[strategy] Comments on the German federal government Blockchain Strategy
We will try to provide a progressive understanding of the technology in-play, assess the functional and operational need for a blockchain, deduce from it the notions of security and integrity, and then determine the scenarios available for an efficient and competitive usage of the technology.
Last week, the German federal government issued their Blockchain strategy report. The document outlines the general approach, directives, roadmap and incentives dedicated to the "blockchain" technology sector. We will hereby focus on the points that were not covered by the report, as we will abstract the capabilities the technology will bring, and understand their implications in order to re-frame the strategic importance of the technology for our stakeholders.
Useful resources
The document, "Blockchain-Strategie der Bundesregierung" is available here (pdf in German): Link 1
If you wish to consult the conclusions of the report, you might want to read this blog post by Pr Philipp Sandner from the Frankfurt School Blockchain Center: Link 2
Their understanding is straight forward, and I will quote it here:
Securities: green light.
Euro on chain: green light.
Bitcoin & Co.: green light.
Private stable coins: red light.
TL;DR
Blokchains are a sub-set of the internet, thus bring-in similar categories of risks, while providing a very specific set of digital services.
Comments
Business environment
From a commercial and financial perspective, the report is quiet positive and highlights the strategic relevance of the industry, for the German government and German regulators.
The document's tone highlights clearly the importance of the research sector that has been mushrooming around the blockchain industry, and in order to capitalize on it, the federal government takes substantial steps in enforcing the investment ecosystem around the technology, but also addresses the necessity to protect the end-users and the potential investors. The latter point means that will the industry will require more transparency around the mutliple blockchain companies, and their respective products.
In-so-far, the German strategy is favorable and encouraging for the prospect investors, and established actors.
However, the goal of this blog post is not to address the points covered in the report. Since the technical terms used are broadly defined, and not specific in regards to the real applications, you will find in the following an elaborated definition of the technology.
We will try to provide a progressive understanding of the technology in-play, assess the functional and operational need for a blockchain, deduce from it the notions of security and integrity, and then determine the scenarios available for an efficient and competitive usage of the technology.
One last note around the healthy business environment in Germany, it is necessary to understand that Germany hosts some of the promising companies in this specific sector. From my own experience, I moved to Berlin from Paris specifically to try to land a job at a bitcoin startup back in 2014. Vink-io UG, the very company behind this blog post was born from this decision to move to a hub where innovative and respected companies in the bitcoin world are accessible, and where it is possible to put faces on brands, or names.
Is blockchain internet?
One of many ways to reply to this question would be to replace at each instance in the report the word "blockchain" by the word "internet". By doing so we would soon enough unveil the "Internet Strategy" of the federal German government, one which covers topics like usability, sector consolidation, risk management and commerical perspectives.
For instance, we will assume at first that there is only a signle blockchain available on the internet. This blockchain is part of the overall network that can be called the internet, and thus is a sub-category of it, or a physical niche that can be accessed through the same device, and acts according to a different logical basis.
In this, we can safely assume that the blockchain is a protocol among several protocols that can be assimilated, when put together, to the internet.
The egg or chicken paradox
Im Finanzsektor fand die Blockchain-Technologie mit der Kryptowährung Bitcoin ihren ersten praktischen Anwen-dungsfall. Wie eingangs erwähnt, wird durch die Blockchain-Technologie die Herausgabe, Übertragung, Speicherung und der Handel mit digitalen (Wert-)Einheiten (Krypto-Token) ermöglicht.
In the financial sector, the block chain technology found its first practical application as the Bitcoin cryptocurrency. As mentioned above, the block chain technology makes it possible to issue, transmit, store and trade digital (value) units (crypto tokens).
The structure of this observation leads to an erroneuous conclusion that will be reflected on the whole document. In that, The "block-chain" first use-case was not bitcoin.
The right formulation would be something like this: The bitcoin crypto-currency required a first implementation of a new architecture to function properly, it is what will be called block-chain.
If we understand bitcoin, we can understand all of the blockchains, and this statement is uni-directional.
