2021-08-18 17:11:38 -06:00
# Altair -- Minimal Light Client
2020-11-16 15:02:11 +08:00
**Notice**: This document is a work-in-progress for researchers and implementers.
## Table of contents
<!-- TOC -->
<!-- START doctoc generated TOC please keep comment here to allow auto update -->
<!-- DON'T EDIT THIS SECTION, INSTEAD RE - RUN doctoc TO UPDATE -->
- [Introduction ](#introduction )
- [Constants ](#constants )
2021-05-06 15:52:52 +02:00
- [Preset ](#preset )
2020-11-17 12:42:09 +00:00
- [Misc ](#misc )
2020-11-16 15:02:11 +08:00
- [Containers ](#containers )
2021-03-11 14:27:23 +08:00
- [`LightClientUpdate` ](#lightclientupdate )
- [`LightClientStore` ](#lightclientstore )
2020-12-10 17:04:11 +08:00
- [Helper functions ](#helper-functions )
2022-04-27 16:07:49 +02:00
- [`is_sync_committee_update` ](#is_sync_committee_update )
2022-02-09 18:06:10 -07:00
- [`is_finality_update` ](#is_finality_update )
2022-04-29 16:22:26 +02:00
- [`is_better_update` ](#is_better_update )
2022-07-08 21:46:34 -07:00
- [`get_safety_threshold` ](#get_safety_threshold )
- [`get_subtree_index` ](#get_subtree_index )
2022-07-08 21:59:09 -07:00
- [`compute_sync_committee_period_at_slot` ](#compute_sync_committee_period_at_slot )
2020-11-16 15:02:11 +08:00
- [Light client state updates ](#light-client-state-updates )
2021-11-30 21:57:43 +08:00
- [`process_slot_for_light_client_store` ](#process_slot_for_light_client_store )
2021-01-19 20:44:21 +08:00
- [`validate_light_client_update` ](#validate_light_client_update )
2020-11-18 10:33:42 +00:00
- [`apply_light_client_update` ](#apply_light_client_update )
2020-11-17 12:42:09 +00:00
- [`process_light_client_update` ](#process_light_client_update )
2020-11-16 15:02:11 +08:00
<!-- END doctoc generated TOC please keep comment here to allow auto update -->
<!-- /TOC -->
## Introduction
2021-08-18 17:11:38 -06:00
The beacon chain is designed to be light client friendly for constrained environments to
access Ethereum with reasonable safety and liveness.
2020-12-07 08:10:39 -07:00
Such environments include resource-constrained devices (e.g. phones for trust-minimised wallets)
and metered VMs (e.g. blockchain VMs for cross-chain bridges).
2020-11-17 12:42:09 +00:00
2020-12-07 08:10:39 -07:00
This document suggests a minimal light client design for the beacon chain that
uses sync committees introduced in [this beacon chain extension ](./beacon-chain.md ).
2020-11-16 15:02:11 +08:00
## Constants
| Name | Value |
| - | - |
2022-01-11 12:07:49 +01:00
| `FINALIZED_ROOT_INDEX` | `get_generalized_index(BeaconState, 'finalized_checkpoint', 'root')` (= 105) |
| `NEXT_SYNC_COMMITTEE_INDEX` | `get_generalized_index(BeaconState, 'next_sync_committee')` (= 55) |
2020-11-17 12:42:09 +00:00
2021-05-06 15:52:52 +02:00
## Preset
2020-11-17 12:42:09 +00:00
### Misc
2022-01-11 12:07:49 +01:00
| Name | Value | Unit | Duration |
| - | - | - | - |
2022-04-26 22:32:25 +02:00
| `MIN_SYNC_COMMITTEE_PARTICIPANTS` | `1` | validators | |
2022-03-03 20:16:32 -08:00
| `UPDATE_TIMEOUT` | `SLOTS_PER_EPOCH * EPOCHS_PER_SYNC_COMMITTEE_PERIOD` | slots | ~27.3 hours |
2020-11-17 12:42:09 +00:00
2020-11-16 15:02:11 +08:00
## Containers
2021-03-11 14:27:23 +08:00
### `LightClientUpdate`
2020-11-16 15:02:11 +08:00
2020-11-17 12:42:09 +00:00
```python
class LightClientUpdate(Container):
2021-11-27 07:25:27 -06:00
# The beacon block header that is attested to by the sync committee
attested_header: BeaconBlockHeader
2022-04-29 16:22:26 +02:00
# Next sync committee corresponding to `attested_header`
2020-11-18 10:33:42 +00:00
next_sync_committee: SyncCommittee
2020-12-16 15:00:06 +08:00
next_sync_committee_branch: Vector[Bytes32, floorlog2(NEXT_SYNC_COMMITTEE_INDEX)]
2021-11-27 07:25:27 -06:00
