How unit 2 is examined
This unit covers how Bitcoin works end to end and the consensus schemes behind it; marks sit on Proof of Elapsed Time (with Byzantine and digital signature), Proof of Work, coin creation, double spending and HashCash vs Bitcoin PoW.
Creation of coins
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Low weight</span>
Definition. <mark>Bitcoin is the first application of blockchain: a peer-to-peer digital cash whose transactions are grouped into blocks, chained by hashes, and whose new coins are created only as the mining reward.</mark>
Key points.
- Bitcoin uses a blockchain as its public ledger; each block holds many transactions and the hash of the previous block, so history cannot be altered.
- A user signs a transaction, which is broadcast and waits in the mempool of every node.
- Miners pick transactions from the mempool, build a block and solve the PoW puzzle; the winner adds the block and receives the block reward (coinbase transaction, 3.125 BTC since April 2024) plus fees.
- Other nodes verify the block, and after about 6 confirmations the coins are treated as final.
Steps of creation. Transaction, mempool, mining, reward (coinbase), confirmation.
Asked: [7 marks] (May 2024) How Bitcoin related with blockchain? Write the various steps of creation in Coins.
Payments and double spending
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Low weight</span>
Definition. <mark>Double spending is spending the same digital coin twice, possible because digital data can be copied; Bitcoin prevents it with a public ledger, consensus and confirmations.</mark>
Key points.
- Physical cash cannot be copied but a digital file can, so digital cash needs a trusted party or a consensus to reject the second spend.
- Bitcoin uses the UTXO model: each transaction consumes unspent outputs once, and every node rejects any input already spent.
- Miners order transactions in blocks by PoW, so only one of two conflicting transactions is confirmed; waiting for 6 confirmations makes reversal very unlikely.
- Double spending is still possible if an attacker controls over 50 percent of hash power (51% attack), wins a race between two conflicting transactions when the merchant accepts zero confirmations, or uses a Finney attack (a miner pre-mines a block containing the conflicting transaction).
Asked: [7 marks] (May 2024) What is Double Spending? Is it possible to double spend in a Blockchain system.
Bit coin Scripts
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>
Definition. <mark>Bitcoin Script is a simple, stack-based, non-Turing-complete language in which every output states the conditions needed to spend it.</mark>
Key points.
- Each transaction output holds a locking script (scriptPubKey) and each input supplies an unlocking script (scriptSig).
- The scripts run on a stack; the spend is valid only if the final top value is true.
- The standard P2PKH script checks a public key hash and a signature using OP_DUP, OP_HASH160, OP_EQUALVERIFY and OP_CHECKSIG.
- It has no loops, which prevents infinite execution; multisig and time-locks are also built from it.
Bit coin P2P Network
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>
Definition. <mark>The Bitcoin network is a peer-to-peer overlay of equal nodes, with no central server, that relays transactions and blocks by gossip.</mark>
Key points.
- A new node finds peers through DNS seeds and then connects to about 8 outgoing peers.
- Full nodes store the whole chain and validate everything; lightweight (SPV) nodes store only block headers.
- Every node forwards valid transactions and blocks to its neighbours (flooding), so news reaches the network in seconds.
- Nodes are anonymous and may join or leave freely, so the network is open and fault tolerant.
Transaction in Bit coin Network
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>
Definition. <mark>A Bitcoin transaction transfers value by consuming inputs (earlier unspent outputs) and creating new outputs, and is authorised by a digital signature.</mark>
Key points.
- Each input refers to a previous output by transaction ID and index and carries the owner's signature.
- Each output states an amount and a locking script for the new owner.
- Fee = total inputs minus total outputs, and it goes to the miner.
- Nodes check the signature, that inputs are unspent and that inputs are at least outputs, then relay the transaction to the mempool.
Block Mining
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>
Definition. <mark>Mining is the process by which nodes collect transactions into a block and repeatedly hash the header until it is below the target, earning the reward for adding the block.</mark>
Key points.
