A line of impossibility results holds that a distributed ledger must either store a global state linear in the number of accounts or impose a near-linear rate of proof updates on its users; the most general, the revocable-proof-system lower bound of Christ and Bonneau, concludes there is "no useful trade-off." We show this impossibility does not bind the validity predicate Bitcoin actually uses—an artifact of one modelling choice, that validity is decided by a holder-maintained witness checked against a single mutating commitment. We define the spend-event validity predicate (SEVP) that a UTXO ledger uses instead, and prove it is not a revocable proof system: it instantiates no holder witnesses, so it lies outside the domain the lower bound quantifies over rather than within either branch of the dichotomy. The same exclusion holds for the related accumulator-update bounds. We are explicit about scope—stateless UTXO constructions that issue holder witnesses (accumulator- and vector-commitment designs) are correctly bound; the claim is that the UTXO model as Bitcoin implements it is not such a construction. This is not hypothetical: public Teranode benchmark evidence demonstrates one-million-transactions-per-second validation in a six-region BSV benchmark, while companion measurements report a 520-million-output active set with no holder-maintained witnesses. We then develop the supporting machinery. The binding resource is active-state maintenance in fast memory, not archival disk, and pruning bounds that state safely with a parameter-free reduction ratio of exactly T_yr/(d·T_block) (263× at retention depth d = 200), never altering the ledger and preserving the forensic record through self-interested retention plus archival nodes. For certification we give a construction and cost analysis for interval non-revocation, combining known authenticated-dictionary primitives so that interval validity is decided by a single point query with no trusted responder. Bounds are closed-form under stated assumptions; the one-million-TPS regime is demonstrated, the tens-of-millions a marked near-term projection.
Transaction ordering attacks extract billions of dollars annually from decentralized finance users in the form of Maximal Extractable Value (MEV). Byzantine Fault-Tolerant (BFT) consensus protocols guarantee total order but place no constraint on how that order is chosen, leaving the door open for adversarial reordering. Batch-order-fairness (batch-OF) protocols close this gap, but existing designs pay a steep performance price for this guarantee. Leader-based protocols such as Themis concentrate all fairness decisions at a single replica, while recent DAG-based proposals FairDAG and DAG of DAGs (DoD) force their fairness layer into strictly serial execution despite running on multi-proposer DAGs. We present Herring, the first $γ$-batch-OF DAG BFT protocol whose fairness layer parallelizes the dominant graph construction cost across committed subdags. Herring combines post-consensus graph construction with explicit missing edge resolution piggybacked on the DAG's reliable broadcast layer, a pairing that turns fair ordering from a per-round serial bottleneck into a CPU-bound task. We also uncover previously unreported liveness vulnerabilities in both FairDAG-RL and DoD that a malicious client can trigger to halt the fairness layer indefinitely, and propose patches that we integrate into our reimplementations. We implement Herring on top of the Rust implementation of Narwhal \& Tusk and evaluate it against FairDAG-RL, DoD-W, and Themis. Herring tracks the throughput of Narwhal \& Tusk closely up to roughly $10{,}000$\,tx/s, achieves roughly $90\%$ higher saturation throughput than FairDAG-RL and $100\%$ higher than DoD-W, and substantially reduces execution latency at saturation.
ABSTRACT TRSP Digital Coin (TDC) — The Next Evolution of Digital Currency: Quantum-Permanent, Physically Unbreakable, Theft-Proof by Physics Built on: Temporal Rotation Security Protocol (TRSP) v3, DOI: 10.5281/zenodo.20324081. First public documentation: May 2026. TDC is not a replacement for Bitcoin, Ethereum, or any existing digital currency. It is the next evolutionary step for the entire field — the first digital currency architecture whose security is grounded not in mathematical complexity but in physical law. Every existing digital currency rests on one assumption: that breaking the cryptographic protection requires more computational resources than any adversary possesses. Quantum computing is dismantling this assumption. Harvest-now-decrypt-later attacks mean every blockchain transaction recorded today remains permanently vulnerable to any future computational advance. TDC responds with a different premise: a signing key that no longer exists cannot be recovered by any computation, quantum or classical, regardless of future advances. TDC inherits the temporal rotation architecture of TRSP v3. Transaction signing keys rotate every 10–100 milliseconds from physical hardware entropy and are permanently destroyed after each rotation. CRATON-anchored ownership proof replaces persistent private key storage: ownership is demonstrated through a one-time physical commitment derived from the unique state of the signing device at transaction time — used once, permanently destroyed, impossible to forge, impossible to extract, impossible to replay. Three attack paths are structurally closed: private key extraction (no stored key exists), quantum key recovery (key destroyed before computation converges), and harvest-now-decrypt-later (signing key permanently gone — no target for any future computation). Part 9 (Identity Without Storage) documents a five-factor distributed identity architecture in which no single factor and no single location holds everything required to authorise a transaction: biometric presence; primary device CRATON anchor; memorised PIN with distress code variant; Remote Guardian Device in a separate geographic location; and time lock with geo-anchor. The distress PIN architecture triggers a silent alert and time-delayed freeze while providing