Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

486 papersLast indexed Aug 31, 2026
Search papers

Paper index

486 results ¡ page 6 of 21

Clear filters
Feb 1, 2026¡Research Corridor Journal of Engineering Science
0 cites
Information Security Governance in Distributed and Decentralized IT Systems: A Coordination-Theoretic Perspective

Khan IMDAD ULLAH

The rapid proliferation of distributed and decentralized IT architectures—ranging from cloud-native microservices and edge computing to blockchain-based ecosystems—has fundamentally eroded the efficacy of traditional, centralized information security governance (ISG). As organizational perimeters dissolve into federated, multi-actor, and ephemeral environments, the hierarchical model of a single governing authority enforcing uniform policy becomes not only obsolete but actively detrimental to system resilience. This research examines the critical governance tension between the necessity for central control to manage aggregate risk and the operational reality of local autonomy required for distributed system performance. By adopting a coordination-theoretic lens, this article conceptualizes security governance not as a static command structure but as a dynamic, distributed coordination problem. The study identifies and analyzes specific mechanisms for aligning security responsibilities, decision rights, and assurance processes across autonomous nodes without relying on a single root of trust or a monolithic control plane. Key insights reveal that effective governance in decentralized environments depends on the implementation of polycentric decision-making frameworks, the utilization of automated policy-as-code enforcement, and the adoption of consensus-based assurance mechanisms. The findings suggest that a shift from "governance by mandate" to "governance by protocol" is essential for securing the next generation of digital infrastructure.

Open access
Information and Cyber Security
Access Control and Trust
Mobile Agent-Based Network Management
Original source
Jan 27, 2026¡arXiv (Cornell University)
0 cites
Enabling SSI-Compliant Use of EUDI Wallet Credentials through Trusted Execution Environment and Zero-Knowledge Proof

Nacereddine Sitouah, Francesco Bruschi, Stefano De Cillis

The passing of the eIDAS amendment marks an important milestone for EU countries and changes how they must manage digital credentials for both public services and businesses. Italy has led in adopting eIDAS, first with CIE and SPID identity schemes, and now with the Italian Wallet (IO app) aligned to eIDAS 2.0. Self-Sovereign Identity (SSI) is a decentralized model born from the success of Distributed Ledgers, giving individuals full control over their digital identity. The current eIDAS 2.0 and its implementation acts diverge from SSI principles, rendering the European Digital Identity Wallet (EUDIW) centralized and merely user-centric, prioritizing security and legal protection over true self-sovereignty. This paper proposes an architecture that enables the use of IT Wallet credentials and services in an SSI-compliant environment through Trusted Execution Environments and Zero-Knowledge Proofs.

Open access
4 source records
cs.ET
cs.DC
Access Control and Trust
Original source
Jan 24, 2026¡Journal of Next-Generation Research 5 0
0 cites
Generic Agnostic AI and Distributed Ledger Enterprise System for Scalable Domain Adaptation

Walter Kurz, Michel Malara, Wojtek Stricker, Eva Albrecht

The objective of this study is to define a compliance-first, conceptually generalisable architecture for a multi-agent artificial intelligence platform integrated with distributed ledger technology, designed to be domain-, deployment-, and vendor-agnostic. It addresses a persistent shortcoming in current AI deployments, where compliance is often treated as a secondary concern, applied retroactively through prompt engineering rather than embedded within the foundational design. The proposed model encodes regulatory, governance, and ESG requirements into an objective-under-constraints framework, ensuring that all specialised agents operate within legally admissible and verifiably auditable parameters prior to any domain-specific implementation. A DAG-based verification layer is incorporated to enable scalable, low-latency, and cost-efficient operation while preserving evidentiary integrity. The analysis evaluates the feasibility of this conceptual model to support sustainable, rapid-deployment vertical applications without inducing vendor lock-in, preserving operational neutrality, and ensuring environmental accountability. The findings suggest that integrating compliance, ESG metrics, and agent specialisation at the architectural level provides a transferable foundation for cross-domain AI–DLT infrastructures.

