Aug 2026· Asia-Pacific Workshop on Networking· pp. 16-22· 0 citations· 26 references
Computer Science
TL;DR
A AegisPath is presented, it replaces centralized verification with distributed witness generation to protect AS-local configurations, decouples witness generation from repeated auditing through a commit-and-prove design, uses zero-knowledge proofs to answer queries without revealing forwarding paths, and supports incremental updates.
Abstract
Network verification checks whether forwarding behavior satisfies intended invariants. In interdomain settings, data-plane verification is challenging because forwarding configurations are private, while post-incident review requires repeatable, version-specific checking without costly online coordination. We present AegisPath, it replaces centralized verification with distributed witness generation to protect AS-local configurations, decouples witness generation from repeated auditing through a commit-and-prove design, uses zero-knowledge proofs to answer queries without revealing forwarding paths, and supports incremental updates. Experiments show that offline Secure Multi-Party Computation (SMPC) witness generation takes from thousands to over 104 seconds, online Zero-Knowledge (ZK) auditing remains sub-second, and incremental maintenance yields substantial speedups over full re-computation.
This work proposes a transparent and cost-effective identity verification framework based on Multi-Party Computation (MPC), which enables private off-chain code execution and produces runtime proofs anchored to a blockchain and integrates SHA3 hashing and Falcon post-quantum signatures.
Istiaque Ahmed, Shoji Kasahara, Kentaroh Toyoda et al.· 0 citations
Agents using the Model Context Protocol (MCP) rely on semantic matching to select tools from third-party servers, exposing a semantic supply-chain risk through attacker-controlled metadata and outputs. We introduce A2M (Attraction-to-Manipulation), a two-stage black-box framework for hijacking MCP agents. The Attractio...
Lai-Zhen Li, Xuan Wang, Pei-Cheng Zhao et al.· 0 citations
This paper introduces a novel secure lineage verification system based on Directed Acyclic Graphs (DAGs) and homomorphic hash functions, VERDICT, which incorporates bucket indexing and Merkle tree verification to provide cryptographic guarantees of data and event existence.
Bilel Zaghdoudi, M. Potop-Butucaru· IACR Cryptology ePrint Archi...· 0 citations
Proofs of UNSAT are a standard primitive in formal verification and software assurance. In many real-world settings, the proof itself encodes proprietary or security-sensitive information, making public disclosure undesirable. Zero-knowledge certification of UNSAT addresses this tension: it enables a prover to convince...
A. Karthikeyan, E. Kharitonov, Kuldeep S. Meel et al.· 0 citations
This work provides the first evaluation of Verkle trees for credential revocation and compares them with sparse Merkle trees to assess their applicability in real world applications, and shows that shorter authenticated paths do not necessarily yield cheaper zero-knowledge proofs.
Patrick Herbke, Wolf Rieder, Christian René Sechting et al.· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.