Skip to main content
QUICK REVIEW

[Paper Review] Barriers to Collusion-resistant Transaction Fee Mechanisms

Yotam Gafni, Aviv Yaish|arXiv (Cornell University)|Feb 13, 2024
Radioactive element chemistry and processing4 citations
TL;DR

This paper resolves an open question in cryptocurrency mechanism design by proving that no non-trivial deterministic transaction fee mechanism (TFM) can simultaneously satisfy dominant strategy incentive compatibility (DSIC), myopic miner incentive compatibility (MMIC), and off-chain agreement (OCA)-proofness—meaning no mechanism can fairly and profitably allocate transactions while resisting collusion between users and miners. The key result is that only the trivial mechanism (zero miner revenue) satisfies all three properties, and even randomized mechanisms are bounded to at most 84.2% efficiency in the worst case.

ABSTRACT

To allocate transactions to blocks, cryptocurrencies use an auction-like transaction fee mechanism (TFM). A conjecture of Roughgarden [44] asks whether there is a TFM that is incentive compatible for both the users and the miner, and is also resistant to off-chain agreements (OCAs) between these parties, a collusion notion that captures the ability of users and the miner to jointly deviate for profit. The work of Chung and Shi [12] tackles the problem using the different collusion resistance notion of side-channel proofness (SCP), and shows an impossibility given this notion. We show that OCA-proofness and SCP are different, with SCP being strictly stronger. We then fully characterize the intersection of deterministic dominant strategy incentive-compatible (DSIC) and OCA-proof mechanisms, as well as deterministic MMIC and OCA-proof ones, and use this characterization to show that only the trivial mechanism is DSIC, myopic miner incentive-compatible (MMIC) and OCA-proof. We also show that a randomized mechanism can be at most 0.842-efficient in the worst case, and that the impossibility of a non-trivial DSIC, MMIC and OCA-proof extends to a couple of natural classes of randomized mechanisms.

Motivation & Objective

  • To resolve Roughgarden's open question on whether a non-trivial, DSIC, MMIC, and OCA-proof transaction fee mechanism (TFM) exists.
  • To clarify the distinction between OCA-proofness and the stronger side-channel proofness (SCP) notion used in prior work.
  • To fully characterize the space of DSIC+OCA-proof and MMIC+OCA-proof mechanisms for both deterministic and randomized settings.
  • To establish tight bounds on efficiency for randomized mechanisms under the same constraints.
  • To examine the impact of anonymity assumptions on the impossibility results, extending to non-anonymous mechanisms.

Proposed method

  • Proposes a novel characterization of OCA-proof mechanisms as 'posted burn' mechanisms, where a fixed reserve burn r is set and payments must be at least r, with all payments fully burned.
  • Uses the single-bidder case as a foundational insight: due to utility alignment between bidder and miner, all payments must be burnt, implying zero miner revenue.
  • Extends this insight to multi-bidder settings by showing that the highest bidder and miner can always collude to extract maximum joint utility, forcing mechanisms to adopt a posted-burn structure.
  • Employs analytical techniques involving integral bounds and utility comparisons to derive efficiency limits in randomized mechanisms, particularly focusing on the allocation probability and payment rules.
  • Applies a transformation to the allocation and payment functions to derive upper bounds on miner revenue and efficiency, using logarithmic and integral inequalities.
  • Considers both anonymous and non-anonymous mechanisms, showing that even without anonymity, only mechanisms with a unique fixed bidder can satisfy all three properties.

Experimental results

Research questions

  • RQ1Is there a non-trivial deterministic transaction fee mechanism that is DSIC, MMIC, and OCA-proof?
  • RQ2How does OCA-proofness relate to the stronger SCP (side-channel proofness) notion used in prior work?
  • RQ3What is the maximal efficiency achievable by a randomized DSIC, MMIC, and OCA-proof mechanism?
  • RQ4Can the impossibility result for deterministic mechanisms be extended to natural classes of randomized mechanisms?
  • RQ5How does the assumption of anonymity affect the feasibility of constructing mechanisms satisfying all three properties?

Key findings

  • The only deterministic mechanism that is DSIC, MMIC, and 1-OCA-proof is the trivial mechanism that never allocates any transaction and thus generates zero miner revenue.
  • OCA-proofness is strictly weaker than SCP, as there exist mechanisms that are OCA-proof but not SCP, showing that SCP is a stronger collusion resistance requirement.
  • For randomized mechanisms, the maximum worst-case efficiency is bounded at 0.842, meaning no such mechanism can achieve more than 84.2% of the optimal social welfare in the worst-case scenario.
  • Even under scale-invariance, the only DSIC, MMIC, and OCA-proof mechanism is the trivial one, indicating that this impossibility is robust across natural classes of mechanisms.
  • In the non-anonymous case, all feasible mechanisms must designate a unique fixed bidder who can be allocated the item, under a burned posted-price structure, severely restricting design freedom.
  • The impossibility result for deterministic mechanisms extends to randomized mechanisms under mild conditions, with efficiency bounded away from 1 even in relaxed settings.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.