Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

1,099 papersLast indexed Aug 31, 2026
Search papers

Paper index

1,099 results · page 3 of 46

Clear filters
Jun 5, 2026·International Journal of Drug Delivery Technology
0 cites
Securing E-Commerce Payments using Decentralized Crypto Escrow

S. Praveena, T. Arasulingam, M. Dineshkumar, P. Puvirajan · 7 authors

The rapid expansion of digital commerce has brought forward new challenges in payment security and transactional trust. Buyers and sellers engaging in online platforms face persistent threats such as payment fraud, unauthorized fund diversions, delayed settlements, and an overreliance on centralized financial intermediaries. Traditional mechanisms, which route payments through banks and payment gateway providers, often introduce additional costs while creating points of vulnerability that undermine consumer confidence. This paper proposes a blockchain-driven decentralized crypto escrow payment framework designed to address these shortcomings in a fundamental way. Rather than routing buyer payments directly to merchant accounts, the system temporarily secures those funds within a smart contract-governed escrow until all agreed-upon transaction conditions have been satisfied — including verified order fulfilment and successful product delivery. In the event of a dispute or transaction failure, the system enforces pre-coded refund protocols without requiring manual intervention. The proposed framework is expected to strengthen the relationship between buyers and sellers, meaningfully raise the bar for payment security, and deliver a transparent, auditable transaction environment through the principles of decentralized finance.

Open access
Blockchain Technology Applications and Security
Cryptography and Data Security
Advanced Authentication Protocols Security
Original source
Jun 2, 2026·arXiv (Cornell University)
0 cites
Reserve Depletion and Security Runway in Proof-of-Stake Systems

Paolo Penna, Manvir Schneider

Many proof-of-stake protocols finance validator rewards from two sources: transaction fees and a finite reserve of tokens. This creates a dynamic hand-off problem. Early in the life of the system, fees may be too small to fund the target level of security; later, fees may become sufficient. The central question is whether the reserve provides enough runway for the protocol to remain secure until this fee-only region is reached. We study this problem in a discrete-time stochastic model of validator participation. Token price and transaction demand fluctuate over time, while validators choose participation strategically. We solve the validator entry game and derive an exact state-dependent reserve threshold, i.e., the minimal reserve stock necessary and sufficient to sustain a target security level. This threshold separates three regions: infeasibility, reserve-dependent security, and fee-only security. Security fails if the reserve first falls below the state-dependent threshold, and a successful hand-off occurs exactly if the fee-only region is reached before that failure time. We derive stress-test guarantees that convert lower confidence bands for token price and demand into reserve requirements, and obtain explicit failure-probability and expected hand-off-time bounds. Finally, we extend the model to forward-looking validators and derive the Markov participation condition that captures how current participation affects future reserve-funded rewards. The main implication is that reserve policy should not be evaluated by nominal depletion dates or steady-state reward ratios alone. A protocol can have a large nominal reserve and still be close to security failure after adverse price or demand shocks. Conversely, once demand crosses the fee-only threshold, the reserve becomes redundant for security. This paper provides a tractable equilibrium framework for stress-testing this transition.

Open access
3 source records
Advanced Authentication Protocols Security
Wireless Communication Security Techniques
Cryptography and Data Security
Original source
Jun 1, 2026·National Documentation Centre (EKT)
0 cites
An ontology-driven approach to security analysis of Sui Move smart contracts

