1
00:00:00,650 --> 00:00:02,770
Now we're going to talk
about another topic for

2
00:00:02,770 --> 00:00:06,760
alternate puzzles, which are puzzles that
discourage consolidation of mining power.

3
00:00:08,810 --> 00:00:11,750
Now, Bitcoin miners mostly
participate by joining mining

4
00:00:11,750 --> 00:00:15,680
pools rather than participating
as independent individuals.

5
00:00:15,680 --> 00:00:20,220
Now this means that very large mining
pools that are directed by a central pool

6
00:00:20,220 --> 00:00:24,250
administrator become a very large
potential consolidation of power.

7
00:00:24,250 --> 00:00:28,420
Now Bitcoin's core value
is decentralization.

8
00:00:28,420 --> 00:00:33,096
So this consolidation of power poses
a big threat to Bitcoin's core values.

9
00:00:33,096 --> 00:00:37,470
Now if the power is consolidated in
a few large, centrally managed pools,

10
00:00:37,470 --> 00:00:42,123
then the large pool operators become a
juicy target for attacks like coercion or

11
00:00:42,123 --> 00:00:42,759
hacking.

12
00:00:44,200 --> 00:00:47,080
So a point could be made that
we might want to discourage

13
00:00:47,080 --> 00:00:49,510
the very large pools from forming.

14
00:00:49,510 --> 00:00:51,510
There's even an analogy to voting here.

15
00:00:51,510 --> 00:00:53,020
It's illegal in the United States, for

16
00:00:53,020 --> 00:00:55,160
example, to sell your vote to someone for
money.

17
00:00:56,260 --> 00:00:59,099
Arguably by participating in
a pool controlled by someone else,

18
00:00:59,099 --> 00:01:01,537
it's akin to selling your
vote in the Bitcoin network.

19
00:01:03,790 --> 00:01:08,410
Now, recently this has become a popular
problem because the very largest

20
00:01:08,410 --> 00:01:10,870
Bitcoin mining pool, GigaHash.IO,

21
00:01:10,870 --> 00:01:15,287
has reached larger than 50% of
the network's overall hash power.

22
00:01:18,351 --> 00:01:23,037
This has led to a bunch of public outcries
explaining that this a very big threat

23
00:01:23,037 --> 00:01:26,587
to Bitcoin, and spells doom or
something to that effect and

24
00:01:26,587 --> 00:01:29,570
demanding technical
solutions to this problem.

25
00:01:31,080 --> 00:01:34,630
Now the observation behind one
technical approach to this problem

26
00:01:34,630 --> 00:01:37,740
is the observation that members
in a Bitcoin mining pool

27
00:01:37,740 --> 00:01:40,200
don't inherently trust each other.

28
00:01:40,200 --> 00:01:44,060
Actually pools can only form and become
very large because members of the pool

29
00:01:44,060 --> 00:01:48,160
are able to prove to the pool
operator that they're towing the line

30
00:01:48,160 --> 00:01:52,030
in doing mining work that can
only benefit the pool as a whole.

31
00:01:52,030 --> 00:01:55,740
This works by using the shares protocol
that was described in earlier lectures.

32
00:01:57,010 --> 00:01:59,170
Now recall that in a Bitcoin mining pool,

33
00:01:59,170 --> 00:02:03,830
there's typically a pool operator
who has a well known public key.

34
00:02:03,830 --> 00:02:07,200
Now each of the miners
sends their near misses or

35
00:02:07,200 --> 00:02:11,710
their mining shares to the pool operator
to show that they're mining on a puzzle

36
00:02:11,710 --> 00:02:15,230
that directs the reward to
the pool operator's public key.

37
00:02:15,230 --> 00:02:18,708
When a solution is found, the pool
operator then distributes the rewards

38
00:02:18,708 --> 00:02:22,313
among the pool participants who have
contributed to finding the solution.

39
00:02:24,786 --> 00:02:27,648
Now there's a interesting
attack on Bitcoin mining pools,

40
00:02:27,648 --> 00:02:30,840
which we're going to call
the vigilante attack.

41
00:02:30,840 --> 00:02:35,000
Suppose that there's a pool member that's
very upset with a large mining pool.

