Achieving data confidentiality and integrity while maintaining secure access is essential in various fields, including in the medical sector. Implementing a blockchain-based technology to secure medical data makes the data decentralized and ensures that the users are the owners and have control over their own data. While blockchain technology (e.g. Ethereum) is still in its infancy, it’s the cutting-edge of research in many industries and universities. The decentralized system of blockchain along with the presence of smart contracts to automate tasks are the two major features that can be utilized to replace our current imperfect health system and invent a secure, flexible, and more reliable system for data protection. Using this technology will require patients to be accountable for their medical records while allowing to 1) store electronic medical records (EMR) for a patient’s lifetime, 2) advance the development of precise medicines, 3) enable medical authorities to securely share medical data. In order to build a robust system to protect medical data, my research will focus on the security aspect of the system by analyzing the blockchain technology constraints, and carefully designing and implementing a secure and scalable system using Ethereum blockchain and smart contracts.
Shayan Eskandari, Jeremy Clark, Vignesh Sundaresan, Moe Adham
In this paper, we present Velocity, a decentralized market deployed on Ethereum for trading a custom type of derivative option. To enable the smart contract to work, we also implement a price fetching tool called PriceGeth. We present this as a case study, noting challenges in development of the system that might be of independent interest to whose working on smart contract implementations. We also apply recent academic results on the security of the Solidity smart contract language in validating our codes security. Finally, we discuss more generally the use of smart contracts in modelling financial derivatives.
We discuss Russia's underlying motives for issuing its government-backed cryptocurrency, CryptoRuble, and the implications thereof and of other likely-soon-forthcoming government-issued cryptocurrencies to some stakeholders (populace, governments, economy, finance, etc.), existing decentralized cryptocurrencies (such as Bitcoin and Ethereum), as well as the future of the world monetary system (the role of the U.S. therein and a necessity for the U.S. to issue CryptoDollar), including a future algorithmic universal world currency that may also emerge. We further provide a comprehensive list of references on cryptocurrencies.
Digital currencies and cryptocurrencies have hesitantly started to penetrate the investors, and the next step will be the regulatory risk management framework. We examine the Value-at-Risk and Expected Shortfall properties for the major digital currencies, Bitcoin, Ethereum, Litecoin, and Ripple. The methodology used is GARCH modelling followed by Filtered Historical Simulation. We find that digital currencies are subject to a higher risk, therefore, to higher sufficient buffer and risk capital to cover potential losses.
We present efficient protocols for amortized secure multiparty computation with penalties and secure cash distribution, of which poker is a prime example. Our protocols have an initial phase where the parties interact with a cryptocurrency network, that then enables them to interact only among themselves over the course of playing many poker games in which money changes hands. The high efficiency of our protocols is achieved by harnessing the power of stateful contracts. Compared to the limited expressive power of Bitcoin scripts, stateful contracts enable richer forms of interaction between standard secure computation and a cryptocurrency. We formalize the stateful contract model and the security notions that our protocols accomplish, and provide proofs using the simulation paradigm. Moreover, we provide a reference implementation in Ethereum/Solidity for the stateful contracts that our protocols are based on. We also adopt our off-chain cash distribution protocols to the special case of stateful duplex micropayment channels, which are of independent interest. In comparison to Bitcoin based payment channels, our duplex channel implementation is more efficient and has additional features.
