## Keyboard shortcuts

Press `←` or `→` to navigate between chapters

Press `S` or `/` to search in the book

Press `?` to show this help

Press `Esc` to hide this help

- Auto
- Light
- Dark

# Algorand Specifications

The _state proof_ is a special transaction used to disseminate and store [State Proofs](https://specs.algorand.co/ledger/ledger-state-proofs).

A _state proof_ transaction additionally has the following fields:

| FIELD | CODEC | TYPE | REQUIRED |
| --- | --- | --- | --- |
| State Proof Type | `sptype` | `uint64` | Yes |
| State Proof | `sp` | `struct` | Yes |
| Message | `spmsg` | `struct` | Yes |
| State Proof Last Round | `sprnd` | `uint64` | Yes |

The _state proof type_ identifies the type of the State Proof.

> Currently, always 00.

The _state proof_ structure as defined in the [State Proof specification](https://specs.algorand.co/crypto/crypto-state-proofs#state-proof-format).

The _message_ is a structure that composes the State Proof message, whose hash is being attested to by the State Proof.

The _message_ structure is defined in the [State Proof message section](https://specs.algorand.co/ledger/ledger-state-proofs#message).

In order for a _state proof_ transaction to be valid, the following conditions **MUST** be met:

- The _transaction type_ **MUST** be `stpf`.
- The _sender_ **MUST** be equal to a special address, which is the hash of the domain-separation prefix `SpecialAddr` (see the corresponding section in the [Algorand Cryptographic Primitive Specification](https://specs.algorand.co/crypto/crypto-domain-separators)) with the string constant `StateProofSender`.
- The _fee_ **MUST** be 00.
- The _lease_ **MUST** be omitted.
- The _group_ **MUST** be omitted.
- The _rekey to_ **MUST** be omitted.
- The _note_ **MUST** be omitted.
- The transaction **MUST NOT** have any signature.
- The _state proof round_ (defined in the _message_ structure) **MUST** be exactly equal to the next expected State Proof round in the _block header_, as described in the [State Proof tracking section](https://specs.algorand.co/ledger/ledger-state-proofs#tracking).
- The state proof verification code **MUST** return `true` (see [State Proof validity](https://specs.algorand.co/crypto/crypto-state-proofs#state-proof-validity)), given the State Proof _message_ and the State Proof _transaction fields_.

In addition, the verifier should also be given a trusted commitment to the _participant_ array and ProvenWeight value. The trusted data **SHOULD** be taken from the Ledger at the relevant round.

To encourage the formation of shorter State Proof, the rule for validity of _state proof_ transactions is dependent on the _first valid round_ in the transaction.

In particular, the signed weight of a State Proof **MUST** be:

- Equal to the _total online stake_, if the _first valid round_ on the transaction is no greater than the _state proof round_ (defined in the _message_ structure) plus δSP.
- At least ProvenWeight+(TotalWeight−ProvenWeight)×Offset, if the _first valid round_ on the transaction is the _state proof round_ (defined in the _message_ structure) plus δSP+Offset.
- At least the minimum weight being proven by the proof, if the _first valid round_ on the transaction is no less than _state proof round_ (defined in the _message_ structure) plus δSP.

Where ProvenWeight=TotalWeight×fSP2

When a _state proof_ transaction is applied to the state, the next expected State Proof round for that type of State Proof is incremented by δSP.

> A node should be able to verify a _state proof_ transaction at any time, even if the transaction _first valid round_ is greater than the next expected State Proof round in the _block header_.

TODO
