ABSTRACT TRSP — The Temporal Security Architecture: The Consolidated Record. Three documents, one DOI: the Security Record, the Economic Record, and a general-audience companion. Every cryptographic system in production today rests on one assumption: that a mathematical problem is too hard to solve in practical time. Quantum computing places an expiry date on that assumption, and adversaries are already recording encrypted traffic and public ledgers at scale — harvest now, decrypt later. This record consolidates the Temporal Rotation Security Protocol (TRSP) series into its canonical form. TRSP closes the attack surface that post-quantum mathematics leaves open: cryptographic keys are generated from physical hardware entropy at the moment of use, exist for a rotation window measured in milliseconds, and are destroyed by hardware-enforced destructive readout. Between operations, no persistent credential exists anywhere in the system. This record comprises three documents under one DOI: Document 1 — The Security Record (TRSP — The Temporal Security Architecture: Time as the Fundamental Security Parameter). The consolidated technical reference of the series. It states the security doctrine with precision as a division of labour across three attack mechanics: temporal rotation eliminates the stored-credential surface (endpoint extraction by malware, insiders, hardware probing, or coercion); NIST-standardised post-quantum mathematics (ML-KEM, ML-DSA) eliminates the recorded-transcript surface; single-use protocol rules eliminate the public-record surface, since a retroactively derived key finds its one permitted action already complete and refused for reuse. Each threat is assigned to the layer that closes it structurally — the combination this architecture defines as quantum permanence. The architecture is organised in three layers named for the Norse Norns of time: URDHR (the irrecoverable past — hardware commitment and Landauer-anchored destruction, with optional macroscopic optical entropy), VERÐANDI (the witnessed present — geographically distributed quorum validation bounded by light-speed, with a canonical rotation-window definition of 10–100 ms default and adaptive extension to 500 ms for global quorums), and SKULD (the anchored future — LEO satellite quorums contributing unpredictable physical state measurements under relativistic timestamp validation). Further parts document the four-layer temporal-quantum hybrid (LTQS), the formal ephemeral verification pipeline with zero-knowledge enrollment binding and an explicit statement of the minimised persistent root, application domains ordered by strategic value (AI-to-AI authentication and micropayment, cloud access immune to credential breaches, interbank settlement finality across multi-decade ledgers, critical infrastructure command authorisation, interplanetary autonomous verification, and the consumer expression documented in the TRSP Citadel record), a compliance architecture reconciling maximum personal privacy with institutional regulatory obligations through enrollment tiers, and nine engineering considerations with documented solution pathways. Document 2 — The Economic Record (TDC — The Temporal Digital Coin: Value Anchored in Verified Moments). The corrected canonical economic layer of the series (NC-TDC-26 through NC-TDC-32). It opens with an explicit correction: earlier records simultaneously asserted fungibility of all units, no re-pricing across phases, and rising per-phase value ranges — three statements that are jointly impossible, since a fungible asset trades at exactly one price. This record resolves the contradiction in favour of the principles and formally retracts the per-phase value ranges. The canonical doctrine: one coin, one price, stability by coupled expansion — supply is admitted only against verified, settled growth of the anchored economies under the quantity-theory identity M·V = P·Q, with governance-bounded elasticity, so that price-level stability becomes an accounting consequence of the issuance rule rather than a promise, and early holders gain no phase windfall by construction. Further parts document Proof of Physical Presence consensus economics (validation democratised to enrolled devices; the attack currency is human recruitment), the corrected role of temporal uniqueness (events anchor authenticity, never scarcity — scarcity derives from governance, value from anchor-economy demand), supply and issuance rules, the multi-anchor demand architecture (machine, institutional, and sovereign economies as demand sources, never price classes), consortium governance defined primarily by its prohibitions, the phased rollout in corrected form, and economic engineering considerations including velocity management, demand shocks, exchange-rate regime, bootstrap liquidity, and measurement integrity. Document 3 — The Companion Article (The Key That Even a Time Machine Cannot Steal). A general-audience presentation of the complete architecture — protocol, secure personal computer, and coin — written for readers outside the field, including the time-traveler thought experiment, the three guards (sortition, light-speed, multilateration) in plain language, and the estate architecture. It introduces no claims beyond the technical records. Newly registered contributions. In addition to consolidating and re-registering all prior novel contributions of the series (NC-TDC-1 through NC-TDC-41, NC-URDHR-1, NC-TRSP-Hybrid-1), this record places the following on the public record of prior art as of its publication date, each with a full enabling defensive specification (Security Record, Part 10a): NC-TDC-42 — Optical Air-Gap