- The miner selects mempool transactions (highest fee first) and adds a coinbase transaction paying itself.
- It builds the Merkle root of the transactions and puts it in the block header with previous hash, timestamp, bits and nonce.
- It changes the nonce until SHA-256(SHA-256(header)) is below the target.
- The first miner to succeed broadcasts the block and collects reward plus fees.
Block propagation and block relay
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>
Definition. <mark>Block propagation is the spreading of a newly mined block to all nodes, each of which validates it before relaying it.</mark>
Key points.
- The miner announces the block with an inv message; peers request it with getdata and receive it.
- Each node validates the block before forwarding it, which stops invalid blocks spreading.
- Compact block relay sends only short transaction IDs because peers already hold most transactions in their mempool, cutting delay.
- Slow propagation causes forks (orphan or stale blocks) and favours large miners, so speed matters.
Distributed consensus in open environments
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>
Definition. <mark>In an open environment anyone can join anonymously, so consensus cannot rely on known identities and must be based on a scarce resource such as computation or stake.</mark>
Key points.
- Classical protocols (Paxos, PBFT) need a known, fixed set of nodes and fail against Sybil attacks where one party fakes many identities.
- Open systems tie voting power to a costly resource (hash power in PoW, coins in PoS), not to the number of identities.
- Agreement is probabilistic: the chance of reversal falls as more blocks are added.
- Nodes follow the rule of the longest (heaviest) valid chain.
Consensus in a Bitcoin network
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>
Definition. <mark>Nakamoto consensus is agreement on one ledger by every node following the longest valid chain, where blocks are made costly by proof of work.</mark>
Key points.
- Nodes independently validate transactions and blocks against the same rules.
- Miners compete with PoW, and the winner's block becomes the next block.
- Temporary forks are resolved when one branch becomes longer and the other is orphaned.
- Incentives (reward and fees) make honest mining more profitable than attacking, as long as honest miners hold over 50 percent of hash power.
Proof of Work (PoW) - basic introduction
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Medium weight</span>
Definition. <mark>Proof of Work is a consensus method in which a miner must find a nonce so that the hash of the block header is below a target; the work is hard to do but easy for everyone to verify.</mark>
Diagram. <figure class="ds-fig" style="margin:1.4rem 0;overflow-x:auto"><svg xmlns="http://www.w3.org/2000/svg" id="dsfig-u2-01" viewBox="0 0 596 80" width="596" height="80" role="img" aria-label="PoW flow. Tx = collect transactions, Blk = build block header, Non = search nonce until hash < target, Bc = broadcast block, Ver = nodes verify and append"><style>#dsfig-u2-01 .e{stroke:#454C5A;stroke-width:1.4;fill:none}#dsfig-u2-01 .e.hi{stroke:#2340B8;stroke-width:2.6}#dsfig-u2-01 .n{fill:#FFFFFF;stroke:#16181D;stroke-width:1.4}#dsfig-u2-01 .n.hi{fill:#E3E9FC;stroke:#2340B8;stroke-width:2.2}#dsfig-u2-01 .n.rb-b{fill:#16181D;stroke:#16181D}#dsfig-u2-01 .n.rb-r{fill:#BD3227;stroke:#BD3227}#dsfig-u2-01 text{font-family:"JetBrains Mono",ui-monospace,Menlo,Consolas,monospace;font-size:13px}#dsfig-u2-01 .t{fill:#16181D;font-weight:500}#dsfig-u2-01 .t.inv{fill:#FFFFFF;font-weight:700}#dsfig-u2-01 .kd{stroke:#16181D;stroke-width:1.2}#dsfig-u2-01 .dot{fill:#16181D}#dsfig-u2-01 .ann{fill:#2340B8;font-size:11px;font-weight:700}#dsfig-u2-01 .lbl{fill:#6F7787;font-family:system-ui,-apple-system,sans-serif;font-size:12px;font-weight:700}#dsfig-u2-01 .ptr{fill:#2340B8;font-size:12px;font-weight:700}#dsfig-u2-01 .ah{fill:#454C5A}#dsfig-u2-01 .ah.hi{fill:#2340B8}#dsfig-u2-01 .wl rect{fill:#FFFFFF;stroke:#DCE0E7}#dsfig-u2-01 .wl .t{font-size:12px;font-weight:700}#dsfig-u2-01 .wl.hi rect{fill:#2340B8;stroke:#2340B8}#dsfig-u2-01 .wl.hi .t{fill:#FFFFFF}html.dark #dsfig-u2-01 .e{stroke:#B1B7C3}html.dark #dsfig-u2-01 .e.hi{stroke:#8FA3FF}html.dark #dsfig-u2-01 .n{fill:#161920;stroke:#E6E8ED}html.dark #dsfig-u2-01 .n.hi{fill:#1E2748;stroke:#8FA3FF}html.dark #dsfig-u2-01 .n.rb-b{fill:#E6E8ED;stroke:#E6E8ED}html.dark #dsfig-u2-01 .n.rb-r{fill:#FF7E71;stroke:#FF7E71}html.dark #dsfig-u2-01 .t{fill:#E6E8ED}html.dark #dsfig-u2-01 .t.inv{fill:#0F1115}html.dark #dsfig-u2-01 .kd{stroke:#E6E8ED}html.dark #dsfig-u2-01 .dot{fill:#E6E8ED}html.dark #dsfig-u2-01 .ann{fill:#8FA3FF}html.dark #dsfig-u2-01 .lbl{fill:#858D9C}html.dark #dsfig-u2-01 .ptr{fill:#8FA3FF}html.dark #dsfig-u2-01 .ah{fill:#B1B7C3}html.dark #dsfig-u2-01 .ah.hi{fill:#8FA3FF}html.dark #dsfig-u2-01 .wl rect{fill:#161920;stroke:#2A2E37}html.dark #dsfig-u2-01 .wl.hi rect{fill:#8FA3FF;stroke:#8FA3FF}html.dark #dsfig-u2-01 .wl.hi .t{fill:#0F1115}</style><defs><marker id="ah2" viewBox="0 0 10 10" refX="9" refY="5" markerWidth="7" markerHeight="7" orient="auto-start-reverse"><path class="ah" d="M0,1 L9,5 L0,9 z"/></marker><marker id="ahh2" viewBox="0 0 10 10" refX="9" refY="5" markerWidth="7" markerHeight="7" orient="auto-start-reverse"><path class="ah hi" d="M0,1 L9,5 L0,9 z"/></marker></defs><path class="e" d="M59,40 L148,40" marker-end="url(#ah2)"/><path class="e" d="M188,40 L277,40" marker-end="url(#ah2)"/><path class="e" d="M317,40 L406,40" marker-end="url(#ah2)"/><path class="e" d="M446,40 L535,40" marker-end="url(#ah2)"/><circle class="n" cx="40" cy="40" r="18"/><text class="t" x="40" y="40" dy=".35em" text-anchor="middle">Tx</text><circle class="n" cx="169" cy="40" r="18"/><text class="t" x="169" y="40" dy=".35em" text-anchor="middle">Blk</text><circle class="n" cx="298" cy="40" r="18"/><text class="t" x="298" y="40" dy=".35em" text-anchor="middle">Non</text><circle class="n" cx="427" cy="40" r="18"/><text class="t" x="427" y="40" dy=".35em" text-anchor="middle">Bc</text><circle class="n" cx="556" cy="40" r="18"/><text class="t" x="556" y="40" dy=".35em" text-anchor="middle">Ver</text></svg><figcaption style="font-size:.82em;opacity:.72;margin-top:.45rem">PoW flow. Tx = collect transactions, Blk = build block header, Non = search nonce until hash < target, Bc = broadcast block, Ver = nodes verify and append</figcaption></figure>
Key points.
- Need: in a decentralised network with no trusted party, nodes must agree on one valid block, and validation must be costly to fake.
- The miner collects pending transactions and forms a candidate block header (previous hash, Merkle root, timestamp, difficulty target).
