Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

1,365 papersLast indexed Aug 31, 2026
Search papers

Paper index

1,365 results · page 1 of 57

Clear filters
Aug 25, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
UUI – UNIVERSAL UNIQUE IDENTITY (Enhanced) A Privacy-Preserving and Globally Interoperable Framework for Universal Digital Identity

Muhammad Asim - Global Progress Volunteer Muhammad Asim - Global Progress Volunteer

UUI – UNIVERSAL UNIQUE IDENTITY (Enhanced) A Privacy-Preserving and Globally Interoperable Framework for Universal Digital Identity A Conceptual Research Framework for Inclusive Identity, Trusted Verification, Human Mobility and Digital Governance (Idea 2 & 32) Muhammad Asim – Global Progress VolunteerIndependent ResearcherORCID: 0000-0002-8575-4447 Abstract Identity is a fundamental requirement for participation in modern economic, social, governmental and digital life. Yet approximately 800 million people worldwide still lack official identification, while at least 2.8 billion people do not have access to a government-recognized digital identity capable of supporting secure online transactions. Existing identity ecosystems are also frequently fragmented across national jurisdictions, institutions, technologies and legal frameworks. This paper proposes the Universal Unique Identity (UUI) Framework, a conceptual model for a secure, privacy-preserving and globally interoperable identity ecosystem. UUI does not seek to replace national identity systems, citizenship, passports or sovereign authority. Instead, it proposes an additional interoperability layer through which authorized identity claims could be securely verified across participating jurisdictions. The framework integrates privacy-by-design, cryptographic verification, interoperable identity standards, artificial-intelligence-assisted verification, distributed technologies, cybersecurity, selective disclosure, consent mechanisms and independent ethical governance. The proposed architecture deliberately avoids assuming that a universal identity system should require a single centralized global database. Instead, it emphasizes federated and interoperable approaches in which identity information remains appropriately controlled by authorized entities while verifiable claims can be exchanged across trusted systems. The paper develops the author's original Global Identification concept introduced in 2016 and the subsequent UUI – Universal Unique Identity concept published in 2025. The present manuscript substantially expands those earlier works by incorporating contemporary digital identity principles, international identity-management standards, privacy safeguards, governance requirements, cybersecurity considerations, implementation stages, limitations and future research directions. The paper argues that a globally interoperable identity layer could potentially reduce identity fragmentation, improve trusted verification, facilitate inclusion and support legitimate cross-border activities. However, such a system would require rigorous safeguards against surveillance, discrimination, exclusion, unauthorized profiling, cyberattack and misuse of personal information. Keywords: Universal Unique Identity; UUI; Global Identification; Digital Identity; Identity Interoperability; Identity Management; Privacy by Design; Artificial Intelligence; Blockchain; Cybersecurity; Digital Inclusion; Human Rights; Global Governance; Verifiable Credentials

Open access
2 source records
Cybersecurity and Cyber Warfare Studies
Privacy, Security, and Data Protection
Blockchain Technology Applications and Security
Original source
Aug 21, 2026·VCULIBRARIES
0 cites
Proof of Recovery: A Model to Enhance Data Integrity in Data Management Systems

Gustaf Barkstrom

Businesses lose millions of dollars every year when they can’t restore data from backups. Research shows that Disaster Recovery Plan (DRP) testing is not conducted frequently enough, nor are records maintained that demonstrate full data recovery from backups. This work introduces a design science artifact called PRTOK that aims to increase DRP testing. The design science artifact is a software solution that integrates with Data Management Systems (DMS) such as iRODS and DSpace, and can work with formats such as HDF5 and BagIt. Proof-of- recovery records, or tokens, are recorded in a replicated, resilient, and indelible proof-of- authority blockchain data structure. Access to the PRTOK blockchain allows practitioners restoring data from any backup software program or DMS integrated with PRTOK to view metadata about restoration operations. Metadata in the PRTOK record includes validation checksums of fully restored data, timestamps, and a documented record of how the data was restored, so that restoration operations can be repeated using those instructions. PRTOK is evaluated for validity within design science frameworks and theories, for both utility and socio- technical contributions to the state of the art in DRP testing. Qualitative data is collected from an online survey that includes a video and an interactive demonstration of the design artifact. Docusign Envelope ID: E4BB68B4-E66F-49EF-8B9D-F60A4B698376 x Participants in the survey are asked questions about their experience with DRP testing and whether and how the introduction of PRTOK contributes to the utility and ease of use of DRP testing processes. The evaluation of the PRTOK artifact included both feature demonstration and validation of knowledge claims against the Larsen framework for design science evaluation (Larsen et al., 2025). A socio-technical survey was also conducted to gain qualitative insights into whether and how practitioners found the PRTOK instantiation useful, whether it improved DRP testing, in what ways it was disadvantageous, and in what areas it needed improvement. The first research question (RQ1) asks what the characteristics of a data integrity model that improves data value by providing evidence of data recovery are. The feature set of the PRTOK instantiation, along with its model description, shows that these characteristics were achieved in the design and implementation of the PRTOK model. The socio-technical survey results show that the majority of respondents found the PRTOK implementation useful for DRP testing, although they also identified areas for improvement and some disadvantages of PRTOK. The second research question (RQ2) asks what risks to VDA are introduced by such a model and how those risks can be mitigated.

