Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

13,648 papersLast indexed Aug 28, 2026
Search papers

Paper index

13,648 results · page 447 of 569

Clear filters
Aug 21, 2020
0 cites
Digitised Academic Credential Verification Using Blockchain

Rohan Parekh, Pooja Pillai, Shambhavi Shukla, Suhasini Parvatikar

Blockchain is a digitized underlying technology having variety of applications that powers cryptocurrencies such as Bitcoin, Ripple and Ethereum. It has not been limited to just cryptocurrencies but has also been exploited and utilized in different domains such as education, healthcare, finance, electronics, commerce, Internet of Things, governance, etc.Some key attributes of this technology are security, decentralization, immutability, and transparency. In education sector, Blockchain technology can be used for various purposes. It can be used for issuing and verification of educational credentials and records digitally to prevent forgery. Counterfeiting academic certificates has been a longstanding obstacle in the academia. While it is an easy task to counterfeit credentials almost instantaneously, verification of authenticity is a complicated and challenging. Hence, we are proposing a blockchain-based solution to help resolve the problem, named ‘Academic credential verification’ in which we are using smart contract and Ethereum for awarding digital form of certificates to students for easy storage and verification of credentials. It also enables students to share their credentials and records to trusted third parties. Keywords:Blockchain technology, decentralized verification, graduation certificate forgery, graduation certificate verification, technology Cite this Article: Rohan Parekh, Pooja Pillai, Shambhavi Shukla, Suhasini Parvatikar.Digitised Academic Credential Verification Using Blockchain. Research & Reviews: A Journal of Embedded System & Applications. 2020; 8(2): 21–29p.

Blockchain Technology Applications and Security
Cloud Data Security Solutions
Original source
Aug 21, 2020
14 cites
Data Provenance Assurance for Cloud Storage Using Blockchain

Abhishekh Patil, Amit Kumar Jha, Mohammed Moin Mulla, D. G. Narayan · 5 authors

Cloud forensics investigates the crime committed over cloud infrastructures like SLA-violations and storage privacy. Cloud storage forensics is the process of recording the history of the creation and operations performed on a cloud data object and investing it. Secure data provenance in the Cloud is crucial for data accountability, forensics, and privacy. Towards this, we present a Cloud-based data provenance framework using Blockchain, which traces data record operations and generates provenance data. Initially, we design a dropbox like application using AWS S3 storage. The application creates a cloud storage application for the students and faculty of the university, thereby making the storage and sharing of work and resources efficient. Later, we design a data provenance mechanism for confidential files of users using Ethereum blockchain. We also evaluate the proposed system using performance parameters like query and transaction latency by varying the load and number of nodes of the blockchain network.

Scientific Computing and Data Management
Cloud Data Security Solutions
Cloud Computing and Resource Management
Original source
Aug 21, 2020·arXiv (Cornell University)
3 cites
BLONDiE: Blockchain Ontology with Dynamic Extensibility

Ugarte-Rojas Hector, Chullo-Llave Boris

There are thousands of projects worldwide based primarily on blockchain technology. These have a large number of users and hundreds of use cases. One of the most popular is the use of cryptocurrencies and their benefits against money without intrinsic value (fiat money) and centralized financial solutions. However, although thousands of new transactions are carried out daily in different platforms, uniform and standardized information does not exist to be able to manage the large amount of data that is generated and exchanged between users through transactions and the generation of new blocks. This research reports the development of BLONDiE, an ontology that allows the semantic representation of knowledge to describe the native structure and related information of the three most relevant blockchain projects to date: Bitcoin, Ethereum and in the recent 1.0 version extends its definitions to include Hyperledger, specifically the Hyperledger Fabric infrastructure. Its use allows having common data formats of different platforms for further processing, such as the execution of semantic queries.

