The advancement of Industrial Internet of Things (IIoT) has enabled cross-domain collaboration among enterprises, facilitating data exchange and coordinated operations for complex manufacturing tasks. As the primary security mechanism, cross-domain continuous authentication periodically verifies external devices to prevent unauthorized access and session hijacking, thereby mitigating system vulnerabilities. However, existing solutions face limitations: some rely on device-specific features incompatible with heterogeneous environments, while others neglect cross-domain scenarios, offering insufficient privacy protection and irreversible identity management. To address these gaps, we propose a cross-domain authentication framework leveraging zero-knowledge proofs and blockchain technology. Devices are assigned anonymous identities, with revocation managed via a distributed ledger. Initial authentication employs zero-knowledge proofs to generate valid tokens, while continuous authentication refreshes these tokens periodically. Security analysis confirms robustness against common threats, and performance evaluations demonstrate that periodic token renewal reduces computational and communication costs compared to repeated initial authentication processes.
Achieving fairness, verifiability, and abandon resistance poses challenges within e-voting protocols. This paper introduces a privacy-preserving self-tallying e-voting system leveraging blockchain technology. The system supports diverse e-voting models, including ‘Yes/No’, approval voting with multiple candidates, and score voting. By employing linearly homomorphic time-lock puzzles (LHTLPs) along with verifiable delay functions (VDFs) and zero-knowledge Succinct Non-interactive Argument of Knowledge schemes (zk-SNARKs), the proposed system ensures crucial security properties, including voter anonymity and eligibility, as well as ballot privacy and validity. It also provides efficient individual and universal verifiability (end-to-end verifiability), and dispute-freeness. More importantly, the system demonstrates fairness and abandon resistance. Furthermore, the evaluation of the proof-of-concept implementation on the Ethereum blockchain indicates that on-chain gas costs are either fixed or increasing slowly and logarithmically with the number of voters.
This study proposes a decentralized framework that merges smart contract based Decentralized Finance (DeFi) protocols and traditional Enterprise Resource Planning (ERP) systems to provide secure, automatic, and verifiable transaction execution. It constructs an additional middleware interface to guarantee interoperability between ERP modules and blockchain networks that utilize smart contracts for procurement, finance, and asset management modules. The system was tested empirically within a hybrid testbed of chains with Ethereum Virtual Machine (EVM) compatibility simulation executing ERP transaction testing on a simulated environment with physical hardware. According to quantitative assessment results, performance increased, achieving a 38% increase in transaction throughput, a 27% decrease in execution costs, increased trust and traceability due to cryptographic audit trails, and improved auditability. The research highlights the potential of DeFi integrated ERP systems for decentralized enterprise finance systems as a scalable secure replacement to centralized enterprise finance systems.
Concerns about security, trust, authentication, fraud, and risk of loss are often cited as among the most significant barriers to the growth of online transactional platforms. A particularly important factor feeding the uncertainty is that traditional authentication mechanisms based on the physical inspection are not feasible online. Both buyers and sellers on online platforms face high levels of uncertainty.This paper attempts to use NFTs to create a digital warranty system using bloackchain smart contracts. Smart contracts are automated transaction protocols that carry out a contract’s terms. The goals are to lessen the necessity for trustworthy intermediaries, the expense of arbitrations and enforcement proceedings, fraud losses, and the occurrence of malicious and unintentional exceptions. Digital warranties give customers authentication and ownership of products when purchasing assets online. It provides the purchasing history, warranty period, and other item information. The warranty card includes the item’s serial number and is sent to the customer’s smartphone. The aims to solve authentication and transactional issues from customers, sellers, and marketplace perspectives. The objective is to create a trustable, secure and error proof e-commerce system. The proposed solution tries to utilise the feature sets of Non Fungible Tokens (NFTs) to provide a more trustable and secure transactional system.
Smartphone apps frequently use smart contracts which are based on blockchain sharded databases. The rapidly increasing cyber-attack rate is threatening the safety and security of smartphone users. In addition, Sybil attacks are commonly used in these cyber-attacks, which cause serious problems in smartphone authentication. To solve these problems, this paper proposes a Certificate based Trust Blockchain for Sharded Databases (CTBSD) scheme, which was designed to prevent Sybil nodes from having a dominant influence on blockchain systems through a trust-based shard clustering mechanism. The CTBSD scheme works with the Diameter authentication protocol, which is used in mobile smartphone networks. The authentication procedures of the Diameter digital certificates (which are based on unique information of each node) are combined with the blockchain consensus process of each shard. In this scheme, the trust authority (TA) collects trust information after the practical Byzantine fault tolerant (PBFT) consensus process, where honest nodes are assigned rewards and suspected Sybil nodes are assigned penalties with commit results. The simulation results show that the proposed scheme improves the security and scalability performance compared to existing schemes.
