시가총액: $2.7165T 3.76%
거래량(24시간): $106.4734B 41.83%
  • 시가총액: $2.7165T 3.76%
  • 거래량(24시간): $106.4734B 41.83%
  • 공포와 탐욕 지수:
  • 시가총액: $2.7165T 3.76%
암호화
주제
암호화
소식
cryptostopics
비디오
최고의 뉴스
암호화
주제
암호화
소식
cryptostopics
비디오
bitcoin
bitcoin

$80932.204561 USD

3.71%

ethereum
ethereum

$2515.487603 USD

4.25%

tether
tether

$0.999884 USD

0.04%

bnb
bnb

$721.835914 USD

3.36%

xrp
xrp

$1.451247 USD

5.70%

usd-coin
usd-coin

$0.999916 USD

0.01%

solana
solana

$103.975202 USD

2.75%

tron
tron

$0.328267 USD

0.57%

hyperliquid
hyperliquid

$86.185949 USD

4.74%

zcash
zcash

$969.268611 USD

16.14%

dogecoin
dogecoin

$0.087343 USD

4.58%

monero
monero

$532.777067 USD

3.46%

chainlink
chainlink

$11.962226 USD

6.22%

unus-sed-leo
unus-sed-leo

$9.309718 USD

0.00%

cardano
cardano

$0.222092 USD

7.73%

암호화폐 뉴스 기사

회로 계층 취약점이 SNARK 기반 시스템에 가장 심각한 위협이 되는 것으로 밝혀졌습니다.

2024/08/09 05:03

Imperial College London의 연구원에 따르면 회로 계층의 취약점은 SNARK(Succinct Non-Interactive Arguments of Knowledge)를 기반으로 하는 시스템에 가장 심각한 위협이 됩니다.

회로 계층 취약점이 SNARK 기반 시스템에 가장 심각한 위협이 되는 것으로 밝혀졌습니다.

Researchers at Imperial College London have found that vulnerabilities at the circuit layer pose the most significant threat to systems based on Succinct Non-Interactive Arguments of Knowledge (SNARKs).

Imperial College London의 연구원들은 회로 계층의 취약성이 SNARK(Succinct Non-Interactive Arguments of Knowledge) 기반 시스템에 가장 심각한 위협이 된다는 사실을 발견했습니다.

The investigation examined 141 vulnerabilities from 107 audit reports, 16 vulnerability disclosures, and various bug trackers associated with popular SNARK projects. The findings were presented on Aug. 7 at the Science of Blockchain Conference at Columbia University.

조사에서는 107개의 감사 보고서, 16개의 취약점 공개 및 인기 있는 SNARK 프로젝트와 관련된 다양한 버그 추적기에서 141개의 취약점을 조사했습니다. 연구 결과는 8월 7일 컬럼비아 대학교에서 열린 블록체인 과학 컨퍼런스에서 발표되었습니다.

SNARKs are a type of zero-knowledge (ZK) proof that allows one to demonstrate that a statement is true without revealing any information about the statement. They are used extensively in Web3 to compress large computations and enable efficient on-chain verification.

SNARK는 진술에 대한 정보를 공개하지 않고 진술이 사실임을 입증할 수 있는 일종의 영지식(ZK) 증명입니다. 이는 대규모 계산을 압축하고 효율적인 온체인 검증을 가능하게 하기 위해 Web3에서 광범위하게 사용됩니다.

However, the complexity and abstraction of ZK circuits can introduce vulnerabilities that might go unnoticed during the development and auditing processes.

그러나 ZK 회로의 복잡성과 추상화로 인해 개발 및 감사 프로세스 중에 눈에 띄지 않을 수 있는 취약점이 발생할 수 있습니다.

To identify and categorize these vulnerabilities, the research team, led by Stefanos Chaliasos, a Ph.D. candidate at Imperial College London, proposed a vulnerability taxonomy and applied it to the analysis of vulnerabilities in circuit layers of several SNARK systems.

이러한 취약점을 식별하고 분류하기 위해 박사 학위인 Stefanos Chaliasos가 이끄는 연구팀은 Imperial College London의 후보자는 취약성 분류법을 제안하고 이를 여러 SNARK 시스템의 회로 계층 취약성 분석에 적용했습니다.

The team identified three main types of vulnerabilities in circuit layers: under-constrained, over-constrained and computational/hints error. The most frequent vulnerability found on zero knowledge circuits arises from insufficient constraints, which cause a verifier to accept invalid proofs, thus compromising a system’s soundness or completeness.

팀은 회로 계층에서 과소 제약, 과잉 제약, 계산/힌트 오류라는 세 가지 주요 취약점 유형을 식별했습니다. 영지식 회로에서 가장 자주 발견되는 취약점은 제약 조건이 충분하지 않아 검증자가 유효하지 않은 증명을 수락하여 시스템의 건전성이나 완전성이 손상되는 데서 발생합니다.