Open access
Privacy, Security, and Data Protection
Knowledge Management and Technology
Personal Information Management and User Behavior
Original source
Jul 26, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
BSDI 2.0: A Policy Framework for Privacy, National Security, Digital Accountability, and Citizen Sovereignty

Vedanta2.0 Agyat Agyani

Description:Bharat Secure Digital Identity (BSDI 2.0) is a citizen-centric, privacy-preserving identity overlay framework designed for India. It addresses the critical paradox of anonymous online harm versus mass surveillance. Unlike traditional systems that store raw identity documents, BSDI 2.0 uses Zero-Knowledge Proofs (ZKP), W3C Decentralized Identifiers (DIDs), and a Judicial Escrow Mechanism to enable attribute-based verification (e.g., age eligibility) without data disclosure. Platforms verify, but do not store, personal data. Lawful identity disclosure is only possible through multi-signature judicial authorization under strict proportionality and due process, anchored in Article 21. The framework is non-disruptive and interoperable with Aadhaar, DigiLocker, and DPDP Act 2023. It is a conceptual research framework for MeitY, NITI Aayog, and academic review. Keywords: Digital Identity, Privacy by Design, Zero-Knowledge Proof, DPDP Act, eIDAS, Judicial Oversight, Citizen Sovereignty

Open access
2 source records
Privacy, Security, and Data Protection
COVID-19 Digital Contact Tracing
Government, Law, and Information Management
Original source
Jul 24, 2026·Cambridge University Press eBooks
0 cites
Privacy and Security on Blockchain

Cüneyt Gürcan Akçora, Murat Kantarcioglu, Yulia R. Gel

In this chapter, you will explore the vulnerabilities and attack surfaces of blockchain systems that arise from their open, permissionless nature. You will learn how privacy and security issues manifest at different layers of blockchain architecture, including peer-to-peer networking, transaction propagation, block mining, and smart contract execution. The chapter introduces you to key privacy challenges such as identity leakage, transaction linkability, and deanonymization in UTXO and account-based systems. You will also study how adversaries can mount attacks that exploit consensus protocols, timestamp synchronization, and transaction ordering. The chapter concludes with detailed examples of smart contract vulnerabilities, including reentrancy, front-running, and oracle manipulation, and highlights the economic and technical incentives that make these attacks feasible in Decentralized Finance ecosystems.

Blockchain Technology Applications and Security
Privacy, Security, and Data Protection
Cryptography and Data Security
Original source
Jul 24, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
Bharat Secure Digital Identity (BSDI): A Policy Framework for Privacy, National Security, and Citizen Sovereignty

Ghanchi Manish Kumar

Description This preprint presents the Bharat Secure Digital Identity (BSDI) framework, a conceptual policy model for privacy-preserving and citizen-centric digital identity governance. The paper explores how decentralized identity technologies—including Decentralized Identifiers (DIDs), Verifiable Credentials (VCs), and Zero-Knowledge Proofs (ZKPs)—may support secure digital verification while minimizing unnecessary disclosure of personal information. BSDI proposes a governance model in which citizens retain primary control over their digital identity through secure digital wallets, the government serves as a trusted root issuer, and digital service providers function as cryptographic verifiers without retaining sensitive identity data. The framework also discusses lawful and targeted access mechanisms for national security within transparent legal oversight. This work is intended as a conceptual research and policy proposal rather than an implemented technical system. It aims to contribute to ongoing discussions on digital identity, privacy, cybersecurity, digital governance, and citizen sovereignty, and to encourage future interdisciplinary research, policy development, and public debate.

