This paper presents TrustBridge, the first universal decentralized trust protocol integrating multi-agent LLM consensus, zero-knowledge proof generation, blockchain attestation, and natural language accessibility for real-world credential verification across employment, education, healthcare, and supply chain domains. The multi-agent consensus engine runs three independent Claude Sonnet instances in parallel, achieving 92% adversarial detection on a controlled test set — a 30 percentage point improvement over single-agent architectures. Zero-knowledge commitment schemes allow claimants to prove credential properties without revealing private values. An ERC-721 NFT certificate provides immutable on-chain attestation. This is Paper 1 of a planned two-paper series. Paper 2 will report large-scale deployment results and full ZK-SNARK integration. Targeting: IEEE Blockchain 2027
LoisID proposes a portable trust and reputation infrastructure designed to enable individuals and organizations to accumulate, verify, and transport trust across digital ecosystems. The framework extends beyond identity verification and introduces a reusable trust layer for finance, education, employment, governance, and Web3 environments. By transforming trust into a portable and interoperable digital asset, LoisID seeks to address reputation fragmentation and establish a foundation for the next generation digital economy.
Trusted Execution Environments (TEEs) have emerged as a critical technology for safeguarding sensitive data and ensuring code integrity in modern computing systems. However, relying on a single TEE implementation makes systems vulnerable to a central point of attack. Building distributed-trust systems leveraging heterogeneous TEEs helps disperse trust but still faces threats from centralized management and adaptive mobile adversaries. To address these challenges, this paper introduces TeeDAO, a novel three-layer framework that automatically organizes multiple heterogeneous TEE instances and provides unified interfaces to support diverse applications, while ensuring long-term guarantees of availability, integrity, and confidentiality. TeeDAO couples BFT-ordered governance with heterogeneity-aware Distributed Proactive Secret Sharing (DPSS) and Secure Multi-Party Computation (MPC) so that attestation-driven committee changes are consistently reflected in secret recovery, resharing, and computation across a dynamic committee of heterogeneous TEEs. We implement a prototype of TeeDAO, integrating COBRA's DPSS scheme with the HotStuff BFT consensus protocol, and adapt it for Intel SGX, TDX, and Hygon CSV. Evaluations demonstrate that TeeDAO achieves up to 1.8x higher key-value store throughput in a large cluster with 61 nodes compared to state-of-the-art systems, efficient autonomous management, and minimal computation overhead (<18%) for multi-party computation tasks.
This technical note introduces the AIKernel Hash-Anchored Trust Layer (HATL), a hybrid trust architecture for Semantic Context Operating Systems and autonomous AI runtimes. HATL separates the trust boundary into an inner high-frequency symmetric ledger and an outer publicly auditable anchoring layer. The inner layer uses HMAC-SHA-512 and HKDF-based forward ratcheting to bind ReplayLogs, execution outcomes, and capability states with low runtime overhead. The outer layer aggregates local ledger commitments into Merkle roots and periodically anchors them using hash-based public signature mechanisms such as LMS, XMSS, and SLH-DSA. The report is distributed as a three-part technical package. Part I contains the full English manuscript and is the canonical version. Part II contains technical appendices, repository specifications, schemas, and reference implementation artifacts. Part III contains the Japanese companion translation. This version incorporates review-driven clarifications on secure erasure in C# / .NET environments, fail-closed handling of indeterminate governance decisions, and future integration of zero-knowledge proof techniques for public anchor verification. Documents are licensed under CC BY 4.0. Code, schemas, and contract specimens included in the appendices are provided under Apache-2.0.
Decentralized verifiable credential systems have seen limited deployment in practice. Existing constructions, built on zero-knowledge proofs, are complex, application-specific, and largely restricted to predicates over structured data. We present Privately Inferred Credentials ($π$Creds): privacy-preserving, legacy-compatible, decentralized verifiable credentials generated by trusted LLM inference over authenticated data. LLMs' ability to semantically reason over unstructured data substantially expands the range of claims $π$Creds can certify over existing credential systems. The use of LLMs also introduces new application-level threats, which we formalize through two problems: the Source-Constrained Adversarial Example (SCAE) problem, which captures robustness against adversaries that manipulate authenticated data to obtain misleading credentials, and the Authenticated Covert Predicate Poisoning (ACPP) problem, which captures privacy leakage through adversarial model selection. We characterize applications of $π$Creds over user data, and a novel class of credentials over proprietary software that certifies properties of a service without revealing its source code. Our prototype supports issuing credentials over live financial, health, email, and code sources, and we empirically study the SCAE and ACPP threats on a product expertise credential over real financial data.
