Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

1,104 papersLast indexed Aug 31, 2026
Search papers

Paper index

1,104 results · page 12 of 46

Clear filters
Sep 1, 2025·DOAJ (DOAJ: Directory of Open Access Journals)
0 cites
A blockchain-based authentication handover protocol for autonomous vehicle networks

Balakrishnan Subramanian, Leelavathy Sivakumar, Sumathi Duraisamy, Simonthomas Sagayaraj · 6 authors

Purpose: The framework of the Autonomous Vehicles (AVs) is facilitated by modern communication systems. In Real-Time (RT), the data is communicated to one another, and it is encouraged by AV. This AV also communicates with organizations stationed along the roadway, and navigates without human intervention. The dynamic and decentralized communication between vehicles and Roadside Units (RSUs) is integrated in Vehicular Ad Hoc Networks (VANETs). Then, there is no centralized structure for utilization in VANET. This distributed system faces difficulties in 2 areas: Authentication and security. The susceptibility to the network is increased by the unpredictable and risky features of AV, because there is currently no robust authentication system in place for multi-broadcast situations. Hence, the network is susceptible to security breaches, illegal access, data tampering, and service interruptions. During Handover Authentication (HA) between RSUs, critical security vulnerabilities are introduced by AV communication in ad-hoc networks, because of their dynamic topology and mobility patterns.Methodology: To address these issues, this study proposes a HA system for ad hoc AVs that uses blockchain technology. Using distributed controllers and Zero Knowledge Proofs (ZKPs), the proposed methodology enables rapid and safe authentication of AVs during handover between RSUs. To optimize authentication, decentralized Smart Network Controllers (SNCs) were used by the suggested method. This suggested method also eliminates the dependency on centralized entities and mitigates Single Point of Failure (SPoF) vulnerabilities.Findings: A private Blockchain network implementation makes the system transparent and immutable while providing tamper-proof storage for vehicle data. Simulation results demonstrate that the protocol achieves a 30.4% reduction in authentication latency, 27.8% lower packet loss rate, and a 23.5% improvement in throughput compared to EMT and GMT baseline protocols. Additionally, the system sustains a 95.2% success rate in mutual authentication under high vehicle density and maintains security integrity against impersonation, Sybil, and replay attacks.Originality/Value: The suggested protocol also mitigates SPoF risk of centralized systems and offers smooth Vehicle-to-Everything (V2X) services without charging any transaction fee. This method provides strong and scalable security for the communication of AVs in smart city systems.

Vehicular Ad Hoc Networks (VANETs)
Blockchain Technology Applications and Security
Advanced Authentication Protocols Security
Original source
Aug 31, 2025·Aaltodoc (Aalto University)
0 cites
Cryptographic primitives from the lattice isomorphism problems

Pham, Harry

The Lattice Isomorphism Problem (LIP) is an emerging foundation for post-quantum cryptography thanks to the pioneering work of Ducas and van Woerden (EUROCRYPT '22). That work lays the foundation for LIP in cryptography with a zero-knowledge proof of knowledge (ZKPoK), a key-encapsulation mechanism, and a digital signature scheme which is further developed into the efficient signature Hawk (ASIACRYPT '22) using structured lattices. However, as compared to the development of lattice-based cryptography from the Short Integer Solution (SIS) and Learning with Errors (LWE) problems, LIP-based cryptography is yet to cover a rich variety of functionalities beyond the two basic ones: encrypting and digitally signing messages. This work is an effort to extend the landscape of LIP-based cryptography from the above basic primitives to more advanced ones by adapting techniques used in SIS-based and LWE-based primitives to LIP. We provide a public-key encryption (PKE) which encrypts plaintexts of integral vectors, and it comes with a zero-knowledge proof of plaintext knowledge. We use this PKE as a commitment scheme in the construction of a ZKPoK for quadratic relations, so this ZKPoK has a straightline extractor naturally. Using the same ZKPoK in non-interactive mode by Fiat-Shamir transformation, we introduce the first LIP-based blind signature scheme which is the blinded version of the digital signatures of Ducas and van Woerden. The security of our scheme stems from a new one-more Close Vector Problem (omCVP) assumption. This assumption is arguably an analogue of the one-more-SIS assumption by Agrawal et al. (CCS '22) and the one-more Short Vector Problem in Hawk signatures. To ensure confidence in omCVP, we provide a cryptanalysis attempt and convince that our parameter choice is in the safe zone.

