With rise of blockchain popularity, more and more people seek to implement blockchain technology into their projects. Most common way is to take existing blockchain stack, such as Azure Blockchain Workbench or Oracle Blockchain Platform. While the blockchain technology is well-protected by its algorithms it is still vulnerable because its privacy relies on regular cryptography. And mistakes or vulnerabilities in key management protocols can affect even the most secure blockchain projects. This article considers question of vulnerabilities within Azure Blockchain Workbench key management system. We describe potential threats for each stage of key management lifecycle based on public reports and then assess how likely are those threats to realize within Azure Blockchain Workbench environment based on the technical documentation for Azure Blockchain Workbench and Azure Key Vault. Finally, we compile results of our assessment into the key management threat table with three distinct degrees of protection: fully protected, partially protected and not protected.
翻译:随着链链受欢迎程度的上升,越来越多的人试图将链链技术应用到他们的项目中。最常见的方法是将现有的链链堆,如Azure链工作网或甲骨文工作网平台。虽然这一链条技术受到其算法的妥善保护,但由于其隐私依赖于常规加密,仍然很脆弱。关键管理协议中的错误或弱点甚至会影响到最安全的链条项目。这一条考虑了Azure链工作网关键管理系统中的脆弱性问题。我们根据公共报告描述了关键管理生命周期每个阶段的潜在威胁,然后根据Azure链工作网环境的技术文件评估这些威胁在Azure链工作网环境中实现的可能性。最后,我们用三个不同的保护程度,即充分保护、部分保护和不保护,将我们的评估结果汇编到关键管理威胁表中。