Showing posts with label blockchain. Show all posts
Showing posts with label blockchain. Show all posts

Tuesday, November 08, 2022

Attack and Defense in Distributed Finance (DeFi)

In the past four years (2018 ~ 2022), the blockchain-based distributed finance (DeFi) industry has raised 253 billion US dollars, and the losses due to attacks have exceeded 3 billion US dollars. Although this is lower than the loss of the traditional financial system, it still sounds the alarm for fintech scholars. Distributed finance is not a silver bullet in the face of multi-level complex attacks.

The paper "SoK: Decentralized Finance (DeFi) Attacks Liyi" co-authored by Imperial College London, Technical University of Munich, University of Macau, Swiss Institute of Technology, University of California, Berkeley, etc. analyzed 77 papers, 30 audit reports, and 181 incidents. Some interesting analysis came up.

First of all, in terms of architecture, the attack involves four layers, from top to bottom:

  • Protocol layer: realize the application of distributed scenarios, digital currency, exchange services, etc.;
  • Smart contract layer: code, data structure and execution environment for implementing financial logic;
  • Consensus layer: consensus algorithm (including PoW, PoS, etc.), incentive mechanism;
  • Network layer: communication and network protocols, traffic analysis, data transmission, etc.

In addition, there are auxiliary services outside the chain, including client, operation layer, Oracle, etc.

A few statistics:

  • The attack trend is increasing, with the highest in August 2021, with a monthly loss of 600 million US dollars. 3.1 attacks per month in 2020 and 8.5 in 2022;
  • Attacks mostly occur at the protocol layer (mostly stablecoins and lending applications), smart contract layers and auxiliary services;
  • Academic research is relatively average across layers, including network and consensus layers. However, almost all audit reports in the industry focus on smart contracts, and a small amount of them are auxiliary services;
  • Most attacks are not fast and can be prevented by a pause at the protocol layer. But in fact, only 1 of the 87 protocols can respond within an hour;
  • Auditing in advance can effectively prevent attacks. 15.49% of unaudited protocols were attacked, while only 4.09% of audited protocols;
  • Early detection is a more effective method, and most contract loopholes can be detected in advance. However, there is currently a lack of effective protocol layer detection tools;
  • Most attackers can be traced due to the centralized trading and mining mechanism used.

From the above statistical results, it can be seen that the attack and defense of DeFi is actually very close to the traditional attack and defense. The most common attacks are often not technically sophisticated enough to be identified at an early stage and effectively stopped, but systematic detection tools are currently lacking. In addition, academia and industry focus differently.

Monday, April 11, 2022

Decentralized Exchange

If you want to exchange between different digital assets, you need to go through intermediary channels such as exchanges.

The traditional exchange is a centralized model, that is, the two parties of the transaction exchange according to the exchange rate through the trading platform provided by the third party, and the trading platform side often needs to collect the handling fee from the transaction. This model is not only costly, but also has the risk of relying too much on the trading platform.

To solve these problems, Decentralized Exchange (DEX) was designed. The initial idea is to allow both parties to exchange directly peer-to-peer through a blockchain-based protocol. Since there is no need to participate in the trading platform, the transaction cost is low, and it can be completed in real time without worrying about security risks. Currently, decentralized exchanges are one of the hottest topics in decentralized finance.

To implement a decentralized exchange, some basic problems need to be solved:

  • The transaction can be completed automatically without manual participation;
  • No one can fake or deceive the other party during the transaction;
  • Calculate the exchange rate automatically and complete the transaction according to the exchange rate;
  • Avoid excessive market volatility and losses.

At present, decentralized exchanges mainly include three modes according to their order positions: on-chain bookkeeping, off-chain bookkeeping and automatic market makers.

On-chain accounting

The idea of ​​on-chain bookkeeping is very simple, and the exchange transactions are directly stored on the blockchain.

This mode is simple to implement, but has major flaws.

  • Every transaction needs to be on the chain, and there will be billing fees. When transactions are frequent, the cost of bookkeeping is too high;
  • All information needs to be recorded on the chain, which may benefit someone from knowing the transaction information in advance;
  • When there are many transactions, the performance requirements of the blockchain are very high, and most public chains cannot support it.
Platforms adopting this scheme include Stellar and others.

Off-chain accounting

In contrast to on-chain bookkeeping, off-chain bookkeeping stores transactions on a third-party platform. Third-party platforms only write transactions to the blockchain when needed.

This method can avoid writing a large number of transactions to the blockchain, but it needs to rely on a third-party platform, and there is a high security risk.

Platforms that have adopted this solution include Binance and others.

Automated market maker

Similar to market makers in the securities market, smart contracts can be used to implement an automated market maker mechanism (AMM).

When users need to exchange currency, they do not directly trade with other users, but exchange with blockchain smart contracts.

Behind the smart contract, the exchange rate is calculated in real time according to its liquidity pool and pricing algorithm (such as reciprocal curve, straight line, etc.). A small fee is charged per transaction (e.g. Uniswap charges 0.3%).

This mechanism does not need to rely on transaction bookkeeping, transaction costs are generally low, and risks are small.

Users can also put the currency they hold into the liquidity pool according to the protocol and become a Liquidity Provider (LP). Liquidity providers can obtain benefits from transaction fees.

The main problem of this model is that the depth of the market depends on the liquidity pool, and it is necessary to balance the contradiction between LP income and transaction costs. At the same time, when the currency price fluctuates greatly, LP may incur Impermanent Loss.

Typical implementation protocols include Uniswap, Bancor, etc., and platforms include Chainlink, Kyber, etc.

Thursday, April 07, 2022

From Digital Artwork to NFT

Over the past few years, digital artwork has explored the possibility of using NFT (Non Fungible Token), a new digital medium for asset transactions.

In the future, a large number of item transactions can be carried out in the form of NFT. In addition, NFTs can digitize asset ownership, making it easier to realize value more fully.

The emergence of NFT represents the urgent need for traders to switch from paper-based contracts to digital contract-based transactions.