Open access
3 source records
Cybersecurity and Cyber Warfare Studies
Privacy, Security, and Data Protection
Access Control and Trust
Original source
Jul 24, 2026·PRAWO i WIĘŹ
0 cites
The Quantum Veil: Privacy, Security, and Legal Frameworks for Zero-Knowledge Advances

Varda Mone, Abhishek Thommandru, Ayubjon Alijonov Qobiljon o‘g‘li, Mamura Turgunboeva

This study examines the potential of Zero-Knowledge Protocols (ZKPs) as cryptographic mechanisms that enhance privacy and security in the context of advancing quantum technologies. Rather than accepting current legal safe guards and regulatory structures at face value, the study critically evaluates their effectiveness, particularly in healthcare environments where highly sensitive data frequently encounters inadequate protection. The methodology employs a multifaceted approach, integrating qualitative insights, legal case studies, and framework analysis. The findings indicate that zero-knowledge proof techniques can significantly enhance the protection of personal health information. A case study of NantHealth Inc.’s quantum-safe healthcare data protection framework illustrates the practical implementation of post-quantum cryptography and homomorphic encryption, demonstrating how health care organizations may proactively address quantum computing threats while enabling secure data collaboration. The study further demonstrates that incorporating these cryptographic methods into existing legal frameworks not only addresses immediate privacy concerns but also facilitates compliance with evolving data protection standards. The study also suggests that healthcare organizations should reconsider their data security approaches by implementing advanced cryptographic measures while maintaining regulatory compliance.

Open access
Privacy, Security, and Data Protection
Cryptography and Data Security
Information and Cyber Security
Original source
Jul 1, 2026·arXiv (Cornell University)
0 cites
No Country for Old Privacy: The Evolving Challenges of Anonymity in Bitcoin

Ben Hawkins, Joshua Levett, Siamak F. Shahandashti

We present a longitudinal measurement study on the adoption of detectable, second-generation anonymisation protocols in the Bitcoin network, including CoinJoin, CoinSwap, CoinShuffle and Stealth Addresses. By implementing and refining a suite of heuristic filters, we identify over 5.94 million CoinJoin and 23.3 million CoinSwap transactions. Besides, the use of CoinShuffle was unexpectedly found to be closely aligned with the Wasabi wallet operation period. Our analysis reveals consistently low adoption rates, with these protocols constituting less than 1% of network transactions, and a sharp decline in detectable usage following key regulatory events. Furthermore, we find no evidence of standardised Stealth Address adoption, indicating a failure to converge on a common privacy standard. This study provides a comprehensive picture of a niche ecosystem whose on-chain visibility has been largely suppressed, strongly suggesting the migration of privacy-seeking users to less transparent and less detectable methods.

Open access
3 source records
cs.CR
Blockchain Technology Applications and Security
Cryptography and Data Security
Original source
Jun 29, 2026·Vestnik BIST (Bashkir Institute of Social Technologies)
0 cites
Digital certification governance mechanism for school students’ achievements in additional IT education based on blockchain: model, implementation, and effectiveness evaluation

Ekaterina S. Avdeeva, Vitaly S. Reznik

The article proposes a governance mechanism for a blockchain-based decentralized certification system to validate school students’ achievements in additional IT education. The relevance stems from the rapid growth of project-based and short-term learning formats and the fragmentation of credentials, which undermines trust and portability across organizations. The study aims to develop a governance model (stakeholders, roles, responsibilities, access rules), describe an implementation algorithm, and propose an effectiveness evaluation framework at institutional and regional levels. It is argued that technological robustness is unattainable without institutional design: distribution of authority, validation and revocation procedures, and separation of data layers in compliance with minors’ personal data protection requirements. A permissioned consortiumbased distributed ledger architecture is considered, where education providers issue verifiable registry records and verifiers access credential status through controlled mechanisms. The paper also links registry-based certification with the concept of micro-credentials for modular IT learning outcomes and specifies effect metrics: reduced verification transaction costs, shorter confirmation time, improved transparency, and lower fraud risks.

Open access
Blockchain Technology Applications and Security
Technology Adoption and User Behaviour
Privacy, Security, and Data Protection
Original source
Jun 22, 2026
0 cites
What Is Privacy? Rethinking Rights, Consent, and Control in the Digital Age

Nate Tombs, Éléonore Fournier-Tombs

Abstract Privacy is a precondition of dignity, autonomy, and democratic legitimacy. This chapter reconceptualizes privacy in an AI‑saturated economy by tracing its philosophical roots and codification and by comparing regulatory models in the EU, United States, Canada, China, and Indigenous data sovereignty frameworks. We diagnose structural limits of consent‑heavy regimes, commodification of personal data, and private surveillance infrastructures that states increasingly co‑opt. We then outline a program for effective protection that shifts responsibility from individuals to accountable institutions through rights‑based law, privacy‑preserving technical design (e.g., Global Privacy Control, Self-Sovereign Identity, Zero-Knowledge Proofs), and coordinated international governance. Treating privacy as a public good anchors the proposal.

