Philip Eappen, Adeyemi Abel Ajibesin, Narasimha Rao Vajjhala
This chapter examines future directions and emerging trends in cybersecurity for knowledge management, emphasizing the necessity of advanced protective strategies as organizations increasingly rely on digital platforms to store, share, and manage knowledge. While digital knowledge management offers efficiency and accessibility, it introduces significant security challenges, such as unauthorized access, data breaches, and knowledge theft. This chapter explores three critical emerging technologiesâArtificial Intelligence/Machine Learning (AI/ML), Blockchain, and Quantum Computingâthat have the potential to enhance knowledge security. AI/ML aids in threat detection, predictive modeling, and automated responses, allowing for rapid identification of cyber threats. Blockchain provides a decentralized, tamper-proof method for managing knowledge and data integrity, ensuring secure data sharing and transaction transparency. Additionally, the chapter discusses quantum-resistant encryption in response to the potential risks posed by quantum computing advancements. The chapter further examines advanced cybersecurity approaches, including Zero Trust Architecture, Privacy-Enhancing Technologies, and Security Automation, which contribute to safeguarding sensitive information in knowledge systems. This chapter also addresses the ethical and regulatory considerations essential for ensuring compliance and accountability. By integrating these cutting-edge technologies and approaches, this chapter provides a holistic framework for future cybersecurity practices in knowledge management, offering valuable insights for professionals, researchers, and policymakers focused on protecting digital knowledge assets in an evolving cyber landscape.
Abstract This paper introduces semi-competitive differential game logic $$\textsf {dG}\mathcal {L}_{sc}$$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mrow> <mml:mi>dG</mml:mi> <mml:msub> <mml:mi>L</mml:mi> <mml:mrow> <mml:mi>sc</mml:mi> </mml:mrow> </mml:msub> </mml:mrow> </mml:math> , which enables verification of safety-critical applications that involve interactions between two agents. In $$\textsf {dG}\mathcal {L}_{sc}$$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mrow> <mml:mi>dG</mml:mi> <mml:msub> <mml:mi>L</mml:mi> <mml:mrow> <mml:mi>sc</mml:mi> </mml:mrow> </mml:msub> </mml:mrow> </mml:math> , these interactions are specified as games on hybrid systems with two players that may collaborate with each other when helpful and may compete when necessary. The players in the hybrid games of $$\textsf {dG}\mathcal {L}_{sc}$$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mrow> <mml:mi>dG</mml:mi> <mml:msub> <mml:mi>L</mml:mi> <mml:mrow> <mml:mi>sc</mml:mi> </mml:mrow> </mml:msub> </mml:mrow> </mml:math> have individual goals that may overlap, leading to nonzero-sum games. This makes $$\textsf {dG}\mathcal {L}_{sc}$$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mrow> <mml:mi>dG</mml:mi> <mml:msub> <mml:mi>L</mml:mi> <mml:mrow> <mml:mi>sc</mml:mi> </mml:mrow> </mml:msub> </mml:mrow> </mml:math> especially well-suited for verifying situations where players, e.g., share safety objectives but otherwise pursue different goals, so that zero-sum assumptions lead to overly conservative results. Additionally, $$\textsf {dG}\mathcal {L}_{sc}$$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mrow> <mml:mi>dG</mml:mi> <mml:msub> <mml:mi>L</mml:mi> <mml:mrow> <mml:mi>sc</mml:mi> </mml:mrow> </mml:msub> </mml:mrow> </mml:math> solves the subtlety that even though each player may benefit from knowledge of the other playerâs goals, e.g., concerning shared safety objectives, unsafe situations might still occur if every player were to mutually assume the other player would act to avoid unsafety. The syntax and semantics, as well as a sound and relatively complete proof calculus are presented for $$\textsf {dG}\mathcal {L}_{sc}$$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mrow> <mml:mi>dG</mml:mi> <mml:msub> <mml:mi>L</mml:mi> <mml:mrow> <mml:mi>sc</mml:mi> </mml:mrow> </mml:msub> </mml:mrow> </mml:math> . The relationship between $$\textsf {dG}\mathcal {L}_{sc}$$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mrow> <mml:mi>dG</mml:mi> <mml:msub> <mml:mi>L</mml:mi> <mml:mrow> <mml:mi>sc</mml:mi> </mml:mrow> </mml:msub> </mml:mrow> </mml:math> and zero-sum differential game logic $$\textsf {dG}\mathcal {L}$$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mrow> <mml:mi>dG</mml:mi> <mml:mi>L</mml:mi> </mml:mrow> </mml:math> is discussed and the purpose of $$\textsf {dG}\mathcal {L}_{sc}$$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mrow> <mml:mi>dG</mml:mi> <mml:msub> <mml:mi>L</mml:mi> <mml:mrow> <mml:mi>sc</mml:mi> </mml:mrow> </mml:msub> </mml:mrow> </mml:math> illustrated in a canonical example.
