pub trait IPVerifierChannel<F: Field> {
type Elem: FieldOps<Scalar = F>;
// Required methods
fn recv_one(&mut self) -> Result<Self::Elem, Error>;
fn sample(&mut self) -> Self::Elem;
fn observe_one(&mut self, val: F) -> Self::Elem;
fn assert_zero(&mut self, val: Self::Elem) -> Result<(), Error>;
// Provided methods
fn recv_many(&mut self, n: usize) -> Result<Vec<Self::Elem>, Error> { ... }
fn recv_array<const N: usize>(&mut self) -> Result<[Self::Elem; N], Error> { ... }
fn recv_public_claim(&mut self) -> Result<Self::Elem, Error> { ... }
fn sample_many(&mut self, n: usize) -> Vec<Self::Elem> { ... }
fn sample_array<const N: usize>(&mut self) -> [Self::Elem; N] { ... }
fn observe_many(&mut self, vals: &[F]) -> Vec<Self::Elem> { ... }
}Expand description
Channel for receiving prover messages and sampling challenges in a public-coin interactive protocol.
In a public-coin protocol, the verifier only sends random challenges (no secret information), so the verifier’s role is to:
- Receive field elements from the prover via
recv_*methods - Sample random challenges via
sample
When used with a Fiat-Shamir transcript, the challenges are derived deterministically from the transcript state, making the protocol non-interactive.
Required Associated Types§
Required Methods§
Sourcefn recv_one(&mut self) -> Result<Self::Elem, Error>
fn recv_one(&mut self) -> Result<Self::Elem, Error>
Receives a single field element from the prover.
Sourcefn sample(&mut self) -> Self::Elem
fn sample(&mut self) -> Self::Elem
Samples a random challenge.
In a Fiat-Shamir transcript, this derives the challenge deterministically from the current transcript state.
Sourcefn observe_one(&mut self, val: F) -> Self::Elem
fn observe_one(&mut self, val: F) -> Self::Elem
Observes a single field element, feeding it into the Fiat-Shamir state.
Returns the element converted to Self::Elem.
Sourcefn assert_zero(&mut self, val: Self::Elem) -> Result<(), Error>
fn assert_zero(&mut self, val: Self::Elem) -> Result<(), Error>
Asserts that a value is zero.
Returns Error::InvalidAssert if the value is not zero.
Provided Methods§
Sourcefn recv_many(&mut self, n: usize) -> Result<Vec<Self::Elem>, Error>
fn recv_many(&mut self, n: usize) -> Result<Vec<Self::Elem>, Error>
Receives n field elements from the prover.
Sourcefn recv_array<const N: usize>(&mut self) -> Result<[Self::Elem; N], Error>
fn recv_array<const N: usize>(&mut self) -> Result<[Self::Elem; N], Error>
Receives a fixed-size array of field elements from the prover.
Sourcefn recv_public_claim(&mut self) -> Result<Self::Elem, Error>
fn recv_public_claim(&mut self) -> Result<Self::Elem, Error>
Receives a value the verifier could compute for itself, taken as advice.
The prover states it and the verifier checks it — by recomputing it, or by any argument that establishes the same thing — which is worth doing when the check is cheaper than the computation, or when several such claims are better checked at once.
The caller MUST check what it receives here. Nothing else does.
A claim is a function of public-channel-derived values alone, so it carries nothing about the witness. Channels that mask the prover’s messages must therefore leave this one in the clear, and channels that carry elements as wires allocate it as a public wire rather than a masked private one. The default is the plain read, for a channel that draws no such distinction.
Sourcefn sample_many(&mut self, n: usize) -> Vec<Self::Elem>
fn sample_many(&mut self, n: usize) -> Vec<Self::Elem>
Samples n random challenges.
Sourcefn sample_array<const N: usize>(&mut self) -> [Self::Elem; N]
fn sample_array<const N: usize>(&mut self) -> [Self::Elem; N]
Samples a fixed-size array of random challenges.
Sourcefn observe_many(&mut self, vals: &[F]) -> Vec<Self::Elem>
fn observe_many(&mut self, vals: &[F]) -> Vec<Self::Elem>
Observes multiple field elements, feeding them into the Fiat-Shamir state.
Returns the elements converted to Vec<Self::Elem>.
Dyn Compatibility§
This trait is not dyn compatible.
In older versions of Rust, dyn compatibility was called "object safety".