- It searches for a nonce so that $H(\text{header}) < \text{target}$; only brute force works, since a hash cannot be inverted.
- The first to find it broadcasts the block, and other nodes verify with a single hash and append it.
- Difficulty adjusts (every 2016 blocks in Bitcoin) so a block appears about every 10 minutes whatever the total hash power.
- Security: rewriting a block means redoing its PoW and all later blocks, so an attacker needs more than 50 percent of the computing power.
- Drawback: heavy electricity use and slow throughput.
Proof of Stake in one line (for Q6). Validators lock coins as stake and are chosen to propose blocks in proportion to stake; dishonesty costs slashing of the stake, so PoS uses little energy but favours the rich (see Proof of Stake below).
Answer frame. Open with the definition; draw the flow diagram; then develop steps 2-4, then difficulty and security (5-6); close with the drawback. For Q6 add one paragraph on need for validation, then PoW and PoS side by side and a 3-row comparison (resource, energy, attack cost).
Asked: [7 marks] (May 2022) Describe the process of PoW. Asked: [7 marks] (May 2024) What are some common validation techniques used in blockchain systems, such as proof-of-work and proof-of-stake?
Hash Cash PoW
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Low weight</span>
Definition. <mark>HashCash (Adam Back, 1997) is a proof-of-work stamp that fights email spam: the sender finds a string whose SHA-1 hash begins with a set number of zero bits, and Bitcoin adopted this idea.</mark>
| Point | HashCash PoW | Bitcoin PoW |
|---|---|---|
| Purpose | Stop spam and denial of service | Agree on the ledger and stop double spending |
| Puzzle | Partial hash collision (leading zero bits) on a stamp with recipient and date | Double SHA-256 of block header below a target |
| Difficulty | Fixed by the service | Adjusted every 2016 blocks |
| Incentive | None; cost is the deterrent | Block reward plus fees |
| Verified by | The single recipient | Every node in the network |
| Result | A stamp attached to a message | A block added to the chain |
Attacks on PoW are covered in the next-but-two sections below (51%, selfish mining, Sybil, eclipse, race).
Asked: [7 marks] (May 2024) Compare HashCash PoW (Proof of Work) with Bitcoin PoW. Also discuss various types of attacks on PoW.
Bit coin PoW
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>
Definition. <mark>Bitcoin PoW is the double SHA-256 hash of the 80-byte block header, which must be below the current target.</mark>
Key points.
- The header holds version, previous hash, Merkle root, timestamp, bits (target) and a 32-bit nonce.
- When the nonce space is used up, miners change the extra nonce in the coinbase or the timestamp.
- The chance of a miner winning a block equals its share of total hash rate.
- One block is targeted every 10 minutes.
Attacks on PoW and the monopoly problem
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>
Definition. <mark>Attacks on PoW try to rewrite or control the chain; the monopoly problem is the concentration of hash power in a few pools or ASIC makers.</mark>
Key points.
- 51% attack: a majority miner rewrites history and double spends.
- Selfish mining: a miner hides found blocks and releases them to waste others' work.
- Sybil and eclipse attacks: fake identities or isolating a node by controlling all its peers.
- Race attack: two conflicting transactions are sent quickly to different nodes.
- Monopoly: ASIC hardware and big pools centralise mining, defeating decentralisation.
Proof of Stake
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>
Definition. <mark>In Proof of Stake, the validator who creates the next block is chosen according to the coins it locks up as stake, not by computation.</mark>
Key points.
- Validators deposit coins as stake; larger stake means a higher chance of being picked.
- Misbehaviour is punished by slashing the stake, so cheating costs money.
- It uses far less energy than PoW and gives faster finality.
- Risks are wealth concentration ("rich get richer") and the nothing-at-stake problem.