Open access
2 source records
Multi-Agent Systems and Negotiation
Advanced Software Engineering Methodologies
Access Control and Trust
Original source
Jan 22, 2026¡Journal of Policy and Development Studies
0 cites
Distributed Ledger Technologies for Student Information Management Systems: A Conceptual and Technical Framework for the Tanzania Institute of Accountancy (TIA)

Costantine Kulwa

Student Information Management Systems (SIMS) are mission critical to higher learning institutions because they govern admissions, registration, fee status, assessment results, progression, graduation, and alumni verification. Yet conventional centralized SIMS architectures may face persistent challenges: record tampering risk, weak end‑to‑end audit trails, fragmented reconciliation across units and campuses, slow and costly credential verification, and limited interoperability with external verifiers.This study develops a conceptual and technical framework for applying Distributed Ledger Technology (DLT) to strengthen SIMS at the Tanzania Institute of Accountancy (TIA). The framework positions DLT as a trust and interoperability layer rather than a replacement for SIMS. It proposes (i) an architecture that anchors cryptographic proofs on‑chain while keeping personal data off‑chain; (ii) standards based digital credentialing using W3C Verifiable Credentials and Decentralized Identifiers; (iii) governance and compliance controls aligned to Tanzanian data protection and cybercrime regimes; and (iv) an implementation roadmap and evaluation metrics grounded in established information systems theories. To make design trade‑offs concrete, the study includes simulated calculations and figures for event volume, storage growth, verification turnaround time, and risk intensity across rollout phases. The framework provides a practical blueprint for a staged pilot at TIA starting with credential verification and assessment audit‑trail anchoring before scaling to additional workflows.

Open access
Cloud Data Security Solutions
Information and Cyber Security
Access Control and Trust
Original source
Jan 17, 2026¡Zenodo (CERN European Organization for Nuclear Research)
0 cites
A Study on Blockchain for Secure Healthcare Data Sharing

Rafat Qureshi

The increasing adoption of distributed ledger technology (DLT) in healthcare promises enhanced data security, integrity, and patient control. This study evaluates the characteristics and security implications within a simulated Electronic Health Record (EHR) network, comprising 1,800 records. The analysis focuses on network access control (Access Policy), data integrity mechanisms (Record Hash), and the incidence of security risks (Malicious Node). The records show a near-even split between 'Read/Write' (50.06%) and 'Read-Only' (49.94%) access policies. Crucially, findings reveal that the presence of a Malicious Node (50.72% of records) is highly uniform across both 'Read-Only' (50.95%) and 'Read/Write' (50.5%) policies, indicating that basic access control alone is ineffective at mitigating security risks within this network. This highlights the need for dynamic, context-aware smart contracts that incorporate behavioural or clinical risk factors for enhanced security.

Open access
2 source records
Blockchain Technology Applications and Security
Information and Cyber Security
Access Control and Trust
Original source
Jan 15, 2026¡arXiv (Cornell University)
0 cites
Fuzzychain-edge: A novel Fuzzy logic-based adaptive Access control model for Blockchain in Edge Computing

Khushbakht Farooq, Muhammad Ibrahim, Irsa Manzoor, Mukhtaj Khan ¡ 5 authors

The rapid integration of IoT with edge computing has revolutionized various domains, particularly healthcare, by enabling real-time data sharing, remote monitoring, and decision-making. However, it introduces critical challenges, including data privacy breaches, security vulnerabilities, especially in environments dealing with sensitive information. Traditional access control mechanisms and centralized security systems do not address these issues, leaving IoT environments exposed to unauthorized access and data misuse. This research proposes Fuzzychain-edge, a novel Fuzzy logic-based adaptive Access control model for Blockchain in Edge Computing framework designed to overcome these limitations by incorporating Zero-Knowledge Proofs (ZKPs), fuzzy logic, and smart contracts. ZKPs secure sensitive data during access control processes by enabling verification without revealing confidential details, thereby ensuring user privacy. Fuzzy logic facilitates adaptive, context-aware decision-making for access control by dynamically evaluating parameters such as data sensitivity, trust levels, and user roles. Blockchain technology, with its decentralized and immutable architecture, ensures transparency, traceability, and accountability using smart contracts that automate access control processes. The proposed framework addresses key challenges by enhancing security, reducing the likelihood of unauthorized access, and providing a transparent audit trail of data transactions. Expected outcomes include improved data privacy, accuracy in access control, and increased user trust in IoT systems. This research contributes significantly to advancing privacy-preserving, secure, and traceable solutions in IoT environments, laying the groundwork for future innovations in decentralized technologies and their applications in critical domains such as healthcare and beyond.

