Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

1,365 papersLast indexed Aug 31, 2026
Search papers

Paper index

1,365 results · page 2 of 57

Clear filters
Feb 24, 2026·Frontiers in Business and Finance
1 cites
Privacy-Enhanced Ad Targeting for Social E-Commerce: A Federated Learning Framework with Zero-Knowledge Verification for Creator Monetization

Xun Yi

The convergence of social networking and electronic commerce has given rise to the social e-commerce paradigm, where content creators serve as the primary drivers of consumer engagement and purchase decisions. However, this ecosystem faces a critical tension between the need for high-precision ad targeting to sustain monetization and the increasingly stringent requirements for user privacy preservation. Traditional centralized recommendation systems require the aggregation of massive user behavioral datasets, creating significant risks of data leakage and violating emerging regulatory frameworks. To address this challenge, we propose a novel framework titled Fed-ZKC (Federated Zero-Knowledge Creator). This architecture synergizes Federated Learning (FL) with Zero-Knowledge Proofs (ZKP) to enable privacy-preserving ad targeting while ensuring verifiable monetization attribution for creators. In our system, user preference models are trained locally on edge devices to prevent raw data transmission, while a cryptographic verification layer ensures that ad interactions are genuine without revealing user identities to the platform or the creators. Extensive experiments conducted on large-scale real-world datasets demonstrate that Fed-ZKC achieves recommendation accuracy comparable to centralized baselines while reducing privacy leakage risks by orders of magnitude. Furthermore, the implementation of succinct non-interactive arguments of knowledge (zk-SNARKs) introduces minimal computational overhead, making the protocol feasible for deployment on modern mobile processors.

Open access
Privacy-Preserving Technologies in Data
Cryptography and Data Security
Privacy, Security, and Data Protection
Original source
Feb 1, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
Privacy-Enhancing-Technologies für die Informationssicherheit in Edge-Cloud-Anwendungen

Nils Frederic Jahnke, Sarah Schimankowitz

Edge-Cloud-Systeme ermöglichen Anwendungen, die auf Basis von Daten intelligenter Objekte und Infrastrukturen wirtschaftliche Mehrwerte schaffen und gesellschaftliche Herausforderungen adressieren. Dies bedarf häufig eines Teilens von Daten mit Partnern in etablierten Wertschöpfungsnetzwerken oder entlang des Edge-Cloud-Kontinuums. Eine fundamentale Anforderung ist dabei die Sicherstellung des Schutzes sensibler betrieblicher und personenbezogener Informationen. Während die lokale Datenverarbeitung an der Edge ein grundlegendes Maß an Datenschutz und Informationssicherheit ermöglicht, reicht ein ausschließlicher Rückgriff auf diese Maßnahme oftmals nicht aus, um diese Anforderungen bei gleichzeitiger Erzielung der Mehrwerte datengetriebener Anwendungen zu erfüllen. Beispielsweise besteht häufig die Notwendigkeit, schützenswerte Daten an zentraler Stelle, beispielsweise der Cloud, zu aggregieren, um zu reichhaltigen Erkenntnissen zu gelangen oder die Integrität der verwendeten Daten sicherzustellen. An dieser Stelle rücken Privacy-Enhancing-Technologies (PET) in den Fokus, die Mechanismen umfassen, um Datenschutz, Informationssicherheit und Datensouveränität „by-Design“ in Systemarchitekturen zu integrieren. Bei PET handelt es sich um eine Klasse von individuellen Werkzeugen, die jeweils spezifische Informationssicherheitsanforderungen und -risiken in Edge-Cloud-Systemen adressieren können. Für Praktiker ergibt sich die Herausforderung, auf Basis der spezifischen Bedarfe ihrer Anwendungen und der verfügbaren PET-Werkzeuge passende PET-Strategien zu entwickeln, die eine Realisierung der Edge-Cloud-Anwendung unter Berücksichtigung der Anforderungen und Risiken für die Informationssicherheit ermöglichen. Diese Orientierungshilfe unterstützt Praktiker bei der Entwicklung eigener PET-Strategien für Edge-Cloud-Anwendungen. Sie bietet Hilfestellungen bei der Identifikation von Informationssicherheitsanforderungen und -risiken, der Auswahl passender PET-Werkzeuge und deren Integration in das Anwendungsdesign. Zentrales Element der Studie ist hierbei die Analyse von PET-Werkzeugen in Edge-Cloud-Anwendungskontexten. Die Orientierungshilfe zeigt, wie PET-Werkzeuge zur Umsetzung von Informationssicherheit beitragen können, welche Voraussetzungen für ihren Einsatz in spezifischen Szenarien geschaffen werden müssen und welche Implikationen sich aus dem Praxiseinsatz der PET-Werkzeuge ergeben. Dazu beruft sich die Orientierungshilfe auf die Erkenntnisse der Early-Adopter von Edge-Cloud-Systemen und PET aus den Projekten des Technologieprogramms „Edge Datenwirtschaft“ des Bundesministeriums für Forschung, Technologie und Raumfahrt (BMFTR). Die Inhalte dieser Orientierungshilfe adressieren insbesondere Systemarchitektinnen und -architekten und Datenschutzbeauftragte, die Datenverarbeitungsprozesse in Edge-Cloud-Systemen datenschutzkonform gestalten müssen. Ausgehend von der Darstellung möglicher Risiken wie physischen Angriffen und Cyberangriffen, unsicherer Datenhoheit, Insiderbedrohungen und Fehlkonfigurationen sowie Anforderungen wie Datenminimierung, Integrität, Zweckbindung und die Verhinderung von Datenabflüssen „by-Design“ in Edge-Cloud-Anwendungen analysiert diese Orientierungshilfe fünf konkrete PET-Werkzeuge in praxisnahen Anwendungsszenarien: § Hardware-Schlüssel für die sichere Authentifizierung ohne personenbezogene Daten in der Lebensmittelwirtschaft, § Federated-Learning für kollaboratives KI-Training ohne Rohdatenweitergabe in der industriellen Fertigung, § Compute-to-Data zur Ausführung von Analysen in der Umgebung des Dateneigentümers in der industriellen Fertigung, § Zero-Knowledge-Proofs für datenbasierte Nachweise ohne Offenlegung sensibler Daten in der Energiewirtschaft, § Trusted-Execution-Environments für vertrauliche Berechnungen in isolierten Hardware-Umgebungen in der Energiewirtschaft. Zudem präsentiert die Studie vier Handlungsfelder und zugehörige Handlungsempfehlungen für den erfolgreichen Einsatz von PET-Werkzeugen in Edge-Cloud-Anwendungen: 1) Aufbau vertrauenswürdiger Partnerökosysteme und Schaffung notwendiger Anreizmechanismen, 2) Schaffung betrieblicher Voraussetzungen für den PET-Einsatz inklusive Schulung und Akzeptanzförderung, 3) Sicherstellung technischer Validität und Integrationsfähigkeit der PET in den Anwendungskontext, 4) Gewährleistung regulatorischer Konformität der PET-gestützten Edge-Cloud-Anwendung. Im Zuge der steigenden Relevanz von Edge-Cloud-Systemen und dem Teilen von Daten zur Generierung von Datenwertschöpfung bei mindestens gleichbleibenden Anforderungen an Datenschutz und Informationssicherheit wird der Einsatz von PET zu einem entscheidenden Erfolgsfaktor. PET ermöglichen nicht nur die Einhaltung regulatorischer Vorgaben, sondern schaffen die Grundlage für vertrauensbasierte Kooperationen in komplexen Edge-Cloud-Ökosystemen. Unternehmen, die zukünftig gemeinsam datengetriebene Wertschöpfung betreiben wollen, sollten sich aktiv mit PET beschäftigen.