Αντώνιος Γιατζής

Τα τελευταία χρόνια, οι Αποκεντρωμένες Εφαρμογές (Decentralized Applications - DApps) γνωρίζουν σημαντική ανάπτυξη, και η ικανότητά τους να διαχειρίζονται ψηφιακά περιουσιακά στοιχεία υψηλής αξίας έχει οδηγήσει σε σημαντική καινοτομία σε τομείς όπως η αποκεντρωμένη χρηματοοικονομική (Decentralized Finance - DeFi), η διακυβέρνηση (governance) και η διαχείριση της εφοδιαστικής αλυσίδας (supply chain management), με τη δημιουργία διαφόρων δικτύων blockchain για την κάλυψη της ζήτησης για τέτοιες υπηρεσίες. Παράλληλα, έχουν αναπτυχθεί διάφορες μεθοδολογίες για την προστασία αυτών των δικτύων από κακόβουλους παράγοντες (malicious actors) που επιχειρούν να εκμεταλλευτούν αδυναμίες (vulnerabilities) που υπάρχουν στα έξυπνα συμβόλαια (smart contracts) τα οποία εκτελούν μια προκαθορισμένη επιχειρηματική λογική (business logic), με σκοπό να κλέψουν μεγάλα χρηματικά ποσά μέσω αυτών. Αν και το οικοσύστημα του Ethereum επωφελείται από μια ώριμη σουίτα εργαλείων ασφαλείας, αυτά είναι κυρίως σχεδιασμένα για τον εντοπισμό συντακτικών αδυναμιών (syntactic vulnerabilities), παραλείποντας συχνά σφάλματα που προκύπτουν από την απόκλιση μεταξύ του επιδιωκόμενου σχεδιασμού ενός έξυπνου συμβολαίου και της υλοποίησής του στην αλυσίδα (on-chain implementation), επιτρέποντας έτσι στους επιτιθέμενους να χειραγωγήσουν τη λειτουργικότητα του συμβολαίου για κακόβουλο όφελος. Νέα δίκτυα blockchain και γλώσσες προγραμματισμού, όπως το δίκτυο Sui και η γλώσσα του Sui Move, έχουν δημιουργηθεί προσφέροντας νέες δυνατότητες και χαρακτηριστικά, αλλά ταυτόχρονα εισάγουν νέες κατηγορίες κινδύνου. Ορισμένα παραδείγματα είναι η διαρροή δυνατοτήτων (capability leakage) και οι παραβιάσεις του προτύπου μάρτυρα (witness pattern violations), οι οποίες είναι αόρατες στις παραδοσιακές ταξινομίες ασφαλείας που βασίζονται στο Ethereum, λόγω των διαφορετικών υποδομών και προγραμματιστικών μοντέλων. Η πρόληψη τέτοιων επιχειρηματικών αδυναμιών (business vulnerabilities) απαιτεί κατάλληλη τυπική μοντελοποίηση και επαλήθευση (formal modeling and verification) της επιδιωκόμενης επιχειρηματικής διαδικασίας εντός των έξυπνων συμβολαίων, διασφαλίζοντας ότι όλες οι πιθανές αλληλεπιδράσεις παραμένουν συνεπείς με την αναμενόμενη συνολική συμπεριφορά του συστήματος. Η παρούσα έρευνα αντιμετωπίζει αυτό το πρόβλημα αναπτύσσοντας ένα τυπικά θεμελιωμένο, καθοδηγούμενο από οντολογίες πλαίσιο ανάλυσης ασφάλειας (formally grounded, ontology-driven security analysis framework) ειδικά για τη γλώσσα Sui Move, κωδικοποιώντας τις σημασιολογικές σχέσεις μεταξύ των δομών κώδικα (code constructs) της Sui Move, των προτύπων ασφαλείας (security patterns) και των κατηγοριών αδυναμιών. Για την επίτευξη αυτού του στόχου, η παρούσα διατριβή ακολουθεί τη μεθοδολογία Design Science Research (DSR), προκειμένου να γεφυρώσει το χάσμα μεταξύ της αρχιτεκτονικής πρόθεσης υψηλού επιπέδου (το «γιατί» - the why) και των ελαττωμάτων κώδικα χαμηλού επιπέδου (το «πώς» - the how). Τα συμπεράσματα που προέκυψαν από μια συστηματική μελέτη χαρτογράφησης (systematic mapping study) και τη σύγκριση των γλωσσών προγραμματισμού Solidity και Sui Move χρησιμοποιούνται για τη δημιουργία δύο τεχνουργημάτων (artifacts): 1) ενός οντολογικού πλαισίου έξι επιπέδων (six-layer ontological framework) για τη Sui Move και 2) ενός εργαλείου ανάλυσης (Sui Move Analyzer). Όσον αφορά το οντολογικό πλαίσιο, περιλαμβάνονται η χαρτογράφηση γραμματικής (grammar mapping), η ταξινόμηση ασφαλείας, τα αρχιτεκτονικά πρότυπα και η τυπική μοντελοποίηση συμπεριφοράς (formal behavioral modeling), σε συνδυασμό με τη δημιουργηθείσα ταξινόμηση Sui-Unified Weakness Classification (SUWC), η οποία κατηγοριοποιεί τα ελαττώματα που σχετίζονται ειδικά με την πλατφόρμα (platform-specific defects) σε τέσσερις ομάδες, ευθυγραμμισμένες με μια βιβλιοθήκη τεσσάρων επαληθευμένων σχεδιαστικών προτύπων ασφαλείας (security design patterns) της ενσωματωμένης οντολογίας. Όσον αφορά το δεύτερο τεχνούργημα, αυτό αναπτύχθηκε για να αξιολογήσει την πρακτική χρησιμότητα του οντολογικού πλαισίου, χρησιμοποιώντας μια αρχιτεκτονική διπλής ροής (dual-pipeline architecture) που συνδυάζει την παραδοσιακή εξαγωγή ευρετικών κανόνων (heuristic extraction) με την οντολογική συλλογιστική που βασίζεται σε SPARQL (SPARQL-based ontological reasoning). Χρησιμοποιώντας αυτή τη μεθοδολογία, ο αναλυτής μπορεί να εντοπίσει κινδύνους σε σημασιολογικό επίπεδο (semantic-level risks), ενώ παράλληλα βοηθά τους προγραμματιστές προτείνοντας αυτοματοποιημένες αποκαταστάσεις βασισμένες σε πρότυπα (pattern-based remediations), οι οποίες βασίζονται σε καθιερωμένα παραδείγματα ασφάλειας (security paradigms). Η αξιολόγηση των τεχνουργημάτων ακολουθεί το Framework for Evaluation in Design Science (FEDS), συνδυάζοντας τεχνητή αθροιστική αξιολόγηση (artificial summative evaluation) μέσω ειδικά κατασκευασμένων συμβολαίων με γνωστή αντικειμενική αλήθεια (ground truth), και φυσιοκρατική αθροιστική αξιολόγηση (naturalistic summative evaluation) μέσω της ανακατασκευής μιας πραγματικής εκμετάλλευσης (exploit reconstruction), προκειμένου να διασφαλιστεί τόσο η εσωτερική όσο και η εξωτερική εγκυρότητα (internal and external validity). Σε 14 συμβόλαια Sui Move, 42 περιπτώσεις δοκιμών (test cases) και ένα σενάριο εκμετάλλευσης (exploit scenario), χρησιμοποιούνται 13 ποσοτικές μετρικές που καλύπτουν την ορθότητα (precision, recall, F1-score), την κάλυψη (taxonomy and pattern completeness) και την πρακτική χρησιμότητα (false-positive rate, runtime performance). Η εγκυρότητα και των δύο τεχνουργημάτων αξιολογείται επιπλέον σε πέντε διαστάσεις (μέσου, τεχνική, σχεδιασμού, σκοπού και γενίκευσης - instrument, technical, design, purpose, and generalization), επιβεβαιώνοντας ότι το πλαίσιο αποδίδει σταθερά σε όλες τις στοχευμένες διαστάσεις εγκυρότητας και πληροί την απαιτούμενη αυστηρότητα (rigor) για να κλείσει επαρκώς τον κύκλο DSR.

