A novel identity management concept known as decentralized identity (or self-sovereign identity) has drawn significant interest and extensive development within both academic and industrial circles. Decentralized oracles empower users to demonstrate the origin of data accessed through TLS from a specific website and verify statements concerning that data. This system operates without the reliance on trusted hardware or requiring modifications on the server side. In DECO (CCS 2020), the first decentralized oracle within TLS 1.2 was introduced. It also investigates the methodology of optionally proving statements about this data in a zero-knowledge setting, preserving the confidentiality of the data itself. Furthermore, a separate study proposed an attribute-based anonymous credential system incorporating a commitment scheme (ASIACRYPT 2020), introducing show proofs to verify a set of attributes in a credential to verifiers without disclosing attribute specifics. Building upon these research findings, this thesis presents a series of optimizations and expansions aimed at advancing self-sovereign identity solutions. First, we present DIDO and DIDO+ (decentralized identification oracle), which expands DECO to TLS 1.3. In DIDO, we address several unresolved challenges, encompassing the incorporation of X25519 key exchange, the creation of a round-optimal three-party key exchange, the structuring of a 2PC system for TLS 1.3 key scheduling, and the optimization of circuit design for 2PC protocols. Furthermore, we expand upon DIDO to create DIDO+, which introduces a protocol named selective disclosure. This protocol facilitates the extraction of particular plaintext substrings from websites, enhancing the functionality and flexibility of the system. Our implementation is verified against real-world websites, and a security proof is furnished to validate its integrity. Next, we introduce DEVS (decentralized verification service), the first generic decentralized verification service built on a decentralized oracle. DEVS enhances the traditional single-verifier oracle by incorporating a multi-verifier mechanism. Our aim is to streamline the protocol for reduced communication and computation costs while enabling reusable proofs and maintaining security. DEVS comprises three key components: a reconstructed decentralized oracle to bolster data trust, secure storage for share retention, and a verification process tailored to the needs of verifiers and authorities. Considering 10 verifiers, the reconstruction reduces the running time (approximately 89.1% or 89.6%) in WAN settings and communication bandwidth (approximately 89.1% or 87.8%) of TLS 1.2 or 1.3, it provides a significant improvement when working with multiple verifiers. Lastly, we introduce a unified attribute-based anonymous credential system where users consistently receive credentials in a standardized format from the issuer. This system allows users to opt for efficient multi-use or single-use show proofs, offering a more user-centric perspective compared to current schemes. Technically, we suggest an interactive method for the credential issuance protocol utilizing two-party computation with additive homomorphic encryption. This approach maintains crucial security features such as impersonation resilience, anonymity, and unlinkability. In addition to the interactive protocol, we develop show proofs tailored for efficient single-use credentials that uphold user anonymity throughout the process.
Delaram Kahrobaei, Ludovic Perret, Martina Vigorito
Abstract Bidoux and Gaborit introduced a new general technique to improve zero-knowledge ( ZK ) proof-of-knowledge ( PoK ) schemes for a large set of well-known post-quantum hard computational problems such as the syndrome decoding, the permuted kernel, the rank syndrome decoding, and the multivariate quadratic ( MQ ) problems. In particular, the authors’ idea in the study of Bidoux and Gaborit was to use the structure of these problems in the multi-instance setting to minimize the communication complexity of the resulting ZK PoK schemes. The security of the new schemes is then related to new hard problems. In this article, we focus on the new multivariate-based ZK PoK and the corresponding new underlying problem: the so-called <m:math xmlns:m="http://www.w3.org/1998/Math/MathML"> <m:msub> <m:mrow> <m:mi mathvariant="monospace">DiffMQ</m:mi> </m:mrow> <m:mrow> <m:mi mathvariant="normal">H</m:mi> </m:mrow> </m:msub> </m:math> {{\mathtt{DiffMQ}}}_{{\rm{H}}} . We present a new efficient probabilistic algorithm for solving the <m:math xmlns:m="http://www.w3.org/1998/Math/MathML"> <m:msub> <m:mrow> <m:mi mathvariant="monospace">DiffMQ</m:mi> </m:mrow> <m:mrow> <m:mi mathvariant="normal">H</m:mi> </m:mrow> </m:msub> </m:math> {{\mathtt{DiffMQ}}}_{{\rm{H}}} which is polynomial-time if <m:math xmlns:m="http://www.w3.org/1998/Math/MathML"> <m:mi>m</m:mi> <m:mo>−</m:mo> <m:mi>n</m:mi> <m:mo>∈</m:mo> <m:mi>O</m:mi> <m:mrow> <m:mo>(</m:mo> <m:mrow> <m:mn>1</m:mn> </m:mrow> <m:mo>)</m:mo> </m:mrow> </m:math> m-n\in O\left(1) . We also present experimental results showing that the algorithm is efficient in practice.
