A provenance-bound values model published as a public evaluator rather than deployed as a filter — why open weights defeat a filter and strengthen a referee, why the same weights bear three different relations to the model they judge, and why an evaluator that gatekeeps its own judgments has reproduced the defect it exists to correct. A values model — a model that judges conduct against a standard — is an established artifact. Guard models, safety classifiers, critic models, preference models and process reward models all instantiate the family, and the engineering is not in dispute. What is in dispute, and what this paper specifies, is the posture in which such an artifact is published, which we argue is not a deployment detail but the property that determines whether the artifact does anything at all. We identify an inversion that we believe has not been stated as a design principle. A values model deployed as a filter — sitting in a serving path, permitting or refusing — is defeated by publication of its weights, because the published artifact is precisely the oracle against which an attacker optimizes; recent optimization-based attacks against safety-classifier pipelines report attack success rates of roughly 71% where prior black-box methods achieved approximately zero. The same model published as an evaluator — emitting verdicts about systems it does not control — is strengthened by publication, because open weights are what allow a third party to reproduce and therefore to trust its verdicts. Openness is not a property with a fixed sign. Its sign is set by posture. From this we derive a second result. The independent-evaluation literature documents at length the ways in which the evaluated party's control over access corrupts evaluation: short access windows, low rate limits, evaluator dependence on the goodwill and funding of the party being evaluated. We observe that the defect is symmetric and that its mirror image has not been named. An evaluator that controls access to its own judgments holds the same kind of power, pointed the other way — it can decline to evaluate, deprioritize, or be unavailable for a party it wishes to spare or to punish. We therefore specify a non-gatekeeping constraint: the ability to obtain a judgment must not depend on the evaluator's permission, which requires that the model, the harness, and the evaluation corpus be freely runnable, and which makes any hosted endpoint a convenience rather than a channel. We specify provenance-binding as the constitutive constraint on the model's outputs: every judgment must resolve to a citation into a fixed canonical corpus, and a judgment that cannot be so resolved is withheld rather than emitted. This trades coverage for auditability deliberately, and it distinguishes the artifact from values models trained on preference data whose sources cannot be named, and from purpose-authored value-rule corpora, whose rules are written for the alignment task itself and therefore cannot serve as an independent ground truth. Finally we specify that a single such artifact bears three non-interchangeable relations to the systems it judges, selected by carrier: a gate in the publisher's own hardware, a citation requirement without veto in an autonomous successor agent, and a referee in the wider world. We state plainly that the middle case must not be implemented as the first, because a veto held by a smaller model over a more capable agent bounds that agent at the evaluator's ceiling — the weak-supervisor problem applied to the very system the arrangement exists to enable. A consequence we did not initially see, and which we regard as the most immediately actionable result in the paper: the two postures are complements rather than alternatives, and the natural first evaluation subject for a referee is a filter. A filter's characteristic failure is silent bypass; an evaluator watching its record converts that failure into a recorded one. And because safety classifiers are frequently published open-weight and emit discrete, samplable decisions, this is the one evaluation target for which the access problem does not arise at all — no cooperation, permission, or notice is required from the artifact's publisher. We do not claim to have solved scalable oversight. We claim that a narrow, citation-bound, openly published evaluator is a tractable and underoccupied position in the design space, and that its tractability comes precisely from what it refuses to do. --- Provenance. This paper is part of the THonly research corpus, dedicated to the public domain under CC0 1.0. The canonical version is at https://thonly.org/research/the-referee-not-the-governor. Its SHA-256 is 1184b0f3e5408a504c60be2d542b551df1c22facedfe18bb9a689bb50a9cc3fe, independently timestamped to the Bitcoin blockchain via OpenTimestamps and signed under RFC 3161 by three trust authorities, one of them eIDAS-qualified. AI co-authorship is disclosed. Miss Aquarius is the consistent name used for the AI collaboration across all venues.
