State Proof - Algorand Specifications
Keyboard shortcuts
Press ← or → to navigate between chapters
Press S or / to search in the book
Press ? to show this help
Press Esc to hide this help
- Auto
- Light
- Dark
Algorand Specifications
The state proof is a special transaction used to disseminate and store State Proofs.
A state proof transaction additionally has the following fields:
| FIELD | CODEC | TYPE | REQUIRED |
|---|---|---|---|
| State Proof Type | sptype |
uint64 |
Yes |
| State Proof | sp |
struct |
Yes |
| Message | spmsg |
struct |
Yes |
| State Proof Last Round | sprnd |
uint64 |
Yes |
The state proof type identifies the type of the State Proof.
Currently, always 00.
The state proof structure as defined in the State Proof specification.
The message is a structure that composes the State Proof message, whose hash is being attested to by the State Proof.
The message structure is defined in the State Proof message section.
In order for a state proof transaction to be valid, the following conditions MUST be met:
- The transaction type MUST be
stpf. - The sender MUST be equal to a special address, which is the hash of the domain-separation prefix
SpecialAddr(see the corresponding section in the Algorand Cryptographic Primitive Specification) with the string constantStateProofSender. - The fee MUST be 00.
- The lease MUST be omitted.
- The group MUST be omitted.
- The rekey to MUST be omitted.
- The note MUST be omitted.
- The transaction MUST NOT have any signature.
- The state proof round (defined in the message structure) MUST be exactly equal to the next expected State Proof round in the block header, as described in the State Proof tracking section.
- The state proof verification code MUST return
true(see State Proof validity), given the State Proof message and the State Proof transaction fields.
In addition, the verifier should also be given a trusted commitment to the participant array and ProvenWeight value. The trusted data SHOULD be taken from the Ledger at the relevant round.
To encourage the formation of shorter State Proof, the rule for validity of state proof transactions is dependent on the first valid round in the transaction.
In particular, the signed weight of a State Proof MUST be:
- Equal to the total online stake, if the first valid round on the transaction is no greater than the state proof round (defined in the message structure) plus δSP.
- At least ProvenWeight+(TotalWeight−ProvenWeight)×Offset, if the first valid round on the transaction is the state proof round (defined in the message structure) plus δSP+Offset.
- At least the minimum weight being proven by the proof, if the first valid round on the transaction is no less than state proof round (defined in the message structure) plus δSP.
Where ProvenWeight=TotalWeight×fSP2
When a state proof transaction is applied to the state, the next expected State Proof round for that type of State Proof is incremented by δSP.
A node should be able to verify a state proof transaction at any time, even if the transaction first valid round is greater than the next expected State Proof round in the block header.
TODO