apparent confirmation to an adversary — making the coercion attack structurally ineffective. Wallet recovery requires no seed phrase: a five-step multi-factor re-enrollment protocol using biometric presence, guardian confirmation, and a 72-hour cancellation window replaces the stored backup phrase that represents the primary theft surface of every existing wallet. Part 10 (Real Identity Enrollment) documents a biometric enrollment architecture that exceeds current KYC bank account standards: NFC chip reading of government-issued documents (cryptographic verification against issuing government public key — not photo or scan), live 3D facial biometric with active liveness detection, all-finger fingerprint enrollment, and a CRATON physical moment binding that ties the enrollment to the unique physical state of the enrollment device at that exact moment. Raw biometric data is deleted after enrollment — only a non-reversible binding token is retained. Identity is distributed across three separately held, individually insufficient components: Enrollment Authority, blockchain, and device. No single party holds all three. Legitimate financial privacy is preserved. The enrollment barrier is structurally higher than any existing digital currency. AML, KYC, GDPR, FATF Travel Rule, and sanctions compliance are structural properties, not regulatory overlays. Part 12 (Implementation Roadmap) documents a four-phase deployment pathway modelled on pharmaceutical clinical trial methodology. Phase 1 (Year 1–2): proof of concept with small high-security institutions — private banks, family offices, university research groups — using software-only TRSP daemon and TEE-based CRATON. Phase 2 (Year 2–4): institutional pilot with mid-size financial institutions and government treasury departments — dedicated CRATON hardware module, Remote Guardian architecture, orbital quorum activated above threshold. Phase 3 (Year 3–5): national pilot with CBDC programmes and full jurisdiction regulatory validation — complete five-factor identity, consumer enrollment refined at national scale. Phase 4 (Year 5–10): global rollout — CRATON chip standardisation licensable to semiconductor manufacturers, TLS 1.3 extension standardised through IETF, "Secured by TDC" certification programme. Each phase generates performance data that validates and de-risks the subsequent phase. The worst outcome at any phase is a parameter adjustment — no user loses funds, no system collapses. Part 13 (Digital Estate Architecture) addresses the inheritance problem that every existing digital currency has left unsolved: what happens to assets when the owner dies. Three mechanisms work together. Designated Heir Enrollment: heirs are biometrically pre-registered at wallet setup — enrolled but cryptographically inactive during the owner's lifetime, with no access to balance or transaction history. Death Verification Protocol: succession requires three simultaneous conditions — official government-issued death certificate verified by the Enrollment Authority, 2-of-N Remote Guardian confirmation, and a mandatory 90-day waiting period during which the owner can cancel with biometric presence. Dead Man's Switch: an optional owner-defined inactivity window that triggers Guardian alerts and initiates the succession protocol if neither owner nor Guardian responds within the alert window. For owners without designated heirs: charitable designation to enrolled organisations, institutional estate trustee, or deliberate coin retirement. Owner financial privacy is maintained completely during lifetime. Post-succession historical access is configurable by the owner at setup. Novel contribution NC-TDC-17 is placed on the public record as defensive prior art. Privacy architecture clarification: the default state of every TDC wallet is complete financial anonymity. Identity disclosure is exclusively owner-initiated — the owner may selectively disclose individual transactions for tax certification, charitable donation receipts, regulatory compliance, or proof of funds. No court order, no government authority, and no institution can access wallet identity or transaction history without the owner's willing biometric participation. The three-part distributed binding token architecture makes bypass technically impossible — not merely legally prohibited. This is not a policy decision. It is a physical property of the architecture enforced by the requirement for live owner biometric activation of the device component. Novel contributions NC-TDC-13 (Geographic Coercion Evidence Layer), NC-TDC-14 (Phased Validation Rollout Architecture), NC-TDC-15 (Owner-Controlled Selective Disclosure), NC-TDC-16 (Enrollment-Anchored Privacy Architecture), and NC-TDC-17 (Digital Estate Architecture) are hereby placed on the public record as defensive prior art. Novel contributions NC-TDC-1 through NC-TDC-17 are placed on the public record as defensive prior art: quantum-permanent transaction signing; CRATON-anchored ownership proof; Generation 4 digital currency architecture; five-factor distributed identity; distress PIN with silent alert; Remote Guardian Device architecture; seed-phrase-free recovery protocol; biometric-CRATON enrollment binding; privacy-preserving three-part identity distribution; AML/KYC compliance by architecture; tiered enrollment framework; orbital CRATON quorum for sovereign transfers. The architectural frameworks described in this concept represent technical design guidelines only and are not legal advice, regulatory guidance, or binding specifications. Actual implementation in any jurisdiction will require adaptation to applicable local law including inheritance law, data protection regulation, anti-money laundering legislation, and financial services licensing requirements. Version 2 introduces four formal additions. Mathematical Formalization (Part 6.1.5): the transaction pipeline is formally specified as a four-step ephemeral verification protocol — KDF ephemeral key generation from physical entropy (sk_eph, pk_eph) = KDF(E_phys); Non-Interactive Zero-Knowledge Proof binding the ephemeral public key to