Fushuai Li, Ruiquan Lin, Wencheng Chen, Jun Wang · 6 authors
Cognitive Internet of Vehicles (CIoV) adds the cognitive engine based on traditional Internet of Vehicles (IoV), which can improve spectrum utilization. However, spectrum sensing data falsification (SSDF) attacks pose a threat to CIoV network security. To ensure the full utilization of spectrum resources and protect primary users transmission, this article combines blockchain with CIoV to defend against SSDF attacks in the presence of vehicle users (VUs) entering and leaving the network. Specifically, this article introduces a virtual currency called Sencoins serve as credential for VUs to purchase transmission shares. And this article proposes a reward and punishment mechanism and a hybrid Proof-of-Stake (PoS) and Proof-of-Work (PoW) mining model to thwart the motivation of the VUs to launch SSDF attacks. On this basis, this article investigates the dynamics of SSDF attack strategy choice of VUs, and uses the largest Lyapunov exponent (LLE) to determine the critical value of Sencoins that avoids the system to exhibit chaotic behavior. To describe the uncertainty of the population proportion of VUs that choose different attack strategies due to high-speed movement and the VUs entering and leaving the CIoV network, this article introduces Gaussian white noise into the replication dynamics equation and builds the Itô stochastic evolutionary game model, and solves it according to the stability judgment theorem of stochastic differential equations and stochastic Taylor expansion. Finally, simulation results verify that the proposed method can quickly and effectively thwart SSDF attacks in the CIoV network. And compared with traditional methods, the proposed method can improve the efficiency of defending against SSDF attacks by 567% and the average throughput by 25%.
Huijuan Zhu, Lei Yang, Liangmin Wang, Victor S. Sheng
Smart contracts have gained extensive adoption across diverse industries, including finance, supply chain, and the Internet of Things. Nevertheless, the surge in security incidents of smart contracts over recent years has led to substantial economic losses. Therefore, ensuring the security of smart contracts has become a critical and complex challenge in both academic and industrial domains. Based on 539 real-world security incidents in the Ethereum platform and audit reports from 10 authoritative auditing institutions, we summarize 27 types of exploited security vulnerabilities and draw insights into their principles, typical cases, relevant research and recommended prevention strategies. Besides, we also gather 7 other potentially threatening vulnerability types as supplements. On this basis, we conduct an in-depth analysis of the root causes of vulnerabilities and further formulate eight safety practical rules. Moreover, we perform a comprehensive review of 178 recent papers on smart contract security analysis, classifying detection methods into formal verification, fuzz testing, machine learning, program analysis, and others. For each category, we seize the specific detection tools and analyze them comprehensively. Then, we conduct an extensive analysis and synthesis from various angles, presenting a comprehensive overview of the current research landscape in smart contract security detection. We also discuss current on-chain and off-chain repair methods. Finally, this review outlines major challenges and highlights potential areas for future research in this field.
Smart contracts are pivotal in blockchain systems, yet ensuring their reliability and security remains challenging due to coding complexities and potential vulnerabilities. This paper explores the use of Large Language Models (LLMs) in enhancing the smart contract code quality. As part of leveraging extensive training data and language understanding, we experiment with different approaches. LLMs aid developers by offering automated code suggestions, identifying vulnerabilities and promoting best practices. Through experimentation, we demonstrate how integrating LLM-based approaches improves code quality and reliability in blockchain applications.
This paper presents an approach to using decentralized distributed digital (DDD) ledgers like blockchain with multi-level verification. In regular DDD ledgers like Blockchain, only a single level of verification is available, which makes it not useful for those systems where there is a hierarchy and verification is required on each level. In systems where hierarchy emerges naturally, the inclusion of hierarchy in the solution for the problem of the system enables us to come up with a better solution. Introduction to hierarchy means there could be several verification within a level in the hierarchy and more than one level of verification, which implies other challenges induced by an interaction between the various levels of hierarchies that also need to be addressed, like verification of the work of the previous level of hierarchy by given level in the hierarchy. The paper will address all these issues, and provide a road map to trace the state of the system at any given time and probability of failure of the system.
