Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

7,397 papersLast indexed Aug 16, 2026
Search papers

Paper index

7,397 results · page 259 of 309

Clear filters
Mar 23, 2020·arXiv
0 cites
Dragoon: Private Decentralized HITs Made Practical

Yuan Lu, Qiang Tang, Guiling Wang

With the rapid popularity of blockchain, decentralized human intelligence tasks (HITs) are proposed to crowdsource human knowledge without relying on vulnerable third-party platforms. However, the inherent limits of blockchain cause decentralized HITs to face a few "new" challenges. For example, the confidentiality of solicited data turns out to be the sine qua non, though it was an arguably dispensable property in the centralized setting. To ensure the "new" requirement of data privacy, existing decentralized HITs use generic zero-knowledge proof frameworks (e.g. SNARK), but scarcely perform well in practice, due to the inherently expensive cost of generality. We present a practical decentralized protocol for HITs, which also achieves the fairness between requesters and workers. At the core of our contributions, we avoid the powerful yet highly-costly generic zk-proof tools and propose a special-purpose scheme to prove the quality of encrypted data. By various non-trivial statement reformations, proving the quality of encrypted data is reduced to efficient verifiable decryption, thus making decentralized HITs practical. Along the way, we rigorously define the ideal functionality of decentralized HITs and then prove the security due to the ideal-real paradigm. We further instantiate our protocol to implement a system called Dragoon, an instance of which is deployed atop Ethereum to facilitate an image annotation task used by ImageNet. Our evaluations demonstrate its practicality: the on-chain handling cost of Dragoon is even less than the handling fee of Amazon's Mechanical Turk for the same ImageNet HIT.

Open access
2 source records
cs.CR
cs.HC
Blockchain Technology Applications and Security
Original source
Mar 23, 2020·IEEE Wireless Communications Letters
16 cites
Blockchain Secured Auction-Based User Offloading in Heterogeneous Wireless Networks

Tianrui Chen, Amjad Saeed Khan, Gan Zheng, Sangarapillai Lambotharan

This letter presents a secure user offloading mechanism in heterogeneous wireless networks (HWNs), where a macrocell base station (MBS) offloads its users to small cell access points (SCAs) using Vickrey auction. Additionally, a user-in-the-loop (UIL) strategy is exploited to encourage the unserved users to move to desired locations for connections. As the participants in the conventional auction-based trading may collude or take selfish actions, we employ Ethereum framework for trustless, secure and distributed auctioning. Simulation results are presented to demonstrate the advantages of the proposed user offloading methodology. The security aspects of the blockchain framework are also discussed.

Open access
Blockchain Technology Applications and Security
Privacy-Preserving Technologies in Data
IoT and Edge/Fog Computing
Original source
Mar 23, 2020·arXiv (Cornell University)
110 cites
A Transactional Perspective on Execute-order-validate Blockchains

Pingcheng Ruan, Dumitrel Loghin, Quang-Trung Ta, Meihui Zhang · 6 authors

Smart contracts have enabled blockchain systems to evolve from simple cryptocurrency platforms, such as Bitcoin, to general transactional systems, such as Ethereum. Catering for emerging business requirements, a new architecture called execute-order-validate has been proposed in Hyperledger Fabric to support parallel transactions and improve the blockchain's throughput. However, this new architecture might render many invalid transactions when serializing them. This problem is further exaggerated as the block formation rate is inherently limited due to other factors beside data processing, such as cryptography and consensus. In this work, we propose a novel method to enhance the execute-order-validate architecture, by reducing invalid transactions to improve the throughput of blockchains. Our method is inspired by state-of-the-art optimistic concurrency control techniques in modern database systems. In contrast to existing blockchains that adopt database's preventive approaches which might abort serializable transactions, our method is theoretically more fine-grained. Specifically, unserializable transactions are aborted before ordering and the remaining transactions are guaranteed to be serializable. For evaluation, we implement our method in two blockchains respectively, FabricSharp on top of Hyperledger Fabric, and FastFabricSharp on top of FastFabric. We compare the performance of FabricSharp with vanilla Fabric and three related systems, two of which are respectively implemented with one standard and one state-of-the-art concurrency control techniques from databases. The results demonstrate that FabricSharp achieves 25% higher throughput compared to the other systems in nearly all experimental scenarios. Moreover, the FastFabricSharp's improvement over FastFabric is up to 66%.