Mohamed Aswith. H, Densingh Joshua Israel, V.V.Kashimma, C. P. Rao ¡ 6 authors
Despite rapid evolution of digital currencies, the demand for secure, fast and scalable cross border payment solution has emerged. At the moment, the frameworks for the existing Central Bank Digital Currency (CBDC) are slow for transactions, lack security, and are not capable of adjusting to the dynamic changes with respect to the exchange rate. This paper therefore suggests a novel Quantum Ledger Based Multi Currency Smart Exchange System (QL-MSES) to counter challenges Quantum computers are capable of, quantum cryptography, quantum ledger technology and machine learning driven prediction models. The real time sound synchronization of global transactions as well as unbreakable encryption are performed in Quantum Key Distribution (QKD) and Quantum Entanglement Protocol (QEP systems in this system. AI-PEX proxies the rest of the world using deep reinforcement learning, and the remainder of the world input is passed through ACMA which dynamically selects the best exchange paths. In addition, the system includes the Homomorphic Encryption and Zero-Knowledge Proofs system, hence allowing the flow of information without jeopardizing the userâs privacy and without violating regulatory compliance. With this evaluation, this proposed QL-MSES is enabled to be faster with transactions, secured with data, and agile in exchanges when markets are volatile. The results of the performance evaluation show that QL-MSES offers higher efficiency and security than a conventional CBDC system. By employing this innovative solution, the applications of CBDC 3.0 can be utilised for cross border remittance, smart treasury management and decentralised finance, a revolutionary structure to adopt CBDC 3.0.
Decentralized finance (DeFi) lending platforms often require over-collateralization, excluding users without substantial crypto holdings. This paper introduces LFG, a novel DeFi protocol that leverages on-chain social profiles and tokenized reputation to assess creditworthiness. By integrating Ethereum smart contracts with Layer-2 solutions (Ethereum, Polygon), decentralized storage (IPFS) and zero-knowledge proofs, LFG enables undercollateralized loans while preserving privacy. We present a technical architecture, analyze security risks, and compare LFGs with traditional models using quantitative metrics. The results show a 40% reduction in collateral requirements for users with high reputation scores on the chain.
