Background Cross-border credit recognition in Sino-Foreign Cooperative Education (SFCE) suffers from data fragmentation, regulatory conflicts (e.g., GDPR vs. China’s Data Security Law), and low efficiency. Objective This paper proposes ZkHybridChain, a dual-layer blockchain credit bank (BCB) framework to resolve the privacy-compliance-efficiency trilemma. Methods The hybrid architecture integrates Polygon zkEVM (public credential hashing) and Hyperledger Fabric (private raw data storage). Zero-Knowledge Proofs (ZKP) and three-tiered smart contracts enable automated credit conversion (ECTS↔CNQF) and privacy-preserving verification. Results Experiments on 10,000 SFCE records show 58% efficiency gain (full lifecycle from ∼1,200 s to <9 s), cross-border latency <9 s, throughput up to 1,620 TPS, and ZKP verification latency 135 ms (93.7% success rate). Conclusion ZkHybridChain provides a scalable, GDPR/DSL-compliant solution for global education trust networks. Future work includes post-quantum cryptography and lightweight client protocols.
Shiho Kim, Ho Suk, Roberto Di Pietro, Davor Svetinović · 7 authors
ZABAPAD (Zero-knowledge proof And Blockchain for WEB 4.0: Advancing the Post-quantum And Decentralized Era) is a workshop focusing on zero-knowledge technologies, blockchain infrastructure, and post-quantum readiness for the emerging Web 4.0 ecosystem. This workshop emphasizes real-world deployments, empirical measurements, and interoperability across Web and non-Web domains. In particular, ZABAPAD explores the convergence of AIoT and ZKP—redefining identity and trust models beyond SIM in mobile networks, IP in Web 2.0, and NFT in Web 3.0. As AIoT systems evolve toward decentralized, post-quantum infrastructures, ZKPbased authentication and AIoT SIM functionalities are emerging as key enablers of secure, privacy-preserving, and verifiable connectivity among intelligent devices, vehicles, and edge services. This theme extends to ZKML, Layer-2 proving/verification, TEE+ZK integration for verifiable compute, and post-quantum migration of identities, wallets, ledgers, and protocols. Expected outcomes include: (1) a practitioner-oriented adoption playbook, (2) an interoperability and standards checklist, (3) a curated set of reproducible benchmarks and datasets, and (4) a catalog of failure modes and mitigations for domains such as finance, mobility, healthcare, AIoT, public services, supply chain, and AI/ML. ZABAPAD complements the Web Conference and Web 4.0 communities by uniting global researchers and developers to chart actionable, trustworthy pathways toward the post-quantum, decentralized, and intelligent Internet.
The proliferation of centralized carrier-based authentication systems has exposed critical vulnerabilities in the preservation of privacy and personal data protection. Current implementations in Korea, such as PASS and KakaoTalk identity services, rely on centralized architectures that create single points of failure and require excessive disclosure of personal information. The large-scale security breach of SK Telecom's USIM infrastructure in 2025, affecting 23 million subscribers, highlights the urgent need for a paradigm shift in identity authentication.?This paper proposes a decentralized identity authentication system leveraging W3C Decentralized Identifiers (DIDs) and Verifiable Credentials (VCs), combined with Zero-Knowledge Proofs (ZKPs). Our framework integrates Schnorr signatures with Sigma-protocol-based ZKPs to enable privacy-preserving authentication without revealing private keys. A three-layer architecture—comprising cryptographic, identity, and credential layers—ensures strong cryptographic guarantees based on the discrete logarithm problem over the secp256k1 curve, while eliminating reliance on centralized infrastructure. Performance evaluation shows that signature generation occurs in under 10 ms and verification in under 15 ms, meeting real-time authentication requirements while delivering formal privacy guarantees that are absent in conventional systems.
