Cryptoassets such as Bitcoin and Ethereum are widely traded around the world. Cryptocurrencies are also transferred between investors. Cryptocurrency has become a new and attractive means of remittance. Thus, blockchain-based smart contracts also attract attention when central banks design digital currencies. However, it has been discovered that a significant amount of cryptoassets on blockchain are lost or stranded for a variety of reasons, including the loss of the private key or the owner's death. To address this issue, we propose a method for recoverable transactions that would replace the traditional transaction by allowing cryptoassets to be sent to a backup account address after a deadline has passed. We provide the computational workload required for our method by analyzing the prototype. The method proposed in this paper can be considered as a good model for digital currency design, including central bank digital currency (CBDC).
Remote voting has become more critical in recent years, especially since the COVID-19 outbreak. Blockchain technology and its benefits such as decentralization, security, and transparency have given rise to proposals for blockchain-based voting systems. However, the traceability of blockchain transactions violates voter anonymity in existing proposals. Besides, transaction costs also need to be considered. Solutions that may cause repeated elections should be avoided for a low-cost scalable voting system. In this work, we propose ElectAnon, a blockchain-based, self-tallying, and ranked-choice voting protocol focusing on anonymity, robustness, and scalability. ElectAnon achieves anonymity by enabling voters to register with identity commitments and cast their votes via zero-knowledge proofs. Robustness is realized by removing the direct control of the authorities in the voting process by using timed-state machines. Each voter encodes the ballot into a single integer and blinds the vote off-chain while making the verification on-chain. This makes the protocol infinitely scalable in the number of voters. ElectAnon is also a solution for governance in Decentralized Autonomous Organizations (DAO): It includes a candidate proposal module and an algorithm-agnostic mechanism to plug-in different tallying methods easily. The Merkle forest extension is proposed for conducting even more trustless elections. ElectAnon is implemented with smart contracts based on Ethereum Virtual Machine (EVM) and a zero-knowledge gadget, Semaphore. The implementation also includes two different sophisticated tallying methods, Borda Count and Tideman. Experimental results show that a 40-voter and 10-candidate election can be implemented with the gas consumption reduced up to 89% compared to previous works. While other studies could not exceed a 25,000-voter setup, ElectAnon has been observed to run safely for 1,000,000 voters. The implementation can be found at https://github.com/ceyonur/electanon .
Abstract. The article examines integration of cryptocurrencies as electronic payment systems in e-commerce enterprises. Practical usage of Ethereum and Bitcoin cryptocurrencies as electronic payment systems, as well as factors that may affect their functionality are studied. Coinbase Commerce and Bitpay, as market leaders in cryptocurrency payment providers, were analyzed to compare integration issues and commission analysis with traditional payment systems LiqPay, PayPal. It is determined that the factors influencing the integration of cryptocurrencies in the enterprise include the field in which this enterprise is operating, instability of the national currency, development of information technology. It has been proven that e-commerce companies specializing on selling consumer goods could use hybrid cryptocurrency payments in Bitcoin in 50% of transactions and Ethereum in 65% of transactions in the studied timeframe to reduce the cost of the transaction compared to the LiqPay system. Key words: electronic payment systems, cryptocurrency, e-commerce, transactions. JEL Classification D2, C50, G23, G41 Formulas: 0; fig.: 9; tabl.: 2; bibl.: 16.
This paper introduces a blockchain-based P2P energy trading platform, where prosumers can trade energy autonomously with no central authority interference. Multiple prosumers can collaborate in producing energy to form a single provider. Clients’ power consumption is monitored using a smart meter that interfaces with an IoT node connected to a blockchain private network. The smart contracts, invoked on the blockchain, enable the autonomous trading interactions between parties and govern accounts behavior within the Ethereum state. The decentralized P2P trading platform utilizes autonomous pay-per-use billing and energy routing, monitored by a smart contract. A Gated Recurrent Unit (GRU) deep learning-based model, predicts future consumption based on past data aggregated to the blockchain. Predictions are then used to set Time of Use (ToU) ranges using the K-mean clustering. The data used to train the GRU model are shared between all parties within the network, making the predictions transparent and verifiable. Implementing the K-mean clustering in a smart contract on the blockchain allows the set of ToU to be independent and incontestable. To secure the validity of the data uploaded to the blockchain, a consensus algorithm is suggested to detect fraudulent nodes along with a Proof of Location (PoL), ensuring that the data are uploaded from the expected nodes. The paper explains the proposed platform architecture, functioning as well as implementation in vivid details. Results are presented in terms of smart contract gas consumption and transaction latency under different loads.