Cryptography and Data Security
Advanced Authentication Protocols Security
Cryptography and Residue Arithmetic
Original source
Aug 26, 2025·2025 IEEE International Symposium on Future Telecommunication Technologies (SOFTT)
0 cites
Benchmarking Zero-Knowledge Proof-Based Authentication Protocols

Zeineb Ben Sassi, Chiheb Chahine Yaici, Jiahui Xiang, Osman Salem · 5 authors

Zero-Knowledge Proof (ZKP) protocols offer a powerful foundation for privacy-preserving authentication by allowing one party to prove knowledge of a secret without revealing it. Such protocols are increasingly relevant in domains such as secure communications, blockchain technologies, digital identity management, and e-health, where data confidentiality and integrity are critical. While various ZKP schemes exist, their practical performance remains a key factor in choosing the appropriate protocol for real-world applications, since efficiency directly impacts scalability, user experience, and system adoption.In this work, we conduct a comparative benchmarking study of five no table ZKP-based authentication protocols: Fiat–Shamir, Zero-Knowledge Succinct Non-Interactive Argument of Knowledge (zk-SNARK), Zero-Knowledge Scalable Transparent Argument of Knowledge, (zk-STARK), Schnorr, and Guillou–Quisquater. Each protocol is evaluated in a standardized virtualized environment to ensure fair comparisons across implementations. We measure and analyze multiple performance metrics, including prover and verifier execution time, Central Processing Unit (CPU) and memory consumption, and network usage per proof. Our results reveal significant differences in resource efficiency, highlighting trade-offs between computational cost, proof size, and cryptographic expressiveness.This study provides a systematic evaluation clarifying the relative strengths and weaknesses of widely used ZKP protocols, serving as a practical reference for researchers, practitioners, and system designers seeking to integrate zero-knowledge techniques under real-world performance constraints.

Cryptography and Data Security
Advanced Authentication Protocols Security
Blockchain Technology Applications and Security
Original source
Aug 22, 2025·2025 9th International Conference on Computing, Communication, Control and Automation (ICCCBEA)
0 cites
Decentralized Access Control and Continuous Monitoring in Healthcare Facilities: A Privacy-Preserving Framework Integrating Zero-Knowledge Proofs, Biometric Authentication, and Blockchain Technology

Saloni Kumbhar, Aditya Mourya, Vinayak Musale, Safalya Satpute · 6 authors

Securing sensitive physical and digital areas, such as equipment rooms, medical records storage, and intensive care units (ICUs), is crucial in modern health care environments. Traditional ways of access control that depend on static authorization and centrally maintained databases are becoming more vulnerable to insider threats, identity spoofing, and data breaches. To enhance privacy, transparency and realtime threat detection in healthcare infrastructure, paper suggests a conceptual architecture for a secure, decentralized access control system that integrates blockchain technology, biometric authentication, and Zero-Knowledge Proofs (ZKPs). Recognition of fingerprints serves as the system's main authentication technique, and feature vectors are safely stored on a decentralized blockchain and cryptographically committed using Pedersen commitments. A zk-SNARK is generated during access requests to verify the accuracy of the user's biometric input without disclosing the real biometric data. Smart contracts validate access decisions, allowing for unaltered event logging and automated policy enforcement. The system combines entry-point security with Edge AI-based continuous monitoring, which tracks people's movements within the secure area using motion sensors and CCTV. The individual's continued authorization during their presence is guaranteed by periodic behavioral verification conducted by ZKPs. Anomalies that are discovered are immediately reported and stored on the blockchain for forensic examination. The approach suggested combines behavioral confirmation with physical identity verification to provide a strong multifactor authentication (MFA) framework. Although conceptual in nature, the architecture provides a scalable and privacypreserving model for next-generation healthcare access control systems because it is based on blockchain and cryptography technologies that have been proven to work.

User Authentication and Security Systems
Access Control and Trust
Advanced Authentication Protocols Security
Original source
Aug 20, 2025·Computer Networks
3 cites
ZETROS: A zero-trust IoT network security framework using distributed blacklisting, trust scoring and smart contracts

Cem Ata Baykara, Ilgın Şafak, Kübra Kalkan

The purpose of Internet of Things (IoT) security is to ensure the availability, confidentiality, and integrity of IoT networks. However, due to the heterogeneity of IoT devices and the possibility of attacks of various kinds from both inside and outside the network, securing an IoT network is a difficult task. Handshake protocols are useful for achieving mutual authentication, which allows secure inclusion of devices into the network. By verifying that the information they receive is accurate and from a trusted source, mutual authentication minimizes the possibility that a malicious actor will compromise their connections. However, handshake protocols do not protect devices from attackers in the network. Use of autonomous anomaly detection and blacklisting prevents nodes with anomalous behavior from joining, re-joining, or remaining in the network. Similarly, trust scoring is another popular method that can be used to increase the resilience of the network against trust based system attacks. In view of the above, the contributions of this paper are three-fold. First, to ensure the security of the IoT network from outsider attacks in a zero-trust environment, we propose a new handshake protocol based on Physical Unclonable Functions that can be used in IoT device discovery and mutual authentication between the IoT device and the server. The proposed protocol is resilient to Man-in-the-Middle, replay and forgery attacks, as proven in our security analysis. Secondly, we propose a real-time intrusion and anomaly detection framework based on machine learning to prevent network-based attacks from insiders. Finally, we propose a trust system which utilizes feedback mechanisms based on smart contracts for managing the trust of a dynamic IoT network to increase resilience against behavioral attacks. Simulation results show that by using blacklisting, our trust management model provides greater resilience against trust-based attacks compared to similar blockchain-based trust models in the literature, and the proposed distributed IoT network security framework can secure an IoT network from both internal and external attacks, even in an environment where half of the devices in the network are compromised.

