Decryption of the world's fourth largest cryptocurrency IOTA

区块链酋长
本文约9318字,阅读全文需要约37分钟
Whether Tangle can meet the security and high performance requirements of the IoT industry under the premise of ensuring decentralization remains to be verified on a large scale.

Whether Tangle can meet the security and high performance requirements of the IoT industry under the premise of ensuring decentralization remains to be verified on a large scale.







review











review

1.1 Project Introduction

IOTA is currently the fourth largest cryptocurrency in the world. The original intention of this project is to design a new type of transaction settlement and data asset circulation system for the Internet of Things industry. It is different from other blockchain projects. Figure) data structure to build a distributed ledger serving the Internet of Things (IOT).

1.2 Market Space, Industry Pain Points and Product Ideas

Market space:

Since 2017, the scale of the global Internet of Things market has continued to grow steadily, and cross-border applications have continued to rise. Due to its natural distributed nature, the Internet of Things is an ideal landing direction for blockchain technology. The original intention of IOTA, which was first proposed in 2015, was to empower the Internet of Things application industry and simplify the transaction process, especially to solve the problem of small transactions. With the continuous development of the Internet of Things, the demand for interaction and resource sharing between smart devices is becoming stronger and stronger.

Industry pain points:

For the traditional Internet of Things industry: In the long-term development and technological innovation process, issues such as equipment security, personal privacy, rigid architecture, and communication compatibility have become the main bottlenecks for the development of the Internet of Things.

For the blockchain field: transaction fees and conflicts between miners and employers caused by the incentive mechanism are always difficult problems to be solved in the industry. Typically, miners prioritize transactions based on a number of different criteria, with fees generally being the top criteria transaction.

IOTA product idea:

The emergence of IOTA has reversed the situation that the blockchain must pay the miners a fee, and launched a new technology Tangle (tangle) that has no blocks, no chains, and no miners. IOTA provides services with zero transaction fees through Tangle technology. Although the network is randomly distributed on different devices, as long as the transaction is valid, the entire network node will become the transaction confirmer. In IOTA, each participant can confirm other transactions, and the two roles of transaction sender and transaction verifier are cleverly combined.

The goal of IOTA is to transform technical capabilities into potential services, build a diverse and open data market, facilitate data flow between business entities, and conduct real-time transactions in the open market. At the same time, it also truly eliminates the original limitations of the blockchain, such as transaction fees, scalability, and centralization of computing power. The framework and concept of IOTA cater to the data exchange in the Internet of Things era to a great extent, and accelerate the arrival of the future era of machine economy.

Generally speaking, the advantages of zero transaction fees and extremely fast confirmation speed in the IOTA framework have greatly solved the pain points of the Internet of Things industry, and at the same time broke the technical barriers of the traditional blockchain industry.

 

1.3 Application scenarios and cooperation cases

According to the introduction of the official website of the IOTA Ecological Foundation, here is a list of some cooperation cases:


  • IOTA has already cooperated with Microsoft, Volkswagen, Samsung and other groups in data security transactions.

  • The IOTA Foundation is included in the Accelerator Program by the Tokyo Metropolitan Government.

  • IOTA has partnered with Volkswagen to develop distributed technology for connected cars.

  • The IOTA Foundation has reached a cooperation with the Taipei government to build a smart city.

  • IOTA and the International Transportation Innovation Center (ITIC) have announced a partnership to develop a testbed for autonomous vehicles.

  • The European Commission approves IOTA and the European Smart Cities Alliance to work together to create smart positive energy cities.



1.4 Foundation

The non-profit IOTA Foundation was founded in Germany in 2017 by Dominik Schiener (IOTA Board Co-Chairman and Founder) and David Sonstebo (IOTA Founder). The foundation is also the first fully regulated non-profit foundation in Germany, capitalized in digital currency (IOTA tokens) (not an initial distribution, but accepting about 5% of the total supply as donations). This token supply serves as the endowment for the IOTA Foundation. The main goals of the IOTA Foundation are research, development, education and standardization of the economy. The foundation is governed by a formal charter, including a council, supervisory board and advisory board.

