Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

13,597 papersLast indexed Aug 16, 2026
Search papers

Paper index

13,597 results · page 492 of 567

Clear filters
Oct 1, 2019
9 cites
Transparent E-Voting dApp Based on Waves Blockchain and RIDE Language

Nazim Faour

Since 2004, different research was handling the challenges in the centralized voting systems, e-voting protocols and recently the decentralized voting. Electronic voting puts forward some difficulties regarding the voter anonymity, the secure casting of the votes and to prevent the voting process from fraud. The decentralized property of the blockchain technology will bring new solutions for many of the challenges in the voting research area and it will bring a new security mechanism of safe and transparent voting. In this paper, a broad comparison between ongoing voting systems has studied by analyzing their structure and the drawbacks that should consider in future to improve the whole election process from keeping the privacy of the voter, casting a vote with the possibility to check if it was counted correctly to publishing the results. The result of the paper will give a new approach to extend the target of the election from small scale to large scale despite the fact of Ethereum limitation which can cast five votes per minute on an average. The primary challenge is to find an answer for this question: “how to balance between voter privacy and transparency without breaking the important rule where the voter can proof for a specific candidate that he voted for him in a bribe situation?”.

Internet Traffic Analysis and Secure E-voting
Advanced Steganography and Watermarking Techniques
Blockchain Technology Applications and Security
Original source
Oct 1, 2019
20 cites
PACEX: PAtient-Centric EMR eXchange in Healthcare Systems using Blockchain

Bhavesh Toshniwal, Prashanth Podili, Ravula Jaysimha Reddy, Kotaro Kataoka

Electronic Medical Records (EMRs) contain private and sensitive information of the patients and require distribution across multiple stakeholders for sustained and consistent medical care. EMRs are owned and maintained by hospital systems. So, patients often face difficulties in getting their data shared among different stakeholders. Blockchain provides distributed, transparent, and immutable log of records that benefit the design of healthcare systems. There have been several studies done to use Blockchain technology as a mediation tool for sharing sensitive EMRs between multiple stakeholders in the e-health care system. However, these studies lack the requirement of patients to have full control over their EMR data. This work develops PACEX, PAtient-Centric EMR eXchange, that enables patients to share and have complete control over their data using Blockchain. In PACEX, we develop an easy-to-use patient application that interacts with different hospital systems and handles EMR exchanges with integrity. We developed a proof of concept implementation of PACEX using Ethereum Blockchain and Smart Contracts to achieve access control and maintain a history of record exchanges among different stakeholders. The evaluation results provide the quantitative analysis that gives time estimates for various transactions involved in PACEX and the qualitative analysis that describes the security properties of the system. PACEX achieves essential security requirements such as Authentication, Integrity, Access Control, and Traceability over the EMR data exchange.

Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Cloud Data Security Solutions
Original source
Oct 1, 2019
6 cites
Experiences Designing a Multi-Tier Architecture for a Decentralized Blockchain Application in the Energy Domain

Denis Rangelov, Nikolay Tcholtchev, Philipp Lämmel, Ina Schieferdecker

In recent years the emergence of the Ethereum Blockchain has introduced a new alternative perspective on how web applications can be build. More precisely, the Ethereum Blockchain allows the development of applications, where programming code can be executed in a decentralized manner with no restrictions imposed by a central authority. However, as it is the case with many emerging technologies, there is a fair amount of trade-offs that have to be considered when this technology is used as a platform for implementing decentralized applications. In this work we present two architectural designs for building decentralized applications (DApps) based on the Ethereum Blockchain technology. Within this context, we discuss the inherent strengths and weaknesses of each of the architectural designs as well as the set of challenges that we faced during the development process.

