NFT (Non-Fungible Token) has emerged as a trending topic in the digital world. This article focuses on the working principle of NFTs and their practical applications in real-world scenarios. Ethereum blockchain serves as the foundational technology that powers NFTs. This document provides a comprehensive technical overview of Ethereum blockchain technology applied in the textile industry for maintaining product ownership verification and authenticity
Open access
Blockchain Technology Applications and Security
Physical Unclonable Functions (PUFs) and Hardware Security
The increasing use of deep learning (DL) models has given rise to significant privacy concerns regarding training and inference data. To address these concerns, the community has increasingly adopted crypto-based privacy-enhancing technologies (CPET) like homomorphic encryption (HE), secure multi-party computation (MPC), and zero-knowledge proofs (ZKP). The integration of CPET with DL, often referred to as CPET-DL, is commonly facilitated by specialized frameworks like CrypTen, TenSEAL, and EZKL. These frameworks offer configurable parameters to balance model accuracy and computational efficiency during privacy-preserving operations. However, these configurations, while seemingly harmless, can introduce subtle vulnerabilities. The stealthy attacks induced by misconfigurations are hard to detect because 1) the plaintext models remain vulnerability-free, and 2) existing auditing tools are hardly applicable to CPET-hardened models. This creates a paradox: tools intended to protect privacy can be undermined through configuration manipulation.
Open access
Cryptography and Data Security
Physical Unclonable Functions (PUFs) and Hardware Security
<p>Document forgery remains a pervasive problem across education, government, and trade sectors. This paper presents a blockchain-based digital document verification system built on the Internet Computer Protocol (ICP). The approach computes SHA‑256 hashes of documents and anchors them to ICP canister smart contracts, ensuring integrity and non-repudiation without storing document contents. The system manages a registry of approved verifiers so that only trusted institutions can enroll documents. In evaluation with 15 documents (85–3025 KB) and five repeated trials per document, the prototype achieved an average verification time of 1.54 s and an accuracy of 99%. Compared with Ethereum-based baselines in prior work, the ICP-based design avoids gas fees and reduces verification latency. The proposed architecture supports future integration of zero-knowledge proofs (ZKP) to validate authenticity while preserving privacy.</p>
Open access
Blockchain Technology Applications and Security
Big Data and Digital Economy
Physical Unclonable Functions (PUFs) and Hardware Security
The convergence of quantum physics and machine learning presents unprecedented opportunities for developing ultra-secure authentication systems. This comprehensive paper investigates the integration of quantum random number generators (QRNGs) with advanced machine learning architectures, including quantum neural networks (QNNs), long short-term memory (LSTM) networks, and hybrid quantumclassical models, to establish authentication mechanisms with information-theoretic security guarantees. We provide rigorous theoretical foundations spanning quantum entropy theory, min-entropy estimation, and randomness certification, complemented by detailed analyses of contemporary QRNG hardware implementations including photonic integrated circuits achieving generation rates exceeding 20 Gbps. The paper explores deep learning architectures for biometric authentication, demonstrating how QNN-enhanced systems achieve superior performance through quantum superposition and entanglement. Furthermore, we examine the application of quantum entropy sources in zero-knowledge proof protocols, particularly zk-SNARKs and zk-STARKs, addressing post-quantum security concerns. Through comprehensive mathematical formulations, algorithmic implementations, and security analyses, we establish that hybrid quantum-classical authentication systems combining QRNG-derived cryptographic keys with ML-based behavioral authentication provide provably secure, practical solutions for next-generation cybersecurity applications. Experimental results from current quantum hardware platforms validate theoretical predictions and demonstrate real-world applicability.
