Sue-Chen Hsueh, P. C. Yeh
No abstract is available for this record.
Follow blockchain research across journals, conferences, and preprint repositories.
1,039 results · page 3 of 44
Sue-Chen Hsueh, P. C. Yeh
No abstract is available for this record.
Arpit Jain, Swati Gupta, Meenu Vijarania, Pratyush Srivastav
Security and user experience are critical priorities in modern banking, yet traditional authentication practicessuch as passwords and one-time passwords (OTPs)-remain vulnerable to phishing, credential theft, and data breaches. This research explores the integration of blockchain-based authentication, specifically using MetaMask for passwordless login, as a secure alternative for digital banking systems. The proposed approach eliminates centralized credential storage by leveraging cryptographic signatures and client-side verification, thereby enhancing both security and user privacy. A prototype banking application was developed and evaluated, demonstrating a 50 % reduction in authentication time and improved resistance to phishing attacks. The study further analyzes decentralized identity management's implications for regulatory compliance, including GDPR and KYC alignment. By comparing conventional and Web3 authentication systems, this work illustrates how decentralized login mechanisms can significantly strengthen banking security, streamline user interaction, and promote a transparent, customer-centric digital banking ecosystem.
Asheshemi Nelson Oghenekevwe, Okoro Akpohrobaro Daniel, Ayeh Blessing Elohor, Ayo Michael Ifioko · 6 authors
Developments of Web 3.0 technologies present vital problems regarding data confidentiality, authentication of users and their privacy in decentralised systems. The traditional multifactor authentication (MFA) systems have been effective when deployed in Web2 environments but have failed in protecting sensitive information in the decentralised environment because they use centralised servers and are also dependent on static security factors. The paper explores the concept of multifactor authentication that is based on blockchain technology as the effective method of improving the use of data confidentiality in Web3. A blockchain-augmented MFA infrastructure was created on the basis of an Ethereum smart contract, decentralised storage, and biometric data that were cryptographically encrypted. Simulation demonstrated significant increases in security relative to conventional MFA systems, a significant drop in the probability of breaching (0.0270 to 0.0040), an improvement in the entropies, a decrease in the likelihood of session hijacking, and limited mutual information leakage. Also, the blockchain-based system becomes more resistant to Man-in-the-Middle (MITM) and phishing attacks, mitigating them by about 60 per cent and 50 per cent success rates, respectively. Whereas the blockchain MFA made some minor sacrifices in latency and computation cost in the course of authentication, such a trade of costs is productive in the Web3 environment where security and data integrity remain of utmost importance. The study could be useful to developers, security practitioners and policymakers who intend to develop more secure, scalable, and user-centric authentication mechanisms in decentralised apps. As a potential improvement, it is suggested that future research should implement the aspect of consensus optimisation and Layer-2 to increase the efficiency and scalability further.
Marcel Pehlke, Sophia Fedder, Clemens Schmitt, Mike Witkowski · 5 authors
Managing cryptographic keys remains a major barrier to blockchain adoption, especially for non-technical users. This paper presents a smart cardbased solution for secure and user-friendly key management, offering physical isolation of private keys and PIN-protected access via NFC. In a comparative study with the Waves Keeper browser extension, 33 participants completed blockchain-related tasks and rated both solutions in different categories of the Technology Acceptance Model (TAM) such as Perceived Usefulness, Ease of Use, and Result Demonstrability. The smart card system showed clear advantages in usability and perceived security. In general, the results highlight the potential of hardware-based approaches to improve blockchain accessibility and acceptance, with implications for Web3 applications and future research on usability and security integration.
Masure, Anthony, Helleu, Guillaume, Juvin, Océane, Gay, Elise · 5 authors
The CryptoKit research project provides a visual mapping of blockchain technology and Web3 protocols to make them accessible to a wide audience. It includes an open source typeface of more than 200 pictograms of key blockchain terms. When paired with IBM Plex, these icons can be arranged in didactic diagrams thanks to a dedicated tool on this website.