Open access
Caching and Content Delivery
Peer-to-Peer Network Technologies
Blockchain Technology Applications and Security
Original source
Oct 1, 2019·Open MIND
13 cites
TradeMap: A FINMA-compliant Anonymous Management of an End-2-end Trading Market Place

Sina Rafati Niya, Sebastian Allemann, Arik Gabay, Burkhard Stiller

Data leaks and privacy scandals have been a growing concern of the last decade. While most traditional, i.e., centralized, online platforms require users to register with their personal data, they potentially expose the user's identity and data to be used for unintended purposes. This work proposes TradeMap as an integrated architecture, designing and enabling an online end-to-end (e2e) trading market place, while supporting anonymous management features. TradeMap addresses the Swiss Financial Market Supervisory Authority (FINMA) regulations by designing a FINMA-complaint Know Your Customer (KYC) platform. Additionally, TradeMap is based on blockchains and employs Ethereum Smart Contracts (SC). Thus, trust and anonymity between the market place and the KYC system relies on zero knowledge proof-based SCs used for user identification processes. With this management approach proposed, the user authentication is only verified within the KYC platform, providing a legally valid and fully anonymous online trading platform.

Open access
2 source records
Blockchain Technology Applications and Security
FinTech, Crowdfunding, Digital Finance
Digital Platforms and Economics
Original source
Oct 1, 2019·arXiv
31 cites
Scaling Blockchains to Support Electronic Health Records for Hospital Systems

Alyssa Donawa, Inema Orukari, Corey E. Baker

Electronic Health Records (EHRs) have improved many aspects of healthcare and allowed for easier patient management for medical providers. Blockchains have been proposed as a promising solution for supporting Electronic Health Records (EHRs), but have also been linked to scalability concerns about supporting real-world healthcare systems. This paper quantifies the scalability issues and bottlenecks related to current blockchains and puts into perspective the limitations blockchains have with supporting healthcare systems. Particularly we show that well known blockchains such as Bitcoin, Ethereum, and IOTA cannot support transactions of a large scale hospital system such as the University of Kentucky HealthCare system and leave over 7.5M unsealed transactions per day. We then discuss how bottlenecks of blockchains can be relieved with sidechains, enabling well-known blockchains to support even larger hospital systems of over 30M transactions per day. We then introduce the Patient-Healthchain architecture to provide future direction on how scaling blockchains for EHR systems with sidechains can be achieved.

Open access
2 source records
cs.CR
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Original source
Oct 1, 2019
12 cites
Pooled Mining is Driving Blockchains Toward Centralized Systems

Liuyang Ren, Paul A. S. Ward

The decentralization property of blockchains stems from the fact that each miner accepts or refuses transactions and blocks based on its own verification results. However, pooled mining causes blockchains to evolve into centralized systems because pool participants delegate their decision-making rights to pool managers. In this paper, we established and validated a model for Proof-of-Work mining, introduced the concept of equivalent blocks, and quantitatively derived that pooling effectively lowers the income variance of miners. We also analyzed Bitcoin and Ethereum data to prove that pooled mining has become prevalent in the real world. The percentage of pool-mined blocks increased from 49.91% to 91.12% within four months in Bitcoin and from 76.9% to 92.2% within five months in Ethereum. In July 2018, Bitcoin and Ethereum mining were dominated by only six and five pools respectively.

Blockchain Technology Applications and Security
Original source
Oct 1, 2019
20 cites
IoT and Blockchain for Smart Locks

Lucas de Camargo Silva, Mayra Samaniego, Ralph Deters

Community-based online platforms for hospitality services have connected hosts and guests globally. With the increasing popularity of those platforms - e.g., Airbnb - some management issues have attracted the attention of researchers - for instance, granting access to properties and rooms remotely, without requiring hosts and guests to meet in person. Solutions have been proposed - e.g., locks with pin pad and vendor centralized smart locks - but they usually have shortcomings that compromise either security, privacy, or convenience. This research designs and proposes a blockchain-based system for smart door locks to provide the convenience of remote access control management, while security and privacy for both hosts and guests are not compromised. Moreover, to surpass current locks' functionalities, this research proposes a feature that enables the guests to cease the hosts' access to the lock, during their stay. This feature also guarantees to the guest that no one will be able to change that access rule without their explicit approval. The proposed solution integrates Ethereum blockchain as the foundation of the system and uses Infura API as the bridge to connect the IoT infrastructure to the blockchain network. Such architecture alleviates hardware demand from the equipment, which can favor the use of resource-constrained IoT devices. Once Ethereum is used to build the solution, and users are charged fees to perform some actions in the blockchain, the system is evaluated concerning operation costs. Three Ethereum test networks - Ganache, Ropsten, and Rinkeby - were used to run the smart contract and assess the charge to complete significant actions in the system. The results show that the cost to use the smart lock is low, especially if the benefits of security, privacy, and convenience are taken into consideration. Most of the actions yielded fees about cents of a US dollar, where the exception is a one-time payment of USD3.83 - worst-case scenario - to deploy the smart contract - i.e., setup the system.

