pub struct PseudoMersennePrimeField { /* private fields */ }Expand description
A struct that implements prime field arithmetic over pseudo-Mersenne modulus.
Field elements are BigUints consisting of PseudoMersennePrimeField::limbs_len limbs.
It is assumed that all field elements are correctly represented (less than modulus).
Implementations§
Source§impl PseudoMersennePrimeField
impl PseudoMersennePrimeField
Sourcepub fn new(
b: &CircuitBuilder,
modulus_po2: usize,
modulus_subtrahend: &[u64],
) -> Self
pub fn new( b: &CircuitBuilder, modulus_po2: usize, modulus_subtrahend: &[u64], ) -> Self
Create a new pseudo-Mersenne prime field.
See PseudoMersenneModReduce for description of the parameters.
Sourcepub const fn limbs_len(&self) -> usize
pub const fn limbs_len(&self) -> usize
Number of limbs in BigUints representing field elements.
Sourcepub fn add(&self, b: &CircuitBuilder, fe1: &BigUint, fe2: &BigUint) -> BigUint
pub fn add(&self, b: &CircuitBuilder, fe1: &BigUint, fe2: &BigUint) -> BigUint
Field addition.
Equivalent formula: (fe1 + fe2) % modulus
Sourcepub fn sub(&self, b: &CircuitBuilder, fe1: &BigUint, fe2: &BigUint) -> BigUint
pub fn sub(&self, b: &CircuitBuilder, fe1: &BigUint, fe2: &BigUint) -> BigUint
Field subtraction.
Equivalent formula: (fe1 - fe2) % modulus
Sourcepub fn square(&self, b: &CircuitBuilder, fe: &BigUint) -> BigUint
pub fn square(&self, b: &CircuitBuilder, fe: &BigUint) -> BigUint
Field squaring.
Equivalent formula: (fe ** 2) % modulus
Sourcepub fn mul(&self, b: &CircuitBuilder, fe1: &BigUint, fe2: &BigUint) -> BigUint
pub fn mul(&self, b: &CircuitBuilder, fe1: &BigUint, fe2: &BigUint) -> BigUint
Field multiplication.
Equivalent formula: (fe1 * fe2) % modulus
Note: Both fe1 and fe2 may be greater or equal to modulus.
Sourcepub fn inverse(&self, b: &CircuitBuilder, fe: &BigUint, exists: Wire) -> BigUint
pub fn inverse(&self, b: &CircuitBuilder, fe: &BigUint, exists: Wire) -> BigUint
Field inverse.
Equivalent formula (for prime modulus): (fe1 ** (modulus - 2)) % modulus
The wire parameter exists is a boolean-wire signifying the existence of the inverse;
if exists is false, the modular reduction constraint is not applied. This is useful
for avoiding overconstraining in skipped parts of larger circuits.
Sourcepub fn div(
&self,
b: &CircuitBuilder,
dividend: &BigUint,
divisor: &BigUint,
exists: Wire,
) -> BigUint
pub fn div( &self, b: &CircuitBuilder, dividend: &BigUint, divisor: &BigUint, exists: Wire, ) -> BigUint
Field division.
Equivalent formula (for prime modulus): (dividend * divisor ** (modulus - 2)) % modulus,
i.e. dividend / divisor (mod modulus).
This collapses a modular inverse followed by a multiplication into a single modular
reduction, halving the multiplication cost relative to mul(dividend, inverse(divisor)).
The returned slope is constrained by slope * divisor = dividend + quotient * modulus,
which is slope * divisor ≡ dividend (mod modulus).
The wire parameter exists is a boolean-wire signifying the existence of the quotient
(i.e. that divisor is invertible modulo the modulus); if exists is false, the modular
reduction constraint is not applied. This is useful for avoiding overconstraining in
skipped parts of larger circuits. The slope < modulus range check is unconditional, so
when exists is false the returned value is an unconstrained dummy < modulus.
§Precondition and incompleteness
dividend must be reduced (dividend < modulus): it plays the role of the remainder in
the reduction slope * divisor = dividend + quotient * modulus. If dividend >= modulus
there is no non-negative quotient satisfying that equation, so (when exists is true)
the constraint system has no satisfying witness and proof generation fails — the gadget is
incomplete for unreduced dividends. Callers must reduce the dividend beforehand; the
field helpers add, sub, mul and
square all return reduced values. (This matches the standard ECDSA
convention of reducing the message hash to a scalar in [0, n) before computing
u1/u2.)
Auto Trait Implementations§
impl Freeze for PseudoMersennePrimeField
impl RefUnwindSafe for PseudoMersennePrimeField
impl Send for PseudoMersennePrimeField
impl Sync for PseudoMersennePrimeField
impl Unpin for PseudoMersennePrimeField
impl UnsafeUnpin for PseudoMersennePrimeField
impl UnwindSafe for PseudoMersennePrimeField
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
§impl<T> Instrument for T
impl<T> Instrument for T
§fn instrument(self, span: Span) -> Instrumented<Self>
fn instrument(self, span: Span) -> Instrumented<Self>
§fn in_current_span(self) -> Instrumented<Self>
fn in_current_span(self) -> Instrumented<Self>
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more