论文标题

在区块链采矿中分享预扣攻击:技术报告

Share Withholding Attack in Blockchain Mining: Technical Report

论文作者

Chang, Sang-Yoon

论文摘要

加密货币使用工作证明(POW)达到分布的共识。对区块链安全的事先研究确定了基于预扣区块的财务激励攻击,这些攻击使攻击者妥协了受害者池并通过提交股票(赚取采矿的信用)来妥协并成为战俘贡献者,但要扣留块(没有对池的实际贡献)。我们提出了这种威胁,以在破坏其他矿工并引入预扣攻击(SWH)的同时为攻击者带来更大的奖励优势。 SWH拒绝股票以增加攻击者在池中的奖励付款,这与先前的威胁扣留的块相反,而建立在持有的持有威胁的基础上,以利用有关即将到来的块提交时间的信息,挑战了普遍确定的假设,即块提交时间是完全随机的,并且对发射者是完全随机的。我们通过确定确定攻击影响的关键系统和环境参数来分析SWH的激励兼容性和漏洞范围。我们的研究结果表明,SWH与块预扣扣的不公平奖励优势以牺牲协议的受害矿工为代价,而理性矿工将自私地推出SWH,以最大程度地提高其奖励利润。我们为新型SWH威胁的区块链和加密货币研究提供了信息,并包括潜在的对策方向,以促进这种研究和发展。

Cryptocurrency achieves distributed consensus using proof of work (PoW). Prior research in blockchain security identified financially incentivized attacks based on withholding blocks which have the attacker compromise a victim pool and pose as a PoW contributor by submitting the shares (earning credit for mining) but withholding the blocks (no actual contributions to the pool). We advance such threats to generate greater reward advantage to the attackers while undermining the other miners and introduce the share withholding attack (SWH). SWH withholds shares to increase the attacker's reward payout within the pool, in contrast to the prior threats withholding blocks, and rather builds on the block-withholding threats in order to exploit the information about the impending block submission timing, challenging the popularly established assumption that the block submission time is completely random and unknown to miners. We analyze SWH's incentive compatibility and the vulnerability scope by identifying the critical systems and environmental parameters which determine the attack's impact. Our results show that SWH in conjunction with block withholding yield unfair reward advantage at the expense of the protocol-complying victim miners and that a rational miner will selfishly launch SWH to maximize its reward profit. We inform the blockchain and cryptocurrency research of the novel SWH threat and include the potential countermeasure directions to facilitate such research and development.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源