# The finalized beacon block header attested to by Merkle branch
finalized_header: BeaconBlockHeader
2020-12-16 15:00:06 +08:00
finality_branch: Vector[Bytes32, floorlog2(FINALIZED_ROOT_INDEX)]
2020-11-17 12:42:09 +00:00
# Sync committee aggregate signature
2022-01-11 11:22:39 +01:00
sync_aggregate: SyncAggregate
2022-04-26 22:32:25 +02:00
# Slot at which the aggregate signature was created (untrusted)
signature_slot: Slot
2020-11-17 12:42:09 +00:00
```
2021-03-11 14:27:23 +08:00
### `LightClientStore`
2020-11-16 15:02:11 +08:00
```python
2021-11-30 20:38:42 +08:00
@dataclass
2021-05-06 10:00:04 -07:00
class LightClientStore(object):
2021-11-27 07:25:27 -06:00
# Beacon block header that is finalized
finalized_header: BeaconBlockHeader
# Sync committees corresponding to the header
current_sync_committee: SyncCommittee
next_sync_committee: SyncCommittee
# Best available header to switch finalized head to if we see nothing else
2021-11-26 15:11:19 -06:00
best_valid_update: Optional[LightClientUpdate]
2021-11-27 07:25:27 -06:00
# Most recent available reasonably-safe header
2021-11-26 15:11:19 -06:00
optimistic_header: BeaconBlockHeader
2021-11-29 07:04:05 -06:00
# Max number of active participants in a sync committee (used to calculate safety threshold)
previous_max_active_participants: uint64
current_max_active_participants: uint64
2020-11-16 15:02:11 +08:00
```
2020-12-10 17:04:11 +08:00
## Helper functions
2022-04-27 16:07:49 +02:00
### `is_sync_committee_update`
```python
def is_sync_committee_update(update: LightClientUpdate) -> bool:
return update.next_sync_committee_branch != [Bytes32() for _ in range(floorlog2(NEXT_SYNC_COMMITTEE_INDEX))]
```
2022-02-09 18:06:10 -07:00
### `is_finality_update`
```python
def is_finality_update(update: LightClientUpdate) -> bool:
2022-05-09 14:37:54 +02:00
return update.finality_branch != [Bytes32() for _ in range(floorlog2(FINALIZED_ROOT_INDEX))]
2022-02-09 18:06:10 -07:00
```
2022-04-29 16:22:26 +02:00
### `is_better_update`
```python
def is_better_update(new_update: LightClientUpdate, old_update: LightClientUpdate) -> bool:
# Compare supermajority (> 2/3) sync committee participation
max_active_participants = len(new_update.sync_aggregate.sync_committee_bits)
new_num_active_participants = sum(new_update.sync_aggregate.sync_committee_bits)
old_num_active_participants = sum(old_update.sync_aggregate.sync_committee_bits)
new_has_supermajority = new_num_active_participants * 3 >= max_active_participants * 2
old_has_supermajority = old_num_active_participants * 3 >= max_active_participants * 2
if new_has_supermajority != old_has_supermajority:
return new_has_supermajority > old_has_supermajority
if not new_has_supermajority and new_num_active_participants != old_num_active_participants:
return new_num_active_participants > old_num_active_participants
# Compare indication of any finality
new_has_finality = is_finality_update(new_update)
old_has_finality = is_finality_update(old_update)
if new_has_finality != old_has_finality:
2022-07-08 22:01:56 -07:00
return new_has_finality
2022-04-29 16:22:26 +02:00
# Compare sync committee finality
if new_has_finality:
new_has_sync_committee_finality = (
2022-07-08 22:03:31 -07:00
compute_sync_committee_period_at_slot(new_update.finalized_header.slot)
== compute_sync_committee_period_at_slot(new_update.attested_header.slot)
2022-04-29 16:22:26 +02:00
)
old_has_sync_committee_finality = (
2022-07-08 22:03:31 -07:00
compute_sync_committee_period_at_slot(old_update.finalized_header.slot)
== compute_sync_committee_period_at_slot(old_update.attested_header.slot)
2022-04-29 16:22:26 +02:00
)
if new_has_sync_committee_finality != old_has_sync_committee_finality:
2022-07-08 22:05:48 -07:00
return new_has_sync_committee_finality
2022-04-29 16:22:26 +02:00
