Enquire Now
70+ Topics · Spectre · Spectre · cloud sim Sim · MATLAB · Webots · Hardware · Bangalore 2026

Asymmetric Laminate Ansys

Simulation · Control · Perception · Hardware — 12 Lead ECG Acquisition — hardware, sensors, cloud dashboards and protocols (Spectre, REST, CoAP, WebSockets) for BE BTech MTech students. Final-year robotics support with Spectre stacks, simulation worlds, reports and viva from Bangalore.

70+
Related Topics
6+
Sim & HW Tools
4.9★
573 Ratings

Abstract

Quorum systems are a key abstraction in distributed fault-tolerant computing for capturing trust as- sumptions. They can be found at the core of many algorithms for implementing reliable broadcasts, systems that model subjective trust. Every process is free to choose which combinations of other pro- cesses it trusts and which ones it considers faulty. Asymmetric quorum systems strictly generalize standard Byzantine quorum systems, which have only one global trust assumption for all processes.

This work also presents protocols that implement abstractions of shared memory, broadcast primi- tives, and a consensus protocol among processes prone to Byzantine faults and asymmetric trust. The model and protocols pave the way for realizing more elaborate algorithms with asymmetric trust.

Ntroduction

Byzantine quorum systems are a fundamental primitive for building resilient distributed systems from untrusted components. Given a set of nodes, a quorum system captures a trust assumption on the nodes in terms of potentially malicious protocol participants and colluding groups of nodes. Based on quorum systems, many well-known algorithms for reliable broadcast, shared memory, consensus and more have been implemented; these are the main abstractions to synchronize the correct nodes with each other and to achieve consistency despite the actions of the faulty, so-called Byzantine nodes.

Traditionally, trust in a Byzantine quorum system for a set of processes P has been symmetric. In other words, a global assumption specifies which processes may fail, such as the simple and prominent threshold quorum assumption, in which any subset of P of a given maximum size may collude and act against the protocol. The most basic threshold Byzantine quorum system, for example, allows all subsets of up to f < n/3 processes to fail. Some classic works also model arbitrary, non-threshold symmetric quorum systems [35, 27], but it is unknown if these have been used in practice.

However, trust is inherently subjective. De gustibus non est disputandum – There is no disputing about taste. Estimating which processes will function correctly and which ones will misbehave may depend on personal taste. A myriad of local choices influences one process’ trust in others, especially because there are so many forms of “malicious” behavior. Some processes might not even be aware of all others, yet a process should not depend on unknown third parties in a distributed collaboration. How can one model asymmetric trust in distributed protocols? Can traditional Byzantine quorum systems be extended to subjective failure assumptions? How do the standard protocols generalize to this model? 1This work combines multiple preliminary publications on asymmetric trust and protocols with asymmetric trust, which appeared at OPODIS 2019 , DISC 2021 , and ESORICS-CBT 2021 3DFINITY, CH-8000 Z¨urich, Switzerland. Work done at IBM Research – Zurich.

Arxiv:1906.09314V2 [Cs.Dc] 2 May 2024

Asymmetric trust. In this paper, we answer these questions and introduce models and protocols for asymmetric distributed trust. We formalize asymmetric (Byzantine) quorum systems for asynchronous protocols, in which every process can make its own assumptions about Byzantine faults of others. We introduce several protocols with asymmetric trust that strictly generalize the existing algorithms, which require common trust.

Our formalization takes up earlier work by Damg˚ard et al. and starts out with the notion of a fail-prone system that forms the basis of a symmetric Byzantine quorum system. A global fail-prone system for a process set P contains all maximal subsets of P that might jointly fail during an execution.

In an asymmetric quorum system, every process specifies its own fail-prone system and a corresponding all processes and a local availability condition, and generalize symmetric Byzantine quorum system according to Malkhi and Reiter .

Quorum systems are used within various fault-tolerant dis- tributed protocols, here specifically within protocols for systems subject to Byzantine faults. An impor- tant aspect of our notion concerns its relation to existing protocols: it should be easy to generalize the known protocols to the asymmetric model, ideally simply by replacing the symmetric quorums with their asymmetric counterparts. Indeed this is the case for many, but not for all protocols described here. A different, generalized analysis is necessary in any case.

We show first that two existing protocols for emulating a shared regular register also work in the asymmetric model. Second, we introduce asymmetric Byzantine consistent and reliable broadcast prim- Third, we address consensus, one of the most important primitives in distributed computing, and extend a randomized binary consensus protocol for asynchronous networks to work with asymmetric trust. The protocol relies on a common coin abstraction, for which a different implementation is needed.

Our randomized consensus takes up the award-winning, randomized, and signature-free implemen- tation of consensus by Most´efaoui et al. . In its 2014 version, however, this protocol suffered from a liveness issue, which was corrected subsequently , although the fix added considerable complex- ity. The corrected algorithm offers the same asymptotic complexity in message and time as the original algorithm, but it requires more communication steps.

Through our randomized asymmetric consensus, we also introduce a novel way of fixing the problem in the original protocol. It retains the latter protocol’s simplicity, which is an appealing property. Ob- viously, our asymmetric consensus protocol can also be instantiated with symmetric threshold quorums to work in the same model as the protocol of Most´efaoui et al. . In order to clearly demonstrate the liveness issue and to show how our approach avoids it, we also include in this work a discussion of this randomized consensus algorithm in the symmetric-trust model.

In the traditional models for quorum-based systems, all correct processes uniformly benefit from the guarantees of a protocol as long as the initial assumption expressed by the fail-prone system holds. With subjective trust, this symmetry no longer exists. Some of the correct processes may have made assumptions that proved appropriate in an execution with actually faulty processes F ⊂P; we call these processes wise. Other correct processes, however, may have assumed that only a proper subset of F actually fails; these processes are na¨ıve and they do not enjoy the same guarantees as the wise ones, even though they are correct. In particular, our protocols typically ensure safety only for wise processes and liveness depends on the existence of a sufficiently large group of wise processes.

Motivation. Interest in consensus protocols based on Byzantine quorum systems has surged recently because of their application to permissioned blockchain networks [14, 6]. Typically run by a consor- tium, such distributed ledgers often use Byzantine-fault tolerant (BFT) protocols like PBFT , Ten- Bitcoin blockchain and many other cryptocurrencies, which triggered this development, started from dif- ferent assumptions and use so-called permissionless protocols, in which everyone may participate. Those algorithms capture the relative influence of the participants on consensus decisions by an external factor, such as invested “work” or “stake” in the system.

A middle ground between permissionless blockchains and BFT-based ones has been introduced by the blockchain networks of Ripple (https://ripple.com) and Stellar (https://stellar. org). Their stated model for achieving network-level consensus uses subjective trust in the sense that each process declares a local list of processes that it “trusts” in the protocol.

Consensus in the Ripple blockchain (and for the XRP cryptocurrency on the XRP Ledger) is executed by its validator nodes. Each node declares a Unique Node List (UNL), which are validators that this node trusts, in the sense that “the given participant believes [they] will not conspire to defraud [the node].” At least up to around 2020, however, nodes have not really been free in their trust choice since “Ripple provides a default and recommended list which we [Ripple] expand based on watching the history of validators operated by Ripple and third parties” . As of 2023, the XRP ledger documentation states that “currently the XRP Ledger Foundation and Ripple are known to publish recommended default lists of high quality validators . . ” . It is clear that two nodes that transact via the XRP ledger need to have some validators that they trust in common. But many questions are left open about the kind of decentralization offered by the Ripple protocol.

Stellar was created as an evolution of Ripple that shares much of the same design philosophy. The Stellar consensus protocol powers the Stellar Lumen (XLM) cryptocurrency and introduces federated Byzantine quorum systems (FBQS); they also capture subjective trust assumptions, but differ technically of a quorum that can convince one particular node of agreement.” In an FBQS, “each node chooses its own quorum slices” and “the system-wide quorums result from these decisions by individual nodes” .

Contribution. The main motivation for this work is to understand how existing ideas of subjective formalization of asymmetric quorums provides a sound foundation for protocols with asymmetric trust.

The protocols described here generalize well-known, classic algorithms in the literature and therefore look similar. This should be seen as a feature, actually, because simplicity and modularity are important guiding principles in science.

Our Contributions Are As Follows:

• We introduce asymmetric Byzantine quorum systems formally in Section 4 as an extension of standard Byzantine quorum systems and discuss some of their properties. • In Section 5, we show two implementations of a shared register, with single-writer, multi-reader • We examine broadcast primitives in the Byzantine model with asymmetric trust in Section 6. In particular, we define and implement Byzantine consistent and reliable broadcast protocols.

• In Section 7, we present the first asynchronous Byzantine consensus protocol with asymmetric trust. It uses randomization, provided by an asymmetric common coin protocol, to circumvent the impossibility of asynchronous consensus.

Before presenting the technical contributions, we discuss related work in Section 2 and state our system model in Section 3. A detailed discussion of the liveness issue in the existing signature-free Byzantine consensus protocol and of our approach to fixing it appears in Appendix A.

Related Work

Practical systems: Ripple and Stellar. The Ripple consensus protocol is run by an open set of val- idator nodes. The protocol uses votes, similar to standard consensus protocols, whereby each validator only communicates with the validators in its UNL. Each validator chooses its own UNL, which makes it possible for anyone to participate, in principle, similar to proof-of-work blockchains. Early investiga- tions suggested that the intersection of the UNLs of every two validators should be at least 20% of each list , assuming that also less than one fifth of the validators in the UNL of every node might be faulty.

An independent analysis by Armknecht et al. later argued that this bound must be more than 40%. A technical report of Chase and MacBrough [20, Thm. 8] concludes, under the same assumption of f < n/5 faulty nodes in every UNL of size n, that the UNL overlap should actually be at least 90%.

However, the same paper also derives a counterexample to the liveness of the Ripple consensus protocol [20, Sec. 4.2] as soon as two validators don’t have “99% UNL overlap.” By generalizing the example, this essentially means that the protocol can get stuck unless all nodes have the same UNL.

According to the standards of the field of distributed systems, though, a protocol needs to satisfy safety and liveness because achieving only one of these properties is trivial. Amores-Sesar et al. confirm the prior analysis and exhibit a wider set of examples how safety and liveness may be violated in executions of the Ripple consensus protocol. They first show that the network may fork, even under the standard condition stated by Ripple on the overlap of UNLs, and then that the consensus protocol may lose liveness in the presence of only one Byzantine process, even if all the processes have the same UNL. These works, however, exploit arbitrary message delays, i.e., a period of asynchronous network behavior, which is not assumed by Ripple and arguably also unlikely to occur in practice.

The Stellar consensus protocol (SCP) also features open membership and lets every node express its own set of trusted nodes [36, 31]. Generalizing from Ripple’s flat lists of unique nodes, every node declares a collection of trusted sets called quorum slices, whereby a slice is “the subset of a quorum convincing one particular node of agreement.” A quorum in Stellar is a set of nodes “sufficient to reach agreement,” defined as a set of nodes that contains one slice for each member node. The quorum choices of all nodes together yield a federated Byzantine quorum systems (FBQS). The literature on Stellar gives properties for FBQS and contains protocols that build on them, which have been implemented in the Stellar blockchain . However, standard Byzantine quorum systems and FBQS are not comparable because (1) an FBQS when instantiated with the same trust assumption for all processes does not reduce to a symmetric quorum system and (2) existing protocols do not directly generalize to FBQS.

Models of asymmetric trust. Starting from Stellar’s notions, Garc´ıa-P´erez and Gotsman build a link from FBQS to existing quorum-system concepts by investigating a Byzantine reliable broadcast abstraction in an FBQS. They show that the federated voting protocol of Stellar is similar to Bracha’s reliable broadcast and that it implements a variation of Byzantine reliable broadcast on an FBQS for executions that contain, additionally, a set of so-called intact nodes. Losa et al. have later formulated an abstraction of the consensus mechanism in the Stellar network by introducing Personal Byzantine quorum systems (PBQS). In contrast to the other notions of “quorums”, their definition does not require each one satisfies agreement and liveness on its own.

The FBQS and PBQS concepts, however, differ from the notion of a Byzantine quorum system in the literature. In particular, the characterization of their properties seems to take into account knowledge of which nodes are Byzantine, and their effects are therefore analyzed in the context of particular executions.

Existing notions of symmetric quorum systems in the literature [35, 27] start from an a-priori assumption about all potentially faulty sets of nodes, through a fail-prone system . This permits to study protocol- Another approach for designing Byzantine fault-tolerant (BFT) consensus protocols has been intro- duced by Malkhi et al. , namely Flexible BFT. This notion guarantees higher resilience by intro- ducing a new alive-but-corrupt fault type, which denotes processes that attack safety but not liveness.

Malkhi et al. also define flexible Byzantine quorums that allow processes in the system to have different faults models. Our work, in contrast, goes back to the model of Damg˚ard et al. . It already contains the basic formulation of asymmetric trust and expresses it in the context of synchronous protocols for secure property, but omits liveness. Damg˚ard et al. also state a characterization of when an asymmetric Byzantine quorum system exists (with the so-called B3), but give no proof. Their work has remained without impact until research on cryptocurrencies has revived interest in heterogeneous and subjective trust models.