Open access
Blockchain Technology Applications and Security
Cryptography and Data Security
Advanced Authentication Protocols Security
Original source
Aug 20, 2025·2025 3rd International Conference on Sustainable Computing and Smart Systems (ICSCSS)
0 cites
Secure Data Transmission via Hybrid Lightweight Authentication Framework

A.Bhargavi, B. Nandini

Cloud storage has undergone drastic improvements in recent years as it facilitates the storage of huge volumes of data. However, storing data in the cloud remains a complex task as it has to deal with security concerns. Blockchain is implemented to successfully avoid the security crises involved in the cloud storage network. Several approaches have been developed to secure data transmission within the cloud, but they have resulted in minimal throughput, failed in detecting threats, and consumed more time to transmit data. To address these complexities, a Hybrid Smart Contract-enabled Lightweight Authentication framework (HSC-LwA) is proposed to secure the transmission of data in a heterogeneous blockchain. The proposed HSC-LwA model works with hybrid concepts that include a consensus algorithm, Proof of Stake (PoS), and Proof of Work (PoW). This hybrid method incorporates a reward-based strategy to verify the transaction to add a block to the network. The primary task of this model is to safeguard the information within the cloud network and the data in a heterogeneous blockchain. The evaluation of the proposed HSC-LwA method obtained the values for Gas Transaction, Genuine user rate, Responsiveness, and Transaction Time is 286.87KB, 0.88, 6.73s, and 5.48s based on transaction analysis, whereas the model showed the improvement by obtaining the values for the above metrics as 330.12KB, 0.86, 6.32s, 5.55s with user analysis.

Advanced Authentication Protocols Security
Chaos-based Image/Signal Encryption
Cryptographic Implementations and Security
Original source
Aug 13, 2025·IEEE Transactions on Vehicular Technology
1 cites
BCUA: A UAV Group Authentication Protocol Based on the CVMerkle Tree Structure

W. Jiang, Zhiqiang Du, Xiaofeng Rong, Yanfang Fu · 6 authors

With the rapid development of 5 G communication technology, small military UAV swarms are increasingly used in reconnaissance, surveillance, and remote sensing fields. Authentication has become a critical factor in ensuring the safe and efficient operation of UAV swarms. Due to their complexity and limitations, traditional methods cannot meet the dynamic deployment and command authority switching requirements of UAV swarms in special wartime environments. Therefore, this study proposes a secure and efficient authentication scheme for UAV swarms based on the CVMerkle tree structure. The scheme integrates distributed digital ledger technology to optimize the authentication process between UAVs and the Airborne Command Center(ACC). This significantly reduces the communication and computational load while improving the security and reliability of authentication. Additionally, the scheme introduces the innovative concept of dynamic authorization in the ACC, which effectively eliminates security threats arising from internal corruption within the core organization. The results of the simulation experiment demonstrate that the scheme offers significant advantages in terms of security, efficiency, and storage requirements. Future research will focus on developing more efficient key management mechanisms and swarm-switching strategies to adapt to the complex and dynamic combat environment, further enhancing the combat effectiveness of UAV swarms.

UAV Applications and Optimization
Advanced Authentication Protocols Security
Security in Wireless Sensor Networks
Original source
Aug 12, 2025·arXiv (Cornell University)
0 cites
A Stream Pipeline Framework for Digital Payment Programming based on Smart Contracts

Meng, Zijia, Victor Feng

Digital payments play a pivotal role in the burgeoning digital economy. Moving forward, the enhancement of digital payment systems necessitates programmability, going beyond just efficiency and convenience, to meet the evolving needs and complexities. Smart contract platforms like Central Bank Digital Currency (CBDC) networks and blockchains support programmable digital payments. However, the prevailing paradigm of programming payment logics involves coding smart contracts with programming languages, leading to high costs and significant security challenges. A novel and versatile method for payment programming on DLTs was presented in this paper - transforming digital currencies into token streams, then pipelining smart contracts to authorize, aggregate, lock, direct, and dispatch these streams efficiently from source to target accounts. By utilizing a small set of configurable templates, a few specialized smart contracts could be generated, and support most of payment logics through configuring and composing them. This approach could substantially reduce the cost of payment programming and enhance security, self-enforcement, adaptability, and controllability, thus hold the potential to become an essential component in the infrastructure of digital economy.

