Reducing Replica Coordination in BFT Consensus through Dependable and Secure In-Network Message Ordering
DOI:
https://doi.org/10.5753/jisa.2026.7765Keywords:
Consensus, Distributed Algorithms, Intrusion toleranceAbstract
Programmable networks enable the deployment of in-network ordering services that can improve the performance of consensus protocols. However, existing approaches either tolerate only crash faults or require additional replica coordination to handle Byzantine failures, limiting their performance gains. In this work, we present NsoBFT, a Byzantine fault-tolerant (BFT) consensus protocol that leverages secure in-network ordering through a USIG (Unique Sequential Identifier Generator)-based message ordering service deployed at the network layer. The ordering service is implemented using Network Functions Virtualization (NFV), allowing it to operate as a virtualized network function that provides isolation and flexible integration into modern infrastructures. By combining NFV-based in-network sequencing with a USIG-protected sequencer, NsoBFT eliminates the extra replica confirmation step required by prior BFT in-network protocols, shortening the critical execution path while preserving consensus safety and liveness properties. We implemented NsoBFT and evaluated it against NeoBFT and NOPaxos, two representative in-network consensus protocols. Experimental results show that NsoBFT consistently achieves lower latency and higher throughput than NeoBFT, significantly narrowing the performance gap between crash-tolerant and Byzantine-tolerant in-network consensus.
Downloads
References
Alchieri, E. A. P., Bessani, A., Greve, F., and Fraga, J. d. S. (2018). Knowledge connectivity requirements for solving byzantine consensus with unknown participants. IEEE Transactions on Dependable and Secure Computing, 15(2):246-259. DOI: 10.1109/tdsc.2016.2548460.
Bessani, A., Sousa, J., and Alchieri, E. E. P. (2014). State machine replication for the masses with bft-smart. In International Conference on Dependable Systems and Networks, pages 355-362. IEEE. DOI: 10.1109/dsn.2014.43.
Boubendir, A., Bertin, E., and Simoni, N. (2018). Flexibility and dynamicity for open network-as-a-service: From vnf and architecture modeling to deployment. In NOMS 2018-2018 IEEE/IFIP Network Operations and Management Symposium, pages 1-6. IEEE. DOI: 10.1109/noms.2018.8406135.
Bravo, M., Chockler, G., and Gotsman, A. (2022). Making byzantine consensus live. Distributed Computing, 35(6). DOI: 10.1007/s00446-022-00432-y.
Burrows, M. (2006). The chubby lock service for loosely coupled distributed systems. In The 7th Symposium on Operating Systems Design and Implementation. DOI: 10.5555/1298455.1298487.
Cachin, C., Kursawe, K., Petzold, F., and Shoup, V. (2001). Secure and efficient asynchronous broadcast protocols. In Advances in Cryptology - CRYPTO 2001, volume 2139 of Lecture Notes in Computer Science, pages 524-541. Springer. DOI: 10.1007/3-540-44647-8_31.
Castro, M. and Liskov, B. (1999). Practical byzantine fault tolerance. In Symposium on Operating Systems Design and Implementation, pages 173-186. USENIX. DOI: 10.5555/296806.296824.
Castro, M. and Liskov, B. (2002). Practical Byzantine fault-tolerance and proactive recovery. ACM Transactions on Computer Systems, 20(4):398-461. DOI: 10.1145/571637.571640.
da Rocha, G. F. L., Alchieri, E. A. P., Venâncio, G., Fulber-Garcia, V., and Duarte Jr., E. P. (2026). Byzantine consensus with secure and intrusion-tolerant in-network ordering. In Rodrigues, L. A. and Oliveira, R., editors, Latin American Dependable and Secure Computing (LADC), pages 148-162, Cham. Springer Nature Switzerland. DOI: 10.1007/978-3-032-11539-3_9.
Dang, H. T., Bressana, P., Wang, H., Lee, K. S., Zilberman, N., Weatherspoon, H., Canini, M., Pedone, F., and Soulé, R. (2020). P4xos: Consensus as a network service. IEEE/ACM Transactions on Networking, 28(4):1726-1738. DOI: 10.1109/tnet.2020.2992106.
