Security analysis of a blockchain-based protocol for the certification of academic credentials

10/10/2019
by   Marco Baldi, et al.
0

We consider a blockchain-based protocol for the certification of academic credentials named Blockcerts, which is currently used worldwide for validating digital certificates of competence compliant with the Open Badges standard. We study the certification steps that are performed by the Blockcerts protocol to validate a certificate, and find that they are vulnerable to a certain type of impersonation attacks. More in detail, authentication of the issuing institution is performed by retrieving an unauthenticated issuer profile online, and comparing some data reported there with those included in the issued certificate. We show that, by fabricating a fake issuer profile and generating a suitably altered certificate, an attacker is able to impersonate a legitimate issuer and can produce certificates that cannot be distinguished from originals by the Blockcerts validation procedure. We also propose some possible countermeasures against an attack of this type, which require the use of a classic public key infrastructure or a decentralized identity system integrated with the Blockcerts protocol.

READ FULL TEXT
research
03/15/2021

Formal Modelling and Security Analysis of Bitcoin's Payment Protocol

The Payment Protocol standard BIP70, specifying how payments in Bitcoin ...
research
08/27/2022

SoK: Decentralized Finance (DeFi) Incidents

Within just four years, the blockchain-based Decentralized Finance (DeFi...
research
02/08/2023

Blockchain-based certificate authentication system with enabling correction

Blockchain has proven to be an emerging technology in the digital world,...
research
06/22/2020

Blockchain for Academic Credentials

Academic credentials are documents that attest to successful completion ...
research
11/20/2017

The Horcrux Protocol: A Method for Decentralized Biometric-based Self-sovereign Identity

Most user authentication methods and identity proving systems rely on a ...
research
07/10/2018

Blockchain-based PKI for Crowdsourced IoT Sensor Information

The Internet of Things is progressively getting broader, evol-ving its s...
research
02/13/2021

Risk Framework for Bitcoin Custody Operation with the Revault Protocol

Our contributions with this paper are twofold. First, we elucidate the m...

Please sign up or login with your details

Forgot password? Click here to reset