# Tiebreaker 1: Sync committee participation beyond supermajority
if new_num_active_participants != old_num_active_participants:
return new_num_active_participants > old_num_active_participants
# Tiebreaker 2: Prefer older data (fewer changes to best)
if new_update.attested_header.slot != old_update.attested_header.slot:
return new_update.attested_header.slot < old_update.attested_header.slot
return new_update.signature_slot < old_update.signature_slot
```
2022-07-08 21:46:34 -07:00
### `get_safety_threshold`
```python
def get_safety_threshold(store: LightClientStore) -> uint64:
return max(
store.previous_max_active_participants,
store.current_max_active_participants,
) // 2
```
### `get_subtree_index`
```python
def get_subtree_index(generalized_index: GeneralizedIndex) -> uint64:
return uint64(generalized_index % 2**(floorlog2(generalized_index)))
```
2022-07-08 21:59:09 -07:00
### `compute_sync_committee_period_at_slot`
```python
def compute_sync_committee_period_at_slot(slot: Slot) -> uint64:
return compute_sync_committee_period(compute_epoch_at_slot(slot))
```
2020-11-16 15:02:11 +08:00
## Light client state updates
2022-01-11 11:48:22 +01:00
A light client maintains its state in a `store` object of type `LightClientStore` and receives `update` objects of type `LightClientUpdate` . Every `update` triggers `process_light_client_update(store, update, current_slot, genesis_validators_root)` where `current_slot` is the current slot based on a local clock. `process_slot_for_light_client_store` is triggered every time the current slot increments.
2021-11-26 15:11:19 -06:00
2021-11-30 21:57:43 +08:00
#### `process_slot_for_light_client_store`
2021-11-26 15:11:19 -06:00
```python
2021-11-30 20:38:42 +08:00
def process_slot_for_light_client_store(store: LightClientStore, current_slot: Slot) -> None:
2021-12-10 07:48:14 -06:00
if current_slot % UPDATE_TIMEOUT == 0:
2021-11-29 07:04:05 -06:00
store.previous_max_active_participants = store.current_max_active_participants
store.current_max_active_participants = 0
2021-12-10 07:48:14 -06:00
if (
current_slot > store.finalized_header.slot + UPDATE_TIMEOUT
and store.best_valid_update is not None
):
# Forced best update when the update timeout has elapsed
2022-04-29 16:22:26 +02:00
if store.best_valid_update.finalized_header.slot < = store.finalized_header.slot:
store.best_valid_update.finalized_header = store.best_valid_update.attested_header
2021-12-10 07:48:14 -06:00
apply_light_client_update(store, store.best_valid_update)
store.best_valid_update = None
2021-11-26 15:11:19 -06:00
```
2020-11-16 15:02:11 +08:00
2021-01-19 20:44:21 +08:00
#### `validate_light_client_update`
2020-11-16 15:02:11 +08:00
```python
2021-11-27 07:25:27 -06:00
def validate_light_client_update(store: LightClientStore,
2021-05-04 07:39:22 -06:00
update: LightClientUpdate,
2021-11-29 07:04:05 -06:00
current_slot: Slot,
2021-03-11 21:02:05 +08:00
genesis_validators_root: Root) -> None:
2022-04-29 16:22:26 +02:00
# Verify sync committee has sufficient participants
sync_aggregate = update.sync_aggregate
assert sum(sync_aggregate.sync_committee_bits) >= MIN_SYNC_COMMITTEE_PARTICIPANTS
2020-11-17 12:42:09 +00:00
# Verify update does not skip a sync committee period
2022-04-29 16:22:26 +02:00
assert current_slot >= update.signature_slot > update.attested_header.slot >= update.finalized_header.slot
2022-07-08 21:59:09 -07:00
store_period = compute_sync_committee_period_at_slot(store.finalized_header.slot)
signature_period = compute_sync_committee_period_at_slot(update.signature_slot)
2022-04-29 16:22:26 +02:00
assert signature_period in (store_period, store_period + 1)
# Verify update is relevant
2022-07-08 21:59:09 -07:00
attested_period = compute_sync_committee_period_at_slot(update.attested_header.slot)