Bitcoin can be thought of as the first prototypical decentralized autonomous organization (DAO). It created a network-based ecosystem of participants who contributed computational power toward a singular goal. In Bitcoin, the distributed protocol providing a financial service and rewarding miners became a rudimentary decentralized organization. In this chapter, we talk about more complex and full DAOs made in Aragon. Aragon (https://aragon.one/) is a decentralized application (DApp) that lets anyone create and manage different kinds of organizations (nongovernmental organizations [NGOs], nonprofits, foundations) on the Ethereum blockchain. Creating a DAO requires numerous steps and originally it was more difficult to implement in Ethereum. However, Aragon implements all the basic features of an organization in a base template that is deployed whenever a user instantiates a company. Most of the traditional features such as a cap table, voting, fundraising, and accounting are offered in Aragon as a decentralized counterpart to run on the blockchain. In addition, an Aragon company can be customized to a very granular extent and extended using new modules that can be added to a company’s existing smart contracts. Aragon enables different organizations to be built on the blockchain, and one interesting use case integrates identity using a two-way verification scheme with Keybase. We talk about how the Keybase to Aragon peg functions to provide identity services in the context of a decentralized system. We also briefly go over the Aragon kernel, which is essentially a task manager with subroutines that ensure smooth communication within an organization, among its members, and in the underlying blockchain.
In the Ethereum ecosystem, transfer of value between users is often realized by the use of tokens that represent digital assets. Ether is the default token and the de facto currency used for transactions and initializing smart contracts on the network. Ethereum also supports the creation of new kinds of tokens that can represent any commonly traded commodities as digital assets. All tokens are implemented using the standard protocol, so the tokens are compatible with any Ethereum wallet on the network. The tokens are distributed to users interested in the given specific use case through an ICO. In this chapter, we focus our attention on tokens created for a very specific use case: high-performance computing (HPC). More precisely, we discuss a model of distributed HPC where miners offer computational resources for a task and get rewarded in some form of Ethereum tokens.
Since Bitcoin was launched in 2009, several new cryptocurrencies have been initiated with variations to Bitcoin's original design. Although Bitcoin still remains the most prominent actor in the market, some technical problems have been raised to the design of the protocol. The objective of this thesis is to determine whether the newer cryptocurrencies handle the technical problems of Bitcoin, or if they also suffer from the same issues. Instead of evaluating several cryptocurrencies for this comparison, the cryptocurrency Ethereum has been chosen as a proxy for the others. Ethereum was started in 2014, is widely backed in the community and is second in line to Bitcoin when it comes to market capitalization. \n\nAs a basis for the comparative analysis a rigorous study of the Bitcoin and Ethereum protocols have been performed, and parallel descriptions of the systems have been devised. Three technical problem have shaped the focus of the analysis: computational waste, concentration of power and ambiguity of transactions. Real world statistical data has been gathered and synthesized to enlighten the findings in the comparison. The main result of the comparison is that both systems suffer from the same problems to a certain degree, due to the fact that they utilize the same consensus mechanism. However, Ethereum utilizes several newer techniques to try and reduce the severity of these problems compared to Bitcoin, with varying degrees of success.
Massimo Bartoletti, Stefano Lande, Livio Pompianu, Andrea Bracciali
Modern cryptocurrencies exploit decentralised blockchains to record a public and unalterable history of transactions. Besides transactions, further information is stored for different, and often undisclosed, purposes, making the blockchains a rich and increasingly growing source of valuable information, in part of difficult interpretation. Many data analytics have been developed, mostly based on specifically designed and ad-hoc engineered approaches. We propose a general-purpose framework, seamlessly supporting data analytics on both Bitcoin and Ethereum --- currently the two most prominent cryptocurrencies. Such a framework allows us to integrate relevant blockchain data with data from other sources, and to organise them in a database, either SQL or NoSQL. Our framework is released as an open-source Scala library. We illustrate the distinguishing features of our approach on a set of significant use cases, which allow us to empirically compare ours to other competing proposals, and evaluate the impact of the database choice on scalability.
Blockchain technology as a whole is experiencing a dramatic rise in adoption, in no small part due to the developer-friendly Ethereum network. While the number of smart-contract powered distributed applications (Dapps) continues to rise, they face many of the same challenges all new technologies face as they are introduced to a market. By modeling the consumer adoption of blockchain technology and analyzing scholarly literature on supply-side factors affecting the diffusion of technology, we seek to prove the growth of a Dapp can be accelerated using abstraction, whole product planning, and complementaries.