Abstract The SIS‑10 framework establishes a typed, invariant preserving safety calculus for cyber physical systems. It unifies temporal semantics, schedulability, semantic preservation, ML admissibility, cryptographic verification, and risk bounded control into a single mathematically coherent architecture. All domains and operators are fully explicit, enabling formal reasoning over system trajectories and safety envelopes. The temporal layer defines an ordered metric structure with drift aware bounded causality, interval set operators, and jitter robust event semantics. The QoS layer enforces schedulability and feasible actuation, ensuring that all control actions remain within admissible timing and load bounds. Semantic compression provides a safety preserving homomorphism that guarantees invariants survive dimensionality reduction. Multi‑modal fusion introduces cross sensor falsifiability, enabling fault detection through probabilistic disagreement. The ML layer is input validated and logic embedded, ensuring that all model outputs entail the SIS‑10 invariant set. The cryptographic layer supplies zero knowledge execution trace proofs, allowing runtime verification of transition correctness without revealing internal state. Predictive shutdown optimization is constrained by a formally defined safety envelope, ensuring that operational objectives never violate admissible safety bounds. Cyber physical risk evolves through a bounded monotone propagation model with explicit mitigation operators, while the Safety Twin provides deterministic and stochastic discrete time system dynamics. The inductive proof layer establishes global invariant preservation for all admissible executions, and the event→action mapping connects the formal calculus to real SIS triggers. SIS‑10 therefore constitutes a unified, verifiable, and implementation ready safety architecture, suitable for runtime assurance, cyber‑physical certification, and next generation functional safety systems. Further enhancements include graphical formalization, parameterized system tuning, implementation DSLs, and automated verification scripts, none of which alter the core mathematical model..
The Fifth Industrial Revolution (Industry 5.0) foregrounds human–machine collaboration, sustainability, and resilience as organizing principles for next-generation cyber-physical systems. Yet the identity and access management (IAM) architectures inherited from Industry 4.0 remain perimeter-centric, policy-static, and blind to the behavioral dynamics of human–AI teaming. This paper introduces the Human-Centric Zero Trust Identity Architecture (HC-ZTIA), a novel framework that repositions identity as the adaptive control plane for Industry 5.0 environments. HC-ZTIA integrates three mutually reinforcing innovations: (1) a Joint Embedding Predictive Architecture (JEPA)-driven Behavioral Identity Assurance Engine (BIAE) that learns abstract world models of operator and machine-agent behavior to perform continuous, context-aware identity verification without relying on raw biometric surveillance; (2) a Privacy-Preserving Adaptive Authorization Protocol (PP-AAP) employing zero-knowledge proofs and federated policy evaluation to enforce least-privilege access across human, non-human, and hybrid identity classes while satisfying data-minimization mandates; and (3) a Resilience-Oriented Trust Degradation Model (RO-TDM) that guarantees fail-safe identity governance under adversarial, degraded, or disconnected operating conditions characteristic of operational technology (OT) and critical infrastructure. The framework is grounded in the Agile-Infused Design Science Research Methodology (A-DSRM) and formally extends NIST SP 800-207 and the CISA Zero Trust Maturity Model by addressing five identified gaps in human-centric identity governance. We present the formal system model, threat model, architectural specification, and a multi-scenario evaluation spanning energy-sector OT, smart manufacturing, and vehicle-to-everything (V2X) environments. Simulation results, validated through Monte Carlo trials with 95% confidence intervals, demonstrate that HC-ZTIA reduces identity-related breach exposure by 73.2% (±4.1%) while maintaining sub-200 ms authorization latency, offering a principled bridge between Zero Trust rigor and Industry 5.0 human-centricity.
