Hash Functions in Blockchains

Total Page:16

File Type:pdf, Size:1020Kb

Hash Functions in Blockchains Hash functions in blockchains Daniel Augot INRIA Saclay–ˆIle-de-France Laboratoire d’informatique de l’Ecole´ polytechnique Head of project-team Grace (crypto) Daniel Augot: 1/50 Well, actually, there are very good research topics. A very narrow view: hash functions. This talk Crypto is standard Power law! Peer-to-peer is Time series unefficient viz: so easy Basic Game theory No big data ! Not consensus Daniel Augot: 2/50 A very narrow view: hash functions. This talk Crypto is standard Power law! Peer-to-peer is Time series unefficient viz: so easy Basic Game theory No big data ! Not consensus Well, actually, there are very good research topics. Daniel Augot: 2/50 This talk Crypto is standard Power law! Peer-to-peer is Time series unefficient viz: so easy Basic Game theory No big data ! Not consensus Well, actually, there are very good research topics. A very narrow view: hash functions. Daniel Augot: 2/50 Outline Transactions and Ledger Hash functions and Proof-of-work Opening the box: SHA-256 SHA256(SHA256(x)) and mining Scrypt Ethash Equihash Daniel Augot: 3/50 Outline Transactions and Ledger Hash functions and Proof-of-work Opening the box: SHA-256 SHA256(SHA256(x)) and mining Scrypt Ethash Equihash Daniel Augot: Transactions and Ledger 4/50 Bitcoin: A Peer-to-Peer Electronic Cash System Satoshi Nakamoto [email protected] www.bitcoin.org What is needed is an electronic Abstract. A purely peer-to-peer version of electronic cash would allow online payment system based on cryp- payments to be sent directly from one party to another without going through a financial institution. Digital signatures provide part of the solution, but the main tographic proof instead of trust, benefits are lost if a trusted third party is still required to prevent double-spending. We propose a solution to the double-spending problem using a peer-to-peer network. The network timestamps transactions by hashing them into an ongoing chain of [. ] without the need for a hash-based proof-of-work, forming a record that cannot be changed without redoing the proof-of-work. The longest chain not only serves as proof of the sequence of events witnessed, but proof that it came from the largest pool of CPU power. As trusted third party long as a majority of CPU power is controlled by nodes that are not cooperating to attack the network, they'll generate the longest chain and outpace attackers. The network itself requires minimal structure. Messages are broadcast on a best effort basis, and nodes can leave and rejoin the network at will, accepting the longest proof-of-work chain as proof of what happened while they were gone. We propose a solution [. ] using 1. Introduction a peer-to-peer distributed times- Commerce on the Internet has come to rely almost exclusively on financial institutions serving as trusted third parties to process electronic payments. While the system works well enough for tamp server to generate [. ] most transactions, it still suffers from the inherent weaknesses of the trust based model. Completely non-reversible transactions are not really possible, since financial institutions cannot avoid mediating disputes. The cost of mediation increases transaction costs, limiting the proof of the chronological order of minimum practical transaction size and cutting off the possibility for small casual transactions, and there is a broader cost in the loss of ability to make non-reversible payments for non- reversible services. With the possibility of reversal, the need for trust spreads. Merchants must transactions be wary of their customers, hassling them for more information than they would otherwise need. A certain percentage of fraud is accepted as unavoidable. These costs and payment uncertainties can be avoided in person by using physical currency, but no mechanism exists to make payments over a communications channel without a trusted party. What is needed is an electronic payment system based on cryptographic proof instead of trust, Satoshi Nakamoto. Bitcoin: allowing any two willing parties to transact directly with each other without the need for a trusted third party. Transactions that are computationally impractical to reverse would protect sellers from fraud, and routine escrow mechanisms could easily be implemented to protect buyers. In A Peer-to-Peer Electronic Cash this paper, we propose a solution to the double-spending problem using a