Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

446 papersLast indexed Aug 31, 2026
Search papers

Paper index

446 results · page 1 of 19

Clear filters
Aug 28, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
Physical Ledger DNS Whitepaper v1.0: A Universal Coordinate Addressing Protocol under the Generalized Projection Theory Framework

Shuqing Cui

On August 28, 2026, Google, Microsoft, Anthropic, OpenAI, and 100 other companies signed an open letter warning of a large-scale AI attack. AI has created systemic risks in the digital world, but the physical world has no defense mechanism. This paper defines the Physical Ledger—a physical world namespace rooted in the Cui coordinate. The Physical Ledger DNS is not a copy of the domain name system; it is an object-addressing protocol for the physical world: every object (shelf position, robot, door, vehicle, starship) is assigned a unique Cui coordinate address. This paper presents a draft protocol for the Physical Ledger DNS, a catalog of 108 problems, the genesis valuation of $100,000,000, and a reward distribution scheme. It proposes the §13 security mechanism (Proof-of-Problem): a distributed firewall for the Physical Ledger DNS, powered by the 108 problems. The more solvers participate, the thicker the firewall. AI can attack digital protocols, but it cannot solve problems—because solving requires understanding the coordinate origin itself. The genesis valuation of the Cui-attribute Shell is defined as US$100,000,000, anchored at 2026-08-27. The appendix includes the Cui-coordinate naming rights and the passphrase lock (recognition of 1/7/8 for entry).

Open access
2 source records
Network Security and Intrusion Detection
Internet Traffic Analysis and Secure E-voting
User Authentication and Security Systems
Original source
Aug 21, 2026·PeerJ Computer Science
0 cites
Multimodal biometric authentication for social e-governance using blockchain with a differential privacy-based deep learning model

Saad Altamimi, Saad Alahmari, Ibrahim Alghamdi, Yousef Alhaizaey · 5 authors

Today, biometric authentication has become a central component of user security in social governance systems, where each government department demands access to user-specific data that varies across agencies. However, storing such data in centralized repositories increases serious privacy concerns, as unrestricted access by multiple entities maximizes the risk of data leakage. To address this, our research presents a novel biometric authentication system integrating robust privacy-preserving techniques, built on advanced deep learning architectures and differential privacy algorithms. A blockchain ledger integrated with a Merkle tree is used to securely store user identities, providing tamper-evident cryptographic validation of registered users. We further develop a novel hybrid model by integrating a pre-trained Vision Transformer (ViT) with a differential privacy-based machine learning enhanced training strategy, wherein the model is trained on noise-induced images to resist inference attacks. The system without differential privacy achieves 90.80% accuracy, 0.94 precision, 0.91 recall, and an F1-score of 0.90 in the standard configuration, while the differentially private model maintains 68.97% accuracy with Δ = 6.2, ensuring a strong privacy—accuracy balance. The evaluation confirms that our proposed model, incorporating differential privacy, provides a secure and scalable solution for managing sensitive citizen data while achieving reliable performance in privacy-aware biometric verification for real-world e-governance applications.

Open access
Biometric Identification and Security
User Authentication and Security Systems
Blockchain Technology Applications and Security
Original source
Aug 11, 2026·Research Square
0 cites
Decentralized AI-Powered Zero-Trust Identity and Access Management Using Blockchain and Deepfake-Resistant Multimodal Biometrics

Anithalakshmi VÂč, Raja PÂČ, N Sripriya, M Lavanya

Abstract Traditional Identity and Access Management (IAM) systems rely on static credentials and centralized authorities, leaving organizations vulnerable to single points of failure, credential theft, insider misuse, and increasingly sophisticated deepfake impersonation attacks. In this paper, we propose a Decentralized AI-powered Zero-Trust IAM (DAZT-IAM) framework that combines permissioned blockchain infrastructure, self-sovereign identity (SSI) principles, and deepfake-resistant multimodal biometric authentication (face, voice, and behavioral keystroke dynamics) with a continuous, risk-adaptive AI trust scoring engine. The proposed system is compliant with ZTA principles and checks every access request continuously, unlike the older “authenticate-once” models. Blockchain-anchored Decentralized Identifiers (DIDs) and Verifiable Credentials (VCs) eliminate the dependency on a central identity provider. The biometric pipeline includes a dedicated deepfake-detection module that employs frequency-domain artifact analysis and temporal consistency checks to counteract synthetic media spoofing. We describe the system architecture, consensus and smart-contract design, the multi-modal fusion and liveness detection pipeline, and a risk-scoring model for adaptive access decisions. The experimental evaluation on simulated and benchmark datasets demonstrates that the proposed framework provides competitive authentication accuracy, high detection rates of deepfake attacks, and low average access decision latency, while removing single points of failure for identity. Our results demonstrate that the integration of blockchain-based decentralization and AI-based continuous trust evaluation provides a pragmatic approach of resilient and privacy-preserving IAM for sustainable digital infrastructure.