KISS
The people behind bitcoin wanted to solve two simple issues:
- How to send a "file" from/to an anonymous machine on the internet (peer-to-peer or like emails).
- How to make sure that only one copy of the "file" is considered valid.
They thought that if they solved these two issues, they will be capable of using these files as cash on the internet.
In practice, the internet is an excellent communication tool, that has brought many benefits to humanity. However, the internet as it was conceived evolved with a set of existent flaws, and brought-in a new category of flaws and risks (privacy mostly).
The system of interconnected computers that we use to communicate are incapable of creating "unique" files, and can not guarantee the identity of the counterpart. If we send an email, there can be many copies, and there is very little to guarantee that the final receiver is the person we intended to interact with. If we send an email using google services, we trust gmail to deliver it. If we use a self-hosted email server, we would not trust more than the logical base of the internet to deliver the message from sender/receiver, the operator being not trusted in many aspects.
These are real issues in communication theory despite their simplicity, and bitcoin was an attempt to build an internet protocol that replies exactly to these two issues, and nothing else.
For communication, a blockchain is a sub-set of the internet, or a way of communicating that enforces a strictly defined set of possible behavior.
Trust, Uniqueness and Identity
To solve these issues the inventors of bitcoin decided to invent an architecture that can be called "block chain"; and decided to not identify the actors who can contribute to the network, taking the assumption that everyone on the network is potentially hostile, and/or will try to misbehave.
If anyone wants to use this specific kind of computed behavior, they will be able to connect to the bitcoin protocol, or to any kind of similar protocol. However, these actors must accept that the bitcoin protocol solves the uniqueness of the files with expensive computation, and solves the issues of identity by not requiring any.
The bitcoin network assumes it will be populated by hostile actors, which are sane assumptions that any sane technology provider must consider. It is a system that does not require trust (uniqueness+identity) to function properly. In this I use the notion of "trust" similarly to the notion of "data integrity".
The blockchain was thus required to make the bitcoin protocol operational, so it delivers a single-use coin to an unidentified (pseudonymous) counterpart. It is a sophisticated architecture, even though it aims to reply to the two simple issues mentioned above.
For players who require high levels of integrity, without requiring a valid identity like for many financial use-cases (markets, digital goods...), the blockchain can be the protocol that they can use to satisfy these conditions. However, blockchains themselves are exposed to systemic risks, like anything else on the internet.
Computation scarcity
In order to secure the operations of the protocol, the inventors of bitcoin needed to attract the biggest number of unidentified contributors. In the absence of any identified trusted actor, there must be someone benevolent who can validate the transfer of the files, without being able to mess up with the file itself, i.e. the users are not required to trust anyone of network operators to handle properly the operations.
For the case of the bitcoin blockchain, there is no single entity to be trusted to run the operations, and thus is like the internet, not a very secure place to handle sensitive (or valuable) files.
The bitcoin network thus guarantees the integrity of the coin, via different mechanisms, including the blockchain which is exposed to 51% attacks. All protocols similar to bitcoin will be exposed to the same attack. It is the case when one single miner holds more than 51% of the global bitcoin's computation power, and thus is able to double-spend the same coin, or in other words make more copies of the same file valid. In order to mitigate this attack, the computation dedicated (mining and validating) must be propagated around the biggest number of players, i.e. miners who seek a financial reward, and validating nodes who seek to strengthen the network.
As counter-example, if we deploy a fresh blockchain that has few computers mining the coins, at first, our blockchain will be extremely vulnerable and can be manipulated by the most powerful operator handling the transfer of the files. In a network of two machines, it will be the machines with the more powerful CPU (or GPU). In the case of a whole network, we would need slightly more than an off-the-shelf hardware.
If we understand that computation worldwide is scarce, by default the "biggest" blockchain, the one to which the biggest number of computers are dedicating their computation power, is the most "secure" one. If we had infinite computation power, most of the blockchains would be equally secure for comprable consensus protocols, but in the real world computation is not unlimited or infinite, and is rather expensive since it implies physical investment and physical resources' consumption.