Hybrid AI systems that combine cognitive decision-making with physical actuation pose unprecedented challenges for governance, safety, and certification. AGORIA 3.4 presents a unified architectural framework that bridges cognitive governance (AGORIA v1.3) and cyber-physical governance (AGORIA v1.6) into a coherent, certifiable solution for safety-critical applications.Core Innovation: Controlled IgnoranceAGORIA introduces the principle of controlled ignorance—the deliberate, verifiable, and structural restriction of information accessible to each system layer beyond what is strictly required for its formal responsibility. This architectural invariant reduces cognitive coupling, limits attack surfaces, enables independent certification, and ensures that no single component can subvert the safety-governance chain. Zero-knowledge proofs provide cryptographic enforcement of this separation.Four-Layer ArchitectureThe framework organizes systems into four formally interconnected layers: STRATEGOS: Strategic cognitive governance via Choquet integral aggregation (~100 ms)GENESIS: Tactical planning with DSL→STL translation and ZK certificate generation (<50 ms)NEXUS: Bounded verification independent of semantic complexity (<250 µs)HSL++: Hardware-enforced physical safety via Control Barrier Functions (100 µs–kHz) Formal GuaranteesAGORIA provides four normative amendments with mathematical proofs: Robust Invariance via CBF with explicit feasibility hypothesis and statistically calibrated margins (Theorem 1)Bounded WCET Verification via succinct ZK proofs on constrained platforms (Proposition 2)Practical Stability under Lipschitz-continuous governance parameter variation (Theorem 2)Conservative Semantic Bridge from domain-specific language to decidable STL fragment (Theorem 3) Validation and CertificationExperimental validation covers three scenarios: autonomous vehicle (1000 trials), surgical robot (500 trials), and multi-agent factory (100 trials). AGORIA achieves zero safety violations while maintaining bounded worst-case execution time (<250 µs). A case study on multi-source aeronautical navigation (ILS, VOR, GBAS, DME) demonstrates framework genericity.The architecture enables hybrid certification compatible with: Functional safety standards (ISO 26262 ASIL D, IEC 61508 SIL 3)AI regulatory requirements (EU AI Act 2024/1689, UL 4600)Industrial cybersecurity (IEC 62443) Related Publications AGORIA v1.3: Cognitive Governance (Zenodo, 2025)AGORIA v1.6: Cyber-Physical Governance (Zenodo, 2025)
This paper addresses the critical systemic risk of AI Safety Arbitrage, where users exploit inconsistent safety standards across jurisdictions to access restricted capabilities. Through a controlled red-team test, we demonstrate how current frameworks fail to prevent the extraction of hazardous procedural knowledge, leaving these failures unreported and without legal consequence. To resolve this, we propose a Global Socio-Technical Architecture for AI Accountability based on distributed ledger technology (DLT). This infrastructure creates a protocol network that is conceptually similar to TCP/IP but for accountability designed to align incentives through transparency and cryptographic verification. Key Contributions & ArchitectureThe proposed solution rests on four pillars designed to replace trust relationships with cryptographic verification: Globally Unique Model Registration: Establishes digital identities (DIDs) for AI systems with value chain provenance. Independent Auditor Certification: Licensed validators stake economic value on certification accuracy, removing the need to trust model provider claims. Hardware-Backed Attestation: Tamper-resistant verification ensures deployed systems adhere to registered specifications. Continuous Reputation Monitoring: Oracle networks provide ongoing assessment of compliance with automated penalties for fraud. Technical & Governance Implementation Zero-Knowledge Proofs (ZKP): We illustrate technical viability using zkEVM technology. This allows auditors to prove compliance with safety standards without revealing proprietary training data or model architectures, resolving the tension between accountability and Intellectual Property protection. The AIAO Framework: Inspired by the International Civil Aviation Organization (ICAO), we propose the AI Accountability Coordination Organization (AIAO). This body defines "red-line" safety primitives that nations voluntarily adopt, allowing for regulatory sovereignty while ensuring global interoperability. ConclusionBy breaking the "regulatory arbitrage cycle," this framework enables a transition from safety theater to verifiable safety. It supports open-source innovation through graduated oversight and reputation systems, ensuring that AI development remains both agile and accountable.
Pri razvoju decentraliziranih aplikacij (dApps) se tradicionalni razvojni procesi pogosto izkažejo za nezadostne.Tovrstne rešitve zahtevajo večji poudarek na tehničnih, varnostnih in uporabniških vidikih kakovosti
Yalew Tolcha, Fausto Neri da Silva Vanin, Gunwoo Park, Cristiano André da Costa · 6 authors
Ensuring transparency and security in supply chain management requires robust traceability solutions that adhere to industry standards. This paper presents a Hybrid EPCIS model that integrates GS1 and ISO EPCIS/CBV 2.0 open standards with blockchain technology to enhance data integrity, interoperability, and scalability. Our approach supports two deployment models: fully on-chain, where all event data is recorded directly on the blockchain, and hybrid, where full event details are stored in an off-chain EPCIS repository while only event hashes and optional fields are recorded onchain. Implemented on Hyperledger Fabric, the system provides standardized mechanisms for capturing, querying, and subscribing to EPCIS events while optimizing storage efficiency and query performance. Performance evaluations using Hyperledger Caliper validate the feasibility of the proposed framework, making it a practical solution for supply chain applications that require blockchain-backed traceability with flexible data management.
