Blockchain technology faces increasing security threats from post-quantum vulnerabilities, sophisticated cyberattacks, and fragmented cryptographic implementations. This study proposes a comprehensive multi-layer cryptographic framework that integrates Zero-Knowledge Proofs (ZKPs), Homomorphic Encryption (HE), post-quantum algorithms, threshold cryptography, and Secure Multi-Party Computation (SMPC) across data, network, consensus, and application layers to realize a defense-in-depth model. Grounded in the Confidentiality, Integrity, and Availability (CIA) triad and defense-in-depth ethics, the framework is implemented on Hyperledger Fabric v2.5.4 with modern cryptographic libraries and evaluated over 10â” transactions, where baseline performance (245 ± 12 ms, 1,250 tx/s) versus the full framework (2,150 ± 78 ms, 168 tx/s) quantifies the overhead of enhanced security. The work contributes a multi-tier framework, a quantum-resilient consensus with Verifiable Delay Functions (VDFs) for 51% attack detection, a standardization roadmap for cross-chain cryptographic substantiation, and practical operations in healthcare, finance, and supply chain setups. Results demonstrate strengthened confidentiality, integrity, and authentication via encrypted computation, Byzantine Fault-Tolerant (BFT) consensus, and threshold multi-signatures, with hybrid classicalâPost-Quantum Cryptography (PQC) and mitigation strategies such as off-chain computation and hardware acceleration offsetting computational costs. Unlike fragmented prior efforts, this integrated, governance-elastic blueprint enables quantum-aware, multi-layer security assurance for regulated enterprises without sacrificing decentralization or scalability.
In the context of banking systems increasingly relying on cloud computing platforms, protecting sensitive data while maintaining processing performance is a major challenge. This paper presents and evaluates a cloud banking data processing model that integrates Homomorphic Encryption (HE), Zero-Knowledge Proof (ZKP), and the ORAM protocol to achieve a balance between security and performance. Experiments were conducted on a real Bank Marketing (UCI) dataset with 5000 records, using DSL query operations to calculate the average balance, count high-balance customers, total call duration, and savings deposit acceptance rate. The results show that the combination of HE, ZKP, and ORAM significantly improves security but increases computational cost; however, a suitable configuration can significantly reduce latency while still meeting security requirements. A detailed analysis of the security-performance trade-off provides an important empirical basis for implementing banking data security solutions in the cloud.
We prove that for planted k-SAT instances with k >= 7 at clause density alpha/alpha_s >= 0.21, a positive fraction of variables are frozen directly in the planted model---without requiring transfer from the random model via quiet planting. The expected number of "support clauses" per variable (clauses in which that variable is the unique satisfying literal) exceeds 1 at remarkably low density: alpha/alpha_s ~ 0.20 for k = 7, compared to the random-model freezing threshold at alpha_f/alpha_s ~ 0.90. We prove that the resulting frozen-core structure implies topological disconnection of the solution subgraph across cluster boundaries, with a cycle-robustness argument showing that short cycles in the factor graph cannot quench the supercritical repair cascade. As an immediate corollary, the Hilbert space spanned by satisfying assignments decomposes into orthogonal sectors preserved by any unitary generated by the adjacency matrix---blocking quantum walks, QAOA at all depths, and quantum annealing. We construct a post-quantum commitment scheme whose binding property reduces to the hardness of solving planted k-SAT, provide formal proofs of completeness, soundness, and zero-knowledge, and derive a digital signature scheme with existential unforgeability via the Fiat-Shamir transform. We present a six-vector quantum attack analysis with proved barriers against five algorithmic families. We give concrete parameter recommendations at NIST security levels 1, 3, and 5, and position the scheme within the landscape of SAT-based and CSP-based cryptographic constructions. We prove that the Grover query complexity for breaking the binding property is Omega(2^{fn/2}); empirical cryptanalysis of Glucose and MiniSat CDCL solvers on our exact distribution yields a classical attack cost of 2^{0.234n} operations, enabling concrete parameter selection at NIST security levels 1, 3, and 5. Empirical validation across 100 random seeds at n = 16 confirms complete cluster isolation at every instance tested.