Open access
3 source records
Blockchain Technology Applications and Security
Distributed systems and fault tolerance
Advanced Data Storage Technologies
Original source
Mar 21, 2020·International Journal of Innovative Technology and Exploring Engineering
10 cites
Smart Contract for Decentralized Water Management System using Blockchain Technology

Soniya Tiwari, Jyoti Gautam, Vimal Gupta, Nitima Malsa

There is A finite amount of portable water which is decreasing day by day. Rapid degradation of useful water on earth results in an unkind impact on livelihood. In future, people may have to face (DAY 0) problem therefore, conservation of water is essential. A solution has been proposed to this problem that is “decentralized water management system” using blockchain technology. Blockchain technology can help to use water more efficiently so that every household can lend/borrow the required/extra water from its peer household in the network. In this research work, water ledger architecture has been proposed. This architecture can serve as the basis for Blockchain implementation which can help inbuilding transparency in the water management system with the ultimate goal of Water Conservation. To purpose a system architecture that meets the “demand and supply” of all consumers in a peer-to-peer network so that water can be conserved. A smart contract has been written for transactions (P2P network of 10 household) using Ethereum as a platform. A web interface is created for consumers. Hence, the overall objective is to create a smart water management system for 10 households using blockchain technology to conserve water by medium of sharing water among peer-to-peer as per their needs.

Open access
Blockchain Technology Applications and Security
FinTech, Crowdfunding, Digital Finance
Original source
Mar 21, 2020·International Journal of Innovative Technology and Exploring Engineering
1 cites
Ethereum Blockchain based Secure E voting S ystem

Sahla Sherin O, Anna Joshy, Neethu Subash

The security and accountability issues are a challenge to the traditional structure from still widespread elections. General e-voting system use a centralized system, where one organization manages overall system. These organisations have full control over the database and system, allowing manipulation of the database. There should be no e-voting system to secure data and potential attacks should be able to withstand. Blockchain technology should solve certain voting problems. In this paper we are implementing an ethereum blockchain based electronic voting system. Ethereum blockchain networks are used to transfer money and store data. Networks are organized by one or more machines. Every node is a machine that running an ethereum client. The eligible one can run the node. By adopting blockchain in e-voting system database distribution, one of the cheating sources of database manipulation and data loss can be reduced. This can be a better solution for the currently existing issues over rigging the electronic voting machines to win elections by the political parties in our government.

Open access
Internet Traffic Analysis and Secure E-voting
Privacy, Security, and Data Protection
Blockchain Technology Applications and Security
Original source
Mar 20, 2020·arXiv
0 cites
Blockchain Governance: An Overview and Prediction of Optimal Strategies using Nash Equilibrium

Nida Khan, Tabrez Ahmad, Anass Patel, Radu State

Blockchain governance is a subject of ongoing research and an interdisciplinary view of blockchain governance is vital to aid in further research for establishing a formal governance framework for this nascent technology. In this paper, the position of blockchain governance within the hierarchy of Institutional governance is discussed. Blockchain governance is analyzed from the perspective of IT governance using Nash equilibrium to predict the outcome of different governance decisions. A payoff matrix for blockchain governance is created and simulation of different strategy profiles is accomplished for computation of all Nash equilibria. The paper elaborates upon payoff matrices for different kinds of blockchain governance, which are used in the proposition of novel mathematical formulae usable to predict the best governance strategy that minimizes the occurrence of a hard fork as well as predicts the behavior of the majority during protocol updates. The paper also includes validation of the proposed formulae using real Ethereum data.

Open access
cs.GT
cs.CY
Original source
Mar 20, 2020·arXiv (Cornell University)
1 cites
Blockchain Governance via Sharp Anonymous Multisignatures

Nida Khan, Tabrez Ahmad, Anass Patel, Radu State

Blockchain governance is a subject of ongoing research and an interdisciplinary view of blockchain governance is vital to aid in further research for establishing a formal governance framework for this nascent technology. In this paper, the position of blockchain governance within the hierarchy of Institutional governance is discussed. Blockchain governance is analyzed from the perspective of IT governance using Nash equilibrium to predict the outcome of different governance decisions. A payoff matrix for blockchain governance is created and simulation of different strategy profiles is accomplished for computation of all Nash equilibria. The paper elaborates upon payoff matrices for different kinds of blockchain governance, which are used in the proposition of novel mathematical formulae usable to predict the best governance strategy that minimizes the occurrence of a hard fork as well as predicts the behavior of the majority during protocol updates. The paper also includes validation of the proposed formulae using real Ethereum data.

