Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

889 papersLast indexed Aug 31, 2026
Search papers

Paper index

889 results · page 9 of 38

Clear filters
Jan 1, 2026·IEEE Transactions on Big Data
0 cites
Traceable, Fair and Privacy-Preserving Decentralized Medical Data Exchange

Rui Song, Yubo Song, Xiaotie Deng, Bin Xiao

To harness the commercial potential of medical data, various blockchain-based data-sharing and exchange platforms have been proposed. A key challenge is accurately tracing the provenance and transformations of medical data assets throughout the exchange process. Existing methods cannot facilitate exchanges of publicly hosted datasets while maintaining fairness, as they require revealing keys to the blockchain during interactions. This paper presents MEDET, a novel data exchange scheme that ensures traceability of medical data assets while protecting data privacy and guaranteeing exchange fairness. MEDET leverages zero-knowledge proofs to securely verify transformations within medical datasets and confirm data authenticity. Unlike previous schemes, MEDET supports both simple data exchanges and detailed tracking of data transformations and transaction histories, aiding in the provenance and value assessment of medical records. Additionally, MEDET features a key-secure protocol for fair exchange without disclosing symmetric keys. Compared to existing fair exchange schemes, MEDET uniquely ensures the privacy of publicly hosted data while simultaneously upholding the exchange fairness. The security analysis of MEDET demonstrates its security and privacy properties. The evaluation of MEDET indicates that it outperforms existing schemes in tracking data transformations and facilitating exchanges.

Cryptography and Data Security
Privacy-Preserving Technologies in Data
Access Control and Trust
Original source
Jan 1, 2026·SSRN Electronic Journal
0 cites
Cognitive Internet Layer (CIL): The Foundational Trust and Reasoning Infrastructure for Autonomous Intelligence Systems

Vengatagiri Gurumani

The current internet architecture was fundamentally designed for deterministic data packet transport and applicationlevel request-response interactions, not for the semantic exchange, verification, governance, and replay of autonomous machine reasoning. As autonomous AI agents scale globally to orchestrate critical infrastructure, medical networks, corporate supply chains, and legal workflows, traditional integration patterns create structural bottlenecks. These limitations introduce severe risks of cognitive fragmentation, black-box opacity, and cascade errors across organizational boundaries. This paper proposes the Cognitive Internet Layer (CIL), a protocol-oriented overlay architecture positioned above conventional network transport and below autonomous AI applications. CIL introduces the Reasoning Exchange Protocol (REP) to route structured decision envelopes containing reasoning metadata rather than raw payloads. To resolve real-world deployment trade-offs, the framework integrates Zero-Knowledge Proofs (ZKPs) for privacy-preserving verification and a Tiered Execution Architecture to isolate highthroughput edge transactions from deep asynchronous multi-agent consensus validation.

Open access
Cognitive Computing and Networks
Access Control and Trust
Distributed systems and fault tolerance
Original source
Jan 1, 2026·SSRN Electronic Journal
0 cites
Secure Explainable Audit Trails for Workflows in Agentic AI

Subhasis Thakur

An Explainable Audit Trail (EAT) records process execution traces of an agentic workflow. EAT can enable an organisation to efficiently remain compliant with regulations by presenting its audit results to it. However, current state of the art in EAT lacks privacy protection of agent's models which can be intellectual properties of the organisation. Exposing audit trails to external entities may facilitate orchestration of attacks on the agent's model. Auditing a complex workflow will require verification of dependencies among tasks as preconditions to execute a task. Further, it is necessary for the audit algorithm to ensure that a process execution trace follows the pre-planned process execution model for security reasons, i.e., audit should include functionality that can check if the agents have deviated from its planned process execution models. In this paper, we build a secure EAT that can address these gaps in the state of the art in EAT for agentic workflows. Our main contribution is the application of zero-knowledge-proof on verifying audit procedures. It proves the audit has validated correctness of chain-of-thoughts, the execution trace at the runtime matches the planned process execution , and complete traceability among logs of a complex workflow involving dependencies among the tasks in terms of preconditions. Our solution provides a trust-less infrastructure to verify the audit results to external entities while not exposing the audit trails. We used lattice-based zero knowledge proof for this procedure. We provide an analysis on the EAT procedure. We show experimental evaluation of the EAT with workflow dataset.