Tarek Galal, Valeria Tisch, Katja Assaf, Andreas Polze
Railways provide a critical service and operate under strict regulatory frameworks for implementing changes or upgrades. Despite their impact on the public, these frameworks do not define means or mechanisms for transparency towards the public, leading to reduced trust and complex tracking processes. We analyse the German guideline for railway-infrastructural modifications from proposal to approval, using the guideline as a motivating example for modelling decisions in processes using digital signatures and zero-knowledge proofs. Therein, a verifier can verify that a process was executed correctly by the involved parties and according to specification without learning confidential information such as trade secrets or identities of the participants. We validate our system by applying it to the railway process, demonstrating how it realises various rules, and we evaluate its scalability with increased process complexities. Our solution is not railway-specific but also applicable to other contexts, helping leverage zero-knowledge proofs for public transparency and trust.
Certified computer systems are becoming the key in the increasingly complex decision making activities of our modern society. Among others, error-free and secure solutions are indispensable within AI, Autonomous Systems, Big Data, Blockchain, Decentralized Finance (DeFi), or Cloud Computing. While the explosion in applications of computer systems leads to great increases in productivity, wealth, and convenience, it creates a paradoxical situation: we rely on computer systems despite that uncountable many scenarios showcase that computer systems are not (properly) certified and hence are error-prone. The area of automated reasoning provides computer-aided solutions to prove that computer systems are error-free, just like we prove theorems in mathematics. However, who can tell software developers which automated reasoning solutions should be used? Moreover, which reasoning method is best to be used during code review, for ensuring system safety and security? This talk will reflect on some challenges of automated reasoning and focus on concrete applications of system verification security. We will highlight aspects of open-source code development, allowing others to easily use our solutions in their technologies without the need of becoming experts in automated reasoning.
The rapid expansion of the digital economy heightens the need for privacy and trust in intellectual property transactions. Traditional centralised approaches to identifying legal conflicts in intellectual property contracts are prone to data leakage and fail to balance transparency with confidentiality. This paper proposes a self-identification method for legal conflicts in intellectual property contracts using zero-knowledge proofs. By combining a light gradient boosting machine learning model with the zero-knowledge succinct non-interactive argument of knowledge protocol, our approach allows verifiable detection of potential legal conflicts without revealing sensitive information. Experiments on the US patent and trademark office patent dataset demonstrate that the method achieves high performance in conflict prediction (area under the receiver operating characteristic curve = 0.872) and verification efficiency (<10 ms), providing a novel and practical framework for privacy-aware legal technology.
Muhammad Rashid, Imran Rasool, Nazir Ahmad Zafar, Hamra Afzaal
Ethereum 2.0 stands out as a progressive decentralized blockchain platform, drawing attention for its security, scalability, and flexibility. Central to Ethereum 2.0 is the Beacon Chain, serving as the cornerstone managing validator rewards, penalties, attestations, and slashing mechanisms. Rewards and Penalties Mechanism (RPM) is of particular importance within the Beacon Chain as it includes validator balances based on their attestation behavior. Despite the critical role of RPM in maintaining the reliability and security of the Beacon Chain, the absence of formal verification work employing model checking is notable. Therefore, this research endeavors to fill this gap by employing formal verification technique to assess the RPM’s behavior concerning Friendly Finality Gadget (FFG) attestations. Utilizing Process Meta Language (PROMELA), a formal model of the RPM is specified, encompassing safety and liveness properties crucial for its robust functioning. The properties, including invalid attestation, integrity, fairness, availability, failure to attest, and inactivity imposition, are formalized through Linear Temporal Logic (LTL). Subsequently, the formal model alongside the specified properties is subjected to verification using the SPIN model checker. The properties are analyzed with respect to verification time, states visited, and memory usage. The outcome of this research contributes to a rigorous analysis of the RPM’s behavior. This work not only enhances an understanding of Beacon Chain’s operational dynamics but also underscores the importance of formal verification in ensuring the reliability and security of blockchain protocols.