Este trabajo de Fin de Grado pretende abordar los desafíos y oportunidades relacionados con la privacidad y el anonimato en la adopción de Monedas Digitales de banco Central (CBDC), con un enfoque particular en el Euro Digital (Moneda Digital propuesta por el Banco Central Europeo (BCE)). Las CBDC representan una innovación disruptiva en el sistema financiero tal y como lo conocemos, ofreciendo una visión alternativa al efectivo tradicional, teniendo un impacto considerable en la privacidad de los usuarios, la transparencia financiera y el marco regulatorio vigente. En el contexto del creciente interés global en las CBDC, el Banco Central Europeo busca equilibrar la protección de datos personales y la transparencia financiera en un sistema que pueda transformar la dinámica del sistema financiero europeo. El objetivo de este trabajo es analizar como las CBDC pueden ser diseñadas e implementadas para maximizar los beneficios, tratando de mitigar los riesgos asociados a la privacidad y transparencia financiera. Los objetivos específicos incluyen: 1. Examinar el concepto y evolución de las CBDC. 2. Identificar desafíos y oportunidades relacionadas con la privacidad y el anonimato. 3. Analizar el marco regulatorio europeo aplicable al Euro Digital. 4. Comparar diseños alternativos de CBDC con énfasis en privacidad. 5. Proponer recomendaciones que equilibren privacidad y transparencia. 6. Explorar y analizar casos de uso alternativos que preserven el anonimato en las operaciones. En este trabajo se lleva a cabo un análisis exhaustivo del impacto de las CBDC en la privacidad de los usuarios, teniendo en cuenta diferentes factores como la tecnología empleada, las políticas regulatorias y las expectativas sociales. Se hace especial énfasis en el desafío de proteger los datos personales de los usuarios en un entorno digital que exige constantemente un alto grado de trazabilidad y cumplimiento normativo. También se explora cómo otras jurisdicciones han abordado estos retos, analizando casos concretos como el yuan digital en China o proyectos piloto en países nórdicos, con el objetivo de identificar lecciones aprendidas y diferentes estrategias aplicables al marco europeo. Además, se investiga acerca de innovaciones tecnológicas como los sistemas de privacidad de conocimiento cero (zero-knowledge proofs) y su utilidad para proteger la identidad el usuario sin comprometer la transparencia. Finalmente se proponen una serie de recomendaciones para el diseño e implantación del Euro Digital, priorizando un equilibrio entre privacidad y transparencia, sugiriendo la creación de un marco regulatorio flexible que permita realizar adaptaciones conforme se desarrollen este tipo de tecnologías y evolucionen las necesidades económicas y sociales. El trabajo concluye que el diseño e implementación del Euro Digital representan una oportunidad clave para modernizar el sistema financiero europeo, equilibrando innovación y respeto por los derechos fundamentales. Si bien las CBDC ofrecen beneficios como eficiencia y trazabilidad, también plantean desafíos significativos en términos de privacidad y anonimato. Este trabajo resalta la necesidad de adoptar un modelo equilibrado que, mediante tecnologías avanzadas y marcos normativos adecuados, proteja la privacidad de los usuarios sin tener que comprometer la transparencia necesaria para la seguridad financiera. Utilizando este enfoque se puede fortalecer la confianza del usuario en el Euro Digital y así consolidar su papel como un referente en el ámbito de las monedas digitales a nivel mundial. ABSTRACT This Final Degree Project aims to address the challenges and opportunities related to privacy and anonymity in the adoption of Central Bank Digital Currencies (CBDCs), with a particular focus on the Digital Euro (the digital currency proposed by the European Central Bank, ECB). CBDCs represent a disruptive innovation in the financial system as we know it, offering an alternative vision to traditional cash and having a considerable impact on user privacy, financial transparency, and the existing regulatory framework. In the context of growing global interest in CBDCs, the European Central Bank seeks to balance personal data protection and financial transparency within a system capable of transforming the dynamics of the European financial system. The objective of this study is to analyze how CBDCs can be designed and implemented to maximize their benefits while mitigating risks associated with privacy and financial transparency. The specific objectives include: 1. Examining the concept and evolution of CBDCs. 2. Identifying challenges and opportunities related to privacy and anonymity. 3. Analyzing the European regulatory framework applicable to the Digital Euro. 4. Comparing alternative CBDC designs with an emphasis on privacy. 5. Proposing recommendations to balance privacy and transparency. 6. Exploring and analyzing alternative use cases that preserve transaction anonymity. This study conducts a thorough analysis of the impact of CBDCs on user privacy, considering various factors such as the technology employed, regulatory policies, and social expectations. Special emphasis is placed on the challenge of protecting user data in a digital environment that constantly demands high levels of traceability and regulatory compliance. The study also explores how other jurisdictions have addressed these challenges, analyzing specific cases such as the digital yuan in China and pilot projects in Nordic countries, with the aim of identifying lessons learned and different strategies applicable to the European framework. Additionally, it investigates technological innovations such as zero-knowledge proof systems and their utility in protecting user identity without compromising transparency. Finally, a series of recommendations are proposed for the design and implementation of the Digital Euro, prioritizing a balance between privacy and transparency. These include the creation of a flexible regulatory framework that allows for adaptations as these technologies develop and as economic and social needs evolve. The study concludes that the design and implementation of the Digital Euro represent a key opportunity to modernize the European financial system by balancing innovation and respect for fundamental rights. While CBDCs offer benefits such as efficiency and traceability, they also pose significant challenges in terms of privacy and anonymity. This work highlights the need to adopt a balanced model that, through advanced technologies and appropriate regulatory frameworks, protects user privacy without compromising the transparency necessary for financial security. By following this approach, user trust in the Digital Euro can be strengthened, consolidating its role as a global reference in the field of digital currencies.