Non-fungible tokens have been a unique transformation in the implementation of the concept of distributed ledger technology in digital assets. NFTs are said to be non-interchangeable, which distinguishes its value from fungible tokens like Bitcoin (Btc). Scammers are utilizing the open source nature of the blockchain to victimize users and steal their NFTs, leaving NFT collectors with infringed artwork. In a bid to eliminate security vulnerability and attack in NFT platform, we implemented a smart contract verification model. Our verification model is a 2-pronged approach that utilized F*, functional programming language. We presented two tools that translated solidity source code and EVM bytecode to solidity* and EVM* respectively. The EVM decompiler analyzes contracts in which the solidity source codes are unavailable as well as low level properties of contracts. The EVM* and Solidity* tools helped to check the equivalence between a solidity program and the bytecode output from the solidity compiler in order to avoid bugs and preserve verified properties at the source level. In this paper, Etherscan token tracker was used to verify and authenticate NFT token before buying or minting such NFT. Keywords: Non-Fungible Tokens (NFTs), The NFT- marketplace (NFTM), Ethereum
Zhou Liao, Shuwei Song, Hang Zhu, Xiapu Luo · 10 authors
Being the most popular programming language for developing Ethereum smart contracts, Solidity allows using inline assembly to gain fine-grained control. Although many empirical studies on smart contracts have been conducted, to the best of our knowledge, none has examined inline assembly in smart contracts. To fill the gap, in this paper, we conduct the first large-scale empirical study of inline assembly on more than 7.6 million open-source Ethereum smart contracts from three aspects, namely, source code, bytecode, and transactions after designing new approaches to tackle several technical challenges. Through a thorough quantitative and qualitative analysis of the collected data, we obtain many new observations and insights. Moreover, by conducting a questionnaire survey on using inline assembly in smart contracts, we draw new insights from the valuable feedback. This work sheds light on the development of smart contracts as well as the evolution of Solidity and its compilers.
The journey towards Industry 4.0 have driven the workforce with the need for continuous competency development to stay on top of their profession and remain attractive to their employers. In this context, E-Portfolio has been conceived as a promising tool for both professionals and employers, in assessing and providing guidance for further workplace learning. Nevertheless, the challenges in implementing E-Portfolio are daunting, particularly with regard to lack of interoperability while collecting and sharing the competency evidences across multiple organizations and institutions. The increasing move towards professional (learner)-centered interoperability poses additional challenges that needs to be addressed to realize the full potential of E-Portfolio in the context of Industry 4.0. This work puts emphasize on realization of professional-centered interoperability and proposes a framework leveraging the advantage of blockchain, decentralized storage system interplanetary file system, smart contract and session management for E-Portfolio creation and sharing evidences across multiple organizations without comprising the confidentiality, integrity and availability of the shared evidences. The proof of concept simulation on Ethereum official test network Rinkeby demonstrates the feasibility of proposed framework in practice. In addition, the evaluation of the proposed framework demonstrates its effectiveness from the aspects of cost and security as a potential solution for implementing E-Portfolio and helping the professional to remain competitive in global labor market.