AIGP-ÎŁ (AI Governance Protocol â Sigma) is a post-quantum cryptographic identity and authorization framework designed for autonomous AI agents operating in multi-agent and agentic payment environments. The protocol suite consists of five interconnected specifications: WP-01: Core Protocol â ML-DSA (CRYSTALS-Dilithium) based identity anchoring with STARK zero-knowledge proofs via RISC0, Bitcoin blockchain timestamping, and a cryptographic Kill Switch mechanism for emergency AI halt. WP-02: Kill Switch â Formal specification of the HALT proof system enabling verifiable, tamper-proof shutdown of AI agents without revealing operational state. WP-03: SSL for Agents â A mutual TLS-equivalent handshake protocol adapted for AI agent-to-agent communication, providing forward secrecy and post-quantum resistance. WP-04: Agentic Payments â Authorization layer for autonomous financial transactions executed by AI agents, with cryptographic scope limitation and audit trails. WP-05: Multi-Agent Orchestration â Trust propagation and delegation model for hierarchical multi-agent systems with verifiable credential chains.
Prof. S. P. Palaskar, Swaraj Chikhale, Shantanu Chimote, Rakshit Sinha · 6 authors
Abstractâ Traditional identity systems rely on centralized authorities, which creates single points of failure and privacy risks. We propose IDentix, a decentralized identity framework leveraging blockchain and cryptography to secure user credentials while preserving privacy. In IDentix, each user owns a self-sovereign identity (SSI) represented by a public/private key pair and a Decentralized Identifier (DID) registered on an Ethereum smart contract. Trusted issuers (e.g. governments, banks) provide verifiable credentials (VCs) to users off-chain, and users present cryptographic proofs (such as zero-knowledge proofs) of specific attributes to verifiers. Verifiers authenticate credentials by checking issuer signatures against public keys on the blockchain and querying an immutable credential registry. Our prototype on the Ethereum Sepolia testnet demonstrates that this design yields tamper-evident identity proofs without exposing personal data. As shown in prior work [1], blockchain-based SSI greatly reduces risks of identity theft while giving users full control over their data. Keywordsâ Blockchain; decentralized identity; self-sovereign identity; verifiable credentials; decentralized identifiers; identity verification; Ethereum; zero-knowledge proof.
This study presents ZK-EHR, a decentralized access control framework designed to enable secure and privacy-preserving sharing of encrypted electronic health records across institutional boundaries. Unlike existing blockchain-based EHR access control systems that expose user identities on-chain or lack cryptographic privacy guarantees, ZK-EHR decouples authorization from identity disclosure by integrating zk-SNARK-based proofs with blockchain smart contracts to verify policy compliance without revealing user roles, affiliations, or credentials. The framework employs three differentiated actor rolesâPatient (Data Owner), Doctor (Care Provider), and Researcher (Authorized Analyst)âwith distinct policy-driven access workflows, a custom Groth16 zero-knowledge circuit for role-based constraint enforcement, and a modular architecture combining on-chain verification with off-chain encrypted storage via IPFS. Concrete design proposals for access revocation and replay attack prevention are introduced to address operational security requirements. The system was evaluated under multiple operational and adversarial scenarios. Experimental results indicate consistent on-chain verification latency (approximately 390 ms), reliable rejection of tampered submissions, and per-verification gas consumption of 216,631 gas. A comparative analysis against representative baseline systems demonstrates that ZK-EHR uniquely combines identity anonymity, on-chain cryptographic policy enforcement, and auditable encrypted record retrieval. These findings establish the feasibility of zk-SNARK-based access control for decentralized, verifiable, and privacy-aware EHR management.
Margherita Cozzolino, Stephan Krenn, Thomas LorĂŒnser
While QKD ensures information-theoretic security at the link level, real-world deployments depend on trusted repeaters, creating potential vulnerabilities. In this paper, we thus introduce a topology-hiding connectivity assurance protocol to enhance trust in quantum key distribution (QKD) network infrastructures. Our protocol allows network providers to jointly prove the existence of a secure connection between endpoints without revealing internal topology details. By extending graph-signature techniques to support multi-graphs and hidden endpoints, we enable zero-knowledge proofs of connectivity that ensure both soundness and topology hiding. We further discuss how our approach can certify, e.g., multiple disjoint paths, supporting multi-path QKD scenarios. This work bridges cryptographic assurance methods with the operational requirements of QKD networks, promoting verifiable and privacy-preserving inter-network connectivity.
