Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

7,409 papersLast indexed Aug 24, 2026
Search papers

Paper index

7,409 results ¡ page 130 of 309

Clear filters
Oct 21, 2023¡IET Blockchain
6 cites
Security and privacy issues in blockchain and its applications

Liangmin Wang, Victor S. Sheng, Boris Dßdder, Haiqin Wu ¡ 5 authors

Blockchain technology has emerged and evolved as a disruptive technology with the potential to be applied in various fields, including digital finance, healthcare, and the Internet of Things (IoT). Besides being a distributed ledger, blockchain enables decentralized and trusted storage/computation without relying on a central trusted party. However, the growing heterogeneity of blockchain platforms and the expanding range of applications have resulted in escalating security and privacy concerns. These concerns encompass persistent privacy breaches, vulnerabilities in smart contracts, and the “impossible triangle” problem. These challenges have emerged as the primary obstacles to the development and seamless integration of blockchain technology with industry applications. To address the security and privacy challenges in blockchain platforms and its applications, numerous researchers have conducted extensive studies in this field by leveraging advanced technologies, including new cryptographic protocols and deep learning techniques. This special issue aims to highlight research perspectives, articles, and experimental studies pertaining to “Security and Privacy Issues in Blockchain and Its Applications”. In this special issue, we received a total of nineteen papers, out of which seventeen underwent a rigorous peer-review process. However, two papers were excluded from the peer-reviewed selection because one was submitted in a draft form and the other was voluntarily withdrawn by the authors. Out of the seventeen papers submitted for review, ten were accepted for publication, six were rejected without being transferred, and one was rejected and referred to a transfer service. The exceptional quality of all the submissions played a crucial role in ensuring the success of this special issue. These accepted papers can be classified into two categories, namely blockchain application security and cross-chain interaction security. The papers in the first category focus on analyzing and providing insights into the security of blockchain applications. Their objective is to keep readers informed about the latest trends, developments, challenges, and opportunities in blockchain application security. Moreover, significant research efforts have been dedicated to security analysis and detection in typical blockchain applications. The papers in this category are of Zhou et al., Grybniak et al., Lv et al., Li et al., Gong et al., Xiao et al. and Videira et al. These contributions further enhance our understanding and capability to safeguard blockchain applications from potential security threats. The second category of papers presents novel solutions that target the enhancement of security in cross-system interactions. These papers are of Feng et al., Xu et al. and Yu et al. By addressing the specific challenges associated with cross-system communication, these solutions contribute to the development of robust and secure blockchain networks. A brief presentation of each of the papers in the special issue is as follows. Zhou et al. present WASMOD, a prototype system designed to detect vulnerabilities in WebAssembly (Wasm) smart contracts. WASMOD utilizes a combination of bytecode instrumentation, run-time validation, and grey-box fuzzing techniques to identify integer overflow and stack overflow vulnerabilities. The tool was effectively applied to the EOSIO blockchain, successfully detecting vulnerable smart contracts. Grybniak et al. propose “Waterfall: Gozalandia”, a distributed protocol based on the Proof of Stake approach. This protocol enables fast finality, proven safety, and liveness in a network utilizing BlockDAG structures. By employing cross-voting for block ordering, the protocol ensures swift consensus and the ability to detect dishonest behaviors. The protocol assumes the presence of a Coordinating network that holds information about the approved ordering. This Coordinating network serves to significantly enhance security and improve network synchronization in a qualitative manner. Through load testing, the protocol has demonstrated its ability to handle a throughput of 3200–3600 transactions per second, with an average confirmation waiting time of 20 s. Lv et al. propose a graph-based embedding classification method for phishing detection on the Ethereum blockchain. The method involves constructing multiple subgraphs using the transaction records collected from Ethereum and introduces a modified version of Graph2Vec called imgraph2vec. This modified approach aims to learn more meaningful information from the subgraphs. To identify phishing attempts, the Extreme Gradient Boosting (XGBoost) algorithm is utilized. Li et al. introduce BlockDetective, an innovative framework based on GCN that employs a student-teacher architecture to identify fraudulent cryptocurrency transactions. The framework incorporates pre-training and fine-tuning, enabling the pre-trained model (teacher) to effectively adapt to the new data distribution and improve prediction performance. Meanwhile, a lightweight model (student) is trained to provide abstract and high-level information. Experimental results demonstrate that BlockDetective outperforms state-of-the-art methods. Gong et al. propose a novel method called SCGformer, which aims to detect vulnerabilities in smart contracts. This novel method combines the power of a control flow graph (CFG) and a transformer model to enhance the accuracy and effectiveness of vulnerability detection. SCGformer involves constructing the CFGs using the operation codes (opcodes) of smart contracts. By focusing on the opcodes, SCGformer provides a language-agnostic solution, ensuring consistent vulnerability detection regardless of specific language versions. The authors conduct experiments to assess the efficacy of SCGformer, yielding an accuracy rate of 94.36%. Xiao et al. introduce a blockchain-based image copyright protection system named BB-RICP. By leveraging the distributed storage technique of blockchain, BB-RICP aims to solve the vulnerabilities of centralized storage, such as data loss and tampering. The system provides a novel solution for managing the entire lifecycle of copyright. It utilizes spread spectrum watermarking to enable traceability and incorporates GM algorithms and the PBFT consensus algorithm to enhance its functionality and effectiveness. Lastly, to enhance the practicality of the system, they implement a copyright blockchain framework called ICP-Chain and conduct evaluations to assess its security and reliability. Videira et al. propose a solution to tackle the offline puzzle in the implementation of central bank digital currencies (CBDC). This solution involves