Bruno M. F. Ricardo, Lucas C. Cardoso, Leonardo T. Kimura, Marcos A. SimplÃcio · 5 authors
In 2023, Barreto and Zanon proposed a three-round Schnorr-like blind signature scheme, leveraging zero-knowledge proofs to produce one-time signatures as an intermediate step of the protocol. The resulting scheme, called BZ, is proven secure in the discrete-logarithm setting under the one-more discrete logarithm assumption with (allegedly) resistance to the Random inhomogeneities in a Overdetermined Solvable system of linear equations modulo a prime number p attack, commonly referred to as ROS attack. The authors argue that the scheme is resistant against a ROS-based attack by building an adversary whose success depends on extracting the discrete logarithm of the intermediate signing key. In this paper, however, we describe a distinct ROS attack on the BZ scheme, in which a probabilistic polynomial-time attacker can bypass the zero-knowledge proof step to break the one-more unforgeability of the scheme. We also built a BZ variant that, by using one secure hash function instead of two, can prevent this particular attack. Unfortunately, though, we show yet another ROS attack that leverages the BZ scheme’s structure to break the one-more unforgeability principle again, thus revealing that this variant is also vulnerable. These results indicate that, like other Schnorr-based strategies, it is hard to build a secure blind signature scheme using BZ’s underlying structure.
With the shift from Centralized Finance (CeFi) to Decentralized Finance (DeFi), financial transactions have become trustless and self-executing through blockchain platforms, creating new opportunities while exposing the ecosystem to significant fraud risks. However, due to the lack of centralized oversight and the vulnerabilities in the blockchain platforms, DeFi transactions still face several security challenges, including fraud, identity theft, insider threats, and data breaches. Various methods, including regulatory frameworks, machine learning (ML), and deep learning (DL) techniques, are employed to detect these threats, particularly fraud, in DeFi transactions. Although these approaches help identify fraudulent activities, they face challenges related to accuracy and zero-day attacks due to insufficient data and the complexity of emergingfraud patterns. This study presents a novel approach for detecting and profiling fraud attacks, including zero-day ones in DeFi transactions, thereby eliminating the reliance on wallet transaction history, a limitation that previous research has heavily depended on. The proposed approach leverages two key components: a novel analyzer named DeFiTransLyzer (V1.0) and an Advanced Genetic Algorithm (AGA) for fraud transaction profiling. DeFiTransLyzer extracts 79 features from transaction and wallet data. At the same time, the AGA incorporates advanced techniques, including Penalized Fitness Evaluation, Elite Retention Strategy, Dynamic Mutation Rate, and dynamic generation, to create precise fraud profiles. By focusing solely on transaction features, the model ensures that all fraudulent activities, including zero-day ones, initiated within the first transaction of a new account can be effectively detected, without relying on prior wallet activity. To address the scarcity of comprehensive validation datasets, we introduce BCCCDeFiFraudTrans-2025, which comprises 1,026,867 annotated Ethereum transaction samples from the DeFi ecosystem. Additionally, the study establishes two taxonomies for systematic classification, covering the literature on fraud detection and profiling methods. Experimental results demonstrate that the proposed method achieves superior accuracy, precision, and efficiency while offering interpretability through its profiling mechanism. These promising outcomes highlight the potential of AGA profiling to enhance the detection and identification of fraudulent activities, including zero-day ones within DeFi transactions, contributing to the security and resilience of blockchainbased financial systems.
Abstract: Ensuring the integrity, privacy and accessibility of electoral system remains a critical global challenge. This paper proposes a secure blockchain based e-voting framework enhanced with anti-spoofing facial recognition for voter authentication and zero-knowledge proofs to preserve voter anonymity while enabling verifiable results. The proposed system integrates seamlessly with existing election infrastructure, allowing transparent vote recording on a tamper-resistant distributed ledger while preventing identity fraud through advanced biometric anti-spoofing techniques. Zero Knowledge Proofs enable vote verification without revealing individual choices, ensuring both privacy and trust. By combining blockchain’s immutability, biometric security and cryptographic privacy guarantees, this approach addresses vote tampering, impersonation, and transparency concerns, offering a scalable , auditable, and privacy-preserving solution for modern elections. Keywords: Blockchain, E-Voting, Anti-Spoofing, Facial Recognition, Zero Knowledge Proofs, Election Security, Privacy preserving systems.