Ethics and Social Impacts of AI
Privacy, Security, and Data Protection
Freedom of Expression and Defamation
Original source
Jun 19, 2026
0 cites
Security and privacy considerations in blockchain-based computer vision

Mohammed Ali Shaik, Salman Ali Syed, Imran Qureshi, Shivaratri Narasimha Rao

This chapter reviews the security and privacy issues related to the integration of blockchain and computer vision (CV) systems. CV is applied in the health sector, in car driving, in shopping centers, and in surveillance, but it highly depends on image and video data, which are difficult to authenticate, secure, or even kept private. The decentralized, immutable, and transparent format of blockchain provides a good choice to address these issues as it allows sharing of data safely, controlling access to data, and ensuring its auditability. This chapter starts with the introduction to the concept of CV applications and the confidentiality risks of these applications and then proceeds to explain how the concept of blockchain can be used to create a dependable, tamper-proof system to handle visual data, through the use of smart contracts and consensus algorithms. It talks of state-of-the-art methods, such as encryption, zero-knowledge, and federated learning (FL), to guarantee privacy preservation in blockchain-based CV systems. In fact, the real-life application illustrates how blockchain is used to lock up medical imaging, self-driving vehicles, and surveillance data. Lastly, this chapter discusses new regulatory and ethical issues such as ownership of the data, legislative privacy, and ethical smart use of surveillance technology.

Blockchain Technology Applications and Security
Privacy, Security, and Data Protection
Privacy-Preserving Technologies in Data
Original source
Jun 10, 2026
0 cites
Beyond Encryption

Arafat Febriandirza

The Metaverse represents a paradigm shift from two-dimensional internet interaction to immersive, persistent, three-dimensional environments. As this ecosystem evolves, the attack surface expands exponentially, introducing novel vulnerabilities that traditional HTTPS and TLS protocols cannot adequately address. This chapter explores the future of secure communication within the Metaverse, moving beyond standard data encryption to address the protection of biometric data, haptic feedback integrity, and avatar identity. We will analyze the unique challenges posed by the convergence of Virtual Reality (VR), Augmented Reality (AR), and the Internet of Things (IoT). The chapter will propose a multi-layered security framework integrating Quantum-Resistant Cryptography, Zero-Knowledge Proofs (ZKPs) for identity verification without exposure, and AI-driven behavioral analysis to detect “Man-in-the-Avatar” attacks. Finally, we will discuss the regulatory and ethical implications of surveillance in a world where user movements and gaze are constantly tracked.

Privacy, Security, and Data Protection
User Authentication and Security Systems
Ethics and Social Impacts of AI
Original source
May 19, 2026·IEEE Transactions on Dependable and Secure Computing
0 cites
Lightweight Privacy-Preserving and Fault-Tolerant Truth Discovery for Mobile Crowdsensing Systems

Li Li, X R Wang, Hong‐Ning Dai, Fang Li · 6 authors

As a paradigm for encouraging users to contribute data spontaneously, mobile crowdsensing (MCS) has received considerable attention recently. It is crucial to evaluate the truthfulness of MCS data by proper truth discovery mechanisms. Although recent truth discovery schemes can determine truthful information, they either provide limited privacy preservation or have heavy computation and communication overheads. Moreover, most of them are not resilient to malicious faults and active attacks. To tackle the above problems, we propose two fault-tolerant and privacy-preserving truth discovery solutions. Our first scheme is mainly used for scenarios with a relatively stable number of users, where participants do not frequently join or leaves. Integrating ring signature with the perturbation technique, we design an anonymous and privacy-preserving truth discovery scheme, namely RsAnonTD, which can achieve privacy preservation and resist active attacks. To address the challenge with dynamically changed workers, we devise a multi-client inner product functional encryption scheme with a lightweight zero-knowledge proof protocol (namely McFeKDeTD) for defending against active attacks. The security analysis shows that both schemes can preserve the privacy of sensory data, weights, and estimated truths while resisting active attacks, thereby guaranteeing fault tolerance. Extensive experiments demonstrate that our designs achieve superior performance than other schemes in terms of accuracy, convergence speed, and system overheads. For example, compared with the state-of-the-art approach RPTD-II, which has a security level comparable to ours, our proposed schemes, RsAnonTD and McFeKDeTD, reduce the computational overheads approximately by 98% and 69%, respectively.