Open access
3 source records
cs.CR
cs.DC
Blockchain Technology Applications and Security
Original source
Jan 12, 2026¡Computer Fraud & Security
0 cites
Blockchain Technology as Trust Infrastructure for Third-Party Risk Management

Sagar Behere

Contemporary organizational ecosystems are critically vulnerable in third-party risk management frameworks due to centralized databases, fragmented documentation systems, and manual processes of assessment. Traditional approaches result in huge inefficiencies through redundant audits, version control complexities, and delayed responses for compliance along multi-jurisdictional vendor networks. The blockchain architecture introduces a fundamental architectural transformation through distributed ledger mechanisms, creating immutable audit trails, cryptographic verification protocols, and decentralized trust formation across organizations. The article reviews how blockchain works as an integrity infrastructure within regulatory technology ecosystems, allowing the automation of compliance through smart contracts, making transparent records available for authorized stakeholders, and removing single-point vulnerabilities from centralized control systems. The technical mechanisms for implementation include immutable vendor record systems, which integrate fragmented documentation into unified, tamper-proof ledgers; smart contract automation that allows deterministic outcomes in governance; and distributed assurance networks, which allow audit verification among multiple organizations. Regulatory dimensions are related to preserving privacy through hybrid on-chain and off-chain architectures, legal recognition challenges of smart contracts within jurisdictional frameworks, and ethics in governance requirements for human input within automated ecosystems of decisions. Implementation challenges involve the complexity of legacy system integration, the development of a structure for consortium governance, scalability constraints, and the scarcity of talent. Future trajectories include hybrid ecosystems, integrating blockchain's immutability with advanced analytics, tokenized reputation frameworks, and integrations with emerging technologies such as artificial intelligence and digital identity systems toward next-generation vendor risk governance.

Open access
3 source records
Blockchain Technology Applications and Security
Access Control and Trust
Energy Law and Policy
Original source
Jan 8, 2026¡arXiv (Cornell University)
0 cites
Proof of Commitment: A Human-Centric Resource for Permissionless Consensus

Homayoun Maleki, Nekane Sainz, Jon Legarda

Permissionless consensus protocols require a scarce resource to regulate leader election and provide Sybil resistance. Existing paradigms such as Proof of Work and Proof of Stake instantiate this scarcity through parallelizable resources like computation or capital. Once acquired, these resources can be subdivided across many identities at negligible marginal cost, making linear Sybil cost fundamentally unattainable. We introduce Proof of Commitment (PoCmt), a consensus primitive grounded in a non-parallelizable resource: real-time human engagement. Validators maintain a commitment state capturing cumulative human effort, protocol participation, and online availability. Engagement is enforced through a Human Challenge Oracle that issues identity-bound, time-sensitive challenges, limiting the number of challenges solvable within each human window. Under this model, sustaining multiple active identities requires proportional human-time effort. We establish a cost-theoretic separation showing that protocols based on parallelizable resources admit zero marginal Sybil cost, whereas PoCmt enforces a strictly linear cost profile. Using a weighted-backbone analysis, we show that PoCmt achieves safety, liveness, and commitment-proportional fairness under partial synchrony. Simulations complement the analysis by isolating human-time capacity as the sole adversarial bottleneck and validating the predicted commitment drift and fairness properties. These results position PoCmt as a new point in the consensus design space, grounding permissionless security in sustained human effort rather than computation or capital.

