AI 中文总结
本文提出带链下组件的区块链智能合约语言模型,用静态信息流控制技术保障链上链下数据完整性与保密性,但因链下组件可编码阻塞结构导致方法失效,最后探讨了补救方式。
AI 中文摘要
本文针对带有链下组件的区块链架构,提出了一种智能合约语言模型。链下组件是智能合约中在区块链节点网络外的指定位置执行的部分,但仍与链上合约状态保持同步;它们会响应链上状态的变化,还可向链上组件通知来自外界的事件(如股票价格、天气数据等),甚至可作为不同区块链之间的桥梁。这为开发者提供了更高的灵活性,但也可能引发新的漏洞。作为具体示例,我们利用该模型研究如何通过静态信息流控制技术,确保链上与链下组件之间数据的完整性和保密性。即使在无循环结构的情况下,该方法也会失效,因为链下组件作为独立线程运行,可通过递归方法调用等方式编码出阻塞结构。最后,我们讨论了可能的补救措施。
英文摘要
This paper develops a model of a smart-contract language for a blockchain architecture with off-chain components. Off-chain components are pieces of smart contracts that execute at designated locations outside of the network of blockchain nodes, but remain synchronised with the on-chain contract state. They react to changes to the on-chain state, but may also notify the on-chain component about events in the world, e.g. stock prices, weather data etc., or even act as a bridge between different blockchains. This affords greater flexibility for the developer, but may also enable new vulnerabilities. As a concrete example, we use the model to study the problem of ensuring integrity and secrecy of data between the on-chain and off-chain components, using static information flow control techniques. This fails, even in the absence of a loop construct, because off-chain components act as separate threads and can encode a blocking construct e.g. through recursive method calls. We end the paper with a discussion of possible ways to remedy this situation.