Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

13,620 papersLast indexed Aug 24, 2026
Search papers

Paper index

13,620 results · page 459 of 568

Clear filters
May 1, 2020
6 cites
Towards Usable Protection Against Honeypots

Christof Ferreira Torres, Mathis Baden, Radu State

The Ethereum blockchain enables the execution of so-called smart contracts. These are programs that facilitate the automated transfer of funds according to a given business logic without the participants requiring to trust one another. However, recently attackers started using smart contracts to lure users into traps by deploying contracts that pretend to give away funds but in fact contain hidden traps. This new type of scam is commonly referred to as honeypots. In this paper, we propose a system that aims to protect users from falling into these traps. The system consists of a plugin for MetaMask and a back-end service that continuously scans the Ethereum blockchain for honeypots. Whenever a user is about to perform a transaction through MetaMask, our plugin sends a request to the back-end and warns the user if the target contract is a honeypot.

Blockchain Technology Applications and Security
Advanced Malware Detection Techniques
Spam and Phishing Detection
Original source
May 1, 2020
21 cites
Replicated state machines without replicated execution

Jonathan Lee, Kirill Nikitin, Srinath Setty

This paper introduces a new approach to reduce end-to-end costs in large-scale replicated systems built under a Byzantine fault model. Specifically, our approach transforms a given replicated state machine (RSM) to another RSM where nodes incur lower costs by delegating state machine execution: an untrusted prover produces succinct cryptographic proofs of correct state transitions along with state changes, which nodes in the transformed RSM verify and apply respectively.To realize our approach, we build Piperine, a system that makes the proof machinery profitable in the context of RSMs. Specifically, Piperine reduces the costs of both proving and verifying the correctness of state machine execution while retaining liveness-a distinctive requirement in the context of RSMs. Our experimental evaluation demonstrates that, for a payment service, employing Piperine is more profitable than naive reexecution of transactions as long as there are > 104nodes. When we apply Piperine to ERC-20 transactions in Ethereum (a real-world RSM with up to 105nodes), it reduces per-transaction costs by 5.4× and network costs by 2.7×.

Open access
Distributed systems and fault tolerance
Blockchain Technology Applications and Security
Advanced Data Storage Technologies
Original source
May 1, 2020
17 cites
Privacy-Preserving Netting in Local Energy Grids

Jacob Eberhardt, Marco Peise, Dong-Ha Kim, Stefan Tai

The production of renewable energies by individual households typically is small-scale and not profitable without public subsidies, yet a critical factor in preventing further global warming. Unlike market-based peer-to-peer trading solutions, which require households to engage in costly peer-to-peer trading activities, we propose a community-based approach where households in a local distribution grid share the energy they produce in a netting process to maximize internal consumption. The technical instantiation of this idea in real-world energy grids comes with several challenges. Households within a community do not necessarily trust each other or electric utilities. Furthermore, energy consumption data is highly sensitive and must be protected. Further idiosyncrasies of national energy markets, regulatory frameworks, and current grid infrastructure exist. Addressing all these challenges, we propose a blockchain-based system that leverages zero-knowledge off-chain computations to facilitate automated energy sharing within a community in a trustless and privacy-preserving way. We provide a proof- of-concept implementation using the ZoKrates framework for verifiable off-chain computations and the Ethereum Blockchain. To support our claims, we provide evaluation results obtained in the context of a major German national research project on blockchain-based energy networks.

Blockchain Technology Applications and Security
Smart Grid Security and Resilience
Smart Grid Energy Management
Original source
May 1, 2020
14 cites
Blockchain-based Information Sharing between Smart Vehicles for Safe Driving

Keonhyeong Kim, Taehyoung Kim, Im Y. Jung

Smart vehicles determine and take various actions with state information with little or no human intervention. More information can be gathered when they can connect to and communicate with other vehicles and their environments, improving safe self-driving. This paper proposes a blockchain-based information sharing that verifies the shared data and the sharing process using a public blockchain, Ethereum. To protect the privacy of the shared information, cryptography and secure protocols are additionally applied to the blockchain technology.