2022-04-29 16:22:26 +02:00
assert update.attested_header.slot > store.finalized_header.slot
2020-11-18 10:33:42 +00:00
2022-06-27 22:36:55 +02:00
# Verify that the `finality_branch` , if present, confirms `finalized_header`
# to match the finalized checkpoint root saved in the state of `attested_header` .
# Note that the genesis finalized checkpoint root is represented as a zero hash.
2022-02-09 18:06:10 -07:00
if not is_finality_update(update):
2022-05-09 14:37:54 +02:00
assert update.finalized_header == BeaconBlockHeader()
2020-11-18 16:27:19 +08:00
else:
2022-06-27 22:26:35 +02:00
if update.finalized_header.slot == GENESIS_SLOT:
2022-05-09 14:37:54 +02:00
finalized_root = Bytes32()
assert update.finalized_header == BeaconBlockHeader()
2022-06-27 22:26:35 +02:00
else:
finalized_root = hash_tree_root(update.finalized_header)
2020-11-18 16:27:19 +08:00
assert is_valid_merkle_branch(
2022-05-09 14:37:54 +02:00
leaf=finalized_root,
2020-11-18 10:33:42 +00:00
branch=update.finality_branch,
2020-12-16 15:00:06 +08:00
depth=floorlog2(FINALIZED_ROOT_INDEX),
2020-12-10 17:04:11 +08:00
index=get_subtree_index(FINALIZED_ROOT_INDEX),
2021-11-27 07:25:27 -06:00
root=update.attested_header.state_root,
2020-11-18 10:33:42 +00:00
)
2020-11-17 12:42:09 +00:00
2022-04-27 16:07:49 +02:00
# Verify that the `next_sync_committee` , if present, actually is the next sync committee saved in the
2022-04-29 16:22:26 +02:00
# state of the `attested_header`
2022-04-27 16:07:49 +02:00
if not is_sync_committee_update(update):
2022-04-29 16:22:26 +02:00
assert attested_period == store_period
2022-04-27 16:07:49 +02:00
assert update.next_sync_committee == SyncCommittee()
2020-11-18 09:31:41 +00:00
else:
2022-04-29 16:22:26 +02:00
if attested_period == store_period:
2022-04-27 16:07:49 +02:00
assert update.next_sync_committee == store.next_sync_committee
2020-11-17 12:42:09 +00:00
assert is_valid_merkle_branch(
2020-11-18 10:33:42 +00:00
leaf=hash_tree_root(update.next_sync_committee),
2020-11-17 12:42:09 +00:00
branch=update.next_sync_committee_branch,
2020-12-16 15:00:06 +08:00
depth=floorlog2(NEXT_SYNC_COMMITTEE_INDEX),
2020-12-10 17:04:11 +08:00
index=get_subtree_index(NEXT_SYNC_COMMITTEE_INDEX),
2022-04-29 16:22:26 +02:00
root=update.attested_header.state_root,
2020-11-17 12:42:09 +00:00
)
2022-01-11 11:22:39 +01:00
2020-11-17 12:42:09 +00:00
# Verify sync committee aggregate signature
2022-04-29 16:22:26 +02:00
if signature_period == store_period:
2022-04-26 22:32:25 +02:00
sync_committee = store.current_sync_committee
else:
sync_committee = store.next_sync_committee
2021-12-14 21:38:58 +08:00
participant_pubkeys = [
pubkey for (bit, pubkey) in zip(sync_aggregate.sync_committee_bits, sync_committee.pubkeys)
if bit
]
2022-04-27 09:50:27 +02:00
fork_version = compute_fork_version(compute_epoch_at_slot(update.signature_slot))
domain = compute_domain(DOMAIN_SYNC_COMMITTEE, fork_version, genesis_validators_root)
2021-11-27 07:25:27 -06:00
signing_root = compute_signing_root(update.attested_header, domain)
2021-12-10 07:48:14 -06:00
