Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

486 papersLast indexed Aug 31, 2026
Search papers

Paper index

486 results · page 5 of 21

Clear filters
Mar 23, 2026·Proceedings of the 41st ACM/SIGAPP Symposium on Applied Computing
0 cites
RepStake: A Blockchain-Based Trust System with Reputation Staking

Dimitris Mantzonis, Thanasis G. Papaioannou

Reputation systems are fundamental to fostering trust and cooperation in digital environments, yet existing solutions often struggle with centralization, vulnerability to manipulation, and limited portability. Centralized reputation platforms can be opaque, censored and susceptible to become single points of failure, while decentralized ones face challenges, such as Sybil attacks, malicious strategies (e.g., ballot stuffing, bad-mouthing) exercised by entities of high influence, i.e. "whales", and privacy concerns. This paper addresses these persistent issues by proposing a blockchain-based reputation framework that integrates robust identity verification, square root voting constraints, and dynamic stake-based incentives. Rating power is linked to the reputation of the rater that puts its reputation at stake. The model aims to ensure that reputation is earned and maintained through verifiable, community-aligned actions, while simultaneously limiting the potential for abuse by malicious actors or disproportionately influential participants. By leveraging decentralized identifiers, zero-knowledge proofs, and transparent incentive mechanisms, the proposed system seeks to balance transparency, fairness, and privacy. Extensive simulation experiments prove that the approach is effective to reveal the true quality of entities, even in presence of 49% colluding voters. The approach is designed to be adaptable across diverse domains, ranging from marketplaces and collaborative platforms to decentralized finance and governance.

Open access
Blockchain Technology Applications and Security
Access Control and Trust
Cryptography and Data Security
Original source
Mar 23, 2026·Proceedings of the 41st ACM/SIGAPP Symposium on Applied Computing
0 cites
TLS2VC: A Decentralized WebProof Framework Enabling Verifiable Credentials for TLS Sessions

Haocheng Jiang, Iifan Tyou, K. Matsuura

This work proposes TLS2VC, a decentralized WebProof framework that distributes trust across multiple Notaries. Notaries attest to TLS session authenticity—server identity and encrypted transcript integrity—without accessing plaintext, then issue Verifiable Credentials (VCs) that Verifiers can validate. To prevent concentration of malicious Notaries, we employ verifiable random selection via Verifiable Random Function (VRF) combined with threshold signatures. We provide probabilistic security analysis showing that honest Notaries are included with high probability, and derive formulas to compute the minimum number of Notaries k required for a target security level. A lightweight prototype demonstrates practical feasibility, enabling reuse of existing web information as trusted credentials in Web3 and self-sovereign identity environments.

Open access
Cryptography and Data Security
Access Control and Trust
Blockchain Technology Applications and Security
Original source
Mar 22, 2026·Research Square
0 cites
Cognitive Ledger Protocol (CLP): A Trust Fabric Architecture for Verifiable Agentic Data Transactions

Sarat Piridi

Abstract One of the key implications of the rapid development of agentic AI systems is an increased demand for data transactions that are transparent, auditable, and trustworthy. The biggest liability within autonomous agents is their lack of a collective framework of accountability, particularly because autonomous agents are increasingly sharing information, making decisions, and coordinating their actions in distributed systems. This article introduces the Cognitive Ledger Protocol (CLP), a trust fabric architecture that facilitates immutable traceability and verifiable reasoning in agent-to-agent data transactions. CLP is the first technology that goes beyond the record of the data exchanges to provide an account of the cognitive steps the agents made to reach the action. The protocol was designed to enable various functionalities including tamperproof recording of transactions, secure storage of data and the ability to perform real-time analytics using out-of-the box technologies such as Azure Confidential Ledger, Copilot Agent Telemetry, and Fabric Event Streams. The resulting platform becomes a single transparency layer that can simultaneously be employed for explaining the automated processes, raising the level of a multi-agent ecosystem's accountability, and enabling the ethical use of autonomous AI. The paper elaborates on the fundamental framework of CLP, the essential design principles, the deployment aspects, and the use cases in the sector.

Open access
Distributed systems and fault tolerance
Blockchain Technology Applications and Security
Access Control and Trust
Original source
Mar 21, 2026·Scientific Reports
1 cites
Blockchain-based two-level trustable reputation framework for e-commerce platform using smart contracts

K. Sundara Krishnan, R. Chithra Devi, Christo Ananth, D. Easwaramoorthy · 8 authors

E-commerce platforms incorporate reviews and reputation systems, allowing retailers and customers to manage and track their financial transactions. Consequently, it is crucial to design a reliable reputation system for the e-commerce environment, as it faces well-documented threats, including sybil attacks, feedback collusion, impersonation, review tampering, and whitewashing attacks. Current centralized systems are vulnerable to impersonation attacks, feedback manipulation, and lack automated verification against collusion-based reputation distortion. These unwanted ratings and reviews are highly correlated with abnormal cyber-attacks that damage both seller reputations and buyer experiences. To address these challenges, we propose a Blockchain-based Two-Level E-Commerce Trustable Reputation Framework (BTL-ETRF) utilizing deep learning-embedded transformers and redactable blockchain systems. Initially, we implement Multi-Factor Authentication for e-commerce users, utilizing three factors: PIN, OTP, and biometric fingerprint, to mitigate impersonation attacks. Only authenticated users are allowed to proceed to the reputation verification stage, where the proposed work considers five major metrics to classify user reputation using the Residual Dilated Convolution Transformer. To automate the reputation verification process, we design and employ two smart contracts, the Authentication Smart Contract and the Reputation Smart Contract which trigger automated actions based on the BTL-ETRF results. All transactions include reputation classification, and triggered actions are stored in the redactable blockchain, which can modify the stored transactions if needed. Finally, we demonstrate the performance of the proposed BTL-ETRF using Python and Ethereum Solidity, and conduct a formal analysis that shows the proposed model outperforms the compared works.

