Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

9,005 papersLast indexed Aug 31, 2026
Search papers

Paper index

9,005 results · page 16 of 376

Clear filters
Mar 29, 2026·International Journal of Natural-Applied Sciences and Engineering
0 cites
BAVS-ZK: Hybrid Entropy-Based Credential Derivation for Anonymous Blockchain E-Voting

Hawraa M. Ali, Ra'ad A. Muhajjar

Blockchain-based electronic voting systems that use zero-knowledge proofs (ZKPs) have been proposed as good candidates to provide both transparency and privacy of ballots. However, a fundamental challenge remains unmet in all existing schemes: the secure generation and protection of the voter's cryptographic secret key.In this paper, HME-KG (Hybrid Multi-Source Entropy Key Generation) is presented, a new credential derivation method which utilizes a cryptographically secure random salt, the national identity number of the voter and a per-device Client Device Secret (CDS) to derive a deterministic, brute-force-resistant secret key. HME-KG is integrated into BAVS-ZK, a complete anonymous blockchain voting framework employing AES-256-GCM encrypted credential storage, a Circom-based Groth16 zk-SNARK voting circuit, and on-chain nullifier verification via Ethereum Sepolia smart contracts. Security analysis demonstrates that HME-KG achieves voter determinism, cross-voter uniqueness, single-source failure resistance, and collision resistance under the security assumptions of SHA-256. Experimental evaluation on a 10,000-voter simulation confirms a 0.9998 scalability coefficient, 1.2-second proof generation, and 306,720 gas per vote—a 38.6% reduction compared to the Open Vote Network baseline. To the extent of current literature, BAVS-ZK is the first blockchain e-voting system to provide a complete, formally specified, and experimentally validated voter credential derivation and protection scheme.

Open access
Internet Traffic Analysis and Secure E-voting
Cryptography and Data Security
Blockchain Technology Applications and Security
Original source
Mar 29, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
Proof-Object Dissociation: An Architectural Principle for Certification Systems / Dissociation preuve-objet : un principe architectural pour les systĂšmes de certification

Franck Gérard

EN — This paper introduces proof-object dissociation as an architectural principle for certification systems. In the major families of existing approaches reviewed here — including trusted timestamping, zero-knowledge proofs, token-based certification models, public key infrastructures, commitment schemes, and proof-of-existence mechanisms — the proof remains structurally tied to the object, secret, or entity whose validity is being established. This paper argues that such coupling should be understood as a dominant architectural convention rather than as a logical necessity. EN — Under proof-object dissociation, a certification reference structure may be generated, preserved, and anchored independently of any future certified object. Certification is then achieved through a controlled activation mechanism that associates an already valid reference structure with a specific object, user, or context. At the architectural level, this shift makes possible a set of properties that are difficult or unavailable in coupled models: pre-certification independent of the future object, deferred activation, mutation or transfer of activation rights without regeneration of the reference layer, and validation without disclosure of confidential source elements. EN — The paper positions this proposal relative to existing certification architectures, outlines a general implementation-agnostic framework, and identifies a further operational capability termed the Blind Pre-Certification Layer (BPCL). FR — Cet article introduit la dissociation preuve-objet comme principe architectural pour les systĂšmes de certification. Dans les principales familles d'approches existantes examinĂ©es ici — notamment l'horodatage de confiance, les preuves Ă  divulgation nulle, les modĂšles de certification fondĂ©s sur des jetons, les infrastructures Ă  clĂ© publique, les schĂ©mas d'engagement et les mĂ©canismes de preuve d'existence — la preuve demeure structurellement liĂ©e Ă  l'objet, au secret ou Ă  l'entitĂ© dont la validitĂ© est Ă©tablie. L'article soutient que ce couplage doit ĂȘtre compris comme une convention architecturale dominante plutĂŽt que comme une nĂ©cessitĂ© logique. FR — Sous dissociation preuve-objet, une structure de rĂ©fĂ©rence de certification peut ĂȘtre gĂ©nĂ©rĂ©e, conservĂ©e et ancrĂ©e indĂ©pendamment de tout objet futur certifiĂ©. La certification est ensuite rĂ©alisĂ©e par un mĂ©canisme d'activation contrĂŽlĂ©e qui associe une structure de rĂ©fĂ©rence dĂ©jĂ  valide Ă  un objet, un utilisateur ou un contexte spĂ©cifique. Au niveau architectural, ce dĂ©placement rend possible un ensemble de propriĂ©tĂ©s difficiles Ă  obtenir ou absentes dans les modĂšles couplĂ©s : prĂ©-certification indĂ©pendante de l'objet futur, activation diffĂ©rĂ©e, mutation ou transfert des droits d'activation sans rĂ©gĂ©nĂ©ration de la couche de rĂ©fĂ©rence, et validation sans divulgation des Ă©lĂ©ments confidentiels sources. FR — L'article situe cette proposition par rapport aux architectures existantes de certification, prĂ©sente un cadre gĂ©nĂ©ral agnostique quant Ă  l'implĂ©mentation, et identifie une capacitĂ© opĂ©rationnelle supplĂ©mentaire nommĂ©e Couche de PrĂ©-Certification Aveugle (BPCL).

