The Bitcoin White Paper Abstract - Explained

Bitcoin: A Peer-to-Peer Electronic Cash System, the white paper, addresses the problems, proposed solution(s), and purposes behind bitcoin. The white paper is the starting point in understanding bitcoin. The Abstract of the white paper, with some additional context and definitions, provides a solid starting point for further discussion. Too many of us were given overly simplified or overly technical explanations of the bitcoin network. Both of those can create distorted understandings and cause educational hurdles later on down the road. I believe the best way to communicate is somewhere in-between. Complex systems can be understood by most people, but the starting point is not talking to adults like five-year-olds. The Abstract is as follows:

"A purely peer-to-peer version of electronic cash would allow online payments to be sent directly from one party to another without going through a financial institution. Digital signatures provide part of the solution, but the main benefits are lost if a trusted third party is still required to prevent double-spending. We propose a solution to the double-spending problem using a peer-to-peer network. The network timestamps transactions by hashing them into an ongoing chain of hash-based proof-of-work, forming a record that cannot be changed without redoing the proof-of-work. The longest chain not only serves as proof of the sequence of events witnessed, but proof that it came from the largest pool of CPU power. As long as a majority of CPU power is controlled by nodes that are not cooperating to attack the network, they'll generate the longest chain and outpace attackers. The network itself requires minimal structure. Messages are broadcast on a best effort basis, and nodes can leave and rejoin the network at will, accepting the longest proof-of-work chain as proof of what happened while they were gone."

— Satoshi Nakamoto, October 31st, 2008

Line by line, let's explain what all of this means and give it some more information.

Peer-to-peer electronic cash

"A purely peer-to-peer version of electronic cash would allow online payments to be sent directly from one party to another without going through a financial institution."

Peer-to-peer refers to the bitcoin infrastructure being distributed between users with the software working from one user to another. Bitcoin does not require a trusted centralized authority to oversee transactions. Bitcoin (the network) relies solely on its users, or those using it, to maintain the network.

Image placeholder 1 — Peer-to-peer network: Show users connected directly to one another without a central intermediary.

This is in sharp contrast to Visa, any bank, or other online payment services like PayPal or Venmo. This is important because a system other than peer-to-peer could be censored, disrupted, or manipulated by a central authority with motivations that differ from the end user. Financial institutions have historically excluded specific individuals based on ideological, political, religious, national, or other such individual characteristics.

Bitcoin is designed to be censorship-resistant: no single party can stop a valid transaction from eventually being added to the blockchain. If you use a currency, bitcoin is an alternative that makes it far harder for anyone to take away your ability to interact with others on a monetary basis. Peer-to-peer systems such as bitcoin also have a lower barrier to entry, allowing for an easier network spread.

Image placeholder 2 — Centralized vs. peer-to-peer payments: Contrast a payment routed through a bank or processor with a peer-to-peer network.

Digital signatures and double-spending

"Digital signatures provide part of the solution, but the main benefits are lost if a trusted third party is still required to prevent double-spending."

Digital signatures, also called cryptographic signatures, or simply signatures, are a mathematical scheme that allows someone to prove ownership. Digital signatures are used in bitcoin when someone makes a transaction. A transaction is "signed" by a cryptographic key that proves the owner is making that transaction of those coins, and the network should accept the transaction. Whoever controls the keys, controls the bitcoin.

This mechanism is called "public-key cryptography" as it utilizes two strings of numbers called keys, one private and one public. These keys allow the network (and individuals) to quickly and efficiently validate that a transaction is legitimate. Think of this like the marker that confirms your $100 bill is real, but it is 100% accurate and works instantly.

Double spending is the spending of the same bitcoin more than once. Until now, solutions to the double spend problem have been centralized and rely on a trusted third party. If someone spends $20 at two places through PayPal simultaneously, this is resolved by PayPal. That situation requires everyone to trust PayPal to do what is right. Without a central authority to mediate this problem, we require a digital signature to verify ownership and a network-wide consensus mechanism to enforce a single spend of those coins.

"We propose a solution to the double-spending problem using a peer-to-peer network."

Bitcoin is the solution, and double spending can be solved by utilizing digital signatures and validation from everyone on the network to ensure the authenticity of all transactions.

Hashes and the chain of blocks

"The network timestamps transactions by hashing them into an ongoing chain of hash-based proof-of-work, forming a record that cannot be changed without redoing the proof-of-work."

This is the real meat of the network.

A hash is the output of a hash function. A hash function is an algorithm that works by taking data and outputting a fixed length unique string of numbers and letters.

Image placeholder 3 — Hash function: Show an input passing through a hash function to produce a fixed-length output.

Getting the output from a hash function is fast and simple. But, this process cannot be done backward. You cannot put in the hash function's output and get the inputs. If you are able to do that, you have solved a system that underpins multiple security layers of the internet and digital communication, and the NSA would like to speak to you.

