LibraryConsensus1988Design paperCorpus record
Consensus in the Presence of Partial Synchrony
Partial Synchrony. Cynthia Dwork, Nancy Lynch and Larry Stockmeyer.
Safety can hold with no timing assumption. Liveness can wait for a period, after some unknown instant, when messages arrive within a bound.
A reading of the public document. Not a copy of it, and not a claim about a later network that reused the name.
Ask a BFT designer which property dies when packets are late. If the answer is safety, they are not in this model.
The five-minute read
The defect
Fully asynchronous consensus with even one fault is impossible, and a fully synchronous network is a fairy tale.
The rule
Safety can hold with no timing assumption. Liveness can wait for a period, after some unknown instant, when messages arrive within a bound.
How it is put together
The GST, the global stabilisation time, is unknown to the protocol. Timeouts can be used for liveness without being used for safety. The model sits between FLP and a lockstep network.
Where the claim stops
Partial synchrony is a model, not a product.
One action, walked through
- Processes propose. Agreement and validity are required even while the network is wild.
- After GST, honest messages get through and a decision is reached.
- A protocol that forks when messages are late has put safety on the clock.
- Does a committed decision ever roll back when messages are delayed?
The argument, unpacked
Why it is still on the desk
Ask a BFT designer which property dies when packets are late. If the answer is safety, they are not in this model.
After the text
PBFT and HotStuff cite this split. Nakamoto consensus does not: its confirmation is probabilistic and timing is the security assumption.
What has to be true
- Partial synchrony is a model, not a product.
- It does not excuse a chain that reorgs committed blocks.
- Timeouts in the implementation may be cruder than the model.
What happened after the paper
PBFT and HotStuff cite this split. Nakamoto consensus does not: its confirmation is probabilistic and timing is the security assumption.
What to check before you use the idea
- Does a committed decision ever roll back when messages are delayed?
- Is the bound known, or only eventually true?
- What is the fault threshold in the model they claim?
Terms
- GST
- An unknown time after which the network behaves for long enough.
- Safety
- Two honest parties never decide differently.
The problem the paper names
Fully asynchronous consensus with even one fault is impossible, and a fully synchronous network is a fairy tale.
What the design proposes
- The GST, the global stabilisation time, is unknown to the protocol.
- Timeouts can be used for liveness without being used for safety.
- The model sits between FLP and a lockstep network.
How the mechanism is specified
- Processes propose. Agreement and validity are required even while the network is wild.
- After GST, honest messages get through and a decision is reached.
- A protocol that forks when messages are late has put safety on the clock.
What this page does not treat as proven
- Partial synchrony is a model, not a product.
- It does not excuse a chain that reorgs committed blocks.
- Timeouts in the implementation may be cruder than the model.
Why a venture studio still reads it
Ask a BFT designer which property dies when packets are late. If the answer is safety, they are not in this model.
This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.
Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.
