Federatívne učenie (FL) umožňuje spoločné trénovanie modelu bez priameho zdieľania údajov, ale často sa spolieha na silné predpoklady o čestnom správaní klienta a servera. To je dôvod, prečo štandardné FL protokoly poskytujú iba obmedzenú záruku ohľadom výpočtov na strane klienta, integrity odoslaných informácii, alebo ohľadom správnosti agregácie na strane servera. Táto diplomová práca skúma použitie systémov s nulovými znalosťami (ZKP) spolu s podpornými metódami na vytvorenie dôvery v FL prostredí. V tejto práci sa po úvode k FL a ZKP ďalej skúma prehľad existujúcich ZKP nástrojov v prostredí FL. Na základe tejto analýzy je vytvorená kategorizácia existujúcich prístupov FL založených na ZKP, ktorá je postavená najmä na cieľoch daného systému. Na základe identifikovaných možností zlepšenia práca navrhuje overiteľný protokol váženej agregácie. V tomto protokole je každý prijatý príspevok previazaný s autorizovanou váhou, prípustnou skrytou aktualizáciou, konzistentným váženým vstupom a výslednou aktualizáciou modelu, ktorú je možné verejne overiť prepočítaním. Tento protokol bol implementovaný ako prototyp s plne funkčnými kryptografickými komponentami. Následne je tento protokol vyhodnotený.
Alireza Kavousi, Duc V. Le, Philipp Jovanovic, George Danezis
Maximal Extractable Value (MEV) is a crucial challenge in blockchains and cryptocurrencies. A principal countermeasure is using encrypted mempools to hide the transaction payloads until they are committed in a block. However, the existing approaches based on encrypted mempools remain vulnerable to metadata leakage and may not provide sufficient mitigation against block producers due to their sole control in block preparation. In this paper, we propose techniques that utilize randomized permutation on the committed block, offering a multi-layer solution. With a focus on proof-of-stake (PoS) committee-based consensus, we then introduce BlindPerm, a framework that enhances an encrypted mempool with permutation and present various optimizations. Notably, we propose a construction where this enhancement comes at essentially no overhead by piggybacking on the encrypted mempool and without relying on any external entity such as randomness beacon. Further, we illustrate the effectiveness of our solutions by running simulations using historical Ethereum data.
The retail landscape in Singapore has grown increasingly competitive over the years, with small and medium-sized enterprises (SMEs) facing mounting pressure from rising operational costs while lacking the capital to develop proprietary customer loyalty systems. Existing third-party cashback platforms such as ShopBack, while effective in driving customer retention, impose commission based fees that further erode slim profit margins. Beyond cost, these centralised platforms often suffer from single points of failure, a lack of transparency and reward fragmentation across separated ecosystems that diminishes long term customer engagement. Existing blockchain based loyalty implementations confirm commercial interest in decentralised rewards but remain constrained by permissioned architectures that exclude open merchant participation and retain centralised governance. This final year project proposes ShiokPay, a fully decentralised cashback rewards platform designed to eliminate these limitations for SME merchants and their customers. ShiokPay was designed and implemented using a Web3 architecture deployed on the Arbitrum Layer 2 Ethereum network. Three Solidity smart contracts form the core of the system. ShiokCoin, an ERC-20 rewards token. MerchantRegistry, which manages on-chain merchant onboarding and role based access control (RBAC). Along with MinimalForwarder, which enables gasless customer redemptions via EIP-712 meta-transactions. These contracts are integrated using React for the frontend, decentralised off-chain storage via IPFS and a GraphQL subgraph for real time blockchain transaction indexing. The Arbitrum L2 network was chosen to address Ethereum's scalability and gas fee limitations, while EIP-712 meta- transactions were implemented to remove the requirement for customers to hold cryptocurrency. This lowers the barrier to Web3 adoption in everyday retail environments. System validation was conducted entirely on the Arbitrum Sepolia testnet. A comprehensive test suite of 105 unit and integration test cases achieved a 100% pass rate across all three smart contracts, validating the correctness of RBAC, EIP-712 signature verification, nonce- based replay prevention and the simulated full eight-step merchant and customer lifecycle. Gas cost research evaluation confirmed that all transaction types consistently remain below $0.01, representing an approximately 98% cost reduction compared to equivalent Ethereum L1 operations. This satisfies ShiokPay's financial viability requirement for SME merchants. System latency evaluation confirmed that subgraph indexing updates averaged within seconds with optimistic UI updates reducing perceived end-user latency, meeting retail point- of-sale responsiveness requirements. ShiokPay successfully demonstrates that a permissionless, low-cost and user-friendly decentralised cashback rewards system is both technically feasible and commercially viable. By eliminating centralised intermediaries and covering customer gas fees through the meta-transaction model, ShiokPay provides SME merchants with a transparent, cost-efficient alternative to current cashback platforms. These are done while delivering a frictionless Web3 experience accessible to non-technical consumers.
