Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

729 papersLast indexed Aug 31, 2026
Search papers

Paper index

729 results · page 1 of 31

Clear filters
Jul 26, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
BSDI 2.0: A Policy Framework for Privacy, National Security, Digital Accountability, and Citizen Sovereignty

Vedanta2.0 Agyat Agyani

Description:Bharat Secure Digital Identity (BSDI 2.0) is a citizen-centric, privacy-preserving identity overlay framework designed for India. It addresses the critical paradox of anonymous online harm versus mass surveillance. Unlike traditional systems that store raw identity documents, BSDI 2.0 uses Zero-Knowledge Proofs (ZKP), W3C Decentralized Identifiers (DIDs), and a Judicial Escrow Mechanism to enable attribute-based verification (e.g., age eligibility) without data disclosure. Platforms verify, but do not store, personal data. Lawful identity disclosure is only possible through multi-signature judicial authorization under strict proportionality and due process, anchored in Article 21. The framework is non-disruptive and interoperable with Aadhaar, DigiLocker, and DPDP Act 2023. It is a conceptual research framework for MeitY, NITI Aayog, and academic review. Keywords: Digital Identity, Privacy by Design, Zero-Knowledge Proof, DPDP Act, eIDAS, Judicial Oversight, Citizen Sovereignty

Open access
2 source records
Privacy, Security, and Data Protection
COVID-19 Digital Contact Tracing
Government, Law, and Information Management
Original source
Jul 24, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
Bharat Secure Digital Identity (BSDI): A Policy Framework for Privacy, National Security, and Citizen Sovereignty

Ghanchi Manish Kumar

Description This preprint presents the Bharat Secure Digital Identity (BSDI) framework, a conceptual policy model for privacy-preserving and citizen-centric digital identity governance. The paper explores how decentralized identity technologies—including Decentralized Identifiers (DIDs), Verifiable Credentials (VCs), and Zero-Knowledge Proofs (ZKPs)—may support secure digital verification while minimizing unnecessary disclosure of personal information. BSDI proposes a governance model in which citizens retain primary control over their digital identity through secure digital wallets, the government serves as a trusted root issuer, and digital service providers function as cryptographic verifiers without retaining sensitive identity data. The framework also discusses lawful and targeted access mechanisms for national security within transparent legal oversight. This work is intended as a conceptual research and policy proposal rather than an implemented technical system. It aims to contribute to ongoing discussions on digital identity, privacy, cybersecurity, digital governance, and citizen sovereignty, and to encourage future interdisciplinary research, policy development, and public debate.

Open access
3 source records
Cybersecurity and Cyber Warfare Studies
Privacy, Security, and Data Protection
Access Control and Trust
Original source
Jul 24, 2026·PRAWO i WIĘĆč
0 cites
The Quantum Veil: Privacy, Security, and Legal Frameworks for Zero-Knowledge Advances

Varda Mone, Abhishek Thommandru, Ayubjon Alijonov Qobiljon o‘g‘li, Mamura Turgunboeva

This study examines the potential of Zero-Knowledge Protocols (ZKPs) as cryptographic mechanisms that enhance privacy and security in the context of advancing quantum technologies. Rather than accepting current legal safe guards and regulatory structures at face value, the study critically evaluates their effectiveness, particularly in healthcare environments where highly sensitive data frequently encounters inadequate protection. The methodology employs a multifaceted approach, integrating qualitative insights, legal case studies, and framework analysis. The findings indicate that zero-knowledge proof techniques can significantly enhance the protection of personal health information. A case study of NantHealth Inc.’s quantum-safe healthcare data protection framework illustrates the practical implementation of post-quantum cryptography and homomorphic encryption, demonstrating how health care organizations may proactively address quantum computing threats while enabling secure data collaboration. The study further demonstrates that incorporating these cryptographic methods into existing legal frameworks not only addresses immediate privacy concerns but also facilitates compliance with evolving data protection standards. The study also suggests that healthcare organizations should reconsider their data security approaches by implementing advanced cryptographic measures while maintaining regulatory compliance.

Open access
Privacy, Security, and Data Protection
Cryptography and Data Security
Information and Cyber Security
Original source
Jul 1, 2026·arXiv (Cornell University)
0 cites
No Country for Old Privacy: The Evolving Challenges of Anonymity in Bitcoin

Ben Hawkins, Joshua Levett, Siamak F. Shahandashti

We present a longitudinal measurement study on the adoption of detectable, second-generation anonymisation protocols in the Bitcoin network, including CoinJoin, CoinSwap, CoinShuffle and Stealth Addresses. By implementing and refining a suite of heuristic filters, we identify over 5.94 million CoinJoin and 23.3 million CoinSwap transactions. Besides, the use of CoinShuffle was unexpectedly found to be closely aligned with the Wasabi wallet operation period. Our analysis reveals consistently low adoption rates, with these protocols constituting less than 1% of network transactions, and a sharp decline in detectable usage following key regulatory events. Furthermore, we find no evidence of standardised Stealth Address adoption, indicating a failure to converge on a common privacy standard. This study provides a comprehensive picture of a niche ecosystem whose on-chain visibility has been largely suppressed, strongly suggesting the migration of privacy-seeking users to less transparent and less detectable methods.

