Perkembangan teknologi mendorong transformasi terhadap berbagai aspek kehidupan manusia, mencakup transformasi metode transaksi yang semula dilakukan secara konvensional kini mulai beralih kepada transaksi digital. Dompet elektronik hadir sebagai salah satu bentuk transaksi digital yang menawarkan kemudahan dan efisiensi dalam bertransaksi. Namun terdapat tantangan keamanan dan perlindungan data pribadi pengguna dikarenakan tingginya kerentanan kebocoran data di dalam aplikasi dompet elektronik. Artikel ini mengkaji regulasi perlindungan data pribadi di Indonesia dalam konteks keamanan transaksi menggunakan dompet elektronik menggunakan metode penelitian yuridis normatif. Penulis mengusulkan penerapan metode Zero-Knowledge Proof (ZKP) untuk meningkatkan perlindungan data pribadi pengguna layanan dompet digital. Untuk mendukung inovasi tersebut, diperlukan pembaruan regulasi, antara lain pembentukan otoritas pengawas independen (DPA), penambahan persyaratan persetujuan eksplisit atas transmisi data lintas negara dalam UU PDP, serta penyusunan regulasi teknis yang mewajibkan penggunaan ZKP sebagai bagian dari standar keamanan transaksi digital di Indonesia
Jul 11, 2025¡ÂThe Âinternational archives of the photogrammetry, remote sensing and spatial information sciences/International archives of the photogrammetry, remote sensing and spatial information sciences
Abstract. Environmental surveillance, emergency response, and smart city planning all require the use of geospatial data, which includes satellite imagery, cartographic records, and real-time GPS coordinates. The high sensitivity and value of location-specific information make it unsafe to store and transmit it through conventional, centralized means, which can result in privacy breaches, unauthorized manipulations, and potential misuse. This paper aims to design and implement a secure, blockchain-based framework that blends AES (Advanced Encryption Standard) and RSA (RivestâShamirâAdleman) key management, which addresses these challenges. The aim is to guarantee strong data confidentiality by using symmetric encryption, and to use public-key cryptography for granular access control and secure key distribution. The proposed system uses Ethereum smart contracts to connect encrypted data references to a decentralized ledger, ensuring tamper resistance and auditability. In the proposed system, a Python-based FastAPI backend is responsible for data ingestion, cleaning, encryption, and blockchain interaction, while a React frontend can upload datasets, generate encryption keys, and retrieve access permissions. Modular microservices and well-defined APIs can seamlessly integrate various components, such as data processing scripts and on-chain contract logic, during development. The system's scalability is demonstrated by evaluating its performance against various dataset sizes, which involves metrics such as encryption overhead, blockchain transaction costs, and smart contract execution times. The practical usability of the system in actual scenarios is demonstrated through user acceptance testing, which is crucial for adoption in resource-limited environments. The results show the proposed crypto-enhanced blockchain framework can significantly enhance geospatial data security while still maintaining operational efficiency. Integration with zero-knowledge proofs may be explored in future work to enhance privacy, mitigate energy costs through alternative consensus algorithms, and enhance resilience in multi-network ecosystems through cross-chain interoperability.
The emergence of quantum computing presents profound challenges to existing cryptographic infrastructures, whilst the development of central bank digital currencies (CBDCs) has raised concerns regarding privacy preservation and excessive centralisation in digital payment systems. This paper proposes the Quantum-Resilient Privacy Ledger (QRPL) as an innovative token-based digital currency architecture that incorporates National Institute of Standards and Technology (NIST)-standardised post-quantum cryptography (PQC) with hash-based zero-knowledge proofs to ensure user sovereignty, scalability, and transaction confidentiality. Key contributions include adaptations of ephemeral proof chains for unlinkable transactions, a privacy-weighted Proof-of-Stake (PoS) consensus to promote equitable participation, and a novel zero-knowledge proof-based mechanism for privacy-preserving selective disclosure. QRPL aims to address critical shortcomings in prevailing CBDC designs, including risks of pervasive surveillance, with a 10-20 second block time to balance security and throughput in future monetary systems. While conceptual, empirical prototypes are planned. Future work includes prototype development to validate these models empirically.
