Andrei Brînzea, Răzvan-Andrei Leancă, Iulian Aciobăniţei, Florin Pop
Traditional Time-Stamping Authorities provide reliable temporal evidence. However, they operate as single points of trust and do not supply a tamper-evident record of event ordering. This paper presents a standards-compliant extension that anchors each issued timestamp token to a blockchain ledger while preserving full compatibility with existing TSA clients. Our proposal is compliant with RFC 3161. The implementation uses an identifier in the token that is also included in the distributed ledger. Experiments were conducted on the Ethereum and Hyperledger Fabric networks. Our design allows for external verification of the existence and relative ordering of tokens without modifying the RFC-defined validation process. Experimental evaluation compares issuance latency, anchoring time, and transaction cost across both networks. Our work presents a practical and viable approach to enhancing trust in digital signature infrastructures by combining the regulatory reliability of qualified TSAs with the auditability and persistence of distributed ledgers.
A proof-carrying trust framework where every EQBSL trust claim ships with a zero-knowledge validity certificate verifiable by any third party without re-running the computation. Establishes the formal link between evidence-based subjective logic opinions and zero-knowledge proof systems, enabling trustless trust attestation in decentralised networks.
International Journal of Computer Sciences and Engineering (A UGC Approved and indexed with DOI, ICI and Approved, DPI Digital Library) is one of the leading and growing open access, peer-reviewed, monthly, and scientific research journal for scientists, engineers, research scholars, and academicians, which gains a foothold in Asia and opens to the world, aims to publish original, theoretical and practical advances in Computer Science,Information Technology, Engineering (Software, Mechanical, Civil, Electronics & Electrical), and all interdisciplinary streams of Computing Sciences. It intends to disseminate original, scientific, theoretical or applied research in the field of Computer Sciences and allied fields. It provides a platform for publishing results and research with a strong empirical component. It aims to bridge the significant gap between research and practice by promoting the publication of original, novel, industry-relevant research.
Open access
Advanced Data Storage Technologies
Security and Verification in Computing
Physical Unclonable Functions (PUFs) and Hardware Security
K.Kalaiselvi, Mohammad Musa Al-Momani, E.Sivajothi, T. Vijetha · 6 authors
Embedded systems are at the heart of critical infrastructure facilities in areas such as energy, transportation, healthcare, defense; where integrity, traceability, and auditability of data generated by the system are of great importance. However, existing data provenance security solutions for embedded settings are highly unsatisfactory because centralized design is vulnerable in embedded environment, they do not scale well and have poor privacy mechanisms. This work presents a novel method of combining immutable data provenance and anonymous blockchain solutions to solve these issues and promote the trustworthiness of embedded systems. The framework takes advantage of privacy-preserving cryptographic methods such as ring signatures, stealth addresses, and zero-knowledge proofs to support tamper-evident decentralized storage of data events without losing source privacy. It's designed to run efficiently under the resource constraints of the embedded platforms, to be low point compatible with low-power devices, without sacrificing the responsiveness of the system or the authenticity of the data. The architecture is designed for real time monitoring and auditability on distributed embedded devices that are installed in critical infrastructure networks. A lightweight consensus algorithm designed for embedded environments allows secure synchronization and validation of data without the need for the heavy computation of a public blockchain. The framework was experimentally validated through prototype implementation and simulation in multiple use-case scenarios, showing its effectiveness against data forgery, unauthorized access and provenance tampering. Performance evaluation demonstrates that the model is scalable, low latency and high throughput under restrained resource environments. This work demonstrated that, by building immutable and anonymous data provenance into embedded systems, in addition to increasing transparency, trustworthiness, and robustness of operation, it is also possible to lay the foundation for a novel class of secure, decentralized infrastructure monitoring tools suitable for adversarial deployments. Results demonstrate a robustness for deployment into actual applications with high-assured data traceability supported with privacy protection.