Signature-free randomized consensus. Most´efaoui et al. present a randomized, signature-free, and round-based asynchronous consensus algorithm for binary values. It achieves optimal resilience and takes O(n2) constant-sized messages. Randomization is achieved through a common coin as defined by Rabin . Their binary consensus algorithm has been taken up for constructing the “Honey Badger BFT” protocol by Miller et al. , for instance. One important contribution of Most´efaoui et al.

is a new binary validated broadcast primitive with a non-deterministic termination property; it has also found applications in other protocols . Tholoniat and Gramoli observe a liveness issue in the protocol by Most´efaoui et al. in which an adversary is able to prevent progress among the correct processes by controlling messages between them and by sending them values in a specific order.

In a later work, Most´efaoui et al. present a different version of their randomized consensus algorithm that does not suffer from the liveness problem anymore. The resulting algorithm offers the same asymptotic complexity in message and time as their previous algorithm , but requires more communication steps.

System Model

Processes. We consider a system of n processes P = {p1, . . , pn} that communicate with each other. The processes interact asynchronously with each other through exchanging messages. The system itself is asynchronous, i.e., the delivery of messages among processes may be delayed arbitrarily and the processes have no synchronized clocks. Every process is identified by a name, but such identifiers are not made explicit. A protocol for P consists of a collection of programs with instructions for all processes.

Protocols are presented in a modular way using the event-based notation of Cachin et al. . Executions and faults. An execution starts with all processes in a special initial state; subsequently the processes repeatedly trigger events, react to events, and change their state through computation steps.

Every execution is fair in the sense that, informally, processes do not halt prematurely when there are still steps to be taken or events to be delivered (we refer to the standard literature for a formal definition ). A process that follows its protocol during an execution is called correct. On the other hand, a faulty process may crash or even deviate arbitrarily from its specification, e.g., when corrupted by an adver- sary; such processes are also called Byzantine. We consider only Byzantine faults here and assume for simplicity that the faulty processes fail right at the start of an execution.

Functionalities. A functionality is an abstraction of a distributed computation, either a primitive that may be used by the processes or a service that they will provide. Every functionality in the system is specified through its interface, containing the events that it exposes to protocol implementations that may call it, and its properties, which define its behavior. A process may react to a received event by changing their state and triggering further events.

There are two kinds of events in an interface: input events that the functionality receives from other abstractions, typically to invoke its services, and output events, through which the functionality delivers information or signals a condition to a process. The behavior of a functionality is usually stated through a number of properties or through a sequential implementation.

Multiple functionalities may be composed together modularly. In a modular protocol implementa- tion, in particular, every process executes the program instructions of the protocol implementations for all functionalities in which it participates.

Links. We assume there is a low-level functionality for sending messages over point-to-point links be- tween each pair of processes. In a protocol, this functionality is accessed through the events of “sending a message” and “receiving a message.” Point-to-point messages are authenticated and delivered reliably among correct processes.

Moreover, we assume FIFO ordering on the reliable point-to-point links for every pair of correct processes. This means that if a correct process has “sent” a message m1 and subsequently “sent” a message m2, then every correct process does not “receive” m2 unless it has earlier also “received” m1.

FIFO-ordered links are actually a very common assumption. Protocols that guarantee FIFO order on top of (unordered) reliable point-to-point links are well-known and simple to implement [26, 11]. We remark that there is only one FIFO-ordered reliable point-to-point link functionality in the model; hence, FIFO order holds among the messages exchanged by the implementations for all functionalities used by a protocol.

Idealized digital signatures. A digital signature scheme provides two operations, signi and verifyi. The invocation of signi specifies a process pi and takes a bit string m ∈{0, 1}∗as input and returns a signature σ ∈{0, 1}∗with the response. Only pi may invoke signi. The operation verifyi takes a putative signature σ and a bit string m as parameters and returns a Boolean value with the response. Its implementation satisfies that verifyi(σ, m) returns TRUE for any i ∈[1, n] and m ∈{0, 1}∗if and only if pi has executed signi(m) and obtained σ before; otherwise, verifyi(σ, m) returns FALSE. Every process may invoke verify.

Asymmetric Byzantine Quorum Systems

This section defines asymmetric Byzantine quorum systems and the notions of a guild and a tolerated system, which are used in protocols later. To set the stage, symmetric Byzantine quorum systems are reviewed first.

Review Of Symmetric Trust

Quorum systems are well-known in settings with symmetric trust. As demonstrated by many applications to distributed systems, ordinary quorum systems and Byzantine quorum systems play a crucial role in formulating resilient protocols that tolerate faults through replication . A quorum system typically ensures a consistency property among the processes in an execution, despite the presence of some faulty processes.

For the model with Byzantine faults, Byzantine quorum systems have been introduced by Malkhi and Reiter . This notion is defined with respect to a fail-prone system F ⊆2P, a collection of subsets of P, none of which is contained in another, such that some F ∈F with F ⊆P is called a fail-prone set and contains all processes that may at most fail together in some execution . A fail-prone system is the same as the basis of an adversary structure, which was introduced independently by Hirt and Maurer .

A fail-prone system captures an assumption on the possible failure patterns that may occur. It speci- fies all maximal sets of faulty processes that a protocol should tolerate in an execution; this means that a protocol designed for F achieves its properties as long as the set F of actually faulty processes satisfies F ∈F∗. Here and from now on, the notation A∗for a system A ⊆2P, denotes the collection of all subsets of the sets in A, that is, A∗= {A′|A′ ⊆A, A ∈A}.

Definition 1 (Byzantine quorum system ). A Byzantine quorum system for F is a collection of sets of processes Q ⊆2P where no set is contained in another and each Q ∈Q is called a quorum, such the

Following Properties Hold:

Consistency: The intersection of any two quorums contains at least one process that is not faulty, i.e.,

∀Q1, Q2 ∈Q, ∀F ∈F : Q1 ∩Q2̸ ⊆F.

Availability: For any set of processes that may fail together, there exists a disjoint quorum in Q, i.e.,

∀F ∈F : ∃Q ∈Q : F ∩Q = ∅.

The above notion is also known as a Byzantine dissemination quorum system and allows a pro- tocol to be designed despite arbitrary behavior of the potentially faulty processes. The notion generalizes the usual threshold failure assumption for Byzantine faults , which considers that any set of f pro- cesses may fail.

We say that a set system T dominates another set system S if for each S ∈S there is some T ∈T such that S ⊆T . In this sense, a quorum system for F is minimal whenever it does not dominate any other quorum system for F. A maximal set system is defined analogously.

Similarly to the threshold case, where n > 3f processes are needed to tolerate f faulty ones in many Byzantine protocols, Byzantine quorum systems can only exist if not “too many” processes fail. Definition 2 (Q3-condition [35, 27]). A fail-prone system F satisfies the Q3-condition, abbreviated as

∀F1, F2, F3 ∈F : P̸ ⊆F1 ∪F2 ∪F3.

In other words, Q3(F) means that no three fail-prone sets together cover the whole system of pro- cesses. A Qk-condition can be defined like this for any k ≥2 . The following result of Malkhi and Reiter [35, Theorem 5.4] considers the bijective complement of a process set S ⊆2P, which is defined as S = {P \ S|S ∈S}, and turns F into a Byzantine quorum system. A related theorem was formulated also by Hirt and Maurer .

Lemma 1. Given a fail-prone system F, a Byzantine quorum system for F exists if and only if Q3(F). In particular, if Q3(F) holds, then F, the bijective complement of F, is a Byzantine quorum system. The quorum system Q = F is called the canonical quorum system of F. According to the duality between Q and F, properties of F are sometimes ascribed to Q as well. However, note that the canonical quorum system is not always minimal. For instance, if F consists of all sets of f ≪n/3 processes, then each quorum in the canonical quorum system has n −f members, but also the family of all subsets of P

With ⌈N+F+1

⌉< n −f processes forms a quorum system. Core sets. A core set C for F is a minimal set of processes that contains at least one correct process in every execution. More precisely, C ⊆P is a core set whenever (1) for all F ∈F, it holds P \F ∩C̸ = ∅ (and, equivalently, C̸ ⊆F) and (2) for all C′ ⊊C, there exists F ∈F such that P \ F ∩C′ = ∅(and, equivalently, C′ ⊆F). With the threshold failure assumption, every set of f + 1 processes is a core set.

A core-set system C is the minimal collection of all core sets, in the sense that no set in C is contained in another. Core sets can be complemented by survivor sets, as shown by Junqueira et al. . This yields a dual Kernels.

Given a symmetric Byzantine quorum system Q, we define a kernel K as a minimal set of processes that overlaps with every quorum. A kernel generalizes the notion of a core set . Definition 3 (Kernel system). A set K ⊆P is a kernel of a quorum system Q if an only if

∀K′ ⊊K : ∃Q ∈Q : Q ∩K′ = ∅.

We also define the kernel system K of Q to be the set of all kernels of Q. For example, under a threshold failure assumption where any f processes may fail, every set of



processes is a kernel. In particular, n = 3f + 1 if and only if every kernel has f + 1 processes. The definition of a kernel is related to that of a core set in the following sense. Lemma 2. Let F be a fail-prone system and Q = F be the canonical quorum system of F. Then the kernel system of Q is the same as the core-set system for F.

Proof. Consider a kernel system K of a Byzantine quorum system Q. By definition, the following two properties hold with respect to every kernel K ∈K: (i) For every quorum Q in Q, the intersection with the kernel K is non-empty, i.e., K ∩Q̸ = ∅.

(ii) For any proper subset K′ of K, there exists a quorum Q in Q such that K′ does not intersect with Q, i.e., Q ∩K′ = ∅. Given the canonical quorum system Q derived from the fail-prone system F, by definition of canonical quorum system of F we have that for every Q in Q, there exists a unique fail-prone set F in F such that Q is precisely the complement of F within P, that is, Q = P \ F. Consequently, the concepts of a kernel and a core set are equivalent in this context, as a core set is defined with respect to sets of the form P \ F.

Lemma 3. Let F, Q, and K be a fail-prone system, a Byzantine quorum system for F, and the kernel system of Q, respectively. Then, for every quorum Q ∈Q, there exists a kernel K ∈K such that K ⊆Q. Proof. Consider the quorum system Q for F. Let F be any such fail-prone set in F. For a given quorum Q ∈Q, define the set K = Q \ F. By definition, K is a subset of Q, i.e., K ⊆Q. The consistency property of the Byzantine quorum system now implies that any two quorums Q, Q′ ∈Q have an intersection Q ∩Q′ that is not fully contained within F. Therefore, K intersects with Q′ since (Q\F)∩Q′ = K∩Q′ is not empty. This property holds for every Q′ ∈Q and confirms that K intersects with every quorum in Q. As such, K satisfies the first property of a kernel of Q.

For the second property, minimality, let us consider such a K. To construct a kernel contained in Q, we progressively remove elements from K, ensuring that the resultant subset retains the property of without losing the intersection property. The minimality of K∗is guaranteed by the contradiction that arises from the assumption that a proper subset of K∗could intersect with all quorums, as this would violate the termination of our removal process. Therefore, K∗is a kernel by definition since it is the minimal intersecting set with every quorum in Q, and it is contained within the original quorum Q from which we subtracted F. This shows that K∗is a kernel of Q.

Asymmetric Trust

In our model with asymmetric trust, every process is free to make its own trust assumption and to express this with a fail-prone system. Hence, an asymmetric fail-prone system F = [F1, . . , Fn] consists of an array of fail-prone systems, where Fi denotes the trust assumption of pi. One often assumes pi̸ ∈Fi for practical reasons, but this is not necessary. This notion has earlier been formalized by Damg˚ard et al.

Definition 4 (Asymmetric Byzantine quorum system). An asymmetric Byzantine quorum system for F is an array of collections of sets Q = [Q1, . . , Qn], where Qi ⊆2P for i ∈[1, n]. The set Qi ⊆2P is called the quorum system of pi and any set Qi ∈Qi is called a quorum (set) for pi. It satisfies: Consistency: The intersection of two quorums for any two processes contains at least one process for which either process assumes that it is not faulty, i.e., ∀i, j ∈[1, n], ∀Qi ∈Qi, ∀Qj ∈Qj, ∀Fij ∈Fi∗∩Fj∗: Qi ∩Qj̸ ⊆Fij.

Availability: For any process pi and any set of processes that may fail together according to pi, there

Exists A Disjoint Quorum For Pi In Qi, I.E.,

∀i ∈[1, n], ∀Fi ∈Fi : ∃Qi ∈Qi : Fi ∩Qi = ∅. Recall that the consistency condition for a (symmetric) Byzantine quorum system requires that at least one process in the intersection of every two quorums is correct. In the asymmetric case, quorums are subjective and defined according to the quorum system for each process. The asymmetric consistency property states that in the intersection of every two subjective quorums of two processes there exists at least one process that is correct according to one of the two processes. On the other hand, the availability condition in the above definition is a direct extension of the symmetric case, since it considers the quorum system of each process separately. We remark that availability suffices for implementing some protocols but a stronger assumption (i.e., the existence of a guild, introduced below) is needed for others.

The existence of asymmetric quorum systems can be characterized with a property that generalizes the Q3-condition for the underlying asymmetric fail-prone systems as follows. Definition 5 (B3-condition). An asymmetric fail-prone system F satisfies the B3-condition, abbreviated

As B3(F), Whenever It Holds That

∀i, j ∈[1, n], ∀Fi ∈Fi, ∀Fj ∈Fj, ∀Fij ∈Fi∗∩Fj∗: P̸ ⊆Fi ∪Fj ∪Fij The following result is the generalization of Lemma 1 for asymmetric quorum systems; it was stated by Damg˚ard et al. without proof.

