
In order to ensure traffic efficiency and network security, an accurate intrusion detection system (IDS) is pivotal in the software-defined networking (SDN)-enabled vehicular ad-hoc network (VANET) environment. However, the traditional methodologies failed to identify the presence of stealthy beacons (SBs) in the VANET environment, thus degrading the system’s reliability. Hence, an enhanced SDN-powered vehicle IDS with SB identification based on blockchain (BC)-enabled deep federated transfer collapsing linear unit R-drop alpha regularized-recurrent neural network is proposed in this article. Initially, the vehicles register in the data plane, followed by application programming interface (API) key generation and digital signature creation (DSC). Afterward, the sensed data are transferred while mitigating the collision. The digital signature verification (DSV) is done in the south-bound APIs. Once the verification is successful, the data are fed into the control plane via the switch. The control messages are protected in the control plane. In addition, the DSV is done in the north-bound APIs. By utilizing the fuzzy bimodal triangular membership inference system (FBTMIS), the presence of an SB is identified in the application plane. If the SB is present, then the transmitted data are terminated; otherwise, the trained local IDS model is utilized for categorizing the data into benign or malignant. Furthermore, to track the attacker’s behavior, the trapdoors are utilized. Thereafter, the detected events are stored in the BC and further broadcast to the vehicles. Similarly, through the router and firewall, the outcomes are updated in the global model (GM) on the server. Therefore, the proposed approach had high reliability with an accuracy of 99.9742%.
Payment channel networks are one of the most promising off-chain solutions to the blockchain scalability problem. However, with the development of quantum computers, most of the payment channel network solutions that resist wormhole attacks are not able to resist adversaries that can access quantum computers. To solve this problem, we use NTRU and AES to design a post-quantum onion router based on the onion routing protocol to ensure the unlinkability and security of onion packets in the delivery process and realize the identity privacy of the payment path nodes. Secondly, we propose the LWE-based time-locked contract (LTLC), which defines the unidirectional problem in the commitment phase as a learning with error problem, and reduces the contraction to the lattice-hard problem to avoid the relaying cost from being stolen by malicious nodes with access to the quantum computer using wormhole attacks, but incurs high-performance overhead. To improve the performance, we further propose a Ring-LWE-based time-locked contract (RLTLC). The communication and computation costs of RLTLC are approximately 3.36% and 10.2% of those of LTLC, respectively. The security analysis and performance evaluation show that the scheme in this paper achieves relational anonymity, atomicity, and resistance to wormhole attacks for post-quantum payment channel networks, and the performance overhead of RLTLC remains acceptable even under quantum computing threats.
With the rapid development of quantum computing technology, blockchain systems based on traditional digital signature algorithms (such as elliptic curve digital signatures) face potential security risks. To construct post-quantum-secure blockchains, this paper primarily integrates the lattice-based post-quantum digital signature algorithm Dilithium-Prime into a UTXO model blockchain system. Given that the Dilithium-Prime algorithm faces challenges such as large storage overhead and lack of key derivation capabilities while ensuring post-quantum security, this paper proposes targeted solutions: innovatively designing UTXO_PUBKEY transaction data structures, separating public key storage from transaction execution logic, and introducing Pubkey-type UTXOs to reuse public key resources; simultaneously optimizing private key storage strategies by using dynamic seeds as temporary private keys to reduce long-term storage pressure on user nodes. This paper provides optimization ideas and directions for the efficient application of lattice-based signature schemes in UTXO-type blockchains, which has important theoretical and practical value for promoting the development of post-quantum blockchain systems.
Non-Fungible Tokens (NFTs) are widely used nowadays for managing digital assets in many applications due to their ability to uniquely identify an asset and securely transfer and trace its ownership. Some scenarios require digital assets to be mutable, i.e., users should be allowed to update asset attributes over time, thus introducing possible security issues, since unwanted (or even malicious) updates could significantly decrease assets’ value. While various methods for NFT mutability exist, they often lack integrated, fine-grained, and on-chain enforceable authorisation models. This paper addresses this issue by considering an NFT expansion, named Non-Fungible Mutable Token (NMT), which natively supports the update of the attributes characterising each digital asset while guaranteeing a strict and fine-grained control over such updates. In fact, the NMT approach embeds an on-chain security support based on the Attribute-Based Access Control model within the NMT architecture, aimed at regulating, through access control policies enforcement, the execution of all the update operations defined on digital assets, from new token minting to ownership transfers and attribute updates.We propose a detailed architecture for NMTs and we outline the involved smart contracts structure, including the on-chain access control system. We validate our proposal by implementing it for two common use cases, wearables and digital event tickets in the metaverse, and by conducting an experimental evaluation of the deployment and execution costs. Moreover, we simulated the usage of NMTs over a given time interval to estimate the sustainability of the proposed approach over time.