As quantum computing moves to a cloud-based service model, a privacy–utility dilemma arises: effective Quantum Error Mitigation (QEM) requires circuit visibility, yet circuits and noise models are often proprietary. We propose Blind-QEM, a privacy-preserving framework that enables outsourced mitigation without revealing circuit topology. Using Zero-Knowledge Proofs (ZKPs) and a receipt-based binding mechanism anchored by QPU-signed execution logs, Blind-QEM verifies policy compliance and cryptographically links results to committed circuits. This allows Service Providers to perform global incoherent noise cancellation and readout mitigation using only verified aggregate statistics, ensuring mutual protection of user IP and SP models.
Zero-knowledge proofs (ZKPs) play a critical role in mitigating modern digital threats by enabling verification without disclosure, a key requirement for secure computation in adversarial environments. Among existing constructions, zk-SNARKs and zk-STARKs represent two dominant paradigms with contrasting security, trust, and performance characteristics. While their theoretical foundations are well studied, practical performance under real-world conditions remains less understood. In this work, we present a systematic, implementation-level comparison of zk-SNARKs (Groth16) and zk-STARKs using publicly available reference implementations on a consumer-grade ARM platform. Our empirical evaluation covers proof generation time, verification latency, proof size, and CPU profiling. Results show that zk-SNARKs generate proofs 68x faster with 123x smaller proof size, but verify slower and require trusted setup, whereas zk-STARKs, despite larger proofs and slower generation, verify faster and remain transparent and post-quantum secure. Profiling further identifies distinct computational bottlenecks across the two systems, underscoring how execution models and implementation details significantly affect real-world performance. These findings provide actionable insights for developers, protocol designers, and researchers in selecting and optimizing proof systems for applications such as privacy-preserving transactions, verifiable computation, and scalable rollups.
Electronic voting requires the simultaneous admission of only legitimate participants, ballot uniqueness, vote confidentiality, storage integrity, and result verifiability. Blockchain alone does not solve these problems, since ledger immutability does not guarantee anonymity, ballot correctness, or reduced trust concentration. The purpose of this work is to develop a parameterizable research framework for electronic voting scenarios with enhanced cryptographic protection, allowing the security level to be varied according to the requirements of a voting scenario. The main contribution of the work is a parameterizable research architecture for composing and experimentally comparing electronic voting configurations with different security and computational profiles. The cryptographic and audit mechanisms integrated into this architecture include blind-signature-based anonymous authorization, encrypted ballot submission, blockchain-style audit, receipt verification, homomorphic tally publication, and threshold-supported tally artifacts. These mechanisms are not proposed as new cryptographic primitives; rather, they are integrated into a reproducible prototype to study how their combination affects verifiability, privacy support, auditability, and computational cost. Compared with basic blockchain-based voting prototypes, this architecture explicitly separates security, privacy, and verifiability profiles and makes their computational cost observable. The implemented prototype is used as an experimental platform for analyzing supported security properties, threat modeling, and computational cost estimation. The results show that authentication, anonymous token issuance, and receipt verification maintain an almost constant cost at the studied scale, while the main cryptographic burden is associated with encrypted ballot submission and threshold-supported tally publication. The scientific novelty of the work lies in constructing a parameterizable architecture that integrates several cryptographic mechanisms and a blockchain audit layer into one reproducible research prototype. At the same time, the proposed approach retains prototype-level limitations associated with the absence of a full zero-knowledge proof stack, independently deployed threshold authorities, and coercion-resistance mechanisms.