Open access
2 source records
Cryptography and Data Security
Advanced Authentication Protocols Security
Security and Verification in Computing
Original source
Mar 28, 2026·Sensors
0 cites
A Security-Enhanced Certificateless Aggregate Authentication Protocol with Revocation for Wireless Medical Sensor Networks

Quan Fan, Yimin Wang, Xiaofeng Li

Wireless medical sensor networks (WMSNs) enable continuous patient monitoring by transmitting sensitive physiological data over open wireless links. Given the resource-constrained nature and large-scale deployment of such networks, authentication mechanisms must be both lightweight and privacy-preserving. Moreover, due to the frequent turnover of patients and devices in hospital environments, timely member revocation is crucial to prevent discharged or compromised entities from injecting forged reports that could mislead medical diagnosis. Although existing pairing-free certificateless aggregate authentication schemes are efficient, they often suffer from critical security and privacy vulnerabilities. Recently, an efficient certificateless authentication scheme with revocation has been proposed. However, our analysis reveals that the scheme presents the following security vulnerabilities: (i) member witnesses can be recovered from public information, (ii) revocation checks can be bypassed via identity grafting attack, and (iii) user identities can be linked due to the long-term use of static pseudonyms. To address these issues, we propose a security-enhanced certificateless aggregate authentication protocol with revocation for WMSNs. Our design enforces strong identity-membership binding to resist grafting attacks, employs a non-interactive zero-knowledge membership proof to preserve witness secrecy, and adopts dynamic pseudonym rotation to achieve unlinkability. We provide formal security proofs and comprehensive performance comparisons. The results indicate that, at the same security level, our protocol achieves more efficient signature verification while maintaining communication overhead comparable to existing schemes. In addition, the overhead introduced by our revocation mechanism remains constant, making it well suited for large-scale WMSNs deployments with frequent membership changes.

Open access
Security in Wireless Sensor Networks
Advanced Authentication Protocols Security
Cryptography and Data Security
Original source
Mar 28, 2026·The Asian Bulletin of Big Data Management
0 cites
An Efficient Approach for Security and Privacy Preserving based on Machine Learning and Federated Learning (FL): Analysis and Performance Optimization for Secure Multiparty Computing

Ammar Ahmed, Amna Saleem Sheikh, Nasir Ayub, Umair Ghafoor · 6 authors

Federated Learning (FL) is an approach that allows numerous users to train a single machine learning model with the oversight of a central server, and with their training data stored locally on their devices. The approach is relevant in alleviating the risks associated with violations in data privacy. It is a process by which a pool of clients collaborates towards solving machine learning problems, with a central coordinator being the one who coordinates the entire process. The paper will review the latest advances in privacy-preserving federated learning and discuss it in the context of machine learning. It assesses privacy-related solutions, which are already in existence, such as secure aggregation, meta-learning, blockchain technology, decentralized training, searchable encryption, and data privacy mechanisms and zero-knowledge proofs. Federated learning (FL) is an emerging technology that can be used in the realm of the intelligence of the Internet of Things. However, the information that is model-related can be shared in FL and reveal the sensitive data of the participants. In this regard, we propose a new privacy-preserving FL framework, which is founded on a new chained secure multiparty computing technique, which we call chain-PPFL. The scheme we are proposing is based mostly on two mechanisms: 1) a single-masking mechanism, which protects the information that is exchanged between participants in a serial chain frame and 2) a chained-communication mechanism, which allows the masked information to be communicated between participants in a serial chain frame. We run large-scale experiments with respect to simulation by comparing the training accuracy and the leak defence to other state-of-the-art schemes with two publicly available data sets (MNIST and CIFAR-100). We established data sample distributions (IID and NonIID), and training models (CNN, MLP and L-BFGS) in our experiments. The experiment results show that the chain-PPFL scheme can offer a realistic privacy preservation (which is the same as the various privacy with Ï” to near zero) to FL at the cost of communication, and without compromising the accuracy and convergence rate of the training model.

Open access
Privacy-Preserving Technologies in Data
Cryptography and Data Security
Big Data and Digital Economy
Original source
Mar 28, 2026·Open MIND
0 cites
Transaction Binding Security for Policy-Bound Authorization Tokens

Rudolf Jacobus Coetzee

Authorization tokens in distributed systems are typically context-free: a cryptographically valid token carries no binding to the specific transaction for which it was issued. This enables reuse and cross-context presentation attacks that are undetectable at the cryptographic layer. In regulated financial infrastructure, cross-border payments, and autonomous agent systems, transaction-scoped enforcement is a hard requirement that existing standards leave unaddressed. We introduce the first formal security model for policy-bound transaction tokens. We define the syntax of a policy-bound transaction token scheme over a formal transaction context space and introduce three game-based security notions: transaction binding (TB), which simultaneously resists forgery and cross-context reuse; existential unforgeability under chosen-context attack (EUF-CCA); and unlinkability (UNL). We prove that TB strictly implies EUF-CCA, establish a formal separation between TB and UNL, and identify the inherent tension between unlinkability and auditability. We construct a scheme parameterized by any EUF-CMA-secure signature scheme and a random oracle, and prove that it achieves transaction binding security with a tight reduction requiring no rewinding. We then address the complementary privacy problem by formalizing zero-knowledge compliance privacy (ZK-CP) and constructing an enhanced scheme that augments transaction-binding tokens with a non-interactive zero-knowledge proof of policy compliance. We prove that the enhanced scheme simultaneously achieves TB security and ZK-CP, and show how it integrates with decentralized identity (DID) systems to enable fully privacy-preserving authorization where the verifier learns only whether compliance is satisfied. We give a concrete instantiation using Ed25519 and SHA-512, derive bit-security parameters, analyze performance costs, and discuss deployment considerations including regulatory alignment with PSD2, MiCA, DORA, the GENIUS Act, SEC token taxonomy, and FinCEN BSA requirements.