Open access
User Authentication and Security Systems
Biometric Identification and Security
Privacy, Security, and Data Protection
Original source
Jul 22, 2026·Technologies
0 cites
Behavioral Biometric Continuous Authentication for Mobile Devices with an Intelligent Personal Agent: A Systematic Review

Madi Gali, Aray Kassenkhan, Y. Chinibayev, A. M. Abshukirova · 5 authors

Static, one-time authentication mechanisms such as passwords and PINs are increasingly inadequate for protecting mobile devices throughout an active session. Behavioral biometric continuous authentication (BBCA) addresses this gap by passively monitoring user-specific interaction patterns—keystroke dynamics, touch and swipe gestures, gait, and motion—to verify identity on an ongoing basis. This systematic review synthesizes 80 studies selected via a PRISMA-compliant protocol from IEEE Xplore, ACM Digital Library, Scopus, ScienceDirect, Web of Science, and SpringerLink (2017–2025). We examine behavioral and multimodal biometric modalities, machine learning approaches ranging from classical classifiers to deep sequence and transformer architectures, and their integration with intelligent personal agents, wearable devices, and IoT/edge infrastructures. Security analyses cover spoofing, adversarial and generative attacks, mimicry, and model-level threats including membership inference and reconstruction. Privacy-preserving mechanisms—cancelable biometrics, Bloom filter encodings, zero-knowledge proof protocols, federated learning, and blockchain-based identity management—are evaluated against practical trade-offs in energy consumption and latency on resource-constrained devices. Key research gaps are identified: the absence of standardized adversarial benchmarks, lack of end-to-end pipeline evaluations under simultaneous adversarial and privacy threat models, and limited user-centered studies on consent and acceptance of privacy-preserving mechanisms under frameworks such as GDPR. Recommended future directions combine adaptive multimodal fusion, privacy-preserving cryptography, energy-aware modality selection, and interdisciplinary human-centered evaluation to advance practical, resilient continuous authentication for mobile and assistant-enriched environments.

Open access
User Authentication and Security Systems
Gait Recognition and Analysis
Biometric Identification and Security
Original source
Jun 25, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
Context-Aware Password Management For Multi-User IoT Environments: A Systematic Review Of Secure Key Rotation And Expiry Mechanisms

Vrutti Mistry, Yassir Farooqui, Amit Barve

The rapid proliferation of Internet of Things (IoT) devices across smart homes, healthcare systems, and industrial environments has intensified the need for robust and adaptive security mechanisms in multi-user settings. Traditional password management approaches remain widely deployed; however, they suffer from persistent vulnerabilities including weak password selection, credential reuse across services, and the absence of structured lifecycle management mechanisms. This paper presents a systematic review of existing authentication, password management, and key lifecycle strategies applicable to multi-user IoT ecosystems. The study follows a structured review methodology to analyze and synthesize contemporary research contributions in the areas of context-aware authentication, secure key rotation, password expiry mechanisms, and lightweight cryptographic implementations. A comparative evaluation of diverse security techniques—such as one-time passwords (OTPs), zero-knowledge proofs (ZKP), symmetric and public-key cryptographic schemes, and machine learning-based threat detection models—is conducted with particular attention to device resource constraints, scalability challenges, and operational efficiency. Conceptual models, analytical tables, and comparative charts are utilized to highlight trade-offs between security strength, computational overhead, and system performance. The review identifies significant research gaps in integrating dynamic key rotation and expiry mechanisms into holistic, context-aware security architectures tailored for multi-user IoT environments. Finally, the paper outlines future research directions aimed at developing scalable, resource-efficient, and adaptive password lifecycle management frameworks for next-generation IoT systems. management frameworks for next-generation IoT systems.

Open access
2 source records
User Authentication and Security Systems
Advanced Authentication Protocols Security
Advanced Malware Detection Techniques
Original source
Jun 20, 2026·OSF Preprints (OSF Preprints)
0 cites
BIP39 Mnemonic Key Generation for Self-Sovereign Browser Identity: Zero-Knowledge Authentication — Browser Engine, Privacy, Web, Sovereign AI, and Post-Cloud Architecture (Kathon)

Lois-Kleinner Alpasan

Self-sovereign identity (SSI) represents a paradigm shift in digital authentication, transferring control from centralized identity providers to individual users (MĂŒhle et al., 2018). This paper presents the Kathon Vault identity system, which implements self-sovereign browser identity through BIP39 mnemonic seed phrases (Palatinus et al., 2013) for Ed25519 hierarchical deterministic (HD) key generation (Bernstein et al., 2012; Wuille, 2012). The system generates a master seed from a BIP39 mnemonic (12, 18, or 24 words with configurable passphrase), derives Ed25519 keypairs through the SLIP-10 key derivation scheme (Pƙikryl, 2022), and enables zero-knowledge authentication across websites through a novel browser-native WebAuthn-hybrid protocol. We demonstrate that the BIP39-derived Ed25519 keys provide equivalent security to standard FIDO2/WebAuthn authenticators (316 bits of entropy for 24-word phrases) while offering three critical advantages: (1) deterministic key recovery from the mnemonic phrase alone, (2) hierarchical key organization matching the SLIP-44 registered coin type for Kathon, and (3) cryptographic privacy through zero-knowledge proofs that enable selective attribute disclosure without revealing the master public key. In a security analysis against brute-force, dictionary, side-channel, and social engineering attacks, the system achieves resistance levels exceeding NIST SP 800-63B Level 4 authentication assurance requirements (NIST, 2020). A usability study with 48 participants demonstrates that BIP39-based authentication achieves 96% successful login rates with 14% lower task completion time compared to password manager-based workflows. This work establishes mnemonic-based HD key generation as a viable and superior alternative to federated identity providers for browser-based authentication. --- Part of The Anticloud research corpus by Lois-Kleinner Alpasan (ORCID: 0009-0009-2233-6107). This work explores browser engine, privacy in the context of sovereign AI infrastructure, post-cloud computing architectures, and transparent, blackbox-free systems.

