Systems and methods for mining on proof-of-work blockchain network
Non-parallelizable mining techniques using sequential algorithms and multi-party computation address the challenges of resource inefficiency and centralization in blockchain networks, enhancing security and efficiency by ensuring unique challenges for each miner.
Patent Information
- Application Number
- JP2025037407
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2019-08-22
- Filing Date
- 2025-03-10
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2040-04-29
AI Technical Summary
Existing blockchain networks face challenges in maintaining consensus and security while reducing computational resource requirements, energy consumption, and preventing centralization of mining power, particularly in proof-of-work protocols.
Implementing non-parallelizable mining techniques using essentially sequential algorithms and multi-party computation to generate unique challenges for each miner, ensuring each miner solves a distinct puzzle through a committee of trusted nodes, thereby maintaining decentralization and security.
This approach enhances the security and efficiency of blockchain networks by ensuring that miners with faster hardware do not gain an unfair advantage, reducing energy consumption, and preventing centralization, while maintaining network consensus.
Smart Images

Figure 2025106255000001_ABST
Abstract
Description
Technical Field
[0001] The present disclosure generally relates to improved blockchain networks and related protocols, including methods and systems for improving the processing efficiency, reliability, security, and resource requirements of computational tasks executed within a blockchain network. In particular, it relates to blockchain networks implementing a proof-of-work protocol.
Background Art
[0002] As used herein, the term "blockchain" is used to include all forms of electronic computer-based distributed ledgers. These include consensus-based blockchain and transaction chain technologies, permissioned and un-permissioned ledgers, shared ledgers, public and private blockchains, and variations thereof. The most widely known application of blockchain technology is the Bitcoin ledger, although other blockchain implementations have also been proposed and developed. Although Bitcoin may be referred to herein for convenience and explanation, it should be noted that the present disclosure is not limited to use in the Bitcoin blockchain, and alternative blockchain implementations and protocols fall within the scope of the present disclosure. The term "user" may refer to a human or a processor-based resource herein. The term "Bitcoin" is used herein to include any version or variation derived from or based on the Bitcoin protocol.
[0003] A blockchain is a peer-to-peer electronic ledger implemented as a computer-based decentralized distributed system, which is composed of blocks, and further, the blocks are composed of transactions. Each transaction is a data structure that encodes the transfer of control rights of digital assets / resources among participants in the blockchain system, and includes at least one input and at least one output. Each block contains the hash of the previous block, and by chaining the blocks, a permanent and immutable record of all transactions written to the blockchain since the start of the blockchain is created. Transactions include a small program called a script embedded in the input and output that specifies how the output of the transaction can be accessed by whom. On the Bitcoin platform, these scripts are written using a stack-based scripting language.
[0004] For a transaction to be written to the blockchain, it must be "validated". Nodes ("miners") on the network check that each transaction is valid, and invalid transactions are rejected from the network. The software client installed on the nodes checks whether the unspent transaction complies with the protocol rules of the blockchain, and further performs this validation operation on the unspent transaction by executing the locking script and the corresponding unlocking script. When the execution results of the locking script and the unlocking script are evaluated as TRUE, the transaction is valid. Therefore, for a transaction to be written to the blockchain, it must be i) validated by the first node that receives the transaction - when the transaction is confirmed to be valid, the mining node relays it to other nodes in the network, ii) added to a new block constructed by the miner, and iii) mined, that is, added to the public ledger of past transactions.
[0005] Miners compete by performing resource-intensive work with the goal of first finding a solution to a calculation (puzzle), also known as a proof of work, "PoW" or "nonce", to build a new block. The difficulty of the puzzle can be adjusted over time to affect the rate at which new blocks are added to the blockchain. In Bitcoin, miners use the SHA256 hash algorithm to find a PoW that generates a hash value below the current difficulty set by the network protocol when hashed.
[0006] When a miner first finds a PoW for the current puzzle, that miner generates a new block, which is then broadcast to other miners on the network. The new block must contain a verifiable PoW if other miners are to accept the block as valid. Thus, mining provides a consensus mechanism that ensures that nodes on the network are synchronized and agree on the legitimate current state of the blockchain. Mining also protects against some types of potential network attacks and provides network security.
[0007] In the early days of Bitcoin, the computational requirements of mining were low enough that miners could handle them with a general-purpose computer equipped with a standard CPU. However, miners with more powerful computers have a competitive advantage over miners with less powerful computers. This incentive, combined with the historical increase in puzzle difficulty, has led to the widespread use of application-specific integrated circuit (ASIC) mining devices. Additionally, groups of ASIC devices can be linked to share the work involved in searching for PoW solutions. In such cases, different machines can be used to try different PoW nonces or ranges thereof. Thus, the mining algorithm is parallelizable across devices.
[0008] However, the more powerful a device is, the more expensive it is and the more energy it requires for operation and cooling. Also, some argue that hardware inequality promotes potential centralization of mining power within the network, which can bring about drawbacks or vulnerabilities. These concerns have led to increased attention on the development of "ASIC-resistant" mining solutions. However, the proposed solutions involve modifications to the PoW algorithm that change the collision-resistant SHA256 hash algorithm to a so-called "bandwidth-hard" function, and their success has been limited or controversial.
[0009] Therefore, among other things, there is a need to address the technical challenge of how to maintain the consensus mechanism and security provided by competing nodes on a blockchain network while reducing the required cost, energy usage, and computational resources and maintaining the advantages of a decentralized network.
