The rising importance of cryptocurrencies as financial assets pushed their applicability from an object of speculation closer to standard financial instruments such as loans. In this work, we initiate the study of secure protocols that enable fiat-denominated loans collateralized by cryptocurrencies such as Bitcoin. We provide limited-custodial protocols for such loans relying only on trusted arbitration and provide their game-theoretical analysis. We also highlight various interesting directions for future research.
Oct 29, 2025·2025 International Conference on Electrical, Electronics, and Computer Science with Advance Power Technologies - A Future Trends (ICE2CPT)
Over the years, managing patient consent for sharing health data has remained a significant challenge due to a lack of transparency about how the data is shared with other systems and the absence of a verifiable audit trail. This paper introduces a new hybrid design that uses an industry-standard Open Authorization (OAuth) 2.0 authorization framework for detailed access grants, complemented by a decentralized, on-chain consent ledger built on the ERC-6551 blockchain standard, enabling digital assets (using Non Fungible Tokens) to act as independent accounts. The primary concept behind this paper is the utilization of the ERC-6551 Token Bound Account (TBA) as a patient-controlled on-chain portfolio of consent grant tokens, which are represented as semi-fungible tokens. We have solved the problem of converting the static, database-bound permissions into a dynamic, patient-owned digital system supported by timely-expiring JWT tokens. With the utilization of the OAuth 2.0 flow, short-lived JSON Web Tokens (JWTs) act as pointers to the durable, immutable consent records on the Blockchain. With our dual-validation approach, resource servers can verify both the off-chain time-based short-lived tokens and the granted access, along with on-chain consent status, to determine whether the patient has revoked the token. This provides a robust, auditable, and patient-sovereign system for managing healthcare data access. Finally, we present the complete design and architecture, along with data flows and cryptographic operations, which we used to analyze the security and performance characteristics and evaluate the outcomes of this implementation.
The healthcare industry is increasingly dependent on digital technologies for the storage, access, and sharing of sensitive patient data. While this brings significant benefits in terms of efficiency and accessibility, it also raises critical concerns regarding privacy, security, and trust. This paper proposes a hybrid Quantum-Blockchain system for secure healthcare through a decentralized, tamper-proof method for managing Electronic Health Records (EHRs). We present the design and implementation of a decentralized application (DApp) that leverages Ethereum smart contracts and InterPlanetary File System (IPFS) to securely store and control access to patient records. The proposed system empowers patients with ownership and control over their medical data, while enabling authorized doctors to access records with explicit patient consent. The system shows a temporal performance efficiency for Ethereum-based DApp mining. However, the system remains approximately 19 times slower than traditional Proof-of-Stake protocols, indicating a trade-off between enhanced security and computational speed.
The rapid expansion of multi-cloud ecosystems has intensified the demand for privacy-preserving analytics across untrusted infrastructures. This paper proposes Federated Zero-Trust Analytics (FZTA), a framework that integrates federated learning, zero-trust security, and privacy-enhancing computation to enable secure data collaboration without centralized trust. The design combines continuous identity verification, decentralized policy enforcement, and hybrid cryptography based on homomorphic encryption and differential privacy. Evaluation across three commercial clouds demonstrates that FZTA achieves near baseline model accuracy (within 2% of centralized training) while maintaining (ε<1.2, δ=10−5) differential privacy guarantees and less than 20% computational overhead. The framework resists eavesdropping, replay, and model inversion attacks while meeting compliance standards such as GDPR and HIPAA. Results confirm that strong privacy and federated scalability can coexist under zero-trust conditions, establishing a foundation for secure cross-domain analytics in healthcare, finance, and IoT applications.
Internet of Things (IoT) is transforming traditional agriculture into a more efficient, sustainable, and data-driven industry. By connecting various devices and sensors across the farm, IoT enables real-time monitoring, control, and optimization of agricultural processes. However, there are many security issues to deal with. IoT devices in precision farming collect sensitive data such as soil moisture, nutrient levels, and livestock health information. Unauthorized access to farm data can result in data theft, manipulation, or misuse. This can compromise the integrity of farming operations and potentially harm the environment. In this paper, we explore the mathematical foundations and practical implementations of model aggregation in federated learning (FL), with a particular focus on integration with distributed ledger technologies (DLT). We present a comprehensive analysis of aggregation algorithms, their convergence properties, and security guarantees. Additionally, we survey existing tools and platforms that facilitate federated learning deployments and examine how blockchain technology can address key challenges in federated learning systems including trust, incentive mechanisms, and auditability. Our analysis demonstrates that the combination of federated learning with blockchain creates a robust, transparent, and decentralized machine learning systems suitable for privacy-sensitive applications across precision farming, healthcare etc.