Growing worries about data security and privacy are driving the development of privacy-enhancing technologies (PETs) like secure multiparty computation (MPC) and zero-knowledge (ZK) proofs. These technologies offer strong theoretical guarantees for protecting sensitive data while still allowing its use. Critical sectors like finance and healthcare are increasingly adopting PETs, facilitated by complex PET systems designed for secure and efficient implementation. However, despite the theoretical strengths of PETs, the intricate nature of these systems can create practical vulnerabilities. Severe incidents have already caused significant financial losses and eroded trust. This thesis tackles these reliability concerns by systematically testing modern PET systems. The first work in this thesis uncovers logic bugs in secure multiparty computation (MPC) compilers. These compilers automatically transform high-level MPC programs, written in domain-specific languages (DSLs), into low-level MPC executables. We introduce MT-MPC, a metamorphic testing (MT) framework, to test MPC compilers using three tailored metamorphic relations (MRs). Despite the high engineering quality of MPC compilers, MT-MPC finds 13 bugs in leading compilers, which compromises the dependability of MPC systems. The second work focuses on the correctness and security of zero-knowledge (ZK) compilers, which compile ZK DSL programs into ZK circuits. We propose MTZK, a MT framework that uncovers logic bugs in ZK compilers. These bugs can allow attackers to generate false ZK proofs that ZK verifiers unexpectedly accept, leading to security breaches and financial losses. MTZK uses two carefully designed MRs to deliver effective test cases for ZK compilers. Evaluation of four industrial ZK compilers reveals 21 bugs. We also demonstrate the severe security implications of these bugs through potential exploits. The third work unveils a new class of vulnerabilities in PET-enhanced machine learning (ML) models. We present ConPETro, the first attack on PET-enhanced ML models with maliciously crafted configurations. These configurations cause PET-enhanced models to behave similarly to plaintext models under normal inputs, but exhibit significantly reduced robustness under trigger-embedded inputs. ConPETro achieves an average maximum attack success rate of 65.6% while maintaining merely 4% of accuracy drop on normal inputs. We also show that such attacks are highly stealthy and can hardly be detected or defended by traditional mechanisms.
Open access
Information and Cyber Security
Transportation Systems and Safety
Physical Unclonable Functions (PUFs) and Hardware Security
This systematic literature review compares two leading selective-disclosure primitives for decentralised identity-BBS+ signatures and Selective-Disclosure JSON Web Tokens (SD-JWT)-to clarify their suitability for privacypreserving credentials. Following Kitchenham's protocol, 226 records from 2017-2025 were screened across IEEE, ACM, SpringerLink, ScienceDirect, IETF and W3C repositories, yielding 31 primary studies with empirical data. Quantitative synthesis shows that BBS+ derived proofs remain constant-size at roughly 140 bytes and verify in about 12 ms on consumer hardware, whereas SD-JWT presentations grow with the number of revealed claims but still verify in under 10 ms for typical twoclaim use cases. Qualitative analysis confirms BBS+ provides strong unlinkability, predicate proofs and zero-knowledge disclosure, while SD-JWT offers seamless integration with existing JOSE/OAuth infrastructures yet carries correlation risk due to stable salted digests. Standardisation progress is comparable: the BBS+ cryptosuite reached W3C Candidate Recommendation in April 2025, and SD-JWT is in late-stage IETF review. The review concludes that privacy-critical scenarios such as age-gated services favour BBS+, whereas high-throughput web applications benefit from SD-JWT; consequently, hybrid wallet support for both formats is recommended. Future research should tackle scalable revocation, post-quantum migration and multi-credential aggregation to sustain long-term trust and interoperability.
Current directions of development of information and communication technologies and control tools 114 ПРОБЛЕМНІ ПИТАННЯ ЗАСТОСУВАННЯ ГОМОМОРФНОГО ШИФРУВАННЯ Гущин Б.-Д.І.Харківський національний університет радіоелектроніки, Харків, Україна Гомоморфне шифрування (Homomorphic Encryption, HE) -технологія, що дозволяє виконувати обчислення над зашифрованими даними без їх розшифрування [1-3].Застосування гомоморфного шифрування відкриває великі можливості для обробки зашифрованих даних без їх розшифрування в багатьох сферах, де критично важливо зберігати конфіденційність інформації.. Однак, попри потенціал, існує низка проблемних питань, які стримують широке впровадження цієї технології в практичні системи безпеки та обробки даних.Метою доповіді є аналіз проблемних питань при практичному застосуванні гомоморфного шифрування.В роботі розглянуті ключові сучасні сфери застосування HE [1-3].1. Хмарні обчислення (Cloud Computing), обробка зашифрованих даних на стороні постачальника хмарних послуг без розкриття вмісту.2. В медицині та біоінформатиці захищене зберігання та аналіз медичних записів пацієнтів, генетичної інформації (DНК).Використання HE у дослідженнях із багатьма організаціями без обміну розшифрованими даними.3. В фінансових сервісах конфіденційна аналітика для банків, страхових компаній, бірж.Обчислення кредитного рейтингу, оцінка ризиків без доступу до відкритих даних клієнта. Електронне голосування (E-voting).Забезпечення анонімності та перевірності результатів голосування, так як дані не розкриваються, але можуть бути агреговані без розшифрування.5. В Інтернеті речей (IoT) для обробки конфіденційних даних, зібраних з розумних пристроїв, безпосередньо на сервері або у хмарі.Використання в промисловому IoT (IIoT), медичних пристроях, Smart City.6. Захист персональних даних у Big Data, аналітика зашифрованих великих масивів даних з соціальних мереж, телекомів, сервісів для обчислення трендів, поведінкових моделей, не розкриваючи особистості.7. Машинне навчання над зашифрованими даними (Privacy-Preserving ML).Навчання або інференс моделей на даних, які ніколи не розшифровуються.Використання в конфіденційній медичній діагностиці, рекомендаційних системах, фінансах.Працює разом з Federated Learning, Secure Multi-Party Computation (SMPC).8. В юридичних сервісах та державному управлінні для безпечної взаємодії між державними структурами при обробці реєстрів, митних даних, податкових баз, де важлива повна конфіденційність.9. В системах кібербезпеки та цифрової ідентичності.Застосовується в антифрод-системах, аналізі поведінки користувачів без втрати їхньої конфіденційності.Підтримка Zero Knowledge Proofs та протоколів автентифікації.
