State Machine Replication under Changing Network Conditions

State Machine Replication under Changing Network Conditions
复制标题

DOI:
10.1007/978-3-031-22963-3_23
复制
发表时间:
2022
期刊:
--
影响因子:
--
通讯作者:
A. Alexandru;Erica Blum;Jonathan Katz;J. Loss
A. Alexandru;Erica Blum;Jonathan Katz;J. Loss
中科院分区:
其他
文献类型:
--
作者:
A. Alexandru;Erica Blum;Jonathan Katz;J. Loss

文献摘要

相似文献

状态机复制(SMR)协议通常是为同步或异步网络设计的,在后一种情况下具有较低的损坏阈值。最近的网络不可知协议在同步或异步网络中运行时都是安全的。我们提出了两个新的网络无关SMR协议的构造,在对抗模型和通信复杂性方面对现有协议进行了改进:一个自适应安全协议,具有最优的破坏阈值和每事务的二次摊销通信复杂度;一个静态安全协议,具有接近最优的破坏阈值和线性化的每个事务的通信复杂性;我们进一步研究了SMR协议运行在一个可以在同步和异步之间任意改变的网络中;各方可以是无破坏的(如在主动模型中),只要保持适当的破坏阈值,协议就应该保持安全。我们证明,如果双方之间没有某种形式的同步,纯粹的异步主动秘密共享是不可能的,从而排除了主动保护网络不可知的SMR协议的自然方法。在这种负面结果的激励下,我们考虑了一个模型,其中对手在协议持续时间内可以破坏的方的总数是有限的,并且在这种情况下,我们的SMR协议即使在任意变化的网络条件下也仍然是安全的。
Protocols for state machine replication (SMR) are typically designed for synchronous or asynchronous networks, with a lower corruption threshold in the latter case. Recentnetwork-agnosticprotocols are secure when run in either a synchronous or an asynchronous network. We propose two new constructions of network-agnostic SMR protocols that improve on existing protocols in terms of either the adversarial model or communication complexity:anadaptively secureprotocol with optimal corruption thresholds and quadratic amortized communication complexity per transaction;a statically secure protocol with near-optimal corruption thresholds andlinearamortized communication complexity per transaction.We further explore SMR protocols run in a network that may change between synchronous and asynchronous arbitrarily often; parties can be uncorrupted (as in the proactive model), and the protocol should remain secure as long as the appropriate corruption thresholds are maintained. We show that purely asynchronous proactive secret sharing is impossible without some form of synchronization between the parties, ruling out a natural approach to proactively secure network-agnostic SMR protocols. Motivated by this negative result, we consider a model where the adversary is limited in the total number of parties it can corrupt over the duration of the protocol and show, in this setting, that our SMR protocols remain secure even under arbitrarily changing network conditions.