Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

886 papersLast indexed Aug 31, 2026
Search papers

Paper index

886 results ยท page 2 of 37

Clear filters
Jul 5, 2026ยทZenodo (CERN European Organization for Nuclear Research)
0 cites
Cross-Agent Governance Alignment (CAGA): Formalizing Cross-Organizational AI Governance as a Zero-Knowledge Coordination Problem

Edward Meyman

Cross-Agent Governance Alignment (CAGA): Verifiable Coordination Across Private AI Governance Domains formalizes the CAGA problem: establishing a declared compatibility relation between AI governance domains across organizational boundaries without disclosing the proprietary policy content on which each domain relies. Cross-organizational agent interaction creates two distinct governance questions: whether each local effect-bearing action is authorized within its own domain, and whether the participating domains can establish the declared relation. This paper formalizes the second problem. CAGA does not itself authorize execution. It produces a privacy-preserving compatibility result and associated evidence that each domain's runtime authorization boundary may materially consume before emitting its own action-bound verdict and authorization artifact. The formal model defines a governance domain as agents, a declared effect-bearing action vocabulary, versioned policy and authority state, governance-relevant state, a material evidence set, and a runtime authorization boundary over the triadic verdict space (ALLOW, DENY, ABSTAIN), where unresolved ABSTAIN remains ABSTAIN and authorized resolution produces a separate resulting action-bound verdict through the boundary. Every CAGA claim is scoped to a declared profile identifying the participating domains and authority roots, action vocabulary, compatibility relation and version, commitments, temporal boundary, leakage profile, scheme and verification parameters, declared replay mode, failure treatment, and expected local-boundary consumption. The Boolean compatibility relation is separated from protocol status: the protocol output comprises a result that may be positive, negative, or unresolved, together with the proof or verifier record and a CAGA evidence artifact. An unresolved result is not a verdict, and neither a negative nor an unresolved result may be treated as affirmative CAGA support for ALLOW. An illustrative prior-authorization compatibility relation between a hospital domain and an insurer domain, together with a worked local-boundary consumption sequence, shows the level at which a CAGA proposition may be stated without disclosing a protocol construction; no execution path originates from CAGA. The paper: Separates local pre-execution authorization from cross-domain compatibility evidence, and reserves the term authorization artifact for the action-bound record emitted by a runtime authorization boundary; a CAGA result may participate in composed authorization only where the Composition Test is satisfied; the CAGA evidence artifact does not thereby become an authorization artifact Formalizes the declared compatibility relation and protocol output under a declared CAGA profile, with cross-domain interactions whose local actions need not be identical, and supplies a terminology and instrument-ownership map locating each evidentiary term in its owning instrument States the threat model with honest-but-curious as the base analytic assumption rather than a prediction about regulated parties, classifies an expanded threat inventory as covered, partially covered, or excluded, and treats Byzantine deviation, arbitrary collusion, and malicious-verifier behavior as outside the base claim, requiring separately specified protocol defenses Identifies the required properties of a declared CAGA protocol: relation completeness and soundness, declared-leakage privacy, deterministic relation result with permitted cryptographic randomness, evidence and reconstruction sufficiency under the declared replay mode, commitment and domain binding, repeated-interaction privacy, optional post-compromise transcript confidentiality, non-authorizing failure, evidence traceability and presentation scope, declared-regime scope, and Input Integrity support, where provenance establishes origin, not truth Restructures the prior-art analysis as a component-and-gap assessment across communication protocols including the current Model Context Protocol specification (2026-07-28), policy composition and distributed authorization, secure multi-party computation and zero-knowledge systems, selective-disclosure credentials, multi-agent and agent-action governance architectures, and ledger approaches, identifying CAGA as the residual problem after those contributions are accounted for Zero-knowledge proof systems, secure multi-party computation, private set intersection, trusted execution, commitment schemes, and selective disclosure are candidate implementation substrates rather than authorization substitutes; no component establishes CAGA or authorization by label alone. The analysis is aligned with the Authorization Artifact Test v1.2, the Authorization Boundary Integrity Model v1.1, the Five Tests Standard v1.2.0, the ABIM Evidence Requirements v3.5, the Closed-World Bargain v1.1, and the Override Asymmetry v2.0. The paper does not assert that any jurisdiction requires CAGA, zero-knowledge proof, or pre-execution authorization, and it deliberately stops at problem formalization: it does not disclose protocol constructions, circuits, trusted-setup designs, or implementation mechanisms. The paper does not present an ideal functionality, security reduction, theorem establishing a protocol construction, or deployable implementation. By defining the problem space and evaluation criteria within a declared closed world, it provides a structured problem specification against which candidate cross-domain coordination protocols and their composition with local runtime authorization boundaries can be assessed. Version 2.0 (August 2026) separates cross-domain compatibility evidence from local pre-execution authorization; replaces the governance-domain enforcement function with a runtime authorization-boundary model; distinguishes the Boolean compatibility relation from unresolved protocol status; defines a declared CAGA profile; separates CAGA evidence artifacts from local authorization artifacts; conditions determinism on declared decision state while permitting cryptographic randomness; replaces default-denial protocol failure with non-authorizing unresolved status; adds an explicit interface to local Input Integrity assessment, authenticated bound materials, replay-mode, closed-world, Composition Test, and authorized-resolution semantics; narrows legal and regulatory claims; updates MCP and multi-agent prior-art references; and restructures the prior-art analysis as a component-and-gap assessment. Version 2.0 also adds an illustrative prior-authorization compatibility relation and a worked local-boundary consumption sequence; clarifies that the paper specifies a formal problem rather than presenting an ideal functionality, security reduction, or protocol proof; adds a terminology and instrument-ownership map; expands the component-and-gap analysis to address policy composition, distributed authorization, selective-disclosure credentials, and recent agent-action governance work; and clarifies the relationship between the paper's CC BY 4.0 copyright license and unlicensed patent rights. It supersedes Version 1.1 (July 2026), which aligned terminology with 5TS v1.2.0 and the FERZ authorization-artifact vocabulary, and Version 1.0 (February 2026), the original problem formalization. Keywords: cross-agent governance alignment, cross-organizational AI governance, private governance domains, privacy-preserving coordination, runtime authorization boundary, pre-execution authorization, authorization artifacts, zero-knowledge proofs, secure multi-party computation, Input Integrity, independent reconstruction