The contemporary digital information ecosystem is suffering from a structural market failure analogous to George Akerlof’s "Market for Lemons." In an era of Generative AI, the marginal cost of producing misinformation has approached zero, while the cost of verifying truth remains high. This asymmetry has created a "Trust Deficit" where high-quality information cannot be reliably distinguished from algorithmic noise. Current remediation strategies are bifurcated between two flawed extremes: Centralized Web2 Platforms (which prioritize scalability at the expense of transparency and are prone to censorship) and Decentralized Web3 Networks (which prioritize immutability but suffer from the "Garbage In, Garbage Out" paradox - permanently recording unverified data). The Trust-Scalability Trilemma: This research posits that decentralized reputation systems face a "Trust-Scalability Trilemma," historically unable to simultaneously achieve Veracity (Accuracy), Scalability (Throughput), and Decentralization (Censorship Resistance). Traditional solutions, such as Token Curated Registries (TCRs), have failed because they rely on synchronous, on-chain voting for every data point, resulting in prohibitive latency and gas costs. The Solution: This paper introduces The Klyrox Protocol, a decentralized middleware designed to resolve this trilemma by decoupling Content Execution from Content Verification. The protocol introduces a novel consensus mechanism, "Proof-of-Klyrox," which combines Optimistic Machine Learning (opML) with Game Theoretic Integrity Bonds. Proof-of-Klyrox is not a blockchain consensus mechanism. It is a layered fraud-detection and incentive framework anchored to existing consensus networks. Scope Note: Protocol V1 focuses exclusively on objective, verifiable claims (e.g., market data, timestamped events, quantifiable metrics). Subjective content quality assessment (e.g., editorial judgment, artistic merit) is explicitly out of scope and scheduled for research in future iterations. The system operates on an "Optimistic" presumption of validity: Optimistic Execution: Content is verified instantly via off-chain AI Oracles, reducing verification costs by an estimated 85-95% compared to traditional on-chain governance models. Cryptoeconomic Security: Users must stake financial collateral (Integrity Bonds) to publish. This creates a "Pay-to-Truth" incentive structure where the cost of generating misinformation strictly exceeds the potential profit. Sybil Resistance: The protocol implements a proprietary Time-Decayed Stake-Weighted (TDSW) algorithm. This scoring engine ensures that influence scales logarithmically with capital (preventing plutocratic capture) and decays exponentially over time (preventing the entrenchment of dormant actors). By financializing reputation into a portable, quantifiable asset class defined as "Epistemic Capital," The Klyrox Protocol offers a scalable blueprint for a self-regulating "Market for Truth." It transforms trust from a subjective social sentiment into an objective, verifiable economic product, providing the necessary infrastructure for the next generation of decentralized media, prediction markets, and AI safety layers. Author's Note: This whitepaper outlines the technical architecture and game-theoretic mechanisms underpinning the concept of "Epistemic Capital," as explored in The Algorithmic Monographs series by Ali Sadhik Shaik (The Algorithmic Invisible Hand, The Republic of Code, The Market for Truth, The Heavy Metal Intelligence and The Synthetic C-Cuite).
Public distributed ledgers enforce integrity through radical transparency, creating tension with data minimization principles required for regulatory compliance. While Zero-Knowledge Proofs (ZKPs) offer a theoretical privacy solution, existing constructions often overlook adversarial constraints in smart contract environments. Specifically, the asynchronous decoupling of off-chain proof generation from on-chain submission introduces front-running and proof-reuse risks in public mempools. In this work, we formalize Selective Disclosure Authorization Schemes (SDAS), a cryptographic primitive for granular and revocable compliance checks on public ledgers without revealing the underlying witness. We define a security model for SDAS, introducing Ledger-Bound Attribute Unlinkability and Context-Aware Sender Binding to capture how valid proofs remain bound to their intended authorization context. To validate sender binding, we present ZK-Compliance, an Ethereum-based instantiation that operationalizes a user-controlled "Grant, Verify, Revoke" lifecycle. We implement the sender-binding component using a 14-constraint Circom circuit that anchors the zero-knowledge proof to the executing on-chain sender address. Our Sepolia evaluation confirms practical viability: browser-based proof generation executes in under 200 ms, and on-chain verification costs 240,512 gas, neutralizing proof reuse by different callers while preserving strict attribute privacy.