As the amount of data generated by terminal devices continues to increase, the data owner (DO) often outsources data to the service provider (SP) to mitigate the burden on local storage and computing resources. Since the physical control of data is transferred to semi-trusted cloud service provider, the outsourced data becomes vulnerable to tampering or damage. Hybrid-storage blockchain is a promising solution for distributed and secure data storage. However, considering that DO may outsource data to multi-SPs in actual scenarios, the current verification scheme is inadequate for supporting fine-grained verifiable queries. The user is unable to discern which data from which SP in the query result has been forged or omitted, and can only receive all or discard all, resulting in huge re-query and transmission costs. First, we propose the fine-grained verifiable data query (FVDQ) scheme, which organizes data into a matrix or cube form, constructs row and column (face) digests using vector commitments and accumulators, and verifies these digests to pinpoint the location of tampered or omitted data. Furthermore, we propose FVDQ for multi-SPs (FVDQ4M), which extends the fine-grained verifiable query approach to multi-SPs environments. By constructing hierarchical vector commitments, FVDQ4M enables users to identify the SP from which the forged results come from. Finally, we present an efficiency-optimized FVDQ4M+ scheme, which reduces on-chain storage costs and off-chain redundant queries, and achieves enhanced query efficiency by digest aggregation and bloom filter-based routing mechanism. Experimental results show that compared with the baseline scheme, our scheme takes less VO construction time and verification time.
Smart contracts are immutable programs that automatically execute predefined logic. Once deployed, their underlying vulnerabilities are notoriously difficult to patch and highly susceptible to malicious exploitation, often leading to severe financial losses. Although existing vulnerability detection methods have demonstrated certain advantages, they still fail to achieve adequate structural–semantic coverage of vulnerability-relevant behaviors, as they are unable to jointly model opcode semantics, control-flow transitions, and data-dependency relations. To overcome these limitations, this paper proposes a novel smart contract vulnerability detection model named Cross-aligned Penetrative Graph Network (CPGNet). Specifically, CPGNet first constructs control flow graphs and data flow graphs from the abstract syntax tree, and combines them with opcode semantic embeddings to form a multidimensional initial code representation. Based on this representation, a cross-alignment mechanism is introduced to effectively capture and integrate the complex interactions between control-flow transitions and data-flow dependencies. Furthermore, an explicit–implicit feature penetration architecture is designed to inject shallow local opcode patterns into the deep semantic modeling process, enabling multi-source features to dynamically complement each other. By jointly modeling opcode semantics, control-flow structures, and data-dependency relations, CPGNet significantly enhances the representation capability for hidden and complex vulnerability patterns. Experimental results on two datasets show that CPGNet achieves stable performance, with F1-scores of 88.69% and 90.58% on the benchmark Ethereum dataset, and 78.10% and 71.53% on DIVE for reentrancy and timestamp dependency detection, respectively. These results verify the effectiveness of jointly modeling opcode semantics and graph-level structural dependencies.
In the context of digital transformation, e-government has become a key path for governments to improve administrative efficiency and optimize the supply of public services. However, the centralized database management model adopted by the existing government approval system faces challenges such as the continuous expansion of data storage scale, insufficient security and privacy protection, and difficulty in tracing data tampering, which restricts the real-time and credibility of approval services. To this end, this study constructs a hybrid on/off-chain blockchain architecture featuring layered encryption and optimized consensus mechanisms. This architecture uses a hierarchical attribute-based encryption algorithm and an improved Merkle tree indexing mechanism to achieve security verification and hierarchical privacy protection of multidimensional government data; at the same time, it uses a hierarchical Practical Byzantine Fault Tolerance consensus protocol(PBFT) to reduce communication complexity and introduces a dynamic equity adjustment factor to improve consensus efficiency, thereby ensuring the real-time response capability of approval services. Experimental results demonstrate that, compared to the traditional blockchain baseline (Hyperledger Fabric), our system achieves substantially higher throughput and markedly lower latency, approaching the performance profile of a centralized system. Furthermore, it outperforms advanced PBFT variants: in a 50-node network, our approach improves throughput by approximately 62.3% over RPBFT and 36.7% over DS-PBFT. Its average consensus latency is also reduced by 21.8% compared to RPBFT and 34.5% compared to DS-PBFT. This work offers a system-level solution for high-concurrency government approval scenarios that effectively combines data credibility, real-time performance, and security.