Content Transfer (formally registered herein, first described in the Citadel record): content crosses a security boundary as rendered light captured by a hardware-switched sensor and locally reconstructed via optical character recognition — the meaning crosses, the file never does; enumerated elements include the security inversion (the receiver harvests, the sender has no channel), the hardware-gated exception to device-level optical silence, and throughput asymmetry as a security property; registered embodiments include matrix-barcode, audio-channel (synthesised speech to local speech-to-text), and enterprise domain-transfer variants. NC-TDC-43 — Chained Presence Verification (newly documented): a unified three-link defence against device-farm collusion — sortition (per-transaction quorum draw via verifiable random function, unpredictable in advance, verifiable after), light-speed (adaptation between draw revelation and window close physically impossible), and multilateration (propagation-delay fingerprints against a relativistically validated time base expose any participant absent from its claimed position) — with the explicit answer to the position-based-cryptography impossibility result (Chandran–Goyal–Moriarty–Ostrovsky 2009): the architecture proves the position of an attested hardware module under an unpredictable draw, removing the pre-positioned-collusion premise the impossibility proof requires. NC-TDC-44 — Ephemeral Witness Relations (newly documented): the formal security model of time-bounded credentials — keys as functions of bounded temporal support with the derived metric of temporal attack surface; erasure completeness as a zero-mutual-information condition I(sk_eph; S(t)) = 0 with Landauer's bound identified as the realisation floor of erasure and explicitly not as a barrier to mathematical re-derivation; the composite adversarial bound over orthogonal domains (computational hardness, temporal measure, combinatorics of presence) with the binomial sortition term; the spacetime-local physical oracle O(D, t) with destructive-readout consumption; and ownership as a time-indexed capability predicate over uncopyable events, including the transient-witness class, the notion of proof of transient knowledge, and the no-retroactive-forgery bound. NC-TDC-45 — Disturbance-Elevated Alpha-Quorum Time Reference. Binding authorisation to short time windows places the local clock in the trusted computing base. This contribution redistributes time-validation authority at the moment of attack rather than fixing it in advance: under normal conditions all nodes validate equally; on detection of a time-source anomaly (cross-source divergence, or a multilateration residual beyond threshold), the system elevates a small set of hardened, atomic-clock-bearing nodes to a median-of-five reference — which tolerates two outliers, so shifting it requires corrupting at least three of five. Membership is fixed by short-lived sortition at the moment of elevation, so the set cannot be pre-targeted. Every coordinated time attack thereby degrades to denial, never forgery: it can interrupt authorisation, not manufacture one. Additionally placed on record in the Economic Record: the coupled-expansion issuance doctrine (corrected canonical form of NC-TDC-29), the corrected scope of NC-TDC-27 (temporal anchoring of authenticity, with uniqueness explicitly disclaimed as a source of value), and the formal retraction recorded in NC-TDC-31 — the corrections themselves are part of the prior-art registration. Consolidation and continuity. This record consolidates and supersedes as canonical reference: TRSP v3 (10.5281/zenodo.20324081), TRSP Digital Coin (10.5281/zenodo.20346658; v2: 20332811; v1: 20288860), TRSP: The Authorization Protocol for Everything (10.5281/zenodo.20402892), and TRSP Citadel (10.5281/zenodo.20481331). The four source records remain in force as prior art; where formulations differ, this record is authoritative. The CRATON designation in prior records and the URDHR designation in this and future records refer to architecturally identical concepts; prior-art continuity is complete and uninterrupted. The economic layer and the security layer are maintained as separate documents within this record by design: each addres
Due to the fast development of digital communication technologies and the creation of distributed computing architecture, it is crucial to ensure the security of communication through effective and safe authentication schemes that can protect data privacy within cybersecurity frameworks. The most efficient cryptographic method for such purposes is zero knowledge proof since it provides ultimate security by proving the authenticity without disclosing any sensitive data to the verifying party. It is fascinating to look into the zero-knowledge proof protocol based on graph isomorphism because of its mathematical nature. A detailed discussion on the graph isomorphism based zero-knowledge authentication techniques along with their significance in the current cryptography is presented in this paper. Working principles and concepts behind graph theoretic based authentication techniques and the concept of graph isomorphism and zero-knowledge proofs have been discussed in this paper. Besides, emerging application areas of these protocols in disciplines like cybersecurity, block-chain. Internet of Things security, cloud computing and post-quantum cryptography have also been highlighted in this paper. In addition to that, this paper provides an analysis of major advantages, drawbacks and future research directions for the graph theoretic zero-knowledge authentication schemes