Open access
3 source records
Distributed systems and fault tolerance
Opportunistic and Delay-Tolerant Networks
Access Control and Trust
Original source
Jan 5, 2026¡Zenodo (CERN European Organization for Nuclear Research)
0 cites
On-Chain Risk Oracle for OSS Vulnerabilities in Web3 Backends (OSV + EPSS + KEV): Signed SBOM-Bound Risk Attestations Anchored On-Chain.

Siddharth Sudhir

This preprint introduces Risk Oracle, an exploit-intelligence–driven SBOM attestation framework designed to support practical risk gating in CI/CD. The system combines signals from Known Exploited Vulnerabilities (KEV) and Exploit Prediction Scoring System (EPSS) with SBOM-to-vulnerability matching to produce a policy-backed gate decision (e.g., pass / warn / block) while keeping the workflow interpretable and reproducible. A core design goal is bounded disclosure: the producer can commit to full findings and then disclose only a limited subset (e.g., top-K highest-risk issues) suitable for downstream verification, reducing disclosure risk while preserving auditability. The paper details the end-to-end pipeline (producer/verifier roles), a typed attestation schema, a scoring and decision procedure, and an evaluation that studies (i) signal behavior under pinned KEV/EPSS snapshots and (ii) operational overhead under synthetic SBOM scaling intended to approximate CI workloads. Key contributions A practical SBOM attestation pipeline that integrates exploit-intelligence signals for operational decision-making in CI/CD. A typed attestation schema and verifier procedure supporting bounded disclosure. A policy-driven scoring and gating framework (pass/warn/block) grounded in vulnerability-management practice. Evaluation focused on interpretability and operational cost (runtime/payload scaling) under reproducible, pinned snapshots. Artifacts / Reproducibility Code, scripts, and pinned snapshot references: [GitHub link] Suggested citationSudhir, S. (2026). Risk Oracle: Exploit-Intelligence–Driven SBOM Attestations with Bounded Disclosure (preprint). Zenodo. DOI: [10.5281/zenodo.18153487] Keywords: SBOM, software supply chain security, vulnerability management, KEV, EPSS, OSV, attestation, CI/CD, bounded disclosure, reproducibility

Open access
2 source records
Security and Verification in Computing
Information and Cyber Security
Access Control and Trust
Original source
Jan 1, 2026¡Open MIND
0 cites
Healthcare security and privacy policy compliance: a blockchain and smart contract-based assurance framework

Md Al Amin, Indrajit Ray, Indrakshi Ray, Yashwant K. Malaiya ¡ 5 authors

Access to electronic health records (EHRs) is heavily regulated by various policies, including federal-level policies, state-level statutes, international data protection laws, and local and organizational-level policies. These policies may include procedures to ensure compliance with other organizational-level regulations. In addition, individual patients can establish agreements, formally known as patient-provider agreements (PPA), with their healthcare providers to express their consent to access or share their protected health information (PHI). When such policies are adequately specified and implemented, they go a long way toward protecting EHR data. However, research has shown that significant policy compliance problems or gaps often go undetected until after a breach or security incident. Further, a recent study shows that subcultures within a healthcare organization influence whether employees violate policies, perhaps unintentionally. These observations motivate us to revisit the compliance and provenance aspects of policies. This dissertation proposes a blockchain-powered, smart contract-based policy-compliance assurance framework to enforce patient-provider agreements and other applicable policies and attributes, ensuring policy compliance and provenance in the healthcare sector. This work proposes a novel compliance review mechanism, Proof of Compliance (PoC), that conducts reviews through a set of independent, distributed, decentralized auditor nodes from various stakeholders, such as healthcare organizations, insurance companies, federal and other government agencies, regulatory agencies, and others mandated by the business requirements. Blockchain smart contracts appear to be a promising new technology for enforcing policies. In addition, blockchains' immutable storage properties and strong integrity guarantees provide hope that an adequate trail of policy compliance (or non-compliance) can be maintained, thereby facilitating provenance.