Shanmugam N, C.Jehan, Khaled Alqawasmi, N E Chandra Prasad · 6 authors
Cyber infrastructures, as the substrate of digital ecosystems, are more and more the objects of advanced cyberattacks, security protocol violations, untrustworthy third-party interactions. It is essential to provide a resounding guarantee of reliability and to enforce compliance across these infrastructures, at a time when the scale and complexity of data exchange and operational dependencies are increasing. In this paper, we present a new approach, which uses blockchain technology and smart contracts for cybersecurity compliance enforcement and operation resiliency in cyber infrastructures. The approach employs the decentralized, immutable, and transparent natures of the blockchain in order to create a tamper-proof and auditable setting where the cybersecurity policy can be enforced. Smart contractable compliance are able to automate compliance checking, record security events, and take responsive actions without the trust in a centralized entity. These smart contracts are self-executing action protocols that encode cybersecurity procedures and validation standards that take care of itself when every organization do abide by the security standards. Such mechanism ensures anticipatory enforcement on anomalous behavior and automatic remediation action execution, based on predetermined policy-rules. In addition, a layered protocol structure is being incorporated so that it can enforce compliance throughout different infrastructure components e.g., networks, cloud platforms, IoT systems, and critical information systems. The system design is tightly integrated with features such as identity management, threat intelligence sharing, behavior audit, and distributed access control, all of which are achieved via smart contracts. To build trust in transactions and operations in the environment, consensus algorithms and cryptography are employed. The paper also provides simulations and case studies illustrating the viability of the proposed method in important domains e.g., healthcare, finance and industrial control. It is found that such optimization results in significant enhancement on accuracy for compliance enforcement, reliability of the system, as well as response time to security incidents. The distributed architecture of the framework also reduces the possibility of single point failures and provides robust protection against insider attacks. This work adds to the increasing nexus of security and blockchain technology, providing a secure, autonomous trust and compliance protocol for dynamic cyber battlefields. It provides the groundwork for a future where intelligent cybersecurity contracts are enforcing regulatory mandates, automating the audit process and hardening infrastructure resiliency in a way that requires very little human intervention. The model effectively changes the narrative around compliance, because it is no longer static as a obligation but rather a dynamic, enforceable and self-governing trait woven into the composition of digital infrastructure.
The proliferation of Web3 and Internet of Things (IoT) applications generates unprecedented volumes of real-time data streams, demanding secure and efficient subscription mechanisms that uphold data sovereignty. While decentralized architectures are the logical paradigm to ensure this sovereignty, a prominent class of existing schemes suffers from critical vulnerabilities—notably revocation attacks and prohibitive communication overhead—that severely hinder their practical deployment in large-scale environments. This paper introduces SegSub, a novel decentralized data subscription scheme specifically designed to significantly enhance both security and efficiency. SegSub's core innovations include the Segmented Dual-Key Regression with Binary Hash Trees (SDKR-BHT) mechanism, which partitions key regression chains into isolated segments to effectively contain potential data leakage and optimize token management and a strategic user grouping policy that localizes key updates, thereby substantially reducing system-wide communication overhead during revocation events. We formally quantify security improvements using a proposed security index and demonstrate a configurable trade-off between security and efficiency. Theoretical analysis and extensive experimental results validate that SegSub's security index is inversely proportional to segment length while communication efficiency is directly proportional. Furthermore, our grouping policy significantly reduces communication costs in large-scale scenarios through optimal group sizing. SegSub offers a robust and adaptable foundation for sovereignty-preserving data subscription services in Web3, empowering system designers with precise control over the critical security-efficiency balance to meet diverse deployment requirements.
