A Runtime Enforcement Framework for Vulnerable Smart Contracts of Crowdsourcing Logistics
Abstract
Blockchain-based crowdsourcing logistics is a promising decentralized paradigm for solving the “last-mile delivery” problem, in which smart contracts automatically execute the business logic. Since crowdsourcing logistics inherently involves frequent fund transfers, its smart contracts are particularly susceptible to reentrancy vulnerabilities. Existing works address reentrancy by inserting a lock mechanism at design-time, which lacks dynamic responsiveness and incurs additional gas overhead. To overcome this limitation, we propose RE4SC, the first runtime enforcement framework for vulnerable smart contracts. RE4SC contains two components: off-Blockchain granularity segmentation and on-Blockchain granular block reordering. At the off-Blockchain level, bytecode is segmented into granular blocks through control flow analysis. This yields a finer granularity than conventional basic blocks in a control flow graph. These granular blocks are then organized into a tree structure that captures their hierarchical nesting relationships. A data flow analysis further ensures data dependency consistency after reordering. At the on-Blockchain level, a runtime enforcer retrieves the pre-computed reordering specifications from off-Blockchain analysis. It applies a depth-first reordering algorithm to reposition key state variable assignments before transfer operations, eliminating reentrancy vulnerabilities without introducing additional bytecode. We implement a prototype tool and make it open-source. Experiments on self-constructed crowdsourcing logistics contracts and three public datasets demonstrate that RE4SC repairs vulnerable contracts with zero gas overhead, outperforming existing approaches.
Community
0 commentsNo discussion yet
Be the first to share a question or observation.