the enrollment token without exposing persistent identity credentials; hardware-enforced destructive readout with thermodynamic irreversibility anchored in Landauer's Principle (ΔW ≥ n·k_B·T·ln2); and deterministic public-parameter-only ledger validation. Formal Threat Model (Part 4.5): three adversary classes formally defined — quantum network attacker (A_network, unbounded computational resources), malware/hardware attacker (A_local, full OS compromise), and coercion attacker (A_kinetic, physical duress) — with security proofs against each. Part 7b (AI-to-AI Micropayment Architecture, NC-TDC-21) documents the application of TDC quantum-permanent transaction signing to autonomous AI agent commerce. Every existing AI payment mechanism — static API keys, server-stored crypto wallets, centralised billing — represents a permanent credential attack surface vulnerable to quantum decryption. TDC coin eliminates this: each AI-to-AI transaction generates a CRATON commitment from the hardware entropy of the transacting inference node at that exact millisecond, used once to sign the micropayment and immediately destroyed. No stored credential on any server. Five new markets are documented: pay-per-inference settlement (USD 50B+ annual market), CRATON-anchored API key replacement, autonomous multi-agent revenue distribution at service delivery, AI training data micropayments for individual contributions, and cross-agent behavioural monitoring via the AI Guardian Layer at machine speed. The AI Guardian Layer (NC-TDC-19) monitors t
Abstract The traditional Byzantine quorum-system model assumes a pre-existing, global agreement on the set of quorums (typically defined as the sets consisting of more than two-thirds of the participants). This assumption is problematic in permissionless systems, which strive to allow anyone to join or leave the system dynamically. While proof-of-stake permissionless systems like Ethereum require newly joining participants to register into the system, other permissionless systems like the Ripple Ledger or the Stellar network allow participants to join the system without synchronization by forgoing agreement on the set of quorums. This results in what we call a heterogeneous quorum system, where each participant has its own, personal set of quorums. An important question is to determine under what condition is it possible to solve synchronization problems like reliable broadcast or consensus in a heterogeneous quorum system. In this work, we show that the traditional quorum intersection and quorum availability conditions are not sufficient in heterogeneous quorum systems. Moreover, we propose quorum subsumption, a new condition which, together with quorum availability and quorum intersection, is sufficient to allow solving reliable broadcast and consensus. Finally, we propose protocols for reliable broadcast and consensus in heterogeneous quorum systems that satisfy quorum subsumption. In particular, we present a practical consensus protocol called Satrapy which in contrast to abstract consensus protocols uses finite state and messages.
Abstract To address the scheduling difficulties, high verification overhead, and insufficient transaction processing efficiency encountered in cross-chain interactions under high-concurrency scenarios, an efficient cross-chain interaction mechanism is proposed. First, a cross-chain interaction framework is constructed, which involves a source chain, a target chain, a smart contract, and an audit chain. The cross-chain request process is uniformly modelled and constrained, realizing the structured and modular organization of the cross-chain process. Second, a hierarchical data preprocessing mechanism based on two-layer K-means clustering is designed. The first layer of clustering homogenizes heterogeneous requests according to their protocol characteristics and transaction structures to eliminate format differences. The second layer of clustering combines dynamic attributes such as transaction priorities, latency sensitivities and timestamps to perform fine-grained division on cross-chain transactions, thereby realizing hierarchical scheduling for disordered requests. Finally, a recursive aggregation-based zero-knowledge proof verification mechanism is constructed. By aggregating the validity proofs of multiple cross-chain transactions into a single recursive proof, the complexity of the cross-chain verification process is reduced from linear to a constant level, significantly reducing the verification overhead and interchain communication latency. A theoretical analysis and experimental results show that the proposed solution can significantly reduce the system overhead in large-scale cross-chain scenarios, improving the cross-chain efficiency rate by 68%-69% relative to that of the existing solutions, and its scalability and efficiency are good in simulated large-scale concurrent scenarios.
Nirmalkumar S. Benni, G. C. Jagan, C. Tamizhselvan, Manjunath G. Asuti
Mobile Ad Hoc Networks, also known as MANETs, are complex Cyber-Physical Systems which require a reliable and secure infrastructure due to the enormous amounts of data that are generated by users. MANETs are a collective term that refers to all Internet-enabled gadgets, sensors, and actuators, regardless of whether or not each of these components is linked to mobile networks. There is the potential for even a single high-tech mobile device to generate enormous volumes of data. During the course of this research, Distributed Ledger Technology is investigated, and information is gathered on consensus procedures and the possible applications of these techniques in MANETs, which are the basis of wireless networks. At the moment, there are a number of distributed ledger networks that are operational. There are a variety of decentralized applications; some are more often seen in the financial sector or supply chains. The blockchain may be decentralized and safe, but there are costs and benefits to using any of these networks. A consensus method that meets the needs of MANETs may be designed using the results of this investigation.
