Bitcoin and Cryptocurrency Technologies
Stanford University Blockchain Main Textbook
ํ์ด๊ฑฐ์คํฐ๋ : ์คํ ํฌ๋๋ํ๊ต ๋ธ๋ก์ฒด์ธ ๊ต๊ณผ์ ๋ฒ์ญ์์ (2)
์ด ์๋ฃ๊ฐ ๋ํ๋ฏผ๊ตญ์ ๋ธ๋ก์ฒด์ธ ์ธ์ฌ์์ฑ์ ์ํด ๊ท์คํ ์ฐ์ฌ์ง๊ธฐ๋ฅผ
์ด ์๋ฃ๋ ๋ธ๋ก์ฒด์ธ ํ์ด๊ฑฐํ์ด ๋ฐฐํฌํ๋ ์๋ฃ์ ๋๋ค.
ํ์ด๊ฑฐํ ๋ฒ์ญ์์๊ฐ
์ด ์๋ฃ๋ ๋ค์๊ณผ ๊ฐ์ ๋ธ๋ก์ฒด์ธํ์ด๊ฑฐ ํ์๋ค์ด
๋ฒ์ญ ๋ฐ ๊ฐ์์ ์ฐธ์ฌํ๊ณ ๊ณ์ญ๋๋ค.
ํ๊ธ/์ํ๋ฒณ์
๊ฐ๋ฏผ(mini)๋ : ๊ต์ก์ฌ๋ฆฌ ์คํํธ์
๊น๋ฏผ์๋ : ๋ธ๋ก์ฒด์ธ์คํํธ์
์ํผํ ๋ฏธ
๋ฅ๊ณต๋ : ์ผ์ฑ์ ์
์์๊ด(์ํฐ)๋ : ์ปค๋ฅํธ๊ต์ก
์ค์ ๋ : ์ธํ
์ค์น์๋ : ๋ธ๋ก์ฒด์ธ์คํํธ์
๋นํธ๋ธ๋ฆฟ์ง
์ค์ข
ํ (shyguy)๋ : ๋ธ๋ก์ฒด์ธ์ ๋๋ฆฌ์คํธ
์ด๋์น(bramd)๋ : ์์ฌ
์ด์ถฉ(์น์ด์ค)๋ : ์น์์ด์ ์ ์น์ด์ค
์ํ๋
น๋ : ์์์๋ํญ๊ณต
์ง๋ฆฌ๋ : ์ผ์ฑ์ ์
Culap๋ : ํ๋๋งค๋์
hakuna๋ : ๋ํํญ๊ณต
danijee ๋ : AIG
๋ธ๋ก์ฒด์ธํ์ด๊ฑฐํ์
์ฐ๋ฆฌ ์ค์ค๋ก์ ๊ณต๋ถ์ ๋๋ถ์ด
๋ํ๋ฏผ๊ตญ ๋ธ๋ก์ฒด์ธ ๊ณต๋์ฒด์ ๋ฐ์ ์ ๊ธฐ์ฌํ๊ธฐ ์ํด์
์คํ ํฌ๋๋ํ๊ต ๋นํธ์ฝ์ธ/๋ธ๋ก์ฒด์ธ ์ ์ฒด๊ณผ์
https://crypto.stanford.edu/cs251/syllabus.html
์ ๊ต๊ณผ์, ๋ชจ๋ pdf ํ์ผ๋ค์ ๋ํ ๋ฒ์ญ ํ๋ก์ ํธ๋ฅผ
์คํํ๊ณ ์์ต๋๋ค.
์ด ์๋ฃ๋ ๋ฉ์ธ๊ต๊ณผ์ Bitcoin and Cryptocurrency Technologies
๋ฒ์ญ์๋ฃ์ด๋ฉฐ ๊ณ์ ์ฑ์คํ ์งํ์ค์
๋๋ค.
The trouble with credit cards online
์จ๋ผ์ธ ์ ์ฉ์นด๋ ๋ฌธ์
Credit and cash are fundamental ideas, to the point that we can sort the multitude of electronic payment methods into two piles.
์ ์ฉ ๋ฐ ํ๊ธ์ ๊ทผ๋ณธ์ ์ธ ์์ด๋์ด์ด๋ฉฐ, ๊ทธ ์ ์์ ๋ค์์ ์ ์ ์ง๋ถ ๋ฐฉ๋ฒ์ ๋๊ฐ์ ๋๋ฏธ๋ก ๋ถ๋ฅํ ์ ์์ต๋๋ค.
Bitcoin is obviously in the โcashโ pile, but letโs look at the other one first.
๋นํธ์ฝ์ธ์ ๋ถ๋ช
ํ โํ๊ธโ ๋๋ฏธ์ ์์ง๋ง, ์ฐ์ ๋ค๋ฅธ ๊ฒ์ ๋จผ์ ์ดํด๋ณด๊ฒ ์ต๋๋ค.
Credit card transactions are the dominant payment method that is used on the web today.
์ ์ฉ์นด๋๊ฑฐ๋๋ ์ค๋๋ ์น์์ ์ฌ์ฉ๋๋ ์ง๋ฐฐ์ ์ธ ์ง๋ถ ๋ฐฉ๋ฒ์
๋๋ค.
If youโve ever bought something from an online seller such as Amazon, you know how the arrangement goes.
Amazon๊ณผ ๊ฐ์ ์จ๋ผ์ธ ํ๋งค์๋ก๋ถํฐ ๋ฌผ๊ฑด์ ๊ตฌ์
ํ ์ ์ด ์๋ค๋ฉด, ๊ณผ์ ์ด ์ด๋ป๊ฒ ์งํ๋๋์ง ์ ์ ์์ต๋๋ค.
You type in your credit card details, you send it to Amazon, and then Amazon turns around with these credit card details and they talk to the โsystemโโa financial system involving processors, banks, credit card companies, and other intermediaries.
์ ์ฉ์นด๋๋ฅผ ์์ธํ ์
๋ ฅํ๊ณ , Amazon์ผ๋ก ๋ณด๋ด๋ฉด, Amazon์ ์ด๋ฌํ ์ ์ฉ์นด๋ ์์ธ์ ๋ณด๋ฅผ ๊ฐ์ง๊ณ ์์คํ
๊ณผ ์ฐ๊ฒฐํ๋๋ฐ, ์ด ์์คํ
์ ํ๋ก์ธ์, ์ํ, ์ ์ฉ์นด๋ํ์ฌ ๋ฐ ์ฌ๋ฌ ์ค๊ฐ์๋ค์ด ๊ด๋ จ๋์ด ์๋ ๊ธ์ต์์คํ
์ ์๋ฏธํฉ๋๋ค.
On the other hand, if you use something like PayPal, what you see is an intermediary architecture.
๋ฐ๋ฉด, Paypal๊ณผ ๊ฐ์ ๊ฒ์ ์ฌ์ฉํ๋ค๋ฉด, ๋น์ ์ด ๋ณด๋ ๊ฒ์ ์ค๊ฐ ์์คํ
๊ตฌ์กฐ์
๋๋ค.
Thereโs a company that sits between you and the seller, so you send your credit card details to this intermediary, which approves the transaction and notifies the seller.
๋น์ ๊ณผ ํ๋งค์ ์ฌ์ด์ ํ์ฌ๊ฐ ์์ผ๋ฏ๋ก, ์ ์ฉ์นด๋ ์ธ๋ถ์ ๋ณด๋ฅผ ์ค๊ฐ์ธ์๊ฒ ๋ณด๋ด๋ฉด, ๊ฑฐ๋๋ฅผ ์น์ธํ๊ณ , ํ๋งค์์๊ฒ ์๋ฆฝ๋๋ค.
The intermediary will settle its balance with the seller at the end of each day.
์ค๊ฐ์ธ์ ํ๋ฃจ๋ฅผ ๋ง๋ฌด๋ฆฌํ ๋ ํ๋งค์์ ์๊ณ ๋ฅผ ๊ฒฐ์ฐํฉ๋๋ค.
What you gain from this architecture is that you donโt have to give the seller your credit card details, which can be a security risk.
๋น์ ์ด ์ด ์ํคํ
์ณ์์ ์ป๋ ๊ฒ์ ๋ณด์ ์ํ์ด ๋ ์ ์๋ ์ ์ฉ์นด๋ ์ ๋ณด๋ฅผ ํ๋งค์์๊ฒ ์ ๊ณตํ ํ์๊ฐ ์๋ค๋ ๊ฒ์
๋๋ค.
You might not even have to give the seller your identity, which would improve your privacy as well.
ํ๋งค์์๊ฒ ์ ์์ ๋ฐํ ํ์ ์กฐ์ฐจ ์์ผ๋ฉฐ, ์ด๊ฒ์ ๋น์ ์ ๊ฐ์ธ์ ๋ณด ๋ณดํธ๋ฅผ ๋ํ ํฅ์ ์ํต๋๋ค.
The downside is that you lose the simplicity of interacting directly with the seller.
๋จ์ ์ ํ๋งค์์ ์ง์ ์ํธ์์ฉํ๋ ๋จ์์ฑ์ ์์คํ๋ค๋ ๊ฒ์
๋๋ค.
Both you and the seller might have to have an account with the same intermediary.
๋น์ ๊ณผ ํ๋งค์ ๋ชจ๋ ๋์ผํ ์ค๊ฐ์์ ๊ณ์ข๋ฅผ ๋ณด์ ํด์ผ ํ ์๋ ์์ต๋๋ค.
Today most of us are comfortable with giving out our credit card information when shopping online, or at least weโve grudgingly accepted it.
์ค๋๋ ์ฐ๋ฆฌ ์ค ๋๋ถ๋ถ์ ์จ๋ผ์ธ ์ผํ์ ํ ๋ ์ ์ฉ์นด๋ ์ ๋ณด๋ฅผ ์ ๊ณตํ๋ ๊ฒ์ ์ต์ํ๋ฉฐ, ํน์ ๊ทธ๋ ์ง ์๋ค ํ๋๋ผ๋, ์ ์ด๋ ๋ง์ง๋ชปํด ๊ทธ๊ฒ์ ๋ฐ์๋ค์
๋๋ค.
Weโre also used to companies collecting data about our online shopping and browsing activity.
์ฐ๋ฆฌ๋ ๋ํ ์จ๋ผ์ธ ์ผํ ๋ฐ ํ์ ํ๋์ ๋ํ ๋ฐ์ดํฐ๋ฅผ ์์งํ๋ ๊ฒ์ ์ต์ํฉ๋๋ค.
But in the 1990s, the web was new, standards for protocol-level encryption were just emerging, and these concerns made consumers deeply uncertain and hesitant.
๊ทธ๋ฌ๋ 1990๋
๋์ ์น์ด ์๋ก ๋ํ๋ฌ๊ณ , ํ๋กํ ์ฝ ๋ ๋ฒจ์ ์ํธํ ํ์ค์ด ์ด์ ๋ง ๋ฑ์ฅํ๊ธฐ ๋๋ฌธ์, ์๋น์๋ค์ ์น์ ์ฌ์ฉํ๋ ๊ฒ์ ํฌ๊ฒ ๋ถํ์คํ๊ณ ์ฃผ์ ํ์ต๋๋ค.
In particular, it was considered crazy to hand over your credit card details to online vendors of unknown repute over an insecure channel.
ํนํ, ์์ ํ์ง ์์ ์ฑ๋์ ์๋, ์ ๋ชจ๋ฅด๋ ์จ๋ผ์ธ ๊ณต๊ธ ์
์ฒด์๊ฒ ์ ์ฉ์นด๋์ธ๋ถ์ ๋ณด๋ฅผ ์ ๋ฌํ๋ ๊ฒ์ ๋ฏธ์น ์ผ๋ก ๊ฐ์ฃผ๋์์ต๋๋ค.
In such an environment, there was a lot of interest in the intermediary architecture.
์ด๋ฌํ ํ๊ฒฝ์์, ์ค๊ฐ ์ํคํ
์ฒ์ ๋ํ ๋ง์ ๊ด์ฌ์ด ์๊ฒจ๋ฌ์ต๋๋ค.
A company called FirstVirtual was an early payment intermediary, founded in 1994.
FirstVirtual์ด๋ผ๋ ํ์ฌ๋ 1994๋
์ ์ผ์ฐ์ด ์ค๋ฆฝ๋ ์ง๋ถ ์ค๊ฐ์
์ฒด์์ต๋๋ค.
Incidentally, they were one of the first companies to set up a purely virtual office with employees spread across the country and communicating over the Internet โ hence the name.
๋๋์๊ฐ, ๊ทธ๋ค์ ์ ๊ตญ์ ํผ์ ธ ์๋ ์ง์๋ค๊ณผ ์ธํฐ๋ท์ ํตํด ์์ฌ์ํตํ๋ ์์ํ ๊ฐ์ ์ฌ๋ฌด์ค์ ์ฒ์์ผ๋ก ์ค๋ฆฝํ ํ์ฌ๋ค ์ค์ ํ๋ ์์ต๋๋ค.
FirstVirtualโs proposed system was a little like PayPalโs current system but preceded it by many years.
FirstVirtual์ด ์ ์ํ๋ ์์คํ
์ Paypal์ ํ์ฌ ์์คํ
๊ณผ ๋น์ทํ์ง๋ง, Paypal ๋ณด๋ค ์๋
์ ์ ์ ์๋์์ต๋๋ค.
In fact, they had a very general proposal for how you might extend the protocol, and one of the use cases that they had was doing payments.
์ฌ์ค, ๊ทธ๋ค์ ํ๋กํ ์ฝ ํ์ฅ ๋ฐฉ๋ฒ์ ๋ํ ๋งค์ฐ ์ผ๋ฐ์ ์ธ ์ ์์ ๊ฐ๊ณ ์์๊ณ , ๊ทธ๊ฒ ์ค์ ํ๋๋ ์ง๋ถ ์ฌ๋ก๋ฅผ ์ฌ์ฉํ๋ ์ฌ์ฉ์ ์ผ์ด์ค์์ต๋๋ค.