Ye Liu, Yuqing Niu, Chengyan Ma, Ruidong Han · 8 authors
Smart contracts are highly susceptible to manipulation attacks due to the leakage of sensitive information. Addressing manipulation vulnerabilities is particularly challenging because they stem from inherent data confidentiality issues rather than straightforward implementation bugs. To tackle this by preventing sensitive information leakage, we present PartitionGPT, the first LLM-driven approach that combines static analysis with the in-context learning capabilities of large language models (LLMs) to partition smart contracts into privileged and normal codebases, guided by a few annotated sensitive data variables. We evaluated PartitionGPT on 18 annotated smart contracts containing 99 sensitive functions. The results demonstrate that PartitionGPT successfully generates compilable, and verified partitions for 78% of the sensitive functions while reducing approximately 30% code compared to function-level partitioning approach. Furthermore, we evaluated PartitionGPT on nine real-world manipulation attacks that lead to a total loss of 25 million dollars, PartitionGPT effectively prevents eight cases, highlighting its potential for broad applicability and the necessity for secure program partitioning during smart contract development to diminish manipulation vulnerabilities.
In view of the problems of false property rights and difficulties in identity authentication in intellectual property transactions, an identity authentication model for intellectual property transactions based on an alliance chain is proposed. Firstly, the two-factor identity authentication model's roles, functions, and processes are constructed. Secondly, the two-factor authentication mechanism of ID password combined with physiological and property rights features is proposed, the identity identification generation method of fingerprint biometrics and intellectual property features is established, and the constraint compression strategy based on Poseidon hash is designed to reduce the workload of zero-knowledge proof algorithm and realize the consistency of property rights identity. Finally, the security and performance analysis of the authentication model is carried out, and the comparison and validation of related models are carried out, which shows that the model has good security and reliability.
Open access
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
Ben Biedermann, Matthew Scerri, Victoria Kozlova, Joshua Ellul
Web3’s decentralised infrastructure has upended the standardised approach to digital identity established by protocols like OpenID Connect. Web2 and Web3 currently operate in silos, with Web2 leveraging selective disclosure JSON web tokens (SD-JWTs) and Web3 dApps being reliant on on-chain data and sometimes clinging to centralised system data. This fragmentation hinders user esxperience and the interconnectedness of the digital world. This article explores the integration of Web3 within the OpenID Connect framework, scrutinising established authentication protocols for their adaptability to decentralised identities. The research examines the interplay between OpenID Connect and decentralised identity concepts, the limitations of the existing protocols like OpenID Connect for verifiable credential issuance, OpenID Connect framework for verifiable presentations, and self-issued OpenID provider. As a result, a novel privacy-preserving digital identity bridge is proposed, which aims to answer the research question of whether authentication protocols should inherently support Web3 functionalities and the mechanisms for their integration. Through a Decentralised Autonomous Organisation (DAO) use case, the findings indicate that a privacy-centric bridge can mitigate the existing fragmentation by aggregating different identities to provide a better user experience. While the digital identity bridge demonstrates a possible approach to harmonise digital identity across platforms for their use in Web3, the bridging is unidirectional and limits root trust of credentials. The bridge’s dependence on centralised systems may further fuel the debate on (de)centralised identities.