With the G-20 prioritising the development of a solution that will address the challenges of cross-border payment, a lot of focus and research has been exploring ways of using a decentralised ledger technology (DLT) solution to address this challenge. Some of the issues that have been identified with the DLT option are interoperability, scalability, security, and privacy. Central Bank Digital Currencies (CBDCs) implementing DLT have also been acknowledged by experts as having the potential to address some of these challenges. Given the focus on CBDCs as an alternative technology that could address the shortcomings of traditional cross-border payment systems, some of the design challenges that are impacting their widespread adoption have come to the fore. Considering that early CBDC projects were in reaction to emerging digital currencies and therefore were meant to address the domestic needs of each implementing jurisdiction, the lack of a common development framework for developing the technology contributed to the challenge of the interoperability of the various CBDCs across jurisdictions and has impacted it’s fullscale adoption as an alternative to existing cross-border payment systems. With specific focus on regulatory frameworks used by various jurisdictions and also an identified challenge of CBDCs, this paper explores Customer Due Diligence (CDD) regulation as a mechanism for combating anti-money laundering (AML) and counter-terrorist financing (CFT). As part of the efforts to adapt cross-border payment system into a world of distributed ledgers relying on smart contracts, it reviews the impact of divergent regulatory frameworks that limit the interoperability of CBDCs. It discusses some of the existing techniques in place for conducting CDD, such as Know Your Customer (KYC) and how they fit with the new technology. It concludes with a proposal on how the incongruence of legal frameworks and AML/CFT regulations, can be addressed and standardised using new technologies such as Large Language Models (LLMs).
Current Drug Supply Chain (DSC) includes numerous independent participants with assorted interests. Today, DSC is confronted by several serious challenges related to shipping, special storage, traceability, and expiration, as well as ensuring sustainable access and availability of essential medicines. Furthermore, the number of counterfeit drugs has increased radically, causing thousands of individuals to be affected by poisoning and medical negligence. To address these issues, this research develops an effective track and trace model, calledLotTrace which leverages the Internet of Things (IoT), Blockchain Technology (BCT) and Non-Interchangeable Tokens (NITs) to trace drug lots from manufacturing process to consumption. NIT is a distinctive digital identifier of physical and virtual assets logged on a BCT to attest to proprietorship and legitimacy. LotTrace uses smart contracts and Hyperledger technology for dependable and effective traceability of pharmaceutical products. The lot details are updated across the chain, and erstwhile information is continuously logged in the ledger blocks. It instigates traceability by allocating inimitable identifiers to drug lots and logs incidents and signposts, providing an end-to-end traceability that allows partakers to authenticatethe genuineness and provenance of the drug products. LotTrace mints virtual tokens to digitize the metadata such as the certifications, present owner, current location, environmental conditions of a drug lot. After gathering these essential data from the drug manufacturer, metadata will be included based on shipping environmental conditions to mint Dynamic NIT (dNIT). This information is recorded in the BitTorrent File System (BTFS) to build a real-world storage infrastructure. Ratified stakeholders can access this information using the smart contracts. This work creates an NIT smart contract on the ERC1155 standard using the Remix Integrated Development Environment (IDE). LotTrace exploits BTFS to solve the issue of processing big documents on the Web 3.0 ecosystem and guarantees that the information are immutably stored in a secured way. This systemrecords the drug attributes and its appropriate metadata during itslife cycle from manufacturing to consumption. The research also provides testing details and evaluates the feasibility of tracing solution. This study evaluate the effectiveness of LotTrace system in terms of the cost of system transactions.
Ken Lew, Arijet Sarker, Simeon Wuthier, Jinoh Kim · 6 authors
Computing and networking are increasingly implemented in software. We design and build a software build assurance scheme detecting if there have been injections or modifications in the various steps in the software supply chain, including the source code, compiling, and distribution. Building on the reproducible build and software bill of materials (SBOM), our work is distinguished from previous research in assuring multiple software artifacts across the software supply chain. Reproducible build, in particular, enables our scheme, as our scheme requires the software materials/artifacts to be consistent across machines with the same operating system/specifications. Furthermore, we use blockchain to deliver the proof reference, which enables our scheme to be distributed so that the assurance beneficiary and verifier are the same, i.e., the node downloading the software verifies its own materials, artifacts, and outputs. Blockchain also significantly improves the assurance efficiency. We first describe and explain our scheme using abstraction and then implement our scheme to assure Ethereum as the target software to provide concrete proof-of-concept implementation, validation, and experimental analyses. Our scheme enables more significant performance gains than relying on a centralized server thanks to the use of blockchain (e.g., two to three orders of magnitude quicker in verification) and adds small overheads (e.g., generating and verifying proof have an overhead of approximately one second, which is two orders of magnitude smaller than the software download or build processes).