This never happened -- the whole extension framework was never deployed in any browsers.
์ด๊ฒ์ ์์ ์ผ์ด๋์ง ์์๋๋ฐ, ํ์ฅ ํ๋ ์์ํฌ๋ ์ด๋ค ๋ธ๋ผ์ฐ์ ์๋ ๋ฐฐํฌ๋์ง ์์์ต๋๋ค.
In 2015, almost two decades later, the W3C has announced that it wants to take another crack at it, and that Bitcoin will be part of that standardization this time around.
๊ฑฐ์ 20๋
ํ์ธ 2015๋
์ W3C๋ ๋ ๋ค๋ฅธ ํ์ ์ ์ํ๋ฉฐ, Bitcoin์ด ํ์คํ์ ์ผ๋ถ๊ฐ ๋ ๊ฒ์ด๋ผ๊ณ ๊ณตํํ์ต๋๋ค.
Given all the past failures, however, I wonโt be holding my breath.
๊ทธ๋์์ ๋ชจ๋ ์คํจ์๋ ๋ถ๊ตฌํ๊ณ , ์ฐ๋ฆฌ๋ ํฌ๊ธฐํ์ง ์์ ๊ฒ์
๋๋ค.
From Credit to (Crypto) Cash
์ ์ฉ์์ (์ํธํ)ํ๊ธ์ผ๋ก
As a user youโd enroll with them and provide your credit card details.
์ฌ์ฉ์๋ ์์คํ
์ ๋ฑ๋กํ๊ณ , ์ ์ฉ์นด๋ ์ ๋ณด๋ฅผ ์ ๊ณตํฉ๋๋ค.
When you want to buy something from a seller, the seller contacts FirstVirtual with the details of the requested payment,
๋น์ ์ด ํ๋งค์๋ก๋ถํฐ ๋ฌด์ธ๊ฐ๋ฅผ ์ฌ๊ณ ์ถ์๋, ํ๋งค์๋ ๊ตฌ๋งค์๋ก๋ถํฐ ์์ฒญ๋ ๊ฒฐ์ ์ธ๋ถ์ฌํญ์ ๊ฐ์ง๊ณ FirstVirtual ์ ์ปจํํฉ๋๋ค.
FirstVirtual confirms these details with you, and if you approve your credit card gets billed.
FirstVirtual์ ์ด๋ฌํ ์ธ๋ถ์ ๋ณด๋ฅผ ๋น์ ์๊ฒ ํ์ธํ๊ณ , ๋น์ ์ด ์น์ธํ๋ฉด, ์ ์ฉ์นด๋์ ์๊ธ์ด ์ฒญ๊ตฌ๋ฉ๋๋ค .
But two details are interesting.
๊ทธ๋ฌ๋ ๋ ๊ฐ์ง ์ธ๋ถ์ฌํญ์ด ํฅ๋ฏธ๋กญ์ต๋๋ค.
First, all of this communication happened over email; web browsers back in the day were just beginning to universally support encryption protocols like HTTPS, and the multi-party
nature of payment protocol added other complexities. (Other intermediaries took the approach of encoding information into URLs or using a custom encryption protocol on top of HTTP.)
์ฒซ์งธ, ๋ชจ๋ ์ปค๋ฎค๋์ผ์ด์
์ ์ด๋ฉ์ผ์ ํตํด ์ผ์ด๋ฉ๋๋ค. ๊ทธ ๋น์์ ์น๋ธ๋ผ์ฐ์ ๋ HTTPS์ ๊ฐ์ ์ํธํ ํ๋กํ ์ฝ์ ์ด์ ๋ง ๋ณดํธ์ ์ผ๋ก ์ง์ํ๊ธฐ ์์ํ์ผ๋ฉฐ, ๊ฒฐ์ ํ๋กํ ์ฝ๋ค์ ๊ทธ ๋ค์์ฑ๋ค๋ก ์ธํด ๋งค์ฐ ๋ณต์กํ์ต๋๋ค.
Second, the customer would have ninety days to dispute the charge, and the merchant would receive the money only after three months! Today the merchant does get paid immediately, but, there still is the risk that the customer will file a chargeback or dispute the credit card statement.
๋์งธ, ๊ณ ๊ฐ์ ์ฒญ๊ตฌ์ ๋ํด 90์ผ๊ฐ ๋ถ์์ ์ผ์ผํฌ ์ ์์์ต๋๋ค. ๊ทธ๋ฆฌ๊ณ ํ๋งค์๋ ๊ณ ๊ฐ์ ๊ฒฐ์ ํ 3๊ฐ์ ํ์ ๋์ ๋ฐ๊ฒ ๋ฉ๋๋ค! ์ค๋๋ ํ๋งค์๋ค์ ์ฆ์ ์ง๋ถ์ ๋ฐ์ต๋๋ค๋ง ์ฌ์ ํ ๊ณ ๊ฐ์ด ์ง๋ถ์ ๊ฑฐ์ ํ๊ฑฐ๋ ์ ์ฉ์นด๋ ๋ช
์ธ์์ ์ด์๋ฅผ ์ ๊ธฐํ ์ํ์ด ์์ต๋๋ค.
If that happens, the merchant will have to return the payment to the credit card company.
๊ทธ๋ฐ ์ผ์ด ์ผ์ด๋๋ฉด, ํ๋งค์ ์ ์ ์ฉ์นด๋ ํ์ฌ๋ก ์ง๋ถ๋ฐ์๋ ๊ธ์ก์ ๋ฐํํด์ผ๋ง ํ ๊ฒ์
๋๋ค.
In the mid โ90s there was a competing approach to the intermediary architecture which weโll call the SET architecture.
90๋
๋ ์ค๋ฐ์๋ SET ์ํคํ
์ฒ๋ผ๊ณ ํ๋ ์ค๊ฐ ์ํคํ
์ฒ์ ๋ํ ์ ๊ทผ๋ฐฉ์์ด ์์์ต๋๋ค.
SET also avoids the need for customers to send credit card information to merchants, but it additionally avoids the user having to enroll with the intermediary.
SET์ ๊ณ ๊ฐ์ด ์ ์ฉ์นด๋์ ๋ณด๋ฅผ ๊ฐ๋งน์ ์ ๋ณด๋ผ ํ์๊ฐ ์๋๋ก ํ๊ณ , ์ถ๊ฐ์ ์ผ๋ก ๊ณ ๊ฐ์ด ๊ฑฐ๋์ค๊ฐ์ ์ฒด์ ๋ฑ๋กํ์ง ์๋๋ก ํฉ๋๋ค.
In SET, when you are ready to make a purchase, your browser passes your view of the transaction details to a shopping application on your computer which, together with your credit card details, encrypts it in such a way that only the intermediary can decrypt it, and no one else can (including the seller).
SET์์๋ ๋น์ ์ด ์ํ์ ๊ตฌ๋งคํ ์ค๋น๊ฐ ๋๋ฉด, ๋ธ๋ผ์ฐ์ ๊ฐ ๊ฑฐ๋ ๋ด์ญ์ ์ ์ฉ์นด๋ ์ธ๋ถ์ ๋ณด์ ํจ๊ป ์ปดํจํฐ์ ์ผํ ์ ํ๋ฆฌ์ผ์ด์
์ ์ ๋ฌํ๊ณ , ๊ฑฐ๋์ค๊ฐ์
์ฒด๋ง์ด ์ํธ๋ฅผ ํด๋
ํ ์ ์๋๋ก ์ํธํํฉ๋๋ค. ๊ฑฐ๋์ค๊ฐ์
์ฒด์ธ์๋ ํ๋งค์๋ฅผ ํฌํจํด์ ์๋ฌด๋ ๊ทธ ์ํธ๋ฅผ ํด๋
ํ ์ ์์ต๋๋ค.
Having encrypted your data it this way, you can send it to the seller knowing that itโs secure.
์ด ๋ฐฉ๋ฒ์ผ๋ก ๋น์ ์ ๋ฐ์ดํฐ๋ฅผ ์ํธํ๋ฉด, ๋น์ ์ ์์ ํ๋ค๊ณ ์ธ์ํ๋ฉด์ ํ๋งค์์๊ฒ ๊ทธ๊ฒ์ ๋ณด๋ผ ์ ์์ต๋๋ค.
The seller blindly forwards the encrypted data to the intermediary โ along with their own view of the transaction details.
ํ๋งค์๋ ์ํธํ๋ ๋ฐ์ดํฐ๋ฅผ ๊ฑฐ๋์ค๊ฐ์
์์๊ฒ ๊ฑฐ๋ ๋ด์ญ๊ณผ ํจ๊ป ์ ๋ฌํฉ๋๋ค.
The intermediary decrypts your data and approves the transaction only if your view matches the sellerโs view.
์ค๊ฐ์ธ์ ๋ฐ์ดํฐ๋ฅผ ํด๋
ํ๊ณ ๊ตฌ๋งค์์ ๊ฑฐ๋๋ด์ญ๊ณผ ํ๋งค์์ ๊ฑฐ๋๋ด์ญ์ด ์ผ์นํ๋ ๊ฒฝ์ฐ์๋ง ๊ฑฐ๋๋ฅผ ์น์ธํฉ๋๋ค.
SET was a standard developed by VISA and MasterCard, together with many technology heavyweights of the day: Netscape, IBM, Microsoft, Verisign, and RSA.
SET์ VISA์ MasterCard๊ฐ ๊ฐ๋ฐํ ํ์ค์ผ๋ก Netscape, IBM, Microsoft, Verisign ๋ฐ RSA์ ๊ฐ์ ๊ทธ ๋น์์ ๋ง์ ๊ธฐ์ ์ ๋ฌธ๊ฐ๋ค๊ณผ ํจ๊ป ์งํ๋์์ต๋๋ค.
It was an umbrella specification that unified several existing proposals.
๊ทธ๊ฒ์ ๊ธฐ์กด์ ๋ช๊ฐ์ง ์ ์๋ค์ ํฉ์น ํตํฉ์ ์ธ ์ฌ์์ด์์ต๋๋ค.
One company that implemented SET was called CyberCash.
SET๋ฅผ ๊ตฌํํ ํ์ฌ๋ ๋ฐ๋ก CyberCash์
๋๋ค.
It was an interesting company in many ways.
๊ทธ๊ฒ์ ์ฌ๋ฌ ๋ฉด์์ ํฅ๋ฏธ๋ก์ด ์ ์ ๊ฐ์ง ํ์ฌ์์ต๋๋ค.
In addition to credit card payment processing, they had a digital cash product called CyberCoin.
๊ทธ๋ค์ ์ ์ฉ์นด๋ ์ง๋ถ์ฒ๋ฆฌ ์ธ์๋ CyberCoin ์ด๋ผ๋ ๋์งํธ ํ๊ธ ์ํ์ด ์์์ต๋๋ค.
This was a micropayment system โ intended for small payments such as paying a few cents to read an online newspaper article.
์ด๊ฒ์ ๋ง์ดํฌ๋กํ์ด๋จผํธ ์์คํ
์ด์๋๋ฐ, ์จ๋ผ์ธ ์ ๋ฌธ๊ธฐ์ฌ๊ตฌ๋
์ ์ํด ๋ช ์ผํธ๋ฅผ ์ง๋ถํ๋ ์์ ์์ก ์ง๋ถ์ ์ํ ๋ชฉ์ ์ด์์ต๋๋ค.
That meant that youโd probably never have more than $10 in your CyberCoin account at any time.
์ด๊ฒ์ CyberCoin ๊ณ์ ์๋ ์ด๋ค ๋๋ผ๋ 10๋ฌ๋ฌ ์ด์์ ๊ฐ์ง ์ ์๋ค๋ ๊ฒ์ ์๋ฏธํ์์ต๋๋ค.
Yet, amusingly, they were able to get U.S. government (FDIC) insurance for each account for up to $100,000.
๊ทธ๋ฌ๋, ์ฌ๋ฐ๋ ์ ์ด ์์๋๋ฐ, ๊ทธ๋ค์ ๊ฐ ๊ณ์ข์ ๋ํด 10๋ง ๋ฌ๋ฌ๊น์ง ๋ฏธ๊ตญ ์ ๋ถ ๋ณดํ์ ๊ฐ์
ํ ์ ์์์ต๋๋ค.
Thereโs more. Back when CyberCash operated, there was a misguided โ and now abandoned โ U.S. government restriction on the export of cryptography, which was considered a weapon.
์ด๊ฒ๋ณด๋ค ๋ํ ๊ฒ์ด ์์์ต๋๋ค. ๋น์ CyberCash๊ฐ ์ด์๋ ๋๋, ์ํธํ์ด ๋ฌด๊ธฐ๋ก ๊ฐ์ฃผ๋์๊ธฐ ๋๋ฌธ์, ์ํธํ์ ์์ถ์ ๋ํ ๋ฏธ๊ตญ ์ ๋ถ์ ๊ท์ ๊ฐ ์์์ต๋๋ค. - ์ง๊ธ์ ํ์ง๋์์ต๋๋ค๋ง
That meant software that incorporated meaningful encryption couldnโt be offered for download to users in other countries.
์ฆ ๊ทธ๊ฒ์ ์ค์ํ ์ํธํ๊ฐ ํฌํจ๋ ์ํํธ์จ์ด๋ ๋ค๋ฅธ ๊ตญ๊ฐ์ ์ฌ์ฉ์์๊ฒ ๋ค์ด๋ก๋ ๋ ์ ์์์ต๋๋ค.
