Topic Editors

Dr. Longxiang Gao
Shandong Fundamental Research Center for Computer Science, Jinan, China
Dr. Bruce Gu
Shandong Fundamental Research Center for Computer Science, Jinan, China

Security and Privacy in Distributed and Trustless Systems

Abstract submission deadline
31 January 2027
Manuscript submission deadline
31 March 2027
Viewed by
4466

Topic Information

Dear Colleagues,

Distributed and trustless systems are becoming a foundational paradigm for modern data-driven applications, enabling large-scale collaboration without relying on centralized authorities or fully trusted intermediaries. Such systems, including blockchain networks, federated learning frameworks, decentralized AI, and multi-agent platforms, introduce new opportunities for secure data sharing and autonomous coordination, while simultaneously raising critical challenges in data security and privacy protection.

This Topic aims to explore recent advances in security- and privacy-preserving techniques for distributed and trustless environments. We invite contributions that investigate theoretical foundations, algorithmic designs, system architectures, and practical deployments addressing threats such as data leakage, inference attacks, malicious participants, and trust misalignment. Topics of interest include, but are not limited to, cryptographic protocols, secure and verifiable computation, privacy-preserving machine learning, decentralized data governance, and trustworthy AI systems. By bringing together interdisciplinary research from security, distributed systems, and artificial intelligence, this Topic seeks to provide a comprehensive view of emerging challenges and solutions for building secure, privacy-aware, and trustworthy distributed systems.

Dr. Longxiang Gao
Dr. Bruce Gu
Topic Editors

Keywords

  • distributed systems
  • trustless computing
  • data security
  • privacy protection
  • data & model governance

Participating Journals

Journal Name Impact Factor CiteScore Launched Year First Decision (median) APC
Algorithms
algorithms
2.6 5.4 2008 17.6 Days CHF 1800 Submit
Applied Sciences
applsci
2.9 6.1 2011 15 Days CHF 2400 Submit
Blockchains
blockchains
- - 2023 23.8 Days CHF 1000 Submit
Computers
computers
5.2 9.1 2012 15.4 Days CHF 1800 Submit
Cryptography
cryptography
2.4 6.4 2017 19.9 Days CHF 1800 Submit
Future Internet
futureinternet
4.6 10.0 2009 15 Days CHF 1800 Submit
Information
information
4.3 8.2 2010 18.7 Days CHF 1800 Submit
Network
network
3.7 8.0 2021 23.2 Days CHF 1200 Submit

Preprints.org is a multidisciplinary platform offering a preprint service designed to facilitate the early sharing of your research. It supports and empowers your research journey from the very beginning.

MDPI Topics is collaborating with Preprints.org and has established a direct connection between MDPI journals and the platform. Authors are encouraged to take advantage of this opportunity by posting their preprints at Preprints.org prior to publication:

  1. Share your research immediately: disseminate your ideas prior to publication and establish priority for your work.
  2. Safeguard your intellectual contribution: Protect your ideas with a time-stamped preprint that serves as proof of your research timeline.
  3. Boost visibility and impact: Increase the reach and influence of your research by making it accessible to a global audience.
  4. Gain early feedback: Receive valuable input and insights from peers before submitting to a journal.
  5. Ensure broad indexing: Web of Science (Preprint Citation Index), Google Scholar, Crossref, SHARE, PrePubMed, Scilit and Europe PMC.

Published Papers (7 papers)

Order results
Result details
Journals
Select all
Export citation of selected articles as:
31 pages, 2446 KB  
Article
A Batch Identity-Based Encryption Scheme for Object-Level Authorization of Smart Tourism Data
by Lixia Sun, Dengshuo Zhu, Changgen Peng, Chenran Xiong and Chuanda Cai
Cryptography 2026, 10(5), 67; https://doi.org/10.3390/cryptography10050067 - 10 Sep 2026
Viewed by 207
Abstract
When smart tourism data are shared across scenic areas, hotels, transportation platforms, and regulatory authorities, existing access control schemes often struggle to simultaneously support batch authorization for data object sets, multi-authority collaboration, revocation-version binding, and low-latency online encryption. To address these challenges, this [...] Read more.
When smart tourism data are shared across scenic areas, hotels, transportation platforms, and regulatory authorities, existing access control schemes often struggle to simultaneously support batch authorization for data object sets, multi-authority collaboration, revocation-version binding, and low-latency online encryption. To address these challenges, this paper proposes a Threshold Distributed Batch Identity-Based Encryption scheme for object-level authorization of smart tourism data, termed TD-BIBE. The scheme jointly binds data object identities, batch labels, authorization periods, revocation versions, and authorization contexts to ciphertext access control. It employs Shamir secret sharing for threshold distributed key generation, preventing any single authorization authority from obtaining the complete master secret key. Set-polynomial digests and membership witnesses are used to support batch authorization over identity sets and object-level membership verification. A revocation-version binding mechanism restricts the validity scope of authorization materials, while an offline/online encryption structure reduces the online computational overhead of data providers. Formal security analyses are conducted in the random oracle model with respect to data confidentiality, object-level authorization, batch-label binding, revocation-version binding, resistance to unauthorized key-combination attacks, and threshold authorization security. Experimental results demonstrate that TD-BIBE is suitable for cross-departmental, multi-object, and on-demand data sharing in smart tourism scenarios. Full article
(This article belongs to the Topic Security and Privacy in Distributed and Trustless Systems)
Show Figures

