Grin: The magic of Harry Potter?

瘾App
本文约7581字,阅读全文需要约30分钟
Grin is a recent popular privacy pass, community-driven development, relatively decentralized, its outbreak is a resurgence of the market in the field of payment and settlement when the public chain encounters bottlenecks in the short term


event


At the beginning of the new year, the coldness of the deep winter is getting stronger, and the blockchain industry and the token market, which have experienced the depression period, are still frozen. However, since the end of 2018, Grin, a privacy token, has become a long-lost hot topic in the blockchain community and has attracted widespread attention from the market. As the mainnet is about to go live, we will approach Grin with you to discuss its nature and possibilities.


text

text


1Grin: An Idealistic Privacy Token

Grin is a relatively popular privacy-attributed payment and settlement token recently, and is committed to becoming an electronic cash that is truly used in daily transactions. The project is developed by a community team, some core members are anonymous, and the pass is completely generated through mining. It is really a clear stream in the blockchain industry where project parties generally have deep routines, and it reminds everyone of the idealism of BTC back then. Grin is committed to realizing the original goal of BTC, returning to the basics, and providing the industry with an asset that is truly suitable for use as cash through privacy, convenience, and an appropriate inflation curve.

1.1 Back to basics, private electronic cash

Grin is based on the underlying protocol of MimbleWimble and has the characteristics of privacy. The underlying protocol of the Grin network, MimbleWimble, is a new encryption protocol based on elliptic curves, which creates multiple signatures for all inputs and outputs, and conducts transactions by sharing "blind factors". There is no concept of addresses, and specific information will not be disclosed to The entire network, but maintains verifiable features. The word "MimbleWimble" comes from the silence spell in "Harry Potter", which vividly reflects the nature of the agreement. Privacy is an inherent feature of cash, while traditional payment and settlement tokens such as BTC directly store the payer address, payee address, and amount on the chain, which limits its "electronic cash" function in many scenarios.

Focus on payment and settlement, relatively decentralized. Smart contracts and public chains are the focus of 2017, leading projects such as EOS have emerged, and ETH has also developed rapidly. For a long time, the blockchain industry has been seeking to realize more application scenarios, and even forked BCH from BTC. It is also developing in the direction of the public chain. However, Grin went against the trend and chose to be a pure payment and settlement token. Payment and settlement is the original function of the blockchain, and it is also one of the few real needs that has been verified. Grin's positioning is more pragmatic. However, Grin’s transaction requires cryptographic interaction between the two parties, which is quite different from BTC and other models that only need to be initiated by the payer, and does not conform to people’s usage habits. Use, such as large-scale collection, donation, etc. The development team stated that they will not limit the implementation of Grin transfers, and will provide a toolkit to facilitate developers to design new exchange solutions. At the same time, the Grin network will delete most of the transaction data, and only keep key information such as the total amount, which greatly reduces the size and operating burden of the full node, and solves the problem of PoW consensus mechanisms such as BTC and ETH due to the reduction of full node operators. Potential centralization problems caused by it, and provide high scalability.

The popularity of Grin is, to a certain extent, the exploration of the community returning to its origin when the public link encounters bottlenecks. ETH introduced the concept of smart contracts, bringing the blockchain industry from the 1.0 stage to 2.0, and the application scenarios are no longer limited to payment and settlement. Practitioners have begun to try in almost all conceivable fields. However, after the group excitement, the public chain technology has not yet broken through its bottleneck, and the practical application in many fields has also encountered setbacks. After a continuous downward cycle in 2018, a round of tide has receded, and people began to rethink the nature and development of the industry. The traditional payment and settlement field has received attention again. The prices of ETH and EOS relative to BTC are to some extent a reflection of this change . The resurgence of payment and settlement tokens has become an opportunity for the rise of the Grin project that began in 2016.

