As the field of cybersecurity has experienced continual changes, up-to-date techniques have become increasingly necessary to analyze and defend against threats. Furthermore, the current methods consistently produce false alarms and sometimes completely miss real threats. This paper proposes an approach that integrates secure blockchain technology with data preprocessing, deep learning, and reinforcement learning to enhance threat detection and response capabilities. To secure the exchange of threat intelligence information, a safe blockchain network is used, which comprises Byzantine Fault Tolerance for high data integrity and Zero-Knowledge Proofs for access control. All relevant information is cleaned and standardized prior to analysis. Subsequently, graph convolutional neural networks with autoencoders are trained on large unlabeled sets of threat data to automatically label various types of threats, with the system employing fuzzy logic to rank and score possible threats. Furthermore, we implemented a feedback loop that incorporates reinforcement learning, thereby improving model performance over time according to guidance provided by cybersecurity specialists. The proposed system achieved high accuracy, precision, negative predictive value, and MCC, as well as notably low FPR and FNR values. The results establish that the proposed system is a reliable and effective measure for detecting cyberthreats.
The Internet of Medical Things (IoMT) is transforming healthcare by enabling devices to generate and share critical patient data. However, securely sharing this data across different healthcare entities remains a significant challenge due to concerns over privacy and security. Traditional solutions using Ciphertext Policy Attribute-Based Encryption (CP-ABE), Self-Sovereign Identity (SSI), and Zero-Knowledge Proofs (ZKPs) offer secure and anonymous data access, but they often fall short in scalability and integration, particularly in cross domain environments. To address these limitations, we introduce SSL-XIoMT, an optimized SSI and ZKP authentication framework within a consortium Hyperledger-based environment. This innovative system integrates SSI under advanced Zero-Knowledge Scalable Transparent Argument of Knowledge (ZK-STARK) and Plonk protocols within a consortium Hyperledger framework for privacy-preserving identity verification. We enhance identity privacy by integrating Multi-Party Computation (MPC), ensuring that identity credentials and ZKP proofs are securely shared and reconstructed without exposing sensitive information. Additionally, we optimize CP-ABE by offloading complex computations to fog nodes, which pre-compute attributes and logical operations. This approach significantly reduces computational overhead and enhances both privacy and efficiency. Our extensive analysis shows that SSL-XIoMT dramatically improves the performance of processing time for CP-ABE encryption and decryption compared to current methods. Moreover, our hybrid ZKPs based authentication approach outperforms the existing schemes regarding processing time and flexibility. The throughput test also demonstrates that SSL-XIoMT is practical for large scale cross-domain data sharing implementation.
Mosbah Alown, Mehmet Sabır Kiraz, Muhammed Ali Bingöl
Electronic voting (e-voting) systems have significantly improved the traditional voting process by addressing key concerns such as security, public acceptability, and convenience. However, these systems often face unique challenges, such as ensuring voter privacy and verifiability, preventing coercion and double voting, and maintaining scalability while protecting participant confidentiality. This study critically analyses and compares various e-voting schemes and technologies, evaluating their security features, verifiability mechanisms, and potential vulnerabilities. This paper reviews Direct Recording Electronic (DRE) voting, internet voting, and blockchain-based e-voting systems. In so doing, we provide an understanding of cryptographic primitives employed in e-voting systems and how they address specific characteristics and challenges associated with each voting scheme. Furthermore, we examine the applications proposed by previous studies in the context of these voting systems, assessing their strengths, limitations, and impact on democratic procedures. The cryptographic primitives reviewed include techniques like homomorphic encryption, blind signatures, and zero-knowledge proofs, which can enhance voter privacy, verifiability, and resistance to coercion and double voting.
The Hadamard product (also known as element-wise multiplication) is a fundamental operation in linear algebra, performed by multiplying corresponding elements of two matrices with the same dimensions. This operation plays a crucial role in various fields, including cryptography, where it enables efficient and parallelizable computations on large datasets—particularly in the design of cryptographic protocols such as zero-knowledge proofs. In this paper, we propose a transparent and efficient method for proving the Hadamard product between vectors that are independently committed in the groups G1and G2under a pairing operation e : G1×G2→ GT . For a vector of length n, the prover has a complexity ofOλ(n), while the proof size isOλ(logn). The verifier operates with a complexity ofOλ(logn), which includesO(logn) operations in GT and onlyO(1) pairing operations, making verification highly efficient. We prove the security of our scheme under the Symmetric External Diffie-Hellman (SXDH) assumption. Furthermore, we propose an aggregator for Groth16 (EUROCRYPT 2016) zk-SNARKs and a proof aggregation technique for the general case of the KZG polynomial commitment scheme (ASIACRYPT 2010), where all crs are distinct. Both applications do not require an additional trusted setup, support logarithmic-sized aggregated proofs, and significantly reduce the verifier’s pairing operations toO(1).