Figure 1

30 pages, 2562 KB  
Article
A Hierarchical Benchmarking Framework for Homomorphic Encryption-Based Aggregation and Validation Using Real Smart Meter Data
by Aiman Ahmad Shivani, Marzia Zaman, Pirathayini Srikantha, Darshana Upadhyay and Kshirasagar Naik
Cryptography 2026, 10(5), 63; https://doi.org/10.3390/cryptography10050063 - 1 Sep 2026
Viewed by 262
Abstract
Homomorphic encryption (HE) enables computation on encrypted data and has emerged as a promising technology for privacy-preserving distributed analytics. However, the practical deployment of HE in large-scale hierarchical systems requires a thorough understanding of its computational overhead, scalability, and accuracy. This paper presents [...] Read more.
Homomorphic encryption (HE) enables computation on encrypted data and has emerged as a promising technology for privacy-preserving distributed analytics. However, the practical deployment of HE in large-scale hierarchical systems requires a thorough understanding of its computational overhead, scalability, and accuracy. This paper presents a generic hierarchical benchmarking framework for systematically evaluating homomorphic encryption schemes in multi-level aggregation environments. The framework supports configurable aggregation topologies, detailed operation-level profiling, and multiple encryption backends, enabling consistent and reproducible performance analysis across node-, cluster-, and global-level aggregation stages. Using the proposed framework, we conduct a comparative evaluation of the Brakerski/Fan–Vercauteren (BFV) and Cheon–Kim–Kim–Song (CKKS) schemes under identical workloads. Experimental results show that CKKS consistently outperforms BFV, achieving a 44.3% reduction in aggregation latency and a 24.6% reduction in decryption latency. For the tested encoding and parameter settings, CKKS delivers significantly lower numerical error, reducing the mean absolute error from 3.21×103 to 5.91×1010. The proposed framework offers a reusable and extensible platform for evaluating emerging HE schemes and privacy-preserving analytics applications, thereby supporting future research and deployment of secure distributed data processing systems. Full article
(This article belongs to the Topic Security and Privacy in Distributed and Trustless Systems)
Show Figures

Figure 1

24 pages, 729 KB  
Article
A Scalable Blockchain Architecture for Digital Certificate Management Using Microservice-Based Processing and Batch Anchoring
by Shweta H. Bhatia and Ravirajsinh S. Vaghela
Blockchains 2026, 4(3), 15; https://doi.org/10.3390/blockchains4030015 - 30 Aug 2026
Viewed by 255
Abstract
Blockchain-based infrastructures have increasingly been adopted for secure and tamper-resistant management of academic credentials. Despite the advantages offered by blockchain technology, existing blockchain-based credential management systems continue to face several scalability challenges, particularly in terms of limited transaction throughput, increased confirmation delays, and [...] Read more.
Blockchain-based infrastructures have increasingly been adopted for secure and tamper-resistant management of academic credentials. Despite the advantages offered by blockchain technology, existing blockchain-based credential management systems continue to face several scalability challenges, particularly in terms of limited transaction throughput, increased confirmation delays, and continuous ledger growth resulting from storing individual certificates as separate blockchain transactions. These limitations become more evident in large-scale educational environments where universities and affiliated institutions are required to issue and verify thousands of digital credentials within limited operational timeframes. To overcome these challenges, this work introduces a performance-optimized blockchain architecture for scalable academic credential management. The proposed framework separates certificate preprocessing from blockchain anchoring by incorporating a microservice-based parallel processing layer, Merkle-tree-based batch anchoring, and distributed off-chain storage mechanisms. This modular design reduces blockchain transaction overhead while maintaining the security, integrity, auditability, and verifiability of academic credentials. To assess system performance, a formal analytical model integrating queueing theory and blockchain performance characteristics is developed to characterize system behavior under varying workload conditions. By enabling multiple certificates to be aggregated and committed through a single blockchain transaction, the proposed architecture improves throughput and enhances storage efficiency compared to conventional blockchain-based approaches. Analytical evaluation demonstrates that the system can sustain high certificate issuance rates while maintaining low confirmation latency and minimal on-chain storage growth. Full article
(This article belongs to the Topic Security and Privacy in Distributed and Trustless Systems)
Show Figures