Open access
2 source records
Blockchain Technology Applications and Security
Cryptography and Data Security
Access Control and Trust
Original source
Mar 27, 2026·Frontiers in Computing and Intelligent Systems
0 cites
Research And Analysis of Cryptographic Methods Based on Blockchain

Rongxi Wei

This paper systematically reviews the research foundation, core technologies, and practical applications of cryptography in the blockchain field. Algorithms, and data immutability relies on cryptographic hash functions and Merkle tree structure; the balance between transparency and privacy in block chain relies on the encryption technique of zero-knowledge proofs, ring signature, homomorphic encryption. Therefore, every part of block chain is based on cryptography; without the mathematical guarantee of cryptography, the trust decentralized by block chain is meaningless. The security of block chain mainly relies on the encryption techniques such as hash functions, digital signatures and encryption algorithms, and traditional cryptographic methods will have vulnerabilities when facing quantum computing, because quantum computer may be used to break currently commonly used algorithms such as RSA, ECC eventually. This “security paradox" requires us to pay more attention to block chain technologies, because block chain technology needs to advance in tandem with cryptography. Traditional blockchain technologies can’t be used indefinitely. Against this background, researching block chain based crypto is of great theoretical significance and practical value: on the one hand, researching on new cryptographic methods applicable to block chain can extend the area of cryptosystems and give people a new way of solving the security problems in block chain; on the other hand, we should not neglect the possibility of breaking the block chain by combining quantum computing with cryptanalysis research.

Open access
Chaos-based Image/Signal Encryption
Cryptography and Data Security
Big Data and Digital Economy
Original source
Mar 27, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
ZK-SPoW: Zero-Knowledge Symbiotic Proof of Work

Mitsuru Kurosu

Proof-of-work (PoW) blockchains expend energy solely for network security. Proof of Useful Work (PoUW) aims to reclaim this cost, but stateful proving (e.g., multi-phase STARKs) breaks the memoryless property required for Nakamoto consensus. ZK-SPoW (Zero-Knowledge Symbiotic Proof of Work) inverts the relationship: instead of making PoW useful, useful STARK Merkle hashing naturally produces PoW tickets as a cryptographic byproduct of every Poseidon2 permutation. Under the pseudorandom permutation (PRP) assumption, each permutation is computationally indistinguishable from an independent Bernoulli trial at nanosecond granularity — restoring computational memorylessness at the permutation level without sacrificing useful computation. We instantiate with Width-24 Poseidon2 over M31: each permutation simultaneously produces a Merkle parent (ZK output) and three PoW tickets. Usefulness is not protocol-enforced but market-driven — miners select which ZK proofs to generate or fall back to Pure PoW, guided by proof demand. Statistical validation via the full NIST SP 800-22 test suite (15/15 tests pass) confirms the pseudorandom quality of the Poseidon2-based mining output.

Open access
2 source records
Blockchain Technology Applications and Security
Cryptography and Data Security
Cryptographic Implementations and Security
Original source
Mar 27, 2026·arXiv (Cornell University)
0 cites
HFIPay: Privacy-Preserving, Cross-Chain Cryptocurrency Payments to Human-Friendly Identifiers

Jian sheng Wang

Human-friendly identifiers such as email addresses and phone numbers are convenient payment targets, but direct mappings from identifiers to blockchain addresses make balances and transaction histories enumerable by anyone who knows the identifier. We present HFI-Pay, a relay-assisted protocol for privacy-preserving identifier-routed cryptocurrency payments. The relay resolves the identifier off-chain and registers only a random intent identifier, a per-intent blinded binding rho_i, and the quoted payment tuple on-chain; no identifier or reusable recipient tag is published before claim. In a verified-quote deployment, the sender verifies an attested quote proving that rho_i was derived from the same hidden binding handle as the recipient's attested binding-key commitment, preventing relay-side recipient substitution before funding. Claims are authorized by a zero-knowledge proof, instantiated through ZK-ACE, that the claimant controls the deterministic identity whose epoch-scoped handle opens the blinded binding and authorizes release of the quoted asset and amount to a chosen destination. We define observer-model games for enumeration resistance and pre-claim unlinkability, state the composition needed for post-quote claim correctness, and characterize relay compromise and post-claim linkability. Keywords: identifier-based payment, privacy-preserving, verifiable quote, blinded claim binding, zero-knowledge authorization