Muhammad Asif, Zeeshan Aziz, Maaz Bin Ahmad, Adnan Khalid · 6 authors
Security has always been the main concern for the internet of things (IoT)-based systems. Blockchain, with its decentralized and distributed design, prevents the risks of the existing centralized methodologies. Conventional security and privacy architectures are inapplicable in the spectrum of IoT due to its resource constraints. To overcome this problem, this paper presents a Blockchain-based security mechanism that enables secure authorized access to smart city resources. The presented mechanism comprises the ACE (Authentication and Authorization for Constrained Environments) framework-based authorization Blockchain and the OSCAR (Object Security Architecture for the Internet of Things) object security model. The Blockchain lays out a flexible and trustless authorization mechanism, while OSCAR makes use of a public ledger to structure multicast groups for authorized clients. Moreover, a meteor-based application is developed to provide a user-friendly interface for heterogeneous technologies belonging to the smart city. The users would be able to interact with and control their smart city resources such as traffic lights, smart electric meters, surveillance cameras, etc., through this application. To evaluate the performance and feasibility of the proposed mechanism, the authorization Blockchain is implemented on top of the Ethereum network. The authentication mechanism is developed in the node.js server and a smart city is simulated with the help of Raspberry Pi B+. Furthermore, mocha and chai frameworks are used to assess the performance of the system. Experimental results reveal that the authentication response time is less than 100 ms even if the average hand-shaking time increases with the number of clients.
Abstract: The electronic voting has emerged over time as a replacement to the paper-based voting to reduce the redundancies and inconsistencies. The historical perspective presented in the last two decades suggests that it has not been so successful due to the security and privacy flaws observed over time. This project is about decentralizing authority to record, count and verify votes and the voters, rather than having a central authority. We are using blockchain technology which is a distributed database. With its immutability property and decentralized architecture, it can run and support a voting scheme that is open, fair and independently verifiable. The project will be developed in Ethereum framework which primarily uses Solidity as a language. Ethereum’s backbone is its decentralized virtual machine called Ethereum Virtual Machine. The application will be deployed on the thirdweb(web3.0). Overall this project is a potential roadmap for blockchain technologies developing in the nation to support complex applications. Keywords: Blockchain, Cryptography, Cryptocurrency, Ethereum Framework, Solidity, Decentralization, Hashing, Dapp, Web3, Digitalizing.
Cryptocurrency miners have great latitude in deciding which transactions they accept, including their own, and the order in which they accept them. Ethereum miners in particular use this flexibility to collect MEV-Miner Extractable Value-by structuring transactions to extract additional revenue. Ethereum also contains numerous bots that attempt to obtain MEV based on public-but-not-yet-confirmed transactions. Private relays shelter operations from these selfsame bots by directly submitting transactions to mining pools. In this work, we develop an algorithm to detect MEV exploitation present in previously mined blocks. We use our implementation of the detector to analyze MEV usage and profit redistribution, finding that miners make the lion's share of the profits, rather than independent users of the private relays. More specifically, (i) 73% of private transactions hide trading activity or re-distribute miner rewards, and 87.6% of MEV collection is accomplished with privately submitted transactions, (ii) our algorithm finds more than $6M worth of MEV profit in a period of 12 days, two thirds of which go directly to miners, and (iii) MEV represents 9.2% of miners' profit from transaction fees. Furthermore, in those 12 days, we also identify four blocks that contain enough MEV profits to make time-bandit forking attacks economically viable for large miners, undermining the security and stability of Ethereum as a whole.
In recent years, blockchain technology has been developing rapidly. More and more traditional industries are using blockchain as a platform for information storage and financial transactions, mainly because of its new characteristics of non-tamperability and decentralization compared with the traditional systems. As a representative of blockchain 2.0, Ethereum has gained popularity upon its introduction. However, because of the anonymity of blockchain, Ethereum has also attracted the attention of some unscrupulous people. Currently, millions of contracts are deployed on Ethereum, many of which are fraudulent contracts deployed by unscrupulous people for profit, and these contracts are causing huge losses to investors worldwide. Ponzi contracts are typical of these contracts, which mainly reward the funds invested by later investors to early investors, and later investors will have no gain. However, although there are some studies for identifying Ponzi contracts on Ethereum, there is some room for progress in the research. Therefore, we propose a method to detect Ponzi scheme contracts on Ethereum-CTRF. This method forms a dataset by extracting the word features and sequence features of the smart contract’s code and the features of transactions. The dataset is divided into a training set and a test set. Oversampling is performed on the training set to deal with the problem of positive and negative sample imbalance. Finally, the model is trained on the training set and tested on the test set. The experimental results show that the model has significantly improved recall compared with existing Ponzi contract detection methods.