Damiano Di Francesco Maesa, Matteo Loporchio, Frank Tietze
This paper considers the application scenario of Intellectual Property (IP) management, a business process yet to fully embrace digitisation and the advantages it brings. We propose to leverage Distributed Ledger Technology (DLT) to digitise license agreements management by providing automated and trustworthy royalty computation, transaction execution, and payment distribution. This can be achieved by employing smart licenses, i.e., bundles of smart contracts implementing the royalty logic of license agreements. To provide scalability, flexibility, and resilience, we propose to deploy smart licenses on a network of networks model, i.e., a set of heterogeneous networks potentially running different DLT protocols and connected by cross-chain information exchange protocols. A novel advantage of the network of networks approach is that it allows for the use of private values for royalty computation, which is impossible in the traditional model. Of course, supporting private DLT networks requires privacy-preserving cross-chain schemes, a still open problem in the literature. This is why we present two alternative privacy-preserving cross-chain schemes for our considered application scenario of license agreements management, one based on Homomorphic Encryption (HE) and the other on Zero-Knowledge (ZK) proofs. Besides discussing their theoretical advantages and drawbacks, we present an experimental evaluation of a prototype implementation of smart licenses based on both schemes. ⢠We propose a network of networks model that enhances scalability in smart license ecosystems. ⢠The proposed model allows smart licenses to leverage data from heterogeneous networks, including private ones. ⢠We compare two methods for privacy-preserving cross-chain communication: homomorphic encryption and zero-knowledge proofs. ⢠We experimentally evaluate and compare two different privacy-preserving smart license implementations.
The rapid advancement of quantum computing presents a fundamental challenge to modern cryptographic security, particularly in the domain of hash functions that ensure data integrity, authentication, and blockchain security. Traditional crypto graphic hash functions such as SHA-256, SHA-3, and BLAKE2 rely on computational hardness assumptions that become obsolete in the presence of large-scale quantum computers. Shorâs algorithm can efficiently break RSA and ECC-based cryptosys tems, while Groverâs algorithm reduces the security of traditional hash functions by square root complexity, significantly weakening their preimage and collision resistance. This quantum threat necessitates the development of post-quantum secure hashing techniques that remain resilient against both classical and quantum adversaries. This paper proposes Quantum Hashing, a novel cryptographic framework that integrates quantum entanglement, lattice-based cryptography, and hybrid quantum classical hashing to construct post-quantum secure hash functions. We introduce a formal model for Quantum Collision Resistance (QCR) and provide entropy-based ran domness enhancement to ensure unpredictable hash outputs. Unlike classical hashing approaches, our framework leverages the hardness of lattice problems (e.g., Shortest Vector Problem, Learning with Errors) to withstand quantum attacks while incorpo rating Quantum Key Distribution (QKD) mechanisms to enhance entropy and key management. Furthermore, we evaluate the security of Quantum Hashing under various attack models, comparing its resistance against Groverâs search and collision attacks. We benchmark its performance against NIST Post-Quantum Cryptography (PQC) final ists, including CRYSTALS-DILITHIUM, SPHINCS+, and Falcon, demonstrating that our approach offers superior resilience while maintaining computational feasibility. Additionally, we present an implementation of Quantum Hashing using Qiskit, show casing its practical applicability in quantum circuits and quantum-secure blockchain architectures. Our findings highlight that Quantum Hashing provides a scalable, entropy-efficient, and post-quantum resilient cryptographic primitive suitable for next-generation cryptographic applications. This work paves the way for secure post-quantum digital signatures, blockchain consensus mechanisms, and zero-knowledge proof systems that require tamper-resistant hashing in a quantum computing era.