According to the research, 95 of the identified issues on SNARK-based systems affected soundness and four affected completeness. For instance, an attacker could exploit an insufficient input constraint to forge a valid proof for an invalid statement or to create a valid proof for a different statement than the one being proven.

연구에 따르면 SNARK 기반 시스템에서 확인된 문제 중 95개는 건전성에 영향을 미쳤고 4개는 완전성에 영향을 미쳤습니다. 예를 들어, 공격자는 잘못된 진술에 대한 유효한 증명을 위조하거나 입증된 진술과 다른 진술에 대한 유효한 증명을 생성하기 위해 불충분한 입력 제약 조건을 이용할 수 있습니다.

“The primary challenge for developers lies in adapting to a different level of abstraction and optimizing circuits for efficiency, which directly impacts the cost of using SNARKs,” the paper notes.

"개발자의 주요 과제는 다양한 수준의 추상화에 적응하고 효율성을 위해 회로를 최적화하는 것입니다. 이는 SNARK 사용 비용에 직접적인 영향을 미칩니다."라고 논문에서는 말합니다.

Other root causes for vulnerabilities on ZK circuits include distinguishing between assignments and constraints, missing input constraints and unsafe reuse of circuits, among others.

ZK 회로 취약점의 다른 근본 원인에는 할당과 제약 조건의 구별, 입력 제약 조건 누락, 안전하지 않은 회로 재사용 등이 포함됩니다.

The research team also highlighted the importance of clear documentation and tooling to help developers identify and fix vulnerabilities early on in the development process.

또한 연구팀은 개발자가 개발 프로세스 초기에 취약점을 식별하고 수정하는 데 도움이 되는 명확한 문서와 도구의 중요성을 강조했습니다.

“The goal is to integrate these findings into a vulnerability scanner that will automatically identify and classify vulnerabilities in ZK circuits,” Chaliasos told Blockworks.

"목표는 이러한 발견을 ZK 회로의 취약점을 자동으로 식별하고 분류하는 취약점 스캐너에 통합하는 것입니다."라고 Chaliasos는 Blockworks에 말했습니다.

Weighted VRFsThe first day of the conference also featured the Aptos team presenting their recently implemented weighted verifiable random functions, or weighted VRFs — a mechanism designed to enhance the randomness in the consensus process.

가중 VRF컨퍼런스 첫날에는 Aptos 팀이 최근 구현한 가중 검증 가능한 임의 함수 또는 가중 VRF(합의 과정에서 무작위성을 향상시키기 위해 설계된 메커니즘)를 선보였습니다.

The approach extends the concept of VRFs by incorporating weights into the random selection process of verifying inputs and outputs on-chain. With weights, participants in the consensus mechanism have different probabilities of being chosen based on their stake (weights).

이 접근 방식은 체인상의 입력 및 출력을 확인하는 무작위 선택 프로세스에 가중치를 통합하여 VRF의 개념을 확장합니다. 가중치를 사용하면 합의 메커니즘의 참가자는 지분(가중치)을 기준으로 선택될 확률이 다릅니다.

Aptos deployed the mechanism on its mainnet in June. “As far as you can tell, this is the first time you see a previously granular script that is unbiaseable, unpredictable, and operates as fast as the network,” said Alin Tomescu, head of cryptography at Aptos, during the presentation.

Aptos는 6월에 메인넷에 이 메커니즘을 배포했습니다. Aptos의 암호화 책임자인 Alin Tomescu는 프레젠테이션 중에 "당신이 알 수 있는 한, 편견이 없고 예측할 수 없으며 네트워크만큼 빠르게 작동하는 이전의 세분화된 스크립트를 보는 것은 이번이 처음입니다"라고 말했습니다.

According to Tomescu, Aptos has processed half a million calls through the new randomness API, with the distributed key generation (DKG) lasting about 20 seconds.

Tomescu에 따르면 Aptos는 새로운 무작위성 API를 통해 50만 건의 호출을 처리했으며 분산 키 생성(DKG)은 약 20초 동안 지속되었습니다.

원본 소스:cointelegraph

부인 성명:info@kdj.com

제공된 정보는 거래 조언이 아닙니다. kdj.com은 이 기사에 제공된 정보를 기반으로 이루어진 투자에 대해 어떠한 책임도 지지 않습니다. 암호화폐는 변동성이 매우 높으므로 철저한 조사 후 신중하게 투자하는 것이 좋습니다!

본 웹사이트에 사용된 내용이 귀하의 저작권을 침해한다고 판단되는 경우, 즉시 당사(info@kdj.com)로 연락주시면 즉시 삭제하도록 하겠습니다.

2026年09月04日 에 게재된 다른 기사