Open access
Blockchain Technology Applications and Security
Information and Cyber Security
Access Control and Trust
Original source
Jan 1, 2026¡International Journal of Modern Innovations and Emerging Trends
0 cites
Blockchain-Enabled Identity Systems for Secure e-Governance

Jana NovakovĂĄ, Adi Lestari

Given that digital governance has achieved extensive spread and people rely increasingly on online services, affordable and trustworthy identity management is now one of the core pillars of contemporary e-Governance systems. Conventional identity systems are usually centralized, highly susceptible to cyber-attacks and most likely to breach privacy. Blockchain technology provides a decentralized, tamper-proof, and transparent system, which guarantees data integrity, data security, and the privacy of the user. In this paper, the authors research the adoption of blockchain-based identity management within e-Governance sites. We discuss available solutions, assess the risks along with their weaknesses and strengths, and suggest a design on how to introduce a safe blockchain-based identity system. Important efforts have been on developing a holistic system that brings smart contract, cryptographic protocols and distributed ledger technologies together to make citizen identification and authentication secure. The outcome of the results shows enhanced security, less identity fraud, and better data security, so there is a possibility of scalability and resilient e-Governance applications.

Open access
Blockchain Technology Applications and Security
Cryptography and Data Security
Access Control and Trust
Original source
Jan 1, 2026¡IEICE Transactions on Information and Systems
0 cites
Signing-Enhanced Forward-Secure Signatures by Leveraging SNARKs

Junhee LEE, Yixi Cai Lili lei Lei Li, Gweonho Jeong, Jihye Kim ¡ 6 authors

Forward-secure digital signatures protect the integrity of past signatures, even if the current signing key is compromised. Among forward-secure signature schemes, the method introduced by Lee et al. [1], based on zero-knowledge succinct non-interactive arguments of knowledge (zk-SNARKs), is particularly notable for achieving constant complexity across all metrics without requiring a predefined maximum time period. However, a naive approach to recursive proof composition results in an excessive amount of redundant computation being repeated for each signing process, which our method reduces significantly. In this paper, we advance a zk-SNARK-based forward-secure signature scheme by significantly improving the efficiency of its signing algorithm. By incorporating commit-and-prove SNARKs, we replace the inner verification process with commit verification within the signing circuit. Furthermore, we employ efficient recursive zk-SNARKs with accumulation and folding schemes to improve the setup and update algorithms. Our implementation demonstrates the practicality of our approach: the signing procedure completes in 0.18 seconds, achieving a 75-fold speedup over the previous scheme, setup time is reduced to 0.71 seconds - over 61 times faster, and public parameters are reduced to 25 MB, more than 16 times smaller.

Open access
Cryptography and Data Security
Security in Wireless Sensor Networks
Access Control and Trust
Original source
Jan 1, 2026¡Recent Advances in Next-Generation Wireless Communication Systems
0 cites
Adaptive Trust Evaluation under Dynamic Service Conditions Using Distributed Verification

Gaurav Tamrakar

The dynamic service conditions, the lack of centralised control in the distributed and federated services, and the growing sophistication of the malicious behaviours are the key challenges to trust management in the distributed and federated services. Standard trust models, based on fixed credentials, central authorities, or aggregation of reputation over the whole world, are no longer suitable to serve high-rate changing contexts in services, and have very high communication and coordination costs. In an effort to curb these issues, this paper puts forward a proposal of adaptive trust evaluation framework that has distributed verification in highly dynamic service-oriented architectures. The suggested model represents trust as a context-based, multi-dimensional digit that conservatively adapts to the context changes in service conduct, workload, and environmental state. To satisfy the decentralized nature of trust updates, a lightweight peer-based verification system is presented and does not need any centralized sources of trust but instead, trust updates are validated through decentralized means without depending upon a full blockchain consensus system. The framework constitutes adaptive weighting of trust, decay of trust and enforcement policies to reliably detect malicious or unreliable services in changing situations. Between the two widely used approaches, the widespread performance analysis of the suggested approach demonstrates that it has a better accuracy in trust, faster in detecting malicious service and with a much lower communication overhead than state of art centralised, reputation-based and ledger-driven approaches to trust. The findings affirm the viability, scalability, as well as viability of the suggested solution to secure trust execution in the next-generation distributed cloud and edge service surroundings.

