Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

65 papersLast indexed Aug 31, 2026
Search papers

Paper index

65 results · page 1 of 3

Clear filters
Aug 28, 2026·Lirias
0 cites
Strategische benaderingen voor latentieoptimalisatie en anonimiteitverbetering in mixnetwerken

Mahdi Rahimi

Today's scale of online activity exposes users to significant privacy risks. A widely adopted safeguard is encryption, which conceals the content of shared data from network intermediaries. However, content protection alone is insufficient. In particular, every digital exchange also generates metadata—such as the sender and recipient of the transmitted data, timestamps, traffic volume, and other contextual information—which constitutes a substantial source of privacy leakage. When collected and analyzed, this metadata can reveal online behavior, social network structures, and other sensitive patterns. To mitigate these risks, anonymous communication systems have been developed under various design paradigms. Among such systems, mix networks (mixnets) remain one of the strongest approaches for limiting metadata leakage. A mixnet operates as an overlay network in which users do not send data directly to recipients. Instead, traffic is routed through a sequence of intermediaries called mixnodes. Each mixnode applies a cryptographic transformation to incoming packets, mixes them with traffic from other users by reordering them, and subsequently forwards them to the next hop. Through layered encryption and probabilistic mixing at every hop, communication metadata becomes unlinkable from its origin—potentially preventing privacy breaches even against a global passive network adversary capable of observing all Internet communication exchanges. Despite their strong privacy guarantees, current mixnet designs face both practical and security limitations. Firstly, mixnets incur substantial latency overhead. In particular, each user communication packet must traverse multiple intermediaries rather than being delivered directly to its recipient, and every mixnode introduces additional delay when forwarding packets due to mixing operations. As a result, mixnets remain primarily suitable for latency-tolerant services such as email, file sharing, or cryptocurrency transactions, while their applicability to latency-sensitive applications—such as web browsing, instant messaging, or live streaming—remains limited. This limitation discourages broader adoption and ultimately reduces the size of the user base, thereby weakening the effective privacy guarantees provided by the system. Accordingly, one major objective of this thesis is to address these latency challenges by introducing protocols for mixnet node arrangement and selection of intermediate mixnodes, together with novel anonymity metrics for rigorous evaluation. At a high level, we design mechanisms that (i) arrange the mixnet such that the probability of forming communication paths composed of latency-proximate mixnodes increases; (ii) enable routing algorithms that prioritize such low-latency paths; and (iii) implement load-balancing mechanisms to ensure that mixnodes handle approximately equal traffic volumes. Through comprehensive simulations and empirical assessments, we show that one of our proposed approaches reduces mixnet latency by up to 9X compared to a baseline configuration, while incurring an anonymity loss of no more than 10%. Secondly, a distinct practical security challenge in mixnets concerns long-term exposure to compromised mixnodes. In typical mixnet deployments, each communication packet is assigned an independently and uniformly random path composed of intermediate mixnodes. While this approach increases mixing diversity and limits correlations between packets within a session—thereby reducing the advantage of a global network adversary—it simultaneously increases the probability that, over time, at least one packet traverses a path consisting entirely of adversarial mixnodes. Once such an event occurs, an adversary controlling those nodes can deanonymize the corresponding communication session by revealing the relationship between source and destination. Specifically, our analysis indicates that compromising only 10-15% of mixnodes may suffice to achieve full deanonymization once the exchanged data volume exceeds approximately 4-30 MB (e.g., sharing an image online) under current mixnet deployments. To address this vulnerability, the second objective of this thesis is to introduce a set of path selection techniques that balance resistance to global adversaries with long-term resilience against compromised mixnodes. Through theoretical analysis, empirical measurements, and extensive simulations, we demonstrate that our proposals reduce vulnerability to compromised mixnodes by up to 85%, while introducing only a marginal increase in the advantage of a global adversary. Collectively, these results show that our approaches enhance both the practicality and the security of mixnets for today's Internet services.