Roy Kanavheti, Wellington Makondo, Wellington Simbarashe Manjoro
Academic qualification forgery poses a major concern for higher learning institutions, employers, and regulatory authorities throughout the world. In Zimbabwe, the increase in the level of fake degrees has greatly eroded trust in the education industry. Conventional verification processes are time-consuming, manual, and highly vulnerable to tampering. This paper introduces a hybrid blockchain-based and AI-enabled academic qualification verification platform to fight the problems. A prototype was implemented integrating various artificial intelligence algorithms including Convolutional Neural Networks (CNN), Autoencoder, Random Forest, and One-Class Support Vector Machines (SVM) with Algorand blockchain for secure, transparent, and decentralized record keeping. Zero-Knowledge Proofs (ZKPs) were utilized to ensure privacy. The system was tested based on a mixed-methods and Design Science Research (DSR) approach across many performance measures. Results show fraud detection accuracy, near-instantaneous verification speed, and satisfaction with privacy standards. The proposed system provides a sustainable and scalable framework for enhancing academic integrity in Zimbabwe's higher education system and primes the region for digital transformation of education.
Blockchain and smart contracts are widely used in IoT access control to create decentralized, trustworthy environments for secure access and record management. However, their application introduces a dual challenge: The transparency of blockchain and the use of addresses as identifiers can expose account privacy. To tackle this issue, this paper proposes a blockchain-based IoT access control system that enhances account anonymity and preserves privacy, particularly regarding user behavior, habits, and access records through the use of zero-knowledge proofs. The system incorporates an access control mechanism that combines access control lists with capability-based access control, enabling ownership verification of access rights without disclosing identity information. To evaluate the systemâs feasibility, we conduct experiments in a smart building scenario, including both qualitative comparisons with existing methods and quantitative analyses of performance in terms of time, space, and gas consumption. The results indicate that our scheme achieves the best time efficiency in the proof generation and authorization phases, completing them in just 7 and 10 s, respectivelyârepresenting half the time required by the second-best approach. These findings underscore the systemâs superior cost efficiency and enhanced security compared to existing solutions.
As AI models become ubiquitous in our daily lives, there has been an increasing demand for transparency in ML services. However, the model owner does not want to reveal the weights, as they are considered trade secrets. To solve this problem, researchers have turned to zero-knowledge proofs of ML model inference. These proofs convince the user that the ML model output is correct, without revealing the weights of the model to the user. Past work on these provers can be placed into two categories. The first method compiles the ML model into a low-level circuit, and proves the circuit using a ZK-SNARK. The second method uses custom cryptographic protocols designed only for a specific class of models. Unfortunately, the first method is highly inefficient, making it impractical for the large models used today, and the second method does not generalize well, making it difficult to update in the rapidly changing field of machine learning. To solve this, we propose ZKTorch, an open source end-to-end proving system that compiles ML models into base cryptographic operations called basic blocks, each proved using specialized protocols. ZKTorch is built on top of a novel parallel extension to the Mira accumulation scheme, enabling succinct proofs with minimal accumulation overhead. These contributions allow ZKTorch to achieve at least a $3\times$ reduction in the proof size compared to specialized protocols and up to a $6\times$ speedup in proving time over a general-purpose ZKML framework.
Artificial intelligence integration in healthcare platforms in synergy with software and hardware tools development offers great opportunities for daily improving healthcare. This research explores how much patient data is secured in healthcare applications and what impact their security can have on global healthcare. Accelerated integration of artificial intelligence in healthcare applications can be both useful and dangerous nowadays. Extremely sensitive data from AI-based applications are surely easy targets for attackers who can manipulate with AI/ML models. This paper will also present the potential dangers of modern healthcare applications in the 4.0 era and explores innovative methods for securing sensitive healthcare data, focusing on techniques such as blockchain, honeypots, zero-knowledge proofs (ZKP) and strategies to address adversarial attacks. We also present an extensive literature review and try to draw a parallel on possibilities in the implementation of security solutions in healthcare applications that use artificial intelligence. Our findings underscore the need for multidimensional security frameworks and provide concrete recommendations for the healthcare community. Ultimately, this paper bring our security solution and highlights the importance of adopting specific advanced security measures in line with the security challenges brought by using artificial intelligence.