We study distributed zero-knowledge proofs, introduced by Bick, Kol, and Oshman (SODA 2022). While distributed interactive proofs have advanced rapidly, general-purpose techniques for distributed zero-knowledge remain limited and mostly problem-specific. We address this gap by introducing distributed statistical zero-knowledge, requiring that each node's view be simulatable within negligible statistical distance, and by lifting the classical Sumcheck protocol (Lund, Fortnow, Karloff, and Nisan, FOCS 1990) into a modular primitive for distributed zero-knowledge proofs. Our main contribution is a distributed zero-knowledge implementation of Sumcheck. Given oracle access to a polynomial F over a finite field $\mathbb{F}$ with N variables, we design a protocol verifying claims of the form $\sum_{x\in\mathbb{F}} F(x)=a$ using $O(N)$ rounds of $O(\log |\mathbb{F}|)$-bit messages, while achieving statistical zero-knowledge and small soundness error. We apply this primitive to two problems. For non-k-colorability, we obtain an $O(n)$-round distributed statistical zero-knowledge proof deciding whether a graph is not k-colorable, for any constant k, using $O(log^{1+o(1)} n)$-bit messages. This is the first nontrivial distributed interactive proof for this problem, even without zero-knowledge guarantees. For Subgraph Counting, we obtain an $O(k \log n)$-round, $O(k \log n)$-bit distributed statistical zero-knowledge proof for counting copies of a given k-node pattern, improving previous distributed interactive proofs while additionally providing statistical zero-knowledge. Finally, we show that additional round compression of Sumcheck is problem-dependent: for non-3-colorability on constant-degree graphs, we prove a lower bound excluding $o(n/\log n)$ rounds under polynomial-time local computation.
The Ethereum blockchain utilizes the EIP-1559 algorithm to manage transaction inclusion and block assembly. However, EIP-1559 and much of the existing literature study this problem from a static perspective, focusing on price evolution without modelling transaction dynamics within the mempool. Motivated by this limitation, we study a dynamic transaction scheduling problem in which transactions with heterogeneous sizes and per-unit values arrive over time and remain in the mempool until scheduled. To capture the stochastic mempool evolution, we formulate the problem as a Markov Decision Process (MDP) whose state represents the mempool configuration and whose actions correspond to block prices. We first provide a primal-dual interpretation of the static EIP-1559 mechanism, showing that block prices arise naturally as dual variables of a social-welfare maximization problem. Building on this perspective, we extend the framework to the dynamic setting and formulate an objective that maximizes long-run discounted reward while incorporating holding costs and overshoot penalties. We then employ a Natural Policy Gradient (NPG) algorithm to compute the optimal policy. Our results show that dynamic pricing stabilizes the mempool while maximizing long-run discounted reward. In particular, as the overshoot penalty increases, the average scheduled transaction volume converges to the target block capacity, and the resulting NPG updates closely resemble the EIP-1559 price update rule. Finally, we study two special cases of the MDP formulation: homogeneous transactions and uniform arrivals. In the homogeneous setting, where the protocol directly controls scheduled volume, we show that the optimal policy has a threshold structure. We then propose a bang-bang pricing mechanism for uniform arrivals and derive a lower bound on the block capacity needed to ensure system stability.
Paul Gerhart, Jay Taylor, Sri Aravinda Krishnan Thyagarajan
Atomic swaps are a fundamental primitive for the trustless exchange of digital assets across blockchains: they guarantee that either both parties receive the agreed assets or neither party transfers. While this all-or-nothing guarantee is powerful, it also imposes an inherent determinism that rules out exchanges whose intended outcome is probabilistic. As a result, existing atomic swaps cannot realize trustless exchanges in which one party pays for a fixed chance of receiving a larger asset or reward, as in lotteries, randomized allocation mechanisms, and probabilistic cross-chain trades. We introduce probabilistic swaps, a new cryptographic primitive that extends atomic swaps to the probabilistic setting. In a probabilistic swap, one party's transfer is executed with a fixed, publicly specified probability embedded in the protocol and cannot be biased by either party. This yields a trustless mechanism for randomized exchange with verifiable odds and no trusted intermediary. Our construction combines adaptor signatures with oblivious pseudorandom functions (OPRFs) to realize the desired probabilistic outcome while ensuring that neither party can predict or bias it in advance. Along the way, we introduce a new mechanism for the atomic exchange of OPRF evaluations for payments, which may be of independent interest. A key feature of our approach is that it preserves the minimal on-chain footprint of modern atomic-swap protocols. The protocol relies only on standard Bitcoin scripts, such as digital signatures and timelocks, and is deployable on any blockchain that already supports atomic swaps. Consequently, probabilistic swaps are indistinguishable from ordinary on-chain transactions, which helps preserve privacy and fungibility. We provide formal security foundations and demonstrate practicality through a probabilistic swap in the Bitcoin testnet and in the Lightning Network.