Chuanni He, Min Liu, Simon M. Hsiang, Nicholas A. Pierce · 6 authors
The decision-making for bridge preservation constitutes two types of rules: explicit rules, which are based on clear specifications to establish an overall baseline preservation plan, and implicit rules, which are rooted in extensive experience and professional judgments to adjust the baseline plan and adapt to the local context. A research gap exists in establishing standards for implicit rules and ensuring efficiency, credibility, and transparency when applying them. Therefore, the research objectives of this study are to (1) develop an information container to structure, store, and describe bridge inspection data leveraging domain knowledge; (2) enhance querying tools for organizing complex reasoning of implicit rules; and (3) establish a decentralized system for data sharing and knowledge communication in implicit decision-making. This research proposes a framework that integrates domain ontology and smart contracts to enable transparent and standardized knowledge streaming. By following a bridge preservation ontology, this research develops a mapping tool that converts element inspection data into a graph data set. Subsequently, implicit decision rules are structured via the SPARQL protocol and applied to the graph data set. A decentralized rule management platform utilizing smart contract and distributed file storage is developed to establish a standard decision-making protocol. Finally, the framework was evaluated based on 13,994 real-world bridge inspection records collected from North Carolina, United States. Results demonstrate that the proposed framework efficiently deploys implicit rules to the target data set with a 94% reduction in execution time without a loss in accuracy. The decentralized platform enforces a new rule evaluation and approval norm. This paper contributes to the body of knowledge by developing an ontological framework that organizes complex reasoning of implicit preservation rules and establishing a decentralized system to enhance efficient collaboration for bridge preservation decision-making.
Decompiler is a specialized type of reverse engineering tool extensively employed in program analysis tasks, particularly in program comprehension and vulnerability detection. However, current Solidity smart contract decompilers face significant limitations in reconstructing the original source code. In particular, the bottleneck of SOTA decompilers lies in inaccurate function identification, incorrect variable type recovery, and missing contract attributes. These deficiencies hinder downstream tasks and understanding of the program logic. To address these challenges, we propose SmartHalo, a new framework that enhances decompiler output by combining static analysis (SA) and large language models (LLM). SmartHalo leverages the complementary strengths of SA’s accuracy in control and data flow analysis and LLM’s capability in semantic prediction. More specifically, SmartHalo constructs a new data structure - Dependency Graph (DG), to extract semantic dependencies via static analysis. Then, it takes DG to create prompts for LLM optimization. Finally, the correctness of LLM outputs is validated through symbolic execution and formal verification. Evaluation on a dataset consisting of 465 randomly selected smart contract functions shows that SmartHalo significantly improves the quality of the decompiled code, compared to SOTA decompilers (e.g., Gigahorse). Notably, integrating GPT-4o mini with SmartHalo further enhances its performance, achieving a precision of 91.32% and a recall of 87.38% for function boundaries, a precision of 90.40% and a recall of 88.82% for variable types, and a precision of 80.66% and a recall of 91.78% for contract attributes.
The cross-chain identity authentication method based on relay chains provides a promising solution to the issues brought by the centralized notary mechanism. Nonetheless, it continues to encounter numerous challenges regarding data privacy, security, and issues of heterogeneity. For example, there is a concern regarding the protection of identity information during the cross-chain authentication process, and the incompatibility of cryptographic components across different blockchains during cross-chain transactions. We design and propose a cross-chain identity privacy protection method based on relay chains to address these issues. In this method, the decentralized nature of relay chains ensures that the cross-chain authentication process is not subject to subjective manipulation, guaranteeing the authenticity and reliability of the data. Regarding the compatibility issue, we unify the user keys according to the identity manager organization, storing them on the relay chain and eliminating the need for users to configure identical key systems. Additionally, to comply with General Data Protection Regulation (GDPR) principles, we store the user keys from the relay chain in distributed servers using the InterPlanetary File System (IPFS). To address privacy concerns, we enable pseudonym updates based on the user’s public key during cross-chain transactions. This method ensures full compatibility while protecting user privacy. Moreover, we introduce Zero-Knowledge Proof (ZKP) technology, ensuring that audit nodes cannot trace the user’s identity information with malicious intent. Our method offers compatibility while ensuring unlinkability and anonymity through thorough security analysis. More importantly, comparative analysis and experimental results show that our proposed method achieves lower computational cost, reduced storage cost, lower latency, and higher throughput. Therefore, our method demonstrates superior security and performance in cross-chain privacy protection.