Increasing attention to digital identity and self-sovereign identity (SSI) is gaining momentum. SSI brings various benefits to natural persons, such as owning controls; conversely, digital identity systems in the real world require Sybil-resistance to comply with anti-money laundering (AML) and other needs. CanDID by Maram et al. proposed that decentralized digital identity systems may achieve Sybil-resistance and preserve privacy by utilizing multi-party computation (MPC), assuming a distributed committee of trusted nodes. Pass et al. proposed the formal abstraction of attested execution secure processors (AESPs) while equipping hardware-assisted security in mobile devices has become the norm. We first describe our proposal to utilize AESPs for building secure Sybil-resistant SSI systems, the architecture with a set of system protocols$\Pi ^{{\mathcal {G}}_{\mathtt {att}}}$, which brings drastic flexibility and efficiency compared to existing systems. In addition, we propose a novel scheme that enables users (holders) to request verifiers to verify their credentials without AESPs, and it further achieves unlinkability among credentials created for public verification. Our scheme introduces a simplified format for computed claims and commitment-based anonymous identifiers. We also describe a technique to utilize zero-knowledge membership proofs, in particular, “One-Out-of-Many Proofs”$\Sigma $-protocol by Groth and Kohlweiss, which can prove the existence of an expected credential without identifying it. Along with other techniques, such as utilizing the BBS+ signature scheme, we demonstrate how our scheme can achieve its goals with the extended anonymous and Sybil-resistant SSI system protocols$\Pi ^{{\mathcal {G}}_{\mathtt {att}}+}$. Entitling unlinkability among derived credentials in the anonymous Sybil-resistant SSI results in proper privacy preservation.
Leandro Loffi, Gerson Luiz Camillo, Cristiano Antonio de Souza, Carla Merkle Westphall · 5 authors
Digital evidence plays an increasingly crucial role in judicial proceedings due to the exponential growth in the creation, storage, and transmission of digital data. However, its inherent volatility and susceptibility to tampering necessitate robust mechanisms to ensure integrity and authenticity, making an effective chain of custody (CoC) a fundamental requirement. While state-of-the-art reviews identify various aspects, it is necessary to include the use of Self-Sovereign Identity (SSI) systems within the scope of research. To address this challenge, this article conducts a systematic review of the literature on the use of blockchain and SSI in managing the chain of custody of digital evidence. The review began with 9,178 studies, which, after a rigorous process applying inclusion and exclusion criteria, resulted in 39 studies directly related to the research topic. The study maps and reviews techniques, tools, methods, approaches, and security components for managing the chain of custody of digital evidence. The findings confirm the widespread adoption of blockchain for preserving digital evidence while indicating that SSI remains an emerging and underexplored concept in forensic applications. The results highlight the need for further research on off-chain storage mechanisms, privacy-preserving techniques such as Zero-Knowledge Proofs (ZKPs) to enhance security, auditability, and interoperability when combined with Verifiable Credentials (VCs). By mapping the current state of research, this study provides valuable insights into CoC, Blockchain, and SSI in forensic-based proposals, identifying research gaps, limitations, and opportunities for developing more robust and scalable evidence management systems.
The increasing reliance on e-commerce platforms has amplified challenges related to transparency, trust, fraud, and inefficiencies in reward distribution systems. Existing centralized architectures fail to address these issues effectively. This paper proposes BlockArc, a blockchain-based smart contract framework designed to revolutionize reward systems in e-commerce. The system leverages a permissioned blockchain and smart contracts to automate reward distribution, enhance security, and ensure transaction transparency. The framework consists of four layers: Blockchain Layer, Smart Contract Layer, Application Layer, and User Roles, each addressing key challenges such as reward fragmentation, fraudulent transactions, and inefficient refund processes. Smart contracts autonomously handle reward issuance, redemption, and expiration while integrating oracles for real-world data validation. Security is reinforced using cryptographic hashing, Zero-Knowledge Proofs (ZKPs), and Role-Based Access Control (RBAC) to prevent fraudulent activities. A performance evaluation demonstrated 112 transactions per second (TPS) under moderate load, fraud detection accuracy of 100%, and a 37% reduction in operational costs by eliminating intermediaries. User satisfaction surveys indicated high levels of trust and transparency. The study concludes that BlockArc enhances e-commerce reward systems by improving efficiency, security, and decentralization, paving the way for scalable and interoperable blockchain applications in digital commerce.