Note: If you want to understand the ins and outs of web 3.0, you can read From web 1.0 to web 3.0.

Digital Art

Digital artwork refers to a set of data with certain artistic value generated by computer technology. Similar to traditional physically created artworks, digital artworks are considered unique and collectible. Since the transactions of digital art are mostly carried out through cryptocurrencies, it is also called CryptoArt.

Back in 1993, Hal Finney (also an early Bitcoin expert) discussed the idea of ​​a "crypto trading card" on the crypto forum Cypherpunks, possibly the earliest discussion of cryptographic artwork and NFTs.

Digital artwork mainly includes the following characteristics:

  • Based on the blockchain platform, once the generation rules are determined, artworks cannot be issued or modified, nor can they be counterfeited;
  • More use of cryptocurrency transactions, all records are publicly visible and can be effectively traced;
  • After the user purchases, the ownership is recorded on the distributed ledger, which cannot be tampered with or faked;
  • Art transactions are completed directly and immediately, and there is no traditional third party;
  • Digital artwork itself is not scarce, and even easily copied, but its ownership is unique and recognized by the market.

In 2014, Robby Dermody, Adam Krellenstein, Ouziel Slama and others launched the Counterparty trading platform based on the Bitcoin network. The platform provides peer-to-peer financial transactions through the Metadata Token Protocol, supports the creation of tokens, decentralized asset transactions, and more. In September 2016, the "Rare Pepe" project was launched, becoming an early digital artwork.

On June 23, 2017, Larva Labs launched the CryptoPunks project. The project created 10,000 punk avatars, each as a unique 24x24 8-bit pixmap. Initially, the project was released for free on the Ethereum network, hoping to honor the spirit of punk. Later, with the publicity and participation of enthusiasts, the project attracted the attention of a large number of users and even investment institutions. It is still very active to this day, and the single price is often tens of thousands of dollars. In June 2021, Avatar No. 7523 sold for $11.8 million. CryptoPunks have unique cultural interest as collectibles and are considered to be the beginning of the later trend of encrypted digital art. Since then, Larva Labs has also developed Autoglyphs and Meebits projects, which have also attracted market attention.

On November 28, 2017, the Axiom Zen team (which later incubated Dapper Labs) launched the CryptoKitties game based on Ethereum trading. Each player can buy a digital cat with ether, breed offspring, and sell it. All records are publicly visible on the Ethereum network. Through this game, players can learn to master the basic usage of ether. The game was once very popular. The price of a single digital cat once exceeded 100,000 US dollars, and related transactions accounted for nearly 20% of the transaction traffic of the Ethereum network, causing transaction delays and blockages. The success of the game has also inspired many imitators. The ERC-721 standard that the project follows is widely adopted.

In April 2021, Yuga Labs launched the Bored Ape Yacht Club project on the Ethereum network, which includes 10,000 different ape portraits, generated by computers. Among them, the portrait numbered 8817 was auctioned for a high price of 3.4 million US dollars.

NFT

Although many NFTs are digital artworks at present, the connotation of NFTs is actually more extensive. Anything that can be circulated in the digital world can be considered an NFT. Including paintings, photography, music, books, games, etc.

NFT literally means non-fungible token. Traditional encrypted digital currency is homogeneous (Fungible Token), there is no difference between any two coins, can be replaced with each other, and can often be split into smaller units, such as Bitcoin. NFTs, on the other hand, are unique, cannot be replaced by other NFTs, and often cannot be divided into smaller units. For example, a painting NFT represents the painting itself and cannot be replaced by other NFTs.

At present, NFT products often have the following characteristics:

  • not interchangeable;
  • cannot be split into smaller units;
  • Often only exists.

The non-homogeneous nature of NFT makes it easy to anchor to objects in the physical world, such as real estate, cars, collectibles, etc. The property rights of any real object can be tied to an NFT. Therefore, NFTs are considered to have great potential.

In 2020, with the massive issuance of sovereign currencies around the world, NFTs have begun to be more and more sought after. In 2021, the NFT project has ushered in a big explosion, so 2021 is also called "the first year of NFT" by many people. At present, most NFTs are traded through platforms such as Opensea, Rarible, and Nifty Gateway, and rely on the Ethereum network and IPFS for storage.

The emergence of the NFT idea is very natural, and its earliest prototype can be traced back to the Bitcoin-based ColoredCoin that appeared in 2012. Colored coins have color attributes, and colors can be used to represent different assets. This provides feasibility for real-world assets to be put on the chain.

But the Bitcoin network does not support smart contracts, limiting its expressiveness. The Ethereum network, which was launched in July 2015, strengthened its support for smart contracts, making the emergence of a large number of NFTs a reality. In particular, in September 2017, the ERC-721 specification was officially proposed and became the reference standard for a large number of NFTs based on Ethereum projects. This year, the encrypted cat project was launched, and the concept of non-fungible tokens was officially established. In 2018, the Ethereum community also proposed the ERC-1155 standard that supports batch transactions, which is currently supported by the trading market Rarible.

Sky Mavis developed the game Axie Infinity in 2018, which has since become one of the popular games on the Ethereum network. It supports players to trade virtual pets and land resources through NFT. At the same time, players can obtain points and exchange them by playing games. Some virtual pets cost as much as 300 ether (about $1 million).

In October 2020, Dapper Labs partnered with the NBA to launch the NBA Top Shot game project. It uploads the highlight video clips of a player in the game to the public chain Flow developed by Dapper Labs and makes it as an NFT product. After the NBA Top Shot project was launched, it attracted the participation of a large number of users. The total turnover has exceeded 200 million US dollars, and the NFT price of some products such as player LeBron James's slam dunk video once soared to 400,000 US dollars.

In addition, the British Museum, the Russian Hermitage Museum, etc. have also auctioned NFT products of world famous paintings.

In February 2021, Linkin Park (Linkin Park) band member Mike Shinoda released an NFT music composition on the platform Zora for a whopping $400,000.