Open access
Access Control and Trust
Blockchain Technology Applications and Security
Cloud Data Security Solutions
Original source
Jan 1, 2026¡OSF Preprints (OSF Preprints)
0 cites
SARMF-Bench: Reproducible Smart Contract Vulnerability Benchmark Dataset

Mohit Tiwari

SARMF-Bench is a structured and reproducible benchmark dataset for smart contract vulnerability analysis. It consists of five minimal Solidity contracts representing canonical vulnerability classes: • Reentrancy • Arithmetic Overflow Behavior • Access Control Weakness • Unchecked External Call • Denial-of-Service Pattern Each contract is paired with machine-readable static analysis outputs generated using Slither v0.11.5. The dataset is designed to support controlled benchmarking experiments for: - Static analyzers - Symbolic execution engines - Fuzzers - AI-assisted smart contract security tools Related assets: GitHub repository: https://github.com/profmohit-edu/sarmf-framework Zenodo software DOI: https://doi.org/10.5281/zenodo.18754015 Reproducibility protocol: https://doi.org/10.17504/protocols.io.bp216eyxdgqe/v1 Mendeley dataset DOI (pending moderation): https://doi.org/10.17632/kd3vcpnn9v.1 HAL record: https://hal.science

Open access
Security and Verification in Computing
Software System Performance and Reliability
Access Control and Trust
Original source
Jan 1, 2026¡Figshare
0 cites
Environment-Coupled Execution (ECE)

Steven Paul Nohr

Decentralized systems are increasingly required to operate across heterogeneous environments involving human presence, real-world assets, regulatory constraints, and adversarial network conditions. Traditional execution models, which assume static infrastructure, context-free computation, and pre-authorized identities, are insufficient for these emerging requirements. This paper introduces a Presence-Centric execution architecture that binds computational validity to verifiable environmental state at execution time. The proposed system is structured around two core components: the Crystal Validator, a context-aware validation layer, and an AI Feedback Loop, which enables adaptive policy enforcement based on observed outcomes. Central to this architecture is <b><i>Environment-Coupled Execution</i></b>, a model in which identity, intent, policy, and environment are jointly evaluated to determine execution validity. By treating environment as a first-class execution dependency, the system enables contextual non-repudiation, replay resistance, regulatory determinism, and post-execution auditability. The proposed approach is applicable to decentralized finance, stablecoins, real-world asset tokenization, governance systems, and presence-driven digital platforms.

Open access
2 source records
Security and Verification in Computing
Access Control and Trust
Mobile Agent-Based Network Management
Original source
Jan 1, 2026¡Figshare
0 cites
Governance Voter Loop Reuse: Recycled Voting Power Exploits in DeFi Governance Systems

Steven Paul Nohr

<b><i>Governance Voter Loop Reuse</i></b> is a strategic exploit in decentralized finance (DeFi) governance systems whereby the same economic capital is repeatedly reused to exert voting influence across multiple proposals, epochs, or governance venues without maintaining sustained economic exposure. By exploiting snapshot-based voting, token mobility, and weak binding between voting power and duration of risk, attackers can artificially amplify governance influence while avoiding long-term commitment. This paper formalizes the exploit, analyzes its structural enablers and execution mechanisms, and evaluates its systemic impact on DAO legitimacy and protocol security. We further propose mitigation requirements centered on time-weighted exposure, continuity-aware governance models, and behavioral detection mechanisms.