Proof of Burn and Proof of Elapsed Time
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">High weight</span>
Definition. <mark>Proof of Burn: miners send coins to an unspendable address to earn the right to mine; Proof of Elapsed Time (PoET, Intel): each node waits a random time inside a trusted hardware enclave (SGX) and the node whose wait ends first creates the block.</mark>
Proof of Burn. Burning coins proves commitment; burnt coins are lost, which acts like buying mining "shares" and wastes no electricity.
Diagram. <figure class="ds-fig" style="margin:1.4rem 0;overflow-x:auto"><svg xmlns="http://www.w3.org/2000/svg" id="dsfig-u2-02" viewBox="0 0 510 338" width="510" height="338" role="img" aria-label="PoET lottery. N1-N3 = nodes with SGX, each draws a random wait time; the shortest wait wins and creates the block"><style>#dsfig-u2-02 .e{stroke:#454C5A;stroke-width:1.4;fill:none}#dsfig-u2-02 .e.hi{stroke:#2340B8;stroke-width:2.6}#dsfig-u2-02 .n{fill:#FFFFFF;stroke:#16181D;stroke-width:1.4}#dsfig-u2-02 .n.hi{fill:#E3E9FC;stroke:#2340B8;stroke-width:2.2}#dsfig-u2-02 .n.rb-b{fill:#16181D;stroke:#16181D}#dsfig-u2-02 .n.rb-r{fill:#BD3227;stroke:#BD3227}#dsfig-u2-02 text{font-family:"JetBrains Mono",ui-monospace,Menlo,Consolas,monospace;font-size:13px}#dsfig-u2-02 .t{fill:#16181D;font-weight:500}#dsfig-u2-02 .t.inv{fill:#FFFFFF;font-weight:700}#dsfig-u2-02 .kd{stroke:#16181D;stroke-width:1.2}#dsfig-u2-02 .dot{fill:#16181D}#dsfig-u2-02 .ann{fill:#2340B8;font-size:11px;font-weight:700}#dsfig-u2-02 .lbl{fill:#6F7787;font-family:system-ui,-apple-system,sans-serif;font-size:12px;font-weight:700}#dsfig-u2-02 .ptr{fill:#2340B8;font-size:12px;font-weight:700}#dsfig-u2-02 .ah{fill:#454C5A}#dsfig-u2-02 .ah.hi{fill:#2340B8}#dsfig-u2-02 .wl rect{fill:#FFFFFF;stroke:#DCE0E7}#dsfig-u2-02 .wl .t{font-size:12px;font-weight:700}#dsfig-u2-02 .wl.hi rect{fill:#2340B8;stroke:#2340B8}#dsfig-u2-02 .wl.hi .t{fill:#FFFFFF}html.dark #dsfig-u2-02 .e{stroke:#B1B7C3}html.dark #dsfig-u2-02 .e.hi{stroke:#8FA3FF}html.dark #dsfig-u2-02 .n{fill:#161920;stroke:#E6E8ED}html.dark #dsfig-u2-02 .n.hi{fill:#1E2748;stroke:#8FA3FF}html.dark #dsfig-u2-02 .n.rb-b{fill:#E6E8ED;stroke:#E6E8ED}html.dark #dsfig-u2-02 .n.rb-r{fill:#FF7E71;stroke:#FF7E71}html.dark #dsfig-u2-02 .t{fill:#E6E8ED}html.dark #dsfig-u2-02 .t.inv{fill:#0F1115}html.dark #dsfig-u2-02 .kd{stroke:#E6E8ED}html.dark #dsfig-u2-02 .dot{fill:#E6E8ED}html.dark #dsfig-u2-02 .ann{fill:#8FA3FF}html.dark #dsfig-u2-02 .lbl{fill:#858D9C}html.dark #dsfig-u2-02 .ptr{fill:#8FA3FF}html.dark #dsfig-u2-02 .ah{fill:#B1B7C3}html.dark #dsfig-u2-02 .ah.hi{fill:#8FA3FF}html.dark #dsfig-u2-02 .wl rect{fill:#161920;stroke:#2A2E37}html.dark #dsfig-u2-02 .wl.hi rect{fill:#8FA3FF;stroke:#8FA3FF}html.dark #dsfig-u2-02 .wl.hi .t{fill:#0F1115}</style><defs><marker id="ah3" viewBox="0 0 10 10" refX="9" refY="5" markerWidth="7" markerHeight="7" orient="auto-start-reverse"><path class="ah" d="M0,1 L9,5 L0,9 z"/></marker><marker id="ahh3" viewBox="0 0 10 10" refX="9" refY="5" markerWidth="7" markerHeight="7" orient="auto-start-reverse"><path class="ah hi" d="M0,1 L9,5 L0,9 