<?xml version="1.0"?>
<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/"><rdf:Description rdf:about="https://repozitorij.uni-lj.si/IzpisGradiva.php?id=124838"><dc:title>Cyber security in decentralized applications</dc:title><dc:creator>TURK,	JAN	(Avtor)
	</dc:creator><dc:creator>Pustišek,	Matevž	(Mentor)
	</dc:creator><dc:creator>Živić,	Nataša	(Komentor)
	</dc:creator><dc:subject>Blockchain</dc:subject><dc:subject>Blockchain technology</dc:subject><dc:subject>Smart contracts</dc:subject><dc:subject>Ethereum</dc:subject><dc:subject>Smart contract security</dc:subject><dc:subject>Smart contract tunnelling</dc:subject><dc:description>Ethereum network introduced executable programming called smart contracts to blockchain technology ecosystem. With the ability to have executable smart contracts on a blockchain network, decentralised applications (DAPPs) started to reach the consumer market. As with every kind of executable programming the information security is an important part of smart contract development. The field is still relatively young; the Ethereum network and the smart contracts were brought to the public domain in 2015.  Since then, the Ethereum network as well as the smart contract programming language, Solidity, has been rapidly developing and there are no extensive guidelines for secure development of smart contracts. This is the reason for researching smart contract security in this thesis.
Blockchain technology overview is included in this thesis and is used as the basis to deduct the smart contract security aspects that need to be considered when writing smart contracts. Blockchain network types, elements and their interactions are analysed, to provide further background in the workings of the blockchain technology. Understanding how transactions are executed, how accounts are represented, the on-chain executable logic and how inter-chain communication is executed, is crucial to secure the development of smart contracts.
Decentralised application security is broken down into blockchain network security, secure blockchain network governance, smart contract security and DAPP interaction security. Blockchain network security is analysed by comparing the relationship between the chain data integrity and transaction throughputs, as well as how the consensus algorithm of the blockchain network can impact the security of the data transmitted over it. Critical secure node mass is explained and its relationship to network security as well.
Smart contract security is a multi-layered term. Smart contract execution sequence is explained in detail as well as how standardization is emerging in smart contract development. Zero-hour exploits, as well as third party code snippets, are detailed in relation to smart contract security. Smart contract weakness classification is explained. Secure smart contract deployment, code reviews and code verification are also discussed in detail. Finally, the way of how users and developers interact with smart contracts through DAPPs is discussed.
DAPP security best practices are outlined starting with the CIA information security triad and passive and active smart contract security. Multi smart contract solutions, hybrid blockchain – server architectures, atomic swaps and blockchain network load predictions and testing are detailed in this chapter.
The practical part of the thesis focuses on applying the previously analysed and outlined smart contract security practices to smart contract back end of a DAPP called Swether. Swether is an electrical charging solution that uses Ethereum network as its backend. The pre-thesis solution is presented and required improvements are presented. It was built in a monolithic manner, meaning there was one smart contract that handled all of the business logic as well as data storage and access control. The monolithic smart contract is separated into seven self-contained modules, which are thoroughly analysed and designed. The modules are classified into platform-agnostic, platform-specific and auxiliary groups. Platform agnostic group of modules is applicable to any project and it provides essential service for the whole platform. They provide per-module access control and module to address resolution service. Platform-specific group of modules contains business logic specific to the platform; in this case specific to charging station service. Auxiliary group of modules brings additional value to the platform and the modules contained in it can be used in various platforms but are not essential for the operation of the platform. Swether auxiliary modules are Loyalty, Escrow and Accumulator.
Transitioning from a single smart contract environment to a multi smart contract environment required a secure way of inter-module access control. Smart Contract Tunnelling (SCT) is introduced to provide secure authentication and access control. SCT utilizes a platform-agnostic group of modules to verify the correct path of the transaction as well as access control for the origin user of the transaction.
Each module was designed for upgradeability and data transfer. This means that if a module is upgraded, the access control can be transferred from the previous version of the module and all of the other modules are notified of the update, so that the update is seamless, and the operation of the platform is not interrupted.
After the successful implementation of the security upgrade of Swether platform, all the smart contracts were analysed using MythX smart contract security audit tool. The results are presented and analysed.
Finally, the roadmap for the future of Swether is laid out and the possible further improvements are presented.</dc:description><dc:date>2021</dc:date><dc:date>2021-02-22 11:35:00</dc:date><dc:type>Magistrsko delo/naloga</dc:type><dc:identifier>124838</dc:identifier><dc:language>sl</dc:language></rdf:Description></rdf:RDF>