[0010] The present disclosure addresses at least these technical concerns by providing aspects and embodiments comprising non-parallelizable mining (NPM) techniques using non-parallelizable consensus mechanisms, hardware and software arrangements, networking techniques and methods, and combinations thereof. The present disclosure may provide security for the state of the blockchain and may use essentially sequential algorithms to establish consensus.
[0011] Here, the term "sequential algorithm" is used to refer to an algorithm that must be executed in order from start to finish without other processes being executed in parallel. Examples are iterative numerical algorithms such as Newton's method (Lipson, John D. "Newton's method: a great algebraic algorithm.", Proceedings of the third ACM symposium on Symbolic and algebraic computation. ACM, 1976) and algorithms that can be mathematically expressed using recurrence relations.
[0012] In this specification, the term "essentially sequential" (or "non-parallelizable") algorithm is used to refer to a sequential algorithm that cannot be optimized using parallelizable routines / subroutines. It should be noted that this phrase is not strictly defined in the technical field, but the definition used in this specification is compatible with the intuitive usage of this term and the definitions existing in the literature (Greenlaw, Raymond. "A model classifying algorithms as inherently sequential with applications to graph searching.", Information and Computation 97.2 (1992): 133 - 149).
[0013] Also, note that the terms "computational challenge" and "challenge" are known in the technical field and are easily understood by those skilled in the art. Also, "challenge" can possibly be called "puzzle" in the technical field.
Prior Art Documents
Non-Patent Documents
[0014]
Non-Patent Document 1
[0015] Embodiments of the present disclosure provide computer-implemented protocols, methods, and systems for use with or on a blockchain network. The blockchain network implements a proof-of-work (PoW) blockchain protocol. This may be a blockchain protocol such as a version of the Bitcoin protocol, for example. However, other blockchain protocols and implementations are also within the scope of the present disclosure.
[0016] A method according to one or more embodiments may include generating a plurality of non-parallelizable challenges (or "puzzles") and assigning each one of the plurality of challenges to a respective miner on the network. Thus, preferably, the challenges are assigned such that each miner receives a different challenge from other miners. The assignment can be performed in any suitable manner, such as randomly selecting a node as the recipient for a given challenge from among the plurality of challenges, for example, although other assignment methods may be used. The challenges may be collision-resistant in that the probability that each challenge is unique among the plurality of challenges is high. Preferably, each miner then attempts to solve the assigned challenge. They may add data or input to the challenge such that the solution is unique among the solutions for the plurality of challenges. Means for Solving the Problems
[0017] In some embodiments, the generation of at least one of the multi-party computation challenges and / or further multi-party computation challenges includes calculating an output for an operation that uses a random or pseudo-random input. Additionally or alternatively, the generation of at least one of the multi-party computation challenges may include generating an RSA key pair.
[0018] Preferably, the mining node must use an essentially sequential (non-parallelizable) algorithm to find a solution to the assigned challenge. The essentially sequential algorithm may include at least one of recursive operations, modular exponentiation, and / or repeated squaring operations. Such an algorithm includes a set of predetermined steps that must be executed to obtain a result. Thus, embodiments of the present disclosure differ from the known PoW arrangement configuration that simply repeats the hash function until the miner reaches a solution without having to execute a predetermined set of steps or operations. The essentially sequential algorithm may require that the output of one operation be used as the input to a subsequent operation for a result (solution) to be generated.
[0019] Preferably, the challenge is generated by a committee of nodes, and a new set of challenges is generated for each block. There may be three or more nodes, each being a trusted entity. The nodes are independent of each other in that they cannot collude. Thus, a cycle or loop may be executed, and for each cycle, a plurality of additional (new) multi-party computation challenges are generated. Each new set of challenges is distributed to the miners at the start of each cycle. Thus, each miner may receive a new challenge at the start of each cycle. The cycle may be repeated such that a new challenge is assigned to the mining node. Preferably, the cycle is repeated for each new block to be added to the blockchain. Thus, when one of the mining nodes finds a solution to the challenge assigned in the previous cycle (i.e., provides a proof of work that enables mining the next block of transactions), a new set of challenges is generated and the cycle starts again.
[0020] Preferably, the generation of the plurality of multi-party computation challenges and / or the plurality of additional multi-party computation challenges is at least in part performed by a plurality of computer-based entities. This may be a subset of entities selected from a set of computer-based entities / a larger plurality of entities. In other words, a committee of nodes may be used to generate the challenges. According to one or more embodiments, the committee may be a subset of mining nodes on the network. In other embodiments, only some of the entities performing the challenge generation may be mining nodes, or none of them may be mining nodes. In some embodiments, the subset of computer-based entities is selected from a plurality of computer-based entities by using a process that is random or pseudo-random.
[0021] In one or more embodiments, the plurality of computer-based entities that generate the challenges may be reselected from a larger plurality of computer-based entities at a pre-determined time. This time may be based on (or affected by) the start of a cycle as described above.
[0022] Advantageously, embodiments of the present disclosure involve the assignment and / or distribution of an essentially sequential algorithm specific to each miner (rather than all miners attempting to solve the same common shared problem first). Thus, the present disclosure employs a completely different and opposite approach to mining compared to the prior art. This new approach provides a random distribution among the problems that miners are attempting to solve. This random distribution may be provided, for example, by a random output of a hash function where the input changes and is randomly generated. This means that it is difficult to predict and that for every new block, miners must find a solution to a newly assigned problem by repeating the steps of the sequential algorithm. The number of iterations required varies depending on the set of miners. This may mean that it is possible to more reliably determine which miner has acquired the right to mine the next block. In contrast, existing approaches mean that miners with faster clock speeds are advantaged. Thus, embodiments of the present disclosure represent a significant departure from conventional PoW blockchain mining approaches. Accordingly, an improved blockchain network and associated protocols are provided. The security of the blockchain network is maintained while efficiency is improved.