Open access
2 source records
q-fin.TR
cs.CR
Blockchain Technology Applications and Security
Original source
Aug 8, 2025·2025 IEEE 8th Advanced Information Technology, Electronic and Automation Control Conference (IAEAC)
1 cites
A Review of Blockchain-Based Authentication Research

Hengjiang Xiao, Zhihong Liang, Yuxiang Huang, Mingming Qin · 5 authors

Blockchain, as a decentralized and tamperproof distributed ledger technology, has gained wide attention in finance, Internet of Things and other fields since it was proposed by Satoshi Nakamoto in 2008. Identity authentication is the basic guarantee for cyberspace security, but traditional centralized identity management suffers from single point of failure, privacy leakage and poor interoperability. Blockchain-based identity authentication utilizes distributed trust mechanism and cryptography technology, which is expected to realize secure sharing and autonomous control of identity data. In this paper, we systematically sort out the infrastructure (network layer, consensus mechanism, etc.) and types of blockchain technology, and elaborate the supportive role of the combination of blockchain and cryptography (hashing, digital signatures, zero-knowledge proofs, etc.) for identity authentication. It focuses on an overview of the research progress on the improvement of public key infrastructure (PKI), biometric combination scheme, and the integration of decentralized identity (DID) and verifiable credentials (VC) in the blockchain environment, and analyzes its application examples in the scenarios of Internet of Things (IoT), smart grids, finance, healthcare, and education. This paper summarizes the current challenges and limitations of blockchain identity authentication, such as performance scaling, privacy protection, standards interoperability, key management, etc., and the possible future research directions, including more efficient consensus algorithms, zeroknowledge proof applications, cross-chain identity mutual recognition mechanisms, and improvement of policies and regulations.

Blockchain Technology Applications and Security
User Authentication and Security Systems
Advanced Authentication Protocols Security
Original source
Aug 7, 2025·2025 Seventeenth International Conference on Contemporary Computing (IC3)
0 cites
EHRShare: A Blockchain-Based Electronic Health Record Sharing System with Zero-Knowledge Proof

Ashutosh Kumar, Amrendra Singh Yadav, Rohit Kumar Sachan, Avadh Kishor · 6 authors

This paper presents a secure and privacy-preserving framework for Electronic Health Record (EHR) sharing using blockchain and zero-knowledge proofs (ZKPs). The system enables patients to control access to their health data through smart contracts, ensuring that only verified users can access sensitive information. ZKPs authenticate users without revealing identities, preserving confidentiality. IPFS is used for off-chain storage, reducing on-chain costs and improving scalability. The proposed model supports dynamic access control, including permission granting, revocation, and automatic expiry. This approach enhances data integrity, verifiability, and privacy in decentralized healthcare environments.

Blockchain Technology Applications and Security
Cryptography and Data Security
Advanced Authentication Protocols Security
Original source
Aug 4, 2025·IEEE Transactions on Intelligent Transportation Systems
3 cites
BCDAP-DGS: Dynamic Group Signature and Batch Cross-Domain Authentication Protocol for Intelligent Transportation

Chuanda Cai, Changgen Peng, Youliang Tian, Weijie Tan · 6 authors

The Internet of Vehicles (IoV), as a core component of intelligent transportation systems, significantly enhances the intelligence level of traffic management by enabling efficient vehicle-to-vehicle (V2V) and vehicle-to-infrastructure information sharing. However, the highly dynamic and open nature of the IoV poses severe security challenges in cross-domain scenarios, mainly due to the lack of trust relationships between different domains, making it difficult to achieve efficient and secure cross-domain authentication(CDA). Existing CDA mechanisms in the IoT context often suffer from high computational complexity, excessive communication overhead, and poor scalability for large-scale deployments. This paper proposes a Batch CDA Protocol based on Dynamic Group Signatures (BCDAP-DGS) to address these issues. The proposed protocol incorporates non-interactive zero-knowledge (NIZK) proofs to achieve secure identity verification without requiring additional data exchange. By leveraging dynamic group signature techniques, BCDAP-DGS supports real-time updates of vehicle membership status and provides conditional anonymity. In addition, an online/offline authentication framework is designed by incorporating vehicle location information to precompute related parameters, thereby significantly improving CDA efficiency. A formal security analysis is conducted under the random oracle model, demonstrating that the proposed protocol satisfies essential security properties, including anonymity, non-frameability, unforgeability, and traceability. Experimental results and performance comparisons show that the proposed protocol outperforms existing schemes in terms of both security and efficiency, making it well-suited for large-scale and highly dynamic IoV CDA scenarios.

