Longest-chain Protocol Meets BFT Finality gadgets,

Published  . 0 views
↓ Download
Longest-chain Protocol Meets BFT Finality gadgets,
1 / 1
Longest-chain Protocol Meets BFT Finality gadgets, - slide 1 of 21 Longest-chain Protocol Meets BFT Finality gadgets, - slide 2 of 21 Longest-chain Protocol Meets BFT Finality gadgets, - slide 3 of 21 Longest-chain Protocol Meets BFT Finality gadgets, - slide 4 of 21 Longest-chain Protocol Meets BFT Finality gadgets, - slide 5 of 21 Longest-chain Protocol Meets BFT Finality gadgets, - slide 6 of 21 Longest-chain Protocol Meets BFT Finality gadgets, - slide 7 of 21 Longest-chain Protocol Meets BFT Finality gadgets, - slide 8 of 21 Longest-chain Protocol Meets BFT Finality gadgets, - slide 9 of 21 Longest-chain Protocol Meets BFT Finality gadgets, - slide 10 of 21 Longest-chain Protocol Meets BFT Finality gadgets, - slide 11 of 21 Longest-chain Protocol Meets BFT Finality gadgets, - slide 12 of 21 Longest-chain Protocol Meets BFT Finality gadgets, - slide 13 of 21 Longest-chain Protocol Meets BFT Finality gadgets, - slide 14 of 21 Longest-chain Protocol Meets BFT Finality gadgets, - slide 15 of 21 Longest-chain Protocol Meets BFT Finality gadgets, - slide 16 of 21 Longest-chain Protocol Meets BFT Finality gadgets, - slide 17 of 21 Longest-chain Protocol Meets BFT Finality gadgets, - slide 18 of 21 Longest-chain Protocol Meets BFT Finality gadgets, - slide 19 of 21 Longest-chain Protocol Meets BFT Finality gadgets, - slide 20 of 21 Longest-chain Protocol Meets BFT Finality gadgets, - slide 21 of 21
Description: Longest-chain Protocol Meets BFT Finality gadgets, CAP Theorem and More! ECE 598 PV: Principles of Blockchains Prof. Pramod Viswanath Lecture 16: March 23, 2021 Suryanarayana Sankagiri The Story So Far Two families Blockchain Protocols

Related Topics

Download Presentation

"Longest-chain Protocol Meets BFT Finality gadgets," is the property of its rightful owner. Permission is granted to download and print the materials on this website for personal, non-commercial use only, and to display it on your personal computer provided you do not modify the materials and that you retain all copyright notices contained in the materials. By downloading content from our website, you accept the terms of this agreement.

Presentation Transcript

slide1. Longest-chain Protocol Meets BFT Finality gadgets, CAP Theorem and More! ECE 598 PV: Principles of Blockchains
Prof. Pramod Viswanath
Lecture 16: March 23, 2021
Suryanarayana Sankagiri<br>
slide2. The Story So Far Two families Blockchain Protocols Safety: all parties have the same ledger Liveness: the ledger keeps growing Longest-chain (Bitcoin): BFT-style (HotStuff): permissionless permissioned unsafe in asynchrony safe under asynchrony TRADEOFFS!<br>
slide3. Best of Both Worlds? Tradeoffs!<br>
slide4. Today’s Lecture Incorporating BFT into Longest-Chain Protocols New Protocols Impossibility Results Broader Perspective of Distributed Systems Hybrid Consensus Finality Gadgets CAP Theorem<br>
slide5. Hybrid Consensus Longest-chain protocol is slow to confirm txns

Can we have fast confirmation in a PoW permissionless system?

Idea: Bring HotStuff to PoW for fast confirmation!