Theorem 4. An asymmetric fail-prone system F satisfies B3(F) if and only if there exists an asymmetric quorum system for F. Proof. Suppose that B3(F). We let Q = [Q1, . . , Qn], where Qi = Fi is the canonical quorum system of Fi, and show that Q is an asymmetric quorum system. Indeed, let Qi ∈Qi, Qj ∈Qj, and Fij ∈ Fi∗∩Fj∗for any i and j. Then Fi = P \Qi ∈Fi and Fj = P \Qj ∈Fj by construction, and therefore, Fi ∪Fj ∪Fij̸ = P holds according to B3(F). This means there is some pk ∈P \ (Fi ∪Fj ∪Fij).

Because pk̸ ∈Fi, it holds pk ∈Qi and analogously pk ∈Qj. This implies in turn that pk ∈Qi ∩Qj but pk /∈Fij and proves the consistency condition. The availability property holds by construction of the To show the reverse direction, let Q be a candidate asymmetric Byzantine quorum system for F that satisfies availability and assume towards a contradiction that B3(F) does not hold. We show that consistency cannot be fulfilled for Q. By our assumption there are sets Fi, Fj, Fij in F such that Fi∪Fj ∪ Fij = P, which means also that P \ (Fi ∪Fj) ⊆Fij. The availability condition for Q then implies that there are sets Qi ∈Qi and Qj ∈Qj with Fi ∩Qi = ∅and Fj ∩Qj = ∅. Now for every pk ∈Qi ∩Qj it holds that pk /∈Fi ∪Fj by availability and therefore pk ∈P \ (Fi ∪Fj). Taken together this means that Qi ∩Qj ⊆P \ (Fi ∪Fj) ⊆Fij. Hence, Q does not satisfy the consistency condition and the statement follows.

Asymmetric core sets and kernels. Let F = [F1, . . , Fn] be an asymmetric fail-prone system. An asymmetric core-set system C is an array of collections of sets [C1, . , Cn] such that each Ci is a core set system for the fail-prone system Fi. We call a set Ci ∈Ci a core set for pi.

Given an asymmetric quorum system Q for F, an asymmetric kernel system for Q is defined analo- gously as the array K = [K1, . . , Kn] that consists of the kernel systems for all processes in P. A set Ki ∈Ki is called a kernel for pi. This means that every kernel for pi has a non-empty intersection with every quorum of pi.

Na¨ıve and wise processes. Recall that the guarantees of quorum-based protocols apply to correct processes only, but not to faulty ones. The faults or corruptions occurring in a protocol execution with an underlying quorum system induce a set F of actually faulty processes. However, no process knows F and this information is only available to an observer outside the system. With a traditional quorum system Q designed for a fail-prone set F, the guarantees of a protocol usually hold as long as F ∈F∗, and if F is not contained in F∗, no useful properties can be derived for any process.

With asymmetric quorums, we further distinguish between two kinds of correct processes, depending on whether they considered F in their trust assumption or not. Given a protocol execution, the processes

Are Therefore Partitioned Into Three Types:

Faulty: A process pi ∈F is faulty. Na¨ıve: A correct process pi for which F̸ ∈Fi∗is called na¨ıve. Wise: A correct process pi for which F ∈Fi∗is called wise.

The na¨ıve processes are new for the asymmetric case, as all correct processes are wise under a symmetric trust assumption. Protocols for asymmetric quorums cannot guarantee the same properties for na¨ıve processes as for wise ones, since the na¨ıve processes may have the “wrong friends.” In one formalization of the Stellar protocol, correct nodes that find themselves in a similar situation have been called “befouled” .

Example 1. We define an example of asymmetric fail-prone system FA on P = {p1, p2, p3, p4, p5}. The

Notation Θn

k(S) for a set S with n elements denotes the “threshold” combination operator and enumerates all subsets of S of cardinality k. W.l.o.g. every process trusts itself. The diagram below shows fail-prone

Sets As Shaded Areas And The Notation N

k in front of a fail-prone set stands for k out of the n processes in the set.

P1

The operator ∗for two sets satisfies A ∗B = {A ∪B|A ∈A, B ∈B}. As one can verify in a straightforward way, B3(FA) holds. Let QA be the canonical asymmetric quo- rum system for FA. Note that since FA contains the fail-prone systems of p3 and p5 that permit two faulty processes each, this fail-prone system cannot be obtained as a special case of Θ5 1({p1, p2, p3, p4, p5}).

When F = {p2, p4}, for example, then processes p3 and p5 are wise and p1 is na¨ıve. Guilds. If too many processes are na¨ıve or even fail during a protocol run with asymmetric quorums, then protocol properties cannot be ensured. A guild is a set of wise processes that contains at least one quorum for each member; by definition this quorum consists only of wise processes. A guild ensures liveness and consistency for typical protocols. This generalizes from protocols with symmetric trust, where the correct processes in every execution form a quorum by definition. A guild represents a group of influential and well-connected wise processes, like in the real world.

Definition 6 (Guild). Given a fail-prone system F, an asymmetric quorum system Q for F, and a protocol execution with faulty processes F, a guild G for F and Q satisfies two properties:

Wisdom: G Is A Set Of Wise Processes:

∀pi ∈G : F ∈Fi∗. Closure: G contains a quorum for each of its members: ∀pi ∈G : ∃Qi ∈Qi : Qi ⊆G.

A guild is related to an “intact set” in the Stellar consensus protocol [36, 31], but the two notions differ in how they are defined. Observe that the union of two guilds is again a guild, since the union consists only of wise processes and contains again a quorum for each member. All guilds overlap, as the next result shows.

Lemma 5. In any execution with a guild G, every two guilds intersect. Proof. Let P be a set of processes, G be a guild, and F be the set of actually faulty processes. Further- more, suppose that there is another guild G′. Let pi ∈G and pj ∈G′ be two processes and consider a quorum Qi ⊆G for pi and a quorum Qj ⊆G′ for pj. From the definition of an asymmetric quorum system it must hold Qi ∩Qj ⊈F, with Qi ∩Qj̸ = ∅and F ∈Fi∗∩Fj∗. It follows that there exists a wise process pk ∈Qi ∩Qj with pk ∈G and pk ∈G′. Notice also that G and G′ both contain a quorum for pk.

It follows that every execution with a guild contains a unique maximal guild Gmax. The next lemma shows that if a guild exists, no quorum for any process contains only faulty processes. Lemma 6. Let Gmax be the maximal guild for a given execution and let Q be the canonical asymmetric quorum system. Then, there cannot be a quorum Qj ∈Qj for any process pj consisting only of faulty processes.

Proof. Given an execution with F as set of faulty processes, suppose there is a guild Gmax. This means that for every process pi ∈Gmax, a quorum Qi ⊆Gmax exists such that Qi ∩F = ∅. It follows that for every pi ∈Gmax, there is a set Fi ∈Fi such that F ⊆Fi. Recall that since Q is a quorum system, B3(F) holds. From Definition 5, we have that for all i, j ∈[1, n], all Fi ∈Fi, ∀Fj ∈Fj, and all Fij ∈Fi∗∩Fj∗, it holds P̸ ⊆Fi ∪Fj ∪Fij.

Towards a contradiction, assume that there is a process pj such that there exists a quorum Qj ∈Qj for pj with Qj = F. This implies that there exists Fj ∈Fj such that Fj = P \ F. Let Fi be the fail-prone system of pi ∈Gmax such that F ⊆Fi and let Fj = P \ F as just defined.

Then, Fi ∪Fj ∪Fij = P. This follows from the fact that Fi contains F and that Fj = P \ F. This contradicts the B3-condition for F. Lemma 7. Let Gmax be the maximal guild for a given execution and let pi be any correct process. Then, every quorum for pi contains at least one process in Gmax.

Proof. The claim naturally derives from the consistency property of an asymmetric quorum system. Consider any correct process pi and one of its quorums, Qi ∈Qi. For any process pj ∈Gmax, let Qj be a quorum of pj such that Qj ⊆Gmax, which exists because Gmax is a guild. Then, the quorum consistency property implies that Qi ∩Qj̸ = ∅. Thus, Qi contains a process in the maximal guild.

Finally, we show with an example that it is possible for a wise process to be outside the maximal guild. Example 2. Let us consider a seven-process asymmetric quorum system QB, defined through its fail- prone system FB.

F7

One can verify that B3(FB) holds; hence, let QB be the canonical quorum system of FB.

=

{{p1, p2, p3, p4}, {p1, p2, p4, p5}, {p1, p3, p4, p5}, {p2, p3, p4, p5}}

=

{{p1, p2, p3, p5}, {p1, p2, p4, p5}, {p1, p3, p4, p5}, {p2, p3, p4, p5}}

{{P1, P2, P6, P7}}

With F = {p4, p5}, for instance, processes p1, p2, p3 and p7 are wise, p6 is na¨ıve, and Gmax = {p1, p2, p3}. It follows that process p7 is wise but outside the guild Gmax, because the unique maximal quorum in Q7 contains the na¨ıve process p6.

Lemma 7 reveals the interesting result that for an execution with a guild, each quorum of every correct process pi contains at least one process that is also in the maximal guild Gmax. Since a kernel for pi is a process set that has some member in common with every quorum of pi, this implies that Gmax contains a kernel for pi.

Corollary 8. In every execution with a guild, the maximal guild Gmax contains a kernel for every correct process. It follows that whenever all processes in the maximal guild send some particular message, then every correct process will eventually receive this message from all processes in one of its kernels. This is exploited by protocols that use kernels, such as Algorithm 4 (in Section 6).

A guild can also be seen as a set of sufficiently many wise processes that allow a protocol to make progress, in the following sense. Lemma 9. Consider an execution, in which the processes in F are faulty and let Gmax be the maximal guild for F. Let A be a superset of F that is disjoint from Gmax, i.e., F ⊆A ⊆P \ Gmax.

Then, in any execution where the processes in A fail, Gmax is also the maximal guild for A. Proof. Let Gmax be the maximal guild in an execution with set of faulty processes F ⊆P \ Gmax. By definition of a guild, Gmax contains a quorum for each of its members. This means that there exists a quorum Qi for every pi ∈Gmax such that Qi ∩F = ∅. This also implies that for every set A ⊇F, with A ⊆P \ Gmax, we have that Qi ∩A = ∅, and the lemma follows.

Given the importance of a guild for an asymmetric Byzantine quorum system, we introduce the following notion. Definition 7 (Tolerated system). Given an asymmetric Byzantine quorum system Q and an execution with faulty processes F, a set of processes T is called tolerated (by Q) if a non-empty guild G for F and Q exists such that T = P \ G.

The tolerated system T of an asymmetric Byzantine quorum system Q is the maximal collection of tolerated sets, where F ranges over all possible executions. Intuitively, the tolerated system of an asymmetric Byzantine quorum system reflects its resilience: even when all processes in a tolerated set fail, there still exists a non-empty guild. Therefore, the tolerated system characterizes the executions in which some processes will be able to operate correctly and make progress (where progress is defined by the protocol they are running). In that sense, the tolerated system of an asymmetric Byzantine quorum system can be seen as a counterpart of the fail-prone system in the symmetric model.

Notice that the tolerated system is a global notion emerging from the subjective trust choices of the participating processes; any process that knows the fail-prone and quorum systems of all processes can calculate it. We remark that the tolerated system is a central concept for composing asymmetric Byzantine quorum system, as shown by Alpos et al. .

The following lemma shows that the tolerated system T of a canonical asymmetric Byzantine quorum system is itself a symmetric fail-prone system. In particular, τ builds a connection to symmetric quorum- based protocols. This property will be used in Section 7 to construct an asymmetric common coin protocol.

Lemma 10. Let Q be an asymmetric Byzantine quorum system among processes P with asymmetric fail- prone system F = Q, i.e., such that Q is a canonical asymmetric Byzantine quorum system, and let T be the tolerated system of Q. If B3(F), then Q3(T ).

Proof. Towards a contradiction, let us assume that T does not satisfy the Q3-condition. This means that there exist T1, T2, T3 ∈T such that T1 ∪T2 ∪T3 = P. Also, let G1, G2, G3 be the corresponding guilds, i.e., G1 = P \T1, G2 = P \T2 and G3 = P \T3. By assumption, every guild contains at least one process and at least one quorum for this process is fully contained in the guild. By the consistency property of an asymmetric Byzantine quorum system, these quorums must intersect pairwise, hence the guilds also intersect pairwise. This means that there exist processes pi ∈G1 ∩G2 and pj ∈G2 ∩G3. Now, because pi is a member of G1, we can make the following reasoning: pi has a quorum Qi ∈Qi such that Qi ⊆G1, the quorum system is canonical, so pi has a fail-prone set Fi = P \ Qi ∈Fi, thus we get T1 ⊆Fi, i.e., T1 ∈Fi. With similar reasoning, we get T2 ∈Fi (because pi ∈G2), T2 ∈Fj (because pj ∈G2), and T3 ∈Fj (because pj ∈G3). But this is a contradiction because pi and pj with fail-prone sets T1, T2, and T3 violate the B3-condition in Q.