With the widespread adoption of mobile smart devices, mobile crowd sensing(MCS) has provided better services for people. To meet the growing sensing demands within a limited budget, platforms have integrated two modesâopportunistic sensing and participatory sensingâto utilize their complementary strengths. However, location privacy issues may reduce workers' willingness to participate, thereby affecting task completion rates. Although existing methods have addressed privacy protection in a single sensing mode, there remains little focus on location privacy in hybrid sensing modes. There are two main limitations in privacy issues related to task allocation: (i) how to effectively preserve workers' location privacy in hybrid sensing modes, and (ii) the usual reliance on trusted thirdparty institution. To address these issues, we propose a privacypreserving hybrid multi-task allocation for MCS (PPHMA). This approach preserves workers' location privacy without relying on a fully trusted third-party institution, while maximizing the number of tasks completed. Specifically, for opportunistic task allocation, we employ zero-knowledge range proofs to protect workers' location , thereby avoiding location privacy leaks. Subsequently, based on the performance capability indicator of opportunistic workers, we select appropriate workers for task allocation. For participatory task allocation, we employ a worker location obfuscation generation algorithm to locally generate and upload obfuscated locations, ensuring that both the worker's real and obfuscated locations satisfy Ďľ-Geo-Indistinguishability within the protected range. Then, based on the execution capability indicator of the participatory workers, we screen for candidate workers and use a greedy immune clone algorithm to optimize the workers' travel distances. Finally, we verify the effectiveness of the scheme through experiments using two real-world datasets
V. Rama Krishna, Abdullah H Maad, Ali Ihsan Alanssari, Nour Rahim Nimah ¡ 6 authors
This article discusses how integrating AI and blockchain technology into digital health platforms might help and hurt privacy, fairness, transparency, and compliance. This research compares AI and blockchain technologies for making honest and ethical healthcare choices. We are investigating federated learning, homomorphic encryption, differential privacy, zero-knowledge proofs, self-sovereign identity systems, explainable AI, blockchain interface protocols, and privacypreserving AI systems. We rated each technique based on data protection, ethical data collecting, computer justice, openness, and system security. While most approaches perform well in certain locations, they all have issues that may render them unsuitable for use in healthcare. The proposed solution addresses these concerns and outperforms speed standards. It evaluates ethical risks based on bias, fairness, and transparency and is continuously improving ethical decision-making. These evaluations improve healthcare AI systems' reliability, fairness, and clarity during decision-making. This implies its potential application in AI-driven healthcare systems.
Blockchain Technology Applications and Security
Ethics and Social Impacts of AI
Neuroethics, Human Enhancement, Biomedical Innovations
ABSTRACT Selfâsovereign identity management systems operate in open network environments and face security threats from semiâtrusted or malicious adversary models. In such environments, verifiable credentials are susceptible to attacks such as theft and forgery. In response to the privacy risks associated with verifiable credentials during issuance and revocation, this article proposes a privacy protection scheme for user information during the issuance and revocation processes of verifiable credentials in selfâsovereign identity management based on blockchain technology. First, a privacyâpreserving method that does not rely on a single identity provider and resists Sybil attacks has been designed using secure multiâparty computation cryptographic techniques. Second, the consortium blockchain committee nodes act as the issuer of verifiable credentials. By combining attribute commitments and zeroâknowledge proof techniques, the user's identity information is hidden, achieving the privacy protection goal during the issuance of verifiable credentials. Furthermore, in order to protect user privacy during the revocation of verifiable credentials (VCs), we employ a cryptographic accumulator technique to implement the revocation operation. This approach ensures the security of user privacy while effectively managing the revocation of credentials. Finally, this paper conducts a security analysis and performance evaluation of the proposed scheme. The results show that our scheme strikes a balance between security needs and time efficiency.