Community development, strong idealism, low degree of commercialization. Grin's development is community-driven rather than corporate-driven, and no financing is accepted, only donations. Before the mainnet went live, the team did not carry out any token distribution and pre-mining, and also stated that it would not actively seek to be listed on the exchange, and the degree of commercialization was low. On the one hand, this reduces the possibility of the project party harming the community and investors, and on the other hand, it will also hinder the promotion and application of Grin to a certain extent.

1.2 Linear supply, gradually reducing inflation

Grin tokens are fully mined, one block is produced every minute, each block has a block reward of 60Grin, and the output is not decreasing. Grin is a token that uses the PoW consensus mechanism. The entire network produces one Grin per second on average, with an annual output of 31.536 million. The total amount is in a state of linear growth and there is no upper limit. This mechanism is significantly different from the production reduction mechanism of PoW tokens such as BTC, and is a non-deflationary economic model. Core developer Michael Cordner “Yeastplume” explained that they designed this mainly to prevent early miners from benefiting significantly more than later miners, and hope that Grin can really become a medium of exchange rather than a tool for value storage or speculation.

The system has a high inflation rate in the early stage, and it will gradually decrease in the later stage. Grin grows at a fixed rate, so the inflation rate of the system decreases as the total size increases. Starting from the second year, the inflation rate in the Nth year is 1/(n-1), which is an inverse proportional function. When N is large enough, the inflation rate will approach 0.


This monetary policy is conducive to the stability of Grin's value and can help it be used more as a trading medium. Traditional digital tokens such as BTC generally have an output reduction mechanism. The output is high in the early stage, but the increase will be greatly reduced in the later stage. The output curve of BTC is discontinuous, and it will be halved at a specific block height, some hardware may be eliminated, and the computing power will fluctuate to a certain extent. The price cycle of BTC is closely related to the cycle of production reduction. In addition, the production reduction model has endogenous deflation, which will stimulate people to use the corresponding token as a value storage tool or even a speculative bargaining chip, which is not conducive to the promotion as a payment and settlement tool. Grin has a high inflation rate in the early stage of rapid system scale growth. As the system scale expands and gradually stabilizes, the inflation rate also tends to be flat, which is in line with the law of ecological development and is more likely to maintain value stability. In addition, when the output is reduced below the limit precision allowed by the data structure, the BTC block reward will disappear, and the miners will completely benefit from the transaction fee, and there is no trace of the changes that will occur in the system during this process. It is more difficult to calculate, uncertainty will reduce stability, and Grin avoids this problem through highly stable return expectations.


2 Technology: Privacy Protocol and Consensus Mechanism

Grin is an open source blockchain project that implements the MimbleWimble privacy encryption protocol and uses the ASIC-resistant PoW algorithm - Cuckoo Cycle.

2.1 MimbleWimble Privacy Agreement

MimbleWimble comes from the "Tongue Curse" in the novel "Harry Potter", through which the caster "knots" the tongue of the caster to prevent him from reciting spells accurately or revealing secrets. The original white paper of MimbleWimble was published by an anonymous developer. On the basis of BTC, the anonymity of transactions was improved by hiding transaction amounts, not reusing "addresses", and merging block transactions.

Each BTC transaction has three key pieces of information: the transaction amount, the address of the transaction sender and the receiver, and the listening nodes in the network can monitor the IP of the transaction broadcaster, so that it is possible to compare the BTC address with the real physical address connect. In addition, once a certain address has made a transaction, it is easy to obtain the transaction history and balance information of this address through tools such as blockchain browsers, so the privacy of both parties to the transaction is difficult to guarantee.

MimbleWimble is like a curse applied to network transactions. It uses cryptography to make each transaction "silent", and no longer reveals these key private information.

In the BTC network, the principle for accounting nodes to judge whether a transaction should be included in the block to be packaged is usually only the legality of the transaction. In the process of verifying the legality of the transaction, the following information is exposed: the address and public key of the transaction sender (used to verify the sender’s right to use UTXO), and the transaction amount (used to verify whether the total input of the transaction is equal to the total output) , the address of the recipient of the transaction.