However, CyberCash was able to get a special exemption for their software from the
Department of State.
๊ทธ๋ฌ๋, CyberCash๋ ๊ตญ๋ฌด๋ถ์์ ๊ทธ๋ค์ ์ํํธ์จ์ด์ ๋ํ ํน๋ณ ๋ฉด์ ๋ฅผ ๋ฐ์ ์ ์์์ต๋๋ค.
The governmentโs argument was that extracting the encryption technology out
of CyberCashโs software would be harder than writing the crypto from scratch.
์ ๋ถ์ ์ฃผ์ฅ์ CyberCash์ ์ํํธ์จ์ด๋ก๋ถํฐ ์ํธํ ๊ธฐ์ ์ ์ถ์ถํ๋ ๊ฒ์ ์ํธ๋ฅผ ์ฒ์๋ถํฐ ์์ฑํ๋ ๊ฒ๋ณด๋ค ๋ ์ด๋ ต๋ค๋ ๊ฒ์ด์์ต๋๋ค.
Finally, CyberCash has the dubious distinction of being one of the few companies affected by the Y2K bug โ it caused their payment processing software to double-bill some customers.
๋ง์ง๋ง์ผ๋ก CyberCash๋ Y2K์ ๋ฒ๊ทธ์ ์ํฅ์ ๋ฐ์ ํ์ฌ๋ค์ค ํ๋๋ก ๊ตฌ๋ถ๋ฉ๋๋ค. - ๋ฒ๊ทธ๋ก ์ธํด ์ง๋ถ ์ฒ๋ฆฌ ์ํํธ์จ์ด๊ฐ ์ผ๋ถ๊ณ ๊ฐ์๊ฒ ์ด์ค์ฒญ๊ตฌํ๋ ์ผ์ด ๋ฐ์ํ์์ต๋๋ค.
They later went bankrupt in 2001.
์ดํ ๊ทธ๋ค์ 2001๋
์ ๋ถ๋๊ฐ ๋ฌ์ต๋๋ค.
Their intellectual property was acquired by Verisign who then turned around and sold it to PayPal where it lives today.
๊ทธ๋ค์ ์ง์ ์ฌ์ฐ์ Verisign์ ์ํด ์ธ์๋์๊ณ , ๋ค์ ๊ทธ๊ฒ์ PayPal์ ํ๋ ค ์ ธ์ ์ค๋๊น์ง ์ด์์์ต๋๋ค.
Why didnโt SET work? The fundamental problem has to do with certificates.
SET๊ฐ ์ ์๋ํ์ง ๋ชปํ์์๊น์? ๊ทธ ๊ทผ๋ณธ์ ์ธ ๋ฌธ์ ๋ ์ธ์ฆ์์ ๊ด๋ จ์ด ์์ต๋๋ค.
A certificate is a way to securely associate a cryptographic identity, that is, a public key, with a real-life identity.
์ธ์ฆ์๋ ์ํธํ ์ ์(์ฆ, ๊ณต๊ฐํค)์ ์ค์ ์ ์๊ณผ ์์ ํ๊ฒ ์ฐ๊ฒฐํ๋ ๋ฐฉ๋ฒ์
๋๋ค.
Itโs what a website needs to obtain, from companies like Verisign that are called certification authorities, in order to show up as secure in your browser (typically indicated by a lock icon).
์น์ฌ์ดํธ์ ์ธ์ฆ์๋ ์ํธํ ์ธ์ฆ๊ธฐ๊ด์ธ Verisign๊ณผ ๊ฐ์ ํ์ฌ๋ค๋ก๋ถํฐ ํ๋๋์ด์ผ ํ ํ์๊ฐ ์์ต๋๋ค. ์ด๊ฒ์ ์ผ๋ฐ์ ์ผ๋ก ์๋ฌผ์ ์์ด์ฝ์ผ๋ก ํ์๋๊ณ , ๋ธ๋ผ์ฐ์ ์ ๋ณด์์ ๋ณด์ฌ์ฃผ๋๋ฐ ์ฐ์
๋๋ค.
Putting security before usability, CyberCash and SET decided that not only would processors and merchants in their system have to get certificates, all users would have to get one as well.
CyberCash์ SET๋ ์ฌ์ฉ์ฑ๋ณด๋ค ๋ณด์์ ์ค์ํด์ ์์คํ
์ ํ๋ก์ธ์๋ค๊ณผ ํ๋งค์๋ค์ด ์ธ์ฆ์๋ฅผ ๋ฐ์์ผ ํ ๋ฟ๋ง ์๋๋ผ, ๋ชจ๋ ์ฌ์ฉ์๋ค๋ ์ธ์ฆ์๋ฅผ ๋ฐ์์ผ ํ๋ค๊ณ ๊ฒฐ์ ํ์ต๋๋ค.
Getting a certificate is about as pleasant as doing your taxes, so the system was a disaster.
์ธ์ฆ์๋ฅผ ๋ฐ๋ ๊ฒ์ ์ธ๊ธ์ ๋ด๋ ๋งํผ์ด๋ ์ฆ๊ฑฐ์ด ์ผ์ด๋ฏ๋ก, ์์คํ
์ ์ผ๋ก๋ ์ฌ์์ด์์ต๋๋ค.
Over the decades, mainstream users have said a firm and collective โnoโ to any system that requires end-user certificates, and such proposals have now been relegated to academic papers.
์ง๋ ์์ญ ๋
๋์, ์ฃผ๋ฅ ์ฌ์ฉ์๋ค์ ์ต์ข
์ฌ์ฉ์ ์ธ์ฆ์๊ฐ ํ์ํ ์ด๋ค ์์คํ
์๋ ๊ฒฌ๊ณ ํ๊ฒ ์ง๋จ์ ์ผ๋ก โ์๋์คโ๋ผ๊ณ ๋งํ์ผ๋ฉฐ, ์ด์ ์ด๋ฌํ ์ ์์ ํ์ ๋
ผ๋ฌธ์ผ๋ก ๋์ด๊ฐ์ต๋๋ค.
Bitcoin deftly sidesteps this hairy problem by avoiding real-life identities altogether.
Bitcoin์ ์ค์ ์ธ์์ ์ ์์ ์ฌ์ฉํ์ง ์์์ผ๋ก์จ ์ด ๊น๋ค๋ก์ด ๋ฌธ์ ๋ฅผ ๋ฅ์ํ๊ฒ ํผํด๊ฐ๋๋ค.
In Bitcoin, public keys themselves are the identities by which users are known, as weโll see in Chapter 1.
1์ฅ์์ ๋ณด๊ฒ ๋ ๊ฒ์ฒ๋ผ Bitcoin์์๋ ๊ณต๊ฐํค ์์ฒด๊ฐ ๋ฐ๋ก ์ฌ์ฉ์์ ์ ์์ด ๋ฉ๋๋ค.
In the mid 90s, when SET was being standardized, the World Wide Web Consortium was also looking at standardizing financial payments.
90๋
๋ ์ค๋ฐ์, SET๊ฐ ํ์คํ๋๊ณ ์์๋, ์๋ ์์ด๋ ์น ์ปจ์์์๋ ๊ธ์ต ์ง๋ถ ํ์คํ๋ฅผ ๊ฒํ ํ๊ณ ์์์ต๋๋ค.
They wanted to do it by extending the HTTP protocol instead so that users wouldnโt need extra software for transactionsโthey could just use their browser.
๊ทธ๋ค์ HTTP ํ๋กํ ์ฝ์ ํ์ฅํ์ฌ ์ฌ์ฉ์๊ฐ ํธ๋์ญ์
์ ์ํ ์ถ๊ฐ ์ํํธ์จ์ด๊ฐ ํ์ ์๋๋ก ํ๊ณ ์ถ์์ต๋๋ค. - ์ฆ, ๊ทธ๋ค์ ๋ธ๋ผ์ฐ์ ๋ฅผ ์ฌ์ฉํ ์ ์์์ต๋๋ค.
Now letโs turn to cash.
์ด์ ํ๊ธ์ ๋ํด ๋ค๋ค๋ด
์๋ค
We compared cash and credit earlier, and noted that a cash system needs to be โbootstrapped,โ but the benefit is that it avoids the possibility of a buyer defaulting on her debt.
์ฐ๋ฆฌ๋ ์์ ํ๊ธ๊ณผ ์ ์ฉ์ ๋น๊ตํ์ผ๋ฉฐ, ํ๊ธ ์์คํ
์ โ๋ถํธ ์คํธ๋ฉโํ ํ์๊ฐ ์์ง๋ง, ๊ตฌ๋งค์๊ฐ ๋ถ์ฑ๋ฅผ ๋ถ์ดํํ ๊ฐ๋ฅ์ฑ์ ํผํ ์ ์๋ ์์ ์ด ์์ต๋๋ค.
Cash offers two additional advantages.
ํ๊ธ์ ๋ ๊ฐ์ง ์ถ๊ฐ ์์ ์ ์ ๊ณตํฉ๋๋ค.
The first is better anonymity. Since your credit card is issued in your name, the bank can track all your spending.
์ฒซ ๋ฒ์งธ๋ ๋ ๋์ ์ต๋ช
์ฑ์
๋๋ค. ๋น์ ์ ์ด๋ฆ์ผ๋ก ๋ฐ๊ธ๋ ์ ์ฉ์นด๋๋ฅผ ํตํด ์ํ์ ๋น์ ์ ๋ชจ๋ ์ง์ถ์ ์ถ์ ํ ์ ์์ต๋๋ค.
But when you pay in cash, the bank doesnโt come into the picture, and the other party doesnโt need to know who you are.
๊ทธ๋ฌ๋ ํ๊ธ์ผ๋ก ์ง๋ถํ๋ฉด, ์ํ์ ์ถ์ ๋์ง ์๊ณ , ์๋๋ฐฉ์ด ๋น์ ์ด ๋๊ตฌ์ธ์ง ์ ํ์๋ ์์ต๋๋ค.
Second, cash can enable offline transactions where thereโs no need to phone home to a third party in order to get the transaction approved.
๋์งธ, ํ๊ธ์ ๊ฑฐ๋๋ฅผ ์น์ธ๋ฐ๊ธฐ์ํด ์ 3์์๊ฒ ์ ํํ ํ์๊ฐ ์์ด ์คํ๋ผ์ธ์ผ๋ก ๊ฑฐ๋ํ ์ ์๊ฒ ํฉ๋๋ค.
Maybe later, they go to a third party like a bank to deposit the cash, but thatโs much less of a hassle.
์๋ง๋ ๊ฑฐ๋ํ ๋์ค์, ํ๊ธ์ ์๊ธํ๊ธฐ ์ํด ์ํ๊ณผ ๊ฐ์ ์ 3์์๊ฒ ๊ฐ์ผ ๋๊ฒ ์ง๋ง, ๊ทธ๊ฒ์ด ๊ทธ๋ ๊ฒ ๋ฒ๊ฑฐ๋ก์ด ์ผ์ ์๋๋๋ค.
Bitcoin doesnโt quite offer these two properties, but comes close enough to be useful.
Bitcoin์ ์ด ๋๊ฐ์ง ์์ฑ์ ์ ๊ณตํ์ง๋ ์์ง๋ง, ์ถฉ๋ถํ ์ ์ฉํ ์ ๋๋ก ์ด ์์ฑ๋ค์ ๊ฐ๊น์ด ์์ต๋๋ค.
Bitcoin is not anonymous to the same level as cash is.
๋นํธ์ฝ์ธ์ ํ๊ธ๊ณผ ๋์ผํ ์์ค์ ์ต๋ช
์ฑ์ ์ ๊ณตํ์ง๋ ์์ต๋๋ค.
You donโt need to use your real identity to pay in Bitcoin, but itโs possible that your transactions can be tied together based on the public ledger of transactions with clever algorithms, and then further linked to your identity if youโre not careful.
Bitcoin์ผ๋ก ์ง๋ถํ๊ธฐ ์ํด ์ค์ ์ ์์ ์ฌ์ฉํ ํ์๊ฐ ์์ต๋๋ค. ๊ทธ๋ฌ๋ ๋น์ ์ ๊ฑฐ๋๋ ์๋ฆฌํ ์๊ณ ๋ฆฌ์ฆ์ ๊ฐ์ง ๊ฑฐ๋ ๊ณต๊ฐ์์ฅ์ ํจ๊ป ๋ฌถ์ฌ์ง๋๋ค. ๊ทธ๋ฌ๋ ์ดํ์ ์ ์คํ์ง ์์ผ๋ฉด ๋น์ ์ ์ ์์ด ๋
ธ์ถ ๋ ์๋ ์์ต๋๋ค.
Weโll get into the messy but fascinating details behind Bitcoin anonymity in Chapter 6.
์ฐ๋ฆฌ๋ 6์ฅ์์ Bitcoin ์ต๋ช
์ฑ ๋ค์ ์๋ ์ด๋ ค์ฐ๋ฉด์๋ ์์ฃผ ์ฌ๋ฏธ์๋ ์ธ๋ถ์ฌํญ์ ๋ค๋ฃจ๊ฒ ๋ ๊ฒ์
๋๋ค.
Bitcoin doesnโt work in a fully offline way either.
๋นํธ์ฝ์ธ์ ์คํ๋ผ์ธ ๋ฐฉ์์ผ๋ก๋ง ์๋ํ๋๊ฑด ์๋๋๋ค.
The good news is it doesnโt require a central server, instead relying on a peer-to-peer network which is resilient in the way that the Internet itself is.
์ข์ ์์์ ๋นํธ์ฝ์ธ์ ์ค์ ์๋ฒ๊ฐ ํ์ ์์ผ๋ฉฐ, ๋์ ์ธํฐ๋ท ์์ฒด์ด๋ฉด์ ๊ฐํ ๋ณต์๋ ฅ์ ๊ฐ์ง ํผ์ด ํฌ ํผ์ด ๋คํธ์ํฌ์ ์์กดํ๋ค๋ ๊ฒ์
๋๋ค.