Open access
Chaos-based Image/Signal Encryption
Physical Unclonable Functions (PUFs) and Hardware Security
Abstract — The Fractal Eavesdrop Detection (FED) protocol defines a cryptographic mutual-authentication... The Fractal Eavesdrop Detection (FED) protocol defines a cryptographic mutual-authentication and integrity validation mechanism between two fractal nodes sharing a recursive lineage. Unlike conventional systems that rely on fixed keys or static hashes, FED uses algorithmic mutability, session-based seed derivation, multi-point challenge validation, and time-bound CRC binding to detect both impersonation and passive eavesdropping. The protocol is designed for lightweight, low-power devices such as ESP32-class microcontrollers and operates without blockchain consensus or zero-knowledge proofs, while still enabling secure proof-of-origin and tamper-awareness. FED serves as the security and validation layer within the EQUORA Institute’s Fractal Economy architecture and complements the BlockFractal cryptographic tokenization layer and the EquoraVault hardware-based proof-of-impact system. This document is released as part of the EQUORA Institute White Paper Series and is a preprint version (v0.8), subject to revision. All versions remain archived for DOI-based citation integrity.
Open access
2 source records
Chaos-based Image/Signal Encryption
Physical Unclonable Functions (PUFs) and Hardware Security
The integration of Industrial Automation Systems (IAS) with the Internet of Things (IoT) under Industry 4.0 has significantly enhanced operational efficiency but also exposed critical communication infrastructures to cyber threats. Conventional security frameworks often fail to ensure end-to-end data integrity, authentication, and confidentiality in real-time industrial networks. This paper proposes a blockchain-enabled mathematical cryptography model designed to secure data transmission between industrial nodes. The framework utilizes Elliptic Curve Cryptography (ECC) for lightweight key generation, SHA-3 hashing for immutable transaction records, and smart contract-based consensus for autonomous trust management within a distributed ledger. A simulated industrial environment demonstrates that the proposed model achieves 42% faster encryption-decryption cycles and a 38% reduction in data latency compared to traditional asymmetric cryptosystems. The mathematical foundation ensures provable security under discrete logarithm assumptions, while blockchain consensus guarantees tamper resistance and auditability. This study contributes a scalable, mathematically robust architecture for secure data transmission in automation networks, offering potential integration within Supervisory Control and Data Acquisition (SCADA) and Programmable Logic Controller (PLC) environments.
Open access
Smart Grid Security and Resilience
Physical Unclonable Functions (PUFs) and Hardware Security
The evolution of 5G and emerging 6G networks has introduced unprecedented opportunities for connectivity, but also expanded the attack surface for Distributed Denial of Service (DDoS) amplification attacks. Service-Based Architecture (SBA), network slicing, and massive IoT (mMTC) environments create new vectors for reflection and amplification, making conventional defenses inadequate. This paper proposes a novel layered defense framework that integrates edge filtering, AI-driven anomaly detection, slice isolation, cloud scrubbing, and quantum-safe cryptography to mitigate DDoS amplification attacks in 5G/6G environments. The framework is theoretically modeled through equations for amplification, mitigation efficiency, resilience, and defense cost, and evaluated experimentally using simulated signaling floods, IoT-driven amplification, slice-targeted floods, and hybrid attacks. Performance was measured using detection rate, false alarm rate, service availability, resilience score, and resource overhead. Two algorithms—pseudonymous authentication with zero-knowledge proof (ZKP) and layered mitigation orchestration—were implemented to operationalize the defense strategy. The results demonstrate that the proposed framework achieves a detection accuracy of 95–97%, reduces false positives to 2%, and maintains a service availability of over 85% under prolonged amplification attacks. It scales efficiently in scenarios with up to 10,000 simulated IoT devices, retaining 70–80% throughput, and maintains URLLC latency below 10 ms, outperforming baseline defenses (firewalls, scrubbing, and AI-only) and state-of-the-art defenses from the literature. These findings validate the framework as a scalable, efficient, and future-ready solution for mitigating amplification attacks in 5G/6G networks, with strong alignment with 3GPP, GSMA, and NIST post-quantum standards.
