Blockchain protocols typically aspire to run in the permissionless setting, in which nodes are owned and operated by a large number of diverse and unknown entities, with each node free to start or stop running the protocol at any time. This setting is more challenging than the traditional permissioned setting, in which the set of nodes that will be running the protocol is fixed and known at the time of protocol deployment. The goal of this paper is to provide a framework for reasoning about the rich design space of blockchain protocols and their capabilities and limitations in the permissionless setting. We propose a hierarchy of settings with different "degrees of permissionlessness", specified by the amount of knowledge that a protocol has about the current participants: These are the fully permissionless, dynamically available and quasi-permissionless settings. The paper also proves several results illustrating the utility of our analysis framework for reasoning about blockchain protocols in these settings. For example: (1) In the fully permissionless setting, even with synchronous communication and with severe restrictions on the total size of the Byzantine players, every deterministic protocol for Byzantine agreement has a non-terminating execution. (2) In the dynamically available and partially synchronous setting, no protocol can solve the Byzantine agreement problem with high probability, even if there are no Byzantine players at all. (3) In the quasi-permissionless and partially synchronous setting, by contrast, assuming a bound on the total size of the Byzantine players, there is a deterministic protocol solving state machine replication. (4) In the quasi-permissionless and synchronous setting, every proof-of-stake state machine replication protocol that uses only time-malleable cryptographic primitives is vulnerable to long-range attacks.
翻译:[翻译的摘要中文]
区块链协议通常旨在运行于无许可环境中,其中节点由大量多样且未知的实体拥有和操作,每个节点可随时自由启动或停止运行协议。该环境比传统的许可环境更具挑战性,后者在协议部署时已固定并明确知晓将运行协议的节点集。本文旨在提供一个框架,用于推演区块链协议在无许可环境中的丰富设计空间及其能力与局限性。我们提出一个按"无许可程度"划分的环境层次结构,由协议对当前参与者的认知量定义:即完全无许可、动态可用和准无许可环境。本文还证明了若干结果,说明了我们的分析框架在推演这些环境中的区块链协议时的实用性。例如:(1)在完全无许可环境中,即使采用同步通信并严格限制拜占庭玩家的总规模,每个用于拜占庭协议的确定性协议都存在无法终止的执行过程。(2)在动态可用和部分同步环境中,即使完全没有拜占庭玩家,任何协议都无法以高概率解决拜占庭协议问题。(3)相比之下,在准无许可和部分同步环境中,假设拜占庭玩家的总规模存在上界,存在一种确定性协议可解决状态机复制问题。(4)在准无许可和同步环境中,所有仅使用时间可塑密码原语的权益证明状态机复制协议都易遭受长程攻击。