Ouroboros: A Provably Secure Proof-of-Stake Blockchain Protocol

被引:889
作者
Kiayias, Aggelos [1 ,2 ]
Russell, Alexander [3 ]
David, Bernardo [4 ,5 ]
Oliynykov, Roman [6 ]
机构
[1] Univ Edinburgh, Edinburgh, Midlothian, Scotland
[2] IOHK, Edinburgh, Midlothian, Scotland
[3] Univ Connecticut, Storrs, CT USA
[4] Tokyo Inst Technol, Tokyo, Japan
[5] IOHK, Tokyo, Japan
[6] IOHK, Kiev, Ukraine
来源
ADVANCES IN CRYPTOLOGY - CRYPTO 2017, PT I | 2017年 / 10401卷
基金
欧盟地平线“2020”; 欧洲研究理事会; 美国国家科学基金会;
关键词
D O I
10.1007/978-3-319-63688-7_12
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
We present "Ouroboros", the first blockchain protocol based on proof of stake with rigorous security guarantees. We establish security properties for the protocol comparable to those achieved by the bitcoin blockchain protocol. As the protocol provides a "proof of stake" blockchain discipline, it offers qualitative efficiency advantages over blockchains based on proof of physical resources (e.g., proof of work). We also present a novel reward mechanism for incentivizing Proof of Stake protocols and we prove that, given this mechanism, honest behavior is an approximate Nash equilibrium, thus neutralizing attacks such as selfish mining.
引用
收藏
页码:357 / 388
页数:32
相关论文
共 26 条
[1]  
[Anonymous], 2014, CORR
[2]  
[Anonymous], 2016, 2016035 CRYPT EPRINT
[3]  
[Anonymous], 2017241 CRYPT EPRINT
[4]  
Ateniese Giuseppe, 2014, Security and Cryptography for Networks. 9th International Conference (SCN 2014). Proceedings: LNCS 8642, P538, DOI 10.1007/978-3-319-10879-7_31
[5]   Security Against Covert Adversaries: Efficient Protocols for Realistic Adversaries [J].
Aumann, Yonatan ;
Lindell, Yehuda .
JOURNAL OF CRYPTOLOGY, 2010, 23 (02) :281-343
[6]  
Bentov Iddo, 2014, ACM SIGMETRICS Performance Evaluation Review, V42, P34
[7]  
Bentov I., 2016, IACR Cryptol. ePrint Arch., P919
[8]  
Bentov I, 2016, IACR CRYPTOLOGY EPRI, V2016, P918
[9]   Secure Proxy Signature Schemes for Delegation of Signing Rights [J].
Boldyreva, Alexandra ;
Palacio, Adriana ;
Warinschi, Bogdan .
JOURNAL OF CRYPTOLOGY, 2012, 25 (01) :57-115
[10]  
Danezis G., 2016, 23 ANN NETW DISTR SY