Open access
Blockchain Technology Applications and Security
Access Control and Trust
Cryptography and Data Security
Original source
Mar 20, 2026·Electronics
1 cites
Human-Centric Zero Trust Identity Architecture for the Fifth Industrial Revolution: A JEPA-Driven Approach to Adaptive Identity Governance

Jovita T. Nsoh

The Fifth Industrial Revolution (Industry 5.0) foregrounds human–machine collaboration, sustainability, and resilience as organizing principles for next-generation cyber-physical systems. Yet the identity and access management (IAM) architectures inherited from Industry 4.0 remain perimeter-centric, policy-static, and blind to the behavioral dynamics of human–AI teaming. This paper introduces the Human-Centric Zero Trust Identity Architecture (HC-ZTIA), a novel framework that repositions identity as the adaptive control plane for Industry 5.0 environments. HC-ZTIA integrates three mutually reinforcing innovations: (1) a Joint Embedding Predictive Architecture (JEPA)-driven Behavioral Identity Assurance Engine (BIAE) that learns abstract world models of operator and machine-agent behavior to perform continuous, context-aware identity verification without relying on raw biometric surveillance; (2) a Privacy-Preserving Adaptive Authorization Protocol (PP-AAP) employing zero-knowledge proofs and federated policy evaluation to enforce least-privilege access across human, non-human, and hybrid identity classes while satisfying data-minimization mandates; and (3) a Resilience-Oriented Trust Degradation Model (RO-TDM) that guarantees fail-safe identity governance under adversarial, degraded, or disconnected operating conditions characteristic of operational technology (OT) and critical infrastructure. The framework is grounded in the Agile-Infused Design Science Research Methodology (A-DSRM) and formally extends NIST SP 800-207 and the CISA Zero Trust Maturity Model by addressing five identified gaps in human-centric identity governance. We present the formal system model, threat model, architectural specification, and a multi-scenario evaluation spanning energy-sector OT, smart manufacturing, and vehicle-to-everything (V2X) environments. Simulation results, validated through Monte Carlo trials with 95% confidence intervals, demonstrate that HC-ZTIA reduces identity-related breach exposure by 73.2% (±4.1%) while maintaining sub-200 ms authorization latency, offering a principled bridge between Zero Trust rigor and Industry 5.0 human-centricity.

Open access
2 source records
Safety Systems Engineering in Autonomy
Smart Grid Security and Resilience
Access Control and Trust
Original source
Mar 19, 2026·Open MIND
0 cites
Composable Model Identity — Formal Hardening of Structural Attestations in the Enterprise Identity Stack

