Skip to main content
QUICK REVIEW

[论文解读] Continuous-Time Analysis of the Bitcoin and Prism Backbone Protocols

Jing Li, Dongning Guo|arXiv (Cornell University)|Jan 16, 2020
Blockchain Technology Applications and Security参考文献 19被引用 7
一句话总结

本文对比特币和Prism骨干协议进行了严格的连续时间分析,引入了‘t-可信区块链’这一新概念,以建立明确的概率安全保证。在具有有界网络延迟且对矿工策略仅假设聚合挖矿速率的现实模型下,作者证明了区块链增长、质量与公共前缀定理,并给出了明确的概率界,表明在可信区块链中深度确认的交易在与 log(1/ε) 成比例的确认时间后,以高概率变为永久性。

ABSTRACT

Bitcoin is a peer-to-peer payment system proposed by Nakamoto in 2008. Based on the Nakamoto consensus, Bagaria, Kannan, Tse, Fanti, and Viswanath proposed the Prism protocol in 2018 and showed that it achieves near-optimal blockchain throughput while maintaining a similar level of security as bitcoin. Previous probabilistic security guarantees for the bitcoin and Prism backbone protocols were either established under a simplified discrete-time model or expressed in terms of exponential order results. This paper presents a streamlined and strengthened analysis under a more realistic continuous-time model. A fully rigorous model for blockchains is developed with no restrictions on adversarial miners except for an upper bound on their aggregate mining rate. The only assumption on the peer-to-peer network is that all block propagation delays are upper bounded by a constant. A new notion of "t-credible blockchains" is introduced, which, together with some carefully defined "typical" events concerning block production over time intervals, is crucial to establish probabilisitic security guarantees in continuous time. A blockchain growth theorem, a blockchain quality theorem, and a common prefix theorem are established with explicit probability bounds. Moreover, under a certain typical event which occurs with probability close to $1$, a valid transaction that is deep enough in one credible blockchain is shown to be permanent in the sense that it must be found in} in all future credible blockchains.

研究动机与目标

  • 为解决以往对区块链协议的离散时间分析和指数阶分析的局限性,提出更现实的连续时间模型。
  • 在最小假设下,为比特币和Prism骨干协议建立明确的、非渐近的概率安全保证。
  • 将‘t-可信区块链’的概念形式化,作为在连续时间中证明活性与一致性的基础。
  • 消除有限时间范围的假设,提供适用于无限运行区块链的结果。
  • 证明在可信区块链中深度确认的交易,以高概率永久地保持在所有诚实链中一致。

提出的方法

  • 引入一个连续时间模型,其中区块生成与传播被建模为具有有界延迟的随机过程。
  • 将‘t-可信区块链’定义为在时间区间内满足特定区块生成与传播条件的区块链,以确保一致性和活性。
  • 在区块链和领导者序列上构建明确定义的概率空间,以严格分析协议行为。
  • 利用关于区块生成的‘典型事件’来限制对手在超越诚实链方面成功的概率。
  • 应用集中不等式和递归界,推导出失败概率的显式指数衰减率。
  • 利用Prism协议中可信领导者序列的概念,证明在高概率条件下交易的永久性。

实验结果

研究问题

  • RQ1在具有有界网络延迟的连续时间模型下,如何加强比特币和Prism的概率安全保证?
  • RQ2在何种条件下,区块链中确认的交易能确保在所有诚实链中永久一致?
  • RQ3能否为区块链增长、质量与公共前缀特性推导出显式、非渐近的失败概率界?
  • RQ4缺乏有限生命周期假设如何影响区块链协议的安全分析?
  • RQ5为确保交易以至少 1−ε 的概率成为永久性,所需的最小确认时间是多少?

主要发现

  • 建立了具有显式概率界的一般区块链增长定理,表明诚实区块以与诚实挖矿速率减去敌对影响成比例的速率被添加。
  • 区块链质量定理证明,在有界延迟下,诚实矿工在任意时间区间内以高概率产生至少恒定比例的区块。
  • 证明了公共前缀定理,表明诚实链中深度为k的区块以随k指数衰减的概率被保证存在于所有未来的诚实链中。
  • 对于Prism协议,证明了在足够确认时间后,可信领导者序列以高概率保持永久,从而确保交易最终性。
  • 在t-可信区块链中确认的交易,在时间t后以至少1−ε的概率变为永久,其中所需确认时间的尺度为O(log(1/ε))。
  • 失败概率被界为 (m+1)μ exp(−η/27 ⋅ (k/(2α) − 2Δ)),在现实的网络与挖矿假设下,该界随确认深度k指数衰减。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。