Internet Traffic Analysis and Secure E-voting
Cryptography and Data Security
IPv6, Mobility, Handover, Networks, Security
Original source
May 28, 2026·arXiv (Cornell University)
0 cites
FIDEM: A Standard-Compliant Framework for Secure Binding of MUD Profiles to IoT Devices

Alessandro Lotto, Savio Sciancalepore, Alessandro Brighente, Mauro Conti

The Manufacturer Usage Description (MUD) standard enables enforcement of network restrictions for IoT devices based on their expected network traffic, as specified by manufacturers in an online MUD file. Devices advertise a URL pointing to this file, yet the standard does not define how to securely bind the issuing device to its profile. As a result, malicious devices can manipulate network policy enforcement by advertising valid URLs referencing genuine MUD profiles, but not intended for that device. Although MUD defines a certificate-based secure issuance method, current deployments rely on the insecure DHCP-based extension due to simpler integration. Existing solutions either depend on Public Key Infrastructure (PKI), break standard compliance, require excessive active manufacturer involvement, or overlook secure profile updates. In this paper, we present FIDEM, a standard-compliant framework for securing DHCP-based MUD URL issuance. FIDEM provides cryptographic binding between IoT devices and their MUD profiles by leveraging Zero-Knowledge-Proof authentication, eliminating PKI reliance, minimizing manufacturers' involvement, and supporting secure profile updates. Formal analysis shows that FIDEM withstands stronger adversaries than in prior work, including supply-chain compromise and attacks using legitimate devices as cryptographic oracles. Our real-world evaluation on two reference constrained devices (ESP32-S3 and ESP32-C6) demonstrates minimal overhead compared to standard DHCP (approximately 5ms and 20mJ) and significant improvements over certificate-based benchmarks (approximately x20 faster, and 35% less energy).

Open access
3 source records
cs.CR
IPv6, Mobility, Handover, Networks, Security
Security and Verification in Computing
Original source
Apr 22, 2026·IEEE Internet of Things Journal
0 cites
OBIA: A Distributed Multiauthority Service Identity Authentication Scheme for Online Banking

S F Wang, Yifan Liu, Fan Feng, Yi Liu · 5 authors

Existing online banking identity authentication protocols typically rely on centralized authorization centers or trusted third parties, which can lead to single points of failure, key escrow risks, and privacy leaks. Addressing multi-party collaboration scenarios under a trustless assumption, this paper proposes an Overseen-by-Multiple-Authorities Identity Authentication (OBIA) scheme tailored for electronic banking environments. This solution integrates attribute-based cryptography with distributed key generation (DKG) mechanisms across multiple authorization centers. Users derive complete personal keys from attribute-based private keys embedded with random factors, enabling implicit binding of identity and attributes. To support dynamic attribute changes and permission revocation, a hierarchical time-driven key update mechanism is designed. Combined with non-interactive zero-knowledge proofs (NIZK) and elliptic curve cryptography (ECC), this enables efficient, privacy-preserving authentication. At the data storage layer, an optimized multi-layer Merkle hash tree (MMHT) structure reduces blockchain storage and verification overhead. Security analysis demonstrates that the proposed scheme effectively resists forgery, replay, man-in-the-middle, and key compromise attacks. Experimental results show that compared to existing multi-authorization authentication schemes, this approach exhibits superior or comparable computational and communication overhead while significantly enhancing the system’s decentralization and auditability.

Access Control and Trust
IPv6, Mobility, Handover, Networks, Security
Advanced Authentication Protocols Security
Original source
Apr 10, 2026·2026 International Conference on Current Research in Artificial Intelligence and Data Science (ICCRAIDS)
0 cites
Decentralized Radio Access Network Virtualization via Distributed Ledger Technology

Ahmed Sarwar Mohammed

This paper explores the application of distributed ledger technology to facilitate dynamic resource allocation in virtualized radio access networks (RANs). A novel architecture is presented that leverages blockchain to automate the exchange of network functions among diverse stakeholders. This approach addresses challenges related to trust and scalability in open RAN environments, enabling autonomous and secure sharing of infrastructure resources. The proposed system employs auction-based mechanisms and network virtualization to allow entities to transact RAN resources, such as virtual network functions (VNFs), in a decentralized manner. Simulation results demonstrate the potential of this framework to enhance flexibility and efficiency in next-generation mobile networks.