W. M. A. B. Wijesundara, Joong-Sun Lee, Eleni Aloupogianni, Dara Tith · 6 authors
Rapid proliferation of smart home IoT devices has intensified the demand for secure, scalable, and autonomous firmware authentication mechanisms. Traditional centralized solutions face challenges related to privacy concerns, limited scalability, and vulnerability to single point of failure. In this paper, we propose DIDAuth-IoTFW, a novel decentralized identity and firmware authentication framework that uniquely integrates Ethereum Layer-2 Arbitrum, InterPlanetary File System (IPFS), and W3C-compliant Decentralized Identifiers (DIDs) and Verifiable Credentials (VCs). DIDAuth-IoTFW provides a complete firmware authentication life cycle, from decentralized identity registration to real-time, on-chain verifiable revocation. While enabling autonomous, cryptographic verification directly on resource-constrained IoT devices and ensuring reliable performance even when gateways are compromised or unavailable. Our proof-of-concept implementation on ESP32 and Raspberry Pi achieved complete resistance to replay, forgery, and revocation threats with verification consistently under 1.2 s. Compared to prior work, DIDAuth-IoTFW uniquely combines firmware–VC hash binding, contract binding that prevents cross-registry replay, and device-side enforcement resilient to gateway compromise. Experimental results indicate a robust, privacy-preserving, and scalable alternative to centralized firmware-update pipelines for smart-home IoT.
Razi Iqbal, Muhammad Afzaal, Geetanjali Rathee
The rapid adoption of Internet of Things (IoT) in Healthcare has significantly enhanced real-time patient monitoring and decision making. However, security and privacy still remain the major concern due to sensitive medical data of patients especially on low-power IoT devices. Traditional authentication schemes like Zero Knowledge Proof (ZKP) and Elliptic Curve Cryptography (ECC) often struggle with efficiency in resource-constraint environments due to their computational overhead. In order to address these challenges, we propose a Neural-Based Hybrid and Adaptive Framework that combines Schnorr ZKP with Kyber-based key encapsulation, using a neural network to dynamically select Kyber variants (512, 768, 1024) based on device parameters (type, authentication time, transmission time) to balance security and efficiency for low-power IoT devices. Extensive experiments validated robust security against replay and spoofing attacks, achieving authentication success for legitimate clients and zero attack successes. Furthermore, our proposed framework outperforms traditional Kyber1024 and ZKP/ECC based authentication schemes in terms of authentication time and computational overhead making it robust and scalable solution for sensitive and resource-limited environments like HealthCare IoT systems. • Design a novel hybrid authentication framework that integrates ZKP and Kyber PQC (Post Quantum Cryptography) to ensure secure and efficient authentication for IoT healthcare devices. • Utilize Neural Network to intelligently select the most appropriate Kyber variant based on threat level and computational efficiency. • Provide comprehensive experimental analysis comparing the proposed hybrid and adaptive framework with traditional ZKP, ECC and static Kyber implementations.
Xingxing Chen, Xiaohong Zhang, Shaojiang Zhong, Shuling Liu
Vehicular Ad Hoc Networks (VANETs) are now a pivotal component of Intelligent Transportation Systems. However, ensuring secure vehicle identity authentication and protecting user privacy remain two challenging issues in VANETs. Addressing these challenges, this paper seamlessly integrates blockchain technology with the InterPlanetary File System to realize a fully decentralized storage solution for identity verification information. Simultaneously, it employs zk-SNARK and elliptic curve cryptography to allow vehicle users to anonymously complete identity verification. Additionally, the lightweight identity authentication proof obtained after successful verification maintains credibility while reducing the computational and communication costs for both roadside units and vehicles. The security and performance analysis of the system show that the proposed scheme has significant advantages in both communication and computation compared with similar research, while also offering superior security and a broader range of functional attributes compared to existing competitive approaches.
Tobias Gösslbauer, Karl Pinter, Thomas Grechenig
This analysis focuses on password-free Electronic IDentity (eID) solutions for eGovernment services under the federated identity management framework Electronic IDentification, Authentication and trust Services (eIDAS). The scope of eID systems is centred on their alignment of the associated technical, legal, and procedural challenges. Through an analysis of five password-free eID solutions—Fast IDentity Online 2 (FIDO2) tokens, Secure Identity Across Borders Linked (STORK), distributed ledgers, mobile authenticators, and eID cards—the study evaluates their compliance with eIDAS standards and identifies key gaps in their design and implementation. While certain solutions, such as FIDO2 tokens and mobile authenticators, demonstrate full compliance, others, including STORK and distributed ledger-based systems, face challenges in achieving interoperability, privacy, and regulatory alignment. This research contributes to the discourse on digital identity management by offering insights into current limitations and recommending pathways for advancing the design, standardization, and deployment of eID systems. These results support the larger objectives of the European digital single market by highlighting the significance of regulations, innovations, and user-oriented design in creating password-free eID systems.