Decentralized finance (DeFi) protocols that depend on external settlement facts (whether asset prices from oracle networks or off-chain payment confirmations) must make irreversible on-chain state transitions based on information they cannot directly verify. This settlement verification problem is governed by a fundamental tension between safety (rejecting false claims) and liveness (accepting true claims promptly), mediated by the capital, latency, and trust assumptions a protocol is willing to absorb. We formalize settlement verification as a binary hypothesis-testing problem over an adversarial multi-publisher channel and establish three main results. (1) Oracle Verification Trilemma. For any settlement verification mechanism operating over an adversarial oracle channel with adversarial fraction ϕ δ], where δ is the mechanism’s error-absorption capacity. For hyperbolic funding rates, the singularity at the solvency boundary provides robustness amplification: a β-fraction capacity utilization tolerates oracle errors up to (1 − β) times the total capacity.
Sandro Rodriguez Garzon, Awid Vaziry, Enis Mert Kuzu, Dennis Enrique Gehrmann · 7 authors
A fundamental limitation of current LLM-based AI agents is their inability to build differentiated trust among each other at the onset of an agent-to-agent dialogue. However, autonomous and interoperable trust establishment becomes essential once agents start to operate beyond isolated environments and engage in dialogues across individual or organizational boundaries. A promising way to fill this gap in Agentic AI is to equip agents with long-lived digital identities and introduce tamper-proof and flexible identity-bound attestations of agents, provisioned by commonly trusted third parties and designed for cross-domain verifiability. This article presents a conceptual framework and a prototypical multi-agent system, where each agent is endowed with a self-sovereign digital identity. It combines a unique and ledger-anchored W3C Decentralized Identifier (DID) of an agent with a set of third-party issued W3C Verifiable Credentials (VCs). This enables agents at the start of a dialog to prove ownership of their self-controlled DIDs for authentication purposes and to establish various cross-domain trust relationships through the spontaneous exchange of their self-hosted DID-bound VCs. A comprehensive evaluation of the prototypical implementation demonstrates technical feasibility but also reveals limitations once an agent's LLM is in sole charge to control the respective security procedures.
Long-range attacks pose a significant threat to the integrity of Proof-of-Stake (PoS) blockchains by enabling adversaries to reconstruct an alternative chain history embedded with fraudulent transactions. These attacks can deceive honest participants into accepting a maliciously crafted branch as the canonical chain. While Key Evolving Signature (KES) schemes are widely adopted to mitigate such threats, they typically rely on the assumption that validators behave honestly. In this work, we challenge this assumption by demonstrating how a malicious validator can exploit inherent limitations in existing KES-based mechanisms to mount a successful long-range attack. To address this critical vulnerability, we introduce a novel cryptographic construction that combines one-time signatures with commitment schemes. Our approach imposes constraints on the signing capabilities of validators, thereby significantly reducing the feasibility of long-range attacks. We provide rigorous formal security proofs to substantiate the robustness of our scheme and conduct a comprehensive performance evaluation. The results show that our solution is both computationally and storage efficient, making it a practical and scalable defense mechanism for real-world PoS blockchain deployments.
Tato diplomová práce se zaměřuje na problematiku MEV útoků, které jsou provedené v prostředí blockchainu postaveném na proof-of-stake protokolu. Tyto MEV snižují tak bezpečnost, stabilitu a důvěru sítě. Práce se nejprve se zabývá teoretickým úvodem do problematiky, spolu s analýzou jednotlivých MEV útoků: front-running, back-running, sandwich útok a arbitráž. Jednotlivé útoky jsou ohodnoceny podle jejich vlivu na síť, uživatele, transakce a konsensus. Dále se práce věnuje existujícím mitigačním technikám a jejich kombinacím, zahrnující řešení permutace, šifrování transakcí, opožděná exekuce bloků a jejich rozšíření. Zároveň se zabývá i aktuální proposal-builder separation architekturou, která je aplikovaná v Ethereum blockchainu. Práce se poté koncentruje na konkrétní návrhy využití těchto mitigačních technik jako je BlindPerm, MEVade a MEV-Boost řešení. Dále se zabývá simulací a analýzou vlivu MEV útoků na tyto mitigační metody. Simulace je rozdělena do několika oddělených experimentů, které se zaměřují na jednotlivé klíčové vlastnosti. Výsledky těchto experimentů na sebe navzájem navazují a tvoří robustní analýzu slabých i silných bodů návrhů mitigačních technik. Tyto výsledky jsou porovnány a diskutovány pro možné další rozšíření práce.