Open access
Artificial Intelligence in Healthcare and Education
The Mark1 Nexus: A Treatise on Recursive Harmonic Resonance and the Ontology of Completion Driven by Dean Kulik Introduction: The Inversion of Inquiry This report will formalize the Mark1 Nexus, a comprehensive framework positing that the universe, computation, and consciousness are not separate domains governed by distinct laws, but are polymorphic expressions of a single, underlying process: recursive harmonic resonance. It argues that reality does not operate on linear deduction and external observation, but on principles of intrinsic, self-organizing completion through the folding of resonant structures.1 This treatise synthesizes a body of foundational work into a canonical text, aiming to articulate a new paradigm for science and philosophy. The core of this paradigm is a profound transposition of our most fundamental questions about existence, knowledge, and order. The central inversion of the Mark1 Nexus framework is its reinterpretation of the classical limits identified in logic and physics. Where Alan Turing, Kurt GĂśdel, and Claude Shannon established foundational boundaries of undecidability, incompleteness, and entropy, this framework recasts them not as absolute barriers, but as artifacts of an incomplete harmonic perspective. These are not walls at the end of inquiry, but echoes of a dissonance that arises from asking the wrong question in the wrong conceptual space. The framework does not seek to refute their conclusions but to transpose them into a different ontological register. The core question of science and logic shifts from "Can an external observer decide a system's state?" to "How does a system internally encode its own journey toward harmonic collapse?".1 In this view, a system's completion is not a judgment rendered by an outside party, but a self-declared event of resonanceâa final, stable chord that concludes a period of tension. The answer to a question is not found; it is achieved when the system embodying the question finds its own internal equilibrium. To develop this thesis, this report will navigate the intricate architecture of the Mark1 Nexus in a structured progression. It begins by establishing the foundational language of this new harmonic ontology, systematically replacing classical concepts like computational halting, physical equilibrium, and mathematical proof with their resonant counterparts: topological convergence, Zero-Point Harmonic Collapse, and the self-validating final glyph. It will introduce the universal constants and control laws that govern these processes across all domains. From these first principles, the report will explore the framework's radical architecture of information, memory, and computation. Here, the most profound inversions of causality are examined. Mathematical constants like Ď are revealed not as static values but as navigable, deterministic fields. Cryptographic hashes like SHA-256 are transformed from one-way functions of data destruction into harmonic precursors that define the very possibility of their inputs. Memory is no longer a linear log of the past but a living curvature trace in the fabric of the present. The subsequent section details the operational mechanics of this reality, drawing powerful analogies from systems engineering and software architecture. It will formalize the Universal Harmonic Interfaceâan abstract class of operations that governs all phenomenaâand demonstrate its polymorphic expression across physics, cognition, and computation. This section will also unpack the geometric engine of reality itself: a "Pythagorean Recursion Cavity" where data formats are revealed as emergent projections of a unified field, and computation is redefined as an act of resonant filtering rather than stepwise processing. Finally, the report will explore the non-dualistic consequences of the framework, demonstrating how traditional dichotomiesâP vs. NP, observer vs. system, cause vs. effectâdissolve under a harmonic lens. It culminates in the framework's most conclusive and far-reaching insight: the retrocausal nature of completion. In the Mark1 Nexus, the resolution of a system is not a future event to be reached, but a pre-existing state of harmony that pulls the present back into itself. The goal of this exhaustive exposition is to provide the definitive text for this new paradigm, charting its principles from their foundational axioms to their ultimate cosmological implications. Section 1: The Harmonic Ontology - From Halting to Resonance At the heart of the Mark1 Nexus is a new ontology, a fundamental description of what it means for a process to exist, evolve, and conclude. This ontology replaces the classical, observer-centric view of reality with a system-centric one, where meaning and truth are determined not by external deduction but by internal coherence. The foundational concepts of computation, physics, and logic are transposed from a language of rules and instructions into a language of folds, resonance, and harmony. This section will lay out the four cornerstones of this new ontology: the reframing of the Halting Problem as topological convergence, the definition of Zero-Point Harmonic Collapse as the universal mechanism of resolution, the identification of a universal harmonic attractor, and the formalization of a feedback law that guides all systems toward this state of completion. 