Evžen Kočenda, Peter Albrecht
No abstract is available for this record.
Follow blockchain research across journals, conferences, and preprint repositories.
7,409 results · page 118 of 309
Evžen Kočenda, Peter Albrecht
No abstract is available for this record.
Mariam Lahami, Moez Krichen, Mohamed Mnassar, Racem Mrabet · 5 authors
No abstract is available for this record.
Carlo Gola, Valentina Cappa, Patrizio Fiorenza, Paolo Granata · 8 authors
Italian Abstract: Il lavoro affronta il tema della governance dei sistemi basati sulla tecnologia dei registri distribuiti (distributed ledged technology, DLT). Questa tecnologia consente di creare un archivio elettronico condiviso e accessibile via internet, in cui sono memorizzate le informazioni in modo sicuro e irreversibile. L’aggiornamento e la gestione del registro avvengono senza ricorrere a un ente terzo fiduciario. L’assenza di strutture organizzative e di governance tradizionali rende complessa la gestione delle DLT. Il lavoro fornisce gli strumenti per comprendere la tecnologia DLT e analizza la governance, sia per le DLT aperte (permissionless), sia per quelle ad accesso limitato (permissioned). Vengono suggeriti diversi approcci per l’applicazione di regole di governo, anche in presenza di DLT con una governance interamente algoritmica (full algorithmic governance). Si mostra che la creazione di strumenti, detti governance tokens, aventi diritti amministrativi e patrimoniali incorporati, favorisce i processi gestionali e di controllo delle DLT. Infine si descrive la struttura di governance di due DLT: Ethereum e Polkadot. English Abstract: This paper deals with the governance of systems based on distributed ledger technology (DLT). This technology enables the creation of a shared electronic archive accessible via the internet, in which information is stored in a secure and irreversible manner. The updating and management of the ledger takes place without resorting to a trusted third party. The absence of traditional organizational and governance structures makes DLT management complex. The work provides the tools to understand DLT technology and analyzes its governance, both for open (permissionless) systems and for those with limited access (permissioned). Different approaches are suggested for the application of governance rules, including for DLT with entirely algorithmic governance. The study shows that the creation of tools known as governance tokens, which incorporate administrative and property rights, facilitates the management and control processes of DLTs. Finally, the governance structure of two DLTs is described: Ethereum and Polkadot.
Chaimaa Nairi, Murtaza Ci̇ci̇oğlu, Ali Çalhan
No abstract is available for this record.
Seyedeh Mehrafarin Ezzati, Roghayyeh Alizadeh, Mohammad Reza Akbari Jokar
Efficiency and transparency are crucial for successful procurement in supply chains. Buyers need to select the right suppliers to avoid wasting money on unsuitable ones. To develop a trustworthy procurement system, we envision an online purchasing platform where transactions are secure and automated, and supplier performance is evaluated using real-time data. In this setting, buyers can confidently make purchases, and selecting or assessing a new supplier becomes less time-consuming. Companies can collaborate with the best partners according to their priorities, without solely relying on information provided by suppliers. Such a system offers a fair and transparent evaluation of supplier performance, benefiting both buyers and suppliers. Blockchain technology, along with its powerful tool, smart contracts, can make this goal a reality. In this paper, we propose an online purchasing platform based on the Ethereum blockchain that utilizes smart contracts to record data and provide precise information for supplier performance evaluation (SPE) systems. This system also ensures a secure payment process, significantly reducing the role of third parties. We test our system under various potential security scenarios, demonstrating its robustness for conducting transactions. Additionally, a cost analysis shows that the proposed system is highly cost-efficient, especially for large-volume orders.
David Krause
No abstract is available for this record.
Daniel Mawunyo Doe, Jing Li, Dusit Niyato, Yuqing Hu · 8 authors
In this paper, we address key challenges in Proof-of-Stake (PoS) blockchains, with a particular focus on Ethereum 2.0. We introduce an innovative mechanism that combines Tullock contests and signaling games to optimize weight assignments based on security deposits from heterogeneous nodes. While Tullock contests motivate participants to allocate resources for potential rewards, signaling games enable efficient information transfer, thereby enriching decision-making. This approach enhances network security, efficiency, and resilience by incentivizing resource investment and facilitating effective information exchange. Our framework significantly outperforms existing methods, achieving a 45.43% increase in blockchain utility and a 47.92% rise in node utility. Additionally, it yields marked improvements in user participation rates (26.89 − 32.21%) and service coverage (24 − 29.54%), and also proves to be resilient against attacks from selfish nodes.