Figure 1

37 pages, 2531 KB  
Article
PEUAP-W3: A Formally Verified Zero-Knowledge Authentication Protocol for Web 3.0 Unifying Conditional Biometric Binding, Threshold-Accountable Anonymity, and Self-Sovereign Identity
by Adarsh S. V. Nair and Rathnakar Achary
Computers 2026, 15(9), 563; https://doi.org/10.3390/computers15090563 - 27 Aug 2026
Viewed by 343
Abstract
Authentication in Web 3.0 faces a structural conflict. Systems that offer full anonymity leave no lawful way to identify a malicious actor. Systems built for accountability expose a persistent wallet address to blockchain-graph analysis, or fall back on centralized key recovery. Existing designs [...] Read more.
Authentication in Web 3.0 faces a structural conflict. Systems that offer full anonymity leave no lawful way to identify a malicious actor. Systems built for accountability expose a persistent wallet address to blockchain-graph analysis, or fall back on centralized key recovery. Existing designs solve one side of this conflict at the cost of the other. This paper presents PEUAP-W3, a Privacy-Enhanced and User-centric Authentication Protocol. Its contribution is the integration of five established components into a single deployed and formally analyzed system. A Circom 2 circuit of 1579 Groth16 constraints proves four facts in a single 192-byte on-chain proof: knowledge of an opening of the session credential commitment, an SpO2 value inside an 85–100% band, single-use nonce binding, and HMAC integrity. Shamir (k = 2, n = 3) sharing distributes the identity payload across three independent relays. The coordinator reconstructs an identity only after a threshold vote has been recorded on chain. Credentials are issued as W3C Verifiable Credentials 2.0 in did:key form. Four Solidity contracts verify the proof on Ethereum Sepolia. Verification costs about 241,000 gas and takes roughly 3 ms. ProVerif and Scyther find no attack under the Dolev–Yao model. A concurrency sweep to 500 simultaneous requests completes 1191 requests with zero failures at about 15.4 requests per second. A behavioral gate screens commodity abuse as a supplementary control; it is not treated as a security boundary. Against a nine-property framework, PEUAP-W3 satisfies six properties. Three remain conditional and are not verified in the current deployment: biological-origin assurance and digital replay prevention, both of which need an attested sensor; and GDPR erasure equivalence. Here, formally verified refers to the protocol models and theorems, not to the complete deployed software. Full article
(This article belongs to the Topic Security and Privacy in Distributed and Trustless Systems)
Show Figures

Graphical abstract

48 pages, 9266 KB  
Article
SDAP-K: A Kerberos-Assisted Secure Data Auditing Protocol for Cloud Storage
by Thangavel Murugan, Nasurudeen Ahamed Noor Mohamed Badusha, Priyan Malarvizhi Kumar and Varalakshmi Perumal
Future Internet 2026, 18(8), 411; https://doi.org/10.3390/fi18080411 - 3 Aug 2026
Viewed by 383
Abstract
Cloud storage services have become a fundamental component of modern computing infrastructures, enabling scalable and cost-effective data management. However, outsourcing data to remote cloud servers introduces significant security challenges, particularly in ensuring data integrity, secure access control, and efficient auditing of stored information. [...] Read more.
Cloud storage services have become a fundamental component of modern computing infrastructures, enabling scalable and cost-effective data management. However, outsourcing data to remote cloud servers introduces significant security challenges, particularly in ensuring data integrity, secure access control, and efficient auditing of stored information. Existing cloud auditing schemes primarily focus on integrity verification and often rely on trusted third-party auditors, leading to additional trust assumptions, communication overhead, and metadata management complexity. To address these limitations, this research presents a Kerberos-Assisted Secure Data Auditing Protocol (SDAP-K) that integrates authenticated service exchange with lightweight integrity verification for outsourced cloud storage. The proposed framework employs Kerberos-based mutual authentication and ticket-driven access control to establish secure communication among the Data Owner, Authentication Server, Metadata Server, and Cloud Data Server. To verify storage correctness, an N-ary hash tree with the Modified Murmur hash algorithm is used to enable efficient file- and block-level auditing without requiring a trusted third-party auditor. The framework further incorporates metadata-assisted auditing, dynamic data operations, and an error localization and recovery mechanism that identifies and restores corrupted data blocks. Security analysis demonstrates that the proposed protocol mitigates unauthorized access, replay attacks, impersonation attempts, and malicious data modification. Experimental results indicate that SDAP-K reduces storage execution time by 18.6%, retrieval time by 24.3%, update time by 21.8%, file-level auditing overhead by 31.5%, and block-level auditing latency by 36.2% compared with state-of-the-art research, while eliminating the need for a trusted third-party auditor. The results indicate that the proposed framework offers a practical, lightweight, and reliable solution for secure cloud data auditing in enterprise cloud storage environments. Full article
(This article belongs to the Topic Security and Privacy in Distributed and Trustless Systems)
Show Figures

