9 ms·
Blockchains from a Distributed Computing Perspective [pdf]
- hyperion2010 9y agoThis seems an appropriate place to dump a thought I had while explaining the failures of all existing blockchains to a layman. 1) The problems with merkle trees & co. aren't the computational complexity, they are the space complexity. 1a) I can screw a current blockchain for all eternity by buying some token and then burning by keys. No one will ever know and they will have to keep track of those dead tokens until the heat death of the universe. 2) To solve space complexity you need a time tax. I propose 1 year, because it is convenient. 3) Any tokens (or fractions of a token) [0] that have not moved for more than a year (rolling) are returned to the common pot. (sort of a non-usage tax) This means that you can limit the space complexity of the whole chain as a function of the number of transactions per 'tax interval.' This, or maybe a similar approach could make the space complexity problem tractable for normal users. (The blithe acceptance of a 1-2Tb (or is it 3 now?) space requirement for the full blockchain by members of the community is so wildly out of touch with reality it is laughable) 0. There are a number of other 'units' that could be considered for tax-interval retirement, such as the wallet. The nice thing about taxing fractions of tokens is that the network can set the rate of the tax for investing over the long term based on the cost of a single transaction fee. The day before a fraction of a token would be dumped back into the pool the owner would just have to send the token to another wallet they control and pay the relevant transaction fee.
- icelancer 9y ago>>No one will ever know and they will have to keep track of those dead tokens until the heat death of the universe Why does it matter? If the address never moves the tokens... it's not really a lot of computation required.
- hyperion2010 9y agoThe point is that it requires space. We have to keep a record of the pointer.
- ulrikrasmussen 9y agoBut also any transactions pertaining to a "dead" account has to be verified whenever a new node boots the chain from scratch, in all future. The aggregated cost in power will, in time, surpass the initial cost of buying those coins.
- hyperion2010 9y agoI don't think so, though maybe I am misunderstanding. In the pathological case, imagine that a node has made no transactions at all for a year. The owner will have to go to look up how much money they have in the ledger before they can complete a transaction and discover they have no money. The space complexity of maintaining accounts is extremely small compared to maintaining transactions. All transactions that were associated with that account have been wiped from the public ledger. An archival ledger may keep a record of retired transactions, but the archival is not required to settle all accounts.
- ulrikrasmussen 9y agoBut that assumes that there is a trusted archival party that can verify account balances with authority. It may be technically possible to devise such a system, but as far as I understand, current decentralized blockchains require that you replay all previous transactions in order to learn the current state of the system.
- builditand 9y agoI'm new to blockchains so I'm sorry if this is stupid, maybe somebody can explain to me. Why do everybody needs to keep everything? The chain will be much smaller with just the id and the hash of the block. The payloads could be kept only by the interested parties and could be validated when needed with the chain.
- masterbit 9y agoLook at R3 Corda, transactions only shared and stored between parties involved, not the rest of the network.
- otoburb 9y agoDemurrage[1] money acts in a similar manner to encourage usage of a currency. Freicoin[2] implemented a demurrage fee mechanism of 5% per year, which would have the effect of eventually clearing out burned "dead" tokens, although the transaction history would still need to be stored until the end of time if you ran a full node that long. [1] https://en.wikipedia.org/wiki/Demurrage_(currency) https://en.wikipedia.org/wiki/Demurrage_(currency) [2] http://freico.in/about/ http://freico.in/about/
- hyperion2010 9y agoIf you have a complete account of the location of every fractional token at time t and a time t + d then we should be able to get rid of all logs for transactions with time < t + d. Is there something that prevents freicoin from doing this?
- deleted 9y ago[deleted]
- drdrey 9y ago> 1-2Tb What blockchain are you talking about? The Bitcoin blockchain is between 150 and 160 GB
- garmaine 9y agoMaybe he meant the UTXO set? Even that is off by a factor of 2 though.
- hyperion2010 9y agoYa sorry, a bit of an exaggeration there. I was recalling the size of the hard disks that some folks routinely kept around just for storing crypto blockchains. That said, the actual numbers are already out of the rang for storage on the vast majority of commercially available mobile devices which basically relegates cryptos to enthusiasts. If we could fit a year worth of transactions in to on the order of 10 gigs, or at least provide a constant size estimate per unit time as a function of the number of transactions then we might be able to get adoption.
- garmaine 9y agoWell a full node doesn't need to keep the full block chain around, just the UTXO set. But you're not going to be able to handle the bandwidth of a full block chain on a mobile device anyway (~1TB/mo).
- drdrey 9y agoThe blockchain grows at a constant linear rate, 1MB every 10 min or 144MB per day. Isn't that what you mean by "constant size estimate per unit time"?
- hyperion2010 9y agoThe number you describe is a constant "change in size." What I describe is a constant maximum worst case "size." Yours would be velocity, mine would be position, function, derivative, etc.
- mbrock 9y agoIt seems that in any real world blockchain, the space growth from actual transactions will be much larger than the space wasted on inactive wallets. And the notion of a secure financial system where if you don't move your money for a year your whole account is confiscated seems rather unappealing! One thing I really want to be able to do with a blockchain system is to put my wallet in cold storage—like, in a safe. I don't want some arbitrary rule that I need to mark my calendar every year to retrieve all my keys from cold storage and do a meaningless transaction!
- BraveNewCurency 9y ago> my calendar every year to retrieve all my keys from cold storage and do a meaningless transaction No, you don't need to retrieve your keys each year. Before storage, create N transactions moving all your coins to the next derived address. Sign all your transactions at once. Then put it in the safe. Store the transactions unencrypted on your computer. Send one each year. An attacker can't do anything with them except send them early (and force you to open your safe "sometime within the next year".)
