Qiping Wei, Fadul Sikder, Huadong Feng, Yu Lei, R. Kacker, Richard Kuhn
{"title":"SmartExecutor: Coverage-Driven Symbolic Execution Guided via State Prioritization and Function Selection","authors":"Qiping Wei, Fadul Sikder, Huadong Feng, Yu Lei, R. Kacker, Richard Kuhn","doi":"10.1145/3678188","DOIUrl":"https://doi.org/10.1145/3678188","url":null,"abstract":"Symbolic execution of smart contracts suffers from sequence explosion. Some existing tools limit the sequence length, thus being unable to adequately evaluate some functions. In this paper, we propose a symbolic execution approach without limiting the sequence length. In our approach, the symbolic execution process is a two-phase model that maximizes code coverage while reducing the number of sequences to be executed. The first phase executes all sequences up to a length limit to identify the not-fully covered functions while the second attempts to cover these functions according to state evaluation and a function graph structure. We have developed a tool called SmartExecutor and conducted an experimental evaluation on the SGUARD dataset. The experimental results indicate that compared with state-of-the-art tools, SmartExecutor achieves higher code coverage with less time. It also detects more vulnerabilities than Mythril, a state-of-the-art symbolic execution tool.","PeriodicalId":380482,"journal":{"name":"Distributed Ledger Technologies: Research and Practice","volume":"27 2","pages":""},"PeriodicalIF":0.0,"publicationDate":"2024-07-15","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"141646805","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
Andrea Pinna, M. I. Lunesu, Roberto Tonelli, Simone Sansoni
{"title":"Soulbound token applications. A case study in the health sector.","authors":"Andrea Pinna, M. I. Lunesu, Roberto Tonelli, Simone Sansoni","doi":"10.1145/3674155","DOIUrl":"https://doi.org/10.1145/3674155","url":null,"abstract":"This paper focuses on the concept of blockchain soulbound tokens, their potential applications, and their implementation in Ethereum-based blockchains. Soulbound tokens add an important piece to blockchain technology, as they could be the key to building Web3 and a trustworthy decentralized society. Issued and strictly linked to an account, representing the soul of a user, the soulbound token makes it possible to represent a property that only the user can have and that cannot be transferred, but only removed, which enhances security. To evaluate their impact on blockchain development, we first examine the concept of soulbound tokens, their potential applications, and their effective adoption. The application sectors include the creation of digital identity certificates, ownership certificates, reputational certificates, governance, and the healthcare sector. We then report and describe relevant blockchain token standards, including soulbound token standards, provided in the form of Ethereum Improvement Proposals. Finally, to study the efficacy of the implementation of soulbound tokens, we propose a case study that includes the design and development of a decentralized vaccine certification prototype based on soulbound tokens. In our system, the vaccination data produced by the health authority is fully decentralized and implemented as the issuance of soulbound tokens for the benefit of a citizen's soul account. As a result, the citizen is the only owner of the vaccination data.","PeriodicalId":380482,"journal":{"name":"Distributed Ledger Technologies: Research and Practice","volume":"147 4","pages":""},"PeriodicalIF":0.0,"publicationDate":"2024-07-03","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"141681809","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
{"title":"Scalable Anonymous Authentication Scheme Based on Zero-Knowledge Set-Membership Proof","authors":"Christopher Wiraatmaja, Shoji Kasahara","doi":"10.1145/3676285","DOIUrl":"https://doi.org/10.1145/3676285","url":null,"abstract":"In this paper, we propose zero-knowledge named proof, a stateless replay attack prevention strategy that ensures the user’s anonymity against malicious administrators. We begin with adopting the zero-knowledge set-membership proof into an authentication setting in which users would delegate their requests to an agent that obstructs the user’s identity from the administrator. This anonymous agent carries the guarantee of authenticity, which the administrator through the set-membership proof can confirm. Next, we prevent replay attacks from other parties by binding the agent’s identity to the authentication proof verifiable by the administrators. By leveraging these properties, a scalable blockchain-based authentication scheme is then built. We quantitatively evaluate the security and measure the time and monetary cost of our scheme under both ideal and realistic environments. On top of it, we provide a third-party authorization scheme derived from our authentication framework to demonstrate its real-world applicability.","PeriodicalId":380482,"journal":{"name":"Distributed Ledger Technologies: Research and Practice","volume":"31 2","pages":""},"PeriodicalIF":0.0,"publicationDate":"2024-07-02","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"141687699","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
Davide Mancino, Alberto Leporati, Marco Viviani, Giovanni Denaro