Open access
2 source records
cs.CR
Semantic Web and Ontologies
Blockchain Technology Applications and Security
Original source
Aug 21, 2020
19 cites
Performance Evaluation of Consensus Algorithms in Private Blockchain Networks

Y Supreet, Patil Mahesh Vasudev, H. Pavitra, Mouna Naravani · 5 authors

Blockchain, one of the modern technologies, has received significant attention recently. The blockchain is an immutable ledger which records the transaction in a decentralized manner that ensures high security. Blockchain-based applications are popular in numerous fields like financial services, cryptocurrencies, cybersecurity, supply chain, health care, E-Governance, asset management, Internet of Things (IoT), and so on. In order to validate a transaction within a ledger, blockchain uses the concept of consensus. Consensus guarantees fault tolerance, reliability and high security of the blockchain systems. The most widely used consensus algorithms in the modern blockchains are the Proof of Work (PoW), the Proof of Stake (PoS), the Proof of Activity(PoA) and the Practical Byzantine Fault Tolerance(PBFT). In this work, we conduct a performance evaluation of these four consensus algorithms using Naive implementation of a blockchain network. We also conduct experiments with two popular consensus mechanisms in Ethereum platform. We study the characteristics of transaction and query latencies by varying the number of complexity and transactions. Finally, we present the conclusion on the performance consensus algorithms.

Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Retinal Imaging and Analysis
Original source
Aug 21, 2020·International Journal of Finance & Economics
56 cites
Cryptocurrencies value‐at‐risk and expected shortfall: Do regime‐switching volatility models improve forecasting?

Leandro Maciel

Abstract This paper evaluates the presence of regime changes in the log‐returns volatility dynamics of cryptocurrencies using Markov‐Switching GARCH (MS‐GARCH) models. The empirical study compares the prediction performance of MS‐GARCH against traditional single‐regime GARCH methods for one‐, five‐ and ten‐steps‐ahead volatility forecasting of six leading digital coins such as Bitcoin, Dashcoin, Ethereum, Litecoin, Monero and Ripple. Using a Bayesian approach, different MS‐GARCH structures are estimated considering specifications up to three regimes, three scedastic functions and six error distributions, resulting in a total of 54 models for each cryptocurrency. Forecasts are compared according to an economic criterion, that is, through the estimation of Value‐at‐Risk (VaR) and Expected Shortfall (ES) risk measures. The results support the evidence of regime changes in the volatility process of selected cryptocurrencies and show that MS‐GARCH models do provide more accurate VaR and ES forecasts than their single‐regime counterparts.

Open access
Market Dynamics and Volatility
Financial Risk and Volatility Modeling
Original source
Aug 19, 2020
0 cites
Rumo a Avaliação do Ethereum e do Hyperlegder Fabric com Dados HeterogĂȘneos

Ana Caroline Fernandes Spengler, Paulo Sérgio Lopes de Souza

Blockchain nasceu com o surgimento do Bitcoin, apresentando-se como uma infraestrutura para o armazenamento distribuĂ­do de transaçÔes financeiras com garantia de imutabilidade. Pelas suas caracterĂ­sticas, o blockchain passou a ser utilizado por outras aplicaçÔes que podem se beneficiar dessa infraestrutura. Essas aplicaçÔes apresentam demandas distintas daquelas focadas em transaçÔes financeiras, como manipulação de diferentes tipos de dados e privacidade das informaçÔes. O objetivo deste projeto em andamento Ă© verificar o desempenho do blockchain quando utilizado aplicaçÔes que demandam dados heterogĂȘneos.

Open access
Blockchain Technology Applications and Security
Original source
Aug 19, 2020·Journal of risk and financial management
12 cites
True versus Spurious Long Memory in Cryptocurrencies

Dooruj Rambaccussing, Murat Mazibaß

We test whether the selected cryptocurrencies exhibit long memory behavior in returns and volatility. We use data on five most traded cryptocurrencies: Bitcoin, Litecoin, Ethereum, Bitcoin Cash, and XRP. Using recent tests of long memory developed against persistent and nonlinear alternatives, this paper finds that long memory is mostly rejected in returns. The tests fail to reject the null hypothesis of long memory in most cases across different volatility proxies and cryptocurrencies. The estimated memory parameters show that volatility is persistent, and when volatility is measured by log range, it is borderline nonstationary.