Thanh Hai To, Vu Trung Duong Le, Van Tinh Nguyen, Van-Tuan Luu · 6 authors
Zero-knowledge proofs have become an essential component for providing privacy and verifiability in decentralized systems. Existing techniques, such as zk-SNARKs, have intrinsic constraints, including the necessity for a trusted setup and sensitivity to quantum attacks, which make them unsuitable for high-assurance applications such as digital banking. In this paper, we provide a viable zk-STARK-based verification system that eliminates the trusted setup while maintaining long-term post-quantum security. Our system integrates off-chain proof generation using Cairo 0, on-chain verification through Cairo 2 smart contracts on Starknet, and decentralized proof storage via IPFS and Filecoin. Experimental results show that the time users wait from transaction submission to confirmation is approximately 1.15 seconds on average, with Cairo 2 contract verification completing in 0.73 seconds and consuming a gas cost of 0.0158 STRK (equivalent to approximately 0.00229 USD) per first-time execution. End-to-end latency for proof publication to IPFS and Filecoin is evaluated separately, reaching up to 63 minutes and 41 hours, respectively. However, these steps run asynchronously without impacting user responsiveness. Compared to zk-SNARK and Bulletproof-based systems, our hashbased, transparent architecture is more scalable, auditable, and quantum-resistant. These findings show that it is possible to install real-world, privacy-preserving, post-quantum verification pipelines for next-generation financial systems.
Pedro F. F. Abreu, Maria R. F. M. Ferreira, Luis H. O. Mendes, Geraldo A. Sarmento Neto · 8 authors
The proliferation of Internet of Things (IoT) devices necessitates secure, scalable, and cost-effective access control mechanisms. While blockchain and Non-Fungible Tokens (NFTs) offer a decentralized paradigm for managing permissions, they remain vulnerable to off-chain resource exhaustion attacks and present practical implementation challenges for low-cost devices. This paper proposes a novel hybrid architecture that enhances NFT-based access control with an off-chain gateway acting as both a Smart Reputation System (SRS) and a delegated signer. This hybrid model combines fast, off-chain pre-validation with authoritative on-chain verification. The SRS serves as a security firewall, mitigating high-frequency invalid requests by dynamically managing the reputation of each device and imposing temporary bans on malicious actors. By delegating cryptographic signing to the gateway, low-cost IoT devices are absolved of managing private keys, significantly reducing their complexity and cost. An experimental evaluation of the implemented system was conducted to assess its resilience against Denial-of-Service attacks. The findings indicate that the system successfully neutralizes threats in under 3 seconds. During this process, a stable end-to-end latency of approximately 626 ms is maintained for legitimate users, with the gateway’s reputation logic introducing a negligible performance overhead of less than 1%. This hybrid approach proves to be a practical and effective solution for deploying secure and resilient access control in real-world IoT environments.
In this work, we present homomorphic encryption-based vaults (Haults), a permissioned privacy-preserving smart wallet protocol for VM-enabled blockchains that keeps users' balances confidential, as well as the amounts transacted to other parties. To comply with regulations, we include optional compliance features that allow specific entities (the auditors) to retrieve transaction amounts or execute force transfers when necessary. Our solution uses ElGamal over elliptic curves to encrypt balances, combined with zero-knowledge proofs to verify the correctness of transaction amounts and the integrity of the sender's updated balance, among other security checks. We provide a detailed explanation of the protocol, including a security discussion and benchmarks from our proof-of-concept implementation, which yield great results. Beyond in-contract issued tokens, we also provide a thorough explanation on how our solution can be compatible with external ones (e.g., Ether or any ERC20).
The main objective of the report is to demonstrate the creation and vulnerability testing of a web3 application for a decentralized system that integrates three key processes – membership management, automatic revenue distribution, and participation in the governance of the organization – within a secure, transparent, and immutable blockchain infrastructure. An analysis is demonstrated to detect and eliminate potential vulnerabilities and integration tests to confirm the correct interaction between the system modules.