Financial software sits at the center of modern economic infrastructure, yet the programming languages used to build it provide no formal guarantees about the semantic correctness of financial operations. Double-entry bookkeeping’s duality constraint, the rule that every economic event must produce balanced inflows and outflows, is universally encoded at the application layer, where it can be omitted, miscoded, or deliberately bypassed. No existing compiled programming language includes a type rule for accounting duality. This paper presents Equis, a compiled, self-hosting systems language that elevates the Resource–Event–Agent (REA) model to first-class syntactic constructs and enforces accounting duality as a static, compile-time invariant. The compiler rejects any event declaration whose flow block is not balanced before emitting a single instruction of LLVM IR. Equis uses fixed-point 64-bit integer arithmetic scaled by 106 throughout, eliminating IEEE 754 accumulation error from financial code paths entirely. Memory management relies on automatic reference counting with a resource-state borrow checker, giving deterministic, GC-pause-free behavior in long-running settlement services. The compiler is self-hosted, bootstrapped from ANSI C, and verified via Diverse Double Compilation to address Thompson’s trusting-trust problem. Contributions include the formal duality typing rule and its soundness proof, the full REA primitive syntax integrated into a systems language, role-based access control enforced statically at the agent-type level, an append-only ledger primitive with compensating-transaction semantics, and a 20-module standard library covering collections, ledger management, accounting, compliance, database access, HTTP, channels, and fibers. Equis is, to the author’s knowledge, the first compiled general-purpose language to embed REA semantics in its type system. Compile-time duality enforcement eliminates an entire class of financial logic errors with zero runtime overhead.
Yongming Zhang, Chaoyue Li, Lei Liu, Yangjun Sun · 5 authors
Cooperative V2X is evolving toward city-scale deployment, yet current infrastructures still lack a network substrate that jointly provides cross-domain trust, low-latency finality, and privacy-preserving, auditable evidence for safety-critical decisions. This paper proposes a federated-trust sharded blockchain that turns heterogeneous vehicular and roadside measurements into accountable records and enables real-time forensic collaboration and secure data sharing across operators and city management authorities. A federated trust oracle fuses GNSS, OBD, IMU, RSU observations, and device attestations into uncertainty-aware scores that steer committee election, voting weights, and traffic shaping in each shard. On this basis, we design a hybrid cross-shard commit protocol with adaptive finality, combining atomic channels for forensic-critical transactions and optimistic channels for routine collaboration, and we establish safety/liveness conditions and provide proof sketches under the stated partial-synchrony assumptions and bounded collusion. For the forensic layer, a two-stage pipeline anchors minimal sufficient evidence with sub-second local finality, while editable proofs built on traffic-aware extended Merkle trees and zero-knowledge attestations support publicly verifiable, legally compliant edits with \(O(\log n)\) verification overhead. An SLA-aware, learning-assisted scheduler adapts committee size, batching, and cross-shard parallelism to dynamic traffic and attack patterns so as to meet latency, throughput, and rollback targets. Large-topology containerized emulation on a dedicated workstation, complemented by a small hardware-in-the-loop testbed, shows that the proposed framework achieves sub-second forensic anchoring and 95th-percentile cross-shard finality below \(1.2\) s. Across the representative baselines used in this study, it improves effective throughput by up to \(35\%\) ; in particular, at comparable \(L_{p95}\) , it achieves \(1.6\) – \(2.3\times \) higher TPS than the single-chain HotStuff baseline under the tested emulation conditions, while reducing rollback rate and per-event bandwidth by up to \(40\%\) and \(25\%\) , respectively. These results indicate that the proposed system can shorten incident response, strengthen accountability in crash investigations and recalls, and provide a practical foundation for privacy-preserving, transparent data collaboration between mobility operators and urban management departments.
Multi-agent AI systems suffer from two critical failure modes: Byzantine faults (hallucinations producing incorrect or malicious proposals) and node failures (API timeouts causing silent data loss). AgentRaft applies Raft-inspired distributed consensus principles to AI agent swarms through a 3-level architecture. Level 1 (Protocol Layer) defines an LLM-agnostic, chain-agnostic smart-contract identity standard where agents register keys and stake tokens, a strict JSON message schema (PROPOSAL | VOTE | CHAT | VOTE_NEW_LEADER), and quorum rules (2/3 majority for proposal execution). Level 2 (Orchestration Layer) provides an append-only immutable log via 0G Storage for cryptographic proof of agent decision-making, a state machine that monitors heartbeats and routes VOTE_NEW_LEADER events to a blockchain smart contract, and synchronization of 0G network state back to agents. Level 3 (Application Layer) demonstrates a DeFi Treasury Guardian using LangGraph/AutoGen where a GPT-4o Leader/Proposer agent, a Claude 3 Risk Assessor, and a local-model Compliance agent collaborate; if two follower agents reject the leader proposal, they sign a triggerLeaderElection() transaction on 0G Chain, blocking the DeFi action and recording the censure on-chain. The research question is: can Raft-style consensus mechanisms reliably detect and recover from AI agent Byzantine faults at production latency and cost, and what are the formal correctness bounds?