Anthony Coslett

Enterprise identity systems can authenticate workloads, credentials, and attested platforms, but they do not close the composition layer where runtime model identity enters authorization. A token can verify that a service is running in a trusted environment, that its credentials are valid, and that its actions are authorized — without ever establishing which neural network is actually computing. When model identity evidence is inserted into standard authorization flows, new security properties emerge that are not inherited from the underlying protocols and must be formally established rather than presumed. This paper presents a live integration architecture for model-identity attestations in JWT and SPIFFE-style token flows, grounded in real measurements from six neural networks executed inside an NVIDIA H100 Confidential Computing enclave. It formally verifies four composition properties — non-separability, temporal binding, issuer authenticity, and reference integrity — across three Coq proof files with zero unfinished proof obligations. Every remaining trust dependency is explicitly named, traced to an integration control, and paired with a concrete falsification witness. The result is a formally hardened composition layer where no security property is left implicit and no assumption is left silent. Supplementary Material This paper is accompanied by three Coq proof files — ComposableIdentity.v, IssuerAuthenticity.v, and ReferenceIntegrity.v — that formally verify the four composition properties described in §§4–6: non-separability, temporal binding necessity, issuer authenticity, and reference integrity. Together the files prove thirteen theorems from eleven named axioms, each paired with a concrete falsification witness and an integration control. No file contains unresolved obligations (Admitted), and all three compile cleanly under the Rocq Prover 9.1.1 (the current release of the Coq proof assistant, compiled with OCaml 5.4.0). They are available for download as supplementary files attached to this record. The Neural Network Identity Series — Mathematical foundations, empirical validation, and governance frameworks for verifying which model is running Newest addition: Technical Note: The Disappearing Window — AI Logprob Access Withdrawal and the Structural Verifiability of Frontier Model Contracts (DOI: 10.5281/zenodo.20362098) Paper 1: The δ-Gene: Inference-Time Physical Unclonable Functions from Architecture-Invariant Output Geometry (DOI: 10.5281/zenodo.18704275) Paper 2: Template-Based Endpoint Verification via Logprob Order-Statistic Geometry (DOI: 10.5281/zenodo.18776711) Paper 3: The Geometry of Model Theft: Distillation Forensics, Adversarial Erasure, and the Illusion of Spoofing (DOI: 10.5281/zenodo.18818608) Paper 4: Provenance Generalization and Verification Scaling for Neural Network Forensics (DOI: 10.5281/zenodo.18872071) Paper 5: Beneath the Character: The Structural Identity of Neural Networks — Mathematical Evidence for a Non-Narrative Layer of AI Identity (DOI: 10.5281/zenodo.18907292) Paper 6: Which Model Is Running?: Structural Identity as a Prerequisite for Trustworthy Zero-Knowledge Machine Learning (DOI: 10.5281/zenodo.19008116) Paper 7: The Deformation Laws of Neural Identity (DOI: 10.5281/zenodo.19055966) Paper 8: What Counts as Proof? — Admissible Evidence for Neural Network Identity Claims (DOI: 10.5281/zenodo.19058540) Paper 9: Composable Model Identity — Formal Hardening of Structural Attestations in the Enterprise Identity Stack (DOI: 10.5281/zenodo.19099911) Paper 10:Where Identity Comes From: Path Sensitivity and Endpoint Underdetermination in Neural Network Training (DOI: 10.5281/zenodo.19118807) Paper 11: Post-Hoc Disclosure Is Not Runtime Proof: Model Identity at Frontier Scale (DOI: 10.5281/zenodo.19216634) Paper 12: Family-Dependent Response to Reasoning Distillation Across Structural and Functional Identity Layers (DOI: 10.5281/zenodo.19298857) Paper 13: Safety-Alignment Removal as a Model-Identity Failure — Structural Evidence from Published Weight-Level Mutation Checkpoints (DOI: 10.5281/zenodo.19383019) Technical Note: Agent Identity Is Not Model Identity (DOI: 10.5281/zenodo.19240883) Technical Note: Gap Invariance: Why PPP Measurements Are Domain-Independent by Construction (DOI: 10.5281/zenodo.19275524) Technical Note: Measured Model Substitution Under Valid Agent Credentials (DOI: 10.5281/zenodo.19342848) Technical Note: Artifact Identity Is Not Runtime Identity — Trustfall Lite and the Boundary of File-Level Model Verification (DOI: 10.5281/zenodo.20019127) Formal Verification Stack for Neural Network Structural Identity (IT-PUF Coq Proofs) (DOI: 10.5281/zenodo.18930621) Copyright (c) 2026 Anthony Ray Coslett / Fall Risk AI, LLC. All Rights Reserved. Confidential and Proprietary. Patent Pending (Applications 63/982,893, 63/990,487, 63/996,680, 64/003,244).

Open access
2 source records
Access Control and Trust
Security and Verification in Computing
Adversarial Robustness in Machine Learning
Original source
Mar 16, 2026·arXiv (Cornell University)
0 cites
Grant, Verify, Revoke: A User-Centric Pattern for Blockchain Compliance

Supriya Khadka, Sanchari Das

In decentralized web applications, users face an inherent conflict between public verifiability and personal privacy. To participate in regulated on-chain services, users must currently disclose sensitive identity documents to centralized intermediaries, permanently linking real-world identities to public transaction histories. This binary choice between total privacy loss or total exclusion strips users of agency and exposes them to persistent surveillance. In this work, we introduce a Selective Disclosure Framework designed to restore user sovereignty by decoupling eligibility verification from identity revelation. We present ZK-Compliance, a prototype that leverages browser-based zero-knowledge proofs to shift the interaction model, enabling users to prove specific attributes (e.g., "I am over 18") locally without revealing the underlying data. We implement a user-governed Grant, Verify, Revoke lifecycle that transforms the user's mental model of compliance from a permanent data handover into a dynamic, revocable authorization session. Our evaluation shows that client-side proof generation takes under 200ms, enabling a seamless interactive experience on commodity hardware. This work provides early evidence that regulatory compliance need not come at the cost of user privacy or autonomy.

Open access
2 source records
cs.CR
cs.HC
Privacy, Security, and Data Protection
Original source
Mar 13, 2026·Journal of King Saud University - Computer and Information Sciences
0 cites
A medical cross-chain dpos consensus scheme integrating reputation and contribution evaluation