Open access
2 source records
Business Process Modeling and Analysis
Access Control and Trust
Explainable Artificial Intelligence (XAI)
Original source
Jan 1, 2026·FH JOANNEUM ePUB
0 cites
Design of an Alternative Identity Proofing Approach for Digital Onboarding to ID Austria

Sandro Stattmann

Digitale Identitätssysteme bilden eine zentrale Grundlage moderner Verwaltungs- und E-Government-Prozesse. Sie ermöglichen die sichere Interaktion zwischen Bürger:innen, staatlichen Stellen und privaten Diensten. Ein besonders kritischer Schritt ist dabei die Identitätsprüfung im Rahmen des Onboardings, da hier die Verbindung zwischen einer realen Person und einer digitalen Identität hergestellt wird. Bestehende Onboarding-Verfahren, etwa persönliche Identifikation, VideoIdent, biometrische Verfahren oder dokumentenbasierte Prüfungen, stellen dafür etablierte Mechanismen bereit, erfordern jedoch häufig die Verarbeitung sensibler personenbezogener Daten und stützen sich stark auf organisatorische Vertrauensstrukturen.Die vorliegende Arbeit untersucht, ob ein deterministischer, registerbasierter und kryptographisch unterstützter Matching-Ansatz auf den Onboarding-Prozess von ID Austria angewendet werden kann. Der Fokus liegt dabei nicht auf der Entwicklung eines neuen kryptographischen Bausteins oder eines vollständig neuen Identitätssystems, sondern auf der konzeptionellen Anwendung und prototypischen Umsetzung von Deterministic Privacy-Preserving Identity Matching als Onboarding-Modell. Dieser Ansatz wird im Rahmen der Arbeit als DPPIM-OM bezeichnet.Die Arbeit folgt einem konstruktiv-analytischen Vorgehen. Zunächst werden die technischen und konzeptionellen Grundlagen digitaler Identität, Identitätsprüfung, privacy-preserving Matching, OPRF/VOPRF-Mechanismen und Zero-Knowledge-Nachweisen analysiert. Darauf aufbauend wird ein Onboarding-Modell beschrieben, das deterministischen Full-Match, kanonisierte Attributrepräsentation, servergebundene kryptographische Auswertung, registerbasierten Vergleich und registergebundene Nachweisführung kombiniert. Anschließend wird ein Prototyp umgesetzt, um die technische Realisierbarkeit des Ansatzes unter kontrollierten Bedingungen zu demonstrieren.Das vorgeschlagene Onboarding-Modell wird dem aktuellen ID-Austria-Onboarding sowie VideoIdent-, biometrischen und dokumentenbasierten Verfahren gegenübergestellt. Die Evaluierung erfolgt entlang zentraler Dimensionen wie Datenexposition, Informationsleckage, Sicherheit, Missbrauchsresistenz, Vertrauensmodell, Verifizierbarkeit, Determinismus, Fehleranfälligkeit, Anforderungen an Datenqualität, Prozesskomplexität, Performance sowie Kompatibilität mit dem europäischen regulatorischen Rahmen.Die Ergebnisse zeigen, dass DPPIM-OM insbesondere in den Bereichen Datenminimierung, Informationskontrolle und Verifizierbarkeit deutliche strukturelle Vorteile aufweist. Gleichzeitig bringt der Ansatz spezifische Anforderungen und Einschränkungen mit sich, insbesondere hinsichtlich Datenkonsistenz, technischer Umsetzungskomplexität und fehlender direkter Personenbindung. Die Arbeit kommt zu dem Ergebnis, dass der Ansatz eine vielversprechende Möglichkeit zur Weiterentwicklung digitaler Onboarding-Prozesse darstellt, insbesondere in hybriden Modellen, die klassische Mechanismen zur Personenbindung mit einem deterministischen und kryptographisch überprüfbaren Attributabgleich kombinieren.

Access Control and Trust
Privacy-Preserving Technologies in Data
Privacy, Security, and Data Protection
Original source
Jan 1, 2026·SSRN Electronic Journal
0 cites
Cryptographic State-Transition Anchoring: A Merkle-Tree Framework for Zero-Knowledge Regulatory Compliance in Insurance Operations

