Zhuang's Diary

言之有物,持之以恒

Rogoff教授以新型货币“战争”来形容这次数字货币的竞争有可能改变国运,因此这是 一个严肃的问题。

Libra从1.0到2.0 (diem), 协会主要从如下九个方面进行修正和回应:

  • Asociation will create a comprehensive compliance program;协会将创建全面的合规计划;

  • Association wilset mandatory standards for unrestricted use of the Libra payment system;对于Libra(不受限制的)支付系统,协会将会设定强制性使用标准;

  • Association will conduc due diligence on Association Members andDesignated Dealers;协会将对协会会员和指定经销商进行尽职调查;

  • Association will distribute Libra Coins through regulated DesignatedDealers;协会将通过受监管的指定经销商分销Libra币;

  • Only regulated or Certified VASPs will be allowed to transact on the network without transaction and address balance limits;只允许受监管或认证的VASP(Virtual Asset Service Provider,数字资产服务提供商)在网络上交易,而且没有交易和余额限制(其他交易者有限制);

  • Automated protocol-level compliance controls will apply for all on-chain activity;链上任何活动都会自动作合规性监;

  • Association will develop an off-blockchain travel rule protocol;协会将开发一个区块链外旅行规则协议(这是一个监管规则);

  • Association’s FIU-function will monitor Libra network activity and coordinate with Libra network participants;协会的FIU职能将监测 Libra网络活动,并与Libra网络参与者协调;

  • Association will respond to identified potentially suspicious sanctioned activity,including through reporting.协会将对已查明的潜在可疑制裁活动作出回应,包括通过报告(合适的监管单位)。

1. 全面的合规计划

这个计划旨在从以下几个方面满足或者超过相关法律要求和标准:

  • 指定首席合规官;
  • 成立一个负责监督报告责任的委员会;
  • 根据风险评估制定书面的反洗钱/反金融恐怖活动/制裁等的合规政策和程序并经协会理事会批准;
  • 对所有成员,指定经销商以及受监管和认证的VASPs进行基于凤险的尽职调查;
  • 根据定期的风险评估以及不断发展的合规要求,定期修订反洗钱/反金融恐怖活动/制裁合规计划;
  • 建立金融情报机构(FIU-Function,Financial Intelligence Unit–Function),以便监测潜在的可疑活动;
  • 指定一个类似于内部审计职能机构,对协会的反洗钱/反金融恐怖活动/制裁合规计划进行定期的独立审查;
  • 进行相关的员工培训。

2. 组织管理
协会会对其会员,指定经销商,受监管或认证的VASPs对准入Libra网络设置强制性标准。
3. 尽职调查
协会将对协会会员和指定经销商进行尽职调查。尽职调查包括但不限于:

  • 实体状态;

  • 制裁筛选;

  • 负面新闻;

  • 受益所有人和控制人;

  • 遵守适用的反洗钱/反金融恐怖活动/制裁合规要求的情况(如果有的话);

  • 许可证和注册;

  • 实体位置及其客户群的地理位置。日青青那组贵食个一丝

4. 发币通过指定经销商
Libra网络将仅与指定经销商一起铸造向市场发行的Libra Coins,并且也只从这些指定经销商处兑换Libra Coins,这些指定经销商必须是受到监管的。Lbra网络和指定经销商一起铸造并销毁Libra Coins,不会和任何交易所或者终端有任何合同关系。

5. 仅受监管或认证的VASPs可以没有交易或是余额限制
协会期望大多数人会通过VASPs和Libra支付系统进行交互。VASPs为了方便用户进行交易,可能会将交易记录在其内部交易账簿上而不是Libra的区块链上。受监管或认证的VASPs在使用Libra交易系统时可无交易和余额的限制。但是Unhosted Wallets(非托管钱包,协会允许的可使用Libra交易系统的非VASPs机构)会受限。
6. 协议层级(protocol-levl)的链上活动自动合规
协会将会在Libra协议层级自动执行合规要求。旨在使得Libra区块链上的交易活动自动合规。比如在协议中自动阻止受制裁的区块链地址的交易。
7. 链下旅行规则协议
协会将开发区块链链下协议,通过明确受监管或认证的VASPs的使用旅行规则和记录保存要求,以促进合规。
8. FIU功能监视Libra网络活动和参与者
协会将设立专门机构发挥金融情报机构的职能,以保持高水平的合规。这个机构将和政府以及服务提供者合作,以发现并阻止不当的平台使用行为。

9. 回应潜在的可疑或受制裁的活动

Libra 2.0 的宏大目标 — 平台霸权

  1. 布局金融基建

Libra 2.0 提出新的支付方式、数字货币为基础的新金融基础基建有可能蔓延开来。Libra 2.0 指出协会期待与各国央行合作,参与国家数字法币的建设和运行。

  1. 币链分离,弃币保链

放弃霸权币来保障霸权链的指导原则。传统数字货币,例如比特币,如果比特币平台不见了,比特币也就不复存在,就没有了价值。这是一种币链需要相互依存的设计和状态。Libra 2.0 的币和链是分离的,计划链处理多种稳定币和央行数字法币。

策略上,放弃在任何国家和当地法币或是将来央行数字货币竞争的机会,换取Libra 2.0 平台在这些国家使用的许可权。正如Libra2.0提出的,Libra协会会和其他国家央行合作,允许这些国家的央行数字法币在Liba平台运行(这就是保链思想),Libra还愿意放弃自己的Libra币(这就是弃币思想),而只使用当地发行的稳定币或是央行数字法币。

Liba协会之所以采取该措施,是因为其重视链,认为币(数字货币)不是主要的创新,真正的突破在于链在协议层级传递价值,协会副主
席Dante Disparte的原文是“Blockchain,Not Crypto,Is at Core of Facebook’s Libra”。为了避免大家有不同认知,他还继续说:“加密货币不是这次创新的重要的维度,真正的突破是在协议层级传递价值,这才是Libra最大的贡献。没有区块链作为核心技术,会非常难开发一个开放钱包和开放用户(微信、支付宝)的平台”。

在链的设计上,Libra2.0还提出了同一链服务多种数字货币的想法。Liba2.0注重开发区块链的底层架构,追求该架构的有效性、低成本及可和多个数字货币、金融机构以及用户交互(interoperability)的能力。Disparte多次强调交互性是Libra2.0的重中之重,链的交互性也代表了平台的交互性。Disparte也批评了传统数字代币(例如比特币)不是支付平台,而是单一数字商品交易平台,因为它不能和其他系统交互。

非常明显,Libra2.0对交互性的追求,是为Libra平台能够做各种金融活动做准备,而不是像比特币平台一样只有单一功能。现在Lib只进行数字货币交易,但当Liba平台可以支持数字股票、衍生品以及其他数字资产交易的时候,Libra平台的价值会更加高涨。,

  1. 避免“数字货币取代”(digital do1 arization)的可能性,追求比目鱼模型行。

“数字货币取代”这一说法经历了三个时间段。其最早出现在2017年,IMF(国际货币基金组织)认为数字货币会取代多国的法币,特别是在当地法币已经弱化的地方,例如津巴布韦,并且认为这是新型货币取代理论 (dolarion2.0)。以前是一个国家法币取代另外一个国家的法币在当地使用,这里是数字货币取代一个国家的法币。

紧接着2019年,Libra 1.0白皮书出现的时候,Libra币被认为比比特币强大得多,如果比特币可以取代一些国家的法币,Lb币有可能会取代或是弱化更多国家的法币。紧接着,出现“8·23”事件一英国前央行行长认为数字货币以后可以取代美元成为世界储备货币,美元的世界储备货币地位受到数字货币的挑战。如果连美元这种强势货币都有可能在将来被取代,世界各国法币以后都有可能受到冲击。

而协会为了让Libra项目能落地,则要积极避免类似的“数字货币取代”的说法,以免引起其他国家的恐慌,不想让其他国家认为Libra币有取代他国法币的企图。所以Libra2.0提到要积极和央行合作数字法币,或者帮助当地建立自己的稳定币或数字法币,并愿意放弃对应的Libra币。

但从另一个角度看,要帮助一个国家或地区建立自已的稳定币,给Libra平台的能力创设了无限大的想象空间,实际是想要让一个国家或地区的稳定币(甚至央行发行的数字法币)依托于它的平台。这样一来,Libra平台会拥有其他国家数字法币的交易数据,也意味着Libra平台会有该国家或地区的金融信息。在未来,拥有这些数据,本身就具有巨大的优势。

另外,Libra2.0追求比目鱼模型理论,即数字货币平台方具有不对称优势。平台背后的国家,相比于其他国家更有优势,比如一个国家可以通过监管的方式,部分决定平台可为与不可为的行为,平台越大,对背后的国家越有利,因为掌握了更多的数据和信息,以及拥有部分可控权。

Libra2.0追求比目鱼模型的体现是允许政府和监管单位监管Libra作业。比如允许美联储参与实时监测Libra链上的交易信息。这也让美联储对数字货币的运作具有更好的“洞察力”。

  1. 改变Libra金融作业架构

​ 4.1 批发链,而非批发币

​ 4.2 混合经济模型 — 批发和零售均被融合进入 Libra 2.0。不是传统金融架构体系,不是传统的数字代币架构体系,也不是原英国央行的数字英镑架构体系,更不是币圈追求的DeFi金融架构体系。Libra 2.0 的混合模型可以使其快速部署。