We know that the private key of BTC is essentially a string representation of a randomly generated large integer, and the public key is calculated based on the private key through elliptic curve encryption (ECC), and the elliptic curve algorithm is known, public Even if the key is public, it is still difficult to decipher the private key. After encrypting information with the private key, a piece of information signature can be obtained, and in the case of known public key, signature, and original information, it can be verified whether the signature is generated by the corresponding private key. This constitutes the cryptographic basis for BTC to transfer and verify transactions.

It is also easy to understand the principle of this type of encryption method, prime number multiplication is an example. Suppose a, b, c.. are several very large prime numbers, and s=abc...is their product. If s is known, it is also difficult to find out its prime factors, but it is very simple to verify whether a or b, c are factors of s, because decomposing large prime factors is difficult to achieve at the current computing level.

An elliptic curve is a function image of a class of equations on a two-dimensional plane. Addition operations can be defined between some points on this curve: P+Q=R, R is the intersection of the line P, Q and the elliptic curve with respect to the x-axis Symmetric point, P+P is defined as the symmetric point of the intersection of the tangent of P and the elliptic curve with respect to the x-axis, and thus the multiplication operation kP can be defined, which is equal to adding P to itself k-1 times (k is an integer) . The set of these points is closed to such addition operations, that is to say, the results of addition and multiplication between any points in the set are still in this set.

Although the "addition" P+Q of elliptic curve points is not the same as the addition we are familiar with, we can understand this concept through integer addition. If k is a very large integer, we can quickly calculate the value of kP=Q through some algorithms, but knowing the calculation result Q and the value of P, it is very difficult to calculate k. It can be understood that point P becomes point Q after k times of "transformation", but knowing P and Q, it is difficult to calculate how many transformations can change P into Q.

(k+j)P=kP+jP

The k in the above example is called the private key, and P is a specific point on the pre-selected specific elliptic curve, then Q=kP is the public key of the private key k on P. Elliptic curve point logarithmic multiplication operation satisfies the distributive law, namely

This feature is also called "homomorphic encryption" in cryptography, and the elliptic curve group satisfies additive homomorphism.

MimbleWimble uses a similar idea to process transaction information, using the additive homomorphic feature of elliptic curve encryption to ensure that it can still verify the legitimacy of the transaction amount without knowing the specific transaction amount.

Assuming k and j are the total input and total output of a transaction respectively, BTC ensures the legitimacy of the transaction amount by verifying k+j=0 through the plaintext transaction amount k and j, that is, it will not create money out of thin air or make money disappear. According to the "elliptic curve distribution law", only need to verify the encrypted result kP+jP=0, then it can be proved that k+j=0 without knowing the specific value.

Due to the limited value range of the transaction amount, the attacker can guess the actual transaction value by exhausting the private key. In order to ensure security and privacy, MimbleWimble also introduces a confusion factor to prevent similar exhaustive attacks. Let r be the private key of the sender (receiver), v is the input (output) of the transaction, G, H are two specific elliptic curve points, rG is the public key of r on G, vH is the public key of v on H public key.

rG+vH is called the Pedersen Commitment, and it will be the only content disclosed by both parties to the transaction. Even if G and H are known, it is difficult to guess the values ​​of r and v. The legality of the transaction can be easily verified through the Pedersen commitment, and the value range of v is verified through the Range Proof (Range Proof), that is, it cannot be negative and cannot exceed the account balance.

MimbleWimble can complete transaction verification without exposing the public keys of both parties. BTC verifies the sender's right to use UTXO and completes the transfer of the use right to the receiver by attaching the addresses of both parties to the transaction and the sender's public key.

The output of a transaction is a Pedersen commitment. If you want to spend this input again, you need to know the values ​​of r and v at the same time, otherwise the Pedersen commitment cannot be restored. The previous sender of this output knows the value of v, so both parties to the transaction must each hold a different r value (private key) that only they know, that is, the private key can be used to prove that Pedersen Ownership of a certain amount of currency contained in a commitment.

