Cointime

Download App
iOS & Android

3 Key Architectural Decisions Behind CCIP’s Advanced Security

Validated Project

From its inception, Chainlink has been committed to providing the most secure infrastructure possible, as secure infrastructure is essential to bringing the world’s assets onchain and powering their movement across various trading environments and regions. Already proven as secure infrastructure in Web3, Chainlink has enabled DeFi to successfully scale by consistently providing secure and reliable pricing data to many of the largest and most critical DeFi applications.

This rigorous security-first approach to developing infrastructure has been applied to the cross-chain problem in the form of Chainlink CCIP. CCIP incorporates many individual key security design decisions, but when compared to other cross-chain systems, there are three standout aspects: the level of decentralization, an independent risk management layer, and client diversity. 

In this blog, we’ll dive into why these key features are required to power a secure cross-chain ecosystem.

1. Level of Decentralization

Some cross-chain systems operate using a multisig with a few keys, or a few sets of signers, or as central hubs where all transactions flow through a single environment—potentially exposing them to single points of failure and introducing conflicts of interest that could put user funds at serious risk.

Chainlink CCIP is the only cross-chain solution achieving level-5 cross-chain security.

In contrast, every CCIP lane has three individual separate oracle networks, which are responsible for confirming three separate aspects of the transaction. The amount of decentralization within CCIP—just based on the number of nodes independently verifying key parts of the transaction—is at a much higher level than the typical cross-chain solution.

2. Risk Management Network

The second key difference between CCIP and other cross-chain solutions is the presence of an independent active risk management layer—the Risk Management Network. It’s a first-of-its-kind innovation that uses software development principles from the aerospace industry, enabling specific policies and configurations to be encoded to address emergent security risks.

The flow of a cross-chain message using CCIP.

If a chain experiences certain types of risks—block reorganization, reliability issues, new adversarial attacks, and more—actions or mitigations of those risks and conditions can be encoded separately from the core protocol into the Risk Management Network. 

In such cases, the core CCIP protocol providing security isn’t altered—more security is being added through the Risk Management Network by putting additional conditions on what a transaction needs to meet. With core security maintained, security is bolstered with additional code and configurations in the Risk Management Network. This unlocks a new layer of decentralization and fault redundancy, and the ability to quickly adapt to emerging risks. 

3. Client Diversity

The third key aspect powering a high degree of cross-chain security is client diversity. The two core networks, the transactional DONs (Committing DON and Executing DON) and the Risk Management Network, have been written in separate codebases and programming languages (Rust and Go).

The CCIP primary system and the Risk Management Network have been written in separate codebases and programming languages.

The core protocol is written in a completely separate codebase, in a different programming language, and was initially written by a separate team from the one that wrote the Risk Management Network and its codebase. Both of these parts of the CCIP system continue to be separate.

This is a very significant difference compared to other cross-chain solutions because even if a flaw is found in one of those codebases, that flaw does not extend to the other codebase. CCIP is the only cross-chain solution that provides client diversity in this sense, with separate codebases interacting with each other in a secure way, providing an unparalleled level of security among cross-chain solutions.

Building the Internet of Contracts With CCIP

There are many other security features within CCIP that surpass other cross-chain solutions, including rate limiting, anomaly detection, and more. Its successful operation with no value loss, continual reliability, and successful outcomes underscore the value of the time and rigor invested in its development. 

When infrastructure is being built to process and interact with the world’s assets, a security-first approach is critical. Chainlink infrastructure and CCIP are designed to meet the scale and complexity of the traditional financial system, which is processing quadrillions per year.

As CCIP is becoming more and more widely adopted across capital markets it’s becoming the standard method for banks and asset managers to transact across chains. If CCIP is able to continue to gain widespread adoption in the public blockchain world and become the secure standard for transactions across chains in capital markets, it could pave the way to a world where all transactions in the public blockchain world and the private bank chain world merge into a single global Internet of Contracts.

The Future of Assets, Powered by CCIP

CCIP is continually becoming even easier for developers to integrate and use in the public blockchain world, supporting more chains, connecting to more dApps, and powering more tokenized real-world assets and stablecoins, all while maintaining a high degree of security and reliability. This ubiquity across the industry, a defining aspect of CCIP’s hyper-scalable design, is critical to how value moves across chains.

If you want to learn more about CCIP’s underlying architecture and code and start building highly secure and reliable cross-chain use cases, check out the CCIP developer documentation.