Shared Memory

This section illustrates a first application of asymmetric quorum systems: how to emulate shared memory, represented by a register. Maintaining a shared register reliably in a distributed system subject to faults is perhaps the most fundamental task for which ordinary, symmetric quorum systems have been introduced, in the models with crashes and with Byzantine faults .

Efinitions

Operations and precedence. For the particular shared-object functionalities considered here, the pro- cesses interact with an object Λ through operations provided by Λ. Operations on objects take time and are represented by two events occurring at a process, an invocation and a response. The history of an execution h consists of the sequence of invocations and responses of Λ occurring in h. An operation is complete in a history if it has a matching response.

An operation o precedes another operation o′ in a sequence of events h, denoted o

Semantics. A register with domain X provides two operations: write(x), which is parameterized by a value x ∈X and outputs a token ACK when it completes; and read, which takes no parameter for invocation but outputs a value x ∈X upon completion.

We consider a single-writer (or SW) register, where only a designated process pw may invoke write, and permit multiple readers (or MR), that is, every process may execute a read operation. The register is initialized with a special value x0, which is written by an imaginary write operation that occurs be- fore any process invokes operations. We consider regular semantics under concurrent access ; the extension to other forms of concurrent memory, including an atomic register, proceeds analogously.

It is customary in the literature to assume pw writes every value in X at most once. Furthermore, the writer and the reader are correct; with asymmetric quorums we assume explicitly that readers and writers are wise. We illustrate below why one cannot extend the guarantees of the register to na¨ıve processes.

Definition 8 (Asymmetric Byzantine SWMR regular register). A protocol emulating an asymmetric

Swmr Regular Register Satisfies:

Liveness: If a wise process p invokes an operation on the register, p eventually completes the operation. Safety: Every read operation of a wise process that is not concurrent with a write returns the value written by the most recent, preceding write of a wise process; furthermore, a read operation of a wise process concurrent with a write of a wise process may also return the value that is written concurrently.

Protocol With Authenticated Data

In Algorithm 1, we describe a protocol for emulating a regular SWMR register with an asymmetric Byzantine quorum system, for a designated writer pw and a reader pr ∈P. The protocol uses data authentication implemented with digital signatures. This protocol is the same as the classic one of Malkhi and Reiter that uses a Byzantine dissemination quorum system and where processes send messages to each other over point-to-point links. The difference lies in the individual choices of quorums by the processes and that it ensures safety and liveness for wise processes.

In more detail, every process stores a triple (ts, v, σ), which consists of a timestamp ts, a value v, and a signature σ. The idea is that the writer maintains a timestamp that increases with every write operation. The writer pw signs the timestamp/value pair and sends it in a message together with the signature to the processes, who will store the data if the timestamp within the received message is higher than the timestamp ts stored locally. A process then responds to pw with an ACK message. The change from the classic protocol is the writer pw obtains ACK messages from all processes in a quorum Qw ∈Qw for itself. The reader pr sends a READ message to all processes. It then waits to receive responses, which carry a triple of value, timestamp, and signature such that the signature is valid, from processes in a quorum Qr for pr. The returned value is the one from the triple with the highest timestamp.

The function highestval(S) takes a set of timestamp/value pairs S as input and outputs the value in the pair with the largest timestamp, i.e., v such that (ts, v) ∈S and ∀(ts′, v′) ∈S : ts′ < ts∨(ts′, v′) = (ts, v). Note that this v is unique in Algorithm 1 because pw is correct. The protocol uses digital signatures, modeled by operations signi and verifyi, as introduced earlier.

Theorem 11. Algorithm 1 emulates an asymmetric Byzantine SWMR regular register. Proof. First we show liveness for wise writer pw and reader pr, respectively. Since pw is wise by as- sumption, F ∈Fw∗, and by the availability condition of the quorum system there is Qw ∈Qw with F ∩Qw = ∅. Therefore, the writer will receive sufficiently many [ACK] messages and the write will Algorithm 1 Emulation of an asymmetric SWMR regular register (process pi).

:

wts: sequence number of write operations, stored only by writer pw

:

rid: identifier of read operations, used only by reader

:

ts, v, σ: current state stored by pi: timestamp, value, signature

:

wait for receiving a message [ACK] from all processes in some quorum Qw ∈Qw

:

wait for receiving messages [VALUE, rj, tsj, vj, σj] from all processes in some Qr ∈Qr such that

Return Highestval({(Tsj, Vj)|J ∈Qr})

16: upon receiving a message [WRITE, ts′, v′, σ′] from pw do

Send Message [Value, R, Ts, V, Σ] To Pr

return. As pr is wise, F ∈Fr∗, and by the analogous condition, there is Qr ∈Qr with F ∩Qr = ∅. Be- cause pw is correct and by the properties of the signature scheme, all responses from processes pj ∈Qr satisfy the checks and read returns.

Regarding safety, it is easy to observe that any value output by read has been written in some preced- ing or concurrent write operation, and this even holds for na¨ıve readers and writers. This follows from the properties of the signature scheme; read verifies the signature and outputs only values with a valid signature produced by pw.

We now argue that when both the writer and the reader are wise, then read outputs a value of either the last preceding write or a concurrent write and the protocol satisfies safety for a regular register. On a high level, note that F ∈Fw∗∩Fr∗since both are wise. So if pw writes to a quorum Qw ∈Qw and pr reads from a quorum Qr ∈Qr, then by consistency of the quorum system Qw ∩Qr̸ ⊆F because pw from pw and returns it to pr.

Example 3. We show why the guarantees of this protocol with asymmetric quorums hold only for wise readers and writers. Consider QA from the last section and an execution in which p2 and p4 are faulty, and therefore p1 is na¨ıve and p3 and p5 are wise. A quorum for p1 consists of p1 and three processes in {p2, . . , p5}; moreover, every process set that contains p3, one of {p1, p2} and one of {p4, p5} is a quorum for p3.

We illustrate that if na¨ıve p1 writes, then a wise reader p3 may violate safety. Suppose that all correct processes, especially p3, store timestamp/value/signature triples from an operation that has terminated and that wrote x. When p1 invokes write(u), it obtains [ACK] messages from all processes except p3.

This is a quorum for p1. Then p3 runs a read operation and receives the outdated values representing x from itself (p3 is correct but has not been involved in writing u) and also from the faulty p2 and p4. Hence, p3 outputs x instead of u.

Analogously, with the same setup of every process initially storing a representation of x but with wise p3 as writer, suppose p3 executes write(u). It obtains [ACK] messages from p2, p3, and p4 and terminates. When p1 subsequently invokes read and receives values representing x, from correct p1 and p5 and from faulty p2 and p4, then p1 outputs x instead of y and violates safety as a na¨ıve reader.

Since the sample operations are not concurrent, the implication actually holds also for registers with only safe semantics.

Ouble-Write Protocol Without Data Authentication

This section describes a second protocol emulating an asymmetric Byzantine SWMR regular register. In contrast to the previous protocol, it does not use digital signatures for authenticating the data to the reader. Our algorithm generalizes the construction of Abraham et al. and also assumes that only a finite number of write operations occur (FW-termination). Furthermore, this algorithm illustrates the use of asymmetric core-set systems in the context of an asymmetric-trust protocol.

This protocol extends Algorithm 1 and every process stores the most recently written timestamp- value pair (ts, v). Every write operation performs two rounds instead of one, a pre-write round and a write round. In addition to the previous protocol, every process stores the most recently pre-written timestamp-value pair (pts, pv). From the perspective of the writer pw, each round proceeds like the single round in Algorithm 1, except that pw does not produce a digital signature. In particular, pw waits in each round for responses that form a quorum Qw ∈Qw for itself.

The reader pr exchanges one round of messages with the processes and waits for responses that form a quorum Qr ∈Qr for pr. Every response contains the pre-written and the written timestamp- value pairs from the sending process. The reader collects these in an array readlist until the following condition is satisfied. A pair (ts∗, v∗), a core set Cr for pr of entries in readlist, and a quorum Qr for pr of entries in readlist exist such that (1) the pair (ts∗, v∗) is either the pre-written or the written pair in all entries of readlist in Cr; and (2) (ts∗, v∗) is the pair with the highest timestamp among the entries in Qr. Intuitively, the initial pre-write round and the core set Cr that reports this value to pr replace the step of authenticating the value through a digital signature. This respects safety because Cr, for a wise pr, contains at least one correct process that has not altered the value. The full protocol appears in Algorithm 2.

Theorem 12. Algorithm 2 emulates an asymmetric Byzantine SWMR regular register, provided there are only finitely many write operations. Proof. We first establish safety when the writer pw and the reader pr are wise. In that case, F ∈Fw∗∩ Fr∗. During in a write operation, pw has received PREACK and ACK messages from Qw ∈Qi and

Q′

w ∈Qi, respectively, and for all Qr ∈Qr it holds that Qw ∩Qr̸ ⊆F and Q′ w ∩Qr̸ ⊆F. We now argue that any pair (ts∗, v∗) returned by pr was written by pw either in a preceding or a concurrent write. From the properties of the core set Cr, because pr is wise, and together with the condition that (ts∗, v∗) satisfies, it follows that at least one correct process exists in Cr that stores (ts∗, v∗) as a pre-written or as a written value. Thus, the pair was written by pw before.

Next we argue that for every completed write(v∗) operation, in which pw has sent [WRITE, wts, v∗], and for any subsequent read operation that selects (ts∗, v∗) and returns v∗, it must hold wts ≤ts∗. Namely, the condition on Qr implies that ts∗≥tsk for all pk ∈Qr. By the consistency of the quorum

W ∩Qr̸ ⊆F, So There Is A Correct Process Pℓ∈Q′

w ∩Qr that has sent tsℓto pr. Then ts∗≥tsℓ≥wts follows because the timestamp variable of pℓonly increases. The combination of the above two paragraphs implies that for read operations that are not concurrent with any write, the pair (ts∗, v∗) chosen by read was actually written in the immediately preceding write.

If the read operation occurs concurrently with a write, then the pair (ts∗, v∗) chosen by read may also originate from the concurrent write. This establishes the safety property of the SWMR regular register. We now show liveness. First, if pw is wise, then there exists a quorum Qw ∈Qw such that Qw ∩ F = ∅. Second, any correct process will eventually receive all [PREWRITE, wts, v] and [WRITE, wts, v] messages sent by pw and process them in the correct order by the assumption of FIFO links. This means that pw will receive [PREACK] and [ACK] messages, respectively, from all processes in one of its quorums, since at least the processes in Qw will eventually send those.

Algorithm 2 Double-write emulation of an asymmetric SWMR regular register (process pi).

:

pts, pv, ts, v: current state stored by pi: pre-written timestamp and value, written timestamp and value

:

wait for receiving a message [PREACK] from all processes in some quorum Qw ∈Qw

Send Message [Read, Rid] To All Pj ∈P

14: upon receiving a message [VALUE, rj, ptsj, pvj, tsj, vj] from pj such that

:

if there exist ts∗, v∗, a core set Cr ∈Cr for pr, and a quorum Qr ∈Qr for pr such that

∧

(tsk < ts∗) ∨(ptsk, pvk) = (ts∗, v∗) ∨(tsk, vk) = (ts∗, v∗)

Send Message [Read, Rid] To All Pj ∈P

24: upon receiving a message [PREWRITE, ts′, v′] from pw such that ts′ = pts + 1 ∧pts = ts do

Send Message [Preack] To Pw

27: upon receiving a message [WRITE, ts′, v′] from pw such that ts′ = pts ∧v′ = pv do

Send Message [Value, R, Pts, Pv, Ts, V] To Pr

Liveness for the reader pr is shown under the condition that pr is wise and that the read operation is concurrent with only finitely many write operations. The latter condition implies that there is one last write operation that is initiated, but does not necessarily terminate, while read is active.

By the assumption that pw is correct and because messages are received in FIFO order, all messages of that last write operation will eventually arrive at the correct processes. Notice also that pr simply repeats its steps until it succeeds and returns a value that fulfills the condition. Hence, there is a time after which all correct processes reply with VALUE messages that contain pre-written and written times- tamp/value pairs from that last operation. It is easy to see that there exist a core set and a quorum for pr that satisfy the condition and the reader returns. In conclusion, the algorithm emulates an asymmetric regular SWMR register, where liveness holds only for finitely many write operations.

Broadcast

This section shows how to implement two broadcast primitives tolerating Byzantine faults with asym- of reliable message delivery and consistency, but they do not impose a total order on delivered messages (as this is equivalent to consensus). The Byzantine broadcast primitives described here, consistent broad- cast and reliable broadcast, are prominent building blocks for many more advanced protocols.

With both primitives, the sender process may broadcast a message m by invoking broadcast(m); the broadcast abstraction outputs m to the local application on the process through a deliver(m) event. Moreover, the notions of broadcast considered in this section are intended to deliver only one message per instance. Every instance has a distinct (implicit) label and a designated sender ps. With standard multiplexing techniques one can extend this to a protocol in which all processes may broadcast messages repeatedly .

Byzantine consistent broadcast. The simplest such primitive, which has been called (Byzantine) con- sistent broadcast , ensures only that those correct processes which deliver a message agree on the content of the message, but they may not agree on termination. In other words, the primitive does not en- force “reliability” such that a correct process outputs a message if and only if all other correct processes produce an output. The events in its interface are denoted by c-broadcast and c-deliver.