1.5 team

According to the official website, the main team information is as follows:

Co-founder:






Founding Team:







Advisory Team:






Overall,


  • IOTA’s official website discloses relatively complete information on the core members of the team, and the information of the main co-founders on social platforms such as Linkin is comprehensive and updated in a timely manner.

  • The team has a strong technical force. Its co-founder and white paper author Serguei Popov has published many papers related to IOTA’s core technology Tangle. According to the current information, the overall development technical team has a strong scientific research background.

  • The co-founding members of the team all have rich experience in the blockchain industry.


 

1.6 Token analysis


  • Initial Token Status:



In November 2015, IOTA carried out crowdfunding by issuing 100% of the tokens. The total number of IOTA tokens is constant at 2,779,530,283,277,761, and there will never be additional issuance, no mining, and no lock-up mechanism. The start-up team did not reserve any IOTA tokens, so there may be insufficient team incentives. The community donates approximately 5% of the total IOTA tokens to the non-profit IOTA Foundation to support the operation of the project. The foundation has not announced the distribution of funds raised. IOTA's unique zero transaction fees and no mining incentives avoid conflicts of interest between miners and users.


  • According to data from CoinMarketCap on January 31, 2019, the current price of IOTA is ¥1.82



 







  • The overall market performance of the IOTA project:








Click to enlarge

According to the overall market trend chart of Coinmarketcap, the IOTA project reached a high point from the end of 2017 to the beginning of 2018, with an obvious top area, and then the price fell back. During the rebound in April 2018, the trading volume was limited, and the peak of the rebound was not even reached The neckline resistance zone of the head and shoulders pattern. It shows that the market's willingness to do more is not strong enough, and the overall price trend is still in a weak range.






Environmental Analysis

2.1 Industry environment

The European Intelligent System Integration Technology Platform (EPoSS) analyzed and predicted in the "Internet of Things in 2020" report that the future development of the Internet of Things will go through four stages. Before 2010, RFID was widely used in logistics, retail and pharmaceutical fields. In 2015, objects will be interconnected, from 2015 to 2020, objects will become semi-intelligent, and after 2020, objects will become fully intelligent. At present, it is the key node for the entire Internet of Things industry to transform from semi-intelligent to fully intelligent.

The blockchain, as an extremely important landing form in the field of the Internet of Things, is in the stage of explosion. According to statistics, as of the end of 2018, there were a total of 54 blockchain IoT projects, involving IoT platforms, smart manufacturing, Internet of Vehicles, agriculture, supply chain and many other fields, including blockchain start-ups, supply chain companies and Internet giants, Well-known companies such as Ali, JD.com, and IBM are all laying out in the blockchain IoT industry.

IOTA is an early concept experimenter. It uses distributed ledger technology to perform identity verification and confirmation, and capitalizes data to protect data privacy. IOTA's distributed ledger technology can realize point-to-point data transmission. Compared with the traditional centralized Internet of Things platform, which significantly reduces communication costs, storage costs, and maintenance costs; in addition, as a distributed Internet of Things infrastructure, IOTA also provides a unified standard, which greatly improves industry interoperability.

2.2 Policy environment

IoT industry:

The IOTA project is registered in Germany. It is understood that Germany has not yet issued any clear policies on the Internet of Things industry. However, as early as in the concept of "Industry 4.0" proposed by the German government, it has been pointed out that the whole country aims to improve the intelligence level of the manufacturing industry and establish smart factories with adaptability, resource efficiency and genetic engineering. Integrate customers and business partners in the value process. The realization of the whole concept is based on the network entity system and the Internet of Things.

In addition, in 2017, the German Federal Ministry of Economic Affairs proposed that it will strive to bring innovation policy to a new dimension, and Germany will actively promote important projects of common interest to Europe to strengthen its national competitiveness in the application fields of the Internet of Things, Industry 4.0, and autonomous driving. Development and manufacturing capabilities to maintain digital sovereignty. From 2017 to 2020, an investment subsidy of 1 billion euros will be provided, which will drive investment of 4.4 billion euros in enterprise projects.