Open access
User Authentication and Security Systems
Web Application Security Vulnerabilities
Spam and Phishing Detection
Original source
Jun 18, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
A Hybrid Zero-Knowledge Proof and Human Interaction Proof Protocol for Secure Authentication and the Prevention of Automated Brute-Force Attacks

Sancaktar Pelin, Necla Kırcalı GĂŒrsoy, Arif GĂŒrsoy

Modern authentication architectures contain structural vulnerabilities against automated credential stuffing and server-side data breaches. Traditional solutions rely on the transmission of raw or hashed passwords over the network; for bot defense, they position third-party Completely Automated Public Turing test to tell Computers and Humans Apart (CAPTCHA) services, which may violate user privacy and create institutional dependencies, as an illusion of two-factor authentication (2FA). This situation raises a critical research question in cybersecurity: How can an integrated cryptographic shield be constructed that is independent of user-privacy-invasive mechanisms and external data authorities, while preventing autonomous bots from targeting the identity and human-verification layers separately?In response to this question, this paper presents a zero-dependency, original, and hybrid protocol that integrates a Zero-Knowledge Proof (ZKP) based on the Schnorr authentication scheme with a local Human Interaction Proof (HIP) mechanism. The main advantage of the proposed architecture is that it mathematically seals the user’s secret credential together with a dynamically generated one-time CAPTCHA token on the client side using the SHA-256 function, thereby transforming the verification process into an indivisible atomic “Hybrid Secret.” In this way, the transmission of password hashes over the network is completely eliminated, and the server evaluates only the mathematical validity of the proof under the Discrete Logarithm Problem (DLP) assumption.Experimental results obtained through Selenium-based automated brute-force attack simulation engines demonstrate that the system provides complete blocking against automated threat vectors. Dynamic one-time nonce mutation immediately invalidates the derived client response, even in extreme scenarios where an attacking bot obtains the correct password string and solves the CAPTCHA image, thereby mathematically defeating brute-force and replay attacks. Furthermore, the autonomous structure of the proposed protocol, with no dependency on third-party analytics services, opens the way for a highly secure and local authentication architecture for internet-isolated critical infrastructures.In this study, the theoretical and mathematical foundations of the proposed protocol are presented, the stages constituting its life cycle are methodologically explained, and Selenium-based experimental simulation results together with telemetry log analyses are detailed.

Open access
2 source records
User Authentication and Security Systems
Advanced Authentication Protocols Security
Security in Wireless Sensor Networks
Original source
Jun 16, 2026·Zenodo (CERN European Organization for Nuclear Research)
11 cites
PrismEco, Use Case Demonstration: The Complete Authentication Triangle, Biometrics, NFC, and Zero-Knowledge Proof in One Flow

I. Smid -Woelders

PrismEco is the showcase demonstration of the Prism Ecosystem. Where the other component demos each illustrate one capability in isolation, PrismEco shows the complete authentication triangle in a single flow: biometric authentication via WebAuthn, a Zero-Knowledge Proof generated in the browser, and NFC presence verification via a physical tag. This technical note follows a single user through the complete login flow on prismeco.globalsecurity.nu. At each step, it documents what the server receives and what it does not receive. The goal is to make visible what is structurally invisible by design: that a working authentication system can process a login without ever knowing who the user is. The three factors are verified independently and must all succeed for the session to open. No single factor is sufficient on its own. The combination is structurally resistant to remote attacks: an attacker would need to compromise biometrics, the device, and physical proximity simultaneously. The complete authentication triangle has been proven in a working PoC as of 12 June 2026. WebAuthn registration and login, ZKP generation and server-side verification (proven 10 June 2026), and NFC tap confirmation with RELAY_TOKEN verification (proven 12 June 2026) all function as an integrated flow on live infrastructure at prismeco.globalsecurity.nu. Screenshots in this document are taken from the live running demonstration. All claims are classified by status: proven in PoC, follows from open standard, or architectural design choice. Part of the Prism Ecosystem. Full technical architecture: The Prism Protocol, Invention Disclosure v20, DOI: 10.5281/zenodo.20029291.

