Securely scaling web3: Exploring shared security responsibilities - Stefan Sopic | Parity
ETH Belgrade Community·Sat, Oct 7, 2023, 12:00 AM
Transcript
hi guys so uh my name is uh Stefan I'm currently a head of engineering at parody parody If you don't know is one of the main engineering forces behind the pocketed ecosystem or are actually uh pocketed chain and yeah um today I want to talk about shared security as a as a way of scaling web 3. what is shared security um it's a economic scaling solution for blockchains right what is what does that really mean so if we we in the web3 space we talk about um when we talk about scaling oftentimes we talk about computational scaling or data scaling but rarely we talk about the economic scaling and so um this is I think a really interesting topic for us to to dive a little bit deeper around because it is a topic that will allow us to get to a place of the true true web through vision I think so um what is what is actually what is actually uh shared security right like um when we talk about uh proof-of-stake blockchains what we're talking about is the underlying value of the underlying asset of the chain securing the network and what does that actually mean but it actually means that securing in the security security in this context is an economic cost for you to um change the chronicle history of the blockchain which we usually call an attack right it doesn't have to be um it is something that the blockchains as a whole were made to be resistant to right um so but it's an economical cost to do that so if you if we're talking about the double spend attack for example which is the most common one um it would be the economical cost to um to to do to do this attack and obviously where this gets us to is a place where if there is more value behind the chain more value securing the chain it would be more resilient to attacks any if if we talk if we talk about realistically if you are trying to attack a chain um which is uh which has a robust Economic Security model you actually have to you have to spend insane amount of money um and to to acquire the underlying asset so you can do this attack and as you do that um the acid underlying asset becomes more scarcer uh in turn so uh increases its potentially increases in value so this when we're talking about um resilient security we're talking about in in the context of the market forces obviously now this to um kind of puts us in a situation where there is a pretty big overlap between economics and the security of of a blockchain right and um I know for for all of us here um who are at the ethereum conference um the the huge moment that happened with ethereum uh switching to profoster State concept this should be pretty um uh self-evident right that uh through proof of stake economics is a huge part of security right now if we if we take this as um assumption let's talk about a bootstrapping problem so what is a blue surfing problem this is something that I like to talk about uh quite a bit if we believe in the true multi-chain future if we believe in the future where there are going to be more and more chains with potentially increased specific um so increasingly specific problem solving chains right like very specialized chains then these are the three things that will always be a problem if you want to launch a chain first I'm not going to spend too much time on on one coding complexity it is what it is like blockchains are are hard they're they're hard to code there are a lot of libraries and sdks to help you one of them is substrate which we in parity use to build kusama and every every other power chain in the ecosystem there is Cosmos SDK which is used to build the cosmos customer words and a few others as well now I want to focus on the second one which is economic security now this is very interesting because we are like aligned with the um economics of the chain and security are actually um there is a big overlap now having this in mind you're launching your chain when you're launching a chain and most of you know this already the that is the point of the highest volatility of the asset with the other all things equal and in in most cases right so the asset being live on a mainnet will change value drastically uh with like going up and down there's going to be Peaks and valleys um all over the place until the market kind of agrees on what is the realistic value of the of the chain right or of the underlying asset and obviously over time that value can change now if you're talking about security tying security to something uh like a volatile asset or volatile asset um of that magnitude asset volatility of that magnitude is um maybe not the best idea in the world right um and this is where we come to one of the one of the big problems of of launching blockchains today and number three obviously we're talking about the multi-chain environment so leveraging this environment itself so not building everything yourself but leveraging the more um specific use cases that you just want to solve without trying to with one chain always solve everything I'm gonna talk about this at the end of the presentation now obviously you shouldn't be as surprised that the solution would be shared security right um so what is this what does this actually mean it means leveraging security of another chain basically in in its in its Basics when you're launching your own chain what you want to do to avoid the volatile economics affecting the security of your chain what you actually want to do is you want to leverage another chain that already has this solved and already has quite substantial and robust security model now let's dig a little bit deeper and explore the different types of shared security there is um Native type this is like something that we came up with um this is uh very similar to what we do in um in pocketed ecosystem it is implemented on a protocol level um what we the relay chain were pocketed in this case uh would be l0 and then all the l1s would be um the one uh chains benefiting from the security of the layer zero blockchain because this is ethereum conference um obviously I'm assuming most of you are aware of Roll-Ups um Roll-Ups are basically using the security of ethereum uh with some very interesting ways how to abstract the actual uh volume of the transactions away from it so that you can still leverage the security of ethereum but still have a huge throughput and restaking this is um kind of a model where we're using already staked Assets in securing uh differentiating like I'm gonna dive a little bit deeper into each one of these so let's start with restaking so um I I think I've forgot the