Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

9,005 papersLast indexed Aug 31, 2026
Search papers

Paper index

9,005 results · page 47 of 376

Clear filters
Oct 14, 2025·2025 7th International Conference on Blockchain Computing and Applications (BCCA)
0 cites
ZeKSA: Zero-knowledge Secured Anonymous IoT Resource Sharing on Blockchain

Muhammad Yasir, Kübra Kalkan

IoT devices constitute an important component of Industry 4.0 paradigm, but are greatly hindered by their inherent resource constraints. Resource sharing is therefore an essential operating requirement for these devices but lack of privacy and heavy reliance on centralized architectures pose a serious risk for stable functioning. Use of decentralized and high availability platforms like distributed ledgers can provide divergent and distributed networking conditions but leaves any inter-device interactions completely exposed to third party view. To resolve this, we utilize an innovative combination of smart contracts alongside a zero-knowledge proof generator, known as Tornado Cash, to align IoT devices on a distributed resource exchange platform with privacy guarantees. In concert with public-key cryptography, our solution provides a framework for resource constrained IoT machines to interact through the blockchain for resource exchange purposes with strong privacy guarantees for both devices. Absolute anonymity is ensured by the protocol’s inherent architecture, meaning that participant devices do not reveal any sensitive information and consequently it becomes nontrivial to breach the privacy of either participant. Performance evaluations performed by testing ZeKSA against a competing & comparatively vulnerable protocol yield promising outcomes in terms of blockchain metrics like gas usage & incurred transaction costs.

Blockchain Technology Applications and Security
Cryptography and Data Security
IoT and Edge/Fog Computing
Original source
Oct 14, 2025·2025 7th International Conference on Blockchain Computing and Applications (BCCA)
1 cites
A Federated Machine Learning Method for Malicious Smart Contract Detection

Giovanni Ciaramella, Fabio Martinelli, Francesco Mercaldo, Paolo Mori · 5 authors

Blockchain adoption has significantly expanded in recent years, with the emergence of smart contracts facilitating practical applications in many domains. Since smart contracts can execute cryptocurrency transfers, malicious users have started implementing fraudulent smart contracts to deceive blockchain users and steal their funds. To mitigate this issue, this paper proposes an approach to detect fraudulent smart contracts leveraging Federated Machine Learning. Our approach generates an image representation for each smart contract by extracting the opcodes and assigning a unique RGB pixel. We utilized two publicly available datasets, including malicious and trustworthy smart contracts, to train multiple models on non-independent and Identically Distributed data to better represent a real-world scenario, achieving interesting results in accuracy. To the best of our knowledge, this article represents the first approach in the unique identification of fraudulent smart contracts using opcodes with a specific color, also leveraging a Federated Machine Learning approach in the blockchain environment.

Blockchain Technology Applications and Security
Imbalanced Data Classification Techniques
Cryptography and Data Security
Original source
Oct 14, 2025·2025 7th International Conference on Blockchain Computing and Applications (BCCA)
0 cites
Using Graph Cycle Detection to Reveal Suspicious Ethereum Token Transfer Behaviour

Andrew Le Gear, Farshad Ghassemi Toosi, Ashish Rajendra Sai, Tawny Whatmore · 5 authors

In the unregulated world of Initial Coin Offerings (ICOs), hiding malicious trading is all too easy in a large-scale set of transactions. This paper uses a graph-based representation of the blockchain to identify a topology that reveals suspicious intent to manipulate the perceived value of those offerings. As the computational complexity of identifying this topology could be prohibitive for unfiltered data-sets, this work derives metrics indicative of the topology. Using these explicitly-defined metrics and a past degradation of service on the Ethereum network originating with the iFishYunYu token, we show how this approach can reveal it to have been a deliberate attack, rather than simply an unprecedentedly highly-traded token. The formalization of this approach in the paper will allow detection of other such “pump-and-dump” attacks in the future.