Atoms and photons, two things so different but yet so alike. The former, the building block of matter, something we learn about in school and imagine it as some tiny marbles encircled by other tinier marbles. The latter, an electromagnetic wave, a light particle or an excitation of the electromagnetic field. Quantum mechanics tells us about the properties of these two entities. And even if it sounds, looks and writes counter-intuitive, it has proven right for over a century now. In this work, I elaborate on how we tested the laws of quantum mechanics and how we used them learn more about the tiny building blocks of nature and the fields they use to talk to each other. The atoms we use, are artificial. Superconducting qubits, small electrical circuits with quantized energy levels behave like electrons that transition between different orbitals in an atom. One of the qubits' advantages, is also a big disadvantage. We design the circuits' energy levels and fabricate them in a cleanroom. This allows for arbitrary spaced energy levels but in contrast to real atoms, prevents two superconducting qubits from being alike. Still, this qubit platform is one of the frontrunners for future quantum computing technology and testing fundamental physics due to their scalability. We interface superconducting qubits, which operate in the GHz regime, with microwave photons. We use 3D aluminum cavities as mediators between qubits and photons. The cavities allow for non-destructive readout of the qubit state, they shield the qubits from noise at the qubit frequency and they give us an easy way to frequency-tune these joint systems. We need to operate superconducting qubits and their cavities at millikelvin temperatures in dilution refrigerators. At higher temperatures, superconductivity suffers and even worse, the environment is filled with thermal noise photons. This poses a fundamental limitation on the scalability of superconducting qubit devices. Also connecting multiple devices in different fridges does not work over room temperature links because the microwave photons used for this purpose will be covered in noise and the quantum information they carry, will be unusable. Infrared photons do not suffer from this noise problem since there are close to zero thermal noise photons at their frequencies at room temperature. We cannot simply interface superconducting devices with optical photons due their frequency mismatch and the destructive effect of optical photons on superconductors. Therefore, we use microwave-to-optics transducers that allow to convert microwave photons into optical ones and vice-versa. The transducers that we use are macroscopic electro-optic transducers using the Pockels effect in a disk-shaped Lithium Niobate whispering gallery mode resonator. By using a strong optical pump, photons from the two frequency domains experience a beam-splitter interaction and get converted from one to the other. We measure the generated optical photons using elaborate optical setups, optical heterodyning and single photon detectors to gain knowledge about the qubit state or the converted microwave photons. Bridging the microwave and the optical world allows us to take advantage of both of their strengths but it also requires deep knowledge about both of their working principles. In this work, we describe two experiments that our group conducted to showcase the opportunities that arise from interfacing superconducting qubits with optical photons but also the pitfalls, one may encounter on the way. In the first experiment, we managed to all-optically read out a superconducting qubit. We show that the assignment fidelity, the probability that a measurement of the qubit state matches the prepared state, is close to equal for all-optical, microwave-to-optics and conventional microwave readout. We show T1 and T2 measurements for all three readout types and give an analysis of the noise caused by the optics. Finally, we show that the infrared light does not affect the qubit performance in a negative way but that the heating it causes does. This is an important insight that we used in the next experiment. The second experiment is the upconversion of itinerant single microwave photons to the optical domain. We show that we can generate single microwave photons from a qubit-cavity system. We upconvert these single photons, measure them with a single photon detector and reconstruct their shape. By conducting a single photon Rabi measurement, we show correlations between the microwave and the optical domain. And by thorough signal-to-noise measurements and noise analysis, we find that we can generate single infrared photons with high signal-to-noise ratio 5.1 and low transducer added noise (<0.012 quanta). We show that this measurement creates a path towards entanglement of a superconducting qubit and an optical photon and what parameters need to be improved to achieve it. Additionally, this experiment is a proof of principle for an on-demand infrared single photon source. More generally, it allows to link microwave quantum technology in general to the optical domain.
