Namdev M. Sawant, Joanne Gomes
No abstract is available for this record.
Follow blockchain research across journals, conferences, and preprint repositories.
889 results · page 8 of 38
Namdev M. Sawant, Joanne Gomes
No abstract is available for this record.
Siddharth Sudhir
This preprint introduces Risk Oracle, an exploit-intelligence–driven SBOM attestation framework designed to support practical risk gating in CI/CD. The system combines signals from Known Exploited Vulnerabilities (KEV) and Exploit Prediction Scoring System (EPSS) with SBOM-to-vulnerability matching to produce a policy-backed gate decision (e.g., pass / warn / block) while keeping the workflow interpretable and reproducible. A core design goal is bounded disclosure: the producer can commit to full findings and then disclose only a limited subset (e.g., top-K highest-risk issues) suitable for downstream verification, reducing disclosure risk while preserving auditability. The paper details the end-to-end pipeline (producer/verifier roles), a typed attestation schema, a scoring and decision procedure, and an evaluation that studies (i) signal behavior under pinned KEV/EPSS snapshots and (ii) operational overhead under synthetic SBOM scaling intended to approximate CI workloads. Key contributions A practical SBOM attestation pipeline that integrates exploit-intelligence signals for operational decision-making in CI/CD. A typed attestation schema and verifier procedure supporting bounded disclosure. A policy-driven scoring and gating framework (pass/warn/block) grounded in vulnerability-management practice. Evaluation focused on interpretability and operational cost (runtime/payload scaling) under reproducible, pinned snapshots. Artifacts / Reproducibility Code, scripts, and pinned snapshot references: [GitHub link] Suggested citationSudhir, S. (2026). Risk Oracle: Exploit-Intelligence–Driven SBOM Attestations with Bounded Disclosure (preprint). Zenodo. DOI: [10.5281/zenodo.18153487] Keywords: SBOM, software supply chain security, vulnerability management, KEV, EPSS, OSV, attestation, CI/CD, bounded disclosure, reproducibility
Md Al Amin, Indrajit Ray, Indrakshi Ray, Yashwant K. Malaiya · 5 authors
Access to electronic health records (EHRs) is heavily regulated by various policies, including federal-level policies, state-level statutes, international data protection laws, and local and organizational-level policies. These policies may include procedures to ensure compliance with other organizational-level regulations. In addition, individual patients can establish agreements, formally known as patient-provider agreements (PPA), with their healthcare providers to express their consent to access or share their protected health information (PHI). When such policies are adequately specified and implemented, they go a long way toward protecting EHR data. However, research has shown that significant policy compliance problems or gaps often go undetected until after a breach or security incident. Further, a recent study shows that subcultures within a healthcare organization influence whether employees violate policies, perhaps unintentionally. These observations motivate us to revisit the compliance and provenance aspects of policies. This dissertation proposes a blockchain-powered, smart contract-based policy-compliance assurance framework to enforce patient-provider agreements and other applicable policies and attributes, ensuring policy compliance and provenance in the healthcare sector. This work proposes a novel compliance review mechanism, Proof of Compliance (PoC), that conducts reviews through a set of independent, distributed, decentralized auditor nodes from various stakeholders, such as healthcare organizations, insurance companies, federal and other government agencies, regulatory agencies, and others mandated by the business requirements. Blockchain smart contracts appear to be a promising new technology for enforcing policies. In addition, blockchains' immutable storage properties and strong integrity guarantees provide hope that an adequate trail of policy compliance (or non-compliance) can be maintained, thereby facilitating provenance.
Jana Novaková, Adi Lestari
Given that digital governance has achieved extensive spread and people rely increasingly on online services, affordable and trustworthy identity management is now one of the core pillars of contemporary e-Governance systems. Conventional identity systems are usually centralized, highly susceptible to cyber-attacks and most likely to breach privacy. Blockchain technology provides a decentralized, tamper-proof, and transparent system, which guarantees data integrity, data security, and the privacy of the user. In this paper, the authors research the adoption of blockchain-based identity management within e-Governance sites. We discuss available solutions, assess the risks along with their weaknesses and strengths, and suggest a design on how to introduce a safe blockchain-based identity system. Important efforts have been on developing a holistic system that brings smart contract, cryptographic protocols and distributed ledger technologies together to make citizen identification and authentication secure. The outcome of the results shows enhanced security, less identity fraud, and better data security, so there is a possibility of scalability and resilient e-Governance applications.
Elvira Immaculate Khwatenge, Mussa Ally, Geminpeter Lyakurwa, Hope Mbelwa
No abstract is available for this record.
Yuxia Zhao, Mingliang Yu, Gang Wang, Wen Yang · 5 authors
No abstract is available for this record.