Graphical abstract

29 pages, 1078 KB  
Article
DAO-TDS: Decentralized Autonomous Trusted Data Space for Global Data Circulation
by Yongjian Wang and Aibo Song
Computers 2026, 15(8), 482; https://doi.org/10.3390/computers15080482 - 29 Jul 2026
Viewed by 832
Abstract
Trusted Data Spaces (TDSs) have emerged as the core infrastructure for secure, privacy-preserving data circulation across industries and jurisdictions. However, state-of-the-art TDS implementations suffer from centralized platform monopoly, rigid cross-border governance failure, unfair value distribution, and poor scalability for global-scale collaboration. This paper [...] Read more.
Trusted Data Spaces (TDSs) have emerged as the core infrastructure for secure, privacy-preserving data circulation across industries and jurisdictions. However, state-of-the-art TDS implementations suffer from centralized platform monopoly, rigid cross-border governance failure, unfair value distribution, and poor scalability for global-scale collaboration. This paper proposes DAO-TDS, a novel decentralized autonomous trusted data space paradigm that enables centerless, cryptography-governed, and value-closed-loop data circulation. We make three core contributions: (1) We formalize the first anti-monopoly, incentive-compatible game-theoretic model for distributed TDS governance, with rigorous provable security guarantees; (2) we design an original Proof of Data Contribution (PoDC) consensus mechanism and a post-quantum secure Crypto-DAO governance protocol, with formal security proofs under the Universal Composability (UC) framework; (3) we implement a full prototype of DAO-TDS and conduct comprehensive, reproducible evaluations, showing that it supports 10,000+ distributed nodes with >12,000 TPS and <2 s 99th-percentile confirmation latency, while delivering >80% of generated value to data contributors (vs. <50% in centralized platforms). While the proposed paradigm demonstrates strong performance and security guarantees, it still faces challenges in adaptive cross-jurisdictional compliance and lightweight edge node deployment, which require further investigation. Full article
(This article belongs to the Topic Security and Privacy in Distributed and Trustless Systems)
Show Figures

Figure 1

24 pages, 2065 KB  
Article
A Hybrid ABAC–RpBAC Framework for Enhancing PoS Consensus Against Sybil Attacks
by Mohammed Al Qurashi and Ibtihaj Al Qarni
Future Internet 2026, 18(6), 276; https://doi.org/10.3390/fi18060276 - 22 May 2026
Viewed by 548
Abstract
Sybil attacks remain a primary challenge for Proof-of-Stake (PoS) blockchain systems, as low-cost identity creation can distort validator participation and limit consensus reliability. This study proposes a hybrid participation–governance framework that integrates Attribute-Based Access Control (ABAC) and Reputation-Based Access Control (RpBAC) with a [...] Read more.
Sybil attacks remain a primary challenge for Proof-of-Stake (PoS) blockchain systems, as low-cost identity creation can distort validator participation and limit consensus reliability. This study proposes a hybrid participation–governance framework that integrates Attribute-Based Access Control (ABAC) and Reputation-Based Access Control (RpBAC) with a trust-based PoS workflow to reduce the influence of suspicious identities during validator selection and block validation. The proposed framework also incorporates graylisting and dynamic reward–penalty updates to support adaptive participation control. The strategy was evaluated in a simulation environment informed by Ethereum-derived block metadata, using network sizes ranging from 100 to 1000 nodes and Sybil attack ratios of 30%, 40%, and 50%. Its performance was compared with PoS-only and PoS + ABAC baselines using both security and performance indicators. The results show that the full ABAC + RpBAC configuration achieved the strongest and most stable security performance across the evaluated settings while introducing additional overhead at larger network sizes. These findings suggest that combining policy-based eligibility control with behavior-based reputation control strengthens the resilience against Sybil in PoS-like blockchain environments. However, this improvement requires a measurable trade-off between security and performance. Full article
(This article belongs to the Topic Security and Privacy in Distributed and Trustless Systems)
Show Figures

Graphical abstract

Back to TopTop