SearcharxivSearch

arXiv subjects

Benjamin Marsh

Publications and source records attributed to Benjamin Marsh.

14 recordsLinked to original sources

Finality Before Disclosure for Ledger Authenticators in the Quantum Random Oracle Model

Public ledgers increasingly authorize state transitions using prior transactions, finalized state, timing, and ordering rather than only a public key, message, and portable signature. We introduce ledger authenticators and $\LAEUF$, an unforgeability experiment for reactive authorization protocols whose public judgment algorithm reads a finalized transcript. The model separates authentication safety from ledger liveness and captures canonical transition freshness, adaptive corruption, exposure before inclusion, censorship, and adversarial ordering. We identify two conditional resource boundaries. An authenticator satisfying our single event conditions yields a contextual one-time signature. Within our rebindable reveal class, safety requires computational post-disclosure non-admissibility. When precursor admission uses only public computation and ledger scheduling, this condition is enforced by closing the evidence eligible to use a disclosed credential. If newly constructed evidence remains admissible after disclosure, censoring the honest reveal gives a forgery. We then define a joint ledger and quantum random oracle execution model in which quantum state persists across classical finalization cuts and oracle evaluations made through the ledger are charged. For a closed finalized target set of size at most $K$, we prove the bound $3\beta_{\mathsf{cut}}^2+3c_{\mathsf{co}}KQ^2/2^\lambda+6\ell/2^\lambda$, where $\beta_{\mathsf{cut}}$ accounts for fresh openings already present at the cut. A commit, close, reveal authenticator instantiates the framework and obtains a multi-user lifetime QROM bound.

cs.CR

Cyclic Shuffle Groups: Universal Two-Transitivity and Complete Classification

Let \(k\geq 3\), \(n\geq 1\), and let \(H_{k,n}=\Sh(C_k,n)\) be the group generated by the standard \(k\) pile perfect shuffle and cyclic pile permutation on a deck of \(kn\) cards. We prove that \(H_{k,n}\) is \(2\)-transitive whenever \(n\) is not a power of \(k\). Residual commutators give translations supported on two pile labels, and a strongly connected digit digraph propagates these translations throughout the deck, a separate argument resolves the antipodal support case. We then combine this result with fixed point ratio bounds for primitive groups and explicit boundary calculations to determine \(H_{k,n}\) for all \(k\) and \(n\). If \(n=k^f\), then \(H_{k,n}\cong C_k\wr C_{f+1}\). If \(k=4\) and \(n=2\cdot4^j\), then \(H_{4,n}\cong\AGL(2j+3,2)\). In every other case, \(H_{k,n}\) is \(\Alt(kn)\) or \(\Sym(kn)\), according to the parity of its generators. This proves Conjecture~1.10 of Amarra, Morgan and Praeger and Conjecture~5.1 of Xia, Zhang, Zhang and Zhu. More generally, we classify \(\Sh(P,n)\) for every pile group \(P\) containing \(C_k\), and obtain the odd \(k\) part of their Conjecture~5.2.

math.CO

Reveal, Correct, Then Pay: Encrypted Mempools and Perpetual Funding Security

Encrypted mempools are designed to hide transaction contents until execution order is fixed, preventing many victim dependent forms of maximal extractable value. This paper studies a different class of attack in the form of self-authored state manipulation, in which the attacker knows its own transaction and owns a downstream claim on the state that transaction changes. Perpetual futures funding is a canonical example. The funding signal determines a transfer rate, while receiving side open interest is the transfer base. In a commit then reveal mempool, an adaptive corrective transaction cannot enter the already committed batch. Privacy can therefore create an economic reaction gap even when cryptographic decryption overhead is negligible. We microfound correction through executable arbitrage opportunities. Correctors choose order size against local price impact and inventory cost, while the protocol information schedule determines which opportunities are actionable. The ordering barrier removes ordinary adaptive searchers from the closed stage. It therefore yields a closed stage correction rate below the adaptive correction rate whenever positive adaptive capacity becomes available after reveal. The distortion entering a funding window is multiplied by an explicit response factor. Transaction privacy can also reduce capitalization of predictable funding into entry prices, producing a second amplification channel. The resulting local security index separates attacker blindness, correction shielding, and capitalization shielding.

