Skip to main content

verify_zk

Function verify_zk 

Source
pub fn verify_zk<F, C>(
    point: &[C::Elem],
    degree: usize,
    eval: C::Elem,
    channel: &mut C,
) -> Result<VerifyZKOutput<C::Elem>, Error>
where F: Field, C: IPVerifierChannel<F>,
Expand description

Variation of the MLE-check protocol that provides the hiding property.

This protocol is based on the zero-knowledge sumcheck technique from Libra, with a modification. When the field has characteristic 2, the Libra ZK-sumcheck protocol is not hiding. Instead, the mask polynomial $g$ is batched together with the multivariate polynomial whose MLE is being evaluated, whereas Libra would batch the mask polynomial together with the MLE itself.