论文标题

镜头:朝着安全,信任最小的乐观区块链执行

Specular: Towards Secure, Trust-minimized Optimistic Blockchain Execution

论文作者

Ye, Zhe, Misra, Ujval, Cheng, Jiajun, Zhou, Wenyang, Song, Dawn

论文摘要

乐观的汇总(ORU)通过将计算委派给不信任的远程链(L2),通过互动争议解决方案协议来裁定任何状态索赔分歧。最先进的Orus采用了一个整体纠纷解决方案,该协议与特定的L2客户二进制界限紧密地耦合了L1裁判,这与系统的高级语义相关。我们认为,这种方法(1)通过使用操作员 - 选手的客户端软件排除了信任最少和无许可的参与来放大单一培养失败的风险; (2)导致不必要的大型且难以审核的TCB; (3)遭受了经常触发但不透明的升级过程 - 进一步增加了审计开销,并扩大了治理攻击表面。为了解决这些问题,我们概述了一种通过促进机会主义1的N-version编程来设计安全且具有最小TCB的方法的方法。由于其独特的挑战和机遇,我们在以太坊生态系统的背景下以具体的方式将这项工作奠定了基础 - Orus在这里获得了巨大的吸引力。具体而言,我们设计了一种语义意识的证明系统,将其定向针对EVM及其指令集。我们在新的ORU中介绍了实施,该实施是机会主义地利用以太坊的现有客户多样性,并以最小的源修改,证明了我们的方法的可行性。

An optimistic rollup (ORU) scales a blockchain's throughput by delegating computation to an untrusted remote chain (L2), refereeing any state claim disagreements between mutually distrusting L2 operators via an interactive dispute resolution protocol. State-of-the-art ORUs employ a monolithic dispute resolution protocol that tightly couples an L1 referee with a specific L2 client binary--oblivious to the system's higher-level semantics. We argue that this approach (1) magnifies monoculture failure risk, by precluding trust-minimized and permissionless participation using operator-chosen client software; (2) leads to an unnecessarily large and difficult-to-audit TCB; and, (3) suffers from a frequently-triggered, yet opaque upgrade process--both further increasing auditing overhead, and broadening the governance attack surface. To address these concerns, we outline a methodology for designing a secure and resilient ORU with a minimal TCB, by facilitating opportunistic 1-of-N-version programming. Due to its unique challenges and opportunities, we ground this work concretely in the context of the Ethereum ecosystem--where ORUs have gained significant traction. Specifically, we design a semantically-aware proof system, natively targeting the EVM and its instruction set. We present an implementation in a new ORU, Specular, that opportunistically leverages Ethereum's existing client diversity with minimal source modification, demonstrating our approach's feasibility.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源