Chapter 16: Digital Cash

Chapter 16 of Trappe & Washington: the four requirements of digital cash and why an electronic object loses the one a physical coin gets free; Brands' scheme built on restricted blind signatures, where one spend hides the spender's identity and two spends reveal it automatically; Bitcoin's five stages, proof of work, and mining; and the boundary this chapter draws between what a cryptocurrency guarantees cryptographically — unforgeability, tamper-evidence, committed blocks — and what it assumes economically, namely that honest participants outspend any attacker.

Subject: Cryptography · 60 slides · diagram-first lesson

Open the interactive version of this deck

What this lesson covers

The lesson, slide by slide

1. Digital Cash

Title

Cryptography · Chapter 16

Unforgeable, anonymous, and spendable exactly once — and why the third requirement leaves mathematics behind

2. What you will be able to do

Objectives

Every previous chapter's requirements could be met by mathematics. This chapter's cannot, and the gap is where cryptocurrencies live.

Figure (svg): The four requirements of a digital cash system, and the tension between anonymity and double-spending detection.

Physical cash gets all four free, because a coin is hard to copy. An electronic object is free to copy, which is the whole problem.

3. Why is electronic cash hard?

Warm-up

A physical coin is unforgeable, anonymous and spendable once, and nobody designed those properties in.

Discussion prompt

Which of them does an electronic object lose, and why does losing it break the other two?

Hint: Ask what is different about copying.

Answer:

Spendable once is what it loses. A physical coin is hard to counterfeit and, crucially, leaves your hand when you spend it. An electronic object can be copied at essentially no cost, so spending it twice is the default behaviour rather than a difficult attack.

Unforgeability is recoverable — a bank's signature on the coin makes minting impossible for anyone else. Chapter 13 solved this.

But now anonymity is in tension with detection. To stop double spending you need to know which coins have been spent, and the natural way is for the bank to recognise each coin — which destroys anonymity.

So the design problem is precisely those two together: a bank that cannot recognise a coin it issued, and can nonetheless catch anyone who spends one twice. Section 16.2's answer is restricted blind signatures, and it is why that scheme is so much more complicated than a coin.

Figure (svg): The four requirements of a digital cash system, and the tension between anonymity and double-spending detection.

Physical cash gets all four free, because a coin is hard to copy. An electronic object is free to copy, which is the whole problem.

4. Setting the Stage for Digital Economies

Section

Section 16.1 · pp. 319-320

5. What a coin has to do

Concept

The book's framing is that electronic objects reproduce at essentially no cost, in contrast to physical cash, which has usually been rather difficult to counterfeit. Everything about the design follows from that one difference.

Unforgeable
Only the bank can create valid coins. A signature does this, and Chapter 13 supplies it.
Anonymous
The bank should not be able to link a spent coin to the person who withdrew it — otherwise electronic cash is just a traceable bank transfer.
Spendable once
The hard one. Copying is free, so this must be prevented by design or detected after the fact.
Verifiable offline
A merchant should ideally be able to accept a coin without contacting the bank — otherwise the bank is in every transaction, which reintroduces the tracking.

Notice the tension. Preventing double spending in real time means the bank sees every transaction, which destroys anonymity and offline use. So the schemes below detect double spending instead — and detection means identifying the cheat, which means anonymity must be conditional.

Figure (svg): The four requirements of a digital cash system, and the tension between anonymity and double-spending detection.

Physical cash gets all four free, because a coin is hard to copy. An electronic object is free to copy, which is the whole problem.

6. Why can't the bank just keep a list?

Socratic

The obvious solution: the bank records every coin it issues and every coin it sees spent, rejecting repeats.

Discussion prompt

What does that cost, and why is it not the answer the chapter gives?

Hint: Consider anonymity, availability and scale in turn.

Answer:

It destroys anonymity. To reject a repeat the bank must recognise the coin, and if it can recognise a spent coin it can link it to the withdrawal. The result is a traceable payment system, which is what a bank transfer already is.

It requires the bank to be online for every transaction. A merchant cannot accept a coin without checking, so the system fails when connectivity does — and a physical coin works in a power cut.

And it scales badly: the list grows without bound, and every transaction worldwide is a query against it.

But it does work, and it is what every centralised payment system does. The interesting question is not whether the problem is solvable with a trusted central party — it obviously is — but whether it is solvable without one, or at least without the party seeing everything.

Section 16.2 removes the seeing, using blind signatures so the bank checks a list of coins it cannot link to people. Section 16.3 removes the central party altogether, at the price of an economic assumption.

7. A Digital Cash System

Section

Section 16.2 · pp. 320-326

8. Digital Cash by restricted blind signatures

Concept

The book presents a system due to Stefan Brands, and is candid that it is much more complicated than the centuries-old system of actual coins — because catching electronic counterfeiters requires something like a signature attached to each coin, and attaching a signature is exactly what threatens anonymity.

The setup is done once by a central authority. Choose a large prime p with q = (p−1)/2 also prime — a safe prime, per Section 10.2 — and let g be the square of a primitive root mod p, so that g has order q.

\[ g^{k_1} \equiv g^{k_2} \!\pmod p \iff k_1 \equiv k_2 \!\pmod q \]

Two secret exponents are chosen, g₁ and g₂ are defined as g raised to them, and the exponents are then discarded — storing them serves no purpose and would compromise the system if discovered. The values g, g₁, g₂ are public, along with two hash functions.

Discarding the exponents is worth pausing on. It is a deliberate destruction of information so that nobody, including the designer, can ever exploit it — the same idea as a nothing-up-my-sleeve constant, and a pattern that recurs in trusted-setup ceremonies today.

Figure (svg): Withdrawing a coin: the spender blinds it, the bank signs without seeing it, and the spender unblinds.

Chapter 13's blind signature, doing the job it was invented for: authorising something without seeing it.

9. Restricted Blind Signature: the key idea

Concept

An ordinary blind signature, from Section 13.1, hides the message completely: the bank signs a value it cannot see and cannot recognise later. That gives anonymity and no accountability at all.

A restricted blind signature constrains what the spender may construct. The blinding is arranged so that the coin necessarily embeds the spender's identity in a hidden form — and the protocol requires the spender to reveal a share of it at spending time.

One share reveals nothing. It is one linear equation in the identity's representation, and the equation is under-determined.

Two shares determine it. If the coin is spent twice, two different merchants issue two different random challenges, so the spender must produce two different shares — and two independent linear equations solve for the identity.

So the system gives anonymity for the honest and identification for the cheat, from one construction. The complexity of the Brands scheme is almost entirely the machinery to make this work.

Figure (svg): Double spending detection: one spend reveals one share of the identity, and two spends reveal enough to recover it.

The merchant's random challenge is what makes the two equations independent; a single spend leaves the system under-determined.

10. Withdrawing, spending, and being caught

Worked example

Three phases, and the third only happens to a cheat.

Withdrawal: the spender constructs a coin embedding her identity, blinds it, and sends it to the bank

Why: The bank debits her account and signs the blinded value. It knows it issued a coin to her and cannot recognise that coin later.

