Secure, interconnected, and compatible data sharing of Electronic Health Records (EHRs) across healthcare domains is essential for timely patient care and improved adaptability in healthcare infrastructures. Current challenges must be addressed, including centralization threats, fragmented standards, and threats from quantum computing. This paper proposes a blockchain-based EHR framework using post-quantum cryptography and HL7 FHIR standards for secure, interoperable data sharing. It employs smart contracts for patient-centric access control and HotStuff BFT consensus, achieving 928 TPS with 2.1-second finalization. Zero-knowledge proofs enable privacy-preserving authentication, and dynamic accumulators improve revocation storage efficiency by 89%. On a 20-node testbed, the system sustains 620 TPS at 500 ms latency, with under three-second access grants and 95% storage efficiency via cryptographic pointers. Compared to current systems, it offers 20× higher throughput and resists quantum threats. Multi-hop exchange across three hospitals reduced normalization efforts by 40%. Comprehensive assessment on the system outcomes reveals that our framework significantly enhances security, scalability, and interoperability for decentralized healthcare networks.
Smart contracts are programs that automatically enforce some kind of agreement between parties, without the need of a trusted third party. Since they frequently deal with large sums of money (in the form of crypto assets) it is critical that smart contracts attain precisely to their specification and do not have any unexpected behaviour. In this thesis, I will present two lines of research, one related to developing smart contract languages for the UTXO blockchain model, and the other related to the formalization of MEV attacks.
The security and privacy of blockchain data have become critical research challeSimilarly, the full-function accounting node verifies the validitynges. While numerous approaches have been proposed to address these concerns, many existing schemes suffer from high computational complexity or excessive verification latency. To bridge this gap, this paper presents a secure and privacy-preserving blockchain data transaction verification system. By integrating the Paillier cryptosystem with a zero-knowledge range proof protocol, the proposed system ensures the confidentiality of transaction amounts and participant identities, simultaneously achieving strong anonymity and conditional traceability for users. Moreover, fully functional accounting nodes support efficient ciphertext-domain balance updates, eliminating the need for decryption during accounting operations. Experimental evaluation confirms the practicality and high performance of the proposed system.
NOXFORD ID is a seven-layer privacy-preserving identity verification architecture designed to address a specific fraud vulnerability in cross-institutional identity validation: the brittleness of exact-match verification against ordinary, legitimate variation in how names and dates are recorded across institutions. The architecture combines hardened Bloom-filter cryptographic linkage (privacy-preserving record linkage), field-separated fuzzy matching, a probabilistic decision engine with an explicit human-review tier, a tamper-evident cross-institutional integrity ledger, a genuine Schnorr zero-knowledge proof of identity knowledge, replay-resistant institution-specific key derivation, and a Root Certificate Authority layer aligned with Nigeria's NIMC Act 2026, which designates the National Identity Management Commission as Root Certification Authority for the country's National Public Key Infrastructure. Each layer is independently implemented and empirically tested against a labeled test corpus, with results reported transparently, including design flaws discovered and corrected during development. The paper documents a measured reduction in false rejection of legitimate citizens from 57% to 14% relative to a representative exact-match baseline, while maintaining zero fraud slip-through in testing, and explicitly states the system's current limitations, including evaluation corpus scale, dependence on enrollment-data integrity, and pending network-level threat-detection integration.