{"title":"A Role and Reward Analysis in Off-chain Mechanisms for Executing MEV Strategies in Ethereum Proof-of-Stake","authors":"Davide Mancino, Alberto Leporati, Marco Viviani, Giovanni Denaro","doi":"10.1145/3672405","DOIUrl":"https://doi.org/10.1145/3672405","url":null,"abstract":"Recently, the Ethereum blockchain changed its consensus algorithm from Proof-of-Work (PoW) to Proof-of-Stake (PoS). This change has greatly reduced overall energy consumption but has paved the way for the profiling of numerous mechanisms and actors that can operate off-chain to achieve Maximal Extractable Value (MEV). This raises questions about how transparent such a scenario is, both from the point of view of block validation power and from the point of view of the rewards achieved by distinct actors within the platform. To address this concern and to mitigate potential negative externalities, a permissionless ecosystem has recently been proposed that should be transparent and fair for the extraction of MEV. In this article, after briefly describing the new ecosystem, we conduct an in-depth analysis of Ethereum blocks and other information about the actors operating in the ecosystem, to highlight potential critical situations.","PeriodicalId":380482,"journal":{"name":"Distributed Ledger Technologies: Research and Practice","volume":"42 19","pages":""},"PeriodicalIF":0.0,"publicationDate":"2024-06-14","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"141344047","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
Christopher Natoli, Parinya Ekparinya, Guillaume Jourjon, Vincent Gramoli
{"title":"Blockchain Double Spending With Low Mining Power and Network Delays","authors":"Christopher Natoli, Parinya Ekparinya, Guillaume Jourjon, Vincent Gramoli","doi":"10.1145/3672403","DOIUrl":"https://doi.org/10.1145/3672403","url":null,"abstract":"\u0000 Traditional blockchain systems offer a secure way of tracking the ownership of digital assets as long as the attacker does not control a large portion of the overall computational or mining power. They typically require participants to generate a proof-of-work before proposing a block at a given index of the chain. To choose one block among the candidate blocks at the same index, Nakamoto’s consensus,\u0000 Ghost\u0000 and the original Ethereum’s consensus select, respectively, the longest branch, the heaviest subtree and the branch with the most difficult crypto-puzzles. This allows an attacker who can generate proofs-of-work faster than others to double spend by overwriting any given branch.\u0000 \u0000 \u0000 In this paper, we present a double spending attack, called the Balance attack, that simply needs to delay some messages. This result sheds new lights on an important, often implicit, assumption of the blockchain,\u0000 synchrony\u0000 , under which the transmission delay of any message should be within a known upper bound. We show that the attack succeeds with high probability on the protocols of the two largest blockchain systems in market capitalization, Bitcoin and Ethereum. To quantify the impact of our attack, we replicated the blockchain network run by fifty financial institutions and achieved double spending in less than 20 minutes. Finally, we demonstrate the success of the attack empirically by modifying the\u0000 geth\u0000 software and hijacking BGP in a controlled distributed system whose distribution of mining power is set to the distribution observed on the Ethereum main blockchain.\u0000","PeriodicalId":380482,"journal":{"name":"Distributed Ledger Technologies: Research and Practice","volume":"10 1","pages":""},"PeriodicalIF":0.0,"publicationDate":"2024-06-13","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"141346692","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
{"title":"BB-FLoC: A Blockchain-based Targeted Advertisement Scheme with K-Anonymity","authors":"Edvinas Kruminis, K. Navaie, Onur Ascigil","doi":"10.1145/3672404","DOIUrl":"https://doi.org/10.1145/3672404","url":null,"abstract":"New data protection regulations, e.g., General Data Protection Regulation (GDPR), enforced advertisement providers to amend their conventional approaches, enhancing users’ data privacy. As a result, major Internet browsers such as Apple Safari and Firefox were quick to announce their plans to remove third-party cookies from their browsers entirely. In an effort to preserve conventional advertising practices, Google proposed a Federated Learning of Cohorts (FLoC) system to deliver higher privacy guarantees to users whilst also providing interest-based advertising. In FLoC, users sharing similar browsing histories are put into cohorts, and thus advertisements can be targeted to them as a group, rather than individually. Since each user independently calculates their cohort group, a minimum cohort size cannot be enforced, making them vulnerable to identification and tracking. To address this issue, in this paper, a blockchain-based FLoC (BB-FLoC) system is proposed that guarantees k-anonymity for its users whilst at the same time allowing for effective personalised advertising. We further evaluate the operational feasibility of such a design and demonstrate that k-anonymity guarantees can be fulfilled in a fully decentralized manner in the proposed system. The proposed system is relatively lightweight, showcasing that it can be adapted for low-end devices such as mobile phones.","PeriodicalId":380482,"journal":{"name":"Distributed Ledger Technologies: Research and Practice","volume":"44 18","pages":""},"PeriodicalIF":0.0,"publicationDate":"2024-06-13","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"141345570","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