The spender unblinds, obtaining a coin bearing the bank's signature

Why: Unforgeable, because only the bank can produce that signature; anonymous, because the bank never saw the coin.

Spending: the merchant sends a random challenge, and the spender responds with a value derived from the challenge and her identity

Why: The merchant checks the bank's signature and the response's consistency. One challenge, one linear equation.

The merchant deposits the coin with the bank, which records it

Why: If the coin appears twice, the bank has two challenge-response pairs.

Verify: two different challenges give two independent equations, which solve for the identity

Why: So the cheat is identified by the mathematics, not by surveillance. The bank learns nothing about honest spenders and everything about a double spender — which is the property the whole scheme exists to deliver. Note that detection is after the fact: the second merchant has already been defrauded, and the system's remedy is legal rather than technical.

Figure (svg): Double spending detection: one spend reveals one share of the identity, and two spends reveal enough to recover it.

The merchant's random challenge is what makes the two equations independent; a single spend leaves the system under-determined.

11. Anonymity that ends exactly at cheating

Anomaly

The scheme gives full anonymity to honest spenders and full identification of double spenders, with no authority deciding which is which.

Predict first

What makes this possible?

  • The bank monitors transactions and revokes anonymity when it sees fraud
  • The identity is secret-shared into the coin, so one spend reveals one share and two spends reveal enough to reconstruct it
  • A trusted third party holds an escrow key
  • The merchant reports suspicious behaviour

Correct: The identity is secret-shared into the coin, so one spend reveals one share and two spends reveal enough to reconstruct it

This is a genuinely elegant idea and it recurs: a secret released only when a rule is broken, with the rule-breaking itself supplying the second share.

It is also the reason the scheme is complicated. Every step exists to make the sharing sound: the spender must not be able to construct a coin with a false identity, and must not be able to answer two challenges with the same share.

Compare Chapter 17's secret sharing, which is the same mathematics used deliberately rather than as a trap.

Why: The identity is embedded so that each spend, under a merchant's random challenge, releases one linear equation about it. One equation is under-determined and reveals nothing; two are independent and solve. Nobody decides to revoke the anonymity — the act of double spending performs the revocation, automatically and with no discretion involved.

Figure (svg): Double spending detection: one spend reveals one share of the identity, and two spends reveal enough to recover it.

The merchant's random challenge is what makes the two equations independent; a single spend leaves the system under-determined.

12. Why is detection acceptable rather than prevention?

Socratic

The Brands scheme catches a double spender afterwards. It does not stop the second transaction happening.

Discussion prompt

Why is that considered an acceptable design, and when would it not be?

Hint: Compare with what prevention would require.

Answer:

Prevention requires an online check on every transaction, which means the bank is present in every payment — destroying offline use and, without blinding, anonymity. Detection buys back both.

And detection has teeth here because the identity is recovered with certainty, not merely suspected. The remedy is legal, and the deterrent is that cheating is guaranteed to be traced rather than probably caught.

It matches physical cash's model. A forged banknote is detected after acceptance too, and the system relies on the cost of forgery plus prosecution rather than on making forgery impossible.

When it is not acceptable: where the fraud is instantly profitable and the cheat is beyond legal reach — an anonymous party in another jurisdiction, or an amount large enough to justify absconding. Then only prevention will do, and prevention means being online.

Which is exactly why Bitcoin chose the other branch. It prevents double spending outright, by making everyone maintain the ledger — at the cost of every transaction being public forever, which is the opposite trade.

13. Double Spending Detection in one picture

Concept

The mechanism is worth stating on its own, because it is the chapter's cleverest idea and the reason the scheme is so intricate.

The spender's identity is represented so that recovering it requires two independent linear equations. The coin carries the representation in blinded form, and the bank never sees it.

\[ \text{spend once} \;\Rightarrow\; 1 \text{ equation} \;\Rightarrow\; \text{under-determined}, \qquad \text{spend twice} \;\Rightarrow\; 2 \text{ equations} \;\Rightarrow\; \text{solved} \]

The merchant's random challenge is what makes the second equation independent of the first. Two different merchants issue two different challenges, so a spender reusing a coin cannot avoid producing two distinct responses.

Nobody decides to unmask the cheat. There is no authority holding an escrow key and no monitoring. The act of double spending performs the identification, automatically, and the bank learns nothing whatever about anyone who spends honestly.

Figure (svg): Double spending detection: one spend reveals one share of the identity, and two spends reveal enough to recover it.

The merchant's random challenge is what makes the two equations independent; a single spend leaves the system under-determined.

14. Break it with a predictable challenge

Counterexample

Suppose a merchant generates its challenge from a counter, or from the time, rather than at random.

Discussion prompt

Show that a double spender can then escape identification.

Hint: She needs the two equations to be dependent rather than independent.

Answer:

She arranges to receive the same challenge twice. With a predictable challenge she can wait for the value to recur, or choose which merchant to visit and when.

Then her two responses are identical, so the two equations are the same equation. The system is still under-determined and her identity is safe.

She has spent one coin twice and cannot be identified, which defeats the entire construction — the bank knows a coin was double spent and has no idea by whom.

So the challenge must be fresh and unpredictable, which is the same requirement as a signature nonce in Chapter 13 and an IV in Chapter 6. It is the third context in which a predictable 'random' value destroys a scheme completely.

And the failure mode is identical each time: the value looks like a formality, its randomness is not obviously load-bearing, and an implementer replaces it with something convenient. Chapter 14's largest failure category, arriving once more.

Figure (svg): Double spending detection: one spend reveals one share of the identity, and two spends reveal enough to recover it.

The merchant's random challenge is what makes the two equations independent; a single spend leaves the system under-determined.

15. Bitcoin Overview

Section

Section 16.3 · pp. 326-329

16. Bitcoin: five stages and no server

Concept

A ledger-based cryptocurrency using a combination of cryptography and decentralized consensus to track every transaction. The book reduces it to five stages, and every user performs all five.

  1. Users maintain a transaction ledger
  2. Users make transactions and announce them to the network
  3. Users gather transactions into blocks
  4. Users solve cryptographic puzzles using these blocks
  5. Users distribute their solved puzzle block

Starting in the middle: transactions happen everywhere and each is broadcast. Every user collects them, verifies they are legitimate, and gathers the valid ones into a block. Then one user — say Zeno — gets lucky, broadcasts the news, and adds his block to the ledger.

About ten minutes later another user, Xenia, gets lucky. If she believes Zeno's block is valid she builds on it; if not, she does not. That choice, made independently by every participant, is the consensus mechanism.

Figure (svg): The five stages of Bitcoin: maintain a ledger, announce transactions, gather them into blocks, solve a puzzle, distribute the solved block.

Cryptography supplies the ledger's integrity; the puzzle supplies the agreement about which ledger is real.