Zuodong Wu, Dawei Zhang, Mianxiong Dong, Kaoru Ota
In the data-driven era, the unchecked collection and processing of personal data has given rise to serious privacy concerns. In response, the General Data Protection Regulation (GDPR) was introduced to grant individuals stronger control over the use of their data. Privacy data retrieval methods show considerable promise in this context, but further improvements are required to balance the principles of lawfulness and data minimization. To address this problem, we propose PDRAA, an efficient privacy data retrieval protocol with anonymous authorization based on the verifiable credential (VC). Specifically, our designed VC achieves anonymous identification of data subjects and facilitates fine-grained access control by supporting selective disclosure of attributes. By combining VC with non-interactive zero-knowledge (NIZK) proofs, PDRAA enables data subjects to anonymously authenticate via VC presentation. This allows the data controller to verify the legitimacy of retrieval requests while ensuring compliance with the principle of data minimization. Besides, PDRAA introduces a re-randomization mechanism to prevent linkability attacks during the authorization process and provides lightweight, flexible authorization revocation. Moreover, we utilize Labeled Private Set Intersection (Labeled PSI) technology to meet the privacy requirements of participants and support batch retrieval. Our protocol takes a comprehensive security analysis within the Universal Composability framework. Experimental results demonstrate that PDRAA outperforms existing methods in terms of performance, which is significant for promoting compliance with GDPR.
Abdelhak Kaddari, Tarik Chanyour
No abstract is available for this record.
Abhinav Dubey, Krishan, Renu Mishra, Ramneet
No abstract is available for this record.
Junhee LEE, Yixi Cai Lili lei Lei Li, Gweonho Jeong, Jihye Kim · 6 authors
Forward-secure digital signatures protect the integrity of past signatures, even if the current signing key is compromised. Among forward-secure signature schemes, the method introduced by Lee et al. [1], based on zero-knowledge succinct non-interactive arguments of knowledge (zk-SNARKs), is particularly notable for achieving constant complexity across all metrics without requiring a predefined maximum time period. However, a naive approach to recursive proof composition results in an excessive amount of redundant computation being repeated for each signing process, which our method reduces significantly. In this paper, we advance a zk-SNARK-based forward-secure signature scheme by significantly improving the efficiency of its signing algorithm. By incorporating commit-and-prove SNARKs, we replace the inner verification process with commit verification within the signing circuit. Furthermore, we employ efficient recursive zk-SNARKs with accumulation and folding schemes to improve the setup and update algorithms. Our implementation demonstrates the practicality of our approach: the signing procedure completes in 0.18 seconds, achieving a 75-fold speedup over the previous scheme, setup time is reduced to 0.71 seconds - over 61 times faster, and public parameters are reduced to 25 MB, more than 16 times smaller.
Janice Author
No abstract is available for this record.
Frederico C Montenegro
No abstract is available for this record.
Abdur Rahman Sarker, Md. Moneruzzaman, Zikra Amin, Md Alif · 6 authors
No abstract is available for this record.
D. Bernal, Paula Medina Lamo, J. Bermejo
No abstract is available for this record.
Maxat Kassen
No abstract is available for this record.
Quoc Khanh Huynh, Nhat Nguyen Nguyen, Tuan-Dung Tran
No abstract is available for this record.
Fei Tong, Haoxuan Zang, Fang Jiang, G. D. Li · 5 authors
Reentrancy Vulnerabilities (RVs) in smart contracts pose severe financial risks to blockchain systems. While deep learning-based detection methods have shown promise, they suffer from critical limitations: (1) vulnerability to adversarial examples, (2) inadequate handling of Cross-Function RVs (CFRVs), and (3) reliance on limited training data. To address these challenges, we present SCAEG, the first adversarial example generation framework specifically designed for RV detection. SCAEG introduces five novel perturbation actions that preserve code functionality while exposing model vulnerabilities, including targeted modifications for CFRV scenarios. Our comprehensive evaluation demonstrates that SCAEG-generated examples sig nificantly degrade the performance of state-of-the-art detectors (e.g., reducing AWDNN's accuracy by 27.51 percentage points), exposing their fragility to adversarial attacks. Building on these insights, we propose VoteRD, an ensemble detection model that combines semantic, rule-based, and positional features through a multi-model voting mechanism. Experimental results show VoteRD achieves superior robustness, outperforming existing approaches by 3.7% in recall and 7.4% in F1-score (compare with AWDNN), while effectively detecting both traditional RVs and CFRVs. This work not only advances RV detection capabilities but also establishes a new benchmark for evaluating model robustness in smart contract security analysis. SCAEG and VoteRD form a synergistic framework: SCAEG systematically evaluates model robustness, while VoteRD leverages adversarial insights to enhance detection accuracy. Our datasets and tools are publicly released to support future research in adversarial testing and vulnerability detection.
Ilyas Sabeshuly, Arslan Toimbekov, Assel Akzhalova, Nuriman Altybayeva · 5 authors
No abstract is available for this record.