Piyoosh Rai

Insurance operations generate continuous streams of regulated state transitions-policy issuance, claim adjudication, premium collection, broker remittance-that must be auditable for years and verifiable on demand by regulators, reinsurance counterparties, and litigation adversaries. The prevailing industry practice protects these audit trails through database access controls and policy-based logging in mutable relational stores. This approach is insufficient: it requires regulators to trust the platform vendor, exposes Personally Identifiable Information (PII) during inspection, and provides no mathematical defense against retrospective tampering by privileged insiders or attackers with database access. This paper introduces the Regure Immutable Audit (RIA) Protocol, a cryptographic statetransition anchoring system that organizes insurance operational events into per-tenant Merkle trees, signs each daily root with a tenant-specific hardware-backed key via AWS Key Management Service, and anchors the signed root to two independent immutable witnesses: AWS S3 Object Lock and the Bitcoin blockchain via OpenTimestamps. Verification is implemented as a zero-knowledge protocol: an external auditor can verify the cryptographic integrity of any specific event in any specific claim using a Merkle proof of length 𝑂(log 𝑛)against a publicly anchored root, without ever observing the underlying claim data. We provide formal definitions of the State-to-Hash Mapping, the Hash-Linked Lifecycle property, and the Dual-Witness Anchoring Construction. We prove that the system is tamper-evident under standard cryptographic assumptions, that verification has logarithmic complexity in the number of events per tenant per day, and that the Zero-Knowledge Audit property holds against both honest-but-curious regulators and an actively malicious platform vendor. We describe the production implementation deployed in Cryptographic State-Transition Anchoring Piyoosh Rai P a g e | 2 Regure, including the integration with AWS KMS for tenant-isolated signing keys and the dual anchoring path through Object Lock storage and Bitcoin transaction confirmation. We discuss the implications for Continuous Assurance under DORA Article 12, the Swiss Federal Act on Data Protection (FADP), the Saudi Arabian Monetary Authority (SAMA) Cyber Security Framework, and Lloyd's market reporting requirements for delegated authority operations. The RIA Protocol moves the insurance industry's audit trust model from "trusting the vendor" to "trusting the math"-a structural shift that resolves the long-standing conflict between the regulatory Right to Audit and the data subject's right to privacy.

Open access
Cryptography and Data Security
Blockchain Technology Applications and Security
Access Control and Trust
Original source
Jan 1, 2026·SSRN Electronic Journal
0 cites
A Modular Zero-Knowledge Credential Framework for Multi-System Attribute Verification with Scoped Unlinkability and Efficient Accumulator-Based Revocation

Sayan Bairagi

This paper presents a zero-knowledge credential framework for secure and privacy-preserving attribute verification across multiple independent systems. The framework enables users to prove statements about their attributes without revealing the underlying values, while preventing cross-domain tracking by eliminating globally stable identifiers. The construction combines commitment schemes, digital signatures, zero-knowledge proofs, scoped pseudonyms, and accumulator-based revocation into a unified and modular design. Scoped identifiers ensure that user activity cannot be linked across different verification domains, while predicate proofs allow verification of conditions such as threshold checks without disclosing sensitive data. Revocation is supported through an efficient accumulator mechanism that enables verification without revealing credential identities and without increasing cost with the size of the revoked set. The system follows a complete lifecycle including credential issuance, proof generation, verification, and revocation checking. All proofs are non-interactive and bound to verifier-specific challenges, ensuring resistance to replay attacks. Security is based on standard cryptographic assumptions, providing guarantees for attribute privacy, proof soundness, unlinkability, and resistance to collusion. Experimental evaluation demonstrates that the framework achieves practical performance, with low verification latency, compact proof size, and stable scalability. The results show that strong privacy, verifiable authenticity, and efficient revocation can be achieved simultaneously without relying on trusted setup or pairing-based cryptography. The modular structure further supports integration with decentralized identity systems and real-world deployment scenarios.

Open access
Cryptography and Data Security
Blockchain Technology Applications and Security
Access Control and Trust
Original source
Jan 1, 2026·IEEE Access
0 cites
Session-Bound Zero-Knowledge Authorization for SRv6 Programmable Data Planes

