Fredy Andrés Aponte-Novoa, Ana Lucila Sandoval Orozco, Ricardo Villanueva-Polanco, Pedro M. Wightman
The applications that use blockchain are cryptocurrencies, decentralized finance applications, video games and many others. Most of these applications trust that the blockchain will prevent issues like fraud, thanks to the built-in cryptographic mechanisms provided by the data structure and the consensus protocol. However, blockchains suffers from what is called a 51% attack or majority attack, which is considered a high risk for the integrity of these blockchains, where if a miner, or a group of them, has more than half the computing capability of the network, it can rewrite the blockchain. Even though this attack is possible in theory, it is regarded as hard-achievable in practice, due to the assumption that, with enough active members, it is very complicated to have that much computing power; however, this assumption has not been studied with enough detail. In this work, a detailed characterization of the miners in the Bitcoin and Crypto Ethereum blockchains is presented, with the aim of proving the computing distribution assumption and to creating profiles that may allow the detection of anomalous behaviors and prevent 51% attacks. The results of the analysis show that, in the last years, there has been an increasing concentration of hash rate power in a very small set of miners, which generates a real risk for current blockchains. Also, that there is a pattern in mining among the main miners, which makes it possible to identify out-of-normal behavior.
Open access
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
In the Blockchain context, Smart Contracts are computer programs that run on the Ethereum platform. Benefiting from the properties of Blockchain, SCs development represents a major challenge to developers, as the code is deployed to an immutable system, besides the Ethereum platform is still evolving. This paper highlights how we can exploit model-driven engineering for generating long terms and high productivity smart contracts. It reviews researches on Smart Contracts generation in the Ethereum blockchain from a model-driven perspective. Based on the studied approaches, we defined a comparative framework to outline the advantages and disadvantages of each approach. The result can be used as a basis of tool selection for specific development aspects of SCs.
Darrell Yonathan, Diyanatul Husna, F. Astha Ekadiyanto, I Ketut Eddy Purnama · 10 authors
This paper discusses the implementation of smart contracts on the Ethereum blockchain system for telemedicine data storage. Telemedicine is one of the currently developing digital technologies in the health and medical sectors. Telemedicine can be more efficient when seeking treatment because patients do not need to see a doctor face to face. When using blockchain technology, the stored data becomes more transparent for each node in the blockchain network but has verification on every transaction which takes time and gas costs. However, telemedicine has several risks and problems, one of which is long data storage process time because there must be a verification process first to ensure data security. Another problem faced is the issue of the gas fee of the blockchain telemedicine system which is billed in every data storage transaction. In this study, a blockchain system was introduced for managing and securing databases on telemedicine. The implementation of this blockchain system was carried out on a website page that can add data to and retrieve data from the blockchain system. The results of this study showed that blockchain was successfully implemented to store telemedicine data with Ethereum. The analysis in this paper refers to the set and gets functions. The set function is used to send data to the blockchain, and the get function is used to retrieve data from the blockchain. From testing, the Get function has a much faster execution time than the Set function because the Get function does not require verification to retrieve its data. In the iterations carried out—namely 1, 10, and 100—the longest time on average was at 100 iterations when compared to the other iterations. In the tests carried out, the more characters that were stored, the more gas costs must be paid. In the tests, the percentage increase in costs was 0.34% per character.
Han Yu, Tiantian Ji, Zhongru Wang, Hao Liu · 7 authors
A smart contract honeypot is a special type of smart contract. This type of contract seems to have obvious vulnerabilities in contract design. If a user transfers a certain amount of funds to the contract, then the user can withdraw the funds in the contract. However, once users try to take advantage of this seemingly obvious vulnerability, they will fall into a real trap. Consequently, the user’s investment in the contract cannot be retrieved. The honeypot induces other accounts to launch funds, which seriously threatens the security of property on the blockchain. Detection methods for honeypots are available. However, studying the manner by which to defend existing honeypots is insufficient to fight against honeypots. The new honeypots that may appear in the future from the perspective of an attacker must also be predicted. Therefore, we propose a type of adversarial honeypot. The code and behavioral features of honeypots are obtained through a comparative analysis of the 158,568 non-honeypots and 352 honeypots. To build an adversarial honeypot, we try to separately hide these features and make the honeypot bypass the existing detection technology. We construct 18 instances on the basis of the proposed adversarial honeypot and use an open-source honeypot detection tool to detect these instances. The experimental result shows that the proposed honeypot can bypass the detection tool with a 100% ratio. Therefore, this type of honeypot should be given attention, and defensive measures should be proposed as soon as possible.
Cardano was launched in October 2017 and by May 2021 has been operational for 44 months. Comparison with its closest rival, Ethereum, reveals that their prices are highly correlated but the change in daily closing prices do not always move in unison. Cardano is also more volatile than Ethereum and In terms of growth Cardano is lagging behind. Cardano’s only saving grace is its transaction fees, which are considerably lower than Ethereum. However, care must be taken in understanding the structure of any data source. In this case three data sources are used and results vary depending on the precision of the price data, particularly Cardano which for a number of years did not trade above one dollar.