Countries' policies on ICO:

The entire European region is the region with the most intensive issuance of ICO policies. It is understood that most projects in the encryption industry are usually registered in a few jurisdictions other than Europe that are conducive to tax avoidance, such as Curacao, Mauritius, Nevis, etc., in order to Avoid tax and regulatory risks. However, the IOTA founding team chose to build in Germany, which may be the most difficult and rigorous path. In the end, however, they managed to become the first fully regulated non-profit foundation in Germany. This has won a lot of opportunities and cooperation resources for IOTA.

Germany: On March 28, 2018, the German Federal Financial Supervisory Authority (hereinafter referred to as "BaFin") issued a "Consultation Letter", stating that BaFin decides on a case-by-case basis whether a token constitutes a German securities exchange law or a financial instrument market guidance item. financial instruments under the German Securities Prospectus Act and on a case-by-case basis whether a token constitutes a monetary investment under the German Money Investment Act. In the "Consultation Letter", BaFin made a detailed definition of the characteristics that constitute financial instruments and securities, and listed the authorization requirements.

United States: Since 2018, the United States has strengthened the regulation of ICOs. On March 7, 2018, the US Securities Regulatory Commission began to supervise ICOs using the SAFT agreement and issued subpoenas to 80 digital currency companies. On March 11, the US SEC announced that digital currency exchanges must be registered. SAFT, Simple Agreement for Future Tokens, Chinese for "simple agreement for future tokens", is an investment contract provided by digital currency developers to qualified investors. The protocol promises to deliver a certain amount of tokens when the network or company operates in the future. The protocol differs from standard ICOs in that ICOs release tokens immediately, whereas SAFTs are effectively a promise to deliver.

In addition, it is reported that U.S. regulators may recognize all tokens as securities, which will have a great negative impact on the implementation of blockchain projects. Once Token is recognized as a security and subject to securities law regulation, its liquidity will be greatly reduced.

Not long ago, the official website of the US Securities Education Commission (SEC) released its 2018 fiscal year report, which mentioned the need to crack down on fraudulent ICOs.

Important measures for ICO in other countries and regions:










Github situation and official website R&D route description

3.1 Github situation:

The latest code released by the official GitHub of the IOTA project shows:

The official github mainly has 6 top code libraries iri, entangled, iota.js, iota.go, rpchub, trinity-wallet. The IOTA project now has a total of 76 code bases, and the search shows that 6 project code bases and 1 WIKI are directly referenced (forked). The evaluation researcher inquired in detail about the 6 project code bases that were directly referenced (forked) and found that 4 code bases including mam.client.js, docker-buildkite-plugin, libopencl-stub, and PearlDiver directly referenced (forked) the external code base address, iota .curl.java, iotavisualization, a total of two code bases directly reference (fork) the personal address in the IOTA code base.

3.2 Official website research and development route:

There are 19 projects in the R&D route of the official website, which are divided into 12 projects under active development and 7 projects still in the research stage.

R&D status of 12 projects under active development:


  • The main code iri developed by the IOTA node and the iota.lib.js (replaced by iota.js) of the JavaScript client version continue to be under long-term maintenance and development.

  • Local Snapshots & Permanodes that enable node operators to maintain or process Tangle history in a way they think is reasonable, Tanglescope that enables in-depth analysis of Tangle performance and indicators through monitoring, PoWBox for developers to debug, and adopts new encrypted hashes A total of 4 projects of Curl+ of the function algorithm have been developed.

  • It is convenient for service providers to integrate IOTA Hub, Coo-free IRI that strips the coordinator from IRI to achieve a new consensus, Trinity for PC and mobile wallets, C Client for in-depth research on embedded IoT devices, full specifications and full functions MAM+, which rewrites MAM (officially defined as a message transfer protocol), has a total of 5 projects under development.

  • Development progress








Development progress

4.1 Core Technology—Tangle:

Tangle is similar to Blockchain. It is a distributed network data structure designed for the establishment of the Internet of Things (IoT). It executes a series of data transmission transactions through a group of independent operators and reaches a consensus to promote a series of security. trade.