Open access
Complex Systems and Time Series Analysis
Market Dynamics and Volatility
Blockchain Technology Applications and Security
Original source
Aug 18, 2020·Digital Finance
32 cites
A blockchain-based Forensic Model for Financial Crime Investigation: The Embezzlement Scenario

Lamprini Zarpala, Fran Casino

The financial crime landscape is evolving along with the digitization in financial services. In this context, laws and regulations cannot efficiently cope with a fast-moving industry such as finance, which translates in late adoption of measures and legal voids, providing a fruitful landscape for malicious actors. In parallel, blockchain technology and its promising features such as immutability, verifiability, and authentication, enhance the opportunities of financial forensics. In this paper, we focus on an embezzlement scheme and we provide a forensic-by-design methodology for its investigation. In addition, the feasibility and adaptability of our approach can be extended and embrace digital investigations on other types of schemes. We provide a functional implementation based on smart contracts and we integrate standardised forensic flows and chain of custody preservation mechanisms. Finally, we discuss the benefits and challenges of the symbiotic relationship between blockchain and financial investigations, along with future research directions.

Open access
2 source records
cs.CR
Blockchain Technology Applications and Security
Digital and Cyber Forensics
Original source
Aug 18, 2020·Sensors
31 cites
BlockSIEM: Protecting Smart City Services through a Blockchain-based and Distributed SIEM

Juan Velandia Botello, Andrés Pardo Mesa, Fabiån Ardila Rodríguez, Daniel Díaz López · 6 authors

The Internet of Things (IoT) paradigm has revolutionized several industries (e.g., manufacturing, health, transport, education, among others) by allowing objects to connect to the Internet and, thus, enabling a variety of novel applications. In this sense, IoT devices have become an essential component of smart cities, allowing many novel and useful services, but, at the same time, bringing numerous cybersecurity threats. The paper at hand proposes BlockSIEM, a blockchain-based and distributed Security Information and Event Management (SIEM) solution framework for the protection of the aforementioned smart city services. The proposed SIEM relies on blockchain technology to securely store and access security events. Such security events are generated by IoT sentinels that are in charge of shielding groups of IoT devices. The IoT sentinels may be deployed in smart city scenarios, such as smart hospitals, smart transport systems, smart airports, among others, ensuring a satisfactory level of protection. The blockchain guarantees the non-repudiation and traceability of the registry of security events due to its features. To demonstrate the feasibility of the proposed approach, our proposal is implemented using Ethereum and validated through different use cases and experiments.

Open access
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Internet Traffic Analysis and Secure E-voting
Original source
Aug 17, 2020·Journal of Information and Optimization Sciences
13 cites
Analyzing the performance of data processing in private blockchain based distributed ledger

Arvind Panwar, Vishal Bhatnagar

A blockchain is a new open-source technology who attract whole the business world and technology experts to research, to explore and to understand the potential of this technology in different areas. Blockchain initially released in 2008 by Satoshi Nakamoto as a fundamental technology for the first-ever global decentralized cryptography-based digital currency known as BITCOIN. A blockchain is a transparent and immutable globally distributed ledger, distributed databases, who have global agreement by all its users. It means that when anything written in distributed ledger is cannot be cheated and modified, it will be trusted if the writer of content is trusted. In this research studies, author analyzes the performance of two widely used blockchain platform one is Ethereum and second is Hyperledger Fabric.

Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Advanced Steganography and Watermarking Techniques
Original source
Aug 13, 2020·arXiv
0 cites
Understanding Gambling Behavior and Risk Attitudes Using Cryptocurrency-based Casino Blockchain Data

Jonathan Meng, Feng Fu

The statistical concept of Gambler's Ruin suggests that gambling has a large amount of risk. Nevertheless, gambling at casinos and gambling on the Internet are both hugely popular activities. In recent years, both prospect theory and lab-controlled experiments have been used to improve our understanding of risk attitudes associated with gambling. Despite theoretical progress, collecting real-life gambling data, which is essential to validate predictions and experimental findings, remains a challenge. To address this issue, we collect publicly available betting data from a \emph{DApp} (decentralized application) on the Ethereum Blockchain, which instantly publishes the outcome of every single bet (consisting of each bet's timestamp, wager, probability of winning, userID, and profit). This online casino is a simple dice game that allows gamblers to tune their own winning probabilities. Thus the dataset is well suited for studying gambling strategies and the complex dynamic of risk attitudes involved in betting decisions. We analyze the dataset through the lens of current probability-theoretic models and discover empirical examples of gambling systems. Our results shed light on understanding the role of risk preferences in human financial behavior and decision-makings beyond gambling.

Open access
physics.soc-ph
q-fin.RM
Original source
Aug 13, 2020·arXiv (Cornell University)
1 cites
Zecale: Reconciling Privacy and Scalability on Ethereum

Antoine Rondelet

In this paper, we present Zecale, a general purpose SNARK proof aggregator that uses recursive composition of SNARKs. We start by introducing the notion of recursive composition of SNARKs, before introducing Zecale as a privacy preserving scalability solution. Then, we list application types that can emerge and be built with Zecale. Finally, we argue that such scalability solutions for privacy preserving state transitions are paramount to emulate "cash" on blockchain systems.

Open access
2 source records
Blockchain Technology Applications and Security
Cryptography and Data Security
Cloud Data Security Solutions
Original source
Aug 12, 2020·Advances in information security, privacy, and ethics book series
1 cites
Blockchain as an Enabler for Zero-Trust Architectures

Authors unavailable

From the lessons that can be learned so far in this book, the author justifies why a new strategy is required to refocus our perception and utilization of computerized capabilities in the future. Chapter 8 focuses on the advancement of the cyber security discipline by determining trust-less control-sets – a fourth dimension if you will, comprising blockchain technology. Blockchain has been implemented in fungible forms, such as public bitcoin and Ethereum, and in a non-fungible manner like private keyless signature infrastructure. It is the latter that is of particular interest, where proven implementations have the potential to demonstrably act as a verifiable trust anchor, embellishing cyber security controls in a number of critical areas to ensure (1) preservation of data integrity, (2) digital finger printing of IoT assets to prove the source of data is trustworthy, (3) validation of identity and access management mechanisms, and (4) software provenance in the supply chain for not only traditional code-bases but also AI algorithms.

Advanced Malware Detection Techniques
Blockchain Technology Applications and Security
Security and Verification in Computing
Original source
Aug 12, 2020·arXiv (Cornell University)
6 cites
GasMet: Profiling Gas Leaks in the Deployment of Solidity Smart Contracts.

Gerardo Canfora, Andrea Di Sorbo, Sonia Laudanna, Anna Vacca · 5 authors

Nowadays, blockchain technologies are increasingly adopted for different purposes and in different application domains. Accordingly, more and more applications are developed for running on a distributed ledger technology (i.e., \textit{dApps}). The business logic of a dApp (or part of it) is usually implemented within one (or more) smart contract(s) developed through Solidity, an object-oriented programming language for writing smart contracts on different blockchain platforms, including the popular Ethereum. In Ethereum, once compiled, the smart contracts run on the machines of miners who can earn Ethers (a cryptographic currency like Bitcoin) by contributing their computing resources and the \textit{gas} (in Ether) corresponds to the execution fee compensating such computing resources. However, the deployment and execution costs of a smart contract strictly depend on the choices done by developers while implementing it. Unappropriated design choices -- e.g., in the data structures and the specific instructions used -- could lead to higher gas consumption than necessary. In this paper, we systematically identify a set of 20 Solidity code smells that could affect the deployment and transaction costs of a smart contract, i.e., \textit{cost smells}. On top of these smells, we propose GasMet, a suite of metrics for statically evaluating the code quality of a smart contract, from the gas consumption perspective. In an experiment involving 2,186 real-world smart contracts, we demonstrate that the proposed metrics (i) have direct associations with deployment costs, and (ii) they could be used to properly identify the level of gas consumption of a smart contract without the need for deploying it.