cs.CR

Slack and Budget Breaking in Threshold Team Production

A threshold system completes a public task only after $\kappa$ verifiable shares are publicly committed. If the honest schedule creates \( \Nstar=\kappa+\Delta \) share opportunities by deadline $t^\star$, then $\Delta$ shares are slack such that a coalition delays completion if and only if it withholds at least $\Delta+1$ shares. The incentive problem is therefore to price the cheapest sabotage set. Agents receive a direct fee $f$ per committed share. A delaying coalition may also obtain delay value at most $L$, and may earn additional fee revenue during recovery after the deadline. Let $R_1^+$ be a pathwise upper bound on the coalition's incremental fee revenue in a recovery slot that completes the task, including any same-slot overshoot. The principal can post a nonnegative completion bounty that depends only on committed shares, uses no deposits or punishments, and expires if completion is late. The optimal rule is uniform, as if completion occurs by $t^\star$, every admissible horizon share receives $B/\Nstar$, otherwise no bounty is paid. Full participation is ex-post strongly delay proof exactly when \( (\Delta+1)f+\frac{\Delta+1}{\Nstar}B \ge L+R_1^+ . \) Equivalently, the exact worst-case budget is \( B^\star = \frac{\Nstar}{\Delta+1} \bigl(L+R_1^+-(\Delta+1)f\bigr)^+ . \) The bound is tight for every nonnegative completion measurable bounty, among the $\Nstar$ horizon shares, some $\Delta+1$ receive total bounty at most $(\Delta+1)B/\Nstar$, and withholding precisely those shares delays completion. The result applies to threshold signatures, data availability certification, coded dissemination, and generic $k$-of-$n$ completion tasks. We also isolate a separate limit, no transfer rule based only on completed shares can remove a final slot race in which a coalition has already observed enough pre-completion shares to act.

cs.GT

Ambulance: saving BFT through racing

Today's practical Byzantine Fault Tolerant (BFT) state machine replication deployments are vulnerable to slowdowns. The main culprit is timeouts. Aggressive timeouts spuriously trigger expensive leader changes, while conservative timeouts leave the system idle and let slowdowns severely inflate latency. Two main alternatives exist: hedging, which improves recovery from slow leaders but still incurs a time-based hedging delay, and cooperative asynchronous protocols, which recover quickly from slowdowns but suffer from high common-case latency and low throughput. This paper presents Ambulance: a BFT state machine replication protocol that sidesteps this trade-off through protocol-rigged races, where replicas, rather than race against the clock, race against each other by executing protocol steps. This enables Ambulance to achieve high throughput and low latency comparable to state-of-the-art timeout-based BFT, while matching the robustness of cooperative approaches.

cs.DC

SNARE: A TRAP for Rational Players to Solve Byzantine Consensus in the 5f+1 Model

The TRAP protocol solves rational agreement by combining accountable consensus with a one-shot BFTCR finalization phase. We present SNARE (Scalable Nash Agreement via Reward and Exclusion), the adaptation of TRAP to $n=5f{+}1$, and prove $\epsilon$-$(k,t)$-robustness for rational agreement tolerating coalitions up to ${\approx}73\%$ with deposits under $0.5\%$ of the gain. A central finding is that appending a single all-to-all broadcast round with the $4f{+}1$ threshold after predecisions yields $\epsilon$-$(k,t)$-robustness for coalitions up to $3f$ (${\approx}60\%$) without any deposit: we need not model or know the utility function of deviating players, only that they participate in the protocol. These players can be \emph{deceitful} (arbitrary unknown utility), not just rational, and the finalization structure prevents disagreement regardless of their motivation. This observation is protocol-agnostic, applies to any $5f{+}1$ protocol at the cost of one message delay that runs concurrently with the next view, and does not require commit-reveal mechanisms. Above $60\%$, the full baiting mechanism with deposits under $0.5\%$ extends tolerance to ${\approx}73\%$. A second finding is that valid-candidacy, the property preventing reward front-running, holds unconditionally regardless of the quorum threshold, removing both the $n>2(k{+}t)$ and $n>\frac{3}{2}k{+}3t$ constraints from the original TRAP. This retroactively extends the $3f{+}1$ bound from $C<n/2$ to $C<5n/9$. The binding constraint in both models is the winner consensus operating on $2f$ residual players after excluding $3f{+}1$ detected equivocators. We explore avenues for relaxing this limit.