17. Proof of Work and Mining

Concept

The 'getting lucky' is a search. A miner assembles a block, appends a nonce, hashes the result, and checks whether the hash falls below a target. If not, she changes the nonce and tries again.

\[ H\bigl(\text{block} \, \| \, \text{nonce}\bigr) < \text{target} \]

The asymmetry is everything. Finding a nonce takes an enormous number of attempts; checking one takes a single hash. So a block is expensive to produce and free to verify — which is exactly what a distributed system needs, because every participant must verify and only one must produce.

The target adjusts so that, across the whole network's combined effort, a block is found about every ten minutes. Adding miners does not produce blocks faster; it makes each one more expensive.

Mining is the incentive. The successful miner is rewarded with newly created coins and the transaction fees in her block. That reward is what makes it profitable to spend electricity following the rules — the security argument is economic, and the cryptography only supplies the puzzle.

Figure (svg): Proof of work: miners search for a nonce making the block's hash fall below a target, which is hard to find and instant to check.

Chapter 11's hash function used as a cost, not as an integrity check: work is what makes a block expensive to fake.

18. How work produces agreement

Worked example

Chapter 12 showed that hash pointers give tamper-evidence relative to a known head, and said agreeing on the head was a separate problem. This is the answer.

Suppose two miners find blocks nearly simultaneously, and the network splits — some users build on Zeno's block, some on Xenia's

Why: A fork. Both chains are internally consistent and neither is wrong.

The rule everyone applies: build on the chain with the most accumulated work

Why: Not the longest by count, but the one representing the most total computation — which is why the rule survives changes in difficulty.

Whichever fork attracts the next block pulls ahead, and miners on the other side switch to it

Why: Their block is orphaned and its transactions return to the pool. The split resolves itself, usually within one or two blocks.

To rewrite history, an attacker must redo the work of every block since the one she wants to change, and outpace the honest network while doing it

Why: Because her chain must become the one with most work.

Verify: this holds only if the honest network controls more computing power than the attacker

Why: That is the assumption, and it is about the world rather than about mathematics. No hash function guarantees it, and it can fail — smaller chains have been reorganised by rented hashpower. The cryptography is sound and the security is an economic argument.

Figure (svg): Two competing chains, with the network following whichever has the most accumulated work.

Tamper-evidence came from hashing; agreement comes from the rule that the chain with the most work wins.

19. Where the security actually comes from

Anomaly

Bitcoin uses SHA-256, ECDSA signatures and Merkle trees, all sound. Its central claim is that the ledger cannot be rewritten.

Predict first

What is that claim actually based on?

  • The collision resistance of SHA-256
  • The unforgeability of ECDSA signatures
  • The assumption that no single party controls more computing power than everyone else combined
  • The size of the network

Correct: The assumption that no single party controls more computing power than everyone else combined

The consequence is that security scales with the total work being spent, not with the cryptography. A small chain using the same SHA-256 is cheap to attack, and several have been reorganised by rented hashpower.

It is also why the book places this chapter after Chapter 15. Every earlier security claim was contingent on a mathematical assumption; this one is contingent on an economic one, and the difference in kind is worth noticing.

Why: Hashing makes tampering detectable and signatures make transactions unforgeable, but neither decides which of two consistent chains is real. That is settled by the most-work rule, and the rule only protects history if honest miners collectively outpace any attacker. It is an assumption about the distribution of resources in the world, and it is the load-bearing one.

Figure (svg): Two competing chains, with the network following whichever has the most accumulated work.

Tamper-evidence came from hashing; agreement comes from the rule that the chain with the most work wins.

20. Cryptocurrencies

Section

Section 16.4 · pp. 329-338

21. Cryptocurrencies: what is guaranteed and what is assumed

Concept

Separating the two is the most useful thing to take from this chapter.

PropertyComes fromKind of guarantee
A transaction is authorised by the coin's ownerECDSA signaturescryptographic
The ledger's history is tamper-evidenthash pointers and Merkle treescryptographic
A block took real effort to produceproof of workcryptographic
Everyone agrees which chain is realthe most-work ruleeconomic assumption
History will not be rewrittenhonest majority of hashpowereconomic assumption
A coin has valuenothing in the protocolsocial

The top three are theorems. The next two hold while an assumption about the world holds. The last is outside the system entirely, and no amount of cryptography addresses it.

Figure (svg): What each requirement of digital cash costs, and which of them cryptography can supply alone.

The first two are mathematics. The third is a systems problem. The fourth is an argument about who controls what.

22. Anonymity in practice

Concept

Bitcoin is often described as anonymous. It is pseudonymous, and the distinction is sharp.

Addresses are public keys, not names — so there is no identity in the protocol. But every transaction is public and permanent, so the entire graph of payments is available to anyone, forever.

Chain analysis links addresses by clustering: inputs spent together are usually controlled by one party; change addresses are identifiable by pattern; and any point where a pseudonym touches the identified world — an exchange, a merchant, a delivery address — attaches a name to a cluster and, retroactively, to everything it ever did.

Compare the Brands scheme. There, anonymity is cryptographic: the bank cannot link a coin to a withdrawal, whatever it later learns. Here, anonymity is a matter of not being linked yet — and the ledger is permanent, so the analysis can improve indefinitely against transactions already made.

This is the clearest illustration of the chapter's theme. Two systems both called anonymous digital cash, with guarantees of completely different kinds.

Figure (svg): Pseudonymity against cryptographic anonymity: a permanent public graph that can be de-anonymised later, against a bank that cannot link a coin at all.

One is 'not linked yet', the other is 'cannot be linked'. The permanence of the ledger makes the difference decisive.

23. Two answers to double spending

Comparison

The Brands scheme and Bitcoin solve the same problem in opposite ways. Fill the blanks.

Comparison matrix

Brands digital cashBitcoin
Double spending isdetected afterwardsprevented, by a shared ledger
Requires a trusted party?yes — the bank issues coinsno issuer; a majority assumption instead
Anonymitycryptographic — the bank cannot link a coinpseudonymous — a permanent public graph
Works offline?yes — the merchant checks a signatureno — confirmation needs the network
Security rests ondiscrete logarithmsan honest majority of computing power

Neither dominates. One needs a bank and gives real anonymity; the other needs no bank and gives a permanent public record of everything.

24. Reading the proof-of-work condition

Notation

One inequality, and every property of mining follows from it.

Annotate

On: \( H\bigl(\text{header} \, \| \, \text{nonce}\bigr) < T \)

  • SHA-256, applied twice in Bitcoin. Chapter 11's primitive, used as a cost rather than as an integrity check.
  • Includes the previous block's hash — so a change anywhere in history invalidates every subsequent proof — and the Merkle root of the transactions, so it commits to all of them at once.
  • The only free variable. Miners vary it (and other fields) and rehash, which is why mining is a brute-force search with no shortcut.
  • Adjusted by the network so blocks arrive about every ten minutes. Lower target means more work — and note that the difficulty is a consequence of how much hashpower exists, not a cause.
  • An inequality makes the probability of success per attempt tunable continuously, and makes verification a single comparison. An equality would be unachievable.

Expensive to satisfy, instant to check, and self-adjusting. Those three properties are what make it usable as a distributed clock.