Biagio Boi, Franco Cirillo, Marco De Santis, Christian Esposito
Context: The digitalization of the healthcare sector faces significant challenges due to the diverse representation of data and their distribution across various hospitals. Moreover, security is a key concern as healthcare-related data are subject to the legal obligations of General Data Protection Regulation (GDPR) and similar data protection legislation. Standardization efforts like Health Level Seven (HL7) have been implemented to enhance data interoperability. However, authentication still remains a critical issue with significant challenges. Aim: This research aims to improve and strengthen the authentication process by introducing a novel architecture for decentralized authentication. Additionally, it proposes a new approach to decentralized data management, which is crucial for handling sensitive medical data efficiently. Methodology: The proposed architecture adopts a user-centric approach, utilizing Self-Sovereign Identity (SSI). It introduced a new non-fungible token (NFT) type called soulbound token (SBT) in the medical context, which will facilitate user authentication across different hospitals, effectively creating a federation of interconnected institutions. Results: The implementation of the proposed architecture demonstrated a significant reduction in authentication time across multiple hospitals. The use of SBT ensured secure and seamless user authentication, enhancing overall system interoperability and data security. The decentralized approach also mitigated the risks associated with centralized authentication servers. Conclusion: This study successfully presents a novel decentralized authentication architecture for the healthcare domain, leveraging SSI and SBTs. This approach accelerates the authentication process and enhances data security and interoperability among hospitals. Future research should explore the scalability of this architecture and its application in other sectors requiring stringent data security measures.
Hainan agarwood is a valuable commodity with a diverse range of applications, including use in spices, medicines, and cultural artifacts. This has led to the emergence of a growing market for the product. Nevertheless, several challenges persist within the Hainan agarwood industry, including inconsistent product quality, recurrent instances of market fraud, and an opaque supply chain. In order to address these issues, we put forth a proposal for an agarwood traceability method based on Distributed Identity (DID) and smart contracts. The implementation of distributed identity technology enables the assignment of a unique digital identity to each entity within the industrial chain, thereby facilitating enhanced accountability and accurate traceability. Concurrently, smart contract technology is utilized across all links of the industrial chain to achieve comprehensive process information recording and retrieval. This method guarantees that the data associated with each link in the agarwood industry chain is stored on the blockchain in a manner that is immutable. The proposed method effectively identifies counterfeit products while not relying on a single organization, thus reducing the risk of single-point failure and abuse of power, and improving the fairness and credibility of the system.
Decentralized Autonomous Organizations (DAOs) have emerged as a pioneering model for organizational structures, leveraging blockchain technology to enable transparent, decentralized governance and global participation. While the concept has gained significant attention, questions persist regarding its long-term viability and effectiveness. This paper explores the feasibility of tokenless DAOs in organizational transformation through empirical case studies. We underscore the transformative potential of DAOs in realizing human networks, leveraging the "six degrees of separation" theory to map and analyze societal dynamics. We further delve into practical implementations and challenges, by integrating DAOs into a meta-IP chain spanning multiple countries, the study demonstrates the scalability and applicability of decentralized technologies in sociological research.
In the contemporary landscape of the battlefield, the enhanced cyber warfare capabilities of adversaries mandate that routing protocols are equipped with endogenous security features. These features must be capable of detecting threats promptly and addressing them effectively to ensure both security and control. They also provide secure configuration options for the intrinsic security architecture of communication nodes within communication systems. This paper introduces a novel, inherently secure identity verification system named ORCA, which utilizes the concept of noninteractive zero-knowledge proof. ORCA streamlines the process of node identity authentication by minimizing communication exchanges, thereby safeguarding network topology integrity and establishing trust upon network formation. Leveraging this framework, the ORCA-OLSR security protocol was developed. Comparative simulations on the OPNET platform between the ORCA-OLSR and the challenge-response mechanism-based CA-OLSR security protocol demonstrate that ORCA-OLSR outperforms its counterpart in metrics such as routing overhead, end-to-end delay, and routing load.