Blockchain Technology Applications and Security
Sharing Economy and Platforms
IoT and Edge/Fog Computing
Original source
Oct 1, 2019·Journal of Computational and Theoretical Nanoscience
13 cites
Analysis on Different Strategies Used in Blockchain Technology

Puneeta Singh, Sahil Verma, Kavita Kavita

Blockchain technology is a distributed ledger, it’s reliable, transparent, secure, trust-worthy, confidential and authenticate. Blockchain is a combination of blocks which contains the header of valid transactions using one of the best hashing algorithm (SHA-256 bits). Different strategies will be used in blockchain i.e., private blockchain, public (Example: Ethereum and bitcoins) and consortium blockchain. In this paper, we discuss about basic process of E-voting, IOT with blockchain, financing and blockchain technology helps for providing highest performance in rural areas.

Blockchain Technology Applications and Security
Original source
Oct 1, 2019
4 cites
Decentralized Cloud Scheduling via Smart Contracts. Operational constraints and costs

Adrian Spătaru, Laura Ricci, Dana Petcu, Barbara Guidi

The applications of Blockchain and Smart Contracts cover all aspects of digital information processing, varying from Asset Management platforms to Online Shops and Digital Identity Management. Several start-up companies and fellow researchers are interested in creating decentralized Clouds using the Blockchain as the mechanism for synchronization, identity management, and payment. This paper presents a conceptual platform exploiting Ethereum Smart Contracts to handle resource scheduling for Cloud Applications, investigates the operational constraints and measures the cost and latency for three scheduling strategies. In addition, it presents the constraints under which instances can be terminated asynchronously, which increases the cost of the transaction. The minimum cost for executing an application is similar to paying 12 hours for a standard Virtual Machine in today's Clouds if the Smart Contracts are deployed on the Ethereum Network, which limits the interest of users with short running applications.

Blockchain Technology Applications and Security
Cloud Computing and Resource Management
IoT and Edge/Fog Computing
Original source
Oct 1, 2019
64 cites
Trusted Computing Meets Blockchain: Rollback Attacks and a Solution for Hyperledger Fabric

Marcus Brandenburger, Christian Cachin, Rüdiger Kapitza, Alessandro Sorniotti

A smart contract on a blockchain cannot keep a secret because its data is replicated on all nodes in a network. To remedy this problem, it has been suggested combining blockchains with trusted execution environments (TEEs), such as Intel SGX, for executing applications that demand confidentiality. As a consequence, untrusted blockchain nodes cannot get access to the data and computations inside the TEE. This paper first explores issues that arise from the combination of TEEs with blockchains: Smart contracts executed inside TEEs are susceptible to rollback attacks, which should be prevented to maintain confidentiality for the application. However, in blockchains with non-final consensus protocols, such as the proof-of-work in Ethereum and others, the contract execution must handle rollbacks by design. This implies that TEEs for securing smart-contract execution cannot be directly used for such blockchains; this approach works only when the consensus decisions are final. Second, this work introduces an architecture and a prototype for smart-contract execution within Intel SGX for Hyperledger Fabric, a prominent enterprise blockchain platform. Our system resolves additional difficulties posed by the specific execute-order-validate architecture of Fabric, prevents rollback attacks on TEE-based execution as far as possible, and minimizes the trusted computing base. For increasing security, our design encapsulates each application on the blockchain within its own enclave that shields it from the host system. An evaluation shows that the overhead of moving the execution into SGX is within 10%-20% for a sealed-bid auction application.

