With the blooming of blockchain-based smart contracts in decentralized applications, the security problem of smart contracts has become a critical issue, as vulnerable contracts have resulted in severe financial losses. Existing research works have explored vulnerability detection methods based on fuzzing, symbolic execution, formal verification, and static analysis. In this paper, we propose two static analysis approaches called ASGVulDetector and BASGVulDetector for detecting vulnerabilities in Ethereum smart contacts from source-code and bytecode perspectives, respectively. First, we design a novel intermediate representation called abstract semantic graph (ASG) to capture both syntactic and semantic features from the program. ASG is based on syntax information but enriched by code structures, such as control flow and data flow. Then, we apply two different training models, i.e., graph neural network (GNN) and graph matching network (GMN), to learn the embedding of ASG and measure the similarity of the contract pairs. In this way, vulnerable smart contracts can be identified by calculating the similarity to labeled ones. We conduct extensive experiments to evaluate the superiority of our approaches to state-of-the-art competitors. Specifically, ASGVulDetector improves the best of three source-code-only static analysis tools (i.e., SmartCheck, Slither, and DR-GCN) regarding the F1 score by 12.6% on average, while BASGVulDetector improves that of the three detection tools supporting bytecode (i.e., ContractFuzzer, Oyente, and Securify) regarding the F1 score by 25.6% on average. We also investigate the effectiveness and advantages of the GMN model for detecting vulnerabilities in smart contracts.
Prof. Sumit Shevtekar, Ajay Raut, Pranit Chaudhari
People no longer trust charities as a result of the lack of openness, which has caused social investment to stagnate. The donor is unaware of how his money is being used legally. Mistrust of the donor is increased by corruption. In this study, a decentralised network named Charity-Chain that is based on the Ethereum blockchain is proposed. By employing smart contract-based incentives to ensure that their impact is independently validated and available to everyone, it aids social organisations in managing initiatives transparently. For funders (philanthropic organisations, impact investors, and small donors), this makes it much simpler for them to monitor their transactions and, as a result, restore their trust in funding these types of social organisations.
This paper recognizes the need for interoperability between heterogeneous blockchain-enabled smart microgrids and heterogeneous prosumers involved in peer-to-peer transactions. It discusses methods of interoperability between different blockchain platforms like Ethereum, Hyperledger Fabric, and Tendermint. It is a work-in-progress draft.
Haruna Umar Yahaya, John Sunday Oyinloye, Samuel Olorunfemi Adams
The future of e-money is crypocurrencies, it is the decentralize digital and virtual currency that is secured by cryptography. It has become increasingly popular in recent years attracting the attention of the individual, investor, media, academia and governments worldwide. This study aims to model and forecast the volatilities and returns of three top cryptocurrencies, namely; Bitcoin, Ethereum and Binance Coin. The data utilized in the study was extracted from the higher market capitalization at 31st December, 2021 and the data for the period starting from 9th November, 2017 to 31st December 2021. The Generalised Autoregressive conditional heteroscedasticity (GARCH) type models with several distributions were fitted to the three cryptocurrencies dataset with their performances assessed using some model criteria. The result shows that the mean of all the returns are positive indicating the fact that the price of this three crptocurrencies increase throughout the period of study. The ARCH-LM test shows that there is no ARCH effect in volatility of Bitcoin and Ethereum but present in Binance Coin. The GARCH model was fitted on Binance Coin, the AIC and log L shows that the CGARCH is the best model for Binance Coin. Automatic forecasting was perform based on the selected ARIMA (2,0,1), ARIMA (0,1,2) and the random walk model which has the lowest AIC for ETH-USD, BNB-USD and BTC-USD respectively. This finding could aid investors in determining a cryptocurrency's unique risk-reward characteristics. The study contributes to a better deployment of investor’s resources and prediction of the future prices the three cryptocurrencies.
