Toward Active and Passive Confidentiality Attacks On Cryptocurrency\n Off-Chain Networks
Abstract
Cryptocurrency off-chain networks such as Lightning (e.g., Bitcoin) or Raiden\n(e.g., Ethereum) aim to increase the scalability of traditional on-chain\ntransactions. To support nodes in learning about possible paths to route their\ntransactions, these networks need to provide gossip and probing mechanisms.\nThis paper explores whether these mechanisms may be exploited to infer\nsensitive information about the flow of transactions, and eventually harm\nprivacy. In particular, we identify two threats, related to an active and a\npassive adversary. The first is a probing attack: here the adversary aims to\ndetect the maximum amount which is transferable in a given direction over a\ntarget channel by actively probing it and differentiating the response messages\nit receives. The second is a timing attack: the adversary discovers how close\nthe destination of a routed payment actually is, by acting as a passive\nman-in-the middle and analyzing the time deltas between sent messages and their\ncorresponding responses. We then analyze the limitations of these attacks and\npropose remediations for scenarios in which they are able to produce accurate\nresults.\n
Community
0 commentsNo discussion yet
Be the first to share a question or observation.