Gaurav Tamrakar
The dynamic service conditions, the lack of centralised control in the distributed and federated services, and the growing sophistication of the malicious behaviours are the key challenges to trust management in the distributed and federated services. Standard trust models, based on fixed credentials, central authorities, or aggregation of reputation over the whole world, are no longer suitable to serve high-rate changing contexts in services, and have very high communication and coordination costs. In an effort to curb these issues, this paper puts forward a proposal of adaptive trust evaluation framework that has distributed verification in highly dynamic service-oriented architectures. The suggested model represents trust as a context-based, multi-dimensional digit that conservatively adapts to the context changes in service conduct, workload, and environmental state. To satisfy the decentralized nature of trust updates, a lightweight peer-based verification system is presented and does not need any centralized sources of trust but instead, trust updates are validated through decentralized means without depending upon a full blockchain consensus system. The framework constitutes adaptive weighting of trust, decay of trust and enforcement policies to reliably detect malicious or unreliable services in changing situations. Between the two widely used approaches, the widespread performance analysis of the suggested approach demonstrates that it has a better accuracy in trust, faster in detecting malicious service and with a much lower communication overhead than state of art centralised, reputation-based and ledger-driven approaches to trust. The findings affirm the viability, scalability, as well as viability of the suggested solution to secure trust execution in the next-generation distributed cloud and edge service surroundings.
Mohit Tiwari
SARMF-Bench is a structured and reproducible benchmark dataset for smart contract vulnerability analysis. It consists of five minimal Solidity contracts representing canonical vulnerability classes: • Reentrancy • Arithmetic Overflow Behavior • Access Control Weakness • Unchecked External Call • Denial-of-Service Pattern Each contract is paired with machine-readable static analysis outputs generated using Slither v0.11.5. The dataset is designed to support controlled benchmarking experiments for: - Static analyzers - Symbolic execution engines - Fuzzers - AI-assisted smart contract security tools Related assets: GitHub repository: https://github.com/profmohit-edu/sarmf-framework Zenodo software DOI: https://doi.org/10.5281/zenodo.18754015 Reproducibility protocol: https://doi.org/10.17504/protocols.io.bp216eyxdgqe/v1 Mendeley dataset DOI (pending moderation): https://doi.org/10.17632/kd3vcpnn9v.1 HAL record: https://hal.science
Steven Paul Nohr
Decentralized systems are increasingly required to operate across heterogeneous environments involving human presence, real-world assets, regulatory constraints, and adversarial network conditions. Traditional execution models, which assume static infrastructure, context-free computation, and pre-authorized identities, are insufficient for these emerging requirements. This paper introduces a Presence-Centric execution architecture that binds computational validity to verifiable environmental state at execution time. The proposed system is structured around two core components: the Crystal Validator, a context-aware validation layer, and an AI Feedback Loop, which enables adaptive policy enforcement based on observed outcomes. Central to this architecture is <b><i>Environment-Coupled Execution</i></b>, a model in which identity, intent, policy, and environment are jointly evaluated to determine execution validity. By treating environment as a first-class execution dependency, the system enables contextual non-repudiation, replay resistance, regulatory determinism, and post-execution auditability. The proposed approach is applicable to decentralized finance, stablecoins, real-world asset tokenization, governance systems, and presence-driven digital platforms.
Steven Paul Nohr
<b><i>Governance Voter Loop Reuse</i></b> is a strategic exploit in decentralized finance (DeFi) governance systems whereby the same economic capital is repeatedly reused to exert voting influence across multiple proposals, epochs, or governance venues without maintaining sustained economic exposure. By exploiting snapshot-based voting, token mobility, and weak binding between voting power and duration of risk, attackers can artificially amplify governance influence while avoiding long-term commitment. This paper formalizes the exploit, analyzes its structural enablers and execution mechanisms, and evaluates its systemic impact on DAO legitimacy and protocol security. We further propose mitigation requirements centered on time-weighted exposure, continuity-aware governance models, and behavioral detection mechanisms.
Steven Paul Nohr
Decentralized finance and stablecoin systems rely extensively on off-chain data oracles to supply price feeds, reserve attestations, and external state signals. While often treated as neutral data providers, oracles constitute a critical enforcement surface vulnerable to coercion, capture, and strategic manipulation. This paper defines <b><i>Off-Chain Data Oracle Coercion</i></b> as a systemic risk whereby economic, governance, or infrastructural pressures distort oracle outputs without violating cryptographic correctness. We demonstrate how oracle coercion enables silent value extraction, destabilizes stablecoin pegs, and undermines regulatory compliance. A validator-enforced, logic-layer control model is proposed to restore oracle neutrality and ensure continuous, verifiable data integrity under MiCA-aligned supervision.
Thanh-Binh Trinh, Ngoc-Minh Le
No abstract is available for this record.