Blockchain Technology Applications and Security
Cryptography and Data Security
Internet Traffic Analysis and Secure E-voting
Original source
Oct 14, 2025·2025 7th International Conference on Blockchain Computing and Applications (BCCA)
0 cites
PPDS: A Practical and Privacy-Preserving Data Sharing Model for Blockchain-Based IoT e-Health Systems Using ECC, Zero-Knowledge Proof, and Access Control

Yuxiao Wu, Kenta Kawai, Yutaka Matsubara

The generation and exchange of diverse e-health records, such as Personal Health Records (PHRs) and Electronic Medical Records (EMRs), have become increasingly critical in supporting comprehensive clinical decision-making across healthcare institutions. While significant progress has been made in securely and efficiently sharing these records, current solutions often struggle to handle multiple types of e-health data simultaneously. Moreover, a patient-centric approach, which balances ease of use for patients with the need to ensure their privacy, remains a critical challenge that requires further exploration. In this paper, we propose a decentralized, IoT-enabled e-health data-sharing model leveraging blockchain and cloud technologies, designed to support both PHRs and EMRs. Our model incorporates advanced security features, including zero-knowledge proof, elliptic-curve cryptography, and decentralized access control, to ensure a practical, secure, and privacy-preserving system. We simulate a real healthcare environment to demonstrate its practical feasibility, and performance evaluations show our system’s superior efficiency and enhanced security compared to existing solutions.

Blockchain Technology Applications and Security
Cryptography and Data Security
IoT and Edge/Fog Computing
Original source
Oct 14, 2025·2025 7th International Conference on Blockchain Computing and Applications (BCCA)
0 cites
SoK: The Role of Zero-Knowledge Proofs in Building Confidential and Trustworthy AI

Reza Nourmohammadi, Kaiwen Zhang

The verifiability of machine learning models and the privacy of training data have become critical concerns due to their widespread deployment in sensitive applications. Ensuring that a model performs as claimed, without revealing private data or algorithms, is a significant challenge. Zero-Knowledge Proof systems (ZKPs) have emerged as a promising cryptographic solution, enabling the verification of statements without disclosing underlying information. Their integration with blockchain technology further enhances trust and decentralization, offering robust solutions for secure and transparent AI systems. This paper explores the use of ZKPs in machine learning, focusing on privacy-preservation techniques, model verifiability, and confidential AI. It compares the differences and challenges of employing ZKPs in machine learning versus blockchains, highlighting their unique requirements and overlapping benefits. We review the basic concepts of ZKPs, advances such as zkSNARKs and zk-STARKs, and their applications in blockchainbased AI frameworks to ensure data integrity, immutability, and scalability. Furthermore, the paper delves into the practical implications of using ZKPs in AI, providing case studies and analyzing their scalability, performance, and limitations. We conclude by identifying key challenges and presenting future research directions to extend the applicability of ZKPs in AI, particularly in federated learning, model fairness, and decentralized AI pipelines.

Cryptography and Data Security
Adversarial Robustness in Machine Learning
Privacy-Preserving Technologies in Data
Original source
Oct 14, 2025·2025 7th International Conference on Blockchain Computing and Applications (BCCA)
1 cites
Performance Evaluation of Decentralized Digital Identity Contracts on Ethereum-Based Blockchain Networks

Jeffson C. Sousa, Bruno Evaristo, Antonio Mateus, Ismael Ávila · 6 authors

This paper presents a performance evaluation of smart contracts designed for managing decentralized digital identities on Ethereum-based blockchain networks. The analysis focuses on core identity lifecycle operations such as creation, update, credential schema definition, and revocation control, all implemented through Solidity smart contracts. Two execution contexts were considered: an environment using Hyperledger Besu operating in permissioned mode, and a reference to the traditional Hyperledger Indy model. The tests were conducted in a private network simulating different load levels and consensus configurations. The evaluated metrics include response time, throughput, resource usage, and scalability. The results provide insights to support the selection of efficient architectures for digital identity solutions based on Self-Sovereign Identity (SSI) and Ethereum, particularly in enterprise or regulated environments.

