This paper proposes a novel blockchain consensus mechanism termed "Distributed Proof-of-Work with Quantum Key Distribution" (DPW-QKD). The core idea is to leverage quantum key distribution (QKD) to replace computationally intensive hash functions in traditional Proof-of-Work (PoW) systems, thereby significantly reducing energy consumption. The system operates by nodes generating cryptographic keys through QKD, which are then utilized in a distributed QKD protocol to verify transaction validity. This approach eliminates the need for miners to solve complex cryptographic puzzles, creating a more energy-efficient and potentially more secure consensus model. The paper outlines the architecture, key components, and operational principles of the DPW-QKD system, highlighting its advantages and potential challenges. Mathematical formulations are presented to illustrate the key processes and security considerations within the system. The research aims to explore a viable pathway towards a sustainable and robust blockchain technology, driven by the inherent security of quantum mechanics.
Open access
2 source records
Blockchain Technology Applications and Security
Physical Unclonable Functions (PUFs) and Hardware Security
Background: In recent years, the Internet of Medical Things (IoMT) has transformed the healthcare sector through real-time patient monitoring and continuous data collection.However, transmitting sensitive medical information over public networks exposes IoMT systems to significant security threats, while emerging quantum computing technologies challenge the reliability of traditional cryptographic systems.Objective: The objective of this study is to propose PQAC-BIoMT, a secure and robust model for remote user authentication and access control in IoMT environments, capable of withstanding both conventional and quantum attacks.Methods: This article proposes a decentralized authentication framework that integrates post-quantum cryptography using Kyber Public-Key Encryption (Kyber-PKE) into blockchain-based smart contracts.Fog computing nodes are used to reduce the authentication latency and improve the system scalability.A role-based authorization mechanism is integrated to link user identities to functional roles and enforce authorization to medical data and system resource access.Formal security verification is conducted using Burrows-Abadi-Needham (BAN) logic to validate the correctness of authentication, and the Automated Validation of Internet Security Protocols and Applications (AVISPA) tool is used to assess resistance to known attacks.PQAC-BIoMT is further evaluated through a comparative analysis of the computational load, energy consumption and security properties.Results: Our security analysis demonstrates that PQAC-BIoMT effectively resists common attacks while providing quantum-resistant protection against them.The performance evaluation shows that the proposed scheme achieves relatively lower computational and energy overhead compared to existing approaches, making it suitable for resource-constrained IoMT devices.Conclusion: The proposed PQAC-BIoMT scheme delivers a secure, quantum-resilient authentication and authorization mechanism for IoMT systems, enhancing both data protection and operational efficiency, which can support practical deployment in real-world IoMT applications.
Open access
Blockchain Technology Applications and Security
Physical Unclonable Functions (PUFs) and Hardware Security
Stian Lybech, Eun-Young Kang, Riccardo Tonello, Anders Dalskov
This paper develops a model of a smart-contract language for a blockchain architecture with off-chain components. Off-chain components are pieces of smart contracts that execute at designated locations outside of the network of blockchain nodes, but remain synchronised with the on-chain contract state. They react to changes to the on-chain state, but may also notify the on-chain component about events in the world, e.g. stock prices, weather data etc., or even act as a bridge between different blockchains. This affords greater flexibility for the developer, but may also enable new vulnerabilities. As a concrete example, we use the model to study the problem of ensuring integrity and secrecy of data between the on-chain and off-chain components, using static information flow control techniques. This fails, even in the absence of a loop construct, because off-chain components act as separate threads and can encode a blocking construct e.g. through recursive method calls. We end the paper with a discussion of possible ways to remedy this situation.