25. How much work is one Bitcoin block?

Estimation

The network's difficulty adjusts so that a block appears about every ten minutes.

Predict first

Roughly how many hash computations does the whole network perform per block?

  • About 10¹²
  • About 10¹⁵
  • About 10²²
  • About 10⁴⁰

Correct: About 10²²

Note what this does and does not buy. It makes rewriting history expensive in proportion to how deep the change is — but only against an attacker who cannot match the network. Against one who can, the same rule that protects the honest chain protects the attacker's.

It is also why the energy debate is not incidental to the design: the cost is the security, so making it cheaper makes the ledger easier to rewrite. That coupling is what proof-of-stake systems try to break.

Why: At a network hashrate on the order of 10²⁰ hashes per second and 600 seconds per block, that is around 10²² attempts for each block found. The number is enormous by design: it is what an attacker must match and exceed to rewrite even one block, and it is why the security is measured in accumulated work rather than in bits.

Figure (svg): Proof of work: miners search for a nonce making the block's hash fall below a target, which is hard to find and instant to check.

Chapter 11's hash function used as a cost, not as an integrity check: work is what makes a block expensive to fake.

26. Cryptographic guarantee or economic assumption?

Definition probe

Sorting these correctly is the whole point of the chapter.

Sort into buckets

Classify each property of a proof-of-work cryptocurrency.

Cryptographic guarantee
Only the key holder can spend a coin; Altering an old block invalidates every block after it; A block header commits to every transaction in the block; A block took real computational effort
Economic assumption
The ledger will not be rewritten; Everyone converges on the same chain
crypto
Signatures, hash pointers, Merkle roots and proof of work are all theorems about the mathematics, holding regardless of who owns what.
econ
Convergence and immutability both depend on honest participants controlling more hashpower than any attacker. That is a fact about the world, it can change, and it has changed for smaller chains.

27. Why does proof of work need to be expensive?

Explain it to yourself

The puzzle produces no useful output. The hash that solves it is discarded.

Discussion prompt

Explain what the expense is buying, and why a cheap puzzle would not work.

Hint: Ask what an attacker must do to rewrite a block.

Answer:

The expense is the security. Rewriting a block means redoing its proof of work and every proof after it, faster than the honest network extends the chain. The cost of that attack is exactly the cost of the work being redone.

A cheap puzzle would let anyone rewrite history, because catching up would cost nothing. There would still be tamper-evidence — the hashes would not match — but no reason to prefer one chain over another.

It also rate-limits block creation without a clock. In a network with no trusted time source, the difficulty of the puzzle is what makes blocks arrive at a predictable rate, which is what lets participants agree on an ordering.

And it makes participation costly, which is a defence against Sybil attacks: creating a thousand identities is free, but creating a thousand identities' worth of hashpower is not. Votes are weighted by work rather than by identity.

The uncomfortable corollary: since cost is the security, reducing the energy cost reduces the security proportionally. That coupling is intrinsic to proof of work, and it is why alternatives such as proof of stake replace the resource rather than making it cheaper.

28. Find the problems in this payment design

Error analysis

From the specification for a store-and-forward digital token system.

Annotate

  • Nothing stops the holder sending the identical token to two merchants. Both verify the same valid signature, and the double spend is discovered a day later when both deposit it.
  • So when the double spend is found, there is no way to determine who did it. The scheme is anonymous and unaccountable — which is the pairing the Brands construction exists to avoid.
  • A whole day of exposure, and a spender can spend one token at hundreds of merchants within it. Detection latency is the attack window.
  • There is no challenge-response, so a merchant has no way to distinguish a first spend from a hundredth. Everything depends on reconciliation after the fact, with no remedy.

The signature makes it unforgeable and does nothing else. The three remaining requirements are all unmet, and the fix is the challenge-response that turns a coin into a one-time object.

29. Why digital cash schemes were not adopted

Real world

Brands' scheme and its relatives were published in the early 1990s, worked, and were not deployed at scale.

Discussion prompt

What defeated them, and what does that suggest about deploying cryptographic protocols generally?

Hint: Chapter 15's Secure Electronic Transaction met the same fate for related reasons.

Answer:

They needed an issuing bank willing to run them, and banks had no incentive to offer a payment instrument they could not trace or reverse. The anonymity that was the scheme's contribution was the reason its operator did not want it.

They needed software on the customer's device, in an era before that was routine — the same obstacle that sank SET.

And credit cards over SSL were good enough. Chargebacks handle fraud, the merchant absorbs the cost, and no user has to install anything. A worse-privacy solution with better operational properties won, which is the ordinary outcome.

What it suggests generally: a protocol competes on operational cost and incentive alignment, not on its security properties. A scheme whose main benefit accrues to users and whose main cost falls on the operator will not be deployed by the operator.

And it explains Bitcoin's shape. It succeeded partly by needing no bank's cooperation at all — the design removes the party whose incentives blocked the earlier schemes, which is a structural answer to a non-technical problem.

30. What a blockchain guarantees

Two truths and a lie

Two of these are claims the mathematics does not support.

Eliminate the wrong options

Which statement is correct?

  • a. Altering a past block is detectable to anyone holding the current head, and expensive to conceal in proportion to the work since
  • b. The data recorded on a blockchain is true
  • c. A blockchain cannot be rewritten

Survives elimination: a

Why: Tamper-evidence is the cryptographic guarantee and it is real. Immutability is an economic one and holds only under a majority assumption. And truthfulness is not a property of the system at all. Keeping the three apart is what lets you evaluate a proposal to 'put X on a blockchain' — the question is always whether the problem was tamper-evidence, and it usually was not.

31. Order these by how hard each is to achieve

Ranking

The four requirements from the start of the chapter, ranked by the machinery they need.

Put in order

  1. Unforgeability
  2. Anonymity
  3. Detecting double spending
  4. Agreeing a shared ledger with no trusted party

Why: Unforgeability is one signature — Chapter 13. Anonymity is a blind signature, from the same chapter. Detecting double spending needs the restricted blind signature and its secret-sharing structure, which is where the Brands scheme's complexity lives. And decentralised agreement leaves cryptography entirely: it needs an incentive structure and a majority assumption. The ordering tracks how far each requirement sits from mathematics.

Figure (svg): What each requirement of digital cash costs, and which of them cryptography can supply alone.

The first two are mathematics. The third is a systems problem. The fourth is an argument about who controls what.

32. What does a Merkle tree do in a block?

Socratic

Each block header contains a single Merkle root committing to all its transactions.

Discussion prompt

Why not just hash the transactions together, and what does the tree structure buy?

Hint: Chapter 12 answered this; the application is what is new.

Answer:

A flat hash would commit to all of them equally well — any change to any transaction changes the digest. So for tamper-evidence alone, a tree is unnecessary.

The tree buys short membership proofs. To prove a transaction is in a block, supply its sibling and one node per level — about log₂ n hashes rather than every transaction in the block.

