Security Assessment of Blockchain in Chinese Classified Protection of Cybersecurity

Classified protection is one of primary security policies of information system in many countries. With the increasing popularity of blockchain in various fields of applications, it is extremely necessary to promote classified protection for blockchain's risk assessment in order to push forward...

Full description

Bibliographic Details
Main Authors: Di Wang, Yan Zhu, Yi Zhang, Guowei Liu
Format: Article
Language:English
Published: IEEE 2020-01-01
Series:IEEE Access
Subjects:
Online Access:https://ieeexplore.ieee.org/document/9249006/
id doaj-05a919c0ddf244d29abe140dd26a7b28
record_format Article
spelling doaj-05a919c0ddf244d29abe140dd26a7b282021-03-30T04:34:04ZengIEEEIEEE Access2169-35362020-01-01820344020345610.1109/ACCESS.2020.30360049249006Security Assessment of Blockchain in Chinese Classified Protection of CybersecurityDi Wang0https://orcid.org/0000-0003-1186-5707Yan Zhu1https://orcid.org/0000-0002-9159-745XYi Zhang2https://orcid.org/0000-0002-7698-6000Guowei Liu3School of Computer and Communication Engineering, University of Science and Technology Beijing, Beijing, ChinaSchool of Computer and Communication Engineering, University of Science and Technology Beijing, Beijing, ChinaSchool of Computer and Communication Engineering, University of Science and Technology Beijing, Beijing, ChinaBeijing Municipal Bureau of Economy and Information Technology, Beijing, ChinaClassified protection is one of primary security policies of information system in many countries. With the increasing popularity of blockchain in various fields of applications, it is extremely necessary to promote classified protection for blockchain's risk assessment in order to push forward the sustainable development of blockchain. Taking the Level 3 in Chinese classified protection 2.0 as an example, this paper proposes the common evaluation rules on blockchain to ensure that blockchain can meet the needs of countries to build it as critical infrastructure. Both assessment requirements and enforcement proposals are presented and analyzed from the standpoint of blockchain's core technologies, e.g., peer-to-peer network, distributed ledger, contract's scripting system, and consensus mechanism. Moreover, the assessment results on three main platforms, Bitcoin, Ethereum, and Hyperledger, are summarized and analyzed in compliance with the control points specified in the level 3. Our investigation indicates that the current blockchain is able to satisfy the requirements of evaluation items in many aspects, such as software fault tolerance, resource control, backup and recovery, but further improvements are still needed for some aspects, including security audit, access control, identification and authentication, data integrity, etc., in order to satisfy the requirements of important fields on national security, economic development and human life.https://ieeexplore.ieee.org/document/9249006/Blockchainclassified protection of cybersecuritypeer-to-peer networkconsensus mechanismassessment and analysis
collection DOAJ
language English
format Article
sources DOAJ
author Di Wang
Yan Zhu
Yi Zhang
Guowei Liu
spellingShingle Di Wang
Yan Zhu
Yi Zhang
Guowei Liu
Security Assessment of Blockchain in Chinese Classified Protection of Cybersecurity
IEEE Access
Blockchain
classified protection of cybersecurity
peer-to-peer network
consensus mechanism
assessment and analysis
author_facet Di Wang
Yan Zhu
Yi Zhang
Guowei Liu
author_sort Di Wang
title Security Assessment of Blockchain in Chinese Classified Protection of Cybersecurity
title_short Security Assessment of Blockchain in Chinese Classified Protection of Cybersecurity
title_full Security Assessment of Blockchain in Chinese Classified Protection of Cybersecurity
title_fullStr Security Assessment of Blockchain in Chinese Classified Protection of Cybersecurity
title_full_unstemmed Security Assessment of Blockchain in Chinese Classified Protection of Cybersecurity
title_sort security assessment of blockchain in chinese classified protection of cybersecurity
publisher IEEE
series IEEE Access
issn 2169-3536
publishDate 2020-01-01
description Classified protection is one of primary security policies of information system in many countries. With the increasing popularity of blockchain in various fields of applications, it is extremely necessary to promote classified protection for blockchain's risk assessment in order to push forward the sustainable development of blockchain. Taking the Level 3 in Chinese classified protection 2.0 as an example, this paper proposes the common evaluation rules on blockchain to ensure that blockchain can meet the needs of countries to build it as critical infrastructure. Both assessment requirements and enforcement proposals are presented and analyzed from the standpoint of blockchain's core technologies, e.g., peer-to-peer network, distributed ledger, contract's scripting system, and consensus mechanism. Moreover, the assessment results on three main platforms, Bitcoin, Ethereum, and Hyperledger, are summarized and analyzed in compliance with the control points specified in the level 3. Our investigation indicates that the current blockchain is able to satisfy the requirements of evaluation items in many aspects, such as software fault tolerance, resource control, backup and recovery, but further improvements are still needed for some aspects, including security audit, access control, identification and authentication, data integrity, etc., in order to satisfy the requirements of important fields on national security, economic development and human life.
topic Blockchain
classified protection of cybersecurity
peer-to-peer network
consensus mechanism
assessment and analysis
url https://ieeexplore.ieee.org/document/9249006/
work_keys_str_mv AT diwang securityassessmentofblockchaininchineseclassifiedprotectionofcybersecurity
AT yanzhu securityassessmentofblockchaininchineseclassifiedprotectionofcybersecurity
AT yizhang securityassessmentofblockchaininchineseclassifiedprotectionofcybersecurity
AT guoweiliu securityassessmentofblockchaininchineseclassifiedprotectionofcybersecurity
_version_ 1724181504021495808