We present ENI6MA and Rosario Cypher as a proof-based identity and authorization architecture for emerging cybersecurity threats involving shadow AI, deepfakes, prompt injection, autonomous agents, credential theft, privacy exposure, and post-quantum risk. The paper responds to major 2026 cybersecurity forecasts by identifying a common root cause across many attack surfaces: conventional systems depend on reusable, stealable artifacts such as credentials, tokens, private keys, sessions, API keys, and stored personal data. ENI6MA replaces possession-based authentication with per-event proof of knowledge, policy-bound authorization, privacy-clean auditability, and contract enforcement behind cryptographically secure proof. Special attention is given to autonomous-agent security. The paper explains how ENI6MA constrains agents through per-action proof, verifier allowlists, policy identifiers, scoped pass credentials, and immutable validation records, reducing the risk of hijacked agents, excessive privilege, non-human identity sprawl, and zero-click prompt-injection exfiltration. The white paper also describes ENI6MA’s flexible deployment and capability model, including passwordless single sign-on, PII validation without disclosure, agent-to-agent authentication, proof-gated signing and custody, post-quantum sealing, sovereign/offline operation, and public verifier anchoring. This document is intended for cybersecurity leaders, AI governance teams, identity architects, privacy and compliance stakeholders, investors, technology partners, and researchers evaluating post-credential identity systems for human and autonomous-agent workflows.
Samukeliso Mabarani, Mohammad Saidur Rahman, Iqbal Gondal, H. M. N. Dilum Bandara
The tokenization of real-world assets (RWAs) through non-fungible tokens (NFTs) has introduced new opportunities for liquidity, enabling fractional ownership of traditionally illiquid assets. Yet, current NFT fractionalization models remain static, lacking adaptive governance and real-time responsiveness required for managing the dynamic nature of RWAs. This paper presents an Adaptive NFT Fractionalization Framework with Rights Segregation that integrates modular smart contracts, oracle data, and machine learning (ML) insights to enable dynamic rights management. The framework segregates and defines distinct rights, governed through cross-layer decision-making and adaptive rights management that updates allocations based on market data and predictive analytics. Experimental results demonstrate accurate, real-time adjustments of fractional rights, consistent governance execution, and efficient gas utilization across stress and concurrency tests. The findings validate the framework's scalability, responsiveness, and cost-effectiveness, establishing it as a viable approach for adaptive, data-driven management of fractionalized RWAs.
Foundational agent interoperability standards, notably the Agent-to-Agent (A2A) protocol and the Model Context Protocol (MCP), have advanced multi-agent system communication, and complementary identity frameworks leveraging W3C Decentralised Identifiers (DIDs) and Verifiable Credentials (VCs) provide cryptographic agent authentication. However, no existing protocol supports content-based semantic routing of agent payloads across organisational trust boundaries without requiring the routing intermediary to decrypt the payload, which is a hard constraint in compliance-sensitive environments governed by GDPR, HIPAA, and MiFID II. We propose SS-ZKR, a three-mechanism privacy-preserving routing protocol designed as a complementary layer atop A2A/MCP. Mechanism I introduces blind routing via differentially private semantic intent vectors cryptographically bound to zero-knowledge proofs of payload-schema consistency. Mechanism II offers vector-weighted adaptive payload sanitisation with formal (epsilon, delta)-differential privacy for numerical fields and heuristic semantic aggregation for textual fields. Mechanism III presents a spatial-to-cryptographic policy compiler that translates visually defined trust-zone topologies into deterministic zero-knowledge access circuits. We provide a formal threat model, analyse information leakage bounds of intent vectors, present pseudocode for all three mechanisms, and give analytical complexity comparisons against TEE-based and homomorphic encryption-based routing baselines. SS-ZKR lets enterprises in financial services, healthcare, and defence orchestrate heterogeneous AI agents across regulatory boundaries without exposing proprietary data to routing infrastructure.
