## Keyboard shortcuts

Press `←` or `→` to navigate between chapters

Press `S` or `/` to search in the book

Press `?` to show this help

Press `Esc` to hide this help

- Auto
- Light
- Dark

# Algorand Specifications

Let

- II be an _address_,
- rr be a _round_,
- pp be a _period_,
- ss be a _step_,
- vv be a _proposal-value_.

Let xx be a canonical encoding of the 5-tuple (I,r,p,s,v), and let x′ be a canonical encoding of the 4-tuple (I,r,p,s).

Let yy be an arbitrary bitstring.

Then we say that the tuple

(I,r,p,s,v,y) is a _vote from II for vv at round rr, period pp, step ss_ (or _a vote from II for vv at (r,p,s)_), denoted

Vote(I,r,p,s,v)

Moreover, let LL be a ledger where \|L\|≥δb.

Let

- (sk,pk) be a keypair,
- B,B¯ be 64-bit integers,
- QQ be a 256-bit integer,
- τ,τ¯ 32-bit integers.

We say that this vote is _valid with respect to_ LL (or simply _valid_ if LL is unambiguous) if the following conditions are true:

- r≤\|L\|+2

- Let v=(Iorig,porig,d,h).
  - If s=0, then porig≤pporig≤p.
  - Furthermore, if s=0 and p=porig, then I=Iorig.

- If s∈{propose,soft,cert,late,redo}, v≠⊥. Conversely, if s=down, v=⊥.

- Let

- (pk,B,rfirst,rlast)=Record(L,r−δb,I),
  - B¯=Stake(L,r−δb,r),
  - Q=Seed(L,r−δs),
  - τ=CommitteeThreshold(s),
  - τ¯=CommitteeSize(s).

Then
  - Verify(y,x,x′,pk,B,B¯,Q,τ,τ¯)≠0,
  - rfirst≤r≤rlast.

Observe that valid votes contain outputs of the Sign procedure; i.e.,
y:=Sign(x,x′,sk,B,B¯,Q,τ,τ¯).

Informally, these conditions check the following:

- The vote is not too far in the future for LL to be able to validate.

- “Propose”-step votes can either propose a new _proposal-value_ for this period (porig=pp) or claim to “re-propose” a value originally proposed in an earlier period (porig<pp). But they can’t claim to “re-propose” a value from a future period. And if the proposal-value is new (porig=pp) then the “original proposer” must be the voter.

- The propose, soft, cert, late, and redo steps must vote for an actual proposal. The down step must only vote for ⊥.

- The last condition checks that the vote was properly signed by a voter who was selected to serve on the committee for this _round_, _period_, and _step_. The committee selection process uses the voter’s stake and keys as of δb rounds before the vote and the seed as of δs rounds before the vote. It also checks if the vote’s round is within the range associated with the voter’s participation key.

An _equivocation vote pair_ or _equivocation vote_ is a pair of votes that differ in their proposal values. In other words,

Equivocation(I,r,p,s)=(Vote(I,r,p,s,v1),Vote(I,r,p,s,v2))

for some v1≠v2.

An equivocation vote pair is _valid with respect to_ LL (or simply _valid_ if LL is unambiguous) if both of its constituent votes are also valid with respect to LL.