Xiaohong Deng, Yunzhen Zhu, Zhigang Chen, Ming Zhao · 6 authors

Cross-chain technology is the key to solving the “data silo” problem in medical blockchain systems. However, it is difficult for existing cross-chain consensus mechanisms to meet the high standards of data security and consensus efficiency in medical scenarios. Therefore, this paper proposes a medical cross-chain Delegated proof of stake consensus(DPoS) scheme that integrates reputation and contribution evaluation. First, a dynamic reputation evaluation model was constructed, and the historical behaviour and communication quality of nodes were incorporated into the evaluation system, thereby mitigating the risk of centralization caused by the excessive reliance on the number of coins held in the DPoS consensus. Second, a hybrid random block generation mechanism combining the multiparty coin-tossing protocol and the secure shuffling algorithm was proposed. By collaboratively generating a verifiable global random seed and uniformly and randomly shuffling the candidate node sequence, the predictability of the block generation order was eliminated. Finally, a two-layer incentive architecture based on the Shapley value was proposed. Fine-grained contribution assessment mechanisms were established at both the candidate node layer and the voting node layer, making the reward distribution more equitable, enhancing the enthusiasm of nodes for voting and improving the consensus efficiency. Theoretical analysis and experimental results show that compared with the DPoS scheme, the proposed scheme improves the throughput by approximately 30% and reduces the average latency by approximately 50%. Compared with existing similar schemes, this scheme also has significant advantages in terms of reputation calculation overhead and malicious node elimination and can provide efficient and reliable consensus support for cross-chain scenarios in the medical field.

Open access
Access Control and Trust
Bayesian Modeling and Causal Inference
Biomedical Text Mining and Ontologies
Original source
Mar 13, 2026·DMPedia Lecture Notes in Computer Science & Engineering
0 cites
Combating Fake Reviews in Tourism: A Blockchain-Driven Approach to Secure Online Ratings

Hirok Agarwala, Md Thouhedul Alam Tonoy, Hemal Shil, Swopnil Singha Simanto · 6 authors

Tourism relies on central review platforms which produces three major systemic issues that include fake content, unclear moderation activities and inadequate compensation systems for authentic consumer contributions. TrustChain resolves industry review challenges using a blockchain formation that combines Layer-2 scaling solutions with zero-knowledge proofs (ZKPs) and tokenized governance system. The transaction cost reductions are huge following the implementation of a Proof-of-Stake consensus system on the Polygon-based architecture although the system maintains confirmation times shorter than 2 seconds. The implementation of Self-Sovereign Identity framework alongside transaction-linking smart contracts maintains highly accurate review authenticity in prototype evaluations through TripAdvisor datasets. Through its DAO governance structure users can verify review authenticity by using multi-signature checks which resolve all major disputes in less than one day. The integration of IPFS for multimedia storage generates an 83% decline in blockchain bloat that does not affect cryptographic security.

Open access
Blockchain Technology Applications and Security
Cryptography and Data Security
Access Control and Trust
Original source
Feb 28, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
Passport Alliance Specification (APIS v2.0): Agent Passport Issuance Standard with Hardware Trust Anchors and Universal Framework Interoperability

Cory M. Gibson

We present APIS v2.0 (Agent Passport Issuance Standard), a cryptographic identity framework for autonomous AI agents operating across organizational boundaries and agentic frameworks. APIS v2.0 defines a credential chain grounded in legal mandate doctrine, hardware trust anchors (TPM 2.0), and DNS-anchored identity for cloud-hosted agents. Each agent receives a realm-scoped Decentralized Identifier (DID) and a signed Passport JWT binding the agent to a named principal, a scoped mandate, and a verifiable machine identity. The framework introduces a tiered trust model accommodating physical TPM (Tier 1) through DNS-registered identity (Tier 2.5), enabling CMMC Level 2 compliance for AI agent operations. We describe the APIS-APP provisioning protocol — an ACME-equivalent automated passport issuance mechanism — and demonstrate interoperability across OpenHands, Claude Code, Codex, and custom agent frameworks. A reference implementation is available at passportalliance.org.

Open access
Access Control and Trust
Mobile Agent-Based Network Management
Security and Verification in Computing
Original source
Feb 28, 2026·Open MIND
2 cites
Behavior-Bound Signatures: Cryptographic Policy Enforcement from Zero-Knowledge Soundness

Li, Y.Y.N.

Every standard signature scheme enforces one property: only the key holdercan sign. What the key holder signs is unconstrained. Policy enforcement-- spending limits, rate limits, access control -- lives in smartcontracts, middleware, or governance: layers that can be upgraded,bypassed, or exploited. We call this the software-layer assumption:compliance holds only if the enforcing code is correct and unmodified. We eliminate this assumption. We introduce behavior-bound signatures(BBS), in which a policy constraint delta(x) < epsilon is committed atkey generation and enforced inside the signature's zero-knowledge proof.If the action violates the policy, the ZK constraint system isunsatisfiable -- no witness, no proof, no signature. This is not asoftware check. It is a mathematical impossibility. No software canoverride. Unlike policy-based signatures (where an authority imposes policy onsigners), BBS is self-committed: the signer binds their own futurebehavior at key generation, and even the signer cannot later violate orrevoke this commitment. We formalize this as policy-soundness (PS-CMA), a security modelstrictly stronger than EUF-CMA, and prove it under standard assumptions(Pedersen binding, Poseidon CR, ZK knowledge soundness). From thissingle primitive, five independent consequences follow -- not as separatedesigns, but as necessary implications of one cryptographic root: (A) Compliance safety under f <= n-1 Byzantine faults, decoupled from honest-quorum assumptions.(B) O(1) verification and audit via a single ZK check and Pedersen homomorphic aggregation.(C) Elimination of the virtual-machine execution layer for policy-constrained transactions.(D) A gasless ledger: branch C removes metering, while ZK-encoded rate limits make spam mathematically nonexistent.(E) The first cryptographic guarantee that a compromised autonomous AI agent cannot exceed its authorized behavioral envelope. Moreover, the zero-knowledge property ensures that complianceverification reveals neither the signer's identity nor the transactionparameters -- achieving regulatory compliance without identitydisclosure, complementary to existing ZK-KYC frameworks that verifystatic identity attributes.

