Proof of Stake

Lecture



Proof-of-stake (PoS) (from the English “proof of stake”) — a security method in cryptocurrencies in which the probability that a participant will form the next block in the blockchain is proportional to the share of that participant’s holdings of the given cryptocurrency’s settlement units out of their total supply. This method is an alternative to the proof-of-work method (PoW), in which the probability of creating the next block is higher for the owner of more powerful hardware .

When this method is used, the block-formation algorithm does not depend on hardware power, but the block is more likely to be formed by the account with the larger current balance. For example, a participant holding 1% of the total supply will on average generate 1% of new blocks .

The idea of proof-of-stake was first proposed on the “Bitcointalk” forum in 2011 . The first implementation of the PoS protocol was presented in 2012 in the cryptocurrency PPCoin (now PeerCoin) .

In practice, mixed schemes for forming new blocks are common. For example, both the PoW and PoS methods are used in the cryptocurrencies Emercoin, NovaCoin and YaCoin. In the cryptocurrencies PeerCoin and Reddcoin, the PoW method is used for the initial distribution, while PoS is used to confirm transactions. In the Nxt and BlackCoin crypto-platforms, the PoS method is used at every stage.

The idea

The idea of proof-of-stake is to solve the problem of proof-of-work associated with heavy electricity consumption. Instead of participants’ computing power, what matters is the amount of cryptocurrency held in their account. Thus, instead of using a large amount of electricity to solve the PoW task, a PoS participant has a limited percentage of possible transaction checks. The limit corresponds to the amount of cryptocurrency held in the participant’s account .

Proof of importance

One of the variants of combined use of PoS technology is “Proof of Importance” (Proof-of-importance, PoI) — an algorithm used in the NEM cryptocurrency. Three components affect the probability of obtaining the right to form a block :

  1. the number of cryptocurrency units on the balance (for PoI, balances above a specified number of units are significant, e.g. no less than 10 thousand for NEM);
  2. account activity (number of transactions);
  3. the length of time the account has been present on the network.

As the balance grows, the influence of the parameters changes — as the number of cryptocurrency units on the balance increases, the influence of the 1st parameter increases, while the influence of the 2nd and 3rd parameters decreases (PoI works almost like PoS). The smaller the balance, the stronger the influence of the 2nd and 3rd parameters.

If the total volume of cryptocurrency emission is limited, then the minimum requirements for the 1st parameter form the maximum number of candidates for creating a block.

Advantages

  • There is no need to consume a large amount of electricity to protect the blockchain. For example, Bitcoin and Ethereum together spend more than 1 million dollars, in terms of electricity, per day within their consensus mechanisms .
  • Because there is no need to consume a large amount of energy, participants’ costs are reduced. Consequently, there is no need to increase the number of currency units to motivate participants .
  • Proof-of-stake makes it possible to use game-theoretic algorithms to effectively counter centralization .

Disadvantages

Arguments raising concerns :

  • Proof-of-stake gives additional motivation to accumulate funds in a few hands, which can lead to centralization of the network .
  • If a small group forms that concentrates sufficiently large funds in its hands, it will be able to impose its own conditions on the functioning of the cryptocurrency, with which the majority of minority holders who do not control forging will disagree .

Implementations

Peercoin

Peercoin— a system based on “pure” proof-of-stake, in the sense that PoW is used only for the initial distribution of the money supply .

Block generation

Participants in the Peercoin network are able to create a block based on the following condition :

Proof of Stake

Proof of Stake — the current time, which in this inequality limits hashing attempts and blocks the creation of the next block.

Proof of Stake — the result of the transaction.

Proof of Stake — the amount of unspent cryptocurrency of the transaction.

If the interested party has the key controlling Proof of Stake, it can generate a block using the key as a signature. In this case, the signature will serve as proof that the condition has been satisfied. For example, a participant holding 50 units of the cryptocurrency will create a new block with a probability 10 times greater than a participant holding 5 units.

Proof of Stake — the time elapsed since the transaction result Proof of Stake was included in a block. The probability of generating the next block immediately after the previous one is generated is very small, but it increases over time. This makes it possible to avoid an exponential distribution among payouts, raising the chances of participants who hold a small amount of cryptocurrency.

Proof of Stake — data from the previous block.

A participant holding a significant share of all the cryptocurrency in the system is able to generate a significant share of the blocks, since the probability of generating a block is proportional to the number of coins in their account. Therefore, from time to time, the interested party is able to generate chains of consecutive blocks .

Proof of Stake — a constant that is adjusted so that blocks are generated on average every 10 minutes.

CoA

CoA (chains of activity) is partly based on a core element of proof-of-activity, for example, on a lottery among active participants via the follow-the-satoshi procedure (a satoshi[10] — is the smallest unit of a cryptocurrency, for example, for bitcoin it equals 0.00000001 BTC).

Follow-the-satoshi[

The algorithm, which takes as input a satoshi coefficient between zero and the total number of satoshis in circulation. It then requests the block in which that satoshi was produced and tracks the transactions through which it passed until it finds the participant currently able to spend it. For example, if Alice has 6 satoshis and Bob has 2, the probability that Alice will be chosen as the next owner of some satoshi is 3 times higher than the probability of Bob being chosen .