The data outsourcing services provided by cloud storage have greatly reduced the headache of data management for users, but the issue of remote data integrity poses further security concerns and computing burdens. The introduction of a third-party auditor (TPA) frees data owners from the auditing burden and alleviates disputes over the audit results between data owners and cloud storage providers. However, malicious cloud servers may collude with TPAs to deceive users for financial profits. Hiring multiple auditors in a single audit assignment appears to be a method to address the above problem, but the ensuing voting issues need to be further explored. In this paper, we proposed a smart contract-based outsourced data integrity auditing scheme for multiauditor scenarios. Unlike some existing schemes using reputation like factors as their voting weights, auditors in our scheme vote equally and audit as they go, without any maintenance. This mechanism not only frees auditors from trivia not related to the auditing but also avoids the drawbacks of centralization associated with over-high voting weights. The challenge used to check the integrity of the outsourced data is jointly generated by each involved auditor. Any collusion would be detected as long as there exists more than one honest auditor in the audit. We implement and deploy the scheme as Ethereum smart contracts. With the help of blockchain, the entire auditing process is public and transparent. Both the generated data and the obtained results are persisted with immutability, which ensures the traceability of all historical audits. The comprehensive theoretical and experimental analyses demonstrate that our scheme meets the claimed targets with high efficiency and low gas costs.
This thesis presents techniques to investigate transactions in uncharted cryptocurrencies and services. Cryptocurrencies are used to securely send payments online. Payments via the first cryptocurrency, Bitcoin, use pseudonymous addresses that have limited privacy and anonymity guarantees. Research has shown that this pseudonymity can be broken, allowing users to be tracked using clustering and tagging heuristics. Such tracking allows crimes to be investigated. If a user has coins stolen, investigators can track addresses to identify the destination of the coins. This, combined with an explosion in the popularity of blockchain, has led to a vast increase in new coins and services. These offer new features ranging from coins focused on increased anonymity to scams shrouded as smart contracts. In this study, we investigated the extent to which transaction privacy has improved and whether users can still be tracked in these new ecosystems. We began by analysing the privacy-focused coin Zcash, a Bitcoin-forked cryptocurrency, that is considered to have strong anonymity properties due to its background in cryptographic research. We revealed that the user anonymity set can be considerably reduced using heuristics based on usage patterns. Next, we analysed cross-chain transactions collected from the exchange ShapeShift, revealing that users can be tracked as they move across different ledgers. Finally, we present a measurement study on the smart-contract pyramid scheme Forsage, a scam that cycled $267 million USD (of Ethereum) within its first year, showing that at least 88% of the participants in the scheme suffered a loss. The significance of this study is the revelation that users can be tracked in newer cryptocurrencies and services by using our new heuristics, which informs those conducting investigations and developing these technologies.
C. Viji, Aniket Kuntal, Aryan Bhardwaz, Darshan Bandari
Abstract: A supply chain is defined as all the various points involved in the production and distribution of goods, from the stage of supply to the final customer. While agriculture is the most important industry in rural areas and provides livelihoods for 70% of the world's poor, it is also the industry that creates the greatest disconnect between suppliers and retailers. In addition, due to lack of transparency, buyers and customers cannot be sure of the true value of a product or service. The proposed system is an agricultural supply chain model using the Ethereum platform. Smart contracts are implemented in different stages of the supply chain. These contracts guarantee to meet all predefined conditions before conducting transactions ensuring security, reliability and transparency. This can give consumers greater confidence in the products they buy, and it is also an opportunity to reward producers who use good agricultural practices to develop their products. This will ultimately lead to sustainable farming practices and responsible consumption. Keywords: Supply Chain; Ethereum; Smart Contracts; Transparency; Agriculture;
In blockchain, bribery is an inevitable problem since users with various goals can bribe miners by transferring cryptoassets. To alleviate the negative effects of such collusion, Ethereum blockchain implemented new transaction fee mechanism in the London Fork, which was deployed on August 5th, 2021. In this paper, we first filter potential bribery by scanning Ethereum transactions, and the potential bribers and bribees are centralized in a small group. Then we construct bribing proxies to measure the active level of bribery and then investigate the effects of bribery. Consequently, bribery can influence both Ethereum and other mainstream blockchains, in aspects of underlying cryptocurrency, transaction statistics, and network adoption. Moreover, the London Fork shows complicated effects on relationship between bribery and blockchain factors. Besides, bribery in Ethereum relates to stock markets, e.g., S&P 500 and Nasdaq, implying implicit interlinks between blockchain and traditional finance.