  1. 积极设定平台协议标准

数字货币平台具有不对称的优势(比目鱼模型,比目鱼具有扁平的身体,眼睛只生长在身体的一侧,具有鱼类中独一无二的不对称结构)
数字法币成为全球通用货币后,监管面临了新的考验。一般来说,数字法币由国家发行,由国家信用保障兑付。即使使用国际货币基金组织提出的央行-民间合作方式,数字货币仍然是一国央行和在该国注册的公司合作的金融产品,其他国家不可能拥有监管权。英国开创数字英镑的重要原因,就是要拿回监管权。如果完成数字英镑,该货币如果成为世界通用货币,其他国家会担心自己的货币金融体系受到了威胁。

因此,对这种非对称监管关系,可能会有以下几种情形出现:

(1)主权独享式:单个国家完全享有监管权,原因是这是由单个国家发行的数字法币,该国央行支持,由该国货币储备保障运行。其他国家、商家或是个人使用,都必须遵守该国法律。但作为全球货币,这种制度渗透和金融霸权模式必定受到其他国家的拒绝,Libra受到德法两国的坚决抵制就是典型的例子。同时,以德国为首的各国都开始在区块链和数字货币领域建立自己的战略部署,建立各国自有的数字法币系统,并不特别说明数字法币是潜在的全球货币,鼓励各国的商家和个人注册和交易,等到米已成粥,才将制度、监管和法律问题一并抛出。该机制以国家主权为第一优先,称为主权式。

(2)完全共享式:发行国和参与国完全共享监管权,这是另外一个极端。数字法币发行国和参与国家共享数据。但这种体系本身也有很多不平衡性,在发行基础设施方面的投入和使用量最大的都是发行国,如果所有交易让所有参与国都可以看见,安全机制和经济利益上都无法说服发行国接受,其他的参与国也可能产生异议,我们称之为完全共享式监管。

(3)部分共享式:发行国可以看到全部交易信息,而参与国只能看到和该国相关的交易信息。这样参与国可能可以接受,而发行国也可以接受。但是这样的监管机制会导致系统十分复杂。例如,该系统有100个国家参与,每个国家的监管机制一定会有各种各样的差异性,对应需要建立100套监管机制,核心运行的是一个系统,但是对应100套监管机制,系统将无法负荷这样的复杂性。要解决这个问题,需要参与国建立联盟式监管机制,建立一个“大监管机制”来包容许多国家的监管法规。但是这种“大监管机制”是否能够顺利完成,在什么条件下可以实现,这些都是数字法币发展中必须考虑的问题。这种机制事实上在美国医药区块链上已经使用,但是这样的机制不涉及主权,只涉及被监管的药。另外,如何确定交易属于哪个国家监管还是一个尚需研究的问题,监管的对象是物理地址还是网络地址仍然有待商榷。在现有网络架构下,如何解决多物理地址和多网络地址问题,并且确保在现有机制下如何保证参与国能够收到应该收到的信息,同时看不见其他国家的交易信息。但是在这种机制下,参与国有理由怀疑发行国作弊,故意不发一些重要信息。因为这一机制下的参与国都只能获得部分信息,所以我们称之为部分共享式。

(4)分层分片式:发行国和参与国都只能看到和该国相关的交易信息。这个机制的公平性大大提高,但新的问题出现了,谁是最合适的信息传输主导者?可能又回到现在SWIFT的环境,由一个中心来主导信息。发行国必定要成为自己数字法币的主导者,不太可能主动出让和分享主导权。但是如果发行国非常想要大力推行自己国家的数字法币,可能会同意该机制。因为这个机制可能会给一个国家的数字法币带来极大的边际效应,大到在其他方面做出大量让步都值得。而机制的设计对信息进行了权属分层和数据切片,使得每个国家只能看到自己的相关信息,通过权属申请可分享的信息,各国在数据分享中各行其志,规避了完全共享中涉及其他国家数据分享的问题,我们称之为分层分片式监管。这个是最靠近对称性的监管机制,但这个还不是对称性。发行方还是有更多的权力,因为系统操纵在发行方。

​ 在部分共享式和分层分片式中,都需要有一套机制来调节和决策信息的分享能力和权属程度。因为交易是高速的,也是实时结算的,相应的监管机制必须是实时的、自动化的。在西方国家,通常会成立一个委员会,由委员会来制定规则,然后交给软件系统自动处理。在区块链领域“代码就是法律”(Code is law),软件自动执行智能合约内容,因此制度的制定至关重要,委员会的会员拥有很大的权力。在数字法币委员会上,发行国在委员会占据大部分的席位,就像Libra中的初始发起会员一样。因此,发行方在整个机制运行控制上还是拥有非常大的权力。

​ 类似的问题也会出现在脸书Libra币的监管中,目前世界各国都在讨论Libra是否能纳入本国监管制度的合规体系。相比之下,一个更重要的问题是各国如何“共同”监管Libra币的运行。区块链中心思想是共识机制,但是主权监管本身是中心化决策,共识型的监管如何在各国金融体系中落地实现,将会是一个难题。

  • 平台理论:数字货币需要平台才能运行,因此数字货币的竞争,也会是平台的竞争。例如电商的竞争(如阿里和京东),也是电商各自平台的竞争;传统数字代币(如比特币和以太坊)离开其平台无法运行,因此数字代币竞争也是平台竞争;若将来央行发行数字法币,也会运行在其平台上,因此如果平台有问题,那么竞争就会失去优势。比如早期一些数字法币平台计划部署在公链上,但是因为公链平台不适合数字法币的运行,因此这些计划很快就没有市场。国际货币基金组织(IMF)、英国央行、普林斯顿大学、美联储都表示数字法币会依托于平台,因此平台优越是竞争的最大优势。平台属性(例如速度、隐私、监管)将决定数字法币的功能、
    性能、安全、市场。
  • 比目鱼模型:数字货币平台方具有不对称的优势(如上文),比平台参与方拥有更多信息,即使使用看似最公平的治理制度,平台方仍然拥有优势。该模型包括主权独享式(平台国家独享监管权)、完成共享式(所有参与国家都有同样的监管权)、部分共享式(参与国可以监管和自己相关的交易信息,但平台方享有全部数据)、分层共享式(所有参与国只可以看到和监管与自己相关的交易信息,但平台方享有全部数据)。即使是公平的方式(完成共享式和分层共享式),平台方还是拥有优势,因为平台方控制后台数据,而且可以使用这数据进行分析。
  • 交易理论:数字货币以交易为最主要的考量,这改变了货币三大用图的平衡:交易媒介、价值储存、计量单位,通过数字货币交易,世界储备货币可以从美元换成合成霸权数字货币。该理论由普林斯顿大学提出,英国央行、欧洲央行、美联储都公开讨论并引用。

区块链架构分类:

1) “小飞象” Dumbo 模型

目前的区块链是构建在互链网之上,安全,身份,都必须由区块链自身来完成,区块链更像是互联网的一个应用,就像一个小飞象,可以飞,但是体重太重。这样的模型以后必定会有大风险,会出问题,就像将高楼建立在沙滩上,风来了,雨来了,必将倾倒。

账户存储在应用层,而不是存储在操作系统底层。央行为了监管比特币和以太坊,需要获得全部交易数据,才能达到国家监管的要求。所以,针对多个国家部署、构成全球网络的区块链,监管机制不应该放在应用层,监管机制需要放入核心层,才能够达到监管的目的。“小飞象”模型这样子的设计,监管机制很可能不能到位。

2)“操作数据库系统”Operation Database System

对所有交易进行监管,所有账户和交易信息任务需要在系统内执行,而且部分任务由硬件处理,保护隐私,增加处理速度。区块链是一个分布式数据系统,这样子的操作系统就可能成为“操作数据库系统”,不再只是操作系统。这是“可监管操作系统”的设计原则。

如上,操作系统具有两个主要进程 — 交易进程(transaction process)和监管进程(regulation process)。同时,操作系统负责追踪交易数据,交易多方各自保证各自的信息真实。如果出错,出错方需要为损失负责。

一种观点是,该“操作数据库系统”Operation Database System可以在现有操作系统上进行改造。例如,在Linux内核的基础上增加一层共识层,该层主要由文件系统加解密,网络传输加解密以及共识协议等服务组成,为上层应用提供加解密和共识协议接口。

3)互链网网络模型

在“操作数据库系统”Operation Database System等基础上,互链网成为其上的应用,互链网需要链接各式各样的链。单链网需要具备的特性:高性能;安全性和隐私性;可扩展性;容错性

组成链网,还需要的特性:多链式架构(同构/异构);互通性;可延伸性(用户参与);可更改性(用户加入/退出);可复制性(快速同步);可管理性及非对称结构(监管节点/域名服务/控制节点/种子节点等);层次性(高层次的链和节点具有不对称的权利);一致性(每条链具有自己的一致性,链与链之间也要有一致性);高可靠性;完备性(共识机制及消息来源与可靠性不同,所以各链的完备性不一样。高完备性的链可以将信息传输给低完备性的链,反之,则不可以)

身份信息处理方式分类:

1)中心化处理:由政府发证,公民使用身份证来注册,交易,上学,就医等等。

2)联邦制处理:有另外一群组织来管理身份。

3)用户管理:个人管理身份。

4)用户自主管控:自我主权身份 self- sovereign identity。

数据保护方面处理分类:

1)不存储关键数据:例如,私钥,例如Sorvin项目就采取这样子的设计,但是这种设计使得系统操作性比较差,因为系统如果需要处理信息,每次都需要对数字身份发起请求,而且在请求协议中,也可能遭到攻击。

2)存储加密信息:在系统里面,关键信息都加密,每次客户使用公钥来读、写、传递加密信息。为了一直保证安全性,系统每隔一段时间需要更换私钥。

3)系统存储明文信息:部分操作系统例如内核是可以相信的,只有内核可以出来保密信息,许多作业都由硬件处理,由硬件来保护,这是目前传统可信操作系统的设计。如intel SGX(Software Guard Extensions),ARM TrustZone等技术。

§8 COMPARISONS AND LIMITATIONS

While the range of identity frameworks proposed is almost limitless, there are four particularly prominent and adjacent paradigms widely discussed in the web3 space that merit comparison: the dominant “legacy” identity ecosystem, the pseudonymous economy, proof of personhood, and verifiable credentials. Each paradigm highlights important contributions and challenges for future development of the social identity paradigm we advocate, and we use such limitations as a springboard for exploring future directions. All that considered, we also explain why we believe our social identity primitives of Souls and soulbound tokens are a more promising path forward for privacy regimes.