Open access
2 source records
Privacy, Security, and Data Protection
Digitalization, Law, and Regulation
Cloud Data Security Solutions
Original source
Feb 1, 2026·International Journal of Social Science Research (IJSSR)
0 cites
PROTECTING POCKETS IN THE DIGITAL AGE: CRYPTOCURRENCY AND CONSUMER LAWS IN INDIA

Pankhi Devi, Prof. (Dr.) Bhuban Ch.Barooah

The anonymity of cryptocurrency transactions poses substantial obstacles to protecting consumer rights, particularly by hindering tracking and dispute resolution, thereby making it challenging to safeguard consumers. This article examines India's legal framework for protecting consumers engaging in cryptocurrency transactions. It highlights the multifaceted challenges consumers face, including fraud, hacking, phishing, and market manipulation, primarily due to the anonymous nature of cryptocurrency transactions and the inherent lack of robust regulation. Comparing India's approach with that of the US, EU, and Japan, it identifies noticeable gaps in current regulations and subsequently proposes specific, actionable recommendations for improvement. The article emphasises the imperative need for consumer education and awareness, as well as for international cooperation among policymakers, industry stakeholders, and regulators to create a safer, more secure cryptocurrency environment. By analyzing consumer protection laws in depth and proposing amendments, it aims to balance transaction security effectively with investor protection, ultimately promoting a more reliable cryptocurrency ecosystem in India while also suggesting practical implementation strategies for regulators and fostering transparency in decentralized finance (DeFi) platforms to enhance overall market integrity. It further outlines specific policy frameworks that can be adopted to mitigate risks associated with anonymity, alongside actionable steps for enhancing dispute-resolution mechanisms and ensuring continual compliance with evolving global standards in digital asset regulation. KEYWORDS:- cryptocurrency transactions, consumer rights, legal framework, consumer education, transaction security

Open access
Cybersecurity and Cyber Warfare Studies
Privacy, Security, and Data Protection
Copyright and Intellectual Property
Original source
Feb 1, 2026·Proceedings on Privacy Enhancing Technologies
0 cites
The Masks We (Think We) Wear: Privacy Threats of Browser-Extension Wallets in the Web3 Ecosystem