Open access
3 source records
cs.CR
cs.DC
Cryptography and Data Security
Original source
Mar 27, 2026·ACM Transactions on Internet Technology
0 cites
A Zero-Knowledge Proof-Driven Architecture for Privacy-Preserving Data Trading on Blockchain

Zhiming Song, Leijin Long, Junrong Song, Rong Jiang

With the accelerating growth of the digital economy, data has emerged as a core asset, making secure and private data trading a pressing necessity. However, traditional centralized data trading platforms face critical challenges, including identity exposure, data leakage, unclear ownership, and lack of trust. Although decentralized, blockchain-based solutions have been proposed, they typically protect only subsets of these properties and seldom provide a unified, verifiable privacy architecture over the entire trading lifecycle. This article introduces a novel decentralized data trading system that comprehensively integrates Groth16-based zero-knowledge proofs (ZKPs), Merkle tree–based data ownership commitments, and smart contracts on blockchain. The proposed system ensures identity anonymity, data confidentiality, ownership traceability, and behavioral privacy while supporting regulatory auditability. Rather than proposing new cryptographic primitives, we reformulate data trading as a zero-knowledge–verifiable privacy problem and embed the resulting privacy logic into the protocol and contract design. The main contributions are as follows. (1) Developing a unified zero-knowledge privacy layer that combines Groth16-based ZKPs with proxy re-encryption, allowing participants to prove transaction eligibility without disclosing identity attributes while keeping traded data encrypted end-to-end. (2) Constructing a zero-knowledge-based ownership lifecycle in which Merkle trees are repurposed as privacy-preserving ownership commitment structures that support unlinkable ownership proof, secure ownership transfer, and privacy-preserving traceability. (3) Designing a malleability-aware ZKP execution framework for Groth16 proofs, implemented via dedicated “anti-malleability” contracts that bind proofs to ownership states, fresh randomness, and protocol stages, thereby mitigating proof malleability and unsafe reuse across the registration–sale–transfer lifecycle. (4) Integrating a trusted regulatory authority into the architecture to enable compliant yet anonymous audits and formulate a system-wide privacy framework covering identity, data, ownership, behavioral, and audit dimensions. Experimental results demonstrate that the system achieves strong privacy guarantees and low on-chain overhead, offering a more robust and privacy-centric approach to data transactions than existing solutions.

Blockchain Technology Applications and Security
Cryptography and Data Security
Distributed systems and fault tolerance
Original source
Mar 27, 2026·Zenodo (CERN European Organization for Nuclear Research)
2 cites
A Formal Analysis of Tangible Encryption: Non-Fungible Tokens as Persistent, Ownable Roots of Trust in Secrets Management Systems

Brandon Husbands, Witchborn Systems

Tangible Encryption is a cryptographic framework that replaces the “secret zero” bootstrap problem in secrets management with a verifiable, identity-based trust model. Instead of requiring an antecedent credential to access protected secrets, this approach binds access control to ownership of a persistent cryptographic token (e.g., an NFT), enabling authentication through proof of ownership rather than shared knowledge. This work formalizes the use of non-fungible tokens as ownable roots of trust, where token ownership encodes identity, access rights, and provenance on a distributed ledger. A deterministic key derivation model is introduced, allowing secrets to be encrypted and decrypted without transmitting or storing a traditional master secret. Verification is performed via cryptographic signatures and on-chain state checks, eliminating circular trust dependencies inherent in systems such as Vault, SOPS, and cloud KMS. The framework is evaluated in the context of AI systems, including model provenance, secure dataset access, and autonomous agent authentication across organizational boundaries. Security considerations such as key compromise, revocation, and ledger integrity are analyzed, alongside implementation tradeoffs between public and permissioned ledgers. Tangible Encryption establishes a portable, verifiable trust anchor that operates independently of any single platform or identity provider, unifying identity, access control, and auditability into a single cryptographic primitive.

Open access
2 source records
Cryptography and Data Security
Blockchain Technology Applications and Security
Physical Unclonable Functions (PUFs) and Hardware Security
Original source
Mar 26, 2026·arXiv (Cornell University)
0 cites
zk-X509: Privacy-Preserving On-Chain Identity from Legacy PKI via Zero-Knowledge Proofs

Yeongju Bak

Public blockchains impose an inherent tension between regulatory compliance and user privacy. Existing on-chain identity solutions require centralized KYC attestors, specialized hardware, or Decentralized Identifier (DID) frameworks needing entirely new credential infrastructure. Meanwhile, over four billion active X.509 certificates constitute a globally deployed, government-grade trust infrastructure largely unexploited for decentralized identity. This paper presents zk-X509, a privacy-preserving identity system bridging legacy Public Key Infrastructure (PKI) with public ledgers via a RISC-V zero-knowledge virtual machine (zkVM). Users prove ownership of standard X.509 certificates without revealing private keys or personal identifiers. Crucially, the private key never enters the ZK circuit; ownership is proven via OS keychain signature delegation (macOS Security.framework, Windows CNG). The circuit verifies certificate chain validity, temporal validity, key ownership, trustless CRL revocation, blockchain address binding, and Sybil-resistant nullifier generation. It commits 13 public values, including a Certificate Authority (CA) Merkle root hiding the issuing CA, and four selective disclosure hashes. We formalize eight security properties under a Dolev-Yao adversary with game-based definitions and reductions to sEUF-CMA, SHA-256 collision resistance, and ZK soundness. Evaluated on the SP1 zkVM, the system achieves 11.8M cycles for ECDSA P-256 (17.4M for RSA-2048), with on-chain Groth16 verification costing ~300K gas. By leveraging certificates deployed at scale across jurisdictions, zk-X509 enables adoption without new trust establishment, complementing emerging DID-based systems.