Blockchain Technology Applications and Security
Vehicular Ad Hoc Networks (VANETs)
IoT and Edge/Fog Computing
Original source
May 1, 2020
28 cites
Automating GDPR Compliance using Policy Integrated Blockchain

Abhishek Mahindrakar, Karuna Pande Joshi

Data Protection regulations, like GDPR, mandate security controls to secure Personal Identifiable Information (PII) of the users which they share with service providers. With the volume of shared data reaching exascale proportions, it is challenging to ensure GDPR compliance in real time. We propose a novel approach that integrates GDPR Ontology with Blockchain to facilitate real time automated data compliance. Our framework ensures data operation is allowed only when validated by data privacy policies in compliance with privacy rules in GDPR. When a valid transaction takes place the PII data is automatically stored off-chain in a database. Our system, built using Semantic Web and Ethereum Blockchain, includes an access-control system that enforces data privacy policy when data is shared with third parties.

Open access
Blockchain Technology Applications and Security
Privacy, Security, and Data Protection
Privacy-Preserving Technologies in Data
Original source
May 1, 2020
64 cites
A Light Blockchain-Powered Privacy-Preserving Organization Scheme for Ride Sharing Services

Mohamed Baza, Mohamed Mahmoud, Gautam Srivastava, Waleed Alasmary · 5 authors

Ride-sharing is a service that enables drivers to share their trips with other riders, contributing to improving traffic congestion as well as assist in reducing Carbon Dioxide (CO2) emission and fuel consumption. It has come to the forefront in recent years as a Green service in large cities. However, the majority of existing ride-sharing services rely on a central third party, which makes them subject to a single point of failure and privacy disclosure concerns by both internal and external attackers. Moreover, they are vulnerable to distributed denial of service (DDoS) and Sybil attacks due to malicious users. There is also high service fees paid to the ride-sharing service provider. In this paper, we propose to decentralize ride-sharing services based on a public Blockchain. Our scheme enables drivers to propose ride-sharing services without relying on a trusted third party. To preserve location privacy, riders send cloaked ride requests to hide their exact pick-up/drop-off locations, and departure/arrival dates. Then, by using an off-line matching technique, drivers sends their offers encrypted to ensure data confidentiality. Upon receiving the ride-offers, the rider can find a ride match using some heuristics as well as the bid price included in the offer. To preserve anonymity, riders/drivers use pseudonyms that change per trip to ensure unlinkabilty. We envision the application of this technology in Green Internet of Things connected smart cities, where ride sharing services are common. Finally, we implement our scheme and deploy it in a test net of Ethereum. The experimental results show the applicability of our protocol.

Blockchain Technology Applications and Security
Transportation and Mobility Innovations
Sharing Economy and Platforms
Original source
May 1, 2020·Intertax
4 cites
VAT Treatment of Cryptocurrency Intermediation Services

Tina Ehrke-Rabel, Lily Zechner

The bitcoin blockchain was construed as a self-regulating system that would eliminate financial institutions serving as trusted third parties. Instead however, various new intermediaries emerged carrying out economic activities related to the blockchain. The most common 'gateways' are cryptocurrency exchange platforms and wallet providers. Moreover, bitcoin's main purpose has shifted from means of payment to speculation. In this article, the authors assess how the mentioned gateways are to be treated for value added tax purposes and challenge the Hedqvist-decision of the European Court of Justice against the backdrop of how bitcoins are being used today. Bitcoin, Ethereum, blockchain, cryptocurrency, token, exchange platform, wallet provider, intermediation, agent, undisclosed agent

Blockchain Technology Applications and Security
Original source
May 1, 2020
19 cites
Monetization using Blockchains for IoT Data Marketplace

Wiem Badreddine, Kaiwen Zhang, Chamseddine Talhi

The number of Internet of Things devices is growing dramatically, generating a huge amount of data which is becoming a valuable asset for data analysts. This trend culminates towards the creation of an IoT data marketplace, where streams of data from heterogeneous sources are sent in real time to various data consumers and are metered for monetization purposes. Publish/subscribe systems, such as Message Queuing Telemetry Transport (MQTT), are a promising solution to act as a transport layer for real-time data streams in a decoupled and large scale manner. However, pub/sub systems lack two key properties for an IoT data marketplace: (1) it does not provide any monetization logic; (2) it assumes that the pub/sub brokers are trusted entities, which is not the case in a decentralized or federated marketplace setting. In this paper, we address these issues using a reliable and transparent monetization system based on Distributed Ledger Technology (DLT) and smart contracts. We propose three monetization solutions and demonstrate the trade-off between the overhead of tracking IoT data on a blockchain vs. the accuracy of the monetization for data producers and consumers. In particular, we provide a Bloom filter-based solution for efficient verification of data exchange. We implement our system using Ethereum and Solidity and evaluate with respect to contract gas cost.