Open access
3 source records
cs.CR
Blockchain Technology Applications and Security
Cryptography and Data Security
Original source
Jun 29, 2026·Vestnik BIST (Bashkir Institute of Social Technologies)
0 cites
Digital certification governance mechanism for school students’ achievements in additional IT education based on blockchain: model, implementation, and effectiveness evaluation

Ekaterina S. Avdeeva, Vitaly S. Reznik

The article proposes a governance mechanism for a blockchain-based decentralized certification system to validate school students’ achievements in additional IT education. The relevance stems from the rapid growth of project-based and short-term learning formats and the fragmentation of credentials, which undermines trust and portability across organizations. The study aims to develop a governance model (stakeholders, roles, responsibilities, access rules), describe an implementation algorithm, and propose an effectiveness evaluation framework at institutional and regional levels. It is argued that technological robustness is unattainable without institutional design: distribution of authority, validation and revocation procedures, and separation of data layers in compliance with minors’ personal data protection requirements. A permissioned consortiumbased distributed ledger architecture is considered, where education providers issue verifiable registry records and verifiers access credential status through controlled mechanisms. The paper also links registry-based certification with the concept of micro-credentials for modular IT learning outcomes and specifies effect metrics: reduced verification transaction costs, shorter confirmation time, improved transparency, and lower fraud risks.

Open access
Blockchain Technology Applications and Security
Technology Adoption and User Behaviour
Privacy, Security, and Data Protection
Original source
May 18, 2026·Big Data and Cognitive Computing
0 cites
Blockchains for Data Management: The DIGI4ECO Use Case and Practical Lessons Beyond Theory

Andreas Polyvios Delladetsimas, Elias Iosif, Stamatis Papangelou, George Giaglis

This article examines blockchain as an enabling technological component for data management tasks that are independent of currency-related functionality, a less-discussed aspect of a technology commonly associated with cryptocurrencies and decentralized finance (DeFi). Drawing on empirical findings from the DIGI4ECO project as a case study, we present a structured literature review and cross-domain analysis of blockchain-based data management systems (BDMSs), examine a representative permissioned BDMS implementation, and synthesize practical design guidelines and implementation insights for BDMS development. This perspective is motivated by core blockchain properties such as immutability and transparency, as well as by the observation that existing resources for BDMS development, including methods, tools, and best practices, remain fragmented and less developed than those available for more mature technologies.

Open access
Blockchain Technology Applications and Security
Privacy, Security, and Data Protection
Cybercrime and Law Enforcement Studies
Original source
Apr 30, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
ConsentLedger: A Blockchain-Based Decentralized Consent Governance Framework

Ayush Mohan Singh, Prakhar Chand, Vidit Goel, Garima Dhawan

In the digital era, personal data is continuously collected, processed, and shared by organizations across various sectors. Traditional consent management systems suffer from centralization, opacity, and insufficient user control, making it difficult for individuals to track and enforce their data-sharing preferences. This paper presents ConsentChain, a decentralized consent governance protocol built on the Polygon blockchain. The system leverages Ethereum-compatible smart contracts to implement purpose-bound, time-limited, and user-revocable consent records, backed by an immutable on-chain audit trail. The architecture employs two core Solidity smart contracts—ConsentManager and AccessController—supported by a React-based frontend and MetaMask wallet integration. Comprehensive end-to-end testing demonstrates 18 of 18 test cases passing, validating the correctness of consent lifecycle management, access validation, role-based access control, and event logging. ConsentChain demonstrates that blockchain technology can provide a transparent, tamper-proof, and user-sovereign alternative to conventional consent management systems, with clear pathways toward enterprise adoption, multi-chain deployment, and zero-knowledge privacy extensions. Index Terms—Blockchain, Consent Management, Smart Contracts, Data Privacy, GDPR, Decentralized Systems, Ethereum, Polygon, Access Control, Audit Trail.

Open access
2 source records
Blockchain Technology Applications and Security
Privacy, Security, and Data Protection
Privacy-Preserving Technologies in Data
Original source
Apr 27, 2026·Mathematics
0 cites
TD-RCRF: A Privacy-Preserving Truth Discovery Resistant to Collusion and Reputation Fraud in Mobile Crowdsensing

Libo Ban, Lei Wu, Wei Wu, Haipeng Peng

Privacy-preserving truth discovery (PPTD) has garnered significant attention in mobile crowdsensing (MCS). However, existing research lacks sufficient privacy protection and is often vulnerable to collusion attacks among malicious participants. Moreover, incorrect data submitted by unreliable users and their weights may reduce the accuracy of truth discovery. To address these issues, this paper proposes a privacy-preserving truth discovery framework resistant to collusion and reputation fraud (TD-RCRF) that is highly resistant to collusion and reputation fraud. The scheme employs additive secret sharing to protect sensing data, weights, intermediate results, and ground truth. To screen trustworthy users who meet reputation requirements under the non-colluding dual-server model, we propose a privacy-preserving reputation verification algorithm that combines Pedersen commitment and zero-knowledge proof to verify the validity of mobile users’ reputation values. Additionally, we propose a homomorphic strategy that converts shares between multiplication and addition and use it to design a lightweight truth discovery algorithm that further improves the accuracy of the “truth” using reputation values. Security analysis proves that TD-RCRF is privacy-preserving and secure under the non-colluding dual-server assumption. Theoretical analysis and experiments show that it is practical and efficient.