Open access
Internet Traffic Analysis and Secure E-voting
Advanced Steganography and Watermarking Techniques
Asfia Aziz, Sunil Suman, Shahab Saquib Sohail, Dag Øivind Madsen
Blockchain offers a secure platform for data exchange across sectors like banking, supply chain, IoT, and healthcare. In medical services, challenges arise from inefficient referral processes, data sharing between facilities, and limited patient access to records. Issues like data abuse and security concerns in electronic health records (EHRs) exacerbate these problems. This study explores blockchain-based smart contracts for managing pharmaceutical records, leveraging the practical Byzantine fault tolerance (PBFT) consensus method. The findings show healthcare practitioners can securely input patient data into the blockchain, while patients can contribute social data such as sleep patterns and activities. This enriched dataset supports improved diagnosis and prognosis. The study also evaluates execution time and data transmission for ledger updates as the network expands with more hospitals and blocks, demonstrating the scalability of blockchain-based healthcare solutions.
Good news for researchers in formal verification: smart contracts regularly suffer exploits such as the DAO bug, which lost the equivalent of 60 million USD on Ethereum. This makes a strong case for applying formal methods to guarantee essential properties.<br/><br/>Which properties would we like to prove? Most previous studies focus on contract-specific properties that do not generalize to a wide class of smart contracts. There is currently no commonly agreed upon list of properties to use as a starting point in writing a formal specification.<br/><br/>We propose three properties that we believe are relevant to all smart contracts: Validity, Liquidity, and Fidelity. Focusing on the concrete case of the Cardano platform, we show how these properties stop exploits similar to the DAO bug, as well as preventing other common issues such as the locking of funds and double satisfaction.<br/><br/>We model an account simulation, a multi-signature wallet, and an order book decentralized exchange, as example smart contract specifications using state transition systems in the Agda proof assistant. We formalize the above properties and prove they hold for the models. The models are then separately proven to be functionally equivalent to a validator implementation in Agda, which is translated to Haskell using agda2hs. The Haskell code can then be compiled and put on the Cardano blockchain directly. We use the Cardano Node Emulator to run property-based tests and confirm that our validator works correctly.
Modern financial technologies (Financial Technologies, FinTech) have improved traditional finance, while concurrently building a fundamentally new financial alternative. The application of FinTech has created digital financial products that are legally regulated but many crypto products still remain outside the law. The cryptocurrency market is a digital decentralized system that operates according to its own rules that users voluntarily accept, using personalized digital transactions. The application of FinTech in banking is a legal activity of banks aimed at strengthening competitive advantages in providing financial services, whereas central banks may require from commercial banks to upgrade or improve part of their digital technologies. In contrast, Blockchain technology has created a digital financial alternative which allows individuals to directly manage their digital wallets via phones and computers, without centralized control and outside of banking systems, by using the Internet and sharing original digital records among networked users worldwide. In the initial period, Blockchain technology generated resistance and was ignored by state regulatory bodies. The process of legal regulation of digital products and markets which were created on the basis of Blockchain and other digital technologies began after several years of actual Blockchain technology application. The subject matter of analysis in this paper is the legal regulation of already developed and widely used digital markets and assets, with specific reference to the legal solutions in the USA, the EU, and Serbia. The challenges of legal regulation of digital assets are numerous, ranging from insufficient knowledge of digital technologies to the unfeasibility of norming the decentralized digital segments. Thus, it is essential for the creators of law and the persons who apply the law to have the basic knowledge of modern digital technologies.
Zaki Rangwala, Stefan Neskovic, Amirhossein Kompanizare
This study examines how well SSL/TLS and blockchain work to secure online transactions, especially purchase orders. Reviewing literature from 2013 to 2024 shows each method's key themes, benefits, and weaknesses. SSL/TLS is known for its strong encryption and solid framework but often has issues like centralization and threats from different attacks, leading to transaction delays and bottlenecks. On the other hand, blockchain technology uses decentralized protocols and features such as zero-knowledge proofs, promising better scalability and security, allowing for smooth and safe transactions without traditional middlemen. This comparison clarifies how effective each method is. It highlights the rise of blockchain as a viable option to the limits of SSL/TLS, deserving more study in e-commerce security.
Domain-specific languages (DSLs) express requirements or designs through visual abstractions.To support complex development tasks such as code generation, testing and analysis, DSLs need semantic foundations.This paper introduces such a semantic framework for DSLs based on graph rewriting.We apply our framework to a DSL for defining multi-party dynamic role-based access control policies for smart contracts.Role-based access control models (RBACMs) express constraints on who can access which resources.Dynamic RBACMs allow a dynamic role membership.Access control policies, in particular for smart contracts, can involve multiple parties such as members of different groups or organisations, combining complex logical and dynamic constraints, and hence are hard to design, understand, validate and test at code level.Our diagrammatic notation supports complex authorisation patterns, including alternatives and multiplicities, to address nuanced access control requirements.Defining the operational semantics for RBACMs by graph rewriting, we let the Groove model checker produce traces for actions where access is granted or denied and generate tests for smart contracts in the Digital Asset Modelling Language (DAML).We validate dynamic access control scenarios generated by ChatGPT for use as test cases or advising users at runtime.Such scenarios represent business workflows interleaved with operations to add or remove role members.They are expressed as Groove control programs and are also verified by its model checker.