[0023] These and other aspects of the invention will be apparent from, and are elucidated with reference to, the embodiments described herein. Next, an embodiment of the present disclosure will be described by way of example only and with reference to the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0024]
Figure 1
Figure 2
[0025] Embodiments of the present disclosure utilize a mining puzzle that includes "trap door" calculations having the following characteristics. 1. It can be executed quickly when some secret information is known. 2. It requires configurable time to execute when the solver does not know any secret information.
[0026] As disclosed in Rivest, Ronald L., Adi Shamir, and David A. Wagner, "Time-lock Puzzles and timed-release crypto" (1996), hereinafter referred to as "Rivest et al.", a "trap door" could be the knowledge of an RSA private key or at least the ability to compute two independent values using the private key.
[0027] According to one or more preferred embodiments of the present disclosure, new puzzles are generated for each miner and each block via multi-party computation (MPC) among a committee of agents (nodes). In some embodiments, the committee includes a subset of eligible miners selected in a random or pseudo-random manner from a plurality of mining nodes on the blockchain network. The shares of the randomly generated RSA modulus are held by the committee members so that the secret key corresponding to the puzzle of a given block is not known to anyone (until the block is confirmed). In one or more embodiments, the committee and / or the secret key are changed after each block.
[0028] This is illustrated in Figure 1. In step 1, a committee of trusted independent nodes (e.g., miners) is selected. In step 2, each node in the committee generates a non-parallelizable computational challenge. This challenge must be solved using a non-parallelizable essentially sequential algorithm. In step 3, each miner receives the challenge. Thus, the miner tries to find a solution to his problem and executes this in step 4. When the miner finds a solution to his challenge, the cycle is repeated for each block mined on the blockchain.
[0029] The components of the arrangement according to the present disclosure include the following. 1. A committee of independent miners (see Gilad, Yossi et al., "Algorand: Scaling byzantine agreements for cryptocurrencies", Proceedings of the 26th Symposium on Operating Systems Principles. ACM, 2017). 2. Multi-party prime number computation (see Algesheimer, Joy, Camenisch, Jan and Shoup, Victor, Efficient Computation Modulo a Shared Secret with Application to the Generation of Shared Safe-Prime Products [Online], as well as Boneh, Dan, and Matthew Franklin, "Efficient generation of shared RSA keys", Annual International Cryptology Conference, Springer, Berlin, Heidelberg, 1997). 3. A hash function as a pseudo-random number generator 4. A time-lock puzzle based on exponentiation by squaring (see Rivest et al.) 5. MPC for validating solution blocks (see Algesheimer, Joy, Camenisch, Jan and Shoup, Victor, "Efficient Computation Modulo a Shared Secret with Application to the Generation of Shared Safe-Prime Products" [Online])
[0030] Mining algorithm Whether or not the mining algorithm is parallelizable, it should basically follow the following characteristics when used to obtain consensus on the state of the blockchain. Characteristic 1: The process of completing the mining algorithm by generating a valid proof C of computation should take a sufficiently long time. Characteristic 2: Given a candidate proof C of computation, it should be possible to verify that C is a valid proof of computation in a much shorter time than it takes to generate a valid C.
[0031] Generally, there are two broad ways to achieve the paradigm defined by these characteristics in a mining algorithm. They are the method of using a keyhole mining function and the method of using a time-based constraint that adheres to both of the above characteristics.
[0032] Keyhole mining function Generally, a good one-way keyhole function is difficult to compute but easy to verify when presented with some additional information, and thus can be mapped to a mining process with both Characteristics 1 and 2.
[0033] For example, in the Rabin cryptosystem, a public key n = p·q is generated from a private key (p, q), where p and q are both prime numbers. Computing a signature (S, U) on a message m is a one-way function, and its solution is given by the equation H(m||U)=S 2 mod n is the value S that satisfies
[0034] The algorithm for finding a valid S is a padlock algorithm or function, which is difficult to find S when (n, m, U) is given, but is easy when the factorization of n is known. The important point here is that before knowing the padlock, mining should be difficult and thus should take a time much longer than the latency of network messaging. However, once a solution is found, the padlock can be made public or jointly calculated, enabling fast verification of the solution using that padlock. Here, the padlock mining function, known as a time-lock puzzle, is used to construct a consensus algorithm for non-parallelizable mining on the blockchain network.
[0035] Time-lock puzzle A time-lock puzzle is a problem that takes a predetermined time to complete. F h (a, t)=L For some given input parameters a, t such that s is known and only then, F e (a, t, s)=L such that O(F e ) << O(F h ) and there exists another algorithm F e the algorithm F h is called a time-lock puzzle. The ability to precisely control the time it takes for a computer to complete the algorithm through the input parameters requires that F h is a function that is essentially sequential so that tasks cannot be shared between machines.
[0036] Exponentiation by squaring as an essentially sequential algorithm The core problem is to compute for specified values of a, t, and n. In this paper, we consider the problem when n is the product of two large prime numbers and t is chosen to set the desired level of puzzle difficulty. a is chosen to be a random number and can be player - specific. The most efficient way to solve the puzzle is to start with the value a and perform t consecutive squaring operations modulo n. That is, execute the following algorithm.
