Qstamp / Mathematics
Formal construction

The mathematics behind every receipt.

This page specifies the Qstamp construction precisely, states the security it achieves against classical and quantum adversaries, and explains why Quanta smart contracts executing on the Quantova Virtual Machine are suited to anchoring the fingerprints of SI agent actions.

§1 · Notation
H(x)
SHA3 with a 256 bit output as specified in FIPS 202
D
record digest computed with algorithm a, where a = 1 for SHA3 and a = 2 for SHA2 with a 256 bit output
s
32 byte salt drawn uniformly from the operating system generator
‖
byte concatenation
n, i
batch size and leaf position, with 1 ≤ n ≤ 2^20 and 0 ≤ i < n
G, C, S, k
genesis hash, contract address, signer address and record kind

§2 · Leaf

Li = H( 0x00 ‖ "QSTAMP/LEAF/V1" ‖ a ‖ Di ‖ si )

The input has a fixed length of 80 bytes. The leading byte and the label separate leaves from every other hash in the system, and the algorithm identifier prevents a digest computed with one algorithm from being presented as a digest of the other.

§3 · Tree

MTH( L0 ) = L0
MTH( L0..n−1 ) = H( 0x01 ‖ MTH( L0..k−1 ) ‖ MTH( Lk..n−1 ) ), k = largest power of two below n

This is the construction of RFC 9162 section 2.1. An inclusion path for leaf i contains at most ⌈log2 n⌉ sibling hashes, which is twenty for the largest batch. Verification follows RFC 9162 section 2.1.3.2 and rejects any path whose length does not match the position and size.

§4 · Commitment

K = H( 0x02 ‖ "QSTAMP/ROOT/V1" ‖ G ‖ C ‖ S ‖ u64( k ) ‖ u64( n ) ‖ MTH )

A bare RFC 9162 root does not determine the size of its tree, so the same path can verify under several sizes. Binding n removes that ambiguity. Binding G, C and S means that a commitment copied from a pending transaction and anchored by another account, contract or network fails verification. Binding k fixes the declared kind of record.

§5 · Anchoring on the QVM

stamp( Khi , Klo , k ) → emit Stamped( caller , K , k )
caller = address( pk ) = H( scheme ‖ pk ), tx valid ⇔ ML-DSA.Verify( pk , H(body) , σ ) = 1

The contract receives K as two 128 bit words and k as a 64 bit word, and emits them unchanged together with the authenticated caller. The QVM writes the caller into contract memory from the verified transaction sender before execution, so the recorded signer cannot be influenced by call data. The event is committed to the block header event root and finalised by the validator committee.

§6 · Security

Work required to forge a receipt.

Changing any part of an anchored receipt requires finding a second preimage of SHA3 or breaking ML DSA. Generic quantum search reduces preimage work to its square root, which still leaves 128 bits of security.

AttackRequired breakClassical workQuantum work
Present different content under an existing receiptSHA3 second preimage2^2562^128 by Grover search
Alter position, size, kind or signerSHA3 second preimage on the commitment2^2562^128
Stamper anchors one digest for two documentsSHA3 collision2^1282^85 in the BHT model with large quantum memory, about 2^128 under realistic cost models
Forge the signer of an anchoring transactionML DSA 65 forgeryNIST security category 3NIST security category 3
Forge block finalityML DSA 65 forgery against the committeeNIST security category 3NIST security category 3
Infer content from the chainInvert a salted commitmentSearch over a 2^256 salt space2^128
§7 · Why Quanta contracts suit agent fingerprints

Properties of the execution layer.

Authenticated authorship

The caller of a Quanta entry is the verified signer of the transaction. An agent, or the service acting for it, is bound to every commitment it anchors without additional signature logic in the contract.

Signed orders for delegated authority

The QVM verifies ML DSA signatures inside a contract through its VERIFY_ML instruction under the context QVM/contract/v1. Agents can carry orders signed by an issuer, and a relayer can submit them without gaining authority. Each order carries a nonce held by the contract, so it cannot be replayed.

Attested code

A contract is admitted only when the SHA3 identifier of its container carries an ML DSA 65 signature from the attested Quanta compiler under the context QUANTOVA/QVM/PROVENANCE/v1. Reviewers can recompile the published source and compare the container byte for byte.

Predictable cost

Execution is metered. The fee for a call is 500 quon for each 1210 units of metering consumed, rounded up, with the unused reserve refunded. A stamp costs the same whether it carries one record or 1048576, so the cost per agent action falls in proportion to 1 over n.

fee( m ) = 500 · ⌈ m ⁄ 1210 ⌉ quon
cost per record = fee ⁄ n
1 TQTOV = 1,000,000 quon

§8 · Assumptions stated plainly

The construction assumes the collision and second preimage resistance of SHA3 and SHA2, the unforgeability of ML DSA 65, and an honest majority of the validator committee. In release 0.1 the anchoring transaction, event and block are confirmed through the network RPC interface. A forthcoming release embeds the block header, the finality certificate and the event inclusion proof in each receipt, which removes reliance on any endpoint. Block time is set by the proposing validator in whole seconds and is accepted only if it is within 15 seconds of the committee's clocks.