cs.GT

Meeting in the Middle: A Co-Design Paradigm for FHE and AI Inference

Modern cloud inference creates a two sided privacy problem where users reveal sensitive inputs to providers, while providers must execute proprietary model weights inside potentially leaky execution environments. Fully homomorphic encryption (FHE) offers cryptographic guarantees but remains prohibitively expensive for modern architectures. We argue that progress requires co-design where specializing FHE schemes/compilers for the static structure of inference circuits, while simultaneously constraining inference architectures to reduce dominant homomorphic cost drivers. We outline a meet in the middle agenda and concrete optimization targets on both axes.

cs.CR

A mechanism design overview of Sedna

Sedna is a coded multi-proposer consensus protocol in which a sender shards a transaction payload into rateless symbols and disseminates them across parallel proposer lanes, providing high throughput and ``until decode'' privacy. This paper studies a sharp incentive failure in such systems. A cartel of lane proposers can withhold the bundles addressed to its lanes, slowing the chain's symbol accumulation while privately pooling the missing symbols. Because finalized symbols become public, the cartel's multi-slot information lead is governed by a chain level delay event where the chain fails to accumulate the $\kappa$ bundles needed for decoding by the honest horizon $t^\star=\lceil \kappa/m\rceil$. We characterize the resulting delay probability with KL-type large deviation bounds and show a knife edge pathology when the slack $\Delta=t^\star m-\kappa$ is zero such that withholding a single bundle suffices to push inclusion into the next slot with high probability. We propose \textsf{PIVOT-$K$}, a Sedna native pivotal bundle bounty that concentrates rewards on the $\kappa$ bundles that actually trigger decoding, and we derive explicit incentive compatibility conditions against partial and coalition deviations. We further show that an adaptive sender ``ratchet'' that excludes lanes whose tickets were not redeemed collapses multi-slot withholding into a first slot deficit when $t^\star\ge 2$, reducing the required bounty by orders of magnitude. We close by bounding irreducible within slot decode races and providing parameter guidance and numerical illustrations. Our results show that for realistic parameters Sedna can reduce MEV costs to 0.04\% of the transaction value.

cs.GT

Sedna: Sharding transactions in multiple concurrent proposer blockchains

Modern blockchains increasingly adopt multi-proposer (MCP) consensus to remove single-leader bottlenecks and improve censorship resistance. However, MCP alone does not resolve how users should disseminate transactions to proposers. Today, users either naively replicate full transactions to many proposers, sacrificing goodput and exposing payloads to MEV, or target few proposers and accept weak censorship and latency guarantees. This yields a practical trilemma among censorship resistance, low latency, and reasonable cost (in fees or system goodput). We present Sedna, a user-facing protocol that replaces naive transaction replication with verifiable, rateless coding. Users privately deliver addressed symbol bundles to subsets of proposers; execution follows a deterministic order once enough symbols are finalized to decode. We prove Sedna guarantees liveness and \emph{until-decode privacy}, significantly reducing MEV exposure. Analytically, the protocol approaches the information-theoretic lower bound for bandwidth overhead, yielding a 2-3x efficiency improvement over naive replication. Sedna requires no consensus modifications, enabling incremental deployment.