Open access
Mobile Crowdsensing and Crowdsourcing
Privacy, Security, and Data Protection
Blockchain Technology Applications and Security
Original source
Apr 12, 2026
0 cites
ShadowClone: Scalable Decentralized Identity with Cross-Domain Anonymity and Accountable Traceability

Y Liu, Zedan Zhao, Boyu Zhao, Na Wang · 6 authors

Decentralized identity (DID) is a key infrastructure for Web3, granting users sovereign control over their private identity data. While existing DID systems like FADID-TT (WWW'25) realize anonymity and traceability within a single domain, the Web3 ecosystem is a multiverse of independent domains like DeFi, GameFi, and DAO. This multi-domain reality presents critical issues for current DID solutions. First, most existing solutions are built on the monolithic committee architecture, facing severe scalability bottlenecks as the committee size grows. Second, most existing solutions cannot offer strong cross-domain anonymity, where frequent cross-domain interaction inevitably exposes the user's privacy. Third, existing methods for tracing the identities of malicious users are inefficient.

Open access
Internet Traffic Analysis and Secure E-voting
Access Control and Trust
Privacy, Security, and Data Protection
Original source
Apr 12, 2026
0 cites
Accessing Web3 Onboarding and Trust via Vipps

Surya Bahadur Kathayat, Magnus Svendsen, Brage Hagemann Brataas

Web3 applications strive to enable decentralization and user sovereignty, but often remain inaccessible to mainstream users due to complex onboarding and unfamiliar interaction paradigms. This study presents a Web2-inspired onboarding solution that integrates an embedded custodial wallet with OpenID Connect (OIDC) authentication via Vipps, a Norwegian bank-backed identity provider with over 4.6 million verified users. The proposed approach abstracts wallet management and removes the need for seed-phrase setup while introducing real-world identity assurance into the Web3 environment. A blockchain-based Battleship proof-of-concept was developed to demonstrate the approach, aiming to make Web3 interactions more intuitive and trustworthy. A mixed-method evaluation, combining usability testing and semi-structured interviews, revealed that integrating familiar login flows with verified identities improves usability, conceptual understanding, and both peer and ecosystem trust. The findings suggest that leveraging centralized identity providers can act as a pragmatic bridge between Web2 and Web3, potentially lowering initial onboarding barriers.

Open access
Personal Information Management and User Behavior
Privacy, Security, and Data Protection
Access Control and Trust
Original source
Apr 10, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
The Immutability Conundrum: Reconciling GDPR Data Subject Rights with Blockchain Architecture in a Borderless and Decentralized Digital Economy

Dr. G.V. Mahesh Naath

This paper examines the complex and evolving relationship between blockchain technology and the General Data Protection Regulation (GDPR), focusing on the fundamental tension between blockchain’s immutability and the data protection rights of individuals. While blockchain offers transformative advantages such as decentralization, transparency, security, and trustless verification, its core architectural feature—immutability—poses significant challenges to compliance with key GDPR principles, particularly the right to erasure, rectification, and data minimization. The study critically analyzes how decentralized and borderless blockchain networks disrupt traditional legal frameworks that rely on identifiable data controllers and territorially bounded regulation. It explores the difficulties in assigning legal responsibility within distributed systems, as well as the complications arising from cross-border data transfers and jurisdictional ambiguities. Further, the paper evaluates emerging technical and regulatory responses aimed at reconciling these conflicts, including off-chain data storage models, encryption-based deletion (crypto-shredding), pseudonymization, and advanced privacy-preserving techniques such as zero-knowledge proofs. It also considers the role of privacy-by-design principles and the need for adaptive regulatory frameworks tailored to decentralized technologies. The paper concludes that the interaction between blockchain and GDPR represents a broader challenge in contemporary law: balancing technological innovation with the protection of fundamental rights. It argues for a coordinated, interdisciplinary approach involving legal scholars, policymakers, and technologists to develop flexible and forward-looking governance models capable of addressing the unique characteristics of decentralized digital ecosystems.

Open access
2 source records
Blockchain Technology Applications and Security
Privacy, Security, and Data Protection
Cybersecurity and Cyber Warfare Studies
Original source
Apr 2, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
Age Verification Without Surveillance on AI-Driven Social Media: How Purpose-Bound Cryptography Resolves the Online Safety Paradox

