// document . 31.10.2008

Bitcoin: A Peer-to-Peer Electronic Cash System

Satoshi Nakamoto · 31 octobre 2008

Les neuf pages qui lancent tout. En référence numéro 1 : le b-money de Wei Dai. En référence numéro 6 : le Hashcash d'Adam Back.

Le 31 octobre 2008, Satoshi Nakamoto poste sur la liste de cryptographie de metzdowd.com un document de neuf pages, signé d'une adresse satoshin@gmx.com et renvoyant à www.bitcoin.org. Il y résout le problème de la double dépense sans tiers de confiance, en combinant signatures numériques, horodatage en chaîne et preuve de travail : la chaîne la plus longue, celle qui cumule le plus de calcul, fait foi.

Le document est aussi une carte de ses influences. Sa toute première référence est le b-money de Wei Dai (1998) ; sa référence numéro 6, le Hashcash d'Adam Back (2002). Ces deux hommes figurent parmi les premiers que Satoshi a contactés, quelques semaines plus tôt.

Le moule Hashcash

Le whitepaper Bitcoin emprunte ouvertement la forme du papier Hashcash : même genre de publication cypherpunk « académique » — un résumé, des sections numérotées, la preuve de travail (proof-of-work) au cœur du dispositif, une bibliographie. Satoshi n'a pas seulement repris l'idée d'Adam Back, il en a repris la présentation. À comparer côte à côte :

↓ bitcoin.pdf (Satoshi, 2008, 9 p.)↓ hashcash.pdf (Adam Back, 2002, 10 p.)

… mais pas la même plume

Le moule est partagé ; l'écriture, non. L'analyse textuelle des deux PDF fait ressortir plusieurs divergences nettes :

Hashcash · Adam Back, 2002

  • orthographe« favor » (américain)
  • registreaucune contraction, très formel
  • phrase moyenne~17 mots
  • compositionLaTeX (GNU Ghostscript)

Bitcoin · Satoshi, 2008

  • orthographe« favour » (britannique)
  • registrecontractions courantes (they'll, can't, he's)
  • phrase moyenne~14 mots
  • compositionOpenOffice.org Writer

Conclusion mesurée : Satoshi a manifestement lu, cité et réutilisé Hashcash, jusqu'à en copier la présentation. Mais l'orthographe britannique de Satoshi face à l'américaine de Back, son registre plus direct (truffé de contractions là où Hashcash n'en compte aucune) et un outil de composition radicalement différent plaident pour deux auteurs distincts. C'est cohérent avec le reste du dossier : Adam Back a toujours nié être Satoshi, et les études stylométriques sérieuses (équipe de l'université d'Aston, 2014) ne le désignent pas, elles pointent plutôt Nick Szabo. Réserve d'usage : la stylométrie sur deux textes courts n'est pas une preuve, mais un faisceau d'indices convergents.

Ci-dessous, le résumé (abstract) et les références du whitepaper, reproduits verbatim.

Abstract Satoshi Nakamoto . satoshin@gmx.com . www.bitcoin.org
Abstract. A purely peer-to-peer version of electronic cash would allow online
payments to be sent directly from one party to another without going through a
financial institution. Digital signatures provide part of the solution, but the main
benefits are lost if a trusted third party is still required to prevent double-spending.
We propose a solution to the double-spending problem using a peer-to-peer network.
The network timestamps transactions by hashing them into an ongoing chain of
hash-based proof-of-work, forming a record that cannot be changed without redoing
the proof-of-work. The longest chain not only serves as proof of the sequence of
events witnessed, but proof that it came from the largest pool of CPU power. As
long as a majority of CPU power is controlled by nodes that are not cooperating to
attack the network, they'll generate the longest chain and outpace attackers. The
network itself requires minimal structure. Messages are broadcast on a best effort
basis, and nodes can leave and rejoin the network at will, accepting the longest
proof-of-work chain as proof of what happened while they were gone.
archive → https://bitcoin.org/bitcoin.pdf
References Bitcoin: A Peer-to-Peer Electronic Cash System, p.9
[1] W. Dai, "b-money," http://www.weidai.com/bmoney.txt, 1998.
[2] H. Massias, X.S. Avila, and J.-J. Quisquater, "Design of a secure timestamping service with minimal
 trust requirements," In 20th Symposium on Information Theory in the Benelux, May 1999.
[3] S. Haber, W.S. Stornetta, "How to time-stamp a digital document," In Journal of Cryptology, vol 3, no
 2, pages 99-111, 1991.
[4] D. Bayer, S. Haber, W.S. Stornetta, "Improving the efficiency and reliability of digital time-stamping,"
 In Sequences II: Methods in Communication, Security and Computer Science, pages 329-334, 1993.
[5] S. Haber, W.S. Stornetta, "Secure names for bit-strings," In Proceedings of the 4th ACM Conference
 on Computer and Communications Security, pages 28-35, April 1997.
[6] A. Back, "Hashcash - a denial of service counter-measure,"
 http://www.hashcash.org/papers/hashcash.pdf, 2002.
[7] R.C. Merkle, "Protocols for public key cryptosystems," In Proc. 1980 Symposium on Security and
 Privacy, IEEE Computer Society, pages 122-133, April 1980.
[8] W. Feller, "An introduction to probability theory and its applications," 1957.