Need decentralized, fair committee election<br>
slide6. Hybrid Consensus Longest-chain protocol can serve as committee election mechanism
A fool-proof, fair, decentralized method! pk1 pk2 pk3 pk5 pk6 pk7 pk9 pk10 pk8 pk4 committee public key<br>
slide7. Hybrid Consensus Can’t stop mining!
Adversary can upend longest chain if honest miners stop
Committee overturned  insecure protocol
Chain quality matters!
1/3 mining adversary  ½ adversary in committee. Cannot tolerate!
Need Fruitchains instead of Nakamoto consensus for ideal chain quality
Susceptible to adaptive corruption
Committee is all-powerful; block proposers are no longer unpredictable!
Committee rotation protects against slow adaptive corruption Some finer details<br>
slide8. Hybrid Consensus What it achieves Where it fails asynchrony offline users It achieves low confirmation latency in a PoW (permissionless) setting Needed for responsiveness Finality gadgets overcome these drawbacks loses safety stalls<br>
slide9. Towards Finality Gadgets A protocol that remains live and safe, despite variable participation
PoW longest chain has this property
longest chain should work, even if BFT component is turned on/off arbitrarily

A protocol that remains safe, despite asynchrony
BFT protocol has this property
longest chain should work What we desire<br>
slide10. Finality Gadget Two-layer design

Longest chain protocol produces and confirms blocks
Works with variable participation
k-deep rule remains viable

BFT protocol independently confirms blocks
Confirms the same set of blocks as produced by PoW!
Switches on or off based on participation level Layer-one: Proof-of-Work Longest Chain Layer-two: Committee-based BFT protocol<br>
slide11. Finality Gadget – Checkpoints fixed committee executes layer-two BFT protocol
call them checkpointers blocks produced by PoW mining treat a checkpointed block as final block checkpointed by votes from BFT protocol<br>
slide12. Rules of Checkpointing Checkpoint blocks on the same chain

Checkpoint blocks on the longest chain

Checkpoint blocks close to the tip If not, safety violation! If not, liveness violation! If not, checkpointing not of much use<br>
slide13. More about Checkpointing Input values
In theory: entire chain leading up to prospective checkpoint block
In practice: hash of prospective checkpoint block

Validity conditions
Classical: if all honest users have same input, that input is finalized
For gadgets: if all honest users have chains with a k-common prefix, then finalized block is on common prefix Checkpointing protocol is a consensus engine<br>
slide14. Two-layer design does not work! Players must follow longest checkpointed chain rule Extend the longest chain below the latest checkpoint block resume synchrony period of asynchrony side-chain of blocks mined by adversary all miners mine here<br>
slide15. Finality Gadget What it achieves Safety under asynchrony

Faster confirmation? Requires confirming blocks at tip. [GRANDPA]

Safety and liveness under variable participation? Requires confirming k-deep blocks. [Checkpointed Longest Chain, Ebb-and-Flow] Open problem: achieve all three properties<br>
slide16. Finality Gadget – Two Confirmation Rules Adaptive rule (k-deep rule)
Remains live and safe under variable participation
Requires synchrony for liveness and safety

Finality-preserving rule (checkpoint-based rule)
Remains safe under all conditions
Is live only under synchrony and fixed participation Each rule generates its own ledger!<br>
slide17. One ledger offering adaptivity and finality?<br>
slide18. The Blockchain CAP Theorem No blockchain protocol can be adaptive and offer finality. [LR, 2020] A decentralized protocol cannot distinguish between offline users and network partition network partition protocol should stall offline users online users should continue<br>
slide19. CAP Theorem in Blockchains Availability-favoring Consistency-favoring Network partition Dynamic participation<br>
slide20. The CAP Theorem Theorem: A distributed system cannot be both Consistent and Available during network Partitions (Brewer 2000, Gilbert & Lynch 2002) Choose liveness or safety during network partition!<br>
slide21. Going around the CAP Theorem Best-effort availability
files in a data center

Typically uses a consensus protocol in the back-end

Best-effort consistency
Web content

No guarantee that the content retrieved is the latest<br>
slide22. Going around the CAP Theorem Consistency-critical applications may also need to have availability! Design principle: explicit partition mode, correct for consistency after partition heals<br>
slide23. Going around the CAP Theorem Data/Query partitioning
e-commerce example

Geographic/User Partitioning
Craigslist example

Blockchains
Dual-ledger design<br>
slide24. Other Implications of CAP theorem Lower bounds on

fault tolerance

latency<br>