Software-Defined Networks and 5G
Network Traffic and Congestion Control
IPv6, Mobility, Handover, Networks, Security
Original source
Feb 11, 2026·Proceedings of NAS RA Technical sciences
0 cites
CENSORSHIP RESISTANCE IN WEB3 ACCESS LAYERS: AN ENGINEERING PERSPECTIVE ON INDEPENDENT RENDERING GATEWAYS

A.SH. HARUTYUNYAN

Censorship resistance is a core value of Web3, yet practical access to decentralized websites remains dependent on centralized gateways such as ipfs.io, .link, and .limo, which are susceptible to regulatory takedowns and availability limitations. This paper investigates the technical barriers to truly censorship-resistant access in decentralized web architectures and presents an engineering-driven analysis of dweb3.wtf, a dedicated rendering gateway developed within the Web3Compass infrastructure. The system directly interfaces with decentralized name systems such as ENS and Unstoppable Domains, autonomously resolves content hashes via on-chain resolvers, and renders the associated IPFS-hosted sites via self-hosted infrastructure. By eliminating reliance on third-party APIs and centralized frontends, the gateway offers a robust alternative to Web2-style intermediaries. This paper presents the architecture, implementation, and performance characteristics of dweb3.wtf, evaluating its effectiveness in ensuring access continuity, domain coverage, and reduced external dependency.

Open access
IPv6, Mobility, Handover, Networks, Security
Peer-to-Peer Network Technologies
Access Control and Trust
Original source
Feb 6, 2026·Electronics
1 cites
Cross-Border Digital Identity System Based on Ethereum Layer 2 Architecture

Yu-Heng Hsieh, Ching-Hsi Tseng, Bang-Yi Luo, Shyan-Ming Yuan

Modern passport systems face significant challenges in secure data sharing, real-time verification, and user-controlled authorization, particularly in cross-border scenarios. Existing digital passport solutions, often built on permissioned blockchains, suffer from limited transparency, scalability, and high operational costs. This paper proposes a decentralized passport management system based on an Ethereum Layer 2 architecture that combines global governance with high-throughput and cost-efficient passport operations. The system adopts a hybrid design in which a Global Passport Registry smart contract is deployed on the Ethereum mainnet for cross-country coordination, while passport issuance, access control, and identity management are handled on Layer 2 networks through country-operated Passport Managers and user-specific Personal Passport smart contracts. Extensive performance evaluations show that Ethereum Layer 1 throughput saturates at approximately 40–50 transactions per second (TPS), whereas the proposed Layer 2 deployment consistently exceeds 150 TPS and reaches up to 300 TPS under higher-performance environments, significantly surpassing the estimated system requirement of 70 TPS. These improvements result in faster response times, reduced congestion, and substantially lower transaction costs, demonstrating that public Ethereum Layer 2 infrastructures can effectively support a scalable, self-sovereign, privacy-preserving, and globally verifiable digital passport system suitable for real-world deployment.

Open access
Advanced Authentication Protocols Security
IPv6, Mobility, Handover, Networks, Security
Network Traffic and Congestion Control
Original source
Jan 1, 2026·Repository of Vinnytsia National Technical University (Vinnytsia National Technical University)
0 cites
Підвищення безпеки веб-застосунків шляхом інтеграції доказів з нульовим розголошенням zk-SNARK у протокол TLS 1.3

С. Ю. Волинець, O.V. Saliieva, О. Saliieva

This paper analyzes the shortcomings of traditional authentication mechanisms in web applications operating over the secure TLS 1.3 protocol. It is established that even with an encrypted channel, the transmission of secret data (passwords, tokens) remains a primary attack vector. An improved protocol is proposed that integrates an authentication mechanism based on zero-knowledge proofs (zk-SNARK) immediately after session establishment via Elliptic Curve Diffie-Hellman (ECDHE) key exchange. This approach completely eliminates the transmission of client credentials, significantly increasing resistance to phishing and server database compromises.

Open access
Advanced Authentication Protocols Security
Cryptography and Data Security
IPv6, Mobility, Handover, Networks, Security
Original source
Jan 1, 2026·SSRN Electronic Journal
0 cites
OrioChain: A Decentralized Document Verification Framework Integrating Ethereum Smart Contracts, IPFS, and SHA-256 Cryptographic Hashing