Behnam Khayer, Siamak Mirzaei, Hooman Alavizadeh, Ahmad Salehi Shahraki
Blockchain technologies offer transformative potential in terms of addressing the security, trust, and identity management issues that exist in large-scale Internet of Things (IoT) deployments. This narrative review provides a comprehensive survey of various studies, focusing on decentralized identity management, trust mechanisms, smart contracts, privacy preservation, and real-world IoT applications. According to the literature, blockchain-based solutions provide robust authentication through mechanisms such as Physical Unclonable Functions (PUFs), enhance transparency via smart contract-enabled reputation systems, and significantly mitigate vulnerabilities, including single points of failure and Sybil attacks. Smart contracts enable secure interactions by automating resource allocation, access control, and verification. Cryptographic tools, including zero-knowledge proofs (ZKPs), proxy re-encryption, and Merkle trees, further improve data privacy and device integrity. Despite these advantages, challenges persist in areas such as scalability, regulatory and compliance issues, privacy and security concerns, resource constraints, and interoperability. By reviewing the current state-of-the-art literature, this review emphasizes the importance of establishing standardized protocols, performance benchmarks, and robust regulatory frameworks to achieve scalable and secure blockchain-integrated IoT solutions, and provides emerging trends and future research directions for the integration of blockchain technology into the IoT ecosystem.
Douglas L. L. Moura, Andre L. L. Aquino, Antonio A. F. Loureiro
The integration of multiple distributed ledgers in Intelligent Transportation Systems (ITS) introduces challenges for scalable and interoperable authentication. Traditional schemes, which rely heavily on Public Key Infrastructure (PKI), face limitations related to certificate management and key escrow. To address these issues, we propose a federated authentication system based on certificateless public key cryptography (CL-PKC) to enable seamless cross-domain and cross-chain authentication without relying on traditional certificates. The proposed approach is designed to operate at the edge, where authentication is performed close to the user to reduce latency and support mobility. Leveraging the CL-PKC scheme, each user independently generates and manages their own cryptographic keys. Simulation results show reduced credential generation time, lower network usage, and improved latency under heavy and cross-domain conditions.
Quantum computing threatens foundational cryptographic assumptions in today’s distributed ledgers, while application demands outgrow the throughput and latency ceilings of single-chain blockchains. Directed acyclic graph (DAG) ledgers unlock parallelism but raise new questions about ordering, security, and light-client viability. This position paper argues for a postquantum (PQ) DAG ledger that matches DAG concurrency with PQ-secure consensus and transactions, plus a privacy-preserving identity/reputation layer. We sketch the architecture, situate it against the literature, and enumerate some open challenges to be addressed for deployment at scale. A carefully engineered PQ DAG can provide credible security and performance in a quantum-enabled adversarial landscape.
Centralized control of vote counting and result declaration is vulnerable to attacks that compromise election integrity, fairness, and transparency. We present a Web3-based system to decentralize the processing of tally sheets generated at polling stations. Our analysis focuses on the electoral systems of Venezuela and Ecuador, both of which rely on a centralized tally sheet processing procedure. We evaluate the vulnerabilities of this approach and propose a solution based on permissioned blockchains and decentralized storage, using Ecuador’s system as a case study. Our solution ensures integrity, fairness, and transparency throughout the digitalization, transmission, processing, and publication of tally sheets and election results. We developed a basic prototype using Hyperledger Fabric and IPFS.
Maxim Jourenko, Mario Larangeira, Kanta Kurazumi, Keisuke Tanaka
Abstract Blockchain-based systems, in particular cryptocurrencies, face a serious limitation: scalability. This holds, especially, in terms of the number of transactions per second. Several alternatives are currently being pursued by both the research and practitioner communities. One venue for exploration is on protocols that do not constantly add transactions on the blockchain and therefore do not consume the blockchain’s resources. This is done using off-chain transactions, i.e. , protocols that minimize the interaction with the blockchain, also commonly known as Layer-2 approaches. This work relates several existing off-chain channel methods, also known as payment and state channels, channel network construction methods, and other components such as channel and network management protocols, e.g. , routing nodes. All these components are crucial to keep the usability of the channel and are often overlooked. In this work, we propose a taxonomy for all the components of Layer-2. We provide extensive coverage of the state-of-the-art protocols available outline their respective approaches, and discuss their advantages and disadvantages.