Blockchain technology has emerged as a foundational framework for secure, transparent, and decentralized data management. This paper presents a comprehensive examination of the underlying theory and methodology of blockchain systems. Fundamental concepts such as cryptographic hashing, distributed ledger structures, peer-to-peer networking, and consensus algorithms are reviewed to establish the theoretical basis of blockchain functionality. Methodological approaches, including protocol design, smart contract development, performance evaluation, and security analysis, are discussed to demonstrate how blockchain systems are built, validated, and optimized. The study also highlights methodological challenges related to scalability, interoperability, governance models, and system verification. By integrating theoretical principles with practical design methodologies, this work provides a holistic understanding of how blockchain systems operate and how they can be effectively engineered for diverse applications.
Sovereign is a Prove/Pull communication protocol designed to address the structural imbalance of modern digital communication, where senders can impose cognitive and computational costs on recipients without corresponding friction. The protocol requires messages to carry a cryptographic proof of intent through one of three mechanisms: adaptive Proof-of-Work, private zero-knowledge proximity credentials, or registry-attested clearance tokens. Verification is performed by a decentralized Sovereign Audit Network (SAN), which attests that messages satisfy recipient-defined acceptance policies before delivery. This document presents the complete architectural specification of Sovereign, including the MessageEnvelope format, federated attestation protocol, dual Sparse Merkle Tree issuer registry with revocation support, Groth16 zero-knowledge proximity credential circuit, identity hierarchy, security assumptions, economic model, limitations, and phased deployment strategy. This release is Version 1.0 of the design specification. It is an unimplemented protocol proposal; all performance figures are engineering targets based on primitive benchmarks and require validation through future reference implementation. The work is published to establish a public technical record, invite peer review, and support future research, collaboration, and implementation efforts.
To make the payment system robust and user friendly, decentralized based Scan and Pay system need to be designed. This paper integrates the Unified Payments Interface (UPI) of India with the Solana-based Blockchain to make the payment system decentralized. Solana offers a high throughput and low-cost based decentralized infrastructure which is combined with the simple and reliable UPI system. So, the proposed system enables cryptocurrency transactions linked to UPI while maintaining user friendliness, scalability, and regulatory compliance. The designed method uses a secure architecture powered by smart contracts and modular design. It offers a viable bridge between centralized financial networks and emerging Web3 ecosystems. Proposed Solana-based UPI is compared with the Non-Solana based UPI which is using Blockchain. Results show that there is improvement of 91% in transaction latency and 95% in transaction cost as compared to the Non-Solana based UPI system.
Abstract When resource-constrained Internet of Things (IoT) terminals connect to industrial control, sensing, and edge systems, it is necessary to balance low-overhead authentication, credential privacy protection, and cross-platform deployment. Traditional password and USBKEY authentication methods rely on static credentials and certificate mechanisms, which are vulnerable to eavesdropping, replay, and forgery attacks, while simultaneously suffering from privacy leakage and high platform adaptation costs. To address these issues, this paper proposes a hardware-assisted zero-knowledge authentication scheme for resource-constrained terminals. It utilizes a USBKEY as the local trusted hardware carrier and introduces a quadratic constrained zero-knowledge proof protocol under the Generalized Subspace Vector Oblivious Linear Evaluation framework (GSVOLE-2DLC) to construct a session-bound dynamic authentication process. In the registration phase, the scheme binds protocol parameters with user credentials and writes them into the USBKEY. In the authentication phase, the server (acting as the verifier \((\mathcal{V})\)) generates a random challenge, and the USBKEY (acting as the prover \((\mathcal{P})\)) generates temporary proof parameters based on local witness information. Subsequently, the verifier \((\mathcal{V})\) completes the verification through constraint consistency and GSVOLE consistency, thereby avoiding the transmission of original identity credentials over the network. To adapt to terminals with varying computational capabilities, this paper further designs configurable finite field parameters and cross-platform modular arithmetic interfaces, which are implemented in a PowerPC-architecture USBKEY prototype and a host-side verification environment. Experimental results demonstrate that under the parameter configuration of a 64-bit prime field, \((n_C=4)\), \((k_C=3)\), \((d_C=3)\), \((\ell=2)\), and \((t=7)\), the total system authentication time is approximately 0.5476 s, and the verification time for the verifier \((\mathcal{V})\) is 0.0031 s. Protocol performance and functional tests indicate that the proposed scheme can correctly execute identity authentication under the assumed threat model, making it suitable for IoT edge scenarios requiring privacy protection and lightweight authentication.