IOTA's Tangle is based on DAG technology, which can achieve high transaction throughput through parallel verification and does not charge transaction fees. Due to the limitation of IOTA's network transaction volume, its security cannot be guaranteed in the Tangle network for the time being, and the Coordinator (coordinator, see 5.1 below for details) is now used.

The difference between Blockchain and Tangle network:






Blockchain network diagram







Tangle network diagram

It can be found that Tangle's unique topology is different from Blockchain's single continuous chain architecture formed by adding blocks. There are three technical elements of Blockchain: transactions, blocks, and chains. In the Tangle, there are only transactions, not blocks and chains.

The data structure and transaction verification methods are different: Tangle’s verification method is that the latter transaction verifies the first two unconfirmed transactions. Blockchain’s transaction verification method is generally that when a node packs a block, it will verify all transactions in the block. Verification is performed, and a transaction needs to be confirmed several times to ensure the final completion of the transaction. It can be roughly understood as: Tangle is like a concurrent multi-threaded "chain" verification, which is a single node to verify the transactions of multiple "chains", which is different from the transaction verification method of Blockchain multi-nodes on a single longest chain.

Tangle is based on directed acyclic graph DAG (also known as directed acyclic graph) refers to a directed graph without loops. As shown in the figure below, if there is a non-directed acyclic graph, and point A departs for B (path 1) and returns to A (path 3) via C (path 2), a loop is formed (closed-loop path: 1-2 -3). Change the edge direction from C to A to A to C (change path 3 to path 4), then it becomes a directed acyclic graph.






Directed Acyclic Graph

In the Tangle network, when a new transaction is added, the new transaction must verify the previous two unconfirmed transactions, and these verification relationships are represented by directional edges, as shown in the figure below (in the figure, time goes to the total is from left to right). If there are at least 2 directed edge paths from transaction A to transaction B, transaction A indirectly verifies transaction B. The understanding of more than 2 directed edge paths here can refer to the above Tangle network diagram. Transaction t indirectly verifies transaction o. There are 4 directed edge paths here, 2-yto of path 1, 2-zto of path 2, and 2-zto of path 2. 3-t-0 for 3, 4-zto for path 4.






Consensus mechanism innovation: Blockchain consensus is completed through a very strict mechanism. Adding the next block in the blockchain requires multiple parties to compete and obtain block rewards or transaction fees. Because of this, consensus and transaction sharing are separated and done by a small number of people in the network. Blockchain usually sets a high threshold, which will lead to further centralization.

4.2 Original hash encryption algorithm Curl

The IOTA team created their own cryptographic hash function called Curl's Trinary Algorithm. The Curl hash function is used in the IOTA light wallet to perform PoW work, and two methods of "Webgl 2 Curl" and "Ccurl implementation" are provided to execute the Curl hash algorithm.

For IoT devices and future AI devices, the traditional binary system cannot succinctly feed back the actual application scenarios, but the ternary logic can handle such situations more conveniently.

Advantages of the ternary algorithm

Traditional binary can only simply represent the states of "1" (yes) and "0" (no), but in actual scenarios there are still unknown situations to be determined, while ternary logic can use the symbol "2" to represent "yes"; The symbol "0" means "no"; the symbol "1" means "unknown to be determined" to deal with the situation of unknown to be determined.

Taking ferrite cores and semiconductor diodes as an example, traditional computer components such as vacuum tubes and transistors are gradually being eliminated by ferrite cores and semiconductor diodes with faster speed and better reliability. This is due to the ratio of ternary logic circuits to Binary logic circuits more easily represent three states of voltage: positive voltage ("1"), zero voltage ("0"), and negative voltage ("-1"), making electronic components such as ferrite cores and semiconductor diodes A good controllable current transformer is formed.

In terms of computer algorithm logic, the ternary system can more simply express the unknown state to be determined, so Curl, which uses the ternary system algorithm, is more in line with the development trend of computers in the Internet of Things and artificial intelligence.

4.3 Establish masked authentication message MAM

Masked Authenticated Message (MAM for short). The advantage of MAM is what sets IOTA apart from other distributed ledgers by making data flow and transactions cheaper, more secure and ubiquitous.