Open access
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Security and Verification in Computing
Original source
Aug 12, 2020·arXiv (Cornell University)
5 cites
Profiling Gas Leaks in Solidity Smart Contracts

Gerardo Canfora, Andrea Di Sorbo, Sonia Laudanna, Anna Vacca · 5 authors

Nowadays, more and more applications are developed for running on a distributed ledger technology, namely dApps. The business logic of dApps is usually implemented within smart contracts developed through Solidity, a programming language for writing smart contracts on different blockchain platforms, including the popular Ethereum. In Ethereum, the smart contracts run on the machines of miners and the gas corresponds to the execution fee compensating such computing resources. However, the deployment and execution costs of a smart contract depend on the implementation choices done by developers. Unappropriated design choices could lead to higher gas consumption than necessary. In this paper, we (i) identify a set of 19 Solidity code smells affecting the deployment and transaction costs of a smart contract, and (ii) assess the relevance of such smells through a survey involving 34 participants. On top of these smells, we propose GasMet, a suite of metrics for statically evaluating the code quality of a smart contract from the gas consumption perspective. An experiment involving 2,186 smart contracts demonstrates that the proposed metrics have direct associations with deployment costs. The metrics in our suite can be used for more easily identifying source code segments that need optimizations.

Open access
Blockchain Technology Applications and Security
Advanced Malware Detection Techniques
Mobile Crowdsensing and Crowdsourcing
Original source
Aug 12, 2020·Journal of Systems and Software
47 cites
Profiling gas consumption in solidity smart contracts

Andrea Di Sorbo, Sonia Laudanna, Anna Vacca, Corrado Aaron Visaggio · 5 authors

Nowadays, more and more applications are developed for running on a distributed ledger technology, namely dApps. The business logic of dApps is usually implemented within smart contracts developed through Solidity, a programming language for writing smart contracts on different blockchain platforms, including the popular Ethereum. In Ethereum, the smart contracts run on the machines of miners and the gas corresponds to the execution fee compensating such computing resources. However, the deployment and execution costs of a smart contract depend on the implementation choices done by developers. Unappropriated design choices could lead to higher gas consumption than necessary. In this paper, we (i) identify a set of 19 Solidity code smells affecting the deployment and transaction costs of a smart contract, and (ii) assess the relevance of such smells through a survey involving 34 participants. On top of these smells, we propose GasMet, a suite of metrics for statically evaluating the code quality of a smart contract from the gas consumption perspective. An experiment involving 2,186 smart contracts demonstrates that the proposed metrics have direct associations with deployment costs. The metrics in our suite can be used for more easily identifying source code segments that need optimizations.

Open access
3 source records
Blockchain Technology Applications and Security
Mobile Crowdsensing and Crowdsourcing
Advanced Malware Detection Techniques
Original source
Aug 11, 2020·Sensors
12 cites
Enhancing Border Gateway Protocol Security Using Public Blockchain