Verifiable Delay Functions (VDFs) introduced by Boneh et al. (CRYPTO'18) are functions that require a prescribed number of sequential steps T to evaluate, yet their output can be verified in time much faster than T. Since their introduction, VDFs have gained a lot of attention due to their applications in blockchain protocols, randomness beacons, timestamping and deniability. This thesis explores the theory and applications of VDFs, focusing on enhancing their soundness, efficiency and practicality. The only practical VDFs known to date are based on repeated squaring in hidden order groups. Consider the function VDF(x,T)=x^(2^T). The iterated squaring assumption states that, for a random group element x, the result of VDF cannot be computed significantly faster than performing T sequential squarings if the group order is unknown. To make the result verifiable a prover can compute a proof of exponentiation (PoE) \pi. Given \pi, the output of VDF can be verified in time much less than T. We first present new constructions of statistically sound proofs of exponentiation, which are an important building block in the construction of SNARKs (Succinct Non-Interactive Argument of Knowledge). Statistical soundness means that the proofs remain secure against computationally unbounded adversaries, in particular, it remains secure even when the group order is known. We thereby address limitations in previous PoE protocols which either required (non-standard) hardness assumptions or a lot of parallel repetitions. Our construction significantly reduces the proof size of statistically sound PoEs that allow for a structured exponent, which leads to better efficiency of SNARKs and other applications. Secondly, we introduce improved batching techniques for PoEs, which allow multiple proofs to be aggregated and verified with minimal overhead. These protocols optimize communication and computation complexity in large-scale blockchain environments and enable scalable remote benchmarking of parallel computation resources. We then construct VDFs with enhanced properties such as zero-knowledge and watermarkability. It was shown by Arun, Bonneau and Clark (ASIACRYPT'22) that these features enable new cryptographic primitives called short-lived proofs and signatures. The validity of such proofs and signatures expires after a predefined amount of time T, i.e., they are deniable after time T. Our constructions improve upon the constructions by Arun, Bonneau and Clark in several dimensions (faster forging times, arguably weaker assumptions). Finally, we apply PoEs in the realm of primality testing, providing cryptographically sound proofs of non-primality for large Proth numbers. This work gives a surprising application of VDFs in the area of computational number theory. Together, our contributions advance both the theoretical foundations and the real-world usability of VDFs in general and in particular of PoEs, making them more adaptable and secure for current and emerging cryptographic applications.
Secure machine learning paradigms have emerged as compelling solutions to address growing concerns of large-scale data collection in modern Machine Learning (ML) systems. These paradigms leverage secure computation techniques to enable the execution of ML applications without the necessity to share raw data, models or predictions to be shared between parties, offering strong, formal privacy guarantees. Recent advances have significantly enhanced both the scalability and expressiveness of these secure paradigms, facilitating their deployment in real-world scenarios across a variety of privacy-sensitive domains. However, the very mechanisms that provide these privacy guarantees also introduce new challenges to robustness, trust, and accountability. To ensure secrecy, secure ML systems conceal the processes of training and inference, making them difficult to inspect, validate, or audit. This intrinsic opacity creates a fundamental tension between privacy and accountability: hiding data and models to protect users’ privacy can also obscure failures and enable undetectable manipulation. Furthermore, in many secure ML frameworks, multiple, potentially untrusted parties collaboratively contribute to computations, thereby amplifying risks. Traditional threat models in adversarial ML often depend on transparent access to data, models, or outputs—assumptions that do not hold in secure settings. As a result, these systems become vulnerable to new and sometimes more potent attack vectors. Without dedicated integrity mechanisms, these privacy-preserving systems cannot be safely deployed in high-stakes domains such as healthcare, finance, or critical infrastructure. Realizing the full potential of secure ML requires a comprehensive understanding of the unique threats these systems face, the development of new integrity mechanisms, and their integration into these systems in a way that is efficient and preserves the privacy guarantees they provide. This dissertation advances accountability in secure ML through two complementary directions. First, it develops an understanding of the robustness challenges that arise in secure settings. We investigate the role of memorization and system-level dynamics in exposing secure systems to targeted manipulation. Based on these insights, we then introduce new cryptographic building blocks to strengthen the robustness and transparency of secure ML. We present RoFL, a system for privacy-preserving input validation in secure Federated Learning; Arc, the first framework for end-to-end auditing of secure ML pipelines; and Artemis, a new construction for generating efficient zero-knowledge proofs for real-world ML models. Together, these contributions lay the foundation for secure ML systems that are not only private, but also accountable and trustworthy in practice.
The Doctrine of Anchored Decentralization constitutes the first comprehensive constitutional and statutory framework capable of reconciling decentralized digital architectures with the legal, regulatory, and jurisprudential structure of the United States. Developed within the broader scholarly series <i>The Republic’s Conscience</i>, this thesis represents the second installment in that corpus—building directly upon the constitutional and structural principles articulated in the inaugural paper and extending them into the domain of digital-asset governance, administrative delimitation, and federal statutory coherence.This work advances the nation’s first universal, architecture-based commodity-versus-security classification framework designed for deployment across American constitutional, statutory, and judicial systems. By replacing rhetorical claims of decentralization with empirically verifiable and legally cognizable structural tests, the Doctrine furnishes courts, Congress, and administrative agencies with a coherent, adjudicable methodology capable of withstanding scrutiny under established Supreme Court jurisprudence, including <i>Howey</i>, <i>Reves</i>, <i>Forman</i>, <i>Marbury</i>, and the post-<i>Chevron</i> administrative landscape.The Doctrine challenges the prevailing assumption that blockchain-based ecosystems may operate as “stateless” economic systems while still participating in markets governed by constitutional law. Through sustained analysis of constitutional text, statutory construction, cryptographic system design, and post-Chevron administrative jurisprudence, the work demonstrates that decentralization cannot acquire legal legitimacy unless it remains anchored to the Chain of Consent — the constitutional requirement that all economic power be traceable to accountable authority.Drawing upon Article I, § 8 (monetary and commercial power), Article I, § 9 (appropriations and fiscal discipline), and the Due Process Clauses of the Fifth and Fourteenth Amendments, the Doctrine establishes that most contemporary decentralized