Open access
Advanced Malware Detection Techniques
Network Security and Intrusion Detection
Physical Unclonable Functions (PUFs) and Hardware Security
A. G. Ramakrishnan, Shubham Agarwal, Sharmila Kumari Selvanayagam, Kunwar P. Singh
As image generation models grow increasingly powerful and accessible, concerns around authenticity, ownership, and misuse of synthetic media have become critical. The ability to generate lifelike images indistinguishable from real ones introduces risks such as misinformation, deepfakes, and intellectual property violations. Traditional watermarking methods either degrade image quality, are easily removed, or require access to confidential model internals – making them unsuitable for secure and scalable deployment. We are the first to introduce ZK-WAGON, a novel system for watermarking image generation models using the Zero-Knowledge Succinct Non-Interactive Argument of Knowledge (ZK-SNARKs). Our approach enables verifiable proof of origin without exposing model weights, generation prompts, or any sensitive internal information. We propose Selective Layer ZK-Circuit Creation (SL-ZKCC), a method to selectively convert key layers of an image generation model into a circuit, reducing proof generation time significantly. Generated ZK-SNARK proofs are imperceptibly embedded into a generated image via Least Significant Bit (LSB) steganography. We demonstrate this system on both GAN and Diffusion models, providing a secure, model-agnostic pipeline for trustworthy AI image generation.
Open access
2 source records
Physical Unclonable Functions (PUFs) and Hardware Security
Adversarial Robustness in Machine Learning
Generative Adversarial Networks and Image Synthesis
Nan Wang, Nan Wu, Xiangyu Hui, Jiafan Wang · 5 authors
As the demand for exercising the "right to be forgotten" grows, the need for verifiable machine unlearning has become increasingly evident to ensure both transparency and accountability. We present {\em zkUnlearner}, the first zero-knowledge framework for verifiable machine unlearning, specifically designed to support {\em multi-granularity} and {\em forgery-resistance}. First, we propose a general computational model that employs a {\em bit-masking} technique to enable the {\em selectivity} of existing zero-knowledge proofs of training for gradient descent algorithms. This innovation enables not only traditional {\em sample-level} unlearning but also more advanced {\em feature-level} and {\em class-level} unlearning. Our model can be translated to arithmetic circuits, ensuring compatibility with a broad range of zero-knowledge proof systems. Furthermore, our approach overcomes key limitations of existing methods in both efficiency and privacy. Second, forging attacks present a serious threat to the reliability of unlearning. Specifically, in Stochastic Gradient Descent optimization, gradients from unlearned data, or from minibatches containing it, can be forged using alternative data samples or minibatches that exclude it. We propose the first effective strategies to resist state-of-the-art forging attacks. Finally, we benchmark a zkSNARK-based instantiation of our framework and perform comprehensive performance evaluations to validate its practicality.
Yagmur Yigit, Mehmet Ali Erturk, Kerem Gursu, Berk Canberk
Digital twin (DT) technology is rapidly becoming essential for smart city ecosystems, enabling real-time synchronisation and autonomous decision-making across physical and digital domains. However, as DTs take active roles in control loops, securely binding them to their physical counterparts in dynamic and adversarial environments remains a significant challenge. Existing authentication solutions either rely on static trust models, require centralised authorities, or fail to provide live and verifiable physical-digital binding, making them unsuitable for latency-sensitive and distributed deployments. To address this gap, we introduce PRZK-Bind, a lightweight and decentralised authentication protocol that combines Schnorr-based zero-knowledge proofs with elliptic curve cryptography to establish secure, real-time correspondence between physical entities and DTs without relying on pre-shared secrets. Simulation results show that PRZK-Bind significantly improves performance, offering up to 4.5 times lower latency and 4 times reduced energy consumption compared to cryptography-heavy baselines, while maintaining false acceptance rates more than 10 times lower. These findings highlight its suitability for future smart city deployments requiring efficient, resilient, and trustworthy DT authentication.
Dan Ivanov, Tristan Freiberg, Shahabi, Shirin, Jonathan Gold · 5 authors
DSperse is a modular framework for distributed machine learning inference with strategic cryptographic verification. Operating within the emerging paradigm of distributed zero-knowledge machine learning, DSperse avoids the high cost and rigidity of full-model circuitization by enabling targeted verification of strategically chosen subcomputations. These verifiable segments, or "slices", may cover part or all of the inference pipeline, with global consistency enforced through audit, replication, or economic incentives. This architecture supports a pragmatic form of trust minimization, localizing zero-knowledge proofs to the components where they provide the greatest value. We evaluate DSperse using multiple proving systems and report empirical results on memory usage, runtime, and circuit behavior under sliced and unsliced configurations. By allowing proof boundaries to align flexibly with the model's logical structure, DSperse supports scalable, targeted verification strategies suited to diverse deployment needs.