Sangam Das

About this paper This paper argues that the conflict between online protection and privacy is not inevitable. The real problem is that most current systems wrongly treat compliance and identity as the same thing. The proposed VI + CJT framework separates them. It allows platforms to receive only the minimum lawful compliance result they need — for example, whether a user falls below the relevant legal age threshold — without learning the child’s name, date of birth, address, biometric profile, or broader identity. In that sense, the paper’s central theme is age verification without surveillance through purpose-bound cryptographic enforcement. How AI Makes the Problem Worse AI makes the children’s online safety problem more serious in three distinct ways. First, it changes exposure from passive to active. Harmful material is no longer merely available on a platform; recommendation and optimisation systems can identify vulnerable users, rank harmful content more aggressively for them, and progressively amplify it based on engagement signals. In that environment, a child is not simply finding harmful content — the system is learning from the child and serving more of it. Second, AI makes weak age-verification methods more dangerous. A false self-declared age is no longer just a wrong entry in a sign-up form. Once accepted, it becomes operational input for recommendation, advertising, and behavioural optimisation systems, which then treat the child as an adult user profile. This means the error is not static; it is continuously acted upon by AI systems that optimise for attention and engagement rather than child protection. Third, AI encourages platforms to solve the problem through more surveillance. In practice, this often means AI-based age estimation using faces, voices, or behavioural patterns. But this approach creates a new harm while claiming to solve another one: it turns child protection into biometric and behavioural monitoring, and can generate datasets that may later be reused for additional profiling or model training. In other words, AI can make age assurance both more intrusive and less accountable. A further difficulty is that AI systems are often opaque even to their operators. As your draft correctly notes, policy rules alone may not be enough, because platforms may not reliably know how their own recommendation systems are treating minors in practice. This is why the problem is not only one of age verification, but also one of enforceable control over AI behaviour. That is precisely why the VI + CJT model matters. It does not ask AI systems to infer age or interpret law for themselves. Instead, it provides a minimal, authoritative compliance signal and machine-readable constraints that can limit recommendation, advertising, and profiling behaviour toward minors without exposing identity. Current Solutions Self-declaration is easily bypassed. A child can simply enter a false age, and the platform’s AI systems then treat that false declaration as valid input for recommendation, targeting, and optimisation. Identity-linked verification creates major privacy risks. When age assurance depends on sharing civil identity information with commercial platforms, the result is unnecessary exposure of family and child data to entities with strong incentives to collect, retain, and monetise it. AI-based age estimation introduces biometric surveillance. Estimating age from face, voice, or behaviour may appear convenient, but it creates new harms by collecting sensitive personal and biometric data as a side effect of child protection. Current systems collapse compliance into identity. What platforms usually need is not the full identity of the user, but only the legally relevant compliance fact. Existing approaches fail because they demand far more data than is necessary for that purpose. Policy rules alone are not enough in AI-driven environments. Even where legal obligations exist, platforms may not reliably translate them into enforceable constraints on opaque recommendation and engagement systems. As a result, compliance may remain declaratory rather than technically enforced. Proposed Solution Use VI + CJT as a purpose-bound cryptographic layer. The framework converts verified civil identity held by trusted authorities into a minimal compliance credential that reveals only the relevant age-threshold result for the applicable jurisdiction. Avoid disclosure of identity data. The credential contains no name, no full date of birth, no address, and no biometric data. Each credential uses a fresh random identifier, making it unlinkable across sessions. Keep the credential under user control. The credential is stored on the user’s device in secure hardware rather than on platform servers, reducing centralised exposure and retention risks. Use zero-knowledge proof for age compliance. When access is requested, the platform receives only a yes-or-no compliance result, without learning the underlying identity attributes or credential contents. Encode law into machine-readable CJTs. The Compliance Jurisdiction Token expresses the applicable legal rules, including jurisdiction-specific age thresholds and AI-related restrictions such as limits on engagement optimisation, advertising targeting, or behavioural profiling for minors. Constrain platform AI without making it identity-aware. Recommendation engines and other AI systems receive only the compliance signal necessary to adjust behaviour for minors, allowing them to become jurisdiction-aware and age-aware without becoming identity-aware. Replace probabilistic AI age estimation with authoritative attestation. Instead of guessing age through opaque models, the framework provides deterministic, government-signed, legally relevant compliance proof. Enable auditability and cross-border enforcement. Regulators can test whether platforms respond correctly to compliance signals, and the applicable child-protection rule can follow the user across borders through jurisdiction-bound credentials and tokens. Core Message The paper’s core message is simple: platforms do not need to know who a child is in order to know what protections the law requires. By separating compliance from identity, the VI + CJT model offers a path to child safety that is enforceable, privacy-preserving, and better suited to AI-driven digital environments.

Open access
2 source records
Ethics and Social Impacts of AI
Privacy, Security, and Data Protection
Digitalization, Law, and Regulation
Original source
Mar 16, 2026·arXiv (Cornell University)
0 cites
Grant, Verify, Revoke: A User-Centric Pattern for Blockchain Compliance

Supriya Khadka, Sanchari Das

In decentralized web applications, users face an inherent conflict between public verifiability and personal privacy. To participate in regulated on-chain services, users must currently disclose sensitive identity documents to centralized intermediaries, permanently linking real-world identities to public transaction histories. This binary choice between total privacy loss or total exclusion strips users of agency and exposes them to persistent surveillance. In this work, we introduce a Selective Disclosure Framework designed to restore user sovereignty by decoupling eligibility verification from identity revelation. We present ZK-Compliance, a prototype that leverages browser-based zero-knowledge proofs to shift the interaction model, enabling users to prove specific attributes (e.g., "I am over 18") locally without revealing the underlying data. We implement a user-governed Grant, Verify, Revoke lifecycle that transforms the user's mental model of compliance from a permanent data handover into a dynamic, revocable authorization session. Our evaluation shows that client-side proof generation takes under 200ms, enabling a seamless interactive experience on commodity hardware. This work provides early evidence that regulatory compliance need not come at the cost of user privacy or autonomy.

