Formal Modelling and Security Analysis of Bitcoin's Payment Protocol

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Modesti, Paolo, Shahandashti, Siamak F., McCorry, Patrick, Hao, Feng
Natura: Preprint
Pubblicazione: 2021
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866917849275039744
author Modesti, Paolo
Shahandashti, Siamak F.
McCorry, Patrick
Hao, Feng
author_facet Modesti, Paolo
Shahandashti, Siamak F.
McCorry, Patrick
Hao, Feng
contents The Payment Protocol standard BIP70, specifying how payments in Bitcoin are performed by merchants and customers, is supported by the largest payment processors and most widely-used wallets. The protocol has been shown to be vulnerable to refund attacks due to lack of authentication of the refund addresses. In this paper, we give the first formal model of the protocol and formalise the refund address security goals for the protocol, namely refund address authentication and secrecy. The formal model utilises communication channels as abstractions conveying security goals on which the protocol modeller and verifier can rely. We analyse the Payment Protocol confirming that it is vulnerable to an attack violating the refund address authentication security goal. Moreover, we present a concrete protocol revision proposal supporting the merchant with publicly verifiable evidence that can mitigate the attack. We verify that the revised protocol meets the security goals defined for the refund address. Hence, we demonstrate that the revised protocol is secure, not only against the existing attacks, but also against any further attacks violating the formalised security goals.
format Preprint
id arxiv_https___arxiv_org_abs_2103_08436
institution arXiv
publishDate 2021
record_format arxiv
spellingShingle Formal Modelling and Security Analysis of Bitcoin's Payment Protocol
Modesti, Paolo
Shahandashti, Siamak F.
McCorry, Patrick
Hao, Feng
Cryptography and Security
Formal Languages and Automata Theory
The Payment Protocol standard BIP70, specifying how payments in Bitcoin are performed by merchants and customers, is supported by the largest payment processors and most widely-used wallets. The protocol has been shown to be vulnerable to refund attacks due to lack of authentication of the refund addresses. In this paper, we give the first formal model of the protocol and formalise the refund address security goals for the protocol, namely refund address authentication and secrecy. The formal model utilises communication channels as abstractions conveying security goals on which the protocol modeller and verifier can rely. We analyse the Payment Protocol confirming that it is vulnerable to an attack violating the refund address authentication security goal. Moreover, we present a concrete protocol revision proposal supporting the merchant with publicly verifiable evidence that can mitigate the attack. We verify that the revised protocol meets the security goals defined for the refund address. Hence, we demonstrate that the revised protocol is secure, not only against the existing attacks, but also against any further attacks violating the formalised security goals.
title Formal Modelling and Security Analysis of Bitcoin's Payment Protocol
topic Cryptography and Security
Formal Languages and Automata Theory
url https://arxiv.org/abs/2103.08436