Recurring Contingent Service Payment

Recurring Contingent Service Payment
复制标题

DOI:
10.1109/eurosp57164.2023.00049
复制
发表时间:
2022-07
期刊:
2023 IEEE 8th European Symposium on Security and Privacy (EuroS&P)
影响因子:
--
通讯作者:
A. Abadi;S. Murdoch;T. Zacharias
A. Abadi;S. Murdoch;T. Zacharias
中科院分区:
其他
文献类型:
--
作者:
A. Abadi;S. Murdoch;T. Zacharias

文献摘要

相似文献

公平交换协议允许相互不信任的两方以任何一方都无法欺骗的方式交换数字数据。它们有各种各样的应用,例如数字物品的交换,或者买方/客户端和卖方/服务器之间的数字硬币和数字服务的交换。在这项工作中,我们正式定义并提出了一个通用的基于区块链的结构,称为“经常性应急服务支付”(RC-S-P)。它(i)允许在客户端和服务器之间安全地重新进行数字货币和可验证服务的公平交换,同时确保当且仅当服务器提供有效服务时才支付服务器,以及(ii)确保各方的隐私得到保护。RC-S-P支持任意可验证服务,例如“可检索性证明”(PoR)或可验证计算,并降低链上开销。我们的形式化处理和构造首次考虑了客户端或服务器是恶意的情况,并给出了可验证服务为PoR时RC-S-P的具体有效实例。我们实现了具体的实例化,并分析了其成本。当它处理一个4GB的外包文件时,验证者可以在90毫秒内检查证明,证明者和验证者之间的争议在0.1毫秒内解决。在CCS 2017上,提出了两个基于区块链的协议来支持数字货币的公平交换和某种可验证服务;即PoR。在这项工作中,我们表明,这些协议(i)容易受到搭便车攻击,使客户端能够在不向服务器付费的情况下接收服务,以及(ii)不适合当事人隐私问题的情况,例如,当服务器的证明状态或买方的文件大小必须对公众保持私密时。RC-S-P同时减轻了上述攻击并保护了各方的隐私。
Fair exchange protocols let two mutually distrustful parties exchange digital data in a way that neither party can cheat. They have various applications such as the exchange of digital items, or the exchange of digital coins and digital services between a buyer/client and seller/server.In this work, we formally define and propose a generic blockchain-based construction called "Recurring Contingent Service Payment" (RC-S-P). It (i) lets a fair exchange of digital coins and verifiable service reoccur securely between clients and a server while ensuring that the server is paid if and only if it delivers a valid service, and (ii) ensures the parties’ privacy is preserved. RC-S-P supports arbitrary verifiable services, such as "Proofs of Retrievability" (PoR) or verifiable computation and imposes low on-chain over-heads. Our formal treatment and construction, for the first time, consider the setting where either client or server is malicious.We also present a concrete efficient instantiation of RC-S-P when the verifiable service is PoR. We implemented the concrete instantiation and analysed its cost. When it deals with a 4-GB outsourced file, a verifier can check a proof in only 90 milliseconds, and a dispute between a prover and verifier is resolved in 0.1 milliseconds.At CCS 2017, two blockchain-based protocols were proposed to support the fair exchange of digital coins and a certain verifiable service; namely, PoR. In this work, we show that these protocols (i) are susceptible to a free-riding attack which enables a client to receive the service without paying the server, and (ii) are not suitable for cases where parties’ privacy matters, e.g., when the server’s proof status or buyer’s file size must remain private from the public. RC-S-P simultaneously mitigates the above attack and preserves the parties’ privacy.