Kunal Tailor

Centralized document authentication infrastructures are inherently susceptible to insider manipulation, single-point-of-failure outages, and operationally slow manual verification workflows. This paper introduces OrioChain, a production-deployed, decentralized verification framework that addresses these architectural weaknesses by combining Ethereum smart contracts, InterPlanetary File System (IPFS) storage, and SHA-256 cryptographic fingerprinting. The system enforces a three-tier rolebased access control (RBAC) hierarchy-comprising Admin, Exporter, and Public roles-exclusively through on-chain Solidity logic, with no reliance on off-chain middleware. Document content is hashed locally within the client browser prior to any network transmission; only the resulting 32-byte fingerprint is persisted to the Ethereum Sepolia blockchain, while the source file is stored on IPFS via Infura and Pinata. This hybrid architecture reduces on-chain gas expenditure by roughly 80 percent relative to storing full document content on-chain. Public verification requires neither a cryptocurrency wallet nor any gas expenditure, and consistently completes in under two seconds with 100 percent hash-match accuracy across all experimental trials. QR code generation at the point of registration enables smartphone-based instant verification for non-technical end users. A structured comparison against nine contemporaneous systems confirms that OrioChain is the sole evaluated implementation that simultaneously delivers gasless public verification, three-tier on-chain RBAC, QR-driven access, and soft-deletion with a preserved immutable audit trail. The architecture supports future migration to Layer-2 networks and is designed for eventual conformance with W3C Decentralized Identifier (DID) and Verifiable Credential (VC) standards.

Open access
Blockchain Technology Applications and Security
IPv6, Mobility, Handover, Networks, Security
Cryptography and Data Security
Original source
Jan 1, 2026·Brno University of Technology Digital Library (Brno University of Technology)
0 cites
Integrating zkLogin for Seamless Web2-to-Web3 Authentication in a Web3 Application

Daniil Kniazkin

Tato práce se zabývá integrací protokolu zkLogin do aplikace Web3, aby se uživatel mohl přihlásit pomocí účtu OpenID Connect místo správy seed phrase. Práce vysvětluje princip zkLogin, porovnává jej s jinými přístupy k autentizaci ve Web3 a implementuje prototyp pro Sui a Ethereum. Větev pro Sui používá nativní podporu zkLogin, zatímco větev pro Ethereum používá Groth16 důkaz, chytrý účet, registr JWK a ERC-4337. Jednoduchý lending scénář ověřuje opakované změny on-chain stavu po přihlášení. Výsledky ukazují, že zkLogin může zjednodušit onboarding a omezit přímé zveřejnění vazby mezi účtem Web2 a on-chain adresou, ale prototyp stále závisí na poskytovateli identity, salt service, proving infrastruktuře a správě veřejných klíčů.

Open access
Web Application Security Vulnerabilities
IPv6, Mobility, Handover, Networks, Security
Web and Library Services
Original source
Nov 18, 2025·2025 7th Conference on Blockchain Research & Applications for Innovative Networks and Services (BRAINS)
1 cites
Towards Next Generation Domain Services: A Committee based Privacy Scheme leveraging Move on IOTA

Antonino Iaria, Mirko Zichichi, Vittorio Ghini, Stefano Ferretti

The inherent complexity of cryptographic addresses in Web3 ecosystems poses significant usability problems. Decentralized Domain Services attempt to solve this challenge yet, in the meantime, jeopardize users’ pseudo-anonymity. This paper investigates the design and implementation of a decentralized naming system leveraging IOTA’s Move smart contract framework. We analyze the system architecture and provide a comparative evaluation against established domain name services such as ENS, SuiNS, SolanaNS, and Avvy, highlighting the unique advantages and limitations of our proposed solution. Moreover, we introduce a novel committee-bridge architecture managing off-chain hashed name storage, enabling selective disclosure of domain information while maintaining low computational overhead. We also present results from an evaluation that assesses the functioning and the performance of the system, which confirm the viability of the proposal.

Cryptography and Data Security
IPv6, Mobility, Handover, Networks, Security
Caching and Content Delivery
Original source
Oct 30, 2025·Ad Hoc Networks
2 cites
MobiAuth: Blockchain-driven decentralized authentication for enhanced security and privacy in mobile networks