虽然提出的身份框架的范围几乎是无限的,但在 web3 空间中有四个特别突出和相邻的范式被广泛讨论,值得比较:占主导地位的“传统”身份生态系统、假名经济、人格证明和可验证的凭证。每个范式都突出了我们所倡导的社会认同范式未来发展的重要贡献和挑战,我们将这些限制作为探索未来方向的跳板。考虑到所有这些,我们还解释了为什么我们相信我们的灵魂和灵魂令牌的社会身份原语是隐私制度的一条更有希望的前进道路。

8.1 Legacy

Legacy identity systems rely on pieces of papers or identity cards issued and mediated by a 3rd party (a government, university, employer, etc). Provenance is established by calling up the 3rd party for a confirmation. While the legacy system has an interesting set of properties we should understand more deeply, such systems are wildly ineffcient and do not lend themselves to composability or computation for rapid, effcient coordination. Moreover, these systems lack social context and makes Souls reliant on a centralized 3rd party to confirm membership to a community, rather than the embedding community. For example, most government issued IDs eventually trace back to a birth certificate issued on the authority of a medical doctor and family members, who are the ultimate source of truth and leave out many equally meaningful social connections that—taken together—o￾er far stronger validation. In fact, when centers of concentrated power seek strong identification (e.g., getting a security clearance from a major government) they rarely rely on such documents, instead turning to interviews in social networks. Thus such legacy identity systems tend to concentrate power in the issuer and in those who can undertake the due diligence to get stronger verification, who in turn become calci￾ed and unreliable bureaucracies. A crucial design goal of DeSoc is ensuring that the security requirements of government IDs can be met and exceeded, allowing horizontal networks to make greater security available to all users and through a range of social substrates.

传统身份系统依赖于由第三方(政府、大学、雇主等)发行和调解的文件或身份证。通过致电第三方进行确认来确定出处。虽然遗留系统具有我们应该更深入地理解的一组有趣的属性,但这些系统效率极低,并且不适合用于快速、有效协调的可组合性或计算。此外,这些系统缺乏社会背景,使得 Souls 依赖于一个集中的第三方来确认社区的成员身份,而不是嵌入社区。例如,大多数政府颁发的身份证最终都可以追溯到由医生和家庭成员授权签发的出生证明,他们是真相的最终来源,并且遗漏了许多同样有意义的社会联系——加在一起——远远超过更强的验证。事实上,当权力集中的中心寻求强有力的身份证明(例如,获得主要政府的安全许可)时,他们很少依赖此类文件,而是转向社交网络中的采访。因此,此类遗留身份系统倾向于将权力集中在发行者和那些能够进行尽职调查以获得更强大验证的人身上,而这些人反过来又会成为刻板和不可靠的官僚机构。DeSoc 的一个关键设计目标是确保能够满足和超过政府 ID 的安全要求,允许横向网络通过一系列社交基础为所有用户提供更高的安全性。

8.2 Pseudonymous Economy

The vision of a society based around combining reputation systems with zero knowledge proof mechanisms to preserve privacy has been most widely promoted by Balaji Srinivasan, who coined and popularized the phrase “pseudonymous economy.” His early version emphasizes the use of pseudonyms to avoid discrimination and evade “cancel culture” by social mobs that seek to harm a person’s reputation and break their social ties. It envisions people accumulating transferable zero-knowledge (ZK) attestations in their wallets and evading reputational attacks by transferring a subset of attestations to new wallets, or splitting the attestations amongst multiple wallets, presumably without traceability. In culling attestations to port, a person chooses the level of desired pseudonymity in the new account, weighing a tradeoff between more anonymity (porting fewer attestations) or more distribution to their social network (porting over more attestations).

The practical difference between typical pseudonymous economy proposals and DeSoc is that we deemphasize identity separation as a primary way to protect participants from abuses and cancel culture. Some level of separation (e.g., different Souls between family, work, politics, etc.) may be healthy, but in general there are great disadvantages to relying on the ability to spin up new identities as a primary crutch against attacks. It makes reputation-staking for lending and provenance harder, and it composes poorly with governance mechanisms that try to correct for correlations or Sybils.

Rather than protecting victims by allowing them to re-emerge from attacks with a new–if diminished—identity, DeSoc would allow other approaches, such as contextualizing the attacker. “Cancellation” often arises precisely because statements and actions are taken out of context and viral signals travel through uncontextualized networks, when a person or bot has little social connection or context to a victim. In the same way that SBTs provide provenance to protect against deep fakes, a map of SBTs socially graphs a “hit piece’s” origin. “Hit pieces” essentially are artifacts arising outside of the victim’s communities (as reflected by shared SBT memberships), or lacking SBT attestations from the victim’s communities—which should cast doubt on the piece’s veracity. SBTs also empower victims to launch a defensive response to counteract the hit, curated and propagated from their network of trust (represented here by the patterns of co-holding of SBTs). By maintaining social context, people can maintain trust, even if they are under threat of cancellation, and hold attackers accountable. Improving provenance improves the social foundation of truth.

8.2 假名经济

Balaji Srinivasan 最广泛地推动了基于将声誉系统与零知识证明机制相结合以保护隐私的社会愿景,他创造并推广了“假名经济”一词。他的早期版本强调使用假名来避免社会暴徒的歧视和“取消文化”,这些暴徒试图损害一个人的声誉并打破他们的社会联系。它设想人们在他们的钱包中积累可转移的零知识 (ZK) 证明,并通过将证明子集转移到新钱包或将证明拆分到多个钱包中来逃避声誉攻击,这可能是没有可追溯性的。在挑选要移植的证明时,一个人选择新帐户中所需的假名级别,权衡更多匿名性(移植较少的证明)或更多分布到他们的社交网络(移植更多的证明)之间的权衡。

典型的匿名经济提案和 DeSoc 之间的实际区别在于,我们不再强调身份分离是保护参与者免受滥用和取消文化的主要方式。某种程度的分离(例如,家庭、工作、政治等之间的不同灵魂)可能是健康的,但一般来说,依靠建立新身份的能力作为抵御攻击的主要拐杖存在很大的缺点。它使贷款和出处的声誉赌注变得更加困难,并且它与试图纠正相关性或 Sybils 的治理机制的组合很差。

DeSoc 不会通过允许受害者以新的身份(如果已减少)重新出现在攻击中来保护受害者,而是允许其他方法,例如将攻击者情境化。 “取消”经常出现,因为当一个人或机器人与受害者几乎没有社交联系或背景时,声明和行动是脱离上下文并且病毒信号通过非上下文网络传播的。与 SBT 提供出处以防止深度伪造的方式相同,SBT 的地图在社交上绘制了“热门作品”的起源。 “热门片段”本质上是在受害者社区之外产生的人工制品(如共享的 SBT 成员资格所反映),或者缺乏来自受害者社区的 SBT 证明——这应该会让人怀疑该作品的真实性。 SBT 还使受害者能够发起防御性反应,以抵消从他们的信任网络中策划和传播的打击(此处以共同持有 SBT 的模式为代表)。通过维护社会背景,人们可以保持信任,即使他们面临取消的威胁,并追究攻击者的责任。改善出处可以改善真理的社会基础。

8.3 Proof of personhood (PoP)

Proof of Personhood protocols (PoP) aim to provide tokens of individual uniqueness, to prevent Sybil attacks and allow non-financialized applications. To do so, they rely on approaches such as global analysis of social graphs, biometrics, simultaneous global key parties, or some combination thereof. However, because PoP protocols seek to represent individual identities—focused on achieving global uniqueness—rather than social identities mapping relationships and solidarities, PoP protocols are limited to applications that treat all humans the same. Most applications we are interested in—such as staking reputation—are relational and move beyond being a unique human to being a differentiated human.

Moreover, PoP protocols are not immune to sybil attacks. In almost all near-term foreseeable applications, PoP systems are effectively open to Sybil attacks, just at a slightly higher cost. Unless most people on the planet are registered for a PoP service and are participating in a particular validation exercise, an attacker can always recruit disinterested humans who are not yet participating to act as Sybils. While such mercenaries are not quite bots, the difference is superficial other than perhaps a small added expense.

Many PoP protocols aim to build a substrate for universal basic income or global democracy. While we don’t share the same ambition, such protocols have spurred us to nonetheless consider how to build gradually towards coordinating plural network goods. In contrast to the binary, individualist and global nature of PoP, our approach aims to construct a rich, contextual and layered substrate for bottom-up reputation, property and governance that allows participation in a range of communities and networks, small and large.