cs.CR

MEV in Multiple Concurrent Proposer Blockchains

We analyze maximal extractable value in multiple concurrent proposer blockchains, where multiple blocks become data available before their final execution order is determined. This concurrency breaks the single builder assumption of sequential chains and introduces new MEV channels, including same tick duplicate steals, proposer to proposer auctions, and timing races driven by proof of availability latency. We develop a hazard normalized model of delay and inclusion, derive a closed form delay envelope \(M(\tau)\), and characterize equilibria for censorship, duplication, and auction games. We show how deterministic priority DAG scheduling and duplicate aware payouts neutralize same tick MEV while preserving throughput, identifying simple protocol configurations to mitigate MCP specific extraction without centralized builders.

cs.GT

The Algorithmic Geometry of Decompression Schedules

We cast decompression planning as hybrid optimal control with ppO$_2$ and narcotic depth feasibility, affine tissue ceilings, and convex oversaturation penalties. A rearrangement theorem gives monotone ascent for terminal objectives. Admitting excursions below the start depth breaks this, a one compartment instance with integrated oversaturation makes re-descent strictly beat every monotone profile, so monotone ascent is only an operational constraint. Without cumulative oxygen exposure the minimum inert feasible gas dominates every pure or relaxed policy along each fixed depth path, giving exact pure attainment with finitely many switches. A CNS/OTU oxygen budget is the path coupling state that restores gas choice and prevents zero inert holds, we derive its oxygen shadow price and gas switching inequality, and a risk price threshold makes no-stop ascent globally optimal. For fixed stops an exact dwell switching identity gives a forward state sweep and a backward adjoint sweep, on-gassing holds are dominated, and the one compartment problem has closed form scalarised and capped solutions. For saturation decompression rectangular uncertainty collapses to one worst case endpoint, while finite bounce exposures admit a unique strictly interior worst rate with closed form location and finitely many critical rates. Clipped oversaturation is not Markov, but full tissue vectors support safe dominance and one sided enclosures certify a hard cap. The finite menu problem is NP-hard with one tissue and has $2^m$ nondominated labels at bounded horizon, yet for fixed tissue dimension and polynomial conditioning, state compression gives an FPTAS for scalarisation and risk repair its exact cap counterpart. A frontier conjugacy theorem characterises which capped points scalarisation recovers, and worked examples match the dwell law, saturation endpoint equality, and time/risk frontier.

math.OC

A Time-Bound Signature Scheme for Blockchains

We introduce a modified Schnorr signature scheme to allow for time-bound signatures for transaction fee auction bidding and smart contract purposes in a blockchain context, ensuring an honest producer can only validate a signature before a given block height. The immutable blockchain is used as a source of universal time for the signature scheme. We show the use of such a signature scheme leads to lower MEV revenue for builders. We then apply our time-bound signatures to Ethereum's EIP-1559 and show how it can be used to mitigate the effect of MEV on predicted equilibrium strategies.

cs.CR

Sei Giga

We introduce the Sei Giga, a multi-concurrent producer parallelized execution EVM layer one blockchain. In an internal testnet Giga has achieved >5 gigagas/sec throughput and sub 250ms finality. Giga uses Autobahn for consensus with separate DA and consensus layers requiring f+1 votes for a PoA on the DA layer before consensus. Giga reaches consensus over ordering and uses async block execution and state agreement to remove execution from the consensus bottleneck.

cs.DC

Pulsar Consensus

In this paper, we informally introduce the Pulsar proof of stake consensus paper and discuss the relevant design decisions and considerations. The Pulsar protocol we propose is designed to facilitate the creation of a proof of stake sidechain for a proof of work blockchain. We present an overview of a novel composable density-based chain selection rule for proof of stake systems which can be seen as a superset of some standard existing longest chain rules for proof of stake protocols. We discuss the Pulsar protocol in comparison to existing proof of stake protocols and define its benefits over existing designs while defining the limitations of the work. Pulsar is currently implemented in the Mintlayer proof of stake Bitcoin sidechain.

cs.CR