Denial-of-Service Vulnerability of Hash-Based Transaction Sharding: Attack and Countermeasure

Denial-of-Service Vulnerability of Hash-Based Transaction Sharding: Attack and Countermeasure
复制标题

DOI:
10.1109/tc.2022.3174560
复制
发表时间:
2020-07
影响因子:
3.7
通讯作者:
Truc D. T. Nguyen;M. Thai
Truc D. T. Nguyen;M. Thai
中科院分区:
计算机科学2区
文献类型:
--
作者:
Truc D. T. Nguyen;M. Thai

文献摘要

相似文献

自 2016 年以来,分片已成为解决遗留区块链系统中可扩展性问题的一个吉祥解决方案。尽管分片具有极大提高区块链吞吐量的潜力,但它也有其自身的安全问题。为了简化决定放置交易的分片的过程,现有的分片协议使用基于哈希的交易分片,其中交易的哈希值决定其输出分片。不幸的是,我们表明这种机制打开了一个漏洞,可被利用来进行单分片洪泛攻击(一种拒绝服务(DoS)攻击),以压倒单个分片,最终降低整个系统的性能。为了对抗单分片泛洪攻击,我们提出了一种对策,通过拒绝使用基于哈希的交易分片来从本质上消除漏洞。该对策利用可信执行环境(TEE)让区块链验证器安全地执行交易分片算法,而开销可以忽略不计。我们为对策提供了正式的规范,并在通用可组合性(UC)框架中分析了其安全属性。最后,开发了概念验证来证明我们的解决方案的可行性和实用性。
Since 2016, sharding has become an auspicious solution to tackle the scalability issue in legacy blockchain systems. Despite its potential to strongly boost the blockchain throughput, sharding comes with its own security issues. To ease the process of deciding which shard to place transactions, existing sharding protocols use a hash-based transaction sharding in which the hash value of a transaction determines its output shard. Unfortunately, we show that this mechanism opens up a loophole that could be exploited to conduct a single-shard flooding attack, a type of Denial-of-Service (DoS) attack, to overwhelm a single shard that ends up reducing the performance of the system as a whole. To counter the single-shard flooding attack, we propose a countermeasure that essentially eliminates the loophole by rejecting the use of hash-based transaction sharding. The countermeasure leverages the Trusted Execution Environment (TEE) to let blockchain's validators securely execute a transaction sharding algorithm with a negligible overhead. We provide a formal specification for the countermeasure and analyze its security properties in the Universal Composability (UC) framework. Finally, a proof-of-concept is developed to demonstrate the feasibility and practicality of our solution.