Purpose This paper aims to examine the risks associated with smart contracts, a disruptive financial technology (FinTech) innovation, and assesses how in the future they could threaten the integrity of the global financial system. Design/methodology/approach A qualitative approach is used to identify risk factors related to the use of new financial innovations, by examining how over-the-counter (OTC) derivatives contributed to the Global Financial Crisis (GFC) which occurred during 2007 and 2008. Based on this analysis, the potential for similar concerns with smart contracts are evaluated, drawing on the failure of The DAO on the Ethereum blockchain, which involved the loss of over $60m of digital currency. Findings Extensive use of bilateral agreements, complexity and lack of standardization, lack of transparency, misuse and speed of contagion were factors that contributed to the GFC that could also become material concerns for smart contract technology as its adoption grows. These concerns, combined with other contextual factors, such as the risk of defects in smart contracts and cyberattacks, could lead to potential destabilization of the broader financial system. Practical implications The paper’s findings provide insights to help make the design, management and monitoring of smart contract technology more robust. They also provide guidance for key stakeholders on proactive steps that can be taken with smart contract technology to avoid repeating the types of oversights that contributed to the GFC. Originality/value This paper draws attention to the risks associated with the adoption of disruptive FinTech. It also suggests steps that regulators and other key stakeholders can take to help mitigate those risks.
An educational institute demands significant computational resources for which it mostly relies on centralized servers, networks and storage facilities. Currently these systems are built around the centralized model which exposes it to risks of data breach, low fault tolerance and the numerous pitfalls of a centralized system. Furthermore, the maintenance of these systems incur significant costs for the institute. The purpose of this research is to introduce a decentralized model of computational system built on blockchain for educational institutions which can mitigate the several drawbacks of a centralized system and further explore the possibilities of introducing a cryptocurrency within the network of the institute. This model proposes to utilize the computational power of devices of the members of the institute by allowing them to be participant nodes in the network. Using the Ethereum blockchain, this study proposes a Smart Contract based system and introduces a cryptocurrency to incentivize the participants of the network.
Investigation of the security of the Ethereum Ropsten test network in connection with the Echosafe application used to record verbal contracts developed by Blocksafe Kft
Open access
Hungarian Social, Economic and Educational Studies
Nghia Duong‐Trung, Ha Xuan Son, Hai Trieu Le, Tan Tai Phan
In this paper, we propose a patient-centric care system based on a smart contract mechanism which is an enhancement to Blockchain technologies. The health records are controlled by the patients, it means the patients could choose and share what kind of information related to their health history to the clinics even the sensitive information. The secure information mechanism and e.ective technical infrastructures to enhance care coordination of individuals and communities are achieved by using Smart Contract which is implemented on Hyperledger Fabric and Ethereum Blockchain. Six algorithms were utilized for interacting data between the components of a Patient-centered healthcare system: createData(), query-Data(), get.eryHistory(), createPatientInformation() / createMedicalRecord() / createDrugInformation() / createHospitalFees() and modifyPatientInformation() / modifyMedicalRecord() / modifyDrug-Information() / modifyHospitalFees(). The simulation results show that the healthcare system and record resources consumption by the aforementioned six algorithms, in terms of execution speed and memory capacity that are allocated for each function at the execution time ranges from 1s.
In recent years, vulnerabilities of smart contracts have frequently break out. In particular, integer overflow of smart contracts, a high-risk vulnerability, has caused huge financial losses. However, most tools currently fail to detect integer overflow in smart contracts. In this paper, we summarize 11 types of integer overflow features for Solidity smart contracts in Ethereum and abstractly define 83 corresponding XPath patterns. And we design an extensible static analysis tool to detect common integer overflow vulnerabilities of Solidity smart contracts in Ethereum through the defined XPath patterns. To evaluate our tool, we tested 7,000 verified Solidity smart contracts and found that there were 430 smart contracts with vulnerabilities of integer overflow. Experimental results show that there are still high-risk vulnerabilities of integer overflow in verified smart contracts.
