AI 中文总结
本文提出首个结合参与方腐败与信道攻击的敌手模型,确立拜占庭协议在并行与并发组合下的紧致安全阈值,并设计通用及基于纠删码的编译器,在满足条件时实现安全且通信高效的可扩展组合。
AI 中文摘要
拜占庭协议(BA)是分布式系统中的基础构建模块,多实例执行下BA协议的安全性分析日益受到关注。然而,现有的大多数敌手模型仅关注参与方腐败,而忽视了网络中通信信道的对抗性操纵所构成的重大威胁。通过信道攻击,消息可以在多次执行之间被重排序,从而导致协议安全保证被违反。在这项工作中,我们提出了首个结合参与方腐败与信道攻击的敌手模型。基于该模型,我们为并行与并发组合下的拜占庭协议确立了新的安全阈值,并辅以互补的不可能性与可能性结果,两者相互匹配以形成紧致界限。对于不可能性结果,我们证明即使经过认证的拜占庭协议在 $n \leq 3t$ 或 $n \leq 2c + 2t + 1$ 时也无法在并行组合下保持安全,其中 $t$ 和 $c$ 分别表示被腐败的参与方和通信信道的数量,$n$ 为参与方数量。对于可能性结果,我们证明当 $n > \max\{3t, 2c+2t+1\}$ 时,存在在并行与并发组合下安全的未认证拜占庭协议。我们首先提供通用的黑盒编译器,可将任何单实例安全的BA协议转换为在并行与并发执行下安全的协议,且无需额外的安全假设。为优化性能,我们进一步利用纠删码设计了改进型编译器。这些改进版本显著降低了通信开销,特别是对于长消息,与原始协议相比实现了常数倍乘性开销,从而达到了相同的渐近通信复杂度。
英文摘要
Byzantine agreement (BA) is a foundational building block in distributed systems, and the security analysis of BA protocols under multi-instance executions has attracted increasing attention. However, most existing adversary models focus solely on party corruption and neglect important threats posed by adversarial manipulations of communication channels in the network. Through channel attacks, messages can be reordered across multiple executions and lead to violations of the protocol's security guarantees, In this work, we present the first adversary model that combines party corruption and channel attacks. Based on this model, we establish new security thresholds for Byzantine agreement under parallel and concurrent compositions, supported by complementary impossibility and possibility results that match each other to form a tight bound. For the impossibility result, we show that even authenticated Byzantine agreement protocols cannot be secure under parallel composition when $n \leq 3t$ or $n \leq 2c + 2t + 1$, where $t$ and $c$ denote the number of corrupted parties and communication channels, respectively, and $n$ is the number of parties. For the possibility result, we prove the existence of secure protocols for unauthenticated Byzantine agreement under parallel and concurrent composition, when $n > \max\{3t, 2c+2t+1\}$. We first provide general black-box compilers that transform any single-instance secure BA protocol into one that is secure under parallel and concurrent executions without additional security assumptions. To optimize performance, we further design refined compilers using erasure-correcting codes. These refined versions significantly reduce communication overhead, particularly for long messages, where they achieve a constant multiplicative overhead compared with the original protocol, thus achieving the same asymptotic communication complexity.
CommentsA preliminary version of this work appeared in the Proceedings of the 7th international conference on Advances in Financial Technologies (AFT'25)