Xiaohui Yang, Kun Zhang
Data is regarded as a valuable asset, and sharing data is a prerequisite for fully exploiting the value of data. However, the current medical data sharing scheme lacks a fair incentive mechanism, and the authenticity of data cannot be guaranteed, resulting in low enthusiasm of participants. A fair and trusted medical data trading scheme based on smart contracts is proposed, which aims to encourage participants to be honest and improve their enthusiasm for participation. The scheme uses zero-knowledge range proof for trusted verification, verifies the authenticity of the patient’s data and the specific attributes of the data before the transaction, and realizes privacy protection. At the same time, the game pricing strategy selects the best revenue strategy for all parties involved and realizes the fairness and incentive of the transaction price. The smart contract is used to complete the verification and game bargaining process, and the blockchain is used as a distributed ledger to record the medical data transaction process to prevent data tampering and transaction denial. Finally, by deploying smart contracts on the Ethereum test network and conducting experiments and theoretical calculations, it is proved that the transaction scheme achieves trusted verification and fair bargaining while ensuring privacy protection in a decentralized environment. The experimental results show that the model improves the credibility and fairness of medical data transactions, maximizes social benefits, encourages more patients and medical institutions to participate in the circulation of medical data, and more fully taps the potential value of medical data.
David Krause
No abstract is available for this record.
Xiaoqin Feng, Fuliang Lin, Tao Feng, Jianfeng Ma · 6 authors
Secure and efficient identity authentication is a fundamental requirement in vehicular ad-hoc networks (VANETs); however, it remains challenging due to the highly dynamic network topology, stringent latency constraints, and the need for conditional privacy preservation. Existing authentication schemes either rely on public key infrastructures (PKI) with complex certificate management or introduce partially decentralized designs that still depend on trusted authorities, leading to inefficiencies and single points of failure. In this paper, we propose EBDA, an Ethereum-based fully distributed authentication mechanism for VANETs. The core innovation of EBDA is to replace the traditional PKI certificate system with a blockchain-maintained Graph of Trust (GoT). Through three dedicated smart contracts, EBDA fully decentralizes the management of vehicle identities and pseudonyms. Vehicles use pseudonyms to preserve privacy in Vehicle-to-Vehicle communications, while authentication is achieved certificate-free via transitive trust within the GoT. Importantly, latency-sensitive operations like message verification are executed off-chain through local checks, meeting VANETs’ strict real-time requirements. A prototype implementation and extensive evaluations demonstrate that EBDA significantly reduces authentication latency by at least 22.93% compared with representative blockchain-assisted and PKI-based baselines while maintaining low computational and storage overhead. These results confirm the feasibility of deploying GoT-based decentralized authentication in practical VANET environments.
Ho-Won Lee, Yoon-Young Park, Sungchul Lee, Yoon-Jae Chae
In today’s rapidly evolving digital landscape, ensuring data integrity is paramount for maintaining the security and reliability of applications. This paper introduces the Application Integrity Assurance System (AIAS), a novel solution designed to enhance data integrity through the integration of Ethereum blockchain technology. AIAS leverages smart contracts and the Interplanetary File System (IPFS) to securely store and verify application manifests. By decentralizing the integrity assurance process, AIAS mitigates the risks associated with tampering and unauthorized modifications, providing a robust framework for maintaining data integrity in various application environments. The system has been prototyped and tested on an augmented reality platform, demonstrating its practical application and efficiency. The AIAS framework offers a cost-effective, infrastructure-free solution for safeguarding application integrity, making it an essential tool for platforms that demand high standards of data integrity and security.
Panara Hit Mukeshbhai, Arpita Prasad, Ankush Kumar, Ballidi Rohit · 5 authors
No abstract is available for this record.