Open access
Blockchain Technology Applications and Security
Game Theory and Applications
Complex Network Analysis Techniques
Original source
Mar 19, 2020·Future Generation Computer Systems
25 cites
Blockchain-based semi-autonomous ransomware

Oscar Delgado-Mohatar, José María Sierra-Cámara, E. Anguiano

No abstract is available for this record.

Open access
Blockchain Technology Applications and Security
Advanced Malware Detection Techniques
Security and Verification in Computing
Original source
Mar 19, 2020·arXiv (Cornell University)
11 cites
Blockchain meets Biometrics: Concepts, Application to Template Protection, and Trends

Oscar Delgado-Mohatar, Julián Fiérrez, Rubén Tolosana, Rubén Vera-Rodríguez

Blockchain technologies provide excellent architectures and practical tools for securing and managing the sensitive and private data stored in biometric templates, but at a cost. We discuss opportunities and challenges in the integration of blockchain and biometrics, with emphasis in biometric template storage and protection, a key problem in biometrics still largely unsolved. Key tradeoffs involved in that integration, namely, latency, processing time, economic cost, and biometric performance are experimentally studied through the implementation of a smart contract on the Ethereum blockchain platform, which is publicly available in github for research purposes.

Open access
2 source records
cs.CV
cs.CR
Blockchain Technology Applications and Security
Original source
Mar 18, 2020·Applied Sciences
78 cites
Blockchain-Based Distributed Patient-Centric Image Management System

Mohamed Yaseen Jabarulla, Heung-No Lee

In recent years, many researchers have focused on developing a feasible solution for storing and exchanging medical images in the field of health care. Current practices are deployed on cloud-based centralized data centers, which increase maintenance costs, require massive storage space, and raise privacy concerns about sharing information over a network. Therefore, it is important to design a framework to enable sharing and storing of big medical data efficiently within a trustless environment. In the present paper, we propose a novel proof-of-concept design for a distributed patient-centric image management (PCIM) system that is aimed to ensure safety and control of patient private data without using a centralized infrastructure. In this system, we employed an emerging Ethereum blockchain and a distributed file system technology called Inter-Planetary File System (IPFS). Then, we implemented an Ethereum smart contract called the patient-centric access control protocol to enable a distributed and trustworthy access control policy. IPFS provides the means for decentralized storage of medical images with global accessibility. We describe how the PCIM system architecture facilitates the distributed and secured patient-centric data access across multiple entities such as hospitals, patients, and image requestors. Finally, we deployed a smart contract prototype on an Ethereum testnet blockchain and evaluated the proposed framework within the Windows environment. The evaluation results demonstrated that the proposed scheme is efficient and feasible.

Open access
2 source records
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Cloud Data Security Solutions
Original source
Mar 18, 2020·Journal of Enterprise Information Management
21 cites
Quantifying the sustainability of Bitcoin and Blockchain

John Fry, Jean‐Philippe Serbera

Purpose The authors develop new quantitative methods to estimate the level of speculation and long-term sustainability of Bitcoin and Blockchain. Design/methodology/approach The authors explore the practical application of speculative bubble models to cryptocurrencies. They then show how the approach can be extended to provide estimated brand values using data from Google Trends. Findings The authors confirm previous findings of speculative bubbles in cryptocurrency markets. Relatedly, Google searches for cryptocurrencies seem to be primarily driven by recent price rises. Overall results are sufficient to question the long-term sustainability of Bitcoin with the suggestion that Ethereum, Bitcoin Cash and Ripple may all enjoy technical advantages relative to Bitcoin. Our results also demonstrate that Blockchain has a distinct value and identity beyond cryptocurrencies – providing foundational support for the second generation of academic work on Blockchain. However, a relatively low estimated long-term growth rate suggests that the benefits of Blockchain may take a long time to be fully realised. Originality/value The authors contribute to an emerging academic literature on Blockchain and to a more established literature exploring the use of Google data within business analytics. Their original contribution is to quantify the business value of Blockchain and related technologies using Google Trends