Zero-Knowledge Proofs (ZKPs) are a rapidly growing technique for privacy-preserving and verifiable computation.ZKPs enable one party (a prover: P) to prove to another (a verifier: V) that a statement is true or correct without revealing any additional information.This powerful capability has led to ZKPs being applied and proposed for application in blockchain technologies, verifiable machine learning, and electronic voting.However, ZKPs have yet to see widespread, ubiquitous adoption due to the exceptionally high computational complexity of the proving process.Naturally, there has been recent work to accelerate ZKP primitives and protocols using GPUs and ASICs.However, the protocols considered so far face one of two challenges: they require a trusted setup for each new application or generate large proofs with high verification costs, limiting their applicability in scenarios with numerous verifiers or strict verification time constraints.HyperPlonk is a state-of-theart ZKP protocol that supports both one-time, universal setup and small proof sizes/verification costs expected by publicly verifiable, consensus-based systems (e.g., blockchain).While HyperPlonk's setup and verifier properties are highly desirable, the proving phase is costly.A HyperPlonk prover must compute on large bitwidths (e.g., 255-381b) and polynomials (e.g., of degree 2 24 ), employs computationally (e.g., MSM) and bandwidth (e.g., SumCheck) intensive kernels, and the complete protocol comprises many steps, each constituting distinct kernels.We present an accelerator, zkSpeed, to
The round complexity of interactive proof systems is a key question of practical and theoretical relevance in complexity theory and cryptography. Moreover, results such as QIP = QIP(3) (STOC'00) show that quantum resources significantly help in such a task. In this work, we initiate the study of round compression of protocols in the bounded quantum storage model (BQSM). In this model, the malicious parties have a bounded quantum memory and they cannot store the all the qubits that are transmitted in the protocol. Our main results in this setting are the following: 1. There is a non-interactive (statistical) witness indistinguishable proof for any language in NP (and even QMA) in BQSM in the plain model. We notice that in this protocol, only the memory of the verifier is bounded. 2. Any classical proof system can be compressed in a two-message quantum proof system in BQSM. Moreover, if the original proof system is zero-knowledge, the quantum protocol is zero-knowledge too. In this result, we assume that the prover has bounded memory. Finally, we give evidence towards the âtightnessâ of our results. First, we show that NIZK in the plain model against BQS adversaries is unlikely with standard techniques. Second, we prove that without the BQS model there is no 2âmessage zero-knowledge quantum interactive proof, even under computational assumptions.
In an era where securing Internet of Things (IoT) devices within Metaverse environments is increasingly critical, existing frameworks often lack robust, quantum-resistant protection suitable for resource-constrained devices. This study aims to develop a comprehensive quantum-resistant security framework designed for IoT-enabled Metaverse applications. Our multilayered architecture incorporates Ideal Coset Lattice Cryptography (ICLC) and a Hypercomplex Multivariate Encryption Scheme (HMES) across the Device, Network, and Metaverse layers. ICLC provides lightweight, quantum-resistant encryption for devices with limited computational resources, while HMES enhances security through complex algebraic structures resistant to quantum attacks. We implement a Zero-Knowledge Proof Authentication mechanism over Hypercomplex Algebras (ZKPHA) to authenticate devices without exposing private keys. An edge computing strategy that employs convex optimization minimizes latency and computational load, ensuring scalability and efficiency. Simulations over a 260-minute period compared our framework with six state-of-the-art methods under various conditions. The results show that our framework reduces the rate of successful cyberattacks on encrypted data to 0.15%, achieves encryption and decryption times of 2.2 milliseconds per operation, and maintains 98.5% system availability during attacks.
The seminal work of Goldreich and Krawczyk (SIAM Journal on Computing) shows that any constant-round public-coin interactive proof for languages not in <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mrow> <mml:mrow> <mml:mi mathvariant="sans-serif">B</mml:mi> <mml:mi mathvariant="sans-serif">P</mml:mi> <mml:mi mathvariant="sans-serif">P</mml:mi> </mml:mrow> </mml:mrow> </mml:math> cannot be black-box zero knowledge. Their result says nothing, however, about proofs (or arguments) of knowledge for languages in <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mrow> <mml:mrow> <mml:mi mathvariant="sans-serif">B</mml:mi> <mml:mi mathvariant="sans-serif">P</mml:mi> <mml:mi mathvariant="sans-serif">P</mml:mi> </mml:mrow> </mml:mrow> </mml:math>. As a special case, their work leaves open the question of whether Schnorr's protocol for proving knowledge of discrete logarithms in cyclic groups is black-box zero knowledge. In this work we focus on the zero knowledge of proofs of knowledge, centering on Schnorr's protocol as a prominent example. We prove two lower bounds, ruling out two different classes of simulators