Disclaimer: This post is for informational purposes only and contains statements about the future. There can be no assurance that actual results will not differ materially from thos

Comments

All Comments

Recommended for you

  • Putin: Russia "supports" Harris, calls her smile "contagious"

    According to foreign media such as TASS and Russia's Sputnik News, Jinse Finance reported that on the afternoon of September 5th local time, Russian President Putin said at the plenary session of the Eastern Economic Forum 2024 that Russia will "support" the US Democratic Party presidential candidate and vice president Harris as recommended by the US President Biden in the upcoming US presidential election. When asked how he viewed the 2024 US election, Putin said it was the choice of the American people. The new US president will be elected by the American people, and Russia will respect the choice of the American people. Putin also said that just as Biden suggested his supporters to support Harris, "we will do the same, we will support her." The report said that Putin also joked that Harris' laughter is "expressive and infectious," which shows that "she is doing everything well." He added that this may mean that she will avoid further sanctions against Russia.

  • An ETH whale repurchased 5,153 ETH with 12.23 million USDT 20 minutes ago

    A certain high-frequency trading ETH whale monitored by on-chain analyst Yu Jin bought 5,153 ETH with 12.23 million USDT 20 minutes ago.

  • CFTC: Uniswap Labs has actively cooperated with the investigation and only needs to pay a fine of US$175,000

    The CFTC has filed a lawsuit against Uniswap Labs and reached a settlement. It was found that Uniswap Labs illegally provided leveraged or margined retail commodity transactions of digital assets through a decentralized digital asset trading protocol. Uniswap Labs was required to pay a civil penalty of $175,000 and cease violations of the Commodity Exchange Act (CEA). The CFTC acknowledged that Uniswap Labs actively cooperated with law enforcement agencies in the investigation and reduced the civil penalty.

  • Federal Reserve Beige Book: Respondents generally expect economic activity to remain stable or improve

    The Federal Reserve's Beige Book pointed out that economic activity in three regions has slightly increased, while the number of regions reporting flat or declining economic activity has increased from five in the previous quarter to nine in this quarter. Overall employment levels remain stable, although some reports indicate that companies are only filling necessary positions, reducing working hours and shifts, or reducing overall employment levels through natural attrition. However, reports of layoffs are still rare. Generally speaking, wage growth is moderate, and the growth rate of labor input costs and sales prices ranges from slight to moderate. Consumer spending has declined in most regions, while in the previous reporting period, consumer spending remained stable overall.

  • Puffpaw Completes $6 Million Seed Round with Lemniscap Ventures as Participant

    Puffpaw has announced the completion of a $6 million seed round of financing, with participation from Lemniscap Ventures. The Puffpaw project plans to launch a blockchain-enabled electronic cigarette aimed at helping users reduce nicotine intake through token incentives. The project encourages users to quit smoking by recording their smoking habits and rewarding them with tokens. Puffpaw's token economics aims to cover 30% of the cost of users' first month of using their product and provide social rewards. The project also considers possible system abuse, but the issue of users potentially reporting smoking habits dishonestly is not yet clear.

  • Affected by Ethervista and others, Ethereum Gas temporarily rose to 33gwei

    According to Etherscan, due to the influence of contracts such as Ethervista, Ethereum Gas has temporarily risen to 33gwei, with the top three being EthervistaRouter, UniswapRouter, and BananaGun.

  • The probability of the Fed cutting interest rates by 25 basis points in September is 55%.

    The probability of the Federal Reserve cutting interest rates by 25 basis points in September is 55.0%, while the probability of a 50 basis point cut is 45.0%. The probability of the Federal Reserve cutting interest rates by a cumulative 50 basis points by November is 32.1%, by 75 basis points is 49.2%, and by 100 basis points is 18.8%.

  • Nvidia: No subpoena received from the US Department of Justice

    Nvidia (NVDA.O) stated that it has not received a subpoena from the US Department of Justice.

  • US SEC again postpones decision on environmentally friendly Bitcoin ETF listing application

    The US Securities and Exchange Commission (SEC) has once again postponed its final decision on the New York Stock Exchange (NYSE) Arca's application for a carbon offset Bitcoin ETF. According to a document dated September 4th, the decision has been extended to November 21st. The ETF aims to provide a Bitcoin investment exposure in an environmentally friendly way by offsetting carbon emissions, tracking an investment portfolio composed of 80% Bitcoin and 20% carbon credit futures. Tidal Investments submitted the fund registration application in December 2023, while NYSE Arca submitted the initial application in March. Concerns have been raised about the environmental impact of Bitcoin mining, with the International Monetary Fund (IMF) reporting that cryptocurrency mining accounts for 1% of global greenhouse gas emissions. The delay in this decision also includes the postponement of approval for the Nasdaq One-Stop Cryptocurrency Investment Portfolio ETF.

  • Japanese regulator calls for lower cryptocurrency tax rates by 2025

    On September 4th, it was announced that Japan's financial regulatory agency has released a comprehensive tax reform plan for the fiscal year 2025, which includes regulations on cryptocurrency to lower its tax rate.