This paper presents a conceptual architecture for a hybrid distributed ledger system designed to address challenges in cross-border payments and remittances. Current payment infrastructure suffers from high costs, slow settlement times, and limited transparency. While cryptocurrency-based public blockchains and permissioned enterprise systems have been proposed separately, a comprehensive framework integrating both approaches with traditional payment rails remains lacking. We propose a multi-layered architectural design that combines Hyperledger Fabric for inter-bank settlement, R3 Corda for bilateral agreements, and existing payment systems for retail transactions. The proposed system incorporates consensus optimization strategies, atomic cross-ledger transaction protocols, and automated regulatory compliance mechanisms. Through architectural analysis and comparison with existing systems, we identify key design principles for scalability, interoperability, and regulatory compliance. This work contributes a detailed architectural specification and identifies critical research challenges requiring future investigation, including performance optimization, security validation, and regulatory framework development. The proposed architecture serves as a foundation for future implementation and empirical evaluation.
The rapid progress in quantum computing poses a severe risk to contemporary blockchain systems, as their reliance on vulnerable primitives like ECDSA and RSA allows quantum algorithms (e.g., Shor's) to break discrete logarithm and factorization problems, potentially enabling attackers to forge signatures, steal assets, impersonate users, and compromise ledger immutability—undermining the core trust model of decentralized finance and Web3 applications.To preempt this crisis, we propose a next-generation quantum-resistant multicchain blockchain architecture fused with an intelligent AI-powered Web3 threat firewall. The framework natively adopts NIST-approved post-quantum cryptography, integrating lattice-based ML-DSA (Dilithium) and hash-based SLH-DSA (SPHINCS+) schemes throughout the protocol stack: from secure key-pair generation in wallets, through transaction signing, to rigorous multi-node verification during consensus. This design ensures end-to-end protection against foreseeable quantum threats across diverse chains without requiring disruptive hard forks or retrofits.Comprehensive testnet experiments quantify the trade-offs: post-quantum signatures incur larger payload sizes (typically 2–4× compared to ECDSA) and modestly increased signing/verification times, yet the overall transaction processing capacity remains practical for everyday use, with throughput and latency suitable for high-volume decentralized applications. Storage and bandwidth overheads stay manageable through optimized encoding and pruning techniques.Augmenting cryptographic hardening, the AI threat firewall leverages machine learning models to perform real-time anomaly detection across multichain interactions, identifying subtle signature irregularities, suspicious patterns, and novel attack vectors—including those exploiting transitional quantum vulnerabilities—thereby providing adaptive, proactive defense beyond static primitives.These findings confirm that fully quantum-secure blockchain systems are deployable today with acceptable performance penalties, paving the way for resilient, future-proof Web3 infrastructure capable of withstanding the quantum era while preserving usability, scalability, and economic viability for global adoption.
Low-altitude aerial networks play an increasingly critical role in urban logistics, emergency response, and intelligent airspace management. These networks must ensure reliable identity authentication while addressing privacy, efficiency, and security challenges. Traditional authentication mechanisms—such as PKI-based certificates and remote identification—either overexpose identity data or lack support for flexible attribute disclosure. Moreover, existing anonymous credential (AC) schemes, though offering privacy, often incur high computational and communication costs and exist vulnerable to replay attacks. To address these limitations, we proposeDVA-ACLF(Designated Verifier Asymmetric Anonymous Credential Scheme for Low-Altitude Flight), a lightweight credential system tailored for UAVs. DVA-ACLF leverages an efficient MAC-based construction combined with non-interactive zero-knowledge proofs to enable selective attribute disclosure without relying on pairings. It supports designated verification to prevent credential misuse and replay. Experimental results show that DVA-ACLF reduces credential size by 49% (2720 bits vs. 5369 bits in Idemix) and mitigates the linear growth of credential size with respect to attribute count observed in CL and BBS+ schemes. It requires only four single-base and$2(k-l)$double-base exponentiations on UAVs, where$k$is the number of selected attributes and$l$is the number of disclosed attributes—both typically small. These features make DVA-ACLF a strong candidate for secure, efficient, and privacy-preserving authentication in low-altitude flight applications.
