pub struct RoundProof<F>(pub RoundCoeffs<F>);Expand description
An MLE-check round proof is a univariate polynomial in monomial basis with the coefficient of the lowest-degree term truncated off.
Since the verifier knows the claimed linear extrapolation of the polynomial values at the points 0 and 1, the low-degree term coefficient can be easily recovered. Truncating the coefficient off saves a small amount of proof data.
This is an analogous struct to sumcheck::RoundProof, except that we truncate the low-degree
coefficient instead of the high-degree coefficient.
In a sumcheck protocol, the verifier has a claimed sum $s$ and the round polynomial $R(X)$ must satisfy $R(0) + R(1) = s$. In an MLE-check protocol, the verifier has a claimed coordinate $\alpha$ and extrapolated value $s$ and the round polynomial must satisfy $(1 - \alpha) R(0) + \alpha R(1) = s$. This difference changes the recovery procedure and which polynomial coefficient is most convenient to truncate.
Tuple Fields§
§0: RoundCoeffs<F>Implementations§
Source§impl<F> RoundProof<F>
impl<F> RoundProof<F>
Sourcepub fn truncate(coeffs: RoundCoeffs<F>) -> Self
pub fn truncate(coeffs: RoundCoeffs<F>) -> Self
Truncates the polynomial coefficients to a round proof.
Removes the first coefficient. See the struct documentation for more info.
§Pre-conditions
coeffsmust not be empty
Sourcepub fn recover(self, eval: F, alpha: F) -> RoundCoeffs<F>where
F: FieldOps,
pub fn recover(self, eval: F, alpha: F) -> RoundCoeffs<F>where
F: FieldOps,
Recovers all univariate polynomial coefficients from the compressed round proof.
The prover has sent coefficients for the purported $i$’th round polynomial $R(X) = \sum_{j=0}^d a_j * X^j$.
However, the prover has not sent the lowest degree coefficient $a_0$. The verifier will need to recover this missing coefficient.
Let $s$ denote the current round’s claimed sum and $\alpha_i$ be the $i$’th coordinate of the evaluation point.
The verifier expects the round polynomial $R_i$ to satisfy the identity $s = (1 - \alpha) R(0) + \alpha R(1)$, or equivalently, $s = R(0) + (R(1) - R(0)) \alpha$.
Using $R(0) = a_0$ $R(1) = \sum_{j=0}^d a_j$ There is a unique $a_0$ that allows $R$ to satisfy the above identity. Specifically, $a_0 = s - \alpha \sum_{j=1}^d a_j$.
Trait Implementations§
Source§impl<F: Clone> Clone for RoundProof<F>
impl<F: Clone> Clone for RoundProof<F>
Source§fn clone(&self) -> RoundProof<F>
fn clone(&self) -> RoundProof<F>
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read moreSource§impl<F: Debug> Debug for RoundProof<F>
impl<F: Debug> Debug for RoundProof<F>
Source§impl<F: Default> Default for RoundProof<F>
impl<F: Default> Default for RoundProof<F>
Source§fn default() -> RoundProof<F>
fn default() -> RoundProof<F>
impl<F: Eq> Eq for RoundProof<F>
Source§impl<F: PartialEq> PartialEq for RoundProof<F>
impl<F: PartialEq> PartialEq for RoundProof<F>
Source§fn eq(&self, other: &RoundProof<F>) -> bool
fn eq(&self, other: &RoundProof<F>) -> bool
self and other values to be equal, and is used by ==.impl<F: PartialEq> StructuralPartialEq for RoundProof<F>
Auto Trait Implementations§
impl<F> Freeze for RoundProof<F>
impl<F> RefUnwindSafe for RoundProof<F>where
F: RefUnwindSafe,
impl<F> Send for RoundProof<F>where
F: Send,
impl<F> Sync for RoundProof<F>where
F: Sync,
impl<F> Unpin for RoundProof<F>where
F: Unpin,
impl<F> UnsafeUnpin for RoundProof<F>
impl<F> UnwindSafe for RoundProof<F>where
F: UnwindSafe,
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
§impl<T> Instrument for T
impl<T> Instrument for T
§fn instrument(self, span: Span) -> Instrumented<Self>
fn instrument(self, span: Span) -> Instrumented<Self>
§fn in_current_span(self) -> Instrumented<Self>
fn in_current_span(self) -> Instrumented<Self>
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more