At this level we can safely assume that there is more than one single blockchain open for users. Amongst the many kinds of blockchains available on the internet, we can objectively compare their security by assessing the number of computers, or the hash rate, dedicated to the network.
Security by scale
We will talk here about "security by scale" rather than "security by design".
There are many solutions that provide security by design on the internet, and deliver in a much more efficient manner, given that at least one single operator is to be trusted. Read, blockchain-less Facebook blockchain.
In the absence of trusted operators, the bitcoin blockchain is the biggest player in terms of computation power, and thus is the most secure protocol that requires a blockchain to function properly.
In order to simplify this point, we can consider a company like Facebook and their partners running Libra, or any set of interconnected companies, well-idenitified with each other. If they want to send a valid file on their internal systems, it would be more expensive and slower for them to use a blockchain. However, if they need to interact with someone outside of their internal network (or infrastrcuture), using the external internet, they would require a robust protocol that is too expensive to maintain on their own.
If they choose to use bitcoin they will pay a fee, and in exchange enjoy the integrity of the data transferred. They can't trust the identity of the person they are intreacting with, or the entity operating the network, but this is not necessary. They only need to trust that the coin (unique version of file) is valid, according to the rules of the protocol, given that no one controls more than 51% of the computation dedicated to the network.
Fantasy VS Ecological efficiency
If one operator is trusted by everyone else, there is no valid - technical or economic - argument for a blockchain. Ecologically, the smallest the number of blockchains, the better it is for the environment.
For instance, for networks of speciliazed interest players like universities, hospitals or supply chain companies, there is little to no need for a similar architecture, unless they wish to not vet nor validate the identity of the operator of their service, which is harldy the case in daily business operations.
What is certain, it is that they will probably need to upgrade their networks and knowledge, in order to leverage the many possibilities of the internet, beyond email.
Unless someone wishes to build a highly innovative protocol that does not care about efficiency, and cares more about anonymity and integrity, then the usage of a blockchain might be justified. However, they will still be exposed to the lack of ciritical mass to secure their system.
To avoid a higher cost on the environment to sustain the biggest number of blockchains, there is a real ecological argument behind limiting the number of blockchains, and support the most secure option already available, if anyone absolutely has to.
The bitcoin blockchain can be a useful tool to secure the architecture of the internet, if the internet needs to relay highly valuable files. However, for most of the existent financial institutions like central banks and/or commerical banks, internally their architecture requires different tools, amaong many less energy-consuming options, to secure these operations.
If banks, or any internet user, needs to use the most secure network to interchange high-value files, to/from anyone with a digital address (idenitified or not), the bitcoin network can prove itself pretty useful.
From the internet's perspective, no other blcokchain can do better what the bitcoin network does best.
Privacy VS Identity
The report mentioned many failed attempts to establish an indentity standard on the internet, or any form of digital identity. Computers are indeed very bad at keeping track of identity in the legal sense of the term, if not the worst available option. It was simply not built for this use-case.
In the same vein, blockchains will not bring-in more trust, as the original implementation was conceived to limit the levels of trust required to run the service.
Companies like Facebook and Google understood this flaw, hence became the most reliable sources of acccurate digital identity. They are central gates, and collect the data available to build hollistic models of identity for their individual users.
Trustless system
If anyone is wondering what can be done in computer-based trust-less environments, the answer would to oberve the real world and deduce the behavior from it.
For instance, in the real world, most of the interactions and behavior we are bound-to are actually not demanding in terms of trust. We do not require to know the identity of the shop owner to buy something, nor do we need to wear bullet-proof jackets to have a walk in Görlizerpark. On the othre hand, we will need to know the identity of our landlord to send him the monthly rent transfer, and wear a bullet-proof jacket if we live in war-torn region.
We are bound to certain societal rules, however we can be free to adopt any behavior that does not infringe those rules, and build a chain of trust around our available freedom. Computer networks will simply make these free interactions faster, more "global", and maybe more permanent.