Light client verification is foundational for resource-constrained devices to achieve decentralized trust in consortium blockchains. However, traditional schemes such as Simplified Payment Verification (SPV) incur linear storage growth O(L) with block height. Although Merkle Mountain Range (MMR) accumulators offer theoretically logarithmic efficiency, current implementations face a critical deployment barrier: they rely on hard forks to embed accumulator roots into block headers. For deployed consortium blockchains, this necessitates invasive protocol upgrades that disrupt service continuity, rendering such solutions operationally prohibitive.To resolve this dilemma, this paper proposes a non-invasive light node verification framework with constant-size persistent client storage that enables zero-downtime upgrades for deployed consortium blockchains. Instead of invasive header modifications, we introduce a Soft Anchoring paradigm: maintaining MMR roots directly within smart contract storage. By leveraging the intrinsic cryptographic commitment of the contract state into the global State Root, our approach inherits the security of the underlying consensus while ensuring seamless backward compatibility. We further introduce two complementary update protocols—quorum-certified checkpoint submission and deterministic recomposition—to balance efficiency and trust. Experimental results on FISCO BCOS demonstrate that our framework reduces the light client’s persistent trusted state to constant size O(1), while query-time witness retrieval remains a separate logarithmic communication cost, and achieves sub-second verification latency under the stated Cortex-M4-class latency profile.
Traditional agricultural traceability systems often suffer from centralized data management, fragmented lifecycle records, weak tamper resistance, and limited scalability in multi-stakeholder supply chains. To address these issues, this study proposes a Hyperledger Fabric-based agricultural quality traceability framework that combines consortium blockchain, smart contracts, and an improved Group-Aggregation PBFT (GA-PBFT) consensus mechanism. The framework models key supply-chain stages, including cultivation, harvesting, processing, warehousing, and quality inspection, and uses modular smart contracts to standardize the registration, transfer, reception, processing, and lifecycle assessment of traceability data. To improve consensus efficiency, GA-PBFT integrates reputation-based node grouping with BLS aggregate signatures, reducing inter-node communication complexity from O(N2) to O(N) while preserving Byzantine fault tolerance. A smart contract-based cotton traceability prototype was implemented on Hyperledger Fabric to verify the feasibility of the proposed framework. Experimental results show that GA-PBFT maintains lower communication overhead and better scalability than traditional PBFT as the number of nodes increases. System benchmark tests further indicate that the average latency of write transactions is 0.09 s, whereas read-only transactions have near-zero latency, demonstrating that the prototype can support high-concurrency traceability queries and data uploads. The proposed framework provides a practical and extensible solution for trustworthy agricultural supply-chain traceability and offers technical support for digital quality supervision in the agricultural sector.
Land is a fundamental resource with significant economic and social value. Land transactions are often carried out by individuals to fulfill their specific needs and requirements that are usually maintained by different governmental offices. However, a land record (LR) generally contains sensitive information associated with the land. In recent decades, the shift from traditional paper-based approaches to digital systems has become increasingly prevalent. Moreover, this transition has brought about certain challenges, including the potential for single-point failures and security vulnerabilities. A blockchain-powered land record management system (LRMS) has the potential to effectively address and resolve the current challenges while maintaining robust security measures. To design a blockchain-based secure LRMS, this paper develops a new lightweight cryptosystem based on a newly proposed hybrid chaotic map that ensures LR privacy. In addition, the paper also proposes a dynamic way of character to integer mapping scheme named the dynamic character to integer (C2I) table that enhances encryption complexity while reducing conversion overhead by approximately 33% compared to the ASCII table. Besides, it streamlines the process of ownership transfer by facilitating a decentralized land trading platform. Moreover, LR integrity is maintained by incorporating both InterPlanetary File System (IPFS) and blockchain as storage. Finally, the experimental results, analyses, and comparisons indicate the effectiveness of the proposed LRMS over the state-of-the-art systems.
