BTC
ETH
HTX
SOL
BNB
View Market
简中
繁中
English
日本語
한국어
ภาษาไทย
Tiếng Việt

Intensive reading and analysis of V God's new book "Proof of Stake" (8)

Oak
特邀专栏作者
2022-10-24 09:30
This article is about 10879 words, reading the full article takes about 16 minutes
Focus on the value of blockchain technology.
AI Summary
Expand
Focus on the value of blockchain technology.

secondary title

Book chapter

The sixth paper, The Value of Blockchain Technology, was published on the Ethereum Blog, April 13, 2015.

secondary title

  • abstract

  • The blockchain is a magical computer where anyone can upload a program and have the program execute itself, where the current and all previous states of each program are always publicly visible, and with very strong cryptoeconomic security guarantees, run on-chain The program will always be executed in the manner specified by the blockchain protocol. Not just basic functions such as ledgers and transactions, consensus mechanisms and state transition parameters. It's about creative freedom, creating new mechanics with new rule sets at breakneck speed. Blockchains are Lego brainstorms for building economic and social institutions. Gavin Wood (former Ethereum CTO, current Polkadot founder) described this idealized computing platform as a "world computer" - a computer whose state is shared among everyone and a large group of people participate in maintenance, Anyone is free to join. You can refer to the translation case.

  • What is the ultimate use of blockchain technology? What will be the "killer app"? People have been thinking and asking these questions. V God believes that there is no killer application at the moment, and the closest thing is the anti-censorship ability of WikiLeaks and Silk Road. Now is the time to focus on blockchain. The future killer application of the blockchain needs to comply with the long-tail effect, that is, the scope of benefits must be very wide.

  • Blockchains are clearly valuable in finance, which in the world is both computationally confidential and trust-intensive, but they are also valuable in many other aspects of Internet infrastructure.

  • As with open source software, the greatest opportunity for revenue based on blockchain technology comes from "infrastructure" services.

  • The new basic layer services of the Internet today are almost entirely information-based: Internet payment systems, identities, domain name systems, certificate authorities, reputation systems, cloud computing, various data feeds. But the highly networked and interdependent nature of these infrastructure services can make it harder for individuals to switch from one system to another, and puts a few private entities in positions of extreme power, risking single points of failure.

  • The two areas of identity and reputation are typical scenarios where blockchain can provide value. The concept of blockchain-based identity management and social multi-signature backup is probably one of the most powerful mechanisms to use in the design of any kind of decentralized system. The current "reputation system" in the modern world is always insecure, either it is impossible for one entity to rate another entity interacting, or it is under centralized control.

  • The issue of cutting consensus costs and improving blockchain scalability is of paramount importance.

  • Blockchain is just a technology, so ultimately the greatest advancements can only be made by combining it with a suite of other decentralized (and decentralization-friendly) technologies: reputation systems, distributed hash tables, "peer-to-peer hypermedia platforms" , distributed messaging protocols, prediction markets, zero-knowledge proofs, and probably many more yet to be discovered.

secondary title

  • Translator's point of view

  • Blockchain is a major invention based on the underlying logic. It has unlimited imagination in the future and is considered by many to be the core of the fourth industrial revolution or metaverse. If you use the example of small rivers converging into big rivers to compare the blockchain. In the early stage of the river, that is, the upper reaches, it can only produce basic values ​​such as drinking water and washing clothes. After reaching the downstream, it can generate huge value through ship transportation, hydropower stations, and farmland irrigation. Therefore, we should not just stay in the early stage of vision, but should actively participate in its evolution process, promote and reap the dividends in the later stage. Although there will be a long-term unknown where we will go in the future, we should keep up with the trend and stay online. In the process of forming this general trend, we will see that new topics constantly eliminate old ones, and newcomers defeat old ones. The only constant is change. If you want not to fall behind, you need to maintain an open, curious, persistent, and moderately profitable mentality.