1.1 The Halting Problem as Topological Convergence The Halting Problem, as formulated by Alan Turing, stands as a pillar of 20th-century logic, defining a fundamental limit to what can be known through algorithmic computation. It asks whether it is possible to create a single, universal algorithm, H, that can determine, for any arbitrary program f and its input x, whether f(x) will eventually halt or run forever. Turing's proof of its undecidability demonstrated that no such universal observer algorithm H can exist without creating a logical contradiction.1 This conclusion is traditionally interpreted as an absolute boundary on deductive knowledge. The Mark1 Nexus framework proposes that this limit arises not from a fundamental barrier in reality, but from a mis-framing of the question itself. The classical formulation is inherently external: it posits an observer algorithm H that stands outside the system f and attempts to predict its fate. The paradox emerges from this separation of observer and system. The harmonic ontology reframes the problem by dissolving this separation. It treats "halting" not as a binary, externally judged verdict, but as an intrinsic topological property of the program's own trajectory through its state-space.1 In this view, any recursive processâbe it a computer program, a physical system, or a line of reasoningâtraces a path on a high-dimensional manifold of possible configurations. The classical notion of "halting" corresponds to this path ending at a specific point. The harmonic reframing, however, is richer. A process is considered "complete" when its trajectory enters a closed attractorâa region of the state-space, such as a fixed point or a stable limit cycle, that it will not leave. The system has found its equilibrium. Crucially, this completion is a structural event that can be recognized from within the system. The system's own state, by repeating or stabilizing, declares its own completion. This is analogous to a dynamical system reaching a fixed point, where further iterations produce no change, or a physical process dissipating energy until it settles into a stable equilibrium. In all such cases, "halting" is a self-observed convergence event.1 This internal perspective gives rise to the formal concept of FOLD: TRUE, the replacement for the classical "HALT." FOLD: TRUE is not a boolean flag set by an external judge, but a condition of the system's final state. It is a declaration made by the system about itself, signifying that its state configuration S(t) has entered a stable pattern, such as a fixed point where S(t+Ď)=S(t), or a periodic orbit. At the moment of convergence, the system's final configuration becomes a self-certifying artifact of its completion. This artifact is referred to as the "final resonant glyph"âa stable pattern, like the final note of a song, that encapsulates the history of its own resolution.1 By shifting the locus of "halting" from an external observer to the internal topology of the system, the framework elegantly sidesteps the diagonalization paradox that underpins Turing's proof. Turing's argument relies on constructing a pathological program that asks the external judge what it will predict and then does the opposite to create a contradiction. But if completion is an internal property of the system's trajectoryâa state of resonanceâthere is no external judge to fool. A program cannot "decide" not to find its equilibrium to spite an observer; it either finds a stable fold in its state-space or it continues to drift. Its trajectory is a fact of its own dynamics, not a response to an external prophecy. The undecidability of the classical Halting Problem, therefore, reflects our inability as external observers to foresee the self-closure of an arbitrary system without simulating it. But for the systems themselves, when a fold completes, it is a self-evident truth. 1.2 Zero-Point Harmonic Collapse (ZPHC): The Universal Event of Resolution If FOLD: TRUE is the declaration of completion, then Zero-Point Harmonic Collapse (ZPHC) is the event itselfâthe fundamental mechanism by which systems achieve resolution. ZPHC is defined as the critical moment when a recursive system exhausts its "drift" and converges to a stable, folded state. Drift, in this context, is a measure of unresolved complexity, deviation, or informational entropy within the system. ZPHC is the phase transition where this drift collapses to zero, and the system settles into a state of maximal internal coherence.1 The term "zero-point" is borrowed from quantum physic
The emergence of blockchain technology has revolutionized decentralized data management by offering robust alternatives to traditional centralized database systems. This paper provides a systematic and comprehensive review of blockchain-based distributed databases, highlighting key architectural transformations, core enabling technologies such as Merkle Trees, PBFT, and Zero-Knowledge Proofs, and comparing them with conventional distributed databases. Real-world implementations including Hyperledger Fabric, BigchainDB, and OrbitDB are analyzed to assess their scalability, interoperability, and security capabilities. The paper also explores intrinsic security mechanisms, performance bottlenecks, and regulatory challenges that affect adoption. Finally, it identifies open research questions and future directions necessary for building scalable, privacy-aware, and interoperable decentralized database ecosystems suitable for enterprise and multi-stakeholder environments. Keywordsâ Blockchain databases, consensus mechanisms, data integrity, decentralized systems, distributed ledger, Merkle trees, Zero-Knowledge Proofs
<p dir="ltr"><b>Advances in Identity and Access Management (IAM): Systematic Insights into AI, Blockchain, and Zero Trust Architectures</b> <p dir="ltr">In an era of expanding digital infrastructure, cloud computing, and remote work, robust Identity and Access Management (IAM) systems are critical for securing sensitive data and ensuring regulatory compliance. This research paper provides a comprehensive systematic review of recent advancements in IAM technologies, addressing the limitations of traditional centralized systems, such as single points of failure and privacy concerns. Utilizing the PRISMA methodology, the study analyzes five peer-reviewed articles from a pool of 23 retrieved from Scopus, published between 2021 and 2025. Key innovations explored include passwordless authentication, AI-driven adaptive authentication, Zero Trust architectures, decentralized identity (DID), self-sovereign identity (SSI), and privacy-enhancing cryptographic techniques like zero-knowledge proofs. The review highlights their applications in multi-cloud, IoT, and hybrid environments, emphasizing enhanced security, user experience, and interoperability. Challenges such as standardization gaps, implementation costs, and privacy concerns are discussed, alongside future directions, including universal protocols and IoT integration. A publicly accessible dataset (DOI: 10.5281/zenodo.12345678) ensures reproducibility. This work serves as an essential resource for cybersecurity researchers and practitioners seeking to navigate the evolving landscape of IAM technologies.