peer-to-peer distributed timestamp server to generate computational proof of the chronological order of transactions. The system is secure as long as honest nodes collectively control more CPU power than any System. Online, bit- cooperating group of attacker nodes. coin.org/bitcoin.pdf. 2008 1 Daniel Augot: Transactions and Ledger 5/50 Transactions I I Alice transfers bitcoins to Bob From Alice To Bob "1" I this is written in a public ledger Daniel Augot: Transactions and Ledger 6/50 Blocks and the ledger Daniel Augot: Transactions and Ledger 7/50 Blocks and the ledger Rebbeca Mary Marewitt "This book must be produced whenever any money is deposited or withdraw" Transaction Officer's signature March 27, 1869 Date stamp of the office to be affixed against each entry Daniel Augot: Transactions and Ledger 8/50 Blocks and the ledger Rebbeca Mary Marewitt adresse bitcoin "This book must be produced whenever any money is deposited or withdraw" registre public Transaction Officer's signature pas d'officier March 27, 1869 ni de signature Date stamp of the office "minage" to be affixed against each entry Daniel Augot: Transactions and Ledger 9/50 Actually, the hash is hard to find: proof-of-work Cynthia Dwork and Moni Naor. “Pricing via Processing or Combatting Junk Mail”. In: CRYPTO’ 92. 1993 Blocks are chained Daniel Augot: Transactions and Ledger 10/50 Actually, the hash is hard to find: proof-of-work Cynthia Dwork and Moni Naor. “Pricing via Processing or Combatting Junk Mail”. In: CRYPTO’ 92. 1993 Blocks are chained hash hash hash Daniel Augot: Transactions and Ledger 10/50 Blocks are chained hash hash hash Actually, the hash is hard to find: proof-of-work Cynthia Dwork and Moni Naor. “Pricing via Processing or Combatting Junk Mail”. In: CRYPTO’ 92. 1993 Daniel Augot: Transactions and Ledger 10/50 Outline Transactions and Ledger Hash functions and Proof-of-work Opening the box: SHA-256 SHA256(SHA256(x)) and mining Scrypt Ethash Equihash Daniel Augot: Hash functions and Proof-of-work 11/50 Cryptographic hash function f0; 1g∗ ! f0; 1gm H : x 7! y = H(x) I deterministic algorithm I no secrets, no keys (neither private, public, or secret) I it is not signature, neither encryption I it is not signature, neither encryption I it is not signature, neither encryption I it is not signature, neither encryption I it is not signature, neither encryption I ... Daniel Augot: Hash functions and Proof-of-work 12/50 Cryptographic hash function any bit string ! m bits H : x 7! y = H(x) I deterministic algorithm I no secrets, no keys (neither private, public, or secret) I it is not signature, neither encryption I it is not signature, neither encryption I it is not signature, neither encryption I it is not signature, neither encryption I it is not signature, neither encryption I ... Daniel Augot: Hash functions and Proof-of-work 12/50 Cryptographic hash function any bit string ! m/8 bytes H : x 7! y = H(x) I deterministic algorithm I no secrets, no keys (neither private, public, or secret) I it is not signature, neither encryption I it is not signature, neither encryption I it is not signature, neither encryption I it is not signature, neither encryption I it is not signature, neither encryption I ... Daniel Augot: Hash functions and Proof-of-work 12/50 Cryptographic hash function any digitalized document ! m/8 bytes H : x 7! y = H(x) I deterministic algorithm I no secrets, no keys (neither private, public, or secret) I it is not signature, neither encryption I it is not signature, neither encryption I it is not signature, neither encryption I it is not signature, neither encryption I it is not signature, neither encryption I ... Daniel Augot: Hash functions and Proof-of-work 12/50 Cryptographic hash function: properties Standard definition I First preimage resistance: given y = H(x), impossible to find x m I no better way than 2 calls to H 0 I Second preimage resistance: given x impossible to find x s.t. H(x 0) = H(x) m I no better way than 2 calls to H 0 0 I Collision resistance: impossible to find x, x s.t. H(x) = H(x ) m=2 I no better way than 2 calls to H Random Oracle Idealization I Hold a table T I when queried for x I if x 2 T return T [x] I if x 62 T return a random y, and set T [x] = y Daniel Augot: Hash functions and Proof-of-work 13/50 Difficult to create, only a few are in use: SHA1, SHA256, Keccak (SHA3) Why such a thing would be useful Most unsemantic function: given x, y = F (x) is (hopefully) pure random! Usage I Ensuring file integrity: M 