In February 2021, digital artist Mike Winkelmann (aka Beeple) created 5,000 digital paintings "Everydays – The First 5000 Days" which took 13 and a half years from May 2007 to create a 316 MB image NFT. , sold at Christie's for a historic price of $69.34 million (42,329 ETH) to cryptocurrency investor Vignesh Sundaresan.

In April 2021, Centrifuge successfully secured a MakerDAO loan using the house as collateral.

In December 2021, the digital artist, codenamed Pak, will include 312,686 digital art collections, "The Merge," sold on digital art auction platform NiftyGateway to 28,983 buyers for a total of $91.8 million. This is also the most expensive NFT work at present.

Advantages of NFT

The use of NFTs for transactions includes the following advantages:

  • Instant transaction: After the buyer and the seller reach a transaction from the platform and write it into the blockchain, the ownership of the NFT is transferred, and the transaction record is stored on the distributed ledger, which cannot be tampered with;
  • Not easy to fake: Once the NFT product is confirmed, its transaction history will be completely recorded, and it is difficult for others to fake it;
  • Improve efficiency: NFT-based transactions are processed automatically through smart contracts, and the processing efficiency is much higher than manual operations;
  • Reduce costs: The handling fee of NFT platforms is usually much lower than the intermediary fee for real transactions, and reducing transaction costs can also promote the prosperity of the market.

Problems with NFTs

The rapid development of NFT has also led to the emergence of some problems:

  • Auditing issues for NFTs: Before becoming an NFT and being traded, the platform or auditor needs to confirm the actual ownership of the bound items. Once there is a false property right situation, there needs to be a way to roll back, which puts forward new requirements for the current distributed ledger technology;
  • The problem of rational return of the market: At present, excellent NFT products are very scarce, resulting in many products being hyped up with inflated prices after they are launched. Excessive prosperity in the early stages of the development of new things often leads to the rapid creation and bursting of bubbles. The trading platform should design a more rational auction mechanism and raise the threshold for participation.
  • Interconnection between different platforms: NFTs based on different platforms often adopt different standards, and it is difficult to interconnect with each other, which limits the circulation of NFTs in the larger market.

From Web 1.0 to Web 3.0

 The Internet ecology has undergone a transformation from web 1.0 to web 2.0 in the past three decades. Where is the future of web 3.0, it is worth thinking about and exploring.

web 1.0

In the early 1990s, after the invention of the HTTP protocol, various websites sprang up one after another. In the early days, such as AOL and Yahoo, they all created amazing growth miracles.

The characteristics of these websites are that the owner is responsible for providing the content, and the user can only read the content and use the service. In other words, the classic single-production-many-consumption model.

The model of web 1.0 makes the right to speak on the World Wide Web in the hands of a few website service providers, a few decide the mainstream voice, and the rest are the silent majority.

web 2.0

web 1.0 spawned the booming .com bubble. Ten years later, in the fall of 2001, Internet stocks crashed, marking the beginning of the 1.0 model's gradual decline.

People began to discuss a new generation of web models, and after several years of exploration, the 2.0 model gradually became popular. This model begins to support user interaction, that is, users can create and decide content.

In the early days of web 2.0, blogs were used as a typical application, which represented a transition from a traditional user consumption model to a user who could become a content producer at the same time. Further, in the later period, social networking sites around social networking were born, and twitter, facebook, etc. became famous for a while. This pattern continues to this day.

While users can interact and create content, the platform remains firmly in the hands of a handful of internet giants, meaning they can easily channel and control so-called "mainstream" voices.

web 3.0

With the emphasis on privacy protection and the awareness of personal data rights, users are beginning to be dissatisfied with the existing network ecosystem, hoping to get their own interests back through a new generation of network models.

Web 3.0 is pinned on this kind of good hope. At present, the concept of web 3.0 is still in development, and the early exploration mainly hopes to combine distributed ledger technology to allow users to control their own identity information while limiting the sharing of data. Decentralized finance, data storage and trading applications have emerged.

Summarize

From the early web 1.0 to the web 3.0 that is still under discussion, it can be seen that the user's demand for interactive participation is constantly increasing, and at the same time, they hope to have their own control over the data on the network. This will be a huge challenge to the existing Internet ecosystem, and it may take ten or even decades to evolve.

Tuesday, June 18, 2019

Facebook 的 Libra 项目到底意味着什么

笔者一直颇为关注 FB 团队在数字资产方面的进展,并认为他们是最有可能首先大规模落地的。月前交流时曾询问具体发布时间,说是这个月中旬左右。
果然,2019 年的 6 月 18 日,Libra 项目白皮书正式面世,要解决全球范围内普惠金融支付的问题。同一天,软件巨头微软宣布加入了全球最大的分布式账本项目——超级账本阵营。
这两件事,恰好是新一代金融科技自比特币起,在支付和分布式账本两条主线上的里程碑。
纵观历史,科技创新的速度越来越快,甚至其加速度本身也在加速!
曾几何时,同一家银行异地取款要收手续费;时至今日,手机异地使用已无漫游费。
人们一直在不断追求更方便、更幸福的生活,正是这种爆发式增长的需求,逼迫科技创新的过程越来越快。凡是无法跟上生产力发展的,必将被历史抛弃。
Libra 项目面世后,支持者有之,反对者有之,困惑者亦不在少数。笔者认为,从金融科技的角度,至少应该认识到如下几点。
  • Libra 目标是落地,并非实验性质。不同于 R3 联盟这样既缺实际需求,又缺研发实力的组织,FB 联合 Visa、eBay、Paypal 等 29 家金融机构,自身手握 27 亿真实用户,同时具备大规模系统的研发经验。这些都表明,Libra 项目落地的概率极高,而且一落地就会承载庞大的交易量。这将让国内的互联网巨头们徒有眼羡不已。
  • Libra 最大的意义并不在于新的数字货币类型,而在于启示思路。无论成败,它都将揭示:全新的、更高效、更开放的金融体系是可行的。大门已经打开,金融机构们要考虑的并非是否应当支持 Libra或者别的方案,而是在未来更先进的普惠金融秩序下如何重新定位自身。历史终将选择能为大多数人谋福利的方案。
  • 短期内受到挑战最大的将是 SWIFT。无论是 Visa 的 B2B connect 还是 FB 的 Libra,实际上都剑指这一金融系统巨头。SWIFT 网络拥有超过 10000 家金融机构,每年超过 100 万亿美金的支付量,曾为全球金融系统做出过重大贡献。然而,它自身的创新太慢了,交易延迟居高不下,手续费过于昂贵。落后就要挨打,就会被创新者挑战。
  • Libra 赌的其实是全球化的趋势。只要全球化的大趋势是对的,跨境的支付,打通不同类型的货币,就是个强需求,就必然会出现相关产品。区别只是在于谁来做,什么时候做的问题。
  • Libra 的短期优势和劣势都是与现实货币锚定。这是没有办法的事情,短期内 FB 必然要向既得利益群体妥协,也要凭借现实货币为其信用背书。这就造成现有金融体系的众多问题和风险,对于 Libra 依然存在。换句话说,未来几年内,其必然会受到大量金融攻击(目前,Libra团队仍缺乏足够的金融专家)。但是长期来看,当实践证明其足够稳定和好用之后,信用将转移到 Libra 本身,届时,将没人关心是否与谁挂钩的问题。
个人预测,Libra 项目的进展并不会那么顺利,这里面仍然存在不少金融科技(特别是隐私、安全、金融攻击)和监管难题;另一方面,重构金融格局带来的巨大变化,必将改变已有的利益分配和游戏规则,这将是很多人所不愿的。
但历史的洪流必将携裹一切,滚滚向前,根本不会在意途中曾有几棵朽木,几堆泥沙。