Open access
3 source records
Blockchain Technology Applications and Security
Access Control and Trust
Multi-Agent Systems and Negotiation
Original source
Jul 1, 2026ยทOpen MIND
0 cites
Credentials and Triangulated Trust Signals on a Single Accountable Identifier: A Hash-Anchored Distributed-Ledger Framework for Portable Identity across Jurisdictions

Walter Kurz

Digital identity remains structurally rigid when it is bound to provider accounts, mutable handles, single social contexts, and local wallet schemes. This paper defines an accountable hash-anchor tier above wallets and credential schemes. Building on a companion model of legal identity assurance, the tier binds an inert root anchor to an event-backed Entity Actor Identity (EAID) assurance state, supports unlinkable profile anchors for distinct contexts, and lets relying parties evaluate gate-specific assurance-at-time over disclosed independent confirmation-event clusters. The formal model states the identifier and capability separation invariant, defines root and profile anchors, models disclosure and lawful resolution as constraints, and gives a two-layer erasure construction for retained commitments and off-chain personal linkage. It also models trust as a reliance event in which pseudonymous interaction becomes rational when a presentation satisfies the requested gate and recourse can reach the legally relevant imputation point. The result is a scheme-agnostic aggregation layer that complements national wallets, supports natural, juridical, and machine actor constellations, and states conditions under which pseudonymity, lawful access, data erasure, and retention can be jointly satisfied.

Open access
2 source records
Access Control and Trust
Cloud Data Security Solutions
Blockchain Technology Applications and Security
Original source
Jul 1, 2026ยทOpen MIND
0 cites
Identity-Staked Consensus and Collusion Resistance in Chartered Validator Sets: A Trust Model for Decentralised and Compliant Distributed Settlement Infrastructure

Walter Kurz

Permissioned ledgers are commonly treated as centralised because admission is restricted. This paper separates permissioning from control distribution and proposes identity-staked consensus as a trust model for accountable settlement ledgers operated by chartered validators. The model treats validator identity as externally costly collateral: public legal identity, charter state, institutional reputation, liability, attributable audit exposure, a phase-indexed conditional identity-loss floor, and loss-realisation channels outside the protocol. It distinguishes this construct from proof-of-authority by formalising validator acts as actor constellations, public validator anchoring, affiliation-aware voting caps, threshold class coverage, per-member collusion margins, observer-supported detectability, bootstrap claim discipline, and a consensus/application enforcement boundary. The paper connects the model to a broader identity-infrastructure series: the actor-assurance paper supplies capability-gate evidence, the trust-anchor paper supplies public validator anchoring and assurance-at-time, and the delegated-authority paper can consume the ledger evidence record for mandate and model-attribution records.

Open access
2 source records
Access Control and Trust
Internet Traffic Analysis and Secure E-voting
Smart Grid Security and Resilience
Original source
Jun 30, 2026ยทThe Journal of Korean Institute of Information Technology
0 cites
A Zero-Knowledge Proof-based Telemetry Data Integrity Mechanism for Policy Compliance Verification