Over past decade cloud services have enabled individuals and organizations to perform different types of tasks such as online storage, email services, on-demand movies and TV shows. The cloud services has also enabled on-demand deployment of applications, at cheap cost with elastic and scalable, fault tolerant system. These cloud services are offered by cloud providers who use authentication, authorization and accounting framework based on client-server model. Though this model has been used over decades, study shows it is vulnerable to different hacks and it is also inconvenient to use for the end users. In addition, the cloud provider has total control over user data which they are able to monitor, trace, leak and even modify at their will. Thus, the user data ownership, digital identity and use of cloud services has raised privacy and security concern for the users. In this thesis, Blockchain and its applications are studied and alternative model for authentication, authorization and accounting is proposed based on Ethereum Blockchain. Furthermore, a prototype is developed which enables users to consume cloud services by authenticating, authorizing and accounting with a single identity without sharing any private user data. Experiments are run with the prototype to verify that it works as expected. Measurements are done to assess the feasibility and scalability of the solution. In the final part of the thesis, pros and cons of the proposed solution are discussed and perspectives for further research are sketched.
This study provides a comparative financial and statistical analysis between the largest and most trad- ed cryptocurrencies. In particular, the exchange rates of Bitcoin, Litecoin, Ripple and Ethereum were collected from August 2010 until May 2017. The raw annualized volatility of cryptocurrencies is compared as well as to fiat currencies and major exchange rates. The results show that Bitcoin is the least volatile cryptocurrency with low correlations with the altcoins, providing possible diversification benefits to cryptocurrency investing. In addition, our results indicate that Bitcoin is the only cryptocurrency that has causality effects on the other cryptocurrencies.
In this paper, we explore remarkable similarities between multi-transactional behaviors of smart contracts in cryptocurrencies such as Ethereum and classical problems of shared-memory concurrency. We examine two real-world examples from the Ethereum blockchain and analyzing how they are vulnerable to bugs that are closely reminiscent to those that often occur in traditional concurrent programs. We then elaborate on the relation between observable contract behaviors and well-studied concurrency topics, such as atomicity, interference, synchronization, and resource ownership. The described contracts-as-concurrent-objects analogy provides deeper understanding of potential threats for smart contracts, indicate better engineering practices, and enable applications of existing state-of-the-art formal verification techniques.
Smart contracts are computer programs that can be consistently executed by a network of mutually distrusting nodes, without the arbitration of a trusted authority. Because of their resilience to tampering, smart contracts are appealing in many scenarios, especially in those which require transfers of money to respect certain agreed rules (like in financial services and in games). Over the last few years many platforms for smart contracts have been proposed, and some of them have been actually implemented and used. We study how the notion of smart contract is interpreted in some of these platforms. Focussing on the two most widespread ones, Bitcoin and Ethereum, we quantify the usage of smart contracts in relation to their application domain. We also analyse the most common programming patterns in Ethereum, where the source code of smart contracts is available.
Cryptocurrencies, such as bitcoin and ethereum, have not only risen to public attention as novel means of payments, but also as facilitators of initial coin offerings (ICOs, also called token sales). In these entirely online-mediated offerings, entrepreneurs sell tokens registered on a blockchain in exchange for cryptocoins. Buyers receive tokens that can be understood as cryptographically-secured coupons which embody a bundle of rights and obligations. In July 2017, the SEC released an investigative report that highlighted that such tokens can be subject to the full scope of US securities regulation. It is unclear, however, to what extent EU securities regulation is applicable to ICOs and, particularly, whether issuers have to publish and register a prospectus in order to avoid criminal and civil prospectus liability in the EU. In conceptual terms, this depends on whether tokens are considered “securities” under the EU prospectus regulation regime. Against this background, this paper develops a nuanced approach that distinguishes between three archetypes of tokens: currency, investment, and utility tokens. It analyzes the differential implications of each of these types, and their hybrid forms, for EU securities regulation, and develops policy proposals for their regulation.