In Chapter 3 weโll look at tricks like โgreen addressesโ and micropayments which allow us to do offline payments in certain situations or under certain assumptions.
3์ฅ์์๋ ํน์ ์ํฉ์ด๋ ํน์ ๊ฐ์ ์์ ์คํ๋ผ์ธ ์ง๋ถ์ ํ์ฉํ๋ โ๋
น์ ์ฃผ์๋คโ(์ญ์ ์ฃผ: ๋ฏฟ์ ์ ์๋ ์ฃผ์๋ค) ๋ฐ ์์ก์ง๋ถ๊ณผ ๊ฐ์ ํธ๋ฆญ๋ค์ ์ดํด๋ณผ ๊ฒ์
๋๋ค.
The earliest ideas of applying cryptography to cash came from David Chaum in 1983.
ํ๊ธ์ ์ํธํ๋ฅผ ์ ์ฉํ ๊ฐ์ฅ ์ด๊ธฐ์ ์์ด๋์ด๋ 1983๋
David Chaum์ด ๋ฐํํ ๊ฒ์
๋๋ค.
Letโs understand this through a physical analogy.
์ ์ฒด์ ๋น์ ํ์ฌ ์ด๊ฒ์ ์ดํด๋ณด๊ฒ ์ต๋๋ค.
Letโs say I start giving out pieces of paper that say: โThe bearer of this note may redeem it for one dollar by presenting it to meโ with my signature attached.
โ์ด ๋ฉ๋ชจ๋ฅผ ์์งํ ์ฌ๋์ด ๋ด ์๋ช
์ ์ฒจ๋ถํ์ฌ ๋์๊ฒ ์ ์ํ๋ฉด 1 ๋ฌ๋ฌ๋ฅผ ํ๋ถ๋ฐ์ ์ ์์ต๋๋ค.โ๋ผ๊ณ ๋งํ๋ ์ข
์ด๋ฅผ ๋๋ ์ฃผ๊ธฐ ์์ํ๋ค๊ณ ํฉ์๋ค.
If people trust that Iโll keep my promise and consider my signature unforgeable, they can pass around these pieces of paper just like banknotes.
์ฌ๋๋ค์ด ๋ด๊ฐ ์ฝ์์ ์งํค๊ณ , ๋์ ์๋ช
์ ์์กฐํ ์ ์๋ค๊ณ ์๊ฐํ๋ค๋ฉด, ๊ทธ๋ค์ ์งํ์ฒ๋ผ ์ด ์ข
์ด์กฐ๊ฐ์ ์ฌ์ฉํ ์ ์๊ฒ ๋ฉ๋๋ค.
In fact, banknotes themselves got their start as promissory notes issued by commercial banks.
์ฌ์ค, ์งํ์์ฒด๋ ์์
์ํ์ด ๋ฐํํ ์ฝ์ ์ด์์ผ๋ก ์์ํ์ต๋๋ค.
Itโs only in fairly recent history that governments stepped in to centralize the money supply and legally require banks to redeem notes.
์ ๋ถ๊ฐ ํตํ ๊ณต๊ธ์ ์ค์ ์ง์คํํ๊ณ , ์ํ์ด ์งํ๋ฅผ ์ฌ์ฉํ๋๋ก ํฉ๋ฒ์ ์ผ๋ก ์๊ตฌํ ๊ฒ์ ์ต๊ทผ์ ์ญ์ฌ์ ๋ถ๊ณผํฉ๋๋ค.
I can do the same thing electronically with digital signatures, but that runs into the annoying โdouble spendingโ problem โ if you receive a piece of data representing a unit of virtual cash, you can make two (or more) copies of it and pass it on to different people.
๋์งํธ ์๋ช
์ ํตํด ์ ์์ ์ผ๋ก ๋์ผํ ์์
์ ์ํํ ์ ์์ง๋ง, ์ด์ค ์ง์ถ ๋ฌธ์ ๋ผ๋ ์ฑ๊ฐ์ ๋ฌธ์ ๊ฐ ๋ฐ์ํฉ๋๋ค. ๊ฐ์ ํ๊ธ ๋จ์๋ฅผ ๋ํ๋ด๋ ๋ฐ์ดํฐ ์กฐ๊ฐ์ ๋๊ฐ(๋๋ ๊ทธ ์ด์)์ ๋ณต์ฌ๋ณธ์ ๋ง๋ค์ด ๋ค๋ฅธ ์ฌ๋๋ค์๊ฒ ๋๊ฒจ ์ค ์ ์์ต๋๋ค.
To stick with our analogy, letโs stretch it a little bit and assume that people can make perfect copies and we have no way to tell copies from the original.
์ฌ๋๋ค์ด ์๋ฒฝํ ๋ณต์ ํ์ ๋ง๋ค ์ ์๊ณ , ์๋ณธ๊ณผ ๋ณต์ฌ๋ณธ์ด ์ด๋ค ๊ฒ์ธ์ง ๊ตฌ๋ณํ ๋ฐฉ๋ฒ์ด ์๋ค๊ณ ํด๋ณด๊ฒ ์ต๋๋ค.
Can we solve double spending in this world?
์ด๋ฌํ ์ด์ค ์ง์ถ ๋ฌธ์ ๋ฅผ ํด๊ฒฐํ ์๊ฐ ์๋๊ฑด๊ฐ์?
Hereโs a possible solution: I put unique serial numbers into each note I give out.
๊ฐ๋ฅํ ํด๊ฒฐ์ฑ
์ ๋ค์๊ณผ ๊ฐ์ต๋๋ค : ๋๋ ์ฃผ๋ ๊ฐ ์ข
์ด์ ๊ณ ์ ์ผ๋ จ๋ฒํธ๋ฅผ ๋ฃ์ต๋๋ค.
When you receive such a note from someone, you check my signature, but you also call me on the phone to ask if a note with that serial number has already been spent.
๋น์ ์ด ๋๊ตฐ๊ฐ๋ก๋ถํฐ ๊ทธ๋ฌํ ์ข
์ด๋ฅผ ๋ฐ์ผ๋ฉด, ๋ด ์๋ช
์ ํ์ธํ์ง๋ง, ๋์๊ฒ ์ ํ๋ ๊ฑธ์ด์, ์ผ๋ จ ๋ฒํธ๊ฐ ์๋ ์ข
์ด๋ฅผ ์ด๋ฏธ ์ฌ์ฉํ๋์ง ๋ฌผ์ด๋ ๋ณผ๊ฒ๋๋ค.
Hopefully Iโll say no, in which case you accept the note.
๋ด๊ฐ ์๋์ค๋ผ๊ณ ๋งํ๋ฉด, ๊ทธ๋ ๋น์ ์ ๊ทธ ์ข
์ด์ ๊ฐ์น๋ฅผ ๋ฐ์๋ค์ผ๊ฒ๋๋ค.
Iโll record the serial number as spent in my ledger, and if you try to spend that note, it wonโt
work because the recipient will call me and Iโll tell them the note has already been spent.
์ข
์ด๊ฐ ์ฌ์ฉ๋๊ฒ ๋๋ฉด ์ฅ๋ถ์ ์ข
์ด์ ์ผ๋ จ๋ฒํธ๋ฅผ ๊ธฐ๋กํ๊ฒ ๋๊ณ , ์ดํ ๋น์ ์ด ๊ทธ ์ข
์ด๋ฅผ ์ฐ๋ ค๊ณ ํ๋ฉด, ๋ฐ๋ ์ฌ๋์ด ๋์๊ฒ ์ ํ๋ฅผ ๊ฑธ๊ฒ ๋๊ณ , ๋ด๊ฐ ๊ทธ ์ข
์ด๋ ์ด๋ฏธ ์ฌ์ฉ๋์๋ค๊ณ ๋งํ๊ฒ ๋๋ฉด ๊ทธ ์ข
์ด๋ ์์ฉ์ด ์๊ฒ ๋ฉ๋๋ค.
What youโll need to do instead is to periodically bring me all the notes youโve received, and Iโll issue you the same number of new notes with fresh serial numbers.
๋น์ ์ด ํด์ผํ ์ผ์ ์ฃผ๊ธฐ์ ์ผ๋ก ๋์๊ฒ ๋น์ ์ด ๋ฐ์ ์ข
์ด๋ฅผ ๋ณด๋ด์ฃผ๋ ๊ฒ์
๋๋ค. ๊ทธ๋ฌ๋ฉด ๋๋ ์๋ก์ด ์ผ๋ จ๋ฒํธ๊ฐ ์๋ ์ ์ข
์ด๋ค์ ๋ฐํํด ์ฃผ๊ฒ ๋ฉ๋๋ค.
This works. Itโs cumbersome in real life, but straightforward digitally provided Iโve set up a server to do the signing and record-keeping of serial numbers.
์ด๋ฌํ ์์คํ
์ ์ ์๋๋ฉ๋๋ค. ์ค์ ํ์ค์์๋ ์ด๋ฌํ ์์คํ
์ ๋ณต์กํ๊ณ ๋๋ฆดํ
์ง๋ง, ์ด๊ฒ์ ๋์งํธ์ ์ผ๋ก๋ ์ฝ๊ฒ ๊ตฌํ๋ฉ๋๋ค. ๋๋ ์ผ๋ จ๋ฒํธ์ ์๋ช
๊ณผ ๊ธฐ๋ก ๋ณด๊ด์ ์ํด ์๋ฒ๋ฅผ ์ค์นํ๊ฒ ๋ฉ๋๋ค.
The only problem is that this isnโt really cash any more, because itโs not anonymous โ when I issue a note to you I can record the serial number along with your identity, and I can do the same when someone else later redeems it.
์ ์ผํ ๋ฌธ์ ๋ ๊ทธ๊ฒ์ด ์ต๋ช
์ด ์๋๊ธฐ ๋๋ฌธ์ ์ด๊ฒ์ ๋ ์ด์ ์ง์ ํ ํ๊ธ์ด ์๋๋ผ๋ ๊ฒ ์
๋๋ค. ๋น์ ์๊ฒ ์ชฝ์ง๋ฅผ ๋ฐํ ํ ๋ ๋น์ ์ ์ ์๊ณผ ํจ๊ป ์ผ๋ จ ๋ฒํธ๋ฅผ ๊ธฐ๋ก ํ ์ ์์ผ๋ฉฐ ๋์ค์ ๋ค๋ฅธ ์ฌ๋์ด ๊ทธ๊ฒ์ ์ฌ์ฉํ ๋๋ ๋์ผํ ์กฐ์น๋ฅผ ์ทจํ ์ ์์ต๋๋ค.
That means I can keep track of all the places where youโre spending your money.
๊ทธ๊ฒ์ ๋ด๊ฐ ๋น์ ์ด ๋์ ์ฐ๋ ๋ชจ๋ ๊ณณ์ ์ถ์ ํ๋ ๊ฒ์ด ๊ฐ๋ฅํ๋ค๋ ๊ฒ์ ์๋ฏธํฉ๋๋ค.
This is where Chaumโs innovation comes in. He figured out to both keep the system anonymous and prevent double-spending by inventing the digital equivalent of the following procedure: when I issue a new note to you, you pick the serial number.
์ด๊ฒ์ Chaum์ ํ์ ์ด ์์๋ ๊ณณ์
๋๋ค. ๊ทธ๋ ๋ค์ ์ ์ฐจ์ ๋์งํธ ์๋ช
์ ๋ฐ๋ช
ํ์ฌ ์์คํ
์ ์ต๋ช
์ผ๋ก ์ ์งํ๊ณ ์ด์ค ์ ์ก์ ๋ฐฉ์งํ๋ ๋ฐฉ๋ฒ์ ์์ ๋์ต๋๋ค: ๋ด๊ฐ ๋น์ ์๊ฒ ์๋ก์ด ๊ธฐ๋ก์ ๋ฐํํ ๋, ๋น์ ์ ์ผ๋ จ ๋ฒํธ๋ฅผ ๋ฐ๊ฒ ๋๋ค๋ ๊ฒ ์
๋๋ค.
You write it down on the piece of paper, but cover it so that I canโt see it. Then Iโll sign it, still unable to see the serial number. This is called a โblind signatureโ in cryptography.
๋น์ ์ด ๊ทธ๊ฒ์ ์ข
์ด์ ์ ์ด ๋๊ฒ ์ง๋ง, ๋น์ ์ ๊ทธ๊ฒ์ ์ ๊ฐ ๋ณผ ์ ์๋๋ก ๊ฐ๋ ค๋์ ๊ฒ ์
๋๋ค. ๊ทธ๋ผ ๋๋ ์๋ช
ํ๊ฒ ์ง๋ง, ๋๋ ์ฌ์ ํ ์ผ๋ จ ๋ฒํธ๋ฅผ ๋ณผ ์ ์์ ๊ฒ ์
๋๋ค. ์ํธํ์์๋ ์ด๋ฅผ "์๋ ์๋ช
(blind signature)" ์ด๋ผ๊ณ ๋ถ๋ฆ
๋๋ค.
Itโll be in your interest to pick a long, random serial number to ensure that it will most likely be unique.
๊ทธ๊ฒ์ ๊ฐ์ฅ ๋
ํนํ ๋ฐฉ์์ผ๋ก ๋ณด์ฆ๋ ๊ธธ๊ณ ๋ถํน์ ํ ์ผ๋ จ ๋ฒํธ๋ก ๋น์ ์ ๊ด์ฌ ์์ ์๊ฒ ๋ ๊ฒ ์
๋๋ค.
I donโt have to worry that youโll pick a serial number thatโs already been pickedโ you can only shoot yourself in the foot by doing so and end up with a note that canโt be spent.