Which enables lightweight clients. A phone can verify that a payment to it was included in a block by downloading only the headers and a short proof, rather than the whole chain. Without the tree, verification would require the full data.

And it makes headers small and uniform. A block header is a fixed size whatever the block contains, so the chain of headers — the thing that carries the proof of work — stays compact.

The general pattern from Chapter 12: commit to a large set with one value, and prove one element in logarithmic space. Certificate Transparency and content-addressed storage use the identical construction for the identical reason.

Figure (svg): Proof of work: miners search for a nonce making the block's hash fall below a target, which is hard to find and instant to check.

Chapter 11's hash function used as a cost, not as an integrity check: work is what makes a block expensive to fake.

33. What would you expect to fail?

Commit first

A cryptocurrency uses SHA-256, ECDSA on secp256k1, Merkle trees and proof of work, all implemented correctly.

Predict first

Where is the realistic failure?

  • SHA-256 collisions
  • Key management — users losing or having private keys stolen, and exchanges being compromised
  • The ECDSA curve being broken
  • Merkle proof forgery

Correct: Key management — users losing or having private keys stolen, and exchanges being compromised

There is also a cryptographic implementation failure with real history: reused or biased ECDSA nonces, which Chapter 13 showed recover the private key outright. Wallets have shipped with this bug and had funds drained.

And the structural point: removing the trusted party removed the recovery mechanism with it. A bank can reverse a fraudulent transfer; a blockchain cannot, by design. That is the same trade in a different place — the property that makes it censorship-resistant makes it unforgiving.

Why: Every cryptographic component is sound and none has been broken. What actually causes loss is key custody: a private key is a bearer instrument with no recovery path, so theft is final and loss is permanent. Exchange compromises, malware stealing wallet files, and users losing their own keys account for essentially all realised losses.

34. When is a blockchain the right tool?

Constraint

A colleague proposes putting a company's internal audit log 'on a blockchain'.

Discussion prompt

Work out whether it fits, and say what would actually solve the problem.

Hint: Ask which of the guarantees is needed, and whether there is a trusted party.

Answer:

Identify the requirement. An audit log needs tamper-evidence: nobody, including an administrator, should be able to alter history undetectably.

Tamper-evidence needs only hash pointers. Chapter 12's construction gives it with no consensus, no mining and no currency — a hash chain where each entry commits to the previous one, with the head published somewhere the administrator does not control.

Consensus is the expensive part, and it is not needed here. There is a trusted party — the company — and the question is only whether it can cheat. Publishing the head to a third party, or to a public transparency log, answers that.

A blockchain would add proof of work or a validator set, a currency, and a distributed network, to solve an agreement problem that does not exist. It would also make the log public, which an audit log usually must not be.

The rule: a blockchain is the right answer when there is no party everyone trusts and the ledger must be public. Where a trusted party exists, a hash chain plus an external witness is the same guarantee at a fraction of the cost.

This is worth stating clearly because the mismatch is extremely common: most proposals to use a blockchain are proposals to solve tamper-evidence, and tamper-evidence was solved in 1979.

35. Complete the double-spending mechanism

Faded example

Four blanks, and the elegance of the Brands scheme is visible in them.

Fill in the blanks

The coin embeds the spender's identity in a form requiring two equations to recover. At spending time the merchant issues a random challenge, and the spender's response gives one equation. So an honest spender stays anonymous, and a double spender supplies two equations and is identified.

Why: The merchant's challenge must be random and unpredictable, or a cheating spender could arrange to receive the same challenge twice and answer identically — producing one equation rather than two and escaping identification. It is the same requirement as a signature nonce in Chapter 13, and it fails in the same way: predictability defeats the whole construction.

36. Which problem does each mechanism solve?

Discrimination

Six mechanisms across the two systems in this chapter.

Sort into buckets

Sort each by the requirement it addresses.

Unforgeability
The bank's signature on a coin
Anonymity
Blinding the coin before signing
Double spending
The merchant's random challenge; Hash pointers between blocks
Agreement, or the incentive to reach it
Proof of work; The block reward paid to a miner
forge
Only the bank holds the private key, so only the bank can mint. Chapter 13's contribution, and the easiest requirement.
anon
Blinding means the bank signs a value it cannot see and cannot recognise on return — cryptographic anonymity rather than merely unlinked-so-far.
dbl
The challenge forces a second, independent equation on a second spend. Hash pointers make the ledger's record of past spends unalterable, which is Bitcoin's prevention rather than detection.
agree
Proof of work makes one chain more expensive than another, and the reward makes producing it worthwhile. Together they are the consensus mechanism, and neither is cryptography in the ordinary sense.

37. How final is a confirmation?

Edge cases

A merchant is told to wait six confirmations before treating a payment as settled.

Discussion prompt

What does each confirmation buy, and is settlement ever final?

Hint: Ask what an attacker must do to reverse a transaction n blocks deep.

Answer:

Each confirmation is one more block of work an attacker must redo. To reverse a transaction six blocks deep, she must build a competing chain of at least seven blocks faster than the honest network builds one — so the cost grows with depth.

Six is a convention, not a threshold. It corresponds to a probability of reversal that is small under the assumption that the attacker controls well under half the hashpower. If she controls more, no number of confirmations suffices.

So settlement is probabilistic, never final. This is a genuine difference from a bank transfer, which is final by legal fiat. A blockchain offers 'increasingly unlikely to be reversed', which is a different kind of assurance.

And the right number depends on the value. A coffee needs zero confirmations because reversing it is not worth the work; a large transfer might sensibly wait for many more.

The general point, and it is the chapter's: where the guarantee is economic, the right parameter is set by comparing the attacker's cost with her gain. That is a business calculation, and no amount of cryptography settles it.

38. What does “it uses blockchain” not tell you?

Missing information

The phrase appears in product descriptions constantly.

Discussion prompt

List what remains undetermined, in the order you would ask.

Hint: Start with whether the agreement problem exists at all.

Answer:

Is there a trusted party? If yes, consensus is unnecessary and a hash chain with an external witness gives the same tamper-evidence far more cheaply.

Who validates, and what stops a Sybil attack? Proof of work, a permissioned validator set, or nothing? 'Distributed' without an answer here means 'a database with extra steps'.

What is the cost of rewriting history, in money? For a small chain this can be a few hundred dollars an hour of rented hashpower — a number worth computing before relying on immutability.

Is the data public, and must it be? Permanent publication is a feature for a currency and a liability for anything containing personal information, which cannot then be deleted.

How are keys custodied and recovered? This is where all realised losses occur, and 'not our responsibility' is a common answer.

And what is actually being solved? If the answer is tamper-evidence, that was solved in 1979 and needs none of the rest.

39. What happens to a transaction in an orphaned block?

Prediction

Two miners find blocks at nearly the same moment, the network splits, and one branch is abandoned.

Predict first

What happens to the transactions in the abandoned block?

  • They are reversed and the money is destroyed
  • They return to the pool and are usually included in a later block
  • They are permanently invalid
  • They are duplicated onto both chains

Correct: They return to the pool and are usually included in a later block

This is also why a transaction with one confirmation is not settled: a shallow reorganisation is a normal event, not an attack, and a payment can move from block 500 to block 501 without anything going wrong.