Jinsu Kim, Eunsun Choi, Namje Park

ํ…”๋ ˆ๋ฉ”ํŠธ๋ฆฌ ๋ฐ์ดํ„ฐ์˜ ๋ฌด๊ฒฐ์„ฑ์€ ์ž๋™ํ™”์™€ ์•ˆ์ „ ์˜์‚ฌ๊ฒฐ์ •์˜ ํ•ต์‹ฌ ๊ธฐ๋ฐ˜์ด์ง€๋งŒ, ๊ธฐ์กด ๋ฐฉ์‹์€ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ์‹ ๋ขฐ์™€ ์›์‹œ๋ฐ์ดํ„ฐ ๋ณด๊ด€์— ์˜์กดํ•˜์—ฌ ํ”„๋ผ์ด๋ฒ„์‹œ ๋ณดํ˜ธ์™€ ๊ฐ์‚ฌ ๊ฐ€๋Šฅ์„ฑ ์ธก๋ฉด์—์„œ ํ•œ๊ณ„๋ฅผ ๊ฐ€์ง„๋‹ค. ์ด์— ๋ณธ ๋…ผ๋ฌธ์€ ๊ฐ’์„ ๊ณต๊ฐœํ•˜์ง€ ์•Š๊ณ  ์ •์ฑ… ์ค€์ˆ˜ ์—ฌ๋ถ€๋ฅผ ์ž…์ฆํ•  ์ˆ˜ ์žˆ๋Š” ์˜์ง€์‹์ฆ๋ช… ๊ธฐ๋ฐ˜์˜ ๋ฌด๊ฒฐ์„ฑ ๋ฉ”์ปค๋‹ˆ์ฆ˜์„ ์ œ์•ˆํ•œ๋‹ค. ์ œ์•ˆ๋œ ๋ฉ”์ปค๋‹ˆ์ฆ˜์€ ์ปค๋ฐ‹, ์ฆ๋ช…, ์˜จ์ฒด์ธ ๊ฒ€์ฆ, ์ •์ฑ… ๋ฒ„์ „ ์•ต์ปค๋ง, ์ง‘๊ณ„ ์šด์šฉ์„ ๋‹จ์ผ ์ ˆ์ฐจ๋กœ ํ†ตํ•ฉํ•˜์—ฌ, ๋ฐ์ดํ„ฐ ๋…ธ์ถœ ์—†์ด ์ •์ฑ… ์ค€์ˆ˜ ํŒ์ •๊ณผ ์žฌํ˜„ ๊ฐ€๋Šฅํ•œ ๊ฐ์‚ฌ๋ฅผ ๊ฐ€๋Šฅํ•˜๊ฒŒ ํ•œ๋‹ค. ๋˜ํ•œ ๋ธ”๋ก์ฒด์ธ์— ํŒ์ • ๊ฒฐ๊ณผ์™€ ์ •์ฑ… ๋ฒ„์ „์„ ๊ธฐ๋กํ•˜์—ฌ ํŒ์ •์˜ ๋ถˆ๋ณ€์„ฑ๊ณผ ์žฌํ˜„์„ฑ์„ ํ™•๋ณดํ•˜๊ณ , ์ง‘๊ณ„ ์ฆ๋ช…์„ ํ†ตํ•ด ๋‹ค๊ฑด ์ œ์ถœ์˜ ๊ฒ€์ฆ ํ˜ธ์ถœ์„ ์ค„์—ฌ ๊ฒ€์ฆ ํšจ์œจ์„ฑ์„ ํ–ฅ์ƒ์‹œํ‚จ๋‹ค. ๊ฒฐ๊ณผ์ ์œผ๋กœ ๋ณธ ๋…ผ๋ฌธ์€ ๋ฐ์ดํ„ฐ ๋ฌด๊ฒฐ์„ฑ, ํ”„๋ผ์ด๋ฒ„์‹œ, ๊ฐ์‚ฌ ๊ฐ€๋Šฅ์„ฑ, ๋น„์šฉ ํšจ์œจ์„ฑ์„ ๋™์‹œ์— ์ถฉ์กฑํ•˜๋Š” ์ƒˆ๋กœ์šด ํ…”๋ ˆ๋ฉ”ํŠธ๋ฆฌ ์‹ ๋ขฐ ๋ชจ๋ธ์„ ์ œ์‹œํ•œ๋‹ค.

Access Control and Trust
Security and Verification in Computing
Data Quality and Management
Original source
Jun 29, 2026ยทarXiv (Cornell University)
0 cites
Rethinking Collaborative Trust for Verifiably Decentralized Blockchain Systems

Yunqi Zhang, Shaileshh Bojja Venkatakrishnan

Despite the promise of decentralization, measurement studies have identified a conspicuous lack of decentralization in blockchains. Centralization has been observed in almost all layers of the blockchain, in decentralized applications, and in decentralized autonomous organizations. In many cases, it is practically impossible to definitively determine the extent of centralization in the system. While multiple works have proposed methods to decrease centralization, by and large blockchains continue to be significantly centralized. In this paper, we develop a general framework for building verifiably decentralized blockchain systems. Our framework is motivated by the core observation that the richness and diversity of collaborative interactions between users -- rather than resource uniformity -- captures the essence and extent of decentralization in a blockchain system. Existing blockchains do not have any incentive mechanisms to encourage inter-coalition collaboration, which directly contributes to centralization. We propose a novel reward design that incentivizes users to collaborate with other users without forming isolated coalitions. Technically, our method uses a Sybil-resistant asymmetric Shapley value for reward attribution within a collaboration group, and the theory of expander graphs for measuring and enforcing decentralization. Our framework is general and can be adapted to alleviate centralization in any layer, application, or decentralized organization. It also has important implications beyond the topic of centralization. For example, we show that our solution can naturally address the blockchain scalability problem. We also identify a new class of decentralized collaborative applications that have hitherto been unexplored in blockchains.

Open access
3 source records
Blockchain Technology Applications and Security
Mobile Crowdsensing and Crowdsourcing
Access Control and Trust
Original source
Jun 24, 2026ยทProceedings of the 31st ACM Symposium on Access Control Models and Technologies
0 cites
SoK: Evolution, Security, and Fundamental Properties of Transactional Systems: [Systematization of Knowledge Paper]

Sky Pelletier Waterpeace, Nikolay Ivanov

Transaction processing systems underpin modern commerce, finance, critical infrastructure, and emerging Self-Sovereign Digital Identity (SSDI) protocols, yet their security has never been studied holistically across the full evolutionary arc of these systems. Over five decades, transaction processing has progressed through four distinct generations, from centralized databases, to distributed databases, to blockchain and distributed ledger technologies (DLTs), and most recently to multi-context systems that span cyber-physical components under real-time constraints. Each generation has introduced new transaction types and, with them, new classes of vulnerabilities; successful exploits now cause billions of dollars in annual losses. Despite this, security research remains fragmented by domain, and the foundational ACID transaction model has not been revisited to reflect the demands of contemporary systems.