Blockchain Technology Applications and Security
Caching and Content Delivery
Peer-to-Peer Network Technologies
Original source
May 1, 2020
37 cites
Blockchain-based e-Tendering System

Dhawal Mali, Divya Mogaveera, Parth Kitawat, Mohd. Jawwad

The tendering process is generally used by governments and companies to procure goods or services from manufacturing companies or service providers. However, e-tendering being the mostly used procurement method, there are various security implications present. Blockchain technology can be used to solve these security implications as it heavily focuses on the decentralization of information and is secured by encryption integrated with undeniable block-based architecture for transaction management. In this paper, how smart contracts (based on ethereum blockchain) can be employed to design a distributed e-tendering system is explored. The project is divided into four sections, 1. Tender creation and publishing process, 2.Bidding process on the tender, 3.Evaluation, and Negotiation of the bid and 4.Selection of the Winning bid. Different algorithms are used to implement each process. The security and audibility challenges are evaluated and compared to the current tendering process. The main aim of this paper is to implement a fair, transparent and open tendering scheme.

Blockchain Technology Applications and Security
FinTech, Crowdfunding, Digital Finance
Original source
May 1, 2020·arXiv
3 cites
Context-based Smart Contracts For Appendable-block Blockchains

Henry C. Nunes, Roben Castagna Lunardi, Avelin F. Zorzo, Regio A. Michelin · 5 authors

Currently, blockchain proposals are being adopted to solve security issues, such as data integrity, resilience, and non-repudiation. To improve certain aspects, e.g., energy consumption and latency, of traditional blockchains, different architectures, algorithms, and data management methods have been recently proposed. For example, appendable-block blockchain uses a different data structure designed to reduce latency in block and transaction insertion. It is especially applicable in domains such as Internet of Things (IoT), where both latency and energy are key concerns. However, the lack of some features available to other blockchains, such as Smart Contracts, limits the application of this model. To solve this, in this work, we propose the use of Smart Contracts in appendable-block blockchain through a new model called context-based appendable-block blockchain. This model also allows the execution of multiple smart contracts in parallel, featuring high performance in parallel computing scenarios. Furthermore, we present an implementation for the context-based appendable-block blockchain using an Ethereum Virtual Machine (EVM). Finally, we execute this implementation in four different testbed. The results demonstrated a performance improvement for parallel processing of smart contracts when using the proposed model.

Open access
2 source records
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Caching and Content Delivery
Original source
May 1, 2020
0 cites
Wallet Contracts on Ethereum

Monika di Angelo, Gernot Salzer

On the blockchain, cryptocurrencies play a role similar to cash, while cryptographic tokens are a universal tool for handling rights and assets. Software wallets interact with blockchains in general and with smart contracts (on-chain programs) in particular. Some wallets are realized (partly) as smart contracts with the intent to increase trust and security by being transparent and by offering features like daily limits, approvals, multiple signatures, and recovery mechanisms. Ethereum is the most prominent platform for both, tokens and smart contracts, and thus also for wallet contracts. We discuss several methods for identifying wallet contracts in a semi-automatic manner by looking at the deployed bytecodes and their interaction patterns. Furthermore, we differentiate characteristics of wallets in use, and group them into six types.

Open access
Blockchain Technology Applications and Security
Advanced Malware Detection Techniques
Cybercrime and Law Enforcement Studies
Original source
May 1, 2020
467 cites
Flash Boys 2.0: Frontrunning in Decentralized Exchanges, Miner Extractable Value, and Consensus Instability

