A sharing framework based on Zero-Knowledge Proof (ZKP) and Proxy Re-encryption (PRE) technologies offers a promising solution for sharing Student Electronic Academic Records (SEARs). As core credentials in the education sector, student records are characterized by strong identity binding, the need for long-term retention, frequent cross-institutional verification, and sensitive information. Compared with electronic health records and government archives, they face more complex security, privacy protection, and storage scalability challenges during sharing. These records not only contain sensitive data such as personal identity and academic performance but also serve as crucial evidence in key scenarios such as further education, employment, and professional title evaluation. Leakage or tampering could have irreversible impacts on a student’s career development. Furthermore, traditional blockchain technology faces storage capacity limitations when storing massive academic records, and existing general electronic record sharing solutions struggle to meet the high-frequency verification demands of educational authorities, universities, and employers for academic data. This study proposes a dedicated sharing framework for students’ electronic academic records, leveraging PRE technology and the distributed ledger characteristics of blockchain to ensure transparency and immutability during sharing. By integrating the InterPlanetary File System (IPFS) with Ethereum Smart Contract (SC), it addresses blockchain storage bottlenecks, enabling secure storage and efficient sharing of academic records. Relying on optimized ZKP technology, it supports verifying the authenticity and integrity of records without revealing sensitive content. Furthermore, the introduction of gate circuit merging, constant folding techniques, Field-Programmable Gate Array (FPGA) hardware acceleration, and the efficient Bulletproofs algorithm alleviates the high computational complexity of ZKP, significantly reducing proof generation time. The experimental results demonstrate that the framework, while ensuring strong privacy protection, can meet the cross-scenario sharing needs of student records and significantly improve sharing efficiency and security. Therefore, this method exhibits superior security and performance in privacy-preserving scenarios. This framework can be applied to scenarios such as cross-institutional academic certification, employer background checks, and long-term management of academic records by educational authorities, providing secure and efficient technical support for the sharing of electronic academic credentials in the digital education ecosystem.
Digital registries are essential for global commerce, intellectual property protection, and cultural preservation. However, they face challenges like centralization risks and evolving security threats. This chapter proposes a framework that utilizes Non-Fungible Token (NFT) technology to develop secure and transparent digital registry systems. Our decentralized architecture eliminates single points of failure while ensuring high performance. We incorporate smart contracts for automated operations, multi-chain compatibility for scalability, and zero-knowledge proofs for privacy. Experimental validation shows a system performance of 33.22 transactions per second with 26-millisecond latency, outperforming many existing solutions while maintaining cost-effectiveness at 126,276 gas units per registration. Comparative analysis with centralized systems (ISBN, DOI, and ISSN) and blockchain alternatives (ENS and IPFS) highlights significant advantages in security and interoperability. Additionally, our economic analysis suggests potential cost reductions of 60–80% compared to traditional registries, enhancing service quality and accessibility. This research contributes to the practical implementation of blockchain-based registry systems, helping organizations consider NFT adoption while addressing scalability and security needs.
The growing threat of cyber-attacks and the fast development of quantum computing have rendered conventional methods of cryptography to be inadequate in ensuring the security of data transmission. In order to resolve this issue, this paper will present a Hybrid Quantum-Safe Cryptographic Framework, a mixture of Post-Quantum Cryptography (PQC), Blockchain, and Zero-Knowledge Proofs (ZKP) to achieve secure, verifiable, and privacy-preserving data sharing. The system utilises quantum resistance based on lattice-based encryption, decentralized identity and tamper-proof storage based on blockchain, and authentication based on ZKP, which does not reveal sensitive user information. Moreover, a Tamil-based linguistic encryption layer that is integrated with AES-256-GCM is added to increase the cryptographic complexity and security of localization. The experimental analysis of the system run on a Windows-based platform proves that the system can encrypt a 1 MB file on average time of 1.9 seconds, at the same time being highly secure and scalable. The access control based on the ZKP had an accuracy of verification 99.2 and the AI-based anomaly detector had an accuracy of detection 96.8 and low rate of false-positive. These findings prove that the proposed framework provides an effective, quantum-resistant, and privacy-aware implementation that can be used in secure systems like e-governance, legal documentation, sensitive data sharing systems.
