HC
H. Chen
info
Please Note
<p>This page displays the records of the person named above and is not linked to a unique person identifier. This record may need to be merged to a profile.</p>
5 records found
1
Within the context of the Ethereum blockchain protocol, reentrancy is a well-known and well-researched smart contract vulnerability. However, when considering GoQuorum, an Ethereum soft fork, barely any research discussing smart contract vulnerabilities exists. This report aims to partly fill this research gap by evaluating the reentrancy smart contract vulnerability in the context of a GoQuorum network. First, the reentrancy attack was demonstrated and its attack features evaluated. Then any known countermeasures were collected. Moreover, it was proposed that some GoQuorum features may also be used as mitigation techniques. Finally, each countermeasure was assessed and categorized. Of all the methods, the checks-effects-interactions pattern is the most direct way to deal with the reentrancy vulnerability. To maximize contract security, however, it is advised to use a combination of the specified prevention and mitigation techniques.
...
Within the context of the Ethereum blockchain protocol, reentrancy is a well-known and well-researched smart contract vulnerability. However, when considering GoQuorum, an Ethereum soft fork, barely any research discussing smart contract vulnerabilities exists. This report aims to partly fill this research gap by evaluating the reentrancy smart contract vulnerability in the context of a GoQuorum network. First, the reentrancy attack was demonstrated and its attack features evaluated. Then any known countermeasures were collected. Moreover, it was proposed that some GoQuorum features may also be used as mitigation techniques. Finally, each countermeasure was assessed and categorized. Of all the methods, the checks-effects-interactions pattern is the most direct way to deal with the reentrancy vulnerability. To maximize contract security, however, it is advised to use a combination of the specified prevention and mitigation techniques.
Hyperledger Fabric is a permissioned enterprise blockchain allowing organizations to collaborate and automate processes via smart contracts. However, these contracts could contain security vulnerabilities leading to unexpected behavior or other negative consequences. Therefore, this study takes a closer look at three reported smart contract vulnerabilities in Fabric: rich queries, pseudorandom number generators, and global variables. Smart contracts containing these vulnerabilities were deployed on a test network, and the vulnerable contract features were exploited and explained. The study provides an estimation of each vulnerability's impact severity, and possible countermeasures to lower it were explored and evaluated. This study found that the proposed countermeasures can at least mitigate the impact severity of all three vulnerabilities.
Additionally, the study provides an overview of compatible analysis tools. The available tools were found to be lacking, however, as most of them do not exist outside of research papers. Overall, static code analysis tools were found to be effective at detecting all three vulnerabilities. ...
Additionally, the study provides an overview of compatible analysis tools. The available tools were found to be lacking, however, as most of them do not exist outside of research papers. Overall, static code analysis tools were found to be effective at detecting all three vulnerabilities. ...
Hyperledger Fabric is a permissioned enterprise blockchain allowing organizations to collaborate and automate processes via smart contracts. However, these contracts could contain security vulnerabilities leading to unexpected behavior or other negative consequences. Therefore, this study takes a closer look at three reported smart contract vulnerabilities in Fabric: rich queries, pseudorandom number generators, and global variables. Smart contracts containing these vulnerabilities were deployed on a test network, and the vulnerable contract features were exploited and explained. The study provides an estimation of each vulnerability's impact severity, and possible countermeasures to lower it were explored and evaluated. This study found that the proposed countermeasures can at least mitigate the impact severity of all three vulnerabilities.
Additionally, the study provides an overview of compatible analysis tools. The available tools were found to be lacking, however, as most of them do not exist outside of research papers. Overall, static code analysis tools were found to be effective at detecting all three vulnerabilities.
Additionally, the study provides an overview of compatible analysis tools. The available tools were found to be lacking, however, as most of them do not exist outside of research papers. Overall, static code analysis tools were found to be effective at detecting all three vulnerabilities.
Bachelor thesis
(2021)
-
M. Cristea-Enache, L.L.G. Dekhuijzen, G. Mazzola, A.N. Feldman, K. Liang, H. Chen, C.C.S. Liem
The NIST Post-Quantum Cryptography standardisation process has called for new algorithms, for the purpose of finding and standardising new cryptographic algorithms, able to withstand attacks enabled by future quantum processing progress. Digital signature schemes are fundamental for validating authenticity and integrity of digital documents. In the pages that follow, algorithms currently submitted in the NIST process, which rely on multivariate equations, will be investigated. This thesis will examine their underlying structure, known attacks, as well as their required storage and efficiency.
...
The NIST Post-Quantum Cryptography standardisation process has called for new algorithms, for the purpose of finding and standardising new cryptographic algorithms, able to withstand attacks enabled by future quantum processing progress. Digital signature schemes are fundamental for validating authenticity and integrity of digital documents. In the pages that follow, algorithms currently submitted in the NIST process, which rely on multivariate equations, will be investigated. This thesis will examine their underlying structure, known attacks, as well as their required storage and efficiency.
In the last decade, development in quantum computing has threatened the security of current public-key cryptography. For this reason, the American National Institute of Standards and Technology (NIST) has organized a competition-like process to
standardize new quantum-resistant public-key encryption and digital signature schemes. This research project aims to give a general overview of post-quantum lattice-based cryptography and analyze and compare the submitted lattice-based public-key encryption schemes over performance, security, distinguishing features and potential vulnerabilities ...
standardize new quantum-resistant public-key encryption and digital signature schemes. This research project aims to give a general overview of post-quantum lattice-based cryptography and analyze and compare the submitted lattice-based public-key encryption schemes over performance, security, distinguishing features and potential vulnerabilities ...
In the last decade, development in quantum computing has threatened the security of current public-key cryptography. For this reason, the American National Institute of Standards and Technology (NIST) has organized a competition-like process to
standardize new quantum-resistant public-key encryption and digital signature schemes. This research project aims to give a general overview of post-quantum lattice-based cryptography and analyze and compare the submitted lattice-based public-key encryption schemes over performance, security, distinguishing features and potential vulnerabilities
standardize new quantum-resistant public-key encryption and digital signature schemes. This research project aims to give a general overview of post-quantum lattice-based cryptography and analyze and compare the submitted lattice-based public-key encryption schemes over performance, security, distinguishing features and potential vulnerabilities
Bachelor thesis
(2021)
-
A.N. Feldman, M. Cristea-Enache, L.L.G. Dekhuijzen, G. Mazzola, K. Liang, H. Chen, C.C.S. Liem
As quantum-resistant cryptosystems will soon benecessary, the NIST has organized a contest aim-ing to its standardization. The proposed schemesmust be evaluated and thoroughly investigated tonotably ensure their security and compare their per-formance. This paper will explore various lattices-based (pqNTRUSign, BLISS, Dilithium, Falcon,qTesla) and code-based (RaCoSS, pqsigRM) dig-ital signature schemes. An efficiency and security-based comparison is conducted among them andtheir features are discussed.
...
As quantum-resistant cryptosystems will soon benecessary, the NIST has organized a contest aim-ing to its standardization. The proposed schemesmust be evaluated and thoroughly investigated tonotably ensure their security and compare their per-formance. This paper will explore various lattices-based (pqNTRUSign, BLISS, Dilithium, Falcon,qTesla) and code-based (RaCoSS, pqsigRM) dig-ital signature schemes. An efficiency and security-based comparison is conducted among them andtheir features are discussed.