Non-Fungible Tokens (NFT) represent a sub form of cryptocurrencies, which allow investments into art, digital rights or any form of unique assets. Our study adds to a young body of research, which tries to analyze the characteristics of these new markets. In our study we present a new methodology to analyze peer-to-peer transactions in Non-Fungible tokens (NFT). We argument that this approach is superior to using prefabricated market data from NFT platform data, because it allows to track transactions to the point 0. Compared to that prefabricated market data could prove to be incomplete, missing peer-to-peer transactions. The difficulty of our approach was to develop a methodology which looks at all available transactions of a NFT on the blockchain, and not just at transactions which take place at specific trading platforms. This research is challenging due to the amount, and complexity of blockchain data which need to be stored and analyzed. For our study we constructed a dataset for the eth blockchain, which represented a complete chain of blockchain transactions, while then comparing our data with platform data on specific NFT’s. We found that our approach provides a more detailed view of the transactions in specific NFT’s. This detailed view allowed us to see specific transaction details. Our approach shall inspire future research to favor complete datasets of NFT transactions, before easily available data from trading platforms.
Die zunehmende Verbreitung verteilter Datenspeicher wie dem InterPlanetary File System erfordert robuste Sicherheitsmechanismen, um den Schutz sensibler Daten in dezentralen Umgebungen zu gewährleisten. Diese Masterarbeit präsentiert ein auf Smart Contracts basierendes Authentifizierungs- und Zugangskontrollsystem, das den Ethereum Attestation Service nutzt, um Rollen und Berechtigungen als nicht übertragbare Attestierungen zu verwalten. Durch die Integration von IPFS und clientseitiger Verschlüsselung wird ein hybrides Modell entwickelt, das öffentliche Datenspeicher durch granular definierte Zugriffskontrollbedingungen absichert. Die Arbeit evaluiert das System in einem praxisnahen Anwendungsfall einer Decentralized Autonomous Organization und demonstriert die Skalierbarkeit durch die Nutzung von Layer-2-Blockchains wie Scroll. Die Analyse der Kosteneffizienz von Smart Contract-Interaktionen zeigt, dass das Framework eine dezentrale, interoperable Verwaltung von Zugriffsrechten ermöglicht und dabei Transaktionskosten durch die Nutzung von Layer-2-Netzwerken signifikant reduziert. Zudem wird die Machbarkeit einer rollenbasierten Zugriffskontrolle ohne zentrale Instanz nachgewiesen, die gleichzeitig die Integrität und Verfügbarkeit der Daten gewährleistet. Die Arbeit leistet einen Beitrag zur Erforschung blockchainbasierter Sicherheitslösungen und bietet eine Blaupause für Organisationen, die dezentrale Speicherlösungen in offenen Ökosystemen einsetzen. Zukünftige Arbeiten könnten die Integration weiterer dezentraler Identitätsmodelle oder die Erweiterung um attributbasierte Zugriffskontrollmechanismen untersuchen, um die Privatsphäre und Flexibilität des Systems weiter zu optimieren.
The rapid expansion of the digital economy heightens the need for privacy and trust in intellectual property transactions. Traditional centralised approaches to identifying legal conflicts in intellectual property contracts are prone to data leakage and fail to balance transparency with confidentiality. This paper proposes a self-identification method for legal conflicts in intellectual property contracts using zero-knowledge proofs. By combining a light gradient boosting machine learning model with the zero-knowledge succinct non-interactive argument of knowledge protocol, our approach allows verifiable detection of potential legal conflicts without revealing sensitive information. Experiments on the US patent and trademark office patent dataset demonstrate that the method achieves high performance in conflict prediction (area under the receiver operating characteristic curve = 0.872) and verification efficiency (<10 ms), providing a novel and practical framework for privacy-aware legal technology.