The widespread adoption of Learning Management Systems (LMSs) as mission-critical digital infrastructures in higher education has introduced significant security and trust challenges. While centralized LMS architectures provide operational efficiency, they remain structurally vulnerable to insider threats, silent database compromise, mutable audit logs, and credential forgery. Existing blockchain-based research in education has largely focused on certificate authentication and transcript portability, leaving internal LMS integrity and enterprise-grade threat mitigation insufficiently addressed. This paper proposes a blockchain-enabled audit extension architecture for LMS environments, designed to enhance assessment integrity, traceability, and institutional trust without replacing existing platforms. Building upon a formal threat model tailored to LMS infrastructures, we derive security requirements including immutability, non-repudiation, auditability, confidentiality, and trust separation. To satisfy these requirements, we introduce a permissioned distributed ledger layer based on Hyperledger Fabric, operating alongside the institutional Information System. The architecture employs event-based transaction modeling, identity-bound cryptographic signatures, distributed endorsement policies, and minimal on-chain storage through hash anchoring of sensitive data. A proof-of-concept implementation within a controlled institutional test network demonstrates the feasibility of recording grade submission and modification events as append-only ledger transactions. The prototype validates distributed validation, identity attribution via Certification Authority infrastructure, and tamper-evident audit logging using a Raftbased ordering service and CouchDB world state management. The results indicate that integrating a permissioned blockchain layer can significantly strengthen enterprise security posture by mitigating structural weaknesses inherent in centralized LMS systems. Although the current deployment remains limited in scale, the proposed model establishes a scalable foundation for secure, verifiable digital education infrastructures and future large-scale institutional integration.
The spectacular development of information technology (IT) led to massive data proliferation. Management systems such as big servers and cloud computing failed to satisfy current requirements engendered by this tricky challenge. The most remarkable shortcomings concern bottlenecks that are the principal causes of security attacks (Denial of Service attacks, confidentiality, integrity, and availability harms) and resource constraints (scarce storage space and computational efficiency). The emergence of decentralized systems (blockchain and decentralized storage) opens new perspectives in handling security and privacy, scalability, and storage shortcomings. The aim of this paper is to conduct a review on works built by the cooperation of the distributed ledger and decentralized storage. After, we define the main concepts, present works made in this field, and analyze recent papers investigated. The discussion demonstrates the relevance of the emerging technology blockchain-based decentralized storage networks in enhancing security and privacy aspects of stored data. In order to sharpen this creative approach, future directions are explored.
Thi Tam Pham, Phuc Hau Nguyen, Рафит Ренатович Набиев
The rapid growth of cloud computing has enabled flexible data storage and sharing; however, it also introduces significant challenges related to security, privacy, and access control. This paper proposes a blockchain-based secure data sharing framework to address the limitations of traditional cloud architectures. The proposed framework integrates distributed ledger technology with smart contracts to enable automated and transparent authentication and access control mechanisms. Data are stored off-chain, while metadata and access permissions are recorded on the blockchain to ensure integrity and traceability. Mathematical models are developed to evaluate the probability of valid access and the effectiveness of the access control mechanism. Analytical results demonstrate that the proposed approach significantly enhances security, mitigates single point of failure risks, and improves resistance against common attacks. Although the use of blockchain introduces additional latency due to consensus mechanisms, the system maintains high scalability. This study provides an effective and practical solution for secure data sharing in distributed cloud environments.