Open access
2 source records
User Authentication and Security Systems
RFID technology advancements
Biometric Identification and Security
Original source
May 28, 2026·Companion Proceedings of the ACM Web Conference 2026
0 cites
Blockchain-Enabled, W3C Standards-Compliant Decentralized Zero-Knowledge Proof Framework for Mobile Identity Authentication

Cheolwoo Ryu, Danyung Kyung, Shiho Kim

The proliferation of centralized carrier-based authentication systems has exposed critical vulnerabilities in the preservation of privacy and personal data protection. Current implementations in Korea, such as PASS and KakaoTalk identity services, rely on centralized architectures that create single points of failure and require excessive disclosure of personal information. The large-scale security breach of SK Telecom's USIM infrastructure in 2025, affecting 23 million subscribers, highlights the urgent need for a paradigm shift in identity authentication.?This paper proposes a decentralized identity authentication system leveraging W3C Decentralized Identifiers (DIDs) and Verifiable Credentials (VCs), combined with Zero-Knowledge Proofs (ZKPs). Our framework integrates Schnorr signatures with Sigma-protocol-based ZKPs to enable privacy-preserving authentication without revealing private keys. A three-layer architecture—comprising cryptographic, identity, and credential layers—ensures strong cryptographic guarantees based on the discrete logarithm problem over the secp256k1 curve, while eliminating reliance on centralized infrastructure. Performance evaluation shows that signature generation occurs in under 10 ms and verification in under 15 ms, meeting real-time authentication requirements while delivering formal privacy guarantees that are absent in conventional systems.

Open access
Blockchain Technology Applications and Security
User Authentication and Security Systems
Cryptography and Data Security
Original source
May 11, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
ChitraVault: A Chitrakavi-Inspired Multi-Modal Authentication Framework for Password Vault Security

Arvind Vijayakumar

ChitraVault is an exploratory conceptual authentication architecture that investigates whether geometric visual traversal patterns, drawn from the Chitrakavi (àźšàźżàź€àŻàź€àźżàź°àź•àŻàź•àź”àźż) classical Tamil literary tradition, can augment password vault security by adding a spatial-behavioral dimension to cryptographic key derivation. This paper proposes the Visual Pattern Key Derivation Function (VP-KDF), which combines a user-drawn Chitrakavi geometric pattern, a text passphrase, and a hardware-bound device fingerprint as inputs to Argon2id key stretching. The framework maps four classical Chitrakavi patterns — Chakra Bandha (wheel), Naga Bandha (serpent), Gomutrika (zigzag), and Thiruezhukkootrirukkai (triangle) — onto distinct cryptographic roles within a zero-knowledge password vault architecture. This work is framed as an exploratory research program, not a finished cryptographic system. All security arguments are bounded by stated assumptions and require empirical and cryptanalytic validation. Future work includes controlled user studies, formal security proofs, and prototype evaluation. Author: Arvind VijayakumarIndependent ResearcherMay 2026

Open access
2 source records
User Authentication and Security Systems
Biometric Identification and Security
Advanced Authentication Protocols Security
Original source
May 6, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
THE WISDOM TOOTH SOLUTION: Architecture of Digital Sovereignty in the Age of AI Chaos

Anton L.

The rapid proliferation of generative AI has collapsed the scarcity-based filters of digital trust, enabling synthetic identities, algorithmic fraud, and systemic epistemological uncertainty. Conventional authentication methods—passwords, cloud-stored biometrics, and external hardware tokens—are inherently fragile, centralized, and vulnerable to coercion or theft. This article proposes a paradigm shift toward bodily cryptographic sovereignty: a dental implant-based digital anchor that derives a Physically Unclonable Function (PUF) key from the unique acoustic resonance and microarchitecture of the human jawbone. The architecture integrates Zero-Knowledge Proofs (ZKP) for privacy-preserving verification, hardware zeroization to neutralize extraction attacks, and a configurable duress protocol for coercion scenarios. By leveraging globally established dental infrastructure and informed-consent medical protocols, the model bypasses the regulatory resistance and psychological friction associated with centralized biometric registries. It enables graded identity, scoped AI-agent delegation, and origin-verified digital communication. The proposed framework transitions digital trust from fragile external devices to an inseparable biological-cryptographic symbiosis, offering a scalable, voluntary, and regulatorily aligned architecture for the post-AI trust economy.

Open access
2 source records
Physical Unclonable Functions (PUFs) and Hardware Security
Adversarial Robustness in Machine Learning
User Authentication and Security Systems
Original source
May 5, 2026·Journals & Books Hosting (International Knowledge Sharing Platform)
0 cites
User Trust and Perception of Cryptographic Technologies in Centralized Electronic Health Record Systems: A Random Forest Analysis