Open access
2 source records
cs.CR
cs.HC
Privacy, Security, and Data Protection
Original source
Mar 5, 2026·arXiv (Cornell University)
0 cites
Why Ethereum Needs Fairness Mechanisms that Do Not Depend on Participant Altruism

Patrick Spiesberger, Nils Henrik Beyer, Hannes Hartenstein

Ethereum's ideals of decentralization and censorship resistance are undermined in practice, motivating ongoing efforts to reestablish these properties. Existing proposals for fairness mechanisms depend on the assumption that a sufficient fraction of block proposers adhere to Ethereum's protocols as intended. We refer to such proposers as altruistic, as this behavior may come at the cost of reduced revenue. Prior analyses indicate that a consistent share of 91 percent of proposers delegate block construction to centralized services, effectively signing externally constructed blocks blindly, and are thus not considered altruistic. To assess whether the remaining 9 percent of proposers genuinely exhibit altruistic behavior, we conducted an empirical analysis and found that an additional 6.1 percent also interact with such external services. Further, we found that less than 1.4 percent of proposers consistently acted in accordance with Ethereum's decentralization and censorship resistance objectives. These findings suggest that relying solely on the mere presence of altruistic proposers is insufficient to ensure that proposed fairness mechanisms reestablish Ethereum's ideals, highlighting the need for additional incentive- or penalty-based mechanisms.

Open access
ICT Impact and Policies
Privacy, Security, and Data Protection
E-Government and Public Services
Original source
Mar 5, 2026·Open MIND
0 cites
Why Ethereum Needs Fairness Mechanisms that Do Not Depend on Participants' Altruism

Patrick Spiesberger, Nils Henrik Beyer, Hannes Hartenstein

Ethereum's ideal of censorship resistance, together with related fairness properties, is undermined in practice, motivating fairness mechanisms that aim to restore these properties. Several of these mechanisms hand control over block contents to a committee of proposers under a 1-of-n honest assumption: at least one committee member complies with the mechanism even when deviating would increase personal revenue. We refer to such proposers as altruistic. Yet prior work shows that roughly 91 percent of blocks are constructed by centralized block-building services that demonstrably take user-adverse actions for financial gain; the responsible proposers sign these blocks blindly, without any means of intervention. A common reading of this figure is that 9 percent of proposers forgo these gains and act altruistically. Our empirical analysis of the full year 2025 shows that this share is far smaller: at most 1.55 percent of proposers can plausibly be regarded as altruistic, whereas the remaining 98.45 percent of proposers exhibit observable non-altruistic behavior. We interpret 1.55 percent as an upper bound on the prevalence of altruistic proposers. These results imply that committee-based fairness mechanisms that rely on altruistic members would require substantially larger committees than currently proposed. This raises concerns about their practical viability and motivates mechanisms in which fair behavior is the rational choice.

Open access
2 source records
cs.DC
ICT Impact and Policies
Privacy, Security, and Data Protection
Original source
Feb 24, 2026·Frontiers in Business and Finance
1 cites
Privacy-Enhanced Ad Targeting for Social E-Commerce: A Federated Learning Framework with Zero-Knowledge Verification for Creator Monetization

Xun Yi

The convergence of social networking and electronic commerce has given rise to the social e-commerce paradigm, where content creators serve as the primary drivers of consumer engagement and purchase decisions. However, this ecosystem faces a critical tension between the need for high-precision ad targeting to sustain monetization and the increasingly stringent requirements for user privacy preservation. Traditional centralized recommendation systems require the aggregation of massive user behavioral datasets, creating significant risks of data leakage and violating emerging regulatory frameworks. To address this challenge, we propose a novel framework titled Fed-ZKC (Federated Zero-Knowledge Creator). This architecture synergizes Federated Learning (FL) with Zero-Knowledge Proofs (ZKP) to enable privacy-preserving ad targeting while ensuring verifiable monetization attribution for creators. In our system, user preference models are trained locally on edge devices to prevent raw data transmission, while a cryptographic verification layer ensures that ad interactions are genuine without revealing user identities to the platform or the creators. Extensive experiments conducted on large-scale real-world datasets demonstrate that Fed-ZKC achieves recommendation accuracy comparable to centralized baselines while reducing privacy leakage risks by orders of magnitude. Furthermore, the implementation of succinct non-interactive arguments of knowledge (zk-SNARKs) introduces minimal computational overhead, making the protocol feasible for deployment on modern mobile processors.

Open access
Privacy-Preserving Technologies in Data
Cryptography and Data Security
Privacy, Security, and Data Protection
Original source
Feb 1, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
Privacy-Enhancing-Technologies fĂŒr die Informationssicherheit in Edge-Cloud-Anwendungen

