Potential Risks of Hyperledger Fabric Smart Contracts

被引:0
作者
Yamashita, Kazuhiro [1 ]
Nomura, Yoshihide [1 ]
Zhou, Ence [2 ]
Pi, Bingfeng [2 ]
Jun, Sun [2 ]
机构
[1] Fujitsu Labs Ltd, Kawasaki, Kanagawa, Japan
[2] FUJITSU Res & Dev Ctr, Beijing, Peoples R China
来源
2019 IEEE 2ND INTERNATIONAL WORKSHOP ON BLOCKCHAIN ORIENTED SOFTWARE ENGINEERING (IWBOSE) | 2019年
关键词
Smart Contract; Validation Tool; Blockchain; Hyperledger Fabric;
D O I
10.1109/iwbose.2019.8666486
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Blockchain is a decentralized ledger technology, and it is the technology underlying Bitcoin and Ethereum. The interest in blockchain has been increasing since its emergence. Hyperledger Fabric is one of the permissioned blockchain frameworks. One of the characteristics of Hyperledger Fabric is it utilizes general-purpose programming languages, e.g., Go, Node.js, and Java, to implement smart contracts (called chaincode in Hyperledger Fabric). The advantages of utilizing these languages are already known to potential developers, and development tools might already exist. However, one of the disadvantages is that these languages were not originally designed for writing smart contracts. Hence, there may be risks that developers do not need to consider when using specific languages such as Solidity of Ethereum. Furthermore, even though development tools exist, how many risks are covered by the tools is an open question. In this paper, we focus on Go language and the tools. First, we surveyed what kind of risks are associated with chaincodes are developed using Go language and observed there are 14 potential risks. Then, we investigated how many risks can be covered by Go tools, e.g., golint and gosec, and a vulnerability detection tool for chaincodes called Chaincode Scanner. From our results, we observed that some risks are not covered by the existing tools. Hence, we develop a detection tool to cover risks by static analysis. Finally, in this paper, we describe how to find the risks with our tool and evaluate the usefulness.
引用
收藏
页码:1 / 10
页数:10
相关论文
共 28 条
[1]  
[Anonymous], 2017, CORR
[2]  
[Anonymous], 2018, PROC 9 ANN HITB SECU
[3]  
[Anonymous], P EUROSYS C
[4]  
[Anonymous], 2016, CORR
[5]  
[Anonymous], CORR
[6]  
[Anonymous], CORR
[7]  
[Anonymous], 2018, CORR ABS180909805
[8]  
[Anonymous], P ISOC S NETW DISTR
[9]  
[Anonymous], P INT S MOD AN SIM C
[10]  
[Anonymous], CORR