Ben Biedermann, Matthew Scerri, Victoria Kozlova, Joshua Ellul
The terms self-sovereign identity (SSI) and decen-tralised identity are often used interchangeably, which results in increasing ambiguity when solutions are being investigated and compared. This article aims to provide a clear distinction between the two concepts in relation to the revised Regulation as Regards establishing the European Digital Identity Framework (eIDAS 2.0) by providing a systematisation of knowledge of technological developments that led up to implementation of eIDAS 2.0. Applying an inductive exploratory approach, relevant literature was selected iteratively in waves over a nine months time frame and covers literature between 2005 and 2024. The review found that the decentralised identity sector emerged adjacent to the OpenID Connect (OIDC) paradigm of Open Authentication, whereas SSI denotes the sector's shift towards blockchain-based solutions. In this study, it is shown that the interchangeable use of SSI and decentralised identity coincides with novel protocols over OIDC. While the first part of this paper distinguishes OIDC from decentralised identity, the second part addresses the incompatibility between OIDC under eIDAS 2.0 and Web3. The paper closes by suggesting further research for establishing a digital identity bridge for connecting applications on public-permissionless ledgers with data originating from eIDAS 2.0 and being presented using OIDC.
Implementing provable fairness in the minting process of non-fungible tokens (NFTs) enables the procedural generation of NFT metadata that can be verified in a decentralized manner, even when stored off-chain. Until now, smart contracts have required additional on-chain data, such as integrity digests, to support the verification of off-chain NFT metadata. Due to the high costs of on-chain data storage, most NFTs do not implement such validation methods, reducing trust in the NFT's off-chain metadata and increasing reliance on centralization. We propose a new method, inspired by the virtual ecology design of sandbox massively multiplayer online role-playing games (MMORPGs). This method utilizes a 256-bit unsigned integer representing a seed value, a Web3-compatible implementation of a pseudorandom number generator (W3PRNG), and an executable ruleset containing attribute definitions and their probability spaces to procedurally generate NFTs. This methodology provides users with a provably fair way of generating NFTs in an open-ended minting smart contract by imitating Proof-of-Work mining, including an arbitrary amount of work to be performed while initializing the PRNG. Due to the extremely large state space of 2^256 possible seeds, any implementation makes the NFT's economy inherently inflationary, offering more attractive features and higher utility in Web3 and Metaverse design than existing fixed supply NFT collections. Furthermore, such a system implicitly guarantees the veracity of off-chain metadata based on the on-chain seed value and the smart contract's immutable integrity configuration. (First published to the Future of Gaming Discord community in November, 2022)
Gang Tian, Guangxin Zhao, Rui Wang, Jiachang Wang · 5 authors
Abstract How to quickly and accurately retrieve relevant smart contracts from a huge amount of smart contracts has become an urgent need for users. The classification of smart contracts offers a solution by narrowing down the search space. Existing smart contract classification methods suffer from incomplete semantic feature extraction and a lack of consideration of the existence of rich semantics in existing smart contracts of the same class. To address the above problems, we propose a contrast learning and semantic feature embedding approach to enhance K-Nearest Neighbor (CL-SFE-IKNN). Our method fuses local features, global features, and account transaction features of the smart contract source code to perfect the semantics of the contract. Our method adopts KNN to retrieve multiple instances of contracts in the same class and assigns weights to the model output based on their labels. Meanwhile, we introduce contrastive learning and semantic feature embedding to enhance KNN retrieval to high-quality nearest neighbors of the same class. Experimental results show that by combining a KNN classifier with a traditional linear classifier, our model achieves the best performance compared with other baseline models.