Narendra Kumar Dewangan, Gauri Shankar

Decentralized authentication in dynamic mobile networks faces significant challenges due to high node mobility, resource constraints, and vulnerabilities to side-channel attacks. In this work, we present MobiAuth , a blockchain-driven framework based on Hyperledger Iroha and OMNET ++ that enables secure, peer-to-peer authentication using compact Ed25519 signatures and ephemeral session keys. Our protocol eliminates single points of failure by distributing trust across a permissioned ledger and employs constant-time cryptographic operations to thwart timing and power-analysis attacks. We validate MobiAuth through co-simulation in OMNET ++ integrated with Iroha via a Python gRPC bridge and benchmark its performance with Hyperledger Caliper. Simulation yields 95% packet delivery with an authentication latency ranging from 12 ms in the only OMNeT ++ and baseline to 20–150ms in the full ledger-integrated system, and a ledger write throughput of 250tps. Comparative experiments demonstrate a 33% reduction in communication overhead and robust operation under random Control Point failures and Byzantine Access Node behavior. Analysis of on-device ledger synchronization further highlights practical storage growth and bandwidth requirements for long-term deployment. These results indicate that MobiAuth achieves strong security and privacy with modest energy impact, scalable performance, and compatibility with mobile devices in real-world network environments. • Vulnerabilities of mobile network devices in a dynamic environment. • Blockchain-based automatic authentication for mobile devices. • Enhanced security and privacy with Ed25519 curve cryptography. • OMNET++ simulation on Hyperledger Iroha for mobile network. • Protocol verification using Scyther for testing security protocol strength.

Open access
Advanced Authentication Protocols Security
IPv6, Mobility, Handover, Networks, Security
IoT and Edge/Fog Computing
Original source
Oct 10, 2025
1 cites
Poster: EMDns: Advancing Security and Privacy in Domain Name Resolution

Pengfei Yue, Jie Ji, Qing Li

This paper presents EMDns, a domain name system based on Ethereum and MongoDB, addressing the centralization, security weaknesses, and privacy issues of the Domain Name System (DNS). EMDns enables automated and decentralized domain management to eliminate SPOF and authority dependence, while resolution is performed via local look-ups with hash comparison to protect privacy against deanonymization attacks. Experimental results show that EMDns maintains resolution efficiency while significantly enhancing security and privacy.

IPv6, Mobility, Handover, Networks, Security
Caching and Content Delivery
Web Application Security Vulnerabilities
Original source
Sep 30, 2025·한국통신학회논문지
0 cites
A Credit Card Based NFT Purchase DApp for Seamless Web3

Kanan Bayramov, Seung Hyun Jeon

There have existed transaction and connection difficulties between Web 2.0 and Web3 for a long time. Seamless Web3 has played a significant role to reduce the complexity of Web3 and the gap between Web2.0 and Web3. We propose a seamless Web3 based decentralized application (DApp) for non-fungible token (NFT) purchase by using credit cards. The proposed seamless Web3 DApp has been tested in an iOS system and shows positive results. The main goal is to connect Web 2.0 users purchase and store NFT within the DApp, without interacting with the complicated blockchain ecosystem such a wallet address, cryptocurrency or a crypto exchange account.

IPv6, Mobility, Handover, Networks, Security
Advanced Authentication Protocols Security
Blockchain Technology Applications and Security
Original source
Aug 4, 2025·IEEE Transactions on Intelligent Transportation Systems
3 cites
BCDAP-DGS: Dynamic Group Signature and Batch Cross-Domain Authentication Protocol for Intelligent Transportation

Chuanda Cai, Changgen Peng, Youliang Tian, Weijie Tan · 6 authors

The Internet of Vehicles (IoV), as a core component of intelligent transportation systems, significantly enhances the intelligence level of traffic management by enabling efficient vehicle-to-vehicle (V2V) and vehicle-to-infrastructure information sharing. However, the highly dynamic and open nature of the IoV poses severe security challenges in cross-domain scenarios, mainly due to the lack of trust relationships between different domains, making it difficult to achieve efficient and secure cross-domain authentication(CDA). Existing CDA mechanisms in the IoT context often suffer from high computational complexity, excessive communication overhead, and poor scalability for large-scale deployments. This paper proposes a Batch CDA Protocol based on Dynamic Group Signatures (BCDAP-DGS) to address these issues. The proposed protocol incorporates non-interactive zero-knowledge (NIZK) proofs to achieve secure identity verification without requiring additional data exchange. By leveraging dynamic group signature techniques, BCDAP-DGS supports real-time updates of vehicle membership status and provides conditional anonymity. In addition, an online/offline authentication framework is designed by incorporating vehicle location information to precompute related parameters, thereby significantly improving CDA efficiency. A formal security analysis is conducted under the random oracle model, demonstrating that the proposed protocol satisfies essential security properties, including anonymity, non-frameability, unforgeability, and traceability. Experimental results and performance comparisons show that the proposed protocol outperforms existing schemes in terms of both security and efficiency, making it well-suited for large-scale and highly dynamic IoV CDA scenarios.