Context: Smart contracts are computer programs that are automatically executed on the blockchain. Vulnerabilities in their implementation have led to severe loss of cryptocurrency. Smart contracts become immutable when deployed to the Ethereum blockchain. Therefore, it is essential to understand the nature of vulnerabilities in Ethereum smart contracts to prevent them in the future. Existing classifications exist, but are limited in several ways. Objective: We aim to characterize vulnerabilities in Ethereum smart contracts written in Solidity, and unify existing classifications schemes. Method: We extracted 2143 vulnerabilities from public coding platforms and popular vulnerability databases and categorized them using a card sorting approach. We targeted the Ethereum blockchain in this paper, as it is the first and most popular blockchain to support the deployment of smart contracts, and Solidity as the most widely used language to implement smart contracts. We devised a classification scheme of smart contract vulnerabilities according to their error source and impact. Afterwards, we mapped existing classification schemes to our classification. Results: The resulting classification consists of 11 categories describing the error source of a vulnerability and 13 categories describing potential impacts. Our findings show that the language specific coding and the structural data flow categories are the dominant categories, but that the frequency of occurrence differs substantially between the data sources. Conclusions: Our findings enable researchers to better understand smart contract vulnerabilities by defining various dimensions of the problem and supporting our classification with mappings with literature-based classifications and frequency distributions of the defined categories.
Abstract: Non-Fungible Tokens (NFTs) have recently attracted a lot of investor interest, with some NFTs achieving selling prices that were previously unthinkable for a non-fungible virtual asset. As with any new and untested investment space, investing in NFTs comes with a number of risks and associated challenges. This paper shows insights on what are NFTs, how do NFTs work and about the sustainability of NFTs. The conclusion of this paper discusses if one should invest in NFTs or not, in addition to its sustainability with respect to environment. Keywords: Non-fungible token (NFT), Blockchain, Scarcity, Marketing, AIDA, Beeple, bitcoin, blockchain, Christie’s, collectibles, copyright, crypto asset, cryptocurrencies, digital art, Ethereum, music business and publishing, online payment systems, property, Second Life, Sotheby’s, synthetic worlds, virtual property, virtual real estate.
Advancements in cryptography and computer science have given birth to blockchain technology. One of the most exciting evolutions of blockchain is the advancements in smart contract technology. Smart contracts can be used for a broad range of use cases, not just financial transactions. Smart contract technology on the public blockchain, represented by Ethereum, due to its public and opaque nature, is not a good choice for many scenarios that do not require full disclosure, such as many IoT applications. On the other hand, the existing blockchain smart contract system still has a strong connection with virtual currency, which also limits its application in non-financial scenarios. In order to solve the above problems and explore more of the potential of smart contracts for the IoT application domain, this paper mainly explores the construction of a smart contract system based on consortium blockchains associated with no virtual currency. Based on the smart contract system designed in this project, blockchain can be more easily applied in payment, product traceability, authority authentication, and other fields. Through a certain centralized way, the system is easier to manage, can reduce the management expenditure, and the power and other resource consumption is less, which is conducive to environmental protection. Results show that our smart contract system has the potential for IoT usage in the future.
