Emanuela Podda, Pol Hölzmer, Alexandre Amard, Johannes Sedlmeir · 5 authors
Zero-knowledge proofs allow the implementation of the data minimisation principle imposed by the GDPR in digital identity wallets and the related personal data transactions, therefore representing a reasonable option to be enforced by lawmakers.
This chapter explores blockchain's potential to address cloud computing security challenges. Despite cloud computing's scalability and cost efficiency, it faces risks like data breaches and regulatory non-compliance, as seen in the 2019 Capital One AWS breach. Blockchain's decentralized ledger, cryptographic hashing, smart contracts, and consensus mechanisms (e.g., PoW, PoS) enhance security through decentralized access control, secure storage, and intrusion detection. Privacy techniques like homomorphic encryption and zero-knowledge proofs protect data. Case studies, including IBM Food Trust and MedRec, show practical applications. However, scalability, interoperability, regulatory conflicts (e.g., GDPR), and high costs pose barriers. Solutions like sharding and layer-2 protocols aim to overcome these. Future research focuses on scalability, privacy, hybrid cloud integration, and AI-driven security. Blockchain strengthens cloud security but requires innovation to achieve widespread adoption.
Rudraksh Joshi, Amrit K. Goel, Prashant Singh, Jitendra Goyal
Blockchain is a distributed ledger technology designed to ensure transparent and tamper-proof transaction recording without centralized control. Despite its benefits, this transparency can compromise the confidentiality of the data. This paper investigates eight privacy-preserving methods such as encryption, steganography, off-chain hashing, and zero-knowledge proofs. Each technique is explored through working implementations and real-world constraints, including gas cost and legal compliance. A hybrid architecture is proposed that blends on-chain verification with IPFS-based off-chain storage, enabling developers to build scalable and privacy-conscious decentralized applications.
Blockchain provides the opportunity for organizations to execute trustable collaborations through smart contract automations. However, linkability problems exist in blockchain-based collaboration platforms due to privacy leakages, which, when exploited, will result in tracing transaction patterns to users and exposing collaborating organizations and parties. Some privacy-preserving mechanisms have been adopted to reduce linkability problems through the integration of access control systems to smart contracts, off-chain data storage, usage of permissioned blockchain, etc. Still, linkability problems persist in applications deployed in both private and public blockchain networks. Zero-knowledge proof (ZKP) systems provide mechanisms for verifying the correctness of transactions and actions executed on the blockchain without revealing complete information about the transaction. Hence, ZKP systems provide a potential solution to eliminating linkability problems in blockchain-based collaboration systems. The objective of this paper is to identify various linkability problems that exist in blockchain-enabled collaboration systems and understand how ZKP algorithms and smart contract frameworks can be used in addressing the linkability problems. Furthermore, a proof of concept (PoC) is implemented and simulated to demonstrate a ZKP system for a privacy-preserving feedback mechanism that mitigates linkability problems in collaboration systems. The scenario-based results from the PoC evaluation show that a feedback system that includes project participants’ verification through membership proofs, verification of on-time submission of feedback through range proofs, and encrypted calculation of feedback scores through homomorphic arithmetic provides a privacy-aware system for executing collaborations on the blockchain without linking project participants.
Tao Wang, Keyong Hong, Bo Yang, Qiliang Yang · 6 authors
The rapid growth in the NFT (Non-fungible token) market has offered a wide variety of opportunities for scammers, fraudsters, wash tradings, and so on. One of the most urgent security issues is how to efficiently authorize and validate the ownership to make the NFT ecosystem avoid infringement and counterfeiting. By exploiting linear homomorphic tagging and robust digital watermarking technologies, this article proposes a generic framework for ownership authorization and batch validation of NFTs. Within this framework, the digital artwork creators can authorize the ownership to a buyer before the NFT is minted in the public blockchain. Anytime in the future who questions the ownership of a claimant can initiate a validation procedure to get an auditing report by running a Challenge-Response protocol that supports efficient batch verification. The completeness and soundness of the proposed framework have been proven by assuming a secure homomorphic tag scheme and a robust watermarking scheme. We also present instantiations of the generic construction, especially with$\Pi _{Pub}$, one can outsource the validation procedure to the public blockchain to release local computation burden. A series of elaborated experiments have shown our proposed framework is practical and efficient.