[0037]
Number
[0038] Algorithm 1
[0039] For i from 0 to t - 1 compute W(0)=a W(0)=a W(i + 1)=W(i)^2 mod n 2 mod n This gives W(t). Without knowing the factorization of n, there is no known way to perform this calculation more efficiently.
[0040] RSA Iterative Squaring Time - Lock Puzzle Rivest et al. introduced a time - lock puzzle based on iterative squaring. Consider the scenario where Alice creates a puzzle that Bob has to solve.
Number
[0041] This can be shown by using Fermat's test which gives
Number
[0042] The square-and-multiply operation is considered an "essentially sequential" process, i.e., there is no obvious way to parallelize it to any significant extent (see Rivest et al.). Thus, even if a large number of computers are used to solve the puzzle, there is no advantage compared to using a single computer, and the change in computation time is related to the speed of a single computer, which can be measured quite easily by the puzzle creator. In other words, the puzzle sent by Alice has a solvable time that is controllable regardless of Bob's computing resources.
[0043] Difficulty of prime factorization An important assumption in implementing a time-lock puzzle is that finding the prime factorization of n is a difficult problem that cannot be solved faster than the puzzle itself. To justify this assumption, consider the following reasons. The best algorithm for solving the integer factorization problem, the General Number Field Sieve (NFS), has a time complexity [Number] (See Buchmann, Johannes, Jiirgen Loho, and Jorg Zayer, "An implementation of the general number field sieve", Annual International Cryptology Conference. Springer, Berlin, Heidelberg, 1993).
[0044] For example, a 256-bit RSA key can be factored with approximately O(exp(46.6)) = 2.5x10E20 operations. Assuming that each operation of the NFS corresponds to one floating-point operation, cracking a 256-bit key would require approximately 250,000 seconds even on a 1 petaFLOPS (floating-point operations per second) computer.
[0045] In the context of a blockchain that is updated periodically, it is required that a different RSA modulus be created for each new block. Therefore, it is only required that it be infeasible to find the prime factorization of n in the same amount of time as the block generation time (e.g., a few minutes). By setting the RSA key to 512 bits, it can be safely assumed that factoring the RSA remainder within the mining cycle is infeasible.
[0046] Verifiable Random Function A verifiable random function (VRF) is a triple of algorithms (see https: / / medium.com / algorand / algorand-releases-first-open-source-code-of-verifiable-random-function-93c2960abd61). · Keygen(r)->(VK,SK) - On a random input seed r, the key generation algorithm generates a pair of a verification key VK and a secret key SK. · Evaluate(SK,m)->(Y,ρ) - The evaluation algorithm takes as input the secret key SK and the message m and generates a pseudorandom output string Y and a proof ρ. · Verify(VK,m,Y,ρ)->0 / 1 - The verification algorithm takes as input the verification key VK, the message m, the output Y, and the proof ρ. This outputs 1 if and only if it verifies that Y is the output generated by the evaluation algorithm on the input SK and m.
[0047] It is important that the output Y is unique, i.e., impossible to find without knowing the secret key. Below, a detailed implementation of subcommittee selection using a verifiable random function is provided.
[0048] Unique and Secure Subcommittee Selection According to some embodiments of the present disclosure, in subcommittee selection, ECDSA signatures are used to replicate a verifiable random function. This process can be classified into three stages: setup, pseudo-random value generation, and subcommittee selection. Miners M1,...M N Consider a network of (N>3).
[0049] Setup Step 1: Each miner has a public key PK1, PK2,..., PK N . Step 2: Each miner selects a unique seed S1,..., S N . These values are propagated and fixed for each public key.
[0050] Pseudo-random value generation Step 3: For each new block, the miner creates a message. The message is simply the hash of the miner's seed value concatenated with the previous block header. That is, for the miner PK k mining block B i , the miner's message is m i,k =H(S i ||X k-1 ) . Where X k-1 is the hash of the previous block header, i.e., X k-1 =H(BH k-1 ). Step 4: The miner generates an ECDSA signature on its message, i.e., ECDSA(sk i ,m i,k )->(s i ,r i ) .
[0051] The miner records the time elapsed from when the timestamp for block B k-1 was generated until the signature was generated. The difference is
Mathematics
[0052] Step 5: Each miner Mi propagates its proof
Mathematics
[0053] Subcommittee Selection Step 6: After receiving the proof, each network node checks the following. 1) The message m i,k is valid for the miner PK i . 2) The signature (s i , r i , r i ) for the message m i is valid for the PK 3) The difference between T i e and the time when the proof message was received is less than the network latency T L , that is, when the message was received, miner j
Mathematics
Mathematics
[0054] Step 7: Subcommittee members are selected by the following process. 1) The value for a miner having the public key PK i is
Number
[0055] V i is the output of a VRF having components s i and
Number
[0056] For the miners to agree on the subcommittee candidate list, each proof needs to be propagated across the network. Assuming low latency and high connectivity, the network should be able to quickly establish a global list of miner values and thus establish the subcommittee. Further, the network only accepts one proof message (the first one sent) per miner, thus preventing the risk of spam attacks.
[0057] Multi-party computation Multi-party computation may be described as a computation that requires multiple (independent) entities to cooperate in order to generate some final value. Ideally, while generating this final output, the entities do not share or communicate their inputs and keep their inputs private. In the context of non-parallelized mining, according to one or more embodiments of the present disclosure, multi-party computation includes the calculation of an RSA modulus used in an iterated squaring time-lock puzzle. In such embodiments, it is important that the prime factorization of the RSA modulus is not controlled by any single miner.