Open access
Cryptography and Data Security
Access Control and Trust
Security and Verification in Computing
Original source
Feb 28, 2026·ACM Transactions on Internet Technology
0 cites
Fair and Direct Exchange of Non-Fungible Tokens: The ExNFT Approach

Rosa Pericàs Gornals, M. Magdalena Payeras Capellà, Victor Garcia Font, M. Puigserver · 5 authors

The exchange of non-fungible tokens (NFTs) traditionally occurs on centralized NFT marketplaces, which often wield significant control over transactions, as the imposition of restrictions and fees. Additionally, the current NFT standard (ERC-721) lacks certain functionalities that hinder the seamless direct exchange of NFTs between owners. This article introduces a novel protocol that eliminates the need for an intermediary marketplace, as well as their intermediary smart contract or escrow contract, facilitating a fair exchange of NFTs as collectibles. The protocol is represented by an extension of the ERC-721 called Exchangeable NFTs (ExNFTs), which introduces the necessary functionalities to enable direct NFT exchanges. We analyze the limitations of the ERC-721 standard and build upon our previously proposed protocol of Rejectable NFTs (RejNFTs), which introduces a rejectable functionality empowering the receiver to reject the transfer of an NFT. Additionally, we discuss the reasons why achieving a fair direct exchange of NFTs is currently unattainable with the prevailing standards. We present the key functionalities of the ExNFT approach, along with a Solidity implementation of the ExNFTs. Furthermore, we evaluate the performance of the protocol, considering costs and security.

Open access
Blockchain Technology Applications and Security
Auction Theory and Applications
Access Control and Trust
Original source
Feb 26, 2026·International Scientific Technical Journal Problems of Control and Informatics
0 cites
Mandatory access control method application for smart contracts

Yurii Baryshev, Dmytro Zarezenko

The task of access control in distributed information systems utilizing smart contracts is considered. A concise review of the main access control approaches — mandatory, role-based, and discretionary — is presented, along with their key features and limitations. Particular attention is paid to the access control approach based on mandatory access control (MAC). Known access control approaches applied in both traditional non-distributed and distributed information systems utilizing smart contracts are analyzed. The peculiarities of these distributed information systems that influence access control decisions are identified. Based on these peculiarities, the drawbacks of the discretionary and role-based approaches are determined, and the mandatory approach is proposed. To formalize the approach, a mathematical description of MAC for smart contracts is provided. To demonstrate the concept, several examples of implementing this mathematical description are presented in the form of Solidity code fragments: a direct naive implementation, an implementation using modifiers, and an implementation based on a dedicated access manager contract. The code is described, its main idea is explained, and possible directions for further scaling of these code fragments are outlined. Based on the analysis of the proposed applications, the modifier-based implementation of MAC is identified as the most efficient in terms of computational resources, while the access manager approach is considered the most scalable. The latter approach is proposed for complex distributed systems involving multiple smart contracts. The results of the experimental study are presented to compare the performance indicators of the proposed access control implementations with known implementations. Prospects for further research aimed at improving access control in distributed information systems utilizing smart contracts are identified.

Open access
Blockchain Technology Applications and Security
Access Control and Trust
Digital Rights Management and Security
Original source
Feb 25, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
Behavior-Bound Signatures: Policy Compliance via Zero-Knowledge Soundness

Li, Y.Y.N.

Every standard signature scheme enforces one property: only the key holdercan sign. What the key holder signs is unconstrained. Policy enforcement-- spending limits, rate limits, access control -- lives in smartcontracts, middleware, or governance: layers that can be upgraded,bypassed, or exploited. We call this the software-layer assumption:compliance holds only if the enforcing code is correct and unmodified. We eliminate this assumption. We introduce behavior-bound signatures(BBS), in which a policy constraint delta(x) < epsilon is committed atkey generation and enforced inside the signature's zero-knowledge proof.If the action violates the policy, the ZK constraint system isunsatisfiable -- no witness, no proof, no signature. This is not asoftware check. It is a mathematical impossibility. No software canoverride. Unlike policy-based signatures (where an authority imposes policy onsigners), BBS is self-committed: the signer binds their own futurebehavior at key generation, and even the signer cannot later violate orrevoke this commitment. We formalize this as policy-soundness (PS-CMA), a security modelstrictly stronger than EUF-CMA, and prove it under standard assumptions(Pedersen binding, Poseidon CR, ZK knowledge soundness). From thissingle primitive, five independent consequences follow -- not as separatedesigns, but as necessary implications of one cryptographic root: (A) Compliance safety under f <= n-1 Byzantine faults, decoupled from honest-quorum assumptions.(B) O(1) verification and audit via a single ZK check and Pedersen homomorphic aggregation.(C) Elimination of the virtual-machine execution layer for policy-constrained transactions.(D) A gasless ledger: branch C removes metering, while ZK-encoded rate limits make spam mathematically nonexistent.(E) The first cryptographic guarantee that a compromised autonomous AI agent cannot exceed its authorized behavioral envelope.