Blockchain Technology Applications and Security
Access Control and Trust
Cryptography and Data Security
Original source
Oct 13, 2025·International Journal For Multidisciplinary Research
0 cites
Privacy-Preserving Federated Learning: Challenges, Techniques, and Prospects for Distributed AI

Aditya Kumar, Mahip Chaurasia, Rishita Singh

The rapid growth of data-driven applications in healthcare, finance, IoT, and autonomous systems has created a pressing need for privacy-preserving and scalable machine learning methods. Traditional centralized learning, which aggregates data into a single repository, faces challenges related to data privacy, security, communication overhead, and regulatory compliance. Federated Learning (FL) offers a decentralized solution, enabling multiple clients to collaboratively train a global model without sharing raw data. Only model updates are exchanged, preserving privacy while leveraging distributed computational resources. This paper reviews FL architectures— including centralized, decentralized, horizontal, vertical, cross-device, and cross-silo—along with core components such as local clients, central servers, and communication protocols. Privacy- preserving techniques like differential privacy, secure aggregation, homomorphic encryption, and anonymization/pseudonymization are discussed to protect sensitive information. FL applications span healthcare, finance, IoT, smart devices, and autonomous systems, highlighting its transformative potential. Key challenges include data and system heterogeneity, efficient aggregation, personalization, robustness, and regulatory compliance. Future directions focus on enhanced privacy, communication efficiency, model personalization, and integration with edge and IoT environments. FL thus represents a promising paradigm for secure, collaborative, and distributed artificial intelligence.

Open access
Privacy-Preserving Technologies in Data
Cryptography and Data Security
Stochastic Gradient Optimization Techniques
Original source
Oct 13, 2025·arXiv
1 cites
Cross-Chain Sealed-Bid Auctions Using Confidential Compute Blockchains

Jonas Gebele, Timm Mutzel, Burak Oez, Florian Matthes

Sealed-bid auctions ensure fair competition and efficient allocation but are often deployed on centralized infrastructure, enabling opaque manipulation. Public blockchains eliminate central control, yet their inherent transparency conflicts with the confidentiality required for sealed bidding. Prior attempts struggle to reconcile privacy, verifiability, and scalability without relying on trusted intermediaries, multi-round protocols, or expensive cryptography. We present a sealed-bid auction protocol that executes sensitive bidding logic on a Trusted Execution Environment (TEE)-backed confidential compute blockchain while retaining settlement and enforcement on a public chain. Bidders commit funds to enclave-generated escrow addresses, ensuring confidentiality and binding commitments. After the deadline, any party can trigger resolution: the confidential blockchain determines the winner through verifiable off-chain computation and issues signed settlement transactions for execution on the public chain. Our design provides security, privacy, and scalability without trusted third parties or protocol modifications. We implement it on SUAVE with Ethereum settlement, evaluate its scalability and trust assumptions, and demonstrate deployment with minimal integration on existing infrastructure.

Open access
2 source records
cs.CR
Blockchain Technology Applications and Security
Cryptography and Data Security
Original source
Oct 11, 2025·Scientific Journal of Artificial Intelligence and Blockchain Technologies
0 cites
Blockchain in Electronic Voting Systems: Trust and Security Challenges

D. Aswini

Electronic voting (e-voting) has become an essential topic in the modernization of democratic systems, with promises of accessibility, faster counting, and reduced logistical challenges compared to traditional paper ballots. Yet, widespread adoption has been hindered by persistent trust and security concerns. Vulnerabilities such as malware, server compromise, insider threats, and limited verifiability have generated skepticism regarding the integrity of e-voting platforms. Blockchain technology has emerged as a disruptive innovation capable of reshaping this discourse. Its intrinsic properties—immutability, decentralization, transparency, and consensus-driven validation—directly address many of the fundamental challenges associated with securing digital elections. This manuscript provides a comprehensive exploration of blockchain-based electronic voting, with particular emphasis on the trust and security challenges that shape its practical deployment. Drawing on global case studies, theoretical models, and simulation insights, the research examines how blockchain can ensure tamper resistance, facilitate end-to-end verifiability, and empower voters through transparent audit trails. Key challenges such as scalability bottlenecks, voter anonymity risks, usability barriers, and regulatory gaps are analyzed in depth. The results indicate that hybrid blockchain architectures, which integrate advanced cryptographic techniques such as zero-knowledge proofs, homomorphic encryption, and sharding, hold promise for balancing the competing demands of scalability, privacy, and trust. Furthermore, blockchain must be supported by strong institutional frameworks, inclusive accessibility measures, and continuous technical audits to achieve legitimacy in electoral processes. By systematically mapping both the opportunities and limitations, this research contributes to the ongoing discourse on how technology can strengthen democratic resilience in the digital era. Ultimately, blockchain-enabled voting should be regarded not as a replacement but as an augmentation of existing systems, combining the strengths of distributed technologies with constitutional safeguards to advance secure, transparent, and inclusive electoral participation.