Blockchain technology has emerged as prominent player in supporting the United Nations’ Sustainable Development Goals (SDGs), by providing transparent, decentralized solutions across various sectors. However, the inherent transparency of blockchain raises significant privacy concerns, particularly in sensitive fields such as healthcare, finance, and supply chains, where confidentiality is essential. To address these challenges, we delve into emerging privacy-preserving techniques such as Ring Signatures, Zero-Knowledge Proofs (ZKPs), Secure Multi-Party Computation (SMPC), Trusted Execution Environments (TEEs), and mixers, examining their implementation, effectiveness and limitations in safeguarding user data without compromising blockchain’s core features. Additionally, we provide a deep technical analysis of next-generation blockchain platforms, which implement these techniques to balance privacy, scalability, and interoperability. By offering a deep dive into the architectures and privacy mechanisms of these platforms, this paper contributes to understanding how blockchain can be leveraged to achieve SDG objectives while addressing the critical issue of data privacy.
The advent of 6G networks places very high demands on ultra-low latency, high throughput, and quantum-secure communication to power Industry 5.0 use cases. Traditional blockchain architectures, given their decentralized and secure nature, often fall short in meeting the performance and security requirements of such an ecosystem. In this paper, we present a post-quantum blockchain architecture that employs CRYSTALS-Dilithium and SPHINCS+ for digital signatures and block and transaction verification, respectively, along with zk-STARKs to facilitate scalable zero-knowledge proof-based privacy, and a DPoS+VDFs consensus protocol to satisfy fairness and efficiency. We prototyped and evaluated the proposed framework with a benchmarking setup composed of Python, PQClean, liboqs, and Google Benchmark tools. Experimental results demonstrate that the system achieves a 40% reduction in latency, a 35% increase in transaction throughput, and a 25% reduction in computational overhead due to the integration of zk-STARK. Furthermore, finality time for consensus was reduced by 30% by using the hybrid DPoS-VDF consensus approach. Comparative studies with various lattice-, hash-, and code-based quantum cryptographic primitives have shown that CRYSTALS-Dilithium and SPHINCS+ outperform others in key generation, signing, and verification performance indicators, and thus qualify as optimal solutions for edge-centric 6G infrastructures. Conversely, zk-Starks showed near-optimal timeliness and verification effectiveness among the several examined zero-knowledge proof schemes. These findings validate the proposed framework as an efficient, scalable, and performance-enhanced blockchain solution for securing industrial ecosystems with latency sensitivity in a 6G-enabled environment.
Frontier AI systems, including large-scale machine learning models and autonomous decision-making technologies, are deployed across critical sectors such as finance, healthcare, and national security. These present new cyber-risks, including adversarial exploitation, data integrity threats, and legal ambiguities in accountability. The absence of a unified regulatory framework has led to inconsistencies in oversight, creating vulnerabilities that can be exploited at scale. By integrating perspectives from cybersecurity, legal studies, and computational risk assessment, this research evaluates regulatory strategies for addressing AI-specific threats, such as model inversion attacks, data poisoning, and adversarial manipulations that undermine system reliability. The methodology involves a comparative analysis of domestic and international AI policies, assessing their effectiveness in managing emerging threats. Additionally, the study explores the role of cryptographic techniques, such as homomorphic encryption and zero-knowledge proofs, in enhancing compliance, protecting sensitive data, and ensuring algorithmic accountability. Findings indicate that current regulatory efforts are fragmented and reactive, lacking the necessary provisions to address the evolving risks associated with frontier AI. The study advocates for a structured regulatory framework that integrates security-first governance models, proactive compliance mechanisms, and coordinated global oversight to mitigate AI-driven threats. The investigation considers that we do not live in a world where most countries seem to be wishing to follow European Union ideals, and in the wake of this particular trend, this research presents a regulatory blueprint that balances technological advancement with decentralised security enforcement.