7! (M; h(M)) If h(M) is secure, there can be non corruption on M =) integrity of the blockchain from last trusted hash h I Password storage (with a pinch of salt) I Blind registration of documents (notarization) d95b82d3187458f83ad36abd509c7688f60cbda4 Daniel Augot: Hash functions and Proof-of-work 14/50 Where do they come from Daniel Augot: Hash functions and Proof-of-work 15/50 Where do they come from Daniel Augot: Hash functions and Proof-of-work 15/50 SHA-1 is well broken (alongside with pdf) Daniel Augot: Hash functions and Proof-of-work 16/50 SHA-1 is well broken (alongside with pdf) Daniel Augot: Hash functions and Proof-of-work 16/50 Mining, proof-of-work Mining is finding a nonce wich contributes to a partially prescribed hash nonce = an arbitrary meaningless number Daniel Augot: Hash functions and Proof-of-work 17/50 T is readjusted every 2016 blocks, to keep producing a block every 10 min 2 weeks difficulty difficulty · time to mine last 2016 blocks where difficulty / 1=T Proof-of-work with SHA2562 Bitcoin uses 64 f0; 1g2 ! f0; 1g256 x 7! SHA256(SHA256(x)) 2 f0; 1g256 256 I given a “target” T 2 [0; 2 ) I to “mine” block-data: UNTIL hash < T nonce = next nonce hash = H(block-data jj nonce) No better way than guessing.
Recommended publications
  • Characterizing Ethereum's Mining Power Decentralization at a Deeper
    Characterizing Ethereum’s Mining Power Decentralization at a Deeper Level Liyi Zeng∗§, Yang Chen†§, Shuo Chen†, Xian Zhang†, Zhongxin Guo†, Wei Xu∗, Thomas Moscibroda‡ ∗Institute for Interdisciplinary Information Sciences, Tsinghua University †Microsoft Research ‡Microsoft Azure §Contacts: [email protected], [email protected] Abstract—For proof-of-work blockchains such as Ethereum, than 50% of the total power has grown from several the mining power decentralization is an important discussion hundred to several thousand. Overall, the power is more point in the community. Previous studies mostly focus on the decentralized at the participant level than 4 years ago. aggregated power of the mining pools, neglecting the pool participants who are the source of the pools’ power. In this paper, However, we also find that this number varied signif- we present the first large-scale study of the pool participants icantly over time, which means it requires continuous in Ethereum’s mining pools. Pool participants are not directly tracking. Additionally, as our current data and method- observable because they communicate with their pools via private ology cannot de-anonymize the participants, it’s possible channels. However, they leave “footprints” on chain as they that some participants split themselves into many smaller use Ethereum accounts to anonymously receive rewards from mining pools. For this study, we combine several data sources ones for various reasons, which could make our estima- to identify 62,358,646 pool reward transactions sent by 47 tion inaccurate if not completely off the target. Further pools to their participants over Ethereum’s entire near 5-year study to improve the estimation accuracy is important.
    [Show full text]
  • Argon and Argon2
    Argon and Argon2 Designers: Alex Biryukov, Daniel Dinu, and Dmitry Khovratovich University of Luxembourg, Luxembourg [email protected], [email protected], [email protected] https://www.cryptolux.org/index.php/Password https://github.com/khovratovich/Argon https://github.com/khovratovich/Argon2 Version 1.1 of Argon Version 1.0 of Argon2 31th January, 2015 Contents 1 Introduction 3 2 Argon 5 2.1 Specification . 5 2.1.1 Input . 5 2.1.2 SubGroups . 6 2.1.3 ShuffleSlices . 7 2.2 Recommended parameters . 8 2.3 Security claims . 8 2.4 Features . 9 2.4.1 Main features . 9 2.4.2 Server relief . 10 2.4.3 Client-independent update . 10 2.4.4 Possible future extensions . 10 2.5 Security analysis . 10 2.5.1 Avalanche properties . 10 2.5.2 Invariants . 11 2.5.3 Collision and preimage attacks . 11 2.5.4 Tradeoff attacks . 11 2.6 Design rationale . 14 2.6.1 SubGroups . 14 2.6.2 ShuffleSlices . 16 2.6.3 Permutation ...................................... 16 2.6.4 No weakness,F no patents . 16 2.7 Tweaks . 17 2.8 Efficiency analysis . 17 2.8.1 Modern x86/x64 architecture . 17 2.8.2 Older CPU . 17 2.8.3 Other architectures . 17 3 Argon2 19 3.1 Specification . 19 3.1.1 Inputs . 19 3.1.2 Operation . 20 3.1.3 Indexing . 20 3.1.4 Compression function G ................................. 21 3.2 Features . 22 3.2.1 Available features . 22 3.2.2 Server relief . 23 3.2.3 Client-independent update .