Philip Daian, Steven Goldfeder, Tyler Kell, Yunqi Li · 8 authors

Blockchains, and specifically smart contracts, have promised to create fair and transparent trading ecosystems.Unfortunately, we show that this promise has not been met. We document and quantify the widespread and rising deployment of arbitrage bots in blockchain systems, specifically in decentralized exchanges (or "DEXes"). Like high-frequency traders on Wall Street, these bots exploit inefficiencies in DEXes, paying high transaction fees and optimizing network latency to frontrun, i.e., anticipate and exploit, ordinary users' DEX trades.We study the breadth of DEX arbitrage bots in a subset of transactions that yield quantifiable revenue to these bots. We also study bots' profit-making strategies, with a focus on blockchain-specific elements. We observe bots engage in what we call priority gas auctions (PGAs), competitively bidding up transaction fees in order to obtain priority ordering, i.e., early block position and execution, for their transactions. PGAs present an interesting and complex new continuous-time, partial-information, game-theoretic model that we formalize and study. We release an interactive web portal, frontrun.me, to provide the community with real-time data on PGAs. We additionally show that high fees paid for priority transaction ordering poses a systemic risk to consensus-layer security. We explain that such fees are just one form of a general phenomenon in DEXes and beyond-what we call miner extractable value (MEV)-that poses concrete, measurable, consensus-layer security risks. We show empirically that MEV poses a realistic threat to Ethereum today. Our work highlights the large, complex risks created by transaction-ordering dependencies in smart contracts and the ways in which traditional forms of financial-market exploitation are adapting to and penetrating blockchain economies.

Open access
Blockchain Technology Applications and Security
Complex Systems and Time Series Analysis
Auction Theory and Applications
Original source
May 1, 2020
9 cites
From Legal Agreements to Blockchain Smart Contracts

Ravi Rahman, Kevin Liu, Lalana Kagal

Complex legal agreements enable many real-world applications, from data sharing systems to financial transactions. However, legal expenses scale with complexity because of the manual processes to draft, revise, and enforce agreements. To reduce such costs, we propose a new framework for lawyers to develop machine readable legal agreements, which are automatically verified and deployed on the Ethereum blockchain. Specifically, our framework introduces domain specific repositories to store human and machine readable legal language, a web interface and Python API to draft legal agreements, correctness checking via formal verification, and a voting system for blockchain based adjudication. Experimental evaluation found that our proposed framework offers an efficient verification system, incurs linear scaling of Ethereum blockchain gas consumption in terms of agreement size, and correctly models 81% of conditions in real-world agreements through the domain specific repositories. These results suggest a practical approach for developing verifiable and blockchain compatible legal agreements.

Blockchain Technology Applications and Security
Original source
May 1, 2020·Office of Scientific and Technical Information (OSTI)
1 cites
The GABLE Report: Garbled Autonomous Bots Leveraging Ethereum

Michael P. Frank, Christopher Cordi, Kasimir Gabert, Carollan Helinski · 8 authors

Simple but mission-critical internet-based applications that require extremely high reliability and availability could potentially benefit from running on robust public programmable blockchain platforms such as Ethereum. Unfortunately, program code running on such blockchains is ordinarily publicly viewable, rendering these platforms unsuitable for applications requiring strict privacy of application code, data, and results. However, might it be possible to encode an application's business logic and data for these platforms in such a way that it becomes impossible for unauthorized parties to infer any meaningful information whatsoever about the semantics of the data, and the operations being performed on that data? In this report, we describe GABLE (Garbled Autonomous Bots Leveraging Ethereum), a system concept developed at Sandia that achieves this security goal in a limited, but still useful range of circumstances. GABLE, uses simple but effective algorithms to permit secure private execution of garbled state machines (and more efficient garbled circuits) on public computing resources. We give an example working implementation for garbled state machines, written using the Python and Solidity programming languages, and outline how our methods can be extended to support a more powerful garbled universal circuit model of computation. The capability embodied by the GABLE, system has significant potential applications, a few of which we discuss in this report.

