## Keyboard shortcuts

Press `←` or `→` to navigate between chapters

Press `S` or `/` to search in the book

Press `?` to show this help

Press `Esc` to hide this help

- Auto
- Light
- Dark

# Algorand Specifications

A _player_ is uniquely identified by a 256-bit string II called an _address_.

Each player owns exactly one _participation keypair_. A participation keypair consists of a _public key_ pkpk and a _secret key_ sksk.

A keypair is defined in the [specification of participation keys in Algorand](https://specs.algorand.co/keys/keys-participation). Each participation keypair is valid for a range of protocol rounds \[rfirst,rlast\].

Let mm, m′ be arbitrary sequences of bits.

Let Bk, B¯ be 64-bit integers representing balances in μALGO with rewards applied.

Let τ, τ¯ be 32-bit integers, and QQ be a 256-bit string.

Let (pkk, skk) be some valid keypair.

A secret key supports a _signing_ procedure

y := Sign(m, m′, skk, Bk, B¯, Q, τ, τ¯)

Where y is opaque and cryptographically resistant to tampering, where defined.

Signing is not defined on many inputs: for any given input, signing may fail to produce an output.

The following functions are defined on y:

- _Verifying_: Verify(y, m, m′, pkk, Bk, B¯, Q, τ, τ¯) = w where w is a 64-bit integer called the _weight_ of y. w ≠ 0 if and only if y was produced by signing by skk (up to cryptographic security). w is uniquely determined given fixed values of m′, pkk, Bk, B¯, Q, τ, τ¯.

- _Comparing_: Fixing the inputs m′, B¯, Q, τ, τ¯ to a signing operation, there exists a total ordering on the outputs y. In other words, if f(sk, B) = Sign(m, m′, sk, B, B¯, Q, τ, τ¯) = y, and S = {(sk0, B0), (sk1, B1), …, (skn, Bn)}, then {f(x) | x ∈ S} is a totally ordered set. We write that y1 < y2 if y1 comes before y2 in this ordering.

- _Generating Randomness_: Let y be a valid output of a signing operation with skk. Then R = Rand(y, pkk) is defined to be a pseudorandom 256-bit integer (up to cryptographic security). R is uniquely determined given fixed values of m′, pkk, Bk, B¯, Q, τ, τ¯.

The signing procedure is allowed to produce a nondeterministic output, but the functions above must be well-defined with respect to a given input to the signing procedure (e.g., a procedure that implements Verify(Sign(…)) always returns the same value).
