Bitcontracts: Supporting Smart Contracts in Legacy Blockchains

Karl Wüst, Loris Diana, Kari Kostiainen, Ghassan Karame, Siniša Matetić, Srđjan Čapkun · 2021

In this paper, our main goal is to design a solution that adds expressive smart contract execution support as a subsystem to existing legacy blockchain systems.The primary usage of our solution is to enhance systems like Bitcoin that have no built-in smart contract capabilities.The secondary usage is to extend the contract execution capabilities of platforms like Ethereum that support contracts but have severe limitations on the complexity of allowed computations. Previous work.Recent research has explored different ways to add contract execution capabilities to blockchains.For instance, Arbitrum [25] and ACE [50] use off-chain execution models, where contract issuers appoint a set of managers who are responsible for executing the contract and communicating the results back to the chain.Hyperledger Fabric [5] uses a similar model in a permissioned setting with an execute-order-validate architecture in which transactions are executed before ordering.The main drawback of such solutions is that they are newly purpose-built systems, and therefore such systems cannot be deployed on legacy systems without modifying the underlying blockchain.Another proposal, FastKitten [16], relies on enclaved execution and collaterals, but only supports short-lived contracts that are restricted to known participants.In addition, such a system cannot tolerate enclave compromise.Recently discovered attacks [11], [45], [29], [13], [44] have shown that TEE compromise is a relevant threat.We discuss the limitations of previous solutions in more detail in Section II-B.Our solution.In this paper, we propose a novel system called Bitcontracts that adds expressive smart contract execution capabilities to legacy cryptocurrencies without requiring protocol changes to the legacy system, and overcomes the main limitations of previous solutions.The starting point of our solution is an off-chain execution model, similar to previous systems like Arbitrum, ACE, or Fabric.In Bitcontracts, the contract issuer appoints a set of service providers that execute the contract's code.The appointed execution set is recorded on the chain together with the contract's code and the contract participants are free to choose if they accept this set.Instead of requiring that all service providers agree on the execution result (as is done in Arbitrum) or trusting the execution environments fully (as is required in FastKitten), we leverage a more flexible quorumbased trust model similar to ACE, where execution results are accepted when t out of n service providers report the same result.Such a model can provide both strong security (up to t -1 service providers can be compromised) and good availability (up to n-t service providers can be unresponsive).Abstract-In this paper we propose Bitcontracts, a novel solution that enables secure and efficient execution of generic smart contracts on top of unmodified legacy cryptocurrencies like Bitcoin that do not support contracts natively.The starting point of our solution is an off-chain execution model, where the contract's issuers appoints a set of service providers to execute the contract's code.The contract's execution results are accepted if a quorum of service providers reports the same result and clients are free to choose which such contracts they trust and use.The main technical contribution of this paper is how to realize such a trust model securely and efficiently without modifying the underlying blockchain.We also identify a set of generic properties that a blockchain system must support so that expressive smart contracts can be added safely, and analyze popular existing blockchains based on these criteria.

Read the paper · More papers on PaperTik