The BLS digital signature scheme, in particular its instantiation with the BLS12-381 curve, has become a cornerstone of modern blockchain protocols such as Ethereum Proof-of-Stake, due to its unique and attractive characteristics (e.g., support for non-interactive signature aggregation). Recently, Cheng et al. (CHES 2025) demonstrated that the enormous Single-Instruction-Multiple-Data (SIMD) computing power of the Intel AVX-512 extensions, when combined with carefully-designed vectorization strategies, can be effectively leveraged to speed up the computation of the optimal ate pairing on BLS12-381, a major component of BLS. This naturally raises the question of whether such SIMD-parallel processing can be exploited more extensively to benefit the entire BLS signature scheme. The present paper answers this question positively by presenting a highly SIMD-optimized BLS implementation using Intel AVX-512, especially the AVX-512IFMA instructions. In order to harness AVX-512 more efficiently for the performance-critical operations of BLS, we explored a wide range of optimization options, including various formulas and vectorization granularities for elliptic curve arithmetic operations, scalar multiplication, and hashto- curve, as well as the fine-tuning and flexible use of different implementations of the finite-field arithmetic. Benchmarking results collected on an Intel Core i3-1005G1 (“Ice Lake”) CPU show that our vectorized BLS software using AVX-512 is at least 1.57 times faster than an x64 assembly implementation of the widely-used blst library
ABSTRACT TRSP — The Temporal Security Architecture: The Consolidated Record. Three documents, one DOI: the Security Record, the Economic Record, and a general-audience companion. Every cryptographic system in production today rests on one assumption: that a mathematical problem is too hard to solve in practical time. Quantum computing places an expiry date on that assumption, and adversaries are already recording encrypted traffic and public ledgers at scale — harvest now, decrypt later. This record consolidates the Temporal Rotation Security Protocol (TRSP) series into its canonical form. TRSP closes the attack surface that post-quantum mathematics leaves open: cryptographic keys are generated from physical hardware entropy at the moment of use, exist for a rotation window measured in milliseconds, and are destroyed by hardware-enforced destructive readout. Between operations, no persistent credential exists anywhere in the system. This record comprises three documents under one DOI: Document 1 — The Security Record (TRSP — The Temporal Security Architecture: Time as the Fundamental Security Parameter). The consolidated technical reference of the series. It states the security doctrine with precision as a division of labour across three attack mechanics: temporal rotation eliminates the stored-credential surface (endpoint extraction by malware, insiders, hardware probing, or coercion); NIST-standardised post-quantum mathematics (ML-KEM, ML-DSA) eliminates the recorded-transcript surface; single-use protocol rules eliminate the public-record surface, since a retroactively derived key finds its one permitted action already complete and refused for reuse. Each threat is assigned to the layer that closes it structurally — the combination this architecture defines as quantum permanence. The architecture is organised in three layers named for the Norse Norns of time: URDHR (the irrecoverable past — hardware commitment and Landauer-anchored destruction, with optional macroscopic optical entropy), VERÐANDI (the witnessed present — geographically distributed quorum validation bounded by light-speed, with a canonical rotation-window definition of 10–100 ms default and adaptive extension to 500 ms for global quorums), and SKULD (the anchored future — LEO satellite quorums contributing unpredictable physical state measurements under relativistic timestamp validation). Further parts document the four-layer temporal-quantum hybrid (LTQS), the formal ephemeral verification pipeline with zero-knowledge enrollment binding and an explicit statement of the minimised persistent root, application domains ordered by strategic value (AI-to-AI authentication and micropayment, cloud access immune to credential breaches, interbank settlement finality across multi-decade ledgers, critical infrastructure command authorisation, interplanetary autonomous verification, and the consumer expression documented in the TRSP Citadel record), a compliance architecture reconciling maximum personal privacy with institutional regulatory obligations through enrollment tiers, and nine engineering considerations with documented solution pathways. Document 2 — The Economic Record (TDC — The Temporal Digital Coin: Value Anchored in Verified Moments). The corrected canonical economic layer of the series (NC-TDC-26 through NC-TDC-32). It opens with an explicit correction: earlier records simultaneously asserted fungibility