A Security Reference Architecture for Blockchains

被引:14
|
作者
Homoliak, Ivan [1 ]
Venugopalan, Sarad [1 ]
Hum, Qingze [1 ]
Szalachowski, Pawel [1 ]
机构
[1] Singapore Univ Technol & Design, Singapore, Singapore
关键词
D O I
10.1109/Blockchain.2019.00060
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Due to their specific features, blockchains have become popular in recent years. Blockchains are layered systems where security is a critical factor for their success. The main focus of this work is to systematize knowledge about security and privacy issues of blockchains. To this end, we propose a security reference architecture based on models that demonstrate the stacked hierarchy of various threats as well as threat -risk assessment using ISO/IEC 15408. In contrast to the previous surveys [23], [88], [11], we focus on the categorization of security vulnerabilities based on their origins and using the proposed architecture we present existing prevention and mitigation techniques. The scope of our work mainly covers aspects related to the nature of blockchains, while we mention operational security issues and countermeasures only tangentially.
引用
收藏
页码:390 / 397
页数:8
相关论文
共 50 条
  • [1] The Security Reference Architecture for Blockchains: Toward a Standardized Model for Studying Vulnerabilities, Threats, and Defenses
    Homoliak, Ivan
    Venugopalan, Sarad
    Reijsbergen, Daniel
    Hum, Qingze
    Schumi, Richard
    Szalachowski, Pawel
    [J]. IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2021, 23 (01): : 341 - 390
  • [2] Security and Trust in Blockchains: Architecture, Key Technologies, and Open Issues
    Zhang, Peiyun
    Zhou, Mengchu
    [J]. IEEE TRANSACTIONS ON COMPUTATIONAL SOCIAL SYSTEMS, 2020, 7 (03) : 790 - 801
  • [3] Security as a Service - A Reference Architecture for SOA Security
    Memon, Mukhtiar
    Hafner, Michael
    Breu, Ruth
    [J]. SECURITY IN INFORMATION SYSTEMS, PROCEEDINGS, 2009, : 79 - 89
  • [4] Security and Privacy Smart Contract Architecture for Energy Trading based on Blockchains
    Nazari, Masoumeh
    Khorsandi, Siavash
    Babaki, Jaber
    [J]. 2021 29TH IRANIAN CONFERENCE ON ELECTRICAL ENGINEERING (ICEE), 2021, : 596 - 600
  • [5] Towards a Security Reference Architecture for NFV
    Alnaim, Abdulrahman Khalid
    Alwakeel, Ahmed Mahmoud
    Fernandez, Eduardo B.
    [J]. SENSORS, 2022, 22 (10)
  • [6] An Improved Security Architecture for an InterCloud Reference Model
    Ghazel, Cherif
    Abassi, Yosra
    Saidane, Leila
    [J]. 2017 EUROPEAN CONFERENCE ON ELECTRICAL ENGINEERING AND COMPUTER SCIENCE (EECS), 2017, : 166 - 173
  • [7] Building a security reference architecture for cloud systems
    Fernandez, Eduardo B.
    Monge, Raul
    Hashizume, Keiko
    [J]. REQUIREMENTS ENGINEERING, 2016, 21 (02) : 225 - 249
  • [8] Security and Privacy for Healthcare Blockchains
    Zhang, Rui
    Xue, Rui
    Liu, Ling
    [J]. IEEE TRANSACTIONS ON SERVICES COMPUTING, 2022, 15 (06) : 3668 - 3686
  • [9] Building a security reference architecture for cloud systems
    Eduardo B. Fernandez
    Raul Monge
    Keiko Hashizume
    [J]. Requirements Engineering, 2016, 21 : 225 - 249
  • [10] SeAAS - A Reference Architecture for Security Services in SOA
    Hafner, Michael
    Memon, Mukhtiar
    Breu, Ruth
    [J]. JOURNAL OF UNIVERSAL COMPUTER SCIENCE, 2009, 15 (15) : 2916 - 2936