English日本語|PDF (EN)PDF (JA)
v0.28.9 — This text is under construction. The structure of the theory, the propositions, and the empirical conclusions may all change. Overview

Chapter 10
The Supplier of the Information Structure: Settlement by Protocol

10.1 The premises imposed in this chapter

Chapter 8 imposed constraints on resources and Chapter 9 took their limit. Both take the information structure 𝒢 of Chapter 4 as given. This chapter varies 𝒢 itself and asks how the set of feasible Φ changes when the supplier of 𝒢 is replaced.

Two things should be said first.

First, this chapter is deduction, not evidence. The validity of the conclusions depends on the validity of the premises.

Second, nothing here is new. Every relation stated has a counterpart in the existing literature, and a correspondence table is given in Appendix A.4.1. The purpose of the chapter is to show how the theory built in Part I works under specific conditions.

What is replaced is the 𝒢 of Chapter 4; the question is who guarantees the measurability condition of Proposition 4.1.

Definition 10.1 (Protocol). A set of rules published in advance, whose execution every participant can verify independently, is called a protocol and written 𝒫. The tuple of variables 𝒫 holds is called its state. State transitions are taken to be atomic: no part of a transition is applied on its own.

The premises are as follows.

(1)
Settlement π is expressed as a state transition on 𝒫
(2)
The execution of 𝒫 can be verified independently by every participant (Definition 10.1)
(3)
Whether delivery δ is contained in the state of 𝒫 depends on the object

The implementation in wide use that satisfies premises (1) and (2) is settlement on a public distributed ledger, that is, a blockchain. Not everything called by that name satisfies the premises, however. Where verifiers are restricted, or where the state is held by a particular operator, (2) fails and the deductions of this chapter do not apply.

Premises (1) and (2) are a relaxation. The 𝒢 = ⋂ ⁡ i𝒢i of Chapter 4 is normally supplied by a third party outside the transacting parties, on whom verification and enforcement of π depended. Premises (1) and (2) make that unnecessary.

Only (3) cannot be fixed as a premise, and that is what forces this chapter’s case split.

Theoretical quantities in this chapter
𝒢 Chapter 4

the object whose supplier is replaced

The index i of κi Eq. (3.2)

becomes an identifier on the protocol. additivity is lost

δ¯ − δ Definition 2.21

observable as protocol state in the “inside” partition

E Eq. (3.8)

appears as collateral

Degrees of freedom (2), (3) Section 2.5

the sieve cuts along these two

Table 10.1: Theoretical quantities in this chapter: the symbols involved when the supplier of the information structure is replaced.

10.2 Translating the premises

10.2.1 Three functions the third party performed

The role of the supplier of 𝒢 in a contract divides into three.

Function

Content

Usual bearer
(a) Recording

holding the state of κi

banks, payment processors
(b) Verification

judging whether the condition triggering π has occurred

courts, auditors
(c) Enforcement

transferring value when the condition holds

courts, banks
Table 10.2: Three functions a third party performs in a contract.

By premises (1) and (2), 𝒫 can always bear (a). It can bear (b) so long as the condition can be judged from the state of 𝒫, and (c) so long as what is transferred is the state of 𝒫.

10.2.2 A case split by where delivery resides

Premise (3) produces two cases.

Partition Where δ resides

What enters 𝒢

Functions 𝒫 can bear

Inside the state of 𝒫

both δ and π

(a), (b), (c)

Outside outside 𝒫

only π

(a), and (b), (c) concerning π

Table 10.3: The partition by where delivery resides, and the functions the protocol can bear.

The difference between the partitions bears directly on degree of freedom (1) of Section 2.5, timing, and fixes the sign of κi in (3.2).

Proposition 10.2 (Simultaneity). In the “inside” partition, for any Φ there is an implementation with κi = 0. In the “outside” partition, κi = 0 cannot be achieved for a Φ that involves δ.

Proof. In the “inside” partition both δ and π are state transitions of 𝒫. By the atomicity of Definition 10.1 the two can be composed as a single transition, and Di and Pi then move together, so the κi of (3.2) is identically 0.