<b>Abstract</b>The rapid growth of decentralized technologies has intensified the need for secure, privacy-preserving, and Sybil-resistant identity systems capable of operating without centralized authorities. Existing blockchain identity mechanisms frequently depend on trusted intermediaries, invasive biometric verification, or token-based incentives that introduce privacy risks, centralization, or economic manipulation. This paper presents the Decentralized Proof of Humanity (dPoH) Protocol, a blockchain-native identity framework designed to establish unique human identities through decentralized verification while preserving user privacy and network scalability.The dPoH protocol combines decentralized attestations, cryptographic verification, reputation mechanisms, and consensus-driven validation to ensure that each participant corresponds to a unique human identity without exposing unnecessary personal information. By eliminating reliance on centralized identity providers, the protocol significantly reduces Sybil attacks while maintaining transparency, auditability, and interoperability across blockchain ecosystems.The proposed architecture is suitable for decentralized finance (DeFi), decentralized governance (DAO), voting systems, digital identity infrastructure, token distribution, and next-generation Web3 applications. The protocol contributes to the growing field of decentralized identity by providing a scalable framework for secure human verification in trustless environments.
Kaja Masthan, Zeeshan Ahmed Mohammed, Rahmat Ali, Abdul Junaid Mohammed
The advancement of medical data handling from conventional paper documents to electronic records enabled secure data movement between authenticated legitimate users. While current identity verification algorithms offer unique solutions, they face significant limitations related to data storage scalability, potential privacy breaches, high computational costs, and the lack of standardized protocols. In order to alleviate these constraints, the research proposes a biometric–Blockchain-based authentication Scheme, a Whirlpool Secure Hash-based Biometric Integrated Key Distribution Function (WShBK) for secure data storage and access in a cloud network. The proposed strong cryptographic scheme generates two unique keys derived from the biometric trait of the patient for both encryption and authentication purposes, ensuring strong protection while accessing and storing the data. Furthermore, the advanced encryption standard WShBK (AWShBK) encryption algorithm leverages the strength of a symmetric block cipher and the unique key, offering robust protection against breaches by rendering intercepted data without the correct decryption key. Furthermore, Hybrid biometric-based zero-knowledge proof (HyBZKP) verification offers secure and private transaction validations while sustaining the blockchain integrity. These advancements of the proposed WShBK scheme improve 0.52 encryption rate and 0.53 decryption rate for 250 users analyzed with an attack compared to other cutting-edge models.
The rapid proliferation of Internet of Things (IoT) devices across smart homes, healthcare systems, and industrial environments has intensified the need for robust and adaptive security mechanisms in multi-user settings. Traditional password management approaches remain widely deployed; however, they suffer from persistent vulnerabilities including weak password selection, credential reuse across services, and the absence of structured lifecycle management mechanisms. This paper presents a systematic review of existing authentication, password management, and key lifecycle strategies applicable to multi-user IoT ecosystems. The study follows a structured review methodology to analyze and synthesize contemporary research contributions in the areas of context-aware authentication, secure key rotation, password expiry mechanisms, and lightweight cryptographic implementations. A comparative evaluation of diverse security techniques—such as one-time passwords (OTPs), zero-knowledge proofs (ZKP), symmetric and public-key cryptographic schemes, and machine learning-based threat detection models—is conducted with particular attention to device resource constraints, scalability challenges, and operational efficiency. Conceptual models, analytical tables, and comparative charts are utilized to highlight trade-offs between security strength, computational overhead, and system performance. The review identifies significant research gaps in integrating dynamic key rotation and expiry mechanisms into holistic, context-aware security architectures tailored for multi-user IoT environments. Finally, the paper outlines future research directions aimed at developing scalable, resource-efficient, and adaptive password lifecycle management frameworks for next-generation IoT systems. management frameworks for next-generation IoT systems.