Open access
3 source records
Security and Verification in Computing
Blockchain Technology Applications and Security
Cryptography and Data Security
Original source
Mar 25, 2026·Journal of risk and financial management
1 cites
Financial Document Authentication and Verification Using Hierarchical Tokenization on Permissioned Blockchains

Chialuka Ilechukwu, Sungchul Hong, Barin N. Nag

Document authentication remains a pressing challenge in various domains, including financial services, academic credentialing, healthcare, and supply chain management. Existing centralized verification systems are vulnerable to manipulation, inefficiency, and limited transparency. Blockchain technology, with its immutability and tamper-resistant capabilities, offers a strong decentralized alternative; however, many current implementations lack structured, issuer-bound relationships for documents. This paper proposes a blockchain-based model that leverages a hierarchical token structure to authenticate and trace the provenance of high-value digital documents, with a focus on financial records. The model introduces the concept of an issuer-bound parent token and document-linked child tokens, enforcing a structured trust relationship between a legitimate institution and the documents it issues. By combining on-chain cryptographic hashing with off-chain file references, the approach is designed to balance verifiability with scalability. We implement a proof-of-concept using Ethereum-compatible smart contracts on a permissioned blockchain and evaluate it in a consortium-style financial setting. Our functional analyses demonstrate the model’s ability to ensure document integrity, provenance, and resistance to document fraud. This work offers a practical and extensible foundation for secure digital document authentication and verification in financial and other trust-sensitive settings.

Open access
Blockchain Technology Applications and Security
Cryptography and Data Security
Advanced Steganography and Watermarking Techniques
Original source
Mar 25, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
Hash-Chained Append-Only Ledgers as a Lightweight Tamper-Evidence Primitive for Remote E-Voting: A Game-Based Security Analysis

Tzanko Golemanov, Emilia Golemanova

Abstract: Remote electronic voting systems require tamper-evident records of ballot submissions, yet the ledger integrity problem - ensuring that the record cannot be silently altered after the fact - has received less formal treatment than ballot-phase cryptography. Existing approaches rely on distributed blockchain consensus, digital signatures on bulletin boards, or external hash-tree timestamping services, each introducing dependencies on specialized infrastructure, continuously trusted parties, or computationally intensive proof systems. This paper provides a formal security analysis of a hash-chained append-only ledger instantiated in a standard relational database with quorum replication, establishing that equivalent tamper-evidence guarantees are achievable under the sole assumption of collision resistance of the instantiated hash function. We define five security properties in the Bellare-Rogaway game-based framework. Tamper-evidence (Proposition 1) bounds any PPT adversary's advantage at 2q(λ) · Adv^CR_H, with a tight reduction to collision resistance. Fork-resistance (Proposition 2) establishes that an adversary corrupting fewer than a quorum threshold of replicas cannot cause divergent chain histories at honest replicas. Retrospective modification resistance (Proposition 3) establishes that post-close modifications are detectable by any auditor holding a real-time replica copy. Cross-ledger binding security (Proposition 4) extends these results to the dual-ledger construction of the Arcaunt architecture, in which a public ballot ledger and a temporal credential ledger are cryptographically bound at insert time, making modifications to either detectable through the other with advantage bounded by 4q(λ) · Adv^CR_H. Selector integrity (Proposition 5) establishes that the last-valid-vote rule - operating on insertion sequence rather than timestamps, making it immune to clock manipulation - is integrity-secure conditional on credential security, formally delineating the boundary between ledger and credential security domains. We apply an eight-metric comparative framework to seven e-voting integrity architectures - hash-chaining, bulletin boards, homomorphic tallying, mixnet-based systems, blockchain, KSI timestamping, and VVPAT hybrids - establishing three findings: tamper-evidence basis is universal but mechanism-specific; fork-resistance is architecturally necessary specifically for revoting-based systems; and auditability complexity is inversely correlated with cryptographic sophistication. The hash-chained relational ledger achieves collision-resistance-based tamper-evidence with O(n) verification accessible to any SQL-capable auditor - a design point unoccupied by existing systems under the same combination of properties. Prototype validation on a Firebird 5.0 implementation confirms that each proposition is instantiated by a specific database trigger mechanism, with 6ms mean ballot submission latency and O(n) verification complexity empirically confirmed.