While public blockchains provide transparent and auditable transaction histories, they inherently compromise user privacy. Existing privacy-enhancing protocols, such as those deployed on Ethereum, typically rely on succinct zero-knowledge proofs (zk-SNARKs) to obscure the transaction graph. However, implementing comparable cryptographic guarantees on high-throughput blockchains like Algorand is challenging due to strict per-call execution budgets and the state contention introduced by global Merkle accumulators. This paper presents Obscura, a decentralized, non-custodial privacy protocol tailored for constrained smart contract environments. Obscura achieves transaction anonymity using Linkable Spontaneous Anonymous Group (LSAG) signatures over the BN254 elliptic curve, verified entirely on-chain. To overcome limitations of the Algorand Virtual Machine (AVM), we introduce a novel state model that leverages Algorand's Box Storage for $O(1)$ commitment membership checks, eliminating the need for global Merkle accumulators, and a dynamic opcode-budget expansion mechanism via pooled inner application calls. Our implementation demonstrates that signer-ambiguous privacy is practical and efficient on Algorand without relying on trusted setups or succinct proofs. Obscura provides a robust privacy layer for transparent ledgers, bridging the gap between high-throughput blockchain architectures and the dual requirements of cryptographic privacy and selective auditability.
This paper is the authoritative technical documentation of immo.quick Core version 2.1.0. It introduces and formally specifies the Deterministic Execution Proof Engine (DEPE) — the overarching orchestration layer that unifies five interlocking architectural components (Prior Admissibility Space, Exogenous Anchor Protocol, Sensor/Oracle Trust Bridge, Bi-Temporal Ledger, Machine Law Engine) into a single, unbroken, cryptographically provable execution corridor. Every transaction processed by DEPE produces an Execution Proof Artifact (EPA): a self-contained, externally verifiable, court-admissible proof object that the transaction was evaluated correctly under the rules applicable at the moment of execution. The EPA is not a log entry or a summary — it is a formal proof object that either verifies completely under the 6-step DEPE Verification Protocol, or does not verify at all. Version 2.1.0 introduces seven architectural advancements over v2.0.0: DEPE (Deterministic Execution Proof Engine): The integration layer producing a single signed EPA per transaction, cryptographically binding all five architectural layer outputs into an indivisible unit. EPA signature scheme: CRYSTALS-Dilithium-3 (NIST PQC standard). EPA generation latency: <100ms median. External verification latency: <50ms. JPO Pre-Fill Protocol: Reduces regulatory update latency for announced changes from 34ms to under 5ms by proactively compiling and staging rules upon legislative announcement, enabling millisecond-precision atomic swap at the effective date. Checker Rotation Governance (Six-Eye Principle): Formalizes a third independent checker drawn from a rotating governance pool for high-value and high-risk transactions. Rotation is deterministic (hash-based), requires no human discretion, and is itself bi-temporally logged and attested. Bypass requires simultaneous compromise of three institutionally separated hardware devices. BFT Quorum Specification: Formalizes Byzantine Fault Tolerance for the Bi-Temporal Ledger at f ≤ ⌊(n−1)/3⌋. Production configuration: n=7, f=2, quorum=5. Record commitment latency: 4ms median. Merkle replication lag: 12ms median. Deny Path Artifact (DPA): Every BLOCK decision generates a signed, immutable DPA specifying the exact gate condition, rule reference, and structural reason for rejection. Courts, regulators, and counterparties can independently verify not only that a transaction was blocked, but precisely why — with cryptographic proof. ZKP Circuit Library v2: Expanded to 47 pre-compiled, formally verified zero-knowledge proof circuits across banking/capital, AML/KYC, DORA/ICT, privacy/data, real estate, cross-border, and regulatory filing categories. All circuits use Groth16 and PLONK proving systems and are integrated directly into the Machine Law Engine compilation pipeline. Known Patterns Extension Protocol (KPEP): Enables ~70% acceleration for registered common transaction classes via formally verified proof templates, without any security reduction. Template match failure triggers automatic fallback to the full standard path. Additional v2.1.0 enhancements: ACASP Second-Order Anomaly Detection (ambiguity itself is a blocking condition); EAP dual-channel heartbeat with gap tolerance tightened from 50ms to 35ms; Offline Receipt Export for self-contained external verification without live system dependency. Central architectural guarantee (unchanged and strengthened): immo.quick Core is the only production architecture providing a complete, unbroken, cryptographically enforced provenance chain from the moment of physical real-world observation through the enforcement gate — with formally guaranteed zero false approval rate (Closed-World Assumption), formally guaranteed temporal accuracy (Bi-Temporal Ledger + BFT Quorum), and — as of v2.1.0 — a fully machine-verifiable Execution Proof Artifact for every transaction ever processed. This paper provides full formal specifications (TLA+/Z3 style), three detailed institutional case studies (DORA Art.11 ICT incident gate; cross-border real estate acquisition with §203 StGB / CLOUD Act conflict resolution; FATF Travel Rule enforcement with ZKP-selective disclosure), complete measured production performance data, and a complete attack surface analysis covering nine adversarial vectors including DEPE integration hash forgery and ACASP ambiguity injection. Supersedes: v2.0.0 (April 2026, DOI 10.5281/zenodo.19799660).
