Chapter 10
The Supplier of the Information Structure: Settlement by Protocol
10.1 The premises imposed in this chapter
Chapter 8 imposed constraints on resources and Chapter 9 took their limit. Both take the information structure of Chapter 4 as given. This chapter varies itself and asks how the set of feasible changes when the supplier of is replaced.
Two things should be said first.
First, this chapter is deduction, not evidence. The validity of the conclusions depends on the validity of the premises.
Second, nothing here is new. Every relation stated has a counterpart in the existing literature, and a correspondence table is given in Appendix A.4.1. The purpose of the chapter is to show how the theory built in Part I works under specific conditions.
What is replaced is the of Chapter 4; the question is who guarantees the measurability condition of Proposition 4.1.
Definition 10.1 (Protocol). A set of rules published in advance, whose execution every participant can verify independently, is called a protocol and written . The tuple of variables holds is called its state. State transitions are taken to be atomic: no part of a transition is applied on its own.
The premises are as follows.
- (1)
- Settlement is expressed as a state transition on
- (2)
- The execution of can be verified independently by every participant (Definition 10.1)
- (3)
- Whether delivery is contained in the state of depends on the object
The implementation in wide use that satisfies premises (1) and (2) is settlement on a public distributed ledger, that is, a blockchain. Not everything called by that name satisfies the premises, however. Where verifiers are restricted, or where the state is held by a particular operator, (2) fails and the deductions of this chapter do not apply.
Premises (1) and (2) are a relaxation. The of Chapter 4 is normally supplied by a third party outside the transacting parties, on whom verification and enforcement of depended. Premises (1) and (2) make that unnecessary.
Only (3) cannot be fixed as a premise, and that is what forces this chapter’s case split.
Theoretical quantities in this chapter
| ||
| Chapter 4 | the object whose supplier is replaced |
|
| The index of | Eq. (3.2) | becomes an identifier on the protocol. additivity is lost |
| Definition 2.21 | observable as protocol state in the “inside” partition |
|
| Eq. (3.8) | appears as collateral |
|
| Degrees of freedom (2), (3) | Section 2.5 | the sieve cuts along these two |
10.2 Translating the premises
10.2.1 Three functions the third party performed
The role of the supplier of in a contract divides into three.
| Function | Content |
Usual bearer |
| (a) Recording | holding the state of |
banks, payment processors |
| (b) Verification | judging whether the condition triggering has occurred |
courts, auditors |
| (c) Enforcement | transferring value when the condition holds |
courts, banks |
By premises (1) and (2), can always bear (a). It can bear (b) so long as the condition can be judged from the state of , and (c) so long as what is transferred is the state of .
10.2.2 A case split by where delivery resides
Premise (3) produces two cases.
| Partition | Where resides | What enters |
Functions can bear |
| Inside | the state of | both and |
(a), (b), (c) |
| Outside | outside | only |
(a), and (b), (c) concerning |
The difference between the partitions bears directly on degree of freedom (1) of Section 2.5, timing, and fixes the sign of in (3.2).
Proposition 10.2 (Simultaneity). In the “inside” partition, for any there is an implementation with . In the “outside” partition, cannot be achieved for a that involves .
Proof. In the “inside” partition both and are state transitions of . By the atomicity of Definition 10.1 the two can be composed as a single transition, and and then move together, so the of (3.2) is identically .
In the “outside” partition is not a state of , so has no time for . requires , but is not determined on . □
That is, in the “inside” partition degree of freedom (1) becomes a full design variable, while in the “outside” partition is forced. Immediate exchange in the real world achieves simultaneity because the parties observe each other at the same moment; has no such observation. This is why 1-1 (immediate exchange) disappears in the “outside” partition in Section 10.4.
Remark 10.3 (The partition is a property of , not of the object). For one and the same object the partition changes with what is taken to be delivery. A exchanging a protocol balance for another balance is inside; a exchanging the same balance for currency outside the protocol is outside.
That a record of ownership sits on the protocol does not make the partition inside. Where a non-fungible token is tied to a physical artwork or a membership, what moves is the record and the delivery is a handover in the real world. Because lies outside , the partition is outside. That the two cannot be identified shows up as the fact that a change of record-holder does not cause a handover. For the same token, a whose delivery is only the exercise of a right on the protocol is inside.
The question “is that object inside or outside?” therefore does not arise. What can be asked is “is that inside or outside?” This has the same form as the conclusion of Section 12.10.3: here too the unit of observation must be rather than the object.
Remark 10.4 (Intermediation in the “outside” partition). To bring a condition concerning into in the “outside” partition, some party must write an external fact into the state. What can verify is only that a prescribed signature is attached; it does not verify that the value written is factual. That party therefore fails premise (2), and the third party supposedly removed returns.