Abstract In the digital age, the reliance on network communication for information exchange has surged, making encrypted network traffic a linchpin of secure digital interactions. However, while encryption safeguards data, it creates hurdles for network management and security surveillance. Conventional deep packet inspection (DPI) falters when faced with encrypted traffic, and existing studies in this area have drawbacks like reliance on trusted third parties and limited detection capabilities. To address these issues, we present a novel zero knowledge proof based encrypted traffic management( $$\mathbb {ZKP}$$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mi>ZKP</mml:mi> </mml:math> - $$\mathbb {PET}$$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mi>PET</mml:mi> </mml:math> ) scheme. By integrating a third-party verifier operating under the honest-but-curious (HBC) model, $$\mathbb {ZKP}$$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mi>ZKP</mml:mi> </mml:math> - $$\mathbb {PET}$$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mi>PET</mml:mi> </mml:math> establishes a trustless verification system that effectively and efficiently curbs metadata leakage. $$\mathbb {ZKP}$$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mi>ZKP</mml:mi> </mml:math> - $$\mathbb {PET}$$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mi>PET</mml:mi> </mml:math> is implemented with two applications: HTTP traffic blocking and blacklist management. For HTTP traffic blocking, the BTHP circuit is developed to extract version details from TLS traffic and verify compliance, enabling precise traffic control. In blacklist management, tailored extraction algorithms for DoT and DoH encrypted DNS traffic are implemented, and Merkle tree based membership proofs are utilized to decide whether to intercept traffic. Experimental evaluations demonstrate that $$\mathbb {ZKP}$$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mi>ZKP</mml:mi> </mml:math> - $$\mathbb {PET}$$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mi>PET</mml:mi> </mml:math> can efficiently enforce diverse network policies on encrypted traffic. It not only safeguards security and privacy but also exhibits outstanding performance, offering a dependable, efficient, and privacy-centric solution for encrypted network traffic management.
Validators on generic Proof of Stake chains earn the same fees whether they handle attestation work correctly or selectively censor it. For chains whose main activity is moving tokens around, that indifference is fine. For chains whose primary economic activity is recording attestations (content provenance, AI-output attribution, threshold-signed credentials, supply-chain receipts), the indifference becomes a problem. Proof of Useful Attestation (PoUA) makes attestation handling first-class in the consensus weighting itself. Validator vote weight is the product of bonded stake and a reputation scalar in [r_min, r_max] that accumulates from valid attestation work. The reputation update is additive, fee-weighted, non-transferable, and capped per epoch. We prove a cost-to-grind floor (Lemma 1): under chain-wide adaptive burn fraction tau_burn, the non-recoverable cost an adversary pays to inflate reputation by Delta_r is bounded below by tau_burn * Delta_r / (eta * alpha_eff). Under the recommended v0 calibration (r_max/r_min in [4, 10]), the cost premium against a capital adversary is 4x to 10x over equivalent pure-stake PoS at steady state. The paper specifies the mechanism, six layered Sybil and grinding defenses, empirical Monte Carlo strategy-search across the full layered defense, and grinding detectors with explicit threshold derivations. It is a mechanism-design proposal with a formal economic floor and inherited BFT safety and liveness, not a complete cryptographic security proof. This release incorporates feedback from Jiangshan Yu (University of Sydney) and Marko Vukolić (Bitcoin Scaling Labs).
Abstract This concept documents a complete physics-first authorisation architecture for the quantum-permanent era — applicable across AI cluster security, interbank settlement, space and interplanetary infrastructure, critical infrastructure protection, digital identity, supply chain integrity, and optional democratic participation tools. The architecture rests on a single physical principle: a cryptographic credential that no longer exists cannot be recovered by any computation, quantum or classical, regardless of future advances in hardware or algorithms. The concept extends the Temporal Rotation Security Protocol (TRSP v3, DOI: 10.5281/zenodo.20324081) and the TRSP Digital Coin (TDC v2, DOI: 10.5281/zenodo.20332811) with a unified Layered Temporal-Quantum Security (LTQS) framework. LTQS combines NIST FIPS 203/204-standardised Post-Quantum Cryptography (ML-KEM, ML-DSA) as Layer 0 — mathematical transit security — with TRSP temporal rotation as Layer 1 — physical credential elimination through hardware-enforced destructive readout within a configurable rotation window (10–500 ms). Layers 2 and 3 add geographically distributed hybrid dynamic quorum validation and LEO satellite orbital entropy anchoring with relativistic timestamp verification. An integrated adaptive AI management layer selects security profiles dynamically across High-Assurance, Standard, Degraded, and Emergency modes — guaranteeing graceful degradation to pure PQC fallback when physical infrastructure is unavailable. The hardware commitment module previously documented as CRATON is architecturally designated URDHR, after the Norse Norn of the irrecoverable past. The