The increasing adoption of Decentralized Applications (DApps) and Web3 infrastructures has exposed critical security challenges, including malicious smart contracts, fraudulent transactions, and decentralized governance exploits. Traditional threat intelligence systems rely on centralized security models, which create single points of failure, reduce data sovereignty, and limit real-time risk mitigation. To address these challenges, we introduce a Decentralized Federated Risk Analysis (DFRA) system, leveraging federated risk aggregation, decentralized storage, and automated security intelligence retrieval to enhance cybersecurity in DApps. Our DFRA system operates through three primary components: (1) Federated Risk Aggregation, where a federated model retrieves and consolidates risk scores, flagged threats, and security insights across decentralized sources; (2) MinIOBased Decentralized Storage, which stores security intelligence in an object storage system to allow distributed retrieval; and (3) Automated Security Intelligence Retrieval, a server-based process that periodically fetches and processes security data in real-time.
Sohel Rana, Rizal Mohd Nor, Mohammad Enayet Hossain, Md Amiruzzaman
The increasing adoption of cryptocurrency has underscored the critical need for robust security measures to protect digital assets stored in cryptocurrency wallets. Traditional security approaches have often proven inadequate in addressing the rapidly evolving threats in the digital landscape. In response, cloud-based security solutions have emerged as a promising method to enhance wallet protection, leveraging scalability, flexibility, and advanced security features. This study investigates the security challenges faced by cryptocurrency wallets and explores the potential of cloud-based solutions, focusing on multi-factor authentication, encryption protocols, real-time monitoring, and secure backup and recovery. The research assesses the effectiveness of these solutions in mitigating risks such as unauthorized access, data breaches, and digital asset theft. Findings reveal that cloud-based security solutions significantly improve protection by offering scalable, adaptable frameworks. However, challenges remain, including privacy concerns, regulatory compliance, and the cost of implementation. The research introduces a cost-efficient approach that integrates cloud-based technologies to optimize the total cost of ownership while maintaining robust security. This study also discusses the regulatory and privacy implications of cloud security in cryptocurrency ecosystems. In conclusion, this research provides novel insights into the integration of cloud-based security solutions, offering a comprehensive framework for safeguarding digital assets in cryptocurrency wallets. It contributes to the growing body of knowledge on the feasibility and impact of cloud technologies in enhancing the security of cryptocurrency systems.
Yao Ma, Wen Yu Kon, J. O. Chu, Kevin Han Yong Loh · 6 authors
Identity verification is the process of confirming an individual's claimed identity, which is essential in sectors like finance, healthcare, and online services to ensure security and prevent fraud. However, current password/PIN-based identity solutions are susceptible to phishing or skimming attacks, where malicious intermediaries attempt to steal credentials using fake identification portals. Alikhani et al. [Nature, 2021] began exploring identity verification through graph coloring-based relativistic zero-knowledge proofs (RZKPs), a key cryptographic primitive that enables a prover to demonstrate knowledge of secret credentials to a verifier without disclosing any information about the secret. Our work advances this field and addresses unresolved issues: From an engineering perspective, we relax further the relativistic constraints from 60m to 30m, and significantly enhance the stability and scalability of the experimental demonstration of the 2-prover graph coloring-based RZKP protocol for near-term use cases. At the same time, for long-term security against entangled malicious provers, we propose a modified protocol with comparable computation and communication costs, we establish an upper bound on the soundness parameter for this modified protocol. On the other hand, we extend the two-prover, two-verifier setup to a three-prover configuration, demonstrating the security of such relativistic protocols against entangled malicious provers.