In the “outside” partition δ is not a state of 𝒫, so 𝒫 has no time for δ. κi = 0 requires τi = 0, but τi is not determined on 𝒢. □

That is, in the “inside” partition degree of freedom (1) becomes a full design variable, while in the “outside” partition κ≠0 is forced. Immediate exchange in the real world achieves simultaneity because the parties observe each other at the same moment; 𝒫 has no such observation. This is why 1-1 (immediate exchange) disappears in the “outside” partition in Section 10.4.

Remark 10.3 (The partition is a property of Φ, not of the object). For one and the same object the partition changes with what is taken to be delivery. A Φ exchanging a protocol balance for another balance is inside; a Φ exchanging the same balance for currency outside the protocol is outside.

That a record of ownership sits on the protocol does not make the partition inside. Where a non-fungible token is tied to a physical artwork or a membership, what moves is the record and the delivery is a handover in the real world. Because δ lies outside 𝒫, the partition is outside. That the two cannot be identified shows up as the fact that a change of record-holder does not cause a handover. For the same token, a Φ whose delivery is only the exercise of a right on the protocol is inside.

The question “is that object inside or outside?” therefore does not arise. What can be asked is “is that Φ inside or outside?” This has the same form as the conclusion of Section 12.10.3: here too the unit of observation must be Φ rather than the object.

Remark 10.4 (Intermediation in the “outside” partition). To bring a condition concerning δ into 𝒫 in the “outside” partition, some party must write an external fact into the state. What 𝒫 can verify is only that a prescribed signature is attached; it does not verify that the value written is factual. That party therefore fails premise (2), and the third party supposedly removed returns.

The writing party may be a single entity or a quorum of several, so removal is continuous rather than discrete. This chapter does not treat that continuum and handles only the two ends (Section 10.7). A classification of implementations is in [35].

10.2.3 The binding constraint switches

In Chapter 8, which of the financial and capacity constraints binds first switches with the premises. The same happens here.

Because premises (1) and (2) widen 𝒢, the measurability condition of Proposition 4.1 is looser in the “inside” partition than anywhere else in this text. 𝒢 therefore ceases to bind and something else does. Section 10.5 identifies what.

10.3 Identifiers diverge from parties

This section is a by-product, placed where Chapter 8 recorded the correspondence A → κS < 0 for the cloud.

The κi of (3.2) is defined per party i and summed as ∑ ⁡ iκi in (3.8). That summation presumes that the index denotes a party uniquely.

What can be identified on a protocol is an identifier. 𝒫 cannot rule out one party holding several identifiers, because generating an identifier costs nothing. This is a known problem [32].

Remark 10.5 (Loss of additivity). Writing j for an identifier, i for a party, and j↦ι(j) for the correspondence, what is observed is κj while what is needed is

κi = ∑ j:ι(j)=iκj (10.1)

Since ι is not observable, (10.1) cannot be evaluated.

This is a limit of the definitions of Chapter 2, not a consequence of this chapter’s premises. It shows that a setting which fixes N and ties the index to a party does not fit an environment where identifiers are freely created. It originates in the same place as the circulation of claims in Section 7.10.3, namely the setting of the domain. The theory is not amended.

Remark 10.5 bears directly on family 7.

Proposition 10.6 (A Φ requiring identification of the beneficiary cannot be implemented). When ι is not observable, a π conditioned on the beneficiary and the payer being different is not 𝒢-measurable.

Proof. The defining property of family 7 is that the party receiving δ differs from the party paying π. 𝒫 identifies an identifier j and ι(j) is not observable, so ι(j1)≠ι(j2) cannot be judged on 𝒢. By Proposition 4.1, a π depending on this condition cannot be written. □

Proposition 10.6 does not depend on the partition: even when δ is a state of 𝒫, the party receiving it cannot be identified. This is why 7-1 and 7-2 drop out in both partitions. 7-4 survives because it makes no explicit exchange and therefore needs no identification of the beneficiary.

That mechanisms presuming parties to be distinct fail when identifiers can be created freely is treated in mechanism design as false-name-proofness [38]. Proposition 10.6 is its manifestation at the level of contract form.

10.4 Sieving the types

The 28 types of Part II are passed through the sieve of the two partitions of Table 10.3.