Security and Verification in Computing
Blockchain Technology Applications and Security
Distributed systems and fault tolerance
Original source
Oct 1, 2019·Institutional Repositories DataBase (IRDB)
0 cites
Simulating Ethereum Network with SimBlock

流之介 永山, Ryunosuke Nagayama, 一幸 首藤, Kazuyuki Shudo

No abstract is available for this record.

Interconnection Networks and Systems
Distributed and Parallel Computing Systems
Software-Defined Networks and 5G
Original source
Oct 1, 2019
58 cites
Bifröst: a Modular Blockchain Interoperability API

Eder J. Scheid, Timo Hegnauer, Bruno Rodrigues, Burkhard Stiller

The blockchain (BC) world is rapidly becoming a universe of several ledgers designed for a specific purpose, holding data previously stored (i.e., siloed) in centralized databases. The use of different BCs for the same purpose could hamper the frictionless exchange of data or value. On one hand, it is natural that there are competing implementations exploring the benefits of BC. On the other hand, the problem of siloed data re-emerges, with respect to isolated chains. In this regard, BC interoperability is necessary to connect different BCs, exchanging information and assets. Moreover, to foster BC employment, developers must be able to interact with such different BCs without knowing the details of each implementation. This paper presents a novel solution, called Bifröst, to store and retrieve data on different BCs. Bifröst employs a notary scheme, which allows for connectivity to different BCs. The presented prototype is highly modular and currently implements seven adapters to popular BC implementations, including Bitcoin, Ethereum, and Stellar. The developed prototype was evaluated concerning performance, security, and data size to verify the feasibility of such an implementation and assess design decisions taken during its development.

Open access
Blockchain Technology Applications and Security
Cloud Computing and Resource Management
Distributed systems and fault tolerance
Original source
Oct 1, 2019
1 cites
JSP Digital Asset Trading System

Thawatchai Chomsiri, Detchasit Pansa

This research presents a novel mechanism of digital asset trading system on blockchain called JSP-DATS. The JSP-DATS includes (1) a novel mechanism of trading, and (2) a novel mechanism of blockchain which will be the infrastructure of the system. The proposed novel mechanism of blockchain uses the "Random-Checker Proof of Stake" consensus model which can decrease transaction time. The blockchain of the JSP-DATS has been designed to multiple layers. This design is easy to develop, and can be used for further research. The internal mechanism of the proposed system including steps of encoding/decoding, key management, and the storage of encrypted digital assets on the blockchain has will be discussed in this paper. In addition, we have implemented the designed model using Microsoft Visual C++ and encryption libraries from the MSDN web-site to create a software prototype. The prototype is used to study and measure the speed of the proposed scheme. The results show that transaction time of the proposed scheme is lower than that in BitCoin and Ethereum blockchain. With the proposed scheme, the seller (digital asset owners) can see transactions of the trading system transparently, and they can receive their percentage share immediately. In addition, we expect that buyers will indirectly benefit from purchasing digital assets at a lower price.

Blockchain Technology Applications and Security
Stock Market Forecasting Methods
Financial Markets and Investment Strategies
Original source
Oct 1, 2019·IEEE Transactions on Industrial Informatics
94 cites
Blockchain-Based Anonymous Authentication With Selective Revocation for Smart Industrial Applications

Yong Yu, Yanqi Zhao, Yannan Li, Xiaojiang Du · 6 authors

Personal privacy disclosure is one of the most serious challenges in smart industrial applications. Anonymous authentication is an effective solution to protect personal privacy. However, the existing anonymous credential protocols are not perfectly suitablefor smart industrial environments such as smart vehicles in the sense that the credential revocation issue is not well-solved. In this article, we propose a Blockchain-based Anonymous authentication with Selective revocation for Smart industrial applications (BASS) for smart industrial applications supporting attribute privacy, selective revocation, credential soundness, and multishowing-unlinkability. Specifically, an efficient selective revocation mechanism is proposed based on dynamic accumulators and the signature algorithm due to Pointcheval and Sanders as the overlay of the BASS. According to the diverse demands of credential authorities, BASS can selectively provide revocation of credentials or revocation of users. We extend BASS from single-attribute privacy to multiattribute privacy as well. Finally, we implement a prototype to evaluate the cryptographic core primitives of BASS by deploying smart contracts in Ethereum to demonstrate the validity of BASS in smart industrial applications.