Open access
2 source records
Internet Traffic Analysis and Secure E-voting
Blockchain Technology Applications and Security
Security and Verification in Computing
Original source
Mar 25, 2026·IEEE Transactions on Dependable and Secure Computing
0 cites
S-Auth: Schnorr-Enhanced Authentication Scheme for Security and Efficiency in Blockchain Web3.0

Jangho Na, Hoh Peter In

Web3 authentication stacks largely inherit ECDSA centric single-signature workflows that limit security and efficiency, while custody of identity data often remains application controlled rather than self-sovereign. We present S-Auth, an authentication layer that combines BIP340 Schnorr signatures with Decentralized Identifiers (DID), Verifiable Credentials (VC), and Content addressing (CID). The proposed solution utilizes Schnorr digital signatures, which have demonstrated improved security and efficiency over traditional schemes. The contributions of this work are as follows. Firstly, we apply the BIP340 standard to Schnorr digital signatures, bolstering security against various attacks including strong unforgeability under chosen message attack (SUF-CMA), non-malleability, linearity, related-key at tacks, hash collision, fault injection, nonce exfiltration, resource exhaustion, and domain separation. Secondly, we leverage the linearity property of Schnorr signatures to enable multi-signature aggregation and batch verification, addressing the inefficiency of existing schemes that rely on single signatures and thereby also enhancing privacy. Third, we combine the blockchain with DID, VC, and IPFS to provide a secure and self-sovereign identity that can be authenticated. Experiments comparing ECDSA, Ed25519, Schnorr, and BIP340 show that S-Auth reduces signature artifacts via aggregation, improves verifier throughput with batching, and decreases anchoring overhead while preserving user-controlled identity. S-Auth provides a self-sovereign, efficient, and secure authentication mechanism suitable for Web3 environments.

Open access
Blockchain Technology Applications and Security
Advanced Authentication Protocols Security
Cryptography and Data Security
Original source
Mar 24, 2026·Scientific Reports
0 cites
Post-quantum secure server-aided password-based authentication using Module-LWE

Shanu Poddar, Sai Sandilya Konduru, Sweta Mishra

Password-based authentication systems remain the most widely used method for user verification despite being highly susceptible to offline dictionary attacks. To mitigate such attacks, server-aided password-based authentication schemes utilize an independent server, which helps to harden the credentials to be stored on the website database. Existing server-aided password-based authentication schemes rely on number-theoretic assumptions that are vulnerable to quantum-enabled adversaries and incorporate complex computations such as bilinear pairings, exponentiation, and Zero-Knowledge Proofs. In this work, we introduce a novel post-quantum secure server-aided password-based authentication scheme based on the Module Learning With Errors (M-LWE) problem. A defining feature of our protocol is its complete operational transparency as it integrates with existing web interfaces without requiring users to modify their login behaviour or perform additional computation. To ensure long-term resilience, our scheme includes a transparent key rotation mechanism that allows service providers to update the entire credential database with a fresh secret key without user intervention. We provide a formal security analysis in the Real-or-Random (RoR) framework. This analysis demonstrates that our protocol's resistance to offline dictionary attacks reduces to the underlying hardness of the M-LWE problem, and the system achieves forward secrecy through a key rotation mechanism. Through an optimized Number Theoretic Transformation (NTT)-based implementation for faster polynomial multiplications, our empirical analysis demonstrates high computational efficiency, with average registration and authentication latencies of 0.88 ms and 0.96 ms, respectively.

Open access
2 source records
Cryptography and Data Security
Advanced Authentication Protocols Security
User Authentication and Security Systems
Original source
Mar 23, 2026·Proceedings of the 41st ACM/SIGAPP Symposium on Applied Computing
0 cites
zkA3: Zero-Knowledge Address Abstraction with Auditability for Cross-Chain Identity Management

Jae Hyun Choi, Geontae Noh, Ji Young Chun, Ik Rae Jeong

Regulatory frameworks like MiCA mandate KYC and auditability for stablecoins, but existing solutions fail to simultaneously achieve privacy, compliance, and cross-chain compatibility. We propose zkA3 (Zero-Knowledge Address Abstraction with Auditability), enabling users to generate pseudonymous identifiers from web2 certificates with unlinkability guarantees while incorporating encrypted audit tokens for authorized identity tracing. We formally prove five security properties: pseudonymity, unlinkability, zero-knowledge authentication, auditability, and cross-chain consistency. Our implementation achieves 29.8ms proof generation with 9,917 constraints, demonstrating practical feasibility. zkA3 is the first scheme simultaneously supporting privacy-preserving cross-chain stablecoin operations and regulatory compliance.

Open access
Cryptography and Data Security
Access Control and Trust
Blockchain Technology Applications and Security
Original source
Mar 23, 2026·IEEE Transactions on Dependable and Secure Computing
1 cites
Smart Contracts - Cloud Storage-Assisted Medical Image Encryption and Sharing Solution

Jianmeng Liu, Zhenlong Man

To address the security risks in sharing medical imaging data and the challenges of insufficient data interoperability between heterogeneous systems, and to achieve secure sharing of medical information across institutions, this paper proposes a secure encryption scheme based on the characteristics of medical images, and uses cloud storage and smart contracts to build a secure framework for cross-institutional information sharing. First, in response to the regional characteristics and uneven information distribution of medical images, an innovative two-stage encryption scheme of “partitioning, diffusion, and coupled scrambling” is proposed. The first stage applies information entropy equalisation processing to non-ROI regions, enhancing their information effectiveness and generating dynamic parameters. The second stage utilises the cross-region coupling dynamic parameters generated in the first stage to optimise the encryption results within ROI regions. Finally, a key driven scrambling factor is employed to complete the global pixel position reconstruction, achieving high-security encryption. Each medical institution encrypts medical images and uploads them to unified cloud storage, along with binary thumbnails generated from the corresponding plaintext images. Simultaneously, essential metadata—including image hash values, ownership details, and access permission policies—is stored on the blockchain. After an authorized user selects the desired data by browsing cloud thumbnails, a smart contract automatically executes the transaction, completing on-chain permission verification, data traceability, and access authentication, thereby coordinating the user's secure access to the corresponding encrypted image data off-chain. Eight experiments have demonstrated the security of the encryption scheme and the proposed sharing framework.

