Paper 2024/1830

A Tight Analysis of GHOST Consistency

Peter Gaži, IOG
Zahra Motaqy, University of Connecticut
Alexander Russell, University of Connecticut, IOG
Abstract

The GHOST protocol was proposed in 2015 as an alternative to the Nakamoto consensus mechanism that underlies Bitcoin. In con- trast to the Nakamoto longest-chain rule, the GHOST rule justifies selec- tion of a chain by maximizing subtree weights rather than path lengths. This chain selection rule has been adopted by a variety of consensus protocols and is featured in the currently deployed protocol supporting Ethereum. We establish an exact characterization of the consistency region of the GHOSTprotocol,identifyingtherelationshipbetweennetworkdelay,the rate of honest block production, and the rate of adversarial block pro- duction that guarantees that the protocol reaches consensus. In contrast to the Nakamoto consensus protocol, we find that the region depends on the convention used by the protocol for tiebreaking: we establish tight results for both adversarial tiebreaking, in which ties are broken adver- sarially in order to frustrate consensus, and deterministic tiebreaking, in which ties between pairs of blocks are broken consistently throughout an execution. We provide explicit attacks for both conventions which stall consensus outside of the consistency region. Our results conclude that the consistency region of GHOST can be strictly improved by incorporating a tiebreaking mechanism; in either case, however, the final region of consistency is inferior to the region of longest-chain rule consensus. On the other hand, in the region where the GHOST protocol is secure it provides superior defense of settled blocks against periods of adversarial majority than the longest-chain rule and, in this sense, is preferable from the perspective of self-healing.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
Preprint.
Keywords
blockchainproof of workGHOST protocol
Contact author(s)
peter gazi @ iohk io
raha @ uconn edu
acr @ uconn edu
History
2026-09-11: last of 3 revisions
2024-11-07: received
See all versions
Short URL
https://ia.cr/2024/1830
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2024/1830,
      author = {Peter Gaži and Zahra Motaqy and Alexander Russell},
      title = {A Tight Analysis of {GHOST} Consistency},
      howpublished = {Cryptology {ePrint} Archive, Paper 2024/1830},
      year = {2024},
      url = {https://eprint.iacr.org/2024/1830}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.