Mobile Crowdsensing and Crowdsourcing
Privacy, Security, and Data Protection
Open Source Software Innovations
Original source
May 18, 2026·Big Data and Cognitive Computing
0 cites
Blockchains for Data Management: The DIGI4ECO Use Case and Practical Lessons Beyond Theory

Andreas Polyvios Delladetsimas, Elias Iosif, Stamatis Papangelou, George Giaglis

This article examines blockchain as an enabling technological component for data management tasks that are independent of currency-related functionality, a less-discussed aspect of a technology commonly associated with cryptocurrencies and decentralized finance (DeFi). Drawing on empirical findings from the DIGI4ECO project as a case study, we present a structured literature review and cross-domain analysis of blockchain-based data management systems (BDMSs), examine a representative permissioned BDMS implementation, and synthesize practical design guidelines and implementation insights for BDMS development. This perspective is motivated by core blockchain properties such as immutability and transparency, as well as by the observation that existing resources for BDMS development, including methods, tools, and best practices, remain fragmented and less developed than those available for more mature technologies.

Open access
Blockchain Technology Applications and Security
Privacy, Security, and Data Protection
Cybercrime and Law Enforcement Studies
Original source
Apr 30, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
ConsentLedger: A Blockchain-Based Decentralized Consent Governance Framework

Ayush Mohan Singh, Prakhar Chand, Vidit Goel, Garima Dhawan

In the digital era, personal data is continuously collected, processed, and shared by organizations across various sectors. Traditional consent management systems suffer from centralization, opacity, and insufficient user control, making it difficult for individuals to track and enforce their data-sharing preferences. This paper presents ConsentChain, a decentralized consent governance protocol built on the Polygon blockchain. The system leverages Ethereum-compatible smart contracts to implement purpose-bound, time-limited, and user-revocable consent records, backed by an immutable on-chain audit trail. The architecture employs two core Solidity smart contracts—ConsentManager and AccessController—supported by a React-based frontend and MetaMask wallet integration. Comprehensive end-to-end testing demonstrates 18 of 18 test cases passing, validating the correctness of consent lifecycle management, access validation, role-based access control, and event logging. ConsentChain demonstrates that blockchain technology can provide a transparent, tamper-proof, and user-sovereign alternative to conventional consent management systems, with clear pathways toward enterprise adoption, multi-chain deployment, and zero-knowledge privacy extensions. Index Terms—Blockchain, Consent Management, Smart Contracts, Data Privacy, GDPR, Decentralized Systems, Ethereum, Polygon, Access Control, Audit Trail.

Open access
2 source records
Blockchain Technology Applications and Security
Privacy, Security, and Data Protection
Privacy-Preserving Technologies in Data
Original source
Apr 27, 2026·Mathematics
0 cites
TD-RCRF: A Privacy-Preserving Truth Discovery Resistant to Collusion and Reputation Fraud in Mobile Crowdsensing

Libo Ban, Lei Wu, Wei Wu, Haipeng Peng

Privacy-preserving truth discovery (PPTD) has garnered significant attention in mobile crowdsensing (MCS). However, existing research lacks sufficient privacy protection and is often vulnerable to collusion attacks among malicious participants. Moreover, incorrect data submitted by unreliable users and their weights may reduce the accuracy of truth discovery. To address these issues, this paper proposes a privacy-preserving truth discovery framework resistant to collusion and reputation fraud (TD-RCRF) that is highly resistant to collusion and reputation fraud. The scheme employs additive secret sharing to protect sensing data, weights, intermediate results, and ground truth. To screen trustworthy users who meet reputation requirements under the non-colluding dual-server model, we propose a privacy-preserving reputation verification algorithm that combines Pedersen commitment and zero-knowledge proof to verify the validity of mobile users’ reputation values. Additionally, we propose a homomorphic strategy that converts shares between multiplication and addition and use it to design a lightweight truth discovery algorithm that further improves the accuracy of the “truth” using reputation values. Security analysis proves that TD-RCRF is privacy-preserving and secure under the non-colluding dual-server assumption. Theoretical analysis and experiments show that it is practical and efficient.

Open access
Mobile Crowdsensing and Crowdsourcing
Privacy, Security, and Data Protection
Blockchain Technology Applications and Security
Original source
Apr 12, 2026·Proceedings of the ACM Web Conference 2026
0 cites
ShadowClone: Scalable Decentralized Identity with Cross-Domain Anonymity and Accountable Traceability

Y Liu, Zedan Zhao, Boyu Zhao, Na Wang · 6 authors

Decentralized identity (DID) is a key infrastructure for Web3, granting users sovereign control over their private identity data. While existing DID systems like FADID-TT (WWW'25) realize anonymity and traceability within a single domain, the Web3 ecosystem is a multiverse of independent domains like DeFi, GameFi, and DAO. This multi-domain reality presents critical issues for current DID solutions. First, most existing solutions are built on the monolithic committee architecture, facing severe scalability bottlenecks as the committee size grows. Second, most existing solutions cannot offer strong cross-domain anonymity, where frequent cross-domain interaction inevitably exposes the user's privacy. Third, existing methods for tracing the identities of malicious users are inefficient.

