Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

9,005 papersLast indexed Aug 31, 2026
Search papers

Paper index

9,005 results · page 67 of 376

Clear filters
Jan 1, 2025·IEEE Access
3 cites
Security Analysis and Performance Evaluation of Certificateless Proxy Re-Encryption for Blockchain Applications

S Remya, Manu J. Pillai, Preethi Ann Jacob, Sruthi Suresh · 5 authors

Certificateless Proxy Re-Encryption (CL-PRE) eliminates certificate management and private key exposure risks for blockchain data sharing, but existing schemes have critical security vulnerabilities and performance limitations. This research work presents comprehensive security analysis and performance evaluation of CL-PRE schemes for blockchain applications. The primary contribution is discovering a critical public key replacement attack against Wang et al.’s CL-PRE scheme, where Type I adversaries completely compromise message confidentiality by substituting legitimate public keys with adversary-controlled keys, enabling ciphertext decryption without private keys and violating IND-CCA security. The systematic performance evaluation of pairing-free PRE schemes for blockchain environments is conducted through extensive benchmarking of three schemes implemented in Go. Results show self PRE achieves superior security but incurs 13.7% higher execution time than certificateless schemes. To address vulnerabilities, this work proposes a secure CL-PRE framework with enhanced validation mechanisms. The Ethereum implementation reduces on-chain storage by 40% while maintaining provable security. The framework achieves 14.1% better performance than existing secure schemes and reduces gas costs by 14.3%. These findings establish security benchmarks and practical guidelines for blockchain developers, emphasizing rigorous cryptographic analysis importance for decentralized access control advancement.

Open access
Cloud Data Security Solutions
Cryptography and Data Security
Original source
Jan 1, 2025·DROPS (Schloss Dagstuhl – Leibniz Center for Informatics)
1 cites
Trustless Bridges via Random Sampling Light Clients

Bhatt, Bhargav Nagaraja, Shirazi, Fatemeh, Stewart, Alistair

The increasing number of blockchain projects introduced annually has led to a pressing need for secure and efficient interoperability solutions. Currently, the lack of such solutions forces end-users to rely on centralized intermediaries, contradicting the core principle of decentralization and trust minimization in blockchain technology. We propose a decentralized and efficient interoperability solution (aka Bridge Protocol) that operates without additional trust assumptions, relying solely on the Byzantine Fault Tolerance (BFT) properties of the two chains being connected. In particular, relayers (actors that exchange messages between networks) are permissionless and decentralized, hence eliminating any single point of failure. We introduce Random Sampling, a novel technique for on-chain light clients to efficiently follow the history of PoS blockchains by reducing the signature verifications required. Here, the randomness is drawn on-chain, for example, using Ethereum’s RANDAO. We analyze the security of the bridge from a crypto- economic perspective and provide a framework to derive the security parameters. This includes handling subtle concurrency issues and randomness bias in strawman designs. While the protocol is applicable to various PoS chains, we demonstrate the protocol’s practical feasibility by showcasing an instantiated bridge between Polkadot and Ethereum (currently deployed), and discuss some practical security challenges. Furthermore, we evaluate the efficiency of our on-chain light client verifier (implemented as an Ethereum smart contract) against SNARK-based approaches, demonstrating significantly lower gas costs for signature verification - even for validator sets up to 10⁶.

Open access
Blockchain Technology Applications and Security
Cryptography and Data Security
Distributed systems and fault tolerance
Original source
Jan 1, 2025·Infoscience (Ecole Polytechnique Fédérale de Lausanne)
0 cites
Votegral: Towards Usable, End-to-End Verifiable, Coercion-Resistant Online Voting