The change of the definition towards asymmetric quorums affects most of its guarantees, which hold only for wise processes but not for all correct ones. This is similar to the definition of a register in Section 5.

Definition 9 (Asymmetric Byzantine consistent broadcast). A protocol for asymmetric (Byzantine)

Consistent Broadcast Satisfies:

Validity: If a correct process ps c-broadcasts a message m, then all wise processes eventually c-deliver m. Consistency: If some wise process c-delivers m and another wise process c-delivers m′, then m = m′. Integrity: For any message m, every correct process c-delivers m at most once. Moreover, if the sender ps is correct and the receiver is wise, then m was previously c-broadcast by ps.

The following protocol is an extension of “authenticated echo broadcast” , which goes back to Srikanth and Toueg . It is a building block found in many Byzantine fault-tolerant protocols with greater complexity. The protocol first has the sender ps send its message m to all processes; then every process echoes m, in the sense that it rebroadcasts an ECHO message with m to all processes. As soon as a process receives a quorum of such ECHO messages that all contain the same m′, the process c- delivers m′. The adaptation for asymmetric quorums is straightforward: Every process considers its own quorum system before c-delivering the message.

Theorem 13. Algorithm 3 implements asymmetric Byzantine consistent broadcast. Algorithm 3 Asymmetric Byzantine consistent broadcast protocol with sender ps (process pi)

:

sentecho ←FALSE: indicates whether pi has sent ECHO

:

echos ←[⊥]N: collects the received ECHO messages from other processes

:

delivered ←FALSE: indicates whether pi has delivered a message

Send Message [Send, M] To All Pj ∈P

7: upon receiving a message [SEND, m] from ps such that ¬sentecho do

Echos[J] ←M

13: upon exists m̸ = ⊥such that {pj ∈P|echos[j] = m} ∈Qi and ¬delivered do

Output C-Deliver(M)

Proof. For the validity property, it is straightforward to see that every correct process sends [ECHO, m]. According to the availability condition for the quorum system Qi of every wise process pi and because F ⊆Fi for some Fi ∈Fi, there exists some quorum Qi for pi of correct processes that echo m to pi.

Hence, pi c-delivers m. To show consistency, suppose that some wise process pi has c-delivered mi because of [ECHO, mi] messages from a quorum Qi and another wise pj has received [ECHO, mj] from all processes in Qj ∈Qj.

By the consistency property of Q it holds Qi ∩Qj̸ ⊆F; let pk be this process in Qi ∩Qj that is not in The first condition of integrity is guaranteed by using the delivered flag; the second condition holds because because the receiver is wise, and therefore the quorum that it uses for the decision contains some correct processes that have sent [ECHO, m] with the message m they obtained from ps according to the protocol.

Example 4. We illustrate the broadcast protocols using a six-process asymmetric quorum system QC, defined through its fail-prone system FC. In FC, as shown below, for p1, p2, and p3, each process always trusts itself, some other process of {p1, p2, p3} and one further process in {p1, . . , p5}. Process p4 and p5 each assumes that at most one other process of {p1, . , p5} may fail (excluding itself). Moreover, none of the processes p1, . , p5 ever trusts p6. For p6 itself, the fail-prone set is {p1, p3}, i.e., it trusts p2, p4, and p5 unconditionally.

=

{{p3, p4, p5, p6}, {p2, p4, p5, p6}, {p2, p3, p5, p6}, {p2, p3, p4, p6}} One can verify that B3(FC) holds; hence, let QC be the canonical quorum system of FC. Again, there is no reliable process that could be trusted by all and QC is not a special case of a symmetric threshold Byzantine quorum system. With F = {p1, p5}, for instance, process p3 is wise, p2, p4, and p6 are na¨ıve, and there is no guild.

Consider now an execution of Algorithm 3 with sender p∗

P∗

5 to denote that they are faulty). This means processes p1, p2, p3 are wise and form a guild because {p1, p2, p3} is a quorum for all three; furthermore, p6 is na¨ıve. The protocol execution proceeds as

P6 : C-Deliver(U)

Hence, p1 receives [ECHO, x] from, say, {p1, p3, p∗ 4} ∈Q1 and c-delivers x, but the other wise processes do not terminate. The na¨ıve p6 gets [ECHO, u] from {p2, p∗

, P∗

5, p6} ∈Q6 and c-delivers u̸ = x. Byzantine reliable broadcast. In the symmetric setting, consistent broadcast has been extended to (Byzantine) reliable broadcast in a well-known way to address the disagreement about termination among the correct processes . This primitive has the same interface as consistent broadcast, except that its events are called r-broadcast and r-deliver instead of c-broadcast and c-deliver, respectively.

A reliable broadcast protocol also has all properties of consistent broadcast, but satisfies the addi- tional totality property stated next. Taken together, consistency and totality imply a notion of agreement, similar to what is also ensured by many crash-tolerant broadcast primitives. Analogously to the earlier primitives with asymmetric trust, our notion of an asymmetric reliable broadcast, defined next, ensures agreement on termination only for the wise processes, and moreover only for executions with a guild.

Also the validity of Definition 9 is extended by the assumption of a guild. Intuitively, one needs a guild because the wise processes that make up the guild are self-sufficient, in the sense that the guild contains a quorum of wise processes for each of its members; without that, there may not be enough wise processes.

Definition 10 (Asymmetric Byzantine reliable broadcast). A protocol for asymmetric (Byzantine) re- liable broadcast is a protocol for asymmetric Byzantine consistent broadcast with the revised validity condition and the additional totality condition stated next: Validity: In all executions with a guild, if a correct process ps r-broadcasts a message m, then all processes in the maximal guild eventually r-deliver m.

Authors:

Peder EZ Larson 1, 2,* , Jenna ML Bernard1, James A Bankson 3, Nikolaj Bøgh 4, Robert A Bok1, Albert P. Chen 5, Charles H Cunningham 6,7, Jeremy Gordon1, Jan-Bernd Hövener 8, Christoffer Laustsen 4, Dirk Mayer 9,10, Mary A McLean11 12, Franz Schilling13, James Slater1, Jean-Luc Vanderheyden5, 14, Cornelius von Morze 15, Daniel B Vigneron1, 2, Duan Xu1, 2, and the HP 13C

94143, Usa.

Denmark. 5 GE Healthcare, Menlo Park, California, USA. 6 Physical Sciences, Sunnybrook Research Institute, Toronto, Ontario, Canada.

ansys-mri-compatible-device Diagram
Figure: System Model & Simulation Flow for Ansys Mri Compatible Device

8 Section Biomedical Imaging, Molecular Imaging North Competence Center (MOIN CC), Medicine, Baltimore, MD, USA. Cambridge, United Kingdom.

ansys-mri-compatible-device Diagram
Figure: System Model & Simulation Flow for Ansys Mri Compatible Device

14Jlvmi Consulting Llc, Dousman, Wi, Usa

#See Acknowledgements for a list of all HP 13C MRI Consensus Group Members This work was supported by the ISMRM Hyperpolarized Media MR Study Group, the ISMRM Hyperpolarization Methods & Equipment Study Group, and the Hyperpolarized MRI Technology Resource Center (NIH/NIBIB grant P41EB013598).

ansys-mri-compatible-device Diagram
Figure: System Model & Simulation Flow for Ansys Mri Compatible Device

Abstract

MRI with hyperpolarized (HP) 13C agents, also known as HP 13C MRI, can measure processes such as localized metabolism that is altered in numerous cancers, liver, heart, kidney diseases, and more. It has been translated into human studies during the past 10 years, with recent rapid growth in studies largely based on increasing availability of hyperpolarized agent preparation methods suitable for use in humans. This paper aims to capture the current successful practices for HP MRI human studies with [1-13C]pyruvate - by far the most commonly used agent, which sits at a key metabolic junction in glycolysis. The paper is divided into four major topic areas: (1) HP 13C-pyruvate preparation, (2) MRI system setup and calibrations, (3) data acquisition and image reconstruction, and (4) data analysis and quantification. In each area, we identified the key components for a successful study, summarized both published studies and current practices, and discuss evidence gaps, strengths, and limitations. This paper is the output of the “HP 13C MRI Consensus Group” as well as the ISMRM Hyperpolarized Media MR and Hyperpolarized Methods & Equipment study groups. It further aims to provide a comprehensive reference for future consensus building as the field continues to advance human studies with this metabolic imaging modality.

ansys-mri-compatible-device Diagram
Figure: System Model & Simulation Flow for Ansys Mri Compatible Device

Keywords: Hyperpolarized MRI, metabolic imaging, carbon-13, pyruvate, dissolution dynamic

Introduction

MRI with hyperpolarized 13C agents, also known as hyperpolarized (HP) 13C MRI, has shown great potential as a novel imaging modality, particularly for its ability to probe metabolic processes in real time. The first human studies with HP [1-13C]pyruvate were performed in 2011 in prostate cancer patients (1).

ansys-mri-compatible-device Diagram
Figure: System Model & Simulation Flow for Ansys Mri Compatible Device

Since then, there have been over 60 papers published with imaging results of human subjects from 13 different sites, with applications including prostate cancer, brain tumors, breast cancer, kidney cancer, pancreatic cancer, metastatic disease, liver disease, ischemic heart disease, diabetes and cardiomyopathies. The vast majority of these studies used [1-13C]pyruvate (1–63), where [2-13C]pyruvate (64) and 13C-urea (56) have been demonstrated too.

ansys-mri-compatible-device Diagram
Figure: System Model & Simulation Flow for Ansys Mri Compatible Device

As clinical HP 13C MRI advances, there is a growing need to build consensus for best practices, which are critical for comparing data across sites, performing multi-site trials,deploying methods to new sites, partnering with vendors, and potentially for obtaining broader regulatory approvals.

ansys-mri-compatible-device Diagram
Figure: System Model & Simulation Flow for Ansys Mri Compatible Device

In March 2022, we initiated an effort to build consensus within the HP 13C MRI community with this opportunity in mind, and it was greeted with strong enthusiasm. The “HP 13C MRI Consensus Group”, containing over 55 members from 27 sites, identified the area of greatest need and opportunity for consensus building to be HP [1-13C]pyruvate human

●

Pyruvate is the most mature and widely used HP agent and has the most significant translational evidence emphasizing the potential clinical impact.

●

Clinical trials, particularly multi-site trials, have the strongest need for consensus methods to ensure that data can be combined across sites. This work is a Position Paper for which the goal is to describe current successful practices and study methods for HP [1-13C]pyruvate human studies along with justification to support those practices. This is divided into four major topic areas: (1) HP 13C-pyruvate preparation, (2) MRI system setup and calibrations, (3) data acquisition and image reconstruction, and (4) data analysis and quantification (Fig. 1). The current successful practices and study methods include a literature review of published peer-reviewed journal papers showing human HP [1-13C]pyruvate study data, up to September 2022 (1–63), as well as new unpublished information from surveys of HP 13C study sites. Based on this information, we also highlight the evidence gaps, strengths, and limitations of current practices which are summarized at the end of each section.

ansys-mri-compatible-device Diagram
Figure: System Model & Simulation Flow for Ansys Mri Compatible Device

Figure 1: Illustration of the HP 13C MRI human study process, including the 4 major areas covered in this paper: Hyperpolarized 13C-pyruvate preparation, MRI system setup and calibration, Acquisition and Reconstruction, and Data Analysis and Quantification.

ansys-mri-compatible-device Diagram
Figure: System Model & Simulation Flow for Ansys Mri Compatible Device

Figure 2: Anatomical targets of HP [1-13C]pyruvate MRI human studies published up to September 2022.

Hyperpolarized 13C-Pyruvate Preparation

This section covers the processes for creating the HP agent, 13C pyruvate, and will include many aspects and considerations that are needed to safely and effectively prepare doses for metabolic imaging studies in human subjects. These include material, personnel, equipment and facility, fluid path preparation, quality control, and release.

ansys-mri-compatible-device Diagram
Figure: System Model & Simulation Flow for Ansys Mri Compatible Device

It is helpful to understand that the specifications of a dose of 13C pyruvate suitable for in vivo MR HP metabolic imaging were shaped in part by early preclinical studies performed by GE HealthCare summarized in Ref. (65). In short, the safety of the two novel drug components, 13C pyruvate and the electron paramagnetic agent (EPA) AH111501, were demonstrated in those studies. The more precise formulation of the dose suitable for human use was then determined from clinical studies (66) that included two Phase 1 clinical trials in young and elderly healthy volunteers without hyperpolarization of the 13C nuclei and another Phase 1/2a dose escalation and imaging feasibility study with HP 13C pyruvate in 31 prostate cancer patients at the With the exception of the first HP 13C imaging clinical trial, which utilized a prototype device in a cleanroom (1), all HP 13C studies performed in humans to date have utilized the SPINlab polarizer (manufactured by GE HealthCare). Consequently all doses of the HP 13C pyruvate delivered by SPINlab have been produced using the “SPINlab Pharmacy Kit” that serves as the container-closure system for the various drug components (13C pyruvic acid and EPA mixture, dissolution medium, and neutralization and dilution medium) during sample polarization, dissolution and quality control (QC) processes. Thus many aspects of the HP sample preparation considerations discussed below are related to the SPINlab instrument and the consumables designed to be used with it (67).

