Close latency-security trade-off for the Nakamoto consensus

Close latency-security trade-off for the Nakamoto consensus
复制标题

中本聪共识的紧密延迟与安全权衡

DOI:
10.1145/3479722.3480992
复制
发表时间:
2020
期刊:
Proceedings of the 3rd ACM Conference on Advances in Financial Technologies
影响因子:
--
通讯作者:
Ling Ren
Ling Ren
中科院分区:
--
文献类型:
--
作者:
Jing Li;Dongning Guo;Ling Ren

文献摘要

参考文献

被引文献

相似文献

比特币是中本聪在2008年发明的一种点对点电子现金系统。虽然它吸引了很多研究兴趣,但其确切的延迟和安全属性仍然是开放的。现有的分析提供了安全性和延迟(或确认时间)保证,这些保证对于实际使用来说太松散了。事实上,由于众所周知的私人挖矿攻击,最著名的上限比下限大几个数量级。本文描述了区块链的连续时间模型,并进行了严格的分析,得出了延迟-安全权衡的接近上限和下限。例如,当攻击者控制了总挖矿能力的10%,并且区块传播延迟在10秒以内时,一个比特币区块在4小时后被确认的错误概率小于10-3,在10小时后被确认的错误概率小于10-9。这些确认时间离相应的下界大约有两个小时的距离。为了建立如此紧密的边界,区块链安全问题被简化为泊松对抗性挖掘过程和由特定种类的诚实区块形成的更新过程之间的竞赛。以封闭形式导出了相关更新时间的矩生成函数。然后将分析中的一般公式应用于研究几种知名的最长链工作量证明加密货币的延迟-安全权衡。还提供了关于如何为不同目的设置参数的指导。
Bitcoin is a peer-to-peer electronic cash system invented by Nakamoto in 2008. While it has attracted much research interest, its exact latency and security properties remain open. Existing analyses provide security and latency (or confirmation time) guarantees that are too loose for practical use. In fact the best known upper bounds are several orders of magnitude larger than a lower bound due to a well-known private-mining attack. This paper describes a continuous-time model for blockchains and develops a rigorous analysis that yields close upper and lower bounds for the latency-security trade-off. For example, when the adversary controls 10% of the total mining power and the block propagation delays are within 10 seconds, a Bitcoin block is secured with less than 10-3 error probability if it is confirmed after four hours, or with less than 10-9 error probability if confirmed after ten hours. These confirmation times are about two hours away from their corresponding lower bounds. To establish such close bounds, the blockchain security question is reduced to a race between the Poisson adversarial mining process and a renewal process formed by a certain species of honest blocks. The moment generation functions of relevant renewal times are derived in closed form. The general formulas from the analysis are then applied to study the latency-security trade-off of several well-known proof-of-work longest-chain cryptocurrencies. Guidance is also provided on how to set parameters for different purposes.
一切都是一场竞赛,中本聪总是获胜
DOI: 10.1145/3372297.3417290
发表时间: 2020
期刊: CCS '20: Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security
影响因子: --
作者:
Dembo, Amir;Kannan, Sreeram;Tas, Ertem Nusret;Tse, David;Viswanath, Pramod;Wang, Xuechao;Zeitouni, Ofer
通讯作者: Zeitouni, Ofer