[0058] MPC for generating a secret RSA residue While other algorithms or methods may be selected by those skilled in the art, in embodiments of the present disclosure, for illustrative purposes, the method disclosed by Boneh and Franklin may be used for generating a shared prime modulus n (Boneh, Dan, and Matthew Franklin, "Efficient generation of shared RSA keys.", Annual International Cryptology Conference. Springer, Berlin, Heidelberg, 1997, hereinafter "Boneh et al."). In their Algorithm 3, independent entities (Alice, Bob, and Henry) establish an RSA modulus n of any size. This method consists of the following five sets of algorithms. · PickCandidates(k)->(p i ,q i ) - Each entity selects two random k-bit integers. · Calculate N~Using private and distributed computation (page 3 of Boneh et al.), three servers calculate n=(p1 + p2 + p3)·(q1 + q2 + q3) explicitly (p i ,q iCalculate without sharing [[ID=]]. Here, since n is public, the entity performs trial division to check that n cannot be divided by small prime numbers. For example, this method is used in the jointly verifiable random secret sharing (JVRSS) protocol in the threshold ECDSA signature implementation form. · Prime number determination - Three servers use private distributed computing to determine that n is actually the product of two prime numbers (see page 4 of Boneh et al.). If the determination fails, the protocol restarts from step 1.
[0059] Boneh et al. give empirical values of experiments for generating moduli of 512, 1024, and 2048 bits (see Table 2 on page 10 of Boneh et al.). It should be noted that the total time required for three parties (using a 333MHz Pentium II running Solaris 2.5.1) to generate a 512-bit modulus was 9 seconds, and the total network traffic was 0.18 Mb.
[0060] MPC for calculating n For the multi-party generation of the RSA modulus n = pq using the private key (p, q), adopt the method outlined in Boneh et al. This algorithm assumes randomly selected sub-committees of three miners that use the minimum number of rounds of communication.
[0061] Setup Miners M1, M2, and M3 are selected using unique and secure sub-committee selection. The miners must establish a direct connection with each other, and all messages between them are encrypted using AES symmetric encryption. The AES key is established using elliptic curve Diffie-Hellman key sharing.
[0062] Multi-party calculation Step 1: Miners M1, M2, and M3 each select candidate (p1, q1), (p2, q2), and (p3, q3) and keep the information secret. Step 2: Miners M1, M2, and M3 use JVRSS to n = (p1 + p2 + p3)·(q1 + q2 + q3) to calculate. Step 3: Miners M1, M2, and M3 perform distributed primality testing (see page 4 of Boneh et al.) to determine whether n is the product of two prime numbers. Step 4: If, as a result of Step 3, a valid composite number n is found, n is propagated to the rest of the network.
[0063] MPC for calculating φ(n) If the multiparty computation has been calculated as above, the next step is to calculate φ(n). For this, the miner needs to know who miner M1 is when the computation becomes asymmetric. However, this can be established in the subcommittee selection process. Step 1: Miner M1 φ1 = n - p1 - q1 + 1 to calculate. Step 2: M2 and M3 φ2 = -p2 - q2, φ3 = -p3 - q3 to calculate. Step 3: Each member of the subcommittee φ(n) = φ1 + φ2 + φ3 can use distributed computing to calculate. φ(n) = (φ1 + φ2 + φ3) = (n - p1 - q1 + 1) + (-p2 - q2) + (-p3 - q3) = n - (p1 + p2 + p3) - (q1 + q2 + q3) + 1 = n - p - q + 1 = (p - 1)(q - 1) It should be observed that.
[0064] Note that after φ(n) is known to the committee, all members of the committee can infer (p, q). (Without loss of generality,)
Number
[0065] Time-Lock Puzzle Mining on a Non-Parallelizable Mining (NPM) Blockchain Embodiments of the present disclosure combine a verifiable random function, multi-party computation, and a time-lock puzzle in a novel way to create a mining algorithm for a PoW blockchain network. The purpose of this algorithm is to calculate a number L that is difficult to find but verifiable if some secret information is known.
[0066] Assumptions: To achieve network-scale consensus for each cycle, the following are required. · Honest majority: At least 51% of the miners must be honest. The same requirement exists for all public blockchain networks. · Honest majority sub-committee: Two out of three members of each sub-committee must be honest to prevent leakage of private keys or key functions. Any suitable incentive strategy may be employed. · Full connectivity: The selection of random sub-committees within the network requires full connectivity among miners so that multi-party computation can be efficiently executed.