Wednesday, October 18, 2017

《区块链原理、设计与应用》荣获2018年度畅销图书奖!


《区块链原理、设计与应用》已经正式出版,详细介绍了区块链相关技术,特别超级账本的设计、架构和应用,欢迎大家阅读使用并反馈建议。

获奖情况

荣获2018年度机械工业出版社畅销图书奖,信息科技领域唯一原创获奖图书。

编辑推荐

本书由超级账本全球技术委员会委员、核心设计和开发者编撰,清华大学五道口金融学院常务副院长廖理教授作序,Apache 基金会创始人 Brian Behlendorf 等国内外专家联袂推荐。
本书由浅入深,详细讲解超级账本 Fabric 架构设计精华与应用开发案例,是区块链与分布式账本开发落地专业指南。

内容简介

全书分为理论篇和实践篇两大部分。
第 1-3 章介绍区块链技术的由来、核心思想及典型的应用场景;第 4-5 章重点介绍区块链技术中大量出现的分布式系统技术和密码学安全技术;第 6-8 章介绍区块链领域的三个典型开源项目:比特币、以太坊以及超级账本;第 9-11 章以超级账本 Fabric 项目为例,具体讲解了安装部署、配置管理,以及使用 Fabric CA 进行证书管理的实践经验;第 12 章重点剖析超级账本 Fabric 项目的核心架构设计;第 13 章介绍区块链应用开发的相关技巧和示例;第 14 章介绍区块链服务平台的设计与开发,并讲解应用超级账本 Cello 项目构建服务平台的相关知识。
本书覆盖了区块链和分布式账本领域的最新技术,可帮助读者深入理解区块链核心原理和典型设计实现,以及高效地开发基于区块链平台的分布式应用。

专家推荐

区块链(Blockchain)无疑是近十年来最具颠覆性的新兴信息技术之一。业界甚至把它与人工智能(Artificial Intelligence)、云计算(Cloud Computing)和数据科学(Data Science)统称的“ABCD”,推崇为未来*有潜力的四大信息技术方向。本书的作者有深厚的学术背景和丰富的实战经验,在区块链技术方面接触广泛、钻研深入,积累了大量基于超级账本的实践和应用案例。本书深入浅出,系统总结归纳了区块链及其相关技术基础,全面比较分析了区块链主要开源项目的异同,相信对区块链技术与系统的应用和研发是一个很有价值的指南。
-- 李军,原清华大学信息技术研究院院长,清华信息科学与技术国家实验室常务副主任
区块链技术正与云计算、大数据和人工智能等新兴技术交叉融合,孕育出新的商业模式和产业格局,具有重构数字经济发展生态的重要潜力。这本书既有对区块链原理的深度解析、三大典型开源区块链项目的底层剖析和Fabric 架构设计的细致阐述,也有转账、资产权属管理、调用其他链码等具体应用的开发示例,是一本知行合一的好书,与大家分享并推荐。
-- 刘多,中国信息通信研究院院长,中国通信标准化协会副理事长
互联网彻底解放了信息,使得信息的创作、获取、存储、再加工无处不在。区块链也将同样解放人类的交易过程,以一种全新的方式建立交易的信任、仲裁、记录基础。区块链和分布式账本技术很可能是我们这个时代下一个可以和互联网相提并论的伟大发明。本书系统介绍了区块链技术和分布式账本技术,包括核心概念、应用场景、关键技术和开发技巧,并且较全面地介绍了三大典型区块链开源项目:比特币、以太坊和超级账本。本书作者不仅是全球发展*快的超级账本项目的重要代码贡献者和开源社区组织者,也是将区块链技术应用到客户实际生产项目的实践者。因此,书中不仅有深入透彻的架构设计剖析,可以让读者快速掌握该领域的核心知识,还有容易上手的实战案例,可以让读者感受区块链技术的应用前景。无论是希望了解区块链和分布式账本领域的核心技术,还是学习如何更好地开发区块链应用,本书都值得一读。
-- 田忠,IBM 全球杰出工程师、IBM 中国创新工程院院长
Baohua Yang has an impressive technical depth and breadth of knowledge on blockchain and distributed ledger technologies and the impact they will have on the way businesses and governments work. He has made enormous contributions to Hyperledger, the distributed ledger project of the Linux Foundation, both in China and globally.
-- Brian Behlendorf,超级账本管理委员会执行董事,Apache基金会创始人

销售渠道

目前已授权京东图书China-pub 等各大渠道进行销售!