The rapid digitalisation of healthcare has accelerated the adoption of telemedicine, Electronic Health Records (EHRs), and the Internet of Medical Things (IoMT), transforming healthcare delivery into a highly interconnected and patient-centric ecosystem. In response to growing concerns about data security, privacy, and interoperability, blockchain technology has emerged as a promising solution for its decentralization, immutability, auditability, and secure access control. However, many existing blockchain infrastructures rely on classical cryptographic primitives, including RSA- or elliptic-curve-based public-key mechanisms and cryptographic hash functions such as SHA-256, whose relevant security properties may be affected by sufficiently powerful quantum attacks. This review investigates the convergence of blockchain and quantum technologies to address emerging security threats in e-health systems. A structured literature review was conducted in accordance with the PRISMA 2020 guidelines using the IEEE Xplore, PubMed, ACM Digital Library, Google Scholar, and Crossref databases, covering studies published between January 2018 and June 2025. Following a systematic screening and eligibility-verification process, 57 relevant studies were selected and analyzed. The review evaluates quantum-resilient security mechanisms, including Quantum Key Distribution (QKD), Quantum Random Number Generation (QRNG), and NIST-standardized Post-Quantum Cryptography (PQC) algorithms specified in FIPS 203, FIPS 204, and FIPS 205. Based on the identified research gaps in the state of the art, this study also proposes a novel four-layer Quantum-Blockchain Security Architecture (QBSA) designed for secure healthcare environments. The analysis further reveals significant challenges associated with lightweight PQC deployment for IoMT devices, interoperability standardization, quantum hardware limitations, and regulatory compliance in cross-institutional healthcare systems. The findings highlight the necessity of integrating quantum-resilient cryptographic frameworks with blockchain infrastructures to support the development of secure, scalable, and patient-centric next-generation e-health ecosystems.
Open access
Blockchain Technology Applications and Security
Cryptography and Data Security
Physical Unclonable Functions (PUFs) and Hardware Security
The Internet of Things (IoT) is expected to interconnect more than 75 billion devices worldwide, yet device authenticity remains one of the most pressing unsolved security challenges in the IoT space. Typical IoT nodes have limited computing power, memory, and battery capacity, making traditional public-key-based authentication difficult to implement without compromising either security or resource conservation. This paper presents a structured narrative review and quantitative comparison of lightweight authentication protocols for IoT environments published between 2024 and 2026, spanning seven families: Elliptic Curve Cryptography (ECC)-based, ECC for Radio Frequency Identification (RFID), hash-based, Physical Unclonable Function (PUF)-based, biometric and behavioural, blockchain-assisted, and machine-learning-augmented protocols. The review adds message-level protocol-flow comparisons for representative ECC- and PUF-based schemes, a benchmarking table of published latency, message-size, and energy indicators, and five sector-specific case studies. Reported findings include dynamic-credential ECC schemes reducing communication and computational overhead by more than 37% over prior ECC schemes; PUF-based techniques using machine learning to improve modelling-attack resistance by more than 35% over earlier techniques; blockchain-assisted authentication for fog-enabled IoT; and multi-sector schemes such as SELAP, reducing computation and communication cost to 422 ms and 960 bits respectively, against 548 ms and 2048 bits for the earlier ELWSCAS protocol. Protocols are also examined against ephemeral information leakage, modelling attacks on PUFs, node cloning, and physical tampering. No protocol category is universally optimal; selection depends on a deployment's constraints, threat model, and sector. Research is converging on hybrid designs combining hardware-rooted trust, efficient public-key primitives, decentralised trust, and intelligent anomaly detection.
Open access
2 source records
Physical Unclonable Functions (PUFs) and Hardware Security
We present an empirical performance evaluation of SILM, a national-scale music-royalty administration platform prototyped for LMKN, Indonesia's collective rights management agency, implemented as a chain of ten event-driven Go microservices connected through an in-memory publish/subscribe bus (Apache Kafka in the production blueprint). The study contributes a Dapper-style trace-per-event instrumentation yielding per-stage latency distributions, a five-point throughput sweep from 100 to 10,000 play events used to locate the operating point and the degradation knee, and a money-conservation and correctness suite. At every tested burst scale up to 10,000 events the pipeline delivers 100\% event delivery and exact money conservation, while median end-to-end (E2E) latency grows approximately 17-fold (0.81 s at 100 events to 13.7 s at 10,000 events); per-stage spans attribute 85.0\% of E2E average latency at the largest scale to a single cross-service queueing stage. A 30-second sustained-load soak at approximately 1,042 events/s exposes the single-consumer ceiling: the bounded subscriber queue overflows in its tail, dropping 7,097 of 31,255 submitted plays (22.7\%), the first measured reliability failure of the platform. All findings are compared against recent published results on tail latency, bottleneck attribution, and channel sizing in event-driven architectures.