This paper describes a zero-knowledge proof system that enables verification of password policy compliance within an asymmetric password-authenticated key exchange (aPAKE) protocol specifically OPAQUE (RFC 9807) without revealing the password to the server. The system is built on a composable sub-circuit architecture: independent verification gadgets are combined into a single zero-knowledge proof, each gadget accepting portions of the private witness and producing public instance values, enabling the server to verify multiple password properties in one proof verification. Four gadgets are disclosed: (1) a Policy Engine for character class verification via lookup tables, (2) a History Nullifier for password inequality proof via squared-difference accumulation, (3) an OPAQUE Binder for cryptographic binding to the aPAKE registration element via hash-to-curve and elliptic curve scalar multiplication, and (4) a Breach Detector for offline breached-password detection via Bloom filter non-membership proof using algebraic hashing. The composable architecture permits addition of further gadgets without modifying existing ones, each extending the public instance vector.
Laila Khalid, Muhammad Usman Akhtar, Muhammad Khalid, Iftikhar Ahmed
The evolving technology in AI and distributed systems requires ethical concepts of how sensitive data can be verified without breach of privacy. Conventional AI systems present the following critical concerns: exposure of data, breach of privacy, and ethical issues concerning transparent but confidential computation. This chapter is a full-fledged cryptographic proof, Zero-Knowledge Proofs (ZKPs), which makes it possible to deploy AI ethically by verifying privacy. The framework is supported by mathematical underpinnings to enable model validation and training verification, as well as federated learning without the underlying datasets or parameters of the models. The chapter shows that ZKPs can be used to meet ethical AI without compromising privacy. It can be used in healthcare, finance, and voting systems where ethical concerns require verification and confidentiality. This chapter offers a new method of dealing with core ethical dilemmas in AI systems and safeguarding privacy and security in algorithmic decision-making exercises.
Threshold transactions in Bitcoin is an effective solution for vulnerability of wallets to the loss or compromise of secret keys. It also enhances the applicability of Bitcoin to include use-cases that require partitioning the trust among a set of parties. Currently, the threshold transactions on Bitcoin expose the actual signers within the group of participants. This poses a threat of wallet hacks or theft targeting these signers. To address this issue of privacy, we propose a novel protocol to create threshold transaction using a combination of on-chain locking and off-chain proof of knowledge. As Bitcoin currently does not support verification of zero-knowledge schemes, the proposed protocol uses a Trusted Third Party ( TTP ) to verify the proofs off-chain. The trust on the third party is only limited to its service of signing on behalf of the users. The main contribution is the development and applicability of a m-out-of-N proof of partial knowledge that maintains the privacy of the signers both on-chain from the transaction verifiers and off-chain from the TTP and other signers as well. The protocol leverages Taprootâs spending path flexibility to incorporate dual spending capabilities and employs off-chain zero knowledge ÎŁ-protocols to prove knowledge of private keys without disclosing their associated public keys. Experimental analysis demonstrates improved scalability and privacy than the mainstream threshold signature schemes for Bitcoin. A formal analysis demonstrates and establishes the security goals of the proposed mechanism.