- mbrock 9y agoThat's a good point, I didn't think about that. It does add some extra complexity though—like, if I do want to make a real transaction, I have to re-make the subsequent "keep-alive" transactions.
- GordonS 9y ago> One thing I really want to be able to do with a blockchain system is to put my wallet in cold storage—like, in a safe AFAIK, you can generate a paper wallet with any blockchain system. You're keys are rendered as a QR code and/or series of words (there is a name for this protocol that hopefully someone else can remember!), and you can then print and store it. Hardware wallets are also a thing for some systems, such as Bitcoin.
- mbrock 9y agoYeah, exactly. BIP39 is a common protocol for mnemonic keys also supporting subkeys. Hardware wallets like the Ledger Nano S have support for Bitcoin, Litecoin, and Ethereum, and they let you sign transactions without ever exposing your private keys to a general purpose computer. And yeah, you can always just keep your private key in any way you want—it's just an n-bit number.
- jasonzemos 9y agoYou may be interested in another paper[1] by Sompolinsky and Zohar describing block-trees rather than block-chains as a better structural approach. 1: https://eprint.iacr.org/2013/881.pdf https://eprint.iacr.org/2013/881.pdf
- matuszeg 9y agoThank you so much for this. I work in this field and have been telling my coworkers that a tree or graph would make more sense. This is what i needed. Thank you Do you know if anyone is working to implement something like this?
- f00_ 9y agohashgraph? https://hashgraph.com/ https://hashgraph.com/
- airstrike 9y agoPlease tell me this is how the internet will work in space.
- refset 9y agohttps://archain.org https://archain.org and their "Blockweave" construction sounds similar. Here is a recent talk from Code Mesh on what they're building: https://m.youtube.com/watch?v=YO3zyQvL3Yg https://m.youtube.com/watch?v=YO3zyQvL3Yg
- deleted 9y ago[deleted]
- DennisP 9y agoEthereum has something along these lines in production; it's how they get higher throughput and 15-second block times.
- deleted 9y ago[deleted]
- 9y ago
- kang 9y ago> a ledger is just an indelible, append-only log of transactions that take place between various parties. Readers should decide either the above statement is true and ethereum is not a blockchain by that definition[0] or blockchain is just an abstract buzzword. Technology wise, git is as powerful as a blockchain at being an append-only log without the most important ingredient - proof-of work. 2. There is a whole section on private blockchains Can you write one program using a private blockchain(for eg use ibm's hyperledger) that can't be written using git? Private blockchains, premined coins, colored tokens, assets etc all of them. 3. Regarding smart contracts, can you show me one use of turing completeness in a blockchain? If yes, ethereum is not turing complete practically cause gas. 4. How does one determine the gas price of an opcode in a network? How does ethereum do it? (i think only people understanding need of proof-of-work will understand this) 5. W.r.t the layers of OSI model, the need for smart contract is trivial. Show me one smart contract you can do 'in' a blockchain and I will tell you how to do it 'on' bitcoin. [0]https://ethereum.stackexchange.com/questions/9535/how-does-a-hard-fork-rollback-transactions https://ethereum.stackexchange.com/questions/9535/how-does-a...
- deleted 9y ago[deleted]
- yarrel 9y agoFrom [0] - "The transactions were not rolled back. The ETH amounts were just transferred automatically at 1,920,000 ." So a transaction did take place "between various parties", nothing previous to block 1920000 was changed, and the transfer is there for all to see.
- mannykannot 9y agoNo amount of wordplay and denial will alter the fact that the DAO fork was a de-facto rollback.
- DennisP 9y agoThere's a fundamental difference: a rollback reverses everybody's transactions, the DAO fork left unrelated transactions alone. Bitcoin had an actual five-hour rollback in its early days, when someone figured out an exploit and awarded themselves over a billion coins.
- 0xdada 9y agoSince it's a draft I'll point out two typos. In 4.1 "if fills" should be "it fills". In 4.3 "1000 to 10" should be "1000 to 100".
- kccqzy 9y agoI appreciate the effort in writing this readable paper, but I do find the analogies in the first few sections to be quite strained. Here's an example: > Alice decides it is time to blockchain her supply chain. She rents some cloud storage to hold the ledger, and installs internet-enabled temperature sensors in each frozen yogurt container. She is concerned that sensors are not always reliable (and that Bob may have tampered with some), so she wires the sensors to conduct a Byzantine fault-tolerant consensus protocol, which uses several rounds of voting to ensure that temperature readings cannot be distorted by a small number of of faulty or corrupted sensors. Now, since all frozen yogurt containers pass from Carol to Bob to Alice, doesn't Bob at some point in time have access to all the frozen yogurt containers and their temperature sensors? Then Bob can easily corrupt all of them, rendering this scheme useless. He can, for example, replace all of the sensors by malicious sensors that report wrong temperatures when they are in Bob's truck. Is there something I'm missing?
- wsxcde 9y agoThe assumption is that there are only "a small number of faulty or corrupted sensors."
- cdetrio 9y agoIts easy to go through a couple containers and find/replace a few sensors. But it would be a lot of work for Bob to go through every single yogurt container and corrupt all the sensors.
- dragandj 9y agoHmmm. But, how does a distributed blockchain help anyway?
- Donzo 9y agoAll of the censors vote on if they have been tampered with. They will leave a record of their votes on the blockchain as Bob tampers with them in real time.
- deleted 9y ago