minting coins with unique serial numbers, which are then stored on a local blockchain within a smartphone or EMV card. The local blockchain is fortified by a two-stage approval architecture that effectively mitigates attacks and facilitates non-repudiation handling. To enhance security, the coins are safeguarded by hardware keys embedded in the microchip and can be continuously mined by the wallet. Feng et al. introduce a novel federated learning framework that leverages a Directed Acyclic Graph (DAG) to enhance interoperability among different blockchains. The framework comprises a shard chain and a main chain, featuring replaceable consensus mechanisms and a weighted context graph to enhance efficiency. The experimental results unequivocally demonstrate the efficacy of the proposed federated framework. Specifically, the framework significantly reduces the global computation requirements while simultaneously increasing the blockchain throughput. Xu et al. introduce ChainKeeper, a cross-chain scheme for governing the chain by chain. ChainKeeper incorporates several key components, including a modular node proxy program, a verifiable node random selection method (VNRS), and a verifiable identity threshold signature method (VITS). These components work together to ensure universality, efficiency, and security throughout the cross-chain process. The scheme is resilient against malicious behaviors and collaborative attacks from both business nodes and supervision nodes. The experimental results demonstrate the effectiveness of ChainKeeper in cross-chain supervision scenarios. Yu et al. present SPRA, a policy-based regulatory architecture designed to regulate blockchain transactions. The architecture comprises four layers: permission layer, regulation layer, bridge layer, and business layer. To facilitate interoperability between these layers, they introduce XRPL, a regulatory policy description language. The regulation layer incorporates JuryBC, a decentralized jury mechanism based on the Shamir threshold secret sharing algorithm and Pedersen commitment. At the business layer, they implement RDShare, a secure and efficient regulatory data sharing mechanism that utilizes attribute-based encryption. All the selected papers in this special issue showcase the continuous advancements in the field of blockchain and its application security. However, it is important to recognize that security and privacy issues in blockchain and its applications continue to pose significant challenges. These challenges serve as a driving force for further research and exploration of new technologies. They highlight the need for ongoing efforts to enhance the security and privacy aspects of blockchain, fostering a more resilient and trustworthy blockchain ecosystem. This work is supported by the National Key R&D Program of China (2020YFB1005500) and the National Natural Science Foundation of China (62372105). The authors would like to express their sincere appreciation to all the contributors who have submitted their scientific findings to this special issue and the anonymous reviewers whose expertise and meticulous work have made this endeavor possible. The authors sincerely hope that this collaborative effort will make a meaningful contribution to the advancement of the field. Lastly, the authors would like to express their utmost appreciation to the editors-in-chief and the editorial office for their unwavering support and guidance throughout this venture. Liangmin Wang received his B.S. degree in computational mathematics in Jilin University, Changchun, China in 1999, and his PhD degree in cryptology from Xidian University, Xi'an, China in 2007. He is a full professor in the School of Cyber Science and Engineering, Southeast University, Nanjing, China. He has been honored as a “Wan-Jiang Scholar” of Anhui Province since November 2013. Now his research interests include data security and privacy. He has published over 70 technical papers at premium international journals and conferences, for example, IEEE/ACM Transactions on Networking and IEEE International Conference on Computer Communications. He has severed as a TPC member of many IEEE conferences, such as IEEE ICC, IEEE HPCC, IEEE Trust-COM. Victor S. Sheng received the master's degree in computer science from the University of New Brunswick, Canada, in 2003, and the PhD degree in computer science from Western University, Ontario, Canada, in 2007. He is an associate professor of computer science, Texas Tech University, and the founding director of the Data Analytics Lab (DAL). His research interests include data mining, machine learning, and related applications. He was an associate research scientist and NSERC postdoctoral fellow in information systems at Stern Business School, New York University, after he obtained his PhD. He is a senior member of the IEEE and a lifetime member of the ACM. He received the test-of-time award for research from KDD’20, the best paper award runner-up from KDD’08, and the best paper award from ICDM’11. He is an area chair and SPC/PC member for several international top conferences and an associate editor for several international journals. Boris Düdder is an associate professor at the department of computer science (DIKU) at the University of Copenhagen (UCPH), Denmark. He is head of the research group Software Engineering & Formal Methods at DIKU. His primary research interests are formal methods and programming languages in software engineering of trustworthy distributed systems, where he is studying automated program generation for adaptive systems with high-reliability guarantees. He is working on the computational foundations of reliable and secure Big Data ecosystems. His research is bridging the formal foundations of computer science and complex industrial applications. Haiqin Wu received her B.E. degree in computer science and Ph.D. degree in computer application technology from Jiangsu University in 2014 and 2019, respectively. She is an associate professor at the Shanghai Key Laboratory of Trustworthy Computing (Software Engineering Institute), East China Normal University, China. Before joining ECNU, she was a postdoctoral researcher in the Department of Computer Science, University of Copenhagen, Denmark. She was also a visiting student in the School of Computing, Informatics, and Decision Systems Engineering at Arizona State University, USA. Her research interests include data security and privacy protection, mobile crowdsensing/crowdsourcing, and blockchain-based applications. Huijuan Zhu received her master's degree at School of Computer Science and Communication Engineering in Jiangsu University, Zhenjiang, China in 2010 and her Ph.D. degree at School of Computer and Control Engineering in University of Chinese Academy of Sciences, Beijing, China in 2017. Her research interests include malware detection and machine learning. She is an associate professor in the School of Computer Science and Communication Engineering at Jiangsu University.