of all units, no re-pricing across phases, and rising per-phase value ranges — three statements that are jointly impossible, since a fungible asset trades at exactly one price. This record resolves the contradiction in favour of the principles and formally retracts the per-phase value ranges. The canonical doctrine: one coin, one price, stability by coupled expansion — supply is admitted only against verified, settled growth of the anchored economies under the quantity-theory identity M·V = P·Q, with governance-bounded elasticity, so that price-level stability becomes an accounting consequence of the issuance rule rather than a promise, and early holders gain no phase windfall by construction. Further parts document Proof of Physical Presence consensus economics (validation democratised to enrolled devices; the attack currency is human recruitment), the corrected role of temporal uniqueness (events anchor authenticity, never scarcity — scarcity derives from governance, value from anchor-economy demand), supply and issuance rules, the multi-anchor demand architecture (machine, institutional, and sovereign economies as demand sources, never price classes), consortium governance defined primarily by its prohibitions, the phased rollout in corrected form, and economic engineering considerations including velocity management, demand shocks, exchange-rate regime, bootstrap liquidity, and measurement integrity. Document 3 — The Companion Article (The Key That Even a Time Machine Cannot Steal). A general-audience presentation of the complete architecture — protocol, secure personal computer, and coin — written for readers outside the field, including the time-traveler thought experiment, the three guards (sortition, light-speed, multilateration) in plain language, and the estate architecture. It introduces no claims beyond the technical records. Newly registered contributions. In addition to consolidating and re-registering all prior novel contributions of the series (NC-TDC-1 through NC-TDC-41, NC-URDHR-1, NC-TRSP-Hybrid-1), this record places the following on the public record of prior art as of its publication date, each with a full enabling defensive specification (Security Record, Part 10a): NC-TDC-42 — Optical Air-Gap Content Transfer (formally registered herein, first described in the Citadel record): content crosses a security boundary as rendered light captured by a hardware-switched sensor and locally reconstructed via optical character recognition — the meaning crosses, the file never does; enumerated elements include the security inversion (the receiver harvests, the sender has no channel), the hardware-gated exception to device-level optical silence, and throughput asymmetry as a security property; registered embodiments include matrix-barcode, audio-channel (synthesised speech to local speech-to-text), and enterprise domain-transfer variants. NC-TDC-43 — Chained Presence Verification (newly documented): a unified three-link defence against device-farm collusion — sortition (per-transaction quorum draw via verifiable random function, unpredictable in advance, verifiable after), light-speed (adaptation between draw revelation and window close physically impossible), and multilateration (propagation-delay fingerprints against a relativistically validated time base expose any participant absent from its claimed position) — with the explicit answer to the position-based-cryptography impossibility result (Chandran–Goyal–Moriarty–Ostrovsky 2009): the architecture proves the position of an attested hardware module under an unpredictable draw, removing the pre-positioned-collusion premise the impossibility proof requires. NC-TDC-44 — Ephemeral Witness Relations (newly documented): the formal security model of time-bounded credentials — keys as functions of bounded temporal support with the derived metric of temporal attack surface; erasure completeness as a zero-mutual-information condition I(sk_eph; S(t)) = 0 with Landauer's bound identified as the realisation floor of erasure and explicitly not as a barrier to mathematical re-derivation; the composite adversarial bound over orthogonal domains (computational hardness, temporal measure, combinatorics of presence) with the binomial sortition term; the spacetime-local physical oracle O(D, t) with destructive-readout consumption; and ownership as a time-indexed capability predicate over uncopyable events, including the transient-witness class, the notion of proof of transient knowledge, and the no-retroactive-forgery bound. NC-TDC-45 — Disturbance-Elevated Alpha-Quorum Time Reference. Binding authorisation to short time windows places the local clock in the trusted computing base. This contribution redistributes time-validation authority at the moment of attack rather than fixing it in advance: under normal conditions all nodes validate equally; on detection of a time-source anomaly (cross-source divergence, or a multilateration residual beyond threshold), the system elevates