Blockchain Technology Applications and Security
Cryptography and Data Security
Privacy-Preserving Technologies in Data
Original source
Oct 1, 2019·2019 International Multi-Conference on Industrial Engineering and Modern Technologies (FarEastCon)
47 cites
Review of Blockchain Technology Vulnerabilities and Blockchain-System Attacks

Andrey Averin, O. Averina

Blockchain is a relatively young technology. In recent years, blockchain has gained popularity, which keeps growing. Such interest is mainly due to cryptocurrencies, such as Bitcoin and Ethereum. This technology has presented promising prospects of application. With the increasing interest in blockchain from cryptocurrency to smart contracts, there are precedents of attacks on the blockchain platform. This, in turn, encourages consideration of blockchain in terms of security, identifying vulnerabilities and predicting the emergence of new vulnerabilities. That further would allow to find new methods and solutions for blockchain security. In this paper, the known vulnerabilities were considered, as well as the known attacks on blockchain and their successful implementations in recent times.

Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Original source
Oct 1, 2019
1 cites
Application and Research of Heterogeneous Computing in Ethereum Consensus Algorithm

Huwan Peng, Chaodong Ling, Yongjie Li

This paper researches the consensus mechanism of Ethereum, focusing on the analysis and research of the consensus algorithm. The consensus algorithm is the kernel of Ethereum implementation, which is the most computationally intensive, time-consuming and occupies much memory. The concrete implementation architecture and method of heterogeneous operation are analyzed and implemented on the Xilinx ZCU106 platform. Finally, the verification content has been obtained.

Cognitive Computing and Networks
Robotics and Automated Systems
Advanced Computing and Algorithms
Original source
Oct 1, 2019·arXiv (Cornell University)
13 cites
Basis Path Coverage Criteria for Smart Contract Application Testing

Xinming Wang, Zhijian Xie, Jiahao He, Gansen Zhao · 5 authors

The widespread recognition of the smart contracts has established their importance in the landscape of next generation blockchain technology. However, writing a correct smart contract is notoriously difficult. Moreover, once a state-changing transaction is confirmed by the network, the result is immutable. For this reason, it is crucial to perform a thorough testing of a smart contract application before its deployment. This paper's focus is on the test coverage criteria for smart contracts, which are objective rules that measure test quality. We analyze the unique characteristics of the Ethereum smart contract program model as compared to the conventional program model. To capture essential control flow behaviors of smart contracts, we propose the notions of whole transaction basis path set and bounded transaction interaction. The former is a limited set of linearly independent inter-procedural paths from which the potentially infinite paths of Ethereum transactions can be constructed by linear combination, while the latter is the permutations of transactions within a certain bound. Based on these two notions, we define a family of path-based test coverage criteria. Algorithms are given to the generation of coverage requirements. A case study is conducted to compare the effectiveness of the proposed test coverage criteria with random testing and statement coverage testing.

Open access
3 source records
Blockchain Technology Applications and Security
Advanced Malware Detection Techniques
Cryptography and Data Security
Original source
Oct 1, 2019·Macroeconomics and Finance in Emerging Market Economies
23 cites
Does uncertainty predict cryptocurrency returns? A copula-based approach

Ur Koumba, Calvin Mudzingiri, Jules Mba

This study is confined in analysing how the economic policy uncertainty (EPU) effects affect exchange rates on cryptocurrency assets in times of financial turbulence characterized by low confidence in the financial stock markets, and tranquil periods where the financial stock markets behave smoothly. Our research employs the D-Vine pair-copula method on daily selected cryptocurrency (Bitcoin, Ethereum and Ripple) prices within the period of the 10 August 2016 to the 23 February 2018. Our findings document the presence of the dependence between the US EPU and cryptocurrencies and indicate a significant correlation with Ethereum which exhibits a much better return.