through which Schnorr's protocol can be proven zero knowledge: We prove that if a relation <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mrow> <mml:mi>â</mml:mi> </mml:mrow> </mml:math> has a public-coin interactive proof of knowledge that is black-box zero knowledge and this protocol is compatible with the Fiat-Shamir transform in the random oracle model, then <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mrow> <mml:mi>â</mml:mi> </mml:mrow> </mml:math> must be efficiently searchable. As an immediate corollary, we deduce that Schnorr's protocol cannot be black-box zero knowledge in groups in which discrete log is hard. We define a new class of simulators for Schnorr's protocol, which we call generic simulators. A generic simulator is one that works in any cyclic group, and does not use the representation of the specific group in which Schnorr's protocol is instantiated. We prove that Schnorr's protocol cannot have generic simulators. As an additional contribution, we generalize the original lower bound of Goldreich and Krawczyk, to prove that a language not in <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mrow> <mml:mrow> <mml:mi mathvariant="sans-serif">B</mml:mi> <mml:mi mathvariant="sans-serif">P</mml:mi> <mml:mi mathvariant="sans-serif">P</mml:mi> </mml:mrow> </mml:mrow> </mml:math> cannot have an interactive proof (not necessarily of knowledge) that is both black-box zero knowledge and compatible with the Fiat-Shamir transform in the random oracle model. In conjunction with recent works, this extends the Goldreich-Krawczyk lower bound to public-coin protocols that are not constant-round but have round-by-round soundness, including the parallel repetition of any public-coin interactive proof.
Michele OrrĂš, George Kadianakis, Mary Maller, Greg Zaverucha
A fundamental challenge in zero-knowledge proof systems is implementing operations that are âforeignâ to the underlying constraint system, in that they are arithmetic operations with a different modulus than the one used by the proof system. The modulus of the constraint system is a large prime, and common examples of foreign operations are Boolean operations, field arithmetic, or public-key cryptography operations. We present novel techniques for efficiently embedding such foreign arithmetic in zero-knowledge, including (i) equality of discrete logarithms across different groups; (ii) scalar multiplication without requiring elliptic curve operations; (iii) proving knowledge of an AES encryption. Our approach combines rejection sampling, sigma protocols, and lookup protocols. We implement and provide concrete benchmarks for our protocols.
Blockchain-driven financial innovation in Hong Kong from 2018 to 2024 has transformed cross-border payment systems through strategic regulatory frameworks and public-private collaboration. Key developments include the e-HKD Pilot Programme, integration with China's digital yuan, and pioneering CBDC initiatives like Project mBridge. This review analyzes technological implementations (Layer-2 solutions, zero-knowledge proofs), regulatory evolution across three distinct phases, and economic impacts including 38\% cost reduction in SME transactions. We examine Hong Kong's unique position bridging China's financial infrastructure with global markets while navigating geopolitical tensions and compliance challenges. The study provides quantitative metrics from 50+ corporate disclosures and regulatory documents, establishing a model for hybrid governance systems in financial technology adoption.
Nishant Jagannath, Christopher Kevin Wong, Braden Mcgrath, Md. Faruque Hossain ¡ 7 authors
The rapid advancement of artificial intelligence (AI) has brought about sophisticated models capable of various tasks ranging from image recognition to natural language processing. As these models continue to grow in complexity, ensuring their trustworthiness and transparency becomes critical, particularly in decentralized environments where traditional trust mechanisms are absent. This paper addresses the challenge of verifying personalized AI models in such environments, focusing on their integrity and privacy. We propose a novel framework that integrates zero-knowledge succinct non-interactive arguments of knowledge (zk-SNARKs) with Chainlink decentralized oracles to verify AI model performance claims on blockchain platforms. Our key contribution lies in integrating zk-SNARKs with Chainlink oracles to securely fetch and verify external data to enable trustless verification of AI models on a blockchain. Our approach addresses the limitations of using unverified external data for AI verification on the blockchain while preserving sensitive information of AI models and enhancing transparency. We demonstrate our methodology with a linear regression model predicting Bitcoin prices using on-chain data verified on the Sepolia testnet. Our results indicate the framework's efficacy, with key metrics including proof generation taking an average of 233.63 seconds and verification time of 61.50 seconds. This research paves the way for transparent and trustless verification processes in blockchain-enabled AI ecosystems, addressing key challenges such as model integrity and model privacy protection. The proposed framework, while exemplified with linear regression, is designed for broader applicability across more complex AI models, setting the stage for future advancements in transparent AI verification.
