摘要
比特币是中本聪在2008年提出的一种数字货币,具有去中心化、去信任化、强健壮性、无监管、发行量固定等特点,一经推出就受到全世界的关注.作为当前最成功的数字货币,比特币基于P2P网络中众多节点构成的分布式数据库来确认并记录所有的交易行为,利用工作量证明机制解决共识问题,并使用密码学的设计来确保货币流通的安全性.随着比特币价格的提升、用户数的增加,比特币的安全性越来越引起人们的重视,比如双重支付问题、交易延展性问题和隐私保护问题.针对比特币系统的不同方面出现了许多的攻击:针对网络的日蚀攻击、路由攻击,针对共识机制的挖矿攻击等等,特别是矿池出现后,出现了一些新的针对矿池的攻击行为.本文主要介绍针对比特币挖矿的各种攻击如51%攻击、区块截留攻击、自私挖矿和FAW攻击,分析攻击的基本思想、基本策略和现实危害,并介绍一些应对攻击的方案.
Bitcoin is a cryptocurrency introduced by Satoshi Nakamoto in 2008, with the features of decentralization, detrusting, strong robustness and fixed total amount, it has received great attention all over the world. As the most successful cryptocurrency to date, Bitcoin recognizes and records all transactions based on a distributed database of nodes in a P2 P network, makes use of PoW to solve the consensus problem and the cryptographic design to ensure the security of currency circulation. With the rising price and increasing number of users, the security of Bitcoin has attracted more attention, such as double spending, transaction malleability, privacy issues. There have been many attacks targeting different aspects of Bitcoin systems, including eclipse attack and routing attacks targeting Bitcoin network, mining attacks targeting consensus mechanism, etc. With the appearance of mining pools,there have been some new attacks targeting the pools. This paper focuses on the attacks targeting mining and mining pools,such as 51% attack, block withholding attack, selfish niining attack, and FAW attack, analyzes the basic idea, basic strategy, and the real threat of the attacks. In addition,some solutions to these attacks are also introduced.
作者
韩健
邹静
蒋瀚
徐秋亮
HAN Jian;ZOU Jing;JIANG Han;XU Qiu-Liang(School of Computer Science and Technology,Shandong University,Jinan 250101,China;State Grid Economic and Technological Research Institute Co.Ltd.,Beijing 102209,China;School of Software,Shandong University,Jinan 250101,China)
出处
《密码学报》
CSCD
2018年第5期470-483,共14页
Journal of Cryptologic Research
基金
国家自然科学基金项目(61572294)
国家自然科学基金重点项目(61632020)
山东省自然科学基金项目(ZR2017MF021)
山东省科技重大创新工程项目(2018CXGC0702)
山东大学基本科研业务费专项资金项目(2017JC019)
国网信息化项目(B3441518G001)~~