Remote Procedure Call (RPC) services have become a primary gateway for users to access public blockchains. While they offer significant convenience, RPC services also introduce critical privacy challenges that remain insufficiently examined. Existing deanonymization attacks either do not apply to blockchain RPC users or incur costs like transaction fees assuming an active network eavesdropper. In this paper, we propose a novel deanonymization attack that can link an IP address of a RPC user to this user's blockchain pseudonym. Our analysis reveals a temporal correlation between the timestamps of transaction confirmations recorded on the public ledger and those of TCP packets sent by the victim when querying transaction status. We assume a strong passive adversary with access to network infrastructure, capable of monitoring traffic at network border routers or Internet exchange points. By monitoring network traffic and analyzing public ledgers, the attacker can link the IP address of the TCP packet to the pseudonym of the transaction initiator by exploiting the temporal correlation. This deanonymization attack incurs zero transaction fee. We mathematically model and analyze the attack method, perform large-scale measurements of blockchain ledgers, and conduct real-world attacks to validate the attack. Our attack achieves a high success rate of over 95% against normal RPC users on various blockchain networks, including Ethereum, Bitcoin and Solana.
Layer 2 rollups offer promising solutions to address Ethereum's scalability issues. However, the centralized nature of the sequencer in these rollups makes them vulnerable to denial of service attacks, in which adversaries overwhelm the sequencer with invalid transactions that cannot be included in blocks, thereby exhausting its computational resources for transaction processing. To mitigate such threat, layer 2 rollups implement the legality check mechanism to filter out invalid transactions before they reach the sequencer.
In many fields, the need to securely collect and aggregate data from distributed systems is growing. However, designs that rely solely on encrypted data transmission make it difficult to trace malicious users. To address this challenge, we have enhanced the secure aggregation (SA) protocol proposed by Bell et al. (CCS 2020) by introducing verification features that ensure compliance with user inputs and encryption processes while preserving data privacy. We present LZKSA, a quantum-safe secure aggregation system with input verification. LZKSA employs seven zero-knowledge proof (ZKP) protocols based on the Ring Learning with Errors problem, specifically designed for secure aggregation. These protocols verify whether users have correctly used SA keys and their L∞, L2 norms and cosine similarity of data, meet specified constraints, to exclude malicious users from current and future aggregation processes. The specialized ZKPs we propose significantly enhance proof efficiency. In practical federated learning scenarios, our experimental evaluations demonstrate that the proof generation time for L∞ and L2 constraints is reduced to about 10-3 of that required by the current state-of-the-art method, RoFL (S&P 2023), and ACORN (USENIX 2023). For example, the proof generation/verification time of RoFL, ACORN and LZKSA for L∞ is 94s/29.9s, 78.7s/33.9s, and 0.02s/0.0062s for CIFAR10, respectively.
Issues in error handling may have critical consequences in blockchain software, ranging from silent execution with invalid states to denial of services due to unexpected crashes. This paper discusses the pitfalls of errors handling within blockchain frameworks written in Go such as Hyperledger Fabric, Tendermint Core (including its derivatives, e.g. CometBFT, Ignite), and other frameworks (e.g. Cosmos SDK), as well as the Ethereum implementation. Then, it explores how a static analysis approach can be applied for the automatic detection of such of issues, allowing to fix buggy code before deployment, i.e., when the code becomes difficult to patch being blockchain a trustless, distributed, and decentralized environment. Finally, we evaluate our analysis implementation within GoLiSA on a set of existing smart contracts and blockchain applications, empirically demonstrating the feasibility of the proposed approach.
Mobile Web3 faces catastrophic retention (< 5%) yielding effective acquisition costs of \$500 - \$1,000 per retained user. Existing solutions force an impossible tradeoff: embedded wallets achieve moderate usability but suffer inherent click-jacking vulnerabilities; app wallets maintain security at the cost of 2 - 3% retention due to download friction and context-switching penalties. We present SecureSign, a PWA-based architecture that adapts desktop browser extension security to mobile via EIP-6963 provider sandboxing. SecureSign isolates dApp execution in iframes within a trusted parent application, achieving click-jacking immunity and transaction integrity while enabling native mobile capabilities (push notifications, home screen installation, zero context-switching). Our drop-in SDK requires no codebase changes for existing Web3 applications. Threat model analysis demonstrates immunity to click-jacking, overlay, and skimming attacks while maintaining wallet interoperability across dApps.