Lukas Mastilak, Marek Galinski, Pavol Helebrandt, Ivan Kotuliak · 5 authors

Communication on the Internet consisting of a massive number of Autonomous Systems (AS) depends on routing based on Border Gateway Protocol (BGP). Routers generally trust the veracity of information in BGP updates from their neighbors, as with many other routing protocols. However, this trust leaves the whole system vulnerable to multiple attacks, such as BGP hijacking. Several solutions have been proposed to increase the security of BGP routing protocol, most based on centralized Public Key Infrastructure, but their adoption has been relatively slow. Additionally, these solutions are open to attack on this centralized system. Decentralized alternatives utilizing blockchain to validate BGP updates have recently been proposed. The distributed nature of blockchain and its trustless environment increase the overall system security and conform to the distributed character of the BGP. All of the techniques based on blockchain concentrate on inspecting incoming BGP updates only. In this paper, we improve on these by modifying an existing architecture for the management of network devices. The original architecture adopted a private blockchain implementation of HyperLedger. On the other hand, we use the public blockchain Ethereum, more specifically the Ropsten testing environment. Our solution provides a module design for the management of AS border routers. It enables verification of the prefixes even before any router sends BGP updates announcing them. Thus, we eliminate fraudulent BGP origin announcements from the AS deploying our solution. Furthermore, blockchain provides storage options for configurations of edge routers and keeps the irrefutable history of all changes. We can analyze router settings history to detect whether the router advertised incorrect information, when and for how long.

Open access
Blockchain Technology Applications and Security
Internet Traffic Analysis and Secure E-voting
Network Security and Intrusion Detection
Original source
Aug 10, 2020
2 cites
BlockMed: Blockchain-based Electronic Consent Management for Secure and Privacy-Protected Healthcare Interoperability (Preprint)

Arghya Kusum Das, Ajanta Das

<sec> <title>BACKGROUND</title> An electronic consent management system can improve the care service significantly by balancing the risks to patient privacy with the benefits of health information exchange and interoperability. Patients leave their health information on multiple providers’ silo. A holistic report and privacy-preserved analysis can help to expedite several medical services including both personal- and community-care. Furthermore, access to consent-based, anonymous health records can accelerate innovation in health services and researches. </sec> <sec> <title>OBJECTIVE</title> We propose BlockMed, a proof-of-concept (POC) for a novel, cost-effective e-consent management system. Given proper consent, BlockMed can query the patient’s information fractured over multiple healthcare-providers’ silo make it available to the patient. At the same time, BlockMed also enables privacy-preserved data analysis by third-party service providers in the same system. Leveraging the unique and anonymous Ethereum id, BlockMed masks out the patient’s original identification in the provider’s secured local silo and abstract away any complication caused by changes in the identification information on multiple silos. </sec> <sec> <title>METHODS</title> The core functionalities of BlockMed are developed with a set of smart contracts on Ethereum blockchain. To develop those smart contracts, we have divided the potential users into three different groups such as, patient, provider, and third-party analyzer. Users are identified by their anonymous Ethereum id and need to sign the consent to access healthcare data. After signing, BlockMed can automatically initiate the queries to fetch data from providers’ data warehouse, enables analysis on any third-party service provider’s infrastructure if required, and finally, presents a report to the intended users including the patient. The signed consents stay on Ethereum forever leaving a permanent audit trail to uphold the integrity of the system. </sec> <sec> <title>RESULTS</title> We evaluated our system in terms of its functionality and cost. Our decentralized application (DApp) can not only query the data from multiple providers' silo but also enable third-party report generation with proper consent and privacy. Masking out the actual patient identification information under anonymous Ethereum ID our DApp can operate irrespective of geographical boundaries. Our cost analysis shows that the adoption of decentralized blockchain-based technology can avoid huge amount of capital investment required for similar services using centralized infrastructure such as AWS cloud. </sec> <sec> <title>CONCLUSIONS</title> Many prior studies have already confirmed that blockchain can improve and expedite data sharing among different providers. Our POC, BlockMed takes it to one step ahead where the data analysis is also integrated. We prove the efficacy of BlockMed by evaluating its functionalities qualitatively as well as its comparing its cost with an alternative cloud-based architecture. </sec>