H Kavitha, Y R Darshan, Subramanya Joshi, S V Nandeesh · 5 authors
As cloud computing becomes increasingly prevalent, the security and privacy of e-KYC (Electronic Know Your Customer) documents stored in the cloud have become critical concerns. Traditional e-KYC systems rely on centralized databases and cloud storage, posing risks of cyber-attacks and data breaches. This project proposes a blockchain-based e-KYC system for digital identity verification, offering a secure, efficient, and reliable solution. Our system ensures data integrity through a distributed ledger, with encryption adding an extra layer of protection against unauthorized access and cyber threats. Incorporating a fingerprint mechanism and batch verification enhances security and efficiency. The decentralized nature of blockchain reduces reliance on central authorities, streamlining the verification process and minimizing operational costs. Leveraging blockchain's core attributes-decentralization, immutability, and transparency-this e-KYC framework provides a robust solution tailored for banking, telecommunications, and government services, ensuring a secure, efficient, and reliable identity verification process.
Hao Luo, Yuhao Lin, Yan Xiao, Xuejiao Hu · 8 authors
Smart contract is a kind of self-executing code based on blockchain technology with a wide range of application scenarios, but the traditional generation method relies on manual coding and expert auditing, which has a high threshold and low efficiency. Although Large Language Models (LLMs) show great potential in programming tasks, they still face challenges in smart contract generation w.r.t. effectiveness and security. To solve these problems, we propose FSM-SCG, a smart contract generation framework based on finite state machine (FSM) and LLMs, which significantly improves the quality of the generated code by abstracting user requirements to generate FSM, guiding LLMs to generate smart contracts, and iteratively optimizing the code with the feedback of compilation and security checks. The experimental results show that FSM-SCG significantly improves the quality of smart contract generation. Compared to the best baseline, FSM-SCG improves the compilation success rate of generated smart contract code by at most 48%, and reduces the average vulnerability risk score by approximately 68%.
In order to ensure the security of data access, correlative control and operational auditing are critical. After years of development, access control models with different properties have been applied under different conditions. However, the centralized access control model has defects such as single-point failure threats and poor scalability. As an emerging distributed data management technology, blockchain can make up for these shortcomings with its advantages of openness, transparency and traceability of operations, and can achieve audit goals. Given the characteristics of blockchain and smart contracts, we design and implement an attribute-based access control model based on the consortium blockchain and smart contracts. Moreover, considering potential policy conflicts, we add two different policy conflict handling methods based on smart contracts to enhance the security of the model. Finally, we tested the main interfaces of the model under different loads. We find that adding a policy conflict handling module will cause extra performance loss. Therefore, choosing suitable conflict handling method based on the application scenario is worth considering.
The application of Internet of Vehicles (IoV) technology has greatly improved users’ driving experience, but it also faces some challenges: 1) the central server is not powerful enough to support the rapid growth of IoV identity authentication requests and 2) there is a privacy leakage issue during vehicle authentication. To address these issues, we propose an anonymous authentication scheme based on trustworthy roadside unit group (TRUG)-PBFT main secondary chains and zero-knowledge proof (ZKP). First, to enhance authentication efficiency, we propose the TRUG-PBFT consensus algorithm. It improves the traditional PBFT by optimizing the PBFT consensus process, reducing the number of consensus nodes using fractional grouping, and selecting main node using verifiable random functions (VRFs). Second, we use a lattice-based ZKP scheme to achieve anonymous authentication of vehicles, and important data in the vehicle authentication process is stored by the main chain maintained by the base station group and the secondary chain maintained by the roadside unit group. Finally, experimental results demonstrate that compared to PBFT consensus, TRUG-PBFT in terms of consensus efficiency is improved by approximately 33%, and the authentication scheme’s computational cost is only 7.08 ms, superior to existing authentication schemes.
Zhiyang Chen, Ye Liu, Sidi Mohamed Beillahi, Yi Li · 5 authors
Smart contracts, self-executing programs on the blockchain, facilitate reliable value exchanges without centralized oversight. Despite the recent focus on dynamic analysis of their transaction histories in both industry and academia, no open-source tool currently offers comprehensive tracking of complete transaction information to extract user-desired data such as invariant-related data. This paper introduces OpenTracer, designed to address this gap. OpenTracer guarantees comprehensive tracking of every execution step, providing complete transaction information. OpenTracer has been employed to analyze 350,800 Ethereum transactions, successfully inferring 23 different types of invariant from predefined templates. The tool is fully open-sourced, serving as a valuable resource for developers and researchers aiming to extract or validate new invariants from transaction traces. A demonstration video of OpenTracer is available at https://youtu.be/vTdmjWdYd30. The source code of OpenTracer is available at https://github.com/jeffchen006/OpenTracer.