Douceur, J. R. (2002). The sybil attack. In International Workshop on Peer-to-Peer Systems, pages 251-260. Springer. DOI: 10.1007/3-540-45748-8_24.
Dwork, C., Lynch, N. A., and Stockmeyer, L. (1988). Consensus in the presence of partial synchrony. Journal of ACM, 35(2):288-322. DOI: 10.1145/42282.42283.
ETSI Industry Specification Group (ISG) NFV (2024). Network functions virtualisation (nfv) release 4; management and orchestration; architectural framework specification. Group Specification GS NFV 006 v4.5.1, European Telecommunications Standards Institute (ETSI). Available at:[link].
Fischer, M. J., Lynch, N. A., and Paterson, M. S. (1985). Impossibility of distributed consensus with one faulty process. Journal of the ACM, 32(2):374-382. DOI: 10.1145/3149.214121.
Freitas, A. E. S., Rodrigues, L. A., and Duarte Jr, E. P. (2024). vcubechain: A scalable permissioned blockchain. Ad Hoc Networks, 158:103461. DOI: 10.1016/j.adhoc.2024.103461.
Fulber-Garcia, V., Duarte Jr, E. P., Huff, A., and dos Santos, C. R. (2020). Network service topology: Formalization, taxonomy and the custom specification model. Computer Networks, 178:107337. DOI: 10.1016/j.comnet.2020.107337.
Hadzilacos, V. and Toueg, S. (1994). A modular approach to the specification and implementation of fault-tolerant broadcasts. Technical report, Department of Computer Science, Cornell University, New York - USA. Available at:[link].
Halpern, J. M. and Pignataro, C. (2015). Service Function Chaining (SFC) Architecture. (7665). DOI: 10.17487/RFC7665.
Hunt, P., Konar, M., Junqueira, F. P., and Reed, B. (2010). $$ZooKeeper$$: Wait-free coordination for internet-scale systems. In USENIX Annual Technical Conference. Available at:[link].
J. C. Corbett, J. D. and et al, M. E. (2012). Spanner: Google's globally distributed database. In The 10th Symposium on Operating Systems Design and Implementation. DOI: 10.1145/2491245.
Kaur, K., Mangat, V., and Kumar, K. (2022). A review on virtualized infrastructure managers with management and orchestration features in nfv architecture. Computer Networks, 217:109281. DOI: 10.1016/j.comnet.2022.109281.
Lamport, L. (1998). The part-time parliament. ACM Transactions on Computer Systems, 16(2):133-169. DOI: 10.1145/279227.279229.
Li, C., Qiu, W., Li, X., Liu, C., and Zheng, Z. (2024). A dynamic adaptive framework for practical byzantine fault tolerance consensus protocol in the internet of things. IEEE Transactions on Computers, 73(7):1669-1682. DOI: 10.1109/tc.2024.3377921.
Li, J., Michael, E., Sharma, N. K., Szekeres, A., and Ports, D. R. (2016). Just say $$NO$$ to paxos overhead: Replacing consensus with network ordering. In Symposium on Operating Systems Design and Implementation, pages 467-483. USENIX. DOI: 10.5555/3026877.3026914.
Liu, X. and Yu, W. (2024). A review of research on blockchain consensus mechanisms and algorithms. In International Conference on Intelligent Informatics and Biomedical Sciences, volume 9, pages 1-10. DOI: 10.1109/iciibms62405.2024.10792685.
Mijumbi, R., Serrat, J., Gorricho, J.-L., Bouten, N., De Turck, F., and Boutaba, R. (2016). Network function virtualization: State-of-the-art and research challenges. IEEE Communications Surveys & Tutorials, 18(1):236-262. DOI: 10.1109/COMST.2015.2477041.
Ongaro, D. and Ousterhout, J. (2014). In search of an understandable consensus algorithm. In USENIX annual technical conference (USENIX ATC 14), pages 305-319. Available at:[link].
Saramago, R. Q., Alchieri, E. A., Rezende, T. F., and Camargos, L. (2018). On the impossibility of byzantine collision-fast atomic broadcast. In International Conference on Advanced Information Networking and Applications, pages 414-421. IEEE. DOI: 10.1109/aina.2018.00069.