Open access
Blockchain Technology Applications and Security
Physical Unclonable Functions (PUFs) and Hardware Security
With the transparency of the Ethereum platform, deployed smart contracts remain permanently public, exposing their virtual machine code to risks such as reverse engineering, control-flow analysis and malicious behavior identification. Although several obfuscation approaches for the EVM have been proposed, existing solutions often suffer from limited resistance against advanced analysis techniques, insufficient structural transformation capability or excessive execution overhead. In this work, we propose a novel obfuscation framework for EVM bytecode that enhances security by combining semantic-aware transformations with control-flow perturbation techniques. The proposed framework significantly increases structural complexity, hinders Control Flow Graph (CFG) recovery and alters discriminative virtual machine code characteristics while preserving the semantic correctness of smart contracts. Experimental results demonstrate that the proposed framework achieves a 100% obfuscation success rate with an average cyclomatic complexity of 90.80. Across all 15 evaluated transformation combinations, the framework introduces an overall mean virtual machine code size increase of 15.99% and a mean gas overhead of 7.04%. Notably, the complete multi-layer pipeline (T1+T2+T3+T4) exhibits overheads of 29.73% for virtual machine code size and 12.58% for gas, which remain acceptable considering the achieved robust resistance against reverse engineering and automated static analysis.
Open access
Advanced Malware Detection Techniques
Security and Verification in Computing
Physical Unclonable Functions (PUFs) and Hardware Security
The Prop Trust Verified Standard (PTVS) v1.0 Reference Architecture establishes the definitive technical specification, capability matrix, and implementation guidelines for the physical verification of tokenized Real-World Assets (RWAs) within the European regulatory framework. This document resolves the "Physical Oracle Gap" — the structural inability of Distributed Ledger Technology (DLT) systems to attest to the physical existence, structural integrity, and legal encumbrances of off-chain assets backing tokenized securities — through a deterministic four-pillar architecture: Pillar I — eIDAS 2.0 Qualified Forensic Audits: On-site inspections conducted by sworn judicial experts under Qualified Electronic Signatures (QES) per Regulation (EU) 2024/1183. Pillar II — SHA-256 Cryptographic Lineage: Canonical JSON serialization with deterministic hashing anchored in permanent registries. Pillar III — Smart Contract Circuit Breakers: The open-source PTVSClaimInjector.sol contract (MIT License) enforces automated protective actions based on PTVS Score. Pillar IV — PTCE Network: Decentralized network of Prop Trust Certified Experts with 85/15 revenue split. Institutional validation: Formal submissions to ESMA (FOI/ESMA/2026-001), EBA (FOI/EBA/2026-002), EIOPA (FOI/EIOPA/2026-003, confirmed & registered), and ECB/SSM (FOI/ECB-SSM/2026-004, ADITO portal) Application to INATBA RWA Working Group (FOI/INATBA/2026-005) Permanent registration at CERN/Zenodo, HAL/CNRS (hal-05713062v1), OSF (DOI: 10.17605/OSF.IO/7D2SJ), and U.S. Copyright Office (Cases 1-15210573311 & 1-15234961091) Open governance via the PTVS Technical Board (17 seats, W3C/ISO-inspired) Document scope: 17 pages covering architecture overview, PTVS Score methodology (0-100), Verifiable Claims lifecycle, ERC-3643/T-REX integration, regulatory alignment matrix (MiCA, Solvency II, Eurosystem, eIDAS 2.0), governance model, 20-capability prior art inventory, and comparative analysis vs. Chainlink, Proof of Reserve, IoT sensors, Big Four audits, and registry oracles. Lead Researcher: Aurelio Tamarit Blay, Certified Judicial Expert (Exp. No. 0161, Spain), ORCID: 0009-0007-5824-3602, Wikidata: Q140774713. Institutional motto: Veritas in Re · Certitudo in Code Canonical source: https://forensics-oracle.org/reference-architecture/