Alexander Kudzin, Kentaroh Toyoda, Satoshi Takayama, Atsushi Ishigame
(1) Background: To solve the blockchain scaling issue, sharding has been proposed; however, this approach has its own scaling issue: the cross-shard communication method. To resolve the cross-shard communication scaling issue, rollups have been proposed and are being investigated. However, they also have their own scaling limitations, in particular, the degree of compression they can apply to transactions (TXs) affecting how many TXs can be included in one block. (2) Methods: In this paper, we propose a series of novel data structures for the compiling of cross-shard TXs sent using rollups for both public and private Ethereum. Our proposal removes redundant fields, consolidates repeated fields, and compresses any remaining fields in the rollup, modifying its data structure to compress the address, gas, and value fields. (3) Results: We have shown that our proposals can accommodate more cross-shard TXs in a block by reducing the TX size by up to 65% and 97.6% compared to the state-of-the-art in public and private Ethereum, respectively. This compression in TX size results in an over 2× increase in transactions per block (TPB) for our proposals targeting both types of Ethereum. (4) Conclusions: Our proposals will mitigate the scaling issue in a sharded blockchain that utilizes rollups for cross-shard communication. In particular, it will enable such sharded Ethereum networks to be deployed for large-scale decentralized systems.
Nabeel Khan, Hanan Aljoaey, Mujahid Tabassum, Ali Farzamnia · 6 authors
Since cloud computing is an essential component of any modern company (usually accounting for a considerable share of information technology (IT) infrastructure investment), consumers rely on cloud services. Data privacy and security are worries when data remains in third-party storage. Existing document version control systems are centralized and at risk from data loss, as seen by higher time utilization and incorrect document update procedures that allow modifications to a document without the awareness of other network operators. Underutilized peer resources might be leveraged to construct storage. According to this argument, an elevated level of data security may be obtained by encrypting the data and dispersing it among numerous nodes. In this study, we attempted to review the security of cloud systems when using the blockchain Ethereum, and cloud computing was briefly discussed with its advantages and disadvantages. The idea of a decentralized cloud was briefly demonstrated with blockchain technology. Furthermore, previous papers were reviewed and presented in tabular form. This dictated that there are still research gaps in the field of blockchain-based cloud computing systems. This study proposed a model for secured data storage over a decentralized cloud by blockchain Ethereum.
Cryptocurrencies aim to replicate physical cash in the digital realm while removing centralized and trusted intermediaries. Decentralization is achieved by the blockchain, a permanent public ledger that contains a record of every transaction. The public ledger ensures transparency, which enables public verifiability but harms untraceability, fungibility, and anonymity. In the last decade, cryptocurrencies attracted millions of users, with their total market cap reaching approximately three trillion USD at its peak. However, their anonymity guarantees are poorly understood and plagued by widespread misbeliefs. Indeed, previous notions of privacy, anonymity, and traceability for cryptocurrencies are either non-quantitative or inapplicable, e.g., computationally hard to measure. In this work, we put forward a formal framework to measure the (un)traceability and anonymity of cryptocurrencies, allowing us to quantitatively reason about the mixing characteristics of cryptocurrencies and the privacy-enhancing technologies built on top of them. Our methods apply absorbing Markov chains combined with Shannon entropy. To the best of our knowledge, our work provides the first practical, efficient, and probabilistic measure to assess the traceability of cryptocurrencies quantitatively, which also generalizes to entire cryptocurrency transaction graphs. We implement and extensively evaluate our proposed traceability measure on several cryptocurrency transaction graphs. Among other quantitative results, we find that in the studied one-week interval, the Bitcoin blockchain, on average, provided comparable but quantifiably more natural mixing than the Ethereum blockchain.
Syed Agha Hassnain Mohsan, Abdul Razzaq, Shahbaz Ahmed Khan Ghayyur, Hend Khalid Alkahtani · 6 authors
Several academicians have been actively contributing to establishing a practical solution to storing and distributing medical images and test reports in the research domain of health care in recent years. Current procedures mainly rely on cloud-assisted centralized data centers, which raise maintenance expenditure, necessitate a large amount of storage space, and raise privacy concerns when exchanging data across a network. As a result, it is critically essential to provide a framework that allows for the efficient exchange and storage of large amounts of medical data in a secure setting. In this research, we describe a unique proof-of-concept architecture for a distributed patient-centric test report and image management (PCRIM) system that aims to facilitate patient privacy and control without the need for a centralized infrastructure. We used an Ethereum blockchain and a distributed file system technology called the Inter-Planetary File System in this system (IPFS). Then, to secure a distributed and trustworthy access control policy, we designed an Ethereum smart contract termed the patient-centric access control protocol. The IPFS allows for the decentralized storage of medical metadata, such as images, with worldwide accessibility. We demonstrate how the PCRIM system design enables hospitals, patients, and image requestors to obtain patient-centric data in a distributed and secure manner. Finally, we tested the proposed framework in the Windows environment by deploying a smart contract prototype on an Ethereum TESTNET blockchain. The findings of the study indicate that the proposed strategy is both efficient and practicable.