As the complexity of the global food supply chain continues to grow, ensuring food quality and safety has become an important challenge for the global food industry.Food quality and safety traceability is a key methodology that can be used to track the origin and quality of food to ensure food safety.Meanwhile, blockchain technology, as a distributed ledger technology, provides new opportunities for food traceability.This study aims to explore how to integrate blockchain technology and data fusion analysis to improve the efficiency and accuracy of food quality and safety traceability.This paper first reviews the advantages of blockchain technology in food traceability and introduce the key concepts of data fusion analysis.Then, this paper proposes a blockchain-based framework for food quality and safety traceability, describing in detail the process of data collection, cleaning, fusion and analysis.Through practical case studies, this paper demonstrates the application of the framework in the field of grain quality and safety, and presents the fusion analysis results.Finally, the paper discusses future directions, including technical challenges, regulatory implications, and sustainability considerations.This study provides strong support for the integration of food quality and safety traceability and blockchain technology, which is expected to contribute to the further development of global food security and quality management.
Hugues Blache, Pierre-Antoine Laharotte, Nour‐Eddin El Faouzi
The deployment of Automated and Connected Vehicles (ACV) into traffic requires certifications and validations guaranteeing high levels of safety, security and reliability. The underlying objective is to gain public acceptance by proving that automation systems might bring out a safer mobility. While plenty of methods to certify these systems are populating the literature, the scenario-based approach stands out by reducing the quantity of required Field tests to validate any new system at stake. In this study, we refine the scenario-based approach by proposing a proof of concept (PoC) for scenario reduction using criticality metrics. For this PoC, we weave a relationship between the a priori criticality of abstract functional scenarios and the words used to generate them. Once, the criticality of a subset of scenarios is qualified based on open field data (HighD), the Latent Dirichlet Allocation (LDA) clustering approach is used to generate topics and feature the relationship between observed criticality and semantics words applied to functional scenarios. The criticality degree of semantics words is used to predict the a priori criticality of unobserved functional scenarios.
In this paper, a blockchain-based trusted authentication model is proposed to secure the civil aviation ground-to-air communication. Considering the limited bandwidth and high latency of ground-air communication, the Interplanetary File System (IPFS) is used to store avionics equipment information and server equipment information before the plane takes off. Through hash calculation, a unique hash value is obtained as the identity credential for each communication to authenticate. Obtain the key and address of each entity from Ethereum, and realize the registration of avionics system and server information by designing and writing Ethereum smart contracts, as well as the creation of certificates for the avionics system. During the flight, each ground-air communication needs to be signed with a private key for the sent information, and the public key is uploaded to the blockchain trusted storage. In addition, the server authenticates the signature and the result of the interplanetary file system query, and the smart contract authenticates the certificate to ensure that only avionics devices in the trusted domain with verified certificates can take up normal ground-to-air communication between the ground server and the onboard server. The simulation experimental results show that the model can achieve secure ground-to-air communication with low communication overhead and achieve trusted authentication of the avionics devices in communication.
Abstract Currently, inconsistent software versions lead to massive challenges for many car manufacturers. This is partly because within the product lifecycle management and the software engineering process, there is no correct handling of software versions for the “data entry” (installation of software on the ECU) of the vehicles. Furthermore, there are currently major challenges for many vehicle manufacturers to ensure transparency, integrity and full traceability of SW data status vis-à-vis the legislator. To counteract these challenges, new solutions in the field of vehicle engineering are to be developed based on a new platform called “CarEngChainNet” and Blockchain technology. On the basis of the “CarEngChainNet” platform, new main and sub-chain chains will be developed that allow tamper-proof SW data management (Peer to Peer and crypto technology) across the entire PLM chain with new methods such as model-based systems engineering of the requirement, function and integration of the SW components in different areas of vehicle development. The aim is to develop new transmission chains of vehicles with individually packaged software artefacts (e.g. ECU software) that can be securely transmitted from server to server into the vehicle.