๋๋ ๋น์ ์ด ์ด๋ฏธ ์ ํ๋์ด์๋ ์ผ๋ จ ๋ฒํธ๋ฅผ ์ ํํ ๊ฒ์ด๋ผ๋ ๊ฑฑ์ ์ ํ์ง ์์๋ ๋ฉ๋๋ค. - ๋น์ ์ด ์ ์ก๋์ด ์ง ์ ์๋ ๊ฒ์ ๊ธฐ๋กํ๊ณ ๊ทธ๋ ๊ฒ ํจ์ผ๋ก์จ ์๊ธฐ ๋ฌด๋ค์ ์ค์ค๋ก ํ ์ ๋ ์๋ค๋ ๊ฒ์ ๋ํด์ ๊ฑฑ์ ํ ํ์๊ฐ ์๋ค๋ ๊ฒ์
๋๋ค.
This was the first serious digital cash proposal.
์ด๊ฒ์ ์ต์ด์ ์ง์งํ ๋์งํธ ์บ์ฌ ์ ์์ด์์ต๋๋ค.
It works, but it still requires a server run by a central authority, such as a bank, and for everyone to trust that entity.
๊ทธ๊ฒ์ ์๋ํ์ต๋๋ค, ๊ทธ๋ฌ๋ ๊ทธ๊ฒ์ ์ํ๊ณผ ๊ฐ์ ์ค์ ๊ธฐ๊ด์ ์ํด ์คํ๋๋ ์๋ฒ๊ฐ ํ์ํ๋ฉฐ, ๊ทธ๋ฆฌ๊ณ ๋ชจ๋ ์ฌ๋์ด ํด๋น ๊ธฐ๊ด์ ์ ๋ขฐํด์ผ ํ์ต๋๋ค.
Moreover, every transaction needs the participation of this server to go through.
๋์ฐ๊ธฐ, ๋ชจ๋ ํธ๋์ญ์
์ ์ด ์๋ฒ๋ฅผ ํตํด์๋ง ์ผ์ด๋ ์ ์์ต๋๋ค.
If the server goes down temporarily, payments grind to a halt.
๊ทธ ์๋ฒ๊ฐ ์ผ์์ ์ผ๋ก ๋ค์ด๋๋ฉด, ์ง๊ธ์ด ์ค๋จ๋ฉ๋๋ค.
A few years later, in 1988, Chaum in collaboration with two other cryptographers Fiat and Naor proposed offline electronic cash.
๋ช ๋
ํ, 1988๋
์ Chaum ์ ๋ค๋ฅธ ๋๋ช
์ ์ํธํ์์ธ Fiat ์ Naor ์ ํ๋ ฅํ์ฌ ์คํ๋ผ์ธ ์ ์์บ์ฌ๋ฅผ ์ ์ํ์ต๋๋ค.
At first sight this might seem to be impossible:
์ฒ์๋ดค์๋ ์ด๊ฒ์ ๋ถ๊ฐ๋ฅํด๋ณด์์์ง๋ ๋ชจ๋ฆ
๋๋ค.
if you try to spend the same digital note or coin at two different shops, how can they possibly stop this unless theyโre both connected to the same payment network or central entity?
์๋ก ๋ค๋ฅธ ๋ ๋งค์ฅ์์ ๋์ผํ ๋์งํธ ์ํ ๋๋ ๋์ ์ ์ฌ์ฉํ๋ ค๊ณ ํ๋ค๋ฉด, ๊ทธ๊ฒ๋ค์ด ๋๋ค ๊ฐ์ ๊ฒฐ์ ๋คํธ์ํฌ ๋๋ ์ค์ ๊ธฐ๊ด๊ณผ ์ฐ๊ฒฐ๋์ง ์๋๋ค๋ฉด ์ด๋ป๊ฒ ์ด๊ฒ์ ๋ฉ์ถ๊ฒ ํ ์ ์์๊น์?
The clever idea is to stop worrying about preventing double-spending and focus on detecting it, after the fact, when the merchant re-connects to the bank server.
์๋ฆฌํ ์์ด๋์ด๋ ์ด์ค ์ง์ถ ๋ฐฉ์ง์ ๋ํ ๊ฑฑ์ ์ ์ค์งํ๊ณ , ์ฌ์ค์ ๋ฐ๊ฒฌํ ํ ์์ ์ด ์ํ์๋ฒ์ ๋ค์ ์ฐ๊ฒฐ๋ ๋, ๊ทธ๊ฒ์ ๊ฐ์งํ๋๋ฐ ์ง์คํ๋ ๊ฒ์
๋๋ค. ,
After all, this is why youโre able to use your credit card on an airplane even if there is no network connection up in the skies.
๊ฒฐ๊ตญ, ์ด๊ฒ์ด ํ๋์์ ๋คํธ์ํฌ๊ฐ ์ฐ๊ฒฐ๋์ด ์์ง ์์๋, ๋นํ๊ธฐ์์ ์ ์ฉ์นด๋๋ฅผ ์ฌ์ฉํ ์ ์๋ ์ด์ ์
๋๋ค.
The transaction processing happens later when the airline is able to re-connect to the network.
๊ฑฐ๋ ์ฒ๋ฆฌ๋ ํญ๊ณต์ฌ๊ฐ ๋คํธ์ํฌ์ ๋ค์ ์ฐ๊ฒฐํ ์ ์์ ๋ ๋์ค์ ๋ฐ์ํ๊ฒ ๋ฉ๋๋ค.
If your card is denied, youโll owe the airline (or your bank) money.
๋น์ ์ ์นด๋๊ฐ ๊ฑฐ์ ๋๋ค๋ฉด, ๋น์ ์ ํญ๊ณต์ฌ ๋๋ ๋น์ ์ ์ํ์ ๋์ ๋น์ง๊ฒ ๋ ๊ฒ์
๋๋ค.
If you think about it, quite a bit of traditional finance is based on the idea of detecting an error or loss, followed by attempting to recover the money or punish the perpetrator.
๋น์ ์ด ์ด๋ฐ ๊ฒ์ ๋ํด ์๊ฐํด๋ณธ๋ค๋ฉด, ์ ํต์ ์ธ ๊ธ์ต์ ์๋น๋ถ๋ถ์ด ๊ฑฐ๋์ ์ค๋ฅ ๋๋ ์์ค์ ๊ฐ์งํ์ฌ์ ๋์ ํ์ํ๊ฑฐ๋, ๋ฒ์ธ์ ์ฒ๋ฒํ๋ ค๊ณ ์๋ํ๋ ์์ด๋์ด์ ๊ธฐ๋ฐํ๋ค๋ ๊ฒ์ ์ ์ ์์ต๋๋ค.
If you write someone a personal check, they have no guarantee that the money is actually in your account, but they can come after you if the check bounces.
๋ค๋ฅธ ์ฌ๋์๊ฒ ๊ฐ์ธ ์ํ๋ฅผ ์ฐ๋ฉด, ๋์ด ์ค์ ๋ก ๋น์ ์ ๊ณ์ข์ ์๋ค๋ ๋ณด์ฅ์ ์์ง๋ง, ๊ทธ ์ฒดํฌ์นด๋๊ฐ ์ฐ์ด๋ฉด, ๊ทธ ๋น์ด ๋น์ ์ ๋ฐ๋ผ์ค๊ฒ ๋ฉ๋๋ค.
Conceivably, if an offline electronic cash system were widely adopted, the legal system would come to recognize double spending as a crime.
์๊ฐํ ์ ์๋ ๋ฐ๋ก๋, ์คํ๋ผ์ธ ์ ์ ์บ์ฌ ์์คํ
์ด ๋๋ฆฌ ์ฑํ๋๋ค๋ฉด, ๋ฒ๋ฅ ์์คํ
์ ์ด์ค ์ง์ถ์ ๋ฒ์ฃ๋ก ์ธ์ ํ๊ฒ ๋ ๊ฒ์
๋๋ค.
Chaum, Fiat, and Naorโs idea for detecting double spending was an intricate cryptographic dance.
Chaum, Fiat ๋ฐ Naor ์ ์ด์ค ์ง์ถ ๊ฐ์ง ์์ด๋์ด๋ ๋ณต์กํ ์ํธํ์ ์ธ ๊ฒ์ด์์ต๋๋ค.
At a high level, what it achieved was this:
๋์ ๋จ๊ณ์์, ๊ทธ๊ฒ์ด ์ฑ์ทจํ๋ ๊ฒ์ ์ด๊ฒ์ด์์ต๋๋ค.
every digital coin issued to you encodes your identity, but in such a way that no one except you, not even the bank, can decode it.
๋น์ ์๊ฒ ๋ฐํ๋ ๋ชจ๋ ๋์งํธ ์ฝ์ธ์ ๋น์ ์ ์ ๋ถ์ ์ํธํ์ง๋ง, ๋น์ ์ ์ ์ธํ ๋ค๋ฅธ ๋๊ตฌ๋, ์ฌ์ง์ด ์ํ ์กฐ์ฐจ๋, ๊ทธ๊ฒ์ ํด๋
ํ ์ ์์ต๋๋ค.
Every time you spend your coin, the recipient will require you to decode a random subset of the encoding, and theyโll keep a record of this.
๋น์ ์ด ์ฝ์ธ์ ์๋นํ ๋๋ง๋ค, ์์ ์๋ ์ํธํ๋ ์์์ ํ์ ์งํฉ์ ํด๋
ํด์ผํ๋ฉฐ, ์ด๊ฒ์ ๊ณ์ ๊ธฐ๋กํ ๊ฒ์
๋๋ค.
This decoding isnโt enough to allow them to determine your identity.
์ด ํด๋
๋ง์ผ๋ก ๋น์ ์ ์ ์์ ํ๋จํ ์๋ ์์ต๋๋ค.
But if you ever double spend a coin, eventually both recipients will go to the bank to redeem their notes, and when they do this, the bank can put the two pieces of information together to decode your identity completely, with an overwhelmingly high probability.
๊ทธ๋ฌ๋ ์ฝ์ธ์ ๋๋ฒ ์ฌ์ฉํ๋ค๋ฉด, ๊ฒฐ๊ตญ ๋ ์์ ์ ๋ชจ๋ ์ํ์ ๊ฐ์ ๊ทธ๋ค์ ์ฝ์ธ์ ํ๊ธ์ผ๋ก ๋ฐ๊พธ๋ ค ํ ๊ฒ์
๋๋ค. ๊ทธ๋ฆฌ๊ณ ๊ทธ๋ฆฌ๊ณ ๊ทธ๋ค์ด ์ด๋ ๊ฒ ํ ๋, ์ํ์ ๋ ๊ฐ์ง ์ ๋ณด๋ฅผ ํจ๊ป ์ฌ์ฉํ์ฌ ๋น์ ์ ์ ์์ ์๋์ ์ผ๋ก ๋์ ํ๋ฅ ๋ก ์์ ํ ํด๋
ํ ์ ์์ต๋๋ค.
You might wonder if someone can frame you as a double spender in this system.
๋น์ ์ ์ด๋ค ์ด๊ฐ ๋น์ ์ ์ด ์์คํ
์์ ์ด์ค ๊ฒฐ์ ์๋ก ๋ชฐ์๊ฐ์ ์๋์ง ์๋์ง๋ฅผ ๊ถ๊ธํดํ ์ง๋ ๋ชจ๋ฆ
๋๋ค.
Say you spend a coin with me, and then I turned around and tried to double-spend it (without redeeming it with the bank and getting a new coin with my identity encoded).
๋น์ ์ด ๋์๊ฒ ์ฝ์ธ์ ์ฐ๊ณ ๋์ ๋ด๊ฐ ๋์๊ฐ์ ๊ทธ๊ฒ์ ์ด์ค ๊ฒฐ์ ํ๋ ค๊ณ ํ๋ค๊ณ ๋งํด๋ด
์๋ค.(๊ทธ๊ฒ์ ์ํ์ ๊ฐ์ ํ๊ธ์ผ๋ก ๋ฐ๊พผ ํ, ๋์ ์ ์์ผ๋ก ์ํธํ๋ ์๋ก์ด ์ฝ์ธ์ผ๋ก ๋ฐ๊พธ์ง ์๊ณ ์)
This wonโt work
์ด๊ฒ์ ์๋ํ์ง ์์ ๊ฒ์
๋๋ค.
โ the new recipient will ask me to decode a random subset, and this will almost certainly not be the same as the subset you decoded for me, so I wonโt be able to comply with their decoding request.
์ ์์ ์๊ฐ ์์์ ํ์ ์งํฉ์ ํด๋
ํ๋๋ก ๋์๊ฒ ์์ฒญํ ๊ฒ์ด๊ณ , ์ด๊ฒ์ ๋น์ ์ด ๋์๊ฒ ํด๋
ํ๊ฒ๊ณผ ๊ฑฐ์ ํ์คํ ๊ฐ์ง ์์ ๊ฒ์
๋๋ค. ๊ทธ๋์ ๋๋ ๊ทธ๋ค์ ํด๋
์์ฒญ์ ๋ฐ๋ฅผ ์ ์์ ๊ฒ์
๋๋ค.
Over the years, many cryptographers have looked at this construction and improved it in various ways.
์๋
์ ๊ฑธ์ณ, ๋ง์ ์ํธํ์๋ค์ ์ด ๊ตฌ์กฐ๋ฅผ ๋ณด๊ณ , ๋ค์ํ ๋ฐฉ๋ฒ์ผ๋ก ๊ทธ๊ฒ์ ๊ฐ์ ํด์์ต๋๋ค.
In the Chaum-Fiat-Naor scheme, if a coin is worth $100, and you wanted to buy something that cost only $75, say, thereโs no way to split that coin into $75 and a $25.