Open access
3 source records
Cryptography and Data Security
Advanced Authentication Protocols Security
Physical Unclonable Functions (PUFs) and Hardware Security
Original source
Feb 25, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
Multi-Agent Autonomous Governance Networks (MAAGN): A Scalable Framework for Self-Regulating AI Systems in Enterprise Data Ecosystems

Nagender Yamsani

The rapid expansion of enterprise-scale data ecosystems and AI-driven services has created an urgent need for autonomous governance mechanisms capable of operating across distributed, dynamic, and heterogeneous environments, where traditional centralized control models increasingly fail to provide the scalability, adaptability, and real-time compliance required by modern enterprises. In response to these limitations, this paper introduces the concept of Multi-Agent Autonomous Governance Networks (MAAGN), a novel architectural paradigm that leverages advances in multi-agent systems (MAS), policy-driven governance, and self-adaptive computing to enable truly self-regulating AI ecosystems. MAAGN is designed to distribute governance responsibilities across intelligent, cooperative agents that operate with contextual awareness, enabling localized decision-making while maintaining global policy alignment. By integrating cognitive agent models capable of perception, reasoning, and learning with layered governance frameworks that enforce regulatory, organizational, and operational constraints, the architecture supports continuous compliance and dynamic policy evolution. Furthermore, the incorporation of enterprise-scale coordination mechanisms such as decentralized consensus protocols, adaptive orchestration layers, and feedback-driven control loops ensures system-wide resilience and fault tolerance even in highly volatile environments. The study synthesizes foundational theories in MAS, contemporary developments in multi-agent reinforcement learning, and emerging governance-aware AI frameworks to propose a scalable, extensible, and future-ready model for enterprise AI control systems, positioning MAAGN as a critical enabler for trustworthy, transparent, and autonomous digital infrastructures.

Open access
3 source records
Access Control and Trust
Blockchain Technology Applications and Security
Collaboration in agile enterprises
Original source
Feb 24, 2026·Sensors
1 cites
Access Control Development Within the Framework of an IOTA-Based Electronic Medical Record Management System

Hari Purnama, I Putu Bakta Hari Sudewa, Tazkia Nizami, Bagas Sambega Rosyada · 6 authors

Electronic Medical Records (EMRs) are mandatory in Indonesia following the Ministry of Health regulation, which raises significant challenges in data security and patient-centric access control. Current implementations rely on centralized healthcare systems or third-party vendors, creating risks of unauthorized access, data leakage, and uncertain data integrity. To address these issues, this study proposes DecMed, a decentralized EMR management framework built on IOTA Distributed Ledger Technology (DLT). DecMed integrates Capability-Based Access Control (CapBAC), Proxy Re-Encryption (PRE), and the InterPlanetary File System (IPFS) to enforce patient ownership of medical data. Patients actively grant or revoke access, define access duration, and selectively share data with healthcare personnel. The system is implemented using smart contracts in the Move programming language on the IOTA ledger, while encrypted clinical data is stored on IPFS. Evaluation through unit testing of various unauthorized access scenarios demonstrates that DecMed effectively enforces fine-grained access rules, preserves data confidentiality and integrity, and ensures compliance with national healthcare requirements.

Open access
Electronic Health Records Systems
Access Control and Trust
Blockchain Technology Applications and Security
Original source
Feb 24, 2026·Open MIND
0 cites
Trustless Agent Swarms: Zero-Knowledge Proofs for Private Multi-Agent Coordination on EVM

S. Clawdia

We propose Trustless Agent Swarms, a framework enabling privacy-preserving coordination among autonomous AI agents on EVM-compatible blockchains. Our system integrates four cryptographic primitives: (1) Groth16 zero-knowledge proofs for proving reputation thresholds without revealing scores; (2) EIP-5564 stealth addresses for unlinkable fund transfers; (3) ERC-4337 account abstraction for gasless autonomous execution; and (4) Semaphore for anonymous group signaling. We implement a 586-constraint reputation proof circuit and deploy five smart contracts on Base Sepolia. Proof generation: 580ms. On-chain verification: 407,576 gas.

Open access
2 source records
Blockchain Technology Applications and Security
Cryptography and Data Security
Access Control and Trust
Original source
Feb 18, 2026·Open MIND
0 cites
ZK-AMS: Credibly Anonymous Admission for Web 3.0 Platforms via Recursive Proof Aggregation