a small set of hardened, atomic-clock-bearing nodes to a median-of-five reference — which tolerates two outliers, so shifting it requires corrupting at least three of five. Membership is fixed by short-lived sortition at the moment of elevation, so the set cannot be pre-targeted. Every coordinated time attack thereby degrades to denial, never forgery: it can interrupt authorisation, not manufacture one. Additionally placed on record in the Economic Record: the coupled-expansion issuance doctrine (corrected canonical form of NC-TDC-29), the corrected scope of NC-TDC-27 (temporal anchoring of authenticity, with uniqueness explicitly disclaimed as a source of value), and the formal retraction recorded in NC-TDC-31 — the corrections themselves are part of the prior-art registration. Consolidation and continuity. This record consolidates and supersedes as canonical reference: TRSP v3 (10.5281/zenodo.20324081), TRSP Digital Coin (10.5281/zenodo.20346658; v2: 20332811; v1: 20288860), TRSP: The Authorization Protocol for Everything (10.5281/zenodo.20402892), and TRSP Citadel (10.5281/zenodo.20481331). The four source records remain in force as prior art; where formulations differ, this record is authoritative. The CRATON designation in prior records and the URDHR designation in this and future records refer to architecturally identical concepts; prior-art continuity is complete and uninterrupted. The economic layer and the security layer are maintained as separate documents within this record by design: each addres
Due to the fast development of digital communication technologies and the creation of distributed computing architecture, it is crucial to ensure the security of communication through effective and safe authentication schemes that can protect data privacy within cybersecurity frameworks. The most efficient cryptographic method for such purposes is zero knowledge proof since it provides ultimate security by proving the authenticity without disclosing any sensitive data to the verifying party. It is fascinating to look into the zero-knowledge proof protocol based on graph isomorphism because of its mathematical nature. A detailed discussion on the graph isomorphism based zero-knowledge authentication techniques along with their significance in the current cryptography is presented in this paper. Working principles and concepts behind graph theoretic based authentication techniques and the concept of graph isomorphism and zero-knowledge proofs have been discussed in this paper. Besides, emerging application areas of these protocols in disciplines like cybersecurity, block-chain. Internet of Things security, cloud computing and post-quantum cryptography have also been highlighted in this paper. In addition to that, this paper provides an analysis of major advantages, drawbacks and future research directions for the graph theoretic zero-knowledge authentication schemes
# VeriSBOM: Secure and Verifiable SBOM Sharing Via Zero-Knowledge Proofs **VeriSBOM**, a trustless, selectively disclosed SBOM framework that provides cryptographic verifiability of SBOMs using zero-knowledge proofs. Within VeriSBOM, third parties can validate specific statements about a delivered software, mainly regarding the authenticity of the dependencies and policy compliance, without inspecting the content of an SBOM. Respectively, VeriSBOM allows independent third parties to verify if a software contains authentic dependencies distributed by official package managers and that the same dependencies satisfy rigorous policy constraints such as the absence of vulnerable dependencies or the adherence with specific licenses models. ## Key Features * **Selective Disclosure (Hiding):** Choose which proprietary components to hide from the public SBOM. The system generates a cryptographic proof that replaces the plaintext data, guaranteeing privacy. * **High-Performance Folding:** Powered by **Nova-Scotia**, utilizing recursive SNARKs to handle SBOMs. * **Interactive Dashboard:** A complete 4-step workflow (Package Manager, Auditor, Vendor, Client) built with **Streamlit**. ## Repository structure The repository contains three main folders: 1. **Empirical**: contains **Benchmarking** and **src**, for the analysis and source code, respectively. 2. **User study**: contains the code and results of the user study. 3. **README_Doc**: contains the images used for this documentation. ## VeriSBOM Architecture The system is divided into four main roles: 1. **Package Manager**: Maintains the package repository with the allowed packages. 2. **Auditor:** Represents the regulatory body marking the compliance status by checking the packages of the package manager. 3. **Software Vendor:** Represents the entity that provides software artefacts and wants to hide the related SBOMs for privacy reasons. He is responsible for the generation of the cryptographic proofs as verifiable substitutes of the hidden packages in SBOMs. 