Jin Zhou, Hongzhi Lu, Jianxin Xiong

The integration of continuous Zero Trust Architecture (ZTA) into Segment Routing over IPv6 (SRv6) networks introduces severe performance bottlenecks and physical constraints of the Maximum Transmission Unit (MTU). Specifically, naively embedding massive Zero-Knowledge Proof (ZKP) for per-packet authentication inevitably triggers catastrophic fragmentation and disrupts stateless forwarding. To address these fundamental limitations, this paper proposes a novel session-bound zero-knowledge authorization framework tailored for SRv6 programmable data planes. Our architecture explicitly decouples heavyweight cryptographic validations from the active forwarding path. Massive ZKP payloads are processed asynchronously via payload transmission in the control plane, while the data plane enforces line-rate access control using lightweight 32-byte capability tokens encapsulated in customized SRv6 extension headers. Furthermore, to mathematically balance robust security with forwarding efficiency, we formulate the dynamic verification process as a risk-aware Partially Observable Markov Decision Process (POMDP). Using in-band network telemetry, we derive an Adaptive Threshold Verification (ATV) algorithm that yields a closed-form <inline-formula> <tex-math notation="LaTeX">$O(1)$ </tex-math></inline-formula> complexity optimal scheduling policy. Extensive evaluations demonstrate that the decoupled mechanism seamlessly resolves the MTU bottleneck, maintaining stable baseline throughput under massive concurrent sessions. Concurrently, the ATV algorithm intelligently adapts to real-time threat intensities, conserving control-plane resources during safe periods while instantaneously triggering precise re-verifications against covert and volumetric cyberattacks.

Open access
Access Control and Trust
Cryptography and Data Security
Security and Verification in Computing
Original source
Jan 1, 2026·Blockchain Research and Applications
1 cites
NxGenT: A decentralized trust system for B5G and 6G networks based on blockchain and smart contracts

Carlos Nú Nez-Gómez, Víctor Garcia-Font, Helena Rifà-Pous, Muhammad Asad

The submitted work contains the following highlights: • We detail NxGenT, a decentralized reputation system for B5G and 6G networks. • We propose a three-phase reputation mechanism based on smart contracts. • We implement NxGenT and release its source code as open-source software. • We analyze NxGenT’s design and resilience against relevant trust attacks. • We evaluate NxGenT’s functionality and performance through experimental analysis. The evolution towards Beyond 5G (B5G) and 6G networks presents highly heterogeneous and dynamic scenarios in which numerous entities, including network operators, service providers and end users, interact in environments of mutual trust. However, the open nature of these networks poses significant challenges regarding security and trust, as traditional centralized mechanisms may prove inadequate or insufficient in such scenarios. In this context, decentralized trust systems are positioned as a promising solution to assess the reliability of entities participating in B5G and 6G networks, thereby enhancing decision-making processes and resilience of these environments. This paper introduces NxGenT , a decentralized reputation system based on blockchain and smart contracts for B5G/6G networks that guarantees the immutability and transparency of the collected evidence on entities’ performance and behavior, while decentralizing and automating the reputation mechanism. NxGenT is a decentralized, trustless system in which entities establish and verify compliance with Service Level Agreements (SLA) and provide feedback or subjective opinions about the entities they interact with in order to compute and assign reputation scores. To evaluate the proposal, we implement a local B5G testbed that deploys the primary components of this type of network, along with a second cloud-based testbed to analyze scalability in networks of different sizes. Finally, we contextualize NxGenT within the 6GENABLERS project as a representative use case of the proposed trust system, thus demonstrating its applicability in real scenarios.

Open access
Blockchain Technology Applications and Security
Access Control and Trust
Software-Defined Networks and 5G
Original source
Jan 1, 2026·IEEE Transactions on Information Forensics and Security
0 cites
Tracing Your Account: A Gradient-Aware Dynamic Window Graph Framework for Ethereum under Privacy-Preserving Services

Shuyi Miao, Wangjie Qiu, Xiaofan Tu, Yunze Li · 6 authors

With the rapid advancement of Web 3.0 technologies, public blockchain platforms are witnessing the emergence of novel services designed to enhance user privacy and anonymity. However, the powerful untraceability features inherent in these services inadvertently make them attractive tools for criminals seeking to launder illicit funds. Notably, existing de-anonymization methods face three major challenges when dealing with such transactions: highly homogenized transactional semantics, limited ability to model temporal discontinuities, and insufficient consideration of structural sparsity in account association graphs. To address these, we propose GradWATCH, designed to track anonymous accounts in Ethereum privacy-preserving services. Specifically, we first design a learnable account feature mapping module to extract informative transactional semantics from raw on-chain data. We then incorporate transaction relations into the account association graph to alleviate the adverse effects of structural sparsity. To capture temporal evolution, we further propose an edge-aware sliding-window mechanism that propagates and updates gradients at three granularities. Finally, we identify accounts controlled by the same entity by measuring their embedding distances in the learned representation space. Experimental results show that even under the conditions of unbalanced labels and sparse transactions, GradWATCH still achieves significant performance gains, with relative improvements ranging from 1.62% to 15. 22% in the MRR and from 3. 85% to 7. 31% in the F_1.