Blockchain Technology Applications and Security
Advanced Authentication Protocols Security
Digital Rights Management and Security
Original source
Jun 1, 2026·Archivo Digital UPM (Universidad Politécnica de Madrid)
0 cites
Análisis criptográfico de la criptomoneda Monero

Analía Olivero Betancor

Este Trabajo Fin de Grado presenta un análisis criptográfico y matemático de la arquitectura de Monero, una criptomoneda diseñada con la privacidad como propiedad fundamental de su protocolo. El estudio comienza con la formalización de los fundamentos algebraicos que conforman el sistema, como las curvas de Edwards retorcidas y la completitud de su ley de grupo, característica que contribuye a mitigar vulnerabilidades asociadas a ataques de canal lateral. Sobre esta base se estudia el protocolo Ring Confidential Transactions (RingCT), núcleo de los mecanismos de privacidad de la red. En particular, se analizan las direcciones sigilosas (stealth addresses), que garantizan la no vinculabilidad de los receptores mediante intercambios Diffie–Hellman sobre curvas elípticas; las firmas de anillo CLSAG y las imágenes de clave, que proporcionan anonimato al emisor y previenen el doble gasto; y los compromisos de Pedersen, utilizados para ocultar las cantidades transferidas. Asimismo, se estudian las pruebas de rango Bulletproofs+, destacando su función en la reducción del tamaño de las transacciones mediante argumentos de producto interno. Finalmente, se examinan diversas vulnerabilidades históricas y técnicas de análisis de trazabilidad aplicadas a Monero, evaluando el grado de resistencia que ofrece el protocolo frente a distintos ataques. Los resultados ponen de manifiesto cómo la integración de herramientas avanzadas de criptografía de clave pública, pruebas de conocimiento cero y estructuras algebraicas sobre curvas elípticas permite construir un sistema financiero con garantías de privacidad, seguridad y fungibilidad. ABSTRACT This Bachelor’s Thesis presents a cryptographic and mathematical analysis of the architecture of Monero, a cryptocurrency designed with privacy as a fundamental property of its protocol. The study begins with the formalization of the algebraic foundations underlying the system, including twisted Edwards curves and the completeness of their group law, a feature that helps mitigate vulnerabilities associated with side-channel attacks. Building upon this mathematical framework, the Ring Confidential Transactions (RingCT) protocol, which forms the core of Monero’s privacy mechanisms, is examined. In particular, the thesis analyzes stealth addresses, which ensure receiver unlinkability through Diffie–Hellman key exchanges over elliptic curves; CLSAG ring signatures and key images, which provide sender anonymity and prevent double-spending; and Pedersen commitments, which are used to conceal transferred amounts. Furthermore, Bulletproofs+ range proofs are studied, highlighting their role in reducing transaction size through efficient inner-product arguments. Finally, several historical vulnerabilities and traceability analysis techniques applied to Monero are reviewed in order to evaluate the protocol’s resistance against different types of attacks. The results demonstrate how the integration of advanced public-key cryptography, zero-knowledge proofs, and algebraic structures based on elliptic curves makes it possible to build a financial system with strong guarantees of privacy, security, and fungibility.

Open access
Advanced Authentication Protocols Security
Cryptography and Data Security
Security in Wireless Sensor Networks
Original source
Jun 1, 2026·arXiv (Cornell University)
0 cites
I-(OT)^2: A Client-optimal Oblivious Transfer Protocol for IoT Devices

E. Onofri, Andrea Ciccotelli, Roberto Di Pietro

Oblivious Transfer (OT) is a fundamental cryptographic primitive enabling privacy-preserving computation and constitutes a core building block for secure multi-party computation while supporting a wide range of security-sensitive applications: private information retrieval, zero-knowledge proofs, and password-authenticated key exchange, to cite a few. While recent advances in OT extension have significantly reduced amortised costs, their reliance on batches of random base OTs and substantial pre-computation phases limits their practicality in scenarios where the number of transfers is modest or where communication latency and client-side computation are critical constraints. In such settings, efficient base OT protocols remain both relevant and necessary. In this work, we introduce $I$-$(OT)^2$, a novel base 1-out-of-2 OT protocol grounded in the quadratic residuosity problem, specifically designed to minimise receiver-side computation and interaction. Our construction is particularly appealing on client--server architectures in which the receiver operates on low-power hardware, such as Internet of Things (IoT) devices. Through a lightweight offline pre-computation phase, $I$-$(OT)^2$ shifts the on-transfer computational burden almost entirely to the Sender, while reducing online communication to only six messages and four digests exchanged. We provide a detailed description of the protocol, accompanied by a formal proof of its security. Moreover, to demonstrate the viability of $I$-$(OT)^2$, we also present an open-source proof-of-concept implementation (in C language) evaluated on real IoT hardware. Results are staggering: for 128-bit security using a 3072-bit RSA modulus, the receiver incurs an average online cost per OT as low as 2.80 μs on desktop platforms and 39.90 μs on IoT devices, more than 10$\times$ faster than the well known SimplestOT.

