consensus mechanism combining Delegated Proof of Stake (DPoS) and Practical Byzantine Fault Tolerance (PBFT) to achieve efficient and tamper-resistant data management. The proposed system employs an on-chain/off-chain hybrid architecture that stores only essential metadata and cryptographic proofs on the blockchain while maintaining the actual data in distributed cloud storage. This design minimizes computational burden and blockchain bloat while ensuring end-to-end transparency and verifiability. A Merkle treeâbased Proof of Storage (PoS) mechanism enables rapid integrity verification without requiring full data retrieval. Comprehensive experiments were conducted using a simulated multi-node cloud environment to evaluate encryption efficiency, transaction latency, throughput, storage overhead, and energy consumption. Results show that the proposed framework outperforms existing blockchain-based models, achieving a 37.7% reduction in encryption/decryption time, a 51.3% decrease in transaction latency, and a 54.5% improvement in energy efficiency. Additionally, the system attained a 99.3% security success rate under various attack scenarios, demonstrating its resilience against unauthorized access, replay, and tampering attempts. These findings confirm that the proposed approach provides a practical balance between security assurance and performance optimization.
Digital identity is critical, yet centralized providers create single points of failure—breaches have exposed billions of records—and quantum computing threatens the classical public-key cryptography (RSA/ECC) on which these systems rely. We present a system-level integration of blockchain, zero-knowledge proofs (ZKPs), and post-quantum cryptography (PQC) for privacy-preserving digital identity. A blockchain-based decentralized identifier (DID) system removes central databases; all signing and key-encapsulation operations use lattice-based PQC (CRYSTALS-Dilithium and Kyber); and selective disclosure is provided by Groth16 zk-SNARKs, with revocation via on-chain Merkle non-membership accumulators. We specify the full credential lifecycle—issuance, two-phase authentication, and revocation—with an explicit trust boundary separating the in-circuit Groth16 relation from the off-circuit issuer-signature check. We report a measured evaluation on a reference prototype: under liboqs 0.15.0, Dilithium-II signs/verifies in 0.19/0.06 ms and Kyber-512 encapsulates/decapsulates in 0.018/0.022 ms; a single-authentication Groth16 proof over the 21,715-constraint BN254 credential circuit takes <inline-formula> <tex-math notation="LaTeX">$\approx 981$ </tex-math></inline-formula> ms (snarkJS) and <inline-formula> <tex-math notation="LaTeX">$\approx 177$ </tex-math></inline-formula> ms (native rapidsnark) on byte-identical inputs, with <inline-formula> <tex-math notation="LaTeX">$\approx 40$ </tex-math></inline-formula> ms verification, a 723-byte proof, and <inline-formula> <tex-math notation="LaTeX">$\approx 243$ </tex-math></inline-formula>,000 gas for on-chain verification on a local EVM. A lifecycle harness with a passing revoked-credential negative test validates correctness. The signing and key-encapsulation layers are quantum-safe under current lattice assumptions; the Groth16 proof layer is classically secure only, and its post-quantum migration is identified as future work. End-to-end credential unforgeability is conditioned on an honest holder wallet performing the off-circuit signature check (Assumption 5). Every quantitative claim is labelled measured [M], simulated [S], assumption [A], or future work [F].