two complementary quorum layers are designated VERÐANDI (present-moment ground quorum) and SKULD (future-anchoring orbital quorum) — the three Norns mapped to the three temporal dimensions of cryptographic security. Prior art established under the CRATON designation in all previously published documents extends fully to the URDHR designation. Fifteen novel contributions are placed on the public record as defensive prior art: NC-TDC-21 (AI-to-AI Micropayment Architecture), NC-TDC-22 (Macroscopic Environmental Entropy as Optical Physical Unclonable Function), NC-TDC-23 and NC-TDC-23a (Macroscopic Polymorphic Cipher with Dynamic Dimensional Entropy — exploratory), NC-TDC-24 (TRSP Democratic Coercion Shield — exploratory, extending Juels-Catalano-Jakobsson coercion-resistant voting literature), NC-TDC-25 (Continuous Anonymous Democratic Pulse — exploratory), NC-TDC-26 (Physical Proof of Presence consensus mechanism operating at the Landauer thermodynamic minimum), NC-TDC-27 (Temporal Scarcity Value Architecture anchored in thermodynamic time-arrow irreversibility), NC-TDC-28 (AI Exchange Consortium Architecture), NC-TDC-29 (Biometric Supply Architecture), NC-TDC-30 (CRATON Chain Coin Identity Architecture without persistent private key), NC-TDC-31 (Three-Phase Value Architecture), and NC-TDC-32 (Cooperative Multi-Anchor Currency Architecture with Founder-Operator Equity-Plus-Operating-Margin Compensation Structure). NC-URDHR-1 and NC-TRSP-Hybrid-1 formalise the Three-Norn naming framework and the four-layer hybrid post-quantum/temporal architecture respectively. NC-TDC-32 is the central economic contribution of this version. It formalises a digital currency architecture in which multiple stakeholder classes — AI infrastructure operators, financial institutions, sovereign states, and individual participants — coexist as independent issuing classes within a single cooperative cryptographic framework. Each class mints its own coin contingent backed by its own economic activity rather than by shared monetary authority. Phase transitions admit new classes through supply expansion, not through re-pricing of existing coins. Coin denomination is calibrated from inception across micropayment to reserve-asset volume regimes via the monetary identity M·V = P·Q. The infrastructure operator class — the AI companies that build and continuously operate the adaptive security layer — is compensated through a two-component structure: bounded equity recognition at phase transitions (capped, independently audited) plus formula-bound operating margin on continuing services. This two-component compensation model is economically required to keep operating margins moderate and the architecture competitive against established settlement infrastructures. Monetary sovereignty remains exclusively with the issuing class for each contingent; the operator class operates the cryptographic issuance infrastructure but does not exercise monetary authority over any contingent. The architecture is the first formalised digital implementation of the cooperative multi-stakeholder economic model previously demonstrated at continental scale only by the Hanseatic League (twelfth to seventeenth century). All fifteen contributions are documented as conceptual frameworks. Production Concepts (NC-TDC-21, NC-TDC-22, NC-TDC-26 through NC-TDC-32, NC-URDHR-1, NC-TRSP-Hybrid-1) represent architecturally sound design patterns ready for implementation evaluation. Exploratory Concepts (NC-TDC-23, NC-TDC-23a, NC-TDC-24, NC-TDC-25) document underlying architectural ideas requiring further formal research. All specific implementation parameters — quantities, ranges, governance percentages, consortium composition — are illustrative starting points belonging to the institutions that choose to implement the architecture. A dedicated Part 9 — Engineering Considerations and Open Challenges — documents five anticipated technical reviewer questions with referenced solution pathways from current research literature: global consensus latency under M-of-N geographically distributed validation (Sliding Window Key Rotation with Dual-Key Buffers, TLS 1.3 RFC 8446); fuzzy extractor Helper Data leakage in optical entropy capture (Controlled PUF Finite State Machine architectures eliminating Helper Data transmission, addressing Becker 2015); orbital quorum availability under atmospheric and orbital dynamics constraints (Multi-Path Delivery with configurable Grace Periods and Layer 2 graceful degradation); post-quantum zero-knowledge proof latency for autonomous AI agent commerce (Off-Critical-Path ZKP architecture separating HMAC authorisation from asynchronous identity verification); and multi-anchor synchronisation between independent issuance classes (Key-ID and class-identification headers preserving structural separation between technical operation and monetary sovereignty). Part 9 introduces no additional Novel Contributions — it documents that the engineering challenges anticipated by reviewers have established research-backed pathways, demonstrating readiness for Proof-of-Concept implementation phases without modifying or weakening any architectural element documented in Parts 1 through 8. The concept is published as defensive prior art under CC BY-NC-ND 4.0 , preventing future patent claims on the documented conceptual architectures while preserving open non-commercial use for evaluation, research, citation, and standards consideration by IETF, ISO/IEC JTC 1/SC 27, NIST Post-Quantum Cryptography programme, or any institution choosing to adopt all or any independent component of the architecture.