Currently, the composition and structure of the production industry's supply chain is becoming increasingly complex. The loss and untimely transmission of supply chain information exacerbated the bullwhip effect. At the same time, due to the lack of a reliable repository of information, difficulties in traceability and accountability have also made supply chain management difficult. Blockchain has the characteristics of supporting distributed networks, synchronization of information between nodes, digital encryption, traceable information and unforgeable block content, which is suitable for use in supply chain and can provide a solution for it. In this paper, a design scheme of an integrated platform for information services provided by supply chain participants and based on the Ethereum blockchain is proposed. Using Ethereum smart contracts, the regular trade involved in the supply chain is realized using blockchain technology, and key information about the production and circulation of the supply chain is stored on the blockchain to ensure that the information cannot be falsified. At the same time, a reputation evaluation method based on smart contracts is used to evaluate the reputation of enterprises in the supply chain, which can provide references for supplier selection among enterprises.
Njoku ThankGod Anthony, Mahmoud Shafik, Fatih Kurugöllü, Hany F. Atlam
Over the past few years, Blockchain technology has been utilized in various applications to improve privacy and security. Although blockchain has proven its worth as a very powerful technology, research has shown that it is not entirely immune to security and privacy attacks. There was a successful 51% attack on Ethereum Classic back in January 2019 which shows that blockchain still facing security and privacy challenges. This paper aims to develop an anomaly detection solution for the Ethereum blockchain to overcome security challenges using Machine Learning (ML). The proposed solution focuses on using a dynamic approach where the normal operational behaviour of the Ethereum blockchain is used to train ML algorithms and any deviation will be tagged as an anomaly and will be detected by the system. Four ML algorithms including K-Nearest Neighbours (KNN), Gaussian Naive Bayes (GaussianNB), Random Forest, and Stochastic Gradient Descent (SDG) were utilized to train and verify the accuracy of the proposed solution. The experimental results demonstrated that the random forest algorithm provided the best accuracy of 99.84% over other ML algorithms.
Major blockchain projects, such as Bitcoin and Ethereum, enable secure global transfers of tokens between untrusted parties. The resulting global financial infrastructure however incurs latency and costs that are prohibitive for many economics applications that are local to a region or a community. Local economics relies on trust and reputation through repeated interactions within a community of participants that know each other, which has not previously been leveraged for the design of crypto-tokens. In this paper, we formulate the design of new local crypto-tokens as a research problem: we present concrete application examples, we identify double-spending detection as a weaker and sufficient alternative to double-spending prevention in local applications, and we formulate desired properties of new local crypto-tokens designs. Based on our analysis, we envision local crypto-tokens to complement existing blockchain projects by facilitating intra-community economics at much lower latency and costs, while evolutions of current blockchain projects will provide global inter-community exchanges of high-value transactions.
Abstract Blockchain technology is meant to perform a potential act to intensify the performance of several information systems. In this view, the platforms and the applications adapted for blockchain must be competitive to communicate and connect. The current blockchain platforms have many limitations, such as interoperability issues in divergent systems. The present platforms of blockchain applications work only within their networks. Blockchain interoperability allows data and values to be sent across various networks. The fundamental technology may be homogeneous, still, it relies on third-party intermediaries using the centralized mechanism to retrieve or exchange data from various interacting blockchain networks. The existing intermediaries incorporate security and trust by maintaining a centralized ledger to monitor ‘account balances’ and verify a transaction’s authenticity. The incompetence of individual and independent blockchains to interact with each other is an ingrained issue in decentralized systems. Cross-Chain Interoperability Protocol (CCIP) and similar mechanisms support networks like Fabric, Ripple and Ethereum to interrelate and interoperate each other. It is identified that the shortfall in such significant inter-blockchain communication creates a hassle for the mainstream adoption of blockchain. The article discusses different techniques and methods that provide cross-chain interoperability, its significant features and its applications in blockchain technology. It proposes the Inter-operable Blockchain Framework Design (IBFD), a cross blockchain architecture for interoperability of blockchain networks.