The challenge of automatically determining the correctness of test executions is referred to as the test oracle problem and is one of the key remaining issues for automated testing. The goal in this paper is to solve the test oracle problem in a way that is general, scalable and accurate. To achieve this, we use supervised learning over test execution traces. We label a small fraction of the execution traces with their verdict of pass or fail. We use the labelled traces to train a neural network (NN) model to learn to distinguish runtime patterns for passing versus failing executions for a given program. Our approach for building this NN model involves the following steps, 1. Instrument the program to record execution traces as sequences of method invocations and global state, 2. Label a small fraction of the execution traces with their verdicts, 3. Designing a NN component that embeds information in execution traces to fixed length vectors, 4. Design a NN model that uses the trace information for classification, 5. Evaluate the inferred classification model on unseen execution traces from the program. We evaluate our approach using case studies from different application domains: 1. Module from Ethereum Blockchain, 2. Module from PyTorch deep learning framework, 3. Microsoft SEAL encryption library components, 4. Sed stream editor, 5. Value pointer library and 6. Nine network protocols from Linux packet identifier, L7-Filter. We found the classification models for all subject programs resulted in high precision, recall and specificity, over 95%, while only training with an average 9% of the total traces. Our experiments show that the proposed neural network model is highly effective as a test oracle and is able to learn runtime patterns to distinguish passing and failing test executions for systems and tests from different application domains.
Vasilios Mavroudis, Karl Wüst, Aritra Dhar, Kari Kostiainen · 5 authors
Permissionless blockchains offer many advantages but also have significant limitations including high latency. This prevents their use in important scenarios such as retail payments, where merchants should approve payments fast. Prior works have attempted to mitigate this problem by moving transactions off the chain. However, such Layer-2 solutions have their own problems: payment channels require a separate deposit towards each merchant and thus significant locked-in funds from customers; payment hubs require very large operator deposits that depend on the number of customers; and side-chains require trusted validators. In this paper, we propose Snappy, a novel solution that enables recipients, like merchants, to safely accept fast payments. In Snappy, all payments are on the chain, while small customer collaterals and moderate merchant collaterals act as payment guarantees. Besides receiving payments, merchants also act as statekeepers who collectively track and approve incoming payments using majority voting. In case of a double-spending attack, the victim merchant can recover lost funds either from the collateral of the malicious customer or a colluding statekeeper (merchant). Snappy overcomes the main problems of previous solutions: a single customer collateral can be used to shop with many merchants; merchant collaterals are independent of the number of customers; and validators do not have to be trusted. Our Ethereum prototype shows that safe, fast (<2 seconds) and cheap payments are possible on existing blockchains.
Cloud auctions provide cost-effective strategies for cloud VM allocation. Most existing cloud auctions simply assume that the auctioneer is trustable, and thus the fairness of auctions can be easily achieved. However, in fact, such a trustable auctioneer may not exist, and the fairness is non-trivial to guarantee. In this work, for the first time, we propose a decentralized cloud VM auction and trade framework based on blockchain. We realize both auction fairness and trade fairness among participants (e.g., cloud provider and cloud users) in this system, which guarantees the interest of each party will not suffer any loss as long as it follows the protocol. Furthermore, we implement our system through the local blockchain and Ethereum official test blockchain, carry out experimental simulations, and demonstrate the feasibility of our system.
The smart factory is a representative element reshaping conventional computer-aided industry to data-driven smart industry, while it is nontrivial to achieve cost effectiveness, reliability, mobility, and scalability of smart industrial systems. Data-driven industrial systems mainly rely on sensory data collected from statically deployed sensors. However, the spatial coverage of industrial sensor networks is constrained due to the high deployment and maintenance cost. Recently, mobile crowd sensing (MCS) has become a new sensing paradigm owing to its merits, such as cost effectiveness, mobility, and scalability. Nevertheless, traditional MCS systems are vulnerable to malicious attacks and single point of failure due to the centralized architecture. To this end, in this article we integrate MCS with industrial systems without introducing any additional dedicated devices. To overcome the drawbacks of traditional MCS systems, we propose a blockchain-based MCS system (BMCS). In particular, we exploit miners to verify the sensory data and design a dynamic reward ranking incentive mechanism to mitigate the imbalance of multiple sensing tasks. Meanwhile, we also develop a sensory data quality detection scheme to identify and mitigate the data anomaly. We implement a prototype of the BMCS on top of Ethereum and conduct extensive experiments on a realistic factory workroom. Both experimental results and security analysis demonstrate that the BMCS can secure industrial systems and improve the system reliability.
