Smart Contract Risk Assessment via Secondary Blockchain Validation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Smart contracts in Turing-complete blockchains are vulnerable to recursive call attacks, which can lead to asset leaks, and existing technologies lack effective mechanisms to detect and mitigate these risks before they are accepted into primary blockchains.
Innovation Solution
Smart contracts are submitted to a secondary blockchain for risk assessment, where they are evaluated for recursive call attack vulnerabilities using profiling tools and time windows computation, and a risk score is assigned based on defined metrics, allowing for acceptance or rejection before being added to the primary blockchain.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If smart contracts are directly accepted into the primary blockchain without prior validation, then the deployment speed and ease of operation are improved, but the reliability and security against recursive call attacks deteriorate
Solution Approach 1:
The patent implements a preliminary validation phase where smart contracts are submitted to a secondary blockchain for risk assessment before being accepted into the primary blockchain. The system performs recursive call attack vulnerability assessments, time window computations, and risk score calculations in advance, ensuring that only validated contracts are deployed to the main network, thus resolving the contradiction between deployment speed and security
Solution Approach 2:
The patent introduces a secondary blockchain as an intermediary layer between contract submission and primary blockchain acceptance. This intermediary system performs validation, risk assessment, and security checks, acting as a mediator that filters out vulnerable contracts before they reach the primary blockchain, thereby maintaining both operational efficiency and security reliability
2Reliability
If comprehensive risk assessment mechanisms are implemented for all smart contracts, then the reliability and security are improved, but the device complexity and processing time increase
Solution Approach 1:
The patent segments the validation process into distinct modular components including recursive call attack vulnerability assessment, time window computation, risk score calculation, and validation decision-making. Each component operates independently in the secondary blockchain, allowing for comprehensive security checks while maintaining system manageability and reducing overall complexity through functional decomposition
3Object-affected harmful factors
If risk assessment is performed on all smart contracts before primary blockchain acceptance, then the loss of harmful factors (asset leaks) is reduced, but the loss of time and processing overhead increase
Solution Approach 1:
The patent changes the validation parameter from binary acceptance/rejection to a risk score-based continuum. By computing risk scores based on multiple factors including recursive call depth, time window violations, and vulnerability metrics, the system can prioritize validation resources on high-risk contracts while expediting low-risk contracts, thus reducing overall validation time while maintaining asset protection
Data Source
AI summary
A system and method for reducing risk of smart contracts in blockchains in a computer environment are presented. One or more smart contracts may be accepted or rejected from a secondary blockchain to a primary blockchain according to a risk assessment to recursive call attack vulnerabilities.