Open access
2 source records
Adversarial Robustness in Machine Learning
Physical Unclonable Functions (PUFs) and Hardware Security
Custom tokens are fundamental in decentralized applications (dApps) operating on Ethereum and other Blockchain platforms. Ethereum, in particular, relies on the ERC-20 standard as a widely accepted token interface, facilitating seamless integration with numerous pre-existing dApps, user interface platforms, and popular web applications like exchange services. A notable security challenge within the ERC-20 framework is the “lost token problem”. This problem arises because users occasionally send tokens to the wrong addresses, and it has caused more than $27 million in damage. In this paper, we evaluate three existing solutions to this issue. Through the utilization of formal modeling, property specification, and the TLC model checker. Most importantly, we propose a novel double-layer solution to remedy the ERC-20 vulnerability. Our formal verification and experimental results indicate our approach encompasses the protection of the already deployed smart contracts, which is a critical aspect that has never been addressed in the existing mitigation techniques.
Open access
Security and Verification in Computing
Radiation Effects in Electronics
Physical Unclonable Functions (PUFs) and Hardware Security
Non-fungible tokens (NFT) have recently become a popular method of tokenizing \& commercializing personal artifacts. Designing NFTs requires selecting different blockchain-based consensus models, encryption techniques, and distribution mechanisms. Existing NFT design techniques use computationally complex encryption models like Elliptic Curve Cryptography (ECC), Advanced Encryption Standard (AES), etc., which restricts their general-purpose usability, limiting their scalability for real-time use cases. To overcome this drawback, while maintaining high security, this text proposes a design of a lightweight, restrictive non-fungible token based on Practically Unclonable Functions (PuFs) via image signature patterns. The proposed model initially collects context-specific information sets about the entity that needs tokenization and uses this information to generate restrictive hash sets. These hash sets are passed through a customized PuF model, which generates image-like hash signatures. The generated hash signatures are iteratively embedded into unique images, which are fused via a dual visual encryption-decryption process. The encryption process generates 2 image sets, for distribution among the buyer \& seller, while the decryption process aggregates these image sets to form a single file token. These tokens are passed through another encryption-decryption-based validation process while reselling operations. Due to use of PuFs and restrictive hash sets, the proposed model is capable of deployment for low-power IoT applications and can be scaled for general-purpose scenarios. The proposed model was tested on different NFT use cases, and showcased 10.4% lower processing delay, 8.3% lower energy consumption during selling, and 4.9% lower energy consumption during reselling processes. The tokens generated via this model were also tested under different attack types, and similar efficiency levels were observed under real-time scenarios.
Open access
Physical Unclonable Functions (PUFs) and Hardware Security
Artificial Intelligence (AI) is profoundly transforming cryptography by significantly enhancing cryptanalysis techniques and informing innovative cryptographic design approaches. This survey reviews recent advancements in applying deep learning methods to side-channel and differential fault analyses, demonstrating substantial improvements over traditional methods in attack efficiency, accuracy, and resilience. Additionally, it highlights breakthroughs such as neural differential cryptanalysis, which expand classical cryptanalytic boundaries. In cryptographic design, Generative Adversarial Networks (GANs) have successfully automated the creation of high-quality cryptographic primitives, particularly S-boxes. Furthermore, AI shows promise in post-quantum cryptography (PQC) by uncovering potential vulnerabilities and optimizing cryptographic parameters. Despite these advancements, challenges persist regarding data dependency, model generalization, and interpretability. Future research directions emphasize enhancing AI model explainability, creating standardized benchmarks, and integrating AI with emerging technologies such as quantum computing and zero-knowledge proofs.