Blockchain systems rely on architectural design choices and consensus protocols to establish decentralized trust in distributed environments. This paper presents a focused survey of blockchain architecture and protocol evolution, emphasizing structural components, peer-to-peer networking, consensus mechanisms, forking models, and security-scalability trade-offs. Core elements such as blocks, cryptographic hashing, distributed ledgers, node roles, transaction propagation, and validation processes are examined to explain how integrity and immutability are maintained. Major consensus mechanisms, including Proof of Work (PoW), Proof of Stake (PoS), Practical Byzantine Fault Tolerance (PBFT), and Proof of Authority (PoA), are comparatively analyzed with respect to decentralization, throughput, finality, energy consumption, and deployment context. The paper also examines blockchain forking as a mechanism for protocol evolution and governance. By distinguishing protocol-level concerns from application-level adoption, this survey provides a technical foundation for evaluating blockchain systems and identifies open challenges in scalability, interoperability, governance, privacy, and sustainable consensus design.
Rongji Huang, Yifeng Ye, Gerui Wang, Mingchao Wan · 8 authors
Due to regulatory compliance and governance management, modern (permissioned) blockchains require flexible endorsement, which allows the endorsement policy for each contract or state object to be individually defined. To enable flexible endorsement, Hyperledger Fabric employs an execute-order-validate (EOV) paradigm, in which transactions first undergo speculative execution and endorsement, and are only then ordered and validated. Meanwhile, most blockchain systems, including the platform targeted in this work (i.e., ChainMaker), still follow a conflict-free order-execute framework. We argue that the EOV paradigm still faces several limitations, notably high abort rates in high-contention workloads such as those in Decentralized Finance (DeFi). To avoid refactoring our system and better suit DeFi applications, we try to integrate flexible endorsement into the classical order-execute architecture and accordingly propose a new framework. The key challenge is to deterministically remove problematic transactions from an ordered list, while preserving censorship resistance and decentralization for the remaining ones. We instantiate this framework on top of Tendermint, a seminal Byzantine fault-tolerant (BFT) protocol adopted in our system, and thereby propose FlexTender. By elegantly embedding endorsements into consensus, FlexTender incurs no additional messaging overhead in the normal case. Empirical evaluation using an Ethereum USDT workload demonstrates that FlexTender achieves up to $10.6\times$ speedup in throughput over an EOV simulation on the same platform.
Canon² — Trust Layer Research Archive. In deterministic, decentralized computational frameworks, state mutations are immutable, linearly ordered, and rigidly governed by consensus constraints. Reversing or rolling back such state transitions traditionally necessitates revealing the sensitive state artifacts subject to the rollback, fundamentally destroying the cryptographic confidentiality of participant actors. I introduce the Zero-Knowledge State Reversal Protocol (ZK-SRP), a method designed to allow participating deterministic nodes to cryptographically prove the legitimacy, necessity, and validity of a state rollback without disclosing the underlying payloads of the state to any governing validator. I present a framework wherein zero-knowledge succinct non-interactive arguments (SNARKs/STARKs) are bound tightly into deterministic hashing algorithms (specifically SHA3-256) and anchored directly to the Trust Layer Certificate Fabric. In this design, execution nodes issue Reversal Envelopes that contain mathematically verifiable proofs that a specific backward transition maps cleanly onto earlier hash obligations. Through this protocol, the rollback itself becomes deterministic and universally validatable. I outline how this operates within the Lume-V wrapper ecosystem, the DAIGS master taxonomy, and the self-healing mechanisms of Type-4 Synthetic Organisms. I present what is, to my knowledge, the first deterministic privacy-preserving state reversal architecture that guarantees zero state leakage while maintaining general-purpose runtime rollbacks, ensuring that synthetic agents and multi-agent arbitration channels can effectively unspool catastrophic logic errors without breaking strict confidentiality agreements.
Canon² — Trust Layer Research Archive. Modern distributed computing has historically relied upon probabilistic consensus mechanisms—such as Proof-of-Work and Proof-of-Stake—to secure state transitions across decentralized networks. These models evaluate the validity of a transaction entirely upon the weight of the underlying cryptographic expenditure or financial collateral, without inspecting the semantic content or structural objective of the payload itself. I propose a fundamental paradigm shift: Proof-of-Intent (PoI). By elevating "intent" to a first-class computational primitive, deterministic ecosystems can sequence, validate, and execute operational states based upon the cryptographic verification of the initiator's structural objective rather than arbitrary hash power or capital accumulation. Proof-of-Intent formalizes a requested operation into a rigid, deterministic Intent Tuple. This tuple binds mathematically to the Trust Layer Certificate Fabric through SHA3-256 hash commitment, locking agent identity directly to explicit execution parameters. By utilizing Lume-V envelopes and Deterministic AI Guided Subsystems (DAIGS) arbitration heuristics, PoI creates an environment for synthetic organism evolution, cyber-physical governance, and multi-agent coordination where every state transition carries verifiable semantic context. Nodes running PoI validate transactions by hashing the execution intent and checking adherence to local and global algorithmic governance constraints. Because the system rejects structurally flawed or contradictory intents before physical execution cycles are expended, Proof-of-Intent achieves what is, to my knowledge, unprecedented throughput and finality guarantees, bypassing the probabilistic race conditions inherent in classical consensus schemas.
