Abstract
We present a publicly verifiable, VDF-free leader-election protocol for blockchain consensus that eliminates per-hop grinding over participant-chosen randomness. The protocol realizes a deterministic random walk over the roster using a transcript-bound BLS relay chain: at hop (k), party (i_k) signs the canonical message (m_k=(Dst,M_{e,r},Sigma_{k-1},i_k)), updates (Sigma_k), and evaluates domain-separated hashes on the new state for leadership testing and successor selection. The first hop whose leadership coin falls below the threshold is the first emph{eligible} leader; if a designated successor or an eligible leader withholds, the protocol uses timeout-certified deterministic failover until a final emph{accepted} leader is produced.
In the random-oracle model, deterministic BLS fixes each hop signature and the evolving aggregate (Sigma_k) yields fresh transcript-bound inputs, so the per-hop eligibility bits are i.i.d. Bernoulli((p)). Hence the first eligible hop count is geometric with mean (1/p). Under (Delta)-bounded synchrony, the corresponding no-withholding delay satisfies (mathbb{E}[T]le Delta/p) and (T_{varepsilon}leDeltaleftlceil ln(varepsilon)/ln(1-p)rightrceil); under exact per-hop latency (Delta), these bounds are equalities. Under withholding, realized-output fairness is over the effective non-withholding set, and if an attempted hop is honest and responsive with probability (h), then the accepted-leader attempt count is geometric with parameter (hp), giving (mathbb{E}[T]=(hDelta_h+(1-h)Delta_b)/(hp)).
Phase~I supplies a public epoch seed and governance threshold key, and epoch transitions use verifiable re-sharing of the same governance secret without public-key rotation. The relay supports transparent replay and a succinct proof mode, making the auditability/bandwidth tradeoff explicit. We prove ROM guarantees and give a scoped UC realization of the relay abstraction.