    [Show full text]
  • Rev. Rul. 2019-24 ISSUES (1) Does a Taxpayer Have Gross Income Under
    26 CFR 1.61-1: Gross income. (Also §§ 61, 451, 1011.) Rev. Rul. 2019-24 ISSUES (1) Does a taxpayer have gross income under § 61 of the Internal Revenue Code (Code) as a result of a hard fork of a cryptocurrency the taxpayer owns if the taxpayer does not receive units of a new cryptocurrency? (2) Does a taxpayer have gross income under § 61 as a result of an airdrop of a new cryptocurrency following a hard fork if the taxpayer receives units of new cryptocurrency? BACKGROUND Virtual currency is a digital representation of value that functions as a medium of exchange, a unit of account, and a store of value other than a representation of the United States dollar or a foreign currency. Foreign currency is the coin and paper money of a country other than the United States that is designated as legal tender, circulates, and is customarily used and accepted as a medium of exchange in the country of issuance. See 31 C.F.R. § 1010.100(m). - 2 - Cryptocurrency is a type of virtual currency that utilizes cryptography to secure transactions that are digitally recorded on a distributed ledger, such as a blockchain. Units of cryptocurrency are generally referred to as coins or tokens. Distributed ledger technology uses independent digital systems to record, share, and synchronize transactions, the details of which are recorded in multiple places at the same time with no central data store or administration functionality. A hard fork is unique to distributed ledger technology and occurs when a cryptocurrency on a distributed ledger undergoes a protocol change resulting in a permanent diversion from the legacy or existing distributed ledger.
    [Show full text]
  • Crypto Research Report ‒ April 2019 Edition
    April 2019 Edition VI. “When the Tide Goes Out…” Investments: Gold and Bitcoin, Stronger Together Technical Analysis: Spring Awakening? Cryptocurrency Mining in Theory and Practice Demelza Kelso Hays Mark J. Valek We would like to express our profound gratitude to our premium partners for supporting the Crypto Research Report: www.cryptofunds.li Contents Editorial ............................................................................................................................................... 4 In Case You Were Sleeping: When the Tide Goes Out…............................................................... 5 Back to the Roots ............................................................................................................................................. 6 How Long Will This Bear Market Last .............................................................................................................. 7 A Tragic Story Traverses the World ................................................................................................................. 9 When the tide goes out… ............................................................................................................................... 10 A State Cryptocurrency? ................................................................................................................................ 12 Support is Increasing ..................................................................................................................................... 14
    [Show full text]
  • Deanonymisation of Clients in Bitcoin P2P Network
    Deanonymisation of clients in Bitcoin P2P network Alex Biryukov Dmitry Khovratovich Ivan Pustogarov University of Luxembourg University of Luxembourg University of Luxembourg [email protected] [email protected] [email protected] Abstract about 100,000 nowadays. The vast majority of these peers Bitcoin is a digital currency which relies on a distributed (we call them clients), about 90%, are located behind NAT set of miners to mint coins and on a peer-to-peer network and do not allow any incoming connections, whereas they to broadcast transactions. The identities of Bitcoin users choose 8 outgoing connections to servers (Bitcoin peers with are hidden behind pseudonyms (public keys) which are rec- public IP). ommended to be changed frequently in order to increase In a Bitcoin transaction, the address of money sender(s) transaction unlinkability. or receiver(s) is a hash of his public key. We call such We present an efficient method to deanonymize Bitcoin address a pseudonym to avoid confusion with the IP ad- users, which allows to link user pseudonyms to the IP ad- dress of the host where transactions are generated, and the dresses where the transactions are generated. Our tech- latter will be called just address throughout the text. In niques work for the most common and the most challenging the current Bitcoin protocol the entire transaction history scenario when users are behind NATs or firewalls of their is publicly available so anyone can see how Bitcoins travel ISPs. They allow to link transactions of a user behind a from one pseudonym to another and potentially link differ- NAT and to distinguish connections and transactions of dif- ent pseudonyms of the same user together.