Zhanwen Chen
The proposal of the first cryptocurrency Bitcoin brings about the new technology called blockchain that massively expands the concept of financial system.Tamper-resistance, decentralization and traceability are three essential properties of a blockchain.In the following years, the original idea of blockchain also inspired the development and research of other cryptocurrency implementations.And the development of blockchain has extended beyond its fundamental transactional attributes.As blockchain can be regarded as an immutable ledger, it can also be exploited in other application scenarios.Ethereum, based on the principles of blockchain, further introduced smart contract technology, allowing any blockchain user to deploy programs on the chain for others to invoke.This has given rise to decentralized applications.Due to the distinct network model of decentralized applications, existing studies regarding the security of centralized models are difficult to directly adapt to decentralized blockchain applications.Therefore, safeguarding information security and user privacy in the blockchain environment has become a focal point of security study.The thesis contains three studies regarding security of decentralized applications.They are primarily categorized into two types according to the scenarios.One type involves using blockchain to enhance existing applications, while the other focuses on native applications based on blockchain.In the first scenario, I utilize blockchain to provide a verifiable endorsement solution for identity authentication in social networking service (SNS) scenarios.Previous identity authentication research in this area rarely incorporated blockchain.I significantly enhance the reliability and efficiency of identity authentication while preventing impersonation using blockchain.In the second scenario, our focus is on NFT trading within the blockchain.Existing research has only addressed NFT privacy issues to a limited extent due to conflicts with Ethereum's transparency principle.To tackle this problem, I proposed two solutions: first, I make the marketplace a semi-trusted entity to achieve anonymous NFT trading.Then, based on previous research, I further propose a solution for anonymous NFT transactions in a trustless environment.Through security analysis and performance evaluation, our solutions meet security requirements with acceptable expenses, making them suitable for practical applications.
Min-Bin Lin, Cathy Yi‐Hsuan Chen, Wolfgang Karl Härdle
This study investigates cryptocurrency volatility dynamics, particularly focusing on Ethereum (ETH). We dissect long- and short-term volatility components to gain deeper insights into its evolution. This approach allows studying the impact of ETH’s Merge upgrade, replacing Proof-of-Work with Proof-of-Stake on September 15, 2022. Employing 29 empirical factors related to blockchain functionality and crypto market characteristics, we explore their long-term equilibrium connection with price volatility. Our findings reveal that scalability factors and wealth dis- tribution significantly influence volatility persistence, ultimately highlighting the stability-enhancing impact of Ethereum’s Merge upgrade.
Tahmina Ehsan, Muhammad Usman Sana, Muhammad Usman Ali, Elizabeth Caro Montero · 7 authors
Smart contracts are becoming increasingly popular for managing transactions or activities in fog computing environments. However, the use of smart contracts for registration and resource access granting is vulnerable to various types of attacks that can compromise their security. Detecting these attacks can be challenging, as attackers can use sophisticated techniques to evade detection. This research uses a machine learning-based approach for detecting different attacks on smart contracts used for registration and resource access granting in fog computing. Data is collected from online Ethereum’s official site “etherscan.io”. Different feature extraction methods and machine learning models are tested. Using accuracy, precision, recall, F1 score, cross-validation, and computational time, the performance of models is evaluated. Results indicate that extreme gradient boosting (XGB) and random forest (RF) provide the highest accuracy of 80% using the term frequency-inverse document frequency (TF-IDF) approach. The light gradient boost classifier provides the highest accuracy of 81% with the Bag of Word (BoW) approach. Similarly, the extra tree provides the highest accuracy of 83% using the N-gram technique. Furthermore, performance using TF-IDF is slightly poorer than BoW and N-gram, however, it has less computational complexity.