Maintaining integrity and traceability throughout the pharmaceutical cold chain logistics is critical to preserving the efficacy of temperature-sensitive products. Traditional tracking systems lack transparency and accurate monitoring, increasing risks of counterfeiting and adulteration that harm patient health. This paper proposes a blockchain-based cold storage management system that uses smart contracts and IoT sensors to securely monitor real-time temperature and quality parameters for pharmaceutical products. Optimized smart contracts automate processes and enforce predefined conditions, ensuring accountability and reducing transaction cost. Our approach leverages IPFS decentralized storage for transaction data, generating unique SHA-256 cryptographic hashes stored on the blockchain to optimize security and reduce gas costs. Transactions are validated through proof-of-stake consensus. The system provides a secure and transparent solution for pharmaceutical cold storage management while enhancing patient safety and contributing significantly to the medical sector.
The cryptographic protocol developments are transforming digital trust is the capacity to verify without revealing any underlying information. Traditional authentication and authorization systems are usually prone to leakage of sensitive data, resulting in compromise of privacy and low scalability in distributed systems. The root of these problems is eliminated through the so-called zero-knowledge techniques that allow demonstrating to one party ownership of some information without exposing it. This paper explores the origin and development of zero-knowledge protocols in light of its efficiency, trustless design, and privacy focus to illustrate why the application is worth the hype. Particular attention is paid to such structures as zk-SNARKs, zk-STARKs, and bulletproofs, as well as their application to constructing transparent, scalable systems. Blockchain aptitudes used anywhere in confidentiality of transactions, decentralized identity systems allow a self-sovereign identity without exaggerating personal information, and the healthcare and finance industries enjoy the ability to share information securely without any effect on compliance aspects. The next discussion points are implementations, the scalability issue, cryptographic assumptions, and integration issues. This survey outlines evaluations of deployments from 2021 to 2025 to determine the following top benefits, barriers, and trends in building systems that safeguard privacy without compromising their performance or trust to the client. Future requirement conclusions provide some insights about future requirements in terms of efficient construction of proofs, standardizations, and ease of usability to expand the adoption of infrastructures built on zero-knowledge into a constantly more integrated digital world.
Detecting similar data is crucial for optimizing file storage and transmission in HTTP protocols and Content Delivery Networks. Traditional MinHash methods encounter significant efficiency challenges due to their reliance on K-shingle structures, resulting in high computational costs and storage requirements. Additionally, these methods expose privacy risks in cloud environments, where sensitive information can be inferred from MinHash signatures. To address both efficiency and security concerns, we propose Horse-MinHash, which integrates a fast, content-defined feature extraction scheme with a non-interactive zero-knowledge proof-based similarity estimation method. Our approach significantly enhances computational efficiency while ensuring robust privacy protection by preventing plaintext exposure. Experimental results demonstrate that Horse-MinHash achieves lower mean squared error in Jaccard similarity estimation and reduces time overhead for average block sizes of 16 KB or more, outperforming state-of-the-art methods.
Essential infrastructure and services depend on critical systems. To ensure that critical systems function properly, regular testing and monitoring are necessary. Establishing direct, dedicated data connections for remote testing can be expensive, while using public cellular, satellite, or fiber Internet connections can introduce privacy and security risks. Securing the medium often requires placing trust in third parties. The novel proposal introduced in this work suggests using zero-knowledge proofs, a modern cryptographic technique, to conduct secure remote testing and monitoring of critical systems over affordable public networks, which can include email or instant messaging apps. This approach guarantees both the integrity and confidentiality of the transmitted data, as well as the integrity of the processes involved in preparing the data for transmission. We will present this approach and demonstrate its implementation through a real-world use case: the remote testing of an electronic railway interlocking system.