The output is a sort of secret code and the input is the password. If my friend gives me the output: ec5cf069dd8ab476d43466fa6c2ff8760c6a1997, I don't know the input until my friend tells me. When they tell me I can easily verify by running the input through the function and checking if the outputs match.

Party at my house tonight! -> Hash Function (SHA1) -> ec5cf069dd8ab476d43466fa6c2ff8760c6a1997

The smallest change in the input has an avalanche effect and drastically changes the output.

For example:

Image placeholder 4 — Avalanche effect: Compare two nearly identical inputs and their very different hashes.

Using a hash function, we can make a chain of outputs that include a prior output. This would form a record from one to the other. If all of the data in the inputs are known, then the series of outputs could be easily verified.

Image placeholder 5 — Hash chain: Show each link incorporating the previous link's hash.

If one of them changed, even in the slightest, it would corrupt everything following in the chain.

Image placeholder 6 — Broken chain: Show how changing an earlier link invalidates the links that follow.

Each piece of the chain is called a "block." Add a time to the block, and now we have a timestamped hash-based chain of blocks. Each block holds the previous block's hash plus a batch of transactions chosen by miners from those waiting to be confirmed. A new block is added about every 10 minutes on average.

Image placeholder 7 — Anatomy of a block: Label the timestamp, previous block hash, and batch of transactions.

Proof-of-work and mining

This is great, but we run into a problem, what if a single person controls a majority of the peers on the network? They could simply edit the data, and because they control the majority of peers, they could force consensus on the network. The solution is to add a piece of difficult-to-reproduce work into the chain. This is done by requiring peers on the network to guess a special number that, when put into the block, creates an output with zeros at the beginning. This special number is called a "nonce."

Image placeholder 8 — Finding a nonce: Show miners trying different nonce values until a hash begins with enough zeros.

Because the hash function cannot be done backward, peers on the network are forced to guess nonces randomly until they get an output with sufficient leading zeros. This exponentially increases the amount of work required to finalize a block, thus increasing the cost an attacker would have to undertake to manipulate the network. Those peers on the network finding the nonce, called miners, are compensated with newly minted bitcoin when they find the correct nonce. This distribution of newly minted bitcoin distributes bitcoin fairly because only those building the network receive compensation.

Once a miner finds the nonce, the block is added to the blockchain and all transactions in that block are confirmed. Each new block added on top makes a transaction exponentially harder to reverse, so settlement is probabilistic rather than instant; around six confirmations is the common rule of thumb for large amounts.

"The steady addition of a constant of amount of new coins is analogous to gold miners expending resources to add gold to circulation. In our case, it is CPU time and electricity that is expended." — Satoshi Nakamoto

Choosing the longest chain

"The longest chain not only serves as proof of the sequence of events witnessed, but proof that it came from the largest pool of CPU power. As long as a majority of CPU power is controlled by nodes that are not cooperating to attack the network, they'll generate the longest chain and outpace attackers."

It is possible for two blocks to be created simultaneously and for there to be two chains. This two-block situation is temporary and will be solved by peers on the network defaulting to the longest chain.

Defaulting to the longest chain is done NOT by counting blocks, but by measuring "difficulty" or the total computational power put into the chain. This proves that the main chain, the active chain with a root to the very first block, is the strongest and most resilient to manipulation.

An attacker would need to control a sustained majority of the network's computing power to keep their malicious chain ahead of everyone else. When the network was tiny and supported by a handful of peers, the concern that pools of network participants would manipulate the network was high. As the network has grown globally, an attack has become far more expensive, though the concentration of mining among a handful of large pools is still debated. Again, the resources required to alter the network are orders of magnitude greater than the monetary reward one would receive.

A network anyone can join

"The network itself requires minimal structure. Messages are broadcast on a best effort basis, and nodes can leave and rejoin the network at will, accepting the longest proof-of-work chain as proof of what happened while they were gone."

Anyone can run a full node on an ordinary computer with a stable internet connection. All additional resources on the network increase its stability and security for everyone.

Messages (transactions) are broadcast to the network by those initiating the transaction. Delivery is on a best-effort basis, meaning there is no definitive end or guarantee that the message will reach its destination.

This is done to simplify the transmission process and reduce potential avenues of attack on the network. Transactions are broadcast to a peer, connected to peers, which is connected to more peers, etc., etc.

This setup allows anyone to join or leave the network freely. There are no commitments or contracts to be on the network. When rejoining the network, a peer will utilize the mechanisms from above to validate the appropriate chain and continue work.

The Abstract of the whitepaper is only the start of understanding the technology.

Energy expenditure is the most significant obstacle for an attacker who wants to manipulate transactions. The hardware and electricity required to alter the network cost far more than an attacker could expect to gain, and anyone with that much computing power would earn more by mining honestly.

*Some of the descriptions are not 100% technically accurate (referencing: nodes, miners, wallets, transactions, signatures, etc.). This technical inaccuracy was intentional to make the material easier to understand for beginners.