Let the private key of the sender of the transaction be r, and the sender inputs rG + vH, which proves that the sender owns the currency of v, and the receiver adds (r+k)G+vH to its own output, and the public key kG, where r+k can be a randomly generated number. In this way, the recipient generates a private key r+k that only he knows, and kG does not disclose any information about the private key and public key rG, (r+k)G of both parties. kG is considered as the signature of this transaction, together with some additional data is called the transaction core. To verify the legality of the transaction, it is only necessary to verify ((r+k)G+vH)-(rG+vH)=kG to prove the following information: the input and output amounts are equal, the sender has the right to use the currency contained in the Pedersen commitment, the The right to use the quantity currency has been transferred to the recipient.

It can be seen that the right to use an unspent transaction is bound to a specific private key, that is to say, there is no concept of address in MimbleWimble, and each transaction uses a different private key. During the process from transaction creation to confirmation, the transaction amount and the public keys of both parties are not exposed to a third party, thus ensuring the privacy of the transaction.

MimbleWimble also further hides the original information of both parties by merging intermediate transactions. The BTC blockchain information using the UTXO model records a complete transaction, so each UTXO can be traced back to the genesis block. Attackers may reveal the transaction relationship between different addresses by analyzing a large number of historical blocks, resulting in the leakage of user privacy information. MimbleWimble merges all transactions in a block, and only retains the transaction core to prove its legitimacy. On the basis of verification, it reduces the block size and enhances privacy.

However, this method is only effective when multiple transactions are included in a block, and its ability to hide transaction relationships is weaker than that of anonymous tokens such as Monero.

2.2 Cuckoo Cycle Consensus Algorithm

The PoW algorithm adopted by BTC requires bookkeeping nodes to prove that they have spent a certain amount of computing power by repeatedly evaluating the Hash function, and compete for the block production rights (booking rights) of the network according to the amount of computing power. However, with the development of ASIC mining machines, the computing power of ordinary users' computing equipment cannot compete with these professional mining equipment, which has caused the community to worry about the centralization of computing power and mining pools.

Cuckoo Cycle is a proof-of-work algorithm proposed in 2014 with the intention of achieving "more equality" and anti-ASIC mining machines, so as to realize the "decentralization" of mining equipment. Since the delay of DRAM is relatively stable compared with the rapid increase in CPU speed, and the cost is also higher, the Memory-hard algorithm that reduces the requirement for computing power and replaces it with memory capacity requirements is generally considered to be resistant to ASICs. Cuckoo Cycle is a graph-theoretic Memory-hard algorithm that requires storage of a large amount of intermediate states during the calculation process. After the main network is launched, the equipment must have at least 6G video memory before mining.


The Grin testnet is currently running two modes of PoW: the ASIC-friendly major mode Cuckatoo31+, and the ASIC-resistant minor mode Cuckatoo29. In the initial mining, the main algorithm will mine 10% of the blocks, and the other blocks will be produced by the secondary algorithm. As the mining progresses, 100% of the blocks will be produced by the main algorithm. Although the main algorithm is ASIC-friendly, none of the current ASIC mining machines support the mining of this algorithm, so this design of Grin may be to motivate chip manufacturers to design ASIC mining machines for their main algorithm.


3 Ecology: community-driven, decentralization of computing power

3.1 Community-based development, high popularity

Grin adopts a community-based development model. Different from the current dominant enterprise development, the development of Grin is driven by the community. At present, there is mainly a core committee to make development decisions, including the main developers and community members. Grin is an open source project, not controlled by any commercial organization, and its development direction reflects the collective will of the community to a certain extent. The following are the main developers:

John Tromp: Inventor of the Cuckoo Cycle consensus algorithm, a computer and mathematical scientist, and a well-known researcher of mathematical problems in Go.

Ignotus Peverell: An anonymous developer whose name comes from the owner of the invisibility cloak in "Harry Potter". He is the initiator of the Grin project and the largest contributor to the code.