  • From the perspective of the traditional Internet and WEB3, both ecology focus on identity, reputation, privacy, cross-application, data sharing and other fields. The traditional Internet circle has encountered problems such as data migration, reputation sharing, data transaction security risks, and lack of incentives. , the demand for blockchain technology is increasing. With the evolution of Ethereum expansion and cross-chain interoperability, this field will explode one day.

secondary title

Brief translation of the content (the order has been adjusted, and the content has been deleted)

When I was researching blockchain technology, one of the core questions I encountered was: What is the ultimate use of blockchain technology? Why do we need a blockchain to do these things, what kind of services should run on a blockchain-like architecture, and why should services run on a blockchain instead of traditional servers? How much value can blockchain really provide: Is blockchain technology necessary, or is it just icing on the cake? And, perhaps most importantly, what will the "killer app" be? I've spent a lot of time over the past few months thinking about this question, discussing it with cryptocurrency developers, venture capital firms, and especially people outside the blockchain space, whether it's civil liberties activists or finance and payments people in the industry, or people in other fields. In the process, I have drawn some important and meaningful conclusions.

First of all, there will be no "killer application" in blockchain technology. The reason is simple: low-fruit first-pick theory. If implementing applications through blockchain technology is already vastly superior to traditional infrastructure, then people are already talking about it. It might seem like an old economics joke, where an economist finds a $20 bill on the ground and concludes it must be fake, or it would have been taken. But searching for a killer app is a slightly different story: Unlike dollar bills, searching for low-hanging fruit is cheap. So even if there's only a 0.01% chance of searching for a killer app, there's a reason to pay for it. But there are already plenty of people with billions of dollars in incentives searching. So far, no one has made an app that really stands out.

  • In fact, it's reasonable to argue that the closest thing to a "killer app" is one that's been accomplished, much-talked-about, but sensationalized: WikiLeaks and Silk Road's censorship resistance. Silk Road, an online anonymous drug marketplace shut down by law enforcement in late 2013, processed more than $1 billion in sales in its two-and-a-half years of operation, during which time WikiLeaks' payment system was in the process of being blocked. Bitcoin and Litecoin donations account for the majority of its revenue. In both cases, the need is clear and the potential economic profit is huge, because before Bitcoin there was no choice but to buy drugs in person and donate to WikiLeaks by mailing cash, Bitcoin therefore provides Great convenience, so profit opportunities are almost instantly preempted. However, this is far from the case now, and the marginal opportunities in blockchain technology are no longer so easy to grasp.

Total Availability and Average Availability

However, does this mean that the effective usability of the blockchain has reached its peak? Absolutely not. In terms of required attributes per user, a peak has been reached, but this is not the same as peak availability. While Silk Road is essential to many of the people who use it, it is not universally essential among drug addicts; although it confuses how the average person is supposed to gain access to this connection, most Most people somehow find a "person" they can trade with. Ease of access to contacts is closely related to interest in drug use. So in the grand scheme of things, the Silk Roads can only be relevant to a very small number of people. WikiLeaks is similar, compared to the total population of the world, there are not many people who care enough about corporate and government transparency to donate money to a controversial organization in support of it. What reason is there? In short, the long tail effect.

So what is the long tail? It's hard to explain. I could list many applications related to the long tail effect, however, blockchain is not essential, but blockchain technology does not provide a strong foundational advantage for these applications. For each case, there is a "blockchain application is overvalued, only bitcoin is important" or "blockchain technology is useless" position, and someone who holds this position can formulate a very reasonable The solution is to implement corresponding products through centralized servers, replace blockchain governance with legal contracts, and change other parts of the application to be more like traditional system applications. On that point they are absolutely correct, blockchain is not essential for that use case. That's the point: These apps don't have the highest number of people using them, as with WikiLeaks and Silk Road; if they were, they would have been implemented long ago. In this long tail, the blockchain is not a necessity, it only provides convenience, and at most it is slightly easier to use than other tools. If these apps were more mainstream, benefitting hundreds of millions of users, the total benefit to society (as can be seen from the area in the graph above) would be much greater.

  • Following this line of reasoning, the following rhetorical question can be asked: What is the killer app of "open source"? Open source is clearly a good thing for society, and millions of software packages around the world use open source software, but it's still hard to answer that question. The reason is the same: there is no killer app, the list of apps has a long tail effect, but basically almost every software imaginable, only emphasizes the low-level library project encryption security library, these technologies have been widely used for a long time .

Blockchain, redefined again

  1. Now, what are the specific benefits of blockchain that make the long tail valuable? First, let me state my current description of the blockchain: a blockchain is a magical computer that anyone can upload a program and have it execute itself, where the current and all previous states of each program are always publicly visible, and With very strong cryptoeconomic security guarantees, programs running on the chain will always execute in the manner specified by the blockchain protocol. Note that my blockchain definition:

  2. Not using financial terms like "ledger", "money" or "transaction", or really any term for a specific use case;

  3. No mention of any specified consensus algorithm, or any technical properties of how a blockchain works (except that it's a technical term for "cryptoeconomics", roughly meaning "it's decentralized, it uses public-key cryptography for authentication, and it uses economic incentives to ensure that it continues to function and does not return in time or cause any other failure");

There is no limitation to any particular type of state transition function.

