Content-Addressed Blind Attestation System for Encrypted Structured Data with Storage-Independent Signature Validity

Fuente: Zenodo
Enregistré dans:
Détails bibliographiques
Auteur principal: Prudnikov, Dmitry
Format: Recurso digital
Langue:anglais
Publié: Zenodo 2026
Sujets:
Accès en ligne:
Tags: Ajouter un tag
Pas de tags, Soyez le premier à ajouter un tag!
_version_ 1866902322994479104
author Prudnikov, Dmitry
author_facet Prudnikov, Dmitry
contents <p>This paper describes a content-addressed blind attestation system where an attestation server cryptographically signs the Merkle root of per-field hash commitments from a multi-field encrypted document, without the server ever accessing any plaintext field value. The resulting attestation signature is bound to the document content (Merkle root of field hashes), not to any storage location, enabling the encrypted document to be freely moved between storage backends while maintaining signature validity.</p> <p>Novelty claims disclosed in this publication include: (1) The first system combining blind attestation with Merkle-based selective disclosure, (2) Storage-delinked signatures where the signature is bound to content rather than storage location, (3) An explicit detach/reattach lifecycle protocol for removing and restoring server copies without re-signing, (4) Multi-provider attestation on a single Merkle root, and (5) Re-encryption resilience where signatures survive re-encryption because they are bound to plaintext hashes instead of ciphertext.</p>
format Recurso digital
id zenodo_https___doi_org_10_5281_zenodo_19387695
institution Zenodo
language eng
publishDate 2026
publisher Zenodo
record_format zenodo
spellingShingle Content-Addressed Blind Attestation System for Encrypted Structured Data with Storage-Independent Signature Validity
Prudnikov, Dmitry
blind attestation
Merkle tree
selective disclosure
content-addressed signatures
encrypted credentials
storage independence
<p>This paper describes a content-addressed blind attestation system where an attestation server cryptographically signs the Merkle root of per-field hash commitments from a multi-field encrypted document, without the server ever accessing any plaintext field value. The resulting attestation signature is bound to the document content (Merkle root of field hashes), not to any storage location, enabling the encrypted document to be freely moved between storage backends while maintaining signature validity.</p> <p>Novelty claims disclosed in this publication include: (1) The first system combining blind attestation with Merkle-based selective disclosure, (2) Storage-delinked signatures where the signature is bound to content rather than storage location, (3) An explicit detach/reattach lifecycle protocol for removing and restoring server copies without re-signing, (4) Multi-provider attestation on a single Merkle root, and (5) Re-encryption resilience where signatures survive re-encryption because they are bound to plaintext hashes instead of ciphertext.</p>
title Content-Addressed Blind Attestation System for Encrypted Structured Data with Storage-Independent Signature Validity
topic blind attestation
Merkle tree
selective disclosure
content-addressed signatures
encrypted credentials
storage independence
url https://doi.org/10.5281/zenodo.19387695