The writing party may be a single entity or a quorum of several, so removal is continuous rather than discrete. This chapter does not treat that continuum and handles only the two ends (Section 10.7). A classification of implementations is in [35].
10.2.3 The binding constraint switches
In Chapter 8, which of the financial and capacity constraints binds first switches with the premises. The same happens here.
Because premises (1) and (2) widen , the measurability condition of Proposition 4.1 is looser in the “inside” partition than anywhere else in this text. therefore ceases to bind and something else does. Section 10.5 identifies what.
10.3 Identifiers diverge from parties
This section is a by-product, placed where Chapter 8 recorded the correspondence for the cloud.
The of (3.2) is defined per party and summed as in (3.8). That summation presumes that the index denotes a party uniquely.
What can be identified on a protocol is an identifier. cannot rule out one party holding several identifiers, because generating an identifier costs nothing. This is a known problem [32].
Remark 10.5 (Loss of additivity). Writing for an identifier, for a party, and for the correspondence, what is observed is while what is needed is
| (10.1) |
Since is not observable, (10.1) cannot be evaluated.
This is a limit of the definitions of Chapter 2, not a consequence of this chapter’s premises. It shows that a setting which fixes and ties the index to a party does not fit an environment where identifiers are freely created. It originates in the same place as the circulation of claims in Section 7.10.3, namely the setting of the domain. The theory is not amended.
Remark 10.5 bears directly on family 7.
Proposition 10.6 (A requiring identification of the beneficiary cannot be implemented). When is not observable, a conditioned on the beneficiary and the payer being different is not -measurable.
Proof. The defining property of family 7 is that the party receiving differs from the party paying . identifies an identifier and is not observable, so cannot be judged on . By Proposition 4.1, a depending on this condition cannot be written. □
Proposition 10.6 does not depend on the partition: even when is a state of , the party receiving it cannot be identified. This is why 7-1 and 7-2 drop out in both partitions. 7-4 survives because it makes no explicit exchange and therefore needs no identification of the beneficiary.
That mechanisms presuming parties to be distinct fail when identifiers can be created freely is treated in mechanism design as false-name-proofness [38]. Proposition 10.6 is its manifestation at the level of contract form.
10.4 Sieving the types
The 28 types of Part II are passed through the sieve of the two partitions of Table 10.3.
The criterion differs from that of Chapter 8. There the cut was feasibility; here it is whether the protocol contributes. A type that receives no contribution in the “outside” partition does not disappear; enforcement simply returns to a third party. Below, a type “receives a contribution” when the condition governing enters and what is enforced is a state of . The judgment is made per , not per type (Remark 10.3).
| No. | Type | Inside | Outside | Grounds |
Family 1: one-off exchange
| ||||
| 1-1 | immediate exchange | yes | — | simultaneity is available only when and are the same state transition |
| 1-2 | one-off advance | yes | yes | comes first and does not refer to |
| 1-3 | one-off arrears | yes | — | outside, completion of cannot be judged |
| 1-4 | instalments | yes | partly | outside, collection of works but default does not reach the underlying asset |
Family 2: continuing access
| ||||
| 2-1 | flat access | yes | yes | does not refer to |
| 2-2 | usage | yes | — | outside, metering needs the party of Remark 10.4 |
| 2-3 | two-part tariff | yes | partly | outside, only the fixed part |
| 2-4 | prepaid | yes | yes | inside, the unused balance is itself the protocol state |
| 2-5 | options and warranties | yes | — | outside, the exercise condition lies outside the protocol |
Family 3: renting an asset over time
| ||||
| 3-1 | lease and rental | yes | — | inside only where the asset itself is a protocol state |
| 3-2 | shared asset | conditionally | — | the range in which utilization can be written as a state transition is narrow |
| 3-3 | transfer plus long collection | yes | — | inside with collateral; outside it does not reach the underlying asset |
Family 4: recovery through a complement
| ||||
| 4-1 | lock-in consumables | conditionally | — | the family presumes the device lies outside the protocol, which fails inside |
| 4-2 | freemium | yes | yes | , but it is self-issued credit and asks no enforcement of the protocol |
| 4-3 | hardware subsidy plus finance | yes | — | outside, the device lies outside the protocol |
Family 5: outcome- and state-contingent
| ||||
| 5-1 | success fee | conditionally | — | only where the of is a protocol quantity |
| 5-2 | revenue share | yes | — | inside, the counterparty’s flow is observable on the protocol |
| 5-3 | cost plus | — | — | actual costs lie outside the protocol either way |
| 5-4 | underwriting | yes | — | inside, is confined to protocol events |
| 5-5 | IP licensing | yes | — | inside, where use is observable on the protocol |
Family 6: intermediation
| ||||
| 6-1 | transaction fee | yes | — | inside, completed in combination with the simultaneity of 1-1 |
| 6-2 | escrow | yes | partly | outside, only one side is held; release needs the party of Remark 10.4 |
| 6-3 | spread | yes | — | inside, inventory becomes a protocol balance |
| 6-4 | charging for opportunity | conditionally | — | only where contact can be defined as a protocol event |
Family 7: separating beneficiary from payer
| ||||
| 7-1 | advertising | — | — | that beneficiary and payer differ cannot be verified (Section 10.3) |
| 7-2 | cross-subsidy | — | — | as above |
| 7-3 | public payment | — | — | the payer sets the price and design freedom sits in the institutional layer |
| 7-4 | donation and support | yes | yes | no explicit exchange, so no identification of the beneficiary is required |
Twenty types receive a contribution in the “inside” partition and five in the “outside” partition. Where the sieve of Chapter 8 cut 28 types down to about ten, the “inside” sieve barely cuts at all. This chapter’s premises are a relaxation, not a constraint.