The Proof-of-Work algorithm that underlies Bitcoin and many other cryptocurrencies is well known for its energy-intensive requirements. The Proof-of-Stake algorithm that underlies Ethereum2 and various other cryptocurrencies is less impactful environmentally, but it has a second, looming issue: the problem of wealth inequality. We have developed an alternative to Proof-of-Work and Proof-of-Stake, called Proof-by-Location, that has the potential to address both of these issues. This paper describes Proof-by-Location and a financial platform called Xylem that is based on it. This platform seeks to distribute transaction fees to billions of cryptocurrency "Notaries" around the world (essentially, anyone with a smartphone), who work together to establish a distributed consensus about financial transactions. Using Xylem as a global financial infrastructure could lead to significantly better social and environmental outcomes than existing financial platforms.
Smart contracts are increasingly used with blockchain systems for high-value applications. It is highly desired to ensure the quality of smart contract source code before they are deployed. This paper proposes a new deep learning-based tool, MANDO-GURU, that aims to accurately detect vulnerabilities in smart contracts at both coarse-grained contract-level and fine-grained line-level. Using a combination of control-flow graphs and call graphs of Solidity code, we design new heterogeneous graph attention neural networks to encode more structural and potentially semantic relations among different types of nodes and edges of such graphs and use the encoded embeddings of the graphs and nodes to detect vulnerabilities. Our validation of real-world smart contract datasets shows that MANDO-GURU can significantly improve many other vulnerability detection techniques by up to 24% in terms of the F1-score at the contract level, depending on vulnerability types. It is the first learning-based tool for Ethereum smart contracts that identify vulnerabilities at the line level and significantly improves the traditional code analysis-based techniques by up to 63.4%. Our tool is publicly available at https://github.com/MANDO-Project/ge-sc-machine. A test version is currently deployed at http://mandoguru.com, and a demo video of our tool is available at http://mandoguru.com/demo-video.
With the development of blockchain technology and digital assets, the problem pages of digital assets at the legal level are becoming more and more prominent. This article will start with smart contracts and combine the case of Shenzhen Ethereum to analyze the legal issues based on blockchain technology and digital assets. The current status of conservation and its possible future development directions are analyzed. This article will specifically discuss the issue of contract law regulation of smart contracts from the perspective of legal system construction, as well as the compatibility between smart contracts and current contract law. Finally, the following conclusions are drawn: Firstly, consciously accepting the law needs to adapt to social changes and accepting the fact that the law needs to be adjusted. Secondly, at the operational level, the use of technology must comply with. Thirdly, at the research level, relevant legal research must be done, and legal scholars must have inter-professional knowledge and capabilities.
M R Jivtesh, Rohit Mathew Samuel, M R Gaushik, Siddhi Menon · 6 authors
Blockchain is the underlying technology for cryptocurrencies. Reliable machine-to-machine automatic transactions, such as auctions, bidding, and payments, utilise the immense potential of blockchain technology. Researchers are exploring blockchain-based applications for automobiles and transportation, such as electric vehicle (EV) charging and highway user fee payment. The use of blockchain eliminates the need for third parties in transactions. This paper presents a proof of concept for using EVs as energy storage in a smart grid system. Generators, consumers, and distributed energy resources (DER), such as solar and wind, make up the elements of a smart grid. We propose storing the surplus power generated by DER in the electric vehicle's battery. When the generation is less, or there is high demand, these EVs can supply the stored energy back to the grid. We use blockchain smart contracts and Ethereum cryptocurrency to monitor and monetise the process. We also make a cost comparison of conventional internal combustion engine (ICE) vehicles and EVs, analysing the financial benefits of employing the suggested method in EV charging instead of more conventional charging methods.