{"title":"Self-Regulated Adaptive Data Distribution for Redundant and Scalable Blockchain Storage","authors":"Azam Khan, Ashiq Anjum, A. V. Moorsel","doi":"10.1145/3665651","DOIUrl":"https://doi.org/10.1145/3665651","url":null,"abstract":"Collaborative blockchain storage is one of the solutions to the blockchain storage scalability challenge, allowing individual nodes to store partial blockchain data. Collaborative blockchains give up redundancy for scalability. However, redundancy is a determinant of blockchain’s decentralization and data availability. In this article, we study the possibility of balancing the scalability-redundancy trade-off in collaborative blockchains. We first present a model for the evaluation of a data distribution scheme for its efficiency in terms of redundancy. Then, we present a fully decentralized self-regulated data distribution scheme assuring storage scalability and redundancy for collaborative blockchains based on fully redundant global state. The proposed solution does not incur additional communication. We examine the efficiency of the proposed scheme based on experiments. Our results demonstrate that the proposed system assures a level of redundancy for a given set of nodes and data volume, optimizes storage space utilization and provides uniform distribution of data.","PeriodicalId":380482,"journal":{"name":"Distributed Ledger Technologies: Research and Practice","volume":"19 1","pages":""},"PeriodicalIF":0.0,"publicationDate":"2024-05-22","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"141108070","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
Xueqin Liang, Xiaokang Wang, Chonggang Wang, W. Pedrycz
{"title":"Introduction to the Special Issue on Recent Advances of Blockchain Evolution: Architecture and Performance","authors":"Xueqin Liang, Xiaokang Wang, Chonggang Wang, W. Pedrycz","doi":"10.1145/3664827","DOIUrl":"https://doi.org/10.1145/3664827","url":null,"abstract":"","PeriodicalId":380482,"journal":{"name":"Distributed Ledger Technologies: Research and Practice","volume":"57 1","pages":""},"PeriodicalIF":0.0,"publicationDate":"2024-05-22","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"141108519","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
Can Zhao, Yibing Wang, Dejun Wang, Guangyan Sun, Bo Meng
{"title":"A Language-independent Quantitative Analysis Method on Conformance between Legal Contract and Smart Contract","authors":"Can Zhao, Yibing Wang, Dejun Wang, Guangyan Sun, Bo Meng","doi":"10.1145/3653679","DOIUrl":"https://doi.org/10.1145/3653679","url":null,"abstract":"The analysis on conformance between legal contracts and smart contracts is necessary and precondition for constructing the secure blockchain. Currently, the analysis method is the language-dependent single qualitative analysis. There doesn't exist quantitative metrics and quantitative analysis methods. Hence the quantitative metric and language-independent quantitative analysis method are proposed to analyze the conformance between legal contract and smart contract. First, the definitions and metrics of partial conformance and complete conformance are proposed, and then rewrite logic and language-independent symbol execution are used to construct a language-independent quantitative method; Then, the executable formal semantic for legal contract description language Business Process Model and Notation2.0 (BPMN2.0) is presented. Finally, the conformance of the five main methods for mapping BPMN2.0 legal contracts to Solidity smart contracts is analyzed. The results show that three methods have partial conformance, one method has complete conformance, and one method hasn't complete conformance and partial conformance.","PeriodicalId":380482,"journal":{"name":"Distributed Ledger Technologies: Research and Practice","volume":"105 5","pages":""},"PeriodicalIF":0.0,"publicationDate":"2024-03-26","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"140380712","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
{"title":"Card Payment Protocol for Cryptocurrencies with Payment Channel Network","authors":"Anupa De Silva, S. Thakur, John G. Breslin","doi":"10.1145/3653681","DOIUrl":"https://doi.org/10.1145/3653681","url":null,"abstract":"Cryptocurrency, despite the upsurge as a speculative investment, is still a long way from being people’s money. The extreme technicality poses a significant barrier for the general public to adopt it as a medium of exchange. Therefore, simplifying the payment process is a predominant necessity; for example, facilitation in adopting conventional payment instruments can bring convenience to both merchants and consumers. This paper proposes a novel cryptocurrency card payment protocol leveraging the Payment Channel Network (PCN) concept, facilitating high throughput and affordable transactions. Our design is based on the Bitcoin-backed Lightning Network (LN) with adjustments to make it executable by a smart card. It also preserves the decentralized nature of cryptocurrencies, reduces operational costs in several ways, and allows instant settlement for the recipients as compared to both conventional and cryptocurrency card payment systems. Our game theoretical analysis, where we model the engagement between the cardholder and the card agent as a long-run extensive form game, attests that they accord with the protocol without experiencing any honest loss under pragmatic conditions. We also discuss the privacy features compared to conventional card payments and LN. The protocol can function independently, without the need for trust, and can also be regulated for those seeking government mediation. This approach can potentially revolutionize the payment landscape by allowing the public to use cryptocurrency for everyday transactions conveniently and allowing existing cryptocurrency holders to conduct affordable micropayments.","PeriodicalId":380482,"journal":{"name":"Distributed Ledger Technologies: Research and Practice","volume":"123 50","pages":""},"PeriodicalIF":0.0,"publicationDate":"2024-03-26","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"140378954","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}