blockchain.md 5.6 KB

Dynamic Proof of Stake

Blockchain

Blockchain $\mathbb{C}$ is a series of epochs: it's a tree of chains, $C_1$, $C_2$, $\dots$, $C_n$, the chain of the max length in $\mathbb{C}$ is the driving chain C.

Epoch

An epoch is a multiple of blocks. Some of those blocks might be empty due to the nature of the leader selection with VRF.

Genesis block

The first block in the epoch updates the stake for stakeholders, which influences the weighted random leader selection algorithm. For epoch j, the pair ($S_j,\eta_j$) is the genesis block's data for n stakeholders of the blockchain:

$$ S_j=((U_1,v_1^{vrf},v_1^{kes},v_1^{dsig},s_1),\dots,(U_n,v_n^{vrf},v_n^{kes},v_n^{dsig},s_n) $$ $$ \eta_j \leftarrow {0,1}^\lambda $$

Note that new stakeholders need to wait for the next epoch to be added to the genesis block

Block

A block $\textbf{B}$ is the building block of the blockchain.

Block $B{i}=(st, d, sl, B{\pi}, \rho, \sigma_s)$ created for slot i by a stakeholder, and slot i leader $U_s$:

$$\textbf{\textcolor{red}{st}}: \text{state of the prebvious block, Hash(head($\mathbb{C}$))}$$ $$\textbf{\textcolor{red}{d}}: \text{data held by the block}$$ $$\textbf{\textcolor{red}{sl}}: \text{slot id generated by the beacon}$$ $$\textbf{\textcolor{red}{$B_\pi$}}: \text{proof the stakeholder ${Us}$ is the owner, $B{\pi}=(U_s,y,\pi)$, y,$\pi$ are the output of the VRF}$$ $$\textbf{\textcolor{red}{$\rho$}}: \text{random seed for vrf, $\rho=(\rhoy,\rho{\pi})$}$$ $$\textbf{\textcolor{red}{$\sigma_{s}$}}: \text{owner signature on the block}$$

Leader selection

At the onset of each slot each a stakeholder needs to verify if it's the weighted random leader for this slot.

$$y < T_{i}$$ check if VRF output is less than some threshold

This statement might hold true for zero or more stakeholders, thus we might end up with multiple leaders for a slot, and other times no leader. Also note that no one would know who the leaderis , how many leaders are there for the slot, until you receive a signed block with a proof claiming to be a leader.

$$y = VRF(\eta||sid)$$

$\eta$ is random nonce generated from the blockchain, $\textbf{sid}$ is block id

$$\phi_{f} = 1 - (1-f)^{\alphai}$$ $$T{i} = 2^{l{VRF}}\phi{f}(\alpha_i^j)$$

Note that $\phi_f(1)=f$, $\textbf{f}$: the active slot coefficient is the probability that a party holding all the stake will be selected to be a leader. Stakeholder is selected as leader for slot j with probability $\phi_f(\alpha_i)$, $\alpha_i$ is $U_i$ stake.

Leaky non-resettable beacon

Built on top of globally synchronized clock, that leaks the nonce $\eta$ of the next epoch a head of time (thus called leaky), non-resettable in the sense that the random nonce is deterministic at slot s, while assuring security against adversary controlling some stakeholders.

For an epoch j, the nonce $\eta_j$ is calculated by hash function H, as:

$$\etaj = H(\eta{j-1}||j||v)$$

v is the concatentation of the value $\rho$ in all blocks from the beginning of epoch $e_{i-1}$ to the slot with timestamp up to $(j-2)R + \frac{16k}{1+\epsilon}$, note that k is a persistence security parameter, R is the epoch length in terms of slots.

Protocol

Appendix

This section gives further details about the structures that will be used by the protocol. Since Streamlet consensus protocol will be used at early stages of the Blockchain development, we created hybrid structures, to enable seemless transition from one protocol to the other, without the need of a blockchain forking.

Blockchain

Field Type Description
blocks Vec<Block> Series of blocks consisting the Blockchain

Block

Field Type Description
st String Previous block hash
sl u64 Slot UID, generated by the beacon
txs Vec<Transaction> Transactions payload
metadata Metadata Additional block information

Metadata

Field Type Description
om OuroborosMetadata Block information used by Ouroboros consensus
sm StreamletMetadata Block information used by Streamlet consensus
timestamp Timestamp Block creation timestamp

Ouroboros Metadata

Field Type Description
proof VRFOutput Proof the stakeholder is the block owner
r Seed Random seed for the VRF
s Signature Block owner signature

Streamlet Metadata

Field Type Description
votes Vec<Vote> Epoch votes for the block
notarized bool Block notarization flag
finalized bool Block finalization flag