Skip to main content
QUICK REVIEW

[論文レビュー] On Cyber Risk Management of Blockchain Networks: A Game Theoretic Approach

Shaohan Feng, Wenbo Wang|arXiv (Cornell University)|Apr 27, 2018
Blockchain Technology Applications and Security参考文献 35被引用数 11
ひとこと要約

本稿は、サイバー保険と予防的インfraストラクチャー投資を統合することで、ブロックチェーンのサイバーリスク管理のためのゲーム理論的枠組みを提案する。ブロックチェーンプロバイダー、保険会社、ユーザーの間の相互作用を二段階のスタックルベルクゲームとしてモデル化し、最適なセキュリティを達成するにはマイニングパワーの投資と保険料のバランスを取る必要があることを示している。攻撃者側の計算能力が高くなるとコストと保険料が上昇する一方、ブロックサイズは投資のインセンティブと攻撃成功確率に影響を与える。

ABSTRACT

Open-access blockchains based on proof-of-work protocols have gained tremendous popularity for their capabilities of providing decentralized tamper-proof ledgers and platforms for data-driven autonomous organization. Nevertheless, the proof-of-work based consensus protocols are vulnerable to cyber-attacks such as double-spending. In this paper, we propose a novel approach of cyber risk management for blockchain-based service. In particular, we adopt the cyber-insurance as an economic tool for neutralizing cyber risks due to attacks in blockchain networks. We consider a blockchain service market, which is composed of the infrastructure provider, the blockchain provider, the cyber-insurer, and the users. The blockchain provider purchases from the infrastructure provider, e.g., a cloud, the computing resources to maintain the blockchain consensus, and then offers blockchain services to the users. The blockchain provider strategizes its investment in the infrastructure and the service price charged to the users, in order to improve the security of the blockchain and thus optimize its profit. Meanwhile, the blockchain provider also purchases a cyber-insurance from the cyber-insurer to protect itself from the potential damage due to the attacks. In return, the cyber-insurer adjusts the insurance premium according to the perceived risk level of the blockchain service. Based on the assumption of rationality for the market entities, we model the interaction among the blockchain provider, the users, and the cyber-insurer as a two-level Stackelberg game. Namely, the blockchain provider and the cyber-insurer lead to set their pricing/investment strategies, and then the users follow to determine their demand of the blockchain service. Specifically, we consider the scenario of double-spending attacks and provide a series of analytical results about the Stackelberg equilibrium in the market game.

研究の動機と目的

  • プルーフ・オブ・ワークブロックチェーンのダブルスペンディング攻撃に対するセキュリティ脆弱性に対処すること。
  • 予防的インfraストラクチャー投資と反応的サイバー保険を組み合わせた経済的リスク管理枠組みを設計すること。
  • 市場環境下でのブロックチェーンプロバイダー、サイバー保険会社、ユーザーの戦略的相互作用をモデル化すること。
  • 合理的行動とリスク調整済み価格の下での均衡戦略を分析すること。
  • 攻撃者側の能力とブロックサイズが市場の結果とセキュリティインセンティブに与える影響を評価すること。

提案手法

  • ブロックチェーンサービス市場を、ブロックチェーンプロバイダーと保険会社をリーダーとし、ユーザーをフォロワーとする二段階のスタックルベルクゲームとしてモデル化する。
  • 保険会社が攻撃リスクの認識とブロックチェーンプロバイダーの投資に基づいて保険料を設定するリスク調整済み保険料メカニズムを統合する。
  • 後退帰納法を用いて、市場参加者全員の均衡戦略を導出する。
  • 攻撃者側の計算能力とブロックサイズ(1ブロックあたりの取引数)が投資、価格、需要に与える影響を分析する。
  • ユーザーがブロックチェーンサービスに価値を置く際に社会的外部効果を統合する。
  • 市場ゲームにおけるスタックルベルク均衡の存在および一意性に関する解析的条件を導出する。

実験結果

リサーチクエスチョン

  • RQ1攻撃リスクの下で利益を最大化するために、ブロックチェーンプロバイダーはインフラストラクチャー投資とサイバー保険の購入をどのように最適にバランスさせるか?
  • RQ2サイバー保険会社は、ブロックチェーンプロバイダーのリスクプロファイルと投資水準に応じて、どのように保険料を設定するか?
  • RQ3攻撃者側の計算能力は、ブロックチェーンプロバイダー、ユーザー、保険会社の均衡結果にどのような影響を与えるか?
  • RQ4ブロックサイズ(1ブロックあたりの取引数)は、投資インセンティブと攻撃成功確率にどのように影響を与えるか?
  • RQ5セキュリティ水準と認識されたリスクの変化に伴い、ユーザー需要とサービス価格はどのように反応するか?

主な発見

  • 攻撃者側の計算能力が高くなると、ブロックチェーンプロバイダーはセキュリティを維持するためにインフラストラクチャー投資を増加させざるを得ず、その結果コストが上昇し利益が減少する。
  • サイバー保険会社は、ブロックチェーンプロバイダーのコスト上昇にもかかわらず、攻撃リスクの上昇に応じて保険料を引き上げることで安定した利益を維持する。
  • 攻撃者側の計算能力が高くなると、ブロックチェーンプロバイダーの価格引き下げにもかかわらず、ユーザー需要はセキュリティの認識が低下するため減少する。
  • 大きなブロックサイズ(例:300件の取引)は、攻撃成功確率が攻撃者側の計算能力の増加に敏感になるのを緩和し、保険料の上昇率を低下させる。
  • 攻撃者側の計算能力が高くなると、ブロックチェーンプロバイダーのインフラストラクチャー投資比率(h*/(a + h*))は低下し、攻撃能力の増大に伴い投資のリターンが逓減する傾向を示している。
  • ブロックサイズが大きいと、ブロックごとのマイニング報酬と補償額が高いため、ブロックチェーンプロバイダーはインフラストラクチャー投資に対するインセンティブが強くなる。

より良い研究を、今すぐ始めましょう

論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。

クレジットカード登録不要

このレビューはAIが作成し、人間の編集者が確認しました。