===== 关于 TechFirst 公众号 =====
专注云计算、大数据、Fintech、人工智能、分布式相关领域的热门技术与前瞻方向。
发送关键词(如云计算、大数据、容器、区块链),获取热门点评与技术干货。
欢迎投稿!
如果你喜欢公众号内容,欢迎鼓励一杯 coffee~


Hyperledger Fabric 核心术语

2017-05-09 TechFirst 
  • Anchor(锚点):一般指作为刚启动时候的初始联络元素或与其它结构的沟通元素。如刚加入一个 channel 的节点,需要通过某个锚点节点来快速获取 channel 内的情况(如其它节点的存在信息)。
  • Auditability(审计性):在一定权限和许可下,可以对链上的交易进行审计和检查。
  • Block(区块):代表一批得到确认的交易信息的整体,准备被共识加入到区块链中。
  • Blockchain(区块链):由多个区块链接而成的链表结构,除了初始区块,每个区块头部都包括前继区块内容的 hash 值。
  • Chaincode(链码):区块链上的应用代码,扩展自“智能合约”概念,支持 golang、nodejs 等语言,多为图灵完备。
  • Channel(通道):Fabric 网络上的私有隔离。通道中的 chaincode 和交易只有加入该通道的节点可见。同一个节点可以加入多个通道,并为每个通道内容维护一个账本。
  • Committer(提交节点):1.0 架构中一种 peer 节点角色,负责对 orderer 排序后的交易进行检查,选择合法的交易执行并写入存储。
  • Commitment(提交):提交节点完成对排序后交易的验证,将交易内容写到区块,并更新世界观的过程。
  • Confidentiality(保密):只有交易相关方可以看到交易内容,其它人未经授权则无法看到。
  • Endorser(推荐节点或背书节点):1.0 架构中一种 peer 节点角色,负责检验某个交易是否合法,是否愿意为之背书、签名。
  • Endorsement:背书过程。按照 chaincode 部署时候的 endorsement 策略,相关 peer 对交易提案进行模拟和检查,决策是否为之背书。如果交易提案获得了足够多的背书,则可以构造正式交易进行进一步的共识。
  • Invoke(调用):一种交易类型,对 chaincode 中的某个方法进行调用,一般需要包括调用方法和调用参数。
  • Ledger(账本):包括区块链结构(带有所有的交易信息)和当前的世界观(world state)。
  • Member(成员):代表某个具体的实体身份,在网络中有用自己的根证书。节点和应用都必须属于某个成员身份。同一个成员可以在同一个通道中拥有多个 peer 节点,其中一个为 leader 节点,代表成员与排序节点进行交互,并分发排序后的区块给属于同一成员的其它节点。
  • MSP(Member Service Provider,成员服务提供者):抽象的实现成员服务(身份验证,证书管理等)的组件,实现对不同类型的成员服务的可拔插支持。
  • Non-validating Peer(非验证节点):不参与账本维护,仅作为交易代理响应客户端的 REST 请求,并对交易进行一些基本的有效性检查,之后转发给验证节点。
  • Orderer(排序节点):1.0 架构中的共识服务角色,负责排序看到的交易,提供全局确认的顺序。
  • Permissioned Ledger(带权限的账本):网络中所有节点必须是经过许可的,非许可过的节点则无法加入网络。
  • Privacy(隐私保护):交易员可以隐藏交易的身份,其它成员在无特殊权限的情况下,只能对交易进行验证,而无法获知身份信息。
  • System Chain(系统链):由对网络中配置进行变更的配置区块组成,一般可以用来作为组成网络成员们形成的联盟约定。
  • Transaction(交易):执行账本上的某个函数调用或者部署 chaincode。调用的具体函数在 chaincode 中实现。
  • Transactor(交易者):发起交易调用的客户端。
  • Validating Peer(验证节点):维护账本的核心节点,参与一致性维护、对交易的验证和执行。
  • World State(世界状态):即最新的全局账本状态。Fabric 用它来存储历史交易发生后产生的最新的状态,可以用键值或文档数据库实现。

===== 关于 TechFirst 公众号 =====
专注云计算、大数据、Fintech、人工智能、分布式相关领域的热门技术与前瞻方向。
发送关键词(如云计算、大数据、容器、区块链),获取热门点评与技术干货。
欢迎投稿!
如果你喜欢公众号内容,欢迎鼓励一杯 coffee~

Monday, September 26, 2016

第二届区块链峰会随记

上周(9.19-9.24)在上海参加了第二届区块链全球峰会。
整体感觉,整个产业已经上升到一个新的阶段了,开始有一些落地的项目,不再只是呼吁概念。

天下大势,三分已成

币圈和链圈渐行渐远,而目前区块链领域从技术实现上已经逐渐划分为三大阵营:以太坊、超级账本和其它。
以太坊(Ethereum):开源阵营。由 VB 同学带领的以太坊团队牵头开发。草根出身,自然受到很多个人开发者的喜爱,相关的客户端、环境支持也比较完善。不少欧洲的创业项目(Consensus 投资了不少)都是基于以太坊的平台来搭建,但普遍规模较小。
超级账本(HyperLedger):开源阵营 + 企业支持。由 Linux 基金会组织团队开发。科技界和金融界的巨头们牵头支持,自然受到各大企业的青睐。不少机构给的对区块链平台的需求和设计,基本可以理解为对超级账本白皮书的解读,包括隐私保护、可审计、安全、插件化的共识等都是超级账本的基本特性。SWIFT 也刚跳出来支持超级账本阵营。更多信息可以查看 这里
其它方案:包括各种开源、非开源的方案。以创业团队居多。百花齐放百家争鸣是好事情,但是可惜自己真的从头做的很少,这也挺正常,毕竟区块链领域相关技术门槛确实比较高。少数几个号称从头做、有底层技术的又不开源,这在如今是一件挺可惜的事情。
个人感觉,区块链产业要想做大,至少在基础设施这一层需要尽快的成熟和规范,这对大家都有好处。Linux、Web Server 这样的开源方案出来被大家认可后,才有了整个互联网的繁荣。