Open access
3 source records
cs.CR
Cryptography and Data Security
Advanced Authentication Protocols Security
Original source
May 24, 2026·arXiv (Cornell University)
0 cites
Decoupling Reentrancy Protection from Smart Contract Implementation Logic

Shashank Joshi, Wojciech Golab

Reentrancy attacks remain a persistent threat to decentralized applications (DApps), with malicious actors siphoning around 80M USD from the DApp ecosystem last year by exploiting EVM's inter-contract message-passing semantics. Existing research focuses primarily on detection, relying on known attack patterns, and fails to provide deployable solutions that eliminate the vulnerability. Traditional reentrancy guards are similarly limited, offering incomplete coverage across attack variations and lacking robustness against complex DApp interactions. In this paper, we introduce Sentinel, a novel proxy-based approach that mitigates reentrancy vulnerabilities in a type-agnostic way by integrating reentrancy logic directly into the proxy layer, intercepting all calls to the underlying implementation contract. Key features include a dual-mode operational system offering both a gas-optimized internal guard and a high-security external lock registry for cross-contract reentrancy prevention. The proxy also intelligently handles static calls, enabling safe view-function execution while protecting against Read-Only Reentrancy (ROR) attacks. Through rigorous evaluation on a dataset of 70 vulnerable smart contracts, Sentinel achieves 100% security coverage across four major reentrancy attack categories, outperforming existing solutions by over 40%

Open access
3 source records
cs.CR
cs.ET
Security and Verification in Computing
Original source
May 21, 2026·Studies in health technology and informatics
0 cites
A Web3-Based Patient-Centric Health Data Management System

Dongjae Shin, Minseon Park, Hyung‐Jin Yoon

This paper presents a Web3-based healthcare system integrated with the Republic of Korea's MyHealthWay platform for secure and user-controlled management of personal health data. The system combines decentralized identifiers, smart contracts, distributed storage, and the HL7 FHIR standard to support decentralized authentication, access control, and interoperability. A conceptual demonstrator, HealthCube, validates feasibility by enabling privacy-preserving health data processing through computation on encrypted data without exposing original information.

Open access
Innovation in Digital Healthcare Systems
Advanced Authentication Protocols Security
Digital Rights Management and Security
Original source
May 16, 2026·arXiv (Cornell University)
0 cites
A Lightweight QR-assisted Zero-knowledge Identification Protocol For Secure Authentication

Hüseyin Bodur

This study proposes a lightweight Zero-Knowledge authentication model supported by QR codes. The approach is based on the Schnorr authentication protocol and provides an additional security layer against replay attacks through nonce and timestamp mechanisms. The proof data generated by the prover is embedded within a QR code and transmitted to the verifier. Thus, the system enables verification of knowledge of the secret key without revealing it. Simulation results show that proof generation and verification times under a 256-bit security level are in the millisecond range. Additionally, the proof size remains constant at approximately 0.5 KB, making it suitable for practical applications in terms of QR code capacity. The findings indicate that the proposed model is applicable in mobile and low-resource systems in terms of both security and performance.

Open access
2 source records
QR Code Applications and Technologies
Advanced Authentication Protocols Security
RFID technology advancements
Original source
May 15, 2026·Advances in computational intelligence and robotics book series
0 cites
Lightweight Cryptography-Based Generative Explainable AI With Multi-Factor Authentication Methods for Safe Cyber Transactions in Oil Sector

Mishall Hammed Al-Zubaidie, Amal Khaleel Hamad

This chapter proposes a novel multi-factor authentication (MFA) with six schemes, namely password salting/hashing, non-interactive zero-knowledge (NIZK) proofs, GPS-based validation, time-based one-time passwords (TOTP), DNA cryptography, and lightweight SPECK ciphers. Taken together, these elements address the deficiencies in prior authentication and achieve a tradeoff between security and computational efficiency. The system is verified by theoretical and experimental methods. Furthermore, it is theoretically examined under the Real-or-Random model (RoR) with generative/explainable Artificial Intelligence (AI)-driven cybersecurity and provides strong security guarantees in terms of unpredictability (even if reduced in certain security parameters) and defends against replay, insider misuse, brute-force key search attacks, as well as spoofing ones. The solution is developed in Java, and the system is empirically evaluated by performing 100 runs to examine essential performance features: randomness, determinism, stability, and scalability.

Smart Grid Security and Resilience
Security in Wireless Sensor Networks
Advanced Authentication Protocols Security
Original source
May 12, 2026·2026 2nd International Conference on Computational Intelligence Approaches and Applications (ICCIAA)
0 cites
A Hybrid NIZKP and Schnorr’s Protocol-Based Two-Factor Authentication for Secure and Scalable Healthcare Systems

Bara’a O. Ghananim, Omar A. Alzubi, Wafa’ Za’Al Alma’Aitah, Hussam N. Fakhouri · 6 authors

Healthcare information systems increasingly rely on networked access to electronic health records and clinical services, making authentication latency and usability as critical as cryptographic strength. This paper presents a lightweight hybrid authentication framework that combines Schnorr identification with a Fiat-Shamir-derived non-interactive zero-knowledge proof (NIZKP), integrates a conventional second factor (OTP and/or biometric), and enforces role-based access control (RBAC). The design eliminates transmission of reusable password secrets during routine logins, keeps proof material constant-size, and targets fast verification suitable for high-throughput hospital gateways. We implement the pipeline and evaluate it under three simulated clinical traffic patterns aligned with eICU-inspired workload modeling: low traffic (50 users), high traffic (500 users), and burst peak load (100 users). Across scenarios, the end-to-end authentication time remains stable between 0.0107 s and 0.0109 s and stays below a 0.02 s benchmark. Reliability remains high, with success rates of 100.0%, 99.8%, and 99.0%; observed failures stem from injected OTP-expiry or biometric-mismatch events rather than cryptographic verification errors. These results suggest that Schnorr-style NIZKP authentication can provide privacy-preserving, scalable access control for healthcare environments when combined with practical 2FA and RBAC enforcement.

