LibraryConsensus2019Design paperCorpus record
SBFT: A Scalable and Decentralized Trust Infrastructure for Blockchains
SBFT. Guy Golan Gueta, Ittai Abraham, Shelly Grossman, Dahlia Malkhi, Benny Pinkas, Michael K. Reiter, Dragos-Adrian Seredinschi, Orr Tamir and Alin Tomescu.
Collectors aggregate signatures into one proof. A client and the replicas see a constant number of messages rather than a quadratic flood, under the paper's collector assumption.
A reading of the public document. Not a copy of it, and not a claim about a later network that reused the name.
If a pitch says linear BFT, ask who aggregates, and what happens when that party delays.
The five-minute read
The defect
PBFT's all-to-all messages do not survive a large replica set.
The rule
Collectors aggregate signatures into one proof. A client and the replicas see a constant number of messages rather than a quadratic flood, under the paper's collector assumption.
How it is put together
Threshold signatures stand in for a pile of individual votes. A fast path commits when a larger set agrees. A linear path remains for the case where the fast path fails.
Where the claim stops
Collectors are an extra role. A censoring collector is a liveness problem.
One action, walked through
- Replicas send votes to a collector.
- The collector returns one signature.
- Commit follows if the signature proves the required threshold.
- Who may aggregate signatures?
The argument, unpacked
Why it is still on the desk
If a pitch says linear BFT, ask who aggregates, and what happens when that party delays.
After the text
Later chains adopted threshold certificates as the normal way to show a quorum. The collector role is the part to read carefully.
What has to be true
- Collectors are an extra role. A censoring collector is a liveness problem.
- The paper assumes a known replica set.
- It does not remove the one-third bound.
What happened after the paper
Later chains adopted threshold certificates as the normal way to show a quorum. The collector role is the part to read carefully.
What to check before you use the idea
- Who may aggregate signatures?
- What is the fast-path threshold?
- Is safety still an intersection of quorums?
Terms
- Collector
- A replica that gathers votes into one signature.
- Threshold signature
- One signature that proves a set signed, without listing them.
The problem the paper names
PBFT's all-to-all messages do not survive a large replica set.
What the design proposes
- Threshold signatures stand in for a pile of individual votes.
- A fast path commits when a larger set agrees.
- A linear path remains for the case where the fast path fails.
How the mechanism is specified
- Replicas send votes to a collector.
- The collector returns one signature.
- Commit follows if the signature proves the required threshold.
What this page does not treat as proven
- Collectors are an extra role. A censoring collector is a liveness problem.
- The paper assumes a known replica set.
- It does not remove the one-third bound.
Why a venture studio still reads it
If a pitch says linear BFT, ask who aggregates, and what happens when that party delays.
This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.
Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.
