Skip to main content
QUICK REVIEW

[论文解读] Bitcoin and Blockchain: Security and Privacy

Ehab Zaghloul, Tongtong Li|arXiv (Cornell University)|Apr 25, 2019
Blockchain Technology Applications and Security参考文献 52被引用 4
一句话总结

本文分析了比特币在安全与隐私方面面临的挑战,重点关注双重支付攻击、点对点网络漏洞以及钱包存储风险。通过概率模型评估攻击的盈利性,证明了即使拥有少于50%网络算力的攻击者最终也会失败,凸显了交易速度与安全信心之间的权衡。

ABSTRACT

A cryptocurrency is a decentralized digital currency that is designed for secure and private asset transfer and storage. As a currency, it should be difficult to counterfeit and double-spend. In this paper, we review and analyze the major security and privacy issues of Bitcoin. In particular, we focus on its underlying foundation, blockchain technology. First, we present a comprehensive background of Bitcoin and the preliminary on security. Second, the major security threats and countermeasures of Bitcoin are investigated. We analyze the risk of double-spending attacks, evaluate the probability of success in performing the attacks and derive the profitability for the attacker to perform such attacks. Third, we analyze the underlying Bitcoin peer-to-peer network security risks and Bitcoin storage security. We compare three types of Bitcoin wallets in terms of security, type of services and their trade-offs. Finally, we discuss the security and privacy features of alternative cryptocurrencies and present an overview of emerging technologies today. Our results can help Bitcoin users to determine a trade-off between the risk of double-spending attempts and the transaction time delay or confidence before accepting transactions. These results can also assist miners to develop suitable strategies to get involved in the mining process and maximize their profits.

研究动机与目标

  • 分析比特币区块链架构与交易机制中固有的安全与隐私风险。
  • 评估在不同网络条件下,双重支付攻击的可行性与盈利性。
  • 评估不同比特币钱包类型(热钱包、冷钱包、纸钱包)之间的安全权衡。
  • 研究比特币点对点网络基础设施中的网络级威胁及其影响。
  • 探索替代代币及新兴区块链技术中的隐私增强方案。

提出的方法

  • 使用两种概率模型,基于链式竞赛动态计算成功实施双重支付攻击的可能性。
  • 应用盈利性模型,评估攻击者的经济激励,综合考虑挖矿成本与收益。
  • 基于安全性、可用性与攻击面,对比分析三种比特币钱包类型——热钱包、冷钱包与纸钱包。
  • 分析比特币点对点网络中的网络级风险,如遮蔽攻击(eclipse attacks)与Sybil攻击。
  • 回顾基于CryptoNote区块链的隐私保护协议,如可追踪环签名与一次性环签名。
  • 评估新兴代币中旨在提升安全与隐私的前沿技术,包括新型共识机制。

实验结果

研究问题

  • RQ1在不同网络条件下,比特币中双重支付攻击的成功概率是多少?
  • RQ2发起双重支付攻击的经济盈利性如何?其与攻击者计算能力的关系是什么?
  • RQ3不同比特币钱包类型在安全性、可用性与风险暴露方面有何差异?
  • RQ4比特币点对点网络中的主要漏洞是什么?它们如何影响系统完整性?
  • RQ5像CryptoNote这样的新兴代币中隐私保护协议,在多大程度上改善了比特币在隐私方面的局限性?

主要发现

  • 拥有少于总网络算力50%的攻击者最终将输掉区块链扩展竞赛,导致双重支付攻击在长期内无利可图。
  • 随着确认数的增加,成功实施双重支付攻击的概率呈指数下降,明确揭示了交易延迟与交易被撤销风险之间的权衡关系。
  • 热钱包具有高可用性,但易受远程入侵;冷钱包与纸钱包则提供更强的安全性,但便利性较低。
  • 比特币点对点网络天然易受遮蔽攻击与Sybil攻击影响,恶意节点可接入并操纵交易传播。
  • 比特币公开账本设计本质上损害了用户隐私,尽管存在普遍误解,该系统并非匿名。
  • 如CryptoNote系统中的一次性环签名等新兴协议可检测并防止双重支付,但其在交易验证与可扩展性方面引入了新挑战。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。