Advanced Authentication Protocols Security
IPv6, Mobility, Handover, Networks, Security
Security in Wireless Sensor Networks
Original source
Jul 11, 2025·2025 2nd International Conference on New Frontiers in Communication, Automation, Management and Security (ICCAMS)
0 cites
Web3 DNS System with PoR, Rate Limiting, and Attack Simulation

V. Hemamalini, R. Jagathrajah, K. Annapurani Panaiyappan

The Domain Name System (DNS) is an indispensable part of the internet’s infrastructure, allowing humans to enter human readable domain names into a computer and the computer will translate it to machine readable IP addresses. However, both the traditional DNS systems have several security, privacy, and scalability issues because of the centralized nature. This paper describes the design and implementation of a Web3 decentralized DNS system on top of the blockchain technology based on Ethereum smart contracts. The Web3 DNS system distributes domain registration, resolution and management in a way that is transparent and unbreakably secured, scalable and insanely fast. It’s a system with integrated criticals such as Proof of Request (PoR) for logging all actions and rate limiting to stop abusing the system. In this paper we explore the root components of the Web3 DNS system such as: domain management via a smart contract, PoR logging and rate limiting. This Web3 DNS is tested with the performance tests and compared to the traditional DNS systems for the handling of domain related transactions with improved security and decentralization. Furthermore, blockchain usage in the system leads to the immutable and transparent record of all actions, decreasing the danger of DNS hijacking and other evil activities. This work tries to bring a robust, transparent and censorship resistant alternative to existing DNS infrastructures. Future work will attempt to scale the system and enhance the capability of interoperating with existing, legacy DNS infrastructure.

IPv6, Mobility, Handover, Networks, Security
Caching and Content Delivery
Network Security and Intrusion Detection
Original source
Jun 12, 2025·Electronics
1 cites
STALE: A Scalable and Secure Trans-Border Authentication Scheme Leveraging Email and ECDH Key Exchange

Jiexin Zheng, Mudi Xu, Jianqing Li, Benfeng Chen · 11 authors

In trans-border data (data transferred or accessed across national jurisdictions) exchange scenarios, identity authentication mechanisms serve as critical components for ensuring data security and privacy protection, with their effectiveness directly impacting the compliance and reliability of transnational operations. However, existing identity authentication systems face multiple challenges in trans-border contexts. Firstly, the transnational transfer of identity data struggles to meet the varying data-compliance requirements across different jurisdictions. Secondly, centralized authentication architectures exhibit vulnerabilities in trust chains, where single points of failure may lead to systemic risks. Thirdly, the inefficiency of certificate verification in traditional Public Key Infrastructure (PKI) systems fails to meet the real-time response demands of globalized business operations. These limitations severely constrain real-time identity verification in international business scenarios. To address these issues, this study proposes a trans-border distributed certificate-free identity authentication framework (STALE). The methodology adopts three key innovations. Firstly, it utilizes email addresses as unique user identifiers combined with a Certificateless Public Key Cryptography (CL-PKC) system for key distribution, eliminating both single-point dependency on traditional Certificate Authorities (CAs) and the key escrow issues inherent in Identity-Based Cryptography (IBC). Secondly, an enhanced Elliptic Curve Diffie–Hellman (ECDH) key-exchange protocol is introduced, employing forward-secure session key negotiation to significantly improve communication security in trans-border network environments. Finally, a distributed identity ledger is implemented, using the FISCO BCOS blockchain, enabling decentralized storage and verification of identity information while ensuring data immutability, full traceability, and General Data Protection Regulation (GDPR) compliance. Our experimental results demonstrate that the proposed method exhibits significant advantages in authentication efficiency, communication overhead, and computational cost compared to existing solutions.