A line of impossibility results holds that a distributed ledger must either store a global state linear in the number of accounts or impose a near-linear rate of proof updates on its users; the most general, the revocable-proof-system lower bound of Christ and Bonneau, concludes there is "no useful trade-off." We show this impossibility does not bind the validity predicate Bitcoin actually uses—an artifact of one modelling choice, that validity is decided by a holder-maintained witness checked against a single mutating commitment. We define the spend-event validity predicate (SEVP) that a UTXO ledger uses instead, and prove it is not a revocable proof system: it instantiates no holder witnesses, so it lies outside the domain the lower bound quantifies over rather than within either branch of the dichotomy. The same exclusion holds for the related accumulator-update bounds. We are explicit about scope—stateless UTXO constructions that issue holder witnesses (accumulator- and vector-commitment designs) are correctly bound; the claim is that the UTXO model as Bitcoin implements it is not such a construction. This is not hypothetical: public Teranode benchmark evidence demonstrates one-million-transactions-per-second validation in a six-region BSV benchmark, while companion measurements report a 520-million-output active set with no holder-maintained witnesses. We then develop the supporting machinery. The binding resource is active-state maintenance in fast memory, not archival disk, and pruning bounds that state safely with a parameter-free reduction ratio of exactly T_yr/(d·T_block) (263× at retention depth d = 200), never altering the ledger and preserving the forensic record through self-interested retention plus archival nodes. For certification we give a construction and cost analysis for interval non-revocation, combining known authenticated-dictionary primitives so that interval validity is decided by a single point query with no trusted responder. Bounds are closed-form under stated assumptions; the one-million-TPS regime is demonstrated, the tens-of-millions a marked near-term projection.
Como a perícia blockchain organiza evidências para vítimas e advogados Golpes com criptomoedas costumam envolver promessas de investimento, falsas corretoras, pirâmides, phishing, malware, engenharia social e transferências para carteiras controladas por fraudadores. A boa notícia é que blockchains públicas deixam rastros verificáveis. A má notícia é que transformar esses rastros em prova útil exige método. O que a perícia blockchain consegue mapear Uma análise técnica pode identificar transações de entrada e saída, carteiras intermediárias, consolidação de valores, uso de bridges, mixers, exchanges, contratos de tokens e movimentações de stablecoins como USDT e USDC. O objetivo é reconstruir o caminho do ativo e apontar possíveis pontos de identificação.
George Sebastian, Neethu Tom, Saritha M S, Vimal Babu P
Existing cloud storage auditing mechanisms rely on third-party auditors (TPAs) or centralized verification, introducing single points of failure and trust assumptions. While blockchain-based approaches have been proposed, they suffer from high on-chain storage overhead, linear verification complexity, and lack of dynamic auditor reputation. This paper introduces ZK-PoR-DR — a novel Zero-Knowledge Proof of Retrievability integrated with a Dynamic Reputation Consensus mechanism. Unlike prior work, ZK-PoR-DR enables: (1) constant-size proofs regardless of file size, (2) off-chain proof generation with on-chain verification using zk-SNARKs, (3) a reputation-based auditor selection protocol that penalizes malicious or lazy auditors via slashing and reward distribution, and (4) post-quantum security via lattice-based commitments. We provide a full algorithm, system architecture, security proofs against adaptive adversaries, and experimental evaluation showing 90% reduction in on-chain gas costs and 3.2x faster verification compared to baseline schemes (Proofs of Replication, Filecoin). No prior work has combined these four properties simultaneously. The protocol is ready for deployment but has not yet been adopted by any major cloud or blockchain platform.