Weihong Wang, Yana Dimova, Victor Vansteenkiste, Tom Van Goethem · 5 authors

Cryptocurrency wallets are the primary interface for managing pseudonymous blockchain addresses, viewing balances, and interacting with Web3 applications. Although users typically assume that their addresses remain independent of each other unless intentionally revealed, modern wallets routinely communicate with both blockchain infrastructure and decentralized applications (dApps), generating network-side and web-side signals that may undermine this assumption. In this paper, we identify and formalize five privacy threats that arise directly from wallets interacting with the network and the web browser. Using large-scale dynamic measurements of 85 of the most popular Chrome Web Store browser-extension wallets (representing 35.16 million users), we observe that routine remote procedure call (RPC) operations leak structural links between a user's addresses; that the majority of Ethereum wallets implement permission revocation inconsistently and continue to expose previously revoked addresses across sessions; and that many wallets inject their provider interfaces into cross-origin iframes, enabling passive cross-site tracking beyond dApps and potentially real-world identity deanonymization without user interaction. Taken together, our results show that these wallet behaviors leak sensitive information that can be used to link multiple addresses to the same user, track wallet users across sessions and sites, and connect their browsing activity to their on-chain wealth. We discuss practical mitigations and show that many of these threats can be substantially reduced through improved wallet implementation, stronger privacy considerations in ecosystem standards, and stricter controls over provider exposure. Our results highlight the need for standardized, privacy-preserving wallet architectures and provide actionable guidance for strengthening user privacy in the emerging Web3 ecosystem.

Open access
5 source records
Privacy, Security, and Data Protection
Advanced Malware Detection Techniques
Spam and Phishing Detection
Original source
Jan 25, 2026·Open MIND
0 cites
The Stateless Pattern: Ephemeral Coordination as the Third Pillar of Digital Sovereignty

Sean Carlin, Kevin Curran

For the past three decades, the architecture of the internet has rested on two primary pillars - communication on the World Wide Web and Value such as Bitcoin/Distributed ledgers. However, a third critical pillar, Private Coordination has remained dependent on centralised intermediaries, effectively creating a surveillance architecture by default. This paper introduces the 'Stateless Pattern', a novel network topology that replaces the traditional 'Fortress' security model (database-centric) with a 'Mist' model (ephemeral relays). By utilising client-side cryptography and self-destructing server instances, we demonstrate a protocol where the server acts as a blind medium rather than a custodian of state. We present empirical data from a live deployment (https://signingroom.io), analysing over 1,900 requests and cache-hit ratios to validate the system's 'Zero-Knowledge' properties and institutional utility. The findings suggest that digital privacy can be commoditised as a utility, technically enforcing specific articles of the universal declaration of human rights not through policy, but through physics.

Open access
3 source records
cs.CR
Cybersecurity and Cyber Warfare Studies
Privacy, Security, and Data Protection
Original source
Jan 14, 2026·Cogent Social Sciences
1 cites
Legal foundations and future directions of AI-enabled cybersecurity: a cross-jurisdictional analysis

Mohamed Chawki

In the contemporary global context, Information and Communication Technologies (ICTs) present multifaceted challenges, particularly in maintaining an appropriate balance between national security requirements and the protection of individual privacy. The rapid advancement of technology has led to an increase in cyber threats, necessitating closer collaboration between the public and private sectors. However, such collaboration often blurs the boundaries between security imperatives and individual privacy rights. This study examines the implications of this balance and assesses whether existing regulations adequately protect individuals’ privacy. The right to privacy is universally safeguarded by ethical norms and legal frameworks. Instruments such as the United States Constitution and the General Data Protection Regulation (GDPR) provide protection against unlawful searches, seizures and the misuse of personal data. Despite these safeguards, information sharing between public institutions and private entities may undermine privacy rights if appropriate accountability mechanisms are not in place. Navigating this complex terrain requires approaches that enable data collection and cybersecurity cooperation without violating individual privacy. Technological innovations, including artificial intelligence (AI) and zero-knowledge proof authentication systems, offer potential solutions by limiting unauthorized access to personal data. This paper argues that reconciling cybersecurity imperatives with the protection of individual rights requires continuous recalibration of legal and ethical boundaries. While data sharing within and across private industries can strengthen defenses against cyber threats, such practices must be carefully evaluated to prevent privacy violations. Achieving this balance ultimately depends on enhanced transparency and accountability.

Open access
Ethics and Social Impacts of AI
Privacy, Security, and Data Protection
COVID-19 Digital Contact Tracing
Original source
Jan 8, 2026·Global Business Review
2 cites
Exploring User Trust in Non-fungible Tokens: A Structural Equation Modelling Perspective

Rangin Lahiri, Subrata Saha, Saikat Chakrabarti

We examined seven factors that shape buyers’ trust in non-fungible tokens (NFTs): authenticity, cost, operational transparency, community behaviour, security, utility and credibility. Through exploratory factor analysis and structural equation modelling, we explore the influence of the factors and subfactors on trust perceptions and levels of confidence of NFT buyers. The results suggest that transparency, cost, community engagement and security measures increase the trust of users, while credibility and utility have little impact. Key point to note, authenticity showed less significant influence on trust, which may be due to the reason of imprecise understanding of the subfactors. The study provides practical recommendations to promote user engagement and loyalty among NFT platforms, focusing on transparency, thorough security audits and active community governance. Ultimately, this research contributes to a deeper understanding of trust dynamics within the rapidly evolving NFT ecosystem.