Cahum-Fiat-Naor ๊ณํ์์, ์ฝ์ธ์ด 100๋ฌ๋ฌ ๊ฐ์น๊ฐ ์๋๋ฐ, ๋น์ ์ ์ค์ง 75๋ฌ๋ฌ ๊ฐ์น๊ฐ ์๋ ์ด๋ค ๊ฒ์ ์ฌ๋ คํ๋ค๋ฉด, ๊ทธ ์ฝ์ธ์ 75๋ฌ๋ฌ์ 25๋ฌ๋ฌ๋ก ๋๋๋ ๋ฐฉ๋ฒ์ ์์ต๋๋ค.
All you could do is go back to the bank, cash in the $100 coin, and ask for a $75 coin and a $25 coin.
๋น์ ์ด ํ ์ ์๋ ๊ฒ์ ์ํ์ผ๋ก ๋์๊ฐ์, 100๋ฌ๋ฌ ์ฝ์ธ์ผ๋ก ํ๊ธ์ ๋ด๊ณ 75๋ฌ๋ฌ ์ฝ์ธ๊ณผ 25๋ฌ๋ฌ ์ฝ์ธ์ ์์ฒญํ๋ ๊ฒ์
๋๋ค.
But a paper by Okamoto and Ohta uses โMerkle treesโ to create a system that does allow you to subdivide your coins.
๊ทธ๋ฌ๋ Okamoto์ Ohta ์ ๋
ผ๋ฌธ์์๋ ๋์ ์ ์ธ๋ถํ ํ ์ ์๋๋ก ํ๊ธฐ ์ํ ์์คํ
์ ๋ง๋ค๊ธฐ ์ํด์ ๋จธํด ํธ๋ฆฌ๋ค์ ์ฌ์ฉํฉ๋๋ค.
Merkle trees would show up in Bitcoin as well, and weโll meet them in Chapter 1.
๋จธํดํธ๋ฆฌ์์๋ ๋นํธ์ฝ์ธ์์ ๋ํ ๋ํ๋๋ฉฐ, ์ฐ๋ฆฌ๋ 1์ฅ์์ ๊ทธ๊ฒ๋ค์ ๋ง๋ ๊ฒ์
๋๋ค.
The Chaum-Fiat-Naor scheme also leaves a lot of room for improvements in efficiency.
Chaum-Fiat-Naor ๊ณํ์ ๋ํ ํจ์จ์ฑ ํฅ์์ ์ํ ๋ง์ ์ฌ์ง๋ฅผ ๋จ๊ฒจ๋ก๋๋ค.
In particular, the application of something called zero-knowledge proofs to this scheme (most notably by Brands; and Camenisch, Hohenberger, and Lysyanskaya) was very fruitfulโzero-knowledge proofs have also been applied to Bitcoin as we will see in Chapter 6.
ํนํ, ์์ง์์ฆ๋ช
์ ์ฌ์ฉํ ์ ํ๋ฆฌ์ผ์ด์
์ ์ด ๊ณํ์ ์ ์ฉํ ๊ฒ์ ๋งค์ฐ ์ ์ตํ์ต๋๋ค. ์์ง์์ฆ๋ช
์ 6์ฅ์์ ๋ณด๊ฒ ๋๊ฒ ์ง๋ง ๋นํธ์ฝ์ธ์๋ ๋ํ ์ ์ฉ๋์์ต๋๋ค.
But back to Chaum: he took his ideas and commercialized them.
๊ทธ๋ฌ๋ ๋ค์ Chaum์ผ๋ก ๋์๊ฐ๋ด
์๋ค : ๊ทธ๋ ๊ทธ์ ์์ด๋์ด๋ฅผ ์์ฉํํ์ต๋๋ค.
He formed a company in 1989 called DigiCash, probably the earliest company that tried to solve the problem of online payments.
๊ทธ๋ 1989๋
์ DigiCash๋ผ ๋ถ๋ฆฌ์ฐ๋ ํ์ฌ๋ฅผ ์ค๋ฆฝํ์ต๋๋ค. ์ด ํ์ฌ๋ ์๋ง๋ ์จ๋ผ์ธ ๊ฒฐ์ ๋ฌธ์ ๋ฅผ ํด๊ฒฐํ๋ ค๊ณ ์๋ํ ๊ฐ์ฅ ์ฒซ๋ฒ์งธ ํ์ฌ์ผ ๊ฒ์
๋๋ค.
They had about a five-year head start on other companies like FirstVirtual and CyberCash that we just discussed.
๊ทธ๋ค์ ์ฐ๋ฆฌ๊ฐ ์ข์ ์ ๋ค๋ฃจ์๋ FirstVirtual ๋ฐ CyberCash์ ๊ฐ์ ๋ค๋ฅธ ํ์ฌ๋ณด๋ค 5๋
๋จผ์ ์์ํ์ต๋๋ค.
The actual cash in Digicashโs system was called Ecash and they had another system called cyberbucks.
Digicash ์์คํ
์ ์ฌ์ฉ๋ ์ค์ ์บ์ฌ๋ Ecash๋ผ ๋ถ๋ ธ๊ณ , ๊ทธ๋ค์ cyberbucks๋ผ๊ณ ๋ถ๋ฆฌ์ฐ๋ ๋ ํ๋์ ์์คํ
์ ๊ฐ์ก์ต๋๋ค.
There were banks that actually implemented it โ a few in the US and at least one in Finland.
์ค์ ๋ก ๊ทธ๊ฒ์ ๊ตฌํํ๋ ๊ฒ์ ์ํ์ด์์ต๋๋ค - ๋ฏธ๊ตญ์ ๋ช ๊ฐ ์ํ์ด ์์๊ณ , ํ๋๋์๋ ์ ์ด๋ ํ๊ฐ๊ฐ ์์์ต๋๋ค.
This was in the 1990s, long before Bitcoin, which might come as surprise to some Bitcoin
enthusiasts who view banks as tech-phobic, anti-innovative behemoths.
์ด๊ฒ์ ๋นํธ์ฝ์ธ์ด ์๊ธฐ ํจ์ฌ ์ค๋์ ์ธ 1990๋
๋ ์์ต๋๋ค. ์ํ๋ค์ด ๊ธฐ์ ๊ณตํฌ์ฆ์ด ์๊ณ , ํ์ ์ ๋ฐ๋ํ๋ ๊ฑฐ๋์กฐ์ง์ด๋ผ๊ณ ์๊ฐํ๋ ์ผ๋ถ ๋นํธ์ฝ์ธ ์ ํธ๊ฐ๋ค์๊ฒ๋ ๋๋ผ์ด ์ฌ์ค์ผ ๊ฒ๋๋ค.
Ecash is based on Chaumโs protocols.
Ecash๋ Chaum์ ํ๋กํ ์ฝ์ ๊ธฐ๋ฐํฉ๋๋ค.
Clients are anonymous, so banks canโt trace how theyโre spending their money.
๊ณ ๊ฐ๋ค์ ์ต๋ช
์ด์๊ณ , ๊ทธ๋์ ์ํ๋ค์ ๊ทธ๋ค์ด ์ด๋ป๊ฒ ๋์ ์ฐ๊ณ ์๋์ง๋ฅผ ์ถ์ ํ ์ ์์์ต๋๋ค.
But merchants in ecash arenโt anonymous.
๊ทธ๋ฌ๋ ecash์ ์์ธ๋ค์ ์ต๋ช
์ด ์๋์์ต๋๋ค.
They have to return coins as soon as they receive them, so the bank knows how much theyโre making, at what times, and so on.
๊ทธ๋ค์ ์ฝ์ธ๋ค์ ๋ฐ์๋ง์ ์ํ์ ๋๋ ค์ค์ผ๋ง ํ์ต๋๋ค. ๊ทธ๋์ ์ํ์ ๊ทธ๋ค์ด ์ธ์ ์ผ๋งํผ ๋์ ๋ฒ๊ณ ์๋์ง ๋ฑ์ ์๊ณ ์์์ต๋๋ค.
Figure 2 shows a screenshot from the software.
๊ทธ๋ฆผ2๋ ์ํํธ์จ์ด์ ์คํฌ๋ฆฐ์ท์ ๋ณด์ฌ์ค๋๋ค.
As you can see, it shows you your balance as well as all the coins that you have that have been issued to you from the bank.
๋น์ ์ด ๋ณผ์ ์๋ ๊ฒ์ฒ๋ผ, ๊ทธ๊ฒ์ ์ํ์๊ณ ์ ์ํ์ผ๋ก๋ถํฐ ๋ฐ๊ธ๋ฐ์ ๋ชจ๋ ๋์ ์ ๋ณด์ฌ์ค๋๋ค.
Since thereโs no way to split your coins, the bank issues you a whole set of coins in denominations of a cent, two cents, four cents, and so on โ powers of two.
๋น์ ์ ๋์ ์ ๋๋๋ ๋ฐฉ๋ฒ์ด ์๊ธฐ ๋๋ฌธ์, ์ํ์ ๋น์ ์๊ฒ ์ ์ฒด ๋์ ์ 1์ผํธ, 2์ผํธ, 4์ผํธ ๋ฑ์ผ๋ก ๋๋ ์ ๋ฐํํฉ๋๋ค.
That way, you (or your software, on your behalf) can always select a set of coins to pay for the exact amount of a transaction.
๊ทธ๋ฐ์์ผ๋ก, ๋น์ ์(๋๋ ๋น์ ์ ๋์ ํ์ฌ ์ํํธ์จ์ด๊ฐ) ์ ํํ ๊ธ์ก์ ๊ฑฐ๋๋น์ฉ์ ์ง๋ถํ๊ธฐ ์ํด์ ์ฝ์ธ๋ค์ ์ธํธ๋ฅผ ํญ์ ์ ํํ ์ ์์ต๋๋ค.
When you want to make a transaction, say, as in this example, you want to make a donation to the non-profit privacy group EPIC, youโd click on a donation link that takes you to the Digicash website.
๋น์ ์ด ํธ๋์ญ์
์ ๋ง๋ค๊ธฐ๋ฅผ ์ํ๋ค๋ฉด, ์๋ฅผ ๋ค์ด, ๋น์๋ฆฌ ํ๋ผ์ด๋ฒ์ ๊ทธ๋ฃน EPIC ์ ๊ธฐ๋ถํ๊ธฐ๋ฅผ ์ํ๋ค๋ฉด, Digicash ์น์ฌ์ดํธ๋ก ์ด๋ํ๋ ๊ธฐ๋ถ ๋งํฌ๋ฅผ ํด๋ฆญํ๋ฉด ๋ฉ๋๋ค.
That would then open a reverse web connection back to your computer.
๊ทธ๋ฌ๋ฉด ๊ทธ๊ฒ์ ๋น์ ์ ์ปดํจํฐ๋ก ์ญ๋ฐฉํฅ ์น ์ฐ๊ฒฐ์ด ์ด๋ฆฌ๊ฒ ๋ฉ๋๋ค.
That means your computer had to have the ability to accept incoming connections and act as a server.
์ด๊ฒ์ ๋น์ ์ ์ปดํจํฐ๊ฐ ๋ค์ด์ค๋ ์ฐ๊ฒฐ๋ค์ ์๋ฝํ๊ณ ์๋ฒ๋ก์ ์๋ํ ์ ์๋ ๋ฅ๋ ฅ์ ๊ฐ์ ธ์ผ๋ง ํ๋ค๋ ๊ฒ์ ์๋ฏธํฉ๋๋ค.
Youโd have to have your own IP address and your ISP would have to allow incoming connections.
๋น์ ์ ๋น์ ์์ ์ IP ์ฃผ์๋ฅผ ๊ฐ์ ธ์ผ๋ง ํ๊ณ , ๋น์ ์ ISP ๋ ๋ค์ด์ค๋ ์ฐ๊ฒฐ๋ค์ ํ์ฉํด์ผ๋ง ํฉ๋๋ค.
*ISP : ๊ฐ์ธ์ด๋ ๊ธฐ์ ์๊ฒ ์ธํฐ๋ท ์ ์ ์๋น์ค, ์น ์ฌ์ดํธ ๊ตฌ์ถ ๋ฑ์ ์ ๊ณตํ๋ ํ์ฌ๋ฅผ ๋งํ๋ค.
If the connection was successful, then the ecash software would launch on your computer and youโd be able to approve the transaction and send the money.
์ฐ๊ฒฐ์ด ์ฑ๊ณตํ๋ฉด, ecash ์ํํธ์จ์ด๊ฐ ๋น์ ์ ์ปดํจํฐ์์ ์์๋๊ณ , ๊ฑฐ๋๋ฅผ ์น์ธํ๊ณ ๋์ ๋ณด๋ผ ์ ์๊ฒ ๋ฉ๋๋ค.
Chaum had several patents on Digicash technology, in particular, the blind-signature scheme that it used.
Chaum ์ Digicash ๊ธฐ์ ์ ๋ํด ์ฌ๋ฌ๊ฐ์ง ํนํ๋ฅผ ๋ณด์ ํ๊ณ ์์๋๋ฐ, ๊ทธ ์ค์๋ ๋ธ๋ผ์ธ๋-์๊ทธ๋์ฒ ์ค๊ณ์ ๊ฐ์ ๊ฒ์ด ์์์ต๋๋ค.
This was controversial, and it stopped other people from developing ecash systems that used the same protocol.
์ด๊ฒ์ ๋
ผ์์ ์ฌ์ง๊ฐ ์์์ต๋๋ค. ๊ทธ๋ฆฌ๊ณ ๊ทธ๊ฒ์ ๋ค๋ฅธ ์ฌ๋๋ค์ด ๊ฐ์ ํ๋กํ ์ฝ์ ์ฌ์ฉํ์ฌ ecash ์์คํ
์ ๊ฐ๋ฐํ๋ ๊ฒ์ ๋ฉ์ถ๊ฒ ํ์ต๋๋ค.