[0067] Method 1: A Predetermined Number of Squaring Operations
[0068] Method Step 1: Network miners M1,...,M nThe group of (n > 3) starts the cycle by selecting a subcommittee of three (connected) miners (M1, M2, and M3 without loss of generality) using a verifiable random function. Step 2a: Miners M1, M2, and M3 n = pq perform a multiparty computation to calculate. However, no individual miner can calculate (p, q). Step 2b: Miners M1, M2, and M3 propagate a time-lock puzzle (t, n) along with a randomly selected proof. Step 3a: Miner M i having the public key PK i receives (t, n) and [Number] calculates. However, X is the previous block header hash. Step 3b: Miner M i receives (t, n) and a = L i mod 32 b = L i + 4 mod 32 t i = H(X||PK i )[a:b] calculates. Step 3c (difficult problem): Miner Mi verifiably randomizes [Number] calculates. L is the solution. Step 4: (Assuming M i wins) Miner Mi propagates (L, L i , t i , PK i ). This solution is propagated along with the miner's block. Step 5a: The verifier L i = 2 H(X||P,K)[0:4] mod n Check it. Step 5b: Miners M1, M2, M3 φ(n) = (p - 1)(q - 1) Use secure multi - party computation to calculate, and use the formula
Number
Number
[0069] Analysis: The proposed scheme has the following key features. · The puzzle is time - locked using two values t and t i . t is the minimum number of squaring operations for the puzzle and serves as a difficulty parameter for the network size. t i is a pseudo - randomly generated value that is unique for each miner and each new block. Furthermore, t i cannot be immediately inferred and instead requires some initial calculations to produce a result. · The solution to the puzzle can only be solved using sequential calculations. · The hash function digest acts as a random number generator so that the puzzle is unique for each miner.
[0070] The pseudo-randomness of the base and exponent used in the calculation means that while the miner can estimate the approximate time required to compute the solution, it cannot accurately predict it until mining begins.
[0071] In addition, time limits can be imposed on steps 1 - 2b and 5c so that broken, slow, or incorrect sub-committees are rejected and can be easily reselected. Note that this system does not need to use proof-of-stake in the selection of sub-committees (although this may be desirable in implementation).
[0072] Method 2: Repeated non-square operations with a target threshold In an alternative application of time-lock puzzle mining for the NPM blockchain, a target is used so that the number of square operations cannot be determined in advance by the miner before the calculation starts.
[0073] Target and difficulty: Target
Number
[0074] The target value represents the maximum value that can be accepted as a valid solution. This value is similar to the target difficulty parameter in Bitcoin (for example, it can be encoded in the block header), and the sub-committee will know this value at verification time ~ see https: / / en.bitcoin.it / wiki / Difficulty.
[0075] Distribution of squares Note that when n is the product of two prime numbers, approximately 1 / 4 of all values in the range {0, ..., n-1} are quadratic residues. This result is derived from Euler's criterion (Lehmer, Emma, "On Euler's criterion." Journal of the Australian Mathematical Society 1.1 (1959): 64-70). Furthermore, for a sufficiently large random composite modulus n, the distribution of quadratic residues is approximately uniform, i.e., the probability of selecting a quadratic residue in the range 0, 1, ..., T i is equal to the probability of selecting a random number from the range 0, 1, ..., T i within
Number
Number
Number
Number
Number
[0076] Hashing of solutions: A solution to the observed ambiguity in the distribution of squares is to hash L and measure its value against the target, i.e., Check if H(L) < T i is true.
[0077] Method Step 1: Network miners M1, ..., M nThe group of (n > 3) starts a cycle by selecting a subcommittee of three (connected) miners (M1, M2, and M3 without loss of generality). Step 2a: Miners M1, M2, M3 perform a multiparty computation to compute n = pq without explicitly calculating (p, q). Step 2b: Miners M1, M2, and M3 propagate the time - lock puzzle (t, n) with a randomly selected proof. Step 3a: Miner M i having the public key PK i receives (t, n) and [Number] where X is the previous block - header hash. Step 3b (difficult problem): Miner M i receives (t, n) and tries to find a t such that [Number] L is the solution and T i is the target. i Step 4: (Assuming miner M i wins) Miner Mi propagates (L, L i , t i , PK i i ). This solution is propagated along with the miner's block. Step 5a: The verifier checks L i = 2 H(X||P,K)[0:4] mod n . Step 5b: Miners M1, M2, and M3 use a secure multiparty computation to compute φ(n)=(p - 1)(q - 1) and the formula [Number] Use i to efficiently calculate shortcut e and e i . Step 5c: Each sub-committee member can
Number
[0078] Analysis This technology has the following features. · The puzzle is time-locked using two values t and t i . t acts as a standard difficulty parameter and is the uniform minimum number of squaring operations for the puzzle, while t i is similar to nonce. This means that it is impossible to say how many additional squaring operations a miner needs to perform without doing the calculations. · The solution of the puzzle (similar to nonce in Bitcoin) can only be found by using sequential calculation. · The solution of the puzzle (nonce) is public key-dependent. This means that a new public key must be generated for each entity repeating the nonce value.
[0079] Similar to Method 1, it is possible to impose time limits on Steps 1-2b and 5c so that damaged, slow, or fraudulent sub-committees are rejected and can be easily reselected. Furthermore, the nonce repetition path is essentially sequential and public key-dependent, and as a result, miners cannot gain an advantage by mining on the same block candidate. This significantly reduces the incentive to form mining pools.
[0080] Thus, embodiments of the present disclosure provide a way for a flat network of distributed computers to establish consensus through sequential computational proofs. Four algorithms may be used, which are subcommittee selection using verifiable random functions, multiparty computation for establishing RSA moduli, and time-lock puzzles using pseudo-random inputs. Also, in embodiments of the present disclosure, cryptographic primitives (hash functions, elliptic curve cryptography) specific to the Bitcoin protocol, and further puzzles based on the difficulty of prime factorization are also utilized.
[0081] Assuming low network latency, that the majority of network participants are honest, and the selection of a subcommittee of honest majority, this embodiment is economically feasible on a scale and has strong resistance to mining centralization.