Federated unlearning enables clients to withdraw their contributions from a global model.However, enabling clients to verify whether the server has honestly and effectively removed their contributions remains a critical challenge. To address this aspect, which has been largely overlooked in existing literature, a verification model based on zero-knowledge proofs was constructed, and a comprehensive framework for verifiable federated unlearning was proposed. Combined with a dynamically updated Merkle tree structure, a novel verifiable federated unlearning scheme was presented characterized by its zero-knowledge property. This allows for the efficient generation of cryptographic proofs for server unlearning operations while rigorously protecting the data privacy of other clients. We evaluate the effectiveness and computational overhead of the proposed scheme. Comparative experiments with Rivest-Shamir-Adleman (RSA) accumulator-based and Hash chain-based schemes demonstrate that, when the model parameter size reaches the order of <inline-formula><alternatives><math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="M2"><msup><mrow><mn mathvariant="normal">10</mn></mrow><mrow><mn mathvariant="normal">5</mn></mrow></msup></math><graphic specific-use="big" xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="alternativeImage/B6D6E598-14B1-468e-9A32-73199F9CD69E-M002.jpg"><?fx-imagestate width="4.23333359" height="2.53999996"?></graphic><graphic specific-use="small" xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="alternativeImage/B6D6E598-14B1-468e-9A32-73199F9CD69E-M002c.jpg"><?fx-imagestate width="4.23333359" height="2.53999996"?></graphic></alternatives></inline-formula>, the proposed scheme improves proof generation speed by approximately two orders of magnitude and verification speed by 13.2 times compared to the RSA-based scheme. Furthermore, it effectively avoids the scalability bottleneck of data linear growth in verification overhead inherent in Hash chain-based schemes.
Abstract With the increasing reliance on cloud services, establishing secure and reliable authentication for terminal devices to remotely access and control data has become a critical challenge. Existing solutions often suffer from limitations such as concentrated computational load, privacy infringements, and dependence on centralized architectures that introduce single points of failure (SPOF). To address these issues, this paper proposes DTAP, a blockchain-based dual-terminal collaborative anonymous authentication protocol. DTAP introduces a novel architecture that splits the user terminal into a U-Shield and a smartphone: the U-Shield securely hosts the master key offline, providing a robust security anchor, while the smartphone leverages BBS+ signatures and zero-knowledge proofs to achieve privacy-preserving authentication and Fine-Grained Access Control (FGAC). Furthermore, the protocol employs blockchain technology to eliminate SPOF, with smart contracts ensuring tamper-proof logging and transactional transparency. Security analysis confirms that the protocol meets the required security properties. Performance evaluation shows that DTAP maintains competitive computational and communication efficiency despite its enhanced functionality, and its deployment on the Ethereum testnet demonstrates practical feasibility.
Traditional digital card games rely on centralized servers, introducing catastrophic single points of failure, while decentralized Web3 alternatives fail to achieve real-time viability due to prohibitive block latency. This paper introduces Panoptes, a highly optimized, hybrid Zero-Trust cryptographic engine that enforces microsecond-latency decentralized consensus for the CoronaPoker peer-to-peer network. Assuming a strict Ring-0 adversary model, Panoptes treats the host operating system and the Java Virtual Machine (JVM) as fundamentally compromised. We detail a bifurcated architecture utilizing a hardened native airgap that leverages OS-level stealth allocators to process ciphertexts without leaving plaintext residue in the managed heap. To mitigate OS-level memory scrapers and hardware-based Direct Memory Access (DMA) attacks, Panoptes implements a multiplexed decoy memory topology (The Vault). It is secured by strict virtual page guarding against software introspection, and heavily relies on offline decryption with immediate sub-millisecond zeroization to temporally starve asynchronous hardware-level carving. The protocol entirely replaces traditional commutative encryption with the deterministic Hand Commitment Megapacket, a flat-buffer payload leveraging X25519 KEM, Additive Secret Sharing, and ChaCha20-Poly1305 to ensure Byzantine fault tolerance without majority voting. We present formal implementations of our micro-architectural defenses, including Mixed Boolean-Arithmetic (MBA) for constant-time execution, direct cross-platform syscalls bypassing libc, OS-level DACL lockdowns, PEB cloaking, and asynchronous SipHash-2-4 binary attestation. Furthermore, we introduce a multithreaded Deadman Switch to detect CPU cycle drift via RDTSC. Evaluated under an exhaustive 42-point "Total Siege" adversarial framework, the engine demonstrates unparalleled resilience against hardware breakpoints, kernel introspection, inline hooking, and temporal drift attacks.