Debugging and auditing zero-knowledge-compatible smart contracts remains a significant challenge due to the lack of source mapping in compilers such as zkSolc. In this work, we present a preliminary source mapping framework that establishes traceability between Solidity source code, LLVM IR, and zkEVM bytecode within the zkSolc compilation pipeline. Our approach addresses the traceability challenges introduced by non-linear transformations and proof-friendly optimizations in zero-knowledge compilation. To improve the reliability of mappings, we incorporate lightweight consistency checks based on static analysis and structural validation. We evaluate the framework on a dataset of 50 benchmark contracts and 500 real-world zkSync contracts, observing a mapping accuracy of approximately 97.2% for standard Solidity constructs. Expected limitations arise in complex scenarios such as inline assembly and deep inheritance hierarchies. The measured compilation overhead remains modest, at approximately 8.6%. Our initial results suggest that source mapping support in zero-knowledge compilation pipelines is feasible and can benefit debugging, auditing, and development workflows. We hope that this work serves as a foundation for further research and tool development aimed at improving developer experience in zk-Rollup environments.
Suhyeon Lee, Euisin Gee, Najmeh Soroush, Muhammed Ali Bingol ¡ 5 authors
Simple commit-reveal beacons are vulnerable to last-revealer strategies, and existing descriptions often leave accountability and recovery mechanisms unspecified for practical deployments. We present Commit-Reveal$^2$, a layered design for blockchain deployments that cryptographically randomizes the final reveal order, together with a concrete accountability and fallback mechanism that we implement as smart-contract logic. The protocol is architected as a hybrid system, where routine coordination runs off chain for efficiency and the blockchain acts as the trust anchor for commitments and the final arbiter for disputes. Our implementation covers leader coordination, on-chain verification, slashing for non-cooperation, and an explicit on-chain recovery path that maintains progress when off-chain coordination fails. We formally define two security goals for distributed randomness beacons, unpredictability and bit-wise bias resistance, and we show that Commit-Reveal$^2$ meets these notions under standard hash assumptions in the random-oracle model. In measurements with small to moderate operator sets, the hybrid design reduces on-chain gas by more than 80% compared to a fully on-chain baseline. We release a publicly verifiable prototype and evaluation artifacts to support replication and adoption in blockchain applications.
Muhammad Jawad, âŞMahmood A. Al-ShareedaâŹâ, Omar Yawez Mustafa Mustafa, Mohammed Amin Almaiah ¡ 5 authors
Analysis of repeated attack signatures is important because of the rapid evolution of the Social Internet of Vehicles (SIoV). However, threats such as replay attacks, session hijacking, and key reuse make secure communication between vehicles, roadside units (RSUs), and the fog node difficult. Traditional models for authentication are limited by computational overhead and lack quick key revocation. In response to these challenges, we propose a hybrid cryptographic authentication scheme that combines a Zero-Knowledge Proof (ZKP) with AES-GCM encryption. Our protocol implements a dynamic key revocation mechanism to avoid rogue and session key migration, minimizing re-authentication delay. Security analysis in the Real-Oracle Random (ROR) model shows that it is not vulnerable to impersonation or replay attacks. Evaluations demonstrate decreases of 58% in authentication latency while achieving 45% and 72% improvements in communication and computation efficiency, respectively. Our approach is also scalable and secure, providing SIoV with higher reliability for automotive applications in the vehicular networks of the future.