Momodu Mustapha, Susan Konyeha, Akinola Samson Olayinka

This study examines user trust and perception of cryptographic technologies specifically SHA3-512 hashing, SERPENT encryption, and Zero-Knowledge Proofs (ZKP) in the context of centralized Electronic Health Record (EHR) systems. As healthcare institutions increasingly migrate patient data to digital platforms, the security and privacy properties of underlying cryptographic mechanisms have become critical determinants of user confidence and system adoption. Using a quantitative, survey-based design, data were collected from 92 healthcare practitioners, IT professionals, and system administrators actively engaged with EHR systems in Auchi, Nigeria. A Random Forest classifier was trained to predict perceived satisfaction levels (Low, Neutral, High) based on respondents' assessments of cryptographic effectiveness, usability, and trust. Results indicate that trust in ZKP is the strongest predictor of overall perception, followed by confidence in SERPENT encryption and SHA3-512 integrity guarantees. The model achieved a classification accuracy of 63.3% on a held-out test set derived from this exploratory sample, with a Kappa statistic of 0.52 reflecting moderate agreement beyond chance. Balanced accuracy across classes (approximately 0.49–0.50) and low per class sensitivity confirm that the findings should be interpreted as preliminary and directional rather than definitive. Key themes from open ended feedback analyzed using TF-IDF text mining reveal that while respondents broadly recognize the security value of these cryptographic mechanisms, concerns about system slowdown, usability complexity, and insufficient user education present barriers to wider adoption. This study contributes a pilot-level empirical baseline for understanding stakeholder perception of layered cryptographic security in resource-constrained healthcare environments, and highlights the need for larger-scale replication studies. Keywords: SHA3-512; SERPENT encryption; Zero-Knowledge Proofs; healthcare data security; user perception; Electronic Health Records; Random Forest

Open access
Electronic Health Records Systems
Mobile Health and mHealth Applications
User Authentication and Security Systems
Original source
Apr 30, 2026·Applied Sciences
1 cites
DistSense: A Distributed P2P System for Privacy-Preserving and Robust Audiovisual Activity Recognition in Smart Homes

José Manuel Torres, Luis P. Mota, Rui S. Moreira, Christophe Soares · 5 authors

Ambient Assisted Living (AAL) systems have become increasingly relevant as aging populations intensify the demand for technologies that promote autonomy, safety, and quality of life. However, the widespread adoption of audiovisual sensing in smart homes raises critical concerns regarding data protection, privacy, and user trust. Ensuring secure processing while maintaining accurate activity recognition remains a key challenge. This work introduces DistSense, a distributed Peer-to-Peer (P2P) system designed to enhance activity detection in domestic environments through collaborative inference among intelligent audiovisual sensors. DistSense prioritizes privacy by performing local processing, sharing only high-level events, and leveraging distributed ledger mechanisms to ensure data integrity and auditability and support cross-device validation. This collaborative strategy reduces false positives caused by occlusions, illumination variability, and acoustic noise. To assess the system, functional tests were conducted for each module, followed by two use cases evaluated in both simulated and real edge hardware environments. The trained models achieved 88% accuracy for audio and 80% for video, and the system demonstrated effective performance in detecting daily activities and domestic hazards under varying noise conditions. Results indicate that DistSense successfully balances security, user acceptance, and inference robustness, positioning it as a viable solution for privacy-preserving activity monitoring in smart home contexts.

Open access
Context-Aware Activity Recognition Systems
Gait Recognition and Analysis
User Authentication and Security Systems
Original source
Apr 26, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
Entros Protocol: A Framework for Temporally-Consistent, Decentralized Proof-of-Personhood

Charles Hooper

The proliferation of sophisticated AI and bot networks necessitates robust methods for verifying human uniqueness and liveness in digital ecosystems. Existing Proof-of-Personhood (PoP) solutions rely on centralized authorities, invasive static biometrics, or socially-correlatable data, creating vulnerabilities in privacy, security, and accessibility. We introduce the Entros Protocol, a decentralized framework for PoP and Self-Sovereign Identity built on Solana. The core innovation is temporal consistency: the assertion that human identity is best proven not by a static secret, but by the bounded, chaotic drift of biological and behavioral patterns over time. The framework captures multi-modal behavioral data (voice prosody, hand tremor, touch dynamics) during a configurable behavioral challenge, extracts a 308-dimensional feature vector, and produces a 256-bit locality-sensitive hash via SimHash. A Groth16 zero-knowledge proof verifies that consecutive fingerprints fall within a bounded Hamming distance without revealing either value. Attestations are anchored to non-transferable identity tokens (SPL Token-2022) with progressive Trust Scores. We provide formal security definitions, analyze the protocol against replay, synthesis, and Sybil attacks, introduce a graduated trust model distinguishing first-time liveness checks from sustained temporal consistency, and present benchmarks from a working implementation deployed on Solana devnet.

Open access
4 source records
User Authentication and Security Systems
Advanced Authentication Protocols Security
Internet Traffic Analysis and Secure E-voting
Original source
Apr 25, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
Prism Protocol: A Privacy-Native Authentication Architecture (Closed Triangle: Biometrics, Device Binding, NFC Presence), Confirmed via Zero-Knowledge Proofs, with Working Implementation