Open access
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Privacy-Preserving Technologies in Data
Original source
Oct 20, 2023¡Communications in computer and information science
3 cites
One-Phase Batch Update on Sparse Merkle Trees for Rollups

Boqian Ma, Vir Nath Pathak, Lanping Liu, Sushmita Ruj

A sparse Merkle tree is a Merkle tree with fixed height and indexed leaves given by a map from indices to leaf values. It allows for both efficient membership and non-membership proofs. It has been widely used as an authenticated data structure in various applications, such as layer-2 rollups for blockchains. zkSync Lite, a popular Ethereum layer-2 rollup solution, uses a sparse Merkle tree to represent the state of the layer-2 blockchain. The account information is recorded in the leaves of the tree. In this paper, we study the sparse Merkle tree algorithms presented in zkSync Lite, and propose an efficient batch update algorithm to calculate a new root hash given a list of account (leaf) operations. Using the construction in zkSync Lite as a benchmark, our algorithm 1) improves the account update time from $\mathcal{O}(\log n)$ to $\mathcal{O}(1)$ and 2) reduces the batch update cost by half using a one-pass traversal. Empirical analysis of real-world block data shows that our algorithm outperforms the benchmark by at most 14%.

Open access
2 source records
cs.DS
Blockchain Technology Applications and Security
Traffic control and management
Original source
Oct 20, 2023
0 cites
EIP Security Analysis: Application Program Standards, Attack Events, and Security Vulnerabilities

Xueyan Tang, Yuying Du, Z Wang, Shawn Chong

With the ongoing advancement and widespread adoption of blockchain technology, Ethereum has established itself as the foremost platform for executing smart contracts.As a focal point of the industry, the security and stability of the Ethereum ecosystem have become crucial. Ethereum Improvement Proposals (EIPs) play a vital role in promoting the technological progress of Ethereum and providing direction for innovation in the blockchain field. ERCs, as a type of EIP, define application-level standards and conventions that are crucial for promoting innovation and ensuring the scalability and maintainability of the system. In particular, some ERCs, such as the ERC-20 token standard, have become the foundation of the Ethereum ecosystem. However, if EIPs have security issues, any security vulnerabilities or design flaws can have severe consequences, including financial losses, data leaks, and damage to the reputation of the entire Ethereum network. This paper primarily focuses on the security analysis of application standard proposals (ERC). We conducted research on the current state of EIP security, performed case studies, and provided security recommendations. The goal is to gain a comprehensive understanding of the security features and potential risks of these proposals, and to propose practical solutions to enhance the security of EIPs.

Open access
Blockchain Technology Applications and Security
Cloud Data Security Solutions
FinTech, Crowdfunding, Digital Finance
Original source
Oct 20, 2023
1 cites
STFN: Spatio-Temporal Fusion Network to Detect Ethereum Phishing Scams

Yandi Xu, Lun Zhang, Turan Vural, Peng Qian ¡ 9 authors

Due to the decentralized and transparent characteristics of the blockchain ecosystem, malicious activities such as phishing scams on the Ethereum platform result in significant financial losses for users. The current methods for detecting phishing largely rely on analyzing original transactions, which makes uncovering hidden transaction patterns challenging. To tackle this limitation, we introduce the Spatio-Temporal Fusion Network (STFN) designed to identify phishing scams on the Ethereum network. Specifically, STFN incorporates two key components: the transactions subgraph encoder for formalizing spatial features, and the transaction sequence BERT encoder for capturing temporal features. By fusing these spatio-temporal features, we facilitate their integration into a machine learning algorithm for classifying phishing accounts. The experimental outcomes underscore the effectiveness of the STFN, achieving an AUC of 93.26% and a Recall of 94.53%, outperforming previous methods for Ethereum phishing detection.

Open access
Blockchain Technology Applications and Security
Spam and Phishing Detection
Imbalanced Data Classification Techniques
Original source
Oct 20, 2023¡Journal of theoretical and applied electronic commerce research
28 cites
Global Market Perceptions of Cryptocurrency and the Use of Cryptocurrency by Consumers: A Pilot Study

M. Murugappan, Rashmi Nair, K. Saravanan

Cryptocurrencies, like Bitcoin and Ethereum, have garnered global attention in recent years as digital alternatives to traditional fiat currencies. This paper explores the complex landscape of cryptocurrency adoption, consumer behavior, and perceptions. Beginning with the origin of cryptocurrencies and the dominance of Bitcoin with its USD 1.23 trillion market capitalization, the paper highlights popular online platforms facilitating Bitcoin trading. It also examines the varying legal statuses and regulations across different countries, with a notable divide between Eastern and Western nations, attributed to factors like wealth, risk tolerance, and government restrictions. The role of blockchain technology as the foundation of cryptocurrencies is explained, emphasizing its role in ensuring secure and transparent transactions. The paper delves into the processes involved in handling cryptocurrencies, including the blockchain, exchanges, wallets, and mining. Consumer behavior and the factors influencing cryptocurrency usage are analyzed, with a focus on speculation, algorithm trust, spending power, and demographics. Survey findings and case studies from diverse geographical areas reveal patterns of adoption and local consumer perceptions. The paper concludes by discussing the cryptocurrency market’s inherent volatility and sensitivity to regulatory changes, as well as the different types of cryptocurrencies and online exchanges shaping this evolving financial landscape. Overall, it offers insights into the complex dynamics surrounding cryptocurrency adoption and its potential impact on global finance.