4. **Client:** The end-user who receives the cryptographic proofs along with the software artefact for verifying binding, inclusion and compliance status. ## Web Access (Recommended) **For direct access to the artefact, VeriSBOM can be accessed at this public link** https://verisbom-verisbom-software.hf.space ## Setup & Installation Follow the README within the artefact ## Operational Workflow The application follows a **linear workflow** composed of four steps. Each step depends on the output generated in the previous one. > **Performance Note** Due to the cryptographic operations involved, generating proofs may take some time depending on the number and complexity of the active policy constraints. In the current reference environment, proof generation takes approximately **~5 seconds**, while verification takes around **~3 seconds per proof**. ## Step 1 — Package Manager In this step, the **Package Manager initialises the package repository**. ### Instructions 1. Open the **Package Manager** tab. 2. Click **`Load repository`**. > For convenience, the system automatically loads a **default repository containing packages from the NPM ecosystem**. ### Expected Output After successful execution: - A **green confirmation message** is displayed. - The **package list** appears on the left panel. - The **dependencies of each package** can be inspected on the right panel using the search bar. - A **dependency graph** is displayed at the bottom of the interface. ## Step 2 — Auditor In this step, the **Auditor defines policy constraints** that will be applied to the packages in the repository. ### Instructions 1. Enter a **policy name** (e.g., `Vulnerabilities`, `MIT License`). 2. Click **`Add`** to create the policy constraint. 3. Use the **search bar** to locate target packages. 4. **Uncheck packages** to mark them as **non-compliant**. > By default, **all packages are marked as compliant**. 5. Click **`Save and Propagate`** to apply the policy. ### Optional - Repeat the previous steps to create additional policy constraints. - Remove policies that are no longer required. ### Expected Output - A **green confirmation message** appears. - A **dependency graph visualisation** shows how non-compliance propagates across dependencies for the selected policy (or combination of policies). ## Step 3 — Software Vendor In this step, the **Software Vendor generates cryptographic proofs for a given SBOM**. ### Instructions 1. Upload a **local SBOM file**. > For demonstration purposes, the system automatically loads an **example SBOM**. 2. In the **Selective Disclosure** section: - Select which SBOM packages should be used for proof generation. 3. Click **`Generate Proofs`**. 3. Click **`Download`**. - Download the SBOM with hidden components and plaintext components ### Expected Output - A **progress bar** indicates the proof generation process. - **Green confirmation messages** appear once proofs are generated successfully. > **Important:** Successful proof generation only means that the **cryptographic proof has been constructed correctly**. Compliance with policies is verified only in **Step 4**. ## Step 4 — Client In the final step, the **Client verifies the proofs generated by the vendor**. ### Instructions 1. Upload the **SBOM**. 2. Select a **policy** from the dropdown menu. 3. Click **`Verify`**. ### Expected Output - **Verified (green badge)** The SBOM satisfies the selected policy. - **Failed (red badge)** The verification failed, and the interface displays the reason for the failure.
Ilango (FOCS 2025) invented effectively zero-knowledge proofs, a new variant of zero-knowledge. We reformulate it in the language of logic and give simple proofs (under the same assumptions as Ilango (FOCS 2025)) of its existence and of the key property defined in Ilango (FOCS 2025) that it is "indistinguishable from true" (that property is in Ilango (FOCS 2025) a part of the definition of the prover, not its consequence). Using the theory of proof complexity generators we show that the concept can be turned it into a genuinely zero-knowledge proofs, assuming a conjecture from the theory about the existence of a hard generator and allowing the parties to share a common random string.
Traditional secret sharing techniques such as Verifiable Secret sharing (VSS) are vulnerable to quantum attacks by a Cryptographically Relevant Quantum Computer (CRQC) running Shor's algorithm. We observe that the binding a VSS needs is required only at the moment of dealing, and this binding can be made before any CRQC exists. We propose Proof in a Bottle (PiB), which decouples verifiability from long-term binding: standard Pedersen commitments provide zero-knowledge, publicly checkable consistency during a pre-quantum window, while a salted, index-bound hash of the share set, anchored to an immutable public ledger, preserves the binding established in that window into the post-quantum era. The guarantee is explicitly a commit-now, reveal-later one: it protects today's honest dealings against tomorrow's quantum adversary.
