Nakamoto consensus (NC) powers major proof-of-work (PoW) and proof-of-stake (PoS) blockchains such as Bitcoin or Cardano. Given a network of nodes with certain communication and computation capacities, against what fraction of adversarial power (the resilience) is Nakamoto consensus secure for a given block production rate? Prior security analyses of NC used a bounded delay model which does not capture network congestion resulting from high block production rates, bursty release of adversarial blocks, and in PoS, spamming due to equivocations. For PoW, we find a new attack, called teasing attack, that exploits congestion to increase the time taken to download and verify blocks, thereby succeeding at lower adversarial power than the private attack which was deemed to be the worst-case attack in prior analysis. By adopting a bounded bandwidth model to capture congestion, and through an improved analysis method, we identify the resilience of PoW NC for a given block production rate. In PoS, we augment our attack with equivocations to further increase congestion, making the vanilla PoS NC protocol insecure against any adversarial power except at very low block production rates. To counter equivocation spamming in PoS, we present a new NC-style protocol Sanitizing PoS (SaPoS) which achieves the same resilience as PoW NC.
翻译:中本聪共识(NC)支撑了比特币和卡尔达诺等主要工作量证明(PoW)及权益证明(PoS)区块链。考虑具备特定通信与计算能力的节点网络,在给定区块生成速率下,中本聪共识能抵御多大比例的敌手算力(即弹性)?此前对NC的安全性分析采用有界延迟模型,该模型无法捕捉因高区块生成速率、突发性敌手区块发布以及PoS中由欺骗行为引发的网络拥塞。针对PoW,我们发现一种名为“戏弄攻击”的新攻击方式,它通过利用拥塞来延长区块下载和验证时间,从而在低于此前分析视为最坏情况的私密攻击所需的敌手算力下得逞。通过采用有界带宽模型来刻画拥塞,并改进分析方法,我们确定了给定区块生成速率下PoW NC的弹性。针对PoS,我们在攻击中引入欺骗行为以进一步加剧拥塞,这使得标准PoS NC协议在除极低区块生成速率外的任何敌手算力下均不安全。为应对PoS中的欺骗垃圾攻击,我们提出了一种新型NC风格协议——“清理型PoS(SaPoS)”,其实现了与PoW NC相同的弹性。