Open access
2 source records
Blockchain Technology Applications and Security
Distributed systems and fault tolerance
Cloud Computing and Resource Management
Original source
May 1, 2020
19 cites
FlyClient: Super-Light Clients for Cryptocurrencies

Benedikt Bünz, Lucianna Kiffer, Loi Luu, Mahdi Zamani

To validate transactions, cryptocurrencies such as Bitcoin and Ethereum require nodes to verify that a blockchain is valid. This entails downloading and verifying all blocks, taking hours and requiring gigabytes of bandwidth and storage. Hence, clients with limited resources cannot verify transactions independently without trusting full nodes. Bitcoin and Ethereum offer light clients known as simplified payment verification (SPV) clients, that can verify the chain by downloading only the block headers. Unfortunately, the storage and bandwidth requirements of SPV clients still increase linearly with the chain length. For example, as of July 2019, an SPV client in Ethereum needs to download and store about 4 GB of data.Recently, Kiayias et al. proposed a solution known as noninteractive proofs of proof-of-work (NIPoPoW) that allows a light client to download and store only a polylogarithmic number of block headers in expectation. Unfortunately, NIPoPoWs are succinct only as long as no adversary influences the honest chain, and can only be used in chains with fixed block difficulty, contrary to most cryptocurrencies which adjust block difficulty frequently according to the network hashrate.We introduce FlyClient, a novel transaction verification light client for chains of variable difficulty. FlyClient is efficient both asymptotically and practically and requires downloading only a logarithmic number of block headers while storing only a single block header between executions. Using an optimal probabilistic block sampling protocol and Merkle Mountain Range (MMR) commitments, FlyClient overcomes the limitations of NIPoPoWs and generates shorter proofs over all measured parameters. In Ethereum, FlyClient achieves a synchronization proof size of less than 500 KB which is roughly 6,600x smaller than SPV proofs. We finally discuss how FlyClient can be deployed with minimal changes to the existing cryptocurrencies via an uncontentious velvet fork.

Open access
Blockchain Technology Applications and Security
Cloud Data Security Solutions
Privacy-Preserving Technologies in Data
Original source
May 1, 2020
2 cites
Parallel Hash-Mark-Set on the Ethereum Blockchain

Zachary Painter, Pradeep Kumar Gayam, Victor Cook, Damian Dechev

Popular blockchains such as Bitcoin or Ethereum provide a transaction isolation level of READ-COMMITTED. This provides difficulties when state changes many times per block interval. Hash-Mark-Set (HMS) alleviates this problem by enabling READ-UNCOMMITTED transactions for state variables. However, the current HMS implementation relies on a sequential algorithm and is susceptible to redundant calculations. As modern processors rely more heavily on parallel algorithms to leverage multiple cores for speedup, sequential algorithms see less benefit from hardware improvements. This paper proposes a lock-free HMS to make use of thread-safe techniques and other optimizations to improve the performance of the HMS algorithm and reduce the latency of read-uncommitted state variable accesses. In our experiments, the proposed algorithm experiences an average 6.4× increase in performance up to 128 go-routines, and a maximum 11.1× increase.

Distributed systems and fault tolerance
Blockchain Technology Applications and Security
Advanced Data Storage Technologies
Original source
May 1, 2020
26 cites
Smart FIR: Securing e-FIR Data through Blockchain within Smart Cities

Nasir D. Khan, Chrysostomos Chrysostomou, Babar Nazir

Electronic First Information Report (e-FIR) is a basic document filed to the police stations by a victim or someone on his/her behalf when a cognizable offense such as murder, kidnapping, rape, theft, etc. is committed. In the e-FIR database, the offense's record can be compromised due to its centralized nature, and further the intentional registration of false e-FIR can occur. Thus, data integrity and transparency are key concerns in e-FIR database. In this paper, e-FIR data integrity and false registration appended with police stations in a centralized database are addressed via a consensus-based distributed blockchain solution, as an integral part of a smart city environment. Specifically, a smart contract based intelligent framework has been utilized to explore the potential of Ethereum blockchain in providing integrity to e-FIR data stored in a police station's database. Local database is interfaced with Ethereum blockchain using Web3 Remote Procedure Call (RPC) protocol. Multiple simulations have been performed to evaluate the performance of the proposed framework. Our results show a trade-off between different hashing algorithm security level for the offenses data and number of transactions stored in a single block on blockchain ledger.

Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
Internet Traffic Analysis and Secure E-voting
Original source
May 1, 2020·2020 5th International Conference on Computer and Communication Systems (ICCCS)
28 cites
Blockchain-Based IoT Application Using Smart Contracts: Case Study of M2M Autonomous Trading

Xinglin Gong, Erwu Liu, Rui Wang

Blockchain technology can be used to track billions of interconnected devices, enabling secure data exchange and data processing. The decentralized and autonomous ability of the blockchain makes it an ideal solution for Internet of Things(IoT) applications. In this paper, we explore a basic IoT-Blockchain fusion model with four layers which contains different types of IoT devices. Distributed file system is considered in the model to store huge amount of IoT data. Then, a case study for blockchain-based IoT application, a Machine-to-Machine(M2M) autonomous trading system, is proposed on the Ethereum blockchain. We build smart contracts for device registration, data storage, service provision and fair payment, and the proof-of-concept is implemented using two Raspberry Pis to interact with smart contracts. The proposed system verifies that blockchain could improve IoT applications in transparency, traceability and security.

Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
FinTech, Crowdfunding, Digital Finance
Original source
May 1, 2020
3 cites
Smart Contract Vulnerabilities on the Ethereum Blockchain: A Current Perspective

Daniel Connelly

Ethereum is a unique offshoot of blockchain technologies that incorporates the use of what are called smart contracts or DApps -- small-sized programs that orchestrate financial transactions on the Ethereum blockchain. With this fairly new paradigm in blockchain, however, comes a host of security concerns and a track record that reveals a history of losses in the range of millions of dollars. Since Ethereum is a decentralized entity, these concerns are not allayed as they are in typical financial institutions. For example, there is no Federal Deposit Insurance Corporation (FDIC) to back the investors of these contracts from financial loss as there is with bank depositors. Furthermore, there is also no Better Business Bureau (BBB) or Consumer Reports organization to offer any sort of ratings on these contracts. However, there exists a well-known method for verifying a program's integrity; a method called symbolic execution. Such an examination promises to give not only a perspective on the security of Ethereum, but also highlight areas where security experts may need to target to more quickly improve upon the security of this blockchain. This paper proposes a solution to ensuring security and increasing end user confidence -- a digital registry of smart contracts that have security flaws in them. A rating system for contracts is proposed and the capabilities one has with knowledge of these vulnerabilities is examined. This research attempts to give a picture of the current state of security of Ethereum Smart Contracts by employing symbolic analysis on a portion of the Smart Contracts up until approximately the 8.4 millionth block. Vulnerabilities in Smart Contracts may be prevalent and, if they are, a registry for enumerating which ones are can be built and potentially used to easily enumerate them.

Open access
Blockchain Technology Applications and Security
FinTech, Crowdfunding, Digital Finance
Original source
May 1, 2020
5 cites
Profiling of Malicious Users Using Simple Honeypots on the Ethereum Blockchain Network

Kazuki Hara, Teppei Sato, Mitsuyoshi Imamura, Kazumasa Omote

Blockchain is a service operated by a peer-to-peer type distributed network, and protocol control such as JSON-RPC is implemented as the interface for flexibility and operability. However, attacks that use protocol control against vulnerable and unmanaged interfaces have been reported. One of the methods to track cyber attacks on such a malicious user's network service is a honeypot that imitates the service and acquires attacker's behavior information. In this research, focusing on the Ethereum network, the behavior of malicious users is clarified using malicious communication history sent to simple honeypots installed in nine countries, Ethereum network information and darknet arrival packets. By analyzing these, the behavior of attackers and the tendency of requests were elucidated, and primary safety measures were established.

Blockchain Technology Applications and Security
Spam and Phishing Detection
Network Security and Intrusion Detection
Original source
May 1, 2020·2020 IEEE International Conference on Blockchain and Cryptocurrency (ICBC)
54 cites
Domain Specific Language for Smart Contract Development

Maximilian Wöhrer, Uwe Zdun

The notion to digitally articulate, execute, and enforce agreements with smart contracts has become a feasible reality today. Smart contracts have the potential to vastly improve the efficiency and security of traditional contracts through their self-executing autonomy. To realize smart contracts several blockchain-based ecosystems exist. Today a prominent representative is Ethereum. Its programming language Solidity is used to capture and express contractual clauses in the form of code. However, due to the conceptual discrepancy between contractual clauses and corresponding code, it is hard for domain stakeholders to easily understand contracts, and for developers to write code efficiently without errors. Our research addresses these issues by the design and study of a domain-specific smart contract language based on higher level of abstraction that can be automatically transformed to an implementation. In particular, we propose a clause grammar close to natural language, helpful coding abstractions, and the automatic integration of commonly occurring design patterns during code generation. Through these measures, our approach can reduce the design complexity leading to an increased comprehensibility and reduced error susceptibility. Several implementations of exemplary smart contract scenarios, mostly taken from the Solidity documentation, are used to demonstrate the applicability of our approach.