Open access
Internet Traffic Analysis and Secure E-voting
Cryptography and Data Security
Blockchain Technology Applications and Security
Original source
Oct 11, 2025·2025 IEEE 2nd International Conference on Green Industrial Electronics and Sustainable Technologies (GIEST)
0 cites
Blockchain-Based Self-Sovereign Identity for Digital Security

Namrata Mishra, P. K. Chidambaram, Hassan Mohamed Mahdi, Arumalla Spandana · 7 authors

SSI is a quickly appearing paradigm to secure and user-sovereign digital identity management. Nevertheless, existing implementations of SSI still have privacyprotection, interoperability, anti-fraud, and anti-cryptographic resiliency weaknesses. To tackle these issues, this paper presents a proposal of an AI-enhanced, blockchain-based protocol incorporating the use of Zero Knowledge Proofs (ZKP), Multiple Layer Decentralization (MLD) as well as quantumresistant cryptography. The framework uses AI to do dynamic Identity verification and real-time fraud detection, risk-based authentication and provides great advantage to traditional SSI models. The system proposed will utilize ZKPs to provide its users with privacy-preserving authentication so that one can confirm attributes but not reveal sensitive personal data. Multi-layer decentralized identity validation structure is developed to enhance the level of trust, reduce dependence on centralized authorities and enhances/supported interoperability across homogeneous systems. Ancillary, postquantum cryptographic schemes will also be incorporated to protect identities by mitigating the possible quantum computing attacks. Experimental evidence shows that our framework significantly enhances the accuracy of verification, the authentication latency and increases security in comparison to centralised and federated identity management solutions. The scheme is very flexible in financing sector, cross boundaries identity, e-governance portals and Web3 online portals. In the end, this study leads to an increment of a scaleable and privacy-sensitive digital identity system because it bridges existing security, usability and compliance gaps and opens pathways to robust and resilient SSI implementations into the future.

Cryptography and Data Security
Blockchain Technology Applications and Security
Cloud Data Security Solutions
Original source
Oct 10, 2025·2025 IEEE International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom)
3 cites
Assessing the Impact of Post-Quantum Digital Signature Algorithms on Blockchains

Alison Gonçalves Schemitt, Henrique Fan da Silva, Roben Castagna Lunardi, Diego Kreutz · 6 authors

The advent of quantum computing poses a threat to the security of traditional encryption algorithms. This has motivated the development of post-quantum cryptography (PQC). In 2024, the National Institute of Standards and Technology (NIST) standardized several PQC algorithms, marking an important milestone in the transition toward quantum-resistant security. Blockchain systems fundamentally rely on cryptographic primitives to guarantee data integrity and transaction authenticity. However, widely used algorithms such as ECDSA, employed in Bitcoin, Ethereum, and other networks, are vulnerable to quantum attacks. Although adopting PQC is essential for long-term security, its computational overhead in blockchain environments remains largely unexplored. In this work, we propose a methodology for benchmarking both PQC and traditional cryptographic algorithms in blockchain contexts. We measure signature generation and verification times across diverse computational environments and simulate their impact at scale. Our evaluation focuses on PQC digital signature schemes (ML-DSA, Dilithium, Falcon, Mayo, SLH-DSA, SPHINCS+, and Cross) across security levels 1 to 5, comparing them to ECDSA, the current standard in Bitcoin and Ethereum. Our results indicate that PQC algorithms introduce only minor performance overhead at security level 1, while in some scenarios they significantly outperform ECDSA at higher security levels. For instance, ML-DSA achieves a verification time of 0.14 ms on an ARM-based laptop at level 5, compared to 0.88 ms for ECDSA. We also provide an open-source implementation to ensure reproducibility and to encourage further research.