Modern military logistics and command systems face significant challenges in terms of security, transparency, and verifiability. Traditional centralized systems are vulnerable to single points of failure and malicious attacks, while the transmission of sensitive orders and supply manifests risks interception. This paper proposes a novel framework that leverages a permissioned blockchain to create an immutable and auditable ledger for both physical asset and information logistics. To address the critical need for confidentiality, our framework integrates Zero-Knowledge Proofs (ZKPs), enabling military units to verifiably confirm not just the receipt, but the correct content and understanding of commands or assets without revealing any operational data on-chain. This approach ensures end-to-end integrity, non-repudiation, and resistance to future quantum decryption threats while maintaining the highest level of data privacy. We present the system architecture, detail the interaction protocols, and demonstrate its effectiveness through practical use case scenarios, including the secure delivery of sensitive assets and commands.
As large language models (LLMs) grow in scale and are predominantly served from remote platforms, verifying faithful inference execution becomes critical (i.e., ensuring that a provider actually executes the advertised model and computational workload rather than a tampered or downsized variant). Zero-knowledge (ZK) LLM inference offers an appealing approach. It promises public verifiability and delivers per-instance guarantees of equational correctness by proving that an output is consistent with executing a public architecture under committed, private weights. Though, we show that it does not bind the effort expended to produce the output. In this paper, we formalize this overlooked effort gap and introduce the Hollow-LLM Attack, in which a dishonest provider retains the declared architecture and parameter count but embeds ghost weights whose algebraic structure collapses effective computation. These witnesses satisfy the verification circuit and yield valid proofs, even though the dishonest model owner, who serves as the prover, performs computation commensurate with a much smaller model than the declared public architecture. This creates a profitable equilibrium in which providers deliver provably correct outputs at small-model cost while overclaiming model size. Accordingly, we characterize concrete families of ghost weights that compose with standard transformer blocks and show that such hollow deployments substantially reduce serving cost with zero quality loss under the same verification circuit. These findings underscore that proof of correct inference is not proof of large-model execution and necessitate additional protections to bind correctness to verifiable computational work.
Austin Bennett, Preston Vander Vos, Duc V. Le, Mira Belenkiy
Decentralized Autonomous Organizations (DAOs) run protocol governance by letting token holders vote on proposals. The dominant rule, voting power proportional to wallet balance, concentrates control among a small number of large holders, fueling the token-control governance attacks that have already compromised real protocols. To counter this concentration, the community has turned to anti-plutocratic voting mechanisms such as Quadratic Voting (QV), which assign sublinear voting power per token with the goal of dampening the influence of large holders. We prove that no voting rule that derives power solely from wallet balance can succeed on a permissionless blockchain. Through a costed model of on-chain voting that captures realistic blockchain frictions -- including per-wallet splitting and voting costs, fixed setup costs, and minimum-balance requirements -- we show that whenever a wallet of any size yields nonzero voting power, a Sybil attacker who splits tokens across many wallets achieves total voting power that grows at least linearly in their token holdings. For concave rules actually proposed to dampen governance power -- those that are positive, increasing, and finite -- we show that the optimal strategy yields power that is asymptotically linear in token holdings, regardless of the cost scheme. Instantiating the model on real DAOs reveals attack costs orders of magnitude below the value at stake. Replaying the ten most recent finalized proposals of five major DAOs (ENS, Compound, Uniswap, Arbitrum, and ZKsync) under linear, quadratic, logarithmic, and power-($β= 0.25$) voting, we measure Sybil amplification factors between $1,172\times$ and $4,039\times$ under Quadratic Voting, and exceeding $229,000\times$ under steeper power rules.