Quantum resource estimates for the elliptic-curve discrete logarithm problem (ECDLP) now shape cryptographic migration planning, blockchain security analysis, and fault-tolerant architecture design. Recent work has moved in two complementary directions: Babbush et al. give improved secp256k1 resource estimates supported by zero-knowledge attestation while withholding sensitive circuit details, whereas Luo et al. publish an explicit reversible modular-inversion construction based on the extended Euclidean algorithm, reducing the logical-qubit footprint of prime-field ECDLP and identifying gate count, depth, and architecture-aware implementation as natural optimization targets. This note proposes a third disclosure model: verifiable resource certificates for public reversible arithmetic blocks. A certificate records a circuit commitment, gate basis, resource counts, input-output specification, deterministic test generation, correctness transcript, and optional proof artifact. We specialize the framework to modular inversion blocks |x⟩|0⟩ → |x⟩|x−1 mod p⟩, for \(x\in\mathbb F_p^\times\), which are central to affine-coordinate quantum ECDLP implementations. We prove a basic soundness bound for hash-derived randomized testing and outline a prototype verifier. The goal is not a new quantum attack, but reproducible, comparable, and independently auditable quantum-ECDLP arithmetic claims.
Digital communication increasingly underpins identity, financial transactions, and regulatory compliance. In many settings, possession of a DKIM-signed email serves as evidence of account control, transaction confirmation, or institutional affiliation. Yet demonstrating such properties typically requires revealing the full email or relying on centralized intermediaries, introducing privacy risks and additional trust assumptions. A framework called ZK Email addresses this limitation by applying zero-knowledge proofs (ZKPs) to email verification, enabling publicly verifiable proofs of authenticity while preserving message confidentiality. However, its existing implementations struggle to support complex, real-world messages due to the inefficiency of regular-expression verification over structured formats and rich alphabets. We address this limitation with a new ZKP system for regex matching based on path verification over epsilon-free NFAs, yielding prover complexity linear in the captured path and independent of the original email's size. This approach enables practical validation of expressive standard structures required for full DKIM-signed email verification. To fully integrate our constructions into ZK Email, we design complete end-to-end ZK circuits that combine (i) DKIM signature verification, (ii) an arbitrary-length SHA-256 circuit with partial precomputation for rsa-sha256 under RFC~6376, and (iii) a general-purpose regex primitive enforcing structural constraints over email headers and body. We formalize the associated zero-knowledge relations and analyze their security under realistic adversary models. We implement the system~(fully integrated with ZK Email and released under the MIT license) in Circom and Noir, targeting Groth16 and UltraHonk backends, and evaluate it in both client-side and zkVM (SP1) deployment settings. Experimental results on a comodity hardware demonstrate substantial efficiency improvements over prior DFA-based approaches, achieving 2-6x in proving time using UltraHonk backend, while supporting a significantly richer class of regex languages.
Blockchain technology has emerged as a foundational framework for secure, transparent, and decentralized data management. This paper presents a comprehensive examination of the underlying theory and methodology of blockchain systems. Fundamental concepts such as cryptographic hashing, distributed ledger structures, peer-to-peer networking, and consensus algorithms are reviewed to establish the theoretical basis of blockchain functionality. Methodological approaches, including protocol design, smart contract development, performance evaluation, and security analysis, are discussed to demonstrate how blockchain systems are built, validated, and optimized. The study also highlights methodological challenges related to scalability, interoperability, governance models, and system verification. By integrating theoretical principles with practical design methodologies, this work provides a holistic understanding of how blockchain systems operate and how they can be effectively engineered for diverse applications.