With the recent advancements in the networking realm of computers as well as achieving real-time communication between devices over the Internet, IoT (Internet of Things) devices have been on the rise; collecting, sharing, and exchanging data with other connected devices or databases online, enabling all sorts of communications and operations without the need for human intervention, oversight, or control. This has caused more computer-based systems to get integrated into the physical world, inching us closer towards developing smart cities. The automotive industry, alongside other software developers and technology companies have been at the forefront of this advancement towards achieving smart cities. Currently, transportation networks need to be revamped to utilize the massive amounts of data being generated by the public’s vehicle’s on-board devices, as well as other integrated sensors on public transit systems, local roads, and highways. This will create an interconnected ecosystem that can be leveraged to improve traffic efficiency and reliability. Currently, Vehicular Ad-hoc Networks (VANETs) such as vehicle-to-vehicle (V2V), vehicle-to-infrastructure (V2I), and vehicle-to-grid (V2G) communications, all play a major role in supporting road safety, traffic efficiency, and energy savings. To protect these devices and the networks they form from being targets of cyber-related attacks, this paper presents ideas on how to leverage distributed ledger technologies (DLT) to establish secure communication between vehicles that is decentralized, trustless, and immutable. Incorporating IOTA’s protocols, as well as utilizing Ethereum’s smart contracts functionality and application concepts with VANETs, all interoperating with Hyperledger’s Fabric framework, several novel ideas can be implemented to improve traffic safety and efficiency. Such a modular design also opens up the possibility to further investigate use cases of the blockchain and distributed ledger technologies in creating a decentralized intelligent transportation system (ITS).
Uniswap is a decentralized exchange (DEX) and was first launched on November 2, 2018 on the Ethereum mainnet [1] and is part of an Ecosystem of products in Decentralized Finance (DeFi). It replaces a traditional order book type of trading common on centralized exchanges (CEX) with a deterministic model that swaps currencies (or tokens/assets) along a fixed price function determined by the amount of currencies supplied by the liquidity providers. Liquidity providers can be regarded as investors in the decentralized exchange and earn fixed commissions per trade. They lock up funds in liquidity pools for distinct pairs of currencies allowing market participants to swap them using the fixed price function. Liquidity providers take on market risk as a liquidity provider in exchange for earning commissions on each trade. Here we analyze the risk profile of a liquidity provider and the so called impermanent (unrealized) loss in particular. We provide an improved version of the commonly denoted impermanent loss function for Uniswap v2 on the semi-infinite domain. The differences between Uniswap v2 and v3 are also discussed.
Smart Contracts are software programs that are deployed and executed within a blockchain infrastructure. Due to their immutable nature, directly resulting from the specific characteristics of the deploying infrastructure, smart contracts must be thoroughly tested before their release. Testing is one of the main activities that can help to improve the reliability of a smart contract, so as to possibly prevent considerable loss of valuable assets. It is therefore important to provide the testers with tools that permit them to assess the activity they performed. Mutation testing is a powerful approach for assessing the fault-detection capability of a test suite. In this paper, we propose SuMo, a novel mutation testing tool for Ethereum Smart Contracts. SuMo implements a set of 44 mutation operators that were designed starting from the latest Solidity documentation, and from well-known mutation testing tools. These allow to simulate a wide variety of faults that can be made by smart contract developers. The set of operators was designed to limit the generation of stillborn mutants, which slow down the mutation testing process and limit the usability of the tool. We report a first evaluation of SuMo on open-source projects for which test suites were available. The results we got are encouraging, and they suggest that SuMo can effectively help developers to deliver more reliable smart contracts.
Juan Cano-Benito, Andrea Cimmino, Raúl García‐Castro
Blockchain has become a pervasive technology in a wide number of sectors like industry, research, and academy. With the emergence of blockchain, new solutions with this technology to existing problems were devised, leading to the introduction of smart contracts. Smart contracts are similar to traditional contracts with the benefits provided by blockchain, such as immutability, privacy, and decentralisation. These contracts are usually defined based on a specific domain, and this domain knowledge can be represented through an ontology. Researches have explored the benefits of using domain ontologies with smart contracts, such as code generation, discovering other contracts in the network, or interaction with other contracts. Notwithstanding, the representation of smart contract languages themselves has not been studied. In this paper, we present an ontology for a well-known smart contract language, Solidity, defining all entities needed to cover the whole language and aligning it to other standardised ontologies such as EthOn, in a way to improve the knowledge of the ontology developed. Furthermore, the ontology has also been validated with already deployed contracts in the Ethereum blockchain. Thus, Solidity will be able to benefit from the advantages provided by ontologies, such as interoperability and the use of semantic web technologies.