Open access
Internet Traffic Analysis and Secure E-voting
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
This paper studies the practical aspects of adding zero-knowledge proofs of vote correctness to Internet voting, specifically to the IVXV system used in Estonia. We discuss various available alternatives and present a concrete instantiation based on Bulletproofs together with implementation details and benchmarking results. As IVXV currently uses the ElGamal cryptosystem with a 3072-bit prime modulus for vote encryption, but Bulletproofs work most efficiently on elliptic curves, a group switching solution is also implemented and benchmarked. Despite all the extra work required, our solution is very performant and well capable of sustaining the load of votes, even during peak vote submission periods.
<b>Abstract</b><br>Traditional electoral systems exhibit critical vulnerabilities including vote manipulation, centralized points of failure, and compromised transparency that undermine democratic integrity. This research presents BLOCKELECT, a decentralised blockchain-based secure voting system designed to address these fundamental challenges. The system employs Ethereum smart contracts written in Solidity to enforce immutable voting rules, Web3.js for blockchain integration, and MetaMask wallet authentication for secure voter verification. The proposed architecture implements dual interfaces for voters and electoral commissions, with distributed consensus mechanisms ensuring real-time transaction validation. Smart contracts automatically enforce electoral rules while maintaining cryptographic immutability of all voting transactions. The decentralised design eliminates single points of failure by distributing vote storage and validation across multiple network nodes. System validation employed comprehensive testing including unit, integration, system, and security testing methodologies. Results demonstrate successful prevention of vote tampering, elimination of double voting, and provision of transparent, auditable election results. Implementation utilised Truffle framework, Ganache blockchain simulation, and Node.js back-end services following an Agile Prototype-based Iterative Development methodology. This research demonstrates the feasibility of blockchain technology in creating trustworthy electoral systems, indicating that blockchain-based voting represents a viable solution for enhancing democratic processes while addressing persistent challenges of electoral fraud and lack of public confidence in traditional voting mechanisms.Traditional electoral systems exhibit critical vulnerabilities including vote manipulation, centralized points of failure, and compromised transparency that undermine democratic integrity. This research presents BLOCKELECT, a decentralised blockchain-based secure voting system designed to address these fundamental challenges. The system employs Ethereum smart contracts written in Solidity to enforce immutable voting rules, Web3.js for blockchain integration, and MetaMask wallet authentication for secure voter verification. The proposed architecture implements dual interfaces for voters and electoral commissions, with distributed consensus mechanisms ensuring real-time transaction validation. Smart contracts automatically enforce electoral rules while maintaining cryptographic immutability of all voting transactions. The decentralised design eliminates single points of failure by distributing vote storage and validation across multiple network nodes. System validation employed comprehensive testing including unit, integration, system, and security testing methodologies. Results demonstrate successful prevention of vote tampering, elimination of double voting, and provision of transparent, auditable election results. Implementation utilised Truffle framework, Ganache blockchain simulation, and Node.js back-end services following an Agile Prototype-based Iterative Development methodology. This research demonstrates the feasibility of blockchain technology in creating trustworthy electoral systems, indicating that blockchain-based voting represents a viable solution for enhancing democratic processes while addressing persistent challenges of electoral fraud and lack of public confidence in traditional voting mechanisms.
This paper presents a comprehensive framework for deploying a blockchain-based electronic voting system in Rwanda to address challenges of transparency, security, and public trust in electoral processes. Through detailed analysis of the current Rwandan electoral infrastructure and limitations, we propose a multilayered blockchain architecture that incorporates advanced cryptographic techniques, a national digital identity framework, and mobile accessibility features tailored to Rwanda's unique socio-economic landscape. Our proposed system leverages permissioned blockchain technology with a hybrid consensus mechanism to ensure the immutability of vote records while maintaining voter privacy through zero-knowledge proofs. The paper further discusses implementation challenges specific to Rwanda's context, including digital literacy (UNESCO, 2019), infrastructure limitations, and regulatory considerations. Our findings suggest that progressive, phased implementation of blockchain voting systems can significantly enhance electoral integrity while maintaining cultural and technological accessibility for Rwanda's diverse population.
Proof-of-Work cryptocurrencies employ miners to sustain the system through algorithmic reward adjustments. We develop a stochastic model of the multicurrency mining market and identify conditions for stable transaction speeds. Bitcoin's algorithm requires hash supply elasticity $\le$ 1 for stability, while ASERT remains stable for any elasticity and can be interpreted as a form of stochastic gradient descent algorithm under a certain loss function. Interactions with other currencies can relax Bitcoin's stability requirements. Using a ``halving'' event, we estimate miners' hash supply elasticity and conduct counterfactual simulations. Our findings reveal Bitcoin's heavy reliance on low hash-supply elasticity and interactions with smaller cryptocurrencies, suggesting an algorithm upgrade is crucial for stability.