In addition to emails, videos and long blog posts like this one, the internet, with its subset of blockchain-based protocols, will be able to deliver more sensible operations like trade, markets, securitization given that the actors accept to not need to trust/know each other, nor trust a central authority, if they use something like bitcoin.
There is little to no-doubt that citizens and attentive educated consumers will choose the most reliable institution if they have to trust one, pick the most privacy-friendly service-provider is they have to choose one, and deposit their life-savings at the most secured bank, because they will need one.
Regulating trust
Since here we are dealing with regulators who care about the well-being of their people to face a new kind of systems, we can point to the safest options so these new systems can not be mis-used or exploited by hostile actors.
In regards to the existent regulations in-place, for a user who wishes to send a small amount of money using the global internet, the bitcoin protocol provides the best available security, least risky and most reliable, without infringing the privacy of the users. Actually by using the bitcoin protocol directly, we are assured that very little data has been collected. Trustworthy and hostile actors will be equally incapable of exploiting the data fed into the protocol.
Other blockchains might provide more private services, but from a critical-mass perspective there will be compromises to be made.
In regards to the players who want to use the most reliable technology, and at the same time prove their good behavior and compliance to the rules, blockchains will be audit-friendly systems where little to nothing is hidden. It is a very minimalistic system to which we can add up layers for notarial and control purposes. Nothing can stop private companies from using the bitcoin protocol, even though they need to enforce further identification and compliance with local regulations.
Here, the blockchains, as a sub-set of the internet, will also act like logging machines which will store plenty of data, in relation to their operations. In exchange of this data, the machines will provide a better service, where better can mean faster, or more secure, or else...
Contingent risks
The struggle in modern systems has always evolved between two edges of the same spectrum.
Interconnected machines produce a lot of data, and none, or very little, of this data can be entrusted to data hoarders. It is very easy to collect the bare minimum data, and equally easy to harvest the biggest amount of data, say related to a user, or an institution.


In this context, the best systems are either the ones who do not wish to collect any data and focus on specific applications (or services); or the ones which require the biggest amount of data available, with the commercial intent of providing services around this data.
Since blockchains are a sub-set of the internet that delivers a specific kind of computed behavior, the risk for the blockchain user is the same, i.e. to be enticed by a private non-regulated company, to deliver the biggest number of behavioral points, with the objective of selling an accurate digital identity.
If we are talking about the financial sector, or the healthcare sector, we will deal with very sensitive personal information, that is preferably not exposed (intentionally or not) to the internet.
For the German regulator, the priority is to best protect the interest of the German citizen, and to only enable the least infringing services.
Incremental knowledge
If for anything, the discussion around blockchains brought up legitimate questions, as mentioned in the report.
The regulators start to talk about distributed public key management infrastructures, and they start to foresee the need for better security measures, and regulation, around the digital realm. Blockchain being a small subset of the cyber planet, we witness here a collective progress in the understanding of the categories of digital things, and the respective risks for each category.
The regulator must acquire the means and knowledge to inform the general public, and teach them the safest ways to handle their digital lives, as this part becomes more-and-more prevalent and necessary in our daily dealings.
Standard
Since the internet provides a profusion of solutions that aim to reply to the problems that we face in our daily lives, and to deliver the communication that ensues this problem-solving, there must be here an opportunity to set up a standard for commerical and financial exchanges in an internet-native fashion.
The report spoke extensively about interchangibilty and interoperability of digital goods (securities, coins...), and that is an obvious path that the internet will eventually enforce.
Maybe there is a need for a global standard of currency (coinage); and if there is one, we might consider - objectively - to use the most secure blockchain available.
Article's Background
I wish for this blog post to provide a complementary understanding to the federal government's report.
In order to provide the best counsel available to our exigent stakeholders, we have been involved since 2015 in research and development, and have directly collaborated with elite IT researchers, professionals from tier-1 banking organizations, select technology providers and regulators.
Vink-io UG, home of Bitdinar and btndlabs.io, is based in Berlin and operating from Berlin and Tunis.