Open access
Blockchain Technology Applications and Security
FinTech, Crowdfunding, Digital Finance
Crime, Illicit Activities, and Governance
Original source
Oct 19, 2023¡IET Blockchain
6 cites
Decentralized trustworthiness score management with smart contracts on the trustlend platform

Wisnu Uriawan, Youakim Badr, Omar Hasan, Lionel Brunie

Abstract The personal lending marketplace, known as Peer‐to‐Peer (P2P) lending, has increased globally. However, providing unsecured loans to peers without requiring collateral remains a challenge. A platform called TrustLend is proposed to enable trustworthy transactions in the personal lending application. The platform attempts to eliminate or minimize the collateral requirement. The trustworthiness score adds to this platform's variable selection rules and can help lenders decide on reliable candidates as borrowers. The prototype implementing the TrustLend platform based on Ethereum smart contracts that use the trustworthiness score is also described and it is illustrated with a Decentralized Application (DApp) case study and customized smart contracts. The prototype demonstrates fundamental features and supports borrowers, lenders, and recommenders in establishing proposals and approvals. Finally, the prototype shows how end‐users can easily access loans with reduced collateral without hidden costs and swift transactions.

Open access
FinTech, Crowdfunding, Digital Finance
Blockchain Technology Applications and Security
Microfinance and Financial Inclusion
Original source
Oct 18, 2023¡Proceedings of the ACM on Measurement and Analysis of Computing Systems
12 cites
Towards Understanding and Characterizing the Arbitrage Bot Scam In the Wild

Kai Li, Shixuan Guan, Darren Lee

This paper presents the first comprehensive analysis of an emerging cryptocurrency scam named "arbitrage bot" disseminated on online social networks. The scam revolves around Decentralized Exchanges (DEX) arbitrage and aims to lure victims into executing a so-called "bot contract" to steal funds from them. To entice victims and convince them of this scheme, we found that scammers have flocked to publish YouTube videos to demonstrate plausible profits and provide detailed instructions and links to the bot contract. To collect the scam at a large scale, we developed a fully automated scam detection system namedCryptoScamHunter, which continuously collects YouTube videos and automatically detects scams. Meanwhile,CryptoScamHunter can download the source code of the bot contract from the provided links and extract the associated scam cryptocurrency address. Through deployingCryptoScamHunter from Jun. 2022 to Jun. 2023, we have detected 10,442 arbitrage bot scam videos published from thousands of YouTube accounts. Our analysis reveals that different strategies have been utilized in spreading the scam, including crafting popular accounts, registering spam accounts, and using obfuscation tricks to hide the real scam address in the bot contracts. Moreover, from the scam videos we have collected over 800 malicious bot contracts with source code and extracted 354 scam addresses. By further expanding the scam addresses with a similar contract matching technique, we have obtained a total of 1,697 scam addresses. Through tracing the transactions of all scam addresses on the Ethereum mainnet and Binance Smart Chain, we reveal that over 25,000 victims have fallen prey to this scam, resulting in a financial loss of up to 15 million USD. Overall, our work sheds light on the dissemination tactics and censorship evasion strategies adopted in the arbitrage bot scam, as well as on the scale and impact of such a scam on online social networks and blockchain platforms, emphasizing the urgent need for effective detection and prevention mechanisms against such fraudulent activity.

Open access
3 source records
cs.CR
cs.SI
Spam and Phishing Detection
Original source
Oct 18, 2023¡Tấp chí Kinh tế và Phåt triᝃn
1 cites
Khảo sát hiệu ứng bất đối xứng trong biến động tỷ suất sinh lợi của các chuỗi tiền điện tử

Chinh Nguyễn Lý Kiều, Anh Trần Thị Tuấn

Nghiên cứu này sử dụng các mô hình GARCH, bao gồm EGARCH(1,1), GJR-GARCH(1,1), TGARCH(1,1) và APARCH(1,1) để khảo sát sự bất đối xứng trong biến động tỷ suất sinh lợi của các loại tiền điện tử như Bitcoin, Ethereum, Ripple (XRP), Binance Coin (BNB) và DigiByte (DGB) trong khoảng thời gian từ ngày 01 tháng 01 năm 2018 đến ngày 31 tháng 5 năm 2023. Kết quả cho thấy mô hình EGARCH(1,1) là mô hình tốt nhất để mô tả hiệu ứng bất đối xứng trong biến động tỷ suất sinh lợi của các chuỗi tiền điện tử. Sự biến động tăng nhiều hơn trong phản ứng với cú sốc tích cực hơn là cú sốc tiêu cực, hàm ý một hiệu ứng bất đối xứng khác với hiệu ứng thường thấy trên thị trường chứng khoán. Kết quả nghiên cứu giúp nhà đầu tư và nhà quản lý rủi ro trong thị trường tiền điện tử hiểu rõ hơn về sự biến động giá, nhận biết, đánh giá rủi ro một cách chính xác hơn và đưa ra các chiến lược đầu tư phù hợp.