Cryptocurrencies have the potential to enable socioeconomic growth throughout the world by offering easier access to capital and financial services. However, many virtual asset service providers (VASPs) that offer cryptocurrency services lack identity management and can be accessed anonymously, which has led to their services being exploited by criminal activities such as money laundering and illegal foreign exchange. Such crimes have a negative impact on socioeconomic sustainability. Building identity systems on blockchains can help VASPs improve their identity management to combat cryptocurrency-based crimes so VASPs can better serve the social economy and achieve their sustainability goals. However, existing solutions have privacy problems because the identity provider can associate users’ identities with their wallet accounts. In addition, there is currently no solution that can support all public blockchains unconditionally, as current solutions can only support EVM-compliant blockchains or require additional work to support new blockchains. This article proposes a KYC (know your customer)-compliant identity scheme based on Ethereum using Merkle trees and smart contracts. The identity and wallet accounts are linked by the user rather than the KYC provider so, in general, no one but the user knows the association between the wallet accounts and the identity, which protects privacy. For suspicious accounts, supervisors can trace their identities and thus achieve supervision. In addition, the scheme supports identifying accounts on all public blockchains by using Merkle trees and smart contracts to bind accounts on multiple blockchains to one identity and no extra work is required. Moreover, the scheme supports users to prove that their attributes meet the requirements of VASPs by adopting the BBS+ signature and the Sigma protocol.
For data privacy, system reliability, and security, Blockchain technologies have become more popular in recent years. Despite its usefulness, the blockchain is vulnerable to cyber assaults; for example, in January 2019 a 51% attack on Ethereum Classic successfully exposed flaws in the platform's security. From a statistical point of view, attacks represent a highly unusual occurrence that deviates significantly from the norm. Blockchain attack detection may benefit from Deep Learning, a field of study whose aim is to discover insights, patterns, and anomalies within massive data repositories. In this work, we define an trusted two way intrusion detection system based on a Hierarchical weighed fuzzy algorithm and self-organized stacked network (SOSN) deep learning model, that is trained exploiting aggregate information extracted by monitoring blockchain activities. Here initially the smart contract handles the node authentication. The purpose of authenticating the node is to ensure that only specific nodes can submit and retrieve the information. We implement Hierarchical weighed fuzzy algorithm to evaluate the trust ability of the transaction nodes. Then the transaction verification step ensures that all malicious transactions or activities on the submitted transaction by self-organized stacked network deep learning model. The whole experimentation was carried out under matlab environment. Extensive experimental results confirm that our suggested detection method has better performance over important indicators such as Precision, Recall, F-Score, overhead.
Securing and managing medical data in hospitals is one of the significant challenges still existing in healthcare. There can be different kinds of patients staying in hospitals with various diseases. All these medical data records need to be secured appropriately for future use and verification. In the hospital, there will be essential documents such as criminal cases and postmortem reports, although it is unclear if they are being handled properly or not. Even the hospital staff can alter these data. This paper proposes a blockchain-based secured medical data management system to manage access to each medical record in a network of hospitals. The proposed system has three main access management categories: one for securing general (fever or cold) medical report, category 2 for postmortem or crime reports security and category 3 for securing cancer /brain death /genetic disorder reports. Sensitive clinical data should not be visible to patients with cancer or genetic disorders as these patients have a higher rate of suicide attempts. Hence, the data is accessible only to doctors, family members, and researchers. The data related to the crime or postmortem reports have only limited access for those with legal permission to access and verify these types of reports. So through blockchain distributed ledger technology and smart contracts, we could store the data in a tamper-proof manner and manage the user access to these data.
Objectives: To propose a reliable Block-chain based Biometric Authentication Solution (BBAS) for the Aadhar biometric authentication system. Methods: We have used Sokoto Coventry Fingerprint Dataset (SOCOFing) data set for biometrics. The presented model was implemented using the Ethereum network Geth (v.1.9.25) and Solidity (v.0.6.0). Python 3.8 and Web3py were used at the client side. Findings: From the proposed solution, it is inferred that the BBAS avoids the single point of failure problem as the biometrics are distributed throughout the block-chain. Novelty: This research proposes a new hybrid scheme that uses a block-chain that stores the hash value of the biometric files and a trusted third party (Aadhar) to store the biometric files, thereby avoiding storing the same bio-metric files throughout the block-chain. Keywords: Biometric; Blockchain; Aadhar; Security; Authentication
The Covid-19 pandemic has caused one of the most severe systematic shocks to global financial markets as investors discovered the sudden slumps in major global stocks indexes in March 2020. However, at the same time, the pandemic also accelerated the rise of decentralized finance and cryptocurrencies as the public began to shift their investments from traditional stock markets to the newly emerged fintech markets as the decentralized financial market’s risks hedging ability are believed to be better during global emergencies. Although it’s tempting to attribute these observed phenomena solely to the Covid-19 pandemic, other political shocks such as the US 2020 election and China’s crypto crackdown in 2021 also exacerbated the uncertainties and thus should be considered as potential reasons for the observations. Through theoretical analysis on financial and political economics as well as empirical modeling utilizing Stata17, this report has constructed a time series ARMA-GARCH model quantifying the relationship between Ethereum’s investment return and potential factors including the daily new confirmed cases of Covid-19 and other policy changes, and discovered for the first time that the rise of Ethereum’s investment return is majorly caused by the two aforementioned policy changes, and the rapid infection of Covid-19 only caused a short-term rise in Ethereum’s investment return whereas the daily new infection numbers of the later stage only caused fluctuations to the Ethereum trading market. Based on the findings, the article made recommendations for both policy makers and investors on crypto investments during the fintech era.
