Uncontrolled Randomness in Blockchains: Covert Bulletin Board for Illicit Activity

被引:14
作者
Alsalami, Nasser [1 ]
Zhang, Bingsheng [2 ]
机构
[1] Univ Lancaster, Lancaster, England
[2] Zhejiang Univ, Hangzhou, Peoples R China
来源
2020 IEEE/ACM 28TH INTERNATIONAL SYMPOSIUM ON QUALITY OF SERVICE (IWQOS) | 2020年
关键词
SIGNATURES;
D O I
10.1109/iwqos49365.2020.9213064
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Public blockchains can be abused to covertly store and disseminate potentially harmful digital content which poses a serious regulatory issue. In this work, we show the severity of the problem by demonstrating that blockchains can be exploited to surreptitiously distribute arbitrary content. More specifically, all major blockchain systems use randomized cryptographic primitives, such as digital signatures and non-interactive zero-knowledge proofs; we illustrate how the uncontrolled randomness in such primitives can be maliciously manipulated to enable covert communication and hidden persistent storage. To clarify the potential risk, we design, implement and evaluate our technique against the widely-used ECDSA signature scheme, the CryptoNote's ring signature scheme, and Monero's ring confidential transactions. Importantly, the significance of the demonstrated attacks stems from their undetectability, their adverse effect on the future of decentralized blockchains, and their serious repercussions on users' privacy and crypto funds. Finally, we present a generic framework to immunize blockchains against these attacks.
引用
收藏
页数:10
相关论文
共 50 条
  • [1] A Subversion-Resistant SNARK
    Abdolmaleki, Behzad
    Baghery, Karim
    Lipmaa, Helger
    Zajac, Michal
    [J]. ADVANCES IN CRYPTOLOGY - ASIACRYPT 2017, PT III, 2017, 10626 : 3 - 33
  • [2] Abe M, 2002, LECT NOTES COMPUT SC, V2501, P415
  • [3] Anderson R., 1996, Information Hiding. First International Workshop Proceedings, P39
  • [4] On the limits of steganography
    Anderson, RJ
    Petitcolas, FAP
    [J]. IEEE JOURNAL ON SELECTED AREAS IN COMMUNICATIONS, 1998, 16 (04) : 474 - 481
  • [5] [Anonymous], 2018, Cryptocurrency Market Capitalizations
  • [6] [Anonymous], 2012, BROADCAST KEY ENCAPS
  • [7] [Anonymous], 2018, FC 2018
  • [8] [Anonymous], 2018, CONFIDENTIAL T
  • [9] Subversion-Resilient Signature Schemes
    Ateniese, Giuseppe
    Magri, Bernardo
    Venturi, Daniele
    [J]. CCS'15: PROCEEDINGS OF THE 22ND ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, 2015, : 364 - 375
  • [10] Redactable Blockchain - or - Rewriting History in Bitcoin and Friends
    Ateniese, Giuseppe
    Magri, Bernardo
    Venturi, Daniele
    Andrade, Ewerton R.
    [J]. 2017 IEEE EUROPEAN SYMPOSIUM ON SECURITY AND PRIVACY (EUROS&P), 2017, : 111 - 126