Open access
Blockchain Technology Applications and Security
Consumer Market Behavior and Pricing
Complex Systems and Time Series Analysis
Original source
Mar 17, 2020·Human-centric Computing and Information Sciences
155 cites
A blockchain-based smart home gateway architecture for preventing data forgery

Younghun Lee, Shailendra Rathore, Jin Ho Park, Jong Hyuk Park · 6 authors

Abstract With the advancement of Information and Communication Technology (ICT) and the proliferation of sensor technologies, the Internet of Things (IoT) is now being widely used in smart home for the purposes of efficient resource management and pervasive sensing. In smart homes, various IoT devices are connected to each other, and these connections are centered on gateways. The role of gateways in the smart homes is significant, however, its centralized structure presents multiple security vulnerabilities such as integrity, certification, and availability. To address these security vulnerabilities, in this paper, we propose a blockchain-based smart home gateway network that counters possible attacks on the gateway of smart homes. The network consists of three layers including device, gateway, and cloud layers. The blockchain technology is employed at the gateway layer wherein data is stored and exchanged in the form blocks of blockchain to support decentralization and overcome the problem from traditional centralized architecture. The blockchain ensures the integrity of the data inside and outside of the smart home and provides availability through authentication and efficient communication between network members. We implemented the proposed network on the Ethereum blockchain technology and evaluated in terms of standard security measures including security response time and accuracy. The evaluation results demonstrate that the proposed security solutions outperforms over the existing solutions.

Open access
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Privacy-Preserving Technologies in Data
Original source
Mar 16, 2020·arXiv
4 cites
Vyper: A Security Comparison with Solidity Based on Common Vulnerabilities

Mudabbir Kaleem, Anastasia Mavridou, Áron Lászka

Vyper has been proposed as a new high-level language for Ethereum smart contract development due to numerous security vulnerabilities and attacks witnessed on contracts written in Solidity since the system's inception. Vyper aims to address these vulnerabilities by providing a language that focuses on simplicity, auditability and security. We present a survey where we study how well-known and commonly-encountered vulnerabilities in Solidity feature in Vyper's development environment. We analyze all such vulnerabilities individually and classify them into five groups based on their status in Vyper. To the best of our knowledge, our survey is the first attempt to study security vulnerabilities in Vyper.

Open access
2 source records
cs.CR
Blockchain Technology Applications and Security
Advanced Malware Detection Techniques
Original source
Mar 16, 2020·arXiv (Cornell University)
1 cites
Vyper: A Security Comparison with Solidity Based on Common\n Vulnerabilities

Mudabbir Kaleem, Anastasia Mavridou, Áron Lászka

Vyper has been proposed as a new high-level language for Ethereum smart\ncontract development due to numerous security vulnerabilities and attacks\nwitnessed on contracts written in Solidity since the system's inception. Vyper\naims to address these vulnerabilities by providing a language that focuses on\nsimplicity, auditability and security. We present a survey where we study how\nwell-known and commonly-encountered vulnerabilities in Solidity feature in\nVyper's development environment. We analyze all such vulnerabilities\nindividually and classify them into five groups based on their status in Vyper.\nTo the best of our knowledge, our survey is the first attempt to study security\nvulnerabilities in Vyper.\n

Open access
Blockchain Technology Applications and Security
Information and Cyber Security
Advanced Malware Detection Techniques
Original source
Mar 16, 2020·Sensors
74 cites
A Decentralized Peer-to-Peer Remote Health Monitoring System

Muhammad Salek Ali, Massimo Vecchio, Guntur Dharma Putra, Salil S. Kanhere · 5 authors

Within the Internet of Things (IoT) and blockchain research, there is a growing interest in decentralizing health monitoring systems, to provide improved privacy to patients, without relying on trusted third parties for handling patients' sensitive health data. With public blockchain deployments being severely limited in their scalability, and inherently having latency in transaction processing, there is room for researching and developing new techniques to leverage the security features of blockchains within healthcare applications. This paper presents a solution for patients to share their biomedical data with their doctors without their data being handled by trusted third party entities. The solution is built on the Ethereum blockchain as a medium for negotiating and record-keeping, along with Tor for delivering data from patients to doctors. To highlight the applicability of the solution in various health monitoring scenarios, we have considered three use-cases, namely cardiac monitoring, sleep apnoea testing, and EEG following epileptic seizures. Following the discussion about the use cases, the paper outlines a security analysis performed on the proposed solution, based on multiple attack scenarios. Finally, the paper presents and discusses a performance evaluation in terms of data delivery time in comparison to existing centralized and decentralized solutions.