Advanced Authentication Protocols Security
Cryptographic Implementations and Security
User Authentication and Security Systems
Original source
May 11, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
ChitraVault: A Chitrakavi-Inspired Multi-Modal Authentication Framework for Password Vault Security

Arvind Vijayakumar

ChitraVault is an exploratory conceptual authentication architecture that investigates whether geometric visual traversal patterns, drawn from the Chitrakavi (சித்திரக்கவி) classical Tamil literary tradition, can augment password vault security by adding a spatial-behavioral dimension to cryptographic key derivation. This paper proposes the Visual Pattern Key Derivation Function (VP-KDF), which combines a user-drawn Chitrakavi geometric pattern, a text passphrase, and a hardware-bound device fingerprint as inputs to Argon2id key stretching. The framework maps four classical Chitrakavi patterns — Chakra Bandha (wheel), Naga Bandha (serpent), Gomutrika (zigzag), and Thiruezhukkootrirukkai (triangle) — onto distinct cryptographic roles within a zero-knowledge password vault architecture. This work is framed as an exploratory research program, not a finished cryptographic system. All security arguments are bounded by stated assumptions and require empirical and cryptanalytic validation. Future work includes controlled user studies, formal security proofs, and prototype evaluation. Author: Arvind VijayakumarIndependent ResearcherMay 2026

Open access
2 source records
User Authentication and Security Systems
Biometric Identification and Security
Advanced Authentication Protocols Security
Original source
May 10, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
SecureAttend: A Privacy-Preserving Cloud-Based Attendance Management Framework Integrating Zero-Knowledge Proof Authentication and Biometric Verification

Umar . Abubakar, Hamza Itopa Sanni, Abdulsalam Aliyu

Conventional attendance management approaches in academic and organisational settings face persistent challenges that include susceptibility to proxy attendance, inadequate protection of biometric credentials, and the absence of privacy-preserving verification mechanisms in cloud-hosted deployments. This paper presents SecureAttend, a cloud-based attendance management framework that addresses these deficiencies through the integration of Zero-Knowledge Proof (ZKP) cryptographic authentication with biometric capture via a ZKTeco K40 Pro fingerprint terminal. The proposed framework employs a challenge-response ZKP protocol that enables users to demonstrate possession of valid authentication credentials without disclosing underlying private keys or biometric templates to the server. Attendance records are encrypted using AES-256 prior to storage in a MongoDB cloud database, while SHA-256 hashing provides tamper-evidence for each record. Session integrity is maintained through JWT-based token management, and access boundaries are enforced via a Role-Based Access Control (RBAC) policy. Functional evaluation across eighteen test scenarios confirmed complete compliance with stated requirements. Security assessment validated correct operation of cryptographic mechanisms, access controls, and audit logging subsystems. Performance benchmarks recorded average API response latencies of approximately 85 milliseconds for authentication requests and 120 milliseconds for attendance marking operations. The results demonstrate that ZKP authentication can be deployed effectively in real-world attendance management contexts, offering measurable improvements in privacy, integrity, and resistance to credential-based attacks compared with conventional approaches.

Open access
2 source records
Cryptography and Data Security
Advanced Authentication Protocols Security
Cloud Data Security Solutions
Original source
May 8, 2026·Open MIND
0 cites
The Role of Cryptography in Network Security: A Systematic Review and Emerging Trends

Daniel Makolo, Obafemi Babatunde Desmond, Dauda Shaibu Anibe, Ejiga Timothy Ikoojo · 7 authors

Cryptography is the backbone of modern network security, providing confidentiality, integrity, authentication, and non-repudiation for digital communication. However, the rapid evolution of cyber threats, particularly the looming arrival of large-scale quantum computers, poses serious challenges to the cryptographic algorithms that protect today's networks. This paper presents a systematic review of cryptography in network security, following the PRISMA 2020 guidelines. A total of 68 studies published between 2016 and 2025 were selected from five major academic databases: IEEE Xplore, ACM Digital Library, Scopus, Web of Science, and ScienceDirect. The review covers classical symmetric and asymmetric algorithms, widely deployed cryptographic protocols such as TLS 1.3, IPsec, and SSH, and the growing body of work on post-quantum cryptography (PQC). Key findings include the following: NIST finalized three post-quantum cryptographic standards (FIPS 203, 204, and 205) in August 2024; lightweight cryptography standards for IoT devices were published in 2025 with the selection of ASCON; and real-world deployment of hybrid classical/post-quantum schemes has already begun in major web browsers and messaging applications. This paper also examines emerging trends in homomorphic encryption, zero-knowledge proofs, and AI-driven cryptanalysis. Based on the findings, this review identifies critical gaps in PQC migration strategies, IoT security, and the integration of cryptography with artificial intelligence, and proposes directions for future research.

Open access
2 source records
Cryptography and Data Security
Chaos-based Image/Signal Encryption
Advanced Authentication Protocols Security
Original source
May 4, 2026·IACR Communications in Cryptology
3 cites
Anonymous Credentials from ECDSA