Open access
2 source records
Blockchain Technology Applications and Security
Access Control and Trust
Security and Verification in Computing
Original source
Jan 1, 2026¡Figshare
0 cites
Off-Chain Data Oracle Coercion: A Structural Failure in DeFi and Stablecoin Enforcement

Steven Paul Nohr

Decentralized finance and stablecoin systems rely extensively on off-chain data oracles to supply price feeds, reserve attestations, and external state signals. While often treated as neutral data providers, oracles constitute a critical enforcement surface vulnerable to coercion, capture, and strategic manipulation. This paper defines <b><i>Off-Chain Data Oracle Coercion</i></b> as a systemic risk whereby economic, governance, or infrastructural pressures distort oracle outputs without violating cryptographic correctness. We demonstrate how oracle coercion enables silent value extraction, destabilizes stablecoin pegs, and undermines regulatory compliance. A validator-enforced, logic-layer control model is proposed to restore oracle neutrality and ensure continuous, verifiable data integrity under MiCA-aligned supervision.

Open access
2 source records
Blockchain Technology Applications and Security
Cryptography and Data Security
Access Control and Trust
Original source
Jan 1, 2026¡SSRN Electronic Journal
0 cites
Cognitive Internet Layer (CIL): The Foundational Trust and Reasoning Infrastructure for Autonomous Intelligence Systems

Vengatagiri Gurumani

The current internet architecture was fundamentally designed for deterministic data packet transport and applicationlevel request-response interactions, not for the semantic exchange, verification, governance, and replay of autonomous machine reasoning. As autonomous AI agents scale globally to orchestrate critical infrastructure, medical networks, corporate supply chains, and legal workflows, traditional integration patterns create structural bottlenecks. These limitations introduce severe risks of cognitive fragmentation, black-box opacity, and cascade errors across organizational boundaries. This paper proposes the Cognitive Internet Layer (CIL), a protocol-oriented overlay architecture positioned above conventional network transport and below autonomous AI applications. CIL introduces the Reasoning Exchange Protocol (REP) to route structured decision envelopes containing reasoning metadata rather than raw payloads. To resolve real-world deployment trade-offs, the framework integrates Zero-Knowledge Proofs (ZKPs) for privacy-preserving verification and a Tiered Execution Architecture to isolate highthroughput edge transactions from deep asynchronous multi-agent consensus validation.

Open access
Cognitive Computing and Networks
Access Control and Trust
Distributed systems and fault tolerance
Original source
Jan 1, 2026¡SSRN Electronic Journal
0 cites
Secure Explainable Audit Trails for Workflows in Agentic AI

Subhasis Thakur

An Explainable Audit Trail (EAT) records process execution traces of an agentic workflow. EAT can enable an organisation to efficiently remain compliant with regulations by presenting its audit results to it. However, current state of the art in EAT lacks privacy protection of agent's models which can be intellectual properties of the organisation. Exposing audit trails to external entities may facilitate orchestration of attacks on the agent's model. Auditing a complex workflow will require verification of dependencies among tasks as preconditions to execute a task. Further, it is necessary for the audit algorithm to ensure that a process execution trace follows the pre-planned process execution model for security reasons, i.e., audit should include functionality that can check if the agents have deviated from its planned process execution models. In this paper, we build a secure EAT that can address these gaps in the state of the art in EAT for agentic workflows. Our main contribution is the application of zero-knowledge-proof on verifying audit procedures. It proves the audit has validated correctness of chain-of-thoughts, the execution trace at the runtime matches the planned process execution , and complete traceability among logs of a complex workflow involving dependencies among the tasks in terms of preconditions. Our solution provides a trust-less infrastructure to verify the audit results to external entities while not exposing the audit trails. We used lattice-based zero knowledge proof for this procedure. We provide an analysis on the EAT procedure. We show experimental evaluation of the EAT with workflow dataset.