There has been a great deal of discussion of the challenges on privacy, data interoperability and quality of Educational Professional Personal Record (EPPR). Therefore, there is a need to reassess the current models, in which various parties generate, exchange and observe a huge amount of personal data with regard to EPPR. Ethereum blockchain has shown that trusted, auditable transactions is detectible using a decentralized network of nodes accompanied by a general ledger. Thus, due to the fast-moving development of educational and professional data generators such as online universities and distance learning, requires learners to engage in detail into their EPPR as well as the educational and professional data generators. In this paper, we propose a novel decentralized framework to manage EPPR using Ethereum blockchain technology. The framework provides the owner of the EPPR a comprehensive immutable log and ease of access to their educational records across the educational record editors and consumers. Furthermore, it provides a recommender engine to endorse skills and competencies to the education record owners and similar candidates for educational records editors and consumers. Ethereum blockchain can provide solutions in terms of exchanging of data among parties by ensuring privacy, accountability and data interoperability. The aim of the proposed framework is to enable educational stakeholders (universities and employing agencies) to participate in the network as blockchain miners rewarded by pseudonymized data in compliance with General Data Protection Rules in United Arab Emirates.
Peer-review is a necessary and essential quality control step for scientific publications but lacks proper incentives. Indeed, the process, which is very costly in terms of time and intellectual investment, not only is not remunerated by the journals but is also not openly recognized by the academic community as a relevant scientific output for a researcher. Therefore, scientific dissemination is affected in timeliness, quality, and fairness. Here, to solve this issue, we propose a blockchain-based incentive system that rewards scientists for peer-reviewing other scientists' work and that builds up trust and reputation. We designed a privacy-oriented protocol of smart contracts called Ants-Review that allows authors to issue a bounty for open anonymous peer-reviews on Ethereum. If requirements are met, peer-reviews will be accepted and paid by the approver proportionally to their assessed quality. To promote ethical behavior and inclusiveness the system implements a gamified mechanism that allows the whole community to evaluate the peer-reviews and vote for the best ones.
With the wide application of blockchain in the financial field, the rise of various types of cybercrimes has brought great challenges to the security of blockchain. In order to better understand this emerging market and explore more efficient countermeasures for effective supervision, it is imperative to track transactions on blockchain-based systems. Due to the openness of Ethereum, we can easily access the publicly available transaction records, model them as a complex network, and further study the problem of transaction tracking via link prediction, which provides a deeper understanding of Ethereum transactions from a network perspective. Specifically, we introduce an embedding based link prediction framework that is composed of temporal-amount snapshot multigraph (TASMG) and present temporal-amount walk (TAW). By taking the realistic rules and features of transaction networks into consideration, we propose TASMG to model Ethereum transaction records as a temporal-amount network and then present TAW to effectively embed accounts via their transaction records, which integrates temporal and amount information of the proposed network. Experimental results demonstrate the superiority of the proposed framework in learning more informative representations and could be an effective method for transaction tracking.
The rapid growth of R&D in the blockchain world can be explained by the industry’s gaining a deeper understanding of where the value is created and captured for a traditional internet company and a blockchain company. Joel Monegro and Naval Ravikant talk about the idea of fat protocols, where most of the innovation in the blockchain space will happen at the core technology level. Then a token layer can monetize the use of the underlying architecture and provide access to the application layer. To that end, we have seen three iterations of blockchains in development: the first version was the original protocol by Satoshi that provides a functional blockchain for transactions. The second version was protocols like Ethereum that provide smart contracts and on-chain operations. The next generation of blockchain protocols allow on-chain execution and the integration of services such as machine learning onto a blockchain for advanced tasks.
The paper presents a new digital infrastructure layer for buildings and architectural assets. The infrastructure layer consists of a combination of topology graphs secured on a decentralised ledger. The topology graphs organise non-fungible digital tokens which each represent and correspond to building components, and in the root of the graph to the building itself.The paper presents background research in the relationship of building representation in the form of graphs with topology, of both manifold and non manifold nature. In parallel we present and analyse the relationship between digital representation and physical manifestation of a building, and back again. Within the digital representations the paper analyses the securing and saving of information on decentralised ledger technologies (such as blockchain). We then present a simple sample of generating and registering a non-manifold topology graph on the Ethereum blockchain as an EC721 token, i.e. a digital object that is unique, all through the use of dynamo and python scripting connected with a smart contract on the Ethereum blockchain. Ownership of this token can then be transferred on the blockchain smart contracts. The paper concludes with a discussion of the possibilities that this integration brings in terms of material passports and a circular economy and smart contracts as an infrastructure for whole-lifecycle BIM and digitally encapsulates of value in architectural designPlease write your abstract here by clicking this paragraph.
Tokenizing assets through the use of blockchain is the next big thing in digital currency markets. Securing the assets in the world of the internet is challenging as most of them can easily be copied and sold in the secondary market. Protecting the rights of the asset owner is one of the challenging research areas. NFTs (non-fungible tokens) are very useful in representing the ownership of unique items for any assets. NFTs ensure that an asset can have only one official owner at any point in time with the help of Ethereum-based blockchain network. Ethereum NFTs can ensure that no one can modify the ownership rights or copy and paste the digital assets. NFTs are a boon to the artists, musicians, and others who want to create impressive digital assets. The objective of this chapter is to take you to the world of NFTs and to explain how the NFTs are going to impact digital transactions in a bigger way in the future. This chapter covers the introduction, technical aspects, security impacts, use cases, and successful implementations of NFTs in various realms.