Protocol parameters

  • The number of participants in the group that generates the next blocks Proof of Stake
  • The number of cryptocurrency units produced by this group Proof of Stake
  • The number of blocks generated by this group Proof of Stake
  • The function Proof of Stake
  • The minimum time between block generation Proof of Stake
  • The minimum stake Proof of Stake
  • The reward Proof of Stake: Proof of Stake

The process of creating CoA blocks makes up a blockchain consisting of groups of Proof of Stake consecutive blocks :

Proof of Stake

Protocol rules

The rules of the chains of activity protocol :

  1. Each new block is generated by one participant
  2. Each new block Proof of Stake is linked to the first bit Proof of Stake of the hash Proof of Stake
  3. The time interval between two blocks Proof of Stake and Proof of Stake must be no less than Proof of Stake. This means that if the next 4 blocks Proof of Stake are created by participants Proof of Stake, then the time interval between Proof of Stake and Proof of Stake must be no less than Proof of Stake
  4. After a group of Proof of Stake blocks Proof of Stake has been created, the network nodes form a Proof of Stake-bit initial state (seed) Proof of Stake, where Proof of Stake are the input values
  5. Next, the initial state (seed) Proof of Stake is used to obtain a sequence of identities used to determine the next Proof of Stake owners via the follow-the-satoshi algorithm.
  6. If the received satoshi Proof of Stake is not spent, the owner must provide an additional signature proving ownership of at least Proof of Stake units of the cryptocurrency, otherwise the participant will not be able to generate a new block.

Dense-CoA

Dense-CoA — an alternative implementation of CoA in which the participants generating the next blocks in the chain are not known in advance. In CoA, block generation is carried out by a single participant, whereas in Dense-CoA each block is created by a group of Proof of Stake participants:

Proof of Stake

Let Proof of Stake be an irreversible function. Let block Proof of Stake be linked to the initial state (seed) Proof of Stake formed by the group of Proof of Stake participants who generated this block. The participant Proof of Stake who decides which transactions will be included in the next block Proof of Stake is determined using the follow-the-satoshi algorithm with the hash function Proof of Stake as the input value. The remaining participants Proof of Stake are determined by the same algorithm, but Proof of Stake is used as the input value, where Proof of Stake.

Next, the chosen Proof of Stake take part in the block-generation procedure Proof of Stake, which consists of two stages:

  1. Each participant Proof of Stake, where Proof of Stake, chooses a random secret value from Proof of Stake
  2. Each participant signs the message Proof of Stake and publishes their signature Proof of Stake and preimage Proof of Stake to the network.

The participant Proof of Stake signs and publishes the block Proof of Stake to the network. The block contains: the transactions, the hash of the previous block Proof of Stake, a current timestamp, Proof of Stake preimages Proof of Stake and the aggregate of all signatures Proof of Stake. The participants use the function Proof of Stake to compute the images Proof of Stake. These images are used to obtain Proof of Stake. The validity of the signature Proof of Stake is then checked against the public keys Proof of Stake of the participants Proof of Stake.

Initial distribution of the cryptocurrency

For a cryptocurrency that does not use proof-of-work, there is one simple way to distribute money among participants — holding an ICO. However, in that case, it is implied that initially the entire currency is controlled by a single party, which complicates the process of decentralization. In many cryptosystems that use proof-of-stake, this problem is solved by using PoW for the initial generation of the cryptocurrency that will subsequently circulate in the system. Thus, the initial value of the cryptocurrency units is determined by the cost of producing them .

Criticism

Some authors argue that proof-of-stake is not an ideal option for a distributed consensus protocol[11].

Nothing at stake

The “nothing at stake” problem consists in the fact that, in the event of a consensus error, block generators lose nothing by voting for several branches of the chains. This means the consensus may never settle.[11]

Double spending

Since forming a chain requires few resources (unlike PoW systems), anyone can abuse the problem by attempting to double-spend funds “for free”[11].

Approaches to solving the problems[

In practice, projects have solved these problems in different ways:

  • The Slasher protocol, proposed by Ethereum, allows users to “punish” malicious actors who work on the end of more than one branch of the chain[12]. This approach assumes that you must sign the creation of a new branch of the chain twice, and that you can be punished if you create a fork without confirming your stake. However, the Slasher protocol was never adopted. Ethereum’s developers concluded that proofs of stake are non-trivial in this case[13]. Instead, Ethereum developed the Ethash protocol, which uses PoW[14].
  • Peercoin uses checkpoints signed with the developer’s private key. This makes it impossible to reorganize the blockchain earlier than the last checkpoint. In this case, the trade-off is that Peercoin’s developer is a central authority controlling the blockchain .
  • The Nxt protocol allows the last 720 blocks to be reorganized. Nevertheless, this only shifts the problem: a client can follow a fork of 721 blocks, regardless of whether it is the longest chain.[15].
  • The hybrid PoS and PoW algorithm of the Decred protocol. In this case, a proof of stake dependent on the timestamp of the PoW algorithm is used, which has been proposed to be called “Proof-of-Activity”, where the problem of proof is solved by the presence of a second proof mechanism — PoW[16].

See also

  • Legal status of cryptocurrencies
  • Alternative currency
  • Digital currency
  • Electronic money
  • Virtual currency
  • Token (cryptocurrency)
  • Stablecoin
  • Crypto-anarchism
  • Online digital currency exchange service
  • Blockchain
  • Double spending
  • Proof of work
  • Proof of stake
  • Proof of activity with limited trust
  • Mining
  • Forging
  • ICO
  • Cryptocurrency bubble
  • 2018 cryptocurrency crash
  • Smart contract
  • Hodl

Comments

To leave a comment

If you have any suggestion, idea, thanks or comment, feel free to write. We really value feedback and are glad to hear your opinion.
To reply

Lectures and tutorial on "Information security, Cryptographic ciphers"

Terms: Information security, Cryptographic ciphers