The method of secure authorization of banking transaction based on the Schnorr scheme represents a cryptographic approach to verifying user authenticity using Zero-Knowledge Proof (ZKP) protocols. The proposed approach is focused at minimizing the risks of compromising confidential data during the execution of transaction in open or partially trusted environments. The method is based on the Schnorr identification protocol, which relies on the computational hardness of the discrete logarithm problem and enables authentication without transmitting the user’s secret key. The authorization model includes the interaction process between three components of the transaction, namely the client, the transaction execution environment, and the banking side. The transaction execution environment is considered to be critical and untrusted component. The protocol consists of a sequence of stages: first, the initial parameters (p, g) are generated; then the public key value (y) is formed; based on it, a proof value (t) is created; on the bank`s side, a challenge (e) is generated followed by the computation of the parameter s, and subsequently the correctness of the verification relation is checked by the bank. A distinctive feature of the approach is the absence of private key transmission and the use of random values, which prevents the recovery of secret parameters even if part of the data is intercepted. Within the scope of the study, simulations of Man-in-the-Middle (MITM) and replay attacks were performed in older to evaluate the robustness of the proposed approach. In the case of a Man-in-the-Middle attack, it is shown that modification of the parameter t leads to a violation of the verification relation, making successful transaction authorization impossible. To counter replay attacks, a timestamp (TS) mechanism and transaction parameter uniqueness were integrated into the model, eliminating the possibility of reusing intercepted data. The constructed model is based on cryptographic strength, reduction of the impact of vulnerabilities in the transaction execution environment, and ensuring the fundamental principles of digital security, namely data integrity, confidentiality, and authenticity. The proposed method demonstrates its effectiveness in scenario with a high level of threats, such as in the financial sector, where transaction protection is a critical component
Cross-border transactions with regulatory compliance have become conventional in the era of globalization. Transactions related to individuals, banking, technology, etc., are eased using Internet of Things (IoT) paradigms. Pervasive access and low interoperability due to improper administration of transaction terminals are significant problems in initiating and completing cross-border transactions. To address the problems, a novel Zero-knowledge proof Inter-Scalable Framework (ZISF) is proposed. This framework includes transaction authentication, Blockchain (BC), and a security generator to ensure security, scalability, and interoperability. The proposed framework consolidates these tasks to support diversified cross-border transactions with flexible regulatory compliance. The proposed ZISF framework achieved a 13.64% improvement in transaction throughput compared with CCMB under varying block-size and transaction-load conditions, while reducing processing latency by 13.79% relative to BETAC-IoT during miniature block scaling operations.
India’s Unified Payments Interface (UPI) gates transaction limits behind Know Your Customer (KYC) compliance tiers mandated by the Reserve Bank of India (RBI) and National Payments Corporation of India (NPCI). Unlocking the Full KYC tier currently requires users to surrender sensitive identity documents (Aadhaar, PAN, income proofs) to Payment Service Providers (PSPs). This centralized storage creates severe breach vulnerabilities and systemically violates the data minimization principle of India’s Digital Personal Data Protection (DPDP) Act 2023, Section 8(3). We present ZKProof-eKYC, the first Zero-Knowledge Proof (ZKP) framework designed specifically for payment system tier access control. By reframing KYC eligibility as a cryptographic access token, a user’s device generates a 1.5 KB non-interactive Groth16 zk-SNARK proof asserting tier eligibility. The PSP receives only a boolean result, eliminating personal data transmission and achieving DPDP Act compliance mathematically. The primary contribution is a multi-predicate Circom 2.0 circuit (≈25,000 R1CS constraints) simultaneously enforcing eleven regulatory predicates (ϕage to ϕtier) mapped across six Indian statutes. The architecture introduces five key elements: (i) an 8-leaf depth-3 Poseidon Merkle credential tree; (ii) a dualdocument commitment scheme protecting the raw PAN (singlehash) and Aadhaar (double-hash) identifiers; (iii) an EdDSAPoseidon issuer signature; (iv) a depth-20 Sparse Merkle Tree (SMT) for real-time revocation; and (v) Poseidon nonce-binding against replay attacks. A novel branch-free finite-field formula calculates NPCI’s tier limits natively: tier = 2 · ⊮[FullKYC] + (1−⊮[FullKYC])·⊮[MinKYC]. We deploy a dual-circuit framework: UPIKYCTierProof for Full KYC and MinKYCTierProof for Min KYC. Functional correctness is validated against 12 adversarial test vectors. Performance profiling projects mobile WASM generation at <400 ms, with off-chain execution measured at ≈96 ms and on-chain verification at ≈242,000 gas. ZKProofeKYC establishes the first “one credential, multiple products” ZKP architecture for national payment infrastructure.