The transition from traditional paper-based voting to electronic systems has introduced significant efficiencies but has simultaneously created centralized vulnerabilities, including susceptibility to database manipulation and a lack of transparent audit trails. This research proposes a decentralized, blockchain-based voting framework designed to restore public trust through cryptographic immutability and end-to-end verifiability. By utilizing a Permissioned Proof of Stake (PPoS) consensus mechanism, the system achieves the high transaction throughput necessary for national-scale elections while maintaining a decentralized security posture that prevents any single entity from compromising the results. The technical core of this framework integrates Zero-Knowledge Proofs (ZKPs) to resolve the tension between voter anonymity and auditability. This allows voters to prove their eligibility and the validity of their ballot without disclosing their identity or specific choice, thereby upholding the sanctity of the secret ballot. To address modern security threats, the study incorporates Post-Quantum Cryptography (PQC) to safeguard against future decryption capabilities and utilizes Layer 2 scaling solutions to ensure network resilience during peak voting periods. Methodological validation was conducted through a simulated electoral environment, testing the system against common attack vectors such as DDoS and 51% attacks. The results indicate that the decentralized model significantly reduces the risk of systemic fraud compared to centralized alternatives. This paper concludes that while socio-technical barriers to entry exist, the proposed blockchain architecture provides a scalable, secure, and transparent foundation for the future of digital democracy.
Zero-knowledge succinct non-interactive arguments of knowledge (zkSNARKs) are a key technology to privacy-preserving applications today. The complexity of proof generation, however, heavily constrains throughput in latency-sensitive environments. The computational burden primarily stems from two fundamental algorithms: Multi-Scalar Multiplication (MSM) and the Number Theoretic Transform (NTT). We propose a series of optimizations for these two kernels, including computation-transfer pipelining, load balancing, and memory access fusion, achieving 1.97 × to 2.16 × proof generation speedup over a state-of-the-art open source GPU acceleration library. Our design also supports out-of-core computation, enabling the generation of large-scale ZKP proofs.
As digital ecosystems expand, secure and interoperable identity management across organizational boundaries has become increasingly important. This paper presents a blockchain-based platform for decentralized identity and trust management to support cross-domain authentication and authorization among autonomous organizations, such as government agencies and academic institutions. The proposed platform employs a consortium blockchain as a tamper-resistant credential and policy repository, enabling each organization to administer its own credentials while supporting verifiable identity sharing across domains. On-ledger trust relationships and authorization policies allow trusted interactions without relying on centralized identity authorities or pre-established bilateral agreements. A prototype was implemented using Hyperledger Fabric and evaluated in a multi-domain setting. The results demonstrate correct authentication behavior, sub-second authentication latency, measurable transaction throughput, and effective revocation propagation. Additional experiments under multi-domain and concurrent authentication workloads show that the platform preserves consistent authentication outcomes while maintaining latency within practical bounds. The proposed approach can be applied to multi-institutional environments, such as inter-university digital services, cross-agency e-government systems, and collaborative research infrastructures, where secure identity sharing and cross-domain access control are required.
Distributed ledger technologies (DLTs) form critical infrastructure for decentralized applications, yet their security relies heavily on classical asymmetric cryptographic primitives that are vulnerable to quantum attacks. Post-quantum cryptography (PQC) provides candidate algorithms designed to resist such threats, but integrating these schemes into operational blockchain systems introduces significant architectural and performance trade-offs.
Sovereign is a Prove/Pull communication protocol designed to address the structural imbalance of modern digital communication, where senders can impose cognitive and computational costs on recipients without corresponding friction. The protocol requires messages to carry a cryptographic proof of intent through one of three mechanisms: adaptive Proof-of-Work, private zero-knowledge proximity credentials, or registry-attested clearance tokens. Verification is performed by a decentralized Sovereign Audit Network (SAN), which attests that messages satisfy recipient-defined acceptance policies before delivery. This document presents the complete architectural specification of Sovereign, including the MessageEnvelope format, federated attestation protocol, dual Sparse Merkle Tree issuer registry with revocation support, Groth16 zero-knowledge proximity credential circuit, identity hierarchy, security assumptions, economic model, limitations, and phased deployment strategy. This release is Version 1.0 of the design specification. It is an unimplemented protocol proposal; all performance figures are engineering targets based on primitive benchmarks and require validation through future reference implementation. The work is published to establish a public technical record, invite peer review, and support future research, collaboration, and implementation efforts.