Open access
Cryptography and Data Security
Advanced Authentication Protocols Security
IPv6, Mobility, Handover, Networks, Security
Original source
Jun 6, 2025·IEEE Transactions on Parallel and Distributed Systems
0 cites
Everything Distributed and Asynchronous: A Practical System for Key Management Service

Zhaoyang Xie, Haibin Zhang, Sisi Duan, Chao Liu · 11 authors

A key management service (KMS) is vital to modern mission-critical systems. At the core of KMS are the key generation process and the key refresh process. In this paper, we design and implement a purely asynchronous system for completely distributed KMS supporting traditional applications such as threshold cryptosystems and multiparty computation (MPC) as well as emerging blockchains and Web3 applications. In this system, we have built a number of new asynchronous distributed key generation (ADKG) protocols and their corresponding asynchronous distributed key refresh (ADKR) protocols. We have demonstrated that our ADKG and ADKR protocols in the standard model outperform existing ones of the same kind, while our protocols in the random oracle model (ROM) are more efficient than other protocols with small and medium-sized networks.

Information and Cyber Security
Cloud Data Security Solutions
IPv6, Mobility, Handover, Networks, Security
Original source
Jun 4, 2025·Romanian Cyber Security Journal
1 cites
Cybersecurity Challenges in Managing Domain Names. From DNS to ENS in the Web3 Era

Adrian Victor VEVERA, Andreea Cătălina CRĂCIUN, Mihail Dumitrache, Ionut SANDU · 6 authors

The Domain Name System (DNS) remains a foundational component of the Internet infrastructure, which is frequently exploited by cybercriminals through increasingly diverse and sophisticated attack vectors.This paper explores the evolving cybersecurity challenges faced by domain name systems (DNSs) and their decentralized counterparts in the Web3 ecosystem, particularly the Ethereum Name Service (ENS), as such, it surveys both the established and novel attack patterns.Furthermore, it explores the implications of decentralized naming systems like the ENS, which introduced novel cybersecurity challenges within the Web3 environments and it highlights the future risks and possible research directions related to the transition to decentralized web services.This study provides a comparative analysis of the cyberattacks targeting the DNS and the ENS, highlighting the evolving threat landscape for each of the two ecosystems.By examining the architectural differences between the DNS and ENS, their common attack vectors, and their security mechanisms, it underscores both the distinct vulnerabilities inherent to each ecosystem and the overlapping risks they share.

Open access
Network Security and Intrusion Detection
IPv6, Mobility, Handover, Networks, Security
Original source
May 22, 2025·Apple Academic Press eBooks
3 cites
Enhancing Network Security with Zero-Trust Principles and Anonymous Identity Authentication

R. N. Kulkarni, Chetna Kaushal, Ismail Keshta, Mukesh Soni · 5 authors

As a prime exemplar of the Internet of Things (IoT), the vehicle-to-vehicle network assumes a pivotal position in the realm of intelligent transportation. It provides various online services for vehicles and reduces the risk of accidents for drivers. However, during communication, the vehicle-to-vehicle network generates sensitive information, such as vehicle location and routes. Enhancing the anonymity of vehicle identities in secure services is a research interest in vehicle-to-vehicle network security, especially in Zero Trust network security. This article introduces an anonymous identity authentication scheme based on batch verification algorithms, leveraging the principles of Zero Trust security. It expands the scope of anonymous authentication methods for IEEE WAVE security services by incorporating techniques such as anonymous credentials and zero-knowledge proofs, in accordance with the tenets of the Zero Trust model. Furthermore, it offers a mechanism for identity recovery via a trusted third party, thereby establishing a holistic 186 security framework. Experimental results indicate that when the number of signatures for batch verification exceeds 11, the computational cost of the proposed scheme is more efficient than some comparative schemes. Based on this, the article suggests the optimal cycle for batch verification in the DSRC’s BSM and vehicle proximity payment applications while maintaining a zero-trust security posture.

Internet Traffic Analysis and Secure E-voting
Network Security and Intrusion Detection
IPv6, Mobility, Handover, Networks, Security
Original source
May 12, 2025·arXiv (Cornell University)
0 cites
Routing Attacks in Ethereum PoS: A Systematic Exploration