8.3 人格证明(PoP)

人格证明协议 (PoP) 旨在提供个人唯一性的代币,以防止 Sybil 攻击并允许非金融化应用程序。为此,他们依赖于社交图谱的全局分析、生物识别、同步的全球关键方或它们的某种组合等方法。然而,由于 PoP 协议寻求代表个人身份——专注于实现全球唯一性——而不是映射关系和团结的社会身份,所以 PoP 协议仅限于对所有人一视同仁的应用程序。我们感兴趣的大多数应用程序(例如质押声誉)都是相关的,并且超越了成为一个独特的人,成为一个与众不同的人。

此外,PoP 协议也不能免受女巫攻击。在几乎所有近期可预见的应用中,PoP 系统都有效地对 Sybil 攻击开放,只是成本略高。除非地球上的大多数人都注册了 PoP 服务并且正在参与特定的验证活动,否则攻击者总是可以招募尚未参与的不感兴趣的人充当 Sybils。虽然这样的雇佣兵并不完全是机器人,但区别只是表面的,可能只是增加了一点点费用。

许多 PoP 协议旨在为普遍基本收入或全球民主建立基础。虽然我们的野心不同,但此类协议仍促使我们考虑如何逐步构建以协调多种网络产品。与 PoP 的二元、个人主义和全球性质相比,我们的方法旨在为自下而上的声誉、财产和治理构建一个丰富的、上下文相关的和分层的基础,允许参与各种大小的社区和网络。

8.4 Verifiable credentials

Verifiable credentials (VCs) are a W3C standard where credentials (or attestations) are zk-shareable at the holder’s discretion. VCs highlight the major limitations of our baseline privacy paradigm and motivate our discussion of privacy extensions above. Until SBTs have privacy extensions that narrow publicity, VCs and SBTs can be seen as natural complements: in particular, SBTs are initially public making them inappropriate for sensitive information like government-issued identification, while VC implementations have struggled with a recovery paradigm that could be addressed by community recovery. The two approaches combined can in the near-term be stronger than either alone. But VCs also have a key limitation: at least in their standardized form, VCs do not support most of the applications we have enumerated because of their unilateral privacy.

Unilateral zk-sharing isn’t incentive-compatible with our use cases, nor does it reflect our norms around privacy. Most of our applications depend on some level of publicity. But under zk-sharing, Souls can’t know another Soul possesses an SBT unless it is shared to them—making reputation-staking, redible commitments, sybil-resistant governance, and simple rental contracts (e.g., apartment lease) impossible to get off the ground as other commitments and encumbrances are not necessarily visible. More deeply, we are skeptical that unilateral shareability is usually the right privacy paradigm. Rarely does one party in a multi-party relationship have the unilateral rights to disclose the relationship without the consent of the other. Just as unilaterally transferable private property is not a rich property regime, simplistic unilateral shareability is not a very rich privacy regime. If two parties co-own an asset and choose to represent their relationship through a VC, such credential doesn’t allow for the mutual-consent and mutual-permissions. This problem travels to more complex cases of plural property and complex organizational forms and permissions, which are a feature of DeSoc.

8.4 可验证的凭据

可验证凭证 (VC) 是 W3C 标准,其中凭证(或证明)由持有者自行决定是 zk-shareable。VC 强调了我们基线隐私范式的主要局限性,并激发了我们对上述隐私扩展的讨论。在 SBT 具有缩小宣传范围的隐私扩展之前,VC 和 SBT 可以被视为自然的补充:特别是,SBT 最初是公开的,因此它们不适用于政府颁发的身份证明等敏感信息,而 VC 的实施一直在努力应对一种恢复范式,这可能是由社区恢复解决。在短期内,这两种方法结合起来可能比单独使用任何一种方法都更强大。但是 VC 也有一个关键的限制:至少在它们的标准化形式上,VC 不支持我们列举的大多数应用程序,因为它们具有单方面的隐私性。

单边零知识共享与我们的用例不兼容激励,也不反映我们关于隐私的规范。我们的大多数应用程序都依赖于某种程度的宣传。但是在 zk-sharing 下,Souls 无法知道另一个 Soul 拥有 SBT,除非它被共享给他们——这使得声誉赌注、redible 承诺、抗女巫治理和简单的租赁合同(例如,公寓租赁)无法脱身其他承诺和产权负担不一定是可见的。更深入地说,我们怀疑单方面的可共享性通常是正确的隐私范式。多方关系中的一方很少有未经另一方同意而单方面披露关系的权利。正如单方面可转让的私有财产不是丰富的财产制度一样,简单的单方面可共享性也不是非常丰富的隐私制度。如果两方共同拥有一项资产并选择通过 VC 代表他们的关系,则这种凭证不允许相互同意和相互许可。这个问题涉及到更复杂的复数财产和复杂的组织形式和权限的情况,这是 DeSoc 的一个特点。

§9 SOUL BIRTH

The path from the current web3 ecosystem to augmented sociality mediated by SBTs faces a classic cold start challenge. On the one hand, SBTs are not transferable. On the other hand, today’s mix of wallets may not be the final home for SBTs because they lack community recovery mechanisms. But in order for community recovery wallets to work, they need a rich variety of SBTs across discrete communities to be secure. What comes first: SBTs or community recovery? Who are the early adopter communities? How do SBTs on different chains interoperate? We cannot aspire to know all the possibilities and answers, but instead sketch a few promising paths for the reader to further explore within the current web3 and even web2 architecture.

从当前的 web3 生态系统到由 SBT 介导的增强社交的路径面临着典型的冷启动挑战。一方面,SBT 不可转让。另一方面,今天的钱包组合可能不是 SBT 的最终归宿,因为它们缺乏社区恢复机制。但为了让社区恢复钱包发挥作用,他们需要跨不同社区的各种 SBT 来保证安全。首先是什么:SBT 还是社区恢复? 谁是早期采用者社区?不同链上的 SBT 如何互操作? 我们不能渴望知道所有的可能性和答案,而是勾勒出一些有希望的路径供读者在当前的 web3 甚至 web2 架构中进一步探索。

9.1 Proto SBTs

Although the hallmark of SBTs is non-transferability, SBTs may also have another property which may prove more useful in bootstrapping: revocability. It’s possible that SBTs first gestate as revocable, transferable tokens, before growing into non-transferability. A token is revocable if an issuer can burn the token and re-issue it to a new wallet. Burning and re-issuing would make sense when, for example, keys are lost or compromised, and the issuer has an interest in ensuring the tokens are not financialized and sold off to a party—in other words, when the token signals authentic community membership. Employers, churches, meet-up groups, clubs with repeat off-chain interactions are well positioned to burn and re-issue tokens because they have a relationship with a person, and can easily check for impersonation by phone call, video-conference, or simple meeting in person. Single interactions, such as attendance to a concert or conference are poorly suited because community bonds are weaker.

Revocable, transferable tokens are a kind of proto-SBT—serving supportive, placental functions before Soul birth. These tokens buy time both for wallets to gestate secure, community recovery mechanisms and for a person to su￾ciently accumulate proto-SBTs that can eventually be burned and re-issued into non-transferable SBTs. Under this pathway, the question is not, “what happens first: SBTs or community recovery?” Rather, SBTs and community recovery instantiate simultaneously, birthing a Soul.

9.1 原型 SBT

尽管 SBT 的标志是不可转让性,但 SBT 可能还具有另一个可能被证明在引导中更有用的属性:可撤销性。SBT 有可能首先孕育为可撤销、可转让的代币,然后才发展为不可转让。如果发行者可以销毁令牌并将其重新发行到新钱包,则令牌是可撤销的。例如,当密钥丢失或泄露时,燃烧和重新发行是有意义的,并且发行人有兴趣确保代币不会被金融化并出售给一方——换句话说,当代币表明真正的社区成员身份时,具有重复链下互动的雇主、教堂、聚会团体、俱乐部很容易销毁和重新发行代币,因为它们与人有关系,并且可以通过电话、视频会议或简单的面对面会议。单一的互动,例如参加音乐会或会议,不太适合,因为社区纽带较弱。

可撤销、可转让的代币是一种原型 SBT——在灵魂出生之前提供支持性的胎盘功能。这些代币为钱包争取时间来孕育安全的社区恢复机制,以及让人们充分积累最终可以被烧毁并重新发行为不可转让的 SBT 的原始 SBT。在这条路径下,问题不是“首先发生什么:SBT 还是社区恢复?”相反,SBT 和社区恢复同时实例化,产生了一个灵魂。

9.2 Community Recovery Wallets

Although today’s wallets lack community recovery, they each have relative strengths and weaknesses in being homes—or perhaps gestational wombs—for SBTs. Proof of Personhood (PoP) protocols have the advantage of already experimenting with social dispute resolution mechanisms, which are the foundation of community recovery. Also, many DAOs use PoPs to facilitate governance, making them natural first issuers of SBTs. However, despite PoPs natural lead, PoP protocols haven’t yet earned broad trust to house valuable token assets, whereas custodial wallets have.

Custodial wallets—despite their flaws of centralization—may thus offer a natural onramp for less sophisticated retail users. Such custodial wallets could also build tooling for retail communities to issue revocable tokens that later convert (or burn and reissue) into SBTs or even tooling for more “corporate” issuers—many of whom are looking for ways to build loyal customer bases in web3 but lack expertise in custody. Once community recovery mechanisms have been formalized and battle-tested, these custodial wallets could decentralize into community recovery, while custodians move on to providing other valuable services in DeSoc (like community management, SBTs issuances, etc.)

For more sophisticated web3 users, decentralized non-custodial wallets (or non-custodial social recovery wallets like Argent and Loopring) are a natural starting point for bootstrapping community recovery mechanisms. Non-custodial wallets have the advantage of being native web3 open-source, and the flexibility to pre-announce and experiment with mechanisms incrementally to a subset of voluntary, sophisticated users to battletest incentives and mix mechanisms (e.g.,mult-sig). All of these approaches—PoPs, custodial, and non-custodial—play an important role in experimenting and onboarding users with different degrees of sophistication and risk tolerance.