Advanced Authentication Protocols Security
IPv6, Mobility, Handover, Networks, Security
Security in Wireless Sensor Networks
Original source
Jul 25, 2025·Proceedings of the 2025 2nd International Conference on Image Processing, Intelligent Control and Computer Engineering
0 cites
Practical secure outsourcing computation in complex cloud environments

Xin Ning

In our research, we propose the first practically deployable construction of a multi-prover zero-knowledge succinct non-interactive argument of knowledge (zkSNARK) protocol specifically tailored for restricted multiplication straight-line (RMS) programs, a computation model widely applicable in evaluating polynomials. Our protocol ensures input privacy, zero-knowledge, and security against fully malicious provers, all while eliminating the need for any inter-prover communication, making it highly suitable for distributed cloud environments. At the core of our approach is the introduction of the Restricted Quadratic Arithmetic Program model, an algebraic structure aligned with RMS semantics that enables provers to independently generate local proofs. We instantiate our framework using the Pinocchio protocol, resulting in a system that requires only 9 group elements per proof and 10 pairings for verification, nearly matching the efficiency of its single-prover counterpart. By leveraging our multi-prover zkSNARK protocol within a multi-server verification computation framework, we enable secure outsourcing of computations to the cloud of fully untrusted cloud servers. Compared to existing works, our protocol uniquely eliminates the need for any inter-server communication while achieving security even against adversaries controlling all servers.

Open access
Cryptography and Data Security
Polynomial and algebraic computation
Advanced Authentication Protocols Security
Original source
Jul 23, 2025·Journal of King Saud University - Computer and Information Sciences
10 cites
A quantum-resilient lattice-based security framework for internet of medical things in healthcare systems

Zeyad Ghaleb Al-Mekhlaf, Murtaja Ali Saare, Jalal Mohammed Hachim Altmemi, ‪Mahmood A. Al-Shareeda‬‏ · 9 authors

The rapid adoption of Internet of Medical Things (IoMT) devices enables real-time patient monitoring and remote diagnostics and has revolutionized healthcare delivery. Traditional cryptographic schemes like RSA and ECC, which rely on meaningful mathematical challenges, are under great threat from quantum computing, threatening sensitive medical data confidentiality and integrity. This paper proposes a quantum-resistant healthcare security framework based on lattice-based cryptographic primitives such as Learning With Errors (LWE), Ring-LWE (RLWE), and Short Integer Solution (SIS). To this end, we design a five-phase IoMT-friendly framework—Initialization, Registration, Authentication, Data Exchange, and Treatment—where each phase is backed up by lightweight cryptography primitives that can be easily implemented on the low-resource IoMT devices. Relative to the state-of-the-art lattice- and hash-based constructions, our framework involves 50-75% smaller ciphertext sizes, up to a 50% reduction of the communication overhead, and nearly 60% less in computational cost. Furthermore, the solution relies on zero-knowledge proofs, homomorphic encryption as well and attribute-based access control to guarantee strong security and privacy. Using the AVISPA tool, the framework is formally verified, showing its resistance against classical and quantum adversaries. Focusing on tangible healthcare threats, including data tampering and unlicensed access to patient diagnostics, this research paves the way for scalable, efficient, and quantum-resistant medical data protection. Our results pave the way for future investigations into secure post-quantum healthcare and IoT applications.

Open access
User Authentication and Security Systems
Advanced Authentication Protocols Security
Cryptography and Data Security
Original source
Jul 22, 2025·arXiv (Cornell University)
0 cites
From Contracts to Code: Automating Smart Contract Generation with Multi-Level Finite State Machines

Lambard Maxence, Cyrille Bertelle, D apos Amours Claude

In an increasingly complex contractual landscape, the demand for transparency, security, and efficiency has intensified. Blockchain technology, with its decentralized and immutable nature, addresses these challenges by reducing intermediary costs, minimizing fraud risks, and enhancing system compatibility. Smart contracts, initially conceptualized by Nick Szabo and later implemented on the Ethereum blockchain, automate and secure contractual clauses, offering a robust solution for various industries. However, their complexity and the requirement for advanced programming skills present significant barriers to widespread adoption. This study introduces a multi-level finite state machine model designed to represent and track the execution of smart contracts. Our model aims to simplify smart contract development by providing a formalized framework that abstracts underlying technical complexities, making it accessible to professionals without deep technical expertise. The hierarchical structure of the multi-level finite state machine enhances contract modularity and traceability, facilitating detailed representation and evaluation of functional properties. The paper explores the potential of this multi-level approach, reviewing existing methodologies and tools, and detailing the smart contract generation process with an emphasis on reusable components and modularity. We also conduct a security analysis to evaluate potential vulnerabilities in our model, ensuring the robustness and reliability of the generated smart contracts.