One of the things that the definition does well is explain what blockchain does, and it explains it in a way that any software developer can grasp its value proposition fairly clearly and intuitively.

One of the things that this definition really emphasizes is that blockchain is not about bringing any given set of rules to the world, whether it's a currency with a fixed supply monetary policy, domain names with a 200-day re-registration time limit, or a specific decentralized Optimizing exchange design, etc.; instead, they are about creative freedom, creating new mechanisms with new rule sets at breakneck speed. Blockchains are Lego brainstorms for building economic and social institutions.

At the heart of the more neutral idea is the prevailing view that “the exciting thing is the blockchain, not the currency”. Indeed, currency is necessary to make cryptoeconomic blockchains work, but currency serves only as an economic conduit to incentivize consensus participation, hold deposits, and pay transaction fees, not center stage for speculative frenzy, consumer interest, and excitement.

  1. Now, why is blockchain useful? in conclusion:

  2. You can store data on the blockchain, and that data is guaranteed to be very highly available.

  3. You can run applications on the blockchain and guarantee extremely high uptime.

  4. You can run applications on the blockchain and be guaranteed extremely high uptime far into the future.

  5. You can run applications on the blockchain and convince your users that the logic of the application is honest and doing what you advertise.

  6. You can run applications on the blockchain and convince your users that your application will continue to work, even if you lose interest in maintaining it, you are bribed or threatened to want to manipulate the application state in some way, or You get a profit motive for manipulating the application wanting the application state in a certain way.

  7. You can run applications on the blockchain, and even provide yourself with backdoor keys if necessary, but place "legal" restrictions on the use of the keys, e.g. pass a public one-month waiting period before requiring a software update, or At least immediately notify users about app updates.

  8. You can run applications on the blockchain and provide backdoor keys for specific governance algorithms (e.g. voting, futarchy, some complex multi-house parliamentary structures) and convince your users that the algorithmic logic of specific governance is applied program control.

  9. You can run applications on the blockchain that can communicate with each other with 100% reliability, even though the underlying platform is only 99.999% reliable.

  10. Multiple users or companies can run applications on the blockchain, and these applications can interact with each other at a very high speed without any network messages, while ensuring that each company has full control over its own application.

You can build applications that use data generated by other applications very easily and efficiently. (Combining the payment and reputation system is probably the biggest takeaway here.).

All of these things are indirectly valuable to billions of people around the world, especially in parts of the world that lack advanced economic, financial, and social Combined with political reforms, many problems can be solved). They are obviously valuable in finance, which in the world is both computationally confidential and trust-intensive, but they are also valuable in many other aspects of Internet infrastructure. It is true that other architectures can provide these properties as well, but they are somewhat less suitable than blockchain. Gavin Wood has begun to describe this idealized computing platform as a "world computer"—a computer whose state is shared among everyone and maintained by a large group of people who are free to join.

Infrastructure

  1. As with open source, by far the biggest opportunity to reap the benefits of blockchain technology comes from so-called "infrastructure" services. Infrastructure services, as a generic category, have the following properties:

  2. Dependencies - many functions need to be closely dependent on infrastructure services;

  3. High network effects - large numbers of people (or even everyone) using the same service can have huge benefits;

High switching costs—It is difficult for individuals to switch from one service to another.

Note that the question of the concept of "necessity" or "importance" has not been adequately addressed; there may be base layers that are not important (e.g., RSS feeds) and important non-base layers (e.g., food). Base layer services existed before civilization existed. In the so-called "caveman age", the most important base-layer service was language. In recent times, prime examples have been roads, legal systems, and postal and transportation systems. In the 20th century we added the telephone network and the financial system, and by the end of the millennium we had the Internet. Now, however, the new base layer services of the Internet are almost entirely informational: Internet payment systems, identity, domain name system, certificate authorities, reputation systems, cloud computing, various data feeds, and perhaps in the near future prediction markets.