2 source records
Blockchain Technology Applications and Security
Digital Rights Management and Security
Advanced Malware Detection Techniques
Original source
May 1, 2020
92 cites
Semantic Understanding of Smart Contracts: Executable Operational Semantics of Solidity

Jiao Jiao, Shuanglong Kan, Shang‐Wei Lin, David Sanán · 6 authors

Bitcoin has been a popular research topic recently. Ethereum (ETH), a second generation of cryptocurrency, extends Bitcoin's design by offering a Turing-complete programming language called Solidity to develop smart contracts. Smart contracts allow creditable execution of contracts on EVM (Ethereum Virtual Machine) without third parties. Developing correct and secure smart contracts is challenging due to the decentralized computation nature of the blockchain. Buggy smart contracts may lead to huge financial loss. Furthermore, smart contracts are very hard, if not impossible, to patch once they are deployed. Thus, there is a recent surge of interest in analyzing and verifying smart contracts. While most of the existing works either focus on EVM bytecode or translate Solidity smart contracts into programs in intermediate languages, we argue that it is important and necessary to understand and formally define the semantics of Solidity since programmers write and reason about smart contracts at the level of source code. In this work, we develop a formal semantics for Solidity which provides a formal specification of smart contracts to define semantic-level security properties for the high-level verification. Furthermore, the proposed semantics defines correct and secure high-level execution behaviours of smart contracts to reason about compiler bugs and assist developers in writing secure smart contracts.

Open access
Blockchain Technology Applications and Security
Cryptography and Data Security
Security and Verification in Computing
Original source
May 1, 2020
242 cites
VerX: Safety Verification of Smart Contracts

Anton Permenev, Dimitar Dimitrov, Petar Tsankov, Dana Drachsler-Cohen · 5 authors

We present VerX, the first automated verifier able to prove functional properties of Ethereum smart contracts. VerX addresses an important problem as all real-world contracts must satisfy custom functional specifications.VerX is based on a careful combination of three techniques, enabling it to automatically verify temporal properties of infinite- state smart contracts: (i) reduction of temporal property verification to reachability checking, (ii) a new symbolic execution engine for the Ethereum Virtual Machine that is precise and efficient for a practical fragment of Ethereum contracts, and (iii) delayed predicate abstraction which uses symbolic execution during transactions and abstraction at transaction boundaries.Our extensive experimental evaluation on 83 temporal properties and 12 real-world projects, including popular crowdsales and libraries, demonstrates that VerX is practically effective.

Open access
Security and Verification in Computing
Blockchain Technology Applications and Security
Advanced Malware Detection Techniques
Original source
May 1, 2020
26 cites
A Data Science Approach for Detecting Honeypots in Ethereum

Ramiro Daniel Camino, Christof Ferreira Torres, Mathis Baden, Radu State

Ethereum smart contracts have recently drawn a considerable amount of attention from the media, the financial industry and academia. With the increase in popularity, malicious users found new opportunities to profit by deceiving newcomers. Consequently, attackers started luring other attackers into contracts that seem to have exploitable flaws, but that actually contain a complex hidden trap that in the end benefits the contract creator. In the blockchain community, these contracts are known as honeypots. A recent study presented a tool called HONEYBADGER that uses symbolic execution to detect honeypots by analyzing contract bytecode. In this paper, we present a data science detection approach based foremost on the contract transaction behavior. We create a partition of all the possible cases of fund movements between the contract creator, the contract, the transaction sender and other participants. To this end, we add transaction aggregated features, such as the number of transactions and the corresponding mean value and other contract features, for example compilation information and source code length. We find that all aforementioned categories of features contain useful information for the detection of honeypots. Moreover, our approach allows us to detect new, previously undetected honeypots of already known techniques. We furthermore employ our method to test the detection of unknown honeypot techniques by sequentially removing one technique from the training set. We show that our method is capable of discovering the removed honeypot techniques. Finally, we discovered two new techniques that were previously not known.

Blockchain Technology Applications and Security
Spam and Phishing Detection
Crime, Illicit Activities, and Governance
Original source