[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-83691-en":3,"doc-seo-83691-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},83691,4810365810221,"Aurora","https://ap-avatar.wpscdn.com/davatar_155a257f0dc6eb9ab79c44ca47cae57d",8,"Research & Report","Cassandra Consensus with Partial Progress via Robust Partitionable View Synchronization","Replicated databases and permissioned blockchains use Byzantine Fault-Tolerant (BFT) consensus to keep replicas in a single transaction order. Safety holds under asynchrony because transactions are committed only after agreement by a strong quorum. During network partitions, however, strong quorums become unreachable, breaking liveness and preventing meaningful progress. Cassandra introduces a consensus design that allows partial progress without sacrificing safety, using a two-tier certification framework, a pacemaker that advances views without strong-quorum reachability, and replica timeout calibration on the critical path.","Cassandra: Consensus with Partial Progress via Robust Partitionable View Synchronization  \nShaokang Xie University of California, Davis  \nDakai Kang University of California, Davis  \nJunchao Chen University of California, Davis  \nSuyash Gupta University of Oregon  \nDaniel P. Hughes∗  \nRadix DLT Ltd.  \nMohammad Sadoghi University of California, Davis  \narXiv :2607 .02856v 1 [ cs .DC] 3 Jul 2026  \nAbstract  \nReplicated databases and permissioned blockchains rely on Byzantine Fault-Tolerant (BFT) consensus to maintain a consistent transaction order across replicas. These protocols preserve safety even under asynchrony, as they commit a transaction only after agreement among a strong quorum of replicas. During network partitions, however, when no strong quorum is reachable, they lose liveness and cannot make useful progress.  \nIn this paper, we present Cassandra, a consensus protocol that enables partial progress without sacrificing safety. Cassandra achieves this through a two-tier certification framework that decouples availability from commitment, allowing each partition to extend its own chain and reconcile these chains once the network is restored. To support this, Cassandra introduces a pacemaker that advances views without requiring a strong quorum and calibrates each replica’s timeout off the critical path.  \nOur evaluation results show that Cassandra remains competitive with state-of-the-art BFT protocols under stable conditions, sustaining 900K TPS at 16 replicas and 480K TPS at 104 replicas, with latency ranging from 0 . 31s at 16 replicas to 0. 75s at 104 replicas. Under severe partitions, Cassandra maintains non-zero speculative throughput through PoA-backed progress, preserving work that can be reconciled once connectivity is restored.  \n1 Introduction  \nDecentralized systems offer their clients an immutable ledger even in the presence of faulty or Byzantine behavior. To achieve this, they employ a Byzantine Fault-Tolerant (BFT) consensus protocol that allows multiple distributed parties to maintain a single, globally consistent transaction order over a shared state [22, 45] . Because these parties often hold the same data, they are termed replicas. State-of-the-art BFT protocols, which have served as the foundational building blocks of permissioned blockchains, provide strong fault tolerance and achieve high throughput and low latency under stable network conditions [11, 51] .  \nIn practice, however, networks are not always stable. Transient network partitions, delay asymmetries, and intermittent connectivity can disrupt communication among replicas. High-impact production incidents reported by major technology providers such as Amazon and Cloudflare demonstrate that network partitions are not merely a theoretical concern but a recurring operational reality with severe consequences [4, 5, 12–14] . For example, a major Amazon EC2/EBS outage in the us-east-1 region revealed how misrouted traffic and aggressive recovery storms can effectively  \n∗ In loving memory of Daniel P. Hughes, a valued friend and colleague, whose foundational contributions, ideas, and passion continue to inspire and shape this work.  \nFigure 1: Comparison between traditional BFT protocols and Cassandra under a network partition. In a 2-2 partition scenario, traditional protocols stall as they cannot reach the required 2/3 quorum, whereas Cassandra maintains partial progress using its Proof of Availability (PoA) mechanism.  \npartition storage clusters, rendering data unavailable for extended periods and causing widespread downtime across SaaS providers and financial platforms, with aggregate losses reaching millions of dollars [5] . Similarly, Cloudflare has experienced outages in which routing anomalies, overloaded or impaired interconnects, and regional reachability failures created partitions between cloud regions [12, 13] . The impact is even more pronounced in decentralized and blockchain systems: network congestion–induced outages in Solana","cbCaimuQEPA3cS5z","https://ap.wps.com/l/cbCaimuQEPA3cS5z","pdf",946398,3,1,17,"English","en",105,"# Introduction\n## Problem: Quorum stall under partitions\n## Key properties and structural dependencies","[{\"question\":\"Why do traditional BFT consensus protocols stall during network partitions?\",\"answer\":\"They require a strong quorum to certify proposals. When partitions prevent replicas from forming that quorum within any connected component, liveness fails even though safety is preserved.\"},{\"question\":\"How does Cassandra enable partial progress without sacrificing safety?\",\"answer\":\"Cassandra uses a two-tier certification framework that decouples availability from commitment. Each partition can extend its own chain and reconcile with others after connectivity is restored.\"},{\"question\":\"What role does Cassandra’s pacemaker play?\",\"answer\":\"The pacemaker advances views without needing a strong quorum, and Cassandra calibrates replica timeouts to keep the protocol responsive along the critical path.\"}]",1784189758,43,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"cassandra-consensus-with-partial-progress-via-robust-partitionable-view-synchronization","",{"@graph":36,"@context":85},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,50],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":20},"https://docshare.wps.com/document/research-report/",{"item":51,"name":13,"@type":43,"position":52},"https://docshare.wps.com/document/cassandra-consensus-with-partial-progress-via-robust-partitionable-view-synchronization/83691/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-24","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"Why do traditional BFT consensus protocols stall during network partitions?","Question",{"text":75,"@type":76},"They require a strong quorum to certify proposals. When partitions prevent replicas from forming that quorum within any connected component, liveness fails even though safety is preserved.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How does Cassandra enable partial progress without sacrificing safety?",{"text":80,"@type":76},"Cassandra uses a two-tier certification framework that decouples availability from commitment. Each partition can extend its own chain and reconcile with others after connectivity is restored.",{"name":82,"@type":73,"acceptedAnswer":83},"What role does Cassandra’s pacemaker play?",{"text":84,"@type":76},"The pacemaker advances views without needing a strong quorum, and Cassandra calibrates replica timeouts to keep the protocol responsive along the critical path.","https://schema.org",{"og:url":51,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":51},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]