Abstract Federated Learning (FL) has emerged as a promising distributed machine learning approach that addresses confidentiality and integrity concerns in various sectors, including Internet of Things (IoT), healthcare, finance, and cybersecurity. In order to improve privacy protection and detection accuracy in decentralized systems, this study investigates the incorporation of FL into Intrusion Detection Systems (IDS). FL is especially useful in situations where data security and privacy are crucial because it allows for the cooperative training of models without centralizing sensitive data. We examine many FL-based IDS solutions across several domains, emphasizing how well they mitigate data breaches, maintain confidentiality, and enhance intrusion detection capabilities. The use of Generative Adversarial Networks (GANs), artificial immune systems, and hybrid deep learning techniques to maximize IDS performance are among the current developments in FL methodology that are covered in the paper. We also look at issues like the requirement for effective aggregation procedures and non-independent and identically distributed (non-IID) data. Finally, we outline future directions and open research topics to improve the scalability, resilience, and effectiveness of FL-based IDS solutions in practical applications.
Evangelos Stavropoulos, Ioanna Karampela, Arjun Singh, Maria K. N. Fountoulakis · 8 authors
—The European research project GHOST challenges the traditional cyber security solutions for the Internet of Things (IoT) sector by exploiting novel technologies, such as blockchain, to provide resilience and integrity of decision making on the communication exchange in a smart home context. When it comes to novel cyber security solutions for extremely heterogeneous environments like IoT and smart homes, the key focus is typically given to the understanding of network activities and elimination of suspicious traffic. The GHOST project adds an extra dimension to this approach by integrating blockchain technology at its core decision mechanism. On a daily basis, each GHOST installation is encountering malicious behaviour and suspicious IoT communications, where easy information sharing with other installations, as well as decentralised decision making, are mandatory features for the efficient protection of the end-user. GHOST's Smart Contracts (SC) are designed to tackle in an easy, yet productive way, the reporting on suspicious IP addresses which the IoT devices in a smart home are trying to communicate with. Two variations of blacklisting smart contracts are presented in this paper, covering a diverse spectrum of possible attack vectors while closely following the Privacy by Design (PbD) principles. A reputation scoring scheme for malicious IPs reporting is integrated in the SC, uncovering the implementation details on the penalisation of existing entries in case of malicious behaviour of reporting devices
Existing electronic voting systems suffer from security concerns, identity theft, electoral fraud, and insufficient transparency in digital voting systems, which pose significant challenges to electoral integrity. Blockchain-based electronic voting systems provide immutability and decentralization. However, they are inappropriate for large-scale elections because of their inadequate consensus mechanisms, scalability issues, and security weaknesses. To provide an equitable electoral process, an electronic voting system must be scalable, secure, and efficient. This method requires real-time vote verification, secure vote recording to avert fraud, and voter authentication. This study introduces a blockchain-based smart contract electronic voting system (BCVS) to improve the security and efficiency of electronic voting. The three algorithms are employed by the proposed BCVS to safeguard and improve the electronic voting process via the utilization of smart contracts. These algorithms ensure the precise tabulation of results and establish a robust foundation for electronic voting by resolving disputes. The proposed approach ensures transparency, immutability, and a minimal likelihood of manipulation through the utilization of the prioritized delegated proof-of-stake (PDPoS) consensus mechanism. The PDPoS functions on Tier 3 scalable networks and diligently documents transactions on the blockchain to resolve critical challenges associated with electronic voting. The scalability and integrity of the proposed e-voting system are ensured through the implementation of a practical Byzantine fault tolerance algorithm. Improved voter authentication is accomplished by multi-factor authentication and elliptic curve digital signatures, reducing the dangers of unwanted access. Additionally, Nightshade sharding from the NEAR algorithm enhances scalability by partitioning the blockchain network into numerous smaller shards, facilitating parallel transaction processing. Consequently, throughput is markedly enhanced, and latency is diminished. The testing results indicate that the proposed BCVS achieves 100% confirmed transactions, 98% compatibility, 95% accuracy, and 95% audited votes. The proposed BCVS outperforms existing state-of-the-art systems in multiple essential domains, such as the volume of votes cast within a specified timeframe, precision, interoperability with other systems, quantity of confirmed transactions, auditability, and duration of vote counting.