Open access
Cryptographic Implementations and Security
Chaos-based Image/Signal Encryption
Physical Unclonable Functions (PUFs) and Hardware Security
Crypto wallets store and protect the private keys needed to sign transactions for crypto currencies; they are secured by multi-factor authentication schemes. However, the loss of a wallet, or a dysfunctional factor of authentication, can be catastrophic, as the keys are then lost as well as the crypto currencies. Such difficult tradeoffs between the protection of the private keys and factors of authentication that are easy to use are also present in public key infrastructures, banking cards, smartphones and smartcards. In this paper, we present protocols based on novel challenge–response pair mechanisms that protect private keys, while using factors of authentication that can be lost or misplaced without negative consequences. Examples of factors that are analyzed include passwords, tokens, wearable devices, biometry, and blockchain-based non-fungible tokens. In normal operations, the terminal device uses all factors of authentication to retrieve an ephemeral key, decrypt the private key, and finally sign a transaction. With our solution, users can download the software stack into multiple terminal devices, turning all of them into backups. We present a zero-knowledge multi-factor authentication scheme allowing the secure recovery of private keys when one of the factors is lost, such as the token. The challenge–response pair mechanisms also enable a novel key pair generation protocol in which private keys can be kept secret by the user, while a Keystore can securely authenticate the user and transmit the public key to a distributed network. The standardized LWE post-quantum cryptographic CRYSTALS Dilithium protocol was selected in the experimental section.
Open access
Physical Unclonable Functions (PUFs) and Hardware Security
Stefan Dziembowski, Shahriar Ebrahimi, Parisa Hassanizadeh
Ensuring the authenticity and credibility of daily media on internet is an ongoing problem. Meanwhile, genuinely captured images often require refinements before publication. Zero-knowledge proofs (ZKPs) offer a solution by verifying edited image without disclosing the original source. However, ZKPs typically come with high costs, particularly in terms of prover complexity and proof size. This paper presents VIMz, a framework for efficiently proving the authenticity of high-resolution images using folding-based zkSNARKs; a type of proving system that minimizes computational overhead by recursively folding multiple evaluations of the same constraints into a compact proof. As a complete proof system, VIMz proves the integrity of both the original and edited images, as well as the correctness of the transformation without revealing intermediate images within a chain of edits--only the final result is disclosed. Moreover, VIMz maintains the anonymity of the original signer and all subsequent editors while proving the authenticity of the final image. We also compare VIMz with the system model in Coalition for Content Provenance and Authenticity (C2PA) from different perspectives and show that VIMz offers higher level of security guarantee by eliminating the need to trust the editing environment. Experimental results show that VIMz performs efficiently in both prover and verifier sides. It can prove the transformations on 8K (33MP,i.e., 100MB) images with up to 13%~25% faster than the competition, while reaching to a peak memory of only 10 GB. Moreover, VIMz has a verification time of under 1 second and achieves succinct proofs of less than 11 KB for all resolutions, which is more than 90% improvement compared to the competition. VIMz's low memory complexity allows for proving multiple transformations in parallel to achieve a 3.5x additional speedup on average.
Open access
Advanced Steganography and Watermarking Techniques
Digital Media Forensic Detection
Physical Unclonable Functions (PUFs) and Hardware Security
Deploying smart contracts and invoking their functions on block-chains incur gas costs, which depend on the operations executed by those functions. This makes optimizing the gas cost of smart contract functions a rewarding goal. However, existing approaches to gas cost optimization of smart contracts mainly involve rule-based optimization or automatic optimization for specific types of patterns. In this paper, we discuss a novel approach to automatically retrieving optimized versions of Solidity functions from a repository of smart contracts. The system identifies and suggests gas-efficient alternatives that maintain functional equivalence by comparing the opcode sequences of individual functions. We evaluate this approach on a dataset of 16,529 functions from real-world contracts, demonstrating substantial gas savings, as high as 34% on average when considering the most similar functions.