I. Smid -Woelders

The Prism Protocol is a privacy-native authentication and identity architecture in which a user can prove attributes or authentication state without directly revealing their identity to the server. It combines WebAuthn (W3C Level 3), Zero-Knowledge Proofs (Groth16 via circom/snarkjs), and NFC-based physical presence verification into a single coherent protocol stack. The core mechanism is a triangular key derivation model: biometric authentication (WebAuthn), a device-bound private key (FIDO2 Secure Enclave), and a time-limited NFC nonce via a passive tag (card, ring, sticker; NFC ISO 14443) jointly produce an ephemeral key. In v18, a working ZKP implementation is demonstrated: an age-threshold circuit proves that a user meets a criterion without the server ever receiving the attribute value. Verification is performed server-side via snarkjs.groth16.verify(). Within the demonstrated implementation flow, the server receives no name, no biometric data, no persistent identifier, and no direct attribute value. Sessions are designed to be unlinkable from the server perspective at the protocol level; timing and metadata correlation are addressed in the threat model as a separate concern. A working proof-of-concept was demonstrated on 25 April 2026 at prismpass.globalsecurity.nu. The broader ecosystem (PrismPass, PrismID, PrismShield, PrismAdd, PrismChat, PrismAir, PrismGuard, PrismHash, PrismWipe, PrismGate) is documented in this Invention Disclosure. The protocol introduces no novel cryptographic primitives; its novelty lies in the specific architectural combination, orchestration model, and protocol-class definition addressing thirteen authentication questions not simultaneously addressed by existing systems. Note: The post-quantum migration path (ML-KEM-768, ML-DSA-65) is documented as a formal architectural claim and forward-compatibility design decision. It describes the intended migration route, not a currently implemented feature. The working implementation uses ECDH, ECDSA, AES-256-GCM and Groth16. The protocol is designed for session unlinkability: the server receives only a cryptographic proof of validity, never a persistent identifier, name, or behavioural trace. This addresses the unlinkability gap identified in the W3C Digital Credentials API and the EUDI Wallet architecture as an unresolved open problem. Author: I. Smid-Woelders, independent inventor, Zwolle, Netherlands. First documented: 25 April 2026. Contact: contact@globalsecurity.nu

Open access
2 source records
Advanced Authentication Protocols Security
User Authentication and Security Systems
RFID technology advancements
Original source
Apr 25, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
Prism Protocol: A Privacy-Native Authentication Ecosystem Combining WebAuthn, Zero-Knowledge Proofs, and NFC Presence Verification , with Working Implementation

Smid-Woelders, I.

The Prism Protocol is a privacy-native authentication and identity architecture in which a user can prove attributes or authentication state without directly revealing their identity to the server. It combines WebAuthn (W3C Level 3), Zero-Knowledge Proofs (Groth16 via circom/snarkjs), and NFC-based physical presence verification into a single coherent protocol stack. The core mechanism is a triangular key derivation model: biometric authentication (WebAuthn), a device-bound private key (FIDO2 Secure Enclave), and a time-limited NFC nonce via a passive tag (card, ring, sticker; NFC ISO 14443) jointly produce an ephemeral key. In v18, a working ZKP implementation is demonstrated: an age-threshold circuit proves that a user meets a criterion without the server ever receiving the attribute value. Verification is performed server-side via snarkjs.groth16.verify(). Within the demonstrated implementation flow, the server receives no name, no biometric data, no persistent identifier, and no direct attribute value. Sessions are designed to be unlinkable from the server perspective at the protocol level; timing and metadata correlation are addressed in the threat model as a separate concern. A working proof-of-concept was demonstrated on 25 April 2026 at prismpass.globalsecurity.nu. The broader ecosystem (PrismPass, PrismID, PrismShield, PrismAdd, PrismChat, PrismAir, PrismGuard, PrismHash, PrismWipe, PrismGate) is documented in this Invention Disclosure. The protocol introduces no novel cryptographic primitives; its novelty lies in the specific architectural combination, orchestration model, and protocol-class definition addressing thirteen authentication questions not simultaneously addressed by existing systems. Note: The post-quantum migration path (ML-KEM-768, ML-DSA-65) is documented as a formal architectural claim and forward-compatibility design decision. It describes the intended migration route, not a currently implemented feature. The working implementation uses ECDH, ECDSA, AES-256-GCM and Groth16. The protocol is designed for session unlinkability: the server receives only a cryptographic proof of validity, never a persistent identifier, name, or behavioural trace. This addresses the unlinkability gap identified in the W3C Digital Credentials API and the EUDI Wallet architecture as an unresolved open problem. Author: I. Smid-Woelders, independent inventor, Zwolle, Netherlands. First documented: 25 April 2026. Contact: contact@globalsecurity.nu

Open access
5 source records
Advanced Authentication Protocols Security
RFID technology advancements
User Authentication and Security Systems
Original source
Apr 2, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
Zero-Knowledge Proof System for Password Policy Verification in Asymmetric Password-Authenticated Key Exchange

Dmitry O. PrĂșdnikov

This paper describes a zero-knowledge proof system that enables verification of password policy compliance within an asymmetric password-authenticated key exchange (aPAKE) protocol specifically OPAQUE (RFC 9807) without revealing the password to the server. The system is built on a composable sub-circuit architecture: independent verification gadgets are combined into a single zero-knowledge proof, each gadget accepting portions of the private witness and producing public instance values, enabling the server to verify multiple password properties in one proof verification. Four gadgets are disclosed: (1) a Policy Engine for character class verification via lookup tables, (2) a History Nullifier for password inequality proof via squared-difference accumulation, (3) an OPAQUE Binder for cryptographic binding to the aPAKE registration element via hash-to-curve and elliptic curve scalar multiplication, and (4) a Breach Detector for offline breached-password detection via Bloom filter non-membership proof using algebraic hashing. The composable architecture permits addition of further gadgets without modifying existing ones, each extending the public instance vector.