Open access
2 source records
cs.CR
cs.ET
cs.PF
Original source
Oct 10, 2025·2025 IEEE International Symposium on Parallel and Distributed Processing with Applications (ISPA)
0 cites
Poster: CoVer: Collaborative Verifiable Proof Generation for Efficient Zero-Knowledge Protocols

Jinwei Zhu, Shuangjie Bai, Xiaoming Hu

Zero-knowledge proofs (ZKPs) are increasingly adopted in practical cryptographic systems, yet zkSNARK generation remains computationally expensive, limiting scalability. Recent distributed zkSNARK frameworks, such as zkSaaS and Siniel, mitigate this cost by partitioning witnesses across multiple workers. However, they often depend on heavy MPC interactions and full verifier-side proof checking, which hinders their usability in asynchronous or large-scale settings. We present CoVer, a novel distributed zkSNARK system over binary fields, optimized for hardware-level parallelism. CoVer introduces a verifier-guided VOLE-based challenge mechanism that enforces global constraint consistency across subproofs while removing multi-round MPC and tag consistency checks. This design reduces communication and prevents challenge manipulation. Experiments show CoVer achieves up to$150 \times$verification efficiency improvement under variable bandwidth conditions.

Cryptography and Data Security
Cryptography and Residue Arithmetic
Cryptographic Implementations and Security
Original source
Oct 10, 2025·2025 IEEE International Symposium on Parallel and Distributed Processing with Applications (ISPA)
0 cites
DAVC: A Verifiable Credentials Model for Dynamic Attribute Management

Feng Wang, Shuo Yang, Min Zhang, Yang Liu · 6 authors

In decentralized ecosystems, Decentralized Identifiers (DID) and Verifiable Credentials (VC) enable self-sovereign identity, cross-domain interoperability, and privacy-preserving data exchange. However, current VC models face critical limitations, including static attribute binding, inefficient updates, high on-chain verification costs, and privacy leakage. To address these issues, this paper proposes a Dynamic Attribute-oriented Verifiable Credential (DAVC) model, designed to support flexible attribute lifecycle management. The model adopts a three-layer architecture that combines minimal on-chain anchoring, off-chain attribute decoupling, and hierarchical recursive verification to enable efficient and scalable identity verification. First, the onchain layer introduces Sparse Merkle Tree (SMT) root hashes to reduce the need for recording off-chain attribute statuses. Second, the off-chain layer achieves semantic isolation between attributes and identities through an Anonymous Attribute Identifier (AID) mechanism, while improving update efficiency via path caching and incremental strategies. Finally, a Hierarchical Recursive Zero-Knowledge Proof (HR-ZKP) mechanism, based on the Halo2 framework, achieves logarithmic complexity in multiattribute proof generation, supporting attribute-level minimal disclosure and structural anonymization. Experimental results demonstrate that DAVC maintains constant on-chain storage, significantly reduces gas consumption, keeps proof sizes within reasonable limits (e.g., 2.9KB for 10 attributes), and achieves proof generation delays within hundreds of milliseconds. Overall system performance exhibits logarithmic growth as the number of attributes increases. The DAVC model achieves a balance between strong privacy protection, high composability, and dynamic identity expression through minimal on-chain data usage and closed verification paths. This provides a valuable reference for composable identity authentication in Web3 scenarios.

Cryptography and Data Security
Cloud Data Security Solutions
Access Control and Trust
Original source
Oct 9, 2025·2025 2nd International Conference on Artificial Intelligence and Knowledge Discovery in Concurrent Engineering (ICECONF)
0 cites
Decentralized Identity Verification using Zero-Knowledge Proofs: A Privacy-Preserving Authentication Framework

Uday Kumar Maurya, Lokesh S, K.Vijaya Kumar

In the contemporary online interaction, digital iden- tity is central, but most systems follow a centralized provider like Google or Facebook. Although convenient, these models pose ma- jor risks to data breach, surveillance, and single point of failure. The proposed paper proposes a privacy-sensitive decentralized identity verification system that uses Zero-Knowledge Proofs (ZKPs) to allow users to make it through claims (e.g., age, citizen- ship, or enrollment) without any personal data being provided, thereby solving the challenges outlined in the paper. Our architecture integrates verifiable credentials, zero-knowledge-SNARKs and an issuer trust registry that is maintained on blockchain smart contracts to guarantee trustless verification and eliminate dependence on centralized authorities. Its system gives its users full control over credentials, allows reuse across applications, and does not expose data.A proof-of-concept implementation has shown the approach to be feasible with Circom and SnarkJS to generate proof, Solidity smart contracts to verify them, and a user interface implemented in React. Results of the evaluations showed that determination of the verification latency is low, the overhead to generate proofs is moderate, and no privacy leakage occurs. It can be used in potential applications such as education, e-governance, healthcare, finance, and online voting.

