Articulo de referencia

El problema de los dos generales

Posiciones de los ejércitos. Los ejércitos A1 y A2 no pueden verse directamente, por lo que necesitan comunicarse mediante mensajeros, pero estos podrían ser capturados por el e...

Posiciones de los ejércitos. Los ejércitos A1 y A2 no pueden verse directamente, por lo que necesitan comunicarse mediante mensajeros, pero estos podrían ser capturados por el ejército B.

En informática, el Problema de los Dos Generales (o Problema de los Generales Chinos [ 1 ] ) es un experimento mental que ilustra las dificultades y los desafíos de diseño que implica coordinar una acción mediante la comunicación a través de un enlace poco fiable. En el experimento, dos generales solo pueden comunicarse enviando un mensajero a través de territorio enemigo. El experimento plantea cómo podrían llegar a un acuerdo sobre el momento de lanzar un ataque, sabiendo que cualquier mensajero que envíen podría ser capturado.

El problema de los dos generales aparece a menudo como introducción al problema más general de los generales bizantinos en cursos introductorios sobre redes informáticas (en particular con respecto al Protocolo de Control de Transmisión , donde muestra que TCP no puede garantizar la consistencia de estado entre los puntos finales y por qué es así), aunque se aplica a cualquier tipo de comunicación entre dos partes donde sean posibles fallos de comunicación. Un concepto clave en la lógica epistémica , este problema resalta la importancia del conocimiento común . Algunos autores también se refieren a esto como la paradoja de los dos generales , el problema de los dos ejércitos o el problema del ataque coordinado . [ 2 ] [ 3 ] El problema de los dos generales fue el primer problema de comunicación informática que se demostró irresoluble. [ 4 ] Una consecuencia importante de esta demostración es que las generalizaciones como el problema de los generales bizantinos también son irresolubles frente a fallos de comunicación arbitrarios, proporcionando así una base de expectativas realistas para cualquier protocolo de consistencia distribuida.

Definición

Dos ejércitos , cada uno liderado por un general diferente , se preparan para atacar una ciudad fortificada. Los ejércitos están acampados cerca de la ciudad, cada uno en su propio valle. Un tercer valle separa las dos colinas, y la única forma en que los dos generales pueden comunicarse es enviando mensajeros a través del valle. Desafortunadamente, el valle está ocupado por los defensores de la ciudad y existe la posibilidad de que cualquier mensajero enviado a través de él sea capturado. [ 5 ]

While the two generals have agreed that they will attack, they haven't agreed upon a time for an attack. It is required that the two generals have their armies attack the city simultaneously to succeed, lest the lone attacker army die trying. They must thus communicate with each other to decide on a time to attack and to agree to attack at that time, and each general must know that the other general knows that they have agreed to the attack plan. Because acknowledgement of message receipt can be lost as easily as the original message, a potentially infinite series of messages is required to come to consensus.[6]

The thought experiment involves considering how they might go about coming to a consensus. In its simplest form, one general is known to be the leader, decides on the time of the attack, and must communicate this time to the other general. The problem is to come up with algorithms that the generals can use, including sending messages and processing received messages, that can allow them to correctly conclude:

Yes, we will both attack at the agreed-upon time.

Allowing that it is quite simple for the generals to come to an agreement on the time to attack (i.e. one successful message with a successful acknowledgement), the subtlety of the Two Generals' Problem is in the impossibility of designing algorithms for the generals to use to safely agree to the above statement.

Illustrating the problem

The first general may start by sending a message: "Attack at 0900 on August 4." However, once dispatched, the first general has no idea whether or not the messenger got through. This uncertainty may lead the first general to hesitate to attack due to the risk of being the sole attacker.

To be sure, the second general may send a confirmation back to the first: "I received your message and will attack at 0900 on August 4." However, the messenger carrying the confirmation could face capture, and the second general may hesitate, knowing that the first might hold back without the confirmation.

Further confirmations may seem like a solution—let the first general send a second confirmation: "I received your confirmation of the planned attack at 0900 on August 4." However, this new messenger from the first general is liable to be captured, too. Thus, it quickly becomes evident that no matter how many rounds of confirmation are made, there is no way to guarantee the second requirement that each general is sure the other has agreed to the attack plan. Both generals will always be left wondering whether their last messenger got through.[7]

Proof

Because this protocol is deterministic, suppose there is a sequence of a fixed number of messages, one or more successfully delivered and one or more not. The assumption is that there should be a shared certainty for both generals to attack. Consider the last such message that was successfully delivered. If that last message had not been successfully delivered, then one general at least (presumably the receiver) would decide not to attack. From the viewpoint of the sender of that last message, however, the sequence of messages sent and delivered is exactly the same as it would have been, had that message been delivered. Since the protocol is deterministic, the general sending that last message will still decide to attack. We've now created a situation where the suggested protocol leads one general to attack and the other not to attack—contradicting the assumption that the protocol was a solution to the problem.