AntiochPeverellAnitioch: Anonymous developer, participated in the Grin project in the early days, the name also comes from "Harry Potter", the second code contributor;

Michael Cordner: namely @yeastplume, the third code contributor, non-anonymous core developer, the communication between the core team and the outside world is often done through him.

Daniel Lehnberg: Responsible for community operations in the Grin team, a person with a lot of personality, responsible for Grin's ecological weekly report.

Quentin LeSceller: Project sponsor Blockcypher team member, developer of Grin mining pool Grinmint.

The team only accepts donations, no tokens are pre-allocated. Similar to Bitcoin, Grin is obtained entirely through mining without any pre-allocation scheme. The development team adheres to a completely community-driven model, does not accept investment, only accepts donations, and the donor team will only express gratitude on social media. As of press time, Grin has initiated 4 donations, 3 of which are project development funds, and 1 is the personal development fund raised by Michael Cordner. The financing scale of the project is very small, and the purpose is relatively transparent.

Grin is a recent popular project, and the community's attention is generally high. Grin's Twitter has 6159 followers and 258 likes, and has published a total of 1531 tweets, with relatively high update frequency and attention. The more popular posts in the Grin official website forum can reach 4.3k views, with active discussions and technical content. Grin’s Chinese community is also relatively active, with multiple WeChat groups of 500 people, where the discussions mainly focus on technology and mining methods. Overall, Grin's community foundation is relatively strong, and the start-up phase may be relatively smooth.

3.2 Early anti-ASIC, high mining threshold, relatively decentralized computing power

Grin's consensus algorithm is ASIC-resistant in the early stage, and the mining threshold is high. Grin adopts the Cuckoo Cycle consensus algorithm, which is ASIC-resistant. It is difficult for manufacturers to develop ASIC mining machines in the early stage, which prevents professional miners from having an excessive advantage over users who use personal computers to mine. The ASIC resistance of this algorithm is achieved through high memory requirements. Nvidia graphics cards with more than 6G memory must be used for mining, which greatly increases the cost of mining. Specifically, GTX1060 6GB and above graphics cards must be used for mining, excluding AMD graphics cards and P106 low-end models that were widely used in graphics card mining machines before. Grin's consensus algorithm prevents the migration of a large number of stock graphics card mining machines, and prevents the monopoly of professional miners to a certain extent. However, compared with the previous 8GB video memory threshold, the current requirement allows a large number of dedicated cards P106-100 to mine Grin, and the algorithm’s hindrance to professional miners has been reduced. This change has also caused great controversy in the community.

The computing power is relatively decentralized to avoid excessive discourse power of miners. Early ASIC resistance and incompatibility with stock graphics card mining machines prevented the problem of centralization of computing power to a certain extent, and it was difficult for miners to gain an absolute advantage in computing power in the early stages of community development. We think this is very beneficial to the early community building, and can avoid the early monopoly of powerful miners’ capital. With the expansion of the community and the reduction of the proportion of newly produced Grin in the system, the ASIC algorithm will be gradually opened, and professional miners will be introduced to maintain the network. At this time, the community has been relatively stable, and the market value of Grin held by community members is relatively high, which can effectively restrict the miner group and avoid similar incidents of BTC and XMR hard forks.


Increasing community mining participation will help improve Grin's market recognition. The decentralization of computing power means that more ordinary community members can participate in mining, and only electricity and high-performance computers are needed. Early Grin tokens will be relatively decentralized, which will help form community consensus and improve Grin's market recognition. The decentralization of computing power and the economic model of high inflation in the early stage can effectively curb miners' costs and speculative capital at a relatively weak stage of the community, ensure the community's dominance of the Grin project, and help Grin realize the vision of the development team and the community.


4 Risks: initial price fluctuations, potential regulatory pressure

Note:

Note:

Due to some reasons, some nouns in this article are not very accurate, mainly such as: general certificate, digital certificate, digital currency, currency, token, crowdsale, etc. If readers have any questions, they can call or write to discuss together.