And it is why a double spend attack works the way it does: the attacker's goal is to get a conflicting transaction into the winning chain, so that the original becomes unincludable rather than merely delayed.

Why: The transactions themselves are still validly signed and still unspent, so miners simply put them back into the pool and include them in a subsequent block. Only the block is orphaned, not the transactions. The exception is the block reward, which is created by the block and disappears with it — which is why miners have a strong incentive to build on the chain everyone else is building on.

Figure (svg): Two competing chains, with the network following whichever has the most accumulated work.

Tamper-evidence came from hashing; agreement comes from the rule that the chain with the most work wins.

40. Reading the anonymity claim

Notation

Two systems both described as anonymous, and the difference is in the quantifier.

Annotate

On: \( \text{Bitcoin: } \Pr[\text{linked}] > 0 \text{ and grows} \qquad \text{blind signature: } \Pr[\text{linked}] = \tfrac{1}{N} \)

  • Linkage probability is not zero and increases over time, because the record is permanent and analysis techniques improve against data already published.
  • Every coin the bank ever signed is equally likely to be the one now presented — so the probability is 1/N for N coins issued, and it is information-theoretic rather than computational.
  • It does not degrade. No future analysis, no faster computer and no quantum algorithm changes it, because the bank never had the information.
  • The number of coins issued in the same batch. If only three people use the system, N = 3 and the guarantee is nearly worthless — a limit no protocol can raise.
  • Timing, amounts, network addresses and delivery details. Both guarantees are about what the protocol reveals, and most real de-anonymisation happens outside it.

The lesson generalises past currency: 'anonymous' is a claim about a specific adversary with a specific view, and the anonymity set is usually the binding constraint rather than the mathematics.

41. How large is the anonymity set?

Estimation

A blind-signature system's privacy depends on how many indistinguishable coins exist.

Predict first

If a bank issues 1000 coins in a batch, what is an observer's best guess about which one a given spend came from?

  • Certainty, from the signature
  • 1 in 1000
  • 1 in 2
  • Impossible to say

Correct: 1 in 1000

Which makes the anonymity set the number to ask about. A system with ten users gives one-in-ten anonymity however good its cryptography, and the mathematics cannot compensate.

This is the same reasoning that makes a mix network or a privacy pool's size the headline figure, and why such systems are less private when they are less popular — an unusual property, where adoption is a security parameter.

Why: Every coin in the batch is equally consistent with the one being presented, so the probability is 1/1000 and no computation improves it. This is an information-theoretic guarantee like the one-time pad's — and, exactly as there, its strength depends on a parameter under the operator's control rather than on any hardness assumption.

42. Find the problems in this token launch

Error analysis

From the technical section of a proposal.

Annotate

  • Security comes from hashrate, not from the algorithm. Sharing SHA-256 with Bitcoin is actively worse: capacity built for Bitcoin can be rented and pointed at this chain for an afternoon.
  • Faster blocks mean more accidental forks and less work per block, so each confirmation is worth proportionally less. Settlement is not faster in security terms, only in appearance.
  • A single confirmation is routinely undone by ordinary forks, before any attacker is involved. Combined with the two points above, it is close to accepting unconfirmed payments.
  • A permanent public record of every transaction is a privacy liability as much as an audit feature, and it cannot be undone later — data published once is published forever.

The first claim is the load-bearing error, and it is the chapter's central point restated: security is hashrate, and hashrate is not inherited.

43. What is missing from a digital cash proposal?

Missing information

A specification says coins are signed by an issuer and verified by merchants.

Discussion prompt

List what remains undetermined, ordered by how badly each could fail.

Hint: Work through the four requirements in turn.

Answer:

What stops a coin being spent twice? Prevention needs an online check; detection needs an embedded identity and a challenge-response. A signature alone gives neither, and this is the requirement most often left out.

Is the challenge fresh and unpredictable? A predictable challenge lets a double spender produce two identical responses and escape identification entirely.

Is the issuance blinded? Without it the issuer can link every coin to a withdrawal, and the system is a traceable ledger with extra steps.

What happens to the setup secrets? Parameters with a hidden relationship must be destroyed, or whoever holds them can forge.

What is the detection latency and the remedy? Detection after the fact means a merchant has already been defrauded, and the answer must be legal rather than technical.

And what is the anonymity set? A system with few users provides little privacy regardless of the mathematics.

44. Four requirements, four levels of difficulty

Picture it

The chapter's shape in one picture. The bars get longer as the requirement moves away from mathematics.

Figure (svg): What each requirement of digital cash costs, and which of them cryptography can supply alone.

The first two are mathematics. The third is a systems problem. The fourth is an argument about who controls what.

The first two were solved three chapters ago. The third needed a new construction. The fourth needed an economy.

45. Explain proof of work to someone who thinks it is wasteful

Explain it

A colleague says mining burns electricity to compute numbers that are thrown away, and that this is obviously absurd.

Discussion prompt

Give the honest explanation — including the part where they are right.

Hint: The waste is the mechanism, not a side effect.

Answer:

Concede the observation: the winning hash is discarded and computes nothing useful. That is accurate.

Then explain what the cost buys. In a network with no trusted party, something must make it expensive to propose a version of history. The electricity is that expense — rewriting the last hour of the ledger means redoing an hour of the entire world's mining, faster than it happens.

And it solves a second problem: identities are free to create, so votes cannot be counted per participant. Weighting by work makes creating a thousand identities useless unless you also have a thousand identities' worth of hardware.

Then the uncomfortable corollary, which is where they are right: because the cost is the security, making it cheaper makes the ledger easier to rewrite. The two cannot be separated within this design, so 'greener proof of work' is close to a contradiction.

Which is why alternatives replace the resource rather than reducing it. Proof of stake makes the expensive thing a deposit that can be confiscated instead of energy that is spent — a different assumption about the world, not an escape from needing one.

The honest summary: the waste is the mechanism, and disliking it is a reasonable position about the mechanism rather than a misunderstanding of it.

46. What an attack on a chain costs

Cost model

The security of a proof-of-work ledger is a number in currency, and it can be computed.

Annotate

On: \( \text{cost} \approx \text{(fraction of network hashrate rented)} \times \text{(time)} \times \text{(price per hash)} \)

  • An attacker needs more than half to rewrite reliably. For a large chain this hardware does not exist to rent; for a small one it does.
  • Long enough to outpace the honest chain past the transaction being reversed. Deeper confirmations mean longer, which is why merchants wait.
  • Set by the rental market for mining capacity. For chains sharing an algorithm with a larger chain, capacity can simply be redirected — which is why a minority chain on a major algorithm is especially exposed.
  • Attack cost against the value of the transaction being reversed. If a transfer is worth more than an hour of rented hashpower, the economics favour the attacker.
  • Security is not a property of the protocol but of the protocol plus its market share. Two chains with identical code have completely different security if one has a hundred times the hashrate.