Open access
Blockchain Technology Applications and Security
Original source
Aug 10, 2020·IEEE Internet of Things Journal
32 cites
Secure Communication for Multiquadrotor Networks Using Ethereum Blockchain

Pramod Abichandani, Deepan Lobo, Smit Kabrawala, William A. McIntyre

Ethereum blockchain is a powerful, open-source technology for creating decentralized and secure information sharing systems. The main contribution of this article is the experimental validation of an Ethereum blockchain-based software and hardware architecture that enables secure communication for multiple small unmanned aerial vehicles (sUAVs). The experiments involved three DJI M100 quadrotors that shared images captured during flight based on smart contracts created using Ethereum’s Turing complete programming language. The smart contract was designed so that only the intended recipient sUAV could access a specific image. The effect of image size, difficulty level, and consensus algorithms on image transfer times during flight are noted and point to the feasibility of this system in practical missions. The effects of wireless network disruptions on the Ethereum network are documented. The fully documented smart contract code is open sourced to assist readers in quick prototyping. As efforts for decentralization and security of multirobot systems continue to grow, the system architecture and implementation detailed here may serve as a guide for future research.

Open access
Blockchain Technology Applications and Security
UAV Applications and Optimization
Original source
Aug 9, 2020·International Journal of Finance & Economics
39 cites
A network analysis of electricity demand and the cryptocurrency markets

David Iheke Okorie

Abstract This article examines the connectedness and information spillover in the Electricity‐Crypto Network (ECN) system. The Bitcoin and Ethereum markets are studied due to the level of electricity demand for active trading and mining in the three leading crypto mining economies (United States, China, and Japan). Among other findings, the leading net transmitter of information is the return of the Bitcoin market while the demand for electricity in the U.S. and Japan are the leading net information receivers in the ECN system. In a nutshell, the return and trading volumes of the cryptocurrency markets are net information transmitters while the markets' volatility and the demand for electricity in the U.S., China, and Japan are net information receivers in the system. As a policy relevance, given the favourable developments in these crypto markets, greener sources of electrical energy are expedient to mitigate emissions while mining these coins. This will reduce the impact of human activities on the climate.

Market Dynamics and Volatility
Blockchain Technology Applications and Security
Energy, Environment, and Transportation Policies
Original source
Aug 9, 2020·Blockchain Research and Applications
13 cites
Security checklists for Ethereum smart contract development: patterns and best practices

Lodovica Marchesi, Michele Marchesi, Livio Pompianu, Roberto Tonelli

Context: Smart contracts and DApps are becoming increasingly important and widespread. DApps are often business-critical, and strong security guarantees must be ensured. However, developing safe and reliable smart contracts remains a challenging task. Despite growing literature, simple and actionable tools to address security issues are still lacking. Objective: This study identifies design patterns and best practices for DApp security. We categorize them into twelve critical areas based on their security goals and map them to the architecture of decentralized applications. For each item, we define concrete actions to support secure implementation. These are further structured into three security assurance checklists. Method: We analyze existing literature and manually review 224 security items, consolidating duplicates and harmonizing terminology. This process results in 84 unique items, divided into 36 design patterns and 48 best practices, further grouped into 12 categories. We also map the items into three checklists based on the development phase of DApp lifecycle. Finally, for each pattern and practice, we derive 374 actionable security tasks to guide secure development. Results: To the best of our knowledge, this is the most comprehensive and structured collection of DApp security items to date. The proposed framework and checklists help developers ensure the consistent and complete application of secure design principles. Conclusion: Focusing on Ethereum and Solidity, we present a comprehensive framework for improving DApp security. Our work supports ongoing efforts to reduce vulnerabilities in decentralized applications and provides developers with practical tools to build safer, more reliable systems.

Open access
4 source records
Blockchain Technology Applications and Security
Advanced Malware Detection Techniques
Cloud Data Security Solutions
Original source