Abstract As AI agents evolve into autonomous economic actors, verifiable and legally binding identity frameworks become critical. This paper presents Ricardian-TEA , a novel architecture combining Triple-Entry Accounting (TEA), Ricardian Contracts, and Distributed Ledger Technology to assign “Legal-Technical Identities” to AI agents. We provide rigorous mathematical foundations: a Ricardian-TEA Integrity Theorem proving that constraint enforcement, non-disputability, and identity binding hold with overwhelming probability under standard cryptographic assumptions, and a Cyber-Chama Convergence Proposition characterising reputation-based trust dynamics. The framework ensures GDPR compliance via Zero-Knowledge Architecture and Crypto-Shredding. Proof-of-concept implementations on Ethereum Sepolia and Bitcoin SV testnets demonstrate chain-agnostic applicability, achieving at worst 1.4 s latency per transaction while maintaining 100% auditability of AI transactions.
PARALLAX-5 is a transition-level obligation interface for value-bearing decentralized systems. The interface consists of five primitive obligations: value conservation, authorization closure, signature integrity, temporal distinctness, and external-attestation trust. Under an explicit security-interface adequacy condition, every trust-base-respecting loss-inducing transition has a non-empty violation signature; the claim is falsifiable by basis counterexamples that are precisely defined. The substrate composes with a production EVM semantics via a typeclass-based refinement: nineteen abstract theorems lift to compiled Lean 4 proof terms over EvmYulLean's EvmYul.EVM.State (Cancun fork). The Lean 4 module compiles to 95 theorems with zero sorry; 129 Python fire tests pass across three suites; a 53-incident empirical catalog (2016–2026, $5.97 billion aggregate losses) classifies each entry by minimum observability set. The package also defines a step-secure execution-time shield, an AI-Agent Containment Theorem, a five-component PARALLAX-CROPS trust-surface vector, a 19-field machine-checkable certificate schema with seven-state lifecycle, an onchain certificate registry (Solidity 0.8.24, live on Sepolia at 0x8015A98dF9037Cd79a03B291a6fF3C2841992D5b), and three worked examples covering value conservation, bridge attestation, and AI-agent runtime gating. The standard text is dedicated under CC0 with structurally irrevocable non-capturability commitments; code artifacts are released under Apache-2.0; this paper is licensed under CC-BY 4.0. v1.0.1 changes (vs v1.0.0, doi:10.5281/zenodo.20400525): repository-hygiene release. Removed four non-substrate subsystems (hse, product, economics, chronos) that were not paper-aligned. Standardized fire-test count from 134 to 129 to reflect the cleaned codebase. Restructured standalone specifications under docs/ directory with canonical names (CHARTER.md, FORK_PROTOCOL.md, CERTIFICATE_SCHEMA.md, etc.). Converted forge-std to a proper git submodule. Added CITATION.cff, CHANGELOG.md, CONTRIBUTING.md, SECURITY.md. The substrate's mathematical content, theorems, and verification gates are unchanged from v1.0.0.
The rapid expansion of decentralized financial applications has increased the importance of understanding user trust in crypto wallet platforms. This study examines trust expressions in multilingual Phantom Wallet reviews using a hybrid classification framework that integrates BERT-based contextual embeddings with an XGBoost model. A total of 12,422 English and Indonesian reviews were collected and processed to construct a multilingual dataset for trust analysis. Exploratory findings reveal a highly polarized distribution of user ratings, indicating that trust in crypto wallets is strongly influenced by clear satisfaction or dissatisfaction rather than moderate evaluations. Cross-linguistic analysis indicates that Indonesian users express a higher proportion of low-trust reviews compared to English users, suggesting greater sensitivity to transaction errors and perceived asset safety concerns. Lexical patterns demonstrate that positive trust is associated with usability and performance stability, while negative trust is primarily driven by system failures, delays, and missing balance incidents. The results confirm that the BERT–XGBoost hybrid model is well-suited for decoding trust-related signals by combining contextual semantic understanding with structured metadata. This study contributes to the broader discourse on digital trust within Web3 environments by demonstrating an effective multilingual machine learning approach for analysing user perceptions in decentralized financial technologies.