systems operate within a constitutional vacuum: they perform value transfer, economic coordination, and pseudo-monetary behavior without satisfying the representational prerequisites of the American constitutional order. This analysis is further grounded in <i>Trustees of Dartmouth College v. Woodward</i>, <i>Gibbons v. Ogden</i>, <i>Wickard v. Filburn</i>, <i>United States v. Lopez</i>, <i>NFIB v. Sebelius</i>, and the post–<i>Loper Bright</i> landscape of statutory interpretation, revealing how modern digital governance architectures strain the boundaries of jurisdiction, accountability, and enforceability.At the systems-engineering level, the Doctrine reframes decentralization not as a monetary phenomenon but as a cryptographic lineage derived from Haber and Stornetta’s foundational timestamping architecture. This lineage demonstrates that Bitcoin’s core innovation was not the creation of new money, but the operationalization of a distributed verification engine. The work therefore distinguishes decisively between decentralization as architectural substrate and cryptocurrency as asset behavior, establishing that most digital tokens cannot qualify as commodities under the Commodity Exchange Act absent a constitutionally anchored framework for origin accountability, managerial neutrality, and market integrity.The Doctrine exposes structural defects in modern legislative approaches — including H.R. 3633 — demonstrating how contemporary statutory efforts misapply classical commodity theory, create jurisdictionally unanchored digital entities, and institutionalize anonymity architectures that undermine due process, enforcement capacity, and market legitimacy. In response, this work develops the Anchored Decentralization Test, the first system-level doctrine to allow Congress, courts, and regulators to classify digital assets based on verifiable architectural behavior rather than semantic self-description.The Doctrine further introduces the novel concept of Autonomous Commodity Primitives (ACPs) — a sovereign-grade digital infrastructure class designed not as speculative instruments but as immutable, cryptographic attestations of real-world sovereign reserve assets. ACPs are engineered to function as Treasury-grade verification rails, enabling real-time auditability, ledger-level integrity, and constitutionally compliant Asset-Backed Digital Currency (ABDC) architecture. Unlike cryptocurrencies, ACPs do not manufacture value; they attest to value that already exists within sovereign reserve systems.To harmonize privacy with constitutional accountability, the Doctrine integrates Zero-Knowledge Proofs, privacy-preserving audit layers, and non-custodial verification mechanisms, allowing digital systems to preserve Fourth Amendment-equivalent privacy while maintaining lawful traceability through institutional channels. This design restores the Chain of Consent without creating surveillance architecture.The Doctrine concludes that decentralization without accountability constitutes a structural form of constitutional evasion — an economy operating beyond representation. By restoring constitutional anchoring to distributed architectures, the Doctrine preserves innovation while reaffirming the Republic’s foundational principle: that economic power is legitimate only when traceable to those whom the Constitution recognizes as sovereign.Ultimately, The Doctrine of Anchored Decentralization provides a constitutional roadmap for the next century of digital infrastructure. It is <i>not a rejection</i> of decentralized technology, but a <i>restoration</i> of its lawful purpose: to function as a verifiable architecture of trust, anchored to the constitutional principles that have sustained the United States for more than two centuries.
随着信息技术的快速发展,数据安全和用户的隐私越发受到重视。本文提出了一种匿名认证密钥交换(Anonymous Key Exchange, AKE)协议,旨在为医疗场景下的医疗数据共享和患者身份隐私提供安全和隐私的保护。该方案通过使用累加器、零知识证明和关联数据加密等技术,实现用户匿名的认证和安全的会话密钥协商,有效防止敌手对于用户和医用物联网设备的攻击,还能抵御诚实且好奇的医疗机构对患者身份的猜测。相较于现有的方案提供了更强的隐私安全保护,并且很好地平衡了性能和安全性,具有重要的理论价值和意义。With the rapid development of information technology, data security and user privacy have been paid more and more attention. This paper proposes an Anonymous authenticated Key Exchange (AKE) protocol to provide security and privacy protection for medical data sharing and patient identity privacy in medical scenarios. By using accumulator, zero-knowledge proof and associated data encryption technology, the scheme realizes anonymous user authentication and secure session key agreement, which effectively prevents adversaries from attacking users and medical IoT devices, and can resist honest and curious medical institutions from guessing the patient’s identity. Compared with the existing schemes, it provides stronger privacy security protection, and a good balance between performance and security, which has important theoretical value and significance.
This talk given at the 2025 MDIC CM&S Summit on "Credible Models in the AI Age" traces the evolution of trust mechanisms in computational systems, from traditional model validation approaches in mechanistic modeling to emerging cryptographic verification methods for AI. We'll explore how the credibility challenge for regulators has transformed as we've moved from deterministic simulations to probabilistic AI systems, and examine how cryptographic proofs, zero-knowledge techniques, and verifiable computation are creating new pathways for establishing trust in AI outputs. By understanding this historical progression, we can better appreciate both the continuity and fundamental shifts in how we ensure reliability in our computational approaches.
This thesis investigates how blockchain technology and data science methods can jointly improve the security, transparency, and trustworthiness of electoral systems. Against a backdrop of rising concerns over election integrity in traditional voting systems, scholars and nations have begun to integrate blockchain systems. However, adoption appears to remain low. This study systematically reviews 116 peer-reviewed articles and analyzes five national case studies (Estonia, Switzerland, the United States, Russia, and Romania). It examines (1) blockchain’s potential to secure voter verification, prevent fraud, and ensure immutable vote records; (2) data-science methods (e.g. machine learning, zero-knowledge proofs, homomorphic encryption) for anomaly detection, performance optimization, and privacy preservation; and (3) the ethical, political, and societal implications of digital voting, including the digital divide and regulatory compliance. A mixed-methods approach was adopted. First, SLR was used to identify, screen, and synthesize 28 core studies. Then multiple case studies were used to analyse real-world blockchain-voting system implementations to highlight practical successes and setbacks. From this, a conceptual framework for a hybrid blockchain voting system that integrates smart contracts, layered consensus model, and an off-chain data-science layer for real-time monitoring was developed. Findings show consensus that blockchain can enhance election integrity, and data-science techniques further strengthen authentication, detect intrusions, and enable privacy-preserving analytics. However, it was also found that legal and regulatory gaps, infrastructure and literacy barriers, lack of scalability, and the need to build public trust remain huge hindrances to widespread adoption. The thesis recommended a hybrid voting architecture that combines public and private blockchains and off-chain data science monitoring, and its interface is user-friendly. Policymakers and election administrators are urged to pilot such integrated systems, refine identity-management protocols, and invest in voter education to ensure both technical robustness and broad societal acceptance, thereby paving the way toward more secure, transparent, and efficient democratic processes.