Privacy-preserving technologies have introduced a paradigm shift that allows for realizable secure computing in real-world systems. The significant barrier to the practical adoption of these primitives is the significant computational and communication overhead that is incurred when applied at scale. In this paper, we present an overview of our efforts to bridge the gap between this overhead and practicality for privacy-preserving learning systems using multi-party computation (MPC), zero-knowledge proofs (ZKPs), and fully homomorphic encryption (FHE). Through meticulous hardware/software/algorithm co-design, we show progress towards enabling LLM-scale applications in privacy-preserving settings. We show the efficacy of our solutions in several contexts, including DNN IP ownership, ethical LLM usage enforcement, and transformer inference.
Driven by the increasing demand for multi-party data computation, Private Set Intersection (PSI) has become a pivotal technique for secure data sharing and privacy preservation. Although several efficient two-party PSI protocols have been developed, multi-party scenarios continue to suffer from limited computational efficiency and inadequate security guarantees. To address this engineering challenge, this study aims to enhance the performance and security of multi-party PSI protocols. We introduce SM-MPSI, a multi-party PSI protocol built upon national cryptographic standards. This protocol integrates SM2 and SM3 cryptographic mechanisms, employs non-interactive zero-knowledge proofs for identity authentication, and leverages domestic secure cryptographic chips to accelerate core algorithms. Experimental comparisons with existing mainstream protocols demonstrate significant improvements in computational efficiency and system scalability, while preserving robust security guarantees. Furthermore, SM-MPSI achieves enhanced communication efficiency and reduced resource consumption in multi-party scenarios. This research offers technical contributions toward advancing China's efforts in independent innovation in privacy-preserving computing and cryptographic technologies, thereby laying a solid foundation for strengthening national cybersecurity capabilities.
In edge computing, fusing privacy-sensitive heterogeneous sensor data poses challenges in balancing utility, privacy, and efficiency. Existing approaches like zkFL and zkGPT fall short in end-to-end verifiable LLM-driven fusion for non-IID data. We propose a framework embedding ZKPs into adaptive LLM layers for secure multimodal fusion with provable privacy. Key contributions: (1) context-aware attention for LLM fusion; (2) custom zk-SNARK circuits for full verification; (3) dynamic edge optimizations reducing latency by $\mathbf{2 5} \boldsymbol{\%}$. Theoretical analyses provide -DP bounds and convergence guarantees. Experiments on UCI HAR and CIFAR extensions show 91.8% accuracy, MI-AUC of 0.52, and $\mathbf{4 5 ~ m s}$ latency on Jetson Nano, outperforming zkFL by 3.5% in accuracy and 25% in efficiency.
This paper reconstructs zero-knowledge extensions on Solana as an architecture theory. Drawing on the existing ecosystem and on the author's prior papers and implementations as reference material, we propose a two-axis model that normalizes zero-knowledge (ZK) use by purpose (scalability vs. privacy) and by placement (on-chain vs. off-chain). On this grid we define five layer-crossing invariants: origin authenticity, replay-safety, finality alignment, parameter binding, and private consumption, which serve as a common vocabulary for reasoning about correctness across modules and chains. The framework covers the Solana Foundation's three pillars (ZK Compression, Confidential Transfer, light clients/bridges) together with surrounding components (Light Protocol/Helius, Succinct SP1, RISC Zero, Wormhole, Tinydancer, Arcium). From the theory we derive two design abstractions - Proof-Carrying Message (PCM) and a Verifier Router Interface - and a cross-chain counterpart, Proof-Carrying Interchain Message (PCIM), indicating concrete avenues for extending the three pillars.
Zoey Ziyi Li, Hui Cui, Alven C. Y. Leung, Dennis Liu · 7 authors
The increasing incidents of data breaches and personal data misuse highlight the urgent need for robust identity management systems. Self-Sovereign Identity (SSI) emerges as the future solution for digital identity management, underpinned by anonymous credentials (AC) and the distributed ledger technology (DLT) for security measures. However, current SSI models only achieve partial decentralization and none of them can fully meet the complex security requirements of real-world applications. In this paper, we address these limitations by constructing a Decentralized Anonymous Credential (DAC) scheme inspired by large universe attribute-based cryptographic primitives. Building on this foundation, we design a distributed identity management system (DisIMS), a comprehensive SSI system built on blockchain, achieving attribute flexibility, anonymity, unlinkability, revocability and selective disclosure. Compared to earlier blockchain-based identity management systems, our DisIMS allows users to selectively link previous transactions to generate verifiable eligibility proofs for the current transaction without leaking their real identities. We also implement DisIMS on both permissioned (Hyperledger Fabric v2.5) and permissionless (Ethereum Sepolia testnet) blockchains. Experimental results show that batch verification outperforms single verification by reducing execution times by approximately 76% to 81% on Hyperledger Fabric and 50% to 71% on Ethereum, based on 200 tests with 10 to 50 credentials containing 50 attributes each, which demonstrates DisIMS practicality for real-world batch verification scenarios.