No cryptographic parameter appears anywhere in this formula, which is the clearest statement of where this chapter's security actually lives.

47. Chains that were actually reorganised

Real world

The majority assumption is not hypothetical, and it has failed repeatedly.

Discussion prompt

What happens when it does, and what does that tell you about how to evaluate such a system?

Hint: Think about chains sharing an algorithm with a much larger one.

Answer:

Several smaller proof-of-work chains have been reorganised by rented hashpower, with attackers reversing their own deposits at exchanges after withdrawing other assets — a double spend at scale, executed for a few hours' rental cost.

The pattern is chains that share a hash algorithm with a much larger one. Capacity built for the large chain can be pointed at the small one for an afternoon, so the small chain's security is set by the large chain's spare capacity rather than by its own miners.

The cryptography was never involved. SHA-256, the signatures and the Merkle trees all behaved exactly as specified. The assumption about resource distribution was false.

How to evaluate such a system, then: compute the cost of an hour of majority hashrate and compare it with the value of transactions being settled. If the second exceeds the first, the ledger is not protecting them.

And the general lesson for the whole course: a security claim resting on an assumption about the world requires you to check that assumption in your setting. It is not inherited from the protocol, and it does not transfer between deployments.

48. Why must the setup exponents be discarded?

Explain it to yourself

The Brands scheme's initialisation chooses two secret exponents, defines g₁ and g₂ from them, and then destroys them.

Discussion prompt

Explain why keeping them would be dangerous, and name the modern practice this anticipates.

Hint: Ask what someone knowing the relationship between g, g₁ and g₂ could do.

Answer:

Knowing the exponents means knowing the discrete logarithms relating g, g₁ and g₂. The scheme's security assumes nobody can find them, so anyone who simply kept them has the trapdoor the whole construction was built to be without.

With them, a spender could construct coins whose identity representation is false, or produce two responses that appear independent while encoding nothing — defeating both unforgeability and double-spending detection.

The book's phrasing is exact: storing them serves no useful purpose, and if a hacker discovers them the system is compromised. The safest state for a secret nobody needs is not to exist.

The modern practice this anticipates is the trusted setup ceremony, used by zero-knowledge proof systems whose parameters have exactly this shape. Participants contribute randomness and destroy their contribution, and the setup is secure if any one participant was honest.

And the related idea is nothing-up-my-sleeve numbers — constants derived from digits of π or similar, so that no designer could have chosen them to embed a trapdoor. AES's S-box being algebraic rather than tabulated is Chapter 8's version of the same concern.

49. Pseudonymity against anonymity

Trade off

Both are called privacy and they are different guarantees. Fill the blanks.

Comparison matrix

BitcoinBlind-signature cash
What is publicevery transaction, permanentlynothing beyond the coin's validity
Linkage to identitypossible, by clustering and touchpointsimpossible — the bank never saw the coin
Improves or decays over timedecays — analysis improves against a permanent recordfixed — no later analysis helps
Accountability for cheatingprevention, so none neededthe identity is revealed automatically
Kind of guaranteenot linked yetcannot be linked

The third row is the decisive one. A permanent public record means today's privacy is subject to tomorrow's analysis, which is not a risk an unconditional guarantee has.

50. Which chapter supplied each ingredient?

Sorting

Nothing in this chapter is a new primitive. Everything is assembled from earlier ones.

Sort into buckets

Sort each ingredient by where it came from.

Chapter 10 — discrete logarithms
A safe prime p with q = (p−1)/2
Chapter 12 — hash applications
Hash pointers linking blocks; The Merkle root in a block header
Chapter 13 — signatures
The bank's signature on a coin; Blinding the coin before signing; ECDSA signatures on transactions
ch10
The safe prime construction comes straight from Section 10.2's requirement that p − 1 have a large prime factor, so that Pohlig-Hellman gains nothing.
ch12
Hash pointers and Merkle trees are exactly Section 12.7's constructions, used here for tamper-evidence and short membership proofs.
ch13
Ordinary and blind signatures, both from Chapter 13. The restricted blind signature is the one genuinely new construction, and it is a refinement of the blind signature rather than a new primitive.

One new construction in the whole chapter. What is new is the combination, and the requirement — agreement without a trusted party — that no combination of primitives can meet.

51. Which system would you trust with a large payment?

Commit first

Three settlement options for a transfer worth more than the daily rental cost of a small chain's hashrate.

Predict first

Which do you choose?

  • A small proof-of-work chain sharing an algorithm with a much larger one
  • A large proof-of-work chain, waiting a generous number of confirmations
  • A bank transfer
  • A blind-signature digital cash scheme

Correct: A large proof-of-work chain, waiting a generous number of confirmations

The point of the question is that the answer depends on a number — attack cost against transaction value — rather than on which technology is better. That is what an economic security guarantee means in practice.

And it explains the confirmation convention: waiting is how you buy more attack cost, and the right amount of waiting scales with the amount at stake.

Why: The small chain fails the cost comparison outright — reversing the transfer costs less than the transfer is worth, and hashpower for its algorithm is rentable. The large chain's attack cost exceeds any plausible gain, and confirmations deepen the protection. A bank transfer is also defensible and offers legal reversibility, which is a different guarantee. The digital cash scheme detects double spending after the fact, which is the wrong shape for a single large payment with no ongoing relationship.

52. When does anonymity actually hold?

Edge cases

A blind signature makes linking a coin to a withdrawal impossible. That is a strong statement with edges.

Discussion prompt

What can still de-anonymise a spender in such a system?

Hint: The cryptography is not the only channel.

Answer:

Timing and amounts. If Alice withdraws a coin of an unusual denomination and one appears minutes later at a merchant, the correlation is obvious without any cryptography being broken. This is traffic analysis, from Chapter 1.

The network layer. The coin travels over a connection with an IP address attached. Blinding protects the coin's contents and not its envelope.

The merchant relationship. A coin spent at a shop that ships to an address links the transaction to a person, whatever the bank can or cannot see.

And withdrawal patterns. If very few people use the system, being a user at all is identifying, and set-size is a limit no protocol can raise.

So the guarantee is precise and narrow: the bank cannot link this coin to this withdrawal. Everything outside that sentence is a separate problem, and most real de-anonymisation happens outside it.

Which is Chapter 1's lesson in its last appearance: a cipher protects the values and not the pattern of the values, and the pattern is often most of the information.

53. Where cryptography stops

Pattern

This is the first chapter in the book whose requirements cannot all be met by mathematics, and the boundary is worth drawing precisely.

  1. Unforgeability is a theorem. A signature scheme with an unforgeability proof, from Chapter 13.
  2. Anonymity can be a theorem. A blind signature makes linking a coin to a withdrawal impossible, not merely difficult — which is stronger than anything the pseudonymous ledger offers.
  3. Detecting double spending is a construction. The restricted blind signature releases one share per spend and the identity on the second, with no discretion involved.
  4. Agreement between untrusting parties is not cryptography at all. Proof of work makes a chain expensive; the most-work rule makes it canonical; and the whole thing holds only while honest participants outspend an attacker.
  5. And value is outside the system entirely. No property of the protocol makes a coin worth anything.