Open access
Access Control and Trust
Biomedical Text Mining and Ontologies
AI-based Problem Solving and Planning
Original source
Jun 24, 2026ยทarXiv (Cornell University)
0 cites
Sponsored Group Signature and its Application to Privacy-preserving Guest Access in Smart Environments

Sepideh Avizheh, Reihaneh Safavi-Naini, Shiwei Sun

Group signatures are privacy preserving signature schemes in which a group member can anonymously sign messages on behalf of the group, while providing accountability, by allowing the signature of a misbehaving group member be ``opened'' and the identity of the signer be revealed. In group signature members are admitted to the group by a (trusted) group manager. We motivate the need for a flexible mechanism in applications, such as privacy preserving access in smart environments, and propose a two-level member-join group signature that we call SPonsored Group Signature (SPGS) where group members of level 1 can ``sponsor'' new members, in level 2, to join the group. This relaxation of user join comes with additional accountability mechanisms: we require that the signature of a sponsored member can be opened to the identity of the sponsor (that is sponsor is responsible for the sponsored member), and while all signatures are anonymous, for the sponsored members, the signatures are linkable. This allows a sponsor to efficiently identify an undesirable sponsored member. We formalize SPGS scheme, define its security using a game-based approach, and give a generic construction of SPGS that uses a (dynamic) group signature scheme, a commitment scheme, and a knowledge-sound non-interactive zero knowledge proof of knowledge, and prove its security. We also give an instantiation of our construction. To show applicability of SPGS in practice, we consider the problem of providing guest access in a smart building, and introduce Anonymous Guest Access Token (AGAT) that allows a temporary guest to anonymously access (a subset of) the building resources. We show how SPGS can be used (together with an IND-CPA secure public key encryption scheme) to give a direct construction for AGAT, and show the efficiency of our guest access protocol when it is instantiated with existing schemes.

Open access
3 source records
cs.CR
cs.NI
Cryptography and Data Security
Original source
Jun 24, 2026ยทarXiv (Cornell University)
0 cites
Can Trustless Agents Be Trusted? An Empirical Study of the ERC-8004 Decentralized AI Agent Ecosystem

Xihan Xiong, Zelin Li, Wei Wei, Qin Wang ยท 6 authors

As autonomous AI agents increasingly transact across organizational boundaries, a fundamental trust challenge emerges: how can an agent assess whether an unknown counterpart is trustworthy? The ERC-8004 protocol addresses this challenge with the first permissionless trust layer for AI agent economies, built around three on-chain registries for Identity, Reputation, and Validation. Despite its rapid adoption, the protocol has not been studied empirically, leaving it unclear whether the information it records provides a trustworthy basis for decision-making. To address this gap, we present the first empirical study of ERC-8004 across three chains: Ethereum, BNB Smart Chain (BSC), and Base, covering the period from protocol deployment through May 13, 2026. We crawl on-chain Identity and Reputation events, off-chain files, and x402 payment transactions. On the identity side, we find that most registrations are placeholders rather than active agents, with only a small fraction (3%, 4%, and 15% across Ethereum, BSC, and Base) exposing a valid ERC-8004 registration file with at least one live service endpoint. On the reputation side, we show that the Registry, as currently deployed, cannot function as a trust signal: values are not commensurable, feedback records are rarely grounded in verifiable interactions, and reputation can be manipulated at minimal cost. Consistent with these design weaknesses, we find that a substantial fraction of reviewers (73.5%, 59.2%, and 90.6% across Ethereum, BSC, and Base) exhibit coordinated Sybil behavior. After removing Sybil-flagged feedback, 15.8%, 77.9%, and 86.8% of rated agents, respectively, are left with no valid feedback. We then turn these findings into concrete recommendations for future revisions of ERC-8004. Our study yields actionable protocol-design implications and establishes an empirical baseline for research on AI agent markets.

Open access
3 source records
Blockchain Technology Applications and Security
Access Control and Trust
Multi-Agent Systems and Negotiation
Original source
Jun 24, 2026ยทJournal of Science and Technology on Information security
0 cites
A Novel Model of Comprehensive Data Encryption for the Website Using Blockchain

Pham Van Huong, Nguyen Ngoc Tuyen, D. H. Long, Trแบงn Quแป‘c Toanh ยท 5 authors

The paper proposes a comprehensive data security model for blockchain-based web applications. This model can be used as a general template for Web3 applications. The model consists of two parts: a blockchain core with integrated database encryption modules, replacing Fabric CA; and an application part that also integrates file encryption, database encryption, and digital signatures. The proposed model was tested on a VBCC management website using Hyperledger Fabric. File and database encryption uses AES, and digital signatures use ECDSA. To improve performance, we also replaced the GolevelDB database management system with LevelDB. Experimental results confirm the accuracy and good performance.

Open access
Cloud Data Security Solutions
Cryptography and Data Security
Access Control and Trust
Original source
Jun 23, 2026ยทApplied and Computational Engineering
0 cites
Patient-Centric Secure Medical Record Sharing on Ethereum: Topic Analysis and Proof-of-Concept

Zhe Zhang

This paper investigates Ethereum-based smart contracts as a decentralized cybersecurity governance layer for Electronic Medical Records (EMRs). It addresses challenge of fragmented healthcare data silos and strict compliance requirements for electronic protected health information (ePHI), such as HIPAA and GDPR by analyzing how blockchain technology enables explicit, patient-centric access control. Current legacy systems often centralize authorization, creating vulnerablilities. Through topic analysis and a Solidity-based Proof of Concept (PoC), the study demonstrates a hybrid architecture that uses on-chain execution for permission management while storing sensitive clinical data off-chain. The PoC shows how immutable ledger entries enforce least-privilege principles, block unauthorized queries, and provide tamper-evident auditability. The architectureโ€™s trade-offs between enhanced accountability, patient sovereignty, and practical limitations in scalability, governance, and costs are assessed. It concludes that while blockchain offers a robust trust layer, integration with off-chain interoperability standards remains essential for clinical adoption.

