Skip to main content

verify

Function verify 

Source
pub fn verify<F, C>(
    point: &[C::Elem],
    degree: usize,
    eval: C::Elem,
    channel: &mut C,
) -> Result<SumcheckOutput<C::Elem>, Error>
where F: Field, C: IPVerifierChannel<F>,
Expand description

An MLE-check protocol is an interactive protocol similar to sumcheck, but with modifications introduced in Gruen24, Section 3.

The prover in an MLE-check argues a that for some $n$-variate polynomial $F(X_0, \ldots, X_{n-1})$ (which is not necessarily multilinear), for a given point $(z_0, \ldots, z_{n-1})$ and claimed value $s$, that

$$ s = \sum_{v \in B_n} F(v) \cdot eq(v, z) $$

Unless $F$ is indeed multilinear, $s \ne F(z)$ necessarily. While the prover and verifier could engage in a standard sumcheck protocol to reduce this claim, it is concretely more efficient to use the optimized protocol from Gruen24, which we call an “MLE-check”.

§Arguments

  • point - The evaluation point for the multilinear extension
  • degree - The degree of the univariate polynomial in each round
  • eval - The claimed multilinear-extension evaluation of the multivariate polynomial
  • channel - The channel for receiving prover messages and sampling challenges

§Returns

Returns a Result containing the SumcheckOutput with the reduced evaluation and challenge point, or an error if verification fails.