9.2 社区恢复钱包

尽管今天的钱包缺乏社区恢复能力,但它们在成为 SBT 的家——或者可能是妊娠子宫——方面都有相对的优势和劣势。人格证明 (PoP) 协议的优势在于已经在尝试社会争议解决机制,这是社区恢复的基础。此外,许多 DAO 使用 PoP 来促进治理,使其自然成为 SBT 的第一发行者。然而,尽管 PoP 自然领先,但 PoP 协议尚未赢得广泛信任来存放有价值的代币资产,而托管钱包则有。

托管钱包——尽管存在中心化缺陷——可能因此为不太成熟的零售用户提供了一个自然的入口。此类托管钱包还可以为零售社区构建工具,以发行可撤销的代币,这些代币随后会转换(或销毁和重新发行)为 SBT,甚至可以为更多“企业”发行人提供工具——其中许多人正在寻找在 web3 中建立忠诚客户群的方法,但缺乏监管方面的专业知识。一旦社区恢复机制正式确定并经过实战考验,这些托管钱包可以分散到社区恢复中,而托管人则继续在 DeSoc 中提供其他有价值的服务(如社区管理、SBT 发行等)

对于更成熟的 web3 用户,去中心化的非托管钱包(或像 Argent 和 Loopring 这样的非托管社交恢复钱包)是引导社区恢复机制的自然起点。非托管钱包具有原生 web3 开源的优势,并且可以灵活地预先宣布和逐步试验机制,让一部分自愿的、成熟的用户对激励和混合机制(例如多重签名)进行战斗测试。所有这些方法(PoP、托管和非托管)在试验和引导具有不同复杂程度和风险承受能力的用户方面发挥着重要作用。

9.3 Proto-Souls

Norms can also shepherd Souls into existence. As we rethink tokens and wallets, we can also reframe how we think about certain classes of NFTs and tokens that are intended to signal membership. In particular, we can introduce a norm of not transferring NFTs and POAPs issued by reputable institutions that reflect attendance to a conference, work experience, or education credentials. Such transfers of membership tokens—if traded for value—could diminish the reputation of a wallet and perhaps discourage issuers from further issuing membership or POAP tokens to that wallet. Already in the non-custodial ecosystem, a significant number of users have achieved significant financial reputation and stake in their wallets, which could bootstrap as effective collateral for them not to abuse non-transferability expectations.

While all these pathways have respective challenges, we hope that the variety of approaches increases the chance of convergence to our quasi-equilibrium state in the medium term through a small set of steps.

9.3 原始灵魂

规范也可以引导灵魂存在。当我们重新考虑代币和钱包时,我们还可以重新定义我们对某些类别的 NFT 和旨在表明会员资格的代币的看法。特别是,我们可以引入不转让由知名机构颁发的反映会议出席情况、工作经验或教育证书的 NFT 和 POAP 的规范。这种会员代币的转移——如果进行价值交易——可能会降低钱包的声誉,并可能阻止发行人进一步向该钱包发行会员或 POAP 代币。已经在非托管生态系统中,大量用户已经获得了显着的财务声誉和钱包中的股份,这可以作为有效的抵押品,让他们不滥用不可转让性期望。

虽然所有这些途径都有各自的挑战,但我们希望各种方法能够通过一小部分步骤增加在中期收敛到我们的准平衡状态的机会。

§10 CONCLUSION

As ambitious as we have been in imagining what DeSoc could enable, in many ways the above are just first steps. There is more than one road to DeSoc, including a number of non-blockchain based frameworks, such as Spritely, ACDC and Backchannel that rely on data stores tied to local machines rather than global ledgers. These frameworks may eventually o￾er even greater trust across social distance, because they can harness transitivity of trust relationships—like trusted introductions—rather than relying on SBTs issued by well-known, high-status institutions (like universities or DAOs). Furthermore the applications we describe above are just the beginning of what DeSoc can empower, not touching virtual worlds: their physics, society, and their complex intersection with the physical world. All this suggests that even the broad ambitions we paint above are just the beginning of what DeSoc may eventually become.

On that path, however, many challenges and open questions remain. The above sketches require extensive red teaming and many of them are more suggestive than fully prescriptive. How can DAOs maintain their publicity of state while thoughtfully comparing patterns of Souls and correlations in SBTs to enforce Sybil protections and decentralization? How incentive compatible is acquiring SBTs in face of various schemes of correlation discounting? How much does privacy conflict with correlation discounting and other DeSoc mechanism designs? How can we measure inequality in a social and yet appropriately private (contextually integral) manner? How should inheritance work in the community recovery framework? Are there red lines that can be drawn or even baked into protocols to avoid dystopian scenarios? Or should we simply race to build the best scenarios first? These questions are just the beginning of what we expect to be a research agenda spanning years that will co-evolve with the DeSoc ecosystem.

Yet the potential that DeSoc offers seems not just worth the price of navigating these tricky challenges, but perhaps necessary to ensure our survival. Albert Einstein told the 1932 disarmament conference that the failures of the “organizing power of man” to keep pace with “his technical advances” had put a “razor in the hands of a 3-year-old child.” In a world where his observation seems more prescient than ever, learning how to program futures that encode sociality—rather than writing over trust—seems a required course for human life on this planet to persist.

尽管我们一直在想象 DeSoc 可以实现什么,但在许多方面,上述只是第一步。通往 DeSoc 的道路不止一条,包括许多基于非区块链的框架,例如 Spritely、ACDC 和 Backchannel,它们依赖于与本地机器而不是全局分类帐相关的数据存储。这些框架最终可能会在社交距离上提供更大的信任,因为它们可以利用信任关系的传递性——比如受信任的介绍——而不是依赖于知名的高地位机构(如大学或 DAO)发布的 SBT。此外,我们上面描述的应用程序只是 DeSoc 能够增强能力的开始,而不涉及虚拟世界:它们的物理、社会以及它们与物理世界的复杂交集。所有这些都表明,即使是我们在上面描绘的广泛野心,也只是 DeSoc 最终可能成为的开始。

然而,在这条道路上,仍然存在许多挑战和悬而未决的问题。上述草图需要大量的红队,其中许多比完全规范更具暗示性。DAO 如何在仔细比较 SBT 中的灵魂模式和相关性以执行 Sybil 保护和去中心化的同时保持其状态宣传?面对各种相关贴现方案,获得 SBT 的激励兼容性如何?隐私与相关折扣和其他 DeSoc 机制设计有多少冲突?我们如何以一种社会性的但又适当的私人(语境整合)方式来衡量不平等?继承在社区恢复框架中应该如何工作?是否有可以绘制甚至纳入协议的红线以避免反乌托邦情景?还是我们应该首先竞相构建最佳场景?这些问题只是我们期望的跨年研究议程的开始,该议程将与 DeSoc 生态系统共同发展。

然而,DeSoc 提供的潜力似乎不仅值得为应对这些棘手的挑战付出代价,而且可能是确保我们生存所必需的。阿尔伯特·爱因斯坦在 1932 年的裁军会议上说,“人的组织能力”未能跟上“他的技术进步”的步伐,这让“一个 3 岁的孩子手里拿着一把剃刀”。在一个他的观察似乎比以往任何时候都更有先见之明的世界里,学习如何编程编码社会性的未来——而不是写在信任之上——似乎是人类在这个星球上生存下去的必修课。

§6 DECENTRALIZED SOCIETY

Web3 aspires to transform societies broadly, rather than merely financial systems. Yet today’s social fabric—families, churches, teams, companies, civil society, celebrity, democracy—is meaningless in virtual worlds (often called the “metaverse”) without primitives representing human souls and the broader relationships they support. If web3 eschews persistent identities, their patterns of trust and cooperation, and their composable rights and permissions, we see, respectively, sybil attacks, collusion, and a limited economic realm of wholly transferable private property—all of which trends towards hyper-financialization.

To skirt hyper-financialization—yet unlock exponential growth—we propose augmenting and bridging our sociality across virtual and physical realities, empowering souls and communities to encode rich social and economic relationships. But simply building on trust and cooperation is not enough. Correcting for biases and tendencies to over-coordinate (or collude) among trust networks is essential to encouraging more intricate, diverse relationships that span greater social distances than before. We call this “Decentralized Society (DeSoc)”: a co-determined sociality, where Souls and Communities convene bottom-up, as emergent properties of each other to produce plural network goods across different scales.

We emphasize plural network goods as a feature of DeSoc, because networks are the most powerful engine of economic growth, yet the most susceptible to dystopian capture by private actors (e.g., web2) and powerful governments (e.g., Chinese Communist Party). Most significant economic growth results from increasing network returns, where every additional unit of input yields incrementally more output. Examples of simple physical networks include roads, electrical grids, cities, and other forms of infrastructure built off labor and other capital inputs. Examples of powerful digital networks include marketplaces, predictive models and plural intelligences built o￾ data. In both cases, network economics diverges from neoclassical economics, which teaches decreasing returns—where every additional unit of input yields incrementally less output—and where private property yields the most efficient outcomes. Private property applied to an increasing returns context has the opposite effect—throttling network growth by rent extraction. A road between two cities can unlock increasing returns from gains from trade. But the same road privately owned can throttle growth if the owners choose to extract rent up to the value trading between the two cities. Public ownership over a network also has its own perils, being susceptible to regulatory capture or underfunding.

