Ekiden: A Platform for Confidentiality-Preserving, Trustworthy, and Performant Smart Contracts

Ekiden: A Platform for Confidentiality-Preserving, Trustworthy, and Performant Smart Contracts
复制标题

DOI:
10.1109/eurosp.2019.00023
复制
发表时间:
2018-04
期刊:
2019 IEEE European Symposium on Security and Privacy (EuroS&P)
影响因子:
--
通讯作者:
Raymond Cheng;Fan Zhang;Jernej Kos;Warren He;Nicholas Hynes;Noah M. Johnson;A. Juels;Andrew K. Miller-Andre
Raymond Cheng;Fan Zhang;Jernej Kos;Warren He;Nicholas Hynes;Noah M. Johnson;A. Juels;Andrew K. Miller-Andre
中科院分区:
其他
文献类型:
--
作者:
Raymond Cheng;Fan Zhang;Jernej Kos;Warren He;Nicholas Hynes;Noah M. Johnson;A. Juels;Andrew K. Miller-Andre

文献摘要

被引文献

相似文献

智能合约是在区块链上执行的应用程序。今天,他们管理着数十亿美元的价值,并推动了广泛的区块链部署的有远见的计划。虽然智能合约继承了区块链的可用性和其他安全保证,但它们受到区块链缺乏保密性和性能低下的阻碍。我们提出了Ekiden,一个通过将区块链与可信执行环境(TEE)相结合来解决这些关键差距的系统。Ekiden利用一种新颖的架构,将共识与执行分离,实现了高效的TEE支持的保密智能合约和高可扩展性。我们的原型(使用Tendermint作为共识层)实现了比以太坊主网高600倍的吞吐量和低400倍的延迟,成本低1000倍的示例性能。本文的另一个贡献是,我们系统地识别和处理了协调TEE和区块链所产生的陷阱。分别对待,TEE和区块链都提供了强大的保障,但混合起来,它们会产生新的攻击。例如,在幼稚的设计中,TEE支持的合同中的隐私可能会受到伪造区块的危害,这是一种看似无关的攻击向量。我们相信从Ekiden学到的见解将在混合TEE区块链系统中具有广泛的重要性。
Smart contracts are applications that execute on blockchains. Today they manage billions of dollars in value and motivate visionary plans for pervasive blockchain deployment. While smart contracts inherit the availability and other security assurances of blockchains, however, they are impeded by blockchains' lack of confidentiality and poor performance. We present Ekiden, a system that addresses these critical gaps by combining blockchains with Trusted Execution Environments (TEEs). Ekiden leverages a novel architecture that separates consensus from execution, enabling efficient TEE-backed confidentiality-preserving smart-contracts and high scalability. Our prototype (with Tendermint as the consensus layer) achieves example performance of 600x more throughput and 400x less latency at 1000x less cost than the Ethereum mainnet. Another contribution of this paper is that we systematically identify and treat the pitfalls arising from harmonizing TEEs and blockchains. Treated separately, both TEEs and blockchains provide powerful guarantees, but hybridized, though, they engender new attacks. For example, in naïve designs, privacy in TEE-backed contracts can be jeopardized by forgery of blocks, a seemingly unrelated attack vector. We believe the insights learned from Ekiden will prove to be of broad importance in hybridized TEE-blockchain systems.