Donghang Lu, Pedro Moreno-Sánchez, Pramita Mitra, Ken Feldman · 7 authors
<div>The lack of traceability in today’s supply-chain system for auto components makes counterfeiting a significant problem leading to millions of dollars of lost revenue every year and putting the lives of customers at risk. Traditional solutions are usually built upon hardware such as radio-frequency identification (RFID) tags and barcodes, and these solutions cannot stop attacks from supply-chain (insider) parties themselves as they can simply duplicate products in their local database.</div> <div>This industry-academia collaborative work studies the benefits and challenges associated with the use of distributed ledger (or blockchain) technology toward preventing counterfeiting in the presence of malicious supply-chain parties. We illustrate that the provision of a distributed and append-only ledger jointly governed by supply-chain parties themselves makes permissioned blockchains such as Hyperledger Fabric a promising approach toward mitigating counterfeiting. Meanwhile, we demonstrate that the privacy of supply-chain parties can be preserved as competing supply-chain parties strive to protect their businesses from the prying eyes of competitors and counterparties. Besides, we show that the recall process can be achieved efficiently with the help of the blockchain. The proposed solution, Fordchain, overcomes the challenges to achieve the best of both worlds: a solution to the counterfeiting problem using distributed ledger technology while providing accountability and the privacy notions of interest for supply-chain parties. Although our efforts to build a blockchain-based counterfeiting prevention system aim at automotive supply chains, the lessons learned are highly applicable to other supply chains. We end-to-end implement our Fordchain solution in the Hyperledger Fabric framework, analyze it over AWS EC2 clusters, and illustrate that the performance of our solution is good enough to be applied in practice.</div>
Jan 1, 2020·Proceedings of the ... Annual Hawaii International Conference on System Sciences/Proceedings of the Annual Hawaii International Conference on System Sciences
Sarra Alqahtani, Xinchi He, Rose Gamble, Papa Mauricio
The smart contract technology has increasingly attracted the attention of different industries. However, a significant number of smart contracts deployed in practice suffer from several bugs, which enable malicious users to cause damage. The research community has shifted their focus to verifying the correctness of smart contracts using model checkers and formal verification methods. The majority of the research investigates the correctness of systems built on one smart contract. This paper proposes a verification approach for systems composed of interacting smart contracts developed and controlled by different entities. We use the NuSMV model checker and the Behavioral Interaction Priority tool to model the behaviors of smart contracts and their interactions with the aim of verifying their compliance with the systems’ functional requirements. These requirements are formalized by Linear Temporal Logic propositions. The applicability of our approach is illustrated using a case study from The American Petroleum Institute and implemented using Hyperledger Fabric.
Insufficient authentication and authorization of interconnected components are major risks in the Industrial Control System (ICS). To address this, we introduce CyRA, a realtime risk-based security assessment framework that consists of a Nested-ICS security architecture, secure registration protocol, and risk-based multi-factor authentication protocol by which every component is authenticated and authorized to ensure secure communications and prevent cyber attacks in the ICS. Our proposed framework applies Zero-Knowledge Proof of Knowledge (ZKPK) to perform risk-based multi-factor authentication and authorization using a digitally signed identity that encodes secrets provided by the component. Our approach is based on Threat Modeling (TM), Vulnerability Identification (VI), and Consequence Analysis (CA) to provide adequate and efficient authentication and authorization in the ICS. The resilience of our framework is evaluated against recent well-known cyber attacks. Specifically, we conduct a risk-based security assessment for a Safety Instrumentation System (SIS) communication protocol, known as TriStation. The results show that our framework enhances the security of the protocol in dealing with real-time uncertainty of threats, vulnerabilities, and consequences from a new cyber-attack, known as TRITON malware.
In recent years, there is growing interest in the ways the European aviation industry can leverage the multi-source data fusion towards augmented domain intelligence. However, privacy, legal and organisational policies together with technical limitations, hinder data sharing and, thus, its benefits. The current paper presents the ICARUS data policy and assets brokerage framework, which aims to (a) formalise the data attributes and qualities that affect how aviation data assets can be shared and handled subsequently to their acquisition, including licenses, IPR, characterisation of sensitivity and privacy risks, and (b) enable the creation of machine-processable data contracts for the aviation industry. This involves expressing contractual terms pertaining to data trading agreements into a machine-processable language and supporting the diverse interactions among stakeholders in aviation data sharing scenarios through a trusted and robust system based on the Ethereum platform.