[0082] Next, referring to FIG. 2, an exemplary simplified block diagram of a computing device 2600 that may be used to implement at least one embodiment of the present disclosure is provided. In various embodiments, the computing device 2600 may be used to implement any of the systems exemplified and described above. For example, the computing device 2600 may be configured to be used as a data server, a web server, a portable computing device, a personal computer, or any electronic computing device. As shown in FIG. 2, the computing device 2600 can include one or more processors having one or more levels of cache memory, and a memory controller (collectively labeled 2602) configured to communicate with a storage subsystem 2606 including main memory 2608 and persistent storage 2610. The main memory 2608 may include dynamic random access memory (DRAM) 2618 and read only memory (ROM) 2620 as illustrated. The storage subsystem 2606 and the cache memory 2602 may be used for storing information such as details related to transactions and blocks, as described in the present disclosure. The processor 2602 may be utilized to provide the steps or functions of any embodiment as described in the present disclosure.
[0083] The processor 2602 can also communicate with one or more user interface input devices 2612, one or more user interface output devices 2614, and a network interface subsystem 2616.
[0084] The bus system 2604 may comprise a mechanism for enabling the various components and subsystems of the computing device 2600 to communicate with each other as intended. Although the bus system 2604 is schematically illustrated as a single bus, in alternative embodiments of the bus system, multiple buses may be used.
[0085] The network interface subsystem 2616 may provide an interface to other computing devices and networks. The network interface subsystem 2616 may function as an interface for receiving data from other systems to and transmitting data from the computing device 2600 to other systems. For example, the network interface subsystem 2616 may enable a data technician to connect the device to a network so that while the device is at a remote location such as a data center, the data technician can transmit data to the device and receive data from the device.
[0086] The user interface input device 2612 may include one or more user input devices such as a keyboard, a pointing device such as an in-built mouse, trackball, touchpad, or graphics tablet, a scanner, a barcode scanner, a touch screen incorporated in a display, an audio input device such as a voice recognition system, a microphone, and other types of input devices. In general, the use of the term "input device" is intended to include all possible types of devices and mechanisms for inputting information into the computing device 2600.
[0087] One or more user interface output devices 2614 may include a non-visual display such as a display subsystem, a printer, or an audio output device. The display subsystem may be a cathode ray tube (CRT), a flat panel device such as a liquid crystal display (LCD), a light emitting diode (LED) display, or a projection or other display device. In general, the use of the term "output device" is intended to include all possible types of devices and mechanisms for outputting information from computing device 2600. One or more user interface output devices 2614 may be used to present the user interface so as to smooth out user interaction with, for example, an application executing the described process and variations thereof, when such interaction is deemed appropriate.
[0088] Storage subsystem 2606 may provide a computer-readable storage medium for storing basic programming and data configurations that may provide the functionality of at least one embodiment of the present disclosure. Applications (programs, code modules, instructions) may provide the functionality of one or more embodiments of the present disclosure when executed by one or more processors and may be stored in storage subsystem 2606. These application modules or instructions may be executed by one or more processors 2602. Storage subsystem 2606 may additionally provide a repository for storing data used by the present disclosure. For example, main memory 2608 and cache memory 2602 can provide volatile storage for programs and data. Persistent storage 2610 can provide persistent (non-volatile) storage for programs and data and may include flash memory, one or more solid state drives, one or more magnetic hard disk drives, one or more floppy disk drives with associated removable media, one or more optical drives (e.g., CD-ROM or DVD or Blue-Ray) with associated removable media, and other similar storage media. Such programs and data can include programs for performing the steps of one or more embodiments as described in the present disclosure, and further data related to transactions and blocks as described in the present disclosure.
[0089] Computing device 2600 may be of various types, including a portable computer device, a tablet computer, a workstation, or any other device described below. In addition, computing device 2600 may include another device that may be connected to computing device 2600 through one or more ports (e.g., USB, headphone jack, Lightning connector, etc.). A device that may be connected to computing device 2600 may have a plurality of ports configured to receive fiber optic connectors. Thus, this device may be configured to convert an optical signal into an electrical signal that may be transmitted through a port that connects the device to computing device 2600 for processing. Since computers and networks are constantly changing in nature, the description of computing device 2600 depicted in FIG. 2 is intended only as an example for illustrative purposes of a preferred embodiment of the device. Many other configurations are possible that have more or fewer components than the system depicted in FIG. 2.
[0090] The above-described embodiments are illustrative of the present invention rather than limiting the present invention, and it should be noted that those skilled in the art can design many alternative embodiments without departing from the scope of the present invention as defined by the appended claims. In the claims, reference symbols enclosed in parentheses shall not be construed as limiting the claims. Also, the terms "comprising", "including" and similar expressions do not exclude the presence of elements or steps other than those described in any claim or the entire specification. In this specification, "comprising" and "including" mean "including or consisting of", and "comprising" and "including" mean "including or consisting of". Reference to an element in the singular does not exclude reference to the plural of such element, and vice versa. The present invention may be implemented using hardware including several distinct elements and using a computer appropriately programmed. In a device claim listing several means, several of these means may be embodied by one and the same item of hardware. The mere fact that certain measures are recited in mutually different dependent claims does not indicate that a combination of these measures cannot be used advantageously.
[0091] One embodiment of the present disclosure may provide a step of generating a plurality of multi-party computation challenges, and a step of providing each mining node in a plurality of mining nodes on a proof-of-work blockchain network with a respective challenge from the plurality of multi-party computation challenges.
[0092] Preferably, each mining node receives a different challenge with respect to other nodes. Thus, each challenge may be unique to the node to which it is provided, and any two challenges within the plurality of multi-party computation challenges may not be the same.