The globalization of digital infrastructures necessitates secure cross-border data transfers, yet existing governance frameworks struggle to reconcile regulatory transparency requirements with enterprise needs for confidentiality. Traditional approaches based on trusted execution environments or blockchain technologies face critical limitations, including prohibitive operational costs and technical inflexibility across cryptographic standards. This paper introduces a novel cryptographic framework that systematically addresses these challenges through three core innovations. First, we establish a lifecycle model integrating transmission, attestation, and verification phases with deterministic cryptographic constraints, ensuring continuous integrity monitoring across distributed systems. Second, our architecture implements non-intrusive compliance validation through zero-knowledge proofs and privacy-preserving verification protocols, eliminating raw data exposure while meeting diverse regulatory mandates. Third, the framework achieves interoperability across conflicting digital certification standards through adaptive policy mappings. Experimental evaluations demonstrate the solution's superiority over conventional approaches, showing significant improvements in verification efficiency, reduced resource consumption, and robust defense against tampering attacks. The proposed model supports multi-jurisdictional legal requirements through auditable cryptographic proofs and timestamped evidence chains, offering enterprises a practical pathway for compliant cross-border operations. By embedding regulatory logic into technical workflows, our approach advances secure global data ecosystems that balance sovereignty preservation with digital economy demands.
This study proposes a secure authentication framework based on Non-Fungible Tokens (NFTs) for enterprise microservices in big data environments.The objective was to overcome the limitations of traditional mechanisms such as JSON Web Tokens (JWTs), which lack built-in traceability, revocation, and protection against session-based attacks.Developed as a conceptual system design project, the framework was simulated using a custom private blockchain built in Go (Golang).NFTs were minted and transferred through smart contracts to act as temporary, verifiable access tokens.A custom hardware wallet, built on the ESP32-S3 microcontroller and programmed using the Arduino framework, was used to establish a physical barrier between the user and the system.This approach ensured that token ownership remained tamper-resistant and device-bound, ensuring that it remained secure.No human subjects were involved in this study; instead, the system was evaluated through functional test scenarios to assess authentication flow, session control, and token lifecycle management.Tools such as Docker and Redis were used to support simulation and deployment.Results indicated that the NFT-based system demonstrated improved resistance to token hijacking, session fixation, and replay attacks compared to JWT-based alternatives.Unlike conventional systems, it does not rely on static credentials and allows token revocation via on-chain burning and session-bound control.The study recommends future validation in real-world enterprise settings to assess scalability, fault tolerance, and real-time integration.The proposed framework offers a pathway toward decentralised, privacy-preserving authentication solutions suitable for secure and distributed environments.
Aufa Nasywa Rahman, Bimo Sunarfri Hantono, Guntur Dharma Putra
Open banking framework enables third party providers to access financial data across banking institutions, leading to unprecedented innovations in the financial sector. However, some open banking standards remain susceptible to severe technological risks, including unverified data sources, inconsistent data integrity, and lack of immutability. In this paper, we propose a layered architecture that provides assurance in data trustworthiness with three distinct levels of trust, covering source validation, data-level authentication, and tamper-proof storage. The first layer guarantees the source legitimacy using decentralized identity and verifiable presentation, while the second layer verifies data authenticity and consistency using cryptographic signing. Lastly, the third layer guarantees data immutability through the Tangle, a directed acyclic graph distributed ledger. We implemented a proof-of-concept implementation of our solution to evaluate its performance, where the results demonstrate that the system scales linearly with a stable throughput, exhibits a 100% validation rate, and utilizes under 35% of CPU and 350 MiB memory. Compared to a real-world open banking implementation, our solution offers significantly reduced latency and stronger data integrity assurance. Overall, our solution offers a practical and efficient system for secure data sharing in financial ecosystems while maintaining regulatory compliance.