The correctness of a computation can be efficiently verified in a privacy-preserving manner without re-execution using zero-knowledge succinct non-interactive arguments of knowledge (zkSNARKs). With short transcript sizes and fast verification times, zkSNARKs enable the potential deployment of computationally intensive algorithms—such as machine learning models—on the blockchain, making them efficiently verifiable through short proofs. However, the prover time for matrix computations in these settings often fails to scale efficiently with increasing model complexity and data size. We are the first to systematically address zkSNARKs for general matrix computations with practical prover efficiency. We achieve an $O(N + nM)$ prover time, asymptotically faster than the unverified matrix computation, for computations involving $M$ matrix operations on $n \times n$ matrices with $N$ total non-zero entries. Starting with a single dense matrix multiplication, we propose zkMatrix, a special-purpose zkSNARK for verifying committed $n \times n$ matrix multiplication through their projections onto random vectors. Among zkSNARKs with $O(\log n)$ transcript size and verifier time, zkMatrix is the first to achieve $O(n^2)$ prover time and $O(n^2)$ RAM usage. Batching multiple proofs together reduces the prover time for each additional multiplication to $O(n)$ group operations. Next, we design zkSNARKs for sparse matrix multiplication with $N$ non-zero entries. zkSmart reduces the prover time from $O(n^2)$ to $O(N + n)$, relying on an $O(N + n)$-prover vector-matrix-vector product argument, achieved by improving Bulletproofs. Moreover, \zksmart formulates verifiable computation represented as a matrix circuit of $M$ nodes, each denoting a matrix operation. Sparse matrix multiplication translates the matrix circuit satisfiability (Mat-Circ-SAT) problem into the high-dimensional rank-1 constraint system (HD-R1CS), a matrix-circuit version of the rank-1 constraint system (R1CS), traditionally used for arithmetic circuits. Using zkSmart, we achieve $O(N + nM)$ prover time for general matrix computations. To reduce the cost of committing to intermediate variable matrices in zkSmart, we introduce Evalyn, which generates proofs using a pre-order tree traversal on the abstract syntax tree (AST) of a matrix expression. Evalyn ensures output and input consistency in serial matrix computations by linking randomness for zkSNARKs between parent and child nodes, eliminating the need to commit to the nodes and significantly improving prover efficiency. Our prover for R1CS outperforms state-of-the-art general-purpose zkSNARKs. As a foundational component of our framework, we optimize Bulletproofs to construct the fastest known inner product argument (IPA). Additionally, we propose a zero-knowledge transformation that commits to transcript elements with only logarithmic overhead—while maintaining compatibility with post-quantum secure, non-homomorphic commitment schemes. We apply our framework to zero-knowledge machine learning (zkML), providing zkSNARKs for neural networks. We translate floating-point truncations and non-linear activation functions into linear algebra equations that can be verified by our framework. We utilize our framework to generate efficient proofs for the attention layer in large language models (LLMs). After resolving all these challenges, we have thoroughly addressed the design of efficient zkSNARKs for matrix computations.
Михайленко, Олександр Ігорович, Гороховський, Кирило Семенович, Гороховський, Семен Самуїлович
The paper explores the possibility of expanding the use of end-to-end encryption protocols based on the Double Ratchet algorithm in applications with low trust in the server, particularly in turn-based games and strategic interactions. The relevance of the research is due to the growing need for secure communication in cyberattacks, especially during military operations. The field of end-to-end encryption requires the study of additional applications beyond the usual ones, such as encrypted communication in text messengers. The developed implementation of the protocol can be safely used in any applications that aim to implement end-to-end encryption and satisfy the criterion of session ephemerality (in cases where secrets are stored outside a secure environment). The implemented server supports ephemeral sessions, which guarantee minimal risks of information compromise, and uses digital signatures (EdDSA) for user authentication. Logical routing of requests ensures efficient message transmission in secure scenarios. The choice of the classic game of checkers as an example allowed the authors to effectively demonstrate the advantages of end-to-end encryption and the capabilities of the implemented protocol. All cryptographic operations, including key generation, encryption and decryption of messages, are successfully performed on client devices. It is important to improve error handling mechanisms and optimize the operation of WebAssembly. An interesting area of further research is the creation of zero-knowledge proof mechanisms to prevent Man-In-The-Middle attacks during the creation of a shared secret, optimizing integration with cryptographic hardware security modules (HSM), and exploring the scalability of the solution. The proposed approach can be used to solve real-world information security problems where trust in the data transmission channel is critically important. Thus, the work has created a comprehensive solution that includes a cryptographic protocol, a backend, and a web client, which demonstrates the viability of end-to-end encryption in browser environments and multiplayer games. The work can be used as a basis for further research and development in the field of security of communication systems and privacy in multiplayer games.