Traditional digital trust architectures suffer from the “Library Problem”: dependency on pre-compiled, static lookup tables or binaries that must be trusted blindly, creating supply-chain vulnerabilities. This paper proposes a paradigm shift to Intrinsic Trust, where encoding infrastructure is mathematically regenerated at runtime rather than distributed. We introduce the 0MXI Calculus, a deterministic lattice system anchored on universal transcendental constants:the golden ratio Φ ≈ 1.618033988749895 and π ≈ 3.141592653589793, with a contraction ratio λ ≈ 0.339949771344778. Operations on a quantized F15 lattice ensure cross-platform determinism, bounded by a Prime Boundary Horizon (N = 23) that guarantees injective reversibility (Theorems 1 and 2).This framework underpins TreeOS, an operating system that bootstraps from a “Math Root-of-Trust” via autogenesis, regenerating a bijective Tick Table for byte encoding without stored dependencies. TreeBABEL, the verifiable data transport protocol, packages data as JSON artifacts with mathematical manifests for independent receiver validation. Extending this, the VMEM Node Architecture transforms online repositories into externalized memory banks, enabling AI models to scrape and derive OS state on demand, eliminating internal weight bloat and static knowledge cutoffs.We demonstrate adaptability to constrained ledgers (e.g., 280-character limits) for efficient chunking. Through rigorous proofs and a Python reference implementation, we show that trust can be calculated, not stored, decoupling systems from physical hardware and fostering entropy-neutral, zero-trust computation.
Modern web applications permanently process large quantities of sensitive information such as personal records, financial information, confidential documents. Typical centralized architectures for web systems are highly susceptible to data breaches, unauthorized access and single-point failures. These limitations pose severe problems in preserving user privacy and data integrity in distributed environment . Block chain technology offers a decentralized and tamperproof framework for secure storage and controlled access of digital information without being based on a single trusted authority. By combining cryptographic hashing, distributed ledger mechanisms and permission-based access control, blockchain can do a lot to improve privacy preservation for web applications. This paper presents the idea of a blockchain enabled privacy preservation system for web applications that provides security of data storage, transparency of accessing verification, and against unauthorized modification.
The dynamic service conditions, the lack of centralised control in the distributed and federated services, and the growing sophistication of the malicious behaviours are the key challenges to trust management in the distributed and federated services. Standard trust models, based on fixed credentials, central authorities, or aggregation of reputation over the whole world, are no longer suitable to serve high-rate changing contexts in services, and have very high communication and coordination costs. In an effort to curb these issues, this paper puts forward a proposal of adaptive trust evaluation framework that has distributed verification in highly dynamic service-oriented architectures. The suggested model represents trust as a context-based, multi-dimensional digit that conservatively adapts to the context changes in service conduct, workload, and environmental state. To satisfy the decentralized nature of trust updates, a lightweight peer-based verification system is presented and does not need any centralized sources of trust but instead, trust updates are validated through decentralized means without depending upon a full blockchain consensus system. The framework constitutes adaptive weighting of trust, decay of trust and enforcement policies to reliably detect malicious or unreliable services in changing situations. Between the two widely used approaches, the widespread performance analysis of the suggested approach demonstrates that it has a better accuracy in trust, faster in detecting malicious service and with a much lower communication overhead than state of art centralised, reputation-based and ledger-driven approaches to trust. The findings affirm the viability, scalability, as well as viability of the suggested solution to secure trust execution in the next-generation distributed cloud and edge service surroundings.
Rajesh Bose, Shrabani Sutradhar, Arfat Ahmad Khan, Sandip Roy · 7 authors
ABSTRACT The promise of blockchain applications is transformative in terms of certificate verification and managing digital identities in the various fields, such as education, healthcare and land records. Nevertheless, current blockchain‐based certificate solutions have serious shortcomings: most are based on simple cryptography protection with no privacy‐preserving systems, have low throughput (16.67 TPS in typical Ethereum‐based systems), have unpredictable response times under varying loads, are not standardised across industries and are expensive to operate due to gas fees. Besides, the current implementations are mostly either theoretical or without performance tests in practice. This paper fills these gaps by suggesting a Plonk‐based system that incorporates zero‐knowledge proofs, digital signatures and trusted identity verification to improve the efficiency, security, and privacy of the verifiable credential digital identity verification and management systems (VC DIVMS). It was implemented at JIS University, India, with 50 transactions per minute (an improvement of 200% over Ethereum), an error rate of 244–1277ms in response times under load conditions (24‐33 faster than Ethereum) and high‐level privacy through ZKP. Contrary to currently used models that are sector‐specific, the offered Plonk framework offers a single, scalable, privacy‐focused model that can be applied in areas of education, healthcare, or credit verification. Intense testing ensured both resilience, scalability and compatibility with a demanding environment, making Plonk a strong and secure substitute to decentralised identity verification and credential management that is resistant to tampering.