Merino, Louis-Henri Manuel Jakob

Online voting promises greater convenience and accessibility, but moving from supervised polling places to unsupervised settings magnifies the risk of coercion and vote buying. A compelling strategy is to give voters fake credentials: credentials that look and behave like real voting credentials but whose ballots are silently excluded from the tally. Despite its conceptual appeal, practical realizations and usability evidence for fake credentials have remained limited. This dissertation presents Votegral, the first end-to-end verifiable, coercion-resistant online voting system with empirical evidence towards practical usability. Votegral has two components: TRIP and VLT. TRIP is a trust-limited, in-person registration scheme that issues voters a real credential and any number of fake credentials on paper, without trusted hardware. TRIP embeds an interactive zero-knowledge proof into the physical printing process so that real credentials carry sound proof transcripts while fake credentials carry identically formatted but unsound proof transcripts -- distinguishable only by the voter during issuance and not transferable thereafter. VLT is a tallying scheme that constrains ballots to registrar-issued credentials to enable linear-time filtering of fake ballots. VLT also introduces standing votes: a voter facing extreme coercion can, at registration, delegate their voting rights to a publicly registered political party and leave the booth with only fake credentials. Tallying then credits the party's ballot by the number of such delegations and publishes publicly auditable proofs, resulting in both transparency and coercion evidence -- evidence that an aggregate number of voters felt unsafe to leave the registrar with a real credential. Our prototype tallies 1 million ballots in about 14 hours on a 128 core, 256 GB RAM machine; this puts Votegral on par with modern end-to-end verifiable systems such as Swiss Post, while significantly outperforming prior JCJ-style systems such as Civitas. TRIP's end-to-end, voter-observable registration session completes in under 20 seconds on resource-constrained hardware. In our main user study with 150 demographically diverse participants recruited in Boston, Massachusetts, 83% successfully registered and cast a ballot in our mock election. Among the 120 participants exposed to fake credentials, 96% correctly understood the purpose of fake credentials. These promising results suggest a path for practical viability of coercion-resistant, end-to-end verifiable online voting using fake credentials.

Open access
Internet Traffic Analysis and Secure E-voting
Spam and Phishing Detection
Cryptography and Data Security
Original source
Jan 1, 2025·International Journal of AI BigData Computational and Management Studies
0 cites
Privacy-Preserving Smart and Secure Contract Solutions for Digital Supply Chain Payments

Ankush Gupta, Soumya Remella

Digital supply chain payments increasingly rely on automated and distributed platforms, yet existing solutions struggle to balance transparency with the confidentiality required by commercial and financial stakeholders. While blockchain-based smart contracts enable tamper-evident settlement and traceability, they often expose sensitive transaction metadata, contractual terms, and risk indicators, limiting adoption in multi-party supply chain environments. This paper presents a privacy-preserving smart and secure contract framework for digital supply chain payments that separates correctness verification from information disclosure. The proposed model combines a permissioned or consortium blockchain with off-chain encrypted data storage, cryptographic commitment schemes, and zero-knowledge proofs to ensure that payment obligations, milestone fulfillment, and financing conditions can be verified without revealing proprietary business details. Tokenized payment obligations represent invoices and receivables on the ledger, while milestone-based smart contracts coordinate delivery confirmation, early financing, dispute resolution, and settlement. Sensitive financial data and documents remain off-chain, anchored to the ledger only through hashes, commitments, and succinct proofs. Optional confidential computing components further enable secure evaluation of dynamic pricing or credit logic. A comprehensive security analysis demonstrates resistance to unauthorized state modification, double financing, insider misuse, and inference attacks under both honest-but-curious and malicious adversary models. Performance evaluation shows that the computational and communication overhead introduced by privacy-preserving mechanisms remains practical for real-world supply chain payment workflows, with low latency, efficient storage growth, and scalable operation across multi-tier ecosystems. The results indicate that the proposed framework provides a viable foundation for secure, privacy-aware, and auditable digital supply chain finance.

Open access
Blockchain Technology Applications and Security
Cryptography and Data Security
Internet of Things and AI
Original source
Jan 1, 2025·Journal of Discrete Mathematical Sciences and Cryptography
0 cites
Cryptographic protocols for passwordless systems with enhanced security