通用平台 vs 专用平台

除了对通用平台的讨论,开始有人意识到专用平台的重要性。
之前不少人喜欢用传统数据库的需求来质疑区块链。实际上区块链技术跟数据库完全是两个领域的事情,解决的不同的问题。如果某个业务场景真的需要特定的功能,则应该结合业务层从一开始就设计支持,而不是所有需求都堆到底下。
大胆预测,未来可能出现专门面向各个领域的专用区块链平台:金融区块链、物联网区块链、众筹区块链……,类似不同的 Linux 发行版。
只有这样,才能真的说区块链落地了。

应用场景

应用场景仍然是五花八门,开始有一些关注到具体实际的问题。
比如解决个人的资产登记问题、跨境资金、分布式电商平台,大部分也都是之前就耳熟能详的。但有些推出了新一代的解决方案,还是有不少亮点的。
对应用来说,技术层面反而要弱化,好的商业模式、对市场的把握、对当地政策的解读往往都是决定性的因素。
从目前来看,明后两年将会出现应用的大爆发,特别是国内市场。

BaaS 将成为短期内热点

随着 IBM、微软、Google 等宣布退出 BaaS 业务,将有更多的云服务商会追随这一趋势。
目前来看,基于 HyperLedger 的 BaaS 有相对成熟的解决方案。

Friday, June 24, 2016

区块链的七年之痒

关于区块链的探讨和争论从未停息。
或许从计算技术的演变历史中能得到一些启发意义。


上图是笔者在某次交流会中提出的。
以云计算为代表的现代计算技术,发展历史上有若干重要的时间点和事件:
  • 1969 - ARPANet(Advanced Research Projects Agency Network):现代互联网的前身,被美国高级研究计划署(Advanced Research Project Agency)提出,其使用 NCP 协议,核心缺陷之一是无法做到和个别计算机网络交流;
  • 1973 - TCP/IP:Vinton.Cerf(文特•瑟夫)与Bob Karn(鲍勃•卡恩)共同开发出 TCP 模型,解决了 NCP 的缺陷;
  • 1982 - Internet:TCP/IP 正式成为规范,并被大规模应用,现代互联网诞生;
  • 1989 - WWW:早期互联网的应用主要包括 telnet、ftp、email 等,蒂姆·伯纳斯-李(Tim Berners-Lee)设计的 WWW 协议成为互联网的杀手级应用,引爆了现代互联网,从那开始,互联网业务快速扩张;
  • 1999 - salesforge:互联网出现后,一度只能进行通信应用,但 salesforge 开始以云的理念提供基于互联网的企业级服务;
  • 2006 - aws ec2:AWS EC2 奠定了云计算的业界标杆,直到今天,竞争者们仍然在试图追赶 AWS 的脚步;
  • 2013 - cognitive:以 IBM Watson 为代表的认知计算开始进入商业领域,计算开始变得智能,进入“后云计算时代”。
从这个历史中能看出哪些端倪呢?
一个是 技术领域也存在着周期律。 这个周期目前看是 7 年左右。或许正如人有“七年之痒”,技术也存在着七年这道坎,到了这道坎,要么自身突破迈过去,要么往往就被新的技术所取代。如果从比特币网络上线(2009 年 1 月)算起,到今年正是在坎上。因此,现在正是相关技术进行突破的好时机。
为何恰好是七年?七年按照产品周期来看基本是 2-3 个产品周期,所谓事不过三,经过 2-3 个产品周期也差不多该有个结论了。
另外,先出现的未必是先驱,也可能是先烈。 创新固然很好,但过早播撒的种子,没有合适的土壤,往往也难长大。技术创新与科研创新很不同的一点便是,技术创新必须立足于需求,过早过晚都会错失良机。科研创新则要越早越好,最好像二十世纪那批物理巨匠们一样,让后人吃了一百多年的老本。
最后,事物的发展往往是延续的、长期的。 新生事物大都不是凭空蹦出来的,往往是解决了前辈未能解决的问题,或是出现了之前未曾出现过的场景。而且很多时候,新生事物会在历史的舞台下面进行长期的演化,只要是往提高生产力的正确方向,迟早会有出现在舞台上的一天。

Wednesday, June 01, 2016

区块链需要关注的应用场景

区块链最近几年炒得很热,国内已有大量与之相关的企业,有些企业已经结合已有业务摸索出了自己的应用场景,但仍有不少企业处于不断试探和反复迷惑状态。
从技术角度讲,区块链涉及到的领域比较杂,包括分布式、存储、密码学、心理学、博弈论、网络协议等,要一下子完全理解确实不太容易。
甚至有人简单将区块链技术归结到分布式数据库的范畴,误导了对其的正确理解。
实际上,要找到合适的应用场景,还是要从区块链自身的特性出发进行分析。
从技术特点上,区块链具有:
  • 分布式容错性:网络极其鲁棒,容错 1/3 左右节点的异常状态。
  • 不可篡改性:一致提交后的数据会一直存在,不可被销毁或修改。
  • 隐私保护性:密码学保证了未经授权者能访问到数据,但无法解析。
随之带来的业务特性包括:
  • 交易成本:设计恰当的区块链应用可以控制每笔交易的成本更低,不需要第三方中介机构。
  • 维护成本:跟传统技术相比,区块链网络维护成本更低,适用环境更多。
  • 安全隐私:直接为终端用户提供一定程度的安全保障和隐私保护。
区块链并非凭空诞生的新技术,更像是技术演化到一定程度突破应用阈值后的产物,因此,其应用场景也跟促生其出现的环境息息相关。
未来几年内,可能深入应用区块链的场景将包括:
  • 征信管理:这是大型社交平台和保险公司都梦寐以求的,目前还缺乏足够的数据来源、可靠的平台支持和有效的数据分析和管理。该领域创业的门槛极高,需要自上而下的推动。
  • 社区资源共享:airbnb 为代表的公司将欢迎这类应用,极大降低管理成本。这个领域创业门槛低,主题集中,会受到投资热捧。
  • 金融交易:主要是降低交易成本,减少跨组织交易风险等。该领域的区块链应用将最快成熟起来,银行和金融交易机构将是主力推动者。
  • 投资管理:无论公募还是私募基金,都可以应用区块链技术降低管理成本和管控风险。虽然有 DAO 这样的试水,谨慎认为该领域的需求还未成熟。
  • 物联网:物联网是很适合的一个领域,短期内会有大量应用出现,特别是租赁、物流等特定场景。但物联网自身的发展局限将导致短期内较难出现规模应用。

Thursday, May 12, 2016

数字货币到底解决了哪些问题?