Open access
2 source records
Blockchain Technology Applications and Security
Digital and Cyber Forensics
Physical Unclonable Functions (PUFs) and Hardware Security
In the last few years, the Internet of Things (IoT) has grown significantly due to technological advancements. However, until recently, there has been no universal set of rules applicable to IoT security. This has opened an area for researchers. The IoT environment enables various smart devices to connect and exchange information; thus, ensuring the authenticity of devices in the IoT network is crucial. We have classified the diverse methods used to authenticate IoT devices to access the data they generate. This study conducted a systematic literature review to identify research gaps, recurring patterns, and potential future directions in IoT authentication, with particular attention to the architectures employed. This review analyzed different authentication techniques and presented their advantages and disadvantages using several criteria for categorization. This survey provides researchers and practitioners with a consolidated understanding of the current state of authentication mechanisms in the IoT. Furthermore, the survey examines emerging authentication paradigms, including blockchain-enabled authentication frameworks, machine-learning-augmented authentication models, and lightweight authentication schemes tailored for resource-constrained IoT devices. The goal of this survey is to aid in creating more robust and secure authentication solutions for the developing IoT by highlighting strengths, limitations, and emerging trends.
User Authentication and Security Systems
Advanced Authentication Protocols Security
Physical Unclonable Functions (PUFs) and Hardware Security
MRS‑AUTH is a novel authentication framework that achieves deniability even against an active verifier who may adaptively query candidate credentials both before and after receiving a challenge. Unlike ring signatures or zero‑knowledge proofs – where the prover holds a single secret witness that can be extracted under coercion – MRS‑AUTH exploits the multiplicative structure of linear Diophantine equations. Through recursive decomposition, it generates a Diophantine forest of exponentially many syntactically valid credential chains. The authentic chain is sampled uniformly from this forest and committed together with k‑1 indistinguishable aliases using a fixed‑shape Merkle tree with dummy leaves, eliminating structure‑ and length‑based side‑channel leakage. The Forest Symmetry Theorem proves that all chains are structurally information‑theoretically indistinguishable. However, the full index‑anonymity against an active verifier is computational and bounded in Theorem 6.6 by k · ε_SHA3 + ε_coll + negl(λ). For cryptographic scales N ∼ 10⁴², the Ehrhart‑based continuous‑volume approximation yields an effective entropy exceeding 371 bits, with a statistical distance to the perfect uniform distribution of Δ ≤ 2⁻¹³⁵ – well below the 128‑bit security threshold. Empirical validation via exact enumeration and a chi‑squared test (χ²/dof ≈ 0.985) confirms the uniformity. A constant‑time Rust implementation, leveraging the subtle and zeroize crates, exhibits an execution time of approximately 0.12 ms across four orders of magnitude of N, demonstrating practical deployability. The work also formalises the Active Verifier Game model, a new adversarial definition that quantitatively captures coercion resistance in a post‑quantum setting.