Open access
Market Dynamics and Volatility
Financial Risk and Volatility Modeling
Monetary Policy and Economic Impact
Original source
Oct 18, 2023¡Electronics
6 cites
Design and Implementation of Enabling SQL–Query Processing for Ethereum-Based Blockchain Systems

Jongbeen Han, Yunhyeong Seo, Sangjin Lee, Sunggon Kim ¡ 5 authors

A blockchain is designed to establish consistent and reliable agreements in an untrusted and decentralized environment. In addition, the blockchain enables transaction processing and the creation of smart contracts. It empowers end users to execute contracts without any intermediate entities. However, there are some issues when it comes to retrieving information, such as the state and history of smart contracts and regular transactions in the blockchain. For example, in a smart contract, user-defined data structures can be used to recall the state of the smart contract for a range query, which can decrease the general performance. In addition, an external database can be required to retrieve regular transactions for range queries, which increases management costs. To achieve this, we propose a new scheme that enables SQL query operations to retrieve a smart contract and regular transaction information within the blockchain system. To achieve this, we combine an embedded relational database with an Ethereum-based blockchain system to provide the SQL query. It enables range queries on smart contracts without requiring user-defined data structures and decreases management costs for regular transactions without any external database. We implement the proposed blockchain system on quorum, which is an Ethereum-based blockchain system. Also, we evaluate the proposed system using a synthetic benchmark. The performance of retrieving smart contract data is improved by up to approximately 22×, with low memory usage compared with the existing system. Moreover, the proposed system demonstrates a similar search performance to the existing system, even when considering external databases in regular transactions.

Open access
Blockchain Technology Applications and Security
Cloud Computing and Resource Management
Caching and Content Delivery
Original source
Oct 16, 2023¡Journal of Islamic Studies and Humanities
1 cites
REVIEW OF PURCHASING AND SELLING NFTS IN ISTIHSAN

Mohammad Farid Fad

AbstractSo far, NFTs have been defined as digital tokens that are shaped like ownership certificates for virtual and physical assets. These NFTs are usually traded online and are often paid for using cryptocurrencies, especially Ethereum. However, the problem is that in 2021 the MUI issued a fatwa that cryptocurrency is illegal. This is because it there are elements of qimar, dharar, and gharar. For this reason, it is necessary to study the methodology of Islamic law regarding Non-Fungible Tokens (NFT) through istihsan (juristic preference). This study uses a qualitative approach. The data were collected from library study, documentation and observation. In analyzing the data used descriptive-analytic analysis with the approach used is ushuliyah. This study revealed that from istihsan point of view, transactions using Non-Fungible Tokens are permitted. This is because, from Qiyas Khafi perspective, NFT is known as the underlying assets of the transaction. Up to the operational level, if qiyas khafi is of greater benefit, then qiyas jali may be abandoned. What is used is qiyas khafi to maintain the principles of maqasid shari'a. Therefore, within the istihsan framework, Non-Fungible Token transactions are allowed through qiyas khafi due to an element of greater benefit.Keywords: Non-Fungible Token Transaction; Istihsan; Maqasid Shari’a, AbstrakSelama ini NFT didefinisikan sebagai token digital yang berbentuk seperti sertifikat kepemilikan untuk aset virtual dan fisik. NFT ini adalah biasanya diperdagangkan secara online dan sering dibayar untuk menggunakan cryptocurrency, khususnya Ethereum. Namun yang menjadi persoalan ialah pada tahun 2021 MUI pernah memfatwakan haram penggunaan cryptocurrency karena mengandung unsur gharar, dharar, dan qimar. Untuk itu, diperlukan kajian metodologi hukum Islam tentang Non-Fungible Token (NFT) melalui istihsan. Penelitian ini menggunakan pendekatan kualitatif. Sementara metode pengumpulan data yang dipakai dalam penelitian ini adalah metode literatur, dokumentasi dan observasi. Dalam menganalisis data yang telah dikumpulkan, peneliti menggunakan analisis deskriptif-analitis dengan pendekatan ushuliyah. Hasil penelitian ini menyatakan bahwa dalam tinjauan istihsan, transaksi dengan menggunakan Non-Fungible Token diperbolehkan. Hal ini dikarenakan dalam tinjauan qiyas khafi, NFT dikenal asset yang mendasari transaksi tersebut (underlying assets). Hingga dalam tataran operasionalnya, bila qiyas khafy lebih besar manfaatnya, maka qiyas jaly itu boleh ditinggalkan dan yang dipakai adalah qiyas khafy demi terpeliharanya prinsip-prinsip maqasid syari’ah. Oleh karena itu, dalam kerangka istihsan, transaksi Non-Fungible Token diperbolehkan melalui qiyas khafi dikarenakan adanya unsur maslahat yang lebih besar.Keywords: Non-Fungible Token; Istihsan; Maqashid Syari’ah.

Open access
Islamic Finance and Communication
Marriage and Family Dynamics
Legal Studies and Policies
Original source
Oct 16, 2023¡Proceedings of the ACM on Programming Languages
15 cites
Asparagus: Automated Synthesis of Parametric Gas Upper-Bounds for Smart Contracts