Cross-domain data exchange is an important technical approach for realizing the value of data assets. However, lacking a single trusted root CA across domains, cross-domain schemes often encounter difficulties in authentication, controlled data flow, and fine-grained authorization. We propose a cross-domain data sharing scheme that uses decentralized identifiers and threshold proxy re-encryption. This scheme adopts the intra-domain leader node to verify the user identity, and the inter-domain multi-agent nodes collaborate in a threshold manner to handle cross-domain registration requests and re-encryption requests. Through threshold cooperation, the problem of single point of failure is effectively solved. The hash value of cross-domain registration information is stored on the blockchain, leveraging the immutable and traceable characteristics of blockchain to achieve trusted cross-domain data sharing. In addition, we introduce a ciphertext version tag to enable fast updates of re-encryption keys and use zero-knowledge proofs to verify re-encrypted ciphertext correctness. The security analysis indicates that our scheme has IND-CCA2 security under the DBDH assumption and can effectively resist collusion attacks. Performance analysis shows that our scheme is efficient, and can better meet the needs of cross-domain data sharing.
This paper presents a novel hybrid zero-knowledge proof protocol resistant to quantum computer attacks. The protocol combines classical cryptography based on the Learning with Errors problem complexity with quantum state properties. The main objective of the protocol is to enable a prover to convince a verifier of knowledge of a secret parameter alpha without revealing its value, even against adversaries with quantum computational capabilities. A key feature of the protocol is the explicit dependence of quantum operations on the secret parameter through a cryptographic hash function modeled as a quantum random oracle. This ensures an inseparable connection between the quantum and classical phases of protocol execution. The protocol includes a mechanism for regular secret updates between interaction rounds, providing protection against adaptive attacks. Special attention is given to accounting for real physical errors of quantum devices â a difference threshold is introduced that allows for a certain level of noise and decoherence. The paper presents a formal security analysis of the protocol. The properties of honest-verifier zero-knowledge and proof of knowledge against quantum polynomial-time adversaries are proven. Security is justified through constructing a sequence of hybrid games showing that the probability of a successful attack is negligible relative to the security parameter plus the probability of physical implementation error. The protocol is of practical interest for building cryptographic systems in the context of quantum computing development.
Muhammad Ahmed, Adnan Ahmad, Furkh Zeshan, Sheeraz Akram
Blockchain-based systems increasingly require authentication mechanisms that simultaneously preserve user privacy, support accountability, and enable efficient credential revocation. However, most existing anonymous authentication schemes rely on pairing-based cryptography which introduce high computational overhead and limit deploy ability on widely adopted blockchain platforms such as Ethereum. This paper presents BAAR, a Blockchain-based Anonymous and Revocable authentication framework designed entirely within the discrete logarithm setting over the secp256k1 elliptic curve. BAAR integrates Pedersen vector commitments, Schnorr-based zero-knowledge proofs, and a Merkle-tree-based dynamic accumulator to support anonymous and unlinkable authentication with selective attribute disclosure and public, auditable revocation. Authentication and proof verification are performed off-chain, while the blockchain maintains only a compact revocation state, significantly reducing on-chain computation and gas costs. A formal security analysis demonstrates unforgeability, unlinkability, attribute privacy, and revocation soundness under standard cryptographic assumptions in the random oracle model. A prototype implementation on Ethereum confirms that BAAR achieves low gas consumption, logarithmic-time revocation, and scalable performance with respect to both the number of users and attributes. These results indicate that BAAR provides a practical balance between strong privacy guarantees and deploy ability, making it suitable for real-world blockchain-based identity and access-control systems.