Yuanyuan Zhang, Stephen Chan, Jeffrey Chu, Hana Sulieman
The market for cryptocurrencies has experienced extremely turbulent conditions in recent times, and we can clearly identify strong bull and bear market phenomena over the past year. In this paper, we utilise algorithms for detecting turnings points to identify both bull and bear phases in high-frequency markets for the three largest cryptocurrencies of Bitcoin, Ethereum, and Litecoin. We also examine the market efficiency and liquidity of the selected cryptocurrencies during these periods using high-frequency data. Our findings show that the hourly returns of the three cryptocurrencies during a bull market indicate market efficiency when using the detrended-fluctuation-analysis (DFA) method to analyse the Hurst exponent with a rolling window. However, when conditions turn and there is a bear-market period, we see signs of a more inefficient market. Furthermore, our results indicated differences between the cryptocurrencies in terms of their liquidity during the two market states. Moving from a bull to a bear market, Ethereum and Litecoin appear to become more illiquid, as opposed to Bitcoin, which appears to become more liquid. The motivation to study the high-frequency cryptocurrency market came from the increasing availability of higher-frequency cryptocurrency-pricing data. However, it also comes from a movement towards higher-frequency trading of cryptocurrency. In addition, the efficiency of cryptocurrency markets relates not only to whether prices are predictable and arbitrage opportunities exist, but, more widely, to topics such as testing the profitability of trading strategies and determining the maturity of cryptocurrency markets.
Blockchain is evolving to be a secure and reliable platform for secure data sharing in application areas such as the financial sector, supply chain management, food industry, energy sector, internet of things and healthcare. In this paper, we review existing literature and applications available for the healthcare system using blockchain technology. Besides, this work also proposes multiple workflows involved in the healthcare ecosystem using blockchain technology for better data management. Different medical workflows have been designed and implemented using the ethereum blockchain platform which involves complex medical procedures like surgery and clinical trials. This also includes accessing and managing a large amount of medical data. Within the implementation of the workflows of the medical smart contract system for healthcare management, the associated cost has been estimated for this system in terms of a feasibility study which has been comprehensively presented in this paper. This work would facilitate multiple stakeholders who are involved within the medical system to deliver better healthcare services and optimize cost.
Sri Aravinda Krishnan Thyagarajan, Adithya Bhat, Bernardo Magri, Daniel Tschudi · 5 authors
Although blockchains aim for immutability as their core feature, several instances have exposed the harms with perfect immutability. The permanence of illicit content inserted in Bitcoin poses a challenge to law enforcement agencies like Interpol, and millions of dollars are lost in buggy smart contracts in Ethereum. A line of research then spawned on Redactable blockchains with the aim of solving the problem of redacting illicit contents from both permissioned and permissionless blockchains. However, all the existing proposals follow the build-new-chain approach for redactions, and cannot be integrated with existing systems like Bitcoin and Ethereum. We present Reparo, a generic protocol that acts as a publicly verifiable layer on top of any blockchain to perform repairs, ranging from fixing buggy contracts to removing illicit contents from the chain. Reparo facilitates additional functionalities for blockchains while maintaining the same provable security guarantee; thus, Reparo can be integrated with existing blockchains and start performing repairs on the pre-existent data. Any system user may propose a repair and a deliberation process ensues resulting in a decision that complies with the repair policy of the chain and is publicly verifiable. Our Reparo layer can be easily tailored to different consensus requirements, does not require heavy cryptographic machinery and can, therefore, be efficiently instantiated in any permission-ed or -less setting. We demonstrate it by giving efficient instantiations of Reparo on top of Ethereum (with PoS and PoW), Bitcoin, and Cardano. Moreover, we evaluate Reparo with Ethereum mainnet and show that the cost of fixing several prominent smart contract bugs is almost negligible. For instance, the cost of repairing the prominent Parity Multisig wallet bug with Reparo is as low as 0.000000018% of the Ethers that can be retrieved after the fix.
