首页> 外文期刊>Computers & Security >Formal modelling and security analysis of Bitcoin's payment protocol
【24h】

Formal modelling and security analysis of Bitcoin's payment protocol

机译:比特币支付协议的正式建模与安全分析

获取原文
获取原文并翻译 | 示例
           

摘要

The Payment Protocol standard BIP70, specifying how payments in Bitcoin are performed by merchants and customers, is supported by the largest payment processors and most widely-used wallets. The protocol has been shown to be vulnerable to refund attacks due to lack of authentication of the refund addresses. In this paper, we give the first formal model of the protocol and formalise the refund address security goals for the protocol, namely refund address authentication and secrecy. The formal model utilises communication channels as abstractions conveying security goals on which the protocol modeller and verifier can rely. We analyse the Payment Protocol confirming that it is vulnerable to an attack violating the refund address authentication security goal. Moreover, we present a concrete protocol revision proposal supporting the merchant with publicly verifiable evidence that can mitigate the attack. We verify that the revised protocol meets the security goals defined for the refund address. Hence, we demonstrate that the revised protocol is secure, not only against the existing attacks, but also against any further attacks violating the formalised security goals.
机译:支付协议标准BIP70,指定Bitcoin的付款方式是由商家和客户进行的,由最大的支付处理器和最广泛使用的钱包支持。由于缺乏退款地址缺乏认证,该协议已被证明易于退款攻击。在本文中,我们给出了第一个正式模型,并正式确定了协议的退款地址安全目标,即退款地址认证和保密。正式模型利用通信渠道作为抽象传达协议制动器和验证者可以依赖的安全目标。我们分析了确认违反退款地址认证安全目标的攻击易受攻击的付款协议。此外,我们提出了一个具体的协议修订提案,支持商家,可以通过公开可验证的证据来减轻攻击。我们核实修订后的协议符合退款地址所定义的安全目标。因此,我们证明修订后的议定书是安全的,而不仅仅是针对现有的攻击,而且还针对违反正式安全目标的进一步攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号