    [Show full text]
  • User Manual Ledger Nano S
    User Manual Ledger Nano S Version control 4 Check if device is genuine 6 Buy from an official Ledger reseller 6 Check the box contents 6 Check the Recovery sheet came blank 7 Check the device is not preconfigured 8 Check authenticity with Ledger applications 9 Summary 9 Learn more 9 Initialize your device 10 Before you start 10 Start initialization 10 Choose a PIN code 10 Save your recovery phrase 11 Next steps 11 Update the Ledger Nano S firmware 12 Before you start 12 Step by step instructions 12 Restore a configuration 18 Before you start 19 Start restoration 19 Choose a PIN code 19 Enter recovery phrase 20 If your recovery phrase is not valid 20 Next steps 21 Optimize your account security 21 Secure your PIN code 21 Secure your 24-word recovery phrase 21 Learn more 22 Discover our security layers 22 Send and receive crypto assets 24 List of supported applications 26 Applications on your Nano S 26 Ledger Applications on your computer 27 Third-Party applications on your computer 27 If a transaction has two outputs 29 Receive mining proceeds 29 Receiving a large amount of small transactions is troublesome 29 In case you received a large amount of small payments 30 Prevent problems by batching small transactions 30 Set up and use Electrum 30 Set up your device with EtherDelta 34 Connect with Radar Relay 36 Check the firmware version 37 A new Ledger Nano S 37 A Ledger Nano S in use 38 Update the firmware 38 Change the PIN code 39 Hide accounts with a passphrase 40 Advanced Passphrase options 42 How to best use the passphrase feature 43
    [Show full text]
  • Blockchain & Distributed Ledger Technologies
    Science, Technology Assessment, SEPTEMBER 2019 and Analytics WHY THIS MATTERS Distributed ledger technology (e.g. blockchain) allows users to carry out digital transactions without the need SCIENCE & TECH SPOTLIGHT: for a centralized authority. It could fundamentally change the way government and industry conduct BLOCKCHAIN & DISTRIBUTED business, but questions remain about how to mitigate fraud, money laundering, and excessive energy use. LEDGER TECHNOLOGIES /// THE TECHNOLOGY What is it? Distributed ledger technologies (DLT) like blockchain are a secure way of conducting and recording transfers of digital assets without the need for a central authority. DLT is “distributed” because multiple participants in a computer network (individuals, businesses, etc.), share and synchronize copies of the ledger. New transactions are added in a manner that is cryptographically secured, permanent, and visible to all participants in near real time. Figure 2. How blockchain, a form of distributed ledger technology, acts as a means of payment for cryptocurrencies. Cryptocurrencies like Bitcoin are a digital representation of value and represent the best-known use case for DLT. The regulatory and legal frameworks surrounding cryptocurrencies remain fragmented across Figure 1. Difference between centralized and distributed ledgers. countries, with some implicitly or explicitly banning them, and others allowing them. How does it work? Distributed ledgers do not need a central, trusted authority because as transactions are added, they are verified using what In addition to cryptocurrencies, there are a number of other efforts is known as a consensus protocol. Blockchain, for example, ensures the underway to make use of DLT. For example, Hyperledger Fabric is ledger is valid because each “block” of transactions is cryptographically a permissioned and private blockchain framework created by the linked to the previous block so that any change would alert all other Hyperledger consortium to help develop DLT for a variety of business users.