Matteo Frigo, abhi shelat

Anonymous digital credentials allow a user to prove possession of an attribute that has been asserted by an identity issuer without the user revealing any extra information about themselves. For example, a user who has received a digital passport credential can prove their “age is <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mrow> <mml:mo>&gt;</mml:mo> <mml:mn>18</mml:mn> </mml:mrow> </mml:math> ” without revealing any other attributes such as their name or date of birth. Despite their clear application to privacy-preserving authentication, anonymous credential schemes have been difficult to deploy at scale. Part of the difficulty arises because schemes in the literature, such as BBS+, use new cryptographic primitives that require system-wide changes to existing issuer infrastructure. In addition, issuers often require digital identity credentials to be device-bound by incorporating the device’s secure element into the presentation flow. As a result, schemes like BBS+ require updates to the hardware on every user's device. We propose new ZK techniques which enable the construction of an anonymous credential scheme for the legacy Elliptic Curve Digital Signature Algorithm (ECDSA) signature scheme. By adding efficient ZK arguments for statements about SHA-256 and document parsing for ISO-standardized identity formats, we construct the first ZK proof of posession of a credential that can be deployed without changing any issuer processes, without changes to mobile devices, and without requiring non-standard cryptographic assumptions. Furthermore, our proof system itself only relies on SHA-256 as its complexity assumption. Producing ZK proofs about ECDSA signatures has been a bottleneck for other ZK proof systems because standardized curves such as P256 use finite fields which do not support efficient number theoretic transforms. We overcome this bottleneck by designing a ZK proof system around sumcheck and the Ligero argument system, by designing efficient methods for Reed-Solomon encoding over the required fields, and by designing specialized circuits for ECDSA. Our proofs for ECDSA can be generated in as little as <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mrow> <mml:mo>≈</mml:mo> <mml:mn>20</mml:mn> </mml:mrow> </mml:math> ms. When incorporated into a fully standardized identity protocol such as the ISO MDOC standard, our system can generate a zero-knowledge proof for the MDOC presentation flow in a few hundred ms on mobile devices. These advantages make our scheme a promising candidate for privacy-preserving digital identity applications.

Open access
Cryptography and Data Security
Cryptography and Residue Arithmetic
Advanced Authentication Protocols Security
Original source
May 4, 2026·IACR Communications in Cryptology
0 cites
zkExp: Zero-Knowledge Succinct Exponentiation Proofs

Biniyam Deressa, M. Hasan

We present zkExp (Zero-Knowledge Succinct Exponentiation Proofs), the first zero-knowledge proof system achieving asymptotically efficient bounds for batched exponentiation: <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mrow> <mml:mover> <mml:mrow> <mml:mi>O</mml:mi> </mml:mrow> <mml:mo stretchy="false">~</mml:mo> </mml:mover> <mml:mo stretchy="false">(</mml:mo> <mml:mi>k</mml:mi> <mml:mi>ℓ</mml:mi> <mml:mo stretchy="false">)</mml:mo> </mml:mrow> </mml:math> prover time, <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mrow> <mml:mi>O</mml:mi> <mml:mo stretchy="false">(</mml:mo> <mml:mn>1</mml:mn> <mml:mo stretchy="false">)</mml:mo> </mml:mrow> </mml:math> verification time, and constant-size (160–256 B) proofs. For statements <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mrow> <mml:msub> <mml:mi>y</mml:mi> <mml:mi>i</mml:mi> </mml:msub> <mml:mo>=</mml:mo> <mml:msup> <mml:mi>g</mml:mi> <mml:mrow> <mml:msub> <mml:mi>x</mml:mi> <mml:mi>i</mml:mi> </mml:msub> </mml:mrow> </mml:msup> </mml:mrow> </mml:math> ( <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mrow> <mml:mi>i</mml:mi> <mml:mo>=</mml:mo> <mml:mn>1</mml:mn> <mml:mo>,</mml:mo> <mml:mo>…</mml:mo> <mml:mo>,</mml:mo> <mml:mi>k</mml:mi> </mml:mrow> </mml:math> ) with private exponents <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mrow> <mml:msub> <mml:mi>x</mml:mi> <mml:mi>i</mml:mi> </mml:msub> </mml:mrow> </mml:math> , zkExp introduces four innovations to overcome long-standing scalability barriers: (1) trace-based square-and-multiply encoding, (2) lazy sumcheck for exponentiation constraints, (3) hybrid FFT decomposition reducing memory from <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mrow> <mml:mi>O</mml:mi> <mml:mo stretchy="false">(</mml:mo> <mml:mi>ℓ</mml:mi> <mml:mo stretchy="false">)</mml:mo> </mml:mrow> </mml:math> to <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mrow> <mml:mi>O</mml:mi> <mml:mo stretchy="false">(</mml:mo> <mml:msqrt> <mml:mrow> <mml:mi>ℓ</mml:mi> </mml:mrow> </mml:msqrt> <mml:mo stretchy="false">)</mml:mo> </mml:mrow> </mml:math> , and (4) sliding-window batching enabling single-proof aggregation via KZG commitments. The protocol is computationally sound under the <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mrow> <mml:mo stretchy="false">(</mml:mo> <mml:mi>q</mml:mi> <mml:mo>,</mml:mo> <mml:mi>ℓ</mml:mi> <mml:mo stretchy="false">)</mml:mo> </mml:mrow> </mml:math> -Generalized Diffie–Hellman Exponent (GDHE) assumption and achieves computational zero-knowledge in the random oracle model. Proofs remain 160–256 B regardless of parameter sizes, with constant verification (3.5 ms). For 4096-bit exponents, prover overhead is <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mrow> <mml:mn>16.3</mml:mn> <mml:mi>×</mml:mi> </mml:mrow> </mml:math> (dropping to <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mrow> <mml:mn>1.35</mml:mn> <mml:mi>×</mml:mi> </mml:mrow> </mml:math> in 1000-batch settings), while Ethereum verification costs <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mrow> <mml:mi>~</mml:mi> <mml:mn>267</mml:mn> <mml:mi>k</mml:mi> </mml:mrow> </mml:math> gas for 1000 exponentiations, <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mrow> <mml:mn>10</mml:mn> <mml:mi>×</mml:mi> </mml:mrow> </mml:math> cheaper than ECDSA, with memory consumption below 1.1 MB. zkExp is the first protocol to match theoretical lower bounds for exponentiation proofs while enabling practical deployment in zero-knowledge rollups, anonymous credentials, and on-chain threshold cryptography.