42
00:02:35,000 --> 00:02:37,490
He can participate in
the pool by mining and

43
00:02:37,490 --> 00:02:42,410
submitting his near missed share values
to the pool operator just like normal.

44
00:02:42,410 --> 00:02:46,311
But in the event that he actually finds a
Bitcoin puzzle solution that would reward

45
00:02:46,311 --> 00:02:50,880
the pool he just throws that away and
doesn't tell the pool operator about it.

46
00:02:50,880 --> 00:02:53,850
Now the effect of this
attack is that the overall

47
00:02:53,850 --> 00:02:56,870
effective mining output of
the mining pool is reduced.

48
00:02:58,130 --> 00:03:01,170
However, the vigilante
only loses a little bit.

49
00:03:01,170 --> 00:03:04,960
because he still gets rewards for
other puzzle solutions that are found.

50
00:03:04,960 --> 00:03:08,359
He gets a proportional reward due
to the shares that he submits.

51
00:03:09,650 --> 00:03:13,610
Now, one problem with this attack is that
a vigilante still has to lose something

52
00:03:13,610 --> 00:03:15,160
and doesn't gain anything.

53
00:03:15,160 --> 00:03:19,440
And so, it seems unwise to rely on
vigilantes like this, monitoring

54
00:03:19,440 --> 00:03:23,600
the network and rightfully choosing when
to do this to only attack large pools.

55
00:03:25,520 --> 00:03:28,510
Here's an illustration of what
the vigilante attack looks like.

56
00:03:28,510 --> 00:03:32,810
The vigilante still submits shares to the
pool operator and if he finds a solution,

57
00:03:32,810 --> 00:03:33,400
discards it.

58
00:03:34,870 --> 00:03:38,678
So the approach of a non-outsourcable
puzzle is to encourage the vigilante to

59
00:03:38,678 --> 00:03:41,410
perform this attack in
the following of way.

60
00:03:41,410 --> 00:03:45,300
We'd like to make it so that whoever
actually finds the Bitcoin puzzle solution

61
00:03:45,300 --> 00:03:47,299
is able to take the reward for themselves.

62
00:03:48,800 --> 00:03:50,750
Now the vigilante would have an incentive,

63
00:03:50,750 --> 00:03:55,780
a direct personal incentive to perform
the same attack and harm the pool.

64
00:03:57,530 --> 00:04:01,300
Now the approach to having a puzzle that
works this way is to have a puzzle where

65
00:04:01,300 --> 00:04:05,430
each puzzle attempt requires
signing the puzzle solution value,

66
00:04:06,490 --> 00:04:08,490
using a private public key pair.

67
00:04:08,490 --> 00:04:09,800
In particular,

68
00:04:09,800 --> 00:04:13,480
each attempt at a puzzle solution
requires knowledge of the private key.

69
00:04:13,480 --> 00:04:16,510
And that same private key would then
be used to spend the reward later.

70
00:04:18,930 --> 00:04:22,990
Now as an illustration of this, instead
of the pool operator just having a key

71
00:04:22,990 --> 00:04:27,130
any of the mining pool participants who
are contributing mining resources also

72
00:04:27,130 --> 00:04:30,960
have to have knowledge of the private key
in order for their mining to be effective.

73
00:04:30,960 --> 00:04:34,820
If any one of them does find a solution,
then they would be able to take the money.

74
00:04:36,250 --> 00:04:39,730
A secondary goal is that we'd like
to even provide the ability for

75
00:04:39,730 --> 00:04:41,930
mining pool members in this
case to evade detection.

76
00:04:43,050 --> 00:04:46,620
Now I'm going to describe how a particular
instance of a nonoutsourceable

77
00:04:46,620 --> 00:04:47,350
puzzle would work.

78
00:04:48,370 --> 00:04:50,700
Now, a solution to this puzzle

79
00:04:50,700 --> 00:04:54,000
contains the same information
as an ordinary Bitcoin puzzle.

80
00:04:54,000 --> 00:04:56,870
Including the previous block hash,
a mrkl_root,

81
00:04:56,870 --> 00:05:00,730
which is a commitment to all the
transactions to be included in this block.