Open access
2 source records
cs.CR
Blockchain Technology Applications and Security
Cryptography and Data Security
Original source
Jul 4, 2025·2025 International Conference on Engineering Innovations and Technologies (ICoEIT)
0 cites
Secure and Adaptive Mutual Authentication for Smart Homes Using Blockchain and Machine Learning

Shiva Soni, Abhilasha Singh

Internet of Thing is a promising technology for creating smart home systems. Devices are being added gradually in the smart home's environments, causes the significant challenges into security, scalability, compatibility, Interoperability, etc. Traditional centralized authentication methods are not able to keep the dynamic and diverse nature of these smart environment. To address these challenges, we proposed an adaptive mutual authentication scheme with Zero Knowledge Proof and machine learning integrated within blockchain based key management and storage system. The proposed approach used Elliptic Curve Cryptography technique for key generation, a consortium blockchain for storing keys and device metadata, and a hybrid encryption scheme adaptively choosing between AES-GCM and ChaCha20-Poly1305 based on IoT device capabilities. Machine learning model is integrated to predicts the optimal cryptographic parameters, and also to ensure both security and resource efficiency. The proposed mutual authentication scheme provides a secure and scalable model for smart home systems.

Advanced Authentication Protocols Security
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Original source
Jul 1, 2025·International Journal of Advances in Soft Computing and its Applications
3 cites
Enhancing VANET Security with Lattice-Based Cryptography and Dynamic Pseudonym Updates

Adi El‐Dalahmeh

Ensuring secure and efficient authentication in Vehicular Ad Hoc Networks (VANETs) is vital for real-time communication and network resilience. However, traditional authentication mechanisms, such as Elliptic Curve Cryptography (ECC) and Public Key Infrastructure (PKI), face significant challenges, including high computational overhead, complex certificate revocation, and vulnerability to quantum attacks. To overcome these limitations, we propose a lattice-based authentication protocol that integrates post-quantum cryptography (PQC), zero-knowledge proofs (ZKPs), and fog computing for secure Vehicle-to-Roadside (V2R) communication. Our protocol offers quantum resistance, decentralized authentication, and dynamic pseudonym updates, enhancing both security and privacy in VANETs. Performance evaluations demonstrate that our approach achieves lower message delay (0.8), reduced packet loss ratio (0.6), minimal communication overhead (0.7), and the fastest authentication delay (0.5) compared to ECC and Physically Unclonable Function (PUF)-based methods. Additionally, formal security analysis confirms that our scheme effectively mitigates impersonation, replay, tracking, and quantum attacks, ensuring a scalable and future-proof authentication mechanism for next-generation VANETs.

Open access
Vehicular Ad Hoc Networks (VANETs)
Advanced Authentication Protocols Security
Network Security and Intrusion Detection
Original source
Jun 24, 2025·IEEE Transactions on Mobile Computing
11 cites
Blockchain-Assisted Lightweight Cross-Domain Authentication for Multi-UAV Wireless Networks

Mingyue Xie, Zheng Chang, Li Wang, Geyong Min

The evolution of future network and control technologies has enabled unmanned aerial vehicles (UAVs) to collaborate across diverse geographical areas and task domains, enhancing task execution efficiency through data and resource sharing. In response to the increasing demand for cross-domain task allocation and operations for UAVs, establishing robust authentication mechanisms within trusted domains has become a critical foundation for ensuring secure cross-domain access. Despite significant progress in UAV identity authentication and cross-domain access, challenges persist, such as cumbersome and inefficient processes, UAV resource limitations, and establishing trust relationships across different domains. To address these challenges, this paper introduces a dual blockchain-assisted trusted authentication scheme for UAVs' cross-domain access. Our approach utilizes a certificateless signcryption algorithm for lightweight UAV authentication, thereby eliminating the need for certificate management. Then, an efficient credit-based trust model is designed to measure the trustworthiness of data-in-transit and cross-domain entities. Furthermore, blockchain technology is introduced to store the relevant information of UAVs and credibility to assist cross-domain authentication. Theoretical security analysis and extensive simulations have been conducted, demonstrating the effectiveness and efficiency of our proposed scheme.

UAV Applications and Optimization
Security in Wireless Sensor Networks
Advanced Authentication Protocols Security
Original source
Jun 17, 2025·PLoS ONE
0 cites
A ZKP-based anonymous biometric authentication scheme for the E-health systems

Xuechun Mao, Xiaqing Zhou, Xiaoming Zhao, Ying Chen

The widespread adoption of e-health systems raises critical concerns regarding data privacy and network security. Ensuring secure and reliable data sharing between patients and healthcare professionals remains a significant challenge. To address this, we propose a novel anonymous authentication scheme tailored for e-health environments, integrating zero-knowledge proof (ZKP) with multimodal biometrics. Our key contributions are as follows: (1) applying the Pedersen vector commitment algorithm to construct a biometric-based ZKP scheme, thereby ensuring enhanced security and privacy-preserving authentication; (2) utilizing multimodal cancelable biometrics generate (MCBG) technology, integrating fingerprint, face, and iris modalities to strengthen the security of the verification process; and (3) providing a detailed security analysis that demonstrates our scheme meets essential security requirements, including anonymity, authenticity, unlinkability, forward security, and resistance to replay attacks. Experimental results demonstrate stable proving and verification time of approximately 78 ms and 140 ms, respectively, regardless of the proof range, validating its efficiency and practicality for secure authentication in e-health systems.