Nils Frederic Jahnke, Sarah Schimankowitz

Edge-Cloud-Systeme ermöglichen Anwendungen, die auf Basis von Daten intelligenter Objekte und Infrastrukturen wirtschaftliche Mehrwerte schaffen und gesellschaftliche Herausforderungen adressieren. Dies bedarf hĂ€ufig eines Teilens von Daten mit Partnern in etablierten Wertschöpfungsnetzwerken oder entlang des Edge-Cloud-Kontinuums. Eine fundamentale Anforderung ist dabei die Sicherstellung des Schutzes sensibler betrieblicher und personenbezogener Informationen. WĂ€hrend die lokale Datenverarbeitung an der Edge ein grundlegendes Maß an Datenschutz und Informationssicherheit ermöglicht, reicht ein ausschließlicher RĂŒckgriff auf diese Maßnahme oftmals nicht aus, um diese Anforderungen bei gleichzeitiger Erzielung der Mehrwerte datengetriebener Anwendungen zu erfĂŒllen. Beispielsweise besteht hĂ€ufig die Notwendigkeit, schĂŒtzenswerte Daten an zentraler Stelle, beispielsweise der Cloud, zu aggregieren, um zu reichhaltigen Erkenntnissen zu gelangen oder die IntegritĂ€t der verwendeten Daten sicherzustellen. An dieser Stelle rĂŒcken Privacy-Enhancing-Technologies (PET) in den Fokus, die Mechanismen umfassen, um Datenschutz, Informationssicherheit und DatensouverĂ€nitĂ€t „by-Design“ in Systemarchitekturen zu integrieren. Bei PET handelt es sich um eine Klasse von individuellen Werkzeugen, die jeweils spezifische Informationssicherheitsanforderungen und -risiken in Edge-Cloud-Systemen adressieren können. FĂŒr Praktiker ergibt sich die Herausforderung, auf Basis der spezifischen Bedarfe ihrer Anwendungen und der verfĂŒgbaren PET-Werkzeuge passende PET-Strategien zu entwickeln, die eine Realisierung der Edge-Cloud-Anwendung unter BerĂŒcksichtigung der Anforderungen und Risiken fĂŒr die Informationssicherheit ermöglichen. Diese Orientierungshilfe unterstĂŒtzt Praktiker bei der Entwicklung eigener PET-Strategien fĂŒr Edge-Cloud-Anwendungen. Sie bietet Hilfestellungen bei der Identifikation von Informationssicherheitsanforderungen und -risiken, der Auswahl passender PET-Werkzeuge und deren Integration in das Anwendungsdesign. Zentrales Element der Studie ist hierbei die Analyse von PET-Werkzeugen in Edge-Cloud-Anwendungskontexten. Die Orientierungshilfe zeigt, wie PET-Werkzeuge zur Umsetzung von Informationssicherheit beitragen können, welche Voraussetzungen fĂŒr ihren Einsatz in spezifischen Szenarien geschaffen werden mĂŒssen und welche Implikationen sich aus dem Praxiseinsatz der PET-Werkzeuge ergeben. Dazu beruft sich die Orientierungshilfe auf die Erkenntnisse der Early-Adopter von Edge-Cloud-Systemen und PET aus den Projekten des Technologieprogramms „Edge Datenwirtschaft“ des Bundesministeriums fĂŒr Forschung, Technologie und Raumfahrt (BMFTR). Die Inhalte dieser Orientierungshilfe adressieren insbesondere Systemarchitektinnen und -architekten und Datenschutzbeauftragte, die Datenverarbeitungsprozesse in Edge-Cloud-Systemen datenschutzkonform gestalten mĂŒssen. Ausgehend von der Darstellung möglicher Risiken wie physischen Angriffen und Cyberangriffen, unsicherer Datenhoheit, Insiderbedrohungen und Fehlkonfigurationen sowie Anforderungen wie Datenminimierung, IntegritĂ€t, Zweckbindung und die Verhinderung von DatenabflĂŒssen „by-Design“ in Edge-Cloud-Anwendungen analysiert diese Orientierungshilfe fĂŒnf konkrete PET-Werkzeuge in praxisnahen Anwendungsszenarien: § Hardware-SchlĂŒssel fĂŒr die sichere Authentifizierung ohne personenbezogene Daten in der Lebensmittelwirtschaft, § Federated-Learning fĂŒr kollaboratives KI-Training ohne Rohdatenweitergabe in der industriellen Fertigung, § Compute-to-Data zur AusfĂŒhrung von Analysen in der Umgebung des DateneigentĂŒmers in der industriellen Fertigung, § Zero-Knowledge-Proofs fĂŒr datenbasierte Nachweise ohne Offenlegung sensibler Daten in der Energiewirtschaft, § Trusted-Execution-Environments fĂŒr vertrauliche Berechnungen in isolierten Hardware-Umgebungen in der Energiewirtschaft. Zudem prĂ€sentiert die Studie vier Handlungsfelder und zugehörige Handlungsempfehlungen fĂŒr den erfolgreichen Einsatz von PET-Werkzeugen in Edge-Cloud-Anwendungen: 1) Aufbau vertrauenswĂŒrdiger Partnerökosysteme und Schaffung notwendiger Anreizmechanismen, 2) Schaffung betrieblicher Voraussetzungen fĂŒr den PET-Einsatz inklusive Schulung und Akzeptanzförderung, 3) Sicherstellung technischer ValiditĂ€t und IntegrationsfĂ€higkeit der PET in den Anwendungskontext, 4) GewĂ€hrleistung regulatorischer KonformitĂ€t der PET-gestĂŒtzten Edge-Cloud-Anwendung. Im Zuge der steigenden Relevanz von Edge-Cloud-Systemen und dem Teilen von Daten zur Generierung von Datenwertschöpfung bei mindestens gleichbleibenden Anforderungen an Datenschutz und Informationssicherheit wird der Einsatz von PET zu einem entscheidenden Erfolgsfaktor. PET ermöglichen nicht nur die Einhaltung regulatorischer Vorgaben, sondern schaffen die Grundlage fĂŒr vertrauensbasierte Kooperationen in komplexen Edge-Cloud-Ökosystemen. Unternehmen, die zukĂŒnftig gemeinsam datengetriebene Wertschöpfung betreiben wollen, sollten sich aktiv mit PET beschĂ€ftigen.