Md Sakibul Islam Sheikh, Md Dipu, Maksudur Rahmand, Kazi Riadul Islam · 7 authors
In today's digital environment, secure and trustworthy identity management is critical as centralized systems remain vulnerable to data breaches, identity theft, and unauthorized access.This paper presents a blockchain-based decentralized identity verification framework that enhances data security, privacy, and user control by eliminating reliance on centralized authorities.The proposed system integrates smart contracts, decentralized identifiers (DIDs), and cryptographic security to enable tamper-resistant and transparent identity verification.Sensitive user documents are encrypted using AES-256-GCM and stored off-chain on IPFS, while only cryptographic hashes and verification records are recorded on the blockchain to preserve privacy and data integrity.Key management is strengthened through HKDF-based derivation, and users can selectively disclose identity attributes using privacy-preserving techniques.Experimental analysis indicates that the system significantly reduces identity fraud, improves verification accuracy, and enhances auditability and scalability.The solution is well-suited for applications in finance, healthcare, e-governance, and secure third-party authentication platforms.
The growing popularity of smart contracts on blockchain platforms in recent years has made the development of reliable verification techniques that ensure code is both logically correct and secure an urgent priority. One of the most effective methods adopted by existing tools is formal verification. This thesis addresses the problem of smart contract verification, particularly focusing on those developed for the Ethereum platform. It concentrates on using Constrained Horn Clauses (CHCs) as an intermediate formalism for representing and analysing program properties. Various verification tools were analysed and compared during the course of the work, particularly those based on CHCs, to identify practical limitations, methodological gaps, and opportunities for improvement. Based on this analysis, new tools and optimisations were designed and developed. On the one hand, we implemented CHCViz, a visualisation system that assists auditors and developers in inspecting and understanding CHCs generated by existing tools, such as SolCMC. On the other hand, a verifier for Yul code was built from scratch to extend the applicability of formal verification via CHCs to the recently released intermediate code from the Ethereum foundation.
Valerio Mandarino, Giuseppe Pappalardo, Emiliano Tramontana
Authentication is essential to hold users accountable across online services. Conventional authentication systems rely on centralized architectures or third-party identity providers, which, however, introduce single points of failure, privacy concerns, and limited user autonomy. Conversely, fully decentralized authentication frameworks often struggle to provide reliable identity attestation mechanisms. This makes them vulnerable to Sybil attacks and self-asserted claims, while limiting their interoperability with trust-based systems. This paper presents dAuth, a hybrid blockchain-based authentication architecture based on Ethereum smart contracts to provide cryptographic tokens that enable authentication to services. These tokens, anchored to the smart contract, are derived by users from institutionally certified base credentials issued by an accredited verifying authority and enable authentication to services without further involvement of the authority. Each token is cryptographically bound to a specific service, constrained in scope and duration, and verifiable off-chain through data and cryptographic commitments provided by the user. No plaintext personal information is published on-chain: identity attributes are committed as cryptographic digests, which anchor certified identity data on-chain while keeping the underlying personal information private and auditable. This design removes the verifying authority from the authentication process, as all authentication steps are assisted by the user-controlled smart contract. The verifying authority’s role is limited to initial identity certification and exceptional update procedures. The result is a privacy-preserving and verifiable hybrid authentication framework that leverages the cryptographic security properties of the underlying blockchain infrastructure and inherits its scalability characteristics. The proposed design has been implemented and experimentally evaluated on the Ethereum platform, addressing public blockchain-specific challenges such as scalability constraints and transaction costs to ensure practical deployment.
