Search papers, labs, and topics across Lattice.
This paper develops a model for a smart-contract language that integrates off-chain components with on-chain blockchain contracts, allowing for enhanced flexibility in responding to external events. The study reveals that traditional static information flow control techniques fail to ensure data integrity and secrecy between on-chain and off-chain components due to the separate execution threads of off-chain components, which can introduce blocking constructs. The authors conclude by discussing potential strategies to mitigate these vulnerabilities, highlighting the need for improved security measures in blockchain architectures.
Static information flow control techniques can't secure off-chain components in blockchain systems, exposing critical vulnerabilities.
This paper develops a model of a smart-contract language for a blockchain architecture with off-chain components. Off-chain components are pieces of smart contracts that execute at designated locations outside of the network of blockchain nodes, but remain synchronised with the on-chain contract state. They react to changes to the on-chain state, but may also notify the on-chain component about events in the world, e.g. stock prices, weather data etc., or even act as a bridge between different blockchains. This affords greater flexibility for the developer, but may also enable new vulnerabilities. As a concrete example, we use the model to study the problem of ensuring integrity and secrecy of data between the on-chain and off-chain components, using static information flow control techniques. This fails, even in the absence of a loop construct, because off-chain components act as separate threads and can encode a blocking construct e.g. through recursive method calls. We end the paper with a discussion of possible ways to remedy this situation.