智能合约安全综述:漏洞分析  被引量:6

A survey on smart contract:Vulnerability analysis

在线阅读下载全文

作  者:赵淦森[1,2,3] 谢智健 王欣明[1,2,3] 何嘉浩 刘学枫 王锡亮 周子衡 田志宏 谭庆丰 聂瑞华[1,2,3] ZHAO Gan-sen;XIE Zhi-jian;WANG Xin-ming;HE Jia-hao;LIU Xue-feng;WANG Xi-liang;ZHOU Zi-heng;TIAN Zhi-hong;TAN Qing-feng;NIE Rui-hua(School of Computer Science, South China Normal University, Guangzhou 510000, China;Guangzhou Key Laboratory of Cloud Computing Security and Assessment Technology,South China Normal University, Guangzhou 510000, China;VeChain blockchain technology and application joint laboratory, South China Normal University, Guangzhou 510000, China;VeChain Foundation, Shanghai 200000, China;Cyberspace Institute of Advanced Technology, Guangzhou University, Guangzhou 510000, China)

机构地区:[1]华南师范大学计算机学院,广东广州510000 [2]华南师范大学广州市云计算安全与测评技术重点实验室,广东广州510000 [3]华南师范大学唯链区块链技术与应用联合实验室,广东广州510000 [4]唯链基金会,上海200000 [5]广州大学网络空间先进技术研究院,广东广州510006

出  处:《广州大学学报(自然科学版)》2019年第3期59-67,共9页Journal of Guangzhou University:Natural Science Edition

基  金:国家重点研发计划资助项目(2018YFB1404402);广东省科技计划资助项目(2019B010137003,2016B030305006,2018A07071702);广州市科技计划资助项目(201804010314,2012224-12);唯链基金会资助项目(SCNU-2018-01)

摘  要:加密货币比特币的出现带动了区块链技术的蓬勃发展,智能合约技术则是区块链技术中的一个技术高地.目前以太坊中的智能合约应用受到大量的关注,创造了海量的价值应用,同时也带来了密集的攻击活动.随着智能合约的数量越来越多,尤其是智能合约中的代码漏洞也逐渐被许多研究人员和恶意攻击者发现,造成了一系列重大的经济损失案件.为了对智能合约技术的稳定性发展提供理论研究基础,文章针对以太坊上已知的智能合约漏洞进行了介绍、分类和总结,并对智能合约安全漏洞进行详细的原理阐述与场景代码复现.The emergence of cryptocurrency bitcoin has driven the vigorous development of blockchain technology, and smart contract technology is a technical highland of blockchain technology. At present, smart contract applications in ethereum have received a lot of attention, creating a lot of value applications, and at the same time bringing intensive attack activities.With the increasing number of intelligent contracts, especially the code loopholes in intelligent contracts have been gradually discovered by many researchers and malicious attackers, which has caused a series of serious economic losses.In order to provide theoretical research basis for the stable development of intelligent contract technology, this paper introduces, classifies and summarizes the known intelligent contract vulnerabilities in ethereum, and elaborates the principle and scene code of intelligent contract security vulnerabilities in detail.

关 键 词:区块链 以太坊 智能合约 安全漏洞 

分 类 号:TP311[自动化与计算机技术—计算机软件与理论]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象