Open access
2 source records
Privacy, Security, and Data Protection
Digitalization, Law, and Regulation
Cloud Data Security Solutions
Original source
Feb 1, 2026·International Journal of Social Science Research (IJSSR)
0 cites
PROTECTING POCKETS IN THE DIGITAL AGE: CRYPTOCURRENCY AND CONSUMER LAWS IN INDIA

Pankhi Devi, Prof. (Dr.) Bhuban Ch.Barooah

The anonymity of cryptocurrency transactions poses substantial obstacles to protecting consumer rights, particularly by hindering tracking and dispute resolution, thereby making it challenging to safeguard consumers. This article examines India's legal framework for protecting consumers engaging in cryptocurrency transactions. It highlights the multifaceted challenges consumers face, including fraud, hacking, phishing, and market manipulation, primarily due to the anonymous nature of cryptocurrency transactions and the inherent lack of robust regulation. Comparing India's approach with that of the US, EU, and Japan, it identifies noticeable gaps in current regulations and subsequently proposes specific, actionable recommendations for improvement. The article emphasises the imperative need for consumer education and awareness, as well as for international cooperation among policymakers, industry stakeholders, and regulators to create a safer, more secure cryptocurrency environment. By analyzing consumer protection laws in depth and proposing amendments, it aims to balance transaction security effectively with investor protection, ultimately promoting a more reliable cryptocurrency ecosystem in India while also suggesting practical implementation strategies for regulators and fostering transparency in decentralized finance (DeFi) platforms to enhance overall market integrity. It further outlines specific policy frameworks that can be adopted to mitigate risks associated with anonymity, alongside actionable steps for enhancing dispute-resolution mechanisms and ensuring continual compliance with evolving global standards in digital asset regulation. KEYWORDS:- cryptocurrency transactions, consumer rights, legal framework, consumer education, transaction security

Open access
Cybersecurity and Cyber Warfare Studies
Privacy, Security, and Data Protection
Copyright and Intellectual Property
Original source
Feb 1, 2026·Proceedings on Privacy Enhancing Technologies
0 cites
The Masks We (Think We) Wear: Privacy Threats of Browser-Extension Wallets in the Web3 Ecosystem

Weihong Wang, Yana Dimova, Victor Vansteenkiste, Tom Van Goethem · 5 authors

Cryptocurrency wallets are the primary interface for managing pseudonymous blockchain addresses, viewing balances, and interacting with Web3 applications. Although users typically assume that their addresses remain independent of each other unless intentionally revealed, modern wallets routinely communicate with both blockchain infrastructure and decentralized applications (dApps), generating network-side and web-side signals that may undermine this assumption. In this paper, we identify and formalize five privacy threats that arise directly from wallets interacting with the network and the web browser. Using large-scale dynamic measurements of 85 of the most popular Chrome Web Store browser-extension wallets (representing 35.16 million users), we observe that routine remote procedure call (RPC) operations leak structural links between a user's addresses; that the majority of Ethereum wallets implement permission revocation inconsistently and continue to expose previously revoked addresses across sessions; and that many wallets inject their provider interfaces into cross-origin iframes, enabling passive cross-site tracking beyond dApps and potentially real-world identity deanonymization without user interaction. Taken together, our results show that these wallet behaviors leak sensitive information that can be used to link multiple addresses to the same user, track wallet users across sessions and sites, and connect their browsing activity to their on-chain wealth. We discuss practical mitigations and show that many of these threats can be substantially reduced through improved wallet implementation, stronger privacy considerations in ecosystem standards, and stricter controls over provider exposure. Our results highlight the need for standardized, privacy-preserving wallet architectures and provide actionable guidance for strengthening user privacy in the emerging Web3 ecosystem.

Open access
5 source records
Privacy, Security, and Data Protection
Advanced Malware Detection Techniques
Spam and Phishing Detection
Original source
Jan 25, 2026·Open MIND
0 cites
The Stateless Pattern: Ephemeral Coordination as the Third Pillar of Digital Sovereignty

Sean Carlin, Kevin Curran

For the past three decades, the architecture of the internet has rested on two primary pillars - communication on the World Wide Web and Value such as Bitcoin/Distributed ledgers. However, a third critical pillar, Private Coordination has remained dependent on centralised intermediaries, effectively creating a surveillance architecture by default. This paper introduces the 'Stateless Pattern', a novel network topology that replaces the traditional 'Fortress' security model (database-centric) with a 'Mist' model (ephemeral relays). By utilising client-side cryptography and self-destructing server instances, we demonstrate a protocol where the server acts as a blind medium rather than a custodian of state. We present empirical data from a live deployment (https://signingroom.io), analysing over 1,900 requests and cache-hit ratios to validate the system's 'Zero-Knowledge' properties and institutional utility. The findings suggest that digital privacy can be commoditised as a utility, technically enforcing specific articles of the universal declaration of human rights not through policy, but through physics.

