Smart Contract Oracle Security Evaluation System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Smart contract-based platforms, such as those on the Ethereum blockchain, are vulnerable to web service attacks due to risks associated with external blockchain resources contacted by oracles, which can compromise the security of transactions and user data.

Innovation Solution

A system and method for identifying security threats in smart contract-based services that utilize off-blockchain resources, involving modules to identify references, detect smart contracts, extract identifiers for off-blockchain resources, determine potential security threats, and perform security actions, such as generating notifications with risk assessments based on evaluations of domain reputation, vulnerabilities, and risk scores.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If oracles are used to connect smart contracts with external blockchain resources, then the functionality and versatility of smart contract-based platforms are improved, but the security vulnerability to web service attacks increases

Engineering Contradiction:
ImprovefunctionalityVSAvoidsecurity vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary security evaluation of off-blockchain resources by extracting identifiers from smart contract source code, evaluating domain reputation databases, checking web stacks for known vulnerabilities, and calculating risk scores before the smart contract executes transactions. This advance security assessment prevents malicious attacks by identifying threats before they can compromise the system.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary security evaluation system that sits between the smart contract oracle and the off-blockchain resources. This intermediary layer extracts identifiers from smart contract code, evaluates the security posture of external resources through multiple databases and services, and provides security feedback without disrupting the oracle's core functionality of connecting smart contracts to external resources.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security evaluation of off-blockchain resources is performed, then the security protection against malicious attacks is improved, but the system complexity increases

Engineering Contradiction:
Improvesecurity protectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security evaluation system is segmented into distinct functional modules: an extraction module that identifies off-blockchain resource identifiers from smart contract source code, an evaluation module that assesses security posture using multiple databases and services, and a feedback module that provides security information. This modular segmentation manages system complexity by organizing the evaluation process into independent, manageable components.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs self-service security evaluation by automatically extracting identifiers from smart contract code, querying multiple security databases and services, calculating risk scores, and providing feedback without requiring manual intervention. The oracle itself becomes part of the security evaluation process by providing its source code for analysis, enabling the system to self-assess its own security posture.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If multiple security evaluation methods are used to assess off-blockchain resources, then the measurement precision of security threats is improved, but the loss of time increases

Engineering Contradiction:
Improvesecurity threat detection accuracyVSAvoidevaluation time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system employs multiple security evaluation methods including domain reputation database checks, web stack vulnerability analysis, and certificate verification. By performing these evaluations in parallel and using a weighted risk score calculation, the system achieves comprehensive security assessment without requiring all evaluation methods to complete sequentially, thus reducing the total evaluation time while maintaining high detection accuracy.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12259970B1Systems and methods for identifying security threats in smart contract-based services to protect against malicious attacks utilizing off-blockchain resources
Publication Date: 2025.03.25 GEN DIGITAL INC
  • US12259970B1 patent drawing
  • US12259970B1 patent drawing
  • US12259970B1 patent drawing

AI summary

The disclosed computer-implemented method for identifying security threats in smart contract-based services to protect against malicious attacks utilizing off-blockchain resources may include (i) identifying a reference associated with a transaction on a smart contract-based platform, (ii) detecting content describing one or more smart contracts associated with the reference on the platform, (iii) extracting an identifier from the content to locate off-blockchain resources utilized by the smart contracts, (iv) determining potential security threats associated with the off-blockchain resources, and (v) performing a security action that protects against the potential security threats. Various other methods, systems, and computer-readable media are also disclosed.