That 1-1 disappears in the “outside” partition follows from Proposition 10.2: if lies outside the protocol, the form degrades into either an advance or arrears.
Receiving a contribution and being executable are, however, different things. The advance forms (1-2, 2-4) pass in the table for the “inside” partition, but executing them requires collateral towards the counterparty and they are not open to a party without assets (Corollary 10.12, Corollary 10.11). Section 10.5 treats this.
Remark 10.7 (The axis along which the sieve cuts). The five types surviving in the “outside” partition are 1-2, 2-1, 2-4, 4-2 and 7-4, and all they share is that is not measurable with respect to . Of the six degrees of freedom of Section 2.5, only (2) carries information for this sieve.
This is not a proposition. Since the “outside” partition was defined as the case where does not enter , the impossibility of writing a -measurable follows from the definition. The information lies not in the claim but in the fact that applying the sieve to 28 types individually turned out to be explained by a single degree of freedom.
Remark 10.8 (The direction in which the institutional layer acts). Types 2-4 (prepaid) and 6-2 (escrow) were the ones removed in Section 8.5 by deposit obligations and licensing. In the “inside” partition they are implemented as protocol.
One and the same type both drops out and returns, depending on the direction in which the institutional layer acts. This is an instance showing that the first form (entry requirement) of the three in Remark 6.9 does not act in only one direction.
10.5 The collateral constraint
Section 10.4 showed that ceases to bind. This section identifies what does.
Consider a in the “inside” partition with , that is, one in which the operator extends credit. To enforce on non-payment of , what is enforced must be a state of . But consists only of states of , so neither the counterparty’s ability to pay nor their past record of performance is in .
Credit can therefore be provided for only through states locked in advance, that is, collateral. Writing for the collateral one has locked for counterparty and for the collateral has locked for oneself, the of (3.2) satisfies
| (10.2) |
Collateral is provided from one’s own assets without duplication, so , and summing (10.2) over gives the following.
Proposition 10.9 (Collateral constraint). In the “inside” partition, the total credit that can be received does not exceed equity.
| (10.3) |
Proof. Summing the second inequality of (10.2) over all gives . The same asset cannot be locked for several counterparties at once, so ; combining the two gives the result. □
Compare (10.3) with (8.1) of Chapter 8. There, under , the requirement was : the credit drawn had to exceed the credit extended. Here the credit that can be drawn is itself bounded by .
Corollary 10.10 (The substitution degenerates to one direction). In the “inside” partition, the substitution of Proposition A.15 becomes one-directional: capital substitutes for credit, but credit does not substitute for capital.
Proof. By Proposition 10.9 the terms with are bounded above by . In (3.8), terms with cannot raise funding beyond . The reverse substitution — substituting for — holds as in Proposition A.15. □
Corollary 10.10 is the third place in this text where Proposition A.15 appears.
| Place | Credit | What binds there |
|
| Chapter 8, solo business | 0 | the only means of funding | the credit bootstrap problem |
| Section 8.6, those with assets | positive | built from zero | capital buys the period in which credit is built |
| This chapter, “inside” | the only means of funding | 0 | there is no period in which to build |
Section 8.7 described the route by which credit forms through accumulated public performance. That route does not operate in the “inside” partition, because identifies only identifiers (Section 10.3) and cannot attribute a past record of performance to a party.
Corollary 10.11 (Exclusion of parties without assets). When and , the only feasible are those with for every .