Stefan Dziembowski, Lisa Eckey, Sebastian Faust, Daniel Malinowski
Payment channels emerged recently as an efficient method for performing cheap micropayments in cryptocurrencies. In contrast to traditional on-chain transactions, payment channels have the advantage that they allow for nearly unlimited number of transactions between parties without involving the blockchain. In this work, we introduce Perun, an off-chain channel system that offers a new method for connecting channels that is more efficient than the existing technique of ``routing transactions'' over multiple channels. To this end, Perun introduces a technique called ``virtual payment channels'' that avoids involvement of the intermediary for each individual payment. In this paper we formally model and prove security of this technique in the case of one intermediary, who can be viewed as a ``payment hub'' that has direct channels with several parties. Our scheme works over any cryptocurrency that provides Turing-complete smart contracts. As a proof of concept, we implemented Perun's smart contracts in Ethereum.
Open access
2 source records
Blockchain Technology Applications and Security
Cryptography and Data Security
Advanced Steganography and Watermarking Techniques
Ethereum represents the second generation of blockchain technology by providing\nan open and global computing platform which allows the exchange of cryptocurrency\n(Ether) and the development of self-verifying smart contract applications.\nSmart contracts present a foundation for possessing digital assets and a variety of\ndecentralized applications within the blockchain area. Ethereum and smart contracts\nare public, distributed and immutable, as such, they are prone to vulnerabilities\nsourcing from simple coding mistakes of developers.\n\nMotivated by the security breaches and recurring financial losses in smart contracts,\nwe aim to advance the field of security in smart contract programming.\nThe main objective is to aid smart contract developers by providing a taxonomy of\nall known security issues and by inspecting the security code analysis tools used\nto identify those vulnerabilities. Based on previous research as well as attacks on\nEthereum smart contracts, we propose an updated taxonomy which categorizes\nall known vulnerabilities within their architectural and severity level. Our second\nproposed taxonomy is a novel categorization of security tools on Ethereum.\n\nFurthermore, we conduct the investigation of security code analysis tools on\nEthereum by assessing their effectiveness and accuracy. In particular, we analyze\nfour security tools, namely, Oyente, Securify, Remix, and SmartCheck. The results\nindicate that there are overall inconsistencies between the tools on different security\nproperties. SmartCheck outperformed the other tools in terms of effectiveness,\nwhereas Oyente performed the best in terms of accuracy. Furthermore, based on\nthe limitations we identified, we propose future improvements within the user interfaces,\ninterpretation of results, and additional vulnerability checks.
The gas mechanism in Ethereum charges the execution of every operation to ensure that smart contracts running in EVM (Ethereum Virtual Machine) will be eventually terminated. Failing to properly set the gas costs of EVM operations allows attackers to launch DoS attacks on Ethereum. Although Ethereum recently adjusted the gas costs of EVM operations to defend against known DoS attacks, it remains unknown whether the new setting is proper and how to configure it to defend against unknown DoS attacks. In this paper, we make the first step to address this challenging issue by first proposing an emulation-based framework to automatically measure the resource consumptions of EVM operations. The results reveal that Ethereum's new setting is still not proper. Moreover, we obtain an insight that there may always exist exploitable under-priced operations if the cost is fixed. Hence, we propose a novel gas cost mechanism, which dynamically adjusts the costs of EVM operations according to the number of executions, to thwart DoS attacks. This method punishes the operations that are executed much more frequently than before and lead to high gas costs. To make our solution flexible and secure and avoid frequent update of Ethereum client, we design a special smart contract that collaborates with the updated EVM for dynamic parameter adjustment. Experimental results demonstrate that our method can effectively thwart both known and unknown DoS attacks with flexible parameter settings. Moreover, our method only introduces negligible additional gas consumption for benign users.