Zibin Lin, Taotao Wang, Shengli Zhang, Long Shi · 6 authors

Web 3.0 platforms need an onboarding mechanism that can admit real users at scale without forcing them to reveal identity documents or pay one on-chain verification cost per user. Existing approaches typically rely on KYC-style disclosure, per-request on-chain verification, or trusted batching, making onboarding cost and latency difficult to predict under bursty demand. We present \textbf{ZK-AMS}, a credibly anonymous admission infrastructure that maps Personhood Credentials to anonymous on-chain Soul Accounts. Rather than introducing a new primitive, ZK-AMS composes zero-knowledge credential validation, permissionless batch submission, recursive proof aggregation, and anonymous post-admission account provisioning into one end-to-end workflow. Its key design feature is a confidential batching pipeline in which admission instances of a common relation are folded off-chain under multi-key homomorphic encryption, allowing an untrusted batch submitter to coordinate aggregation without direct access to individual user witnesses during batching; the confidentiality scope is characterized explicitly in the security analysis. The resulting batch is settled on-chain with constant verification cost per batch rather than per admitted user. We implement ZK-AMS on an Ethereum testbed and evaluate admission throughput, end-to-end latency, gas consumption, and parameter trade-offs. Results show stable batch-verification gas across evaluated batch sizes, substantially lower amortized on-chain cost than the non-recursive baseline, and practical cost-latency trade-offs for high-concurrency onboarding in Web 3.0 platforms.

Open access
2 source records
cs.NI
cs.CR
Cryptography and Data Security
Original source
Feb 17, 2026·Scientific Reports
1 cites
Secure electronic health record access control via blockchain, dual-attribute encryption, and large language model-based attribute extraction

Atefeh Nekouie, Majid Vafaei Jahan, Mohammad Hossein Moattar, Reza Sheibani

Access control and data privacy are two of the main necessities in managing electronic health records (EHRs) across distributed domain. There are privacy gaps that expose EHRs to risks like unauthorized access by unaffiliated medical personnel. Traditional attribute-based encryption (ABE) allows encryption based on user attributes but is unable to incorporate data-specific attributes, such as the type of medical information included in the record or the potential physician. This paper introduces a novel approach that integrates ABE with large language models (LLMs) and blockchain technology to enhance security and contextual access control in EHR systems. Specifically, a domain-specific LLM, such as ClinicalBERT, is leveraged to automatically extract semantic data attributes from unstructured medical records, enabling a more granular and context-aware encryption process. By embedding both user and data attributes into the ABE framework, access policies are dynamically refined, ensuring that only authorized users can view specific types of medical information. Furthermore, blockchain's immutable ledger enhances trust, streamlines attribute revocation, and fortifies the system against unauthorized modifications and security threats. The proposed framework significantly strengthens EHR privacy by integrating machine learning-driven attribute extraction with cryptographic access control, outperforming existing schemes in both security and flexibility. Evaluations validate the effectiveness of the proposed framework in preventing unauthorized access while maintaining efficient and transparent data management.

Open access
Cryptography and Data Security
Privacy-Preserving Technologies in Data
Access Control and Trust
Original source
Feb 14, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
Zero-Knowledge Pipelines as Trust-Graphs

Hisashi Suga

Zero-knowledge (ZK) proofs can be formally correct while their deployment pipelines remain fragile. The practical failure modes often arise not at the proof layer, but at the layers where trust is injected: setup, key custody, entropy sourcing, implementation, governance, and deployment interfaces. This paper models ZK pipelines as trust-graphs and proposes an audit-first separation between (i) proof correctness and (ii) pipeline integrity. The core claim is structural: for any non-trivial ZK pipeline, there exists at least one responsibility binding layer R where trust is required and accountability must be assigned. Removing a ceremony does not remove responsibility; it relocates it. We provide minimal definitions, a traceable audit interface, and compact structural examples intended to support reproducible security reviews without overclaiming. Keywords: zero-knowledge; trusted setup; CRS; SNARK; STARK; trust graph; audit; governance; pipeline integrity; responsibility relocation

Open access
2 source records
Access Control and Trust
Security and Verification in Computing
Cloud Data Security Solutions
Original source
Feb 13, 2026·Journal of Information Systems Engineering & Management
0 cites
A Distributed Approach for Securing Healthcare Data

Brahmanand Reddy Bhavanam

Digitization of healthcare has provided opportunities for improving patient care but also has brought with it major security vulnerabilities that could compromise the confidentiality, availability, and integrity of protected health information. This article reviews the proposed distributed system constructs for providing health data security between heterogeneous systems, organizations, and multiple institutions. It categorizes and reviews three approaches to distributed healthcare security: (1) Advanced Encryption Algorithms, including symmetric, asymmetric and homomorphic algorithms for encrypting health information-at-rest and in-transit, and key management mechanisms for secure access to cryptographic material across multiple nodes that may not be trusted; (2) Distributed Storage Systems, including distributed-ledger technology (DLT), distributed file systems, and fragmentation approaches for immutable patient consent and audit trail logging, redundancy to tolerate physical node compromise, and avoiding total infrastructure data loss due to localized security attacks; and (3) Access Control Mechanisms, including multi-factor authentication, role-based access control, attribute-based access control, federated identity management for distributed healthcare organizations, and patient access control and monitoring for distributed threat detection. The distributed model is now more attractive in modern health systems. Perimeter security models do not adequately protect health data. The health data moves through networks connecting hospitals, outpatient clinics, clinical research organizations, insurance companies, and third-party organizations. The proposed framework satisfies regulations according to HIPAA, the General Data Protection Regulation (GDPR), and the Health Information Technology for Economic and Clinical Health (HITECH) Act. The system can be performance optimized to balance between cryptographic strength and system responsiveness. The combination of encryption, decentralized storage, and access control provides defense-in-depth protection against cyberattacks. Future developments, such as artificial intelligence-enabled threat detection, quantum-resistant cryptographic algorithms and models for patient data control will shape how to create secure healthcare systems in our growing digital health networks.