name of the uh the protocol um einken eichen is the one the currently um at the Forefront in ethereum space of using risk taking Solutions um obviously there is uh there it's a very interesting uh approach I think um the the benefits here uh are mainly uh that there there doesn't need to be a need of the protocol of the two chains um so of the chain leveraging the security of something like ethereum it doesn't have to have any protocol alignment it could be um whatever chain that just has this one thing implemented where ethereum staked ethereum on ethereum network is also used to secure another Network so it is pretty protocol agnostic which is definitely a positive thing um and obviously it's not too expensive now the negative side of this is like I wrote some things there um what I when I think about restaking Solutions I think about the the housing crisis of 2008 and the the underlying acid that that caused the the whole economy to collapse was uh mortgage payments right so mortgages that were before that super secure and then building cdos and then building synthetic videos on top of these so scaling up um The Leverage basically that you're building on top of a single asset uh could be detrimental if anything goes even mildly wrong and in those cases uh in the recycling Solutions this would be slashing um slashing happening on on any uh level would would be very problematic for for this type of network now let's talk about Roll-Ups and one of the the ones that I want to mention is optimistic rollups they're really cool um uh arbitrum Optimum is our um to that are usually I think the most popular in ethereum space and there are a bunch of benefits so what rollup actually does is roll ups a lot of transaction happening off chain um takes the a route of transactions in root of state and just uses that to um push into ethereum and validate in ethereum so there's like a bunch of advantages there massive amounts of data can be put in the street transition function um which obviously um helps with with the scaling which is what we're here all to talk about they can be paralyzed and obviously they're not necessarily limited to the the evm right and they they have their own implementations I think um and they can have multiple parallel uh implementations of these roll-ups now the the drawbacks are around the sequencer being centralized which causes a lot of security risks long time to finality I mean we're talking in some cases weeks which in blockchain space is not necessarily something that you want to expose yourself to um because there's a lot of things that can go wrong in a week right and obviously it is still participant of the underlying Network and as such it does kind of fall under the same set of problems that other transactions will fall under which is like high guess prices in in Peaks and congestion of the network itself but still a very interesting way of solving this problem now Ezekiel rollups uh I'm guessing you probably heard a lot about those in recent months this is some this is a topic that has been heating up quite a bit um the the cool thing about it is obviously using the the ziki circuits to create a proof of validity which brings finality actually brings down the time to finality by a lot um it's almost instantaneous in some cases it's just that those proofs of Mobility are extremely difficult to calculate and they don't always they can't cannot be always applicable to every single smart contract um obviously the positives here would be lower gas fees and um yeah transaction throughput which could be quite substantial when we're talking about the drawbacks of the complexity of the ZK um as you can roll up is something that obviously comes up quite a bit the hardware needed to run those machines that provide proof of validity are extremely specialized and expensive which obviously leads to fears of centralization same way as um in other chains when you have validators that have specs out of this world um you obviously have a very limited amount of people who can afford those machines and then you have this risk of centralizations cool now um let's talk about the native shared Security on the example of pokeret so um when we're talking about polka very briefly it is um a relay chain that actually has chains attached to it we call those power chains uh l0 L1 is the nomenclature that we use and through um to attaching to the um to attaching to the relay chain you basically leverage the security of the relay chain so attacking any of the pair of jeans is exactly the same as attacking polkadot itself so any type of transactions um that you might have with any other uh similarly secure chains um is basically immutable and this is a huge Advantage if we're talking if we're talking about the concept of shared security and the concept of scaling web 3 right because not everybody has this same forces in play um we uh in in Pocket ecosystem we completely um divide the runtime from uh from the client um we pack we use bosom for this um so the vas and binaries are the only actually thing that is different that is the logic of the chain and that is the only thing different between polka dot Moonbeam which is an evm chain on pocketed ecosystem um akala origin Trail um the only difference is the actual just logic and the binary and everything else stays the same so obviously the finality is quite fast and low risk of centralization because the collators which control the power chains are sufficiently decentralized compared to sequences or Hoovers in in the ZK space and no gas chains like when you actually attach to the no gas fees when you actually attach to the chain you don't actually have um gas fees for the duration of the slot that you got as well has drawbacks and wasn't fast actually it's half of the time of the Native runtime of native compilation sorry um requires a large amount of data um to uh in inside of proof of validity function and there are limits to entering the system now I must say that like I talked about the drawbacks of each of these Solutions I have to now say that every drawback that I had here there are people and projects working on fixing those like decentralizing sequencers I think that was a big topic uh it still is um as well as like in in the in the case of polkadot and we're working on um blockchains that have um shared security as a pay-as-you-go model basically you batch up a bunch of transactions um and then when you feel like you have enough if you have a blockchain or a blockchain solution that is um doesn't doesn't have to verify every single transaction um you know in six seconds or 12 seconds you can just wait for those two section transactions