Open access
2 source records
Cryptography and Data Security
Physical Unclonable Functions (PUFs) and Hardware Security
The subject matter of the article is the cryptographic integrity of digital authentication systems facing quantum computing threats, specifically focusing on post-quantum alternatives and efficient authenticated data structures. The goal is to design and formally analyze VERKLE-FRI—a hybrid architecture synthesizing Verkle tree proof-size reduction with FRI-based quantum-resistant commitments, establishing a scalable, stateless, and quantum-secure framework. The tasks are: analyze limitations of hash-based signatures and Merkle trees; evaluate polynomial commitment schemes (KZG, Bulletproofs, FRI, lattice-based); propose a hybrid Verkle-FRI design; develop a formal security proof against classical and quantum adversaries; execute complexity analysis with concrete implementation parameters. The methods used are: theoretical cryptographic analysis, formal security modeling via reductionist proofs, algebraic methods over finite fields, polynomial interpolation, random oracle model, FRI protocol with DEEP-FRI optimization, Merkle trees, vector commitments, and asymptotic complexity analysis. The following results were achieved: a novel architecture where Verkle node vectors are polynomial-encoded, committed via Merkle trees over FRI codewords, and verified through FRI with out-of-domain sampling. A formal proof establishes λ-bit quantum security using 2λ-bit hash functions. Complexity yields proof size O(λ log² N), prover time O(λ N log N), and verifier time O(λ log N). Concrete 128-bit quantum parameters include SHA3-512, field size ≈2²⁵⁵, branching factor 256, and 128 FRI rounds, achieving soundness error ≤2⁻¹²⁷. For a concrete benchmark authenticating 2²⁶ elements, a traditional Merkle proof requires ≈0.8 KB, whereas our VERKLE-FRI proof requires ≈180 KB. While larger, this provides quantum resistance and eliminates the trusted setup, a critical trade-off for long-term security. Conclusions. Scientific novelty consists in: 1) the first hybrid Verkle-FRI architecture replacing pairing-based assumptions with hash-based proximity testing; 2) a formal security proof reducing security to hash collision resistance and FRI soundness; 3) quantified efficiency-security trade-offs; 4) a viable pathway for quantum-resistant infrastructure in blockchains, software distribution, and government communications.
Open access
Cryptographic Implementations and Security
Cryptography and Data Security
Physical Unclonable Functions (PUFs) and Hardware Security
This paper presents a threshold-cryptographic architecture for reducing the risk of premature leakage of digital examination papers during the interval between question-paper finalization and examination administration. The proposed design separates the data path from the control path. Examination content is encrypted using a fresh AES-256-GCM key, while the key is protected through envelope encryption under a key-release service. The capability to release that key is distributed using (k,n)-Shamir secret sharing across independent custodians, preventing any single custodian from unilaterally authorizing early release. At the scheduled release time, a quorum-based time authority provides an independently attested timestamp. Once the required time quorum and custodian threshold are satisfied, the key-release service reconstructs its private key within an HSM boundary, unwraps the examination key, and derives recipient-specific keys for individual examination centers. These keys are separately wrapped under each center's registered public key, limiting the impact of a compromise at any single examination center. The paper presents an actor and trust model, an explicit adversary model, a step-by-step release protocol, a threat-to-control security analysis, and a qualitative comparison with physical custody, blockchain-anchored distribution, and time-lock-puzzle-based timed-release cryptography. It also explicitly discusses residual risks, including custodian collusion, post-decryption optical or physical exfiltration, hardware and supply-chain trust, and compromise of the time-authority quorum. The architecture is presented as a research design rather than a claim of unconditional leak prevention. Future work includes implementing a prototype, evaluating quantitative performance, replacing reconstruct-and-zeroize key handling with threshold decryption, evaluating post-quantum key-encapsulation mechanisms, and conducting a formal mechanized security proof.
Open access
2 source records
Chaos-based Image/Signal Encryption
Physical Unclonable Functions (PUFs) and Hardware Security
Function-hiding functional commitment schemes allow one party to commit to a private function f and later prove f(x)=y for public x and y without revealing additional information about the function. We construct efficient function-hiding functional commitment schemes for arithmetic circuits of bounded size that achieve proof sizes below 1.6 kB—over an order of magnitude smaller than previous constructions—while simultaneously reducing proving and verification times. We achieve these results by introducing a novel information-theoretic interactive proof system called Polynomial Interactive Oracle Proofs with Randomized Indexer (rPHPs). By compiling rPHPs with commit-and-prove zkSNARKs, we are able to leverage relaxed zero-knowledge notions for our building blocks. This approach eliminates the overhead of strict privacy requirements of prior work, directly translating into improved efficiency in both communication and computation.
Open access
Cryptography and Data Security
Complexity and Algorithms in Graphs
Physical Unclonable Functions (PUFs) and Hardware Security