惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - 三生石上(FineUI控件)
博客园 - 叶小钗
博客园 - 聂微东
博客园 - 司徒正美
Hugging Face - Blog
Hugging Face - Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Google DeepMind News
Google DeepMind News
Recent Announcements
Recent Announcements
IT之家
IT之家
J
Java Code Geeks
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
I
InfoQ
爱范儿
爱范儿
Vercel News
Vercel News
Apple Machine Learning Research
Apple Machine Learning Research
阮一峰的网络日志
阮一峰的网络日志
博客园 - Franky
U
Unit 42
酷 壳 – CoolShell
酷 壳 – CoolShell
腾讯CDC
F
Fortinet All Blogs
V
Visual Studio Blog
人人都是产品经理
人人都是产品经理

Cryptology ePrint Archive

Fast Isogeny Evaluation on Binary Curves Quick Draw Queries: Lightweight Searchable Public-key Ciphertexts with Hidden Structures via Non-Interactive Key Exchange A Constructive Treatment of Authentication Boolean Arithmetic over $\mathbb{F}_2$ from Group Commutators HAWK with Hint: Algebraic Key Recovery from Side-Channel Leakage Post-Quantum Secure k-Times Traceable Ring Signature A Key Schedule Design and Evaluation under Boundary Round-Key Leakage 2G2T: Constant-Size, Statistically Sound MSM Outsourcing Proximity Signatures Breaking Optimized HQC: The First Cache-Timing Full Decryption Oracle Key-Recovery Attack in Post-Quantum Cryptography Efficient Partially Blind Signatures from Isogenies PipeSC: A Resource-efficient and Pipelined Hardware Accelerator for Sumcheck Protocol Evaluating PQC KEMs, Combiners, and Cascade Encryption via Adaptive IND-CPA Testing Using Deep Learning High-Throughput Side-Channel-Protected Stream Cipher Hardware for 6G Systems Efficient e = 3 Threshold RSA via Integer Coordinates for Intel SGX Zeal: PIR for Non-Cooperative Databases VEIL: Lightweight Zero-Knowledge for Hash-Based Multilinear Proof Systems Witness-Indistinguishable Arguments of Knowledge and One-Way Functions The many faces of Schnorr: a touch-up Open Problems in List Decoding and Correlated Agreement Compressed Key Exchange Protocol from Orientations of Large Discriminant Using AVX-512 SPLASH: SPeculative Leakage-Adaptive Secure Hardware An Efficient Identity-Based Blind Signature Scheme from SM9 Efficient Batch Threshold Encryption Using Partial Fraction Techniques A note on the Unsuitability of LIGA for Linkable Ring Signatures: The perils of non-commutativity Verification Facade: Masquerading Insecure Cryptographic Implementations as Verified Code Cryptographic Implications of Worst-Case Hardness of Time-Bounded Kolmogorov Complexity Efficient Merkle-Tree Consistent Accumulator FLOSS: Fast Linear Online Secret-Shared Shuffling Which Privacy Blanket is Optimal in the Shuffle Model?
Making Uncertified DAG BFT Provably Live with Linear Payl...
Nikita Polyanskii, IOTA Foundation · 2025-03-28 · via Cryptology ePrint Archive

Paper 2025/567

Making Uncertified DAG BFT Provably Live with Linear Payload and Quadratic Metadata Communication

Sebastian Mueller, Aix-Marseille University

Ilya Vorobyev, IOTA Foundation

Abstract

Uncertified DAG-based BFT protocols, such as Mysticeti and Cordial Miners, achieve state-of-the-art latency by eliminating per-block quorum certificates. However, they have lacked rigorous liveness proofs, and recent work has demonstrated explicit desynchronization attacks where honest parties fail to commit leaders after Global Stabilization Time (GST). We present Starfish, an uncertified DAG-based BFT protocol that closes this gap with a new Push pacemaker. This mechanism ensures party synchronization after GST by requiring parties to create their own blocks before advancing rounds and introducing a safe “catch-up” condition for slow parties. To address scalability, Starfish decouples payload from metadata: block headers carry only commitments to Reed-Solomon-encoded fragments, and data availability is certified directly on the DAG via Data Availability Certificates (DACs). This achieves order-optimal worst-case linear payload communication while increasing sequencing latency by only one round. We further propose Starfish-L, combining multi-signatures with a Lazy-Push pacemaker to reduce metadata communication from quartic to cubic in the worst case and quadratic in the happy case. Applying these techniques to Mysticeti yields Mysticeti-L, which matches Mysticeti's low latency while achieving quadratic metadata and linear payload communication costs in the happy case. Finally, we provide full safety and liveness proofs and derive latency bounds in terms of the actual message delay.

Note: -Increased a timeout in the lazy push pacemaker -Loosen the assumption of threshold signatures to multi-signatures

BibTeX

@misc{cryptoeprint:2025/567,
      author = {Nikita Polyanskii and Sebastian Mueller and Ilya Vorobyev},
      title = {Making Uncertified {DAG} {BFT} Provably Live with Linear Payload and Quadratic Metadata Communication},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/567},
      year = {2025},
      url = {https://eprint.iacr.org/2025/567}
}