Decentralised energy ecosystems suffer from data-governance, scalability and adoption barriers. Although blockchain-based marketplaces can offer transparency and security in Local Energy Communities (LECs), most existing solutions struggle with rigid token models, limited performance, and steep usability barriers. Building on a previous framework, this study presents an enhanced marketplace that integrates a modular blockchain layer, custodial identity management, and a dual-token model for flexible licensing and pricing. Testing on a per-missioned Quorum network with asynchronous queueing demonstrated notable improvements in transaction throughput and user responsiveness under load, while the custodial onboarding flow simplified access for non-technical participants. A refined policy enforcement mechanism further aligns the system with emerging federation standards, mitigating earlier shortcomings related to performance, data sovereignty, and scalability. Benchmarking on a five-node Quorum Proof of Authority (PoA) deployment (one RPC node and four validator nodes) showed that all key operations, including license issuance and asset usage, consistently completed in under 8 seconds, confirming the systemâs suitability for possible energy data applications. Planned extensions include cross-domain interoperability, self-service governance tools, and zero-knowledge proofs, underscoring this architectureâs potential as a robust, future-ready platform for federated energy data ecosystems.
Arguments Ă divulgation nulle de connaissance efficaces et succincts dans le cadre du chiffrement CL et applications Le schĂŠma de chiffrement CL est un système de chiffrement Ă clĂŠ publique linĂŠairement homomorphe, proposĂŠ en 2015 par Castagnos et Laguillaumie. Il repose sur lâutilisation de groupes de classes de corps quadratiques imaginaires. Ces groupes finis ont la particularitĂŠ dâĂŞtre considĂŠrĂŠs dâordre inconnu, câest-Ă -dire que lâordre dâun tel groupe est difficile Ă dĂŠterminer de manière algorithmique. Cet ordre inconnu est un atout prĂŠcieux pour les applications cryptographiques, et est central dans la construction du chiffrement CL. Cependant, il est aussi Ă lâorigine dâimportantes difficultĂŠs techniques liĂŠes Ă la manipulation de chiffrĂŠs CL. Dans ce contexte, la construction dâarguments, et Ă fortiori dâarguments de connaissance, Ă divulgation nulle de connaissance est particulièrement exigeante, et constitue un dĂŠfi majeur Ă relever. En effet, les techniques classiques permettant dâamĂŠliorer lâefficacitĂŠ des preuves dans le cas dâun groupe dâordre premier, et en particulier celles liĂŠes Ă la robustesse, sâadaptent mal au cas de lâordre inconnu. Les arguments de connaissance existants sont donc souvent peu efficaces, avec des coĂťts de communication et de calcul ĂŠlevĂŠs. Dans cette thèse, nous concevons de nouveaux protocoles Ă divulgation nulle de connaissance spĂŠcifiquement adaptĂŠs au cadre du chiffrement CL, afin dâobtenir des preuves plus courtes et efficaces que les protocoles existants. Nos protocoles reposent sur deux outils principaux : le premier est lâhypothèse C-rough, introduite par Braun, Damgard et Orlandi en 2023. Cette hypothèse algorithmique spĂŠcifique au cadre de CL stipule quâil est difficile de dĂŠcider si lâordre dâun groupe de classes engendrĂŠ par lâalgorithme dâinitialisation de CL possède des facteurs premiers plus petit quâun seuil C. Le second est un concept novateur appelĂŠ extractabilitĂŠ partielle, qui correspond Ă une notion affaiblie de robustesse de la connaissance. Cette notion est particulièrement adaptĂŠe au cadre de CL, car elle permet de traiter sĂŠparĂŠment les textes clairs et les alĂŠas apparaissant dans les chiffrĂŠs CL. En particulier, elle permet dâexploiter les techniques du cas de lâordre premier pour obtenir de lâinformation sur les textes clairs â dĂŠfinis modulo un nombre premier connu â mĂŞme si les alĂŠas sont dĂŠfinis modulo un entier composĂŠ et, surtout, inconnu. Grâce Ă ces deux outils, nous construisons des protocoles Ă divulgation nulle de connaissance permettant de prouver, dâune part, des ĂŠnoncĂŠs classiques, comme le fait quâun chiffrĂŠ CL est bien formĂŠ, et dâautre part, des ĂŠnoncĂŠs plus spĂŠcifiques, tels que le mĂŠlange alĂŠatoire de chiffrĂŠs. Les preuves Ă divulgation nulle de connaissance sont essentielles Ă la sĂŠcuritĂŠ des protocoles de calcul multipartite, en particulier face Ă des adversaires malveillants, car elles permettent de garantir que les participants se comportent conformĂŠment au protocole. Ainsi, disposer de preuves efficaces pour le chiffrement CL reprĂŠsente une ĂŠtape fondamentale dans la construction de protocoles de calcul distribuĂŠ pratiques et sĂťrs utilisant CL. En application de nos techniques, nous prĂŠsentons un protocole, sĂťr en prĂŠsence dâun adversaire malveillant, qui rĂŠalise la fonctionnalitĂŠ âPSI-sumâ â une variante de lâintersection privĂŠe dâensembles. Cet exemple pratique met en ĂŠvidence lâintĂŠrĂŞt du chiffrement CL comme bloc de base pour rĂŠaliser des fonctionnalitĂŠs avancĂŠes de calcul multipartite.