Proof. Substituting into (10.3) gives for every . On the other hand, by Proposition A.15, when the requirement is , whose left-hand side is , giving . □
Corollary 10.12 (Growth through advance payment requires capital). In the “inside” partition, achieving requires .
Proof. By (5.1), with . Substituting into Proposition 10.9 gives for every , which together with gives and hence . □
Chapter 8 showed a route by which a solo business without assets creates through annual prepayment — a state in which growth generates cash. That route closes in the “inside” partition, because receiving an advance requires collateral towards the counterparty and collateral is provided out of capital.
That is, what remains to a party without assets is confined to types with identically : 1-1 (immediate exchange), 2-2 (usage) and 6-1 (transaction fee), which Part II recorded as , and their composites. In Chapter 8, required ; here it forces . Solutions (a), (b) and (c) of Section 8.5 all presumed a shortage of credit; what is short here is capital.
Remark 10.13 (Correspondence with existing theory). Nothing in this section is new. The structure by which net worth constrains funding through collateral capacity is in [33], and the formulation in which collateral constraints govern a firm’s financing and risk management jointly is in [36, 37]. Proposition A.15 itself has counterparts there too (Appendix A.4.1).
That the contractible space widens under premises (1) and (2) is treated in [31]. The point corresponding to Corollary 10.11 — that a mechanism demanding collateral excludes parties without capital — also has a literature [34].
The role of this section is to place these on one and the same inequality, that of (3.8).
10.6 Observability
Premise (2) has a secondary consequence. Because the state of is verifiable by every participant, the following quantities are individually observable in the “inside” partition.
| Quantity | Measurement status in this text |
Status in the “inside” partition |
| requires per-firm data and is meaningless in aggregate |
observable per identifier |
|
| as above |
as above |
|
| only estimable from aggregates |
directly observable as the unused balance |
|
| this text has no corresponding quantity |
observable as locked state |
What is observable, however, is per identifier, and by Remark 10.5 the per-party cannot be recovered. The obstacle to measurement changes from the absence of aggregation to the impossibility of it. This differs from category (v) of Section 13.2 (Remark 13.2) and is a new form relative to the taxonomy of Part III.
10.6.1 A population frame becomes available
It is not only quantities that become observable.
The conditioning on survival of Chapter 12 arises because the objects observed are limited to paths that did not violate (4.3). In the “inside” partition the record of the protocol is itself the population. Every that operated remains, including those that stopped, so no conditioning occurs.
Chapter 17 abandoned direct measurement of the unmanned operating period for want of a population frame. That reason disappears here.
10.6.2 What can and cannot be tested
Being observable does not mean being testable. Three cases must be separated first.
| Case | Content |
| Quantities the protocol enforces | observing them is not a test; it is reading the rules |
| Quantities that result from design | these are what can be tested |
| Per-party quantities | cannot be recovered (Remark 10.5) |
The collateral constraint of Proposition 10.9 belongs to the first case. Since the protocol requires collateral, observing that collateral is posted does not test the proposition. What can be tested is confined to quantities that appear as the result of an operator’s choice.
Remark 10.14 (The population differs). A distribution measured in the “inside” partition cannot be generalized to firms at large. In the sense of Chapter 12 it is a different population. What can be tested here is whether a deduction is correct, not whether that deduction applies to real solo businesses. The propositions of Chapter 8 can be tested; nothing is said about that chapter’s objects.
Chapter 18 observes these quantities in practice.
10.7 Limits of this chapter
- (1)
- This is deduction. The conclusions depend on premises (1), (2) and (3). The tests of Section 18.2 measure the implications of the deduction and do not verify the premises themselves.
- (2)
- A rule was needed to narrow what is judged. Table 7.8 takes as given and cannot be applied directly to ledger identifiers. Section 18.2 places the question “is this a ?” before the assignment order (Remark 18.5). That step is not part of the rule of Chapter 7.
- (3)
- Only the two ends are treated. As Remark 10.4 notes, the degree to which the third party is removed in the “outside” partition is continuous. This chapter treats only full removal and no removal, not the middle. Most existing arrangements are in the middle.
- (4)
- A limit of the definitions remains. The unobservability of in Section 10.3 originates in fixing in Chapter 2. This chapter records it and does not extend the domain. It is the same place as the circulation of claims in Section 7.10.3.
- (5)
- is not treated. This chapter argues only about the feasibility of and does not apply the three-way decomposition of surplus of Chapter 6. An argument of the same form as the remark in Chapter 9 — that the replicability of a protocol puts pressure on — could hold, but judging it requires measured fees and is not attempted here.