The Internet of Medical Things (IoMT) transforms healthcare by enabling real-time monitoring of patient vitals, such as heart rate and glucose levels, but faces significant challenges in securing sensitive data against cyber threats and ensuring reliability in resource-constrained wearable devices, like low-power biosensors with limited computational capacity. The rise of quantum computing, particularly Shor algorithm, threatens to break traditional cryptographic methods (e.g., RSA, ECC) within 5–10 years by efficiently solving their underlying mathematical problems, endangering patient data confidentiality. Post-quantum cryptography (PQC), such as lattice-based schemes, offers resilience but demands high computational resources, challenging IoMT scalability. Unlike other PQC IoMT frameworks, such as those using NTRU, which prioritize computational simplicity but lack advanced privacy mechanisms, Q-PRADAX pioneers a secure, adaptive data aggregation framework, integrating Ring-LWE-based PQC for quantum-resilient confidentiality, compact zk-SNARK proofs for tamper-proof verification of patient vitals, and adaptive clustering for enhanced network reliability and scalability. Evaluated using OMNeT + + 6.0.3 with INET 4.5, Q-PRADAX achieves 94.5% diagnostic accuracy on ECG datasets, 100% tampering detection, and 99.9% packet delivery across 1000 devices in its Baseline scenario, with a security latency of 12.2 ms/packet and energy consumption of 0.38 mJ/packet on ARM Cortex-M4 devices (200 mAh). Outperforming existing IoMT solutions in security and fault tolerance, Q-PRADAX establishes a global standard for a secure, patient-centric IoMT ecosystem, redefining reliable healthcare delivery.
Uzay Işın Alıcı, Adem Orsdemir, Muhammad Tahir, Alptekın Küpçü
Blockchain technology allows us to make trust-based transactions without third-party intermediaries. However, its rapidly developing nature brings serious security vulnerabilities. These vulnerabilities are a research priority because smart contracts (SC) maintained on the blockchain system cannot be modified or reversed after deployment. Our research indicates that Deep Learning (DL) and Machine Learning (ML) methodologies have recently become popular for detecting these vulnerabilities in SC. This systematic literature evaluation highlights its contributions compared to similar studies with the most common vulnerabilities.
Chong Chen, Jiachi Chen, Lingfeng Bao, David F. Lo · 10 authors
Smart contract vulnerabilities, particularly improper Access Control that allows unauthorized execution of restricted functions, have caused billions of dollars in losses. GitHub hosts numerous smart contract repositories containing source code, documentation, and configuration files-these serve as intermediate development artifacts that must be compiled and packaged before deployment. Third-party developers often reference, reuse, or fork code from these repositories during custom development. However, if the referenced code contains vulnerabilities, it can introduce significant security risks. Existing tools for detecting smart contract vulnerabilities are limited in their ability to handle complex repositories, as they typically require the target contract to be compilable to generate an abstract representation for further analysis. This paper presents TRACE, a tool designed to secure non-compilable smart contract repositories against access control vulnerabilities. TRACE employs LLMs to locate sensitive functions involving critical operations (e.g., transfer) within the contract and subsequently completes function snippets into a fully compilable contract. TRACE constructs a function call graph from the abstract syntax tree (AST) of the completed contract. It uses the control flow graph (CFG) of each function as node information. The nodes of the sensitive functions are then analyzed to detect Access Control vulnerabilities. Experimental results demonstrate that TRACE outperforms state-of-the-art tools on an open-sourced CVE dataset, detecting 14 out of 15 CVEs. In addition, it achieves 89.2% precision on 5,000 recent on-chain contracts, far exceeding the best existing tool at 76.9%. On 83 real-world repositories, TRACE achieves 87.0% precision, significantly surpassing DeepSeek-R1's 14.3%.