Open access
2 source records
Advanced Authentication Protocols Security
Cryptography and Data Security
User Authentication and Security Systems
Original source
Mar 27, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
IAM Protocol: A Framework for Temporally-Consistent, Decentralized Proof-of-Humanity

Charles Hooper

The proliferation of sophisticated AI and bot networks necessitates robust methods for verifying human uniqueness and liveness in digital ecosystems. Existing Proof-of-Humanity (PoH) solutions rely on centralized authorities, invasive static biometrics, or socially-correlatable data, creating vulnerabilities in privacy, security, and accessibility. We introduce the IAM Protocol, a decentralized framework for PoH and Self-Sovereign Identity built on Solana. The core innovation is temporal consistency: the assertion that human identity is best proven not by a static secret, but by the bounded, chaotic drift of biological and behavioral patterns over time. The framework captures multi-modal behavioral data (voice prosody, hand tremor, touch dynamics) during a configurable behavioral challenge, extracts a 134-dimensional feature vector, and produces a 256-bit locality-sensitive hash via SimHash. A Groth16 zero-knowledge proof verifies that consecutive fingerprints fall within a bounded Hamming distance without revealing either value. Attestations are anchored to non-transferable identity tokens (SPL Token-2022) with progressive Trust Scores. We provide formal security definitions, analyze the protocol against replay, synthesis, and Sybil attacks, introduce a graduated trust model distinguishing first-time liveness checks from sustained temporal consistency, and present benchmarks from a working implementation deployed on Solana devnet.

Open access
2 source records
User Authentication and Security Systems
Advanced Authentication Protocols Security
Biometric Identification and Security
Original source
Mar 24, 2026·Scientific Reports
0 cites
Post-quantum secure server-aided password-based authentication using Module-LWE

Shanu Poddar, Sai Sandilya Konduru, Sweta Mishra

Password-based authentication systems remain the most widely used method for user verification despite being highly susceptible to offline dictionary attacks. To mitigate such attacks, server-aided password-based authentication schemes utilize an independent server, which helps to harden the credentials to be stored on the website database. Existing server-aided password-based authentication schemes rely on number-theoretic assumptions that are vulnerable to quantum-enabled adversaries and incorporate complex computations such as bilinear pairings, exponentiation, and Zero-Knowledge Proofs. In this work, we introduce a novel post-quantum secure server-aided password-based authentication scheme based on the Module Learning With Errors (M-LWE) problem. A defining feature of our protocol is its complete operational transparency as it integrates with existing web interfaces without requiring users to modify their login behaviour or perform additional computation. To ensure long-term resilience, our scheme includes a transparent key rotation mechanism that allows service providers to update the entire credential database with a fresh secret key without user intervention. We provide a formal security analysis in the Real-or-Random (RoR) framework. This analysis demonstrates that our protocol's resistance to offline dictionary attacks reduces to the underlying hardness of the M-LWE problem, and the system achieves forward secrecy through a key rotation mechanism. Through an optimized Number Theoretic Transformation (NTT)-based implementation for faster polynomial multiplications, our empirical analysis demonstrates high computational efficiency, with average registration and authentication latencies of 0.88 ms and 0.96 ms, respectively.

Open access
2 source records
Cryptography and Data Security
Advanced Authentication Protocols Security
User Authentication and Security Systems
Original source
Mar 23, 2026·Proceedings of the 41st ACM/SIGAPP Symposium on Applied Computing
0 cites
Delegated Keys for Smart Wallets: Enabling Secure Transaction Execution from Apple Watch via ERC-4337 & Kernel Wallet

Artem Delikatnyi, Kristiån KoƥƄål, Michal Géci

This paper explores the potential of using modern smartwatches, particularly the Apple Watch, as an additional device for signing transactions and interacting with the blockchain. Modern crypto applications on smart-watches are limited to a read-only paradigm. The reason is a lack of security, specifically the absence of biometric verification for each transaction. When creating a classic Externally Owned Account wallet on the smartwatch side, these vulnerabilities carry a high risk of losing all of the user's funds. To solve this problem, an architecture based on the ERC-4337 standard was proposed. The proposed solution includes creating a wallet based on the kernel architecture, which allows setting access for additional keys to use funds, but within specific limitations. Consequently, one account can have several keys that can access funds. One key is the root key and has no restrictions. The established keys are called delegated and may have different restrictions. The root key can install a new delegated key or delete a previously established delegated key at any time. These delegated keys are used on the smartwatch to enable signing transactions according to the allowed rules. The main novelty of the proposed solution lies in its architecture, which enables smartwatches to be used as autonomous Web3 clients without compromising the root key, while strictly adhering to restrictions on executable operations and prioritizing security.