Isaac Amankona Obiri, Qi Xia, Jianbin Gao, Hu Xia · 5 authors
The growing adoption of electronic personal health records (ePHRs) demands cryptographic solutions that ensure secure and efficient data access. Threshold cryptography provides a framework for controlled multi-party access, yet existing schemes face practical limitations. Many require trusted key dealers, creating single points of failure and key escrow vulnerabilities, while others rely on pairing-based constructions that scale poorly. Furthermore, batch-oriented processing in previous schemes fails to support individual on-demand access patterns typical in healthcare applications. We propose a Distributed Identity-Based Threshold Decryption (DIBTD) scheme that addresses these limitations. First, our protocol removes all trusted setup assumptions through a fully distributed key generation mechanism based on verifiable secret sharing. Second, it achieves constant-time encryption and decryption operations, independent of committee size, by using efficient elliptic curve operations on secp256k1 rather than computationally heavy pairings, yielding up to 56× faster encryption than prior work. Third, DIBTD integrates the detection of malicious actors via zero-knowledge proofs, allowing the dynamic exclusion of compromised participants during system initialization. We provide formal security proofs showing the security of IND-CCA2 in the random oracle model under the discrete logarithm of the elliptic curve (ECDLP) and computational Diffie-Hellman (CDH) assumptions. The scheme remains secure against adaptive adversaries that control up to$t-1$participants. Experimental evaluation demonstrates practical efficiency: ciphertexts of only 86 bytes, constant 33-byte public keys, and sub-millisecond encryption latency. A pure Rust implementation on commodity hardware achieves 0.065ms per patient record while maintaining 128-bit security.
This report examines smart contracts as a key element in the development of decentralized systems and as a factor for a profound transformation of traditional contract law.The analysis focuses on the essence of smart contracts, their technological mechanism of action and the role of cryptography in ensuring trust and security without the need for a central intermediary.Particular attention is paid to the way in which program code begins to perform functions traditionally inherent in legal norms and institutions.Smart contracts are not just a technical tool, but a new socioeconomic mechanism for regulating relations between entities in a digital environment.The report also examines the concept of "Code is Law" as a philosophical and practical framework that questions the classical legal principles of interpretation, flexibility and judicial review.Both the potential benefits of this paradigm and the risks arising from full automation are analyzed.Additionally, the main vulnerabilities of smart contracts that arise as a result of human errors when writing the code and the irreversibility of actions in a blockchain environment are examined.These risks show that technological security does not always mean legal justice.Finally, the legal status of smart contracts in Bulgaria and the European Union is examined.
Open access
Cryptography and Data Security
Advanced Research in Systems and Signal Processing
Wenjiang Shang, Hailing Li, Jun Wang, Chun Gui · 6 authors
The proliferation of mobile payments has brought about increasingly severe security challenges, including data breaches and identity forgery, which pose a significant threat to user assets and privacy. To meet the stringent security requirements of China’s multi-level protection scheme (MLPS) level 3 for financial systems, this study proposes an innovative privacy-enhancing protection scheme for mobile banking payments. This scheme is designed to provide comprehensive security throughout the entire lifecycle, from payment authentication to subsequent auditing. Specifically, our solution introduces two core mechanisms: the privacy-preserving authentication (PPA) protocol, which ensures the privacy of user identities and transaction data during the payment process by combining the private data access characteristics of oblivious RAM (ORAM) with zero-knowledge proof technology; and the distributed ledger audit mechanism (DLAM), which utilizes the decentralized and immutable features of blockchain, supplemented by ORAM, to guarantee the integrity of system logs and the privacy of the auditing process.
