{"id":"2075e267-c8a2-411a-98ca-7784a30972cd","arxiv_id":"2412.10722","paper_version":1,"verdict":"REJECT","confidence":"HIGH","novelty_score":3.0,"correctness_risk":"high","formal_verification":"none","parameter_count":1,"one_line_summary":"The paper claims IP networks are inherently insecure and unable to evolve, and proposes the CoG-MIN architecture with blockchain governance and cyberspace customs as a complete replacement, backed by self-reported tests and unsupported theorems.","lead":"This paper proposes CoG-MIN, a blockchain-governed network architecture that would replace IP addressing with multi-identifier management, cyberspace customs, and built-in user authentication. It argues that IP has three 'genetic defects' and presents a trilogy of security theorems intended to prove deterministic security is impossible on IP but possible on MIN.","discovery_kind":"extension","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Theorem B's 4.8e15-year estimate is the load-bearing support for MIN's claimed exponential security, and it is deferred to a self-authored monograph rather than derived in this paper.","rationale":"In good faith, the paper has real components worth credit: MIN is a concrete prototype with published pieces (MIS, MIR, MIN-VPN), some refereed references, and a plausible compatibility story for TLV-based identifier evolution. The Section 4 competition outcomes, while anecdotal, are at least direct evidence that in controlled settings the system was not publicly broken. These count in the paper's favor.\n\nHowever, the strongest claim, the one the abstract and conclusion lean on, is quantitative security superiority: 'deterministic security' with 'exponential increase' over IP. The only numerical support is the 4.8e15-years figure in Theorem B, deferred to the authors' own monograph. This is not an internal contradiction in MIN, but it makes the central security theorem unevaluable from the submitted manuscript; the reader cannot distinguish a rigorous estimate from a rhetorical number. That is the single most load-bearing spot: if the deferred derivation is missing or rests on unrealistic assumptions, the paper's central claim collapses; if the derivation is valid and robust, the claim would be supported, but the current paper does not show either.\n\nThe reader's REJECT is justified by these evidentiary gaps. Our concern does not change that verdict; it sharpens the reason. We set verdict_should_be UNCHANGED and agreement_with_reader PARTIAL because the reader identified both the Theorem B citation and the universal-participation assumption (Sec. 3.5); we single out Theorem B as the decisive one, while acknowledging the adoption assumption is a separate coordination/sociological risk that would also need to be addressed for real-world deployment.","tokens_in":20842,"tokens_out":3846,"duration_ms":36468,"concrete_test":"Obtain the monograph [17] (Li & Yang 2021, Springer) and independently reconstruct Section 4.7.5. Write down the martingale model's assumptions: per-attempt success probability p, attack rate lambda, number of attackers A, and the event whose expected time is 4.8e15 years. Recompute that expectation, then rerun it under a parallel-attacker scenario (e.g., A=1000 simultaneous attackers), an insider or stolen-biometric-credential scenario, and a device/key-compromise scenario. If the monograph's model omits these cases, or if the recomputed value drops by more than one order of magnitude under realistic parameters, the exponential-improvement claim is unsupported.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The paper's central claim is that MIN offers deterministic security and an exponential improvement over IP. The quantitative part of that claim is Theorem B (Sec. 5.2): breaching a MIN private network is estimated to take approximately 4.8e15 years 'under some normal scenario,' using a martingale stochastic process model. The derivation is not included; it is referred to Section 4.7.5 of the authors' own monograph [17]. No adversary model, attack rate, per-attempt success probability, parallelism, insider/adversary capabilities, or key-compromise assumptions are stated, so the number cannot be checked, falsified, or compared with IP. The empirical support in Section 4 is not a substitute: the competition results are self-reported aggregates without raw data, attack budgets, or a formal attack model, and 'unbreached' outcomes cannot establish a rate. Theorem A (Sec. 5.1) is also a non sequitur: 'the United States has not implemented S1' does not imply 'no technical solution exists.' Thus the central security claim is not established; the decisive quantitative assertion rests on an unsupported citation to an external work.","agreement_with_reader":"partial"},"referee_report":{"model":"deepseek-v4-flash","summary":"This manuscript proposes a Co-governed Multi-Identifier Network (CoG-MIN, abbreviated MIN) as a next-generation network architecture intended to address what the authors call the three 'genetic defects' of IP: unilateral governance, lack of