M. Albrecht, Matilda Backendal, Daniele Coppola, Kenneth G. Paterson
Nextcloud is a leading cloud storage platform with more than 20 million users. Nextcloud offers an end-to-end encryption (E2EE) feature that is claimed to be able “to keep extremely sensitive data fully secure even in case of a full server breach”. They also claim that the Nextcloud server “has Zero Knowledge, that is, never has access to any of the data or keys in unencrypted form”. This is achieved by having encryption and decryption operations that are done using file keys that are only available to Nextcloud clients, with those file keys being protected by a key hierarchy that ultimately relies on long passphrases known exclusively to the users. We provide the first detailed documentation and security analysis of Nextcloud's E2EE feature. Nextcloud's strong security claims motivate conducting the analysis in the setting where the server itself is considered malicious. We present three distinct attacks against the E2EE security guarantees in this setting. Each one enables the confidentiality and integrity of all user files to be compromised. All three attacks are fully practical and we have built proof-of-concept implementations for each. The vulnerabilities make it trivial for a malicious Nextcloud server to access and manipulate users' data. We have responsibly disclosed the three vulnerabilities to N extcloud. The second and third vulnerabilities have been remediated. The first was addressed by temporarily disabling file sharing from the E2EE feature until a redesign of the feature can be made. We reflect on broader lessons that can be learned for designers of E2EE systems.
The proposed system introduces a decentralized platform built on the Ethereum blockchain, enabling users to acquire, trade, and utilize unique domain names as cryptographic identifiers. Leveraging the ERC-721 standard for non-fungible tokens (NFTs), the platform ensures the secure and transparent ownership of digital assets. The system integrates with the popular MetaMask wallet for user authentication, offering a seamless and widely-adopted solution. Users can mint new domains, buy existing ones, and list owned domains for sale, all facilitated by smart contracts governing domain creation, ownership transfer, and transaction execution. The architecture emphasizes security measures, such as code audits, access controls, and encryption, to safeguard user assets. The platform not only provides a novel approach to digital asset ownership but also simplifies cryptocurrency transactions by allowing users to conduct transactions using easily memorable domain names rather than complex wallet addresses. This research paper explores the technical intricacies, security considerations, and user interactions within the Crypto Domains ecosystem, contributing to the broader understanding of decentralized applications and non-fungible token platforms.
Dincy R. Arikkat, Mert Cihangiroglu, Mauro Conti, Rafidha Rehiman K. A. · 7 authors
The rise of IT-dependent operations in modern organizations has heightened their vulnerability to cyberattacks. Organizations are inadvertently enlarging their vulnerability to cyber threats by integrating more interconnected devices into their operations, which makes these threats both more sophisticated and more common. Consequently, organizations have been compelled to seek innovative approaches to mitigate the menaces inherent in their infrastructure. In response, considerable research efforts have been directed towards creating effective solutions for sharing Cyber Threat Intelligence (CTI). Current information-sharing methods lack privacy safeguards, leaving organizations vulnerable to proprietary and confidential data leaks. To tackle this problem, we designed a novel framework called SeCTIS (Secure Cyber Threat Intelligence Sharing), integrating Swarm Learning and Blockchain technologies to enable businesses to collaborate, preserving the privacy of their CTI data. Moreover, our approach provides a way to assess the data and model quality and the trustworthiness of all the participants leveraging some validators through Zero Knowledge Proofs. Extensive experimentation has confirmed the accuracy and performance of our framework. Furthermore, our detailed attack model analyzes its resistance to attacks that could impact data and model quality. • Definition of a Swarm Learning approach for collaborative CTI. • Definition of a Blockchain-based solution for privacy preservation in CTI sharing. • Secure CTI validation using a consensus mechanism and Zero-Knowledge Proof.