The traditional voting process, whether paper-based or electronic, is often criticized for its lack of transparency, susceptibility to fraud, and dependence on centralized authorities. Blockchain technology, particularly in the Web3 ecosystem, provides a decentralized, secure, and tamper-proof solution for digital voting. This paper explores how blockchain can enhance election integrity by leveraging decentralized applications (DApps), smart contracts, and cryptographic security. The proposed system employs Ethereum-based smart contracts to automate vote casting and tallying while ensuring voter privacy through zero-knowledge proofs. Decentralized Identity (DID) is integrated for secure authentication, preventing double voting and identity fraud. The paper discusses system architecture, security considerations, scalability challenges, and real-world applications of blockchain voting, highlighting how Web3 can transform democratic elections.
Account-based anonymous blockchain systems can provide robust privacy protection for users. However, they become highly inefficient when handling high-frequency micro-payment scenarios. This paper presents systematic optimizations for batch processing and micro-payment transactions in account-based anonymous blockchain systems to enhance both privacy and efficiency. Building on BlockMaze, the first account-based anonymous blockchain system fully protecting transaction privacy, we propose innovations in batch transfers, batch receipts, and micro-payment handling. By reducing redundant data, improving circuit design, and optimizing zk-SNARK proof generation, we achieve up to 55.90% and 23.02% reductions in overall time consumption for batch transfers and receipts, respectively, significantly cutting computational cost and memory use. For micro-payments, a solution encapsulating the payment deadline reduces transaction delays and fund freezing. Experimental results show only slight increases in proof generation time—1.41 seconds for transfers and 1.02 seconds for payments—while maintaining privacy protection. This research lays a foundation for practical applications of account-based anonymous blockchain systems, enhancing privacy, processing efficiency, and transferability to other systems. • Optimized batch processing and improve transaction efficiency in account-based anonymous blockchain systems. • Optimized circuit design reduces redundant data and shortens zero-knowledge proof times. • Time consumption decreased by up to 55.90% in batch transfer function and 23.02% in batch receipt function. • Highly transferable to other account-based anonymous blockchain systems, offering strong flexibility and application potential. • Offers future research directions to improve blockchain efficiency and privacy protection.
Open access
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
The digitization of democratic processes promises greater accessibility but presents challenges in terms of security, privacy, and verifiability. Existing electronic voting systems often rely on centralized architectures, creating single points of failure and forcing too much trust in authorities, which contradicts democratic principles. This research addresses the challenge of creating a secure, private e-voting system with minimized trust dependencies designed for the most versatile personal device: the smartphone. We introduce SmartphoneDemocracy, a novel e-voting protocol that combines three key technologies: the emerging European Digital Identity (EUDI) Wallet for Sybil-resistant identity verification, Zero-Knowledge Proofs for privacy-preserving validation, and a peer-to-peer blockchain (TrustChain) for a resilient, serverless public bulletin board. Our protocol enables voters to register and cast ballots anonymously and verifiably directly from their smartphones. We provide a detailed protocol design, a security analysis against a defined threat model, and a performance evaluation demonstrating that the computational and network overhead is feasible for medium- to large-scale elections. By developing and prototyping this system, we demonstrate a viable path to empower citizens with a trustworthy, accessible, and user-controlled digital voting experience.
Transparency is one of the key benefits of public blockchains. However, the public visibility of transactions potentially compromises users' privacy. The fundamental challenge is to balance the intrinsic benefits of blockchain openness with the vital need for individual confidentiality. The proposal suggests creating a confidential version of wrapped Ethereum (cWETH) fully within the application layer. The solution combines the Elliptic Curve (EC) Twisted ElGamal-based commitment scheme to preserve confidentiality and the EC Diffie-Hellman (DH) protocol to introduce accessibility limited by the commitment scheme. To enforce the correct generation of commitments, encryption, and decryption, zk-SNARKs are utilized.
Encouraging just, secure, and open election processes is a fundamental aspect of any democratic culture. Traditional and even modern electronic voting systems are plagued by persistent issues like the failure to provide anonymity for voters, forgery risks, scalability, and the absence of verifiable trust. This paper proposes a blockchain-based digital voting framework designed to address these systemic limitations by leveraging distributed ledger technology and smart contracts. The proposed solution offers end-to-end verifiability, vote immutability, and decentralized auditing mechanisms through a mobile-accessible platform built on Ethereum using Solidity and Hardhat, with Node.js and React.js for frontend interfacing. Experimental results demonstrate improved system scalability, resistance to tampering, and support for remote voting, while maintaining ballot privacy and affordability. The research also evaluates key performance indicators under various test scenarios, establishing the system’s effectiveness and practical relevance in real-world electoral environments.