Verifiable network telemetry is crucial for ensuring transparency and trust in network measurements. However, telemetry logs (e.g., NetFlow records) often contain sensitive data, making public verification challenging. Recent work has attempted to address this problem using Trusted Execution Environments (TEEs), such as Intel SGX, to provide confidentiality and integrity guarantees. However, TEEs are known to suffer from complex deployment requirements and limited scalability. In this paper, we introduce a software-based approach utilizing the latest advances in Zero-knowledge Proofs (ZKPs) to enable verifiable network telemetry without revealing the underlying sensitive logs or relying on special-purpose hardware. Our system employs a general-purpose ZKP virtual machine (RISC Zero) to generate cryptographic proofs over NetFlow data, enabling operators to securely attest to network flow metrics. Our preliminary results indicate that our ZKP-based design offers a viable path toward overcoming deployment and scalability limitations inherent in the solutions that require special-purpose hardware.
Smart contract vulnerabilities continue to cause significant financial losses, despite the implementation of security measures such as manual audits and bug bounty platforms. A critical component often required by these security measures is the proof-of-concept (PoC) exploit, which validates vulnerability exploitability, assesses impact severity, and guides developers in fixes. Existing tools have explored automated PoC generation with techniques like symbolic execution, fuzzing, and program synthesis. However, these approaches frequently fail to generate PoCs for vulnerabilities exploited in real-world incidents, primarily due to their limitations in handling complex transaction dependencies, navigating vast on-chain state spaces, or requiring extensive manual specifications. Our migration-based approach extracts critical information from documented security incidents and applies it to generate PoCs for similar vulnerable code. This approach leverages proven exploit patterns rather than generating PoCs from scratch. This approach is motivated by two key observations: the prevalence of code reuse in smart contracts (up to 90% at the function level) and the increasing availability of documented PoCs for real-world incidents. Our approach operates in three phases: (1) abstracting essential components (i.e., environment properties, attack logic, and verification checks) from existing PoCs into templates, (2) given a new target contract, selecting suitable templates with adapted values through clone-detection and property-feasibility analysis, and (3) generating and validating PoCs in simulated environments. Our evaluation demonstrates effectiveness and efficiency across multiple scales. Our approach successfully generates valid PoCs for 62 out of 67 manually validated cases without false positives and completes analysis in 3.8 hours compared to 133.2 and 210.5 hours required by existing tools. Large-scale evaluation on 979,512 contracts identifies 256 vulnerable contracts across blockchain networks with 64 cross-chain cases, demonstrating real-world applicability.
Smart contracts have become a foundational component of blockchain systems, enabling decentralized, transparent, and autonomous execution of application logic across various domains, including decentralized finance (DeFi), gaming, and digital identity. Due to their immutable and trustless nature, smart contracts often manage and transfer substantial amounts of assets without human intervention. However, vulnerabilities in smart contracts can lead to substantial financial losses. Among these, access control vulnerabilities are particularly critical, typically originating from inadequately designed or incorrectly implemented permission mechanisms. Most existing methods for detecting access control vulnerabilities are based on static analysis, which heavily relies on manually defined rules and pattern matching. While these methods are efficient at identifying certain classes of known vulnerabilities, they are inherently limited in scope and generalization. In particular, they often fail to capture the underlying business logic of smart contracts.In this paper, we propose an LLM-based multi-agent system, named ACTaint, for detecting access control vulnerabilities in Solidity smart contracts. ACTaint first performs static analysis to guide the sink agent in identifying potential sinks. Then, based on the identified sinks, the taint agent conducts taint analysis to determine whether a data flow exists from untrusted sources to these sinks. We evaluate our approach on three datasets: known CVE cases, a set of 624 real-world smart contracts, and another set of 93 real-world smart contracts. The results demonstrate that our method outperforms existing tools in both datasets. On the first dataset, our approach outperforms state-of-the-art tools, including AChecker and GPTLens, achieving higher recall and F1-score. On the second dataset, our method surpasses the leading static analysis tool AChecker, with a 8.3% improvement in precision and an 9.7% improvement in F1-score.