Open access
Cryptography and Data Security
Complexity and Algorithms in Graphs
Advanced Authentication Protocols Security
Original source
May 1, 2026·Global Journal of Engineering Innovations and Interdisciplinary Research
0 cites
Blockchain For Enhancing Trust & Privacy in E-KYC

Dr. P. U. Anitha, G.Rachana, K. Sushmitha, A. V. Senthil Kumar · 5 authors

Electronic Know Your Customer (e-KYC) systems play a crucial role in verifying user identities for financial institutions, telecom operators, and other service providers. However, traditional eKYC frameworks rely heavily on centralized databases, making them vulnerable to data breaches, unauthorized access, single points of failure, and privacy risks. To address these challenges, this paper proposes a blockchain-based e-KYC system that enhances trust, security, and user privacy. The proposed architecture integrates distributed ledger technology with smart contracts to create a transparent, tamperproof, and decentralized identity verification platform. User data is encrypted and stored securely, while verification records are maintained on an immutable blockchain ledger. Authorized entities can access customer information only through permissioned smart contracts, ensuring controlled data sharing and minimizing exposure. This approach eliminates repeated KYC processes, reduces operational costs, prevents identity fraud, and strengthens user control over personal data.Over all, the blockchainenabled e-KYC system provides a more reliable, efficient, and privacy-preserving solution compared to conventional centralized models. It significantly improves trust among stakeholders and establishes a secure foundation for digital identity management in modern financial and governmental ecosystems.

Blockchain Technology Applications and Security
Cryptography and Data Security
Advanced Authentication Protocols Security
Original source
Apr 26, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
Entros Protocol: A Framework for Temporally-Consistent, Decentralized Proof-of-Personhood

Charles Hooper

The proliferation of sophisticated AI and bot networks necessitates robust methods for verifying human uniqueness and liveness in digital ecosystems. Existing Proof-of-Personhood (PoP) solutions rely on centralized authorities, invasive static biometrics, or socially-correlatable data, creating vulnerabilities in privacy, security, and accessibility. We introduce the Entros Protocol, a decentralized framework for PoP and Self-Sovereign Identity built on Solana. The core innovation is temporal consistency: the assertion that human identity is best proven not by a static secret, but by the bounded, chaotic drift of biological and behavioral patterns over time. The framework captures multi-modal behavioral data (voice prosody, hand tremor, touch dynamics) during a configurable behavioral challenge, extracts a 308-dimensional feature vector, and produces a 256-bit locality-sensitive hash via SimHash. A Groth16 zero-knowledge proof verifies that consecutive fingerprints fall within a bounded Hamming distance without revealing either value. Attestations are anchored to non-transferable identity tokens (SPL Token-2022) with progressive Trust Scores. We provide formal security definitions, analyze the protocol against replay, synthesis, and Sybil attacks, introduce a graduated trust model distinguishing first-time liveness checks from sustained temporal consistency, and present benchmarks from a working implementation deployed on Solana devnet.

Open access
4 source records
User Authentication and Security Systems
Advanced Authentication Protocols Security
Internet Traffic Analysis and Secure E-voting
Original source
Apr 25, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
Prism Protocol: A Privacy-Native Authentication Architecture (Closed Triangle: Biometrics, Device Binding, NFC Presence), Confirmed via Zero-Knowledge Proofs, with Working Implementation

I. Smid -Woelders

The Prism Protocol is a privacy-native authentication and identity architecture in which a user can prove attributes or authentication state without directly revealing their identity to the server. It combines WebAuthn (W3C Level 3), Zero-Knowledge Proofs (Groth16 via circom/snarkjs), and NFC-based physical presence verification into a single coherent protocol stack. The core mechanism is a triangular key derivation model: biometric authentication (WebAuthn), a device-bound private key (FIDO2 Secure Enclave), and a time-limited NFC nonce via a passive tag (card, ring, sticker; NFC ISO 14443) jointly produce an ephemeral key. In v18, a working ZKP implementation is demonstrated: an age-threshold circuit proves that a user meets a criterion without the server ever receiving the attribute value. Verification is performed server-side via snarkjs.groth16.verify(). Within the demonstrated implementation flow, the server receives no name, no biometric data, no persistent identifier, and no direct attribute value. Sessions are designed to be unlinkable from the server perspective at the protocol level; timing and metadata correlation are addressed in the threat model as a separate concern. A working proof-of-concept was demonstrated on 25 April 2026 at prismpass.globalsecurity.nu. The broader ecosystem (PrismPass, PrismID, PrismShield, PrismAdd, PrismChat, PrismAir, PrismGuard, PrismHash, PrismWipe, PrismGate) is documented in this Invention Disclosure. The protocol introduces no novel cryptographic primitives; its novelty lies in the specific architectural combination, orchestration model, and protocol-class definition addressing thirteen authentication questions not simultaneously addressed by existing systems. Note: The post-quantum migration path (ML-KEM-768, ML-DSA-65) is documented as a formal architectural claim and forward-compatibility design decision. It describes the intended migration route, not a currently implemented feature. The working implementation uses ECDH, ECDSA, AES-256-GCM and Groth16. The protocol is designed for session unlinkability: the server receives only a cryptographic proof of validity, never a persistent identifier, name, or behavioural trace. This addresses the unlinkability gap identified in the W3C Digital Credentials API and the EUDI Wallet architecture as an unresolved open problem. Author: I. Smid-Woelders, independent inventor, Zwolle, Netherlands. First documented: 25 April 2026. Contact: contact@globalsecurity.nu

Open access
2 source records
Advanced Authentication Protocols Security
User Authentication and Security Systems
RFID technology advancements
Original source
Apr 25, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
Prism Protocol: A Privacy-Native Authentication Ecosystem Combining WebAuthn, Zero-Knowledge Proofs, and NFC Presence Verification , with Working Implementation

Smid-Woelders, I.

