State Root in Blockchain Systems
A
state root is a cryptographic hash that represents the entire state of a blockchain at a specific point in time
1. It is essentially the root of a Merkle tree, which is used to efficiently and securely track changes to the blockchain's state
1.
Function and Mechanism
The state root serves as a commitment to the current state of all accounts, balances, and storage data on the chain
1.
Key aspects of the state root:
- State Commitment The state of a blockchain, including all Layer 2 (L2) accounts and balances, is organized into a Merkle tree 1. The cryptographic hash of this Merkle tree's root is the state root, which is stored in an on-chain contract 1. This allows the protocol to track changes to the state 1.
- State Transition When a new set of transactions is executed, the blockchain transitions to a new state 1. The operator responsible for initiating this transition must compute a new state root and submit it to the on-chain contract 1.
- Verification In systems like Zero-Knowledge (ZK) rollups, the new state root is submitted along with a validity proof 1. If the verifier contract authenticates the proof, the new Merkle root becomes the canonical state root of the ZK-rollup 1.
- Transaction Processing The process of updating the state root involves:
- Decreasing the sender's balance and increasing the receiver's balance 1.
- Hashing the updated account data 1.
- Rebuilding the rollup's Merkle tree 1.
- Submitting the new Merkle root (the new state root) to the on-chain contract 1.
Role in Zero-Knowledge Rollups
In ZK-rollups, the state root is critical for verifying the correctness of state updates
1.
When an L2 operator submits a batch of transactions and a validity proof to the Layer 1 (L1) verifier contract, the proof includes public inputs that form part of the verification process
1:
- Pre-state root The old state root of the ZK-rollup before the batched transactions were executed, reflecting the last known valid state 1.
- Post-state root The new state root after the execution of the batched transactions, reflecting the chain's newest state 1. This is the final root derived after applying all state updates in the proving circuit 1.
The ZK-proving circuit iterates over the entire transaction batch, verifying the sequence of updates that result in the final state root after the last transaction is executed
1. This final computed Merkle root becomes the newest canonical state root of the ZK-rollup
1.
State Root in Other Contexts
The concept of a state root is also relevant in other blockchain architectures:
- Stateless Clients In the concept of stateless clients, consensus nodes only store a state root of the chain 2. Transactions are accompanied by the state they access and a witness to prove that the state is part of the stored state root 2.
- Dispute Games In systems like the OP Stack, claims in a fault dispute game can be commitments to the state within a "super root state transition" 3.
- Historical Data Historical roots for the entire beacon chain history are stored in the state, allowing a recent state to quickly judge if an era file is part of the same history, which is useful for checkpoint synchronization 4.