The proliferation of numerous portable mobile devices has made mobile crowd-sensing (MCS) systems a promising new trend. Traditional MCS systems typically outsource sensing tasks to the data aggregator (e.g., cloud server). They collect and analyze the provided sensing data through an appropriate truth discovery (TD) method to identify valuable data sets. However, existing privacy-preserving MCS systems lack transparency, enabling data aggregators to deviate from the specified protocols and allowing malicious users to provide false or invalid sensing data, thereby contaminating the resulting data sets. The lack of transparency and public verifiability in MCS systems undermines widespread adoption by preventing data requesters from confidently verifying data integrity and accuracy. To address this issue, we propose a transparent and privacy-preserving mobile crowd-sensing system with truth discovery (TP-MCS) constructed using zero-knowledge proof (ZKP) and the Merkle commitment tree. This scheme enables data requesters to effectively verify the correctness of the truth discovery service while ensuring data privacy. Furthermore, theoretical analysis and extensive experiments demonstrate that this scheme is secure and efficient.
Following the emergence of the COVID-19 pandemic, electronic voting has gradually become an inseparable part of people's lives. However, it has also raised a series of severe privacy and trust challenges. The immutable and publicly transparent characteristics of blockchain are a perfect fit for the development of electronic voting systems, effectively eliminating voters' concerns about ballot tampering.At the same time, zero-knowledge proofs enable the prover to show they possess certain information to the verifier, without disclosing the actual details. It is important to note that with the rapid development of quantum technology, traditional cryptographic schemes face unprecedented security threats. To address this challenge, We present a quantum-resistant blockchain solution for electronic voting, incorporating zero-knowledge proofs. Compared to conventional elliptic curve-based zero-knowledge proof schemes, our proposed solution is based on RLWE, ensuring voter privacy, and uses BFV fully homomorphic encryption technology to implement a blockchain-based electronic voting protocol, ensuring the systemâs high availability, security, and anonymous voting. Security analysis and performance testing, along with comparisons to existing similar solutions, show that our scheme has advantages in terms of security and robustness, making it highly practical.
The global shift towards sustainable transportation necessitates efficient and secure payment systems for electric vehicle (EV) charging on electrified roads. Current blockchain-based payment infrastructures face high transaction costs, inefficiencies, and security vulnerabilities, impeding EV adoption. To address these challenges, we propose a blockchain-based Vehicle Payment System (VPS) tailored for electrified roads. VPS integrates a hybrid consensus mechanism combining Proof of Stake (PoS) and Practical Byzantine Fault Tolerance (PBFT) for secure, decentralized, and efficient transaction validation. Scalability is enhanced through sharding, which distributes transaction load, while Zero-Knowledge Proofs (ZKPs) ensure transaction confidentiality, and multi-signature transactions provide additional security. State channels further optimize performance by enabling off-chain transactions, reducing congestion, and increasing throughput. Unlike prior research, which often neglects scalability, privacy, and real-time performance holistically, VPS achieves under 3000 ms latency for invoke transactions, under 450 ms for queries with 1000 users, and a throughput of approximately 1100 transactions per second (TPS) at a send rate of 1300. These advancements establish VPS as a scalable, efficient payment solution for EV charging, supporting the transition to green mobility and informing sustainable infrastructure policies.
Distributed Ledger Technologies (DLTs), including Blockchain, have revolutionized financial systems by offering decentralized, transparent, and secure mechanisms for data management and transactions. However, for these systems to maintain integrity and protect sensitive financial data, robust cryptographic techniques are essential. Cryptography ensures data confidentiality, authenticity, integrity, and non-repudiation, which are critical for the security of financial transactions in DLTs. This article examines the role of cryptographic protocols such as hashing, digital signatures, asymmetric encryption, and zero-knowledge proofs in safeguarding distributed ledgers. Furthermore, we explore their applications in securing financial transactions, preventing fraud, ensuring compliance, and enhancing the overall reliability of DLTs in financial systems. The discussion also delves into the challenges of cryptographic security in the face of emerging threats and the potential impact of quantum computing on existing cryptographic protocols.