2 source records
Blockchain Technology Applications and Security
Cryptography and Data Security
Access Control and Trust
Original source
Jun 23, 2026ยทUnicam Scientific Publications (University of Camerino)
0 cites
"From Static to Protected and Mutable Non-Fungible Tokens:Design and Evaluation Across Usage Scenarios"

Francesco Donini

The increasing adoption of decentralised technologies, such as blockchain, is reshaping the way distributed systems are used and, in particular, how digital and physical resources are represented and managed. While tokenisation techniques have enabled the representation of unique and verifiable artefacts on the blockchain, Non-Fungible Tokens (NFTs), the most popular standards used to encode them still provide limited support for those resources that need to change over time. Updates to their content are handled through poorly structured, weakly regulated, and often opaque mechanisms, making it difficult to model assets whose lifecycle requires controlled modifications, and verifiable state transitions. This thesis addresses these limitations and introduces a conceptual and operational framework for the structured, controlled, and traceable man- agement of asset mutability within blockchain-based ecosystems running on Ethereum-compatible platforms. The proposed approach formalises the mu- tability of asset attributes, defines an explicit model for updates, and inte- grates on-chain authorisation mechanisms to ensure that every modification, every transfer and every minting operation is performed in accordance with predefined policies and in a permanently verifiable manner. The thesis defines update-control rules, more fine-grained metadata rep- resentations, and coordination schemes that enable creators, owners, and authorised actors to collaborate safely on the modification of a resource. The validity of the framework is assessed through the application of real use cases and simulation tools that analyse performance, costs, and behavioural properties, as well as the long-term sustainability in the blockchain across different scenarios. The results show that a more precise and structured treatment of muta- bility significantly enhances the expressiveness, reliability, applicability, and, iii most importantly, the intrinsic value of blockchain-based asset representa- tions. This provides a more realistic and flexible management of the lifecycle of digital resources, while opening new directions towards future develop- ments in areas such as decentralised identity, cross-chain interoperability, and distributed collaborative systems.

Blockchain Technology Applications and Security
Mobile Agent-Based Network Management
Access Control and Trust
Original source
Jun 22, 2026
0 cites
Blockchain Based Security System for Digital Health Records

J Janisha, J J Karthikeya, Shamik Prameed, Thota Jagadeesh Naidu ยท 5 authors

The Trust Revolution in Digital Health (Comprehensive)The total digitization of health care demands a fundamental change in the practice of data management, because the existing Digital Health Records (DHR) systems involve insurmountable tension between the unconditional privacy of patients and the necessity to benefit large-scale medical data utility. Although it has been demonstrated that established decentralized solutions, especially those that are based on the permissioned Hyperledger Fabric (HLF) are effective in ensuring integrity of data and basic Role-Based Access Control (RBAC), they, structurally, fall short of three important, real-life shortcomings: the inherent threat of unlimited unauthorized access, the full traceability of user identities on the unalterable ledger and the ethical stalemate regarding collaborative use of data. This paper presents a very new, integrated DHR architectural design that greatly secures the HLF core by integrating three synergistic, state-of-the-art cryptographic and privacy enhancing pillars: 1) Time-Bound Keys (T-BK) a very innovative mechanism that substitutes current access policy flags with cryptographically enabled and self revoking key mechanism to enforce granular time-sensitive access control. 2) Zero-Knowledge Proofs (ZKP) and Fabrics Transient Fields, which guarantee assured transaction unlinkability and full.

Blockchain Technology Applications and Security
Cryptography and Data Security
Access Control and Trust
Original source
Jun 22, 2026ยทZenodo (CERN European Organization for Nuclear Research)
0 cites
KENOS - The Full Spectrum Operating Environment

