Skip to main content

PseudoMersennePrimeField

Struct PseudoMersennePrimeField 

Source
pub struct PseudoMersennePrimeField { /* private fields */ }
Expand description

A struct that implements prime field arithmetic over pseudo-Mersenne modulus.

Field elements are BigUints consisting of PseudoMersennePrimeField::limbs_len limbs. It is assumed that all field elements are correctly represented (less than modulus).

Implementations§

Source§

impl PseudoMersennePrimeField

Source

pub fn new( b: &CircuitBuilder, modulus_po2: usize, modulus_subtrahend: &[u64], ) -> Self

Create a new pseudo-Mersenne prime field.

See PseudoMersenneModReduce for description of the parameters.

Source

pub const fn limbs_len(&self) -> usize

Number of limbs in BigUints representing field elements.

Source

pub const fn modulus(&self) -> &BigUint

Field modulus.

Source

pub fn add(&self, b: &CircuitBuilder, fe1: &BigUint, fe2: &BigUint) -> BigUint

Field addition.

Equivalent formula: (fe1 + fe2) % modulus

Source

pub fn sub(&self, b: &CircuitBuilder, fe1: &BigUint, fe2: &BigUint) -> BigUint

Field subtraction.

Equivalent formula: (fe1 - fe2) % modulus

Source

pub fn square(&self, b: &CircuitBuilder, fe: &BigUint) -> BigUint

Field squaring.

Equivalent formula: (fe ** 2) % modulus

Source

pub fn mul(&self, b: &CircuitBuilder, fe1: &BigUint, fe2: &BigUint) -> BigUint

Field multiplication.

Equivalent formula: (fe1 * fe2) % modulus Note: Both fe1 and fe2 may be greater or equal to modulus.

Source

pub fn inverse(&self, b: &CircuitBuilder, fe: &BigUint, exists: Wire) -> BigUint

Field inverse.

Equivalent formula (for prime modulus): (fe1 ** (modulus - 2)) % modulus The wire parameter exists is a boolean-wire signifying the existence of the inverse; if exists is false, the modular reduction constraint is not applied. This is useful for avoiding overconstraining in skipped parts of larger circuits.

Source

pub fn div( &self, b: &CircuitBuilder, dividend: &BigUint, divisor: &BigUint, exists: Wire, ) -> BigUint

Field division.

Equivalent formula (for prime modulus): (dividend * divisor ** (modulus - 2)) % modulus, i.e. dividend / divisor (mod modulus).

This collapses a modular inverse followed by a multiplication into a single modular reduction, halving the multiplication cost relative to mul(dividend, inverse(divisor)). The returned slope is constrained by slope * divisor = dividend + quotient * modulus, which is slope * divisor ≡ dividend (mod modulus).

The wire parameter exists is a boolean-wire signifying the existence of the quotient (i.e. that divisor is invertible modulo the modulus); if exists is false, the modular reduction constraint is not applied. This is useful for avoiding overconstraining in skipped parts of larger circuits. The slope < modulus range check is unconditional, so when exists is false the returned value is an unconstrained dummy < modulus.

§Precondition and incompleteness

dividend must be reduced (dividend < modulus): it plays the role of the remainder in the reduction slope * divisor = dividend + quotient * modulus. If dividend >= modulus there is no non-negative quotient satisfying that equation, so (when exists is true) the constraint system has no satisfying witness and proof generation fails — the gadget is incomplete for unreduced dividends. Callers must reduce the dividend beforehand; the field helpers add, sub, mul and square all return reduced values. (This matches the standard ECDSA convention of reducing the message hash to a scalar in [0, n) before computing u1/u2.)

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

§

impl<T> Instrument for T

§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided [Span], returning an Instrumented wrapper. Read more
§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self>

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
§

impl<T> Pointable for T

§

const ALIGN: usize

The alignment of pointer.
§

type Init = T

The type for initializers.
§

unsafe fn init(init: <T as Pointable>::Init) -> usize

Initializes a with the given initializer. Read more
§

unsafe fn deref<'a>(ptr: usize) -> &'a T

Dereferences the given pointer. Read more
§

unsafe fn deref_mut<'a>(ptr: usize) -> &'a mut T

Mutably dereferences the given pointer. Read more
§

unsafe fn drop(ptr: usize)

Drops the object pointed to by the given pointer. Read more
Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
§

impl<T> WithSubscriber for T

§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a [WithDispatch] wrapper. Read more
§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a [WithDispatch] wrapper. Read more