Takayuki Sasaki, Jia Wang, Kazumasa Omote, Katsunari Yoshioka · 5 authors
In recent years, Ethereum, which is a leading application for realizing blockchain services, has received much attention for its usability and functionality. Ethereum executes smart contracts and arbitrary programmable calculations, in addition to cryptocurrency trading. However, cyberattacks target misconfigured Ethereum clients with application programming interface (API) enabled, specifically JSON-RPC. Herein, we propose EtherWatch, a framework to detect and analyze malicious and/or suspicious Ethereum accounts using three data sources (a honeypot, an internet-wide scanner, and a blockchain explorer). The honeypot, named Etherpot, leverages a proxy server placed between a real Ethereum client and the internet. It modifies client responses to attract attackers, identifies malicious accounts, and analyzes their behaviors. Using scan results from Shodan, we also detect suspicious Ethereum accounts registered on multiple nodes. Finally, we utilize Etherscan, a well-known blockchain explorer, to track and analyze the activities of the detected accounts. During six weeks of observations, we discovered 538 hosts attempting to call JSON-RPC of our honeypots using 41 types of methods, including a type of unreported attack in the wild. Specifically, we observed account hijacking, mining, and smart contract attacks. We detected 16 malicious accounts using the honeypots and 64 suspicious accounts from the Shodan scan results, with five overlapping accounts. Finally, from Etherscan, we collected records of activities related to the detected accounts, including transactions of 21.50 ETH and mining of 22.61 ETH (equivalent to 39,494 US$ and 41,533 US$, respectively, as of June 9, 2023).
Alpesh Bhudia, Daniel O’Keeffe, Darren Hurley-Smith
No abstract is available for this record.
Arusoaie, Andrei, Bărbieru, Claudiu-Nicu, Captarencu, Oana-Otilia, Felber, Pascal · 9 authors
Ethereum is the dominant blockchain ecosystem capable of executing Turing-complete smart contracts. Rollups gained significant traction as the primary layer 2 (L2) solution meant to bring horizontal scalability to the main Ethereum network (L1). A core component of any rollup is the sequencer, which creates new L2 blocks to be submitted in rollup batches to L1. In most of the current rollup architectures, this component is centralised. As a result, these designs are prone to inconspicuous censorship practices by the sequencer. Trusted execution environments (TEEs) can guarantee the integrity of various sequencer components, which is instrumental in addressing censorship. However, the reaction of the system design to censorship attempts depends on where a TEE is integrated and which components it protects. In particular, this reaction is limited in the case of a monolithic TEE-protected sequencer design. Proposer-Builder Separation (PBS) is a non-monolithic paradigm adopted on L1, which separates the production of blocks from proposing them for inclusion in the blockchain. Recently, PBS has been considered for integration with L2 sequencers, with an impact on alleviating censorship. In this paper, we explore the design space of TEE-integrating PBS and non-PBS sequencer variants. First, we introduce a formal framework for the censorship actions that captures the specificity of the L2 sequencer. Then, we analyse to what extent the different designs address these censorship actions. Our main contribution is a novel design variation that allows for a precise observation of censored transactions. In the presence of TEEs, in a PBS setting, we demonstrate this precise observability, which is necessary to enable resilience to censorship.
Peng Liao, Chaoge Liu, Jie Yin, Zhi Wang · 5 authors
Digital assets have boomed over the past few years with the emergence of Non-fungible Tokens (NFTs). To be specific, the total trading volume of digital assets reached an astounding $55.5 billion in 2022. Nevertheless, numerous security concerns have been raised by the rapid expansion of the NFT ecosystem. NFT holders are exposed to a plethora of scams and traps, putting their digital assets at risk of being lost. However, academic research on NFT security is scarce, and the security issues have aroused rare attention. In this study, the NFT ecological process is comprehensively explored. This process falls into five different stages encompassing the entire lifecycle of NFTs. Subsequently, the security issues regarding the respective stage are elaborated and analyzed in depth. A matrix model is proposed as a novel contribution to the categorization of NFT security issues. Diverse data are collected from social networks, the Ethereum blockchain, and NFT markets to substantiate our claims regarding the severity of security concerns in the NFT ecosystem. From this comprehensive dataset, nine key NFT security issues are identified from the matrix model and then subjected to qualitative and quantitative analysis. This study aims to shed light on the severity of NFT ecosystem security issues. The findings stress the need for increased attention and proactive measures to safeguard the NFT ecosystem.
Mikel Cortes-Goicoechea, Tarun Mohandas-Daryanani, José L. Muñoz, Leonardo Bautista-Gomez
No abstract is available for this record.
David Krause
No abstract is available for this record.