Zhuo Cai, Soroush Farokhnia, Amir Kafshdar Goharshady, S. Hitarth

Modern programmable blockchains have built-in support for smart contracts, i.e. ‍programs that are stored on the blockchain and whose state is subject to consensus. After a smart contract is deployed on the blockchain, anyone on the network can interact with it and call its functions by creating transactions. The blockchain protocol is then used to reach a consensus about the order of the transactions and, as a direct corollary, the state of every smart contract. Reaching such consensus necessarily requires every node on the network to execute all function calls. Thus, an attacker can perform DoS by creating expensive transactions and function calls that use considerable or even possibly infinite time and space. To avoid this, following Ethereum, virtually all programmable blockchains have introduced the concept of “gas”. A fixed hard-coded gas cost is assigned to every atomic operation and the user who calls a function has to pay for its total gas usage. This technique ensures that the protocol is not vulnerable to DoS attacks, but it has also had significant unintended consequences. Out-of-gas errors, i.e. ‍when a user misunderestimates the gas usage of their function call and does not allocate enough gas, are a major source of security vulnerabilities in Ethereum. We focus on the well-studied problem of automatically finding upper-bounds on the gas usage of a smart contract. This is a classical problem in the blockchain community and has also been extensively studied by researchers in programming languages and verification. In this work, we provide a novel approach using theorems from polyhedral geometry and real algebraic geometry, namely Farkas’ Lemma, Handelman’s Theorem, and Putinar’s Positivstellensatz, to automatically synthesize linear and polynomial parametric bounds for the gas usage of smart contracts. Our approach is the first to provide completeness guarantees for the synthesis of such parametric upper-bounds. Moreover, our theoretical results are independent of the underlying consensus protocol and can be applied to smart contracts written in any language and run on any blockchain. As a proof of concept, we also provide a tool, called “Asparagus” that implements our algorithms for Ethereum contracts written in Solidity. Finally, we provide extensive experimental results over 24,188 real-world smart contracts that are currently deployed on the Ethereum blockchain. We compare Asparagus against GASTAP, which is the only previous tool that could provide parametric bounds, and show that our method significantly outperforms it, both in terms of applicability and the tightness of the resulting bounds. More specifically, our approach can handle 80.56% of the functions (126,269 out of 156,735) in comparison with GASTAP’s 58.62%. Additionally, even on the benchmarks where both approaches successfully synthesize a bound, our bound is tighter in 97.85% of the cases.

Open access
Blockchain Technology Applications and Security
Security and Verification in Computing
Distributed systems and fault tolerance
Original source
Oct 16, 2023¡arXiv (Cornell University)
4 cites
Bridging BRC-20 to Ethereum

Qin Wang, Guangsheng Yu, Shiping Chen

In this paper, we design, implement, and (partially-) evaluate a lightweight bridge (as a type of middleware) to connect the Bitcoin and Ethereum networks that were heterogeneously uncontactable before. Inspired by the recently introduced Bitcoin Request Comment (BRC-20) standard, we leverage the flexibility of Bitcoin inscriptions by embedding editable operations within each satoshi and mapping them to programmable Ethereum smart contracts. A user can initialize his/her requests from the Bitcoin network, subsequently triggering corresponding actions on the Ethereum network. We validate the lightweight nature of our solution and its ability to facilitate secure and seamless interactions between two heterogeneous ecosystems.

Open access
3 source records
Blockchain Technology Applications and Security
Physical Unclonable Functions (PUFs) and Hardware Security
Distributed systems and fault tolerance
Original source
Oct 15, 2023¡International Journal of Innovative Research in Engineering & Management
3 cites
Secure Data Management with Blockchain-Enabled Attribute-Based Access Control

Bindu Babu, K. Suresh Babu, Durga Prasad Kare

The security of computerized systems depends on mechanisms for controlling access. For the enrichment and reinforcement of such systems, a combination of attribute-based access control and blockchain technologies may be deployed. On the other hand, attribute-based encryption may be used to enable secure data management and safeguard access policies. In this research, we have presented innovative blockchain-enabled attribute-based access control. Our architecture is the first to integrate different aspects to accomplish many security aspects as well as give partial and total revocation at the same time. The experimental findings and analysis, done utilizing the blockchain of the Ethereum network, proved the superior performance of the suggested method compared to prior research works.

Open access
Blockchain Technology Applications and Security
Cryptography and Data Security
Access Control and Trust
Original source
Oct 15, 2023¡Applied Sciences
7 cites
Authenticity, and Approval Framework for Bus Transportation Based on Blockchain 2.0 Technology

Tariq Jamil Saifullah Khanzada, Muhammad Farrukh Shahid, Ahmad Mutahhar, Muhammad Ahtisham Aslam ¡ 8 authors

The intelligent transport system (ITS) has transformed urban transportation, enhancing daily commutes with services like congestion management, vehicle crash prevention, traffic control, roadside safety, breakdown assistance, ticket booking, vehicle registration, and insurance. However, in urban bus transportation, the ITS faces security threats, such as data forgery and manipulation. To counter these challenges, a blockchain-based framework for bus transportation approval is proposed, ensuring data integrity and security. The framework’s performance is evaluated based on processing time, central processing unit (CPU), graphical processing unit (GPU), cloud usage, and memory consumption, and compared to Ethereum and Aurora testnet, in terms of gas cost, security, and performance. Stochastic algorithms, including the genetic algorithm and Tabu search, are used for time complexity analysis, to obtain an optimized solution. The decision-making trial and evaluation laboratory (DEMATEL) analysis is also performed to assess factors like transaction costs, execution time, memory consumption, and security. The results show that execution time, memory consumption, and processing time are crucial, while transaction cost, reliability, and transparency positively impact the system’s effectiveness. By reducing the risk of false data presentation and ensuring accurate records, the proposed framework contributes to a more efficient and reliable transportation system.