Yoon-Nyoung Jung, Subin Jo, Seo-Hyun Yun, Hwajeong Seo
Electronic voting systems inherently encompass a structural tension among ballot secrecy, verifiability, and coercion resistance. Voters must be able to verify whether their votes have been included; however, if such verification information can serve as evidence presentable to a third party, it becomes a basis for post-election intimidation. Existing studies have focused primarily on performance evaluation or data separation, and have not comprehensively addressed the structural tension between verifiability and coercion resistance. This study defines this tension as the verification paradox and designs and implements an electronic voting prototype on a three-organization consortium based on Hyperledger Fabric 2.5, combining a 2-of-3 endorsement policy, nullifier-based anonymity, Exponential ElGamal homomorphic tallying, zero-knowledge proof (ZKP)-based ballot validity verification, panic-password-based deniable verification, and Private Data Collection (PDC)-based coerced vote separation. Quantitative evaluation results confirm a server latency overhead of +0.9% for ElGamal relative to the AES performance baseline, statistical indistinguishability between normal and panic responses (p>0.05), and a peak throughput of approximately 40.7 TPS (with an error rate of 0%) under 1000 concurrent voters. Through this prototype implementation and quantitative evaluation, we show the potential of permissioned blockchains to partially and practically mitigate the verification paradox. This study, however, does not provide a formal security proof, and it is subject to a trust assumption on PDC as well as to the experimental limitations of a single evaluation environment and a limited load range.
We introduce NTRU-VRF, the first verifiable random function (VRF) constructed directly from the NTRU lattice hardness assumption, and instantiated concretely using the NIST-standardized Falcon-512 (FN-DSA) signature scheme. A VRF is a pseudorandom function that produces a publicly verifiable proof of correctness for each output. All currently deployed VRFs (IETF RFC 9381, Algorand, Ethereum) rely on elliptic-curve assumptions broken by Shor's algorithm. Prior post-quantum VRF constructions either require only a few-time security guarantee (Esgin et al., ePrint 2020/1222), rely on symmetric primitives that lack a worst-case lattice hardness reduction (Buser et al., ePrint 2021/302), or are based on Module-LWE/Module-SIS rather than NTRU. No prior work constructs a many-time, lattice-based VRF from NTRU hardness with a formal security proof. Our construction exploits a fundamental and previously unformalized property of Falcon's deterministic signing mode: for any fixed public key and input, there exists exactly one valid short-norm signature. This unique-signature property is the key structural feature that transforms a lattice signature into a VRF. We prove three theorems: Uniqueness: For any input, the NTRU-VRF output is unique. This follows directly from the unique-short-coset-vector property of the NTRU lattice. Pseudorandomness: If the Short Integer Solution (SIS) problem on NTRU lattices is hard and the hash function is modelled as a random oracle, then the VRF output is computationally indistinguishable from a uniformly random value. Provability: The Falcon signature is an efficient, publicly verifiable proof, checkable by any party holding the public key. As a concrete application, we define PQ-Sortition, a post-quantum proof-of-stake leader-election protocol that replaces ECVRF-based sortition with our NTRU-VRF construction. We provide the entropy-chain design, stake-weighted win condition, adaptive liveness mechanism, equivocation slashing, and a formal security analysis of the resulting consensus protocol. Instantiated with Falcon-512, NTRU-VRF achieves a VRF output of 32 bytes, a proof size of <= 666 bytes, evaluation time of ~0.8 ms, and verification time of ~0.1 ms on standard hardware—significantly outperforming all existing post-quantum VRF constructions and making it the first many-time, compact, lattice-based VRF suitable for high-throughput blockchain consensus.