Market Dynamics and Volatility
Blockchain Technology Applications and Security
Complex Systems and Time Series Analysis
Original source
Oct 1, 2019
10 cites
Blockchain Architectures for P2P Energy Trading Between Neighbors

Beom Suk Lee, Jae Song, Sung Jun Moon, In Hwan Park · 5 authors

We consider blockchain architectures for P2P energy trading of surpluses and demands between prosumers and consumers in the neighborhood without any intermediaries. We identify key elements comprising the P2P energy trading platform based on blockchain. The software architecture of our energy trading platform is provided with example codes. We build smart contracts on Ethereum for determination of trading price as well as matching between prosumers and consumers in such a way to balance the surpluses and the demands. At the start of each trading period, the prosumers and consumers send their respective amounts of surplus or demand. And the smart contract for price determination automatically evaluates the price in a predetermined way to balance surplus and demand within the neighborhood. Another smart contract performs matching between prosumers and consumers using this price. Authenticated and private messaging called `whisper' is employed for prosumers and DSO(Distributed System Operator)s to notify injection of surplus energy to the DSO and verify the ownership of the injected energy. Each participant interacts with Ethereum virtual machine through web server built with Node.js, Web3.js and Geth. We build a small experimental setup with 4 Raspberry-Pis in a private Ethereum network to provide proof-of-concept for our blockchain based P2P trading architecture between neighbors.

Blockchain Technology Applications and Security
Peer-to-Peer Network Technologies
Caching and Content Delivery
Original source
Oct 1, 2019
20 cites
Exploring Ethereum’s Blockchain Anonymity Using Smart Contract Code Attribution

Shlomi Linoy, Natalia Stakhanova, Alina Matyukhina

Blockchain users are identified by addresses (public keys), which cannot be easily linked back to them without out-of-network information. This provides pseudo-anonymity, which is amplified when the user generates a new address for each transaction. Since all transaction history is visible to all users in public blockchains, finding affiliation between related addresses can hurt pseudo-anonymity. Such affiliation information can be used to discriminate against addresses that were found to be related to a specific group, or can even lead to the de-anonymization of all addresses in the associated group, if out-of-network information is available on a few addresses in that group. In this work we propose to leverage a stylometry approach on Ethereum's deployed smart contracts' bytecode and high level source code, which is publicly available by third party platforms. We explore the extent to which a deployed smart contract's source code can contribute to the affiliation of addresses. To address this, we prepare a dataset of real-world Ethereum smart contracts data, which we make publicly available; design and implement feature selection, extraction techniques, data refinement heuristics, and examine their effect on attribution accuracy. We further use these techniques to test the classification of real-world scammers data.

Blockchain Technology Applications and Security
Spam and Phishing Detection
Cybercrime and Law Enforcement Studies
Original source
Oct 1, 2019
2 cites
Migration from POW to POS for Ethereum

B Prashant, I Makrant, M Mansi

Block-chain is rapidly evolving. There are continuous enhancements. In order to validate transactions algorithm is used. The traditional approach of Proof of Work (POW) is where miners are incentivized to compete with each other to complete transactions. Alternate system is proof of stake (POS) where in the validators lock up some of their tokens and thus replace the role of miners. Generation three block chain, which are the latest and fastest ones are mostly Proof of Stake (POS). Hence the POW systems seek to leverage the POS properties in order to attain higher speed and scalability. The paper discusses the approach with Ethereum has taken to migrate from the current POW protocol to POS protocol. The concept of Caster is focused as implementation. Casper further has two subtypes of approaches know as Friendly Finality Gadget (FFG) and Correct by Construction (CBC). The paper discusses on safety guard over these algorithms.