Ujjwal Saini, Pardeep Kumar, Andrew Lambert
With the rapid advancement of Vehicle-to-Everything (V2X) communication systems, ensuring robust security has become a critical challenge. Various studies have proposed several protocols; however, many of them may suffer from potential threats, such as impersonation attacks. This paper presents an efficient and lightweight authentication protocol for V2X communication. Our scheme uses zero-knowledge proof to perform mutual authentication without revealing the real identities in V2X communication. The proposed protocol ensures that all vehicles on the network are authenticated without compromising the integrity. Hence, the proposed scheme protects V2X communication against possible attacks. The preliminary result shows that the proposed scheme is efficient in terms of computational complexity.
Dennis Hamm, Erwin Kupris, Thomas Schreck
No abstract is available for this record.
Pei Ren, Bo Yang, Yanwei Zhou, Tao Wang · 6 authors
No abstract is available for this record.
Chetan Chauhan, Pradeep Laxkar, Ram Kumar Solanki, S. R. Parihar · 6 authors
Blockchain technology has emerged as a promising paradigm for addressing the inherent vulnerabilities of Internet of Things (IoT) networks. Conventional IoT systems rely on centralized architectures that are prone to single points of failure, data breaches, and unauthorized access. This paper presents a blockchain-enabled secure communication framework for smart IoT systems that integrates symmetric encryption, distributed ledger validation, and smart-contract–driven access control. The proposed model is formalized through mathematical definitions of encryption, hashing, and contract execution, and validated using simulation tools such as NS-3 and Ethereum-based test environments. Comparative results demonstrate that the framework significantly improves communication security, data integrity, and resistance to cyberattacks while reducing latency and energy consumption relative to traditional models. The findings suggest that blockchain integration provides a scalable, resilient, and efficient foundation for trustworthy IoT communication in smart environments.
Vaishali Kapure, Deepika Ajalkar, Arti Patle, Shibani Borde · 6 authors
Paper define innovative approach to unify authentication across Web2 and Web3 ecosystems by using biometric-driven decentralized identifiers (DIDs). The framework employs zero-knowledge attestations (ZKPs) to ensure privacy during verification processes [7], [11] and utilizes Chainlink's Cross-Chain protocol related toInteroperability(CCIP) for flawless operation across multiple blockchains [17]. To enhance liveness detection, we incorporate federated learning to eliminate centralized storage of sensitive biometric data [19]. A novel contribution is the Biometric Soulbound Token (BST), a non-transferable NFT that securely stores hashed facial data [5]. Also, quantum-resistant ZKPs are used to verify biometric matches without exposing raw inputs [14]. The DIDs function cohesively across Ethereum, Polygon, and Solana. Experimental results demon- strate a 99.2% authentication accuracy, a 1.3 -second latency, and full compliance with GDPR. By empowering users with control over their biometric data, this framework bridges centralized and decentralized platforms, enabling secure and efficient identity management.
Saloni Kumbhar, Aditya Mourya, Vinayak Musale, Safalya Satpute · 6 authors
Securing sensitive physical and digital areas, such as equipment rooms, medical records storage, and intensive care units (ICUs), is crucial in modern health care environments. Traditional ways of access control that depend on static authorization and centrally maintained databases are becoming more vulnerable to insider threats, identity spoofing, and data breaches. To enhance privacy, transparency and realtime threat detection in healthcare infrastructure, paper suggests a conceptual architecture for a secure, decentralized access control system that integrates blockchain technology, biometric authentication, and Zero-Knowledge Proofs (ZKPs). Recognition of fingerprints serves as the system's main authentication technique, and feature vectors are safely stored on a decentralized blockchain and cryptographically committed using Pedersen commitments. A zk-SNARK is generated during access requests to verify the accuracy of the user's biometric input without disclosing the real biometric data. Smart contracts validate access decisions, allowing for unaltered event logging and automated policy enforcement. The system combines entry-point security with Edge AI-based continuous monitoring, which tracks people's movements within the secure area using motion sensors and CCTV. The individual's continued authorization during their presence is guaranteed by periodic behavioral verification conducted by ZKPs. Anomalies that are discovered are immediately reported and stored on the blockchain for forensic examination. The approach suggested combines behavioral confirmation with physical identity verification to provide a strong multifactor authentication (MFA) framework. Although conceptual in nature, the architecture provides a scalable and privacypreserving model for next-generation healthcare access control systems because it is based on blockchain and cryptography technologies that have been proven to work.