Networks with increasing returns are most efficient when treated neither as purely public nor purely private goods, but rather as partial and plural shared goods. DeSoc provides the social substrate to unbundle and reconfigure rights—rights of use (“usus”), rights to consume or destroy (“abusus”), and rights of profit (“fructus”)—and enable efficient governance mechanisms across these rights that augment trust and cooperation while checking for collusion and capture. We’ve explored several mechanisms throughout this paper, such as community-based SALSA and quadratic funding (and voting) discounted by correlation scores. This third way of partial and plural ownership avoids the Charybdis of private rent extraction and Scylla of public regulatory capture.

Web3 渴望广泛地改变社会,而不仅仅是金融系统。然而,今天的社会结构——家庭、教堂、团队、公司、公民社会、名人、民主——在没有代表人类灵魂的原始人和他们所支持的更广泛关系的虚拟世界(通常称为“元界”)中毫无意义。如果 web3 避开持久性身份、信任和合作模式以及可组合的权利和许可,我们将分别看到女巫攻击、勾结和完全可转让的私有财产的有限经济领域——所有这些都趋向于超金融化。

为了避免过度金融化——同时释放指数级增长——我们建议在虚拟和物理现实中增强和连接我们的社交性,赋予灵魂和社区以编码丰富的社会和经济关系的能力。但仅仅建立在信任与合作之上是不够的。纠正信任网络之间的偏见和过度协调(或勾结)的倾向对于鼓励比以前跨越更大社会距离的更复杂、更多样化的关系至关重要。我们称之为“去中心化社会(DeSoc)”:一种共同决定的社会性,灵魂和社区自下而上地聚集在一起,作为彼此的新兴属性,以生产不同规模的多种网络商品。

我们强调多元网络商品是 DeSoc 的一个特征,因为网络是经济增长最强大的引擎,但最容易被私人参与者(例如 web2)和强大的政府(例如中国共产党)所俘获。最显着的经济增长来自网络回报的增加,其中每增加一个输入单位就会产生更多的输出。简单的物理网络的例子包括道路、电网、城市和其他形式的基础设施,这些基础设施是建立在劳动力和其他资本投入之上的。强大的数字网络的例子包括市场、预测模型和基于数据的多元智能。在这两种情况下,网络经济学都不同于新古典经济学,后者教导收益递减——每增加一个单位的投入产生的产出就会逐渐减少——而私有财产产生最有效的结果。在收益递增的情况下,私有财产会产生相反的效果——通过提取租金来抑制网络增长。两座城市之间的道路可以从贸易收益中获得越来越多的回报。但如果业主选择将租金提高到两个城市之间的价值交易,同一条私人拥有的道路可能会抑制增长。网络的公共所有权也有其自身的风险,容易受到监管或资金不足的影响。

**当既不将其视为纯粹的公共物品或纯粹的私人物品,而是将其视为部分和复数的共享物品时,回报递增的网络效率最高。**DeSoc 为分解和重新配置权利提供了社会基础——使用权(“usus”)、消费或破坏权(“abusus”)和利润权(“fructus”)——并在这些权利中启用有效的治理机制, 在检查合谋和俘虏的同时增强信任和合作。 我们在本文中探索了几种机制,例如基于社区的 SALSA 和相关分数打折的二次融资(和投票)。 第三种部分和复数所有权避免了私人租金提取的 Charybdis 和公共监管捕获的 Scylla。

In many ways, DeFi today is a decreasing returns private property paradigm retro￾tted onto increasing returns networks. Built on the premise of trustlessness, DeFi is inherently limited to the realm of wholly transferable private property (e.g., transferable tokens) that mostly bundles “usus,” “abusus,” and “fructus.” At best, DeFi risks throttling network growth by rent extraction and at worst risks ushering in dystopian surveillance monopolies dominated by “whales’’ who harvest and hoover up data in a race-to-the-bottom—much like web2.

DeSoc transforms DeFi’s race to control and speculate on the value of networks into a bottom-up coordination to build, participate, and govern them. At minimum, DeSoc’s social substrate can make DeFisybil-resistant (enabling community governance), vampire-resistant (internalizing positive externalities to build an open-source network), and collusion-resistant (preserving a network’s decentralization). With DeSoc’s structural corrections, DeFi can support and expand plural networks that confer benefits broadly—as agreed upon by the most diverse members—rather than further entrenching networks captured by narrow interests.

Yet, the greatest strength of DeSoc is its network composability. Sustained increasing returns and network growth isn’t simply avoiding the perils of rent extraction, but also encouraging the proliferation and intersection of nested networks. A road may form a network between two cities. But cut off from broader cooperation, two cooperating cities will eventually hit a ceiling of diminishing returns—either because of congestion (roads and housing) or exhaustion (reaching the limits of the people they can serve). Only through technological innovation and growing broader, if looser, cooperation with neighboring networks for new sources of increasing returns can value continue to grow exponentially. Some cooperation will be physical, incrementally extending physical trade across space. But many more connections will be informational and digital. Over time, we will see new matrices of cooperation between physical and digital networks, reliant upon and extending the social interconnections they are built on. It is precisely this intersecting, partly nested structure of ever growing network cooperation across digital and physical worlds that DeSoc enables.

Through composing networks and coordination, DeSoc emerges at the intersection of politics and markets—augmenting both with sociality. DeSoc empowers the vision of JCR Licklider—founder of ARPANET that created the internet—of “man-computer symbiosis” in an “intergalactic computer network” with dramatically increased social dynamism built on trust. Rather than build on DeFi’s trustless premise, DeSoc encodes trust networks that underpin the real economy today and enables us to harness them to generate plural network goods resilient to capture, extraction, or domination. With such augmented sociality, web3 can eschew short-term hyper-financialization in favor of an unbounded future of increasing returns across social distance.

在许多方面,**今天的 DeFi 是一种收益递减的私有财产范式,被改造成收益递增的网络。**DeFi 建立在无需信任的前提下,本质上仅限于完全可转让的私有财产(例如可转让代币)领域,主要捆绑了 “usus”、 “abusus” 和 “fructus”。充其量,DeFi 有可能通过提取租金来限制网络增长,而在最坏的情况下,有可能迎来由“鲸鱼”主导的反乌托邦监视垄断,这些鲸鱼在竞相下收集和吸食数据——就像 web2 一样。

DeSoc 将 DeFi 控制和推测网络价值的竞赛转变为自下而上的协调,以构建、参与和管理它们。至少,DeSoc 的社会基础可以使 DeFisybil 抗性(支持社区治理)、吸血鬼抗性(内化正外部性以构建开源网络)和抗共谋(保持网络的去中心化)。通过 DeSoc 的结构修正,DeFi 可以支持和扩展多元化的网络,这些网络可以广泛地赋予利益——正如最多样化的成员所同意的那样——而不是进一步巩固被狭隘利益集团俘获的网络。

然而,DeSoc 的最大优势在于其网络可组合性。持续递增的回报和网络增长不仅避免了租金提取的危险,而且还鼓励嵌套网络的扩散和交叉。一条道路可以形成两个城市之间的网络。但如果切断更广泛的合作,两个合作的城市最终将达到收益递减的上限——要么是因为拥堵(道路和住房),要么是因为疲惫(达到了他们可以服务的人群的极限)。只有通过技术创新和更广泛(如果更松散)与邻近网络合作以获得新的收益增加来源,价值才能继续呈指数级增长。一些合作将是实体的,逐步扩展跨空间的实体贸易。但更多的连接将是信息化和数字化的。随着时间的推移,我们将看到物理和数字网络之间的新合作矩阵,依赖并扩展它们所建立的社会互连。正是这种交叉、部分嵌套的跨数字和物理世界不断增长的网络合作结构正是 DeSoc 实现的。

通过组成网络和协调,DeSoc 出现在政治和市场的交汇处——同时增强了社会性。 DeSoc 赋予了 JCR Licklider (创造互联网的 ARPANET 的创始人)在“星际计算机网络”中“人机共生”的愿景,并在信任的基础上显着增强了社会活力。DeSoc 不是建立在 DeFi 的去信任前提之上,而是对支撑当今实体经济的信任网络进行编码,并使我们能够利用它们来生成多种网络商品,以适应捕获、提取或支配。借助这种增强的社交性,web3 可以避免短期的超金融化,转而支持跨越社交距离的无限未来增加回报。

§7 IMPLEMENTATION CHALLENGES

Privacy presents a key challenge for DeSoc. On the one hand, too many public SBTs may reveal too much information about a Soul, making them vulnerable to social control. On the other hand, too many purely private SBTs may also lead to private communication channels that eschew correlation discounting for governance and social coordination—presenting important incentive compatibility questions. Closely related to the issue of privacy is the issue of cheating: Souls may misrepresent their social solidarities, while coordinating through private or side channels. We cannot aspire to know all the possibilities and answers, but instead explore the nature of the challenge here and sketch a few promising paths for future research.

隐私对 DeSoc 来说是一个关键挑战。一方面,太多的公共 SBT 可能会泄露太多关于灵魂的信息,使他们容易受到社会控制。另一方面,过多的纯私人 SBT 也可能导致私人沟通渠道避开治理和社会协调的相关性折扣——这提出了重要的激励相容性问题。与隐私问题密切相关的是欺骗问题:灵魂可能会歪曲他们的社会团结,同时通过私人或辅助渠道进行协调。我们不能渴望知道所有的可能性和答案,而是在这里探索挑战的本质,并为未来的研究勾勒出一些有希望的路径。

7.1 Private Souls

Blockchain-based systems are public by default. Any relationship that is recorded on-chain is immediately visible not just to the participants, but also to anyone in the entire world. Some privacy can be retained by having multiple pseudonyms: a family Soul, a medical Soul, a professional Soul, a political Soul each carrying different SBTs. But done naively, it could be very easy to correlate these Souls to each other. The consequences of this lack of privacy are serious. Indeed, without explicit measures taken to protect privacy, the “naive” vision of simply putting all SBTs on-chain may well make too much information public for many applications.