We study the design of self-enforcing mechanisms that do not depend on trusted third parties (e.g., courts, trusted mechanism designers) or long-term relationships. Instead, we leverage blockchain-based smart contracts. We develop the digital court, a smart contract designed to punish agents who violate agreements, replacing one of the roles of legal enforcement. Our digital court enables the execution of general agreements while maintaining the confidentiality of agreement details, even when deployed on public blockchains. With existing smart contract platforms (e.g., Ethereum), our approach is readily available in practice. Our results demonstrate that, if misused, smart contracts could facilitate illegal agreements.
This bachelor thesis pursues blockchain technology, smart contracts and use possibilities of these technologies particularly in e-business field. In theoretical part, there will be introduced blockchain technology, its functionality and features, furthermore, there will be introduced smart contracts technology, its importance for Ethereum cryptocurrency, and use of all these technologies in e-business field. The practical part of this thesis will be concerned about creating our own blockchain, based on Ethereum platform, and afterwards implementation of our very own smart contract will happen. In the final phase of this thesis, there will be interpretation of overall results.
Central Bank Digital Currencies (CBDCs) have captured the attention of world leaders. The current conversation is dominated by high-level motivations like the efficiency benefits of a cashless society. This discourse neglects the potential use of CBDC data for new analytics capabilities. This thesis makes three main contributions to that end. First, it identifies and explores the inherent challenges of analyzing blockchain data (as a proxy for future CDBC data), making future design recommendations where possible. Second, it develops a novel technique to extract useful sector-based macro-economic data from pseudonymous transaction data, using the Ethereum blockchain as a case study. This also enables a novel breakdown of the Ethereum ecosystem by actor type. Third, it unearths evidence new insights about the public blockchain ecosystem, for example that Ethereum users are becoming more sophisticated over time and that Initial Coin Offerings (ICOs) may have caused the 2018 cryptocurrency bubble.
This thesis examines methods which could be used for developing MMORPG games so that there is no single entity that could arbitrarily control game mechanics, virtual assets or other game aspects. The theoretical part systematically analyzes the usual aspects of MMORPG games, then the principles of decentralized cryptocurrencies are presented, and one of them, Ethereum, is analyzed in more detail. Based on this theoretical knowledge, methods are proposed on how to use Ethereum to implement the identified aspects of MMORPG games, and the restrictions which must be imposed on these aspects are recognized. The practical part then introduces a specific implementation of MMORPG game on Ethereum, which demonstrates the above methods. In conclusion, the chosen approach is compared to the games with a common client-server architecture, especially in terms of complexity and gaming costs. 1
991012879763303412 HKUST Electronic Theses Coverage-directed differential testing of EVM implementations by Hang Xu thesis 2020 x, 37 pages : illustrations ; 30 cm Ethereum virtual machine(EVM) is the heart of the Ethereum infrastructure and functions as the runtime environment for…Read more ›
In efforts to meet the targets of carbon emissions reduction in power systems, policy makers formulate measures for facilitating the integration of renewable energy sources and demand side carbon mitigation. Smart grid provides an opportunity for bidirectional communication among policy makers, generators and consumers. With the help of smart meters, increasing number of consumers is able to produce, store, and consume energy, giving them the new role of prosumers. This thesis aims to address how smart grid enables prosumers to be appropriately integrated into energy markets for decarbonising power systems. \n \nThis thesis firstly proposes a Stackelberg game-theoretic model for dynamic negotiation of policy measures and determining optimal power profiles of generators and consumers in day-ahead market. Simulation results show that the proposed model is capable of saving electricity bills, reducing carbon emissions, and increasing the penetration of renewable energy sources. Secondly, a data-driven prosumer-centric energy scheduling tool is developed by using learning approaches to reduce computational complexity from model-based optimisation. This scheduling tool exploits convolutional neural networks to extract prosumption patterns, and uses scenarios to analyse possible variations of uncertainties caused by the intermittency of renewable energy sources and flexible demand. Case studies confirm that the proposed scheduling tool can accurately predict optimal scheduling decisions under various system scales and uncertain scenarios. Thirdly, a blockchain-based peer-to-peer trading framework is designed to trade energy and carbon allowance. The bidding/selling prices of individual prosumers can directly incentivise the reshaping of prosumption behaviours. Case studies demonstrate the execution of smart contract on the Ethereum blockchain and testify that the proposed trading framework outperforms the centralised trading and aggregator-based trading in terms of regional energy balance and reducing carbon emissions caused by long-distance transmissions.
