12.8 Bitcoins and Blockchains
219
source code of an implementation available on a public repository. The system went
online in January 2009. The first few bitcoins had a very low value, they are, after all,
just bits in a computer’s memory, but soon they could be used to buy real items, such
as a pizza costing 20 000 bitcoins, which was the first trade that connected bitcoins to
the real-world economy. Over the years these connections grew as bitcoins could be
used to pay for goods and services and, importantly, be exchanged for conventional
currencies. In many countries the gains from trading bitcoins are even taxable. The
exchange rate of bitcoins (BTC on foreign exchanges) is very volatile. From an
exchange rate of about 400 US$ per Bitcoin early 2016 it rose to almost 20000 US$
in late 2017. It trades, at the time of writing, at around 9000 US$.
In order to understand how the bitcoin system works let us follow the money
and consider Alice who, after her graduation, has received a wallet with one bitcoin,
worth 10
8 satoshis, from a rich aunt. A wallet is a computer program that maintains a
private and a public key pair, as is illustrated on the left-hand side in Fig. 12.8. Since
bitcoin uses secp256k1 elliptic-curve cryptography, the private key d A is a 256-bit
long integer and her public key is the point P A = d A G. The wallet can run on
a variety of platforms, including her smartphone, which she has to guard carefully
such that only she has access to d A . Now, she wants to pay Bob for her share of
a pizza—about 9 $ or 10
5 satoshis. Therefore she initiates her wallet program and
asks Bob for his public key P B before initiating the transfer, which is just a message
m A stating that 10
5 satoshis move from P A to P B . The wallet then calculates the
SHA-256 hash of m A , resulting in h A , which Alice signs with her private key d A
yielding the signed hash ˆ
h A . Finally the wallet sends the package of m A and ˆ
h A to
the bitcoin system, where it ends up in a pool, waiting to be processed.
This pool is emptied of the messages by miners, let’s call one of them Marge,
who, together with many other miners, works competitively to verify transactions
and then enters them into the blockchain database. Marge works through a long list
of transaction and when she comes to P A ’s transaction m A , she verifies that wallet
P A actually has sufficient bitcoins, that ˆ
h A is signed by P A and that the hash of
m A gives h A . Finally Marge makes sure that P B is a valid destination address. If
the transaction m A passes these tests, she puts m A and its hash h A in the list of
validated transaction, shown on the bottom in Fig. 12.9. After all transactions are
validated Marge starts building the next block, here numbered n of the blockchain.
She successively combines two hashes to form a Merkle tree and stores the root of the
tree in the block, next to a timestamp and the hash of the completed previous block,
which ensures the continuity and the unique linking of the blocks into the blockchain.
Finally, Marge has to validate her work by varying a dummy variable, called a nonce,
to ensure that the hash of block n begins with a specified number of zeros. This step
is required to ensure that the competitor among the miners with the fastest hardware
first completes this step. Once block n is complete, work on the next block n + 1
can begin. This proof of work scheme ensures that the transaction m A is part of a
block that is quickly buried under a large number of successive blocks. Reversing
the transaction would entail to recalculate all subsequent transactions and blocks
and would require even more powerful hardware. This scheme therefore provides
an essential contribution to the integrity of the bitcoin network and prevents double
219
source code of an implementation available on a public repository. The system went
online in January 2009. The first few bitcoins had a very low value, they are, after all,
just bits in a computer’s memory, but soon they could be used to buy real items, such
as a pizza costing 20 000 bitcoins, which was the first trade that connected bitcoins to
the real-world economy. Over the years these connections grew as bitcoins could be
used to pay for goods and services and, importantly, be exchanged for conventional
currencies. In many countries the gains from trading bitcoins are even taxable. The
exchange rate of bitcoins (BTC on foreign exchanges) is very volatile. From an
exchange rate of about 400 US$ per Bitcoin early 2016 it rose to almost 20000 US$
in late 2017. It trades, at the time of writing, at around 9000 US$.
In order to understand how the bitcoin system works let us follow the money
and consider Alice who, after her graduation, has received a wallet with one bitcoin,
worth 10
8 satoshis, from a rich aunt. A wallet is a computer program that maintains a
private and a public key pair, as is illustrated on the left-hand side in Fig. 12.8. Since
bitcoin uses secp256k1 elliptic-curve cryptography, the private key d A is a 256-bit
long integer and her public key is the point P A = d A G. The wallet can run on
a variety of platforms, including her smartphone, which she has to guard carefully
such that only she has access to d A . Now, she wants to pay Bob for her share of
a pizza—about 9 $ or 10
5 satoshis. Therefore she initiates her wallet program and
asks Bob for his public key P B before initiating the transfer, which is just a message
m A stating that 10
5 satoshis move from P A to P B . The wallet then calculates the
SHA-256 hash of m A , resulting in h A , which Alice signs with her private key d A
yielding the signed hash ˆ
h A . Finally the wallet sends the package of m A and ˆ
h A to
the bitcoin system, where it ends up in a pool, waiting to be processed.
This pool is emptied of the messages by miners, let’s call one of them Marge,
who, together with many other miners, works competitively to verify transactions
and then enters them into the blockchain database. Marge works through a long list
of transaction and when she comes to P A ’s transaction m A , she verifies that wallet
P A actually has sufficient bitcoins, that ˆ
h A is signed by P A and that the hash of
m A gives h A . Finally Marge makes sure that P B is a valid destination address. If
the transaction m A passes these tests, she puts m A and its hash h A in the list of
validated transaction, shown on the bottom in Fig. 12.9. After all transactions are
validated Marge starts building the next block, here numbered n of the blockchain.
She successively combines two hashes to form a Merkle tree and stores the root of the
tree in the block, next to a timestamp and the hash of the completed previous block,
which ensures the continuity and the unique linking of the blocks into the blockchain.
Finally, Marge has to validate her work by varying a dummy variable, called a nonce,
to ensure that the hash of block n begins with a specified number of zeros. This step
is required to ensure that the competitor among the miners with the fastest hardware
first completes this step. Once block n is complete, work on the next block n + 1
can begin. This proof of work scheme ensures that the transaction m A is part of a
block that is quickly buried under a large number of successive blocks. Reversing
the transaction would entail to recalculate all subsequent transactions and blocks
and would require even more powerful hardware. This scheme therefore provides
an essential contribution to the integrity of the bitcoin network and prevents double