The criterion differs from that of Chapter 8. There the cut was feasibility; here it is whether the protocol contributes. A type that receives no contribution in the “outside” partition does not disappear; enforcement simply returns to a third party. Below, a type “receives a contribution” when the condition governing π enters 𝒢 and what is enforced is a state of 𝒫. The judgment is made per Φ, not per type (Remark 10.3).

No. Type Inside Outside

Grounds

Family 1: one-off exchange
1-1 immediate exchange yes —

simultaneity is available only when δ and π are the same state transition

1-2 one-off advance yes yes

π comes first and does not refer to δ

1-3 one-off arrears yes —

outside, completion of δ cannot be judged

1-4 instalments yes partly

outside, collection of π works but default does not reach the underlying asset

Family 2: continuing access
2-1 flat access yes yes

π = F does not refer to δ

2-2 usage yes —

outside, metering δ needs the party of Remark 10.4

2-3 two-part tariff yes partly

outside, only the fixed part F

2-4 prepaid yes yes

inside, the unused balance is itself the protocol state

2-5 options and warranties yes —

outside, the exercise condition lies outside the protocol

Family 3: renting an asset over time
3-1 lease and rental yes —

inside only where the asset itself is a protocol state

3-2 shared asset conditionally —

the range in which utilization can be written as a state transition is narrow

3-3 transfer plus long collection yes —

inside with collateral; outside it does not reach the underlying asset

Family 4: recovery through a complement
4-1 lock-in consumables conditionally —

the family presumes the device lies outside the protocol, which fails inside

4-2 freemium yes yes

κ > 0, but it is self-issued credit and asks no enforcement of the protocol

4-3 hardware subsidy plus finance yes —

outside, the device lies outside the protocol

Family 5: outcome- and state-contingent
5-1 success fee conditionally —

only where the y of π = h(y) is a protocol quantity

5-2 revenue share yes —

inside, the counterparty’s flow is observable on the protocol

5-3 cost plus — —

actual costs lie outside the protocol either way

5-4 underwriting yes —

inside, ω is confined to protocol events

5-5 IP licensing yes —

inside, where use is observable on the protocol

Family 6: intermediation
6-1 transaction fee yes —

inside, completed in combination with the simultaneity of 1-1

6-2 escrow yes partly

outside, only one side is held; release needs the party of Remark 10.4

6-3 spread yes —

inside, inventory becomes a protocol balance

6-4 charging for opportunity conditionally —

only where contact can be defined as a protocol event

Family 7: separating beneficiary from payer
7-1 advertising — —

that beneficiary and payer differ cannot be verified (Section 10.3)

7-2 cross-subsidy — —

as above

7-3 public payment — —

the payer sets the price and design freedom sits in the institutional layer

7-4 donation and support yes yes

no explicit exchange, so no identification of the beneficiary is required

Table 10.4: Sieving the 28 types. “yes” marks those that receive a contribution.

Twenty types receive a contribution in the “inside” partition and five in the “outside” partition. Where the sieve of Chapter 8 cut 28 types down to about ten, the “inside” sieve barely cuts at all. This chapter’s premises are a relaxation, not a constraint.

That 1-1 disappears in the “outside” partition follows from Proposition 10.2: if δ lies outside the protocol, the form degrades into either an advance or arrears.

Receiving a contribution and being executable are, however, different things. The advance forms (1-2, 2-4) pass in the table for the “inside” partition, but executing them requires collateral towards the counterparty and they are not open to a party without assets (Corollary 10.12, Corollary 10.11). Section 10.5 treats this.

Remark 10.7 (The axis along which the sieve cuts). The five types surviving in the “outside” partition are 1-2, 2-1, 2-4, 4-2 and 7-4, and all they share is that π is not measurable with respect to δ. Of the six degrees of freedom of Section 2.5, only (2) carries information for this sieve.

This is not a proposition. Since the “outside” partition was defined as the case where δ does not enter 𝒢, the impossibility of writing a δ-measurable π follows from the definition. The information lies not in the claim but in the fact that applying the sieve to 28 types individually turned out to be explained by a single degree of freedom.

Remark 10.8 (The direction in which the institutional layer acts). Types 2-4 (prepaid) and 6-2 (escrow) were the ones removed in Section 8.5 by deposit obligations and licensing. In the “inside” partition they are implemented as protocol.