Open access
Internet Traffic Analysis and Secure E-voting
Access Control and Trust
Privacy, Security, and Data Protection
Original source
Apr 12, 2026·Proceedings of the 8th International Workshop on Emerging Trends in Software Engineering for Blockchain
0 cites
Accessing Web3 Onboarding and Trust via Vipps

Surya Bahadur Kathayat, Magnus Svendsen, Brage Hagemann Brataas

Web3 applications strive to enable decentralization and user sovereignty, but often remain inaccessible to mainstream users due to complex onboarding and unfamiliar interaction paradigms. This study presents a Web2-inspired onboarding solution that integrates an embedded custodial wallet with OpenID Connect (OIDC) authentication via Vipps, a Norwegian bank-backed identity provider with over 4.6 million verified users. The proposed approach abstracts wallet management and removes the need for seed-phrase setup while introducing real-world identity assurance into the Web3 environment. A blockchain-based Battleship proof-of-concept was developed to demonstrate the approach, aiming to make Web3 interactions more intuitive and trustworthy. A mixed-method evaluation, combining usability testing and semi-structured interviews, revealed that integrating familiar login flows with verified identities improves usability, conceptual understanding, and both peer and ecosystem trust. The findings suggest that leveraging centralized identity providers can act as a pragmatic bridge between Web2 and Web3, potentially lowering initial onboarding barriers.

Open access
Personal Information Management and User Behavior
Privacy, Security, and Data Protection
Access Control and Trust
Original source
Apr 10, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
The Immutability Conundrum: Reconciling GDPR Data Subject Rights with Blockchain Architecture in a Borderless and Decentralized Digital Economy

Dr. G.V. Mahesh Naath

This paper examines the complex and evolving relationship between blockchain technology and the General Data Protection Regulation (GDPR), focusing on the fundamental tension between blockchain’s immutability and the data protection rights of individuals. While blockchain offers transformative advantages such as decentralization, transparency, security, and trustless verification, its core architectural feature—immutability—poses significant challenges to compliance with key GDPR principles, particularly the right to erasure, rectification, and data minimization. The study critically analyzes how decentralized and borderless blockchain networks disrupt traditional legal frameworks that rely on identifiable data controllers and territorially bounded regulation. It explores the difficulties in assigning legal responsibility within distributed systems, as well as the complications arising from cross-border data transfers and jurisdictional ambiguities. Further, the paper evaluates emerging technical and regulatory responses aimed at reconciling these conflicts, including off-chain data storage models, encryption-based deletion (crypto-shredding), pseudonymization, and advanced privacy-preserving techniques such as zero-knowledge proofs. It also considers the role of privacy-by-design principles and the need for adaptive regulatory frameworks tailored to decentralized technologies. The paper concludes that the interaction between blockchain and GDPR represents a broader challenge in contemporary law: balancing technological innovation with the protection of fundamental rights. It argues for a coordinated, interdisciplinary approach involving legal scholars, policymakers, and technologists to develop flexible and forward-looking governance models capable of addressing the unique characteristics of decentralized digital ecosystems.

Open access
2 source records
Blockchain Technology Applications and Security
Privacy, Security, and Data Protection
Cybersecurity and Cyber Warfare Studies
Original source
Apr 2, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
Age Verification Without Surveillance on AI-Driven Social Media: How Purpose-Bound Cryptography Resolves the Online Safety Paradox