General Considerations

While more than 860 patients or healthy subjects having been injected with HP 13C pyruvate as of January 2022 without reports of any serious adverse events (68), HP 13C pyruvate injection remains an investigational MR contrast agent and can only be administered by those with Investigational New Drug (IND) exemption from the Food and Drug Administration (FDA) in the USA, a Clinical Trial Application (CTA) in Canada, approval from National Research Ethics Committee Services in the UK, or approval from the relevant local regulatory body. Thus, methods and processes involved to produce a dose should have patient safety as the first priority. Since utilizing dissolution dynamic nuclear polarization (dissolution-DNP) for human use is still a relatively new development, there are no existing published regulatory guidelines specifically for this method.

There are two major production styles that determine how various sites approach the agent preparation. In the US, the most common approach is to rely on a sterilizing filter (“Terminal Sterilization”) to ensure sterility of the final product, akin to PET tracer production, where a starting molecule with a radioisotope is processed using various other ingredients to make the final, desired and injectable contrast agent within a necessarily short amount of time (69). For these sites, sterilization of the components and accessories upstream of this filter are not required, although many of them were manufactured and tested following Good Manufacturing Practice (GMP) or Good Laboratory Practice (GLP) requirements. The filling process is usually performed under an ISO 5 laminar flow hood, but a clean room or an isolator is not required.

This approach is typically accompanied by testing the integrity of the sterilizing filter prior to release of the dose for injection. Typically, post release endotoxin and sterility tests are performed using an aliquot reserved from each released dose.

In the UK and EU, the most common approach is to more-closely follow sterile pharmaceutical compounding guidelines (70), where all components and ingredients are required to be sterile or manufactured under GMP guidelines and are assembled and filled within a clean room environment or an isolator system (“Sterile Preparation”). Typically a batch of Pharmacy Kits for HP 13C pyruvate injection are prepared together. The sterility of the final dose is also ensured by batch validation testing, in addition to the sterility of the ingredients and the sterile compounding process. The endotoxin and sterility testing are performed for the process validation but are not performed for each injected dose.

Some institutions fill and assemble the Pharmacy Kit required for a specific study on the same day or the day prior to polarization, dissolution, and patient administration, but others have also demonstrated the feasibility of preparing a batch of kits, keeping them in a -20ºC freezer and using them over a period of a few months.

Beyond the obvious requirements that the process and the facility has to ultimately produce a dose that is safe to inject into a human, regulatory authorities will also focus on the question “Are you in control of your processes?”. To be in control of your process requires an in-depth and broad understanding of all processes involved in pre, post, and during the production process.

Personnel

It is typical and may be required to have licensed personnel involved in the production process depending on local regulations.Typically a pharmacist, radiopharmacist or other similarly qualified person (QP), in charge of the facility where the Pharmacy Kit filling and preparation is taking place, is responsible for the overall process and the release of the injectable dose.

Qualified cleanroom technicians are often involved in the Pharmacy Kit filling under the supervision of the pharmacist or QP. As is required for pharmaceutical compounding or PET tracer production, training requirements and training records for all personnel need to be maintained and available for audit by the FDA or equivalent.

Equipment And Facility

The facility and all equipment need to have standard operating procedures (SOPs) that describe how equipment is used, maintained, and calibrated to comply with relevant legislation. Currently, almost all the filling of the Pharmacy Kit takes place within a compounding laminar flow hood or isolator (typically ISO 5). At some sites, the filling is conducted within a cleanroom, while at others, it is conducted in a dedicated non-cleanroom space, reflecting differences in cleanroom approach and specifications between regulators worldwide (71). Some equipment or facilities, such as the compounding hood or cleanroom, may require external certified laboratories for testing.

Material Handling

Material handling guidelines (69,70) require SOPs detailing a system to track all of the materials involved in the HP production process for a particular patient dose, similar to current good manufacturing practice (cGMP) requirements for material handling for drug compounding. This includes acceptance standards, storage conditions, amount used in the patient dose for each ingredient and materials used in the assembly of the fluid path and Pharmacy Kit. Currently some users choose to open and inspect and sometimes modify the Pharmacy Kits upon arrival, but some users keep them in the sealed packaging until they are required for dose preparation.

Pharmacy Kit Filling And Assembling

As required by an IND or its equivalent, the preparation of the doses of HP 13C agent are detailed in the Chemistry, Manufacturing, and Control (CMC) section of an applicable regulatory submission; an example of this has been made available (72). It describes the processes of filling the Pharmacy Kit with the different components that make up the final drug product, and of assembling the final kit for either storage or immediate use in the polarizer. Special attention should be given to the laser welding process in order to satisfy installation qualification (IQ) and operational qualification (OQ). Typically, the final developed process is validated by process qualification (PQ) runs, during which 3 or more Pharmacy Kits are filled and used and the final HP 13C products are tested for endotoxin and sterility and to confirm that they meet the dose specifications for injections (usually including pyruvate concentration, residual EPA concentration, pH, liquid state polarization level and dose temperature). The data from 3 consecutive PQ runs are submitted as part of the IND submission (or its equivalent), and are often also reviewed by the Institutional Review Board (IRB) where the studies are conducted.

Quality Control And Dose Release

The quality control (QC) and dose release can be separated into two aspects: one is the QC and release of the filled Pharmacy Kit, and second is the QC and release of the HP 13C agent for injection, after polarization and dissolution. For institutions filling a batch of kits and storing them to use over a period of time, typically the batch can be released based on initial validation, environmental monitoring data from the day of kit production, and if filters are used during preparation of any of the components, filter integrity testing. But in some cases one or more kits are used for validation before the batch of kits are released for future use. For institutions that fill only the kits required for specific studies shortly before the experiment, the filled kits often do not go through separate release tests before they are used.

The quality control of the HP 13C pyruvate solution post dissolution is primarily performed to ensure that the agent meets the dose specifications (Table 1) before it is administered to the subject. These specifications target both safety (pH, residual EPA, temperature) and efficacy (pyruvate concentration, polarization, volume). Typically, the pyruvate concentration, residual EPA concentration, pH, dose temperature, dose volume, and liquid state polarization are measured by the QC accessory associated with the SPINlab polarizer. Some users perform a secondary measurement for one of the parameters, such as pH, using a different instrument or pH paper. For sites that do not go through a separate release testing process for batch filled kits, the integrity of the sterilization assurance filter, a part of the Pharmacy Kit, is typically tested as a part of the dose release. It is also common for these users to preserve an aliquot of the final HP 13C pyruvate solution for post-release endotoxin and sterility testing. This testing cannot be completed fast enough to test an individual dose prior to injection, but this is why other processes such as PQ runs and validation testing are done to minimize the chance a subject could be injected with a contaminated dose.

The Final Dose Release And Injection

should be done under the supervision of a licensed professional, based on local regulations.

Some Key Challenges

Many of the challenges associated with HP 13C pyruvate preparation can be attributed to the conditions required for the dissolution-DNP method of high magnetic field (~3-7 T) and very low temperature (~1 K) during polarization, with pressurized and superheated water necessary for the rapid dissolution event. These extreme conditions are quite challenging for the design of the container-closure and fluid path system. In particular, the cryogenic temperature in the polarizer requires special attention to any moisture or ambient (moist) air introduced into that portion of the fluid path, which can form an ice block at ~1 K. This ice can lead to flow restriction during the dissolution event and reduce the strength of the laser welded bond between the cryovial and its cap. This can ultimately produce failures in the dissolution step, including variations in final pyruvate concentration and pH that may fail to meet QC release criteria as well as fluid path ruptures that provide no available dose and result in polarizer down-time.

The polarization of the HP 13C pyruvate sample decays quickly over the span of a few minutes after dissolution, and thus the process of dissolution, QC for release, and injection should be completed as fast as possible to preserve the high polarization level achieved. Any delays in the preparation process, such as transportation time or equipment malfunction, can significantly reduce the final polarization and result in lower quality imaging data.

Current Practices

A summary of data collected from all sites performing clinical trials with HP 13C-pyruvate is shown in Fig. 3 and Table 1, including the specification of the final dose and how the quality control and release of the final dose are performed. There is a split in the Production Style, described in the General Considerations section above, with 8/13 sites using Sterile Preparation versus 5/13 using Terminal Sterilization. While many of the dose specifications show notable differences in acceptable ranges, all of these variations listed in tables have been successfully and safely been used to perform HP 13C pyruvate studies in humans. Their differences depend on the institutions’ preferences, resources and their particular regulatory situation. There is high similarity in pyruvate ranges, temperature ranges, EPA limits, and volume limits. There is modest variability in pH ranges and large variability in the endotoxin test limit. There is a 3-fold difference in acceptable polarization levels, which are measured to ensure a futile dose is not injected since the polarization is directly proportional to SNR. This reflects the decision by several sites to believe that useful data can be still be obtained with suboptimal polarizations.

Figure 3: Hyperpolarized agent preparation methods reported by sites currently performing HP

In House

Table 1: HP 13C-pyruvate preparation parameters, methods, and dose specifications used for quality control testing and release as well as validation. These were obtained from a survey of all sites performing clinical trials with HP [1-13C]pyruvate. The parameters used for product release are noted in bold text, otherwise these parameters are measured for batch validation or other QC measurements. The endotoxin and sterility testing are performed during process validation of the batch and/or post-injection, and largely depends on the agent production approach.

Summary

The overall safety record of HP 13C-pyruvate has been very strong, and the SPINlab hyperpolarizer has proven to provide high polarizations at human sized doses while meeting numerous QC and release criteria. A weakness remains the failure modes of the SPINlab Phamacy Kits (e.g. ice blocks, path ruptures), which are placed under extreme requirements particularly during dissolution. The preparation process still requires a high degree of expertise.

Therefore, there is a significant need to improve the reliability, robustness, and ease of operation for generating HP 13C-pyruvate doses for human studies. Furthermore, there is a divide between manufacturing and sterile compounding style preparation as well as other site-specific practices, resulting in variations in SOPs and justification required to relevant regulatory bodies. There have also been no comparisons between these approaches. It is also unclear what release criteria and QC parameters are truly required to ensure patient safety.

However, all of the reported methods are acceptable and approved by the appropriate regulatory authorities, and have led to the rapid expansion of successful human studies in recent years.

Mri System Setup And Calibrations

This section covers the MRI system setup, including the imaging system, RF coils, phantoms, and prescan calibration methods.

Imaging System

The main prerequisite for a given MRI scanner to be capable of supporting studies with HP 13C is its “broadband” capability to transmit and receive radiofrequency (RF) signal at the frequency of 13C, which is around 4 times lower than 1H. This does not come as a default on clinical MR devices. The transmit power of the broadband amplifier should also be sufficient to support the intended flip angle and RF pulse shape with the employed transmission RF coil(s) for 13C. Most studies to date use relatively low flip angles (< 90 degrees) for HP 13C in order to preserve polarization for time-resolved imaging. The capability to receive 13C signal on multiple channels is also desirable to increase SNR, as discussed further in the “RF coils” section.

The choice of magnetic field strength is primarily dependent on the metabolites’ frequency separation due to chemical shift dispersion and 1H imaging. High field strengths do not enhance hyperpolarized 13C signal as they do for 1H because the signal strength in a HP experiment relies on manipulating the population of quantum energy states outside of the MRI scanner.

However, the injected HP 13C-pyruvate and its metabolic products have greater frequency separation at higher fields, and it may thus be easier to separate and quantify these resonances at higher fields. This comes at the cost of a reduction in the achievable T2* and often reduced T1. As the initial polarization is independent of the imaging field strength it has been proposed that the increased T2* at 1.5T can potentially be exploited to increase SNR by adapting the acquisition bandwidth or reduce off-resonance imaging effects in cases when the decay of the transverse magnetization is dominated by T2* (73). In practice, 3T has been used in all published human 13C-pyruvate studies surveyed (Supporting Table S1), and comprises the majority of scanners currently in use for human studies (Table 3). A field strength of 3T is well-suited for 1H MRI anatomical reference and correlative imaging.

Stronger and more rapidly slewing magnetic field gradients support more rapid spatial encoding, particularly for metabolite-specific single-shot imaging using echo-planar imaging (EPI) or spiral imaging (See “Acquisition and Reconstruction”). Although the spatial resolution acquired for HP 13C imaging is typically much coarser than for 1H MRI, the factor of ~4 in gyromagnetic ratio leads to the same reduction factor in performance of the gradient system, so 13C experiments are potentially more limited by gradient hardware performance. To date, all human studies have used the commercially-available integrated gradient systems provided in clinical MRI scanners.

Optimization of scanner design has understandably focused on minimization of artifacts in 1H MRI, where devices such as room lights, the gradient amplifiers, and the motors driving the patient bed are checked to ensure that they do not produce RF interference at the 1H frequency, but artifacts may arise at other frequencies. Eddy current compensation is also not always appropriately adjusted for nuclei at other frequencies (74). In order to optimize for 13C, many sites have performed checks on phantoms for RF interference, gradient artifacts, and eddy currents (74), including the use of post-hoc gradient impulse response function characterisation and correction, and some vendors have fixed these issues as well.

Rf Coils

For HP 13C imaging studies in humans, RF coils for both 1H and 13C nuclei are needed, with 1H MRI providing an anatomical reference for registration and optional additional multiparametric MRI readouts. At the Larmor frequency of 13C nuclei, the relative contributions from coil noise compared to sample noise increase compared to 1H (73,75), although sample noise still is likely the dominant contributor for human-sized coils at 32.1MHz - the resonance frequency of 13C nuclei at 3T.