But a bunch of cryptographers who hung out on what was called the cypherpunks mailing list wanted an alternative.
๊ทธ๋ฌ๋ cypherpunks ๋ฉ์ผ๋ง ๋ฆฌ์คํธ์ ๊ฐ์ ์ฐ๊ตฌ์ ๋งค๋ฌ๋ ค ์์๋ค ๋ง์ ์ํธํ์๋ค์ ๋ค๋ฅธ ๋์์ ์ํ์์ต๋๋ค.
Cyperpunks was the predecessor to the mailing list where Satoshi Nakamoto would later announce Bitcoin to the world, and this is no coincidence.
Cyperpunks ๋ ์ฌํ ์ ๋์นด๋ชจํ ๊ฐ ๋นํธ์ฝ์ธ์ ์ธ๊ณ์ ์๋ฆฌ๋๋ฐ ์ฌ์ฉํ๋ ๋ฉ์ผ๋ง ๋ฆฌ์คํธ์ ์ ์ ์ด๋ฉฐ, ์ด๊ฒ์ ๊ฒฐ์ฝ ์ฐ์ฐ์ด ์๋๋๋ค.
Weโll talk about the cypherpunk movement and the roots of Bitcoin in Chapter 7.
์ฐ๋ฆฌ๋ 7์ฅ์์ cypherpunk ๋ฌด๋ธ๋จผํธ์ ๋นํธ์ฝ์ธ์ ๊ทผ์์ ๋ํด ์ด์ผ๊ธฐํ ๊ฒ์
๋๋ค.
The cypherpunk cryptographers implemented a version of of ecash called MagicMoney.
cypherpunk ์ฐ๊ตฌ ์ํธํ์๋ค์ MagicMoney ๋ผ ๋ถ๋ฆฌ์ฐ๋ ecash ๋ฒ์ ์ ๊ตฌํํ์์ต๋๋ค.
It did violate the patents, but was billed as being only for experimental use.
๊ทธ๊ฒ์ ํนํ๋ค์ ์๋ฐํ์์ง๋ง, ์คํ์ฉ๋๋ฅผ ์ํด์๋ง ์ฌ์ฉ๋์์ต๋๋ค.
It was a fun piece of software to play with.
๊ทธ๊ฒ์ ์ฌ๋ฏธ์๊ฒ ๋ ์ ์๋ ์ํํธ์จ์ด์์ต๋๋ค.
The interface was all text-based.
๊ทธ ์ธํฐํ์ด์ค๋ ๋ชจ๋ ํ
์คํธ ๊ธฐ๋ฐ์ด์์ต๋๋ค.
You could send transactions by email.
๋น์ ์ ์ด๋ฉ์ผ๋ก ๊ฑฐ๋๋ค์ ๋ณด๋ผ ์ ์์์ต๋๋ค.
You would just copy and paste the transactions into your email and send it to another user.
๋น์ ์ ๋จ์ง ๊ฑฐ๋๋ค์ ๋ณต์ฌํ์ฌ ์ด๋ฉ์ผ์ ๋ถ์ฌ ๋ฃ์ ๋ค์, ๊ทธ๊ฒ์ ๋ค๋ฅธ ์ฌ์ฉ์์๊ฒ ๋ณด๋
๋๋ค.
Hopefully, youโd use end-to-end email encryption software such as PGP to protect the transaction in transit.
์ ์ก์ค์ธ ํธ๋์ญ์
์ ๋ณดํธํ๊ธฐ ์ํด์ PGP์ ๊ฐ์ end-to-end ์ด๋ฉ์ผ ์ํธ ์ํํธ์จ์ด๋ฅผ ์ฌ์ฉํ์์ต๋๋ค.
Then thereโs a proposal called Lucre by Ben Laurie with contributions from many other people.
๊ทธ๋ฆฌ๊ณ ๋์ ๋ง์ ์ฌ๋๋ค์ ํ์์ผ๋ก Ben Laurie์ ์ํด ๋ง๋ค์ด์ง Lucre ๋ผ ๋ถ๋ฆฌ๋ ์ ์์ด ์๊ฒ ๋ฉ๋๋ค.
Lucre tries to replace the blind-signature scheme in ecash with a non-patent-encumbered alternative, with the rest of the system largely the same.
Lucre ๋ ๊ทธ ์์คํ
์ ๋๋จธ์ง ๋ถ๋ถ์ ๊ฑฐ์ ๋์ผํ ์ํ์์ ecash ์ ๋ธ๋ผ์ธ๋-์๋ช
์ค๊ณ๋ฅผ ํนํ๊ฐ ์๋ ๋ค๋ฅธ ๋์์ผ๋ก ๋์ฒดํ๋ ค๊ณ ํ์ต๋๋ค.
Yet another proposal, by Ian Goldberg, tries to fix the problem of not being able to split your coins to make change.
Ian Goldberg๊ฐ ์ ์ํ ๋ ๋ค๋ฅธ ์ ์์ ๊ฑฐ์ค๋ฆ๋์ ๋ด๊ธฐ ์ํด์ ๋น์ ์ ๋์ ์ ๋๋๋ ค ํ ๋, ๊ทธ๊ฒ์ ํ์ง ๋ชปํ๋ ๋ฌธ์ ๋ฅผ ํด๊ฒฐํ๊ธฐ ์ํด ๋
ธ๋ ฅํฉ๋๋ค.
His idea was that the merchant could send you coins back if they had some coins, so that you might overpay for the item if you didnโt have exact change, and then youโd get some coins back.
๊ทธ์ ์์ด๋์ด๋ ์์ ์ด ์ฝ์ธ๋ค์ ๊ฐ์ก๋ค๋ฉด, ๋น์ ์๊ฒ ์ฝ์ธ๋ค์ ๋๋ก ๋ณด๋ด์ค ์ ์๋ค๋ ๊ฒ์ด์์ต๋๋ค. ๊ทธ๋์ ๋น์ ์ด ์ ํํ ์์ด ์ฝ์ธ์ ๊ฐ์ง์ง ์์์ ์ํ์ ๋ํด ์ด๊ณผ ์ง๋ถํ์์ง๋ผ๋ ๋น์ ์ ๊ทธ์ ๋ํ ๊ฑฐ์ค๋ฆ๋์ ๋๋ ค ๋ฐ์ ์ ์๊ฒ ๋์์ต๋๋ค.
But notice that this introduces an anonymity problem.
๊ทธ๋ฌ๋ ์ด๊ฒ์ ์ต๋ช
์ฑ์ ๋ฌธ์ ๋ฅผ ์ผ๊ธฐํ๊ฒ ๋ฉ๋๋ค.
As we saw earlier, in ecash, senders are anonymous but merchants arenโt.
์ฐ๋ฆฌ๊ฐ ์์์ ๋ณด์๋ฏ์ด, ๋ฐ์ ์๋ ์ต๋ช
์ด์ง๋ง, ์์ธ์ ๊ทธ๋ ์ง ์์ต๋๋ค.
When the merchant sends cash back, technically, theyโre the sender, so theyโre anonymous.
์์ ์ด ์บ์ฌ๋ฅผ ๋๋ ค๋ณด๋ผ๋, ๊ธฐ์ ์ ์ผ๋ก, ๊ทธ๋ค์ ๋ฐ์ ์์ด๋ฉฐ, ๊ทธ๋์ ๊ทธ๋ค์ ์ต๋ช
์ด๊ฒ ๋ฉ๋๋ค.
But you, as someone who has to return this cash to the bank, arenโt anonymous.
๊ทธ๋ฌ๋ ๋น์ ์ ์ด ๋๋ ค๋ฐ์ ์บ์ฌ๋ฅผ ์ํ์ผ๋ก ๊ฐ์ ธ๊ฐ์ผ๋ง ํ๊ธฐ ๋๋ฌธ์, ์ต๋ช
์ด ์๋๊ฒ ๋ฉ๋๋ค.
Thereโs no way to design this system without breaking the anonymity of users trying to
buy goods.
๋ฌผํ ๊ตฌ๋งค๋ฅผ ํ๋ ค๋ ์ฌ์ฉ์์ ์ต๋ช
์ฑ์ ์นจํดํ์ง ์์ผ๋ฉด์ ์ด ์์คํ
์ ๋์์ธํ ๋ฐฉ๋ฒ์ ์์ต๋๋ค.
So Goldberg came up with a proposal where there were different types of coins that
would allow these transactions to occur, allow you to get change back, and still preserve your anonymity.
๊ทธ๋์ ๊ณจ๋๋ฒ๊ทธ๋ ํ ๊ฐ์ง ์ ์์ ํ๋๋ฐ, ๊ทธ๊ฒ์ ์๋ก ๋ค๋ฅธ ์ข
๋ฅ์ ์ฝ์ธ๋ค์ด ์์ด์, ์ด๋ฌํ ๊ฑฐ๋๋ค์ด ์ผ์ด๋๊ฒ ํ๊ณ , ๋น์ ์ด ๊ฑฐ์ค๋ฆ๋์ ๋๋ ค๋ฐ๊ณ ๋์๋, ์ฌ์ ํ ๋น์ ์ ์ต๋ช
์ฑ์ ์ ์งํ ์ ์๊ฒ ํ๋ ์ ์์ด์์ต๋๋ค.
Now, why did DigiCash fail?
์ ๊ทธ๋ผ, ์ DigiCash๋ ์คํจํ์๋์?
The main problem with DigiCash was that it was hard to persuade the banks and the merchants to adopt it.
DigiCash ์ ๊ฐ์ฅ ํฐ ๋ฌธ์ ์ ์ ์ํ๋ค๊ณผ ์์ ๋ค์ด ๊ทธ๊ฒ์ ์ฑํํ๋๋ก ์ค๋ํ๊ธฐ๊ฐ ์ด๋ ต๋ค๋ ๊ฒ์ด์์ต๋๋ค.
Since there werenโt many merchants that accepted ecash, users didnโt want it either.
ecash๋ฅผ ์๋ฝํ๋ ๋ง์ ํ๋งค์๋ค์ด ์์๊ธฐ ๋๋ฌธ์, ์ฌ์ฉ์๋ค๋ ๊ทธ๊ฒ์ ์ํ์ง ์์์ต๋๋ค.
Worse, it didnโt support user-to-user transactions, or at least not very well.
๋ ์์ข์ ๊ฒ์, ์ฌ์ฉ์๊ฐ ํธ๋์ญ์
๋ค์ ์ง์ํ์ง ์์๊ณ , ํน์ ์ ์ด๋ ๊ทธ๋ฆฌ ์ข์ง ์์์ต๋๋ค.
It was really centered on the user-to-merchant transaction.
๊ทธ๊ฒ์ ์ค์ ๋ก ์ฌ์ฉ์ ๋ ํ๋งค์ ํธ๋์ญ์
์ ์ค์ฌ์ผ๋ก ํ์์ต๋๋ค.
So if merchants werenโt on board, there was card companies won.
๊ทธ๋์ ํ๋งค์๋ค์ด ์ฌ์ฉํ์ง ์์์๊ณ , ์นด๋ ํ์ฌ๋ค์ด ์น๋ฆฌํ๊ฒ ๋์์ต๋๋ค.
As a side note, Bitcoin allows user-to-merchant and user-to-user transactions.
๋ถ๊ฐํ์๋ฉด, ๋นํธ์ฝ์ธ์ ์ฌ์ฉ์-ํ๋งค์ ๋ฐ ์ฌ์ฉ์-์ฌ์ฉ์๊ฐ์ ํธ๋์ญ์
์ ํ์ฉํฉ๋๋ค.
In fact, the protocol doesnโt have a notion of merchant thatโs separate from the notion of user.
์ฌ์ค, ์ด ํ๋กํ ์ฝ์๋ ์ฌ์ฉ์์ ๊ฐ๋
๊ณผ๋ ๊ตฌ๋ณ๋๋ ์์ ์ด๋ผ๋ ๊ฐ๋
์ด ์์ต๋๋ค.
The support for user-to-user transactions probably contributed to Bitcoinโs success.
์ฌ์ฉ์ ๋ ์ฌ์ฉ์ ํธ๋์ญ์
์ ๋ํ ์ง์์ด ์๋ง๋ ๋นํธ์ฝ์ธ์ ์ฑ๊ณต์ ๊ธฐ์ฌํ์ ๊ฒ์
๋๋ค.
There was something to do with your bitcoins right from the beginning:
์ฒ์๋ถํฐ ๋ฐ๋ก ๋นํธ์ฝ์ธ์ ๊ฐ์ง๊ณ ํ ์ ์๋ ๊ฒ์ด ์์์ต๋๋ค.
send it to other users, while the community tried to drum up support for Bitcoin and get merchants to accept it.
๊ทธ๊ฒ์ ๋ค๋ฅธ ์ฌ์ฉ์๋ค์๊ฒ ๋ณด๋ผ ์ ์์์ต๋๋ค. ๊ทธ๋ฆฌ๊ณ ์ปค๋ฎค๋ํฐ๋ ๋นํธ์ฝ์ธ์ ๋ํ ์ง์์ ๊ฐํํ๊ณ , ํ๋งค์๋ค๋ก ํ์ฌ๊ธ ๊ทธ๊ฒ์ ๋ฐ์๋ค์ด๋๋ก ํ์์ต๋๋ค.
In the later years of the company, DigiCash also experimented with tamper-resistant hardware to try to prevent double-spending rather than just detecting it.