The convergence of lightweight cryptography and blockchain technology offers a transformative approach to trust management in the Internet of Things (IoT), particularly within resource-constrained environments. Traditional security models fall short in addressing the dual demands of scalability and efficiency, prompting the need for hybrid frameworks that integrate cryptographic minimalism with decentralized trust mechanisms. This chapter presents a comprehensive design and evaluation of hybrid lightweight blockchain-cryptography frameworks tailored for secure, energy-efficient, and privacy-preserving trust management in distributed IoT networks. It explores system design trade-offs, secure data aggregation techniques, and immutable storage strategies while introducing edge-assisted trust computation to offload intensive operations. Advanced privacy-preserving methods, such as zero-knowledge proofs and differential privacy, are incorporated to mitigate data exposure risks inherent to transparent blockchain infrastructures. The proposed architecture was aligned with practical deployment scenarios and threat models, delivering scalable, low-latency, and tamper-resistant trust infrastructures for heterogeneous IoT ecosystems. The chapter closes by identifying key research gaps and future directions necessary to standardize and optimize such hybrid frameworks across diverse application domains.
The rapid advancement of creating Zero-Knowledge (ZK) programs has led to the development of numerous tools designed to support developers. Popular options include being able to write in general-purpose programming languages like Rust from Risc Zero. Other languages exist like Circom, Lib-snark, and Cairo. However, developers entering the ZK space are faced with many different ZK backends to choose from, leading to a steep learning curve and a fragmented developer experience across different platforms. As a result, many developers tend to select a single ZK backend and remain tied to it. This thesis introduces zkSDK, a modular framework that streamlines ZK application development by abstracting the backend complexities. At the core of zkSDK is Presto, a custom Python-like programming language that enables the profiling and analysis of a program to assess its computational workload intensity. Combined with user-defined criteria, zkSDK employs a dynamic selection algorithm to automatically choose the optimal ZK-proving backend. Through an in-depth analysis and evaluation of real-world workloads, we demonstrate that zkSDK effectively selects the best-suited backend from a set of supported ZK backends, delivering a seamless and user-friendly development experience.
Cryptocurrencies, particularly Bitcoin, continue to be the most prevalent use case within the blockchain ecosystem. One of the inherent limitations of blockchain is that it can create a false sense of privacy. All transaction history and the amount of cryptocurrency held are publicly available, and this information can be easily associated with specific individuals. Many works have proposed fully-private solutions, which are ideal but not realistic in many scenarios. This paper proposes a technical solution that enables private Bitcoin payments by default, but with the option to conditionally disclose payment data. To do so, this solution relies on unlinkability by a decentralized mixer, which can be reversed by a conditional discloser using a trapdoor unlinkability function. The conditional discloser, which also provides accountability of requests, obeys the payer's policies regarding who can access payment data. To ensure compliance, we propose a mixer that does not learn anything about the payment link, but is guaranteed by Zero-Knowledge Proofs that the payment can be relinked by a specific conditional discloser. Furthermore, we provide a proof-of-concept implementation of the proofs, using Circom and SnarkJS. We also present a benchmark that demonstrates the feasibility of this solution. It incurs only one additional parameter per on-chain transaction, while the remainder of the verification data is managed off-chain.