One and the same type both drops out and returns, depending on the direction in which the institutional layer acts. This is an instance showing that the first form (entry requirement) of the three in Remark 6.9 does not act in only one direction.

10.5 The collateral constraint

Section 10.4 showed that 𝒢 ceases to bind. This section identifies what does.

Consider a Φ in the “inside” partition with κi > 0, that is, one in which the operator extends credit. To enforce on non-payment of π, what is enforced must be a state of 𝒫. But 𝒢 consists only of states of 𝒫, so neither the counterparty’s ability to pay nor their past record of performance is in 𝒢.

Credit can therefore be provided for only through states locked in advance, that is, collateral. Writing Bi for the collateral one has locked for counterparty i and Bi′ for the collateral i has locked for oneself, the κi of (3.2) satisfies

max ⁡ {κi,0}≤Bi′,max ⁡ {−κ i,0}≤Bi (10.2)

Collateral is provided from one’s own assets without duplication, so ∑ ⁡ iBi ≤ E, and summing (10.2) over i gives the following.

Proposition 10.9 (Collateral constraint). In the “inside” partition, the total credit that can be received does not exceed equity.

∑ i max ⁡ {−κi,0}≤E (10.3)

Proof. Summing the second inequality of (10.2) over all i gives ∑ ⁡ i max ⁡ {−κi,0}≤∑ ⁡ iBi. The same asset cannot be locked for several counterparties at once, so ∑ ⁡ iBi ≤ E; combining the two gives the result. □

Compare (10.3) with (8.1) of Chapter 8. There, under E ≈ 0, the requirement was ∑ ⁡ max ⁡ {−κi,0}≥∑ ⁡ max ⁡ {κi,0}: the credit drawn had to exceed the credit extended. Here the credit that can be drawn is itself bounded by E.

Corollary 10.10 (The substitution degenerates to one direction). In the “inside” partition, the substitution of Proposition A.15 becomes one-directional: capital substitutes for credit, but credit does not substitute for capital.

Proof. By Proposition 10.9 the terms with κ < 0 are bounded above by E. In (3.8), terms with κ < 0 cannot raise funding beyond E. The reverse substitution — E substituting for κ < 0 — holds as in Proposition A.15. □

Corollary 10.10 is the third place in this text where Proposition A.15 appears.

Place E Credit

What binds there

Chapter 8, solo business 0 the only means of funding

the credit bootstrap problem

Section 8.6, those with assets positive built from zero

capital buys the period in which credit is built

This chapter, “inside” the only means of funding 0

there is no period in which to build

Table 10.5: The three places Proposition A.15 appears. The two ends line up.

Section 8.7 described the route by which credit forms through accumulated public performance. That route does not operate in the “inside” partition, because 𝒫 identifies only identifiers (Section 10.3) and cannot attribute a past record of performance to a party.

Corollary 10.11 (Exclusion of parties without assets). When A = Inv = 0 and E = 0, the only feasible Φ are those with κi = 0 for every i.

Proof. Substituting E = 0 into (10.3) gives κi ≥ 0 for every i. On the other hand, by Proposition A.15, when A = Inv = E = 0 the requirement is ∑ ⁡ i max ⁡ {−κi,0}≥∑ ⁡ i max ⁡ {κi,0}, whose left-hand side is 0, giving κi ≤ 0. □

Corollary 10.12 (Growth through advance payment requires capital). In the “inside” partition, achieving CCC < 0 requires E > 0.

Proof. By (5.1), CCC = W∕r with W = ∑ ⁡ iκi + Inv. Substituting E = 0 into Proposition 10.9 gives κi ≥ 0 for every i, which together with Inv ≥ 0 gives W ≥ 0 and hence CCC ≥ 0. □

Chapter 8 showed a route by which a solo business without assets creates CCC < 0 through annual prepayment — a state in which growth generates cash. That route closes in the “inside” partition, because receiving an advance requires collateral towards the counterparty and collateral is provided out of capital.