ํ์ฌ ํ๋ฐ๊ธฐ์, DigiCash๋ ์ด์ค ์๋น ๋ฅผ ๊ฐ์งํ๋ ๊ฒ๋ณด๋ค ๊ทธ๊ฒ์ ๋ง๊ธฐ ์ํ ๋ณ์กฐ ๋ฐฉ์ง ํ๋์จ์ด๋ฅผ ์๋ํ์์ต๋๋ค.
In this system, youโd get a small hardware device that was usually called a wallet, or some sort of card.
์ด ์์คํ
์์๋ ์ผ๋ฐ์ ์ผ๋ก ์ง๊ฐ์ด๋ผ๋ ๋ถ๋ฆฌ๋ ์ผ์ข
์ ์นด๋์ ๊ฐ์ ์์ ํ๋์จ์ด ์ฅ์น๋ฅผ ์ฌ์ฉํ๊ฒ ๋ฉ๋๋ค.
The device would keep track of your balance, which would decrease when you spent money and increase if you loaded the card with more money.
์ฅ์น๋ ๋น์ ์ ์์ก์ ์ถ์ ํฉ๋๋ค. ์๊ณ ๋ ๋น์ ์ด ๋์ ์ธ ๋ ๊ฐ์ํ๊ณ , ๋ ๋ง์ ๋์ ์นด๋์ ์ ์ฌํ๋ฉด ์ฆ๊ฐํฉ๋๋ค.
The point of the device is that there should be no way to physically or digitally go in and
tamper with its counter.
์ฅ์น์ ์์ ์ ๋ฌผ๋ฆฌ์ ์ผ๋ก ๋๋ ๋์งํธ ๋ฐฉ์์ผ๋ก ๋ค์ด์์ ๊ทธ๊ฒ์ ์นด์ดํฐ๋ฅผ ๋ณ๊ฒฝํ๋ ๋ฐฉ๋ฒ์ด ์์ด์ผ ํ๋ค๋ ๊ฒ์
๋๋ค.
So if the counter hits zero, then the card stops being able to spend money until itโs re-loaded.
๊ทธ๋์ ์นด์ดํฐ๊ฐ 0์ด ๋๋ฉด, ์นด๋๋ ์ฌ ์ถฉ์ ๋ ๋๊น์ง ๋์ ์ธ ์ ์๊ฒ ๋ฉ๋๋ค.
There were many other companies that had electronic cash systems based on tamper-resistant hardware.
์กฐ์ ๋ฐฉ์ง ํ๋์จ์ด๋ฅผ ๊ธฐ๋ฐ์ผ๋ก ํ๋ ์ ์ ์บ์ฌ ์์คํ
๋ค์ ๊ฐ์ก๋ ๋ค๋ฅธ ๋ง์ ํ์ฌ๋ค์ด ์์์ต๋๋ค.
DigiCash later worked with a company called CAFE which was based in Europe.
DigiCash๋ ๋์ค์ ์ ๋ฝ์ ๊ธฐ๋ฐ์ ๋ CAFE๋ผ๋ ํ์ฌ์ ํจ๊ป ์ผํ์ต๋๋ค.
Another company formed around this idea was called Mondex and it was later acquired by Mastercard.
์ด ์์ด๋์ด๋ฅผ ์ค์ฌ์ผ๋ก ํ์ฑ๋ ๋ ๋ค๋ฅธ ํ์ฌ๋ Mondex ๋ผ ๋ถ๋ ธ๊ณ , ๋์ค์ Mastercard๊ฐ ์ธ์ํ์์ต๋๋ค.
Visa also had their own variant called VisaCash.
Visa ๋ํ VisaCash ๋ผ๋ ์์ ๋ง์ ์์คํ
์ ๊ฐ์ก์์ต๋๋ค.
Figure 3: Mondex system, showing user card and wallet.
๊ทธ๋ฆผ 3: MOndex ์์คํ
์ ์ฌ์ฉ์ ์นด๋์ ์ง๊ฐ
Figure 3 shows the user side of the Mondex system.
๊ทธ๋ฆผ3 ์ Mondex ์์คํ
์ ์ฌ์ฉ์ ์ธก์ ๋ณด์ฌ์ค๋๋ค.
Thereโs a smart card and thereโs a wallet unit, and you can load either of them with cash.
์ค๋งํธ์นด๋์ ์ง๊ฐ์ด ์์ผ๋ฉฐ, ๋น์ ์ ํ๊ธ์ผ๋ก ๊ทธ ์ค ํ๋๋ฅผ ์ถฉ์ ํ ์ ์์ต๋๋ค.
And if you wanted to do user-to-user swap of money, the giver user would first put their card into the wallet and move money off of the card onto the wallet.
๊ทธ๋ฆฌ๊ณ ์ฌ์ฉ์ ๋ ์ฌ์ฉ์๊ฐ ๋์ ๊ตํํ๊ธฐ๋ฅผ ์ํ๋ค๋ฉด, ์ก๊ธ์ธ์ ๋จผ์ ์์ ์ ์นด๋๋ฅผ ์ง๊ฐ์ ๋ฃ๊ณ , ์นด๋์์ ๋์ ์ง๊ฐ์ผ๋ก ์ฎ๊น๋๋ค.
Then the receiver would stick their card in the wallet then youโd move the money onto the second card.
๊ทธ๋ฆฌ๊ณ ๋์ ์์ ์ธ์ ์นด๋๋ฅผ ์ง๊ฐ์ ๋ถ์ด๋ฉด, ๋๋ฒ์งธ ์นด๋๋ก ๋์ ์ฎ๊ธธ ์ ์์ต๋๋ค.
This was a way to exchange digital cash, and it was anonymous.
์ด๊ฒ์ ๋์งํธ ์บ์ฌ๋ฅผ ๊ตํํ๋ ๋ฐฉ๋ฒ์ด์์ผ๋ฉฐ, ์ต๋ช
์ผ๋ก ์ฒ๋ฆฌ๋์์ต๋๋ค.
Mondex trialled their technology in a bunch of communities.
Mondex ๋ ๋ง์ ์ปค๋ฎค๋ํฐ์์ ๊ทธ๋ค์ ๊ธฐ์ ์ ์์ฐํ์ต๋๋ค.
One community happened to be a city very close to where I grew up: Guelph, Ontario.
๊ทธ์ค์ ํ ์ปค๋ฎค๋ํฐ๋ Ontario ์ Guelph ๋ผ๋ ๋ด๊ฐ ์๋๋ ๊ณณ์์ ๋งค์ฐ ๊ฐ๊น์ด ๋์์์ต๋๋ค
Youโve probably already guessed that it didnโt really catch on.
๋น์ ์ ์๋ง๋ ์ด๋ฏธ ๊ทธ๊ฒ์ด ๊ทธ๋ ๊ฒ ์ธ๊ธฐ๊ฐ ์์ง๋ ์์๋ค๋ ๊ฒ์ ์์ํ์์ ๊ฒ๋๋ค.
A major problem with Mondex cards is that theyโre like cash
Mondex ์นด๋์ ๊ฐ์ฅ ํฐ ๋ฌธ์ ๋ ๊ทธ๊ฒ์ด ํ๊ธ๊ณผ ๊ฐ์ ๊ฒ์ด์๋ค๋ ๊ฒ๋๋ค.
โ if you lose them or they get stolen, the moneyโs gone.
๋ง์ฝ ๋น์ ์ด ๊ทธ๊ฒ์ ์์ด๋ฒ๋ฆฌ๊ฑฐ๋ ๋๋ ๋นํ๋ฉด, ๋์ ์์ด์ง๊ฒ ๋ฉ๋๋ค.
Worse, if thereโs some sort of malfunction with the card, if the card reader wouldnโt read it, thereโs no way to figure out if that card had balance on it or not.
๋ ๋์ ๊ฒ์ ๋ง์ฝ์ ์นด๋์ ์ด๋ค ์ข
๋ฅ์ ์ค์๋์ด ์์ด์, ์นด๋ ๋ฆฌ๋๊ธฐ๊ฐ ๊ทธ๊ฒ์ ์ฝ์ง ๋ชปํ๋ค๋ฉด, ๊ทธ ์นด๋์ ์๊ณ ๊ฐ ์ผ๋ง์ธ์ง๋ฅผ ํ์ธํ ๋ฐฉ๋ฒ์ด ์๋ค๋ ๊ฒ์ด์์ต๋๋ค.
In these scenarios, Mondex would typically eat the cost.
์ด๋ฐ ์ผ์ด ๋ฐ์ํ๊ฒ ๋๋ฉด, Mondex ๊ฐ ์ผ๋ฐ์ ์ผ๋ก ๊ทธ ๋น์ฉ์ ์ง๋ถํ๊ฒ ๋ฉ๋๋ค.
Theyโd assume that the card was loaded and reimburse the user for that lost money.
๊ทธ๋ค์ ์นด๋๊ฐ ์ถฉ์ ๋์๋ค๊ณ ๊ฐ์ ํ๊ณ , ์ฌ์ฉ์์๊ฒ ์์ด๋ฒ๋ฆฐ ๋์ ๋ฐฐ์ํฉ๋๋ค.
Of course, that can cost a company a lot of money.
๋ฌผ๋ก , ๊ทธ๊ฒ์ ํ์ฌ์๊ฒ ๋ง์ ๋น์ฉ๋ถ๋ด์ด ๋์์ต๋๋ค.
Further, the wallet was slow and clunky.
๊ฒ๋ค๊ฐ, ์ง๊ฐ์ ๋งค์ฐ ๋๋ฆฌ๊ณ ํฌ๋ฐํ์์ต๋๋ค.
It was much faster to pay with a credit card or with cash.
์ ์ฉ์นด๋ ๋๋ ํ๊ธ์ ๊ฐ์ง๊ณ ์ง๋ถํ๋ ๊ฒ์ด ํจ์ ๋ ๋นจ๋์ต๋๋ค.
And retailers hated having several payment terminals;
๊ทธ๋ฆฌ๊ณ ์๋งค์
์ฒด๋ค์ ์ฌ๋ฌ ๊ฐ์ ์ง๋ถํฐ๋ฏธ๋๋ค์ ๊ฐ์ง๋ ๊ฒ์ ์ซ์ดํ์ต๋๋ค.
they wanted just one for credit cards.
๊ทธ๋ค์ ์ ์ฉ์นด๋๋ฅผ ์ํ ํฐ๋ฏธ๋ ํ๋๋ง์ ์ํ์์ต๋๋ค.
All these factors together did Mondex in.
์ด ๋ชจ๋ ์์ธ๋ค์ด ํจ๊ป ๋ชฌ๋ฑ์ค์๊ฒ ์ํฅ์ ๋ผ์ณค์ต๋๋ค.
However, these cards were smart cards, which means that they have small microcontrollers on them, and that technology has proved successful.
๊ทธ๋ฌ๋, ์ด ์นด๋๋ค์ ์ค๋งํธ ์นด๋์์ต๋๋ค. ์นด๋๋ค์ ์ํ ๋ง์ดํฌ๋ก ์ปจํธ๋กค๋ฌ๋ค์ ์ฌ์ฉํ์๊ณ , ๊ทธ ๊ธฐ์ ์ ์ฑ๊ณต์ ์ด์์์ด ์
์ฆ๋์์ต๋๋ค.
In many countries today, including Canada, where I live, every single credit card and every single debit card now has smart card technology in it.
๋ด๊ฐ ์ด๊ณ ์๋ ์บ๋๋ค๋ฅผ ํฌํจํ์ฌ, ์ค๋๋ ๋ง์ ๊ตญ๊ฐ๋ค์์ ๋ชจ๋ ์ ์ฉ์นด๋์ ์ฒดํฌ์นด๋์๋ ์ค๋งํธ ์นด๋ ๊ธฐ์ ์ด ์ ์ฉ๋ฉ๋๋ค.
Itโs used for a different purpose, though.
ํ์ง๋ง ๊ทธ๊ฒ์ ๋ค๋ฅธ ์ฉ๋๋ก ์ฌ์ฉ๋ฉ๋๋ค.
Itโs not used to prevent double-spending โ the problem doesnโt arise since itโs not a cash-based technology.
๊ทธ๊ฒ์ ์ด์ค์ง์ถ์ ๋ฐฉ์งํ๋๋ฐ ์ฌ์ฉ๋์ง ์์ต๋๋ค - ์ ์ฉ์นด๋๋ ํ๊ธ ๊ธฐ๋ฐ ๊ธฐ์ ์ด ์๋๊ธฐ ๋๋ฌธ์ ์ด์ค์ง์ถ ๋ฌธ์ ๊ฐ ๋ฐ์ํ์ง ์์ต๋๋ค.
The bank, rather than your card, keeps track of your balance or available credit.
๋น์ ์ ์นด๋๊ฐ ์๋ ์ํ์ด ๋น์ ์ ์๊ณ ๋๋ ๊ฐ๋ฅํ ์ ์ฉ์ ๊ณ์ ์ถ์ฒํฉ๋๋ค.
Instead the chip is used for authentication, that is, to prove that you know the PIN thatโs associated with your account.
๋์ ์นฉ์ ์ธ์ฆ์ ์ฌ์ฉ๋ฉ๋๋ค. ์ฆ, ๋น์ ์ด ๊ณ์ ๊ณผ ์ฐ๊ฒฐ๋ PIN ์ ์๊ณ ์๋์ง๋ฅผ ์ธ์ฆํ๊ธฐ ์ํด์ ์ฌ์ฉ๋ฉ๋๋ค.
But Mondex was using it long before this technology was adopted widely by the banking industry.
๊ทธ๋ฌ๋ Mondex ๋ ์ด ๊ธฐ์ ์ด ์ํ์
๊ณ์์ ๋๋ฆฌ ์ฑํ๋๊ธฐ ์ค๋์ ๋ถํฐ ๊ทธ๊ฒ์ ์ฌ์ฉํ๊ณ ์์์ต๋๋ค.