CRII: SaTC: Discerning the Upgradeability of Smart Contracts in Blockchains From a Security Perspective

CRII:SaTC:从安全角度辨别区块链智能合约的可升级性

基本信息

  • 批准号:
    2245627
  • 负责人:
  • 金额:
    $ 17.48万
  • 依托单位:
  • 依托单位国家:
    美国
  • 项目类别:
    Standard Grant
  • 财政年份:
    2023
  • 资助国家:
    美国
  • 起止时间:
    2023-03-15 至 2024-12-31
  • 项目状态:
    已结题

项目摘要

Smart contracts in blockchains, which store cryptocurrencies and tokens worth billions of USD, have transformed many important aspects of our lives, such as finance and gaming. Smart contracts are widely believed to have strong security guarantees as they are immutable once deployed, not even the owner of the contract can change its code. However, a new type of smart contract, namely upgradeable smart contract (USC), allows developers to upgrade the logic of their smart contracts and practically breaks the security assumption. This special type of smart contract has become increasingly prominent and has been adopted by many major companies (e.g., Compound Finance and Opensea.io). Despite the importance, there exists no comprehensive research that studies the status quo of USCs in the wild and even worse, the emerging security risks that are associated with upgradeability. This project conducts a series of novel studies to discern the upgradeability of smart contracts in the real world. Specifically, it answers three essential research questions regarding the importance of USCs in the current market, different design patterns and their strengths and weaknesses, and more importantly, the real-world security risks with USCs. To do so, this project pioneers a practical static analysis-based approach to effectively detect USCs based on intrinsic characteristics, and perform further automatic behavior and security analyses. To differentiate USC design patterns, this project develops a complete taxonomy that can systematically characterize USCs at both syntactic and semantic levels. Moreover, the investigator conducts the first extensive and large-scale study on USCs to uncover and report unique designs and security risks in the real world. Eventually, this project creates the first comprehensive USC dataset that facilitates future research in this emerging direction.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
区块链中的智能合约存储了价值数十亿美元的加密货币和代币,改变了我们生活的许多重要方面,例如金融和游戏。智能合约被广泛认为具有强大的安全保障,因为它们一旦部署就不可变,即使是合约的所有者也不能更改其代码。然而,一种新型的智能合约,即可扩展智能合约(USC),允许开发人员升级其智能合约的逻辑,实际上打破了安全假设。这种特殊类型的智能合约已经变得越来越突出,并已被许多大公司采用(例如,Compound Finance和Opensea.io)。尽管重要,但目前还没有全面的研究来研究USCs在野外的现状,更糟糕的是,与可移植性相关的新出现的安全风险。该项目进行了一系列新颖的研究,以识别智能合约在真实的世界中的可识别性。具体来说,它回答了三个基本的研究问题,即USCs在当前市场中的重要性,不同的设计模式及其优缺点,更重要的是,USCs的现实安全风险。为此,该项目开创了一种实用的基于静态分析的方法,以有效地检测基于内在特征的USCs,并执行进一步的自动行为和安全分析。为了区分USC设计模式,本项目开发了一个完整的分类法,可以在语法和语义层面系统地描述USC。此外,调查人员还首次对USCs进行了广泛和大规模的研究,以发现和报告真实的世界中的独特设计和安全风险。最终,该项目创建了第一个全面的南加州大学数据集,促进了这一新兴方向的未来研究。该奖项反映了NSF的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。

项目成果

期刊论文数量(1)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
Proxy Hunting: Understanding and Characterizing Proxy-based Upgradeable Smart Contracts in Blockchains
  • DOI:
  • 发表时间:
    2023
  • 期刊:
  • 影响因子:
    0
  • 作者:
    William Edward Bodell;Sajad Meisami;Yue Duan
  • 通讯作者:
    William Edward Bodell;Sajad Meisami;Yue Duan
{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Binghui Wang其他文献

State Estimation via Inference on a Probabilistic Graphical Model - A Different Perspective
通过概率图形模型推理进行状态估计 - 不同的视角
Experimental analysis on the cyclic strength and deformation characteristics of marine coral sand under different loading frequencies
  • DOI:
    10.1016/j.soildyn.2024.109165
  • 发表时间:
    2025-03-01
  • 期刊:
  • 影响因子:
  • 作者:
    Ruirong Zhou;Shuanglong Xin;Binghui Wang;Lei Zhang;Yunfei Zhang;Qi Wu;Weijia Ma;You Qin
  • 通讯作者:
    You Qin
Rapid C to FPGA Prototyping with Multithreaded Emulation Engine
使用多线程仿真引擎快速进行 C 到 FPGA 原型设计
Phylogenetic characteristics of dengue virus revealed the hig relatedness 1 between imported and local strains during the dengue outbreak in 2013 in 2 Yunnan , China
登革热病毒的系统发育特征揭示了2013年2中国云南登革热暴发期间进口毒株与本地毒株之间的高度相关性1 。
  • DOI:
  • 发表时间:
    2014
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Binghui Wang;Yaping Li;Yue Feng;Hongning Zhou;Yaobo Liang;Jie;Dai;Weihong Qin;Yunzhang Hu;Yajuan Wang;Li Zhang;Z. Baloch;Heng;X. Xia
  • 通讯作者:
    X. Xia
Phylogenetic characteristics of HIV among female cross‐border travelers in Yunnan province between 2003 and 2012
2003-2012年云南省女性出境旅游者HIV病毒系统发育特征
  • DOI:
    10.1002/jmv.27079
  • 发表时间:
    2021-05
  • 期刊:
  • 影响因子:
    12.7
  • 作者:
    Ting Yang;Shuwen Liang;Shuting Yang;Yihan Lin;Ziqin Dian;Ting Zhao;Hui Su;A‐mei Zhang;Jingying Liu;Baoyang Huang;Yifan Zhang;Xueshan Xia;Binghui Wang;Weihong Qin
  • 通讯作者:
    Weihong Qin