Academic research indicates an urgent need for safe, tamper-proof storage of sensitive medical information due to the rapid digitalization of healthcare data. Traditional systems are susceptible to both internal and external assaults because of their dependence on centralized servers. SEC-HEALTH implements a system for the secure storage of electronic health records (EHRs) by combining the immutable, distributed ledger technology of blockchain with the InterPlanetary File System (IPFS).This system use Solidity smart contracts to archive patient data and transaction records on the Ethereum blockchain. Comprehensive EHR files are preserved on IPFS and may be accessed via their blockchain hash addresses. The architecture guarantees data integrity, transparency, and safe access independent of trusted third parties.User modules include appointment scheduling, prescription management, patient and physician authentication, and platform registration. The graphics illustrate a fully operational web interface created in Python, implemented smart contracts, and the integration of blockchain with IPFS. The approach is resilient and decentralized, providing an alternative to traditional centralized health data management systems.
This paper presents a comprehensive analysis of privacy-preserving authentication mechanisms within the MF+SO sovereign identity vault, focusing on the protocol's implementation of zero-knowledge identity proofs, anonymous credentials, blind signatures, and data minimization techniques. Traditional authentication protocols require the user to disclose their identity to each service provider, creating a centralized record of the user's activities across services. MF+SO's privacy architecture inverts this model: users authenticate to services without revealing their MF+SO identifier, using cryptographic techniques that provide the verifier with assurance of the user's authorization status while revealing minimal information about the user's identity. We examine three canonical privacy-preserving authentication mechanisms implemented in MF+SO: (1) zero-knowledge identity proofs using the Groth16 zk-SNARK construction, enabling users to prove possession of valid credentials without revealing which credentials they hold; (2) anonymous credentials based on the Camenisch-Lysyanskaya (CL) signature scheme, providing multi-show unlinkability where the same credential can be presented multiple times without the presentations being correlatable; and (3) blind signature-based tokens for email cloaking, where the MF+SO service issues a blind signature on a user's email address for use with third-party services without learning the email address. The paper provides a formal security analysis of the unlinkability guarantees of each mechanism, proving that under the decisional Diffie-Hellman (DDH) assumption, CL-based anonymous credential presentations are computationally unlinkable. We present benchmark data for each mechanism on mobile platforms: CL credential issuance (120 ms), CL credential presentation (85 ms), blind RSA signature issuance (45 ms), and zk-SNARK-based verification (2.3 ms). The implementation details include the MF+SO privacy layer architecture, the credential ... Part of The Anticloud research corpus by Lois-Kleinner Alpasan (ORCID: 0009-0009-2233-6107). This work explores cryptography, key management in the context of sovereign AI infrastructure, post-cloud computing architectures, and transparent, blackbox-free systems.
This paper presents a comprehensive analysis of zero-knowledge proof (ZKP) systems and their application to privacy-preserving identity management within the MF+SO sovereign identity vault. Zero-knowledge proofs, introduced by Goldwasser, Micali, and Rackoff (1985), enable a prover to convince a verifier of the truth of a statement without revealing any information beyond the statement's validity. We examine three families of ZKP systems in the context of MF+SO's identity assertions: zk-SNARKs (Zero-Knowledge Succinct Non-Interactive Arguments of Knowledge), zk-STARKs (Zero-Knowledge Scalable Transparent Arguments of Knowledge), and Bulletproofs. For each family, we analyze the setup assumptions (trusted setup vs. transparent), proof size, verification complexity, prover computation, and post-quantum security. The paper identifies three canonical use cases within MF+SO: (1) age verification without date of birth disclosure, where the user proves that their age exceeds a threshold without revealing their exact birth date; (2) credential possession proof, where the user proves they hold a valid credential for a resource without revealing which credential among a set they hold; and (3) membership in an allowlist without position disclosure, where the user proves their identifier appears in a list without revealing their position in the list. We present benchmark data for each use case using the Groth16 zk-SNARK (prover time: 1.2 seconds, proof size: 192 bytes, verification: 2.3 ms) and the STARK-based approach using the Winterfell library (prover time: 4.8 seconds, proof size: 48 KB, verification: 8.1 ms). The implementation complexity analysis demonstrates that zk-SNARKs require trusted setup ceremonies but provide the most compact proofs, while zk-STARKs eliminate the trusted setup requirement at the cost of larger proofs. The paper concludes with an analysis of the protocol integration requirements, including circuit compilation for the MF+SO identity predicate lang... Part of The Anticloud research corpus by Lois-Kleinner Alpasan (ORCID: 0009-0009-2233-6107). This work explores cryptography, key management in the context of sovereign AI infrastructure, post-cloud computing architectures, and transparent, blackbox-free systems.