Open access
2 source records
Ethics and Social Impacts of AI
Artificial Intelligence in Healthcare and Education
Modern demand for blockchain scaling demanded the developmentof sharding as a viable solution that facilitates parallel processingwhile supporting cross-shard communications. The implementation ofsharding provides excellent scalability to decentralized systems, but itentails enormous complexities in maintaining integrity of smart contracts across different shards. This study analyzes pivotal deploymentslike Ethereum 2.0, NEAR protocol, and Polkadot. This innovationidentifies vulnerabilities on atomicity, consistency, and validator security when executing decentralized applications (dApps). This researchreviews contemporary literature and emerging technologies to identifykey security risks such as replay attacks, shard takeover, and data unavailability events. Various methodologies for reducing vulnerabilities,including atomic commit protocols, dynamic validator assignment,zk-SNARKs, and SP-Chain architecture, are assessed in this report.This study evaluates the implementation of an Escrow smart contract that utilizes Practical Byzantine Fault Tolerance (PBFT) and Proofof-Stake (PoS) coordination protocols through evaluation tests. Thisresearch work analyzes code using both static and dynamic methods to detect security weaknesses in contracts and then recommendssolutions that enhance the robustness of these contracts.The intelligent contract is tested for performance in single-shardmode as well as cross-shard operations. It experiences quick responsetimes and effective data processing with single-shard execution butfaces latency, receipt verification issues, and synchronization difficulties with cross- shard operations. This study findings are that organizations require more effective systems for communication of databetween shards. This research suggests future improvement throughthe addition of zero-knowledge proofs, dynamic re-sharding procedures, and decentralized arbitration secure and scalable smart contractdeployment methods. The proposed solution is applicable to use casessuch as freelancing, crowdfunding, and supply chain processes, withdemonstrations using real-life examples.As a result of the comprehensive assessment, improved safe smartcontract frameworks for next generation blockchain systems are developed, making it easier to implement decentralized applications widelyin scale network contexts.
The consensus problem in distributed ledger systems has two distinct dimensions that existing protocols systematically conflate. The first is the Byzantine fault-tolerance question: can a network reach agreement in the presence of arbitrary failures? The second — less formalised but no less fundamental — is the anti-cartel question: can the incentive structure of the consensus mechanism structurally resist the formation of cartels that reconstitute centralised authority under a nominally decentralised banner? Bitcoin's proof-of-work has produced a system where a small number of industrial mining pools control the majority of hash power. BitCell is a proposal that takes the anti-cartel question seriously as an engineering problem rather than an economic folk theorem. BitCell replaces hash-grinding and stake-weighting with cellular automaton tournaments as the computational substrate for block proposal rights. In each round, miners commit to a pattern in a bounded Conway's Game of Life grid, are verifiably randomly paired via a VRF-based pairing mechanism, and compete in a deterministic single-elimination tournament whose outcome depends on strategic pattern design rather than raw computational expenditure or capital size. Victory rights are not transferable and are not enhanced by pooling strategies: a cartel of sub-majority miners cannot coordinate to construct a jointly optimal pattern that dominates unilateral honest play, because the tournament's pairwise structure, hidden identities (via ring signatures), non-shareable rewards, and reputation-gated eligibility remove each of the primary economic motivations that make mining pools attractive. Under a simple Bayesian model of miner incentives, collusive strategies for sub-majority cartels yield strictly lower expected payoffs than unilateral honest participation. Tournament eligibility and reward weighting are governed by an Evidence-Based Subjective Logic (EBSL) reputation layer. All state transitions are proven using succinct zero-knowledge proofs, enabling a ZKVM-backed smart contract layer with native privacy. BitCell makes three primary contributions: (i) a proof-of-computation consensus mechanism whose computational task is verifiable, bounded, non-parallelisable by pooling, and intellectually non-trivial; (ii) a game-theoretic proof that the combination of pairwise tournaments, anonymised pairing, non-transferable victory rights, and reputation gating renders cartel coordination strictly dominated in a Bayesian Nash equilibrium; and (iii) a native ZKVM execution environment for privacy-preserving smart contracts.
Identity-based cryptography (IBC), proposed by Adi Shamir, revolutionized public key authentication by eliminating the need for certificates, enabling a more efficient and scalable approach to cryptographic systems. Meanwhile, in \cite{Katsumata2024group}, Katsumata et al. were the first to present the blind signature protocol based on the hardness assumption of isogeny with provable security, which resembles the Schnorr blind signature. Building upon these foundational concepts, we propose an Identity-Based Blind Signature Scheme with an Honest Zero-Knowledge Verifier utilizing the CSIDH framework. This scheme combines blind signatures for privacy preservation with zero-knowledge proofs to ensure the verifier's honesty without revealing any additional information. Leveraging the quantum-resistant properties of CSIDH, a post-quantum secure scheme based on supersingular isogenies, our scheme offers strong protection against quantum adversaries while maintaining computational efficiency. We analyze the security of the introduced protocol in the standard cryptographic model and demonstrate its effectiveness in safeguarding privacy and verifier honesty. Furthermore, we present a performance evaluation, confirming the practical viability of this quantum-resistant cryptographic solution for privacy-preserving applications. This work advances the creation of secure, and scalable cryptographic systems for the post-quantum era.
