Uncontrolled Randomness in Blockchains : Covert Bulletin Board for Illicit Activity

Al-Salami, Nasser and Zhang, Bingsheng (2020) Uncontrolled Randomness in Blockchains : Covert Bulletin Board for Illicit Activity. In: 2020 IEEE/ACM 28th International Symposium on Quality of Service (IWQoS) :. IEEE. ISBN 9781728168883

[thumbnail of main]
Text (main)
main.pdf - Accepted Version
Available under License Creative Commons Attribution-NonCommercial.

Download (903kB)


Public blockchains can be abused to covertly store and disseminate potentially harmful digital content which poses a serious regulatory issue. In this work, we show the severity of the problem by demonstrating that blockchains can be exploited to surreptitiously distribute arbitrary content. More specifically, all major blockchain systems use randomized cryptographic primitives, such as digital signatures and non-interactive zero-knowledge proofs; we illustrate how the uncontrolled randomness in such primitives can be maliciously manipulated to enable covert communication and hidden persistent storage. To clarify the potential risk, we design, implement and evaluate our technique against the widely-used ECDSA signature scheme, the CryptoNote's ring signature scheme, and Monero's ring confidential transactions. Importantly, the significance of the demonstrated attacks stems from their undetectability, their adverse effect on the future of decentralized blockchains, and their serious repercussions on users' privacy and crypto funds. Finally, we present a generic framework to immunize blockchains against these attacks.

Item Type:
Contribution in Book/Report/Proceedings
Additional Information:
©2020 IEEE. Personal use of this material is permitted. However, permission to reprint/republish this material for advertising or promotional purposes or for creating new collective works for resale or redistribution to servers or lists, or to reuse any copyrighted component of this work in other works must be obtained from the IEEE.
ID Code:
Deposited By:
Deposited On:
18 Dec 2020 12:50
Last Modified:
14 Jun 2024 00:09