Ten years from now, the highly networked and interdependent nature of these services may make it harder for individuals to switch from one system to another than it is for people to change which government they want to live under. This means ensuring that these services are built correctly and that their governance does not place a few private entities in positions of extreme power is critical. Currently, many of these systems are built in a centralized manner, in part because the original design of the World Wide Web failed to recognize the importance of these services and implement these default properties. So even today, most websites ask you to "log in with Google" or "log in with Facebook," and certificate authorities have a problem with this: On Saturday, an Iranian hacker claimed control over the theft of some of the web's largest Web sites, including Google, Microsoft, Skype, and Yahoo. Early reactions from security experts have been mixed, with some believing the hackers' claims while others are skeptical. Last week, speculation centered on a state-sponsored attack, possibly sponsored or carried out by the Iranian government, that hit a certificate reseller affiliated with US-based Comodo. Comodo acknowledged the attack on March 23, saying that eight days earlier, hackers had obtained nine fake certificates for use in login sites for Microsoft's Hotmail, Google's Gmail, Internet calling and chat service Skype, and Yahoo Mail. Also got a Mozilla Firefox add-on certificate.

  • Why not decentralize the certificate authority again based on the M-of-N system? (Note that the current widespread use of M-of-N is not necessarily related to blockchain, but blockchain happens to be a good platform for running M-of-N.)

identity

"Identity on the Blockchain". In general, what do you need to have an identity? The simplest answer is what we already know: you need to have public and private keys. You publish your public key, which becomes your ID, and use your private key to digitally sign every message you send, allowing anyone to verify that those messages were generated by you (from their perspective, "you" means "the entity that holds that particular public key"). However, there are some challenges:

1. What if your key is stolen and you need to get a new one?

2. What should I do if the key is lost?

3. What if you want to refer to other users by their name, not just a random 20-byte string of encrypted data?

4. What if you want to use more advanced security methods (such as multi-signature) instead of just a single key?

Let's try to address these challenges one by one. We can start with the fourth. A simple solution is: instead of needing a specific cryptographic signature type, your public key becomes a program, and a valid signature becomes a string that returns 1 when entered into the program along with the message. In theory, any single-key, multi-key, or any other type of rule set could be encoded into such a paradigm. However, there is a problem with this: the public key can become too long. We can solve this by putting the actual "public key" in some data store (e.g. a distributed hash table if we want decentralization) and using the hash of the "public key" as the user ID this problem. This doesn't require a blockchain yet, although in the latest designs, a scalable blockchain isn't too dissimilar to a DHT (Distributed Hash Table), so it's entirely possible that within a decade, it'll be used for all sorts of things All decentralized systems will incorporate some scalable blockchain technology intentionally or unintentionally.

Now, consider the first question. We can think of this as a certificate revocation problem: if you want to "revoke" a specific key, how do you make sure it's visible to everyone who needs to see it? This itself can again be solved with a distributed hash table. However, this leads to the next question: if you want to revoke a key, what do you replace it with? If your key is stolen, both you and the attacker own it, so neither of you can be convincingly more authoritative. One solution is to have three keys, then if one is revoked, signatures from both or all keys are required to approve the next key. But this leads to the "no collateral (no cost to do evil, infinite benefits)" problem: if an attacker eventually manages to steal all three of your keys from some point in history, they can simulate assigning new keys. key's history, from where more new keys are assigned, and your own history is no longer authoritative. It's a timestamping problem, so blockchain can actually help.

For the second question, holding multiple keys and reassigning them would also work fine, no blockchain needed here. In fact, you don't need to reassign; by clever use of secret sharing, you can actually recover from key loss by keeping keys in "shards", so that if you lose any single shard, you always Yes it can be simply recovered from other shards using secret sharing math. For the third problem, blockchain-based name registration is the easiest solution. In practice, however, most people don't do a good job of safely storing multiple keys, and accidents always happen, and centralized services often play an important role: helping people get their accounts back when something goes wrong . Blockchain technology's solution to this problem is simple: social M-of-N standby.

You choose eight entities, which could be your friends, your employer, certain companies, nonprofits, or even a future government, and a combination of five of them can recover your key if anything goes wrong. This concept of social multi-signature backup is probably one of the most powerful mechanisms used in any kind of decentralized system design, and provides very high levels of security very cheaply and without reliance on centralized trust. Note that blockchain-based identities, especially Ethereum's contract model, make all of this very easy to program: in a name registry, register your name and point it to the contract that maintains the currently associated Have an identity master key and backup key, and formulate logic for regular updates. An identity system that is secure enough for grandma and easy to use without the control of any individual entity (except you!).