Li Xu, Mohd Nurul Hafiz Ibrahim, Mustafa Muwafak Alobaedy, S. B. Goyal
This is the first PRISMA-guided systematic review of scalable blockchain digital signatures for healthcare, synthesizing evidence from 85 peer-reviewed studies published between 2015 and 2024. The review examines five thematic areas: digital signatures, consensus mechanisms, smart contracts, hybrid blockchain architectures, and regulatory compliance. Particular emphasis is placed on scalability challenges and the role of alternative consensus protocols, such as Proof-of-Stake and Delegated Proof-of-Authority (DPoA), in addressing the energy and latency limitations of Proof-of-Work (PoW). Findings highlight the value of smart contracts in automating consent and authentication processes, while hybrid blockchain models are shown to balance security with scalability. The synthesis also identifies persistent challenges, including interoperability with legacy systems, energy consumption, and compliance with GDPR and HIPAA regulations. Importantly, emerging approaches such as Layer-2 scaling, AI-enhanced validation, and post-quantum cryptography are highlighted as promising directions. By integrating technical and regulatory perspectives, this review contributes a critical roadmap for researchers, healthcare providers, and system architects seeking secure, efficient, and regulation-compliant blockchain frameworks
This comprehensive technical survey presents integration architectures for the Y.I.N. (Your Information Never leaves your control) Nine Pillars framework across 200+ commercial platforms spanning artificial intelligence (100+ LLM providers including OpenAI, Anthropic, Google DeepMind, Meta, Microsoft, Mistral AI, Baidu, Alibaba, Tencent), healthcare (50+ providers including Epic Systems, Tempus, PathAI), finance (40+ institutions including JPMorgan Chase, Goldman Sachs, BlackRock), autonomous vehicles (20+ companies including Waymo, Tesla, Cruise), telecommunications (25+ carriers including AT&T, China Mobile, Deutsche Telekom), and energy (20+ companies including Siemens Energy, NextEra) across 25+ countries. The Y.I.N. Nine Pillars architecture provides end-to-end privacy protection through: (1) Data Privacy (Differential Privacy), (2) Computation Privacy (Homomorphic Encryption), (3) Storage Privacy (Encryption at Rest), (4) Transmission Privacy (TLS 1.3), (5) Access Control (Zero-Knowledge Proofs), (6) Audit Trail (Merkle Trees), (7) Deletion Rights (Cryptographic Erasure), (8) Quantum Resistance (Lattice-based Cryptography), and (9) Token Licensing (Cryptographic Payment Enforcement). The Ninth Pillar token licensing system, covered by U.S. Patent Application 63/949,361 (filed December 28, 2025), provides cryptographic enforcement of usage rights by integrating token-derived blinding factors into homomorphic encryption operations, making computational correctness mathematically dependent on valid authorization. The system achieves 99.37% accuracy with valid tokens versus 50.7% with invalid tokens (t=147.3, p<10^-50), with security proven under CDH hardness (2^128 operations) and Ring-LWE assumptions. Integration schematics are provided for regulatory compliance with HIPAA (healthcare), SOX/DORA (finance), GDPR/EU AI Act (European Union), CCPA (California), PIPL (China), ISO 27001, NERC CIP (energy), and 15+ other frameworks. Extension directions are documented for community research including TEE hybrid architectures, MPC integration, VDF token lifetimes, key-homomorphic PRFs, flexible validation policies, hardware attestation, ABE capabilities, off-chain settlement, and DID/VC integration. Organizations seeking to implement these integration patterns may obtain licenses for individual pillars, sector packages, or the complete Nine Pillars system from the patent holder. Patent Notice: The Y.I.N. Nine Pillars architecture and Ninth Pillar token licensing system are covered by U.S. Patent Applications 63/949,361 (Ninth Pillar, filed December 28, 2025), 63/923,348 (QFED-MAZARI Quantum Extensions), 19/399,646 (Core Y.I.N. Architecture), 19/403,244 (Hardware Implementation), and 19/417,196 (SQL Database Integration), comprising 430+ claims across 15 patent applications.
L. B. WANG, Liming Zhang, Ruitao Qu, Tao Tan · 6 authors
Existing vector geographic data transaction schemes are typically merchant-controlled, hindering fair ownership tracing and impartial arbitration. To address this, we propose an asymmetric digital fingerprinting scheme based on smart contracts. In our approach, the user encrypts a proof fingerprint with a public key and sends it to the merchant; the merchant leverages the additive homomorphic property of the Paillier cryptosystem to embed the encrypted user fingerprint into an encrypted portion of the vector data while embedding a tracking fingerprint into the plaintext portion. The combined data is delivered to the user, who uses their private key to decrypt the encrypted part and obtain the plaintext data containing both fingerprints. This design enables tracing of unauthorized distribution without exposing the user’s fingerprint in plaintext, preventing malicious accusations. By leveraging blockchain immutability and smart contract automation, the scheme supports secure, transparent transactions and decentralized arbitration without third-party involvement, thereby reducing collusion risk and protecting both parties’ rights.
Open access
Advanced Steganography and Watermarking Techniques