Communication publiée dans un périodique (Colloques, congrès, conférences scientifiques et actes)
A Quantitative Analysis of Security, Anonymity and Scalability for the Lightning Network
TIKHOMIROV, Sergei; Moreno-Sanchez, Pedro; Maffei, Matteo
2020In Proceedings of 2020 IEEE European Symposium on Security and Privacy (EuroS&P)
Peer reviewed
 

Documents


Texte intégral
quantitative-analysis-lightning.pdf
Postprint Auteur (552.55 kB)
Télécharger
Annexes
lightning-quantitative-slides.pdf
(383.95 kB)
Télécharger

Tous les documents dans ORBilu sont protégés par une licence d'utilisation.

Envoyer vers



Détails



Mots-clés :
Bitcoin; Lightning Network; privacy; security; anonymity; scalability
Résumé :
[en] Payment channel networks have been introduced to mitigate the scalability issues inherent to permissionless decentralized cryptocurrencies such as Bitcoin. Launched in 2018, the Lightning Network (LN) has been gaining popularity and consists today of more than 5000 nodes and 30000 payment channels that jointly hold 895 bitcoins (7.6M USD as of February 2020). This adoption has motivated research from both academia and industry. Payment channels suffer from security vulnerabilities, such as the wormhole attack, anonymity issues, and scalability limitations related to the upper bound on the number of concurrent payments per channel, which have been pointed out by the scientific community but never quantitatively analyzed. In this work, we first analyze the proneness of the LN to the wormhole attack and attacks against anonymity. We observe that an adversary needs to control only 2% of LN nodes to learn sensitive payment information (e.g., sender, receiver and payment amount) or to carry out the wormhole attack. Second, we study the management of concurrent payments in the LN and quantify its negative effect on scalability. We observe that for micropayments, the forwarding capability of up to 50% of channels is restricted to a value smaller than the overall channel capacity. This phenomenon not only hinders scalability but also opens the door for DoS attacks: We estimate that a network-wide DoS attack costs within 1.5M USD, while isolating the biggest community from the rest of the network costs only 225k USD. Our findings should prompt the LN community to consider the security, privacy and scalability issues of the network studied in this work when educating users about path selection algorithms, as well as to adopt multi-hop payment protocols that provide stronger security, privacy and scalability guarantees.
Disciplines :
Sciences informatiques
Auteur, co-auteur :
TIKHOMIROV, Sergei ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > Computer Science and Communications Research Unit (CSC)
Moreno-Sanchez, Pedro;  TU Wien > Security and Privacy research unit
Maffei, Matteo
Co-auteurs externes :
yes
Langue du document :
Anglais
Titre :
A Quantitative Analysis of Security, Anonymity and Scalability for the Lightning Network
Date de publication/diffusion :
septembre 2020
Nom de la manifestation :
IEEE Security & Privacy on the Blockchain (IEEE S&B 2020)
Date de la manifestation :
07-09-2020
Manifestation à portée :
International
Titre du périodique :
Proceedings of 2020 IEEE European Symposium on Security and Privacy (EuroS&P)
Peer reviewed :
Peer reviewed
Focus Area :
Security, Reliability and Trust
URL complémentaire :
Projet FnR :
FNR11684537 - Security, Scalability, And Privacy In Blockchain Applications And Smart Contracts, 2017 (01/08/2018-31/07/2021) - Alex Biryukov
Disponible sur ORBilu :
depuis le 19 octobre 2020

Statistiques


Nombre de vues
165 (dont 15 Unilu)
Nombre de téléchargements
533 (dont 4 Unilu)

citations Scopus®
 
42
citations Scopus®
sans auto-citations
37
citations OpenAlex
 
5
citations WoS
 
32

Bibliographie


Publications similaires



Contacter ORBilu