Open access
Biometric Identification and Security
User Authentication and Security Systems
Advanced Authentication Protocols Security
Original source
Jun 16, 2025·2025 IEEE 38th Computer Security Foundations Symposium (CSF)
3 cites
One For All: Formally Verifying Protocols which use Aggregate Signatures

Xenia Hofmeier, Andrea Raguso, Ralf Sasse, Dennis Jackson · 5 authors

Aggregate signatures are digital signatures that compress multiple signatures from different parties into a single signature, thereby reducing storage and bandwidth requirements. BLS aggregate signatures are a popular kind of aggregate signature, deployed by Ethereum, Dfinity, and Cloudflare amongst others, currently undergoing standardization at the IETF. However, BLS aggregate signatures are difficult to use correctly, with nuanced requirements that must be carefully handled by protocol developers. In this work, we design the first models of aggregate signatures that enable formal verification tools, such as Tamarin and ProVerif, to be applied to protocols using these signatures. We introduce general models that are based on the cryptographic security definition of generic aggregate signatures, allowing the attacker to exploit protocols where the security requirements are not satisfied. We also introduce a second family of models formalizing BLS aggregate signatures in particular. We demonstrate our approach's practical relevance by modelling and analyzing in Tamarin a device attestation protocol called SANA. Despite SANA's claimed correctness proof, with Tamarin we uncover undocumented assumptions that, when omitted, lead to attacks.

Cryptography and Data Security
Advanced Authentication Protocols Security
User Authentication and Security Systems
Original source
Jun 14, 2025·International Journal of Computer Applications Technology and Research
0 cites
Integrating Zero Trust Architectures and Blockchain Protocols for Securing Cross-Border Transactions and Digital Financial Identity Systems

Authors unavailable

As global financial ecosystems become increasingly digitized, the need for secure, resilient, and interoperable frameworks to protect cross-border transactions and digital financial identities has grown exponentially.Traditional perimeter-based security models have proven insufficient in addressing the sophisticated cyber threats targeting financial networks, especially in decentralized and multi-jurisdictional environments.This has spurred the adoption of Zero Trust Architectures (ZTA)-a paradigm that assumes no implicit trust across networks, devices, or users-and mandates continuous verification at every interaction point.While ZTA enhances access control and minimizes attack surfaces, it faces implementation challenges in distributed financial infrastructures due to trust management, data integrity, and auditability concerns.Simultaneously, blockchain protocols-with their decentralized consensus, immutability, and cryptographic assurance-have emerged as powerful enablers of secure, transparent, and tamperresistant financial systems.This article explores the convergence of ZTA and blockchain technologies as a transformative strategy for enhancing the confidentiality, integrity, and availability of cross-border payment systems and digital identity frameworks.It examines how smart contracts, decentralized identifiers (DIDs), and distributed ledgers can reinforce ZTA principles such as least-privilege access, continuous authentication, and micro-segmentation in a decentralized context.Drawing on real-world use cases and regulatory insights, the study proposes a layered security model integrating ZTA with permissioned blockchain infrastructures, highlighting architectural synergies, potential threats, and scalability considerations.It also addresses the interoperability challenges and governance frameworks necessary for adoption in multi-stakeholder financial environments.By bridging trustless identity verification with cryptographic consensus, this integrated approach offers a future-ready blueprint for securing global digital finance in the era of open banking, fintech innovation, and evolving cyber threats.

Open access
Blockchain Technology Applications and Security
Cryptography and Data Security
Advanced Authentication Protocols Security
Original source
Jun 12, 2025·Electronics
1 cites
STALE: A Scalable and Secure Trans-Border Authentication Scheme Leveraging Email and ECDH Key Exchange

Jiexin Zheng, Mudi Xu, Jianqing Li, Benfeng Chen · 11 authors

In trans-border data (data transferred or accessed across national jurisdictions) exchange scenarios, identity authentication mechanisms serve as critical components for ensuring data security and privacy protection, with their effectiveness directly impacting the compliance and reliability of transnational operations. However, existing identity authentication systems face multiple challenges in trans-border contexts. Firstly, the transnational transfer of identity data struggles to meet the varying data-compliance requirements across different jurisdictions. Secondly, centralized authentication architectures exhibit vulnerabilities in trust chains, where single points of failure may lead to systemic risks. Thirdly, the inefficiency of certificate verification in traditional Public Key Infrastructure (PKI) systems fails to meet the real-time response demands of globalized business operations. These limitations severely constrain real-time identity verification in international business scenarios. To address these issues, this study proposes a trans-border distributed certificate-free identity authentication framework (STALE). The methodology adopts three key innovations. Firstly, it utilizes email addresses as unique user identifiers combined with a Certificateless Public Key Cryptography (CL-PKC) system for key distribution, eliminating both single-point dependency on traditional Certificate Authorities (CAs) and the key escrow issues inherent in Identity-Based Cryptography (IBC). Secondly, an enhanced Elliptic Curve Diffie–Hellman (ECDH) key-exchange protocol is introduced, employing forward-secure session key negotiation to significantly improve communication security in trans-border network environments. Finally, a distributed identity ledger is implemented, using the FISCO BCOS blockchain, enabling decentralized storage and verification of identity information while ensuring data immutability, full traceability, and General Data Protection Regulation (GDPR) compliance. Our experimental results demonstrate that the proposed method exhibits significant advantages in authentication efficiency, communication overhead, and computational cost compared to existing solutions.