Binghui Wang的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('Binghui Wang', 18)}}的其他基金

Collaborative Research: SHF: Small: LEGAS: Learning Evolving Graphs At Scale
协作研究:SHF:小型:LEGAS:大规模学习演化图
  • 批准号:
    2331302
  • 财政年份:
    2024
  • 资助金额:
    $ 17.48万
  • 项目类别:
    Standard Grant
CAREER: Towards Trustworthy Machine Learning via Learning Trustworthy Representations: An Information-Theoretic Framework
职业:通过学习可信表示实现可信机器学习:信息理论框架
  • 批准号:
    2339686
  • 财政年份:
    2024
  • 资助金额:
    $ 17.48万
  • 项目类别:
    Continuing Grant
CRII: SaTC: Towards Understanding the Robustness of Graph Neural Networks against Graph Perturbations
CRII:SaTC:了解图神经网络对抗图扰动的鲁棒性
  • 批准号:
    2241713
  • 财政年份:
    2023
  • 资助金额:
    $ 17.48万
  • 项目类别:
    Standard Grant

相似海外基金

CRII: SaTC: Automated Knowledge Representation for IoT Cybersecurity Regulations
CRII:SaTC:物联网网络安全法规的自动化知识表示
  • 批准号:
    2348147
  • 财政年份:
    2024
  • 资助金额:
    $ 17.48万
  • 项目类别:
    Standard Grant
CRII: SaTC: Reliable Hardware Architectures Against Side-Channel Attacks for Post-Quantum Cryptographic Algorithms
CRII:SaTC:针对后量子密码算法的侧通道攻击的可靠硬件架构
  • 批准号:
    2348261
  • 财政年份:
    2024
  • 资助金额:
    $ 17.48万
  • 项目类别:
    Standard Grant
CRII: SaTC: Privacy vs. Accountability--Usable Deniability and Non-Repudiation for Encrypted Messaging Systems
CRII:SaTC:隐私与责任——加密消息系统的可用否认性和不可否认性
  • 批准号:
    2348181
  • 财政年份:
    2024
  • 资助金额:
    $ 17.48万
  • 项目类别:
    Standard Grant
SaTC: CORE: Small: An evaluation framework and methodology to streamline Hardware Performance Counters as the next-generation malware detection system
SaTC:核心:小型:简化硬件性能计数器作为下一代恶意软件检测系统的评估框架和方法
  • 批准号:
    2327427
  • 财政年份:
    2024
  • 资助金额:
    $ 17.48万
  • 项目类别:
    Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Differentially Private SQL with flexible privacy modeling, machine-checked system design, and accuracy optimization
协作研究:SaTC:核心:中:具有灵活隐私建模、机器检查系统设计和准确性优化的差异化私有 SQL
  • 批准号:
    2317232
  • 财政年份:
    2024
  • 资助金额:
    $ 17.48万
  • 项目类别:
    Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Using Intelligent Conversational Agents to Empower Adolescents to be Resilient Against Cybergrooming
合作研究:SaTC:核心:中:使用智能会话代理使青少年能够抵御网络诱骗
  • 批准号:
    2330940
  • 财政年份:
    2024
  • 资助金额:
    $ 17.48万
  • 项目类别:
    Continuing Grant
CRII: SaTC: Evolving I/O Protocols for Confidential Computing
CRII:SaTC:用于机密计算的不断发展的 I/O 协议
  • 批准号:
    2348130
  • 财政年份:
    2024
  • 资助金额:
    $ 17.48万
  • 项目类别:
    Standard Grant
CRII: SaTC: Enforcing Expressive Security Policies using Trusted Execution Environments
CRII:SaTC:使用可信执行环境执行表达性安全策略
  • 批准号:
    2348304
  • 财政年份:
    2024
  • 资助金额:
    $ 17.48万
  • 项目类别:
    Standard Grant
Collaborative Research: NSF-BSF: SaTC: CORE: Small: Detecting malware with machine learning models efficiently and reliably
协作研究:NSF-BSF:SaTC:核心:小型:利用机器学习模型高效可靠地检测恶意软件
  • 批准号:
    2338301
  • 财政年份:
    2024
  • 资助金额:
    $ 17.48万
  • 项目类别:
    Continuing Grant
CRII: SaTC: The Right to be Forgotten in Follow-ups of Machine Learning: When Privacy Meets Explanation and Efficiency
CRII:SaTC:机器学习后续中被遗忘的权利:当隐私遇到解释和效率时
  • 批准号:
    2348177
  • 财政年份:
    2024
  • 资助金额:
    $ 17.48万
  • 项目类别:
    Standard Grant
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了