On the (in)security of Proofs-of-Space based Longest-Chain Blockchains

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Baig, Mirza Ahad, Pietrzak, Krzysztof
Format: Preprint
Veröffentlicht: 2025
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866909617885282304
author Baig, Mirza Ahad
Pietrzak, Krzysztof
author_facet Baig, Mirza Ahad
Pietrzak, Krzysztof
contents The Nakamoto consensus protocol underlying the Bitcoin blockchain uses proof of work as a voting mechanism. Honest miners who contribute hashing power towards securing the chain try to extend the longest chain they are aware of. Despite its simplicity, Nakamoto consensus achieves meaningful security guarantees assuming that at any point in time, a majority of the hashing power is controlled by honest parties. This also holds under ``resource variability'', i.e., if the total hashing power varies greatly over time. Proofs of space (PoSpace) have been suggested as a more sustainable replacement for proofs of work. Unfortunately, no construction of a ``longest-chain'' blockchain based on PoSpace, that is secure under dynamic availability, is known. In this work, we prove that without additional assumptions no such protocol exists. We exactly quantify this impossibility result by proving a bound on the length of the fork required for double spending as a function of the adversarial capabilities. This bound holds for any chain selection rule, and we also show a chain selection rule (albeit a very strange one) that almost matches this bound. Concretely, we consider a security game in which the honest parties at any point control $ϕ>1$ times more space than the adversary. The adversary can change the honest space by a factor $1\pm \varepsilon$ with every block (dynamic availability), and ``replotting'' the space takes as much time as $ρ$ blocks. We prove that no matter what chain selection rule is used, in this game the adversary can create a fork of length $ϕ^2\cdot ρ/ \varepsilon$ that will be picked as the winner by the chain selection rule. We also provide an upper bound that matches the lower bound up to a factor $ϕ$. There exists a chain selection rule which in the above game requires forks of length at least $ϕ\cdot ρ/ \varepsilon$.
format Preprint
id arxiv_https___arxiv_org_abs_2505_14891
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle On the (in)security of Proofs-of-Space based Longest-Chain Blockchains
Baig, Mirza Ahad
Pietrzak, Krzysztof
Cryptography and Security
The Nakamoto consensus protocol underlying the Bitcoin blockchain uses proof of work as a voting mechanism. Honest miners who contribute hashing power towards securing the chain try to extend the longest chain they are aware of. Despite its simplicity, Nakamoto consensus achieves meaningful security guarantees assuming that at any point in time, a majority of the hashing power is controlled by honest parties. This also holds under ``resource variability'', i.e., if the total hashing power varies greatly over time. Proofs of space (PoSpace) have been suggested as a more sustainable replacement for proofs of work. Unfortunately, no construction of a ``longest-chain'' blockchain based on PoSpace, that is secure under dynamic availability, is known. In this work, we prove that without additional assumptions no such protocol exists. We exactly quantify this impossibility result by proving a bound on the length of the fork required for double spending as a function of the adversarial capabilities. This bound holds for any chain selection rule, and we also show a chain selection rule (albeit a very strange one) that almost matches this bound. Concretely, we consider a security game in which the honest parties at any point control $ϕ>1$ times more space than the adversary. The adversary can change the honest space by a factor $1\pm \varepsilon$ with every block (dynamic availability), and ``replotting'' the space takes as much time as $ρ$ blocks. We prove that no matter what chain selection rule is used, in this game the adversary can create a fork of length $ϕ^2\cdot ρ/ \varepsilon$ that will be picked as the winner by the chain selection rule. We also provide an upper bound that matches the lower bound up to a factor $ϕ$. There exists a chain selection rule which in the above game requires forks of length at least $ϕ\cdot ρ/ \varepsilon$.
title On the (in)security of Proofs-of-Space based Longest-Chain Blockchains
topic Cryptography and Security
url https://arxiv.org/abs/2505.14891