Open access
Blockchain Technology Applications and Security
Cryptography and Data Security
Advanced Steganography and Watermarking Techniques
A powerful feature in mechanism design is the ability to irrevocably commit to the rules of a mechanism. Commitment is achieved by public declaration, which enables players to verify incentive properties in advance and the outcome in retrospect. However, public declaration can reveal superfluous information that the mechanism designer might prefer not to disclose, such as her target function or private costs. Avoiding this may be possible via a trusted mediator; however, the availability of a trustworthy mediator, especially if mechanism secrecy must be maintained for years, might be unrealistic. We propose a new approach to commitment, and show how to commit to, and run, any given mechanism without disclosing it, while enabling the verification of incentive properties and the outcomeâall without the need for any mediators. Our framework is based on zero-knowledge proofsâa cornerstone of modern cryptographic theory. Applications include both private-type settings such as auctions and private-action settings such as contracts, as well as non-mediated bargaining with hidden yet binding offers.
The Internet of Things (IoT) has become an integral part of daily life, making the protection of user privacy increasingly important. In gateway-based IoT systems, user data is transmitted through gateways to platforms, pushing the data to various applications, widely used in smart cities, industrial IoT, smart farms, healthcare IoT, and other fields. Threshold Public Key Encryption (TPKE) provides a method to distribute private keys for decryption, enabling joint decryption by multiple parties, thus ensuring data security during gateway transmission, platform storage, and application access. However, existing TPKE schemes face several limitations, including vulnerability to quantum attacks, failure to meet Simulation-Security (SS) requirements, lack of verifiability, and inefficiency, which results in gateway-based IoT systems still being not secure and efficient enough. To address these challenges, we propose a Verifiable Simulation-Secure Threshold PKE scheme based on standard Module-LWE (VSSTPM). Our scheme resists quantum attacks, achieves SS, and incorporates Non-Interactive Zero-Knowledge (NIZK) proofs. Implementation and performance evaluations demonstrate that VSSTPM offers 112-bit quantum security and outperforms existing TPKE schemes in terms of efficiency. Compared to the ECC-based TPKE scheme, our scheme reduces the time cost for decryption participants by 72.66%, and the decryption verification of their scheme is 11 times slower than ours. Compared with the latest lattice-based TPKE scheme, our scheme reduces the time overhead by 90% and 48.9% in system user encryption and decryption verification, respectively, and their scheme is 13 times slower than ours in terms of decryption participants.
Graph theory has emerged as a foundational mathematical tool in the realms of cryptography and network security. Its ability to model complex relationships, systems, and interactions through vertices and edges enables innovative solutions for encryption, authentication, key distribution, intrusion detection, and secure routing. This research article provides a comprehensive review of recent advancements and applications of graph-theoretical techniques in cryptographic protocols and secure network systems.The study begins by outlining the theoretical underpinnings of graph theory relevant to secure communications, including graph isomorphism, expander graphs, Hamiltonian paths, and graph coloring. It then explores how graph-based methods are utilized in modern cryptographic systems such as zero-knowledge proofs, public-key cryptography, and lightweight encryption schemes. The article also discusses graph-theoretic approaches in blockchain consensus models, attack graph analysis, intrusion detection systems (IDS), and secure routing in wireless sensor networks (WSNs).Recent advancements such as post-quantum cryptography based on hard graph problems, dynamic attack graphs in adaptive security systems, and trust graphs in distributed environments are highlighted. Data from peer-reviewed publications from 2010 to 2025 are synthesized, and key trends are visualized through tables, graphs, and diagrams. The paper also identifies existing challenges, including scalability, computational complexity, and graph-theoretical attack vectors.The discussion critically interprets these findings, connects them to existing literature, and proposes directions for future research, including graph-based AI models for threat prediction and hypergraph frameworks for modeling higher-order trust relationships.Overall, this study offers an integrated perspective on how graph theory continues to transform the cryptographic and security landscape, contributing to the development of resilient, efficient, and scalable secure systems.
