发表机构
University of Illinois Urbana-Champaign; Institute for Advanced Study; a16z Crypto Research(伊利诺伊大学厄巴纳-香槟分校; 高等研究院; a16z 加密研究)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本研究基于PKI和VRF的最小假设,设计出支持完全波动式参与、处理节点去腐化的休眠共识协议,无需VDF或硬件假设,突破了现有PoS协议的稳健性局限。
AI 中文摘要
比特币基于工作量证明(PoW)的协议对参与者的要求极低:矿工可随时暂停工作,且提供了独特的悔改路径——恶意矿工只需在最长链上恢复挖矿即可恢复诚实状态,该协议仅要求诚实矿工在任意时刻掌握多数算力。类似的权益证明(PoS)协议通常通过Pass和Shi(2017)提出的休眠模型形式化,但在稳健性上不及前者。实际上,纯PKI模型下的休眠共识协议必须严格限制敌手参与度随时间的波动。Efron、Neu和Pitassi(2025)的近期工作通过引入外部敌手模型,使休眠模型支持完全波动式参与,但其协议依赖可验证延迟函数(VDF)这一强密码原语,假设敌手无法比诚实节点显著更快计算顺序工作,这与PoW类似。本研究中,我们在诚实多数、外部敌手及完全波动式参与的条件下,基于最小假设设计了一种休眠共识协议:仅需公钥基础设施(PKI)和可验证随机函数(VRF),不依赖VDF或硬件假设。我们的核心技术是分级唤醒机制,这一新颖原语使节点能就其他节点的唤醒状态形成一致观点。我们进一步扩展了协议以处理去腐化场景,即恶意节点恢复诚实状态,该扩展仅需对VRF输出的不可预测性提出温和附加假设以保障活性。
英文摘要
Bitcoin's proof-of-work (PoW)-based protocol is remarkable for how little it asks of its participants. Not only can miners take breaks from work whenever they please, but it is almost unique in offering a path of contrition: corrupt miners can reclaim honest status simply by resuming mining on the longest chain. The protocol only requires that honest miners hold the majority of computational power at any given time. Analogous proof-of-stake (PoS) protocols, usually formalized via the sleepy model of Pass and Shi (2017), have fallen short of matching this robustness. In fact, sleepy consensus protocols in the plain PKI model must heavily restrict fluctuations in adversarial participation over time. The recent work of Efron, Neu, and Pitassi (2025) enables fully fluctuating participation in the sleepy model by introducing the external adversary model. Their protocol, however, relies on verifiable delay functions (VDFs), a strong cryptographic primitive that somewhat resembles PoW, by assuming that the adversary cannot compute sequential work significantly faster than honest nodes. In this work, we design a sleepy consensus protocol for fully fluctuating participation with an external adversary under an honest majority, from minimal assumptions: a public key infrastructure (PKI) and a verifiable random function (VRF). In particular, we make no VDF or hardware assumptions. Our key technique is graded wakeness, a novel primitive that allows nodes to form consistent opinions on which other nodes are awake. We further extend our protocol to handle uncorruption, where corrupt nodes return to honesty. This extension requires only a mild additional assumption on the unpredictability of VRF outputs for liveness.
DOI:10.4230/LIPIcs.DISC.2026.44