assert bls.FastAggregateVerify(participant_pubkeys, signing_root, sync_aggregate.sync_committee_signature)
2020-11-16 15:02:11 +08:00
```
2020-11-18 10:33:42 +00:00
#### `apply_light_client_update`
```python
2021-11-27 07:25:27 -06:00
def apply_light_client_update(store: LightClientStore, update: LightClientUpdate) -> None:
2022-07-08 21:59:09 -07:00
store_period = compute_sync_committee_period_at_slot(store.finalized_header.slot)
finalized_period = compute_sync_committee_period_at_slot(update.finalized_header.slot)
2022-04-29 16:22:26 +02:00
if finalized_period == store_period + 1:
2021-11-27 07:25:27 -06:00
store.current_sync_committee = store.next_sync_committee
store.next_sync_committee = update.next_sync_committee
2022-04-29 16:22:26 +02:00
store.finalized_header = update.finalized_header
2022-01-25 10:09:10 +01:00
if store.finalized_header.slot > store.optimistic_header.slot:
store.optimistic_header = store.finalized_header
2020-11-18 10:33:42 +00:00
```
#### `process_light_client_update`
2020-11-16 15:02:11 +08:00
2020-11-16 15:07:40 +08:00
```python
2021-11-26 15:11:19 -06:00
def process_light_client_update(store: LightClientStore,
update: LightClientUpdate,
current_slot: Slot,
2021-03-11 21:02:05 +08:00
genesis_validators_root: Root) -> None:
2021-11-29 07:04:05 -06:00
validate_light_client_update(store, update, current_slot, genesis_validators_root)
2021-12-14 22:05:09 +08:00
2022-01-11 11:22:39 +01:00
sync_committee_bits = update.sync_aggregate.sync_committee_bits
2021-12-14 22:05:09 +08:00
2021-11-26 15:11:19 -06:00
# Update the best update in case we have to force-update to it if the timeout elapses
2021-11-30 20:38:42 +08:00
if (
store.best_valid_update is None
2022-04-29 16:22:26 +02:00
or is_better_update(update, store.best_valid_update)
2021-11-30 20:38:42 +08:00
):
2021-11-29 07:04:05 -06:00
store.best_valid_update = update
2021-12-15 23:43:54 +08:00
2021-11-30 20:38:42 +08:00
# Track the maximum number of active participants in the committee signatures
2021-11-29 07:04:05 -06:00
store.current_max_active_participants = max(
2021-11-30 20:38:42 +08:00
store.current_max_active_participants,
2021-12-14 22:05:09 +08:00
sum(sync_committee_bits),
2021-11-26 15:11:19 -06:00
)
2021-12-15 23:43:54 +08:00
2021-11-26 15:11:19 -06:00
# Update the optimistic header
if (
2021-12-15 23:43:54 +08:00
sum(sync_committee_bits) > get_safety_threshold(store)
and update.attested_header.slot > store.optimistic_header.slot
2021-11-26 15:11:19 -06:00
):
2021-11-27 07:25:27 -06:00
store.optimistic_header = update.attested_header
2021-12-15 23:43:54 +08:00
2021-11-26 15:11:19 -06:00
# Update finalized header
2020-12-09 17:35:22 +08:00
if (
2021-12-14 22:05:09 +08:00
sum(sync_committee_bits) * 3 >= len(sync_committee_bits) * 2
2022-04-29 16:22:26 +02:00
and update.finalized_header.slot > store.finalized_header.slot
2020-12-09 17:35:22 +08:00
):
2021-11-26 15:11:19 -06:00
# Normal update through 2/3 threshold
2021-11-27 07:25:27 -06:00
apply_light_client_update(store, update)
2021-11-26 15:11:19 -06:00
store.best_valid_update = None
2020-11-16 15:02:11 +08:00
```