intrinsic security, and architectural rigidity. The paper describes the MIN architecture, including a hierarchical consortium-blockchain-based identifier system (MIS), a multi-identifier router (MIR), a biometric-identity-based authentication and traceability layer, and a 'Cyberspace Customs' border-control protocol. It reports prototype deployments and results from security competitions, and it states a 'trilogy' of results: Theorem A claims no deterministic security solution exists within IP, Theorem B claims MIN (or a similar future architecture) provides an exponential security improvement with an estimated time-to-breach of approximately 4.8e15 years, and Conjecture C proposes that deterministic security can be achieved. The paper's central claim is that MIN is a viable technical basis for global cyberspace governance. The security theorems are not mathematically established in the manuscript as written.","tokens_in":21109,"tokens_out":4367,"duration_ms":38262,"significance":"The potential significance of a viable architecture that provides traceability, co-governance, and strong security would be considerable, and the manuscript does describe a concrete, partially implemented system with some real deployment activity. Credit is due for the breadth of prototype testing reported and for the explicit attempt to connect technical design with governance. However, the core theoretical claims are not substantiated. Theorem A is a non sequitur, Theorem B's quantitative estimate is deferred to an unattached and self-authored source, and the empirical evidence is self-reported without a controlled comparison or raw data. The concept of 'deterministic security' is never formally defined, so the central assertions are not falsifiable in their present form. Given that the quantitative security claim is load-bearing and unsupported, the paper does not meet the evidentiary standard for its conclusions.","major_comments":[{"comment":"The proof of Theorem A is not a valid impossibility argument. From the premise that the United States has not implemented a deterministic security solution for IP, the text concludes that 'the probability of any other nation achieving it within the IP framework is effectively zero' and hence that no such solution exists. This is a non sequitur: absence of implementation by one actor is not evidence of impossibility, and no exhaustive enumeration of candidate solutions is provided. The manuscript also does not define what 'deterministic security' means, so the theorem's statement is not precise enough to prove. Consequently, the claimed unsolvability of IP security is not established.","section":"§5.1, Theorem A"},{"comment":"The central quantitative claim—that breaching a MIN private network requires approximately 4.8e15 years—is not derived in this manuscript. The text refers the reader to Section 4.7.5 of reference [17], a self-authored monograph, for the 'detailed proof.' No adversary model, per-attempt success probability, attack rate, or parallelism assumption is specified, and no comparison baseline for IP is defined. As a result, the claimed 'exponential improvement' cannot be checked or falsified from the paper. A theorem whose proof is entirely contained in an inaccessible external source does not support the manuscript's conclusion.","section":"§5.2, Theorem B"},{"comment":"The empirical evidence for MIN's security is reported as aggregate competition statistics (e.g., 10,417,598 attacks over 25 days in one event) with no attack budget, no rules of engagement, no definition of 'compromise,' and no raw dataset. The statement that the system was 'unbreached' in these competitions is anecdotal and cannot establish a breach rate or a security guarantee. Without a controlled comparison in which the same adversaries were given equivalent time and resources against an IP-based baseline under identical scoring rules, the claim that MIN is 'significantly more secure' than IP is not supported.","section":"§4.3, Tables 3 and 4"},{"comment":"The traceability and law-enforcement claims rely on universal participation: every user must accept a real-name biometric identity, every state must operate Cyberspace Customs, and non-participating networks must agree to resolve disputes through the proposed cyberspace court. The manuscript does not analyze what happens when these assumptions fail (e.g., a state that declines to implement MIN, or a user who refuses biometric registration). Since the paper presents these governance features as part of the technical solution, the lack of a threat model for non-cooperation is a significant gap in the claimed 'rule of law, peace, and security.'","section":"§3.5 and §5.3"}],"minor_comments":[{"comment":"The notation in Equations (1)–(4) should be clarified: Equation (1) likely means a bitwise AND of UNIX time with 0xFFFFFFFFFFFFFFF0, and the 'xor' operation in Equations (3) and (4) is not defined for binary strings of potentially different lengths; please specify bit-lengths and key sizes.","section":"§3.4, Eqs. (1)-(4)"},{"comment":"The entry 