    [Show full text]
  • Asymmetric Proof-Of-Work Based on the Generalized Birthday Problem
    Equihash: Asymmetric Proof-of-Work Based on the Generalized Birthday Problem Alex Biryukov Dmitry Khovratovich University of Luxembourg University of Luxembourg [email protected] [email protected] Abstract—The proof-of-work is a central concept in modern Long before the rise of Bitcoin it was realized [20] that cryptocurrencies and denial-of-service protection tools, but the the dedicated hardware can produce a proof-of-work much requirement for fast verification so far made it an easy prey for faster and cheaper than a regular desktop or laptop. Thus the GPU-, ASIC-, and botnet-equipped users. The attempts to rely on users equipped with such hardware have an advantage over memory-intensive computations in order to remedy the disparity others, which eventually led the Bitcoin mining to concentrate between architectures have resulted in slow or broken schemes. in a few hardware farms of enormous size and high electricity In this paper we solve this open problem and show how to consumption. An advantage of the same order of magnitude construct an asymmetric proof-of-work (PoW) based on a compu- is given to “owners” of large botnets, which nowadays often tationally hard problem, which requires a lot of memory to gen- accommodate hundreds of thousands of machines. For prac- erate a proof (called ”memory-hardness” feature) but is instant tical DoS protection, this means that the early TLS puzzle to verify. Our primary proposal Equihash is a PoW based on the schemes [8], [17] are no longer effective against the most generalized birthday problem and enhanced Wagner’s algorithm powerful adversaries.
    [Show full text]
  • Zcash Protocol Speci Cation
    Zcash Protocol Specication Version 2018.0-beta-14 Daira Hopwood† Sean Bowe† — Taylor Hornby† — Nathan Wilcox† March 11, 2018 Abstract. Zcash is an implementation of the Decentralized Anonymous Payment scheme Zerocash, with security xes and adjustments to terminology, functionality and performance. It bridges the exist- ing transparent payment scheme used by Bitcoin with a shielded payment scheme secured by zero- knowledge succinct non-interactive arguments of knowledge (zk-SNARKs). It attempts to address the problem of mining centralization by use of the Equihash memory-hard proof-of-work algorithm. This specication denes the Zcash consensus protocol and explains its differences from Zerocash and Bitcoin. Keywords: anonymity, applications, cryptographic protocols, electronic commerce and payment, nancial privacy, proof of work, zero knowledge. Contents 1 1 Introduction 5 1.1 Caution . .5 1.2 High-level Overview . .5 2 Notation 7 3 Concepts 8 3.1 Payment Addresses and Keys . .8 3.2 Notes...........................................................9 3.2.1 Note Plaintexts and Memo Fields . .9 3.3 The Block Chain . 10 3.4 Transactions and Treestates . 10 3.5 JoinSplit Transfers and Descriptions . 11 3.6 Note Commitment Trees . 11 3.7 Nullier Sets . 12 3.8 Block Subsidy and Founders’ Reward . 12 3.9 Coinbase Transactions . 12 † Zerocoin Electric Coin Company 1 4 Abstract Protocol 12 4.1 Abstract Cryptographic Schemes . 12 4.1.1 Hash Functions . 12 4.1.2 Pseudo Random Functions . 13 4.1.3 Authenticated One-Time Symmetric Encryption . 13 4.1.4 Key Agreement . 13 4.1.5 Key Derivation . 14 4.1.6 Signature . 15 4.1.6.1 Signature with Re-Randomizable Keys .