Zhang Dayong, Nur Haliza Abdul Wahab, Juniardi Fadila, Arafat Al-Dhaqm · 8 authors
Practical Byzantine Fault Tolerance (PBFT) serves as a cornerstone consensus protocol for distributed systems. However, its inherent limitations, including quadratic communication complexity, scalability bottlenecks, and insufficient privacy protection, hinder its applicability in large-scale and privacy-sensitive environments. This study presents a systematic and comprehensive review of cryptographic advancements aimed at addressing these challenges. By analyzing peer-reviewed literature from 2015 to 2025, we demonstrate that the integration of Verifiable Random Function (VRF) and Boneh–Lynn–Shacham (BLS) aggregate signatures effectively reduces PBFT's communication complexity from O(N²) to O(N) or even O(logN), significantly enhancing scalability and reducing consensus latency. Moreover, advanced cryptographic schemes such as zero-knowledge proofs, homomorphic encryption, group signatures, ring signatures, hash ring, threshold signatures, attribute-based Encryption and lattice-based cryptography are shown to substantially strengthen consensus efficiency, privacy preservation and node security. Despite these improvements, trade-offs arise in terms of computational overhead and system complexity. The findings provide critical insights into the synergetic application of cryptography within PBFT-based systems and offer future directions for constructing scalable, secure, and privacy-preserving distributed architectures, particularly in Internet of Things and other resource-constrained scenarios.
Saha Reno, Koushik Roy, G M Abdullah Al Kafi, Khandakar Md Shafin
ABSTRACT The simultaneous achievement of scalability, security and decentralisation remains an open problem for distributed ledger technologies. This paper introduces InternxtChain, a novel framework leveraging Internxt's decentralised storage infrastructure with zero‐knowledge proofs (ZKPs) and sharded proof‐of‐storage (SPoS) consensus. Specifically, erasure‐coded sharding ensures data availability and fault tolerance by splitting files into encoded fragments distributed across nodes; BLS‐381 aggregated signatures enable efficient consensus by compressing multiple signatures into a single short proof; and zk‐SNARK audits provide tamper‐evident storage verification without revealing user data. InternxtChain addresses this challenge through three synergistic mechanisms: (i) erasure‐coded sharding with (6,3) Reed–Solomon encoding, (ii) zk‐SNARKs for storage auditability and (iii) an SPoS consensus based on BLS‐381 aggregated signatures. Experimental evaluation on a testbed of 2048 nodes across 16 geographic regions shows that InternxtChain processes 2800 transactions per second (TPS) with a median latency of 420 ms, while maintaining 99.9% data integrity under up to 30% Byzantine nodes. These results establish a practical path toward harmonising Web3 principles with real‐world throughput, cost and General Data Protection Regulation (GDPR) auditability requirements.