To deal with over-publicity, there are a number of solutions with different levels of technical complexity and functionality. The simplest approach is that an SBT could store data on-chain.

基于区块链的系统默认是公开的。 记录在链上的任何关系不仅对参与者,而且对全世界的任何人都是立即可见的。使用多个假名可以保留一些隐私:家庭灵魂、医疗灵魂、专业灵魂、政治灵魂,每个都携带不同的 SBT。但是如果天真地完成,很容易将这些灵魂相互关联起来。 这种缺乏隐私的后果是严重的。事实上,如果没有采取明确的措施来保护隐私,简单地将所有 SBT 上链的“幼稚”愿景很可能会使许多应用程序公开太多信息。

为了应对过度宣传,有许多具有不同技术复杂性和功能级别的解决方案。 最简单的方法是 SBT 可以在链上存储数据。

The choice of how to store the o￾-chain data is left to the person; possible solutions include (i) their own devices, (ii) a cloud service trusted by them, or (iii) decentralized networks such as the Interplanetary File System (IPFS). Storing data off-chain lets us continue to have smart contracts that permission the right to write SBT data, but at the same time have separate permissions to read that data. Bob can choose to reveal the contents of any of his SBTs (or the data stores which they permission) only when he wishes to. This already gets us quite far, and has the further benefit of improving technical scalability because most data only needs to be handled by a very small number of parties. But to fully achieve properties like plural privacy, as well as more fine-grained forms of disclosure, we need to go further. Fortunately, many cryptographic technologies let us do that.

One powerful set of building blocks that enables new ways to partially reveal data is a branch of cryptography called “zero knowledge proofs.” While zero knowledge proofs are most frequently used today to enable privacy-preserving transfers of assets, they also can allow people to prove arbitrary statements without revealing any more information beyond the statement itself. For example, in a world where government documents and other attestations are cryptographically provable, someone could prove a statement like “I am a citizen of Canada, who is over 18 years old and has a university degree in economics and over 50,000 Twitter followers, and who has not yet claimed an account in this system.”

Zero-knowledge proofs can be computed over SBTs to prove characteristics about a Soul (e.g., that it has certain memberships). This technique can be extended further by introducing multi-party computation techniques such as garbled circuits, which could make such tests doubly private: the prover does not reveal who they are to the verifier, and the verifier does not reveal their verification mechanism to the prover. Instead, both parties make the computation together and only learn the output.

Another powerful technique is designated-verifier proofs. In general, “data” is slippery: if I send a movie to you, I cannot technologically prevent you from recording and sending it to a third party. Workarounds like Digital Rights Management (DRM) have at best limited e￾ectiveness, and often come at great costs to users. Proofs, however, are not slippery in the same way. If Amma wants to prove some property X about her SBTs to Bob, she can make a zero knowledge proof of the statement “I hold SBTs that satisfy property X, OR I have the access key to Bob’s Soul.” Bob would find this statement convincing: he knows that he did not make the proof, and so Amma must actually have SBTs that satisfy property X. But if Bob passes the proof along to Cuifen, Cuifen would not be convinced: for all he knows, Bob could have made the proof with his own key. This can be made even stronger with verifiable delay functions (VDFs): Amma can make and present a proof that can only be made with the required SBTs right now, but anyone else will be able to make five minutes from now. This means it is possible to represent sophisticated access permissions to trustworthy proofs about data despite the impossibility of making the same kinds of selective permissions to the raw data itself, which may simply be copy and pasted. This may take us quite far nonetheless. Just as blockchains o￾er traceability in transactions that prevents someone from right-click copy-and-pasting a valuable NFT (and sybil attacking the original owner), similarly SBTs can o￾er traceability in social prevenance, which at minimum can reduce the value of copy-and-pasted data with unverified origins.

These off-chain data and zero-knowledge techniques are compatible with negative reputation—SBTs that are made visible even if the holder does not want them to be visible. Important examples of negative reputation include credit history, data about unpaid loans, negative reviews and complaints from business partners, and SBTs attesting to social connections relevant for coordination. Blockchains coupled with the same cryptography could offer a potential solution: Souls could be forced by smart contract logic to incorporate negative SBTs into a data structure like a Merkle tree that is stored off-chain, and any zero knowledge proof or garbled circuit computation would require them to introduce that information, because otherwise there would be a visible “hole” in the provided data that the verifier would recognize. The Unirep protocol is an example of how this might be implemented.

The point of these examples is not to show exactly how cryptographic technology can be used to solve all of the privacy and data permissioning problems with SBTs. Rather, it is to sketch out a few examples to show the power of such technologies. An important future research direction is to scope the exact limits of different kinds of data permissioning and the specific combinations of techniques that work best to achieve the desired level of permissions. Another question is what types of plural property regimes are desirable to govern data, and how to properly unbundle access (“usus”), editing (“abusus”) and cash.

如何存储外链数据的选择由个人决定;可能的解决方案包括(i)他们自己的设备,(ii)他们信任的云服务,或(iii)去中心化网络,例如星际文件系统(IPFS)。将数据存储在链下让我们继续拥有有权写入 SBT 数据的智能合约,但同时拥有读取该数据的单独权限。Bob 可以选择仅在他愿意时透露他的任何 SBT(或他们允许的数据存储)的内容。这已经让我们走得很远,并且具有提高技术可扩展性的进一步好处,因为大多数数据只需要由极少数方处理。但要完全实现多元隐私等属性,以及更细粒度的披露形式,我们还需要更进一步。幸运的是,许多加密技术让我们能够做到这一点。

一组强大的构建块能够以新的方式部分揭示数据,它是密码学的一个分支,称为**“零知识证明”**。虽然如今零知识证明最常用于保护隐私的资产转移,但它们也可以让人们证明任意陈述,而无需透露陈述本身之外的任何更多信息。例如,在一个政府文件和其他证明可以通过密码证明的世界中,有人可以证明这样的陈述:“我是加拿大公民,年满 18 岁,拥有大学经济学学位和超过 50,000 名 Twitter 关注者,并且谁还没有在这个系统中申请账户。”零知识证明可以通过 SBT 计算来证明灵魂的特征(例如,它具有某些成员资格)。通过引入多方计算技术(例如乱码电路)可以进一步扩展该技术,这可以使此类测试具有双重私密性:证明者不会向验证者透露他们是谁,而验证者不会向证明者透露他们的验证机制。相反,双方一起进行计算,只学习输出。

另一种强大的技术是指定验证者证明。总的来说,“数据”是很滑的:如果我向您发送电影,我无法在技术上阻止您录制并将其发送给第三方。数字版权管理 (DRM) 之类的变通办法充其量只能起到有限的作用,而且通常会给用户带来巨大的成本。然而,证明并不是以同样的方式滑溜的。如果 Amma 想向 Bob 证明一些关于她的 SBT 的属性 X,她可以对“我持有满足属性 X 的 SBT,或者我拥有 Bob 的灵魂的访问密钥”这一陈述进行零知识证明。 Bob 会发现这个陈述令人信服:他知道他没有做出证明,因此 Amma 实际上必须有满足性质 X 的 SBT。但是如果 Bob 将证明传递给 Cuifen,Cuifen 不会被说服:据他所知, Bob 可以用他自己的密钥来证明。这可以通过可验证的延迟函数 (VDF) 变得更加强大:Amma 可以制作并展示目前只能使用所需的 SBT 制作的证明,但其他任何人都可以在五分钟后制作。这意味着尽管不可能对原始数据本身(可能只是简单地复制和粘贴)进行相同类型的选择性权限,但可以表示对有关数据的可信证明的复杂访问权限。尽管如此,这可能会让我们走得很远。正如区块链在交易中提供可追溯性以防止某人右键单击复制和粘贴有价值的 NFT(以及女巫攻击原始所有者)一样,SBT 可以在社会传播方面提供可追溯性,这至少可以减少来源未经验证的复制粘贴数据的价值。

这些链下数据和零知识技术与负面声誉兼容——即使持有者不希望它们可见,SBT 也会变得可见。负面声誉的重要示例包括信用记录、未付贷款数据、负面评论和业务合作伙伴的投诉,以及证明与协调相关的社会关系的 SBT。与相同密码学相结合的区块链可以提供一个潜在的解决方案:智能合约逻辑可以强制 Souls 将负 SBT 合并到数据结构中,例如存储在链外的 Merkle 树,并且任何零知识证明或乱码电路计算都需要他们介绍该信息,否则在提供的数据中会有一个可见的“漏洞”,验证者会识别出来。 Unirep 协议是如何实现这一点的一个例子。

这些示例的重点并不是要准确说明如何使用加密技术来解决 SBT 的所有隐私和数据许可问题。相反,它是勾勒出几个例子来展示这些技术的力量。一个重要的未来研究方向是确定不同类型数据许可的确切限制以及最适合实现所需许可级别的技术的特定组合。 另一个问题是需要什么样的多元财产制度来管理数据,以及如何正确地拆分访问(“usus”)、编辑(“abusus”)和现金。

7.2 Cheating Souls

If SBTs are the social substrate upon which plural property, network goods and intelligences are coordinated, one might be concerned that Souls will try to trick or cheat their way into communities to gain access to governance or property rights that we imagine SBTs permissioning. For example, if many applications depend on SBTs representing conference attendance, unscrupulous conferences could offer such SBTs in exchange for bribes. With enough bribes, humans (and bots) could generate a fake social graph that makes the account look like an authentic human Soul, richly ifferentiated by (fake) SBTs. Just as DAOs can be bribed, so can Souls and the on-chain voting mechanisms which they use. Conversely, if SBTs are used to discount coordination, Souls may avoid SBTs to maximize their influence. Why should we believe that the SBTs a Soul possess accurately reflect their true social commitments rather than simply how they choose to play this game?