A non-deterministic protocol with a potentially variable message count can be compared to an edge-labeled finite tree, where each node in the tree represents an explored example up to a specified point. A protocol that terminates before sending any messages is represented by a tree containing only a root node. The edges from a node to each child are labeled with the messages sent in order to reach the child state. Leaf nodes represent points at which the protocol terminates. Suppose there exists a non-deterministic protocol P which solves the Two Generals' Problem. Then, by a similar argument to the one used for fixed-length deterministic protocols above, P' must also solve the Two Generals' Problem, where the tree representing P' is obtained from that for P by removing all leaf nodes and the edges leading to them. Since P is finite, it then follows that the protocol that terminates before sending any messages would solve the problem. But clearly, it does not. Therefore, a non-deterministic protocol that solves the problem cannot exist.

Engineering approaches

A pragmatic approach to dealing with the Two Generals' Problem is to use schemes that accept the uncertainty of the communications channel and not attempt to eliminate it, but rather mitigate it to an acceptable degree. For example, the first general could send 100 messengers, anticipating that the probability of all being captured is low. With this approach, the first general will attack no matter what, and the second general will attack if any message is received. Alternatively, the first general could send a stream of messages and the second general could send acknowledgments to each, with each general feeling more comfortable with every message received. As seen in the proof, however, neither can be certain that the attack will be coordinated. There is no algorithm that they can use (e.g. attack if more than four messages are received) that will be certain to prevent one from attacking without the other. Also, the first general can send a marking on each message saying it is message 1, 2, 3 ... of n. This method will allow the second general to know how reliable the channel is and send an appropriate number of messages back to ensure a high probability of at least one message being received. If the channel can be made to be reliable, then one message will suffice and additional messages do not help. The last is as likely to get lost as the first.

Assuming that the generals must sacrifice lives every time a messenger is sent and intercepted, an algorithm can be designed to minimize the number of messengers required to achieve the maximum amount of confidence the attack is coordinated. To save them from sacrificing hundreds of lives to achieve very high confidence in coordination, the generals could agree to use the absence of messengers as an indication that the general who began the transaction has received at least one confirmation and has promised to attack. Suppose it takes a messenger 1 minute to cross the danger zone, allowing 200 minutes of silence to occur after confirmations have been received will allow us to achieve extremely high confidence while not sacrificing messenger lives. In this case, messengers are used only in the case where a party has not received the attack time. At the end of 200 minutes, each general can reason: "I have not received an additional message for 200 minutes; either 200 messengers failed to cross the danger zone, or it means the other general has confirmed and committed to the attack and has confidence I will too".

History

The Two Generals' Problem and its impossibility proof was first published by E. A. Akkoyunlu, K. Ekanadham, and R. V. Huber in 1975 in "Some Constraints and Trade-offs in the Design of Network Communications",[8] where it is described starting on page 73 in the context of communication between two groups of gangsters.

This problem was given the name the Two Generals Paradox by Jim Gray[9] in 1978 in "Notes on Data Base Operating Systems"[10] starting on page 465. This reference is widely given as a source for the definition of the problem and the impossibility proof, though both were published previously as mentioned above.

References

  1. Lamport, Leslie; Shostak, Robert; Pease, Marshall (1982-07-05). "The Byzantine Generals Problem". ACM Transactions on Programming Languages and Systems: 382–401.
  2. Gmytrasiewicz, Piotr J.; Edmund H. Durfee (1992). "Decision-Theoretic Recursive Modeling and the Coordinated Attack Problem". Artificial Intelligence Planning Systems. San Francisco: Morgan Kaufmann Publishers. pp. 88–95. doi:10.1016/B978-0-08-049944-4.50016-1. ISBN 9780080499444. Retrieved 27 December 2013.{{cite book}}: |journal= ignored (help)
  3. The coordinated attack and the jealous amazons Alessandro Panconesi. Retrieved 2011-05-17.
  4. Leslie Lamport. "Solved Problems, Unsolved Problems and Non-Problems in Concurrency". 1983. p. 8.
  5. Ruby, Matt. "How the Byzantine General's Problem Relates to You in 2024". Swan Bitcoin. Retrieved 2024-02-16.
  6. "The Byzantine Generals Problem (Consensus in the presence of uncertainties)"(PDF). Imperial College London. Retrieved 16 February 2024.
  7. Lamport, Leslie; Shostak, Robert; Pease, Marshall. "The Byzantine Generals Problem"(PDF). SRI International. Retrieved 16 February 2024.
  8. Akkoyunlu, E. A.; Ekanadham, K.; Huber, R. V. (1975). Some constraints and trade-offs in the design of network communications. Portal.acm.org. pp. 67–74. doi:10.1145/800213.806523. S2CID 788091. Retrieved 2010-03-19.
  9. "Jim Gray Summary Home Page". Research.microsoft.com. 2004-05-03. Retrieved 2010-03-19.
  10. R. Bayer, R. M. Graham y G. Seegmüller (1978). Sistemas operativos . Springer-Verlag. págs. 393–481 . ISBN  0-387-09812-7.{{cite book}}: CS1 maint: varios nombres: lista de autores ( enlace ) Versión en línea: Notas sobre sistemas operativos de bases de datos . Portal.acm.org. Enero de 1978. págs. 393–481 . ISBN  978-3-540-08755-7. Consultado el 19 de marzo de 2010 .

Véase también