---
res:
  bibo_abstract:
  - "The blocks in the Bitcoin blockchain \"record\" the amount of work W that went
    into creating them through proofs of work. When honest parties control a majority
    of the work, consensus is achieved by picking the chain with the highest recorded
    weight. Resources other than work have been considered to secure such longest-chain
    blockchains. In Chia, blocks record the amount of disk-space S (via a proof of
    space) and sequential computational steps V (through a VDF).\r\nIn this paper,
    we ask what weight functions Γ(S,V,W) (that assign a weight to a block as a function
    of the recorded space, speed, and work) are secure in the sense that whenever
    the weight of the resources controlled by honest parties is larger than the weight
    of adversarial parties, the blockchain is secure against private double-spending
    attacks.\r\nWe completely classify such functions in an idealized \"continuous\"
    model: Γ(S,V,W) is secure against private double-spending attacks if and only
    if it is homogeneous of degree one in the \"timed\" resources V and W, i.e., αΓ(S,V,W)
    = Γ(S,α V, α W). This includes the Bitcoin rule Γ(S,V,W) = W and the Chia rule
    Γ(S,V,W) = S ⋅ V. In a more realistic model where blocks are created at discrete
    time-points, one additionally needs some mild assumptions on the dependency on
    S (basically, the weight should not grow too much if S is slightly increased,
    say linear as in Chia).\r\nOur classification is more general and allows various
    instantiations of the same resource. It provides a powerful tool for designing
    new longest-chain blockchains. E.g., consider combining different PoWs to counter
    centralization, say the Bitcoin PoW W₁ and a memory-hard PoW W₂. Previous work
    suggested to use W₁+W₂ as weight. Our results show that using e.g., √{W₁}⋅ √{W₂}
    or min{W₁,W₂} are also secure, and we argue that in practice these are much better
    choices.@eng"
  bibo_authorlist:
  - foaf_Person:
      foaf_givenName: Mirza Ahad
      foaf_name: Baig, Mirza Ahad
      foaf_surname: Baig
      foaf_workInfoHomepage: http://www.librecat.org/personId=3EDE6DE4-AA5A-11E9-986D-341CE6697425
  - foaf_Person:
      foaf_givenName: Christoph Ullrich
      foaf_name: Günther, Christoph Ullrich
      foaf_surname: Günther
      foaf_workInfoHomepage: http://www.librecat.org/personId=ec98511c-eb8e-11eb-b029-edd25d7271a1
  - foaf_Person:
      foaf_givenName: Krzysztof Z
      foaf_name: Pietrzak, Krzysztof Z
      foaf_surname: Pietrzak
      foaf_workInfoHomepage: http://www.librecat.org/personId=3E04A7AA-F248-11E8-B48F-1D18A9856A87
    orcid: 0000-0002-9139-1654
  bibo_doi: 10.4230/LIPIcs.AFT.2025.16
  bibo_volume: 354
  dct_date: 2025^xs_gYear
  dct_isPartOf:
  - http://id.crossref.org/issn/1868-8969
  - http://id.crossref.org/issn/9783959774000
  dct_language: eng
  dct_publisher: Schloss Dagstuhl - Leibniz-Zentrum für Informatik@
  dct_title: Nakamoto consensus from multiple resources@
...