Secure cross-domain identity authentication is critical for data access in multi-domain environments. However, traditional authentication often suffers from interoperability issues, complex cross-certification, and misaligned policy coordination across disparate trust domains. Furthermore, existing solutions typically rely on centralized trusted third parties (e.g., PKIs/CAs), introducing single points of failure and key-escrow vulnerabilities. While blockchain technology provides decentralized trust, its naive application risks exposing sensitive identity information on-chain. To address these challenges, this paper proposes a lightweight, privacy-preserving cross-domain authentication scheme integrating blockchain with zero-knowledge proofs. Specifically, we utilize KZG polynomial commitments and dynamic membership accumulators for verifiable credential management and efficient revocation. Meanwhile, a non-interactive zk-SNARK protocol facilitates anonymous cross-domain authentication without leaking sensitive attributes. Our design achieves a practical balance among user anonymity, identity revocability, and system auditability. Additionally, we introduce a domain-management snapshot mechanism to accelerate intra-domain verification and support incremental state updates. Comprehensive security analysis and performance evaluations demonstrate that the proposed scheme is secure, efficient, and highly scalable for decentralized multi-domain authentication.
Numerous reports and studies indicate that the lack of effective regulation in cryptocurrencies has not only led to substantial financial losses but also eroded the traditional ”central bank-commercial bank” framework, thereby destabilizing financial systems. To address these issues, a growing body of research has focused on developing regulatory mechanisms for cryptocurrencies. However, existing regulatory proposals face a persistent trilemma: they fail to simultaneously achieve three critical properties—(i) one‑time registration with self‑updating addresses, (ii) completeness (including a lost‑coin retrieval mechanism), and (iii) fine‑grained access control that respects the ”central bank‑commercial bank” framework. This study bridges this gap by proposing TCoin, the first regulatory cryptocurrency that fulfills all three requirements. We first introduce TSFG, a traceable scheme built on SkyEye, which employs cryptographic techniques to achieve one‑time registration with self‑updating addresses and fine‑grained access control for tracing. By integrating TSFG into the RSCoin framework, we construct TCoin—a regulatory cryptocurrency that achieves one‑time registration with self‑updating addresses, ensures completeness through a novel coin recovery mechanism, and enforces fine‑grained access control. Compared to prior work (CB, DAP, PDC, RSCoin, e‑CNY, and RECoin), TCoin is the first to resolve the regulatory trilemma, offering a comprehensive solution that reconciles the disruptive potential of cryptocurrencies with the stability requirements of the traditional monetary system.
This study examines how blockchain technology (BT) can extend the conventional double-entry accounting (DEA) framework to improve financial information transparency. The study revisits the duality concept underlying DEA and explores its development toward a triple-entry accounting (TEA) structure supported by blockchain infrastructure. Using a design science approach in information systems, the study proceeds through problem identification, artefact definition, and conceptual system design. Drawing on the resource-event-agent (REA) framework, the study develops a conceptual architecture that integrates a third ledger into the accounting entry system. The proposed model positions message type (MT) as a navigational mechanism that coordinates transaction validation within a blockchain-enabled TEA environment. This structure supports improved tracking, verification, and transparency of financial information, particularly in external transactional relationships. The findings contribute to the ongoing discussion on blockchain-based accounting systems by clarifying how the duality principle can evolve within a distributed ledger environment. The study also outlines potential directions for future research on the development of triple-entry accounting and third-ledger mechanisms in accounting information systems.