Open access
3 source records
cs.CE
Access Control and Trust
Data Quality and Management
Original source
Jan 1, 2026·Open MIND
2 cites
Poster: Privacy-Preserving Compliance Checks on Ethereum via Selective Disclosure

Supriya Khadka, Dhiman Goswami, Sanchari Das

Digital identity verification often forces a privacy trade-off, where users must disclose sensitive personal data to prove simple eligibility criteria. As blockchain applications integrate with regulated environments, this over-disclosure creates significant risks of data breaches and surveillance. This work proposes a general Selective Disclosure Framework built on Ethereum, designed to decouple attribute verification from identity revelation. By utilizing client-side zk-SNARKs, the framework enables users to prove specific eligibility predicates without revealing underlying identity documents. We present a case study, ZK-Compliance, which implements a functional Grant, Verify, Revoke lifecycle for age verification. Preliminary results indicate that strict compliance requirements can be satisfied with negligible client-side latency (&lt; 200 ms) while preserving the pseudonymous nature of public blockchains.

Open access
5 source records
cs.CR
cs.HC
Privacy, Security, and Data Protection
Original source
Jan 1, 2026·2026 IEEE SoutheastCon, Huntsville, AL, USA, 2026
0 cites
Device-Native Autonomous Agents for Privacy-Preserving Negotiations

Joyjit Roy, Samaresh Kumar Singh

Automated negotiations in insurance and business-to-business (B2B) commerce encounter substantial challenges. Current systems force a trade-off between convenience and privacy by routing sensitive financial data through centralized servers, increasing security risks, and diminishing user trust. This study introduces a device-native autonomous Artificial Intelligence (AI) agent system for privacy-preserving negotiations. The proposed system operates exclusively on user hardware, enabling real-time bargaining while maintaining sensitive constraints locally. It integrates zero-knowledge proofs to ensure privacy and employs distilled world models to support advanced on-device reasoning. The architecture incorporates six technical components within an agentic AI workflow. Agents autonomously plan negotiation strategies, conduct secure multi-party bargaining, and generate cryptographic audit trails without exposing user data to external servers. The system is evaluated in insurance and B2B procurement scenarios across diverse device configurations. Results show an average success rate of 87%, a 2.4x latency improvement over cloud baselines, and strong privacy preservation through zero-knowledge proofs. User studies show 27% higher trust scores when decision trails are available. These findings establish a foundation for trustworthy autonomous agents in privacy-sensitive financial domains.

Open access
4 source records
cs.CR
cs.AI
cs.ET
Original source
Jan 1, 2026·International Journal of Computing and Artificial Intelligence
0 cites
A conceptual framework for efficient and secure blockchain-based trust and verification systems in distributed environments

Shubhangi Rajendra Patil

cloud computing environments and multi agent systems has presented huge difficulties in creating a trust system, verifying securely and largely being transparent amongst the heterogeneous entities. The traditional centralized methods continue to become unsuitable with their vulnerability to the single point of failure, breach of data and unimpeccable auditability. The decentralized and immutable nature of blockchain technology has become a promising solution, but the currently operational blockchain-based systems still present severe constraints which are associated with scalability, high computation cost, disturbing latency as well as absence of adaptive trust mechanism.The current paper suggests a set of new conceptual frameworks on the use of an efficient and secure blockchain-based trust and verification system adapted to the distributed environment. The model uses a hybrid design that combines on-chain and off-chain processing to make the performance efficient and do not compromise security. An active screening system of trust is presented to determine the trustworthiness of each of the participating nodes on the basis of transaction history, behavioral patterns as well as their success rate of validation. Also, it includes a featherweight hybrid consensus which is based on Proof of Stake (PoS) and Practical Byzantine Fault Tolerance (PBFT) to ensure that it uses less energy to execute and also enhance the speed of transactions verification.The framework also includes smart contracts to verify and control access and use of data array of cryptography methods to guarantee the integrity of data and authentication. The proposed model offers a practical and flexible solution to the current distributed system since it tackles major challenge related to the system, namely scalability, efficiency and security. The framework is applicable to various areas which have been showcased in the IoT networks, management of supply chains, data sharing in healthcare, and e-governance. Future research possibilities include incorporating the element of artificial intelligence in the adaptive trust and quantum-resistant cryptographic research.

Open access
Blockchain Technology Applications and Security
Cloud Data Security Solutions
Access Control and Trust
Original source