Jelena Gjorgjev, Nexhibe Sejfuli-Ramadani, Valentina Angelkoska, Pero Latkoski · 5 authors
This paper performs a comparative examination of well-known blockchain networks and their corresponding layers, with a specific focus on their effectiveness and appropriateness for developing decentralized applications (DApps). The evaluation of platforms like Ethereum, Binance Smart Chain, Solana, and Cardano involves a combination of literature review, empirical data collecting, and qualitative assessments. The parameters used for evaluation include transaction speed, scalability, fees, and community support. The research delineates distinct attributes of Layer 1 and Layer 2 solutions that impact the performance of DApps and their adoption by users. The findings suggest that Ethereum continues to be the most inclusive platform for developers, thanks to its advanced smart contract capabilities and wide range of tools. However, Solana and Binance Smart Chain have distinct benefits in terms of transaction speed and cost-effectiveness, making them more suitable for DApps that require a large number of transactions with minimal user interaction. Cardano's Ouroboros consensus algorithm offers a combination of sustainability and scalability, making it well-suited for DApps that demand robust security procedures. The results indicate that the selection of a blockchain network and layer should be strategically aligned with the operational needs and target audience of the DApp, with a focus on the trade-offs between decentralization, security, and performance efficiency.
Advancements in blockchain technologies empower society with trust-based applications. Smart contracts, which are programs designed to facilitate activities on the blockchain, serve as important instruments for executing agreements. Smart contracts are established among involved parties to codify their respective requirements and commitments. In various situations, where a smart contract manages substantial and valuable transactions, the likelihood of encountering issues and asset losses increases significantly. Therefore, it becomes essential to verify and test smart contracts thoroughly. In this paper, we present a new tool to measure condition coverage criterion for smart contracts using Solidity-based model checkers. We demonstrate the process of annotating the original smart contract by the condition coverage properties and employ the model checker to validate the feasibility of the specified properties. Further, we assess the properties instrumented to compute the condition coverage score. We conducted experiments on 70 smart contracts, employing both the Bounded Model Checker (BMC) and Constrained Horn Clauses (CHC). Our findings demonstrate BMC's superior performance compared to CHC. The tool we propose assists smart contract developers in verifying their code through condition coverage analysis. Utilizing both model checkers in tandem contributes to enhancing the quality of smart contracts, as the outcome may vary, and either of the checkers might yield superior condition coverage. Video-cast: https://youtu.beI13kuIjpPGPI?si=YQIWYPJhp7vzORI4
In this era, significant transformations in industries and tool utilization are driven by AI/Large Language Models (LLMs) and advancements in Machine Learning. There’s a growing emphasis on MLOps for managing and deploying these AI models, along with a focus on distributed inferences. Concurrently, the imperative for secure on-chain computation is escalating. Our paper introduces an innovative framework that integrates blockchain technology, particularly the Cosmos SDK, to facilitate distributed AI inferences on edge devices. This system, built on WebAssembly (WASM), enables interchain communication and deployment of WASM modules executing AI inferences across multiple blockchain nodes. We critically assess this system’s safety, scalability, and model security, with a special focus on its portability and engine-model agnostic deployment on edge devices.
Sebastian Bănescu, Morena Barboni, Andrea Morichetta, Andrea Polini · 5 authors
Smart contracts hold the potential to revolutionize various industries, but their implementation requires thorough testing due to the associated financial risks. Mutation testing is a powerful technique that can boost the fault-detection capabilities of a test suite, but it can also foster a deeper understanding of smart contract behavior. This work investigates the productivity of mutants with respect to their capabilities in disclosing Solidity issues. Based on these findings, it proposes an enhanced mutation strategy to better assist smart contract auditors during code inspection activities. 9 novel mutation operators are introduced in this paper and 13 existing operators are improved. The results show a $30 \%$ reduction in the number of generated mutants and time savings of $62 \%$, while increasing the set of productive mutants related to issues by $43 \%$ overall. We note that the most valuable type of mutants that could help disclose an issue as a result of manual mutant inspection was increased by $125 \%$.