to form a block and then verify it every six hours or something like that if you don't have something that is time sensitive and in those cases obviously uh pay as you go model actually works for you quite quite well so there's a there's an another thing I want to say before we before we go to the slide there's another thing I want to say if you remember at um slide number two three I mentioned that there is like um three problems that you saw uh that you're facing when you are uh starting at your chain um so the number one is the code complexity number between shared security or Economic Security and the number three would be um leveraging the multi-chain environment right because it's never good like I think we are getting into a space where we're kind of done with these blockchains they can do everything right now we're entering the phase as a ecosystem in which we have more specialized chains and in that ecosystem if you have a more specialized chain you don't want to build all the other stuff every other chain has you don't want to necessarily build identity you don't necessarily want to build nfts you don't want to build I don't know like a decks yourself you can leverage a lot of these other things that exist and you can just focus on your own solution right and for that to happen you need to have trustless trustless communication between between different chains and shared security is a way to get there right shared security would be the easiest way for you to exchange messages trust with other consensus implementations and fully trust that those messages actually mean the same thing when they are executed on on a different consensus protocol of of your own right in in poker we call this cross status messaging or Axiom maybe you heard of that and those messages are actually being passed through between parachains and relay chain but if you think about it on a on a one level higher if you have a chain that trusts another chain implicitly trusts like for example the same governance model controls both of them right and that then that other chain that you trust could be an intermediary for you to communicate with the change that you don't trust completely like for example you have popular in ethereum right pocketed in theorem right now don't have any trust and will probably never have trust they are completely different consensus protocols right and they shouldn't have trust between each other but pocket does trust um something like a statement which is an asset para chain it is controlled by the same governance that controls polkadot so it is trusted and in that case what you can have you can have transactions between pocketed and ethereum that Leverage The this intermediary trusted chain call statement as a reserve back right so um you're believing that when ethereum says oh yeah this this ether is actually been moved from this account to this account you actually believe them because they actually have those reserves on a on a third party trusted chain and so from that model you can now build trustless bridges for example now I want to go back to the the the the main thing here and and if you truly believe in the multi-chain future which I'm guessing most of us do because I haven't seen a lot of Bitcoin maxes at this conference um if you if you do believe in that future the true potential of that future needs to happen by leveraging shared security what is the alternative alternative is that we have new chains being launched that have a sufficient Economic Security but who can who can have that today there's people like sui right Aptos so massive amounts of VC money that were poured into projects that solve problems uh completely valid problems but it is the VCS then that control what our web3 future looks like it's VCS and established chains right like if an established chain creates a side chain like midnight or something um what would that be that would be leveraging the the ecosystem that you already built the community of people that you already built and telling them hey trust us on on this as well right but what if you're new to the to the ecosystem and you just want to have your own cool new botting hybrid hybrid chain f chain solution that you think will kill it right um and you don't necessarily have the VC backing but you do have the knowledge of just like doing it yourself then I think for those people the people that we used to be when we started this um the shared security is the thing that actually bridges that Gap security is um a topic that is gaining a lot of popularity right now there are other projects that I haven't mentioned here that are trying to do something similar I was limiting myself to what I call true shared security meaning that something like Cosmos zones or subnets in avalanche I believe are not part of this presentation because the validator said that secures those transactions are not the same as the one that secures the main net so the underlying mainnet so I just focused on those also I didn't talk a lot uh too much about bridges because again when you have a bridge between the two chains what you're actually doing is you're lowering the security of both of those chains to the one that has the lowest security right that's that's how bridges work um and yeah so I'm talking here about um like shared Security in the context of the underlying chain actually securing um all the transactions and uh I guess I guess that's it um thank you I think um this is uh has been something I've been thinking about for a while and a lot of people in in parody have so yeah do you have any questions or something uh hi there thanks for the wonderful presentation thank you I have uh like a few questions uh coming from like the different Community like we're here from ethereum uh can you explain to us like how paulot really uh uses the share security concept because like in ethereum and roll ups you have the entire layer one validating like um holding the call data or in the case an optimistic roll up or validating the validity proof and of course later it's planned that uh the layer one can also be like a censorship resistance layer meaning if you get censored on a layer to roll up you can always exit the roll up through uh L1 transaction sure so are there similar plans in polkadot and uh how does the entire uh relay chain validate um no okay so that that would be a little bit unfeasible and wouldn't be actually the The Innovation that we're talking about right um it's basically the pair chains are shards they are um logic shards and because we we have this uh sharding there is a subset of validators so their validators are validating all the blocks on the