Open access
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
EEG and Brain-Computer Interfaces
Original source
Mar 15, 2020·International Journal of Social Science and Business
24 cites
ANALISIS VOLATILITAS CRYPTOCURRENCY, EMAS, DOLLAR, DAN INDEKS HARGA SAHAM (IHSG)

Oey Laurensia Dewi Warsito, Robiyanto Robiyanto

This research was conducted to analyze cryptocurrency volatility. Gold, Dollar Index, and Composite Stock Prices Index in the Indonesia Stock Exchange (IDX) variable are used as independent variables. The cryptocurrency objects in this study are Bitcoin and Ethereum which have the largest market capitalization. The data used in this study is from 1st January 2017 to 31st December 2019. This study uses GARCH analysis. The result of this study indicates that the volatility of Bitcoin and Ethereum is not influenced by other variables, but it is influenced by the prices of each Bitcoin and Ethereum at past prices. This shows that the cryptocurrency market is an inefficient market.

Open access
2 source records
Currency Recognition and Detection
Blockchain Technology in Education and Learning
Data Mining and Machine Learning Applications
Original source
Mar 15, 2020·International Journal for Research in Applied Science and Engineering Technology
14 cites
Crowd Funding Using Blockchain

K SRI, J. S. Supriya, Ms. P. Geetha Nanditha Sai, P. Siva Prasad

Crowdfunding is an innovative way of financing projects that allows anyone to contribute money online and support various initiatives, such as businesses, causes, or solutions. However, traditional crowdfunding platforms face some challenges, such as lack of transparency and security, high fees, and limited control over the funds by the contributors and the project owners. Blockchain technology, which is a P2P, decentralized ledger, which is distributed can offer a more reliable, secure, and transparent solution for crowdfunding. Blockchain-based crowdfunding can leverage smart contracts, which are self-executing agreements that encode the rules and conditions of the funding process and ensure that the funds are released only when the predefined criteria are met. This paper aims to propose a concept for designing efficient smart contracts for crowdfunding, which can enable both the contributors and the project owners to have more control and influence over the funds and the project outcomes. Unlike the existing literature-based ideas, our proposed method not only allows the contributors to invest their own money, but also guarantees them that their token values will be preserved. This method can be integrated without disrupting the existing logic of the blockchain. The methodology provides higher control and transparency for all the parties involved in the crowdfunding process.

Open access
3 source records
FinTech, Crowdfunding, Digital Finance
Blockchain Technology Applications and Security
Spam and Phishing Detection
Original source
Mar 13, 2020·arXiv
1 cites
On Exploiting Transaction Concurrency To Speed Up Blockchains

Daniël Reijsbergen, Tien Tuan Anh Dinh

Consensus protocols are currently the bottlenecks that prevent blockchain systems from scaling. However, we argue that transaction execution is also important to the performance and security of blockchains. In other words, there are ample opportunities to speed up and further secure blockchains by reducing the cost of transaction execution. Our goal is to understand how much we can speed up blockchains by exploiting transaction concurrency available in blockchain workloads. To this end, we first analyze historical data of seven major public blockchains, namely Bitcoin, Bitcoin Cash, Litecoin, Dogecoin, Ethereum, Ethereum Classic, and Zilliqa. We consider two metrics for concurrency, namely the single-transaction conflict rate per block, and the group conflict rate per block. We find that there is more concurrency in UTXO-based blockchains than in account-based ones, although the amount of concurrency in the former is lower than expected. Another interesting finding is that some blockchains with larger blocks have more concurrency than blockchains with smaller blocks. Next, we propose an analytical model for estimating the transaction execution speed-up given an amount of concurrency. Using results from our empirical analysis, the model estimates that 6x speed-ups in Ethereum can be achieved if all available concurrency is exploited.

