Access control is a fundamental component of the design of distributed ledgers, influencing many aspects of their design, such as fairness, efficiency, traditional notions of network security, and adversarial attacks such as Denial-of-Service (DoS) attacks. In this work, we consider the security of a recently proposed access control protocol for Directed Acyclic Graph-based distributed ledgers. We present a number of attack scenarios and potential vulnerabilities of the protocol and introduce a number of additional features which enhance its resilience. Specifically, a blacklisting algorithm, which is based on a reputation-weighted threshold, is introduced to handle both spamming and multi-rate malicious attackers. The introduction of a solidification request component is also introduced to ensure the fairness and consistency of network in the presence of attacks. Finally, a timestamp component is also introduced to maintain the consistency of the network in the presence of multi-rate attackers. Simulations to illustrate the efficacy and robustness of the revised protocol are also described.
翻译:访问控制是设计分布式分类账的一个基本组成部分,影响到分类账设计的许多方面,例如公平、效率、网络安全的传统概念以及拒绝服务(DoS)攻击等对抗性攻击。在这项工作中,我们考虑最近提议的《定向环形图分布式分类账出入控制协议》的安全性。我们介绍了一些攻击情景和协议的潜在脆弱性,并引入了一些增强其复原力的其他特征。具体地说,采用了基于信誉加权阈值的黑名单算法来处理垃圾和多率恶意攻击者。还引入了固化请求部分,以确保网络在攻击发生时的公平性和一致性。最后,还引入了时间设置部分,以便在多率攻击者在场的情况下保持网络的一致性。还介绍了用于说明订正协议效力和稳健性的模拟。