Sangam Das

About this paper This paper argues that the conflict between online protection and privacy is not inevitable. The real problem is that most current systems wrongly treat compliance and identity as the same thing. The proposed VI + CJT framework separates them. It allows platforms to receive only the minimum lawful compliance result they need — for example, whether a user falls below the relevant legal age threshold — without learning the child’s name, date of birth, address, biometric profile, or broader identity. In that sense, the paper’s central theme is age verification without surveillance through purpose-bound cryptographic enforcement. How AI Makes the Problem Worse AI makes the children’s online safety problem more serious in three distinct ways. First, it changes exposure from passive to active. Harmful material is no longer merely available on a platform; recommendation and optimisation systems can identify vulnerable users, rank harmful content more aggressively for them, and progressively amplify it based on engagement signals. In that environment, a child is not simply finding harmful content — the system is learning from the child and serving more of it. Second, AI makes weak age-verification methods more dangerous. A false self-declared age is no longer just a wrong entry in a sign-up form. Once accepted, it becomes operational input for recommendation, advertising, and behavioural optimisation systems, which then treat the child as an adult user profile. This means the error is not static; it is continuously acted upon by AI systems that optimise for attention and engagement rather than child protection. Third, AI encourages platforms to solve the problem through more surveillance. In practice, this often means AI-based age estimation using faces, voices, or behavioural patterns. But this approach creates a new harm while claiming to solve another one: it turns child protection into biometric and behavioural monitoring, and can generate datasets that may later be reused for additional profiling or model training. In other words, AI can make age assurance both more intrusive and less accountable. A further difficulty is that AI systems are often opaque even to their operators. As your draft correctly notes, policy rules alone may not be enough, because platforms may not reliably know how their own recommendation systems are treating minors in practice. This is why the problem is not only one of age verification, but also one of enforceable control over AI behaviour. That is precisely why the VI + CJT model matters. It does not ask AI systems to infer age or interpret law for themselves. Instead, it provides a minimal, authoritative compliance signal and machine-readable constraints that can limit recommendation, advertising, and profiling behaviour toward minors without exposing identity. Current Solutions Self-declaration is easily bypassed. A child can simply enter a false age, and the platform’s AI systems then treat that false declaration as valid input for recommendation, targeting, and optimisation. Identity-linked verification creates major privacy risks. When age assurance depends on sharing civil identity information with commercial platforms, the result is unnecessary exposure of family and child data to entities with strong incentives to collect, retain, and monetise it. AI-based age estimation introduces biometric surveillance. Estimating age from face, voice, or behaviour may appear convenient, but it creates new harms by collecting sensitive personal and biometric data as a side effect of child protection. Current systems collapse compliance into identity. What platforms usually need is not the full identity of the user, but only the legally relevant compliance fact. Existing approaches fail because they demand far more data than is necessary for that purpose. Policy rules alone are not enough in AI-driven environments. Even where legal obligations exist, platforms may not reliably translate them into enforceable constraints on opaque recommendation and engagement systems. As a result, compliance may remain declaratory rather than technically enforced. Proposed Solution Use VI + CJT as a purpose-bound cryptographic layer. The framework converts verified civil identity held by trusted authorities into a minimal compliance credential that reveals only the relevant age-threshold result for the applicable jurisdiction. Avoid disclosure of identity data. The credential contains no name, no full date of birth, no address, and no biometric data. Each credential uses a fresh random identifier, making it unlinkable across sessions. Keep the credential under user control. The credential is stored on the user’s device in secure hardware rather than on platform servers, reducing centralised exposure and retention risks. Use zero-knowledge proof for age compliance. When access is requested, the platform receives only a yes-or-no compliance result, without learning the underlying identity attributes or credential contents. Encode law into machine-readable CJTs. The Compliance Jurisdiction Token expresses the applicable legal rules, including jurisdiction-specific age thresholds and AI-related restrictions such as limits on engagement optimisation, advertising targeting, or behavioural profiling for minors. Constrain platform AI without making it identity-aware. Recommendation engines and other AI systems receive only the compliance signal necessary to adjust behaviour for minors, allowing them to become jurisdiction-aware and age-aware without becoming identity-aware. Replace probabilistic AI age estimation with authoritative attestation. Instead of guessing age through opaque models, the framework provides deterministic, government-signed, legally relevant compliance proof. Enable auditability and cross-border enforcement. Regulators can test whether platforms respond correctly to compliance signals, and the applicable child-protection rule can follow the user across borders through jurisdiction-bound credentials and tokens. Core Message The paper’s core message is simple: platforms do not need to know who a child is in order to know what protections the law requires. By separating compliance from identity, the VI + CJT model offers a path to child safety that is enforceable, privacy-preserving, and better suited to AI-driven digital environments.

Open access
2 source records
Ethics and Social Impacts of AI
Privacy, Security, and Data Protection
Digitalization, Law, and Regulation
Original source
Mar 24, 2026
0 cites
Secure, Smart, Automated, and Privacy-Preserving Cybersecurity Policy Compliance Framework for Sensitive Data Protection

Jemima Owusu-Tweneboah, Amani Altarawneh

Cybersecurity regulatory and compliance frameworks such as NIST SP 800-53 Rev. 5, the HIPAA Security Rule, and the GDPR define essential security and privacy obligations for healthcare information systems and their supporting infrastructures. Despite their critical role, compliance assurance in healthcare is predominantly manual and centered on periodic, point-in-time assessments, relying on human interpretation of regulatory requirements and fragmented evidence collection. As healthcare ecosystems evolve toward decentralized systems and extensive third-party participation, there is a growing need for compliance mechanisms that enable continuous assurance, verifiable accountability, and privacy-preserving enforcement across organizational boundaries. This paper proposes SSAP-CPCF, a Secure, Smart, Automated, and Privacy-Preserving Cybersecurity Policy Compliance Framework that integrates permissioned blockchain orchestration, LLM-assisted regulatory interpretation with human validation, and zero-knowledge proof-based verification. The framework explicitly encodes regulatory authority, assessor oversight, and multi-party approval into its protocol design, ensuring that automation enforces, rather than replaces, governance structures. SSAP-CPCF treats compliance as an enforceable system property by binding assessments to vendor-declared obligations and enforcing approval and oversight requirements at the ledger level, ensuring integrity, auditability, and separation of authority. A prototype implemented on a multi-organization Hyperledger Fabric network demonstrates the feasibility of privacy-preserving, ledger-enforced compliance automation in realistic multi-stakeholder settings.

