TESC: TLS/SSL-certificate endorsed smart contracts

Ulrich Gallersdörfer, Florian Matthes

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

4 Scopus citations

Abstract

Although nearly all information regarding smart contract addresses is shared via websites, emails, or other forms of digital communication, blockchains and distributed ledger technologies are unable to establish secure bindings between websites and the corresponding smart contracts. A user cannot differentiate between a website link to a legitimate smart contract set up by a reputable business owner and that to an illicit contract aiming to defraud the user. Surprisingly, current attempts to resolve this issue are based mostly on information redundancy, e.g., displaying contract addresses multiple times in varying forms of images and text. These verification processes are burdensome because the user is responsible for verifying the accuracy of an address. More importantly, these measures do not address the core problem because the contract itself does not contain information on its authenticity. To resolve such limitations and to increase security, we propose a solution that leverages publicly issued Transport Layer Security (TLS)/Secure Sockets Layer (SSL) certificates of Fully-Qualified Domain Names (FQDN) to ensure the authenticity of smart contracts and their owners. Our approach combines on-chain endorsement storage that utilizes signatures from the respective certificate and off-chain authentication of the smart contract. The system is open and transparent because the only requirement for usage is ownership of a TLS/SSL certificate. Further, moderate deployment and maintenance costs, a widely accepted public key infrastructure, and a simple interface enable TLS/SSL endorsed smart contracts (TeSC) to bridge the gap between websites and smart contracts.

Original languageEnglish
Title of host publicationProceedings - 3rd IEEE International Conference on Decentralized Applications and Infrastructures, DAPPS 2021
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages95-100
Number of pages6
ISBN (Electronic)9781665434850
DOIs
StatePublished - 2021
Event3rd IEEE International Conference on Decentralized Applications and Infrastructures, DAPPS 2021 - Virtual, Online, United Kingdom
Duration: 3 Aug 20216 Aug 2021

Publication series

NameProceedings - 3rd IEEE International Conference on Decentralized Applications and Infrastructures, DAPPS 2021

Conference

Conference3rd IEEE International Conference on Decentralized Applications and Infrastructures, DAPPS 2021
Country/TerritoryUnited Kingdom
CityVirtual, Online
Period3/08/216/08/21

Keywords

  • Authentication
  • Certificates
  • Ethereum
  • Smart contracts
  • blockchain

Fingerprint

Dive into the research topics of 'TESC: TLS/SSL-certificate endorsed smart contracts'. Together they form a unique fingerprint.

Cite this