Ahmad Bilal Khan

KENOS โ€” Kohenoor Operating System Official Description and Public Disclosure KENOS, the Kohenoor Operating System, is the unified digital operating environment of the Kohenoor ecosystem. It brings together artificial intelligence, Education 3.0, blockchain infrastructure, hybrid finance, business applications, development tools, governance controls and operational supervision within one coordinated ecosystem. <Explainer film added> The transition from KENHYFI Hub to the broader KENOS architecture reflects the continued expansion of the Kohenoor ecosystem. KENHYFI was originally developed as a hybrid-finance and ecosystem hub. However, the name and positioning of KENHYFI did not fully represent the wider capabilities that had developed around it, particularly: KAI โ€” Kohenoor Artificial Intelligence, the ecosystemโ€™s multilayered intelligence powerhouse and orchestration system. ProEdge, the Education 3.0, professional learning and workforce-development hub. Blockchain, development, commerce, security, governance and institutional-support applications extending beyond hybrid finance. For this reason, KENOS was established as the umbrella operating environment for the complete ecosystem. KENHYFI remains an important integrated hub within KENOS, but it no longer represents the entire ecosystem by itself. The relationship is therefore defined as follows: KENOS is the complete Kohenoor Operating System and umbrella ecosystem. KAI is the principal intelligence and orchestration powerhouse of KENOS. ProEdge is the principal Education 3.0 and professional-learning hub. KENHYFI is the integrated hybrid-finance and ecosystem-services hub within KENOS. Other applications and modules provide specialized capabilities in blockchain, commerce, development, security, finance and operational management. KENOS is built on three foundational pillars: Education 3.0 Artificial Intelligence Blockchain These pillars support the complete digital-economic journey: Learn โ†’ Plan โ†’ Build โ†’ Execute โ†’ Analyze โ†’ Supervise โ†’ Improve โ†’ Scale Artificial Intelligence Pillar KAI, Kohenoor Artificial Intelligence, serves as the principal intelligence powerhouse of KENOS. KAI is designed as a multilayered hybrid-intelligence and workflow-orchestration system rather than a conventional chatbot. It supports knowledge retrieval, document analysis, specialist-role activation, business intelligence, financial analysis, educational guidance, application planning, risk assessment, reporting, workflow coordination and Human-in-the-Loop escalation. Within KENOS, KAI connects users, knowledge, applications, workflows and authorized human decision-makers. Education 3.0 Pillar ProEdge serves as the principal learning and professional-development hub within KENOS. It supports practical education, workforce transformation, professional training, institutional capacity building and industry-linked learning in areas including: Artificial intelligence Blockchain and Web3 Business intelligence Cybersecurity Hybrid finance Digital transformation Communication and professional skills Software and application development Entrepreneurship and business execution ProEdge ensures that KENOS is not limited to providing technology. It also develops the human capability required to understand, manage and apply that technology effectively. Blockchain Pillar The blockchain pillar provides smart contracts, programmable assets, digital ownership, transparent records, settlement mechanisms, token utilities and verifiable ecosystem operations. Blockchain functions are designed to operate alongside KAI-supported intelligence, business rules, governance controls and authorized human supervision. Purpose of KENOS KENOS is designed to support individuals, professionals, businesses, educational institutions, developers, government entities and other organizations participating in the AI-powered digital economy. It connects learning with intelligence, intelligence with execution and execution with monitoring and supervision. KENOS may support: Education and professional development Artificial intelligence and business intelligence Financial and hybrid-finance services Blockchain and smart-contract development Digital commerce and procurement Application and software development Security and operational resilience Governance and institutional intelligence Reporting, monitoring and supervision Development Status At the time of this publication: KENOS is in the Early Beta phase. KENHYFI Hub is in the Alpha+ phase. Individual applications and modules may have different levels of development, testing and availability. The official public web host and disclosure gateway for KENOS is: https://www.kohenoor.net Within the KENOS architecture: KAI serves as the principal intelligence and orchestration layer. KENHYFI Hub operates as an integrated hybrid-finance and ecosystem services hub. Education 3.0 platforms support learning, reskilling and professional development. Blockchain applications provide smart-contract, digital-asset, settlement and verification capabilities. Business and development modules support planning, commerce, procurement, software development, financial intelligence, security, reporting and operational management. KENOS is intended to serve individuals, professionals, businesses, educational institutions, developers, government organizations and other entities participating in the AI-powered digital economy. The architecture is modular and may support public web access, controlled organizational deployments, private-cloud environments, local installations, sovereign infrastructure and integration with existing enterprise systems. Governance remains a core element of KENOS. High-stakes activities are intended to remain subject to authorized human review, role-based permissions, validation controls, risk classification, activity logging and Human-in-the-Loop approval. At the time of this publication, KENOS is in the Early Beta phase, while KENHYFI Hub is in the Alpha+ phase. Applications and modules within the ecosystem may therefore have different levels of development, testing, availability and production readiness. The official public web host and disclosure gateway for KENOS is: https://www.kohenoor.net This publication provides the official conceptual definition, ecosystem positioning, service scope, architectural relationships, development status, governance principles and public-disclosure framework of KENOS. Keywords: KENOS; Kohenoor Operating System; Kohenoor Technologies; KAI; Kohenoor Artificial Intelligence; KENHYFI; Education 3.0; artificial intelligence; blockchain; hybrid finance; digital economy; business intelligence; digital transformation; smart contracts; Human-in-the-Loop; ecosystem architecture; AI governance; Web3; enterprise AI; institutional intelligence Kohenoor Technologies remains committed to transparency, security, responsible disclosure, and continuous improvement of the KEN ecosystem. #kenhyfi #kai #hyfi #kohenoortechnologies #futureofeducation #futureoffinance #futureofai #kohenoorken #cryptocurrencies #kohenoorken #AI #actionai #agenticai #AGI #ArtificialGeneralIntelligenceAGI #AIAssistant #education3 #defi #hybridfinance #hyfi #cedefi #blockchain #innovation #settlements #auditreadycertificates #DASC #cybersecurity #web3 #businessintelligence #proedge #industrygradetrainings #quantumcomputing

Open access
2 source records
Knowledge Management and Technology
Real estate and construction management
Leadership, Behavior, and Decision-Making Studies
Original source
Jun 20, 2026ยทOSF Preprints (OSF Preprints)
0 cites
Decentralized Identity and W3C Standards โ€” Cryptography, Key Management, Post-Quantum, Sovereign AI, and Post-Cloud Architecture (Mf+So)

Lois-Kleinner Alpasan

This paper presents a comprehensive analysis of the World Wide Web Consortium (W3C) decentralized identity standards and their relationship to the MF+SO sovereign identity vault architecture. We examine the W3C Decentralized Identifier (DID) Core specification (W3C, 2022), the Verifiable Credential (VC) Data Model (W3C, 2022), and related standards including DID Resolution, DID URL dereferencing, and the Verifiable Credential Proof Formats. The paper provides a taxonomic analysis of DID methods (did:key, did:ethr, did:ion, did:web, did:indy) in terms of their trust assumptions, ledger requirements, latency, cost, and privacy properties. We compare MF+SO's identity modelโ€”which uses Ed25519 public keys as self-certifying identifiers with a local hash chain for state verificationโ€”against the W3C DID Core model, identifying both alignments and divergences. Key findings include: MF+SO identifiers are functionally equivalent to DIDs but use a simplified resolution mechanism that does not require a distributed ledger or external registry; MF+SO's hash chain audit trail provides state verification properties comparable to DID Document versioning on a ledger; and MF+SO's selective disclosure mechanisms using zero-knowledge proofs (see Paper VII) directly implement the W3C Verifiable Credential selective disclosure and data minimization requirements. We analyze the interoperability implications of MF+SO's architecture, demonstrating how MF+SO DIDs can be registered on external DID methods for cross-system interoperability while maintaining the local hash chain as the authoritative state source. The paper also examines the Verifiable Credential lifecycle within MF+SO: issuance, storage, presentation, and revocation, with attention to the credential schema registry, proof format compatibility (Data Integrity Proofs, JSON Web Signatures), and the holder-binding mechanisms that prevent credential sharing. A comparative assessment evaluates MF+SO against three alternative decentra... Part of The Anticloud research corpus by Lois-Kleinner Alpasan (ORCID: 0009-0009-2233-6107). This work explores cryptography, key management in the context of sovereign AI infrastructure, post-cloud computing architectures, and transparent, blackbox-free systems.