The proliferation of Internet of Things (IoT) devices creates unprecedented security, privacy, and transparency challenges in distributed systems. Traditional encryption-based approaches provide privacy but impose significant computational overhead, storage bloat, and key management complexity. This paper presents CIPHER-IoT, a blockchain-based framework that integrates Zero-Knowledge Proofs (ZKPs) with Hyperledger Fabric for privacy-preserving IoT data management. Unlike encryption-based approaches that store encrypted data on-chain, CIPHER-IoT utilises Groth16 zk-SNARKs to generate cryptographic proofs of data validity while storing only commitments on the blockchain, achieving stronger privacy guarantees with lower storage overhead. The framework employs Ed25519 for lightweight digital signatures and implements comprehensive chaincode for ZKP verification, commitment uniqueness checking, and access control enforcement. CIPHER-IoT targets gateway/edge IoT deployments with moderate computational capacity (ARM processors 500 MHz+) rather than ultra-constrained sensors. We evaluate CIPHER-IoT against two baseline systems, SPAS (homomorphic encryption-based) and SPAS-H (AES encryption with Hyperledger Fabric), using realistic simulation with 50â500 devices and transaction rates of 10â75 TPS. Experimental results demonstrate superior privacy (98% confidentiality vs. 80â95% for encryption-based approaches) alongside competitive performance: read latency improves 37% (p < 0.001), throughput increases 14.6% (p < 0.001), memory reduces 21.4%, network bandwidth saves 47%, and disk I/O reduces 37.8%. The system maintains zero data loss under failure scenarios and scales linearly to 500 devices with minimal degradation (9.9%). CIPHER-IoT demonstrates that verification-based privacy mechanisms can achieve stronger privacy and better performance than transformation-based approaches in distributed validation contexts, particularly suitable for enterprise IoT deployments requiring coordinated privacy-preserving infrastructure.
Cross-chain bridges represent one of the most critical yet vulnerable components of blockchain infrastructure, with over $2.5 billion lost to bridge exploits between 2022-2023 alone. MERIDIAN LINK introduces an architecture combining Light Protocol's ZK Compression on Solana with GrotH16 zero-knowledge proofs for verification on EVM chains, reducing trust assumptions compared to signature-based bridges while acknowledging explicit trade-offs. Key Properties: Cost reduction: 95%+ savings on Solana storage via compressed accounts (~15,000vs ~1,600,000 lamports per deposit record) Verification: GroTH16 proofs (~100-bit security on BN254) replace multisig attes-tation for withdrawal authorization Latency: ~20-25 seconds end-to-end (competitive with intent-based bridges) Replay protection: Poseidon-based nullifiers with on-chain tracking Explicit Limitations: Throughput: ~12-20 withdrawals per minute per direction (sequential IMT updates) EVM costs: Withdrawal verification costs ~$4-6 at 30 gwei, dominating total transfer cost Trust assumptions: GroTH16 trusted setup, Light Protocol implementation, Photon indexer availability, relayer liveness The protocol shifts the trust model from "honest majority of signers" to "cryptographic soundness plus infrastructure liveness." A compromised relayer cannot forge proofs or double-spend, but can censor transactions or extract MEV through reordering.
The integrity of distributed healthcare databases is continuously threatened by unauthorized modifications, hardware faults, software vulnerabilities, and increasingly sophisticated cyberattacks. Traditional relational and NoSQL database systems rely on centralized access-control mechanisms and periodic audit logs that cannot provide cryptographic proof of unaltered history or real-time anomaly detection. This paper presents ChainGuard, a novel middleware framework that integrates Ethereum-based smart contracts, a network of IoT integrity-sensing nodes, and an AI-powered anomaly classifier to provide end-to-end, tamper-evident integrity assurance for distributed healthcare information systems. ChainGuard records SHA-256 hash digests of critical database state snapshots onto a permissioned Ethereum ledger, while a constellation of lightweight IoT agents embedded at database server nodes continuously monitors system-level indicatorsâI/O throughput, memory bus activity, and cryptographic nonce validationâat ten-second intervals. Deviations from baseline behavior trigger smart-contract-enforced quarantine procedures that freeze suspect transactions and emit verifiable incident records onto the immutable ledger. A Random Forest classifier trained on 12,000 synthetic database-event logs achieves 96.4% accuracy in discriminating legitimate bulk insertions from covert data-tampering attempts. Evaluation across three clinical deployment scenarios demonstrates that ChainGuard reduces mean time to tamper detection from 47 minutes (baseline centralized audit) to 38 seconds, with a false-positive rate of 1.7%. The framework is deployable on existing PostgreSQL and MongoDB infrastructure without schema modification, making it an immediately practicable path toward regulatory compliance with HIPAA, GDPR, and the forthcoming NIS2 Directive.