Isaac Osei Asante, Libing Wu
No abstract is available for this record.
Minfeng Qi, Qin Wang, Guangsheng Yu, Ruiqiang Li · 6 authors
We argue that the technical foundations of non-fungible tokens (NFTs) remain inadequately understood. Prior research has focused on market dynamics, user behavior, and isolated security incidents, yet systematic analysis of the standards underpinning NFT functionality is largely absent. We present the first study of NFTs through the lens of Ethereum Improvement Proposals (EIPs). We conduct a large-scale empirical analysis of 191 NFT-related EIPs and 10K+ Ethereum Magicians discussions (as of July, 2025). We integrate multi-dimensional analyses including the automated parsing of Solidity interfaces, graph-based modeling of inheritance structures, contributor profiling, and mining of community discussion data. We distinguish foundational from emerging standards, expose poor cross-version interoperability, and show that growing functional complexity heightens security risks.
Hengjiang Xiao, Zhihong Liang, Yuxiang Huang, Mingming Qin · 5 authors
Blockchain, as a decentralized and tamperproof distributed ledger technology, has gained wide attention in finance, Internet of Things and other fields since it was proposed by Satoshi Nakamoto in 2008. Identity authentication is the basic guarantee for cyberspace security, but traditional centralized identity management suffers from single point of failure, privacy leakage and poor interoperability. Blockchain-based identity authentication utilizes distributed trust mechanism and cryptography technology, which is expected to realize secure sharing and autonomous control of identity data. In this paper, we systematically sort out the infrastructure (network layer, consensus mechanism, etc.) and types of blockchain technology, and elaborate the supportive role of the combination of blockchain and cryptography (hashing, digital signatures, zero-knowledge proofs, etc.) for identity authentication. It focuses on an overview of the research progress on the improvement of public key infrastructure (PKI), biometric combination scheme, and the integration of decentralized identity (DID) and verifiable credentials (VC) in the blockchain environment, and analyzes its application examples in the scenarios of Internet of Things (IoT), smart grids, finance, healthcare, and education. This paper summarizes the current challenges and limitations of blockchain identity authentication, such as performance scaling, privacy protection, standards interoperability, key management, etc., and the possible future research directions, including more efficient consensus algorithms, zeroknowledge proof applications, cross-chain identity mutual recognition mechanisms, and improvement of policies and regulations.
Mohsen Rahmanikivi, Cristina Pérez‐Solà, Víctor Garcia-Font
This paper introduces “SmartBLock”, a novel protocol that integrates smart lock management with the Bitcoin blockchain. By employing blockchain technology, the SmartBLock protocol eliminates the need for centralized databases (reducing the risk of data breaches) and ensures accountability for all access events. Authentication is accomplished through Bitcoin's cryptographic signature scheme. Additionally, SmartBLock is an open and manufacturer-agnostic protocol, relying on the open and permissionless Bitcoin blockchain rather than proprietary tools or protocols. Given the limited computational capabilities of Internet of Things (IoT) devices, achieving this integration presents a significant challenge. This paper provides a comprehensive review of the state of the art in smart lock protocols, details the design of the SmartBLock protocol, presents a proof-of-concept prototype to validate its feasibility, and offers a meticulous analysis of its security, privacy, and traceability features. • Literature review on blockchain-integrated smart locks. • Propose a smart lock protocol on Bitcoin for immutable and transparent management. • Provide a demonstration that the protocol is secure, private, and transparent. • Build a PoC for the proposal on an IoT device and gather evidence of its feasibility.