Open access
2 source records
cs.DC
Blockchain Technology Applications and Security
Cloud Computing and Resource Management
Original source
Mar 12, 2020·arXiv
53 cites
ÆGIS: Shielding Vulnerable Smart Contracts Against Attacks

Christof Ferreira Torres, Mathis Baden, Robert Norvill, Beltrán Borja Fiz Pontiveros · 6 authors

In recent years, smart contracts have suffered major exploits, cost- ing millions of dollars. Unlike traditional programs, smart contracts are deployed on a blockchain. As such, they cannot be modified once deployed. Though various tools have been proposed to detect vulnerable smart contracts, the majority fails to protect vulnera- ble contracts that have already been deployed on the blockchain. Only very few solutions have been proposed so far to tackle the issue of post-deployment. However, these solutions suffer from low precision and are not generic enough to prevent any type of attack. In this work, we introduce ÆGIS, a dynamic analysis tool that protects smart contracts from being exploited during runtime. Its capability of detecting new vulnerabilities can easily be extended through so-called attack patterns. These patterns are written in a domain-specific language that is tailored to the execution model of Ethereum smart contracts. The language enables the description of malicious control and data flows. In addition, we propose a novel mechanism to streamline and speed up the process of managing attack patterns. Patterns are voted upon and stored via a smart contract, thus leveraging the benefits of tamper-resistance and transparency provided by the blockchain. We compare ÆGIS to current state-of-the-art tools and demonstrate that our solution achieves higher precision in detecting attacks. Finally, we perform a large-scale analysis on the first 4.5 million blocks of the Ethereum blockchain, thereby confirming the occurrences of well reported and yet unreported attacks in the wild.

Open access
2 source records
Blockchain Technology Applications and Security
Security and Verification in Computing
Advanced Malware Detection Techniques
Original source
Mar 12, 2020·Scientific Reports
37 cites
Network Dynamics of a Financial Ecosystem

Shahar Somin, Yaniv Altshuler, Goren Gordon, Alex Pentland · 5 authors

Global financial crises have led to the understanding that classical econometric models are limited in comprehending financial markets in extreme conditions, partially since they disregarded complex interactions within the system. Consequently, in recent years research efforts have been directed towards modeling the structure and dynamics of the underlying networks of financial ecosystems. However, difficulties in acquiring fine-grained empirical financial data, due to regulatory limitations, intellectual property and privacy control, still hinder the application of network analysis to financial markets. In this paper we study the trading of cryptocurrency tokens on top of the Ethereum Blockchain, which is the largest publicly available financial data source that has a granularity of individual trades and users, and which provides a rare opportunity to analyze and model financial behavior in an evolving market from its inception. This quickly developing economy is comprised of tens of thousands of different financial assets with an aggregated valuation of more than 500 Billion USD and typical daily volume of 30 Billion USD, and manifests highly volatile dynamics when viewed using classic market measures. However, by applying network theory methods we demonstrate clear structural properties and converging dynamics, indicating that this ecosystem functions as a single coherent financial market. These results suggest that a better understanding of traditional markets could become possible through the analysis of fine-grained, abundant and publicly available data of cryptomarkets.

Open access
Complex Systems and Time Series Analysis
Complex Network Analysis Techniques
Blockchain Technology Applications and Security
Original source
Mar 12, 2020·arXiv (Cornell University)
6 cites
{\AE}GIS: Shielding Vulnerable Smart Contracts Against Attacks

Christof Ferreira Torres, Mathis Baden, Robert Norvill, Beltrán Borja Fiz Pontiveros · 6 authors

In recent years, smart contracts have suffered major exploits, costing\nmillions of dollars. Unlike traditional programs, smart contracts are deployed\non a blockchain. As such, they cannot be modified once deployed. Though various\ntools have been proposed to detect vulnerable smart contracts, the majority\nfails to protect vulnerable contracts that have already been deployed on the\nblockchain. Only very few solutions have been proposed so far to tackle the\nissue of post-deployment. However, these solutions suffer from low precision\nand are not generic enough to prevent any type of attack.\n In this work, we introduce {\\AE}GIS, a dynamic analysis tool that protects\nsmart contracts from being exploited during runtime. Its capability of\ndetecting new vulnerabilities can easily be extended through so-called attack\npatterns. These patterns are written in a domain-specific language that is\ntailored to the execution model of Ethereum smart contracts. The language\nenables the description of malicious control and data flows. In addition, we\npropose a novel mechanism to streamline and speed up the process of managing\nattack patterns. Patterns are voted upon and stored via a smart contract, thus\nleveraging the benefits of tamper-resistance and transparency provided by the\nblockchain. We compare {\\AE}GIS to current state-of-the-art tools and\ndemonstrate that our solution achieves higher precision in detecting attacks.\nFinally, we perform a large-scale analysis on the first 4.5 million blocks of\nthe Ethereum blockchain, thereby confirming the occurrences of well reported\nand yet unreported attacks in the wild.\n