Schneider, F. B. (1990). Implementing fault-tolerant services using the state machine approach: A tutorial. ACM Computing Surveys, 22(4):299-319. DOI: 10.1145/98163.98167.
Singh, A., Kumar, G., Saha, R., Conti, M., Alazab, M., and Thomas, R. (2022). A survey and taxonomy of consensus protocols for blockchains. Journal of Systems Architecture, 127:102503. DOI: 10.1016/j.sysarc.2022.102503.
Sousa, J. and Bessani, A. (2012). From byzantine consensus to bft state machine replication: A latency-optimal transformation. In Proceedings of the 9th European Dependable Computing Conference (EDCC), pages 37-48. IEEE. DOI: 10.1109/EDCC.2012.32.
Sun, G., Jiang, M., Khooi, X. Z., Li, Y., and Li, J. (2023). NeoBFT: Accelerating byzantine fault tolerance using authenticated in-network ordering. In ACM Special Interest Group on Data Communications Conference, page 239–254, New York, NY, USA. ACM. DOI: 10.1145/3603269.3604874.
Vassantlal, R., Alchieri, E., Ferreira, B., and Bessani, A. (2022). Cobra: Dynamic proactive secret sharing for confidential bft services. In Symposium on Security and Privacy, pages 1335-1353. IEEE. DOI: 10.1109/sp46214.2022.9833658.
Venâncio, G., Fulber-Garcia, V., Flauzino, J., Alchieri, E. A., and Duarte, E. P. (2024). Dependable virtual network services: An architecture for fault-and intrusion-tolerant sfcs. In Conference on NFV and SDN, pages 1-6. IEEE. DOI: 10.1109/nfv-sdn61811.2024.10807480.
Venâncio, G., Garcia, V. F., da Cruz Marcuzzo, L., Tavares, T. N., Franco, M. F., Bondan, L., Schaeffer-Filho, A. E., Paula dos Santos, C. R., Granville, L. Z., and P. Duarte Jr, E. (2021a). Beyond vnfm: Filling the gaps of the etsi vnf manager to fully support vnf life cycle operations. International Journal of Network Management, 31(5):e2068. DOI: 10.1002/nem.2068.
Venâncio, G., Turchetti, R. C., Camargo, E. T., and Duarte Jr, E. P. (2021b). Vnf-consensus: A virtual network function for maintaining a consistent distributed software-defined network control plane. International Journal of Network Management, 31(3). DOI: 10.1002/nem.2124.
Venâncio, G., Turchetti, R. C., and Duarte, E. P. (2019). Nfv-rbcast: Enabling the network to offer reliable and ordered broadcast services. In The 9th Latin-American Symposium on Dependable Computing, pages 1-10. IEEE. DOI: 10.1109/ladc48089.2019.8995681.
Venâncio, G., Turchetti, R. C., and Duarte Jr, E. P. (2022). Nfv-coin: unleashing the power of in-network computing with virtualization technologies. Journal of Internet Services and Applications, 13(1):46-53. DOI: 10.5753/jisa.2022.2342.
Veronese, G. S., Correia, M., Bessani, A. N., Lung, L. C., and Verissimo, P. (2013). Efficient byzantine fault-tolerance. IEEE Transactions on Computers, 62(1):16-30. DOI: 10.1109/tc.2011.221.
Vukolić, M. (2015). The quest for scalable blockchain fabric: Proof-of-work vs. bft replication. In IFIP WG 11.4 International Workshop Open Problems in Network Security, pages 112-125. Springer. DOI: 10.1007/978-3-319-39028-4_9.
White, B., Lepreau, J., Stoller, L., Ricci, R., Guruprasad, S., Newbold, M., Hibler, M., Barb, C., and Joglekar, A. (2002). An integrated experimental environment for distributed systems and networks. ACM SIGOPS Operating Systems Rev., 36(SI):255-270. DOI: 10.1145/844128.844152.
Zou, Y., Yang, L., Jing, G., Zhang, R., Xie, Z., Li, H., and Yu, D. (2024). A survey of fault tolerant consensus in wireless networks. High-Confidence Computing, 4(2). DOI: 10.1016/j.hcc.2024.100202.
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Journal of Internet Services and Applications

This work is licensed under a Creative Commons Attribution 4.0 International License.