Blockchain Technology Applications and Security
Cryptography and Data Security
Access Control and Trust
Original source
Oct 9, 2025·Proceedings of the ACM on Programming Languages
0 cites
Tabby: A Synthesis-Aided Compiler for High-Performance Zero-Knowledge Proof Circuits

Junrui Liu, Jiaxin Song, Yanning Chen, Hanzhi Liu · 8 authors

Zero-knowledge proof (ZKP) applications require translating high-level programs into arithmetic circuits–a process that demands both correctness and efficiency. While recent DSLs improve usability, they often yield suboptimal circuits, and hand-optimized implementations remain difficult to construct and verify. We present Tabby, a synthesis-aided compiler that automates the generation of high-performance ZK circuits from highlevel code. Tabby introduces a domain-specific intermediate representation designed for symbolic reasoning and applies sketch-based program synthesis to derive optimized low-level implementations. By decomposing programs into reusable components and verifying semantic equivalence via SMT-based reasoning, Tabby ensures correctness while achieving substantial performance improvements. We evaluate Tabby on a suite of real-world ZKP applications and demonstrate significant reductions in proof generation time and circuit size against mainstream ZK compilers.

Open access
Cryptography and Data Security
Security and Verification in Computing
Cryptographic Implementations and Security
Original source
Oct 7, 2025·arXiv (Cornell University)
2 cites
Privacy-Preserving On-chain Permissioning for KYC-Compliant Decentralized Applications

Piper, Fabian, Karl H. Wolf, Jonathan Heiss

Decentralized applications (dApps) in Decentralized Finance (DeFi) face a fundamental tension between regulatory compliance requirements like Know Your Customer (KYC) and maintaining decentralization and privacy. Existing permissioned DeFi solutions often fail to adequately protect private attributes of dApp users and introduce implicit trust assumptions, undermining the blockchain's decentralization. Addressing these limitations, this paper presents a novel synthesis of Self-Sovereign Identity (SSI), Zero-Knowledge Proofs (ZKPs), and Attribute-Based Access Control to enable privacy-preserving on-chain permissioning based on decentralized policy decisions. We provide a comprehensive framework for permissioned dApps that aligns decentralized trust, privacy, and transparency, harmonizing blockchain principles with regulatory compliance. Our framework supports multiple proof types (equality, range, membership, and time-dependent) with efficient proof generation through a commit-and-prove scheme that moves credential authenticity verification outside the ZKP circuit. Experimental evaluation of our KYC-compliant DeFi implementation shows considerable performance improvement for different proof types compared to baseline approaches. We advance the state-of-the-art through a holistic approach, flexible proof mechanisms addressing diverse real-world requirements, and optimized proof generation enabling practical deployment.

Open access
3 source records
Blockchain Technology Applications and Security
Cryptography and Data Security
Access Control and Trust
Original source
Oct 6, 2025·IACR Communications in Cryptology
0 cites
Who Verifies the Verifiers?

Sabine Oechsner, Vítor Pereira, Peter Schöll

Computer-aided cryptography, with particular emphasis on formal verification, promises an interesting avenue to establish strong guarantees about cryptographic primitives. The appeal of formal verification is to replace the error-prone pen-and-paper proofs with a proof that was checked by a computer and, therefore, does not need to be checked by a human. In this paper, we ask the question of how reliable are these machine-checked proofs by analyzing a formally verified implementation of the Line-Point Zero-Knowledge (LPZK) protocol (Dittmer, Eldefrawy, Graham-Lengrand, Lu, Ostrovsky and Pereira, CCS 2023). The implementation was developed in EasyCrypt and compiled into OCaml code that was claimed to be high-assurance, i.e., that offers the formal guarantees of guarantees of completeness, soundness, and zero knowledge. We show that despite these formal claims, the EasyCrypt model was flawed, and the implementation (supposed to be high-assurance) had critical security vulnerabilities. Concretely, we demonstrate that: 1) the EasyCrypt soundness proof was incorrectly done, allowing an attack on the scheme that leads honest verifiers into accepting false statements; and 2) the EasyCrypt formalization inherited a deficient model of zero knowledge for a class of non-interactive zero knowledge protocols that also allows the verifier to recover the witness. In addition, we demonstrate 3) a gap in the proof of the perfect zero knowledge property of the LPZK variant of Dittmer, Ishai, Lu and Ostrovsky (CCS 2022) that the EasyCrypt proof is based, which, depending on the interpretation of the protocol and security claim, could allow a malicious verifier to learn the witness. Our findings highlight the importance of scrutinizing machine-checked proofs, including their models and assumptions. We offer lessons learned for both users and reviewers of tools like EasyCrypt, aimed at improving the transparency, rigor, and accessibility of machine-checked proofs. By sharing our methodology and challenges, we hope to foster a culture of deeper engagement with formal verification in the cryptographic community.