That is, what remains to a party without assets is confined to types with κ identically 0: 1-1 (immediate exchange), 2-2 (usage) and 6-1 (transaction fee), which Part II recorded as κ ≈ 0, and their composites. In Chapter 8, E = 0 required κC < 0; here it forces κ = 0. Solutions (a), (b) and (c) of Section 8.5 all presumed a shortage of credit; what is short here is capital.

Remark 10.13 (Correspondence with existing theory). Nothing in this section is new. The structure by which net worth constrains funding through collateral capacity is in [33], and the formulation in which collateral constraints govern a firm’s financing and risk management jointly is in [36, 37]. Proposition A.15 itself has counterparts there too (Appendix A.4.1).

That the contractible space widens under premises (1) and (2) is treated in [31]. The point corresponding to Corollary 10.11 — that a mechanism demanding collateral excludes parties without capital — also has a literature [34].

The role of this section is to place these on one and the same inequality, that of (3.8).

10.6 Observability

Premise (2) has a secondary consequence. Because the state of 𝒫 is verifiable by every participant, the following quantities are individually observable in the “inside” partition.

Quantity

Measurement status in this text

Status in the “inside” partition

M(t)

requires per-firm data and is meaningless in aggregate

observable per identifier

κj

as above

as above

δ¯ − δ

only estimable from aggregates

directly observable as the unused balance

B

this text has no corresponding quantity

observable as locked state

Table 10.6: Quantities that become observable in the “inside” partition.

What is observable, however, is per identifier, and by Remark 10.5 the per-party κi cannot be recovered. The obstacle to measurement changes from the absence of aggregation to the impossibility of it. This differs from category (v) of Section 13.2 (Remark 13.2) and is a new form relative to the taxonomy of Part III.

10.6.1 A population frame becomes available

It is not only quantities that become observable.

The conditioning on survival of Chapter 12 arises because the objects observed are limited to paths that did not violate (4.3). In the “inside” partition the record of the protocol is itself the population. Every Φ that operated remains, including those that stopped, so no conditioning occurs.

Chapter 17 abandoned direct measurement of the unmanned operating period for want of a population frame. That reason disappears here.

10.6.2 What can and cannot be tested

Being observable does not mean being testable. Three cases must be separated first.

Case

Content

Quantities the protocol enforces

observing them is not a test; it is reading the rules

Quantities that result from design

these are what can be tested

Per-party quantities

cannot be recovered (Remark 10.5)

Table 10.7: Three cases among the quantities observable in the “inside” partition.

The collateral constraint of Proposition 10.9 belongs to the first case. Since the protocol requires collateral, observing that collateral is posted does not test the proposition. What can be tested is confined to quantities that appear as the result of an operator’s choice.

Remark 10.14 (The population differs). A distribution measured in the “inside” partition cannot be generalized to firms at large. In the sense of Chapter 12 it is a different population. What can be tested here is whether a deduction is correct, not whether that deduction applies to real solo businesses. The propositions of Chapter 8 can be tested; nothing is said about that chapter’s objects.

Chapter 18 observes these quantities in practice.

10.7 Limits of this chapter

(1)
This is deduction. The conclusions depend on premises (1), (2) and (3). The tests of Section 18.2 measure the implications of the deduction and do not verify the premises themselves.
(2)
A rule was needed to narrow what is judged. Table 7.8 takes Φ as given and cannot be applied directly to ledger identifiers. Section 18.2 places the question “is this a Φ?” before the assignment order (Remark 18.5). That step is not part of the rule of Chapter 7.
(3)
Only the two ends are treated. As Remark 10.4 notes, the degree to which the third party is removed in the “outside” partition is continuous. This chapter treats only full removal and no removal, not the middle. Most existing arrangements are in the middle.
(4)
A limit of the definitions remains. The unobservability of ι in Section 10.3 originates in fixing N in Chapter 2. This chapter records it and does not extend the domain. It is the same place as the circulation of claims in Section 7.10.3.
(5)
ϕ is not treated. This chapter argues only about the feasibility of Φ and does not apply the three-way decomposition of surplus of Chapter 6. An argument of the same form as the remark in Chapter 9 — that the replicability of a protocol puts pressure on ϕ𝑝𝑟𝑜𝑑 — could hold, but judging it requires measured fees and is not attempted here.