Sudan Jha, Nishant Jha, Deepak Prashar, Sultan Ahmad · 6 authors
Autonomous vehicles offer various advantages to both vehicle owners and automobile companies. However, despite the advantages, there are various risks associated with these vehicles. These vehicles interact with each other by forming a vehicular network, also known as VANET, in a centralized manner. This centralized network is vulnerable to cyber-attacks which can cause data loss, resulting in road accidents. Thus, to prevent the vehicular network from being attacked and to prevent the privacy of the data, key management is used. However, key management alone over a centralized network is not effective in ensuring data integrity in a vehicular network. To resolve this issue, various studies have introduced a blockchain-based approach and enabled key management over a decentralized network. This technique is also found effective in ensuring the privacy of all the stakeholders involved in a vehicular network. Furthermore, a blockchain-based key management system can also help in storing a large amount of data over a distributed network, which can encourage a faster exchange of information between vehicles in a network. However, there are certain limitations of blockchain technology that may affect the efficient working of autonomous vehicles. Most of the existing blockchain-based systems are implemented over Ethereum or Bitcoin. The transaction-processing capability of these blockchains is in the range of 5 to 20 transactions per second, whereas hashgraphs are capable of processing thousands of transactions per second as the data are processed exponentially. Furthermore, a hashgraph prevents the user from altering the order of the transactions being processed, and they do not need high computational powers to operate, which may help in reducing the overall cost of the system. Due to the advantages offered by a hashgraph, an advanced key management framework based on a hashgraph for secure communication between the vehicles is suggested in this paper. The framework is developed using the concept of Leaving of Vehicles based on a Logical Key Hierarchy (LKH) and Batch Rekeying. The system is tested and compared with other closely related systems on the basis of the transaction compilation time and change in traffic rates.
In this digital world, information technology is growing day by day. Due to this, a large amount of data is generated every day from various domains, and one of the domains is medical health records. A large amount of medical data is generated every day. Such as electronic medical records, medical images, diagnostic reports, X-rays, MRI scans, etc. These medical records can help in treating a patient when needed and can be shared with different medical institutions. There are systems built that are used to store all the medical records of patients. But they are centralized and may not be secured, and a user may not know how and where these records are shared. However, if these medical records are leaked or shared with a third party, the owner of that medical record may not know how and where these medical records are used, thus sabotaging the patient's privacy. Therefore, controlling the access rights to medical data is an urgent issue. On the other hand, patients do not have any proper application that will help them store and view their history of medical records and have control over them. This project aims to build a decentralized application to store the medical records of patients on the Ethereum Blockchain and Inter Planetary File System (IPFS). This app will help users to keep electronic medical records in one place, and the user will have full control over their data. This app will help doctors diagnose the patients by seeing their medical history. This will also help researchers to research various diseases. This app will store the data of patients from doctors and pathology labs. Users will be able to control who can add the medical details and see them. They can give access and revoke it. This application will store the file in DICOM, JPEG, JPG, PNG, and PDF format. In this application, there is no centralized authority. This application is secured because of peer-to-peer and distributed networks, it is tamper-proof. User has control over their data. They can choose whom to share their data with, and blockchain is reliable.
Filipe Pinto, Catarina Ferreira da Silva, Sérgio Moro
To understand how distributed ledger technology (DLT) enables people-centered IoT solutions we conducted a systematic literature review of tested implementations since 2017. We created a people-centered classification to analyze 39 implementations. We found that people-centered DLT-IoT architectures are in their infancy and detected no evidence of emerging patterns. We observed that Ethereum is the most used DLT. Fit-for-purpose technologies like IOTA and concepts like Self-Sovereign Identity (SSI) were underrepresented. We noted an increased interest in privacy-preserving and edge-computing mechanisms, and identified three areas for future research. We hope this survey will assist others learning more about people-centered IoT solutions.