Identity is not the only problem blockchain can alleviate. Another component closely related to identity is reputation. At present, the "reputation system" in the modern world is always insecure, either it is impossible for one entity to rate another entity that is interacting; or through a centralized method, reputation data is bound to a specific platform and makes This data is under the control of a centralized platform. When you switch from Uber to Lyft, your Uber rating doesn't migrate.

Ideally, a decentralized reputation system will consist of two separate layers: a data layer and an evaluation layer. Data will include individuals who rate others independently, transaction-related ratings (for example, using blockchain-based payments could create an open system so you can only rate merchants if you actually pay), and others A range of sources where anyone can run their own algorithms to evaluate their data; "light-client-friendly" algorithms for quickly evaluating reputation proofs with specific datasets may become an important area of ​​research (many naive ’s reputation algorithm involves matrix mathematics, which has an almost cubic level of computational complexity, making it difficult to achieve decentralization). "Zero-knowledge" reputation systems that allow users to provide some sort of cryptographic credential that they have at least x reputation points based on a specific metric without revealing any other information are also promising.

  1. The case for reputation is interesting because it combines multiple benefits of blockchain as a platform:

  2. Used as identity data storage;

  3. data storage for reputation records;

  4. Inter-application interoperability (ratings related to payment proofs, ability to work across datasets, etc.);

  5. guarantee that the underlying data is future-portable (companies can voluntarily provide a reputation certificate in an exportable format, but they have no way to pre-commit to continue to have it);

Wider use of blockchain technology to ensure reputations are not manipulated by computers.

  • Now for all these benefits, there are alternatives: we can trust Visa and Master cards to provide cryptographically signed receipts that certain transactions occurred, we can store reputation records on archive.org, we can have servers communicate with each other, we can have private companies Specify in their terms of service that their consent is fine, etc. All of these work, but they're not as pretty as putting everything in the open, running it on the "world computer", and letting cryptographic verification and proofs do the work.

cost cutting

If the greatest value of blockchain technology comes from the long tail, as this article suggests, then an important conclusion follows: the per-transaction gain from using blockchain is very small. Therefore, the issue of reducing consensus costs and improving blockchain scalability becomes critical. When using centralized solutions, users and businesses are used to paying essentially zero fees per "transaction"; while individuals wishing to donate to WikiLeaks may be willing to pay a $5 fee to complete their transaction, trying to upload a reputation The person who recorded it might only be willing to pay a fee of $0.0005. So it's a matter of making consensus cheaper, both in an aggregate sense (i.e. Proof of Stake) and in a per-transaction sense (i.e. via a scalable blockchain algorithm where up to a few hundred nodes process each transaction) Absolutely the most important. Additionally, blockchain developers should remember that software development over the past 40 years has been a history of moving to less and less efficient programming languages ​​and paradigms because this can allow developers to become inexperienced and lazy. It is necessary to design the blockchain algorithm, and the following principles need to be considered: When developers actually develop on the blockchain, a well-designed transaction fee system may allow developers to learn some experience, but there is no guarantee that they are all very smart and wise.

Therefore, there is great desire now to achieve a greater degree of decentralization in the future; however, the days of easy profit are over. Now is the time for a harder, longer-term exploration of the real world to see how blockchain technology can actually benefit the world. At this stage we may find that at some point we will hit an inflection point where most instances of "blockchain for x" will not be created by blockchain enthusiasts looking for something meaningful, encountering x And try to do it in a way, but it's the enthusiasts in the field of x who see blockchains and realize they're a pretty useful tool, implemented by this kind of crowd. x The domains run the gamut from the Internet of Things, financial infrastructure in developing countries, bottom-up societies, cultures, economic institutions, better data aggregation and healthcare, to controversial philanthropy and Reviewed market. In the latter two cases, the inflection point may have been reached, and many original blockchain enthusiasts have become blockchain enthusiasts due to political reasons. However, once it happens in other contexts, then we will see it become mainstream and the biggest humanitarian gains are coming.

  • Furthermore, we may find that the very concept of a "blockchain community" will cease to carry any quasi-political movement significance; if any label applies, "crypto 2.0" may be the most convincing one. The reason is similar to why we don't have a concept of a "distributed hash table community", while the "database community" exists, but is really just a group of computer scientists who happen to specialize in databases. Blockchain is just a technology, so ultimately the greatest advancements can only be made by combining it with a suite of other decentralized (and decentralization-friendly) technologies: reputation systems, distributed hash tables, "peer-to-peer hypermedia platforms" , distributed messaging protocols, prediction markets, zero-knowledge proofs, and probably many more yet to be discovered.

background supplement

What is the doctrine of low-hanging fruit?