    [Show full text]
  • Piecework: Generalized Outsourcing Control for Proofs of Work
    (Short Paper): PieceWork: Generalized Outsourcing Control for Proofs of Work Philip Daian1, Ittay Eyal1, Ari Juels2, and Emin G¨unSirer1 1 Department of Computer Science, Cornell University, [email protected],[email protected],[email protected] 2 Jacobs Technion-Cornell Institute, Cornell Tech [email protected] Abstract. Most prominent cryptocurrencies utilize proof of work (PoW) to secure their operation, yet PoW suffers from two key undesirable prop- erties. First, the work done is generally wasted, not useful for anything but the gleaned security of the cryptocurrency. Second, PoW is natu- rally outsourceable, leading to inegalitarian concentration of power in the hands of few so-called pools that command large portions of the system's computation power. We introduce a general approach to constructing PoW called PieceWork that tackles both issues. In essence, PieceWork allows for a configurable fraction of PoW computation to be outsourced to workers. Its controlled outsourcing allows for reusing the work towards additional goals such as spam prevention and DoS mitigation, thereby reducing PoW waste. Meanwhile, PieceWork can be tuned to prevent excessive outsourcing. Doing so causes pool operation to be significantly more costly than today. This disincentivizes aggregation of work in mining pools. 1 Introduction Distributed cryptocurrencies such as Bitcoin [18] rely on the equivalence \com- putation = money." To generate a batch of coins, clients in a distributed cryp- tocurrency system perform an operation called mining. Mining requires solving a computationally intensive problem involving repeated cryptographic hashing. Such problem and its solution is called a Proof of Work (PoW) [11]. As currently designed, nearly all PoWs suffer from one of two drawbacks (or both, as in Bitcoin).
    [Show full text]
  • Short Selling Attack: a Self-Destructive but Profitable 51% Attack on Pos Blockchains
    Short Selling Attack: A Self-Destructive But Profitable 51% Attack On PoS Blockchains Suhyeon Lee and Seungjoo Kim CIST (Center for Information Security Technologies), Korea University, Korea Abstract—There have been several 51% attacks on Proof-of- With a PoS, the attacker needs to obtain 51% of the Work (PoW) blockchains recently, including Verge and Game- cryptocurrency to carry out a 51% attack. But unlike PoW, Credits, but the most noteworthy has been the attack that saw attacker in a PoS system is highly discouraged from launching hackers make off with up to $18 million after a successful double spend was executed on the Bitcoin Gold network. For this reason, 51% attack because he would have to risk of depreciation the Proof-of-Stake (PoS) algorithm, which already has advantages of his entire stake amount to do so. In comparison, bad of energy efficiency and throughput, is attracting attention as an actor in a PoW system will not lose their expensive alternative to the PoW algorithm. With a PoS, the attacker needs mining equipment if he launch a 51% attack. Moreover, to obtain 51% of the cryptocurrency to carry out a 51% attack. even if a 51% attack succeeds, the value of PoS-based But unlike PoW, attacker in a PoS system is highly discouraged from launching 51% attack because he would have to risk losing cryptocurrency will fall, and the attacker with the most stake his entire stake amount to do so. Moreover, even if a 51% attack will eventually lose the most. For these reasons, those who succeeds, the value of PoS-based cryptocurrency will fall, and attempt to attack 51% of the PoS blockchain will not be the attacker with the most stake will eventually lose the most.
    [Show full text]
  • Implementation and Performance Analysis of PBKDF2, Bcrypt, Scrypt Algorithms
    Implementation and Performance Analysis of PBKDF2, Bcrypt, Scrypt Algorithms Levent Ertaul, Manpreet Kaur, Venkata Arun Kumar R Gudise CSU East Bay, Hayward, CA, USA. [email protected], [email protected], [email protected] Abstract- With the increase in mobile wireless or data lookup. Whereas, Cryptographic hash functions are technologies, security breaches are also increasing. It has used for building blocks for HMACs which provides become critical to safeguard our sensitive information message authentication. They ensure integrity of the data from the wrongdoers. So, having strong password is that is transmitted. Collision free hash function is the one pivotal. As almost every website needs you to login and which can never have same hashes of different output. If a create a password, it’s tempting to use same password and b are inputs such that H (a) =H (b), and a ≠ b. for numerous websites like banks, shopping and social User chosen passwords shall not be used directly as networking websites. This way we are making our cryptographic keys as they have low entropy and information easily accessible to hackers. Hence, we need randomness properties [2].Password is the secret value from a strong application for password security and which the cryptographic key can be generated. Figure 1 management. In this paper, we are going to compare the shows the statics of increasing cybercrime every year. Hence performance of 3 key derivation algorithms, namely, there is a need for strong key generation algorithms which PBKDF2 (Password Based Key Derivation Function), can generate the keys which are nearly impossible for the Bcrypt and Scrypt.
    [Show full text]