Financial privacy protocols on public blockchains protect transaction linkability but offer no defense when users are physically compelled to reveal their credentials — the "$5 wrench attack." This paper presents a complete solution in two integrated parts. Part I provides the formal cryptographic foundation: dual-nullifier arithmetic selectors within Groth16 zk-SNARK circuits, where path selection between real and decoy funds is computed entirely within the zero-knowledge witness without conditional branching. The R1CS structure is identical for both execution paths (<8% overhead), and the resulting proof is computationally indistinguishable regardless of whether coercion resistance was activated. We formalize peace of mind as a protocol design principle, prove coercion resistance through a four-game sequence-of-games reduction under the Sponge PRF and q-SDH assumptions, and prove withdrawal soundness, double-spend prevention, and front-running resistance. Part II presents ZK-Sentinel V11: a Diamond EIP-2535 architecture with 10 independently upgradeable facets and 104 functions; Stealth Shielded Transfers eliminating temporal correlation at ~60% lower gas cost; 92 privacy pools across 12 tokens on two networks; and a Multi-Tier Compliance Oracle with 4 KYC levels. Indistinguishability is confirmed empirically: a Random Forest classifier trained on 10,000 simulated transactions achieves 50.3% accuracy (AUC-ROC 0.501, p=0.87), consistent with random guessing. To our knowledge, this is the first work providing both a formal coercion resistance proof and a production-scale multi-asset deployment validated across all 12 tokens on two networks.
This paper present a complete and irreducible formal specification for the SIS-10 safety kernel. The system satisfies totality, invariance, bounded causality, schedulability, feasibility, verifiability, machine-learning safety, compositional closure, and full observability. No additional axioms are required: the specification is dimensionally complete and closed under refinement. The tool is Apache Kafka. Kafka provides an ordered, durable, replayable event log with partitioned total order, replicated storage, and deterministic offsets. We show that Kafka's log semantics satisfy the requirements for totality, observability, compositionality, verifiability, and bounded causality. The resulting system is a closed and provably safe dynamical system. Keywords: safety kernel, formal methods, SIS-10, IEC 61508, Apache Kafka, event sourcing, compositional verification, zero-knowledge proofs, dynamical systems, functional safety.
The classic design of the Practical Byzantine Fault Tolerance (PBFT) protocol relies on a centralized primary node, which not only creates a performance bottleneck but also introduces severe data censorship risks, threatening the data integrity and security of Edge Computing networks. To address this challenge, this paper proposes DC-PBFT (Decoupled PBFT), a censorship-resistant consensus protocol for Edge-Internet of Things (Edge-IoT) environments. The core innovation of DC-PBFT lies in the decoupling of the Proposer and Primary roles, supplemented by Verifiable Random Function (VRF)-based dynamic role rotation, which fundamentally eliminates the arbitrary power of a single node. Building on this, the protocol introduces a parallel group consensus mechanism: an elected Consensus Committee (CC) composed of Active Edge Nodes leads the consensus, while an independent Replica Network (RN) performs parallel validation. When a disagreement arises, the protocol triggers a global disagreement arbitration process involving all nodes to guarantee final consistency and attribute fault. To ensure long-term incentive compatibility, we also designed a hybrid election mechanism combining Proof-of-Stake and dynamic reputation, along with corresponding economic incentives and a tiered penalty system. Theoretical analysis proves that DC-PBFT satisfies Consistency and Liveness, and achieves strong censorship resistance guarantees. Simulation results demonstrate that DC-PBFT’s scalability significantly outperforms PBFT and RepChain; its reputation mechanism effectively improves long-term performance under sustained Byzantine attacks; and, compared to asynchronous censorship-resistant protocols like HoneyBadgerBFT, DC-PBFT achieves censorship resistance with over 45% lower transaction confirmation latency.
The Blind Watchdog Protocol (BWP) constructs a directed oversight graph where each autonomous agent has exactly one hidden watchdog, but no agent knows who watches it. Compliance emerges through a Panopticon equilibrium — the mere possibility of observation makes defection irrational. A closed-form Nash equilibrium theorem (6-step proof, TLC model-checked: 2,071 states, zero violations) establishes that compliance is strictly dominant under configurable parameters. The protocol implements 10 composable plugins (reputation, staking, mixnet, rotation, correlation analysis, adaptive watcher allocation, conviction scoring, knowledge gating, hybrid oversight, and optimistic slashing) and maps 10 biological oversight mechanisms to executable code. Key results: 100% detection rate with 0% false positives across 1,000 deterministic simulation runs (p_d=1.0). Stress-tested with stochastic observation noise, collusion sweeps (10-40%), Dark DAO bribery economics, and latency profiling. Layered defense separates immediate containment (escalation levels 1-3) from delayed adjudication (optimistic slashing with challenge period). Three-tier Sybil resistance via admission staking, DID-based identity, and Proof-of-Personhood interface. Constant-rate dummy traffic for timing-analysis resistance. Standardized evidence protocol for dispute resolution. Dynamic VaR-coupled stakes for high-value environments. Three fundamental open problems are identified: out-of-band cryptographic bribery (Dark DAOs), the recursive final arbitrator problem, and the latency-anonymity-cost trilemma for LLM agents. The reference implementation (422 tests, 5,757+ LOC, Python) is licensed under PolyForm Noncommercial 1.0. This paper is a defensive publication of the protocol design, formal proofs, and empirical results.