Technology Adoption and User Behaviour
Privacy, Security, and Data Protection
User Authentication and Security Systems
Original source
Jan 2, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
Bitcoin Custody Failure Modes: A Taxonomy for Professional Interpretation

CustodyStress

Bitcoin custody systems are designed by individuals with full contextual knowledge and later encountered by others—executors, trustees, attorneys, heirs—who must interpret and operate these systems without the original owner present. This interpretive gap produces recurring failure patterns that persist even when custody components technically exist. This paper presents a taxonomy of failure modes observed in Bitcoin custody systems when those systems are encountered under stress conditions including death, incapacity, device loss, and institutional failure. The taxonomy distinguishes between legal authority and cryptographic access, between security and survivability, and between documentation that enables action and documentation that merely describes existence. Seven failure mode categories are examined: (1) documentation without usability, where correct and comprehensive records nonetheless fail to enable execution; (2) time as an active dependency, where dormant systems degrade through institutional change, memory loss, and technological obsolescence; (3) dependency overlap, where apparently redundant components share hidden common roots; (4) partial access traps, where incomplete recovery attempts constrain or block subsequent paths; (5) authority-access misalignment, where legal entitlement and operational capability diverge; (6) coordination failure, where distributed control prevents action when parties cannot align; and (7) delay-induced state changes, where outcomes differ based on when recovery is attempted. The paper provides canonical vocabulary for professional communication about custody situations and offers a scenario reference for modeling system behavior under stress. It is intended as a descriptive reference for fiduciaries, estate planning attorneys, and advisors who encounter Bitcoin custody systems in professional contexts. The paper does not provide recommendations, evaluate custody arrangements, or establish standards of care.

Open access
2 source records
Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Privacy, Security, and Data Protection
Original source
Jan 1, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
Examining Bitcoin Custody Under Stress: A Framework for Observation and Recording

CustodyStress

Bitcoin custody systems are constructed under conditions of full knowledge and activated under conditions of partial knowledge. The person who designs a custody arrangement understands its components, dependencies, and intended operation. The person who later encounters that system—often an executor, trustee, or heir—must interpret and operate it without access to the designer's contextual understanding. This paper defines a descriptive framework for examining Bitcoin custody systems under stress conditions at a point in time, producing reference records for later interpretation. The framework treats examination as observation rather than evaluation: it records what exists, what dependencies connect components, and how the system behaves under modeled stress scenarios. It explicitly excludes advice, recommendations, certification, and adequacy assessment. The framework introduces four modeled outcome states—survives, constrained, blocked, and indeterminate—that describe observed system behavior without normative judgment. It defines stress conditions including owner absence, cognitive unreliability, device loss, institutional delay, and coordination failure. It specifies what reference artifacts examination produces: system snapshots, scenario-bound observations, dependency maps, and assumption registries. The paper addresses how professionals—attorneys, fiduciaries, advisors—can engage with examination records without overstepping interpretive boundaries. It distinguishes what records can establish (what was described, what was modeled, what assumptions applied) from what records cannot establish (adequacy, correctness, future outcomes). The framework is offered as a reference for professional contexts where Bitcoin custody must be understood by parties other than its original designer.

Open access
2 source records
Blockchain Technology Applications and Security
Internet Traffic Analysis and Secure E-voting
Privacy, Security, and Data Protection
Original source
Jan 1, 2026·SSRN Electronic Journal
0 cites
AGE VERIFICATION FOR ONLINE CONTENT COMPARATIVE ANALYSIS OF AZERBAIJANI LEGISLATION AND TEXAS HOUSE BILL 1181

Leyla Tomayeva

The increasing use of the internet by children in Azerbaijan to access harmful content demonstrates the weakness and absence of age verification mechanisms. The Law on the Protection of Children from Harmful Information has a comprehensive system of labeling information that is harmful to children on the offline and broadcasted information and has no direct enforcement mechanisms on the labeling of information on online and digital platforms. This research evaluates both the advantages and the missing aspects of the Azerbaijani system, outlines the enforcement mechanisms of the Texas House Bill 1181, and analyzes the constitutional and practical aspects of the enforcement mechanism of mandatory age verification. The Texas model provides a legal framework for age verification and was upheld under intermediate scrutiny in Free Speech Coalition, Inc. v. Paxton, raising significant privacy concerns. One of the concerns was disclosing users personal information to private platforms, which creates risks related to data collection, storage and potential misuse. Azerbaijan's digital identification systems, ASAN Imza and SIMA Imza, are implemented and are privacy- preserving, and therefore, the Texas system can be avoided by use of the given digital identification systems with the inclusion of the zero-knowledge proofs. The study focuses on the policy and the legal framework on the system to enhance the privacy aspects of the rights of the children, and in accordance with the data protection system, describes in detail the steps, legal aspects, and proposed changes to the privacy systems.