Open access
2 source records
Access Control and Trust
Blockchain Technology Applications and Security
Cloud Data Security Solutions
Original source
Jun 20, 2026ยทarXiv (Cornell University)
0 cites
TRACE: A Threat Modelling Methodology for Distributed, Cloud-First, and Decentralized Organisations

Stefan Beyer

Established threat modelling methodologies (STRIDE, PASTA, Trike, OCTAVE, LINDDUN, attack trees, and adversary-behaviour catalogues such as MITRE ATT&amp;CK) were designed for software products and enterprises with a discernible security perimeter, a single owning organisation, and a clean separation between technical and operational risk. Modern organisations violate all three assumptions: they run on cloud and SaaS control planes they do not own, distribute privileged authority across founders, contractors, vendors, signers, committees, and automation, and expose value through human approval ceremonies and supply-chain edges rather than a network boundary. The dominant failures are authorised-but-malicious actors, collusion across nominally independent parties, control-plane and CI/CD compromise, and operational mishandling of high-value actions, which existing methods largely omit. We present TRACE, a methodology that treats threat actors, roles, assets, critical invariants, and trust/authority edges as first-class, evidence-linked objects spanning three layers: protocols, systems, and organisations. We compare nine widely used frameworks across ten dimensions, show where each falls short in distributed, cloud-first, zero-trust settings, and specify TRACE: its core model, three application pillars, sequential gated workflow, and an evidence-and-traceability discipline for human-AI co-working in which language models accelerate coverage while senior reviewers retain judgement over invariants, severity, and collusion. TRACE was developed through Web3 security practice but is stack-agnostic. We discuss its relationship to zero trust architecture and accountable Byzantine consensus, its limitations, and open questions around empirical validation.

Open access
3 source records
Information and Cyber Security
Access Control and Trust
Security and Verification in Computing
Original source
Jun 12, 2026ยทZenodo (CERN European Organization for Nuclear Research)
4 cites
Dormant Continuity Theory

K Takahashi

This manuscript develops Dormant Continuity Theory (DCT), a protocol-relative mathematical framework for reasoning about systems that remain inactive at their protected core while retaining auditable continuity, recovery, diagnostic, and handoff capabilities. The theory formalizes dormant processes using finite transition systems, typed certificates, observable histories, evidence algebra, guarded authorization, replayable resolution, extraction adequacy, and fail-closed classification.DCT addresses practical challenges in long-lived distributed systems, including forked ledger histories, bounded model checking, data availability, zero-knowledge proof soundness boundaries, watcher incentives, MEV-resistant reward mechanisms, resource conservation, guardian corruption, maintenance transitions, and certificate-level HTLC handoff to extinction-style OSCT semantics. The framework distinguishes safety, bounded-griefing, diagnostic routing, and liveness assumptions, avoiding unconditional trustless claims while providing a rigorous finite core for verification and implementation-oriented extensions.

Open access
2 source records
Distributed systems and fault tolerance
Access Control and Trust
Security and Verification in Computing
Original source
Jun 12, 2026ยทScientific Reports
0 cites
A collaboration mechanism for medical insurance settlement based on isolation forest and Fleiss kappa smart contract

Chuanjia Yao, Zhihui Jiang, Xufeng Su, Xinchun Ma ยท 10 authors

The management of medical insurance funds is pivotal to the development of medical consortia. These funds serve as the operational lifeline of medical consortia and constitute critical public resources essential for public welfare. Medical expense settlement involves multiple stakeholders, including patients, tiered healthcare institutions, and insurance administrative agencies. However, disputes frequently arise between medical insurance authorities and hospitals regarding expense legitimacy due to information asymmetry and interpretative discrepancies. Such conflicts impede smoothness of payment mechanism, thereby undermining consortium operations and inter-institutional collaboration. To address these challenges, this study proposes a blockchain-based framework integrating medical expense investigation with insurance settlement. The system employs two core components: Anomaly detection via the Isolation Forest (IF) algorithm to identify potentially irregular expenses. Consensus-driven adjudication using Fleiss Kappa-based smart contracts facilitated by an anonymous panel of medical experts. This design enhances coordination between expense oversight and settlement processes, thus streamlining dispute resolution for medical expense anomalies and improving the scientific governance of insurance funds. Experimentally, the statistical validity demonstrated for unsupervised anomaly detection of IF and potential engineering applicability indicated in the analysis of healthcare cost. The healthcare consortium blockchain based on a Delegated Proof-of-Stake (DPoS) consensus mechanism and smart contract batch processing achieved a peak throughput of 229.64 transactions per second (TPS) and reduced transaction costs by up to 3,095 gwei. This demonstrates scalability for real-world medical insurance collaborative settlement systems.