Oliver Aleksander Larsen, Rasmus Stenbak Larsen, Mahyar Tourchi Moghaddam
Today's internet concentrates identity, payments, communication, and content hosting under a small number of corporate intermediaries, creating single points of failure, enabling censorship, and extracting economic rent from participants. We present BitSov, an architectural framework for sovereign internet infrastructure that composes existing decentralized technologies (Bitcoin, Lightning Network, decentralized storage, federated messaging, and mesh connectivity) into a unified, eight-layer protocol stack anchored to Bitcoin's base layer. The framework introduces three architectural patterns: (1) payment-gated messaging, where every transmitted message requires cryptographic proof of a Bitcoin payment, deterring spam through economic incentives rather than moderation; (2) timechain-locked contracts, which anchor subscriptions and licenses to Bitcoin block height (the timechain) rather than calendar dates; and (3) a self-sustaining economic flywheel that converts service revenue into infrastructure growth. A dual settlement model supports both on-chain transactions for permanence and auditability and Lightning micropayments for high-frequency messaging. As a position paper, we analyze the quality attributes, discuss open challenges, and propose a research agenda for empirical validation.
The growing adoption of the Electronic Health Records (EHR) has revolutionized healthcare information management. However, seamless and secure interoperability between different healthcare organizations continues to be a hard challenge. Data silos, centralized trust model, and lack of scalability are common impairments of traditional systems in care delivery which limit âpatient centricâ way of care delivery. While blockchain technology offers decentralized trust and immutability, current solutions tend to be closed on a single blockchain platform, and thus not able to provide cross network interoperability and accessing data. To address this gap, this research introduces a Cross Chain EHR Sharing Framework that may be leveraged for the secure, bi-directional synchronization of EHR between Hyperledger Fabric (private blockchain) and Ethereum Sepolia Testnet (public blockchain) via decentralized storage by IPFS with AES 256 encryption. To facilitate interoperability the research introduces a smart middleware layer that autonomously monitors the blockchain events, processes encrypted Content Identifier (CID)s, enforces real time cross chain consistency and smart contract-based access control. The experimental evaluation shows that proposed framework achieves low synchronization times (< 195 ms), efficient blockchain operations with low gas and latency costs, small encryption overhead (< 4â5 KB), robust file storage and retrieval through IPFS. It also provides scalability, security and real-world applicability for the cross-chain healthcare interoperability.
Ryan Babbush, Adam Zalcman, Craig Gidney, Michael Broughton · 9 authors
This whitepaper seeks to elucidate implications that the capabilities of developing quantum architectures have on blockchain vulnerabilities and mitigation strategies. First, we provide new resource estimates for breaking the 256-bit Elliptic Curve Discrete Logarithm Problem, the core of modern blockchain cryptography. We demonstrate that Shor's algorithm for this problem can execute with either <1200 logical qubits and <90 million Toffoli gates or <1450 logical qubits and <70 million Toffoli gates. In the interest of responsible disclosure, we use a zero-knowledge proof to validate these results without disclosing attack vectors. On superconducting architectures with 1e-3 physical error rates and planar connectivity, those circuits can execute in minutes using fewer than half a million physical qubits. We introduce a critical distinction between fast-clock (such as superconducting and photonic) and slow-clock (such as neutral atom and ion trap) architectures. Our analysis reveals that the first fast-clock CRQCs would enable on-spend attacks on public mempool transactions of some cryptocurrencies. We survey major cryptocurrency vulnerabilities through this lens, identifying systemic risks associated with advanced features in some blockchains such as smart contracts, Proof-of-Stake consensus, and Data Availability Sampling, as well as the enduring concern of abandoned assets. We argue that technical solutions would benefit from accompanying public policy and discuss various frameworks of digital salvage to regulate the recovery or destruction of dormant assets while preventing adversarial seizure. We also discuss implications for other digital assets and tokenization as well as challenges and successful examples of the ongoing transition to Post-Quantum Cryptography (PQC). Finally, we urge all vulnerable cryptocurrency communities to join the ongoing migration to PQC without delay.