Open access
Law, Rights, and Freedoms
Legal Cases and Commentary
Privacy, Security, and Data Protection
Original source
Jan 1, 2026·SSRN Electronic Journal
0 cites
Privacy-Preserving Compliance: A Cryptographic Framework for Selective Disclosure in Regulated Markets

Oyelokiki George Egbedayo

Compliance verification in regulated markets requires that verifiers obtain confidence in an entity's regulatory status before making downstream decisions. The conventional resolution of this requirement is full disclosure of underlying evidence to each verifier on each verification occasion, with substantial cost to the entity's informational privacy and substantial duplication of sensitive-data storage across verifier organisations. Modern cryptography offers, in principle, the tools to better balance verifier information needs against entity privacy: zero-knowledge proof systems, selective-disclosure credentials, vector commitments, and privacy-preserving aggregation primitives are now mature enough for serious regulatory consideration. Yet the legal and regulatory frameworks under which these tools would be deployed have not caught up with their technical readiness. We develop the legal and policy case for adoption of a cryptographic framework for selective disclosure in regulated markets. We analyse the framework's interaction with data-protection law (UK GDPR, EU GDPR, US state-level privacy regimes), financial-services regulation (FATF Recommendations, FCA rules, BSA/AML obligations), employment law (right-to-work, employment background screening), and identity system regulation (eIDAS 2.0, US REAL ID, digital identity wallets). We identify the principal legal uncertainties that constrain adoption and propose specific reforms to resolve them: data-protection safe harbours for cryptographic verification protocols; reconceiving regulatory data-retention requirements in terms of cryptographic attestations rather than underlying evidence; standardising regulator-grade revocation mechanisms; clarifying the legal status of zero-knowledge proofs as admissible evidence in supervisory and enforcement actions. We make four policy recommendations: (i) data-protection regulators (ICO, EDPB, equivalent) should issue guidance affirming that cryptographic selective-disclosure protocols meeting specified properties are compliant with data-protection law; (ii) financial-services regulators should issue guidance clarifying that cryptographic attestations satisfying specified properties can substitute for evidence retention obligations under AML/KYC rules; (iii) standard-setters should coordinate cross-jurisdictional protocol standards through W3C, IETF, and ISO/TC 307 with regulator participation; (iv) legislators in jurisdictions with active digital-identity programmes (UK, EU, US, Singapore) should ensure that statutory frameworks accommodate selective-disclosure verification. The paper contributes to the law-and-economics literature on data sharing under privacy constraints, to the policy economics of RegTech, and to the legal-academic literature on emerging-technology regulation. It complements the technical and economic threads of work developed in companion papers in this series.

Open access
Privacy, Security, and Data Protection
Cybersecurity and Cyber Warfare Studies
Blockchain Technology Applications and Security
Original source
Jan 1, 2026·Brno University of Technology Digital Library (Brno University of Technology)
0 cites
Sybil-Resistant Identity Systems in Decentralized Environments

Michal Ľaš

Takmer všetky systémy pre správu identít, centralizované alebo decentralizované, používajú na zaistenie Sybil-rezistencie, ochrany pred útokmi, ktoré využívajú veľké množstvo falošných identít, centralizovaný prístup. Tieto systémy zvyčajne vyžadujú overenie prostredníctvom telefónneho čísla alebo dokladu totožnosti vydaného štátom. Cieľom tejto práce je navrhnúť a implementovať decentralizovaný systém pre správu identít, ktorý zabezpečí Sybil-rezistenciu, anonymitu používateľov a súkromie ich osobných údajov. Navrhované riešenie využíva overenie biometrie tváre a anti-Sybil analýzu sociálneho grafu. Pre zabezpečenie decentralizácie, anonymity a ochrany súkromia sa využívajú technológia blockchain, zero-knowledge proofs a trusted execution environments. Výsledkom je robustný systém, ktorý zabezpečuje jedinečnosť registrovaných užívateľov, ich anonymitu a súkromie bez spoliehania sa na centralizované autority. To predstavuje významný krok k dosiahnutiu samostatnej správy identít, ktorá je v dnešnom svete kľúčová, keďže osobné údaje sú cennou komoditou.

Cryptography and Data Security
Privacy-Preserving Technologies in Data
Privacy, Security, and Data Protection
Original source
Jan 1, 2026·FH JOANNEUM ePUB
0 cites
Design of an Alternative Identity Proofing Approach for Digital Onboarding to ID Austria