Open access
3 source records
cs.CR
Cybersecurity and Cyber Warfare Studies
Privacy, Security, and Data Protection
Original source
Jan 14, 2026·Cogent Social Sciences
1 cites
Legal foundations and future directions of AI-enabled cybersecurity: a cross-jurisdictional analysis

Mohamed Chawki

In the contemporary global context, Information and Communication Technologies (ICTs) present multifaceted challenges, particularly in maintaining an appropriate balance between national security requirements and the protection of individual privacy. The rapid advancement of technology has led to an increase in cyber threats, necessitating closer collaboration between the public and private sectors. However, such collaboration often blurs the boundaries between security imperatives and individual privacy rights. This study examines the implications of this balance and assesses whether existing regulations adequately protect individuals’ privacy. The right to privacy is universally safeguarded by ethical norms and legal frameworks. Instruments such as the United States Constitution and the General Data Protection Regulation (GDPR) provide protection against unlawful searches, seizures and the misuse of personal data. Despite these safeguards, information sharing between public institutions and private entities may undermine privacy rights if appropriate accountability mechanisms are not in place. Navigating this complex terrain requires approaches that enable data collection and cybersecurity cooperation without violating individual privacy. Technological innovations, including artificial intelligence (AI) and zero-knowledge proof authentication systems, offer potential solutions by limiting unauthorized access to personal data. This paper argues that reconciling cybersecurity imperatives with the protection of individual rights requires continuous recalibration of legal and ethical boundaries. While data sharing within and across private industries can strengthen defenses against cyber threats, such practices must be carefully evaluated to prevent privacy violations. Achieving this balance ultimately depends on enhanced transparency and accountability.

Open access
Ethics and Social Impacts of AI
Privacy, Security, and Data Protection
COVID-19 Digital Contact Tracing
Original source
Jan 2, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
Bitcoin Custody Failure Modes: A Taxonomy for Professional Interpretation

CustodyStress

Bitcoin custody systems are designed by individuals with full contextual knowledge and later encountered by others—executors, trustees, attorneys, heirs—who must interpret and operate these systems without the original owner present. This interpretive gap produces recurring failure patterns that persist even when custody components technically exist. This paper presents a taxonomy of failure modes observed in Bitcoin custody systems when those systems are encountered under stress conditions including death, incapacity, device loss, and institutional failure. The taxonomy distinguishes between legal authority and cryptographic access, between security and survivability, and between documentation that enables action and documentation that merely describes existence. Seven failure mode categories are examined: (1) documentation without usability, where correct and comprehensive records nonetheless fail to enable execution; (2) time as an active dependency, where dormant systems degrade through institutional change, memory loss, and technological obsolescence; (3) dependency overlap, where apparently redundant components share hidden common roots; (4) partial access traps, where incomplete recovery attempts constrain or block subsequent paths; (5) authority-access misalignment, where legal entitlement and operational capability diverge; (6) coordination failure, where distributed control prevents action when parties cannot align; and (7) delay-induced state changes, where outcomes differ based on when recovery is attempted. The paper provides canonical vocabulary for professional communication about custody situations and offers a scenario reference for modeling system behavior under stress. It is intended as a descriptive reference for fiduciaries, estate planning attorneys, and advisors who encounter Bitcoin custody systems in professional contexts. The paper does not provide recommendations, evaluate custody arrangements, or establish standards of care.

Open access
2 source records
Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Privacy, Security, and Data Protection
Original source
Jan 1, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
Examining Bitcoin Custody Under Stress: A Framework for Observation and Recording

CustodyStress

Bitcoin custody systems are constructed under conditions of full knowledge and activated under conditions of partial knowledge. The person who designs a custody arrangement understands its components, dependencies, and intended operation. The person who later encounters that system—often an executor, trustee, or heir—must interpret and operate it without access to the designer's contextual understanding. This paper defines a descriptive framework for examining Bitcoin custody systems under stress conditions at a point in time, producing reference records for later interpretation. The framework treats examination as observation rather than evaluation: it records what exists, what dependencies connect components, and how the system behaves under modeled stress scenarios. It explicitly excludes advice, recommendations, certification, and adequacy assessment. The framework introduces four modeled outcome states—survives, constrained, blocked, and indeterminate—that describe observed system behavior without normative judgment. It defines stress conditions including owner absence, cognitive unreliability, device loss, institutional delay, and coordination failure. It specifies what reference artifacts examination produces: system snapshots, scenario-bound observations, dependency maps, and assumption registries. The paper addresses how professionals—attorneys, fiduciaries, advisors—can engage with examination records without overstepping interpretive boundaries. It distinguishes what records can establish (what was described, what was modeled, what assumptions applied) from what records cannot establish (adequacy, correctness, future outcomes). The framework is offered as a reference for professional contexts where Bitcoin custody must be understood by parties other than its original designer.

Open access
2 source records
Blockchain Technology Applications and Security
Internet Traffic Analysis and Secure E-voting
Privacy, Security, and Data Protection
Original source