The growth of decentralized data ecosystems has increased the need for transparent and traceable contract agreements between organizations. Although the Eclipse Dataspace Components offer a flexible, open-source framework for sovereign data exchange, they present limitations in terms of end-to-end transparency and traceability of these agreements. This thesis explores how blockchain technologies, specifically smart contracts and tokenized assets, can enhance the Eclipse Dataspace Components to address these limitations. We introduce a model in which contract agreements are represented as non-fungible tokens. These tokens represent uniquely identifiable off-chain contracts whose state changes are immutably recorded on the blockchain. This allows for contract life-cycle monitoring and tamper-proof traceability across dataspace participants. The implementation includes a custom ERC-721 smart contract deployed on the Sepolia Testnet, as well as a decentralized application that connects its functionality to the Eclipse Dataspace Components. The evaluation is conducted using a Minimum Viable Dataspace hosted on two separate servers, representing one data provider and one data consumer. The evaluation demonstrates that agreements based on smart contracts significantly improve transparency and traceability while maintaining data sovereignty. Overall, the results show that blockchain-based contract agreements build trust without modifying the existing workflows of the Eclipse Dataspace Components. This provides a viable path toward the management of trustworthy and sovereign contracts in future dataspaces.
The rapid increase in fraudulent reproduction and misuse of digital certificates has become a critical concern for organizations and institutions worldwide. Fake or tampered certificates are often used to obtain employment in domains where individuals lack the required qualifications, thereby compromising organizational credibility and posing significant risks, particularly in sensitive sectors such as healthcare. With the proliferation of online learning platforms, certificates are issued digitally, making them vulnerable to unauthorized access, duplication, and identity forgery. To address these challenges, this paper proposes a secure and sustainable framework for proof of ownership of valuable educational assets using blockchain technology. Leveraging the capabilities of non-fungible tokens (NFTs), the proposed system ensures that each certificate is uniquely identifiable, tamper-proof, and verifiable. Unlike fungible digital assets, NFTs represent immutable and distinct records on the blockchain, enabling transparent and decentralized ownership verification. The proposed approach not only enhances trust and authenticity in educational credentials but also demonstrates applicability across multiple domains, including healthcare, supply chain, and digital asset management
cloud computing environments and multi agent systems has presented huge difficulties in creating a trust system, verifying securely and largely being transparent amongst the heterogeneous entities. The traditional centralized methods continue to become unsuitable with their vulnerability to the single point of failure, breach of data and unimpeccable auditability. The decentralized and immutable nature of blockchain technology has become a promising solution, but the currently operational blockchain-based systems still present severe constraints which are associated with scalability, high computation cost, disturbing latency as well as absence of adaptive trust mechanism.The current paper suggests a set of new conceptual frameworks on the use of an efficient and secure blockchain-based trust and verification system adapted to the distributed environment. The model uses a hybrid design that combines on-chain and off-chain processing to make the performance efficient and do not compromise security. An active screening system of trust is presented to determine the trustworthiness of each of the participating nodes on the basis of transaction history, behavioral patterns as well as their success rate of validation. Also, it includes a featherweight hybrid consensus which is based on Proof of Stake (PoS) and Practical Byzantine Fault Tolerance (PBFT) to ensure that it uses less energy to execute and also enhance the speed of transactions verification.The framework also includes smart contracts to verify and control access and use of data array of cryptography methods to guarantee the integrity of data and authentication. The proposed model offers a practical and flexible solution to the current distributed system since it tackles major challenge related to the system, namely scalability, efficiency and security. The framework is applicable to various areas which have been showcased in the IoT networks, management of supply chains, data sharing in healthcare, and e-governance. Future research possibilities include incorporating the element of artificial intelligence in the adaptive trust and quantum-resistant cryptographic research.