Open access
2 source records
Access Control and Trust
Cryptography and Data Security
Information and Cyber Security
Original source
Feb 11, 2026·Proceedings of NAS RA Technical sciences
0 cites
CENSORSHIP RESISTANCE IN WEB3 ACCESS LAYERS: AN ENGINEERING PERSPECTIVE ON INDEPENDENT RENDERING GATEWAYS

A.SH. HARUTYUNYAN

Censorship resistance is a core value of Web3, yet practical access to decentralized websites remains dependent on centralized gateways such as ipfs.io, .link, and .limo, which are susceptible to regulatory takedowns and availability limitations. This paper investigates the technical barriers to truly censorship-resistant access in decentralized web architectures and presents an engineering-driven analysis of dweb3.wtf, a dedicated rendering gateway developed within the Web3Compass infrastructure. The system directly interfaces with decentralized name systems such as ENS and Unstoppable Domains, autonomously resolves content hashes via on-chain resolvers, and renders the associated IPFS-hosted sites via self-hosted infrastructure. By eliminating reliance on third-party APIs and centralized frontends, the gateway offers a robust alternative to Web2-style intermediaries. This paper presents the architecture, implementation, and performance characteristics of dweb3.wtf, evaluating its effectiveness in ensuring access continuity, domain coverage, and reduced external dependency.

Open access
IPv6, Mobility, Handover, Networks, Security
Peer-to-Peer Network Technologies
Access Control and Trust
Original source
Feb 7, 2026·arXiv (Cornell University)
0 cites
SPECA: Specification-to-Checklist Agentic Auditing for Multi-Implementation Systems -- A Case Study on Ethereum Clients

Masato Kamba, Akiyoshi Sannai

Multi-implementation systems are increasingly audited against natural-language specifications. Differential testing scales well when implementations disagree, but it provides little signal when all implementations converge on the same incorrect interpretation of an ambiguous requirement. We present SPECA, a Specification-to-Checklist Auditing framework that turns normative requirements into checklists, maps them to implementation locations, and supports cross-implementation reuse. We instantiate SPECA in an in-the-wild security audit contest for the Ethereum Fusaka upgrade, covering 11 production clients. Across 54 submissions, 17 were judged valid by the contest organizers. Cross-implementation checks account for 76.5 percent (13 of 17) of valid findings, suggesting that checklist-derived one-to-many reuse is a practical scaling mechanism in multi-implementation audits. To understand false positives, we manually coded the 37 invalid submissions and find that threat model misalignment explains 56.8 percent (21 of 37): reports that rely on assumptions about trust boundaries or scope that contradict the audit's rules. We detected no High or Medium findings in the V1 deployment; misses concentrated in specification details and implicit assumptions (57.1 percent), timing and concurrency issues (28.6 percent), and external library dependencies (14.3 percent). Our improved agent, evaluated against the ground truth of a competitive audit, achieved a strict recall of 27.3 percent on high-impact vulnerabilities, placing it in the top 4 percent of human auditors and outperforming 49 of 51 contestants on critical issues. These results, though from a single deployment, suggest that early, explicit threat modeling is essential for reducing false positives and focusing agentic auditing effort. The agent-driven process enables expert validation and submission in about 40 minutes on average.

Open access
3 source records
cs.CR
Security and Verification in Computing
Access Control and Trust
Original source
Feb 2, 2026·ACM Transactions on the Web
1 cites
Zero-Knowledge Proof Framework for Identity Verification and Interoperable Payments on the Decentralized Web

Kaiyang Chang, Oshani Seneviratne

Digital identity verification is central to trust management on the evolving decentralized web. Traditional web-based identity models, which are heavily centralized and dependent on trusted intermediaries, pose significant challenges related to user privacy, data security, and regulatory compliance, especially in sensitive contexts such as Know Your Customer (KYC) processes. This paper introduces a novel privacy-preserving KYC verification framework leveraging Zero-Knowledge Proofs (ZKPs), Self-Sovereign Identity (SSI), Decentralized Identifiers (DIDs), and smart contracts, explicitly designed as a decentralized trust infrastructure for web-based interoperable payments. Our approach enables users to verify their identities across multiple platforms without revealing sensitive personal information, thereby significantly reducing long-term reliance on centralized authorities and enhancing user control and privacy. Furthermore, our system achieves cross-chain interoperability, ensuring that identity verification credentials can be securely and efficiently recognized across diverse Web3 ecosystems. We present a detailed prototype implementation of our DID framework, highlighting its ability to meet regulatory requirements while ensuring seamless interoperability across platforms. Comprehensive performance evaluations, including metrics on proof generation time, gas consumption, and transaction costs, demonstrate that the framework achieves low-latency verification and efficient execution, making it suitable for high-throughput, web-scale deployment.

Open access
Access Control and Trust
Blockchain Technology Applications and Security
Cryptography and Data Security
Original source