Sandro Stattmann

Digitale Identitätssysteme bilden eine zentrale Grundlage moderner Verwaltungs- und E-Government-Prozesse. Sie ermöglichen die sichere Interaktion zwischen Bürger:innen, staatlichen Stellen und privaten Diensten. Ein besonders kritischer Schritt ist dabei die Identitätsprüfung im Rahmen des Onboardings, da hier die Verbindung zwischen einer realen Person und einer digitalen Identität hergestellt wird. Bestehende Onboarding-Verfahren, etwa persönliche Identifikation, VideoIdent, biometrische Verfahren oder dokumentenbasierte Prüfungen, stellen dafür etablierte Mechanismen bereit, erfordern jedoch häufig die Verarbeitung sensibler personenbezogener Daten und stützen sich stark auf organisatorische Vertrauensstrukturen.Die vorliegende Arbeit untersucht, ob ein deterministischer, registerbasierter und kryptographisch unterstützter Matching-Ansatz auf den Onboarding-Prozess von ID Austria angewendet werden kann. Der Fokus liegt dabei nicht auf der Entwicklung eines neuen kryptographischen Bausteins oder eines vollständig neuen Identitätssystems, sondern auf der konzeptionellen Anwendung und prototypischen Umsetzung von Deterministic Privacy-Preserving Identity Matching als Onboarding-Modell. Dieser Ansatz wird im Rahmen der Arbeit als DPPIM-OM bezeichnet.Die Arbeit folgt einem konstruktiv-analytischen Vorgehen. Zunächst werden die technischen und konzeptionellen Grundlagen digitaler Identität, Identitätsprüfung, privacy-preserving Matching, OPRF/VOPRF-Mechanismen und Zero-Knowledge-Nachweisen analysiert. Darauf aufbauend wird ein Onboarding-Modell beschrieben, das deterministischen Full-Match, kanonisierte Attributrepräsentation, servergebundene kryptographische Auswertung, registerbasierten Vergleich und registergebundene Nachweisführung kombiniert. Anschließend wird ein Prototyp umgesetzt, um die technische Realisierbarkeit des Ansatzes unter kontrollierten Bedingungen zu demonstrieren.Das vorgeschlagene Onboarding-Modell wird dem aktuellen ID-Austria-Onboarding sowie VideoIdent-, biometrischen und dokumentenbasierten Verfahren gegenübergestellt. Die Evaluierung erfolgt entlang zentraler Dimensionen wie Datenexposition, Informationsleckage, Sicherheit, Missbrauchsresistenz, Vertrauensmodell, Verifizierbarkeit, Determinismus, Fehleranfälligkeit, Anforderungen an Datenqualität, Prozesskomplexität, Performance sowie Kompatibilität mit dem europäischen regulatorischen Rahmen.Die Ergebnisse zeigen, dass DPPIM-OM insbesondere in den Bereichen Datenminimierung, Informationskontrolle und Verifizierbarkeit deutliche strukturelle Vorteile aufweist. Gleichzeitig bringt der Ansatz spezifische Anforderungen und Einschränkungen mit sich, insbesondere hinsichtlich Datenkonsistenz, technischer Umsetzungskomplexität und fehlender direkter Personenbindung. Die Arbeit kommt zu dem Ergebnis, dass der Ansatz eine vielversprechende Möglichkeit zur Weiterentwicklung digitaler Onboarding-Prozesse darstellt, insbesondere in hybriden Modellen, die klassische Mechanismen zur Personenbindung mit einem deterministischen und kryptographisch überprüfbaren Attributabgleich kombinieren.

Access Control and Trust
Privacy-Preserving Technologies in Data
Privacy, Security, and Data Protection
Original source
Jan 1, 2026·Investing in Crypto with Confidence
0 cites
Criticisms of Bitcoin

Javier Pineda

No abstract is available for this record.

Blockchain Technology Applications and Security
Cultural Studies and Postmodernism
Privacy, Security, and Data Protection
Original source
Jan 1, 2026·Open MIND
2 cites
Poster: Privacy-Preserving Compliance Checks on Ethereum via Selective Disclosure

Supriya Khadka, Dhiman Goswami, Sanchari Das

Digital identity verification often forces a privacy trade-off, where users must disclose sensitive personal data to prove simple eligibility criteria. As blockchain applications integrate with regulated environments, this over-disclosure creates significant risks of data breaches and surveillance. This work proposes a general Selective Disclosure Framework built on Ethereum, designed to decouple attribute verification from identity revelation. By utilizing client-side zk-SNARKs, the framework enables users to prove specific eligibility predicates without revealing underlying identity documents. We present a case study, ZK-Compliance, which implements a functional Grant, Verify, Revoke lifecycle for age verification. Preliminary results indicate that strict compliance requirements can be satisfied with negligible client-side latency (< 200 ms) while preserving the pseudonymous nature of public blockchains.

Open access
5 source records
cs.CR
cs.HC
Privacy, Security, and Data Protection
Original source
Jan 1, 2026·Gesellschaft für Informatik (GI)
0 cites
Tensions Between Data Minimisation and Legal Proof Obligations: Zero-Knowledge Proofs in the EUDI Wallet

Alen Horvat, Steffen Schwalm, Johannes Sedlmeir, Hakan Yildiz

Among the privacy-enhancing technologies explored in the context of the European Digital Identity (EUDI) Wallets, zero-knowledge proofs stand out for their ability to maintain established levels of cryptographic verifiability while enabling data minimisation – relative to the requirements expressed by the relying party (RP). However, legal frameworks in many sectors require the collection of verifiable data beyond the RP’s immediate needs, which may substantially narrow down the scope of data minimisation that can be achieved in regulated domains. Accordingly, this paper examines the tensions between the strict data minimisation requirements for the EUDI Wallets and the extensive legal proof obligations that relying parties must fulfil. Our analysis of the regulatory foundations and relevant technical mechanisms identifies documentation, audit, and long-term preservation obligations as key sources for friction. We explore the implications of the corresponding tensions, point to gaps in current standardisation and compliance regimes, and suggest potential technical and non-technical solution approaches that could help reap the benefits advanced privacy-enhancing technologies can offer in practice.