货币是人类文明发展过程中的一大发明。很难想象没有了货币,现代社会的金融体系还能否持续运转。
一般等价物都可以作为货币使用。然而平时最常见的货币形式还是纸币,它既方便携带、不易仿制、又相对容易辩伪。
或许有人认为信用卡更方便。相对于信用卡这样的集中式支付体系来说,货币提供了更好的匿名性。而且碰到系统故障、断网、木有刷卡机器等情况,信用卡就不可用了。ps,货币 vs 信用卡并不是本文所关注的问题。
无论是货币,还是信用卡模式,都需要额外的系统(例如银行)来完成生产、分发、管理等操作,带来很大的额外成本和使用风险。诸如伪造、信用卡诈骗、盗刷、转账等安全事件屡见不鲜。
很自然的,如果能实现一种数字货币,保持既有货币的这些特性,消除纸质货币的缺陷,无疑将带来巨大的社会变革,极大提高经济活动的运作效率。
近三十年来,数字货币技术经历了几代演进。目前看来,比较有影响力的模式有两种,一种是类似 paypal 这样的选择跟已有的系统合作,成为代理;一种是以比特币这样的完全丢弃已有体系的分布式技术。
现在还很难讲哪种模式将成为未来的主流,甚至未来还可能出现更先进的技术。但对比特币这一类数字货币的设计进行探索,将是一件十分有趣的事情。
让我们来对比现在的数字货币和现实生活中的纸币:
属性分析胜出方
便携这点上应该没有争议,显然数字形式的货币胜出。数字货币
防伪这点上应该说两者各有千秋,但数字货币可能略胜一筹。纸币依靠的是各种设计(纸张、油墨、暗纹、夹层等)上的精巧,数字货币依靠的则是密码学上的保障。事实上,纸币的伪造时有发生,但数字货币的伪造明面上还没能实现。数字货币
辩伪纸币需要依托验钞机,数字货币依靠密码学。数字货币胜出。数字货币
匿名通常情况下,两者都能提供很好的匿名性。但都无法防御有意的追踪。平局
交易对纸币来说,谁持有纸币就是合法拥有者,交易通过纸币自身的转移即可完成。对数字货币来说则复杂的多,因为任何数字物品都是可以被复制的,因此需要额外的机制。为此,比特币发明了区块链技术来实现可靠的交易。纸币
资源100 美元钞票的生产成本是 0.1 美元左右。100 面额人民币的生产成本说法众多,但估计应该在几毛到几块范围内。数字货币消耗的资源则复杂的多,以最坏情况估计,算出来多少就要消耗多少电(往往要更多)。纸币
发行纸币的发行需要第三方机构的参与,数字货币则通过分布式算法来完成发行。在人类历史上,好几次通胀和通缩就是不合理的发行纸币造成的。但数字货币在这方面的表现还有待观察。平局
可见,数字货币并非在所有领域都优于已有的货币形式。不带前提的在所有领域都鼓吹数字货币并不是一种严谨的态度,应该针对具体情况具体分析。实际上,仔细观察目前支持数字货币的交易机构就会发现端倪。其中,物联网相关领域无疑是一个很有希望的方向。
最后,虽然当前的数字货币已经取得了巨大成功,但可见的局限也很明显:分布式账本还无法做到大规模场景下的快速确认;交易的频度还远低于已有的交易系统;资源的消耗还过高。这些问题还有待于相关技术的进一步发展。

Thursday, April 07, 2016

Hyperledger -- Linux 基金会的开源区块链

区块链已经成为当下最受人关注的开源技术。然而对很多人来说,区块链过于底层,而且缺乏统一规范。
2016 年刚过去三个多月,Linux 基金 会牵头,联合三十家初始成员(包括各大金融、科技公司和相关开源组织),共同宣告 了Hyperledger 项目的成立。该项目试图打造一个超级账本项目,作为区块链技术的开源规范和标准,让更多的应用能更容易的建立在区块链技术之上。
IBM 贡献了数万行已有的 Open Block Chain 代码,Digital Asset 则贡献了企业和开发者相关资源,R3 贡献了新的金融交易架构,Intel 也刚贡献了跟分布式账本相关的代码。
首届技术委员会主席由来自 IBM 开源技术部 CTO 的 Chris Ferris 担任,委员会主席则由来自 Digital Asset Holdings 的 CEO Blythe Masters 担任。
该项目的出现,实际上宣布区块链技术已经不单纯是一个开源技术了,已经正式被主流机构和市场认可;同时,对于区块链相关产业的发展意义深远。
项目官方地址托管在 Linux 基金会网站,代码托管在 Github 上,目前已经获得了不少关注。
转载请注明来源。

Sunday, January 17, 2016

从比特币到区块链的未来

很早就想写一写区块链(Blocking Chain)技术,作为比特币等一系列应用背后最核心的技术,它的前景充满了各种可能和挑战。最近身边不少人感兴趣,正好总结下。