z"/></marker></defs><path class="e" d="M56.3,49.8 L237,158.2" marker-end="url(#ah3)"/><path class="e" d="M59,169 L234,169" marker-end="url(#ah3)"/><path class="e" d="M56.3,288.2 L237,179.8" marker-end="url(#ah3)"/><path class="e" d="M274,169 L449,169" marker-end="url(#ah3)"/><g class="wl"><rect x="310.6" y="160" width="103.8" height="18" rx="9"/><text class="t" x="362.5" y="169" dy=".35em" text-anchor="middle">shortest_wait</text></g><circle class="n" cx="40" cy="40" r="18"/><text class="t" x="40" y="40" dy=".35em" text-anchor="middle">N1</text><circle class="n" cx="40" cy="169" r="18"/><text class="t" x="40" y="169" dy=".35em" text-anchor="middle">N2</text><circle class="n" cx="40" cy="298" r="18"/><text class="t" x="40" y="298" dy=".35em" text-anchor="middle">N3</text><circle class="n" cx="255" cy="169" r="18"/><text class="t" x="255" y="169" dy=".35em" text-anchor="middle">SGX</text><circle class="n" cx="470" cy="169" r="18"/><text class="t" x="470" y="169" dy=".35em" text-anchor="middle">Win</text></svg><figcaption style="font-size:.82em;opacity:.72;margin-top:.45rem">PoET lottery. N1-N3 = nodes with SGX, each draws a random wait time; the shortest wait wins and creates the block</figcaption></figure>
PoET key points.
- Every node runs code inside Intel SGX (Software Guard Extensions), a trusted execution environment that cannot be tampered with.
- Each node requests a random wait time from the enclave and sleeps for that time, so it uses almost no CPU.
- The first node to wake up wins the lottery and proposes the next block, and the enclave issues a signed proof that it really waited.
- Other nodes verify the attestation, which is cheap, and accept the block.
- It is a fair lottery, energy-efficient and suits permissioned (Hyperledger Sawtooth) networks; the weakness is trust in Intel hardware.
b) Byzantine algorithm. <mark>A Byzantine fault tolerant algorithm lets a system reach agreement even when some nodes fail or act maliciously (arbitrarily).</mark> With $n$ nodes it tolerates $f$ faulty ones if $n \ge 3f+1$; honest nodes exchange messages, vote and accept the value backed by a majority (for example PBFT). It solves the Byzantine Generals problem.
c) Digital signature. <mark>A digital signature is a value computed from a message and the signer's private key, which anyone can verify using the public key.</mark>
- Keys: the signer holds a private key and publishes the public key.
- Signing: hash the message and encrypt the hash with the private key; send message and signature.
- Verification: the receiver decrypts the signature with the public key, hashes the message and compares the two hashes.
- A match proves authenticity, integrity and non-repudiation (Bitcoin uses ECDSA).
Answer frame. Write three parts a), b), c) as separate mini-answers of about 4-5 lines. For a) give the definition, then n >= 3f+1; for b) draw the PoET lottery diagram and mention SGX; for c) give the sign and verify steps with the two hash comparison. Close each with one use in blockchain.
Pitfall: Do not say PoET needs mining hardware; its whole point is to replace computation with a trusted random wait.
