Proof-of-Stake blockchains based on a longest-chain consensus protocol are an attractive energy-friendly alternative to the Proof-of-Work paradigm. However, formal barriers to "getting the incentives right" were recently discovered, driven by the desire to use the blockchain itself as a source of pseudorandomness \cite{brown2019formal}. We consider instead a longest-chain Proof-of-Stake protocol with perfect, trusted, external randomness (e.g. a randomness beacon). We produce two main results. First, we show that a strategic miner can strictly outperform an honest miner with just $32.5\%$ of the total stake. Note that a miner of this size {\em cannot} outperform an honest miner in the Proof-of-Work model. This establishes that even with access to a perfect randomness beacon, incentives in Proof-of-Work and Proof-of-Stake longest-chain protocols are fundamentally different. Second, we prove that a strategic miner cannot outperform an honest miner with $30.8\%$ of the total stake. This means that, while not quite as secure as the Proof-of-Work regime, desirable incentive properties of Proof-of-Work longest-chain protocols can be approximately recovered via Proof-of-Stake with a perfect randomness beacon. The space of possible strategies in a Proof-of-Stake mining game is {\em significantly} richer than in a Proof-of-Work game. Our main technical contribution is a characterization of potentially optimal strategies for a strategic miner, and in particular, a proof that the corresponding infinite-state MDP admits an optimal strategy that is positive recurrent.
翻译:以最长期的协商一致协议为基础的“获取链的证明”链链链是一个有吸引力的、对能源友好的替代“工作证明”范式。然而,最近发现了“使激励正确”的正式障碍。由于希望利用这一链条本身作为假冒随机性的来源,因此最近发现了“使激励正确”的正式障碍。我们认为,一个具有完美、可信、可信赖、外部随机性(例如随机信标)的最长期链条的“获取证明”协议是一个最长久的链条。我们产生了两个主要结果。首先,我们证明一个战略采矿者能够严格地超越一个诚实的采矿者,其总利害价值只有32.5美元。注意到这样一个规模的采矿者不能在“工作证明”模式中超越一个诚实的采矿者。这证明,即使有一个完全随机的灯塔,一个在“工作证明”和“获取最随机”协议的激励器(例如随机信标)中,我们也证明一个比总利值30.8美的“采矿者”更可靠的战略。这意味着,一个最优的游戏的游戏的准确性战略, 也是一个最可靠的,一个最安全的,一个最精确的,一个最精确的,一个最精确的,也是最安全的,一个最精确的,一个最精确的,也是最精确的,一个最安全的,一个最安全的, 最安全的,一个最安全的,最安全的, 最安全的,一个最安全的, 最有可能的, 最安全的, 最安全的, 也是最安全的,一个最安全的, 的, 最安全的, 最安全的, 最安全的,最安全的,最安全的,最安全的,最安全的,最安全的,最安全的, 最安全的,最安全的,最安全的,最安全的,最安全的,最安全的,最安全的,最安全的,最安全的,最安全的,最安全的,最安全的,最安全的,最安全的,最安全的,最安全的,最安全的,最安全的,最安全的,最安全的,最安全的,最安全的,最安全的,最安全的,最安全的,最安全的,最安全的,最安全的,最安全的,最安全的,最安全的,最安全的,最安全的,最安全的,最安全的,最安全的, 最安全的, 最安全的,最安全的,最安全的,最安全的, 最安全的,最安全的,最安全的,最安全的,最安全的,最安全的,最安全的,最安全的,最安全的,