The habit to carry: when a system claims a property, ask whether it is a theorem, an assumption about the world, or a social fact. All three appear in this chapter, and only the first is what the previous fifteen chapters were about.

Figure (svg): What each requirement of digital cash costs, and which of them cryptography can supply alone.

The first two are mathematics. The third is a systems problem. The fourth is an argument about who controls what.

54. A blockchain makes data immutable

Trap

The trap

The trap. Each block contains the hash of the previous one, so altering any block breaks every hash after it. The data is therefore immutable — it cannot be changed, and that is a cryptographic guarantee.

This is the standard description, and the first sentence is exactly right.

The fix

Why it fails. Hashing gives tamper-evidence, not immutability: it makes a change detectable to anyone holding the true head. It does nothing to prevent someone building an alternative chain, which is perfectly consistent and equally valid to the hash function.

What actually prevents rewriting is the cost of redoing the work, plus the rule that the chain with the most work wins. Both are outside the cryptography, and the second holds only while honest participants control more hashpower than any attacker.

And that assumption fails in practice. Several smaller proof-of-work chains have been reorganised by attackers renting hashpower for a few hours, at costs in the hundreds or thousands of dollars. Their cryptography was identical to Bitcoin's.

The accurate statement is: rewriting history is detectable, and costs approximately the work done since the point being changed. That is an economic barrier of computable size, and treating it as an absolute is how people end up relying on a chain whose reorganisation costs less than the transaction they are protecting.

The general habit: whenever a system's guarantee involves a majority, a cost, or an incentive, it is an assumption about the world. Assumptions about the world change; theorems do not.

55. Check: what proof of work provides

Check

Work it out before you click.

Check your understanding

Hash pointers already make a chain tamper-evident. What does proof of work add?

  • A. It makes the hashes harder to compute
  • B. It makes producing a competing chain expensive, so participants can agree on which chain is canonical (correct)
  • C. It encrypts the transactions
  • D. It prevents forged signatures

Answer: B

Why: Hash pointers detect alteration relative to a known head; they cannot say which of two internally consistent chains is real. Proof of work attaches a measurable cost to each block, so 'the chain with the most work' becomes a rule everyone can apply independently and nobody can cheaply subvert. It solves agreement, not integrity.

Why A tempts people
SHA-256's cost per evaluation is unchanged; the puzzle requires many evaluations, which is a different thing.
Why C tempts people
Blockchain transactions are not encrypted at all — they are public by design, which is what makes chain analysis possible.
Why D tempts people
Signature unforgeability comes from ECDSA and is entirely separate from mining.

56. Check: the double-spending mechanism

Check

Recall how the identity is protected and released.

Check your understanding

In the Brands scheme, why does spending a coin once reveal nothing about the spender?

  • A. The bank encrypts the identity
  • B. The response gives one linear equation in the identity, which is under-determined (correct)
  • C. The merchant deletes the record
  • D. The identity is not in the coin at all

Answer: B

Why: The identity is embedded so that recovering it needs two independent equations. One spend, under one merchant's random challenge, produces one — leaving the system under-determined and the spender anonymous. A second spend under a different challenge produces the second equation, and the identity falls out. Nobody decides to revoke the anonymity; double spending performs the revocation.

Why A tempts people
There is no encryption of an identity and no key that could decrypt it — that would require a party able to unmask honest spenders, which is what the scheme avoids.
Why C tempts people
The merchant deposits the coin with the bank; nothing is deleted, and the record is what enables detection.
Why D tempts people
It is in the coin, in a hidden form. If it were absent, a double spender could never be identified.

57. Check: which guarantee is which

Check

The distinction this chapter exists to draw.

Check your understanding

Which of these is an economic assumption rather than a cryptographic guarantee?

  • A. Only the private key holder can spend a coin
  • B. The block header commits to every transaction in the block
  • C. History more than six blocks deep will not be rewritten (correct)
  • D. Altering a block invalidates every subsequent hash pointer

Answer: C

Why: Immutability of history depends on honest participants controlling more hashpower than any attacker — a claim about how resources are distributed in the world, not a theorem. It has failed for several smaller chains. The other three follow from signature unforgeability, Merkle tree structure and hash collision resistance respectively, and hold regardless of who owns what.

Why A tempts people
ECDSA unforgeability. A theorem, contingent only on the discrete log problem in the curve group.
Why B tempts people
The Merkle root's collision resistance, from Chapter 12. Independent of any assumption about participants.
Why D tempts people
Hash collision resistance again — and note that this is detectability, which is exactly what option C is not.

58. Draw the boundary

Connect it up

This chapter's value is knowing where the mathematics ends.

Draw it

List the four requirements of digital cash and, beside each, the mechanism that meets it and whether that mechanism is a theorem, an assumption about the world, or a social fact. Then draw the withdraw-spend-deposit cycle of the Brands scheme, marking where anonymity comes from and where the second equation appears. Beside it, draw Bitcoin's five stages and mark which one involves no cryptography. Finish with the accurate one-sentence statement of what a blockchain guarantees.

That final sentence — tamper-evidence relative to a head, and a cost to rewrite proportional to the work since — is the version worth being able to say precisely, because almost every claim made about blockchains is a loose version of it.

59. Exit ticket

Exit ticket

One question, about the boundary this chapter draws.

Predict first

What does a proof-of-work cryptocurrency assume that is not a mathematical fact?

  • That SHA-256 is collision resistant
  • That honest participants collectively control more computing power than any attacker
  • That signatures are unforgeable
  • That hash pointers detect alteration

Correct: That honest participants collectively control more computing power than any attacker

Why: The other three are cryptographic assumptions of the ordinary kind — well studied, and about mathematics. The majority-hashpower assumption is about how resources happen to be distributed in the world, it can change, and it has changed for smaller chains that were reorganised by rented computing power. Tamper-evidence is cryptographic; immutability is economic, and separating the two is what this chapter is for.

60. What to carry into Chapter 17

Recap

The first requirements in this book that mathematics alone cannot meet.

Chapter 17 next. Secret sharing: splitting a secret among n people so that any k of them can recover it and any k−1 learn nothing at all. It is the same polynomial mathematics that hid the identity in a coin, used deliberately — and it is unconditionally secure, which almost nothing in this book is.

Figure (svg): What each requirement of digital cash costs, and which of them cryptography can supply alone.

The first two are mathematics. The third is a systems problem. The fourth is an argument about who controls what.

Sources

  1. Introduction to Cryptography with Coding Theory, 3rd edition — Wade Trappe and Lawrence C. Washington — Pearson, 2020 (ISBN 978-0-13-485906-4)
  2. Chapter 16 — Digital Cash (sections 16.1-16.4) — Trappe & Washington, 3rd edition, pp. 318-339

Want this taught 1-on-1? Alexander tutors Cryptography — $55/session, free consultation.

Book on Wyzant · Text (657) 465-8108