When posting a new message on a channel, the publisher has three options:

Public (public mode): The masked message is decrypted by root and can be viewed by everyone.

Private (private mode): The masked message is decrypted by root and only you (the seed owner) can view it.

Restricted (restricted mode): Masked messages are decrypted using a sideKey, a key you can tell someone to authorize him to be a viewer. This key is named sideKey in the source code.

Taking the vending machine as an example, the public mode is the screen advertisement message on the vending machine; the private mode is that the enterprise can check the sales inventory of the vending machine and the energy consumption of the machine through the MAM channel in real time; the restricted mode is that the enterprise authorizes the employees of regional outlets or cooperate Partners, etc. check the situation of the vending machines that are limited in this area.






Landing assessment

5.1 The coordinator is a centralized solution

IOTA was established for large-scale applications, but the current network transaction volume is relatively small, so for security reasons, the project party has adopted an autonomous and temporary consensus mechanism coordinator (coordinator, hereinafter referred to as Coo). Every two minutes, the IOTA Foundation creates a milestone transaction, and all transactions confirmed by it are immediately considered with 100% confirmation confidence.

The coordinator acts as a protection mechanism in the early development stage of the IOTA network. When the complete Tangle distributed consensus algorithm starts to function, the IOTA Foundation will shut down the coordinator, allowing the Tangle to evolve and develop entirely on its own. This will happen in an iterative phase, and when the network matures enough to get rid of the coordinator, the network itself will immediately become more efficient. But as a centralized solution, theoretically, it has two logical loopholes:

1. It allows the foundation to choose which transactions get priority;

2. It allows the foundation to freeze funds as milestones ignore transactions that consume them.

This is a point of attack: if for some reason Coo stops working or is taken over, confirmations in the network will stop, so Coo has been the limiting factor in network scalability until now.

5.2 IOTA ternary risk factor is higher

One of the characteristics of ternary code is symmetry, that is, the consistency of opposite numbers, so it is different from binary code, and there is no concept of "unsigned number". In this way, the architecture of the ternary computer is much simpler, more stable and more economical. Its command set is very efficient, easier to read, and even somewhat resistant to quantum attacks. However, the ternary algorithm still has the following limitations in actual implementation:

1. The development of IOTA's ternary algorithm is relatively rudimentary, and the officially promoted JINN processor is only a product of the exploration stage of the ternary CPU. In addition, Neha Narula, a professor of cryptography at MIT, once published a report that found that the Curl hash function has a collision vulnerability. Overall, the ternary algorithm developed by IOTA is still far from commercialization at this stage.

2. Most of IOTA's current codes are binary. In the program, it is necessary to convert ternary into binary, and then convert back to ternary after processing. The efficiency is actually much lower than direct binary processing. Since it does not match the mainstream binary system in the current computer world, even if the ternary algorithm is well developed, it will not substantially improve the IOTA network in the short term. On the contrary, the current IOTA full-node code is all written in JAVA, and requires a lot of conversion, low execution efficiency, and high memory usage.






Potential attack risks and solutions

6.1 Double spending attack:

a. Large weight attack

The attacker sends a modified and forged transaction (double payment transaction) to the original payment, and before the original payment transaction, by using all the computing power for the double payment transaction, as much as possible to verify a large number of transactions to be verified in the network, This double payment transaction gets a higher weight, thereby increasing the possibility of the double payment transaction sent by the attacker being confirmed, and recovering the token spent in the original payment transaction, completing the double spending attack.






Solution: At present, there is not enough transaction volume in the system to avoid centralized large-weight attacks. You can set the upper limit of transaction weight or set it to a constant.

b. Parasitic chain attack:

The attacker secretly builds a sub-tangle that others cannot see. This tangle is generally called a "parasite chain". At a certain point in time, the attacker has published a transaction A (an honest transaction) to the main tangle, and the tangle does not directly or indirectly verify the original payment transaction A. After the payee confirms acceptance of transaction A, the attacker will connect the parasitic chain carrying transaction B to the public network when broadcasting, so that the legitimacy of transaction B is recognized by the public network, making the original transaction A invalid , so as to get back the token spent in the transaction, and complete the double-spend attack.