Open access
Blockchain Technology Applications and Security
Distributed systems and fault tolerance
Original source
Oct 1, 2019
1 cites
Prototype Distributed Ledger Technology of UF 6 Cylinder Tracking in Ethereum

Nicholas D. Pattengale, David Farley

We have created a demonstration permissioned Distributed Ledger Technology (DLT) datastore for the UF<sub>6</sub> cylinder tracking safeguards use-case utilizing the Ethereum DLT framework and using Solidity for smart contract code. Our demonstration creates a simulated dataset representing tracking of 75,000 UF<sub>6</sub> cylinders across 11 example nuclear facilities worldwide. Our DLT system allows for easy input and reading of shipping and receiving data, including a Graphical User Interface (GUI). Sandia’s Emulytics capability was leveraged to help create the DLT node network and assess performance. We find that our DLT prototype can easily handle to ~150,000 UF<sub>6</sub> cylinder shipments per year worldwide, without any excessive computational or storage burden on the IAEA or Member States. Next steps could include a demonstration to the IAEA and potentially demonstrating integration with TradeLens, a DLT in use by a consortium of international shipping companies representing over half of world shipping trade.

Open access
Real-time simulation and control systems
Engineering Applied Research
Original source
Oct 1, 2019·arXiv
37 cites
MPro: Combining Static and Symbolic Analysis for Scalable Testing of Smart Contract

William Zhang, Sebastian Banescu, Leonardo Pasos, Steven Stewart · 5 authors

Smart contracts are executable programs that enable the building of a programmable trust mechanism between multiple entities without the need of a trusted third-party. At the time of this writing, there were over 10 million smart contracts deployed on the Ethereum networks and this number continues to grow at a rapid pace. Smart contracts are often written in a Turing-complete programming language called Solidity, which is not easy to audit for subtle errors. Further, since smart contracts are immutable, errors have led to attacks resulting in losses of cryptocurrency worth 100s of millions of USD and reputational damage. Unfortunately, manual security analyses do not scale with size and number of smart contracts. Automated and scalable mechanisms are essential if smart contracts are to gain mainstream acceptance. Researchers have developed several security scanners in the past couple of years. However, many of these analyzer either do not scale well, or if they do, produce many false positives. This issue is exacerbated when bugs are triggered only after a series of interactions with the functions of the contract-under-test. A depth-n vulnerability, refers to a vulnerability that requires invoking a specific sequence of n functions to trigger. Depth-n vulnerabilities are time-consuming to detect by existing automated analyzers, because of the combinatorial explosion of sequences of functions that could be executed on smart contracts. In this paper, we present a technique to analyze depth-n vulnerabilities in an efficient and scalable way by combining symbolic execution and data dependency analysis. A significant advantage of combining symbolic with static analysis is that it scales much better than symbolic alone and does not have the problem of false positive that static analysis tools typically have. We have implemented our technique in a tool called MPro, a scalable and automated smart contract analyzer based on the existing symbolic analysis tool Mythril-Classic and the static analysis tool Slither. We analyzed 100 randomly chosen smart contracts on MPro and our evaluation shows that MPro is about n-times faster than Mythril-Classic for detecting depth-n vulnerabilities, while preserving all the detection capabilities of Mythril-Classic.

Open access
2 source records
Security and Verification in Computing
Advanced Malware Detection Techniques
Adversarial Robustness in Machine Learning
Original source
Oct 1, 2019
8 cites
A Study of Inequality in the Ethereum Smart Contract Ecosystem

Bishwas C Gupta, Sandeep K. Shukla

Ethereum is one of the most popular blockchain platforms and is the second most valuable cryptocurrency. It allows developers to create smart contracts - small computer programs that sit on the blockchain. These programs can be written in programming languages like solidity and are executed by the Ethereum Virtual Machine (EVM). Since Ethereum is a public blockchain, all the data of the blockchain is available publicly. However, getting smart contract data is a tedious process and public data-sets for smart contracts are not available for further analysis. Therefore, in this work, we collect a total of 1.9M smart contracts till the block height of 7.1M, and provide a first of its kind analysis across different parameters like duplicity, ether balance, ether moved, etc. We observe that across all these different parameters, only a small fraction of the smart contracts are dominant. We label such 2900 dominant contracts as the `Contracts of Importance' and use it for further analysis using the various tools available to give us an insight into the vulnerability trends and patterns in smart contracts.

Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
Internet Traffic Analysis and Secure E-voting
Original source