Cryptography and Data Security
Blockchain Technology Applications and Security
Cloud Data Security Solutions
Original source
Mar 23, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
ZKP Banking Interface: A Privacy-Preserving, Context-Aware Authentication System Using Zero-Knowledge Proofs

Mr. Utsav Pandey, Ms. Sania Parkar, Mr. Anant Sarode, Prof. Amit Chakrawarti

Traditional banking systems rely on passwords, PINs, and centralized biometric storage, exposing users to phishing, SIM-swap attacks, and credential reuse vulnerabilities. This paper presents the ZKP Banking Interface, a pinless, context-aware financial authentication system built on Zero-Knowledge Proof (ZKP) technology. A unified ZK-SNARK circuit (Groth16), implemented in Circom, encodes three simultaneous security factors: identity commitment, trusted network context, and transaction threshold logic using Poseidon hashing. Conditional biometric and puzzle challenges are enforced cryptographically for higher-risk scenarios. Proof generation and verification are fully automated within the browser using snarkJS and WebAssembly artifacts, eliminating manual proof handling. The system supports two verification modes: local (device-only privacy) and on-chain (public auditability via a Solidity smart contract on a Hardhat network). Experimental evaluation across five test scenarios confirms correct contextual policy enforcement, successful proof validation in both modes, and a smooth, practical banking user experience. The proposed system demonstrates that ZKP-based authentication can replace traditional credentials while maintaining strong privacy guarantees.

Open access
2 source records
Cryptography and Data Security
Blockchain Technology Applications and Security
Advanced Authentication Protocols Security
Original source
Mar 23, 2026·Proceedings of the 41st ACM/SIGAPP Symposium on Applied Computing
0 cites
RepStake: A Blockchain-Based Trust System with Reputation Staking

Dimitris Mantzonis, Thanasis G. Papaioannou

Reputation systems are fundamental to fostering trust and cooperation in digital environments, yet existing solutions often struggle with centralization, vulnerability to manipulation, and limited portability. Centralized reputation platforms can be opaque, censored and susceptible to become single points of failure, while decentralized ones face challenges, such as Sybil attacks, malicious strategies (e.g., ballot stuffing, bad-mouthing) exercised by entities of high influence, i.e. "whales", and privacy concerns. This paper addresses these persistent issues by proposing a blockchain-based reputation framework that integrates robust identity verification, square root voting constraints, and dynamic stake-based incentives. Rating power is linked to the reputation of the rater that puts its reputation at stake. The model aims to ensure that reputation is earned and maintained through verifiable, community-aligned actions, while simultaneously limiting the potential for abuse by malicious actors or disproportionately influential participants. By leveraging decentralized identifiers, zero-knowledge proofs, and transparent incentive mechanisms, the proposed system seeks to balance transparency, fairness, and privacy. Extensive simulation experiments prove that the approach is effective to reveal the true quality of entities, even in presence of 49% colluding voters. The approach is designed to be adaptable across diverse domains, ranging from marketplaces and collaborative platforms to decentralized finance and governance.

Open access
Blockchain Technology Applications and Security
Access Control and Trust
Cryptography and Data Security
Original source
Mar 23, 2026·Proceedings of the 41st ACM/SIGAPP Symposium on Applied Computing
0 cites
TLS2VC: A Decentralized WebProof Framework Enabling Verifiable Credentials for TLS Sessions

Haocheng Jiang, Iifan Tyou, K. Matsuura

This work proposes TLS2VC, a decentralized WebProof framework that distributes trust across multiple Notaries. Notaries attest to TLS session authenticity—server identity and encrypted transcript integrity—without accessing plaintext, then issue Verifiable Credentials (VCs) that Verifiers can validate. To prevent concentration of malicious Notaries, we employ verifiable random selection via Verifiable Random Function (VRF) combined with threshold signatures. We provide probabilistic security analysis showing that honest Notaries are included with high probability, and derive formulas to compute the minimum number of Notaries k required for a target security level. A lightweight prototype demonstrates practical feasibility, enabling reuse of existing web information as trusted credentials in Web3 and self-sovereign identity environments.