polka dot and then there's a subset of validators that are called uh pair chain validated subset something like that and then they are and they are chosen at every era randomly which means that it is technically the whole validator set that that validates every uh parachain because you'd never know are you going to be selected to validate a parenting or not so they're randomly selected into the subset and then assigned each to each exec execution core which in uh our sense means um a pairing slot right and they're assigned randomly in pairs to or in tweezer fives or I think to each uh purchase slot and then those are validated and those are accepted as true in the chain because of the true randomization of everything and they're changed all the time okay so that means if an attacker gets lucky and is somehow picked to validate his nodes are picked to validate one pirate chain he can essentially push whatever he wants you have to have five validators being lucky at the same time but it's out of out of 300. so the the yeah but in that case like um there isn't like a fallback mechanism where you can dispute yes there are disputes yes yes the five validators yeah yeah we have uh disputes in in place right uh dispute is something that we actually released with the like disputes are something that we continuously release it's an evolving thing like there's time disputes there's um um uh disputes on between the two collators themselves um uh who are securing the the pair teams themselves so um as as we go along like we're increasing that um that aspect of the security but the disputes are actually I don't know 100 000 lines of code that you never expect to be executed but they're there yeah okay and um anybody can raise a dispute and then when you raise a dispute then um you get other people validating everybody validating and then you can get slashed it's a similar mechanism that I think arbitrum has I think um it's just on a scale of actual undermined finality in that two weeks but for that like dispute you would need like a lot of data so I don't know how you guys do like data availability on the on the relay chain or yeah I mean the the data availability in pocketed is um as as I mentioned before like the our povs are are huge and like that that's kind of the drawback of having the system because data needs to be available we do something called Erasure coding which makes sure that there's always one third of all the data in each validator so they can actually any two validators can complete uh all the data sets all the data together and what about censorship like what if the pirate chain sensors me like can I somehow exit the pirate chain through the relay chain or how do you tackle that problem so so before before Stefan um answers is there any more questions just so we can there's one um anyone else just so we make it a little bit more fair um if we end up with some more time we'll get I mean we can we can sorry can we get can we get a microphone here please those are those were really amazing questions yeah yeah really really good hey Stefan uh thanks for presentation uh what's uh the state of development uh uh Bridge of polkadot and ethereum and uh what's the case uh what's the problem with this bridge because it's it is developing a rather [Laughter] thank you for the question uh it's it's really nice I'll I'll I'll I'll do it really quickly so um developing what we are interested in in parity obviously there are bridges between popular and ethereum they're just trusted Bridges and they're usually using Moonbeam or some other prior chains as um um as kind of Transport what we are trying to develop in parity with other uh common good uh providers is what we call a trustless bridge and I know this will trigger some people trust minimized in that case uh Bridge which actually is a like line Bridge right so we're developing a like climb bridge that understands xcm so cross messaging across consensus messaging format that we developed we are now teaching it to ethereum through a smart contract um there is on ethereum uh um like client there is a like client of ethereum on polka dot and they're the ones um actually communicating through relayers um right now I would say more than 80 or 90 of the code is is done we're going to do it in two stages so what we're talking about for a wider audience maybe is what we called common good uh infrastructure or um we rename them into system infrastructure so this means that we do have functionality and power chains on polka dot that don't have their own token that are actually controlled by the same governance um that therefore they are trusted so we have this bridge Hub parity which will host bridge to kusama bridge to ethereum which Bitcoin potentially in the future and some other stuff um so um for for that we are going to first launch uh Summer Bridge which is coming up I think in the next two months and then right after that is going to be ethereum I don't want to make any promises on a stage where I'm recorded but I would expect Q3 everything you say again will be yes so we we are out of the time but I am having the questions so can we get back to um that question over there if Stefan yeah sure yeah that's fine question was about censorship so how do you prevent it like in the polka dot ecosystem on a pirate chain uh so censorship on a parachain would can you be more specific uh what do you mean by understanding like their call letters or how do you call them and they produce blocks that are later validated by a subset of the really chain validators what happens if for some reason I get censored by those callers uh that's the parenting protocol disputes you can raise that as a dispute and then uh validators are actually going through the the parenting block validators of polkadot are actually going to go through a transaction of of the parenting block and try to validate every single one of them and so um so in in that case um you uh wouldn't be like you wouldn't be incentivized to do that because collages also have uh slashing yeah but I wouldn't find my transaction in the block because the quality didn't include it in the blog that they produced it's somewhere in the mempool I don't think that is um I I don't know maybe we can talk a little bit afterwards and I we can go a little bit more in detail so I can understand your question absolutely like if anyone has any more questions or wants to meet up with Stefan afterwards um you can meet him up in the lobby after the talk and once again thank you Stefan for an amazing time and give it up for Stefan please thank you guys cheers [Applause]
Automatic transcript — names and jargon may be misspelled.