Open access
Blockchain Technology Applications and Security
Traffic Prediction and Management Techniques
Traffic control and management
Original source
Oct 14, 2023¡arXiv (Cornell University)
3 cites
A Framework for Empowering Reinforcement Learning Agents with Causal Analysis: Enhancing Automated Cryptocurrency Trading

Rasoul Amirzadeh, Dhananjay Thiruvady, Asef Nazari, Mong Shan Ee

Despite advances in artificial intelligence-enhanced trading methods, developing a profitable automated trading system remains challenging in the rapidly evolving cryptocurrency market. This research focuses on developing a reinforcement learning (RL) framework to tackle the complexities of trading five prominent altcoins: Binance Coin, Ethereum, Litecoin, Ripple, and Tether. To this end, we present the CausalReinforceNet~(CRN) framework, which integrates both Bayesian and dynamic Bayesian network techniques to empower the RL agent in trade decision-making. We develop two agents using the framework based on distinct RL algorithms to analyse performance compared to the Buy-and-Hold benchmark strategy and a baseline RL model. The results indicate that our framework surpasses both models in profitability, highlighting CRN's consistent superiority, although the level of effectiveness varies across different cryptocurrencies.

Open access
2 source records
cs.AI
cs.LG
Blockchain Technology Applications and Security
Original source
Oct 13, 2023¡Future Generation Computer Systems
64 cites
A scalable and lightweight group authentication framework for Internet of Medical Things using integrated blockchain and fog computing

Norah Alsaeed, Farrukh Nadeem, Faisal Albalwy

The Internet of Medical Things (IoMT) is the network of medical devices, software applications, and healthcare information systems used for remote monitoring and delivery of healthcare services. Despite the several advantages of IoMT for today smart healthcare, security issues are growing due to the inadequate computation, limited storage and insufficient self-protection capabilities of IoMT devices. Authentication of IoMT devices is the main requirement to secure IoMT systems. Although, the recent authentication schemes based on tamper-proof decentralized architecture of blockchain technology are robust and enjoy a high level of security, yet they require high computation, more storage, and long authentication time. These issues lead to reduced scalability and time efficiency, which are necessary for large-scale, time-sensitive IoMT systems. To this end, this paper proposes a novel group authentication framework for IoMT Systems. The group authentication scheme is implemented through a four-phase process, including setup, registration, secret construction, and authentication. To enhance both efficiency and scalability, the proposed group authentication framework employs a combination of elliptic curve cryptography (ECC), Shamir’s secret sharing (SSS) algorithm, and blockchain-based fog computing technologies. We simulated the proposed framework through the Ethereum platform and Solidity language and its performance is evaluated using the Hyperledger Caliper tool. The simulation experiments of the proposed framework showed that the average latency of authenticating IoMT devices was 0.5 second and the throughput was 400 transactions per second. Our analysis of the proposed framework’s performance against other cutting-edge blockchain-based authentication techniques showed that it outperformed them in terms of latency and throughput. A security analysis of the proposed framework was conducted using the widely accepted Automated Validation of Internet Security Protocols and Applications (AVISPA) tool. The formal and informal security analysis demonstrated that the proposed framework is secure and resistant to potential authentication-related attacks. We also noted that the average latency of the proposed framework maintains a fairly narrow range when the number of submitted transactions rises, indicating that it supports the scalability of the IoMT system.

Open access
Advanced Authentication Protocols Security
User Authentication and Security Systems
Blockchain Technology Applications and Security
Original source
Oct 13, 2023¡arXiv (Cornell University)
2 cites
How to Rationally Select Your Delegatee in PoS

Yuzhe Zhang, Qin Wang, Shiping Chen, Chen Wang

This paper centers around a simple yet crucial question for everyday users: How should one choose their delegated validators within proof-of-stake (PoS) protocols, particularly in the context of Ethereum 2.0? This has been a long-overlooked gap, as existing studies have primarily focused on inter-committee (validator set) behaviors and activities, while neglecting the dynamic formation of committees, especially for individual stakeholders seeking reliable validators. Our study bridges this gap by diving into the delegation process (normal users delegate their small-value tokens to delegatees who later act as validators) before entering an actual consensus phase. We propose a Bayesian model to quantify normal users' trust in delegatees, which we further incorporate into a game-theoretical model to simulate users' reactions against a set of critical factors identified through extensive research (including 10+ staking service provider as well as 30+ PoS blockchains). Our results reveal that users tend to choose their delegatees and utilize their tokens by carefully weighing the delegation cost, the behaviors of other users, and the reputation of delegatees, ultimately reaching a Nash equilibrium. Unfortunately, the collective trend significantly increases the likelihood of token concentration on a small number of delegatees.

Open access
2 source records
Blockchain Technology Applications and Security
Mobile Crowdsensing and Crowdsourcing
cs.CR
Original source
Oct 12, 2023
1 cites
Public Blockchain in Support of Transactive Energy Markets

Akin Eker, Theo Tryfonas, George Oikonomou

Transactive Energy Markets (TEM) have the potential to reduce wasted energy, increase the utilisation of renewable energy resources and enable independence in the energy sector. Blockchain has been utilised in TEMs in the literature aiming to acquire transparency, security and trustless operations. Though public blockhain enables leveraged transparency and fairness, the majority of proposals suggest adoption of private or consortium blockchains mainly due to performance concerns. In this paper, we created a TEM environment where consumers, prosumers and suppliers bid for price agreement upon a game theory model and then deployed it on localised Ethereum blockchain infrastructure. To compare the performance, we created a centralized TEM environment keeping all the settings the same. The obtained results show that public blockchains may be adaptable to TEMs to enhance system transparency and fairness as well as automated and trustless transactions. Conducted test results show that our proposal exhibit a similar scalability trend as the referenced centralized system.