Sancaktar Pelin, Necla Kırcalı Gürsoy, Arif Gürsoy
Modern authentication architectures contain structural vulnerabilities against automated credential stuffing and server-side data breaches. Traditional solutions rely on the transmission of raw or hashed passwords over the network; for bot defense, they position third-party Completely Automated Public Turing test to tell Computers and Humans Apart (CAPTCHA) services, which may violate user privacy and create institutional dependencies, as an illusion of two-factor authentication (2FA). This situation raises a critical research question in cybersecurity: How can an integrated cryptographic shield be constructed that is independent of user-privacy-invasive mechanisms and external data authorities, while preventing autonomous bots from targeting the identity and human-verification layers separately?In response to this question, this paper presents a zero-dependency, original, and hybrid protocol that integrates a Zero-Knowledge Proof (ZKP) based on the Schnorr authentication scheme with a local Human Interaction Proof (HIP) mechanism. The main advantage of the proposed architecture is that it mathematically seals the user’s secret credential together with a dynamically generated one-time CAPTCHA token on the client side using the SHA-256 function, thereby transforming the verification process into an indivisible atomic “Hybrid Secret.” In this way, the transmission of password hashes over the network is completely eliminated, and the server evaluates only the mathematical validity of the proof under the Discrete Logarithm Problem (DLP) assumption.Experimental results obtained through Selenium-based automated brute-force attack simulation engines demonstrate that the system provides complete blocking against automated threat vectors. Dynamic one-time nonce mutation immediately invalidates the derived client response, even in extreme scenarios where an attacking bot obtains the correct password string and solves the CAPTCHA image, thereby mathematically defeating brute-force and replay attacks. Furthermore, the autonomous structure of the proposed protocol, with no dependency on third-party analytics services, opens the way for a highly secure and local authentication architecture for internet-isolated critical infrastructures.In this study, the theoretical and mathematical foundations of the proposed protocol are presented, the stages constituting its life cycle are methodologically explained, and Selenium-based experimental simulation results together with telemetry log analyses are detailed.
The recent developments having an impact on the electronic payments landscape within the EU are examined in this chapter. The presentation of the EU legal framework on payment services focuses on its transparency requirements and the rights and obligations of the parties. The characterisation and main features of electronic money are discussed alongside the legal framework governing the business of electronic money institutions. Particular attention is devoted to the implementation of rules relating to the use of Distributed Ledger Technology in finance and to analyse how Regulation (EU) 2023/1114 on markets in crypto-assets (MiCA) has contributed decisively to transforming the previous situation and the regulatory framework concerning the issuance and trading of crypto-assets as well as the provision of crypto-asset services in the EU market.
Donggoo Kim, Rajesh Upadhayaya, Milosz Bator, Tao Le
Proof of Reserves (PoR) enables centralized crypto exchanges to demonstrate that on-chain reserves are sufficient to cover customer liabilities. However, existing approaches, including Merkle-tree-based proofs and zero-knowledge PoR systems, remain difficult for everyday users to verify in practice, resulting in limited participation and weakened transparency. We introduce LPOR, a layered, usability-focused PoR framework that separates lightweight user-side checks from auditor-level cryptographic verification, enabling non-technical users to verify inclusion and publicly recompute total liabilities with minimal friction. By lowering verification barriers, LPOR increases user participation and substantially improves the probability of detecting omitted liabilities. We evaluate its scalability and omission detectability at a multi-million-user scale.