Automated Risk Evaluation Dimension Library for Ethereum Improvement Proposals

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Developers and auditors face inefficiencies and inaccuracies when manually searching and analyzing numerous Ethereum Improvement Proposals (EIPs) for standards, protocols, parameters, return values, visibility, and function modifiers to evaluate security risks and vulnerabilities in smart contracts, leading to prolonged evaluation times and potential oversight of security measures.

Innovation Solution

An automated method for generating a risk evaluation dimension library for EIPs, which involves extracting information about interfaces, constructing a risk matrix library, and evaluating risks based on preset standards, allowing for quick and accurate assessment by taking interfaces as one dimension and parameters, return values, visibility, and function modifiers as other dimensions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual search and analysis of EIP standards is used, then developers and auditors can review codes against EIP requirements, but the process suffers from low efficiency, inescapable flaws, and low accuracy

Engineering Contradiction:
Improveaccuracy of EIP standard reviewVSAvoidefficiency of EIP standard search and analysis
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent replaces the manual mechanical process of searching and analyzing EIP standards with an automated computer-based system. The system automatically extracts interface information from EIP documents, constructs risk matrix libraries, and performs automated code auditing, eliminating human manual search operations and significantly improving both efficiency and accuracy.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system enables automated self-service auditing by constructing risk matrix libraries that automatically evaluate code against EIP standards. The automated extraction and evaluation processes allow the system to perform security audits without requiring developers or auditors to manually review each EIP standard, thereby resolving the contradiction between thoroughness and efficiency.

Inventive Principle:
Principle #25Self-service

2Reliability

If developers and auditors manually review all EIP standards and elements, then comprehensive security checks can be performed, but the process takes prolonged time and suffers from oversight of security measures

Engineering Contradiction:
Improvecomprehensiveness of security risk evaluationVSAvoidtime required for EIP standard analysis
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary action by automatically extracting all interface information from EIP documents and pre-constructing risk matrix libraries before actual code auditing begins. This preprocessing ensures that all security requirements are ready for automated evaluation, eliminating the need for time-consuming manual review during the auditing process while maintaining comprehensive coverage.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The automated system replaces manual security review processes with algorithm-driven extraction and evaluation. The system automatically identifies all security-relevant elements in EIP standards and systematically evaluates code against them, ensuring comprehensive coverage without the time constraints and human errors inherent in manual processes.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Productivity

If automated extraction of EIP information is implemented, then efficiency and accuracy of risk evaluation improve, but the system complexity increases

Engineering Contradiction:
Improvespeed of risk evaluationVSAvoidcomplexity of automated extraction system
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the complex automated extraction system into distinct functional modules: an extraction module that retrieves EIP information, a construction module that builds risk matrix libraries, and an evaluation module that performs automated auditing. This segmentation manages system complexity by organizing functions into independent, manageable components while maintaining high productivity through automated processing.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20230385737A1Method for automatically generating risk evaluation dimension library for eip
Publication Date: 2023.11.30 BEIJING LINGZONG SECURITY TECH CO LTD
  • US20230385737A1 patent drawing
  • US20230385737A1 patent drawing

AI summary

The present disclosure provides a method for automatically generating a risk evaluation dimension library for an Ethereum Improvement Proposal (EIP), which belongs to the technical field of blockchains. The method includes: extracting the EIP, and automatically extracting information about all interfaces in the EIP, where the information includes standards, protocols, parameters, return values, visibility and function modifiers; and constructing a risk matrix library of the EIP by taking the interfaces as one dimension and taking the parameters, the return values, the visibility and the function modifiers as other dimensions, and evaluating a risk of the EIP according to an EIP standard and an element definition standard in the EIP standard. According to the present disclosure, problems of big errors and low efficiency caused by manual extraction are solved, a speed and accuracy of extraction are better, and evaluation results can be stored.