The key requirement for human 13C-pyruvate RF coils are that the coil geometry and sensitive volume must cover the volume of interest in the subject. Table 2 and Figure 4 shows coil configurations that have been used and optimized for applications in different anatomic regions.

Volume resonators are most commonly used for transmit, as they surround the subject to

Provide B1 Transmit Across The Fov (B1

+). While 1H relies on a large birdcage (“body”) coil built into the scanner, 13C transmit coils must be placed inside the bore. This takes up valuable space within the magnet, and also has led to the use of designs with relatively inhomogeneous

B1

+. Many human studies have used Helmholz pair resonators for transmit, including the “clamshell coil”, which has a notably inhomogeneous B1

+ Profile But Has Been Used Because Of

relatively easy integration into the scanner bore. B1

+ Variation Results In Variations In The Flip

angles that control the use of the hyperpolarized magnetization and creates errors in common HP metrics (9,76). The exception are head coils, where birdcage designs with highly

Homogeneous B1

+ can be placed around the head while easily fitting inside the bore. As with 1H MRI, higher SNR can typically be achieved by smaller receive coil elements, such as surface coils or phased arrays, and the majority of 13C receive coils used have layouts similar to 1H phased arrays.

RF coil quality control is important to ensure proper functioning of the coils to provide consistent imaging quality, especially with limited natural abundance 13C signal in vivo. It typically involves 1) a physical integrity check of the coil cables and connectors and 2) phantom SNR tests to check the coil’s performance and to monitor it over time (see Phantoms below). An useful reference for RF coil quality control is outlined in the MRI accreditation program of the American College of Radiology (77) and can be adapted for 13C coils.

Notably, configurations for brain and prostate studies used dual-tuned 1H/13C coil designs, which greatly simplify workflow and registration of 1H and 13C images, as no switching of coils is needed.

(1)

Table 2: RF coil configurations reported for human HP [1-13C]pyruvate studies.

Tx = Transmit

coil, RX = receive coil. The commonly used “clamshell” TX coil is a Helmholz pair design. For 1H RF configurations, all used the Body coil for TX unless otherwise noted, and “repositioned” indicates the 13C coil was removed for 1H imaging. One representative reference is listed for each configuration. The RF coil configurations reported in the reviewed papers are shown in Supporting Table S1.

Figure 4: Examples of RF coil configurations used for human HP [1-13C]pyruvate brain studies. (A,B) 13C Clamshell TX (Helmholz pair) and 2× 4-channel paddle RX arrays. (C) 13C Birdcage volume TX and 32-channel RX array (RX array slides into TX coil). (D) 13C Birdcage volume TX and 24-channel RX array, combined with a 1H 8-channel RX array. Image reproduced with permission from Ref (16).

Phantoms

Since hyperpolarized magnetization is non-renewable, phantoms containing 13C nuclei are important to: 1) test the multi-nuclear capabilities of the imaging system, including all parts of the signal excitation and receive chain; 2) perform calibration measurements before a scan with hyperpolarized nuclei; and 3) perform necessary pre-scan adjustments (see “Prescan Calibration” section). The phantoms currently in use are listed in Table 3. Their composition must provide sufficient 13C signal, with additional considerations of conductivity, stability, chemical shift(s) present, potential for dynamic imaging, and cost. The phantom geometries are typically either compact, in order to be used alongside the subject during a HP scan, or large enough to mimic the inner volume of a RF coil for system testing.

One popular compact design contains enriched 13C-urea at high concentration, typically 8 M, which provides a single resonance, placed inside a small container ~1 mL. The most common recipe mixes 13C-urea in a 90% water/10% glycerol solution, with glycerol used to increase the urea solubility and doping with a Gd-based contrast agent to shorten T1 which increases the potential SNR per unit time. For example, when Dotarem is added at a 3:1000 volume ratio the 13C-urea T1 is around 500 ms and T2 is around 100 ms. However, when testing pulse sequences influenced by T1 and T2, doping should be used carefully. This phantom is suitable for frequency calibration, transmit gain calibration, sequence testing, and as a fiducial marker when placed next to a patient. However, enriched 13C-urea has a relatively high cost compared to natural abundance compounds.

For larger volumes (>100 ml), the phantoms most often used contain undiluted ethylene glycol, glycerol, or dimethyl silicone. These compounds have sufficiently high carbon concentrations to provide sufficient 13C signal even with the 1.1% natural abundance of 13C. These larger phantoms matching the inner volume of an RF coil are useful for coil testing, including transmit

+) And Receive (B1

-) coil profile mapping, as well as to mimic acquisitions using in vivo FOV requirements. In this case, size and conductivity should match the expected subject size in order to mimic coil loading and get a realistic estimation of B1+. Large-volume natural abundance urea phantoms have also been used by some sites, but suffer from higher conductivity compared to biological tissues. Typically, it is easier to increase the conductivity and hence coil loading of the non-conductive phantom by adding NaCl to match physiological loading (16,78).

Dynamic phantoms that aim to mimic metabolite kinetics have also been developed (79–81), and have the potential to more closely mimic the HP experiment, but so far these are not widely used.

Prescan Calibration

Prior to performing an MRI acquisition, the so-called prescan procedure is used to set the shim parameters to maximize B0 homogeneity over the field of view (FOV) or a specific region of interest (ROI), the scanner center frequency (CF), the RF transmit gain, and the receiver gain.

While this calibration procedure is usually automated for 1H, the lack of sufficient natural abundance 13C signal prevents use of automated methods. (Although natural abundance 13C lipid signal has been detected, there are so far no reports on using this signal for prescan.) Table 3 shows current practices across sites.

Maximizing B0 homogeneity is independent of the nucleus and is therefore performed prior to 13C imaging using the 1H water signal and existing shimming tools, such as by a standard automated process (“Auto Shimming”) or using high order shimming routines. Similarly, the 13C CF can be calculated from the 1H CF using a predetermined scaling factor that depends on the target chemical shift (82). Another common approach used is to have a small, high-concentration 13C phantom, e.g. 8M 13C-urea, integrated in the RF coil or placed next to the scan subject (1). The reference frequency can also be based on real-time measurements after the HP injection but prior to imaging (83). Both the CF and B0 shimming are critical when using spectrally-selective RF pulses, as inmetabolite-specific imaging methods, where the desired excitation bandwidths are typically very narrow and frequency offsets can lead to a failure mode that is only apparent after injection.

The calibration of the RF transmit power is typically performed on a small, high-concentration 13C phantom placed near the region of interest during the scan or on a large 13C phantom of similar size and coil loading as the subject, prior to the subject scan. Reference power is often done by sweeping the power in a pulse-acquire sequence (53,62), or the Bloch-Siegert method (52,84). When using a small phantom, the location of the phantom, B1

+ Inhomogeneity As Well

as any shielding effects, e.g., when the phantom is integrated into a coil (1), may degrade the accuracy. Other methods include real-time Bloch-Siegert method measurements after the HP injection (83), and using the stronger natural abundance 23Na signal that is close enough to the 13C resonance frequency to be detected by 13C coils (82).

The receiver gain is predetermined, either systematically based on independent phantom measurements and assuming the dose and polarization of the HP compound is known prior to injection, or based on past HP imaging studies.

Power [Kw]

Phantom(s) - during study Phantom(s) - before study 13C Frequency

8

13C-bicarbonate doped with dimethyl silicone, various

Power [Kw]

Phantom(s) - during study Phantom(s) - before study 13C Frequency

Maximum Values

Table 3: Summary of the imaging systems, phantoms, and prescan procedures used at sites currently performing HP 13C-pyruvate human studies. These were obtained from a survey of all sites performing clinical trials with HP [1-13C]pyruvate. *Previously performed studies with a Siemens 3T Tim Trio. The imaging systems, phantoms, and prescan procedures reported in the reviewed papers are shown in Supporting Table S1.

Summary

Commercially available 3T MRI systems are by far the most commonly used for human HP 13C-pyruvate studies, although a systematic investigation of the impact of B0 has only recently been investigated (73). The multi-nuclear RF transmit and receive chain has proven sufficient for current acquisition strategies, although many sites have observed artifacts due to RF interference, gradient interference, and residual eddy currents when operating at the 13C frequency. A variety of 13C RF coils, tailored for numerous anatomical targets, have been successfully demonstrated, with the main limitation that most transmit coils take up a lot of additional space inside the bore and provide relatively inhomogeneous B1

+ Profiles. The

phantoms used have converged into generally 2 categories - small phantoms containing 13C-enriched compounds that can be used during the study and human-sized phantoms containing compounds with high carbon concentrations but without 13C enrichment that are used to test and calibrate the coils. There are no standardized compositions or geometry, and dynamic phantoms that recapitulate in vivo kinetics would be desirable but are still an emerging area. Prescan calibration procedures were not well defined in most publications, so we surveyed individual sites to determine current practices. Calibration procedures for the B0 field (13C CF and shimming) for most sites take advantage of 1H signal and methods, while methods

For Calibration Of B1

+ is more variable across sites, likely a reflection of remaining challenges in how to perform this calibration. Standardization of both phantoms and calibration procedures would synergistically improve the robustness and reproducibility of HP 13C studies.

Acquisition And Reconstruction

Data acquisition strategies in human HP [1-13C]pyruvate MRI studies must account for multiple chemical shifts, efficiently utilize the non-renewable HP magnetization, and acquire data quickly relative to metabolism and relaxation decay processes. These studies require spectral encoding to separate metabolites, necessitating pulse sequences that efficiently encode up to 5D data (3 spatial + 1 spectral + 1 temporal dimension). RF pulses must efficiently sample without immediately saturating the non-renewable HP magnetization, and sequences must acquire data quickly and be robust to both experimental and physiologic variation (e.g. B1

+ Inhomogeneity,

variation in perfusion) to ensure reproducibility and minimize scan-to-scan variability. This section covers current successful practices for data acquisition in human [1-13C]pyruvate studies, and accompanying 1H imaging, from different anatomic regions, including scan parameters and image reconstruction.

Acquisition And Reconstruction Methods

The acquisition methods used in human [1-13C]pyruvate studies can be classified into 3 categories: 1) MR spectroscopy or MR spectroscopic imaging (“MRS/I”), 2) chemical shift encoding methods, and 3) metabolite-specific imaging (Fig. 5).

Mrs/I Methods Specifically

resolve a spectrum that can be analyzed to extract expected as well as unexpected resonances, making this approach very robust. It was used in many initial studies (1).

Chemical Shift

encoding methods, most commonly the Iterative Decomposition of water and fat with Echo Asymmetry and Least-squares estimation (IDEAL) method, use imaging sequences acquired with multiple TEs and rely on a model-based separation of expected chemical shifts (85).

Metabolite-specific imaging methods use specialized RF pulses that are spatially and spectrally selective to excite individual metabolites which are then typically imaged with fast k-space trajectories such as echo planar imaging (EPI) or spirals (86).

Their Application To Different

organ systems is described below. The image reconstruction methods used in human [1-13C]pyruvate studies have typically been conventional methods (e.g. FFT, non-uniform FFT, or equivalent). The incorporation of accelerated imaging and advanced reconstruction methods including parallel imaging (4,57,87) and compressed sensing (7) has also been applied in human studies for improved spatial resolution, temporal resolution and coverage, but have the potential for additional artifacts as well as SNR losses due to ill-conditioning of the reconstruction (e.g. g-factor).

The Majority Of

published studies do not use accelerated imaging indicating the resolution and coverage achievable without acceleration is currently adequate for successful data collection. Performing coil combination, even with fully sampled data has also been shown to have specific challenges for HP human images: using naive sum-of-squares methods suffer from high noise amplification in the relatively low SNR regime of HP [1-13C]pyruvate (compared to 1H), motivating several HP 13C-specific methods that include data-driven coil sensitivity estimation which have shown obvious improvements over sum-of-squares (11).

More recently denoising techniques have been applied as post-processing of human HP data(41,42,44). The techniques applied are based on spatial-temporal singular value decomposition for unsupervised estimation of signal and noise components. They have shown improvements in apparent SNR in the brain and liver, while care must be taken to choose parameters such as the rank threshold to avoid oversmoothing and overfitting to the estimated signal components.

Prostate Studies

Prostate cancer was the first human application of HP [1-13C]pyruvate (1), and data was acquired with MRS/I methods: 1D dynamic MRS, single-slice 2D dynamic echo-planar spectroscopic imaging (EPSI), and single time point 3D EPSI. Advances in imaging strategies led to the development and application of new acquisition schemes, including undersampled 3D EPSI with compressed-sensing (7), model-based chemical shift encoding methods that use a priori information (47,59), and metabolite-specific EPI (10), all of which can provide volumetric whole-organ coverage and dynamic acquisitions.

The pyruvate bolus arrival in the prostate can vary by ± 10 s between patients, necessitating dynamic imaging to reliably and consistently capture the pyruvate bolus (18). For this reason, all currently ongoing studies acquire dynamic data. While MRS/I, chemical shift encoding, and metabolite-specific imaging can all achieve dynamic imaging, chemical shift encoding and metabolite-specific imaging provide greater dynamic and volumetric coverage (85). For scan prescriptions, the FOV is designed to provide full prostate coverage and typically to match the orientation of the anatomic imaging used for registration. Flip angles used in current studies are constant through time, as quantification with a variable-through-time flip scheme is highly sensitive to bolus timing (8) and errors in the RF transmit (B1 +) field (76).