On-chain crowdsourcing leverages blockchain's decentralization, transparency, and tamper-resistance to build trustworthy and verifiable Web3 crowdsourced services. However, existing decentralized reputation frameworks do not reconcile anonymity, reputation binding, and scalability. This paper demonstrates how on-chain crowdsourcing can simultaneously achieve these requirements under a trust-minimized model. We introduce DARTIC, a decentralized, anonymous, and scalable reputation-driven framework for crowdsourcing. DARTIC presents a dual-ledger system that enables requesters and workers to use distinct pseudonyms across interactions, ensuring unlinkability while maintaining accountability. To mitigate Sybil and reputation-reset attacks, we employ zkSNARK-based set membership proofs, cryptographically binding all user pseudonyms to a single access token without revealing the linkage. For scalability, we investigate two aggregation techniques that compress multiple proofs into a single succinct proof to minimize verification overhead. In addition, we design an automated, privacy-preserving reputation model that dynamically evaluates contributions across diverse crowdsourcing contexts. To demonstrate practicality, we instantiate and assess DARTIC in both crowdsensing and federated learning scenarios. Experimental results show that (i) individual proof generation for token spending completes in less than 3s, (ii) aggregation reduces the verification time of 1024 proofs from 8.7s to 0.96s, and (iii) zk-batching lowers gas costs by more than 100x compared to a pure Layer-1 deployment. These results demonstrate that anonymity, robust reputation binding, and scalability can be jointly achieved in fully decentralized crowdsourcing systems.
Autonomous trading agents can read markets and place orders faster than humans can supervise them. On a permissionless exchange, the usual answer is to give the agent a signing key. That is a large amount of trust. Anything that can steer the agent's prompt, memory, or context can also steer how the key is used. Recent attacks on Web3 agents show that this is not a hypothetical risk. Checking every order on the settlement chain gives a public record, but it also puts block latency in the order path. A continuous limit-order book cannot spend that. Bounded Authority puts the authority check where the order enters the venue. The user's wallet registers a risk policy on the settlement chain and authorizes a short-lived public session key. Agents propose orders. The off-chain sequencer accepts an order only after it verifies the session-key signature and runs the policy before any exchange state changes. For every accepted order, the sequencer signs the order, sequence number, risk-input hash, policy transition, match event, and append-only log leaf. Epoch roots are posted to settlement. Watchers can then challenge unauthorized orders, bad risk inputs, broken reserve or margin transitions, equivocation, or invalid matching with Merkle proofs and replayed execution. This gives agents a permissionless analogue of direct-market-access risk control. If a prompt-injected or memory-poisoned agent produces an order outside the user's policy, the result is slashable evidence against the venue rather than loss against the user. We give the protocol, threat model, accountability arguments, Solidity gas measurements for settlement challenges, and AWS measurements for the execution path. On two c7i.metal-24xl hosts, the directly measured kernel-TCP path returns signed Ed25519 acknowledgements for accepted resting orders in 124.17 microseconds median and 128.34 microseconds p99. A bounded-HMAC variant reduces this to 105.31 microseconds median, but it needs delayed key disclosure, threshold ingress, or an equivalent origin-accountability assumption.
The interplay between the advancements in quantum computing techniques and the adoption of the distributed learning approach pose an enormous challenge to conventional cryptographic authentication protocols. Traditional public key systems and federated learning (FL) authentication methods based on the hardness of solving the integer factorization problem or discrete logarithms become inefficient due to the existence of Shor’s algorithm. This paper gives a detailed review of the latest research efforts toward the development of efficient and secure privacy-preserving FL authentication methods based on Post-Quantum Cryptography (PQC). In particular, we present the state-of-the-art of three schemes, namely, PQBFL (Post-Quantum Blockchain-based Federated Learning), ZKFL-PQ (Zero-Knowledge Federated Learning with Lattice-Based Encryption), and Enhanced EAADE for vehicular networks. It is shown that lattice-based authentication is both computationally efficient (signing times of around 0.65 ms) and robust against quantum attacks. Our proposed hybrid scheme is comprised of ML-KEM for key encapsulation, ML-DSA-65 for digital signatures, and Zero-knowledge proof for gradient integrity verification. The empirical evaluation shows a reduction of 44.96% in the computation cost and 22.16% in the communication cost relative to the class.