The exponential growth of cloud computing has enabled large-scale data outsourcing but has simultaneously introduced critical challenges related to data confidentiality, integrity, and trust. Traditional cryptographic and blockchain-based cloud security solutions often suffer from high computational overhead, latency, and scalability limitations, which hinder their practical adoption. To address these issues, this study proposes a robust and lightweight blockchain-based security framework for secure cloud data storage. The framework integrates hybrid AES–ECC encryption, smart contract–driven access control, and a lightweight consensus mechanism combining Delegated Proof of Stake (DPoS) and Practical Byzantine Fault Tolerance (PBFT) to achieve efficient and tamper-resistant data management. The proposed system employs an on-chain/off-chain hybrid architecture that stores only essential metadata and cryptographic proofs on the blockchain while maintaining the actual data in distributed cloud storage. This design minimizes computational burden and blockchain bloat while ensuring end-to-end transparency and verifiability. A Merkle tree–based Proof of Storage (PoS) mechanism enables rapid integrity verification without requiring full data retrieval. Comprehensive experiments were conducted using a simulated multi-node cloud environment to evaluate encryption efficiency, transaction latency, throughput, storage overhead, and energy consumption. Results show that the proposed framework outperforms existing blockchain-based models, achieving a 37.7% reduction in encryption/decryption time, a 51.3% decrease in transaction latency, and a 54.5% improvement in energy efficiency. Additionally, the system attained a 99.3% security success rate under various attack scenarios, demonstrating its resilience against unauthorized access, replay, and tampering attempts. These findings confirm that the proposed approach provides a practical balance between security assurance and performance optimization.
Digital identity is critical, yet centralized providers create single points of failure—breaches have exposed billions of records—and quantum computing threatens the classical public-key cryptography (RSA/ECC) on which these systems rely. We present a system-level integration of blockchain, zero-knowledge proofs (ZKPs), and post-quantum cryptography (PQC) for privacy-preserving digital identity. A blockchain-based decentralized identifier (DID) system removes central databases; all signing and key-encapsulation operations use lattice-based PQC (CRYSTALS-Dilithium and Kyber); and selective disclosure is provided by Groth16 zk-SNARKs, with revocation via on-chain Merkle non-membership accumulators. We specify the full credential lifecycle—issuance, two-phase authentication, and revocation—with an explicit trust boundary separating the in-circuit Groth16 relation from the off-circuit issuer-signature check. We report a measured evaluation on a reference prototype: under liboqs 0.15.0, Dilithium-II signs/verifies in 0.19/0.06 ms and Kyber-512 encapsulates/decapsulates in 0.018/0.022 ms; a single-authentication Groth16 proof over the 21,715-constraint BN254 credential circuit takes <inline-formula> <tex-math notation="LaTeX">$\approx 981$ </tex-math></inline-formula> ms (snarkJS) and <inline-formula> <tex-math notation="LaTeX">$\approx 177$ </tex-math></inline-formula> ms (native rapidsnark) on byte-identical inputs, with <inline-formula> <tex-math notation="LaTeX">$\approx 40$ </tex-math></inline-formula> ms verification, a 723-byte proof, and <inline-formula> <tex-math notation="LaTeX">$\approx 243$ </tex-math></inline-formula>,000 gas for on-chain verification on a local EVM. A lifecycle harness with a passing revoked-credential negative test validates correctness. The signing and key-encapsulation layers are quantum-safe under current lattice assumptions; the Groth16 proof layer is classically secure only, and its post-quantum migration is identified as future work. End-to-end credential unforgeability is conditioned on an honest holder wallet performing the off-circuit signature check (Assumption 5). Every quantitative claim is labelled measured [M], simulated [S], assumption [A], or future work [F].
Mohammad Fairus Bin Zulkifli, Rabiah Abdul Kadir, mohamad nazir ahmad
Growing reliance on digital knowledge sharing across academic, corporate, and public sectors has raised serious concerns about data integrity, trust, and security. Blockchain consensus mecha-nisms offer a promising path forward through decentralized, transparent, and tamper-proof frameworks. This systematic review examines how these mechanisms enhance trust in knowledge sharing platforms, focusing on four directions: how these mechanisms are applied within knowledge sharing con-texts, the challenges they introduce for knowledge sharing de-ployment, and the advantages they provide to trust-based knowledge sharing ecosystems. Following PRISMA 2020 guide-lines, three databases Scopus, IEEE Xplore, and Web of Science were searched, and peer-reviewed studies published between 2020 and 2025 were selected for analysis. In terms of knowledge sharing applications, blockchain consensus mechanisms build trust through multiple co-occurring pathways, including distrib-uted verification, transparency, cryptographic security, immu-tability, incentive alignment, and smart contract automation. Algorithms such as Proof of Work, Proof of Stake, Delegated Proof of Stake, and Byzantine Fault Tolerance variants are widely adopted, each offering different trade-offs between secu-rity, efficiency, and scalability. In terms of challenges, scalabil-ity, energy consumption, and integration complexity with exist-ing systems remain the most significant barriers to adoption. In terms of advantages, blockchain consistently delivers stronger data security, greater transparency, and reduced dependence on centralized authorities across knowledge sharing contexts. This review concludes that blockchain consensus mechanisms offer layered and compounding trust benefits, yet technical and or-ganizational barriers continue to limit widespread deployment. Future research should focus on energy-efficient protocols, scalable architectures, and real-world effectiveness studies.
