[論文レビュー] Correctness and Fairness of Tendermint-core Blockchains
この論文は、Tendermint-coreブロックチェーンの正しさと公平性を形式的に検証し、1/3未塔のByzantineバリデーターが存在する場合、最終的に同期的である環境下で、改変されたプロトコルが1回限りおよび繰り返しのコンセンサスを達成することを証明している。また、システムが最終的に同期的である場合に限り、公平な報酬メカニズムが存在することを確立し、元のTendermint報酬メカニズムが公平でないが、洗練されたタイムアウトとメッセージ内容により最終的に公平にできると示している。
Tendermint-core blockchains (e.g. Cosmos) are considered today one of the most viable alternatives for the highly energy consuming proof-of-work blockchains such as Bitcoin and Ethereum. Their particularity is that they aim at offering strong consistency (no forks) in an open system combining two ingredients (i) a set of validators that generate blocks via a variant of Practical Byzantine Fault Tolerant (PBFT) consensus protocol and (ii) a selection strategy that dynamically selects nodes to be validators for the next block via a proof-of-stake mechanism. However,the exact assumptions on the system model under which Tendermint underlying algorithms are correct and the exact properties Tendermint verifies have never been formally analyzed. The contribution of this paper is two-fold. First, while formalizing Tendermint algorithms we precisely characterize the system model and the exact problem solved by Tendermint. We prove that in eventual synchronous systems a modified version of Tendermint solves (i) under additional assumptions, a variant of one-shot consensus for the validation of one single block and (ii) a variant of the repeated consensus problem for multiple blocks. These results hold even if the set of validators is hit by Byzantine failures, provided that for each one-shot consensus instance less than one third of the validators is Byzantine. Our second contribution relates to the fairness of the rewarding mechanism. It is common knowledge that in permisionless blockchain systems the main threat is the tragedy of commons that may yield the system to collapse if the rewarding mechanism is not adequate. Ad minimum the rewarding mechanism must be fair, i.e.distributing the rewards in proportion to the merit of participants. We prove, for the first time in blockchain systems, that in repeated-consensus based blockchains there exists an (eventual) fair rewarding mechanism if and only if the system is (eventual) synchronous. We also show that the original Tendermint rewarding is not fair, however, a modification of the original protocol makes it eventually fair.
研究の動機と目的
- 現実的なシステム仮定の下でTendermint-coreコンセンサスプロトコルの正しさを形式的に分析すること。
- コンセンサスの安全性とライブネスを損なう微細なバグを同定・修正すること。
- バリデーターの貢献度に基づく報酬メカニズムの公平性を定義し、証明すること。
- ブロックチェーンシステムにおける最終的に公平な報酬メカニズムが存在するための必要十分条件を確立すること。
- 実用的なブロックチェーン実装と形式的分散システム理論の間のギャップを埋めること。
提案手法
- 最終的に同期的仮定を用いた分散システムフレームワークを用いてTendermint-coreプロトコルの形式的モデル化を行う。
- 元のプロトコルにおけるライブネス問題を是正するための洗練されたタイムアウトメカニズムを導入する。
- バリデーターが正しく参加し、メッセージを適切に配信した割合に比例して報酬が支払われる、貢献度に基づく報酬メカニズムを定義する。
- バリデーターの1/3未塔がByzantineであるという条件下で、コンセンサスの終了性と妥当性を証明する。
- コミットメッセージに正しく動作するプロセスとByzantineプロセスを識別するための区別情報を含める、改変されたコンセンサスモデルを採用する。
- 双方向含意による証明により、最終的に公平な報酬メカニズムが存在する iff システムが最終的に同期的であることを確立する。
実験結果
リサーチクエスチョン
- RQ1元のTendermintプロトコルは、どのようなシステム仮定のもとでコンセンサスの正しさを達成するか?
- RQ2元のTendermintプロトコルは、Byzantineバリデーターが存在する状況でも、形式的に修正可能で、ライブネスと安全性を保証できるか?
- RQ3繰り返しコンセンサスブロックチェーンにおける報酬メカニズムが公平と見なされるために必要な条件は何か?
- RQ4非同期システムでは、Tendermint-coreブロックチェーンにおける報酬の公平性は可能か?
- RQ5元のTendermint報酬メカニズムは、最終的に公平にするように修正可能か?
主な発見
- バリデーターの1/3未塔がByzantineである限り、改変されたTendermintプロトコルは、最終的に同期的システムで1回限りおよび繰り返しのコンセンサスを達成する。
- 元のTendermintプロトコルは、標準的な仮定のもとではライブネスのバグのため正しくないが、洗練されたタイムアウトメカニズムを用いることで修正可能である。
- 繰り返しコンセンサスブロックチェーンにおける公平な報酬メカニズムが存在するのは、システムが最終的に同期的または同期的である場合に限る。
- 元のTendermint報酬メカニズムは、最終的に同期的システムであっても、同期化中のメッセージ可視性の不完全さのため公平でない。
- より良い報酬メカニズム—2n/3を超えるメッセージ受信と適切なタイムアウト調整に基づくもの—は、最終的に同期的システムで最終的に公平にできる。
- 非同期システムでは、すべてのバリデーターが正常であっても、(最終的)に公平な報酬メカニズムは存在しない。これは、このような環境下での公平性の根本的な制限を示している。
より良い研究を、今すぐ始めましょう
論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。
クレジットカード登録不要
このレビューはAIが作成し、人間の編集者が確認しました。