首页> 外文期刊>Communications Surveys & Tutorials, IEEE >The Security Reference Architecture for Blockchains: Toward a Standardized Model for Studying Vulnerabilities, Threats, and Defenses
【24h】

The Security Reference Architecture for Blockchains: Toward a Standardized Model for Studying Vulnerabilities, Threats, and Defenses

机译:BlockChains的安全参考架构:朝着学习漏洞,威胁和防御的标准化模型

获取原文
获取原文并翻译 | 示例
           

摘要

Blockchains are distributed systems, in which security is a critical factor for their success. However, despite their increasing popularity and adoption, there is a lack of standardized models that study blockchain-related security threats. To fill this gap, the main focus of our work is to systematize and extend the knowledge about the security and privacy aspects of blockchains and contribute to the standardization of this domain.We propose the security reference architecture (SRA) for blockchains, which adopts a stacked model (similar to the ISO/OSI) describing the nature and hierarchy of various security and privacy aspects. The SRA contains four layers: (1) the network layer, (2) the consensus layer, (3) the replicated state machine layer, and (4) the application layer. At each of these layers, we identify known security threats, their origin, and countermeasures, while we also analyze several cross-layer dependencies. Next, to enable better reasoning about security aspects of blockchains by the practitioners, we propose a blockchain-specific version of the threat-risk assessment standard ISO/IEC 15408 by embedding the stacked model into this standard. Finally, we provide designers of blockchain platforms and applications with a design methodology following the model of SRA and its hierarchy.
机译:Blockchains是分布式系统,其中安全性是他们成功的关键因素。然而,尽管他们越来越受欢迎和采用,但缺乏研究区间有关的安全威胁的标准模型。为了填补这一差距,我们工作的主要重点是系统化,并扩展了对BlockChains的安全和隐私方面的知识,并有助于该域的标准化。我们提出了布置区块的安全参考架构(SRA),这适用于堆叠模型(类似于ISO / OSI),描述了各种安全性和隐私方面的性质和层次结构。 SRA包含四层:(1)网络层,(2)共识层,(3)复制状态机层,和(4)应用层。在每个这些层,我们确定已知的安全威胁,它们的起源和对策,而我们还分析了几个横梁依赖性。接下来,为了通过嵌入堆叠模型将堆叠的模型嵌入本标准,我们提高了关于SlowtChains的安全方面的安全方面,提出了一个小区特定的威胁风险评估标准ISO / IEC 15408。最后,我们提供Slinchain平台和应用程序的设计者,并在SRA的模型和其层次结构之后具有设计方法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号