Digital document communication between an enterprise and a customer is becoming a primary form of communication rather than the traditional physical document communication. A PDF document, the most popular document format, provides an identical document layout regardless of OS or device and has a content integrity verification feature with a digital signature. However, it has a bad user experience, such as low readability on a mobile device. On the other hand, an HTML document has a weakness in verifying the content integrity even though it is the primary document format and provides a good user experience on mobile devices. There are certified document services using blockchain technology, but it is still vulnerable to verifying content integrity. Furthermore, research on the document HTML has proposed the trusted document generation technique by HTML conformance and digital signature; however, this research does not provide content delivery verification, and there is a file size overhead. In this paper, we have developed the chained document HTML by defining HTML conformance, digital signature, and blockchain technology. First, the chained document HTML has to embed all resources and does not allow loading content on-demand. Second, the file is signed by a digital signature, and the signature value is added in the file header. Lastly, the metadata to verify the content integrity is inserted in a blockchain node. We have created the chained document HTML generation and verification experiment environment by Ethereum and Python. We have confirmed that the chained document HTML provides content and delivery integrity verification in the research. We expect the chained document HTML will be widely used in document communication between an enterprise and a customer, especially if the document has sensitive personal information that might have a legal dispute.
Heidelinde Rameder, Monika di Angelo, Gernot Salzer
Programs on public blockchains often handle valuable assets, making them attractive targets for attack. At the same time, it is challenging to design correct blockchain applications. Checking code for potential vulnerabilities is a viable option to increase trust. Therefore, numerous methods and tools have been proposed with the intention to support developers and analysts in detecting code vulnerabilities. Moreover, publications keep emerging with different focus, scope, and quality, making it difficult to keep up with the field and to identify relevant trends. Thus, regular reviews are essential to keep pace with the varied developments in a structured manner. Regarding blockchain programs, Ethereum is the platform most widely used and best documented. Moreover, applications based on Ethereum are entrusted with billions of USD. Like on similar blockchains, they are subject to numerous attacks and losses due to vulnerabilities that exist at all levels of the ecosystem. Countermeasures are in great demand. In this work, we perform a systematic literature review (SLR) to assess the state of the art regarding automated vulnerability analysis of smart contracts on Ethereum with a focus on classifications of vulnerabilities, detection methods, security analysis tools, and benchmarks for the assessment of tools. Our initial search of the major on-line libraries yields more than 1,300 publications. For the review, we apply a clear strategy and protocol to assure consequent, comprehensive, and reproducible documentation and results. After collecting the initial results, cleaning up references, removing duplicates and applying the inclusion and exclusion criteria, we retain 303 publications that include 214 primary studies, 70 surveys and 19 SLRs. For quality appraisal, we assess their intrinsic quality (derived from the reputation of the publication venue) as well as their contextual quality (determined by rating predefined criteria). For about 200 publications with at least a medium score, we extract the vulnerabilities, methods, and tools addressed, among other data. In a second step, we synthesize and structure the data into a classification of both the smart contract weaknesses and the analysis methods. Furthermore, we give an overview of tools and benchmarks used to evaluate tools. Finally, we provide a detailed discussion.
The sharing economy is centralizing services, leading to misuses of the Internet. We can list growing damages of data hacks, global outages and even the use of data to manipulate their owners. Unfortunately, there is no decentralized web where users can interact peer-to-peer in a secure way. Blockchains incentivize participants to individually validate every transaction and impose their block to the network. As a result, the validation of smart contract requests is computationally intensive while the agreement on a unique state does not make full use of the network. In this paper, we propose Collachain, a new byzantine fault tolerant blockchain compatible with the largest ecosystem of DApps that leverages collaboration. First, the pariticipants executing smart contracts collaborate to validate the transactions, hence halving the number of validations required by modern blockchains (e.g., Ethereum, Libra). Second, the participants in the consensus collaborate to combine their block proposal into a superblock, hence improving throughput as the system grows to hundreds of nodes. In addition, Collachain offers the possibility to its users to interact securely with each other without downloading the blockchain, hence allowing interactions via mobile devices. Collachain is effective at outperforming the Concord and Quorum blockchains and its throughput peaks at 4500 TPS under a Twitter DApp (Decentralized Application) workload. Finally, we demonstrate Collachain's scalability by deploying it on 200 nodes located in 10 countries over 5 continents.