Open access
Cryptography and Data Security
Access Control and Trust
Blockchain Technology Applications and Security
Original source
Mar 21, 2026·Scientific Reports
1 cites
Blockchain-based two-level trustable reputation framework for e-commerce platform using smart contracts

K. Sundara Krishnan, R. Chithra Devi, Christo Ananth, D. Easwaramoorthy · 8 authors

E-commerce platforms incorporate reviews and reputation systems, allowing retailers and customers to manage and track their financial transactions. Consequently, it is crucial to design a reliable reputation system for the e-commerce environment, as it faces well-documented threats, including sybil attacks, feedback collusion, impersonation, review tampering, and whitewashing attacks. Current centralized systems are vulnerable to impersonation attacks, feedback manipulation, and lack automated verification against collusion-based reputation distortion. These unwanted ratings and reviews are highly correlated with abnormal cyber-attacks that damage both seller reputations and buyer experiences. To address these challenges, we propose a Blockchain-based Two-Level E-Commerce Trustable Reputation Framework (BTL-ETRF) utilizing deep learning-embedded transformers and redactable blockchain systems. Initially, we implement Multi-Factor Authentication for e-commerce users, utilizing three factors: PIN, OTP, and biometric fingerprint, to mitigate impersonation attacks. Only authenticated users are allowed to proceed to the reputation verification stage, where the proposed work considers five major metrics to classify user reputation using the Residual Dilated Convolution Transformer. To automate the reputation verification process, we design and employ two smart contracts, the Authentication Smart Contract and the Reputation Smart Contract which trigger automated actions based on the BTL-ETRF results. All transactions include reputation classification, and triggered actions are stored in the redactable blockchain, which can modify the stored transactions if needed. Finally, we demonstrate the performance of the proposed BTL-ETRF using Python and Ethereum Solidity, and conduct a formal analysis that shows the proposed model outperforms the compared works.

Open access
Blockchain Technology Applications and Security
Access Control and Trust
Cryptography and Data Security
Original source
Mar 21, 2026·American Journal of AI Cyber Computing Management
0 cites
QuantumMedLedger: A Post-Quantum Secure Blockchain Framework for Healthcare

Pasupunooti Anusha, Nallabelly Nithin, Mamidala Nandha Kishori, Miriyala Sriram Reddy · 5 authors

The rapid adoption of digital healthcare systems has significantly increased the use of Electronic Health Records (EHR), online appointment platforms, and digital prescription management. While these technologies enhance accessibility and operational efficiency, they also introduce critical challenges related to data confidentiality, secure authentication, record integrity, and protection against unauthorized access. Healthcare data contains highly sensitive personal and medical information, making security a primary concern. Ensuring secure communication and verified access between patients and doctors remains a major challenge in maintaining trust and privacy within digital healthcare environments. Many existing healthcare management systems rely on centralized storage models and basic authentication mechanisms, exposing them to risks such as data breaches, impersonation attacks, and unauthorized record modification. Although basic encryption mechanisms may be applied to protect stored data, key management and authentication processes often rely on standard approaches without decentralized verification or advanced cryptographic reinforcement. As a result, centralized architecture creates a single point of failure, increasing vulnerability to unauthorized access, data tampering, and weak identity verification. Limited transparency and auditability further restrict effective monitoring of data usage and system activities. To address these issues, the proposed system introduces Quantum Crypt (QC), a hybrid security approach that integrates blockchain technology with Post-Quantum Cryptography (PQC) concepts and advanced encryption mechanisms. Medical reports and prescriptions are secured using the Advanced Encryption Standard in Cipher Block Chaining mode (AES-CBC), with encryption keys generated through a quantum-inspired mechanism. Authentication is enhanced through a lattice-inspired model implemented via Qiskit-based quantum circuit simulation to ensure secure key validation between patients and doctors. Blockchain integration using Web3 and smart contracts ensures immutable storage of healthcare records, improving transparency, strengthening data integrity, and enabling controlled access within the digital healthcare ecosystem.

Open access
Blockchain Technology Applications and Security
Cryptography and Data Security
Cloud Data Security Solutions
Original source
Mar 20, 2026·Open MIND
0 cites
Dual-Mode Blockchain Based Auction System for Secure and Anonymous Bidding

Vaishnavi K, Santhiya S, Ashvitha S, Anusha D

Traditional selling systems often limit products to local markets and rely heavily on intermediaries, resulting in reduced profit margins, inconsistent quality, and limited market reach. Maintaining consistent quality and ensuring market transparency remain significant challenges in these legacy frameworks. To address these issues, this project proposes a secure and efficient Double Auction System for multi-category product trading. To enhance security, privacy, and trust, the project integrates advanced cryptographic mechanisms. zk-SNARKs (Zero-Knowledge Succinct Non- Interactive Arguments of Knowledge) are employed for sealed bidding, ensuring that both bidder identities and bid values remain hidden while maintaining mathematical verifiability. Conversely, Linked Ring Signatures are used for open bidding, allowing bid values to remain transparent while masking the identities of the bidders. A Commit-Reveal Scheme is implemented to prevent bid manipulation and ensure fairness during the submission phase. Additionally, a Reputation Score Algorithm incentivizes honest participation by rewarding users with a trust score based on their historical behavior. Finally, Blockchain technology is integrated via a private blockchain to record all auction data and reports in an immutable and tamper-proof manner. This multi-layered approach ensures a fair, secure, and sustainable trading ecosystem, benefiting both producers and buyers across diverse sectors.

Open access
2 source records
Blockchain Technology Applications and Security
Auction Theory and Applications
Cryptography and Data Security
Original source