Open access
Blockchain Technology Applications and Security
Internet Traffic Analysis and Secure E-voting
Advanced Steganography and Watermarking Techniques
As interest in the practical use of cryptocurrencies continues to grow, so does the focus on the (perceived) privacy and anonymity of users within this domain. Despite this attention, there is a notable absence of standardized definitions for these terms. This article aims to address this gap by exploring the various interpretations of privacy, anonymity, and related concepts in the context of cryptocurrencies. Drawing from a thorough review of existing literature, we propose practical definitions for both privacy and anonymity. Utilizing these definitions, we introduce an ontology designed to streamline future research, identify knowledge gaps, and facilitate clearer communication in the field.
Open access
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
Data integrity in Smart Grids (SG) systems can be vulnerable with the implementation of the novel Community Blockchain-Driven Traceability Framework (CBDTF). It enhances Detection Rates (DR), maintains low End-to-End Delay (EED), and uses less energy by using distributed ledger technology and community-based validation. This model deployed a Delegated Proof of Stake (DPoS) consensus mechanism and community-driven testing, resulting in an average Detection Rate (DR) of 98.7% for Data Tampering attacks and a False Positive Rate (FPR) of 1.78%. It outperforms conventional Blockchain (BC) solutions with an EED of 120.8 ms and an average CPU utilization of 1,113 tx/kWh. When compared with conventional Proof-of-Work (PoW), CBDTF requires 60% less energy while proving 96.2% consensus resilience against distinct attacks. Applying real-world SG data collected by a distributed network of 100 nodes, the accuracy of this model was tested. The present study makes a valuable contribution to the field by signifying how BC platforms driven by the public can address SG's data security issues while maintaining the accuracy of real-time operations.
This paper presents the design and implementation of a decentralized electronic voting system based on a hybrid architecture that integrates the TRON blockchain with off-chain authentication mechanisms.The proposed solution employs smart contracts written in Solidity to record votes in an immutable and publicly auditable manner, while a backend service implemented in Node.js and a MySQL database handles voter authentication and enforces voter uniqueness.To prevent duplicate voting and ensure auditability, cryptographic hash functions are used to bind voter credentials and election parameters to each vote without exposing sensitive data on-chain.Experimental results demonstrate that the system effectively mitigates common security threats, such as duplicate voting and unauthorized data manipulation, while maintaining low transaction costs and practical usability.The findings indicate that the proposed hybrid approach provides a secure, transparent, and cost-effective alternative for electronic voting systems in real-world scenarios.
Software-Defined Networking (SDN) has revolutionized network administration with its unparalleled flexibility and programmability. The secure placement of controllers within a Software-Defined Networking framework remains a significant challenge. This research provides an innovative solution that integrates blockchain technology with the advanced reinforcement learning algorithm MuZero to optimize and secure the placement of SDN controllers. The suggested framework utilizes critical security parameters, including network latency, traffic volume, and the quantity of connected devices, to evaluate and record secure controller locations, employing Mininet for network emulation and OpenDaylight as the SDN controller. These criteria are essential for identifying secure deployment locations and assessing network efficacy. The suggested solution ensures the security and efficacy of controller placement in SDN systems by integrating blockchain technology for transparent and invulnerable documentation of secure locations.
In this framework, Blockchain-Integrated Access Control for Wireless Edge Networks intends to attempt authentication and authorization by using smart contracts and immutable ledgers making it secure and decentralized. It increases trust among edge nodes by connecting them, thereby creating a single point of failure, while providing transparent and tamper-resistant enforcement of policies, which improves scalability, resilience, and performance, ultimately making it the Mold for IoT and edge computing environments. The objectives that the system intends to apply towards are design and implement decentralized access control for wireless edge networks using Blockchain, to provide tamper-proof identity verification solutions, to ensure dynamic access policies enforced through smart contracts, to reduce dependency on central authorities, and also to increase security and privacy, scaling trust, and transparency in the distributed IoT and edge environments. The proposed system proposed to implement decentralized access control via private Blockchain in wireless edge networks. Smart contracts are crafted to dynamically facilitate identity authentication, access rights, and the enforcement of policies. Edge nodes interface with the Blockchain to verify credentials and log access attempts immutably. To curb latency and overhead, lightweight cryptography schemes and consensus algorithms such as PBFT are employed. Simulation in a wireless edge environment showed improvements in access request validation by 35%, unauthorized access attempts down by 42%, and improved scalability with respect to conventional centralized models, showing that the model is effectual and robust in secure access control.