Yukun Niu, Lingbo Wei, Chi Zhang, Jianqing Liu · 5 authors
Anonymous yet accountable authentication can protect users' privacy and security and prevent users from misbehaving when they access public Wi-Fi hotspots. However, most existing privacy-enhanced authentication schemes either do not meet the accountability requirements in public Wi-Fi hotspot access or they are inherently dependent on trusted third parties, and therefore are undeployable in practical settings. In this paper, we design and implement an access authentication scheme to simultaneously and efficiently provide anonymity and accountability without relying on any trusted third party by utilizing a permissionless blockchain (e.g., Bitcoin or Ethereum) and Intel SGX. Inspired by the recent progress on Bitcoin techniques such as Colored Coins, we utilize the unmodified Bitcoin blockchain as the powerful platform to manage access credentials without introducing any trusted third party. We leverage SGX-based mixer to allow users to anonymously exchange their access credentials and design the verification path of access credentials to support blacklisting misbehaving access credentials without compromising users' anonymity. By integrating with the anti-double-spending property of the Bitcoin blockchain, our scheme can simultaneously provide users' accountability and anonymity without involving any trusted third party. Finally, we demonstrate that our proposed scheme is compatible with the current Bitcoin system or other permissionless blockchains, and is highly effective and practical for public Wi-Fi hotspot access control systems.
Constant advancements in technology have a significant impact on our everyday lives and the ecosystem in which we live. The growing popularity of cryptocurrencies (e.g., Bitcoin and Ethereum), along with Non-Fungible Tokens (NFTs), which are founded on blockchain technology, has opened the way for these blockchain projects to be integrated into a wide range of other kinds of applications (apps). Today, cryptocurrencies are used as a popular method of payment online; however, their popularity on the dark Web is also increasing. For example, they can be used to buy and perform various illegal activities among criminals due to their anonymity. Web3 cryptocurrency wallets, used to store cryptocurrencies, have not been studied as thoroughly as many other apps from a digital forensic perspective on mobile devices, given the increasing number of these services and apps today for many platforms, including the leading mobile operating systems (i.e., iOS and Android). Therefore, the purpose of this research is to guide investigators to unlock the full potential of popular cryptocurrency Web3 wallets, Trust Wallet and Metamask, to understand what can be recovered, and to look at areas where there are knowledge gaps. We digitally analyzed and forensically examined two mobile wallets that do not require any personal identifiers to register and are widely used for Web3 cryptocurrencies on Android and iOS devices. We review the digital evidence we have collected and discuss the implications of the forensic tools we have used. Finally, we propose a proof of concept extension to the iOS Logs, Events, And Plists Parser (iLEAPP) tool to automatically recover artifacts.
This article proposes a graph neural network strategy (GNN), in which the long short-term memory (LSTM) and graph convolution network (GCN) are applied to capture both temporal and spatial features to forecast the price of Bitcoin, Litecoin, Ethereum, and Dash Coin with the ‘stable-coin’ Tether (USDT) and financial stress index (FSI). The main results show that the GNN strategy has better performance than univariate LSTM and multivariate LSTM in all of the seven steps forward forecasting. A sensitivity check shows that USDT and FSI/sub-FSI are important factors in the construction of the graphs and they verify the validity of the results.