Gaurav Kumawat, Tapan Kant, Vivek Bhardwaj, Mukesh Kumar · 6 authors

Password-based authentication systems are vulnerable to a variety of security risks, such as phishing, credential theft, and user fatigue due to complex password requirements. This paper introduces a novel passwordless authentication framework that leverages advanced cryptographic techniques, including Zero-Knowledge Proofs (ZKP), Secure Multi-Party Computation (SMPC), and Homomorphic Encryption to enhance security, privacy, and user experience. The proposed system eliminates the need for traditional passwords by utilizing biometric data to generate cryptographic keys, ensuring that sensitive information remains secure. The architecture is composed of three primary components: the client device, the authentication server, and the key management system (KMS). The client device captures biometric data and transforms it into cryptographic keys using SMPC, while the server verifies the authentication using ZKP and establishes secure communication channels via Diffie-Hellman key exchange. The KMS handles key generation, storage, and rotation to ensure secure communication. Evaluation results show that the system is highly resistant to common attack vectors such as replay and man-in-the-middle attacks, with a 0% attack success rate. Performance analysis reveals an average authentication time of 180 ms, which is 10% faster than WebAuthn.

Advanced Authentication Protocols Security
User Authentication and Security Systems
Cryptography and Data Security
Original source
Jan 1, 2025·DSpace repository (University of Tartu)
0 cites
Alati kaks : Kahe osapoolega SDitH digiallkirjad

Veri, Hans Kristjan

The rise of quantum computing threatens to break many of the cryptographic systems that secure today’s digital world. In response, researchers are developing new tools designed to remain secure in a post-quantum future. Most of the promising candidates for post-quantum digital signatures rely on security assumptions based on lattices or properties of hash functions. Another promising approach transforms secure multi-party computation protocols into zero-knowledge proofs, which are then turned into digital signatures. This technique, known as multi-party computation in-the-head (MPCitH), offers strong security properties and flexibility for distributed applications. This thesis investigates whether MPCitH digital signatures can be efficiently adapted for use by two cooperating parties to jointly produce a signature. Here we show how to construct two-party signatures based on syndrome decoding in-the-head (SDitH) signatures. We propose a provably secure scheme that achieves the smallest known communication overhead among two-party MPCitH signatures, while resulting in a signature size approximately double that of a single-prover variant. This result provides a new data point in the design space of multi-party MPCitH signatures and post-quantum digital signatures in general.

Open access
Cryptography and Data Security
Cloud Data Security Solutions
Advanced Authentication Protocols Security
Original source
Jan 1, 2025·Proceedings of the 22nd International Conference on Security and Cryptography
0 cites
Honorific Security: Efficient Two-Party Computation with Offloaded Arbitration and Public Verifiability

Tianxiang Dai, Yufan Jiang, Yong Li, Jörn Müller‐Quade · 5 authors

In the secure two-party computation (2PC), an adversary is often categorized as semi-honest or malicious, depending on whether it follows the protocol specifications. Covert security (Aumann and Lindell, 2010) first looks into the “middle ground”, such that an active adversary who cheats will be caught with a predefined probability. Other security notions, such as publicly auditable security (Baum et al., 2014) and (robust) accountability family (Küsters et al., 2010; Graf et al., 2023; Rivinius et al., 2022), achieve public verifiability as a stronger security guarantee by relying on heavy offline and online constructions with zero knowledge proofs and (or) a bulletin board functionality. In this work, we propose a new security notion called honorific security, where an external arbiter can identify the cheater without a bulletin board. Specifically, we delay and outsource the verification steps to the arbiter, so that the original online computation is thus accelerated. We show that a maliciously secure garbled circuit (GC) (Yao, 1986) protocol can be constructed with only slightly more overhead than a passively secure protocol. Our construction performs up to 2.37 times and 13.30 times as fast as the state-of-the-art protocols with covert and malicious security, respectively.

Open access
Cryptography and Data Security
Privacy-Preserving Technologies in Data
Blockchain Technology Applications and Security
Original source
Jan 1, 2025·Lecture notes in computer science
0 cites
Batch Anonymous MAC Tokens from Lattices

Yingfei Yan, Sherman S. M. Chow, Lucien K. L. Ng, Harry W. H. Wong · 6 authors

No abstract is available for this record.