Open access
Blockchain Technology Applications and Security
Auction Theory and Applications
Access Control and Trust
Original source
Jun 10, 2026ยทResearch Square
0 cites
DT-Share: A State-Bound Access Control Middleware for High-Churn Distributed Data Sandboxes

Guangfu Wu, Libin Xiao, Daojing He, Sammy Chan

Abstract Hybrid architectures in permissioned blockchains combining on-chain policies with Threshold Proxy Re-Encryption (TPRE) suffer from a structural audit gap: cryptographic enforcement is decoupled from the ledger's state. This allows Byzantine proxies to execute unaccountable data transformations (ghost requests). Furthermore, traditional TPRE access revocation incurs O(N) linear overhead, creating a scalability bottleneck.To address these flaws, we propose DT-Share, a state-bound access control middleware. By leveraging a novel State-Bound Evidence mechanism, DT-Share cryptographically anchors TPRE outputs to the global ledger epoch. This transforms access revocation from an O(N) key-management task into a constant-time O(1) ledger state transition.A full-stack implementation using Hyperledger Fabric and IPFS demonstrates that DT-Share guarantees strict accountability with negligible overhead. Under high-concurrency workloads, it exhibits an elasticity inversion phenomenon, adaptively scaling throughput during bursty requests to provide a highly scalable, Byzantine-resistant middleware for distributed consortia.

Open access
Blockchain Technology Applications and Security
Cryptography and Data Security
Access Control and Trust
Original source
Jun 10, 2026ยทarXiv (Cornell University)
0 cites
PriME-Deal: Privacy-Preserving Bilateral Data Trading with Efficient Matchmaking and Auditable Fair Exchange on Blockchain

Jie Zhang, Xiaohong Li, Shanshan Xu, Hanwei Wu ยท 6 authors

Bilateral attribute-based access control for data trading must hide policies, provide cryptographic fairness, and avoid trusted third parties. Existing solutions either leak policy information, incur super-linear costs, or rely on trusted dispute resolution. We present PriME-Deal, a non-interactive protocol that simultaneously achieves policy-hiding bilateral matching, efficient threshold access control, and auditable fair exchange on public blockchains. The seller embeds a secret token under the buyer policy into an oblivious key-value store with pseudorandom masking; the buyer reconstructs the token locally via tag-based probing, eliminating combinatorial enumeration, and proves correctness in zero-knowledge. Fair exchange is enforced through a collateralized on-chain reveal with a cryptographic audit that penalizes misbehaviour without trusted parties. We prove security in the Universal Composability framework under standard assumptions. Compared with the state-of-the-art threshold fuzzy IB-ME scheme, the seller's publishing time is reduced by two orders of magnitude (e.g., 8.76s vs. 690s for a policy of 500 attributes). For a typical configuration of (200,20,5), the buyer completes token reconstruction and proof generation in 8.9s, with the zero-knowledge proof taking under 0.6s and remaining constant across all parameter scales. The on-chain cost is approximately 28.6M gas, well within Ethereum's block limit. PriME-Deal thus delivers the first practical privacy-preserving data trading protocol that combines linear seller overhead, bilateral policy hiding, and auditable fairness.

Open access
3 source records
cs.CR
Cryptography and Data Security
Blockchain Technology Applications and Security
Original source
Jun 10, 2026ยทInformation
0 cites
A Layered Governance Coverage Model for Decentralized Autonomous Organizations: Formalization, Empirical Analysis, and Implications for Blockchain-Based IoT/AI Systems

Abeer S. Al-Humaimeedy, Rand Alkharashi

Decentralized Autonomous Organizations (DAOs) enable blockchain-based collective governance, yet existing studies often evaluate DAO governance through isolated mechanisms, particularly voting systems. This narrow view does not sufficiently explain recurring problems such as governance capture, weak accountability, inadequate safeguards, and inefficient resource allocation. This paper proposes a Layered Governance Coverage Model that conceptualizes DAO governance as a system of seven interdependent institutional functions spanning participation, agenda formation, collective choice, safeguards, execution, incentives, and meta-governance. The model uses a four-level strength scale to assess not only whether governance functions are present, but also how strongly they are institutionalized. It is empirically applied to thirty-seven active DAOs through evidence-based coding of publicly available governance artifacts. The results show that governance breadth does not necessarily imply governance maturity: collective choice and execution mechanisms are more developed than accountability, safeguards, and meta-governance. Beyond DAO-native settings, the paper positions governance maturity as a trust and resilience regime for blockchain-based IoT and AI infrastructures, where governance affects security, reliability, data integrity, and risk oversight. The paper discusses AI-enabled governance analytics as a support mechanism for monitoring governance activity, detecting anomalies, and improving governance observability. The proposed framework contributes a structured approach for evaluating and designing resilient governance architectures in DAOs and blockchain-based IoT/AI systems.

Open access
Blockchain Technology Applications and Security
Access Control and Trust
Ethics and Social Impacts of AI
Original source
Jun 9, 2026ยทZenodo (CERN European Organization for Nuclear Research)
0 cites
FairWave: A Fairness-Aware Asynchronous DAG-BFT Consensus

Syariful Mujaddiq

Proof-of-Stake DAG-BFT consensus faces a trilemma between sybil resistance, reward fairness, and plutocracy. Existing protocols prioritize liveness over fair stake-based selection, driving longitudinal centralization. FairWave is a dual-channel DAG-BFT protocol that separates anchor selection from reward distribution. The selection channel is super-linear in stake, guaranteeing Sybil gain &lt; 1 for K &gt; 1; the reward channel is sub-linear via square-root stake normalization. DAG-derived uptime and latency metrics eliminate external oracles,and lagged reputation breaks circular dependency between selection outcomes and weights. Evaluated through approximately 550,000 Monte Carlo rounds against eight baselines, FairWave shows Gini 0.140 (vs. Pure-PoS 0.490, monotone HHI reduction from 0.039 to 0.020 over 50,000 epochs, and optimal Sybil split K * = 1. Safety follows unconditionally from the 2f + 1 commit rule; the liveness model predicts monotone degradation from 94.0% at b = 0.20 to 74.0% at b = 1/3, consistent with the architectural expectation of no discontinuous cliff.

Open access
5 source records
Vehicular Ad Hoc Networks (VANETs)
Access Control and Trust
Distributed systems and fault tolerance
Original source