Smart Contract Risk Assessment via Secondary Blockchain Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Smart contracts in Turing-complete blockchains are vulnerable to recursive call attacks, which can lead to asset leaks, and existing technologies lack effective mechanisms to detect and mitigate these risks before they are accepted into primary blockchains.

Innovation Solution

Smart contracts are submitted to a secondary blockchain for risk assessment, where they are evaluated for recursive call attack vulnerabilities using profiling tools and time windows computation, and a risk score is assigned based on defined metrics, allowing for acceptance or rejection before being added to the primary blockchain.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If smart contracts are directly accepted into the primary blockchain without prior validation, then the deployment speed and ease of operation are improved, but the reliability and security against recursive call attacks deteriorate

Engineering Contradiction:
Improvesmart contract deployment speedVSAvoidsmart contract security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements a preliminary validation phase where smart contracts are submitted to a secondary blockchain for risk assessment before being accepted into the primary blockchain. The system performs recursive call attack vulnerability assessments, time window computations, and risk score calculations in advance, ensuring that only validated contracts are deployed to the main network, thus resolving the contradiction between deployment speed and security

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a secondary blockchain as an intermediary layer between contract submission and primary blockchain acceptance. This intermediary system performs validation, risk assessment, and security checks, acting as a mediator that filters out vulnerable contracts before they reach the primary blockchain, thereby maintaining both operational efficiency and security reliability

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If comprehensive risk assessment mechanisms are implemented for all smart contracts, then the reliability and security are improved, but the device complexity and processing time increase

Engineering Contradiction:
Improvesmart contract securityVSAvoidvalidation system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the validation process into distinct modular components including recursive call attack vulnerability assessment, time window computation, risk score calculation, and validation decision-making. Each component operates independently in the secondary blockchain, allowing for comprehensive security checks while maintaining system manageability and reducing overall complexity through functional decomposition

Inventive Principle:
Principle #1Segmentation

3Object-affected harmful factors

If risk assessment is performed on all smart contracts before primary blockchain acceptance, then the loss of harmful factors (asset leaks) is reduced, but the loss of time and processing overhead increase

Engineering Contradiction:
Improveasset leak preventionVSAvoidcontract validation time
Core Design Contradiction:
Object-affected harmful factorsVSLoss of time

Solution Approach 1:

The patent changes the validation parameter from binary acceptance/rejection to a risk score-based continuum. By computing risk scores based on multiple factors including recursive call depth, time window violations, and vulnerability metrics, the system can prioritize validation resources on high-risk contracts while expediting low-risk contracts, thus reducing overall validation time while maintaining asset protection

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11176257B2Reducing risk of smart contracts in a blockchain
Publication Date: 2021.11.16 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11176257B2 patent drawing
  • US11176257B2 patent drawing
  • US11176257B2 patent drawing

AI summary

A system and method for reducing risk of smart contracts in blockchains in a computer environment are presented. One or more smart contracts may be accepted or rejected from a secondary blockchain to a primary blockchain according to a risk assessment to recursive call attack vulnerabilities.