起源和背景

相比区块链,更多人都听说过比特币。其实最早 08 年的时候比特币就已经问世了,但真正流行起来还是在 10 年后的事情。其官方网站是 bitcion。发明人(传言代号为中本村的澳大利亚人)到目前为止尚无法确认身份,但是一个团队的概率较大。
比特币是一种概念金融货币。主要是希望解决已有金融货币系统的几个问题:
  • 被掌控在发行机构手中;
  • 自身的价值无法保证;
  • 无法匿名化交易。
搞金融的人都能想到,实际上,要设计这么一套系统,最关键的还是一套强大的交易记录系统和中立的货币发行机制。
首先,这个系统要能中立、公正、无法被篡改地记录发生过的每一笔交易。对比已有的银行系统,可以看出,现在的银行机制作为第三方,是有代价的提供了这样的服务,即如果交易双方都相信银行的数据库,那么就没问题了。可是如果是世界范围内流通的货币呢?有哪个银行能让大家完全信任它?于是,需要有一套分布式的数据库,在世界范围内都可以访问,而且都无法去控制。这也就是区块链设计的目的。
货币的发行则是通过比特币的协议来规定的,总量必须控制,发行速度会自动调整。既然总量一定,那么单个比特币的价值肯定会随着承认比特币的实体经济的加入而水涨船高。发行速度的调整则避免了通胀或者滞涨的出现。

原理

区块链的基本原理其实十分简单。
首先假设存在一个 P2P 的数据库(这方面的技术相对成熟),剩下来就是大家如何决策去添加数据上来。只允许添加、不允许删除避免了作伪的可能性。这个数据库的结构是一个链,由一个个块组成,这也是其名字的来源。新的数据要加入,必须作为一个新的块来加入。而这个块能否加入,可以通过一些手段来检验出来。
具体到比特币如何使用了区块链技术。比特币将每十分钟内所有的交易都打包在一起,这些信息组成一个块。然后,网络中所有的成员都可以试图来找到一个合法的块(比如基于当前的块的信息,加上时间、id,加上某些其它有用信息等),然后进行一些 hash 计算,并且找到的结果还得满足一定条件(比如小于某个值)。一旦算出来就可以进行全网广播,大家拿到这个算出来的结果,进行正向验证,发现确实符合条件了,就承认你算出来了。
因为算出来的概率要从数学上进行保证,比如每十分钟内大概就刚好算出来一个。所以保证了区块链每十分钟增加一个块。算出来的这个人将获取得到这个时间内所有交易产生的管理费和协议固定发放的奖励费(目前是 25 比特币)。也即俗称的挖矿。

挖矿

五年前,挖矿还是一个很有前途的行业。但是现在,建议还是不要考虑了,因为从概率上说,由于当前参与挖矿的计算力实在过于庞大(已经超出了大部分的超算中心),获得比特币的收益已经眼看要 cover 不住电费了。特别那些想着用云计算虚机来挖矿的想法,意义确实不大了。
从普通的 CPU、到后来的 GPU、到后来的 asic 矿机、到现在的 asic 数据中心。短短数间,比特币矿机的技术走完了过去的计算机的历程,并且还颇有创新之处。确实是哪里有利益,哪里的技术就飞速发展!
有哥们当年去内蒙古用近乎白给的价格租了当地的机房,打着创业幌子搞挖矿,不知道今日身家几何!
很自然的,有人会想到,如果我有很强大的计算力,所有的块我都算出来了,那是不是就能破坏比特币网络。确实如此,基本上拿到 1/3 的计算力,比特别网络就存在被破坏的风险了;拿到 1/2,概率上就掌控整个网络了。
想想看,你可以一直不承认别人的计算结果,只承认自己的,从概率上风险是很大的。这里,要区别分布式系统里面的拜占庭将军问题,这里完全是概率意义,并非数学证明。
那么有没有办法防护呢?
除了尽量避免计算力放到同一个组织手里,没太好的办法,这是目前 pow (proof of work)的协议规定的。
也有人觉得为了算一个块,大部分计算力(特别到最后根本没算出来的)其实都浪费了。
有人提出用所谓的 pos,即大节点作为多个节点代理人的模式来节约计算力。那怎么选大节点?又容易导致“富则越富”问题。呵呵,这就是完全民主 vs 选举人制度嘛。
个人认为,无论 pow 还是 pos,都无法解决问题。要从根本上解决,得引入随机代理人制度,通过算法在某段时间内只让部分节点参加计算,然后要发放一部分“普世奖励”给所有在线节点。

安全

既然区块链一个可能的应用前景是金融系统,那么安全自然是讨论最多、挑战最多的话题。区块链的实现是开源的,基于了现有的成熟的密码学算法。但这是否就能确保其安全呢?
未必。有如下几个方面是很难逃避的。
首先是,攻击区块链系统是否是犯罪?攻击银行系统是要承担后果的。但是目前还没有任何法律保护区块链以及基于它的实现。
其次是软件实现的潜在漏洞是无法避免的。考虑到使用了几十年的 openssl 还带着那么低级的漏洞(heart bleeding),而且是源代码在大家眼皮底下。这背后曾经发生过啥,让人遐想连篇。金融系统自身到底有没有必要开源,也值得商榷。
另外,区块链所有交易都是公开可见的。搞大数据的人听了是不是开始激动起来了,呵呵,这里面能分析的东西还真不少,而且规模够大、影响力够大……
还有就是作为一套完全的分布式系统,区块链缺乏足够的调整机制,一旦运行起来,真的无人能控制。即使是让它变得更公平、更完善的修改,只要有部分既得利益者合起来反对,那就无法加入进去。这让比特币本身的价值也蒙上了一层阴影。

展望

无论如何,区块链确实是第一个试图做公开、中立、匿名化的分布式数据库的系统。它的出现,让大家意识到除了互联网这样的基础设施外,数据库系统也可以成为公共基础设施。而且像比特币这样的例子,给与了区块链更多的遐想空间。如果交易无法造价,信息无法造价,世界是不是会多了一些算法来保证的公平呢?这是又一次用技术给人类发展带来进步的福利。
不提这种去中心化的金融系统是否现实(个人认为至少 5-10 年后的事情了),在跨国交易、跨组织合作日益频繁的今天,区块链、比特币都是很好的一些尝试和参考。