Growing worries about data security and privacy are driving the development of privacy-enhancing technologies (PETs) like secure multiparty computation (MPC) and zero-knowledge (ZK) proofs. These technologies offer strong theoretical guarantees for protecting sensitive data while still allowing its use. Critical sectors like finance and healthcare are increasingly adopting PETs, facilitated by complex PET systems designed for secure and efficient implementation. However, despite the theoretical strengths of PETs, the intricate nature of these systems can create practical vulnerabilities. Severe incidents have already caused significant financial losses and eroded trust. This thesis tackles these reliability concerns by systematically testing modern PET systems. The first work in this thesis uncovers logic bugs in secure multiparty computation (MPC) compilers. These compilers automatically transform high-level MPC programs, written in domain-specific languages (DSLs), into low-level MPC executables. We introduce MT-MPC, a metamorphic testing (MT) framework, to test MPC compilers using three tailored metamorphic relations (MRs). Despite the high engineering quality of MPC compilers, MT-MPC finds 13 bugs in leading compilers, which compromises the dependability of MPC systems. The second work focuses on the correctness and security of zero-knowledge (ZK) compilers, which compile ZK DSL programs into ZK circuits. We propose MTZK, a MT framework that uncovers logic bugs in ZK compilers. These bugs can allow attackers to generate false ZK proofs that ZK verifiers unexpectedly accept, leading to security breaches and financial losses. MTZK uses two carefully designed MRs to deliver effective test cases for ZK compilers. Evaluation of four industrial ZK compilers reveals 21 bugs. We also demonstrate the severe security implications of these bugs through potential exploits. The third work unveils a new class of vulnerabilities in PET-enhanced machine learning (ML) models. We present ConPETro, the first attack on PET-enhanced ML models with maliciously crafted configurations. These configurations cause PET-enhanced models to behave similarly to plaintext models under normal inputs, but exhibit significantly reduced robustness under trigger-embedded inputs. ConPETro achieves an average maximum attack success rate of 65.6% while maintaining merely 4% of accuracy drop on normal inputs. We also show that such attacks are highly stealthy and can hardly be detected or defended by traditional mechanisms.
Open access
Information and Cyber Security
Transportation Systems and Safety
Physical Unclonable Functions (PUFs) and Hardware Security
The rapid evolution of quantum computing poses significant threats to traditional cryptographic schemes, particularly in Decentralized Finance (DeFi) systems that rely on legacy mechanisms like RSA and ECDSA for digital ident... | Find, read and cite all the research you need on Tech Science Press
Open access
Physical Unclonable Functions (PUFs) and Hardware Security
Advancements in Semiconductor Devices and Circuit Design
Physical unclonable function (PUF) is a critical hardware primitive that provides unique identities for authenticating a large number of devices in the Industrial Internet of Things (IIoT). Most existing PUF-based schemes face challenge-response pair (CRP) leakage during machine-learning attack. Some studies that use hardware or time-consuming cryptographic operations to protect the PUF responses are expensive and unsuitable for existing IIoT devices. To address these issues, a lightweight and anonymous PUF-based authentication scheme is proposed for resource-constrained IIoTs. Using elliptic curve cryptography and zero-knowledge proof, a lightweight blinding mechanism is designed in the proposed scheme that prevents explicit CRP leakage and ensures anonymity. In addition, the authenticated keys are random with forward and backward secrecy. Moreover, the security of the proposed scheme is demonstrated using a random oracle model. Experimental results demonstrate that the proposed scheme is notably more efficient and practical for resource-constrained devices compared to other related schemes.
Open access
Physical Unclonable Functions (PUFs) and Hardware Security
Khoa Tan Vo, Minh Ngo, Thu Nguyen, Thu-Thuy Ta · 7 authors
Scalability remains a key challenge for layer 1 blockchains. ZK-Rollups, leveraging zero-knowledge proofs, offer a promising layer 2 solution by improving throughput and reducing costs while preserving security. However, the performance of ZK-Rollup still poses a major barrier to practical implementation. The proving circuits in popular applications like ERC-20 transactions are highly complex, often containing a large number of constraints, which directly impacts the computation time and resources required to generate zero-knowledge proofs. This study presents an empirical study on the impact of constraint optimization in Circom on the performance of ERC-20 ZK-Rollups using Groth16. Three optimization levels (–O0, –O1, –O2) are evaluated across transaction batches ranging from 4 to 128, with further exploration up to 512 for specific optimization levels to assess scalability. Results show a trade-off: –O2 reduces constraints by up to 73.2% but increases compilation time by 213.35% at batch size 128, while –O1 offers a more balanced approach suitable for development stages. Findings confirm that proof generation time is closely tied to constraint count and complexity. Based on these insights, this study introduces ZCLS (ZK-Circuit Lifecycle Strategy), a practical framework for selecting optimization flags aligned with development stages to enhance ZK-Rollup system efficiency.
