Our contributions with this paper are twofold. First, we elucidate the methodological requirements for a risk framework of custodial operations and argue for the value of this type of risk model as complementary with cryptographic and blockchain security models. Second, we present a risk model in the form of a library of attack-trees for Revault -- an open-source custody protocol. The model can be used by organisations as a risk quantification framework for a thorough security analysis in their specific deployment context. Our work exemplifies an approach that can be used independent of which custody protocol is being considered, including complex protocols with multiple stakeholders and active defence infrastructure.
翻译:首先,我们阐明了监管业务风险框架的方法要求,并主张这类风险模式与加密和闭锁安全模式相辅相成的价值;其次,我们提出了一个风险模式,其形式为:一个用于Revault的攻击树图书馆 -- -- 一种开放源码保管协议;这一模式可供各组织用作风险量化框架,用于对其具体部署情况进行彻底的安全分析;我们的工作体现了一种可以独立使用的方法,目前正在考虑采用这一方法,包括与多个利益攸关方和活跃的国防基础设施签订复杂的协议。