Constantine Doumanidis, Maria Apostolaki

With the promise of greater decentralization and sustainability, Ethereum transitioned from a Proof-of-Work (PoW) to a Proof-of-Stake (PoS) consensus mechanism. The new consensus protocol introduces novel vulnerabilities that warrant further investigation. The goal of this paper is to investigate the security of Ethereum's PoS system from an Internet routing perspective. To this end, this paper makes two contributions: First, we devise a novel framework for inferring the distribution of validators on the Internet without disturbing the real network. Second, we introduce a class of network-level attacks on Ethereum's PoS system that jointly exploit Internet routing vulnerabilities with the protocol's reward and penalty mechanisms. We describe two representative attacks: StakeBleed, where the attacker triggers an inactivity leak, halting block finality and causing financial losses for all validators; and KnockBlock, where the attacker increases her expected MEV gains by preventing targeted blocks from being included in the chain. We find that both attacks are practical and effective. An attacker executing StakeBleed can inflict losses of almost 300 ETH in just 2 hours by hijacking as few as 30 IP prefixes. An attacker implementing KnockBlock could increase their MEV expected gains by 44.5% while hijacking a single prefix for less than 2 minutes. Our paper serves as a call to action for validators to reinforce their Internet routing infrastructure and for the Ethereum P2P protocol to implement stronger mechanisms to conceal validator locations.

Open access
2 source records
IPv6, Mobility, Handover, Networks, Security
Network Traffic and Congestion Control
Security and Verification in Computing
Original source
Apr 27, 2025·Blockchain Research and Applications
3 cites
Distributed Ledgers and Security Mechanisms on Radio Access Networks: A Systematic Review

Daniel Hindemburg de Miranda Marques, Dalton Cézane Gomes Valadares

5G is the most recent technology standard for cellular networks, and one of its key elements is the Radio Access Networks (RAN), which furthers the enabling of the 5G basic capabilities: enhanced Mobile Broadband (eMBB), Massive Machine-Type Communication (mMTC), and Ultra-Reliable, Low-Latency Communication (URLLC). To meet the capabilities required by 5G use cases, 5G is distributed, virtualized, and architecturally more complex than previous generations. These capabilities bring benefits but introduce risks and security challenges that must be addressed through controls designed to support and secure 5G services across any operator cloud. Therefore, this paper focuses on studying and evaluating security mechanisms used in RANs. Special attention is given to Distributed Ledger Technologies (DLTs) since they are one of the most studied topics regarding security enhancement. DLTs could bring advantages for improving network security through encryption to protect the information and automate verification and execution of transactions. For this reason, we carried out a systematic review, extracting and analyzing data from 39 papers from 2010 to 2023. Our main results list RAN-related susceptible security dimensions, vulnerabilities, and possible attacks and threats. We also show how DLTs can enhance RANs and present other considered mechanisms to increase RAN security. • The evolution of mobile communication based on openness, softwarization, and virtualization inserts new vulnerabilities into networks. • The increasing number of connected devices, especially IoT ones, is a security attention point in mobile networks. • Various security mechanisms, including Distributed ledger technologies (DLT), may enhance RAN security once these technologies can increase system resilience. • Other security approaches may also address RAN security issues.

Open access
2 source records
Blockchain Technology Applications and Security
Caching and Content Delivery
Internet Traffic Analysis and Secure E-voting
Original source
Feb 20, 2025·Proceedings of the 2025 10th International Conference on Intelligent Information Technology
0 cites
BL0K-ME Protocol: A Zero-Knowledge Proof Approach For Message Authentication In E2EE Conversations

Phuc-Hung Pham Le, Trung-Tin Tran, Toan Q. Dinh, Quy N.

As end-to-end encryption (E2EE) becomes the standard for secure communication, ensuring message authenticity while maintaining user privacy poses significant challenges.This paper introduces the BL0K-ME protocol, a novel cryptographic solution that combines Zero-Knowledge Proofs (ZKP), RSA encryption, and Bloom filters to authenticate individual messages within E2EE conversations.RSA encryption is employed to secure the transmission of messages between users, ensuring that only the intended recipient can decrypt the content, while ZKP enables third-party verification of specific message content without exposing the entire conversation.By leveraging Bloom filters, the protocol provides efficient logging and verification of message existence, balancing privacy protection with legal and regulatory requirements for digital evidence.BL0K-ME addresses a critical gap in current messaging systems by allowing service providers to verify message authenticity for legal investigations without compromising the confidentiality of unrelated communications.This research demonstrates the potential of integrating RSA encryption, ZKP, and Bloom filters to offer a scalable, secure solution for message authentication in E2EE systems, safeguarding both user privacy and the integrity of digital evidence.

Open access
Network Packet Processing and Optimization
IPv6, Mobility, Handover, Networks, Security
Advanced Authentication Protocols Security
Original source