Open access
Cryptography and Data Security
Complexity and Algorithms in Graphs
Logic, Reasoning, and Knowledge
Original source
Oct 6, 2025·CISPA Helmholtz Center
0 cites
Traceable Ring Signatures Revisited: Extended Definitions, O(1) Tracing, and Efficient Log-Size Constructions

Xiangyu Liu

Traceable Ring Signatures (TRS) were introduced by Fujisaki and Suzuki~[PKC'07], where a trace algorithm can publicly check if two signatures with the same event label were generated by the same signer (linkability). In addition, if the two signatures correspond to different messages, then the signer's identity is revealed (traceability). Following [PKC'07], most subsequent works adopt the same definitions and consider three security properties, anonymity, linkability, and exculpability. [PKC'07] proved that the latter two properties together imply unforgeability, a fundamental requirement for all signature-like primitives. ~~~~In this work, we identify a gap in the aforementioned proof, which arises from the insufficient consideration of linkability and exculpability in [PKC'07]. To address this, we revisit the syntax and security notions of TRS, and close this gap by defining extended linkability and extended exculpability. Building on these, we design a new framework of TRS from PseudoRandom Functions (PRF) and Zero-Knowledge Proofs of Knowledge (ZKPoK) that supports tracing, provided that both two signatures are valid. This constitutes a substantial improvement over existing approaches---all of which require tracing with the size of the ring---and elevates TRS to a level of practicality and efficiency comparable to Linkable Ring Signatures (LRS), which have already achieved widespread deployment in practice. Finally, we instantiate our generic framework from the DDH assumption and leverage the Bulletproofs [S\&P'18] to construct a TRS scheme with log-size signatures. The proposed scheme achieves highly optimized signature sizes in practice and remains compatible with most existing DLog-based systems. On Curve25519, the signature size is bytes, which to our best knowledge is the shortest LRS scheme for a ring .

Open access
2 source records
Cryptography and Data Security
Advanced Authentication Protocols Security
Privacy-Preserving Technologies in Data
Original source
Oct 6, 2025·Discover Artificial Intelligence
1 cites
Enhancing blockchain-based audit data privacy via hybrid chaotic and RSA encryption: mechanism design and performance evaluation

Cheng Zhang

This paper focuses on the research of auditing data privacy protection mechanism under blockchain technology and constructs an efficient computational model. The model is based on the distributed ledger characteristic of blockchain, and ensures the data tampering and traceability by optimizing the consensus mechanism. In the proposed model, the consensus mechanism is optimized by utilizing the tamper proof properties of blockchain. By building a multi node collaborative framework that supports batch auditing, this model improves data synchronization efficiency. The focus of optimization is to reduce the consensus reaching time and thus improve the overall performance and scalability of the blockchain network. At the same time, smart contracts are utilized to realize automated data sharing and auditing processes to improve auditing efficiency. In terms of data encryption algorithm design, a chaotic system based on RSA algorithm encryption is designed by combining the randomness and complexity of chaos theory to further strengthen the security of data. The results show that the model in this paper can make the ciphertext image uncorrelated in all directions and improve the encryption strength of the image. The method of this paper can make the audit data information on the degree of privacy protection and the complexity of the ciphertext image increase up to about 50% and 45% than the comparison method; the encryption and decryption time of the data is reduced by about 20 s. In addition, the running time of the stages of this paper’s algorithm increases with the increase in the number of concurrent requests and this paper’s system can support concurrency of 500 users at the same time and make its throughput up to 583.49/s.