82
00:05:00,730 --> 00:05:02,650
And an arbitrarily chosen nonce value.

83
00:05:02,650 --> 00:05:08,210
Now this also includes the public key PK,
which the miner would

84
00:05:08,210 --> 00:05:11,870
have to know the corresponding private
key in order to find puzzle solutions.

85
00:05:11,870 --> 00:05:16,120
It's also going to include two signatures
made using this key pair, s1 and s2.

86
00:05:17,610 --> 00:05:20,400
Now the first step to determining
whether a particular nonce

87
00:05:20,400 --> 00:05:25,070
value is a puzzle solution is to create
a signature s1 using the key pair.

88
00:05:25,070 --> 00:05:28,350
Now this has to be a valid signature
over the previous block hash

89
00:05:28,350 --> 00:05:30,370
as well as the nonce
value that's been chosen.

90
00:05:31,440 --> 00:05:34,689
Now in order to tell if this
nonce was a valid solution,

91
00:05:34,689 --> 00:05:39,283
you have to compute the #H over the string
containing the previous block #,

92
00:05:39,283 --> 00:05:42,407
the public key, the nonce,
and the signature s1.

93
00:05:42,407 --> 00:05:46,901
Then, you compare this # value to
a target just like in Bitcoin's puzzle.

94
00:05:46,901 --> 00:05:52,069
Now only after you find out whether or not
this nonce was a valid puzzle solution,

95
00:05:52,069 --> 00:05:57,340
you then compute a second signature,
s2, using the same key pair.

96
00:05:57,340 --> 00:06:00,920
And only in this signature do you include
the mrkl_root of the transactions.

97
00:06:02,030 --> 00:06:05,260
So the idea here is that you
need to be able to compute

98
00:06:05,260 --> 00:06:09,240
the signature value s1 using the private
key, in order to find out whether or

99
00:06:09,240 --> 00:06:11,070
not you found a puzzle solution.

100
00:06:11,070 --> 00:06:15,050
And only if you found a puzzle solution
do you then compute the second signature

101
00:06:15,050 --> 00:06:18,990
s2 in order to choose which
transactions are going to be included.

102
00:06:18,990 --> 00:06:21,880
This means that to find a puzzle solution,
you have to know the private key.

103
00:06:21,880 --> 00:06:23,300
And if you know the private key,

104
00:06:23,300 --> 00:06:27,440
you get to choose transactions that
will direct the reward to yourself.

105
00:06:28,440 --> 00:06:31,520
There are several potential concerns
with this non-outsourcable puzzle.

106
00:06:32,530 --> 00:06:36,130
One problem is that it basically throws
the baby out with the bath water.

107
00:06:36,130 --> 00:06:39,590
This non-outsourcable puzzle would
discourage all pools from forming,

108
00:06:39,590 --> 00:06:42,550
not only the decentralized ones which
were the original motivation for

109
00:06:42,550 --> 00:06:46,630
this, but also the harmless
decentralized mining pools like P2Pool.

110
00:06:46,630 --> 00:06:48,670
Which were discussed in
previous lectures as well.

111
00:06:50,600 --> 00:06:53,370
Now the effect of this could be that if

112
00:06:54,740 --> 00:06:58,070
miners are discouraged from participating
in any mining pool, they might find

113
00:06:58,070 --> 00:07:02,070
themselves steered towards other forms of
outsourcing, which are even more harmful,

114
00:07:02,070 --> 00:07:06,910
such as hiring hosted mining services
to do their mining for them.

115
00:07:06,910 --> 00:07:10,510
Now, hosted mining services
are potentially an even larger threat to

116
00:07:10,510 --> 00:07:13,090
the decentralization of
Bitcoin's mining power,

117
00:07:13,090 --> 00:07:16,440
because the hosted mining
administrator is actually in physical

118
00:07:16,440 --> 00:07:18,846
possession of all of
the Bitcoin mining rigs.

119
00:07:18,846 --> 00:07:21,862
Now there are potential approaches
to addressing these concerns, but

120
00:07:21,862 --> 00:07:25,139
that's an ongoing research project and
we won't get into the details here.