Open access
Physical Unclonable Functions (PUFs) and Hardware Security
The growing importance of software supply chain security has revealed the critical need for securely sharing Software Bills of Materials (SBOMs). SBOMs enhance transparency by providing a detailed inventory of software components, but can inadvertently expose sensitive proprietary information and vulnerabilities when shared publicly. Addressing this challenge, this thesis explores the use of cryptographic techniques to achieve privacy-preserving and verifiable SBOM sharing. This thesis addresses this challenge by proposing zkSBOM (Zero-Knowledge Software Bill of Materials), a proof-of-concept system for privacy-preserving and verifiable SBOM sharing. It explores the system requirements and design for achieving secure yet transparent SBOM sharing, the effectiveness of various cryptographic techniques in safeguarding sensitive SBOM information, and the integration with real-world SBOMs. Through system design analysis and an experimental approach, this work provides solid insights into privacy-enhanced SBOM-sharing. The results demonstrate that the use of established cryptographic techniques is suitable to securely share SBOMs in real-world scenarios. We propose a centralised system enabling software vendors to upload their SBOMs and allowing verifiers to query for vulnerabilities. Additionally, we offer a local verifier system that allows verifiers to independently validate the proofs generated by the centralised system. The system leverages cryptographic techniques such as Merkle Trees, Sparse Merkle Trees, Merkle Patricia Tries, and Zero-Knowledge Sets. Using them, zkSBOM enables selective disclosure of SBOM information efficiently. The system ensures transparency through verifiable inclusion and non-inclusion proofs while safeguarding critical information. In a case study, we successfully ingest 16 out of 18 SBOMs and generate inclusion proofs for dependencies affected by a given vulnerability. This research contributes to advancing privacy-preserving SBOM sharing, paving the way for broader adoption in the software industry while strengthening the security of software supply chains.
Open access
Blockchain Technology Applications and Security
Physical Unclonable Functions (PUFs) and Hardware Security
Counterfeit drugs represent a serious global risk, accounting for about 10% of the medicines worldwide. This per-centage increases significantly in developing countries, reaching up to 30%, and has become a major cause of child mortality in these regions. Blockchain technology provides a good solution to address this critical issue through improving transparency and traceability of pharmaceuticals from manufacturers to end users. However, traditional blockchain applications face major challenges, particularly in terms of high costs and scalability especially when handling large volumes of data and transactions such as those found in the pharmaceutical supply chain. To address these limitations, researchers have introduced Layer 2 blockchain technologies, which operate on top of standard blockchain networks to improve scalability and reduce costs. This paper aims to design an efficient, secure, and scalable framework that can support traceability in pharmaceutical supply chains and contribute to reducing counterfeit drugs. This framework lever-ages Layer 2 blockchain solutions and combines Non-Fungible Tokens (NFTs) linked to Quick Response (QR) codes to provide unique identification for each drug. Furthermore, it incorporates the InterPlanetary File System (IPFS) for off-chain storage to reduce the amount of data stored directly on the blockchain. Additionally, an access control mechanism is incorporated to ensure the protection of sensitive data by limiting access based on predefined roles. This enhances privacy and reduces the risk of data leakage or misuse. In conclusion, this work provides the global scientific community with a secure and scalable framework that can be applied internationally to strengthen pharmaceutical supply chains and reduce the risks of counterfeit drugs.
Open access
Pharmaceutical Quality and Counterfeiting
Blockchain Technology Applications and Security
Physical Unclonable Functions (PUFs) and Hardware Security