Open access
Cryptography and Data Security
Advanced Authentication Protocols Security
IPv6, Mobility, Handover, Networks, Security
Original source
Jun 11, 2025·IEEE Transactions on Dependable and Secure Computing
16 cites
Epass: Efficient and Privacy-Preserving Asynchronous Payment on Blockchain

Weijie Wang, Jinwen Liang, Chuan Zhang, Ximeng Liu · 6 authors

Buy Now Pay Later (BNPL) is a rapidly proliferating e-commerce model, offering consumers to get the product immediately and defer payments. Meanwhile, emerging blockchain technologies endow BNPL platforms with digital currency transactions, allowing BNPL platforms to integrate with digital wallets. However, the transparency of transactions causes critical privacy concerns because malicious participants may derive consumers' financial statuses from on-chain asynchronous payments. Furthermore, the newly created transactions for deferred payments introduce additional time overheads, which weaken the scalability of BNPL services. To address these issues, we propose an efficient and privacy-preserving blockchain-based asynchronous payment scheme (Epass), which has promising scalability while protecting the privacy of on-chain consumer transactions. Specifically, Epass leverages locally verifiable signatures to guarantee the privacy of consumer transactions against malicious acts. Then, a privacy-preserving asynchronous payment scheme can be further constructed by leveraging time-release encryption to control trapdoors of redactable blockchain, reducing time overheads by modifying transactions for deferred payment. We give formal definitions and security models, generic structures, and formal proofs for Epass. Extensive comparisons and experimental analysis show that \textsf{Epass} achieves KB-level communication costs, and reduces time overhead by more than four times in comparisons with locally verifiable signatures and Go-Ethereum private test networks.

Open access
2 source records
cs.CR
Blockchain Technology Applications and Security
Cryptography and Data Security
Original source
Jun 11, 2025·HAL (Le Centre pour la Communication Scientifique Directe)
0 cites
Conception de protocoles de sécurité et analyse symbolique : protocoles hybrides, Modèles d'adversaires dérivés et Théories équationnelles affinées

Mahmoud, Dhekra

The security proof of a protocol, though formally rigorous within a given model, is entirely contingent on the model's assumptions. If the adversary's capabilities are underspecified, the cryptographic primitives are idealized, or the security properties are incompletely formalized, the proof may not hold in practice.The first contribution advances prior work on refining symbolic models for crypto- graphic primitives to better capture their behaviors. Specifically, we propose more precise equational theories for the ElGamal cryptosystem, DSA signatures, and Zero-Knowledge Proofs. Standard symbolic modeling of these primitives disregards their algebraic prop- erties, which may lead to missed attacks in larger protocols. Additionally, we introduce a formal model of exponentiation and re-encryption Mix-Networks. By combining these models with our equational theories, we can automatically find attacks based on the incorrect use of the Mix-Networks missed by previous symbolic models.The second contribution involves analyzing the WireGuard protocol. We examine the protocol's claimed security properties under an adversary capable of compromising any possible key combinations. To systematize this analysis, we introduce the concepts of minimal defensive model and minimal offensive adversary model. The defensive models ensures that violating a security property requires possessing specific atomic capabilities. Minimal offensive models define the smallest sets of adversarial capabilities that break security. Theses derivations helped to identify an implementation optimization that introduces new attack vectors.The third contribution presents a hybrid protocol combining WireGuard and Post- Quantum WireGuard, aligning with recommendations for a secure transition to post- quantum cryptography. Although a symbolic analysis of PQ-WireGuard existed, we uncover discrepancies between the model and the protocol's specifications, including pre- viously missed Unknown Key-Share attacks. We propose fixes and ensure the hybrid protocol's security relies on both the corrected post-quantum and classical WireGuard protocols. We formally defined a hybrid protocol's security as when there exists both minimal defensive models dependent on post-quantum keys and defensive models depen- dent on classical keys. Our work underscores the importance of iterative analysis during design, as achieving hybrid security required repeated refinement between modeling and verification.

Open access
Advanced Authentication Protocols Security
Cryptography and Data Security
Cryptographic Implementations and Security
Original source