Tokenization of real-world assets (RWAs) as non-fungible tokens (NFTs) is increasingly used to represent ownership and rights on blockchains. While NFTs are issued on a single blockchain, they may be traded across multiple marketplaces, each relying on different metadata schemas. This results in inconsistent interpretation of asset attributes such as valuation, usage rights, and provenance, limiting interoperability and reliable presentation of tokenized assets. In this paper, we present MOSAICO, a framework that introduces a shared semantic layer for NFT metadata. MOSAICO formalizes NFT metadata using a domain-specific ontology enabling precise and machine-interpretable representation of asset properties and constraints. An adaptive metadata adapter service then translates this semantic representation into marketplace-specific metadata formats, ensuring consistent interpretation and display across multiple platforms. The framework is validated through OWL reasoners HermiT and Pellet used for cross-validation and a custom full-branching tableau reasoner with justification and clash tracing used to explain satisfiability and inconsistencies in NFT class definitions. In addition, SPARQL queries verify structural constraints and semantic invariants across NFT instances. Experimental results show that MOSAICO enforces semantic consistency and enables marketplace-agnostic interpretation of tokenized assets.
Hyperledger Fabric’s migration to Byzantine Fault-Tolerant (BFT) consensus via SmartBFT-Go represents a significant security upgrade from previous crash fault-tolerant versions. While BFT theory guarantees safety and liveness under network synchrony assumptions, our analysis reveals that a single Byzantine node can exploit implementation-specific design choices to induce cascading failures and effective livelock. Through a client request flooding attack, we demonstrate how SmartBFT-Go’s request handling can be exploited to violate the bounded delay property essential for practical systems, triggering a feedback loop of view changes, timeouts, and desynchronization that severely degrades or halts practical service availability, despite the protocol’s theoretical resilience guarantees. Experimental results show attack-induced latency escalation from 150ms to 4.5s (30x) and end-to-end delays exceeding 200 seconds–severe performance degradation contradicting theoretical BFT assumptions. Our solution addresses this implementation gap through a queue management system that maintains BFT security guarantees while eliminating attack-induced overhead, reducing latency by 98.7% under sustained bombardment. This work bridges the gap between BFT theory and production-grade implementations, providing both vulnerability analysis and practical hardening measures for enterprise blockchain systems.
In the blockchain-based social network platforms, consensus algorithms still cannot take into account both security and performance. In addressing the aforementioned challenges, we introduce SNPBFT, a pragmatic Byzantine fault-tolerant algorithm tailored for social networks. This algorithm leverages a reputation model to optimize both the selection of master nodes and the consensus mechanism among nodes. It can reduce request latencies and improve system throughput while enhancing the algorithm’s resilience against Byzantine attacks. Specifically, we designed a reputation model based on user social behavior for the first time. For the four social behaviors of browsing, liking, commenting and sharing, we use a linear weighting method to calculate the reputation value of nodes, dynamically updating and determining the final reputation value in a distributed manner. This approach enhances the reliability of the reputation value and reduces the probability of malicious nodes dominating the consensus process. Meanwhile, considering the large volume of social media communication, we simplify the PBFT consensus process and remove the submission stage to improve the efficiency of the consensus communication. The experimental results demonstrate that, in comparison to the other five benchmark algorithms, the SNPBFT algorithm reduces the average latency by 17.44% and increases the average throughput by 23.76%. Meanwhile, the SNPBFT algorithm has good scalability and stability for different sizes of node numbers and request loads. Furthermore, the SNPBFT algorithm maintains a high consensus success rate, exhibits commendable latency and throughput performance under malicious node attacks and reputation attacks, thereby fulfilling the consensus requirements of blockchains in social networks.
Blockchain technology is the foundation for cryptocurrencies, facilitating their use and global adoption. However, the extent of acceptance of cryptocurrencies varies significantly across different political regimes. The cryptocurrency literature has yet to empirically examine the relationships among cryptocurrency usage, political regimes, technology, society, institutions, and the macro-environment. Therefore, this study examines the influence of governance on cryptocurrency ownership, highlighting the mediating roles of financial systems and the macroeconomic environment in both autocratic and democratic contexts. The study employs partial least squares structural equation modeling (PLS-SEM), a statistical technique for analyzing complex relationships between observed and latent variables, using WarpPLS 8.0 software. This approach enables an in-depth examination of how governance, financial systems, and macroeconomic conditions interplay to influence cryptocurrency ownership. Data from 43 countries spanning 9 years (2016–2024) are used, encompassing a mix of autocratic and democratic regimes. The dataset includes variables such as governance quality, financial market efficiency, banking system quality, and trust within financial markets. Macroeconomic conditions and cryptocurrency ownership rates were also considered. The results indicate that stronger governance, stable macroeconomic conditions, and advanced financial and banking infrastructures are associated with lower levels of cryptocurrency ownership. Conversely, weak regulatory frameworks and unreliable financial systems appear to foster greater investment in cryptocurrencies. By illustrating the interconnectedness of governance, financial systems, and macroeconomic conditions, this research contributes a new perspective on the global variation in cryptocurrency adoption. These findings are essential for informing future regulatory frameworks and financial policies amid a growing digital landscape economy.
