Verifiable random functions
RFC 9381 ECVRF on Network 1: unpredictable, publicly checkable randomness for probes, spot checks and contracts.
A verifiable random function (VRF) turns a secret key and a public input into a random-looking output, together with a proof. Anyone with the matching public key can check the proof and confirm the output is correct, but nobody can predict the output before the key holder computes it, and the key holder cannot choose a different output for the same input.
Tenzro Network 1 implements the RFC 9381 suite ECVRF-EDWARDS25519-SHA512-TAI.
| Item | Size |
|---|---|
| Public key | 32 bytes |
Proof (Gamma, c, s) | 80 bytes |
| Output | 64 bytes |
The implementation rejects low-order public keys and non-canonical scalars, as the RFC requires.
Where Network 1 uses it
SLA probes. Validators check that staked providers are live and meeting their service levels. Each probe is derived from a VRF output over the epoch, the round and the provider's DID, and carries the proof. The provider cannot predict when it will be probed, and cannot claim a probe was rigged, because anyone can recompute it. See SLA attestation and metering.
Spot checks and assignment. Choosing which provider re-runs a piece of work, or which challenger reviews a result, uses VRF outputs so that assignments are unpredictable in advance and auditable afterwards.
Your own contracts. EVM contracts can verify a VRF proof with the VRF_VERIFY precompile and use the output as fair randomness: task assignment among agents, sampling for audits, or ordering a queue.
A validator's VRF key is derived on demand from its hardware-rooted keys, in the same way as its other signing keys. See Hardware-rooted keys.
Choosing the input
The input (called alpha in the RFC) should be public data fixed before the output is needed, such as a block hash, a request id or an epoch number. If the key holder can pick the input freely, they can try many inputs and keep the output they like.
Verifying a proof
With the CLI:
tenzro vrf verify \
--pubkey 0x<32-byte public key> \
--proof 0x<80-byte proof> \
--alpha 0x<input bytes>With JSON-RPC (open method):
curl -s https://rpc.tenzro.xyz \
-H 'content-type: application/json' \
-d '{"jsonrpc":"2.0","id":1,"method":"tenzro_verifyVrfProof","params":{"pubkey":"0x...","proof":"0x...","alpha":"0x..."}}'A valid proof returns the output:
{ "valid": true, "output": "0x...", "output_len": 64 }An invalid proof returns "valid": false with the reason.