Open access
Blockchain Technology Applications and Security
Cryptography and Data Security
Cloud Data Security Solutions
Original source
Oct 6, 2025·IACR Communications in Cryptology
0 cites
Blind ECDSA from the ECDSA Assumption

Jules Maire, Alan Pulval-Dady

Blind signatures have become a cornerstone for privacy-sensitive applications such as digital cash, anonymous credentials, and electronic voting. The elliptic curve variant of the Digital Signature Algorithm (ECDSA) is widely adopted due to its efficiency in resource-constrained environments, such as mobile devices and blockchain systems. Building blind ECDSA is hence a natural goal. One presents the first such construction relying solely on the ECDSA assumption. Despite the inherent complexities in integrating blindness with ECDSA, we design a protocol that ensures both unforgeability and blindness without introducing new computational assumptions and ensuring concurrent security. It involves zero-knowledge proofs based on the MPC-in-the-head paradigm for complex statements combining relations on encrypted elliptic curve points, their coordinates, and discrete logarithms.

Open access
Cryptography and Data Security
Privacy-Preserving Technologies in Data
Internet Traffic Analysis and Secure E-voting
Original source
Oct 6, 2025·2025 IEEE 22nd International Conference on Mobile Ad-Hoc and Smart Systems (MASS)
0 cites
PAVE: Privacy-Preserving Aggregated Verification For Multi-Enterprises Blockchain

Xiaoxue Zhang, Sammy Tesfai, Minmei Wang, Haofan Cai

Multi-enterprise applications in fields like supply chain management, finance, and healthcare require complex collaboration and data exchange among organizations to ensure operational efficiency and build trust. Permissioned blockchains emerged as a promising solution, providing shared, immutable ledgers that enhance transparency, traceability, and trust among authorized parties. However, during asset trading between organizations, they must verify the legitimacy of asset transfers, including asset ownership and quantity, while protecting sensitive asset owner information. To achieve both verifiability and privacy, this paper introduces PAVE, Privacy-preserving Aggregated Verification system for Multi-Enterprises Blockchain, a framework that integrates zero-knowledge proofs to enable secure asset verification without breaking user privacy. To achieve proof efficiency, PAVE introduces a proof aggregation mechanism that consolidates multiple transaction verifications into a single proof, significantly reducing computational overhead for large-scale scenarios. Evaluation results show that, with the proof aggregation mechanism, PAVE achieves low verification latency and resource utilization, making it a scalable solution for privacy-preserving asset verification across multiple enterprises.

Blockchain Technology Applications and Security
Big Data and Digital Economy
Cryptography and Data Security
Original source
Oct 6, 2025·IACR Communications in Cryptology
4 cites
Leaky LWE: Learning with Errors with Semi-Adaptive Secret- and Error-Leakage

Russell W. F. Lai, Monisha Swarnakar, Ivy K. Y. Woo

The Learning with Errors (LWE) problem asks to distinguish noisy samples s^T A + e^T mod q from uniformly random values given the random matrix A. In this work, we show that a variant called Leaky LWE, where the distinguisher receives additionally noisy leakages (s^T, e^T) L + f^T of the LWE secret s and error e for low-norm matrix L chosen adaptively by the distinguisher after seeing A, is not easier than the standard LWE of the same dimensions up to polynomial losses in the noise level and the modulus. More generally, we show that the Leaky LWE problem is hard even if the public matrix A is structured and/or hinted and if the non-leaky parts of the secret and error do not follow Gaussian distributions, as long as the corresponding LWE problem without leakage is hard. Our reduction from LWE to Leaky LWE unifies and extends prior results on the Error-Leakage LWE problem [Döttling-Kolonelos-Lai-Lin-Malavolta-Rahimi, EUROCRYPT'23], where L only acts on the error e and the Hint-MLWE problem [Kim-Lee-Seo-Song, CRYPTO'23], where L is restricted to concatenations of random Gaussian scalar matrices not controlled by the distinguisher. Previously, the Hint-MLWE and Error-Leakage LWE assumptions were used as computational replacements of the statistical noise flooding technique in security proofs which led to improved parameters in lattice-based cryptographic constructions such as zero-knowledge proofs, threshold signatures and registration-based encryption. We provide lemmas which abstract out such computational arguments based on Leaky LWE.

Open access
Cryptography and Data Security
Privacy-Preserving Technologies in Data
Security in Wireless Sensor Networks
Original source