Solution: weighted random walk (choose the mcmc algorithm of tip) to solve the potential attack risk of the parasitic chain, and at the same time solve the problem of Lazy Tips (here Tips refers to transactions to be confirmed).

6.2 Fragmentation Attack

Under high load, the attacker splits the tangle into two branches (both branches have at least one pair of conflicting transactions, preventing honest nodes from effectively merging the two branches into one), and maintains own fund balances and let them continue to grow. In the high load state, it is assumed that the transactions in the network are equally distributed to the two branches, so that it can "compensate" for random fluctuations, even if he has only relatively small computing power. If this method is successful, the attacker can have the same amount of funds in both branches, thereby doubling the funds and completing the split attack.






Solution: optimize the weighted random walk (mcmc tip selection method) algorithm






Operational Evaluation

7.1 Community building

The official social media operated by IOTA are mainly Facebook, Twitter, and Reddit. In particular, the number of followers of Twitter and Reddit has exceeded 110,000. Official social media operations are more active, with a larger number of fans and higher-quality discussions.






The quality of operation of IOTA’s various community channels:


  • Twitter: 700+ tweets, dynamics can basically guarantee real-time updates;

  • YouTube: There are many interpretations of IOTA, and the number of hits on each is basically more than 10,000, indicating that the project has received more attention abroad;

  • China Community: There is an official website of the China Community, the information on which is comprehensive and updated in a timely manner; the WeChat official account is regularly posted, but the amount of reading is relatively small.



7.2 Market popularity

Google Trends

According to Google Trends, the overall market popularity is mediocre, which shows that the project party does not pay attention to promotion. On November 3, 2017, the IOTA Foundation officially announced that it had been officially registered as a non-profit entity according to German law, and the attention of the project reached its peak in that month.






Alexa popularity

advantage:










Summarize

advantage:

1. Tangle is based on DAG technology, which can achieve high transaction throughput through parallel verification and does not charge transaction fees.

2. Using the original hash encryption algorithm Crul, it is faster to execute through GPU than CPU.

3. MAM differentiates IOTA from other distributed ledgers by making data flow and transactions cheaper, more secure and ubiquitous.

shortcoming:

shortcoming:

1. The coordinator is a centralized solution. If for some reason Coo stops working or is taken over, the confirmation in the network will stop.

2. IOTA ternary risk factor is higher

3. No incentive tokens have been reserved for the team, and the enthusiasm for subsequent team development and promotion is doubtful.

All information in this assessment report is based on open source sources. If non-public information such as unopened code bases are not included, relevant IOTA documents are attached:

[1]IOTAWhitepaper:The Tangle

[2] IOTA official website: https://www.iota.org

Disclaimer:

[4]IOTA GitHub:https://github.com/iotaledger

Disclaimer:


  • This report clearly and accurately reflects the analysis point of view of the appraiser, and strives to be independent, impartial, objective and rigorous. The conclusion is not inspired or influenced by any third party, hereby declares;

  • The data used in this report come from public compliance channels such as the project’s official website, white paper, and LinkedIn, and no guarantee is made for the accuracy, completeness, and reliability of the information used;

  • None of the information or opinions expressed in this report constitutes investment advice for anyone. In any case, the chief rating entity, chief rating staff or affiliated institutions do not promise investors investment returns, nor are they responsible for anyone's use of this report. Any responsibility for any loss caused by any content in;

  • Without the official authorization of the blockchain chief, any behavior of rating employees or affiliated institutions does not represent the official attitude;

  • The copyright of this report is only owned by Chief Rating, and no institution or individual may reprint, reproduce, publish or quote in any form without written permission. If it is quoted and published with the consent of the Chief Rating, it must be used within the scope of the permission, and the source should be indicated as "The Chief Rating", and this report must not be quoted or modified against its will;

  • If you have any doubts about this report, please contact the official email at cgl@conew.com. Please indicate the source when reprinting this report. Commercial reprinting is prohibited; if you use this report in violation of regulations, you will be held accountable by law.