Open access
Cryptography and Data Security
Privacy, Security, and Data Protection
Blockchain Technology Applications and Security
Original source
Jan 1, 2026·Journal of Institutional Economics
1 cites
Verified pseudonymity as governance technology: decentralized identity, soulbound tokens, and online discourse

Christos A. Makridis

Abstract Cheap, disposable online identities make abuse easier to externalize. Users can harass, evade bans, amplify content through fake accounts, or abandon a damaged reputation at low cost, while other users, moderators, and platforms bear the consequences. This paper examines verified pseudonymity as an institutional response to that problem. First, I model online communities as club-governed informational commons in which incivility degrades the shared environment and raises enforcement costs. The model shows that conduct can improve when sanctions attach to a persistent pseudonymous identity and when users have future access, reputation, or governance rights at stake. Second, I compare verified pseudonymity with open pseudonymity, real-name mandates, centralized know-your-customer verification, algorithmic moderation, and no intervention. Decentralized identifiers, verifiable credentials, proof of personhood, and non-transferable standing credentials matter because they can separate authentication from public identification. Third, I add a community-currency layer that separates access to scarce attention from governance rights. The result is a governance framework in which accountability depends less on public naming than on durable standing, credible sanctions, and reusable privacy-preserving credentials.

Open access
Hate Speech and Cyberbullying Detection
Privacy, Security, and Data Protection
Cybercrime and Law Enforcement Studies
Original source
Jan 1, 2026·SSRN Electronic Journal
0 cites
The Dawn of a New Era for the Internet: A Discussion of the Global Need, Ethics, and Criteria for Web3

Jonathan C Kraft

The Internet has evolved from its early promise of global connection and freedom into a centralized system dominated by Big Tech and governments, resulting in widespread data exploitation, surveillance, censorship, and erosion of user privacy and ownership. This paper traces the historical development of Web2 infrastructure, its foundational flaws—particularly the linkage of digital identities to real-world persons and the unchecked power of intermediaries—and the societal pressures that have exposed these vulnerabilities through events such as the Great Firewall of China, the Snowden revelations, the Cambridge Analytica scandal, and large-scale hacks. In response, the paper positions Web3 , underpinned by blockchain technology, as a necessary paradigm shift toward a decentralized, user-centric Internet. Web3 severs the tie between digital and physical identities, enables true data ownership, peer-to-peer encryption, global accessibility without geo-restrictions, and algorithmic governance that reduces reliance on potentially abusive middlemen. It argues that Web3 can encode core democratic values, including freedom of expression as articulated in Article 19 of the Universal Declaration of Human Rights, while addressing resistance from governments (concerned with control and taxation), Big Tech (threatened by loss of data monopolies), and everyday users (wary of complexity and perceived risks). The paper examines ethical considerations, potential misuse by bad actors, and the dual nature of technological innovation. It proposes four critical criteria for evaluating successful Web3 implementations: 1) affordability and equitable access with long-term cost reduction; 2) robust protection of individuals through privacy and bias mitigation, coupled with "freedom of speech, not reach"; 3) absence of any central governing body with control over development; and 4) a community-representative judicial system for handling violations of shared terms of service. Ultimately, this work contends that Web3 represents an inevitable evolution capable of empowering billions of users—particularly those in repressive regimes—by fostering transparency, equity, and self-governance, provided implementations adhere to these ethical and practical standards. It calls for cautious optimism, due diligence, and open-source verification in the transition to a more liberated and democratic digital era.

Open access
2 source records
Cybersecurity and Cyber Warfare Studies
Privacy, Security, and Data Protection
Impact of Technology on Adolescents
Original source
Dec 31, 2025·The Eastasouth Journal of Information System and Computer Science
0 cites
Mapping Blockchain Identity Management Research: A Bibliometric Analysis (2010–2025)

Loso Judijanto

This study presents a comprehensive bibliometric analysis of blockchain identity management research published between 2010 and 2025, aiming to map its intellectual structure, thematic evolution, and global collaboration patterns. Using data retrieved from the Scopus database and analyzed with VOSviewer, the study applies network visualization, overlay visualization, density mapping, citation analysis, and co-authorship analysis to uncover dominant research streams and emerging frontiers. The results reveal that the field is conceptually centered on blockchain-based authentication and decentralized identity management systems, with increasing scholarly attention toward privacy-preserving mechanisms such as zero-knowledge proofs, anonymity, and data protection. Thematic evolution indicates a clear transition from foundational infrastructure-oriented studies to application-driven and regulatory-sensitive research domains, including e-government, IoT, healthcare, and digital governance. Collaboration analysis highlights the leading role of China and India, supported by strong transcontinental linkages with the United States and European countries, reflecting a globally interconnected yet regionally concentrated research landscape. By systematically mapping publication trends, thematic clusters, and collaboration networks, this study provides a structured knowledge base that supports future theoretical development, guides practical implementation, and informs policy formulation in blockchain-based digital identity ecosystems.