Yaish, Aviv, Qin, Kaihua, Zhou, Liyi, Zohar, Aviv · 5 authors
Transaction fees compensate actors for resources expended on transactions and can only be charged from transactions included in blocks. But, the expressiveness of Turing-complete contracts implies that verifying if transactions can be included requires executing them on the current blockchain state. In this work, we show that adversaries can craft malicious transactions that decouple the work imposed on blockchain actors from the compensation offered in return. We introduce three attacks: (i) ConditionalExhaust, a conditional resource exhaustion attack (REA) against blockchain actors. (ii) MemPurge, an attack for evicting transactions from actors' mempools. (iii) GhostTX, an attack on the reputation system used in Ethereum's proposer-builder separation (PBS) ecosystem. We evaluate our attacks on an Ethereum testnet and find that by combining ConditionalExhaust and MemPurge, adversaries can simultaneously burden victims' computational resources and clog their mempools to the point where victims are unable to include transactions in blocks. Thus, victims create empty blocks, thereby hurting the system's liveness. The attack's expected cost is $376, but becomes cheaper if adversaries are validators. For other attackers, costs decrease if censorship is prevalent in the network. ConditionalExhaust and MemPurge are made possible by inherent features of Turing-complete blockchains, and potential mitigations may result in reducing a ledger's scalability.
Sheng, Peiyao, Ranvir Rana, Bala, Senthil, Himanshu Tyagi · 5 authors
Layer 1 (L1) blockchains such as Ethereum are secured under an "honest supermajority of stake" assumption for a large pool of validators who verify each and every transaction on it. This high security comes at a scalability cost which not only effects the throughput of the blockchain but also results in high gas fees for executing transactions on chain. The most successful solution for this problem is provided by optimistic rollups, Layer 2 (L2) blockchains that execute transactions outside L1 but post the transaction data on L1. The security for such L2 chains is argued, informally, under the assumption that a set of nodes will check the transaction data posted on L1 and raise an alarm (a fraud proof) if faulty transactions are detected. However, all current deployments lack a proper incentive mechanism for ensuring that these nodes will do their job "diligently", and simply rely on a cursory incentive alignment argument for security. We solve this problem by introducing an incentivized watchtower network designed to serve as the first line of defense for rollups. Our main contribution is a "Proof of Diligence" protocol that requires watchtowers to continuously provide a proof that they have verified L2 assertions and get rewarded for the same. Proof of Diligence protocol includes a carefully-designed incentive mechanism that is provably secure when watchtowers are rational actors, under a mild rational independence assumption. Our proposed system is now live on Ethereum testnet. We deployed a watchtower network and implemented Proof of Diligence for multiple optimistic rollups. We extract execution as well as inclusion proofs for transactions as a part of the bounty. Each watchtower has minimal additional computational overhead beyond access to standard L1 and L2 RPC nodes. Our watchtower network comprises of 10 different (rationally independent) EigenLayer operators, secured using restaked Ethereum and spread across three different continents, watching two different optimistic rollups for Ethereum, providing them a decentralized and trustfree first line of defense. The watchtower network can be configured to watch the batches committed by sequencer on L1, providing an approximately 3 minute (cryptoeconomically secure) finality since the additional overhead for watching is very low. This is much lower than the finality delay in the current setup where it takes about 45 minutes for state assertions on L1, and hence will not delay the finality process on L1.
Huma Zafar
As early as 2013, Vitalik Buterin introduced Ethereum with the possibility of its widespread use (Antonopoulos, 2018). There are several applications based on the Ethereum protocol, including ERC-20 tokens, which are Ethereum-based tokens that can be created and deployed on the Ethereum network. Over 400 million transactions have been made on Ethereum since its inception. There have been a number of illegal activities related to Ethereum, including smart-Ponzi schemes, phishing, money laundering, and fraud. Detecting and predicting such attacks over blockchain can be achieved through anomaly detection for blockchain. The paper makes a number of contributions; first of all, it proposes a Random Forest Classifier, which is an effective method for detecting illicit accounts on the Ethereum network based on the testing of 8 models of four distinct types (Decision Tree, Random Forest, Gradient Boosting, and Extreme Gradient Boosting); secondly, it gives a multiple linear regression model for estimating total Ethereum transfers; and thirdly, it provides coherent and graphical representations of historical data. The software tool, KNIME is used to execute the statistical tasks. This tool uses visual nodes to do descriptive, predictive and prescriptive analytics (Berthold et al., 2009).