Asked: [14 marks] (May 2024) Explain the following term: a) Byzantine algorithm b) Proof of Elapsed Time c) Digital signature
The life of a Bitcoin Miner
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>
Definition. <mark>A miner repeatedly listens for transactions and blocks, builds a candidate block, hashes for a valid nonce, and either wins the reward or restarts on the new chain tip.</mark>
Key points.
- The miner runs a full node, validates incoming transactions and keeps them in its mempool.
- It builds a block with a coinbase transaction and hashes with ASIC hardware.
- If it hears of a valid block from someone else first, it drops its work and starts on top of that block.
- Rewards halve every 210,000 blocks (about 4 years), so fees become more important over time.
Mining Difficulty
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>
Definition. <mark>Mining difficulty is how hard it is to find a hash below the target, and it is adjusted every 2016 blocks to keep the block time near 10 minutes.</mark>
Formula. $$\text{New difficulty} = \text{Old difficulty} \times \frac{2016 \times 10\ \text{min}}{\text{actual time for last 2016 blocks}}$$
Key points.
- The target time for 2016 blocks is 20,160 minutes (2 weeks).
- If blocks came in 1 week, difficulty doubles; if in 4 weeks, it halves.
- A single adjustment is limited to a factor of 4 up or down.
- Lower target means more leading zeros and a higher difficulty.
Mining Pool
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>
Definition. <mark>A mining pool is a group of miners who combine hash power and share the reward in proportion to the work each contributes.</mark>
Key points.
- A solo miner with small hash power may wait years for a block, so pools give steady small payouts.
- The pool manager hands out work; miners submit shares (hashes meeting an easier target) as proof of effort.
- Reward is split by share count (schemes such as PPS and PPLNS) after a pool fee.
- Large pools threaten decentralisation because a pool near 51 percent could attack the chain.
Last-minute revision
- Bitcoin is the first blockchain application; coin creation = transaction, mempool, mining, coinbase reward, confirmation.
- Double spending = spending one coin twice; prevented by UTXO, PoW consensus and 6 confirmations; possible by 51%, race or Finney attack.
- Bitcoin Script is stack-based with no loops; P2PKH uses OP_DUP, OP_HASH160, OP_EQUALVERIFY, OP_CHECKSIG.
- Block header: version, previous hash, Merkle root, timestamp, bits, nonce.
- PoW: find nonce so header hash is below target; hard to find, easy to verify.
- Difficulty changes every 2016 blocks; block time is 10 minutes; reward halves every 210,000 blocks (3.125 BTC now).
- HashCash (Adam Back) was anti-spam with no reward; Bitcoin PoW has adjusted difficulty and rewards.
- PoW attacks: 51%, selfish mining, Sybil, eclipse, race.
- PoS chooses validators by stake and slashes cheaters; PoB burns coins; PoET uses SGX random wait.
- BFT tolerates f faults if n is at least 3f+1.
- Digital signature: sign the hash with the private key, verify with the public key.
Memory hooks
- Coin creation: "T-M-M-R-C": Transaction, Mempool, Mining, Reward, Confirmation.
- Double spend attacks: "51, Race, Finney".
- PoW = Work, PoS = Stake, PoB = Burn, PoET = wait (lottery in SGX).
- 2016 blocks x 10 min = 2 weeks.
- Sign with private, verify with public.
Coverage checklist
- Creation of coins: Q2.
- Payments and double spending: Q4.
- Bit coin Scripts: no past question.
- Bit coin P2P Network: no past question.
- Transaction in Bit coin Network: no past question.
- Block Mining: no past question.
- Block propagation and block relay: no past question.
- Distributed consensus in open environments: no past question.
- Consensus in a Bitcoin network: no past question.
- Proof of Work (PoW) - basic introduction: Q5, Q6.
- Hash Cash PoW: Q3.
- Bit coin PoW: no past question.
- Attacks on PoW and the monopoly problem: covers the attacks part of Q3.
- Proof of Stake: supports Q6.
- Proof of Burn and Proof of Elapsed Time: Q1.
- The life of a Bitcoin Miner: no past question.
- Mining Difficulty: no past question.
- Mining Pool: no past question.