The phrase "low fruit first" refers to tasks that are easy to accomplish or problems that are easy to solve in a given situation. It's a cliché that's recurring in business settings, widely used and occasionally abused.

Tasks described as "low fruit first" were irrelevant to the larger challenge. Like simple but low-priority items on a to-do list, they might get done quickly, but they are relatively insignificant given the larger challenge ahead. As time management experts advise, focusing on the most important priorities yields the best results, and business professionals should avoid spending too much time chasing low-hanging fruit.

  1. The low hanging fruit are tempting, but probably not as valuable as more challenging problems. Examples of other low-hanging fruit may include:

  2. Customers who regularly reorder products and only need an occasional reminder call from a sales representative;

  3. Fix easily identifiable manufacturing quality defects;

  4. Improve employee morale through feedback and recognition only;

  5. Remediate performance issues;

Satisfy customers by fulfilling return requests.

  • When setting goals, you should not choose him as the pursuit goal because it is easy. Business objectives should be prioritized according to their overall importance to achieving the organization's strategy. Proper goal setting includes linking goals to key strategic priorities and establishing mechanisms to measure and monitor performance. If the goal is not directly related to the company's key strategy, it should not be pursued.

Nothing At Stake, a situation where someone loses nothing when behaving badly, but stands to gain everything.

What is the nothing at stake problem?

The essence of the Nothing At Stake problem is "doing evil has no cost, and the benefits are infinite." Specifically, when there is a fork in the PoS consensus system, the block producing node can produce blocks for multiple chains at the same time without any loss, so that it is possible to obtain "all benefits ".

It's like there is a window, you can get money by queuing up, when there is only one window, everyone will line up obediently, everyone has it, and it is fun. But when the second window appears. As we all know, in the end, only one of the two windows may receive "real money", and the other's money will become waste paper. But you don't know which window will be the window to send "real money" while queuing. So what do you do? You might place an errand order to help you double up while you line up at another window.

However, in the actual PoS block generation node, the avatar has no cost at this time, and it is just a calculation performed by the computer. What kind of chaos will this cause? Smart block producing nodes will have the motivation to generate new forks, support or initiate illegal transactions, and other profit-seeking block producing nodes will queue up blocks on multiple chains (windows) at the same time to support new forks. As time goes by, there are more and more forks, illegal transactions, and rampant evil. The blockchain will no longer be the only chain, and there is no way for all block producers to reach a consensus.

In addition, the nothing-at-stake problem also makes double-spend attacks easier. Unlike PoW 51% attacks, PoS attack nodes only need a certain amount of computing power (sometimes only 1%) to attack. For example, for a coin whose pledged total amount accounts for only 30% of the currency in circulation, the attack cost is easier to attack than a network with a 60% pledged rate.

  • How easy is it? As shown in the figure below, there are still three block producing nodes A, B, and C. If A is an attacking node, it will create two transactions when a fork occurs. Send X coins to one of your own wallet addresses, and at the same time send X coins to the exchange on another fork. Because of Nothing At Stake, block producing nodes of B and C will produce blocks on the two forked chains at the same time. When the transaction is confirmed by the exchange, A sells X coins and converts them into privacy coins, and moves them out of the exchange. After that, A increases the block weight by increasing the amount of pledged coins, or creating multiple other block producing nodes, and only continues to produce blocks in the forked chain. At this time, the longest chain is obvious, and the gap is gradually widened, and it will eventually become the longest chain, and A successfully double spends X coins.

What is M-of-N?

M-of-N is also known as "multi-person control" or "group-based authentication". So the two key elements inherent in the name here are more than one (person, like the key holder) and "quorum".

  1. The private part of a key pair can be divided into N parts, so in order to create a signature using the private key, M of these parts need to be put together. Such techniques are known as M-of-N, where M of N total parts protect the underlying data. Those numbers could be 3 out of 4. Or 5 out of 50. Can help mitigate two key risks:

  2. Theft, if fewer than M parts are stolen or hacked, it is impossible for an adversary to generate a valid signature;

Losses, in most cases (M is less than N), a part of unintentional losses can be made up by spare parts.

ETH
Vitalik
Welcome to Join Odaily Official Community