Validators on generic Proof of Stake chains earn the same fees whether they handle attestation work correctly or selectively censor it. For chains whose main activity is moving tokens around, that indifference is fine. For chains whose primary economic activity is recording attestations (content provenance, AI-output attribution, threshold-signed credentials, supply-chain receipts), the indifference becomes a problem. Proof of Useful Attestation (PoUA) makes attestation handling first-class in the consensus weighting itself. Validator vote weight is the product of bonded stake and a reputation scalar in [r_min, r_max] that accumulates from valid attestation work. The reputation update is additive, fee-weighted, non-transferable, and capped per epoch. We prove a cost-to-grind floor (Lemma 1): under chain-wide adaptive burn fraction tau_burn, the non-recoverable cost an adversary pays to inflate reputation by Delta_r is bounded below by tau_burn * Delta_r / (eta * alpha_eff). Under the recommended v0 calibration (r_max/r_min in [4, 10]), the cost premium against a capital adversary is 4x to 10x over equivalent pure-stake PoS at steady state. The paper specifies the mechanism, six layered Sybil and grinding defenses, empirical Monte Carlo strategy-search across the full layered defense, and grinding detectors with explicit threshold derivations. It is a mechanism-design proposal with a formal economic floor and inherited BFT safety and liveness, not a complete cryptographic security proof. This release incorporates feedback from Jiangshan Yu (University of Sydney) and Marko Vukolić (Bitcoin Scaling Labs).
Sybil attacks remain a primary challenge for Proof-of-Stake (PoS) blockchain systems, as low-cost identity creation can distort validator participation and limit consensus reliability. This study proposes a hybrid participation–governance framework that integrates Attribute-Based Access Control (ABAC) and Reputation-Based Access Control (RpBAC) with a trust-based PoS workflow to reduce the influence of suspicious identities during validator selection and block validation. The proposed framework also incorporates graylisting and dynamic reward–penalty updates to support adaptive participation control. The strategy was evaluated in a simulation environment informed by Ethereum-derived block metadata, using network sizes ranging from 100 to 1000 nodes and Sybil attack ratios of 30%, 40%, and 50%. Its performance was compared with PoS-only and PoS + ABAC baselines using both security and performance indicators. The results show that the full ABAC + RpBAC configuration achieved the strongest and most stable security performance across the evaluated settings while introducing additional overhead at larger network sizes. These findings suggest that combining policy-based eligibility control with behavior-based reputation control strengthens the resilience against Sybil in PoS-like blockchain environments. However, this improvement requires a measurable trade-off between security and performance.
Syed Abrar Ahmed, Ricardo Correia Bezerra, Simon Lewerenz, Henrique Martins
The EHDS Regulation establishes patient opt-out rights for data use, yet current implementations face fragmented registries and limited tamper-proof mechanisms. In this context, opt-out refers to a patient's proactive right to object to the reuse of their health data for purposes beyond direct clinical care. We propose a distributed ledger technology (DLT)-based architecture to enhance opt-out management. Using design research and regulatory analysis of EHDS and TEHDAS, we developed a proof-of-concept leveraging permissioned DLT, smart contracts, and decentralised identifiers for an immutable registry. This architecture aligns with EHDS requirements for tamper-evident audit trails and cross-border verification. This work bridges regulatory mandates with patient-centric governance across the EU.
Autonomous actors, including AI agents, decentralized autonomous organizations, decentralized unincorporated nonprofit associations, algorithmically managed funds, and individuals operating through programmatic interfaces, are increasingly executing financial transactions on distributed ledger networks without governance oversight. Existing approaches rely on application-level middleware operating within the same trust boundary as the actors being governed, post-transaction monitoring that detects violations after irreversible execution, or multi-party computation systems that provide distributed key management without policy evaluation. This paper presents SovereignGate, a deterministic governance enforcement system that achieves structural enforcement through protocol-native multi-signature co-signing with disabled master keys. The system comprises a Rust enforcement kernel with layered crate dependencies, a deterministic policy evaluation engine with deny dominance and independent fact inference, a bylaws-as-code domain-specific language for encoding entity governance rules as content-addressed policy bundles, a cryptographic receipt chain with Ed25519-signed Merkle-anchored attestation, and a structural co-signing mechanism making transaction execution without governance approval structurally impossible at the consensus layer. The preferred embodiment integrates with the XRP Ledger. The architecture is chain-agnostic. No existing system combines deterministic policy enforcement, Merkle-chained cryptographic attestation, and structural protocol-level co-signing for autonomous financial actors.