With the exponential growth in the demand for cloud computing, data security and integrity are becoming critical issues when the data is outsourced to the cloud. To address these issues, this paper proposes a lightweight privacy-preserving federated blockchain framework for cloud data. Unlike traditional mechanisms, the proposed framework minimizes computational and storage overhead by storing only encrypted metadata on the blockchain, which ensures end-to-end data encryption and pseudonymity of user identities. Experimental results demonstrate the validity of the framework’s scalability and efficiency, achieve a 47% reduction in key generation time, 40% faster data registration, and a 50% decrease in auditing overhead compared to state-of-the-art approaches. The framework is evaluated under simulated multi-cloud environments. Therefore, the proposed work provides a novel, scalable, and privacy-centric solution for secure cloud data management in the Internet of Things era, setting a new benchmark for lightweight and privacy-enhanced data provenance in distributed environments.
With the rapid proliferation and interconnection of massive IoT devices, efficient and secure identity authentication has become a crucial prerequisite for ensuring communication security. Establishing trust among mutually untrusted devices remains a key research focus. Leveraging its tamper-resistance and traceability, blockchain technology has emerged as a foundational infrastructure for building trustworthy identity management systems. However, existing blockchain-based identity authentication schemes face critical challenges in large-scale IoT environments, including low authentication efficiency, complex certificate management, and risks of user privacy leakage. Achieving a balance among authentication efficiency, certificateless key management, and privacy protection remains a pressing challenge.In this paper, we propose a certificateless identity authentication scheme based on blockchain sharding. The scheme employs blockchain sharding to parallelize identity authentication across multiple shards, significantly enhancing overall efficiency. Within each shard, a certificateless public key cryptography (CL-PKC) scheme is adopted to eliminate certificate issuance and enable key generation via user interaction, thereby reducing key management overhead and improving security. For cross-shard authentication, a registration-based encryption (RBE) mechanism is utilized, allowing users to authenticate via their identity after registration. Any verifier can confirm the legitimacy of the authentication message solely based on the registration information and the user ID, ensuring transparency and public verifiability. Furthermore, a zero-knowledge proof-based verifiable credential (VC) selective disclosure mechanism is introduced, enabling users to reveal only the minimal necessary information required for authentication while protecting sensitive identity attributes.Experimental results demonstrate that the proposed scheme maintains high throughput under high-concurrency scenarios while effectively preserving user privacy.
Regenerative Finance (ReFi) is a Web3 ecosystem for tokenizing, trading, and retiring voluntary carbon credits on blockchain. Yet whether these networks are truly decentralized, and whether such decentralization predicts future on-chain carbon credit retirement, remains unclear. Using daily ERC-20 transfer records for Toucan Protocol’s BCT and KlimaDAO’s KLIMA tokens on Polygon from June 1, 2022, to August 31, 2025, we develop a composite framework for measuring transaction-network decentralization across participation, flow, structure, and temporal persistence. We further examine whether the level of decentralization predicts future on-chain retirement, measured by retired amount, retirement count, and retirement participants. We find that ReFi transaction networks do not fully realize their decentralization promise, instead mostly exhibiting significant core–periphery structure and lower decentralization than benchmark DeFi protocols such as Uniswap and Aave. Within ReFi, KlimaDAO exhibits a more decentralized transaction network than Toucan Protocol, with its composite index exceeding Toucan’s by 0.74 pooled standard deviations on average, mainly through broader participation, more dispersed value flows, and higher structural decentralization. Moreover, higher decentralization is associated with stronger future cumulative on-chain retirement, mainly in retirement count for Toucan Protocol and in both retired amount and retirement count for KlimaDAO, consistent with Toucan’s infrastructure-layer and KlimaDAO’s application-layer settings. These findings suggest that transaction-network decentralization is central to evaluating whether ReFi markets translate tokenization into actual carbon-credit use.