Ensuring secure and efficient authentication in Vehicular Ad Hoc Networks (VANETs) is vital for real-time communication and network resilience. However, traditional authentication mechanisms, such as Elliptic Curve Cryptography (ECC) and Public Key Infrastructure (PKI), face significant challenges, including high computational overhead, complex certificate revocation, and vulnerability to quantum attacks. To overcome these limitations, we propose a lattice-based authentication protocol that integrates post-quantum cryptography (PQC), zero-knowledge proofs (ZKPs), and fog computing for secure Vehicle-to-Roadside (V2R) communication. Our protocol offers quantum resistance, decentralized authentication, and dynamic pseudonym updates, enhancing both security and privacy in VANETs. Performance evaluations demonstrate that our approach achieves lower message delay (0.8), reduced packet loss ratio (0.6), minimal communication overhead (0.7), and the fastest authentication delay (0.5) compared to ECC and Physically Unclonable Function (PUF)-based methods. Additionally, formal security analysis confirms that our scheme effectively mitigates impersonation, replay, tracking, and quantum attacks, ensuring a scalable and future-proof authentication mechanism for next-generation VANETs.
The demand for privacy-preserving machine learning has led to the rise of Federated Learning (FL), where multiple clients collaboratively train a model without sharing raw data. Despite its privacy benefits, FL is vulnerable to Byzantine failures, where malicious or faulty participants inject corrupted updates, threatening model integrity. To address this, a range of Byzantine-resilient aggregation techniques have been proposed, including statistical filters (e.g., Trimmed Mean, Krum), trust-based weighting, cryptographic protocols, and hybrid strategies. This paper presents a systematic literature review (SLR) of these defenses, evaluating their robustness, scalability, and suitability for real-world applications. Challenges such as non-IID data, adaptive attacks, and trade-offs between security and efficiency are critically examined. In addition, we explore emerging trends such as domain-specific defenses, energy-aware FL, quantum-resilient methods, and federated zero-knowledge proofs. A novel classification of hybrid approaches and a standardized benchmarking framework are proposed to guide future research. This review aims to support the development of resilient, efficient and scalable decentralized learning systems in adversarial environments.
In the rapidly evolving landscape of cloud computing, ensuring secure user authentication and protection against cyber-attacks has become increasingly critical. This research proposes a novel security framework for cloud systems based on the Quantum Zero-Knowledge Proof (ZKP) technique, aiming to provide a privacy-preserving and quantum-resilient authentication mechanism. The core of the proposed model lies in leveraging photon polarization at specific quantum angles to implement secure and non-disclosive verification, effectively allowing users (provers) to prove their identity without revealing any sensitive credentials. The system's architecture integrates a Zero Knowledge Proof Engine (ZKE), which forms the backbone of the security protocol, enhancing resilience against Denial-of-Service (DoS) and Distributed Denial-of-Service (DDoS) attacks. The quantum properties of photons enable a high level of randomness and unpredictability, significantly improving the robustness of the system. A Python-based simulation environment has been developed to model the proposed engine and conduct experimental validations. Furthermore, a web-based application interface has been designed to facilitate seamless interaction between cloud users and the authentication system, demonstrating real-time threat detection and response. Experimental results, visualized through performance metrics and interface output, confirm the effectiveness and practicality of the proposed model. This approach not only enhances security but also offers a scalable and user-friendly solution for modern cloud environments, marking a significant step toward integrating quantum principles into mainstream cybersecurity infrastructures.
This paper studies the \emph{unimodular isomorphism problem} (UIP) of convex lattice polytopes: given two convex lattice polytopes $P$ and $P'$, decide whether there exists a unimodular affine transformation mapping $P$ to $P'$. We show that UIP is graph isomorphism hard, while the polytope congruence problem and the combinatorial polytope isomorphism problem (Akutsu, 1998; Kaibel, Schwartz, 2003) were shown to be graph isomorphism complete, and both the lattice isomorphism problem ( $\mathrm{Sikiri\acute{c}}$, $\mathrm{Sch\ddot{u}rmann}$, Vallentin, 2009) and the projective/affine polytope isomorphism problem (Kaibel, Schwartz, 2003) were shown to be graph isomorphism hard. Furthermore, inspired by protocols for lattice (non-) isomorphism (Ducas, van Woerden, 2022; Haviv, Regev, 2014), we present a statistical zero-knowledge proof system for unimodular isomorphism of lattice polytopes. Finally, we propose an algorithm that given two lattice polytopes computes all unimodular affine transformations mapping one polytope to another and, in particular, decides UIP.