Open access
Advanced Authentication Protocols Security
User Authentication and Security Systems
Blockchain Technology Applications and Security
Original source
Mar 18, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
ZKP-GDIS: A Zero-Knowledge Proof-Augmented Global Decentralized Identity System with Deepfake-Resistant Liveness Detection and Privacy-by-Design Architecture

Kondwani Nyirenda

The global digital identity landscape is undergoing an unprecedented crisis. Approximately 1.1 billion individuals worldwide lack any verifiable form of digital identity, while existing identity systems face existential threats from the industrialization of deepfake technology with injection attacks targeting biometric verification surging 900% since 2022 and occurring at a rate of once every five minutes in 2024. Simultaneously, conventional blockchain-based identity proposals that store biometric templates on-chain introduce critical privacy vulnerabilities incompatible with emerging regulatory frameworks including the EU AI Act (2024) and GDPR. This paper presents ZKP-GDIS (Zero-Knowledge Proof Global Decentralized Identity System), a novel, privacy-by-design identity architecture that fundamentally departs from prior work in three key dimensions. First, ZKP-GDIS never stores raw biometric data on-chain; instead, it employs zk-SNARK (Zero-Knowledge Succinct Non-Interactive Argument of Knowledge) cryptographic commitments that allow identity verification without any disclosure of underlying biometric features. Second, we introduce a Hybrid Deepfake-Resistant Liveness Pipeline (HDRLP) — a multi-modal anti-spoofing layer that fuses passive CNN-based texture analysis, photoplethysmography (PPG) heart-rate detection, and hardware-attested device fingerprinting to defeat both presentation and injection attack vectors. Third, the system adopts W3C Decentralized Identifier (DID) standards and implements a federated governance model, enabling cross-jurisdictional interoperability while respecting national digital sovereignty. We provide formal security proofs under the computational Diffie-Hellman hardness assumption, evaluate the system against the ISO/IEC 30107-3 Presentation Attack Detection benchmark, and report experimental results demonstrating 99.87% genuine acceptance rate, 0.004% false acceptance rate under deepfake attack, and 94% reduction in on-chain gas costs versus Ethereum mainnet through zkEVM Polygon deployment. ZKP-GDIS establishes a reproducible, standards- compliant, and audit-ready framework for the next generation of global digital identity infrastructure.

Open access
2 source records
Blockchain Technology Applications and Security
User Authentication and Security Systems
Adversarial Robustness in Machine Learning
Original source
Feb 26, 2026·arXiv (Cornell University)
0 cites
Privacy-Preserving Proof of Human Authorship via Zero-Knowledge Process Attestation

David Condrey

Process attestation verifies human authorship by collecting behavioral biometric evidence, including keystroke dynamics, typing patterns, and editing behavior, during the creative process. However, the very data needed to prove authenticity can reveal intimate details about an author's cognitive state, health conditions, and identity, constituting sensitive biometric data under GDPR Article 9. We resolve this privacy-attestation paradox using zero-knowledge proofs. We present ZK-PoP, a construction that allows a verifier to confirm that (a) sequential work function chains were computed correctly, (b) behavioral feature vectors fall within human population distributions, and (c) content evolution is consistent with incremental human editing, all without learning the underlying behavioral data, exact timing, or intermediate content. Our construction uses Groth16 proofs over arithmetic circuits with Pedersen commitments and Bulletproof range proofs. We prove that ZK-PoP is computationally zero-knowledge, computationally sound, and achieves unlinkability across sessions. Evaluation shows proof generation in under 30 seconds for a 1-hour writing session, with 192-byte proofs verifiable in 8.2 ms, while incurring less than 5% accuracy loss in simulation at practical privacy levels (epsilon >= 1.0) compared to non-private baselines.

Open access
3 source records
cs.CR
cs.CY
cs.IT
Original source
Feb 12, 2026·Open MIND
0 cites
Blockchain-Enabled Proof-of-Humanity for Secure In-Game Transactions

Dr M.Santhalakshmi, Bharath K, Suraj Shenoy, Avani Singh, Tanushka Jain, Swamy Samartha

The rapid expansion of the blockchain gaming sector, projected to reach a $268.8 billion valuation by 2025 1 , has been severely compromised by the proliferation of automated Sybil attacks and bot-driven economic manipulation. Traditional anti-bot measures, such as CAPTCHAs and behavioural analytics, are increasingly circumvented by advanced AI-driven scripts. This paper proposes a novel Context-Aware Reputation-Identity Hybrid (CRIH) framework that integrates biometric-backed Proof-of-Personhood (PoP) with decentralized reputation metrics. By leveraging World ID’s hardware-oracle verification and recursive Zero-Knowledge Proofs (ZKPs), the CRIH framework enables thrustless identity portability across Layer 2 (World Chain) and Layer 3 (Mythos Chain) architectures. We demonstrate that this tiered, risk-sensitive approach significantly reduces bot-driven inflation while preserving player privacy and minimizing onboarding friction.

Open access
2 source records
Blockchain Technology Applications and Security
Cryptography and Data Security
User Authentication and Security Systems
Original source