본문

서브메뉴

Compositional Security for Smart Contracts
Compositional Security for Smart Contracts
Compositional Security for Smart Contracts

Detailed Information

자료유형  
 학위논문 서양
최종처리일시  
20250211152007
ISBN  
9798384048107
DDC  
004
저자명  
Yao, Siqiu.
서명/저자  
Compositional Security for Smart Contracts
발행사항  
[Sl] : Cornell University, 2024
발행사항  
Ann Arbor : ProQuest Dissertations & Theses, 2024
형태사항  
163 p
주기사항  
Source: Dissertations Abstracts International, Volume: 86-03, Section: A.
주기사항  
Advisor: Myers, Andrew.
학위논문주기  
Thesis (Ph.D.)--Cornell University, 2024.
초록/해제  
요약Securing smart contracts remains a fundamental challenge. At its core, it is a question of building software that is secure in composition with untrusted code, which extends far beyond the blockchain setting. We introduce SCIF, a language for building smart contracts that are compositionally secure. SCIF is based on the fundamentally compositional principle of secure information flow, but extends this core mechanism to be the first language to include protection against reentrancy attacks, confused deputy attacks, and improper error handling, even in the presence of malicious contracts that do not follow the rules of SCIF. SCIF proposes a novel and principled way to understand and prevent reentrancy attacks and confused deputy attacks. Additionally, SCIF supports a rich ecosystem of interacting principals with partial trust through its mechanisms for dynamic trust management. SCIF has been implemented as a compiler to Solidity. We describe the SCIF language, including its static checking rules and its runtime system. Finally, we implement several applications requiring intricate security reasoning, showing how SCIF supports building complex smart contracts securely and provides the programmer with accurate diagnostics about potential security bugs.
일반주제명  
Computer science
일반주제명  
Computer engineering
일반주제명  
Information science
키워드  
Decentralized systems
키워드  
Information flow control
키워드  
Integrity
키워드  
Programming languages
키워드  
Security
기타저자  
Cornell University Computer Science
기본자료저록  
Dissertations Abstracts International. 86-03A.
전자적 위치 및 접속  
로그인 후 원문을 볼 수 있습니다.

MARC

 008250123s2024        us                              c    eng  d
■001000017162396
■00520250211152007
■006m          o    d                
■007cr#unu||||||||
■020    ▼a9798384048107
■035    ▼a(MiAaPQ)AAI31330754
■040    ▼aMiAaPQ▼cMiAaPQ
■0820  ▼a004
■1001  ▼aYao,  Siqiu.▼0(orcid)0000-0003-1825-0561
■24510▼aCompositional  Security  for  Smart  Contracts
■260    ▼a[Sl]▼bCornell  University▼c2024
■260  1▼aAnn  Arbor▼bProQuest  Dissertations  &  Theses▼c2024
■300    ▼a163  p
■500    ▼aSource:  Dissertations  Abstracts  International,  Volume:  86-03,  Section:  A.
■500    ▼aAdvisor:  Myers,  Andrew.
■5021  ▼aThesis  (Ph.D.)--Cornell  University,  2024.
■520    ▼aSecuring  smart  contracts  remains  a  fundamental  challenge.  At  its  core,  it  is  a  question  of  building  software  that  is  secure  in  composition  with  untrusted  code,  which  extends  far  beyond  the  blockchain  setting.  We  introduce  SCIF,  a  language  for  building  smart  contracts  that  are  compositionally  secure.  SCIF  is  based  on  the  fundamentally  compositional  principle  of  secure  information  flow,  but  extends  this  core  mechanism  to  be  the  first  language  to  include  protection  against  reentrancy  attacks,  confused  deputy  attacks,  and  improper  error  handling,  even  in  the  presence  of  malicious  contracts  that  do  not  follow  the  rules  of  SCIF.  SCIF  proposes  a  novel  and  principled  way  to  understand  and  prevent  reentrancy  attacks  and  confused  deputy  attacks.  Additionally,  SCIF  supports  a  rich  ecosystem  of  interacting  principals  with  partial  trust  through  its  mechanisms  for  dynamic  trust  management.  SCIF  has  been  implemented  as  a  compiler  to  Solidity.  We  describe  the  SCIF  language,  including  its  static  checking  rules  and  its  runtime  system.  Finally,  we  implement  several  applications  requiring  intricate  security  reasoning,  showing  how  SCIF  supports  building  complex  smart  contracts  securely  and  provides  the  programmer  with  accurate  diagnostics  about  potential  security  bugs.
■590    ▼aSchool  code:  0058.
■650  4▼aComputer  science
■650  4▼aComputer  engineering
■650  4▼aInformation  science
■653    ▼aDecentralized  systems
■653    ▼aInformation  flow  control
■653    ▼aIntegrity
■653    ▼aProgramming  languages
■653    ▼aSecurity
■690    ▼a0984
■690    ▼a0464
■690    ▼a0723
■71020▼aCornell  University▼bComputer  Science.
■7730  ▼tDissertations  Abstracts  International▼g86-03A.
■790    ▼a0058
■791    ▼aPh.D.
■792    ▼a2024
■793    ▼aEnglish
■85640▼uhttp://www.riss.kr/pdu/ddodLink.do?id=T17162396▼nKERIS▼z이  자료의  원문은  한국교육학술정보원에서  제공합니다.

Preview

Export

ChatGPT Discussion

AI Recommended Related Books


    New Books MORE
    Statistics for the past 3 years. Go to brief

    Подробнее информация.

    • Бронирование
    • не существует
    • моя папка
    • Первый запрос зрения
    • Non-Book Loan Application
    • Nighttime Book Loan Application
    материал
    Reg No. Количество платежных Местоположение статус Ленд информации
    TF13834 전자도서 대출가능 My Folder 부재도서신고 비도서대출신청 야간 도서대출신청

    * Бронирование доступны в заимствований книги. Чтобы сделать предварительный заказ, пожалуйста, нажмите кнопку бронирование

    Books borrowed together with this book

    Related Popular Books

    Available after logging in.