Open access
2 source records
Business Process Modeling and Analysis
Access Control and Trust
Explainable Artificial Intelligence (XAI)
Original source
Jan 1, 2026¡SSRN Electronic Journal
0 cites
Cryptographic State-Transition Anchoring: A Merkle-Tree Framework for Zero-Knowledge Regulatory Compliance in Insurance Operations

Piyoosh Rai

Insurance operations generate continuous streams of regulated state transitions-policy issuance, claim adjudication, premium collection, broker remittance-that must be auditable for years and verifiable on demand by regulators, reinsurance counterparties, and litigation adversaries. The prevailing industry practice protects these audit trails through database access controls and policy-based logging in mutable relational stores. This approach is insufficient: it requires regulators to trust the platform vendor, exposes Personally Identifiable Information (PII) during inspection, and provides no mathematical defense against retrospective tampering by privileged insiders or attackers with database access. This paper introduces the Regure Immutable Audit (RIA) Protocol, a cryptographic statetransition anchoring system that organizes insurance operational events into per-tenant Merkle trees, signs each daily root with a tenant-specific hardware-backed key via AWS Key Management Service, and anchors the signed root to two independent immutable witnesses: AWS S3 Object Lock and the Bitcoin blockchain via OpenTimestamps. Verification is implemented as a zero-knowledge protocol: an external auditor can verify the cryptographic integrity of any specific event in any specific claim using a Merkle proof of length 𝑂(log 𝑛)against a publicly anchored root, without ever observing the underlying claim data. We provide formal definitions of the State-to-Hash Mapping, the Hash-Linked Lifecycle property, and the Dual-Witness Anchoring Construction. We prove that the system is tamper-evident under standard cryptographic assumptions, that verification has logarithmic complexity in the number of events per tenant per day, and that the Zero-Knowledge Audit property holds against both honest-but-curious regulators and an actively malicious platform vendor. We describe the production implementation deployed in Cryptographic State-Transition Anchoring Piyoosh Rai P a g e | 2 Regure, including the integration with AWS KMS for tenant-isolated signing keys and the dual anchoring path through Object Lock storage and Bitcoin transaction confirmation. We discuss the implications for Continuous Assurance under DORA Article 12, the Swiss Federal Act on Data Protection (FADP), the Saudi Arabian Monetary Authority (SAMA) Cyber Security Framework, and Lloyd's market reporting requirements for delegated authority operations. The RIA Protocol moves the insurance industry's audit trust model from "trusting the vendor" to "trusting the math"-a structural shift that resolves the long-standing conflict between the regulatory Right to Audit and the data subject's right to privacy.

Open access
Cryptography and Data Security
Blockchain Technology Applications and Security
Access Control and Trust
Original source
Jan 1, 2026¡SSRN Electronic Journal
0 cites
A Modular Zero-Knowledge Credential Framework for Multi-System Attribute Verification with Scoped Unlinkability and Efficient Accumulator-Based Revocation

Sayan Bairagi

This paper presents a zero-knowledge credential framework for secure and privacy-preserving attribute verification across multiple independent systems. The framework enables users to prove statements about their attributes without revealing the underlying values, while preventing cross-domain tracking by eliminating globally stable identifiers. The construction combines commitment schemes, digital signatures, zero-knowledge proofs, scoped pseudonyms, and accumulator-based revocation into a unified and modular design. Scoped identifiers ensure that user activity cannot be linked across different verification domains, while predicate proofs allow verification of conditions such as threshold checks without disclosing sensitive data. Revocation is supported through an efficient accumulator mechanism that enables verification without revealing credential identities and without increasing cost with the size of the revoked set. The system follows a complete lifecycle including credential issuance, proof generation, verification, and revocation checking. All proofs are non-interactive and bound to verifier-specific challenges, ensuring resistance to replay attacks. Security is based on standard cryptographic assumptions, providing guarantees for attribute privacy, proof soundness, unlinkability, and resistance to collusion. Experimental evaluation demonstrates that the framework achieves practical performance, with low verification latency, compact proof size, and stable scalability. The results show that strong privacy, verifiable authenticity, and efficient revocation can be achieved simultaneously without relying on trusted setup or pairing-based cryptography. The modular structure further supports integration with decentralized identity systems and real-world deployment scenarios.

Open access
Cryptography and Data Security
Blockchain Technology Applications and Security
Access Control and Trust
Original source