Han Liu, Daoyuan Wu, Yi Sun, Shuai Wang · 6 authors
OpenZeppelin is a building block for many smart contracts on Ethereum-compatible blockchains. It provides mod-ular and reusable libraries for various Ethereum standards (e.g., ERC20 and ERC721) and common functionalities such as upgradeable contracts. Little research has been done on Open-Zeppelin security except for a recent study, which focused only on the misuse of OpenZeppelin code, assuming OpenZeppelin itself is secure but contract developers may not follow OpenZeppelin’s function checks appropriately. We argue that, despite appearing robust, OpenZeppelin itself could have many vulnerabilities, and these library-level vulnerabilities could inadvertently affect third-party smart contracts, even without misuse from developers.We present ZepCompare, the first end-to-end system for demystifying OpenZeppelin’s own vulnerabilities and analyzing their propagation in third-party smart contracts. ZepCompare incorporates a manual analysis stage where we review OpenZeppelin’s 64 historical releases, identifying 109 vulnerable-fixed code pairs, exposing flaws in cryptographic utilities, access control, etc. Leveraging these pairs, ZepCompare introduces facts of changes, a novel structure capturing vulnerable and fixed code contexts for flexible matching. Evaluated across 88,605 contracts from three Ethereum-compatible chains, ZepCompare detects 4,708 instances of OpenZeppelin-derived vulnerabilities. Manual sampling and a ground-truth experiment confirm that ZepCompare achieves 86.7% precision and 77.1% recall. Our findings reveal significant security risks in both historical and the latest versions of OpenZeppelin libraries, underscoring the urgent need for systematic auditing of foundational contracts components.
Zero-knowledge proof (ZKP) circuits implemented in programming languages like Circom are fundamental to blockchain and privacy-preserving applications. These code often suffer from constraint-related issues where constraints fail to accurately specify intended computations. While existing analysis tools have been proposed, they struggle with large-scale circuits containing complex template embeddings. We present ScaleCirc, a novel framework that addresses such limitations through: 1) systematic management of analysis redundancy via circuit deduplication strategies; 2) constrainedness propagation methods leveraging source code semantic information; and 3) a generalizable framework for different circuit analysis tasks. Evaluation on 691 real-world circuits shows ScaleCirc demonstrates higher efficiency, and successfully analyzes many Circom programs that existing works failed on.
Physical Unclonable Functions (PUFs) and Hardware Security
Solana has rapidly evolved into a leading next generation platform for supporting decentralized applications due to its high performance and low transaction costs. Its new contract execution model, which decouples code logic from states, gives rise to new vulnerability threats that can result in significant financial losses for users within the ecosystem. However, existing studies towards detecting vulnerabilities are predominantly tailored for Ethereum smart contracts, which are unsuitable for Solana platform because of the variations in implementation languages and runtime semantics. In this paper, we propose Soleker, a novel approach that leverages learning-based techniques to automatically identifying potential vulnerabilities in Solana smart contract bytecode. More specifically, Soleker captures runtime semantic information from instructions that are associated with blockchain interactions and extracts vulnerability-specific localized features. Then, a prefix-guided graph learning model is introduced to learn and integrate extracted features, enabling effective vulnerability detection. We conduct experiments on a newly constructed contract dataset and the results demonstrate that Soleker significantly outperforms the baseline methods, achieving an average effectiveness improvement of 126.4% and a 335× boost in efficiency.