In recent years, generative artificial intelligence (GenAI) has demonstrated remarkable capabilities in high-stakes domains such as molecular science. However, challenges related to the verifiability and structural privacy of its outputs remain largely unresolved. This paper focuses on the task of molecular toxicity repair. It proposes a structure-private verification framework—ToxiEval-ZKP—which, for the first time, introduces zero-knowledge proof (ZKP) mechanisms into the evaluation process of this task. The system enables model developers to demonstrate to external verifiers that the generated molecules meet multidimensional toxicity repair criteria, without revealing the molecular structures themselves. To this end, we design a general-purpose circuit compatible with both classification and regression tasks, incorporating evaluation logic, Poseidon-based commitment hashing, and a nullifier-based replay prevention mechanism to build a complete end-to-end ZK verification system. Experimental results demonstrate that ToxiEval-ZKP facilitates adequate validation under complete structural invisibility, offering strong circuit efficiency, security, and adaptability, thereby opening up a novel paradigm for trustworthy evaluation in generative scientific tasks. The code is available at: https://github.com/DeepYoke/ToxiEval-ZKP .
Elizaveta Pertseva, Alex Ozdemir, Shankara Pailoor, Alp Bassa · 7 authors
Abstract This paper presents a new refutation procedure for multimodular systems of integer constraints that commonly arise when verifying cryptographic protocols. These systems, involving polynomial equalities and disequalities modulo different constants, are challenging for existing solvers due to their inability to exploit multimodular structure. To address this issue, our method partitions constraints by modulus and uses lifting and lowering techniques to share information across subsystems, supported by algebraic tools like weighted Gr bner bases. Our experiments show that the proposed method outperforms existing state-of-the-art solvers in verifying cryptographic implementations related to Montgomery arithmetic and zero-knowledge proofs.
With the increasing use of online services, the protection of the privacy of users becomes more and more important. This is particularly critical as authentication and authorization as realized on the Internet nowadays, typically relies on centralized identity management solutions. Although those are very convenient from a user's perspective, they are quite intrusive from a privacy perspective and are currently far from implementing the concept of data minimization. Fortunately, cryptography offers exciting primitives such as zero-knowledge proofs and advanced signature schemes to realize various forms of so-called anonymous credentials. Such primitives allow to realize online authentication and authorization with a high level of built-in privacy protection (what we call privacy-preserving authentication). Though these primitives have already been researched for various decades and are well understood in the research community, unfortunately, they lack widespread adoption. In this paper, we look at the problems, what cryptography can do, some deployment examples, and barriers to widespread adoption. Latter using the example of the EU Digital Identity Wallet (EUDIW) and the recent discussion and feedback from cryptography experts around this topic. We also briefly comment on the transition to post-quantum cryptography.
Edward Danso Ansong, Simon Bonsu Osei, Raphael Adjetey Adjei
The surge in identity fraud, driven by the rapid adoption of mobile money, internet banking, and e-services during the COVID-19 pandemic, underscores the need for robust cybersecurity solutions. Zero-Knowledge Proofs (ZKPs) e... | Find, read and cite all the research you need on Tech Science Press
The public ledger characteristic of blockchain grants data immutability but simultaneously introduces privacy leakage risks, making association analysis between on-chain behaviors and real-world identities possible. Existing privacy protection schemes struggle to balance the anonymity of the querier with the traceability of malicious behaviors. On one hand, legitimate inquiry behaviors are easily reverse-tracked by third parties through on-chain records (i.e., "human flesh search" targeting the querier); on the other hand, a completely anonymous environment may lead to data abuse without the possibility of accountability.To address this issue, this paper proposes an anti-"human flesh search" privacy protection system based on blockchain and zero-knowledge proofs. Addressing the aforementioned contradictions, this paper presents a blockchain data sharing scheme that balances privacy and regulation. The scheme utilizes IPFS to implement graded encrypted storage for large files. The core innovation lies in combining the Schnorr protocol and Chameleon Hash to construct a Blockchain Designated Verifier Proof (BDVP). While verifying user query permissions through blockchain smart contracts, the system utilizes the trapdoor property of the Chameleon Hash to achieve the non-transferability of proofs, preventing third parties from reverse-tracking the querier's identity by analyzing on-chain records<sup>[<xref ref-type="bibr" rid="R2">2</xref>]</sup>. Furthermore, the system introduces a threshold private key held by regulatory agencies to ensure that, in the event of data abuse, malicious users can be de-anonymized and held accountable according to the law.