Open access
Blockchain Technology Applications and Security
Smart Grid Energy Management
Caching and Content Delivery
Original source
Oct 12, 2023¡Science of Computer Programming
9 cites
SolAR: Automated test-suite generation for solidity smart contracts

Stefan Driessen, Dario Di Nucci, Damian A. Tamburri, W.-J. van den Heuvel

Smart contracts have rapidly gained popularity as self-contained pieces of code, especially those run on the Ethereum blockchain. On the one hand, smart contracts are immutable, have transparent workings, and execute autonomously. On the other hand, these qualities make it essential to properly test the behavior of a smart contract before deploying it. In this paper, we introduce SolAR, a tool and approach for Solidity Automated Test Suite GeneRation. SolAR allows smart contract developers to generate test suites for Solidity smart contracts optimized automatically for branch coverage using either a state-of-the-art genetic algorithm or a fuzzing approach. It enables a novel way to handle blockchain operations—or ChainOps—from a pipeline perspective, entailing a larger-scale as well as more manageable and maintainable service continuity.

Open access
Software Testing and Debugging Techniques
Advanced Malware Detection Techniques
Software Engineering Research
Original source
Oct 11, 2023¡arXiv
3 cites
Trusting a Smart Contract Means Trusting its Owners: Understanding Centralization Risk

Metin Lamby, Valentin Zieglmeier, Christian Ziegler

Smart contract access control mechanisms can introduce centralization into supposedly decentralized ecosystems. In our view, such centralization is an overlooked risk of smart contracts that underlies well-known smart contract security incidents. Critically, mitigating the known vulnerability of missing permission verification by implementing authorization patterns can in turn introduce centralization. To delineate the issue, we define centralization risk and describe smart contract source code patterns for Ethereum and Algorand that can introduce it to smart contracts. We explain under which circumstances the centralization can be exploited. Finally, we discuss implications of centralization risk for different smart contract stakeholders.

Open access
2 source records
Blockchain Technology Applications and Security
Cryptography and Data Security
Security and Verification in Computing
Original source
Oct 11, 2023
3 cites
Exploring Locality in Ethereum Transactions

Matthieu Pigaglio, Michał Król, Étienne Rivière

Early open blockchain designs face low throughput, high latency, and prohibitive costs for setting up a full node. New designs improve this with innovative mechanisms for handling transactions and the blockchain state, often assuming locality properties in the workload of transactions. Temporal locality allows efficient space management such as light nodes or snapshot-based bootstrap. Disjoint access parallelism, which depends on spatial locality, enables parallel processing of non-conflicting transactions. We analyze locality properties and their interplay in the largest transactional workload available to date, that of Ethereum. Our results show that, although transactions generally display good locality, a minority of accounts are responsible for caching- or parallelism-unfriendliness, calling for specific identification and handling in future blockchain designs.

Open access
Blockchain Technology Applications and Security
Caching and Content Delivery
Cloud Computing and Resource Management
Original source
Oct 9, 2023
2 cites
A Secured Blockchain Framework for Healthcare Data Management System

Toqeer Ahmed, Saeed Mian Qaiser, Asad Waqar

In the healthcare system, electronic medical records are very critical, and they must be authenticated and verified. During the medical check-up, a large amount of patient medical data is generated which includes reports related to blood, life-threatening diseases, and personal information such as credit card numbers and addresses. Any privacy breach in patient medical records will bring various risks. A simple blockchain (Ethereum) can be effective to validate and authenticate stored data by deploying an immutable ledger. However, the main challenge in the simple blockchain is that its data can be easily accessible. In this paper, the authors create a business network for healthcare using Hyperledger fabric, which ensures that data is only available to the concerned person and its access rights are granted and revoked by the concerned participant. Additionally, the authors tested different scenarios to access blockchain security and its benefits.

Open access
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Cloud Data Security Solutions
Original source
Oct 9, 2023¡ICST Transactions on Scalable Information Systems
1 cites
Framework for Data Provenance Assurance in Cloud Environment using Ethereum Blockchain

Gautham Narayan, Pavitra Haveri, B H Rashmi, Yashwardhan Deewan

Ensuring secure data provenance is crucial for maintaining accountability and confidentiality in cloud environments. Cloud data provenance involves recording the history of creation and operations performed on cloud data objects. However, establishing trust between cloud customers and service providers remains a challenge, highlighting the need for assured data provenance models in cloud storage. Blockchain technology has emerged as a solution for designing data provenance assurance mechanisms. It provides a decentralized and distributed ledger to record the provenance of digital assets. In this context, we present a blockchain-based framework for ensuring data provenance in cloud storage. Initially, we develop a cloud storage application using OpenStack swift storage. This application caters to the storage needs of university students and faculty while providing data provenance capabilities. Subsequently, we design a data provenance assurance framework for confidential files of users using the Ethereum blockchain. To evaluate the scalability and performance of the proposed framework, we analyze various factors such as transaction throughput, latency, network size, and load on the blockchain network. The performance of the system is compared under two consensus algorithms: Proof of Work and Proof of Authority. By conducting this analysis, we aim to assess the effectiveness and efficiency of the blockchain-based solution in ensuring data provenance in cloud storage environments.

Open access
Scientific Computing and Data Management
Blockchain Technology Applications and Security
Cloud Data Security Solutions
Original source