Open access
Blockchain Technology Applications and Security
Privacy, Security, and Data Protection
Cybercrime and Law Enforcement Studies
Original source
Dec 22, 2025·2025 International Conference on Computer and Applications (ICCA)
0 cites
Blockchain based Privacy Solutions Brokered with AI for Data Compliance

Nachiappan Chockalingam, Rajesh Purushothaman, Jeevan Shanbhag, Arun Kumar Elengovan · 8 authors

This paper introduces an AI based Privacy Broker (AIBPB), a unified framework that combines blockchain, zero knowledge proofs, attribute based encryption, and differential privacy to enable verifiable and compliant data sharing in regulated environments. The system automatically interprets high level policies such as GDPR, HIPAA, and CCPA, and synthesizes optimized proof strategies through a multi objective cost privacy model. The architecture blends off chain cryptographic computation with on chain verification to balance privacy and transparency. Simulation based experiments demonstrate a 3.2 times improvement in proof generation latency, a 7.8 times reduction in information disclosure, and regulatory satisfaction rates exceeding 95% compared to baseline approaches. The results show that AI driven proof orchestration can significantly enhance scalability, compliance automation, and privacy protection in blockchain based systems.

Privacy-Preserving Technologies in Data
Blockchain Technology Applications and Security
Privacy, Security, and Data Protection
Original source
Dec 10, 2025·Journal of Money Laundering Control
1 cites
Privacy and national security issues relating to the introduction of a central bank digital currency in Australia

Nancy Michail, Niloufer Selvadurai, Doron Goldbarsht

Purpose The purpose of this paper is to analyse privacy and national surveillance laws in Australia, including but not limited to the federal Privacy Act 1988 and the federal Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (AML/CTF), to determine whether a tension exists between these two statutes within the context of the deployment of central bank digital currency (CBDC) in Australia. Design/methodology/approach The paper adopts doctrinal and normative approaches for analysis of the relevant legislations. Furthermore, the paper adopts a functionalist theoretical perspective to interrogate the interrelationship between regulation and society. Findings The paper suggests that the relevant legislations contain undefined terms, such as “reasonable grounds”, which may give the appearance of a balanced approach to the interactions between privacy and national surveillance laws within the context of deployment of CBDCs. The paper argues that lack of definition of these terms, however, renders the terms ineffective, leading to a potential regulatory overreach. The paper recommends administrators need internal policies and procedures that would give clear guidance on the possible meanings of those legislative terms to achieve the balance desired between privacy and national security requirements in Australia when deploying CBDCs. It is suggested that internal policies are to base suspicion on factual basis for decision-makers to have reasonable grounds for contravening privacy legislations. This may be achieved through requiring decision-makers to justify their decisions and consider alternative options before infringing on privacy, thus enhancing accountability. Furthermore, it is suggested that the transparency and traceability provided by distributed ledger technologies will compel decision-makers to assess the benefits of privacy violations against their costs, promoting a balanced approach to surveillance and personal data disclosure. Originality The originality of the paper lies in its seminal analysis of the interaction of privacy an anti-money laundering laws in the context of the introduction of a central bank digital currency.

Privacy, Security, and Data Protection
Cybercrime and Law Enforcement Studies
Blockchain Technology Applications and Security
Original source
Dec 8, 2025·European Scientific Journal ESJ
0 cites
Self-Sovereign Identity Architecture for National Use with Wallet Proofs Zero-Knowledge and the VWR Framework

M. A. Mansur

National identity systems require efficient, equitable decision-making that safeguards personal data. This article proposes a Self-Sovereign Identity (SSI) architecture, supported by a Verify-Without-Reveal (VWR) framework, designed for national-scale implementation. SSI places credentials in a citizen wallet and enables selective disclosure and zero-knowledge proofs, so services can verify attributes without seeing underlying records. VWR adds the policy and accountability spine: yes/no attribute APIs for holder-absent cases, purpose-bound and zero-trust enforcement on every call, and an immutable audit layer on a permissioned ledger. The study synthesises current standards and leading implementations in Europe and worldwide and formulates a deployable blueprint with clear roles, consent and lawful-override flows, per-agency pseudonyms, and regulator and citizen visibility. The study outlines reference APIs, user experiences for wallets and verifiers, and performance metrics suited for national workloads. Privacy-preserving AI strengthens biometric liveness, fraud detection, and anomaly response without centralising sensitive data. The framework aligns with GDPR data minimisation and purpose limitation, supports the European Digital Identity Wallet, and meets high-risk AI governance requirements. Results show how SSI proofs and VWR controls reduce unconsented disclosure and cross-agency browsing, while keeping latency low and interoperability high. The contribution is both conceptual and operational: a phased migration path that turns verify-without-reveal into the default mode for government and regulated services, improving security, inclusion, and public trust.

Open access
2 source records
Ethics and Social Impacts of AI
Privacy, Security, and Data Protection
COVID-19 Digital Contact Tracing
Original source