One argument is that the varying incentives to cheat may “balance out.” Souls may sort and self-identify into the networks that are important to them at the right scale, much like how Harberger taxes balance out the incentive to over-value and under-value assets to elicit approximately accurate market valuations. Souls will want to hold more SBTs to gain influence within their communities, but on the other hand will eschew SBTs from communities they care less about to score lower on correlation metrics and increase their influence in governance over broader networks.

But it would be naive to assume that the two incentives—to gain access and maximize influence—always evenly cancel out, or even come close to canceling out, as though by magic. There may be many communities that use systems other than SBTs to gate access and governance. Or communities may—counter to our primary assumption about publicity—dole out private SBTs to reflect governance rights, but induce community members to keep these SBTs secret in broader decisions.

The problem of “gaming” should not be understated. It is a significant issue and resolving it is one of the most important foci for future research. Indeed, it is a major reason why open-sourcing many existing algorithms that prioritize or filter for human users is very challenging. To mitigate and deter SBT gaming, we suggest several norms and cryptographic directions:

如果 SBT 是多种财产、网络商品和智能在其上协调的社会基础,人们可能会担心灵魂会试图欺骗或欺骗他们进入社区,以获得我们想象 SBT 允许的治理或财产权。例如,如果许多应用程序依赖于代表会议出席的 SBT,则不道德的会议可能会提供此类 SBT 以换取贿赂。有了足够的贿赂,人类(和机器人)可以生成一个虚假的社交图谱,使该帐户看起来像一个真实的人类灵魂,并被(假的)SBT 丰富地分化。就像 DAO 可以被贿赂一样,Souls 和他们使用的链上投票机制也可以。相反,如果使用 SBT 来降低协调性,Souls 可能会避免 SBT 以最大化其影响力。为什么我们应该相信灵魂拥有的 SBT 准确地反映了他们真正的社会承诺,而不仅仅是他们选择玩这个游戏的方式?

一个论点是,不同的作弊动机可能会“平衡”。灵魂可能会以适当的规模分类和自我识别到对他们来说很重要的网络中,就像哈伯格税收如何平衡高估和低估资产的激励,以得出大致准确的市场估值一样。 Souls 将希望持有更多的 SBT 以在其社区中获得影响力,但另一方面,他们会避开他们不太关心的社区中的 SBT,以在相关性指标上得分较低,并增加他们在更广泛网络治理中的影响力。

但是,如果假设这两种激励措施——获得访问权和最大化影响力——总是均匀地抵消,甚至接近于抵消,就好像施了魔法一样,那就太天真了。可能有许多社区使用 SBT 以外的系统来控制访问和治理。或者社区可能——与我们关于公开的主要假设相反——发放私人 SBT 以反映治理权利,但诱使社区成员在更广泛的决策中对这些 SBT 保密。

“游戏”的问题不容小觑。这是一个重要的问题,解决它是未来研究的最重要的焦点之一。事实上,这也是为什么开源许多为人类用户优先考虑或过滤的现有算法非常具有挑战性的一个主要原因。为了减轻和阻止 SBT 游戏,我们建议了几个规范和加密方向:

  1. The ecosystem of SBTs could bootstrap off “thick” community channels, where SBTs signal authentic off-chain community membership with strong social bonds and repeat interactions. This would make it easier for communities to filter and revoke SBTs of impersonators and bots. Such thick channels—which we often find in churches, workplaces, schools, meet-up groups, and organizations in civil society—would provide a more sybil-resistant social substrate to police gaming (e.g., through bots, bribes, impersonation) in more “thin” social channels.
  2. Nested communities could require SBTs to force context on potential collusion vectors “just below” them. For example, if a state were holding a funding round or vote, the state might require every participating citizen to also hold an SBT of a defined county and municipality.
  3. The openness and cryptographic provability of the SBT ecosystem could itself be used to actively detect collusive patterns and penalize inauthentic behavior—perhaps discounting the voting power of collusive Souls, or obliging Souls to accept SBTs representing negative attestations. For example, if one Soul attests to the humanity of another Soul that turns out to be a bot, the case can be escalated and publicly verified, leading to that Soul having a large number of negative attestations. This already happens to an extent within the GitCoin QF ecosystem, where a range of signals are used to detect “collusive groups.”
  4. ZK technology (eg. MACI) could cryptographically prevent some attestations made by a Soul from being provable. This would make attempts to sell certain kinds of attestations non-credible, because the briber would have no way to tell whether or not the bribe recipient followed through on their side of the deal. There has been a large body of research on the use of such techniques for voting, but ultimately any non-financialized social mechanism may end up benefiting from similar ideas.
  5. We could encourage whistleblowers as a way of making collusion of significant size unstable. Instead of detecting and penalizing incorrect or abusive behavior, we detect and penalize abusive patterns of collusion. This technique is risky to overuse because of the possibility of false-flag bribes, but it is nevertheless part of the toolkit.
  6. We could use mechanisms from peer-prediction theory to encourage reporting to be honest in all cases except where collusion is extremely large. Instead of the conference attesting to attendees’ attendance, attendees could attest to each other’s attendance, so the number of participants that would need to be bribed to attest to a false claim becomes very large. The rewards need not be financial, but could be SBTs, making the rewards more useful to genuine community members than they are to attackers.
  7. We could use correlation scores that focus on correlations where there is a large incentive to be honest if a group of Souls share a common interest. For example, the correlation scoring technique used in bounded pairwise quadrating funding uses quadratic funding donations themselves to determine how correlated two participants are, and therefore how much to discount their intersection. If two participants share many common interests, their incentive to express this fact to the QF mechanism is certainly diminished with correlation discounting, but it never becomes zero or negative.

While the range of identity frameworks proposed is almost limitless, there are four particularly prominent and adjacent paradigms widely discussed in the web3 space that merit comparison: the dominant “legacy” identity ecosystem, the pseudonymous economy, proof of personhood, and verifiable credentials. Each paradigm highlights important contributions and challenges for future development of the social identity paradigm we advocate, and we use such limitations as a springboard for exploring future directions. All that considered, we also explain why we believe our social identity primitives of Souls and soulbound tokens are a more promising path forward for privacy regimes.

  1. SBT 的生态系统可以引导“厚”的社区渠道,在这些渠道中,SBT 通过强大的社会纽带和重复互动表明真正的链下社区成员身份。 这将使社区更容易过滤和撤销冒充者和机器人的 SBT。 如此密集的渠道——我们经常在教堂、工作场所、学校、聚会小组和民间社会的组织中发现——将为警察博弈(例如,通过机器人、贿赂、冒充)提供更具抗女巫性的社会基础。 “瘦”社交渠道。
  2. 嵌套社区可能需要 SBT 将上下文强加在“正下方”的潜在共谋向量上。例如,如果一个州正在举行一轮融资或投票,该州可能会要求每个参与的公民也持有一个确定的县和市的 SBT。
  3. SBT 生态系统的开放性和密码学可证明性本身可用于主动检测合谋模式并惩罚不真实行为——可能会降低合谋 Souls 的投票权,或迫使 Souls 接受代表负面证明的 SBT。例如,如果一个灵魂证明另一个灵魂是机器人的人性,那么案件可以升级并公开验证,导致该灵魂有大量负面证明。这在 GitCoin QF 生态系统中已经在一定程度上发生了,其中使用一系列信号来检测“合谋团体”。
  4. ZK 技术(例如 MACI)可以通过密码防止灵魂做出的某些证明是可证明的。这将使出售某些类型的证明的尝试变得不可信,因为贿赂者无法判断受贿者是否遵守了他们的交易。已经有大量关于使用这种技术进行投票的研究,但最终任何非金融化的社会机制都可能最终受益于类似的想法。
  5. 我们可以鼓励举报人,以此来使大规模的串通变得不稳定。我们不是检测和惩罚不正确或滥用行为,而是检测和惩罚共谋的滥用模式。由于存在虚假贿赂的可能性,这种技术有过度使用的风险,但它仍然是工具包的一部分。
  6. 我们可以使用来自同行预测理论的机制来鼓励在所有情况下都诚实报告,除非串通非常大。与会议证明与会者的出席不同,与会者可以证明彼此的出席,因此需要贿赂以证明虚假声明的与会者数量变得非常大。奖励不一定是金钱上的,但可以是 SBT,这使得奖励对真正的社区成员比对攻击者更有用。
  7. 如果一群灵魂有共同的兴趣,我们可以使用关注相关性的相关性分数。例如,有界成对二次融资中使用的相关评分技术使用二次融资捐赠本身来确定两个参与者的相关性,从而确定他们的交集的折扣程度。如果两个参与者有许多共同利益,他们向 QF 机制表达这一事实的动机肯定会随着相关性折扣而减少,但它永远不会变成零或负数。

虽然提出的身份框架的范围几乎是无限的,但在 web3 空间中有四个特别突出和相邻的范式被广泛讨论,值得比较:占主导地位的“传统”身份生态系统、假名经济、人格证明和可验证的凭据。每个范式都突出了我们所倡导的社会认同范式未来发展的重要贡献和挑战,我们将这些限制作为探索未来方向的跳板。考虑到所有这些,我们还解释了为什么我们相信我们的灵魂和灵魂令牌的社会身份原语是隐私制度的一条更有希望的前进道路。