Votes - Algorand Specifications
Keyboard shortcuts
Press ← or → to navigate between chapters
Press S or / to search in the book
Press ? to show this help
Press Esc to hide this help
- Auto
- Light
- Dark
Algorand Specifications
Let
- II be an address,
- rr be a round,
- pp be a period,
- ss be a step,
- vv be a proposal-value.
Let xx be a canonical encoding of the 5-tuple (I,r,p,s,v), and let x′ be a canonical encoding of the 4-tuple (I,r,p,s).
Let yy be an arbitrary bitstring.
Then we say that the tuple
(I,r,p,s,v,y) is a vote from II for vv at round rr, period pp, step ss (or a vote from II for vv at (r,p,s)), denoted
Vote(I,r,p,s,v)
Moreover, let LL be a ledger where |L|≥δb.
Let
- (sk,pk) be a keypair,
- B,B¯ be 64-bit integers,
- QQ be a 256-bit integer,
- τ,τ¯ 32-bit integers.
We say that this vote is valid with respect to LL (or simply valid if LL is unambiguous) if the following conditions are true:
r≤|L|+2
Let v=(Iorig,porig,d,h).
- If s=0, then porig≤pporig≤p.
- Furthermore, if s=0 and p=porig, then I=Iorig.
If s∈{propose,soft,cert,late,redo}, v≠⊥. Conversely, if s=down, v=⊥.
Let
(pk,B,rfirst,rlast)=Record(L,r−δb,I),
- B¯=Stake(L,r−δb,r),
- Q=Seed(L,r−δs),
- τ=CommitteeThreshold(s),
- τ¯=CommitteeSize(s).
Then
- Verify(y,x,x′,pk,B,B¯,Q,τ,τ¯)≠0,
- rfirst≤r≤rlast.
Observe that valid votes contain outputs of the Sign procedure; i.e., y:=Sign(x,x′,sk,B,B¯,Q,τ,τ¯).
Informally, these conditions check the following:
The vote is not too far in the future for LL to be able to validate.
“Propose”-step votes can either propose a new proposal-value for this period (porig=pp) or claim to “re-propose” a value originally proposed in an earlier period (porig<pp). But they can’t claim to “re-propose” a value from a future period. And if the proposal-value is new (porig=pp) then the “original proposer” must be the voter.
The propose, soft, cert, late, and redo steps must vote for an actual proposal. The down step must only vote for ⊥.
The last condition checks that the vote was properly signed by a voter who was selected to serve on the committee for this round, period, and step. The committee selection process uses the voter’s stake and keys as of δb rounds before the vote and the seed as of δs rounds before the vote. It also checks if the vote’s round is within the range associated with the voter’s participation key.
An equivocation vote pair or equivocation vote is a pair of votes that differ in their proposal values. In other words,
Equivocation(I,r,p,s)=(Vote(I,r,p,s,v1),Vote(I,r,p,s,v2))
for some v1≠v2.
An equivocation vote pair is valid with respect to LL (or simply valid if LL is unambiguous) if both of its constituent votes are also valid with respect to LL.