'Non-intranet' in the IP-MIN column is unclear; please specify what was observed in those tests.","section":"§4.2, Table 2"},{"comment":"The Figure 3 caption uses 'PoV' while the text and reference [12] consistently use 'PPoV'; please harmonize the terminology.","section":"§3.2, Figure 3"},{"comment":"The phrase 'consistently appearing among the top 10 annually' lacks a referent (top 10 of which list or vulnerability index?) and is not a formal premise for the theorem.","section":"§5.1(b)"},{"comment":"The statements that MIN 'is about to enter the commercial stage in China' and 'has gradually become a standard' are strong factual claims; they should be supported by specific citable evidence.","section":"Abstract and §4.5"},{"comment":"Several substantial factual claims are cited to Wikipedia ([20]) or general news articles ([46]); please replace these with primary or peer-reviewed sources where possible.","section":"References"}],"recommendation":"reject","confidential_remarks":"The manuscript functions largely as a position paper advocating the authors' own architecture, and the self-referential citation pattern—most notably Theorem B's proof being deferred to the authors' own monograph—makes independent verification difficult. The paper would need to include complete derivations, formal definitions of 'deterministic security,' and independently audited empirical comparisons before it could be considered for publication. The emphasis on policy and advocacy also creates a questionable fit with a technical security journal."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"You asked about arXiv:2412.10722. The short version: this paper describes a real and ambitious network architecture, but the security theorems that carry its central argument don't hold up. Theorem A is a non sequitur, and Theorem B's headline number is an appeal to the authors' own monograph.\n\nWhat's actually here: a detailed proposal for a blockchain-governed multi-identifier network (MIN), with TLV packet formats, a cyberspace-customs border mechanism, biometric user identities, and a migration path from IP. The paper does a decent job of summarizing the familiar governance and security pathologies of IP, and the cited literature is real. The reported deployments and competition results suggest the group has built working prototypes, which is more than most such proposals can show.\n\nThe trouble starts in Section 5. Theorem A's proof by enumeration is simply not a proof. The fact that the US has not implemented a deterministic security solution does not imply no such solution exists; the premise is about resources and the conclusion is about possibility. Theorem B then asserts that breaching a MIN private network takes about 4.8e15 years, 'under some normal scenario,' and refers to Section 4.7.5 of the authors' own book. No adversary model, no per-attack success probability, no key-compromise or insider assumptions are given, so the number cannot be checked or compared with any IP baseline. The empirical section doesn't fill the gap: 'unbreached in a competition' is not a rate, and the results are self-reported aggregates without methodology or raw data.\n\nThe paper's broader claims — that MIN will end cyber warfare and is a natural progression of the internet — are advocacy, not argument. The assumption that every user will accept a real-name biometric identity and every state will cooperate in network customs enforcement is enormous and largely unaddressed.\n\nSo where does this leave the paper? If you want a survey of what MIN is and why its authors think it matters, it's a useful read. As a security contribution, it doesn't establish its central claims. I wouldn't cite it for the theorems, and I wouldn't publish it as is. But it deserves a real referee rather than a desk reject: the topic is important, the engineering is substantial, and the flaws are the kind a careful review should expose. I'd send it out, expect a reject, but with a report that tells the authors where the load-bearing gaps are.","headline":"A real architecture with unsupported security theorems — the load-bearing 4.8e15-year estimate is deferred, not derived.","tokens_in":21637,"tokens_out":3852,"would_cite":false,"duration_ms":34571,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"The paper claims that IP's three genetic defects—monopolized governance, missing intrinsic security, and rigidity—can be solved by a blockchain co-governed multi-identifier network that nations jointly manage.","keywords":["Co-governed Multi-Identifier Network","Internet governance","network security","blockchain","IP protocol","traceability","cyberspace sovereignty","identifier evolution"],"falsifier":"Run or inspect a red-team test against a MIN private network comparable to the paper's competitions and find a successful full compromise (e.g., remote control of a MIN-V2X vehicle or a forged cyberspace visa/passport accepted by a border router) with effort far below the claimed $4.8 \\times 10^{15}$ years; alternatively, recompute the Section 4.7.5 stochastic model