Information security incident under-reporting is unambiguously a business problem, as identified by a variety of sources, such as ENISA (2012), Symantec (2016), Newman (2018) and more. This research project identified the underlying issues that cause this problem and proposed a solution, in the form of an innovative artefact, which confronts a number of these issues. This research project was conducted according to the requirements of the Design Science Research Methodology (DSRM) by Peffers et al (2007). The research question set at the beginning of this research project, probed the feasible formation of an incident reporting solution, which would increase the motivational level of users towards the reporting of incidents, by utilizing the positive features offered by existing solutions, on one hand, but also by providing added value to the users, on the other. The comprehensive literature review chapter set the stage, and identified the reasons for incident underreporting, while also evaluating the existing solutions and determining their advantages and disadvantages. The objectives of the proposed artefact were then set, and the artefact was designed and developed. The output of this development endeavour is “IRDA”, the first decentralized incident reporting application (DApp), built on “Quorum”, a permissioned blockchain implementation of Ethereum. Its effectiveness was demonstrated, when six organizations accepted to use the developed artefact and performed a series of pre-defined actions, in order to confirm the platform’s intended functionality. The platform was also evaluated using Venable et al’s (2012) evaluation framework for DSR projects. This research project contributes to knowledge in various ways. It investigates blockchain and incident reporting, two domains which have not been extensively examined and the available literature is rather limited. Furthermore, it also identifies, compares, and evaluates the conventional, reporting platforms, available, up to date. In line with previous findings (e.g Humphrey, 2017), it also confirms the lack of standard taxonomies for information security incidents. This work also contributes by creating a functional, practical artefact in the blockchain domain, a domain where, according to Taylor et al (2019), most studies are either experimental proposals, or theoretical concepts, with limited practicality in solving real-world problems. Through the evaluation activity, and by conducting a series of non-parametric significance tests, it also suggests that IRDA can potentially increase the motivational level of users towards the reporting of incidents. This thesis describes an original attempt in utilizing the newly emergent blockchain technology, and its inherent characteristics, for addressing those concerns which actively contribute to the business problem. To the best of the researcher’s knowledge, there is currently no other solution offering similar benefits to users/organizations for incident reporting purposes. Through the accomplishment of this project’s pre-set objectives, the developed artefact provides a positive answer to the research question. The artefact, featuring increased anonymity, availability, immutability and transparency levels, as well as an overall lower cost, has the potential to increase the motivational level of organizations towards the reporting of incidents, thus improving the currently dismaying statistics of incident under-reporting. The structure of this document follows the flow of activities described in the DSRM by Peffers et al (2007), while also borrowing some elements out of the nominal structure of an empirical research process, including the literature review chapter, the description of the selected research methodology, as well as the “discussion and conclusion” chapter.
Blockchain is a decentralized and public ledger system where people store data of transactions without any centralized party having control. It is a technology that enables data security, transparency, and trust. Since birth in 2008, it has gained extensive popularity in many fields, especially in finance and Information technology. Many technology specialists and leaders often consider blockchain technology as the next fundamental generation of technology. One of the best-known usages of blockchain is cryptographic currencies such as Bitcoin and Ethereum. \n \nNowadays, many implementations of blockchain are widely increasing in different types of applications. This project seeks to explore blockchain technology in the mobile phone environment. The mobile application, called “Fundraising,” was developed and built in the Ethereum blockchain network. The application is allowed to do crowdfunding with the enhanced security features of data integrity and improved trust environment. \n \nIn the project, data of “Fundraising” decentralized mobile application is stored, updated, and retrieved successfully between the Ethereum blockchain network and mobile application. Node js javascript library was used to implement server and front-end mobile applications, and solidity language was used to implement the smart contract for Ethereum blockchain