Cryptography and Data Security
Internet Traffic Analysis and Secure E-voting
Privacy-Preserving Technologies in Data
Original source
Jan 1, 2025·Advances in Mathematics of Communications
0 cites
A digital signature scheme based on the vector space factorization problem and the MPC-in-the-Head paradigm

Philippe Gaborit, Mercedes Haiech, Romaric Neveu

At a time when post-quantum cryptography is more and more present in the cryptographic landscape, it is of great interest to find new hard problems on which we can rely. Here, we present a new problem, the vector space factorization problem, and use it to build a signature scheme. The idea of factorizing subspaces of a finite field is used in rank metric codes, most notably in the decoding of LRPCs. In this context, one of the subspaces is known to factorize. Factorizing without the knowledge of both subspaces appears in the signature scheme Murave, in which the rank support basis decomposition problem is introduced from a coding theory in rank metric point of view. In Bro's thesis, the SquareSpace problem is introduced, where one wants to find the 'square root' of a subspace. We generalize here this problem into the vector space factorization problem, which is the same as the rank support basis decomposition problem introduced in Murave, the difference being we do not look at it from a coding theory point of view, but really from a vector subspace one. We use it here to build a zero-knowledge proof of knowledge. The scheme uses the MPCitH paradigm, and especially the TCitH framework, which is an efficient way to build ZK proofs. We study the difficulty of solving the vector space factorization problem by detailing the combinatorial attacks on the problem, analyzing their complexity, and describing an algebraic model to solve the problem. We then explain the MPC protocol used to build the signature scheme. Finally, this construction allows us to obtain sizes of signature of 8.9 to 10.9 kB for the first security level defined by NIST, which is reasonable as MPC-in-the-Head signatures typically range from 2.5 kB for an MQ instance to 14 kB for lattice-based instances.

Open access
Cryptography and Data Security
Cryptography and Residue Arithmetic
Coding theory and cryptography
Original source
Jan 1, 2025·International Journal of Networking and Computing
0 cites
Efficient Group Signatures with Designated Traceability over Openers’ Attributes from Lattices

Hiroaki Anada, Masayuki Fukumitsu, Shingo Hasegawa

The group signature with designated traceability (GSdT) is a kind of group signatures (GS) which aim to restrict the opening authority of the group manager; by setting an access structure over openers' attributes at the signing, a signer is able to control openers who can open the signature.A generic construction of GSdT was given when the notion was introduced, then a pairing-based construction and a symmetric-key-based one were presented.Nonetheless, it remains open whether a post-quantum GSdT with full anonymity can be truly constructed.In this paper, we give a lattice-based GSdT scheme that has full anonymity for the first time.In our construction, the lattice-based ciphertext-policy attribute-based encryption (CP-ABE) by Tsabary and the lattice-based group signatures (GS) by Libert et al. are employed.The CP-ABE is based on the Regev public-key encryption, while the GS uses a non-interactive zero-knowledge proof to prove the correctness of the encryption in the signing process.Based on the compatibility, we combine and modify them to build up a GSdT scheme.

Open access
Cryptography and Data Security
Privacy-Preserving Technologies in Data
Access Control and Trust
Original source
Jan 1, 2025·IEEE Transactions on Computational Social Systems
0 cites
Secure and Robust Aggregation for Federated Learning with Dynamic User Update

Hu Xiong, Yaxin Zhao, Hourui Deng, Erqiang Zhou · 6 authors

Existing secure aggregation schemes in federated learning (FL) face challenges related to detecting poisoning attacks and managing dynamic membership updates. To address these limitations, this article proposes a robust and dynamic aggregation framework for FL (RDFL), a robust and dynamic aggregation framework for FL. RDFL integrates a trimmed median algorithm with noninteractive range zero-knowledge proofs, providing a tunable mechanism for detecting abnormal updates. Client behavior is evaluated through a dynamic reputation scoring module, with malicious clients being added to a revocation list. By incorporating revocable attribute-based encryption, RDFL supports dynamic user management, ensuring that only authorized participants can access or update the global model. In addition, RDFL employs Shamir’s secret sharing and a pseudorandom double-masking scheme to maintain aggregation accuracy and protect communication privacy despite client dropouts. Experimental evaluations on the Extended MNIST (EMNIST) and CIFAR-100 datasets demonstrate that RDFL achieves strong security, communication efficiency, and model accuracy, making it suitable for FL involving a large number of clients with dynamic participation.

Privacy-Preserving Technologies in Data
Cryptography and Data Security
Access Control and Trust
Original source