In this age of always-on connection, it is very important to keep data safe while also protecting user privacy. In today's networks, where data travels through many pathways, such as cloud services and IoT devices, cryptographic algorithms are very important for keeping private data safe. But it's still exceptionally difficult to create beyond any doubt that information is secure without putting people's protection at chance. This conversation goes into detail almost privacy-preserving security strategies, looking at their significance, issues, and other ways to solve them. The objective of privacy-preserving cryptographic strategies is to create beyond any doubt that private information is kept secure whereas still permitting secure contact and computation. To keep data secure from individuals who shouldn't have get to to it, these frameworks utilize diverse sorts of cryptography, like encryption, hashing, and secure multi-party computation (SMPC). Information spills and illicit observing are less likely to happen with these methods because they cover up information at diverse steps of exchange and handling. Indeed in spite of the fact that they may well be useful, privacy-preserving cryptographic strategies have a number of issues. Finding a great blend between client security and information security is one of the most issues. Extreme security measures may offer assistance keep information secure, but they frequently include collecting information in ways that are as well intrusive and abuse people's security. On the other hand, putting as well much accentuation on protection might make security weaker, taking off information open to being abused. Finding a cautious adjust between these competing objectives is key to making cryptographic frameworks that work well. A few potential methods that permit secure information taking care of whereas ensuring security are homomorphic encryption, differential protection, and zero-knowledge proofs. Improvements in hardware-accelerated cryptography and distributed computing tools also make it possible to speed up secure processes and make them more scalable.
V. S. Balatska, R. L. Tkachuk, A. I. Ivanusa, V. I. Yashchuk · 5 authors
Problem. The growing intensity of cyberattacks on state registers and the increasing complexity of insider threats expose the weaknesses of traditional comprehensive information security systems (CISS), particularly the reliance on centralized logging and change verification mechanisms. This reduces audit transparency, complicates the evidential value of incidents, and creates regulatory risks in personal data protection. Purpose. To develop and substantiate a scientific and methodological approach for integrating permissioned blockchain technology into CISS of state registers to enhance resistance to insider actions, ensure transparency of access control, and increase trust in electronic public services. Methods. The study applies a systems analysis of CISS architectures and regulatory requirements, mathematical modeling of data flows, and experimental modeling in a virtualized environment using Hyperledger Fabric as a decentralized logging and verification module. Zero-Knowledge Proofs were applied to preserve transaction confidentiality, and behavioral analytics based on machine learning algorithms were used to detect anomalous activity. Results. A hybrid architecture was proposed in which traditional mechanisms of authentication, access control, and cryptographic protection are reinforced by a distributed event log and consensus-based verification of operations. This integration ensures data immutability and reproducibility of access history, reduces the possibility of hidden record editing by administrators, accelerates the detection of atypical user behavior, and creates a reliable evidential base for auditing. The proposed architecture complies with ISO/IEC 27001 requirements and supports data minimization and accountability principles, facilitating GDPR compliance during personal data processing. Conclusions. Integrating permissioned blockchain into CISS of state registers establishes a new level of trust and controllability of security: it increases audit transparency, mitigates insider risks, and preserves transaction confidentiality. The proposed approach is scalable and suitable for national e-government platforms and interagency data exchange systems.
This paper tackles a low earth satellite governance paradox beyond the Kármán Line (100 kilometers above sea level): the same proprietary AI that keeps satellites safe also hides the reasoning states need to supervise private actors and assign responsibility. AI black-box compliance is now routine—operators disclose maneuvers but not the internal signals, thresholds, or telemetry transformations—leaving due regard, peaceful-use expectations, and fault analysis to operate on conjecture rather than evidence. The result is an accountability gap across core space-law instruments: Article VI of the Outer Space Treaty presumes continuing supervision; the Liability Convention relies on reconstructable causation; the LTS Guidelines anticipate demonstrable prevention measures. Terrestrial approaches offer partial assistance. The EU’s qualified transparency and the U.S. post-incident auditing travel unevenly off-Earth, and neither framework reliably reaches proprietary on-orbit autonomy. This paper shows with concrete operational scenarios (e.g., dynamic conjunction-thresholding, autonomous servicing approaches), provides an inevitable loss of public-law legitimacy and lack of protection for intellectual property. To address this, the paper proposes a dual-layer disclosure regime that protects legitimate trade secrets while restoring verifiable oversight. Layer 1—Regulatory Safe Rooms: accredited neutral venues conduct confidential code/model/telemetry review under treaty-backed non-disclosure, enabling certification, adversarial stress-testing, and forensic replay without commercial expropriation. Layer 2—Explainability Without Exposure: operators supply functional evidence—validated performance envelopes, adversarial test outcomes, decision bounds—augmented by privacy-preserving attestations (e.g., zero-knowledge proofs) in lieu of source disclosure. Implementation follows a “pressure-valve” path: condition launch licensing, frequency assignments, and mission approvals on participation now; seek UNCOPUOS endorsement later through a model protocol that harmonizes Artemis practices with non-signatories and codifies a TRIPS-compatible IP-Transparency Equilibrium Clause. The payoff is pragmatic rather than utopian: traceability sufficient to make due regard and liability doctrines workable again; incentives preserved for R&D; and a template that can translate to other thin-sovereignty domains (deep-sea, Antarctic, high-altitude autonomy) where algorithmic opacity currently outruns public law.