The tremendous progress of medical foundation models has proven to be groundbreaking in meta-analysis of clinical prediction, diagnosis, and multimodal healthcare analytics, but the development of medical foundation models is limited due to stringent data privacy concerns, cross-institutional trust issues, and security risks in a collaborative learning environment. Traditional federated learning allows for distributed training of the model with no central sharing of data but is prone to poisoning of the model, inference attacks, and low verifiability of participating institutions. This study proposes an idea of Autonomous Trust and Zero-Knowledge Blockchain Framework (AT-ZKBF) for Federated Medical Foundation Models, to establish decentralized trust, cryptographic verifiability and secure collaboration among heterogeneous healthcare providers. The framework combines the foundation model training in a federated peer-to-peer setup, the permissioned blockchain network for trust orchestration and mechanisms using the zero-knowledge proof (ZKP) for model updates to avoid the content of sensitive parameters of the model. Every local update is cryptographically authenticated with zk-SNARK-based zero-knowledge proofs that check proper gradient descent running and limited limit on updates without exposing private gradients or data. A reputation-driven trust scoring module automatically scores the reliability of participants. Experimental evaluation done on a BraTs, a multi-institutional medical imaging dataset shows that the proposed framework can get 96.4% classification accuracy (up 4.8% vs. standard federated learning) with poisoning model control decreased by 63% and communication overhead reduced by 21% by optimized blockchain batching. Security analysis makes sure of the robustness from gradient inferences and Byzantine attacks. The validation upon integration of autonomous trust computation, and zero-knowledge cryptography to blockchain enabled federated learning substantially adds to security, transparency and scalability for collaborative medical foundation model training providing a probable way forward to privacy preserving trust worthy AI in healthcare ecosystems.
Autonomous trading agents can read markets and place orders faster than humans can supervise them. On a permissionless exchange, the usual answer is to give the agent a signing key. That is a large amount of trust. Anything that can steer the agent's prompt, memory, or context can also steer how the key is used. Recent attacks on Web3 agents show that this is not a hypothetical risk. Checking every order on the settlement chain gives a public record, but it also puts block latency in the order path. A continuous limit-order book cannot spend that. Bounded Authority puts the authority check where the order enters the venue. The user's wallet registers a risk policy on the settlement chain and authorizes a short-lived public session key. Agents propose orders. The off-chain sequencer accepts an order only after it verifies the session-key signature and runs the policy before any exchange state changes. For every accepted order, the sequencer signs the order, sequence number, risk-input hash, policy transition, match event, and append-only log leaf. Epoch roots are posted to settlement. Watchers can then challenge unauthorized orders, bad risk inputs, broken reserve or margin transitions, equivocation, or invalid matching with Merkle proofs and replayed execution. This gives agents a permissionless analogue of direct-market-access risk control. If a prompt-injected or memory-poisoned agent produces an order outside the user's policy, the result is slashable evidence against the venue rather than loss against the user. We give the protocol, threat model, accountability arguments, Solidity gas measurements for settlement challenges, and AWS measurements for the execution path. On two c7i.metal-24xl hosts, the directly measured kernel-TCP path returns signed Ed25519 acknowledgements for accepted resting orders in 124.17 microseconds median and 128.34 microseconds p99. A bounded-HMAC variant reduces this to 105.31 microseconds median, but it needs delayed key disclosure, threshold ingress, or an equivalent origin-accountability assumption.
A framework for reusable compliance attestation in regulated industries based on cryptographic primitives, vector commitments with selective-opening proofs, re-randomisable signatures, zero-knowledge succinct non-interactive arguments of knowledge, and cryptographic accumulators with succinct non-membership proofs, composed into a protocol structure adapted to the specific structure of multidimensional compliance state. We identify five gaps that separate the generic primitives from a deployable solution for compliance attestation: multidimensional state binding, temporal freshness without correlation, revocation under reuse, cross-issuer aggregation, and verifier predicate richness. We sketch the protocol structure that addresses these gaps, analyse its security and privacy properties, and discuss applications in age verification, right-to-work assurance, and continuous-compliance monitoring. Companion preprint to UK Patent Application GB2611280.5 filed at the UK Intellectual Property Office on 14 May 2026.