from the monograph and show that the expected breach time is orders of magnitude smaller under the stated assumptions.","tokens_in":20615,"feed_emoji":"🔐","tokens_out":5435,"duration_ms":47298,"temperature":0.7,"pith_summary":"The paper argues that the Internet Protocol has three built-in defects—concentrated governance, no intrinsic mechanism to authenticate or trace packets, and a rigid architecture that resists change—and that none of them can be fixed from inside IP. It proposes the Co-governed Multi-Identifier Network (CoG-MIN, or MIN), a blockchain-based architecture in which nations jointly manage top-level identifiers, every packet is signed by a user bound to a real identity, and network borders are checked by cyberspace customs using passport and visa-style hashes. The paper claims a trilogy of results: deterministic security is impossible within IP, future architectures such as MIN can achieve exponential security improvements, and a combination of technical, managerial, legal, and insurance mechanisms could make cyberspace durably peaceful. If the claims hold, MIN offers a path from the current IP internet to a co-governed, traceable, evolvable network without a disruptive flag-day transition.","feed_headline":"Blockchain network CoG-MIN claims to fix IP's three genetic flaws","feed_subtitle":"If it works, nations co-govern the internet and every packet becomes traceable, ending anonymous attacks.","key_machinery":"The load-bearing mechanism is the Multi-Identifier System (MIS), a hierarchical consortium blockchain whose PPoV consensus algorithm is claimed to resolve the CAP trilemma and let countries co-manage top-level identifiers through voting. Around it, the paper builds the Multi-Identifier Router (MIR), TLV-encoded packets that support both push and pull semantics, a cyberspace customs layer that attaches visa and passport hashes to each packet, and a biometric identity registry that makes every signed packet traceable. This stack is what converts governance, security, and evolvability from add-on features into properties of the network layer itself.","core_discovery":"The central claim is that a complete network architecture, rather than added security protocols, is required to fix the internet. MIN replaces the IP narrow waist with a multi-identifier layer: identity, content, service, IP, and other identifiers coexist, encoded in TLV packets, and are routed by Multi-Identifier Routers (MIR) under the governance of a hierarchical consortium blockchain called the Multi-Identifier System (MIS). User identities are linked to real names and biometrics; packets are signed, activity is logged on-chain, and cyberspace customs issue visas and passports so countries can police their borders. On this basis the paper states Theorem A—no technical solution can give deterministic security inside IP—Theorem B—MIN-class architectures offer exponentially better security, quantified as roughly $4.8 \\times 10^{15}$ years to breach a MIN private network—and Conjecture C, that deterministic security can be realized by layering technology with management, law, and insurance. The paper presents competition and deployment evidence that MIN has so far remained unbreached.","pith_inferences":["Because the security estimate in Theorem B is deferred entirely to a cited monograph, the exponential claim stands or falls on a model the paper does not show; a reader should treat the $4.8 \\times 10^{15}$-year figure as an unverified derived result rather than a demonstrated fact.","Traceability depends on universal adoption of real-name biometric identity and on states operating customs and courts cooperatively; if a major state refuses, the architecture's security and co-governance properties degrade in ways the paper does not quantify.","The cyberspace customs idea—visa and passport hashes at network borders—is separable from the blockchain governance layer and could plausibly be adopted by any future network architecture that wants sovereign borders.","A testable extension: if MIN is deployed at scale, attack attribution times and cross-border incident costs should drop dramatically compared with IP, while states gain a new technical lever to block traffic from named foreign actors."],"forward_implications":["Countries could co-govern top-level identifiers through a voting mechanism, breaking the current concentration of control over address and domain allocation.","With every packet signed by a real-name, biometric identity and logged on-chain, attackers cannot hide behind spoofed addresses; misbehavior becomes attributable and repeat offenders can be permanently blocked.","MIN is IP-compatible: existing IP devices keep working, and IP packets are routed by MIRs, so the transition away from IP can be gradual and market-driven rather than a flag-day cutover.","Network-layer cyberspace customs give each state a technical border it can enforce, including real-time revocation of visas for malicious foreign users.","If Theorem B's stochastic estimate is right, a MIN private network would take on the order of $4.8 \\times 10^{15}$ years to breach under normal assumptions, an exponential gap over IP networks."],"supporting_citations":[{"why":"Provides the multi-identifier management and resolution system that is the core of MIN's co-governed identifier layer.","marker":"[11]"},{"why":"Supplies the consortium blockchain consensus algorithm that MIS uses to co-manage top-level identifiers.","marker":"[12]"},{"why":"Establishes the CAP-trilemma-solving blockchain framework that underlies the MIS design.","marker":"[13]"},{"why":"Defines the real-name, biometric-linked identity management that makes packets traceable.","marker":"[14]"},{"why":"Contains Section 4.7.5, the stochastic process model behind Theorem B's $4.8 \\times 10^{15}$-year breach estimate.","marker":"[17]"},{"why":"Defines the MIN packet types (Interest, Data, GPPkt) and the dual push/pull network-layer design.","marker":"[30]"},{"why":"Describes the Multi-Identifier Router that forwards packets across identifier types.","marker":"[34]"},{"why":"Presents the cyberspace customs protocol with visa and passport hashes that secures network borders.","marker":"[38]"}],"fun_headline_variants":["CoG-MIN claims to fix IP's three genetic flaws with blockchain","Blockchain network CoG-MIN aims to replace IP for secure, equal governance","CoG-MIN: multi-identifier network that claims unbreachable security","CoG-MIN: a blockchain fix for IP's power concentration and lack of security"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The load-bearing premise is that the stochastic process model in the cited monograph correctly predicts how long a MIN network takes to breach, and that every state will actually enforce real-name biometric identity and cyberspace customs; if either part fails, the paper's deterministic-security and exponential-improvement claims do not follow.","fun_headline_variants_meta":{"raw":{"variants":["CoG-MIN claims to fix IP's three genetic flaws with blockchain","Blockchain network CoG-MIN aims to replace IP for secure, equal governance","CoG-MIN: multi-identifier network that claims unbreachable security","CoG-MIN: a blockchain fix for IP's power concentration and lack of security"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.001072,"raw_usage":{"total_tokens":4554,"prompt_tokens":1071,"completion_tokens":3483,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":687,"completion_tokens_details":{"reasoning_tokens":3398}},"tokens_in":687,"tokens_out":3483,"duration_ms":24525,"temperature":1.0,"reasoning_tokens":3398,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-11T15:39:43.644086+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Run or inspect a red-team test against a MIN private network comparable to the paper's competitions and find a successful full compromise (e.g., remote control of a MIN-V2X vehicle or a forged cyberspace visa/passport accepted by a border router) with effort far below the claimed $4.8 \\times 10^{15}$ years; alternatively, recompute the Section 4.7.5 stochastic model from the monograph and show that the expected breach time is orders of magnitude smaller under the stated assumptions.","supporting_citations":[{"cited_title":"Mis: A multi-identifier management and resolution system in the metaverse","cited_arxiv_id":null,"evidence_quote":"Provides the multi-identifier management and resolution system that is the core of MIN's co-governed identifier layer."},{"cited_title":"A data lightweight scheme for parallel proof of vote consensus","cited_arxiv_id":null,"evidence_quote":"Supplies the consortium blockchain consensus algorithm that MIS uses to co-manage top-level identifiers."},{"cited_title":"Gbt-chain: A system framework for solving the general trilemma in permissioned blockchains","cited_arxiv_id":null,"evidence_quote":"Establishes the CAP-trilemma-solving blockchain framework that underlies the MIS design."},{"cited_title":"An identity management protocol for multi-identifier network","cited_arxiv_id":null,"evidence_quote":"Defines the real-name, biometric-linked identity management that makes packets traceable."},{"cited_title":"Co-governed Sovereignty Network: Legal Basis and Its Prototype & Applications with MIN Architecture","cited_arxiv_id":null,"evidence_quote":"Contains Section 4.7.5, the stochastic process model behind Theorem B's $4.8 \\times 10^{15}$-year breach estimate."},{"cited_title":"A network architecture containing both push and pull semantics","cited_arxiv_id":null,"evidence_quote":"Defines the MIN packet types (Interest, Data, GPPkt) and the dual push/pull network-layer design."},{"cited_title":"Mir: Multi-identifier router and its prototype","cited_arxiv_id":null,"evidence_quote":"Describes the Multi-Identifier Router that forwards packets across identifier types."},{"cited_title":"A border management protocol for multi- identifier network within the network layer and its attack detection extension","cited_arxiv_id":null,"evidence_quote":"Presents the cyberspace customs protocol with visa and passport hashes that secures network borders."}],"review_version":1}