The Prism Protocol is a privacy-native authentication and identity architecture in which a user can prove attributes or authentication state without directly revealing their identity to the server. It combines WebAuthn (W3C Level 3), Zero-Knowledge Proofs (Groth16 via circom/snarkjs), and NFC-based physical presence verification into a single coherent protocol stack. The core mechanism is a triangular key derivation model: biometric authentication (WebAuthn), a device-bound private key (FIDO2 Secure Enclave), and a time-limited NFC nonce via a passive tag (card, ring, sticker; NFC ISO 14443) jointly produce an ephemeral key. In v18, a working ZKP implementation is demonstrated: an age-threshold circuit proves that a user meets a criterion without the server ever receiving the attribute value. Verification is performed server-side via snarkjs.groth16.verify(). Within the demonstrated implementation flow, the server receives no name, no biometric data, no persistent identifier, and no direct attribute value. Sessions are designed to be unlinkable from the server perspective at the protocol level; timing and metadata correlation are addressed in the threat model as a separate concern. A working proof-of-concept was demonstrated on 25 April 2026 at prismpass.globalsecurity.nu. The broader ecosystem (PrismPass, PrismID, PrismShield, PrismAdd, PrismChat, PrismAir, PrismGuard, PrismHash, PrismWipe, PrismGate) is documented in this Invention Disclosure. The protocol introduces no novel cryptographic primitives; its novelty lies in the specific architectural combination, orchestration model, and protocol-class definition addressing thirteen authentication questions not simultaneously addressed by existing systems. Note: The post-quantum migration path (ML-KEM-768, ML-DSA-65) is documented as a formal architectural claim and forward-compatibility design decision. It describes the intended migration route, not a currently implemented feature. The working implementation uses ECDH, ECDSA, AES-256-GCM and Groth16. The protocol is designed for session unlinkability: the server receives only a cryptographic proof of validity, never a persistent identifier, name, or behavioural trace. This addresses the unlinkability gap identified in the W3C Digital Credentials API and the EUDI Wallet architecture as an unresolved open problem. Author: I. Smid-Woelders, independent inventor, Zwolle, Netherlands. First documented: 25 April 2026. Contact: contact@globalsecurity.nu

Open access
5 source records
Advanced Authentication Protocols Security
RFID technology advancements
User Authentication and Security Systems
Original source
Apr 24, 2026·Advances in computational intelligence and robotics book series
0 cites
Synchronized Digital Identities

Khalil Omar, Wissam Al Khadour, Jamal Zraqou, Jawad Alkhateeb

Metaverse ecosystems pose new challenges that have never been seen before in ensuring that digital identities are consistent across heterogeneous platforms. The chapter suggests a new twin architecture based on the digital twin principles of managing identity that introduces a federated model that includes credential, behavioral, context, and authorization sub-twins. In our methodology, we use privacy-preserving protocols of synchronization using zero-knowledge proofs. On benchmark datasets (LFW, VGGFace2, KeyRecs) the system has been shown to achieve 99.1% authentication accuracy, 0.7% EER (22% better than current systems) and 127ms average latency and 99.8% cross-platform synchronization reliability. These results provide a roadmap to the next-generation authentication systems that would enable the smooth experiences across the physical-virtual metaverse boundaries.

User Authentication and Security Systems
Blockchain Technology Applications and Security
Advanced Authentication Protocols Security
Original source
Apr 23, 2026·Peer-to-Peer Networking and Applications
0 cites
Blockchain-based privacy-preserving authentication protocol for UAV cross-domain

Liefeng Cao, Haoran Ji, Quanwei Wang, Guozi Sun

As unmanned aerial vehicles (UAVs) become increasingly integral in domains such as agriculture, logistics, and military operations, secure cross-domain authentication mechanisms are essential. Existing centralized protocols are prone to single points of failure, privacy vulnerabilities, and physical capture risks. This paper presents a novel blockchain-based, privacy-preserving authentication protocol for UAVs operating across multiple domains. By combining zero-Knowledge succinct non-interactive arguments of knowledge (zk-SNARKs) and physical unclonable functions (PUFs), the proposed protocol ensures secure identity verification without disclosing sensitive information. The blockchain platform offers a decentralized, tamper-resistant environment for UAV authentication, addressing the challenges of scalability, privacy, and security in cross-domain operations. We demonstrate the security and effectiveness of the protocol through formal and informal security proofs and performance evaluations. The results indicate that the proposed protocol outperforms traditional methods, achieving significant reductions in both computational and communication costs while maintaining high security standards.

Open access
UAV Applications and Optimization
Blockchain Technology Applications and Security
Advanced Authentication Protocols Security
Original source
Apr 23, 2026·International Journal on Semantic Web and Information Systems
0 cites
Semantic-Enhanced Risk-Aware Dual-Layer Privacy-Preserving Verifiable Access Control for OT Systems

Bian Zhu, Ling Niu

Industrial operational technology systems are becoming more intelligent and interconnected, requiring remote maintenance and multiparty collaboration. While traditional approaches improve efficiency, they introduce risks like data leakage and unauthorized operations. Existing access control schemes struggle with compliance verification and auditing while ensuring privacy. A novel access control scheme was proposed that combines zero-knowledge proof with the publicly verifiable covert security model. The scheme features a dual-layer verification mechanism: a basic layer using zero-knowledge proof to protect identities and permissions during remote maintenance and an enhanced layer for high-risk operations that uses oblivious transfer and digital signatures to detect malicious behavior and generate cheating certificates. Security analysis showed the scheme ensures privacy, access legitimacy, and non-repudiation. Experiments demonstrated the scheme had faster proof generation and verification compared to existing methods with effective malicious behavior detection and accountability.

Open access
Access Control and Trust
Cryptography and Data Security
Advanced Authentication Protocols Security
Original source