Gulshan Kumar, Rahul Saha, Mauro Conti, Tai-hoon Kim
De-anonymization attacks in blockchains are significant concerns as they compromise the privacy of users on a public ledger. Such attacks, in the form of network analysis and transaction patterns, aim to link a blockchain address to the identity of its owner, potentially revealing sensitive information. Though researchers introduce various solutions using Tor, VPN, and i2P to protect against de-anonymization in blockchains, they have certain limitations: i) non-verification of the private transactions, ii) reveal of the transaction graph, and iii) requirement of a trusted setup that is itself vulnerable to the adversary. All these lead to the revocation of de-anonymization problems. In this paper, we show a novel privacy assurance framework for blockchains. The proposed framework is called De-Anonymization Withstanding Solution (DAWS). DAWS is the first privacy-preserved blockchain framework against de-anonymization attacks. DAWS uses privacy-classifying smart contract execution and a novel consensus called Proof-of-Privacy (PoPri). A set of experiments is executed on PoPri as well as DAWS. The blockchain transactions are modified by including user-defined privacy labels. DAWS can handle attacker advantage ≥0.008 with a privacy breach probability < 0.01% under our threat model. Besides, an improvement in the throughput of DAWS is noticed as compared to Ethereum (almost 80 times) with the Hyperledger configuration for consensus. The gas consumption improvement is 20%. All the listed features enhance the appeal of the proposed DAWS as a robust privacy-preserving solution against blockchain de-anonymization attacks.
The emergence of blockchain technology has revolutionized decentralized data management by offering robust alternatives to traditional centralized database systems. This paper provides a systematic and comprehensive review of blockchain-based distributed databases, highlighting key architectural transformations, core enabling technologies such as Merkle Trees, PBFT, and Zero-Knowledge Proofs, and comparing them with conventional distributed databases. Real-world implementations including Hyperledger Fabric, BigchainDB, and OrbitDB are analyzed to assess their scalability, interoperability, and security capabilities. The paper also explores intrinsic security mechanisms, performance bottlenecks, and regulatory challenges that affect adoption. Finally, it identifies open research questions and future directions necessary for building scalable, privacy-aware, and interoperable decentralized database ecosystems suitable for enterprise and multi-stakeholder environments. Keywords— Blockchain databases, consensus mechanisms, data integrity, decentralized systems, distributed ledger, Merkle trees, Zero-Knowledge Proofs
LLMs have brought new, amazing abilities for understanding language, generating it and making decisions. Yet, there are serious concerns about data privacy, the ability to scale LLMs and how different components of a cloud-native system interact. The paper outlines a new Federated Data Modelling (FDM) framework specifically for making use of LLMs in secure and efficient distributed cloud settings. The framework achieves decentralized training, prevents data being leaked and meets the requirements of data residency laws by using federated learning and dynamic schema harmonization with container orchestration. Moreover, the proposed FDM technique relies on zero-trust security, confidential computing and Kubernetes-native operations to provide isolation, watching and traceability among the various tenants. On typical benchmark datasets, the approach shown here performs better in terms of privacy, how quickly the model learns and how quickly it may be used in practice compared to centralized training. By using this study, AI service providers can ensure their LLM service is trustworthy and safe for IAP use in healthcare, finance and government.
Juan Cano-Benito, Andrea Cimmino, Sven Hertling, Heiko Paulheim · 5 authors
Data spaces are emerging as decentralised infrastructures that enable sovereign, secure, and trustworthy data exchange among multiple participants. To achieve semantic interoperability within these environments, the use of semantic web technologies and knowledge graphs has been proposed. Although distributed ledger technologies (DLT) fit as the underlying infrastructure for data spaces, there remains a significant gap in terms of the efficient storage of semantic data on these platforms. This paper presents a systematic evaluation of semantic data storage across different types of DLT (public, private, and hybrid), using a real-world knowledge graph as an experimental basis. The study compares performance, storage efficiency, resource consumption, and the capabilities to update and query semantic data. The results show that private DLTs are the most efficient for storing and managing semantic content, while hybrid DLTs offer a balanced trade-off between public auditability and operational efficiency. This research leads to a discussion on the selection of the most appropriate DLT infrastructure based on the data sovereignty requirements of decentralised data ecosystems.