Open access
2 source records
Blockchain Technology Applications and Security
Advanced Malware Detection Techniques
Security and Verification in Computing
Original source
Mar 12, 2020·Energies
86 cites
Privacy-Preserving Peer-to-Peer Energy Trading in Blockchain-Enabled Smart Grids Using Functional Encryption

Ye-Byoul Son, Jong-Hyuk Im, Hee-Yong Kwon, Seong-Yun Jeon · 5 authors

Advanced smart grid technologies enable energy prosumers to trade surplus energy from their distributed renewable energy sources with other peer prosumers through peer-to-peer (P2P) energy trading. In many previous works, P2P energy trading was facilitated by blockchain technology through blockchain’s distributive nature and capacity to run smart contracts. However, the feature that all the data and transactions on a blockchain are visible to all blockchain nodes may significantly threaten the privacy of the parties participating in P2P energy trading. There are many previous works that have attempted to mitigate this problem. However, all these works focused on the anonymity of participants but did not protect the data and transactions. To address this issue, we propose a P2P energy trading system on a blockchain where all bids are encrypted and peer matching is performed on the encrypted bids by a functional encryption-based smart contract. The system guarantees that the information encoded in the encrypted bids is protected, but the peer matching transactions are performed by the nodes in a publicly verifiable manner through smart contracts. We verify the feasibility of the proposed system by implementing a prototype composed of smart meters, a distribution system operator (DSO) server, and private Ethereum blockchain.

Open access
Blockchain Technology Applications and Security
Cryptography and Data Security
Internet Traffic Analysis and Secure E-voting
Original source
Mar 9, 2020·arXiv
5 cites
Ransomware as a Service using Smart Contracts and IPFS

Christos Karapapas, Iakovos Pittaras, Nikos Fotiou, George C. Polyzos

Decentralized systems, such as distributed ledgers and the InterPlanetary File System (IPFS), are designed to offer more open and robust services. However, they also create opportunities for illegal activities. We demonstrate how these technologies can be used to launch a ransomware as a service campaign. We show that criminals can transact with affiliates and victims without having to reveal their identity. Furthermore, by exploiting the robustness and resilience to churn of IPFS, as well as the decentralized computing capabilities of Ethereum, criminals can remain offline during most procedures, with many privacy guarantees.

Open access
2 source records
cs.CR
Advanced Malware Detection Techniques
Blockchain Technology Applications and Security
Original source
Mar 8, 2020·Lecture notes in computer science
223 cites
Attacking the DeFi Ecosystem with Flash Loans for Fun and Profit

Kaihua Qin, Liyi Zhou, Benjamin Livshits, Arthur Gervais

Credit allows a lender to loan out surplus capital to a borrower. In the traditional economy, credit bears the risk that the borrower may default on its debt, the lender hence requires upfront collateral from the borrower, plus interest fee payments. Due to the atomicity of blockchain transactions, lenders can offer flash loans, i.e., loans that are only valid within one transaction and must be repaid by the end of that transaction. This concept has lead to a number of interesting attack possibilities, some of which were exploited in February 2020. This paper is the first to explore the implication of transaction atomicity and flash loans for the nascent decentralized finance (DeFi) ecosystem. We show quantitatively how transaction atomicity increases the arbitrage revenue. We moreover analyze two existing attacks with ROIs beyond 500k%. We formulate finding the attack parameters as an optimization problem over the state of the underlying Ethereum blockchain and the state of the DeFi ecosystem. We show how malicious adversaries can efficiently maximize an attack profit and hence damage the DeFi ecosystem further. Specifically, we present how two previously executed attacks can be "boosted" to result in a profit of 829.5k USD and 1.1M USD, respectively, which is a boost of 2.37x and 1.73x, respectively.

Open access
3 source records
Blockchain Technology Applications and Security
FinTech, Crowdfunding, Digital Finance
cs.CR
Original source