This study presents a novel framework for integrating algorithmic audit trails into cloud banking compliance systems through the application of zero-knowledge proofs (ZKPs), addressing the critical tension between regulatory transparency and data privacy. The increasing migration of banking operations to cloud infrastructures has intensified the need for robust audit mechanisms that can verify compliance with financial regulations—such as anti-money laundering (AML) and know-your-customer (KYC) mandates—without exposing sensitive client information or proprietary risk models. Traditional audit trails, which rely on logging and storing plaintext transactional data, introduce significant vulnerabilities, including data breaches, unauthorized access, and inconsistencies across distributed cloud environments. Conversely, pure cryptographic anonymization can render audits meaningless by obscuring the provenance and integrity of records. The proposed architecture leverages ZKPs to allow an auditor (a regulatory body or internal compliance officer) to verify that a set of transactions adheres to predefined compliance rules without ever accessing the underlying data. In this system, each financial transaction executed within a cloud banking platform generates a cryptographic commitment. This commitment, along with a zero-knowledge proof, attests that the transaction satisfies all applicable regulatory constraints—such as limits on transaction value, jurisdictional restrictions, or multi-factor authentication requirements—without revealing the specific account numbers, personal identifiers, or the exact transaction details. The proof is constructed using succinct non-interactive zero-knowledge arguments (zk SNARKs), which provide both scalability and computational efficiency suitable for high-frequency transaction environments. The framework is built upon a dual-layer architecture. The first layer, the compliance engine, resides within the cloud banking application and is responsible for executing transactions, generating the corresponding ZK proofs, and committing the hashed transaction data to an immutable, decentralized ledger—a permissioned blockchain. This ledger serves as the algorithmic audit trail, recording only the cryptographic commitments and the proofs. The second layer, the audit interface, is accessible to authorized auditors. When an audit is required, the auditor submits a verification request against a specific range of transactions. The system retrieves the relevant commitments and proofs from the blockchain and runs a verification algorithm. The output is a simple Boolean result: either all transactions in the requested range are compliant, or the proof fails, triggering a detailed exception process. Importantly, the auditor gains no knowledge of the underlying transaction data; they only learn whether the regulatory predicates have been met. To realize this framework, the study identifies and addresses three principal challenges: proof generation overhead, scalability within cloud environments, and the integration of dynamic regulatory rules. Proof generation, particularly for complex compliance rules, can be computationally intensive. The proposed solution employs a hybrid approach: pre-computed proof templates for standard compliance checks (e.g., transaction size limits) are cached and reused, while complex, multi-condition checks (e.g., suspicious activity reporting rules) generate proofs on-the-fly using optimized multi-party computation techniques. For scalability, the audit trail ledger utilizes a sharded blockchain architecture, where transaction records are partitioned across multiple parallel chains based on geographic region or transaction type, ensuring that proof verification can be performed concurrently without a single bottleneck. Dynamic regulatory rules are accommodated through a modular smart contract layer. When a regulation changes, the underlying compliance predicate is updated on the blockchain, and all subsequent proofs are generated against the new rule. Existing valid proofs remain immutable, providing a historical record of compliance at the time of each transaction