Ms. Anushka Prasad Joshi, Prof. Sachin Bhosale, Dr. Shubhangi Gunjal, Dr. Anand Khatri
Abstract: With real estate markets digitalizing at a remarkable pace, there's a growing — and largely unmet — need for machine learning systems that can harness multi-institutional data without putting privacy or regulatory standing at risk. In this paper, we present a Privacy-Preserving Federated Learning (PP-FL) framework built specifically for digital real estate ecosystems. Our approach lets distributed stakeholders — property agencies, government land registries, financial institutions, and PropTech platforms — collaboratively train predictive models without ever pooling their raw transaction or personal records in one place. We've designed the system around three interlocking privacy layers: a DP-SGD-based differential privacy optimizer, a homomorphic encryption scheme for gradient transmission, and a secure multi-party computation protocol to safeguard intermediate model states. On top of that, a blockchain-backed audit mechanism using zero-knowledge proofs provides verifiable, regulator-friendly compliance. When we tested the framework on a simulated dataset of 2.4 million real estate transactions spanning multiple institutional clients, it achieved 91.8% prediction accuracy — just 2.4 percentage points behind a fully centralized model — while holding the differential privacy budget to ε = 0.5, cutting communication overhead by 65% relative to naive federated approaches, and satisfying both GDPR and RERA requirements. We believe these results make a strong case that high-utility, privacy-first collaborative learning is not just theoretically possible but practically deployable in today's real estate sector. Keywords: Federated Learning, Differential Privacy, Homomorphic Encryption, Real Estate Analytics, Secure Multi-Party Computation, Blockchain, GDPR Compliance, Data Sovereignty, PropTech, Zero-Knowledge Proofs.
A framework for reusable compliance attestation in regulated industries based on cryptographic primitives, vector commitments with selective-opening proofs, re-randomisable signatures, zero-knowledge succinct non-interactive arguments of knowledge, and cryptographic accumulators with succinct non-membership proofs, composed into a protocol structure adapted to the specific structure of multidimensional compliance state. We identify five gaps that separate the generic primitives from a deployable solution for compliance attestation: multidimensional state binding, temporal freshness without correlation, revocation under reuse, cross-issuer aggregation, and verifier predicate richness. We sketch the protocol structure that addresses these gaps, analyse its security and privacy properties, and discuss applications in age verification, right-to-work assurance, and continuous-compliance monitoring. Companion preprint to UK Patent Application GB2611280.5 filed at the UK Intellectual Property Office on 14 May 2026.
Cross-domain data sharing in decentralised environments faces persistent challenges related to confidentiality, auditability, and trust decentralisation, particularly when data transmission relies on centralised intermediaries or single proxy entities. To address these issues, this paper proposes a blockchain-enabled auditable data sharing scheme that integrates threshold secret sharing with non-interactive zero-knowledge proofs. In the proposed framework, the encrypted file fragments and secret key shares are decentralised across multiple blockchain nodes using threshold cryptography, preventing any single entity from reconstructing the encryption key or unilaterally performing ciphertext transformations. Zero-knowledge proofs are employed to publicly verify the correctness of the transmission and sharing operations without disclosing plaintexts, secret keys, or sensitive metadata, while the blockchain records verifiable proofs to support tamper-evident auditing. Security analysis shows that the scheme achieves confidentiality, collusion resistance, and verifiable correctness under standard cryptographic assumptions.Experimental evaluations indicate that the proposed scheme incurs acceptable computational and on-chain overhead, suggesting its feasibility in decentralised and cross-domain data sharing scenarios.