CheapBFT: resource-efficient byzantine fault tolerance

CheapBFT: resource-efficient byzantine fault tolerance
复制标题

DOI:
10.1145/2168836.2168866
复制
发表时间:
2012-04
期刊:
--
影响因子:
--
通讯作者:
R. Kapitza;J. Behl;C. Cachin;T. Distler;Simon Kuhnle;Seyed Vahid Mohammadi;Wolfgang Schröder-Preikschat;Klaus Stengel
R. Kapitza;J. Behl;C. Cachin;T. Distler;Simon Kuhnle;Seyed Vahid Mohammadi;Wolfgang Schröder-Preikschat;Klaus Stengel
中科院分区:
其他
文献类型:
--
作者:
R. Kapitza;J. Behl;C. Cachin;T. Distler;Simon Kuhnle;Seyed Vahid Mohammadi;Wolfgang Schröder-Preikschat;Klaus Stengel

文献摘要

被引文献

相似文献

拜占庭容错(BFT)系统没有得到广泛应用的主要原因之一在于它们的高资源消耗:3f+1副本只需要容忍f个错误。最近的工作已经能够通过依赖可信子系统将最小副本数量减少到2f+1,该子系统可以防止副本在不被检测到的情况下向其他副本发出冲突语句。尽管如此,这些系统的设计重点是故障处理,但在正常情况下的操作中,这些系统仍然使用大部分副本来完成看似冗余的工作。此外,可用的可信子系统在性能与安全性之间进行权衡;也就是说,它们要么实现高吞吐量,要么提供一个小的可信计算基础。本文介绍了CheapBFT,这是一个BFT系统,它首次允许在正常情况下除一个副本外的所有副本都出现故障。CheapBFT运行复合协议协议,并利用被动复制来节省资源;在没有错误的情况下,它只需要f+1个副本主动同意客户端请求并执行它们。在怀疑有错误行为的情况下,CheapBFT触发一个转换协议,该协议激活额外的被动副本,并使所有非故障副本重新进入一致状态。例如,这种方法允许系统安全地切换到另一个更有弹性的协议协议。CheapBFT依赖于基于fpga的可信子系统来对协议消息进行身份验证,该子系统提供高性能,并包含一个小型可信计算基础。
One of the main reasons why Byzantine fault-tolerant (BFT) systems are not widely used lies in their high resource consumption: 3f+1 replicas are necessary to tolerate only f faults. Recent works have been able to reduce the minimum number of replicas to 2f+1 by relying on a trusted subsystem that prevents a replica from making conflicting statements to other replicas without being detected. Nevertheless, having been designed with the focus on fault handling, these systems still employ a majority of replicas during normal-case operation for seemingly redundant work. Furthermore, the trusted subsystems available trade off performance for security; that is, they either achieve high throughput or they come with a small trusted computing base. This paper presents CheapBFT, a BFT system that, for the first time, tolerates that all but one of the replicas active in normal-case operation become faulty. CheapBFT runs a composite agreement protocol and exploits passive replication to save resources; in the absence of faults, it requires that only f+1 replicas actively agree on client requests and execute them. In case of suspected faulty behavior, CheapBFT triggers a transition protocol that activates f extra passive replicas and brings all non-faulty replicas into a consistent state again. This approach, for example, allows the system to safely switch to another, more resilient agreement protocol. CheapBFT relies on an FPGA-based trusted subsystem for the authentication of protocol messages that provides high performance and comprises a small trusted computing base.