Information and Cyber Security
Privacy, Security, and Data Protection
Access Control and Trust
Original source
Mar 17, 2026
0 cites
Zero-Knowledge Consent: Auditable and Private Data Permission Management via Blockchain

Filippo Scaramuzza, Marco Tonnarelli, Damian A. Tamburri, W.J.A.M. van den Heuvel

The challenge of achieving auditable, GDPR-compliant consent management while preserving true data subject privacy persists, as current blockchain-based solutions compromise anonymity through public ledgers. This paper addresses this by introducing a novel, privacy-by-design IT artefact built on the Ethereum platform that employs Zero-knowledge Succinct Non-Interactive ARgument of Knowledge (zk-SNARKs) to enable truly anonymous and irrefutable validation of data processing permissions. Implemented and evaluated through a Design Science Research (DSR) approach, the artefact demonstrated a high degree of functional and GDPR compliance, confirming its capacity to generate trustless, auditable on-chain proof of permission status. The proof of concept successfully implements core privacy-by-design principles through anonymity and encryption, with technical benchmarks indicating acceptable performance for the artefact's intended use despite the computational intensity of proof generation.

Blockchain Technology Applications and Security
Cryptography and Data Security
Privacy, Security, and Data Protection
Original source
Mar 16, 2026·arXiv (Cornell University)
0 cites
Grant, Verify, Revoke: A User-Centric Pattern for Blockchain Compliance

Supriya Khadka, Sanchari Das

In decentralized web applications, users face an inherent conflict between public verifiability and personal privacy. To participate in regulated on-chain services, users must currently disclose sensitive identity documents to centralized intermediaries, permanently linking real-world identities to public transaction histories. This binary choice between total privacy loss or total exclusion strips users of agency and exposes them to persistent surveillance. In this work, we introduce a Selective Disclosure Framework designed to restore user sovereignty by decoupling eligibility verification from identity revelation. We present ZK-Compliance, a prototype that leverages browser-based zero-knowledge proofs to shift the interaction model, enabling users to prove specific attributes (e.g., "I am over 18") locally without revealing the underlying data. We implement a user-governed Grant, Verify, Revoke lifecycle that transforms the user's mental model of compliance from a permanent data handover into a dynamic, revocable authorization session. Our evaluation shows that client-side proof generation takes under 200ms, enabling a seamless interactive experience on commodity hardware. This work provides early evidence that regulatory compliance need not come at the cost of user privacy or autonomy.

Open access
2 source records
cs.CR
cs.HC
Privacy, Security, and Data Protection
Original source
Mar 5, 2026·Open MIND
0 cites
Why Ethereum Needs Fairness Mechanisms that Do Not Depend on Participants' Altruism

Patrick Spiesberger, Nils Henrik Beyer, Hannes Hartenstein

Ethereum's ideal of censorship resistance, together with related fairness properties, is undermined in practice, motivating fairness mechanisms that aim to restore these properties. Several of these mechanisms hand control over block contents to a committee of proposers under a 1-of-n honest assumption: at least one committee member complies with the mechanism even when deviating would increase personal revenue. We refer to such proposers as altruistic. Yet prior work shows that roughly 91 percent of blocks are constructed by centralized block-building services that demonstrably take user-adverse actions for financial gain; the responsible proposers sign these blocks blindly, without any means of intervention. A common reading of this figure is that 9 percent of proposers forgo these gains and act altruistically. Our empirical analysis of the full year 2025 shows that this share is far smaller: at most 1.55 percent of proposers can plausibly be regarded as altruistic, whereas the remaining 98.45 percent of proposers exhibit observable non-altruistic behavior. We interpret 1.55 percent as an upper bound on the prevalence of altruistic proposers. These results imply that committee-based fairness mechanisms that rely on altruistic members would require substantially larger committees than currently proposed. This raises concerns about their practical viability and motivates mechanisms in which fair behavior is the rational choice.

Open access
2 source records
cs.DC
ICT Impact and Policies
Privacy, Security, and Data Protection
Original source