Bing Xu, Ahmed Bouridane, Qiang Ni, Richard Jiang
Since the mid-1990s, the evolution of internet technologies has significantly transformed global connectivity and digital interaction. Today, advances in computing and networking continue to support the development of emerging paradigms such as the metaverse and digital twins—concepts that aspire to bridge physical and digital experiences. Parallel to this, blockchain technology is reshaping traditional notions of trust by enabling immutable transaction records and smart contract automation, thereby fostering the rise of decentralized autonomous organizations (DAOs). Building on these foundations, this study presents a biometric blockchain-based e-passport system designed to improve the operational efficiency of automated border control (ABC) systems. At the core of our approach is the concept of a DAO-inspired framework for border control wherein identity verification and management tasks are executed through atomic smart contracts and recorded immutably on the blockchain. Our system incorporates biometric authentication and decentralized identity features to digitize border documentation and automate verification processes. This creates a secure, verifiable digital representation of an individual’s identity that can interact with ABC workflows. Performance evaluations conducted using Hyperledger Caliper demonstrate the potential of the proposed system, showing a 3.5-fold improvement in processing efficiency compared to traditional ABC setups.
Zeyad Ghaleb Al-Mekhlaf, Murtaja Ali Saare, Jalal Mohammed Hachim Altmemi, Mahmood A. Al-Shareeda · 9 authors
The rapid adoption of Internet of Medical Things (IoMT) devices enables real-time patient monitoring and remote diagnostics and has revolutionized healthcare delivery. Traditional cryptographic schemes like RSA and ECC, which rely on meaningful mathematical challenges, are under great threat from quantum computing, threatening sensitive medical data confidentiality and integrity. This paper proposes a quantum-resistant healthcare security framework based on lattice-based cryptographic primitives such as Learning With Errors (LWE), Ring-LWE (RLWE), and Short Integer Solution (SIS). To this end, we design a five-phase IoMT-friendly framework—Initialization, Registration, Authentication, Data Exchange, and Treatment—where each phase is backed up by lightweight cryptography primitives that can be easily implemented on the low-resource IoMT devices. Relative to the state-of-the-art lattice- and hash-based constructions, our framework involves 50-75% smaller ciphertext sizes, up to a 50% reduction of the communication overhead, and nearly 60% less in computational cost. Furthermore, the solution relies on zero-knowledge proofs, homomorphic encryption as well and attribute-based access control to guarantee strong security and privacy. Using the AVISPA tool, the framework is formally verified, showing its resistance against classical and quantum adversaries. Focusing on tangible healthcare threats, including data tampering and unlicensed access to patient diagnostics, this research paves the way for scalable, efficient, and quantum-resistant medical data protection. Our results pave the way for future investigations into secure post-quantum healthcare and IoT applications.
Yacine Belhocine, Abdallah Meraoumia, Hakim Bendjenna, Lakhdar Laimeche · 7 authors
No abstract is available for this record.
Anna Zafeiropoulou, Evangelos Sakkopoulos
As digital identity solutions become increasingly prevalent, the necessity for robust age verification mechanisms has emerged as a critical concern for a range of services, from online transactions to access to age-restricted content. Current age verification methods often fall short of accommodating the diverse standards across jurisdictions, leading to vulnerabilities and inconsistencies in user experience. One of the main objectives of this study is to identify and analyze in a systematic way existing age verification methods and the main relevant international regulatory frameworks. The Age Verification Profile by the European Commission is including and exploring Zero-Knowledge Proof-based solutions for age verification, which are also considered in the EUDI Wallet Architecture and Reference Framework. This approach not only minimizes data privacy risks but also facilitates seamless digital interactions across the European Union. This paper primarily aims to explore the critical role of the European Digital Identity Wallet Architecture and Reference Framework in age verification and demonstrate that the EUDI Wallet seeks to enhance the security and efficiency of online transactions by introducing robust age verification mechanisms that effectively balance user privacy, security, and compliance with various regulatory requirements while preventing unauthorized access to services with age restrictions, which is in line with the broader objectives of the European Digital Identity initiative. Furthermore, we examine the European Union's age verification approach via the EUDI Wallet and the U.S. framework approach, conducting a comparative analysis between them that highlights key differences in architectural design and legal underpinnings and emphasizes their advantages.
Anjum Mohd Aslam, Aditya Bhardwaj, Rajat Chaudhary
No abstract is available for this record.