[0093] Each mining node within a plurality of mining nodes attempts to find a solution to its respective multiparty computation challenge. This may involve each node generating an output / value. This may be performed by using one or more inputs to an algorithm. The inputs may be kept secret or private by each node in that they share or transmit their respective input values with other nodes within the plurality of nodes.
[0094] Preferably, each challenge within a plurality of multiparty computation challenges requires the use of an essentially sequential algorithm to find a solution to the challenge. This method includes the step of generating a plurality of further multiparty computation challenges, and / or may further include the step of providing each mining node within the plurality of mining nodes with a respective further challenge from the plurality of further multiparty computation challenges.
[0095] Preferably, these steps are performed by one of the mining nodes among the plurality of mining nodes when a solution to a multiparty computation challenge or a further multiparty computation challenge is found.
[0096] Preferably, the generation of the plurality of multiparty computation challenges and / or the plurality of further multiparty computation challenges is performed, at least in part, by a subset of computer-based entities selected from a plurality of computer-based entities. At least one of the computer-based entities may be a mining node on a blockchain network. The subset of computer-based entities may be selected from the plurality of computer-based entities by a random or pseudo-random selection process.
[0097] The generation of at least one of the multiparty computation challenge and / or further multiparty computation challenges may include calculating an output for an operation using a random or pseudorandom input. The generation of at least one of the multiparty computation challenge and / or further multiparty computation challenges may include generating an RSA key pair.
[0098] The challenge may include calculating an RSA modulus. Preferably, the RSA modulus is used in an iterative squaring operation time-lock puzzle.
[0099] This method may further include the step of using an essentially sequential algorithm to find a solution to at least one of the multiparty computation challenge and / or further multiparty computation challenges. The essentially sequential algorithm may include at least one of a recursive operation, a modular exponentiation, and / or an iterative squaring operation.
[0100] The present invention also provides a system, which includes a processor, and a memory including executable instructions that, as a result of execution by the processor, cause the system to execute any embodiment of the computer-implemented method described herein.
[0101] Preferably, the system includes a plurality of nodes on a blockchain network, and at least one of the nodes includes a processor, a memory, and executable instructions.
[0102] The present invention also provides a non-transitory computer-readable storage medium storing thereon executable instructions that, as a result of being executed by a processor of a computer system, cause the computer system to at least execute an embodiment of the computer-implemented method described herein.
Description of the Signs
[0103] 2600 Computing Device 2602 Cache Memory 2604 Bus System 2606 Storage Subsystem 2608 Main Memory 2610 Persistent Storage 2612 User Interface Input Device 2614 User Interface Output Device 2616 Network Interface Subsystem
Claims
1. A computer-implemented method, comprising: generating a plurality of multi-party computation challenges; providing each mining node among a plurality of mining nodes on a proof-of-work blockchain network with a respective challenge from the plurality of multi-party computation challenges; and A computer-implemented method comprising the steps of:
2. The method of claim 1, wherein each challenge in the plurality of multi-party computation challenges requires the use of an essentially sequential algorithm to find a solution to the challenge.
3. generating a plurality of additional multi-party computation challenges; providing each mining node among the plurality of mining nodes with a respective additional challenge from the plurality of additional multi-party computation challenges; and The method according to claim 1 or 2, further comprising:
4. The method of claim 3, wherein the steps of claim 3 are performed by one of the mining nodes among the plurality of mining nodes when a solution to a multi-party computation challenge or an additional multi-party computation challenge is found.
5. The method according to any one of claims 1 to 4, wherein the generation of the plurality of multi-party computation challenges and / or the plurality of additional multi-party computation challenges is at least partly performed by a subset of computer-based entities selected from a plurality of computer-based entities.
6. The method of claim 5, wherein at least one of the computer-based entities is a mining node on the blockchain network.
7. The method according to claim 5 or 6, wherein the subset of computer-based entities is selected from the plurality of computer-based entities by a random or pseudo-random selection process.
8. The method according to any one of claims 1 to 7, wherein the generation of at least one of the multi-party computation challenges and / or the additional multi-party computation challenges includes calculating an output for an operation using a random or pseudo-random input.
9. The method according to any one of claims 1 to 8, wherein the generation of at least one of the multi-party calculation challenges and / or further multi-party calculation challenges includes the generation of the RSA key pair.
10. The method according to any one of claims 1 to 9, further comprising the step of using an essentially sequential algorithm to find a solution to at least one of the multi-party calculation challenges and / or further multi-party calculation challenges.
11. The essentially sequential algorithm is a recursive operation, a modular exponentiation, a repeated squaring operation The method according to claim 10, including at least one of the operations.
12. The challenge includes the calculation of the RSA modulus, preferably, the RSA modulus is used in a repeated squaring operation time-lock puzzle, The method according to any one of claims 1 to 11.
13. A computer-implemented system, a processor, a memory including executable instructions that cause the system to execute any embodiment of the computer-implemented method described in any one of claims 1 to 12 as a result of execution by the processor A computer-implemented system comprising.
14. The system includes a plurality of nodes on a blockchain network, and at least one of the nodes includes the processor, memory, and executable instructions described in claim 13. The computer-implemented system according to claim 13.
15. A non-transitory computer-readable storage medium storing thereon executable instructions that cause at least one embodiment of the method described in any one of claims 1 to 12 to be executed by a processor of a computer system.
Citation Information
Patent Citations
Robust and Efficient Distributed rsa Key Generation
JP2002517024A