Heart Studies

Data acquisition methods for 13C imaging in the heart must be designed to meet the demands of significant cardiac motion and blood flow. To cope with the periodic cardiac motion, most human heart studies to date used gating to the diastolic window, the longest cardiac cycle interval, which has reduced motion (2,22,28,30,35,36,38,45,52). The duration of the diastolic window limits the available data sampling time, making cardiac acquisitions the most time-constrained of the HP 13C MRI applications. The most common acquisition approach is metabolite-specific imaging with spiral k-space trajectories (2). Their single-shot imaging capability makes these methods particularly robust to motion effects. Furthermore, spiral k-space trajectories provide rapid k-space coverage and relatively benign flow and motion artifacts. The majority of studies have used 2D multi-slice acquisitions, but 3D encoding has also been used successfully (35).

Brain Studies

For HP 13C MRI of the human brain, the majority of studies have also used 2D (slice selective) acquisitions (10–12,14,16,28,33,40,41,44,51,53,60), with a trend toward volumetric coverage using 2D multi-slice metabolite-specific imaging. 3D metabolite-specific imaging of the whole brain, with phase encoding of the slice direction (34,57), has been shown to provide similar SNR efficiency (88) compared with multislice imaging. A number of studies have employed MRS/I (5,6,29,31–33,50,55) resulting in a spectrum from each voxel, which has the advantage of not requiring a priori information about which peaks to encode. This was important in early brain studies when it was not known which peaks would be detectable. Chemical shift encoding, using a set of images with different echo times and an iterative reconstruction of the individual resonances (i.e. the IDEAL approach (85)), has also been used (12,49,54), with the drawback that coverage in the slice direction was limited due to the time required to acquire multiple echo time images.

Abdomen And Breast Studies

The fundamental approaches to data acquisition and reconstruction in the abdomen and breast are largely similar to the aforementioned applications, but demand attention to particular challenges associated with these anatomic regions, especially relating to respiratory motion.

Although it has been shown that a basic 2D MRSI approach based on phase encoding and FID readout can be successfully applied for HP 13C imaging in breast (15) and kidney (13), major advantages in terms of spatiotemporal resolution and coverage have been realized using tailored approaches based on metabolite-specific imaging (43,62) and chemical shift encoding (43), which have facilitated multi-slice or 3D dynamic acquisitions over large FOVs in the abdomen (4,37,46).

The significant respiratory motion encountered in these regions can directly blur 13C images, and has further favored these rapid acquisition strategies. Motion also degrades B0 homogeneity, which can shift frequency-selective excitation profiles and introduce artifacts into rapid imaging readouts. This makes accurate determination of the acquisition center frequency and shimming essential in these regions which often cover large FOVs. (See “Prescan Calibration” section for more information). In some studies, breath-holding was used to minimize motion effects and enforce frame-to-frame data consistency (42). A pragmatic and reasonably effective approach for dealing with respiratory motion during 13C data acquisition is an initial breath-hold (as long as can be tolerated), followed by free-breathing (46,62).

1H Imaging

Collection of 1H imaging data is essential both for prescribing the 13C acquisition and for interpretation of the resulting 13C data. Multi-planar 1H scouts are acquired prior to 13C acquisition to enable graphical prescription of the 13C imaging region. All human HP 13C-pyruvate imaging studies acquire conventional MRI scans (e.g. T1- and T2-weighted volumes) for anatomic reference, aiming to cover at least the full 13C FOV. Acquiring these anatomic scans as close as possible to the time of 13C imaging (immediately before or after) minimizes potential misregistration between the data sets. Depending on the application, other advanced 1H sequences are also acquired (e.g. diffusion-weighted imaging for cancer imaging).

When contrast-enhanced data is acquired, it is done after 13C imaging, as paramagnetic contrast agents will accelerate 13C relaxation.

Reported Study Parameters

Figures 5 and 6, and Supporting Table S2 shows the reported acquisition study parameters for human HP [1-13C]pyruvate studies published as of September 2022. Figure 5 shows a mixture of MRS/I, metabolite-specific imaging, and chemical shift encoding methods have been successfully used, where spectroscopy-based methods have become less prevalent in recent studies. Figure 6 shows the acquisition timing, including the important start time and interval/temporal resolution, is quite variable across studies.

Figure 5: Acquisition methods used in published HP [1-13C]pyruvate human studies published up to September 2022, classified into: MR spectroscopy and spectroscopy imaging (MRS/I); chemical shift encoding methods, such as IDEAL, that use multiple TEs and model-based reconstructions; and metabolite-specific imaging methods that use spectrally-selective excitation to image a single resonance at a time.

Figure 6: Temporal acquisition characteristics reported in HP [1-13C]pyruvate human studies published up to September 2022. (a) Reported referencing of acquisition start times.

(B)

Acquisition start times reported when using dynamic imaging and when timing was reported relative to the end of the injection. (c) Temporal resolutions. “Not Applicable” indicates dynamic imaging was not used.

Summary

Three general categories of acquisition strategies have been used successfully for human HP 13C-pyruvate studies: MRS/I, model-based chemical shift encoding (e.g. IDEAL) methods, and metabolite-specific imaging methods. These have enabled successful studies in the prostate, heart, brain, abdomen, and breast. Recent studies increasingly have used the imaging-based strategies of metabolite-specific imaging and chemical shift encoding which are the fastest methods, although a heads-to–head comparison between techniques has not been performed.

Metabolite-specific imaging is quite popular because of its speed and compatibility with single-shot imaging, but is sensitive to B0 field variations and thus requires careful calibrations. Nearly all studies surveyed acquired data dynamically, allowing measurement of the bolus and metabolite kinetics. The exact timings and associated flip angles vary quite widely across reported studies, with no consensus yet as to how to choose these parameters. Image reconstruction is typically done directly using Fourier Transform methods, and accelerated imaging strategies are uncommon.

Data Analysis And Quantification

This section covers the analysis of data from human HP [1-13C]pyruvate studies, including modeling and metrics, visualization, as well as considerations for how to store data and metadata. Depending on study design, the analysis may need to give quantitative or semi-quantitative output reflecting a biological process or may just reflect a contrast between different regions of interest for quantitative evaluation.

Metrics

Figure 7: HP [1-13C]pyruvate raw data (A) have typically been quantified using four categories of metrics depending on the acquisition. Data acquired as a single time point are often quantified using normalized metabolite images or metabolite ratios (B). Dynamic data can be quantified using normalized metabolite images or metabolite ratios (B), or with metabolite timings such as time-to-peak (TTP) or pharmacokinetic (PK) models (C). The latter two require the data to be time-resolved. [1-13C]alanine and 13C-bicarbonate are analyzed similarly to [1-13C]lactate but omitted here for display.

Metabolite images are commonly used as summary metrics for HP MRI data, often including some form of normalization as well as summed over time as an area under the time curve (AUC) (17). These are analogous to the visual evaluation that is most used for routine clinical work (89,90). In these metabolite images, we expect that the [1-13C]pyruvate AUC signal is predominantly weighted towards perfusion and uptake, while [1-13C]lactate, [1-13C]alanine and 13C-bicarbonate AUCs represent metabolic conversion. The strength of this approach lies in its simplicity and relatively few underlying assumptions. Limitations to the use of single-metabolite images or AUCs include sensitivity to inhomogeneous coil profiles (57,87,91), the acquisition strategy and acquisition parameters, pyruvate polarization and concentration level, and signal relaxation rates (92). Further, the reader must be careful to interpret all the images in conjunction to better understand the underlying biology; for example, increased [1-13C]lactate in the presence of decreased [1-13C]pyruvate delivery can have a very different meaning compared to increased [1-13C]lactate with increased [1-13C]pyruvate delivery.

In an attempt to address variations in coil sensitivity, polarization level, and pyruvate delivery, AUC images are often computed by normalizing to a specified parameter, such as the maximum pyruvate or average lactate signals, or presented as a ratio such as lactate/pyruvate or divided by “total Carbon” - the sum total of HP 13C signal observed across all metabolites. The AUC ratios between metabolites and pyruvate are proportional to the corresponding forward kinetic rates (81,93), but are not directly comparable to rate constants when magnetization loss rates (e.g. relaxation and losses due to signal excitation) differ between studies. Similarly, the ratios between the produced metabolites (e.g. bicarbonate/lactate) can reflect the balance between downstream metabolic pathways (12,55). Care must be taken to consider how AUC images are calculated and normalized before comparing values between studies.

To further quantify the interpretation, pharmacokinetic (PK) modeling approaches were developed to compute the apparent kinetics of pyruvate-to-metabolite exchange (92,94–99). These yield semi-quantitative to quantitative apparent rate constants, given in s-1. Some models require a vascular input function, while others avoid this requirement (95). PK models can explicitly account for acquisition-specific details such as excitation angle and repetition time, and thus may reduce the effects of these details on quantification. An input-less model, provided in the Hyperpolarized-MRI-Toolbox (https://github.com/LarsonLab/hyperpolarized-mri-toolbox) (100) and thus frequently employed for human data, has been shown to fit well and robustly to prostate and brain data (8,20). PK models are quantitative in nature, arguably provide more relevant biological information (8,20), and appear to be reproducible across sites (51). However, rate constants derived from PK models are still apparent rates, and likely do not reflect a single biological characteristic.

Some additional considerations include whether complex or magnitude data is used, as the noise behaviors will impact the analysis differently. Additionally, cut-off thresholds or other criteria may be used to identify and avoid voxels with insufficient SNR before analysis to improve robustness (20,41).

Regardless of the analysis approach, the underlying biology is not always clearly represented by the data; instead, the metrics may be influenced by perfusion, barrier permeability, intercellular shuttles, enzyme activities, co-substrate concentrations, or combinations thereof, depending on the organ and disease of interest (19,43,94,101–103). This may be addressed by incorporating complementary information. As an example, HP 13C pyruvate data is influenced by perfusion, and thus addition of perfusion MRI could be important for interpretation (98,104,105).

All the methods outlined above have been explored in clinical studies, described in Supporting Table 3 and summarized in Figure 8. As of September 2022, approximately 52% of studies involving human subjects report rate constants derived from a PK model with a few different models reported. A nearly equal fraction (51%) of the studies report AUC ratio values.

Approximately 66% of these studies report metabolite-specific images or AUC values. About 40% report SNR values; this metric is particularly frequent in manuscripts that describe technical developments for clinical HP MRI. Approximately 16% of these studies summarize model-free metrics, and 10% report measurements from a single timepoint. Most studies report a combination of quantities.

Figure 8: Reported metrics used for analysis in HP [1-13C]pyruvate human studies published up to September 2022.

Visualization

A wide variety of approaches have been used for visualizing data from human HP 13C-MRI studies. The challenges and practical considerations are: 1) choosing the appropriate metrics to display, 2) how to encode the parameters (e.g. the colormap), and 3) choosing how to provide anatomical context and other multi-parametric data. The choice of visualization also depends on the goal which could be for diagnostic interpretation, but also quality control, reproducibility among readers and publication.

Metrics

The choice of HP 13C metrics is described in detail above. At this stage in HP 13C development where there is no standardized metric, often a combination of metabolite images and ratios or PK model parameters are shown.

Parameter Encoding

The mapping function chosen should provide an adequate, often quantitative, impression of the parameter mapped. There is a consensus in the visualization field that perceptually uniform maps are best suited to visualize continuous parameters, like the greyscale typically used by radiologists as well as other monochrome (black to blue) and color ranges (fire-type, rainbow-type) (106,107). Multi-color heatmaps have been the most frequently employed method for HP 13C data, while greyscale has infrequently been used but it ensures there is no coloring-based bias as well as facilitating later reuse (Fig. 9a). Among the color schemes employed in the clinical HP 13C literature, fire-type scheme seems to be the most common [similar to “Plasma” or “Inferno” in matplotlib.org]. Next most commonly employed is the rainbow-type scheme [similar to “Rainbow” in matplotlib.org].

Anatomical Context

HP MRI faces the challenge that it does not necessarily depict the anatomical features, similar to PET, and thus requires an anatomical reference. Most often, a grayscale anatomical image is overlaid with a HP colormap (Fig. 9c,d). This approach is very intuitive, but can skew perception as the grey-scale anatomical reference may affect the brightness of the HP data (e.g. signal in the skull). This bias does not occur when showing adjacent maps (Fig. 9a, b). Here, anatomical outlines may help to provide reference (Fig. 9b).

Related Journal Articles & DOI Links

Selected peer-reviewed publications relevant to 12 Lead ECG Acquisition. Click the DOI to access the full paper (may require institutional access).

Why Choose Us?

Bangalore guidance for robotics, Spectre and autonomous systems projects.

Spectre & Simulation

Gazebo, cloud twin and Webots worlds with navigation, SLAM and control stacks.

Control & Planning

Compliance, deep learning control, path planning and behavior trees.

Hardware Bring-up

Motors, sensors, ESP32/STM32 firmware and HIL validation paths.

Report & Viva

University-format documentation, PPT and viva preparation.

FAQ

Spectre, Gazebo, NVIDIA cloud twin, MATLAB/Simulink, Webots, Blynk / ThingSpeak, plus Arduino/STM32/ESP32, cameras, LiDAR and motor drivers.
Yes — simulation packages, hardware guidance, report, PPT and viva Q&A.