Skip to main content

RoundProof

Struct RoundProof 

Source
pub struct RoundProof<F>(pub RoundCoeffs<F>);
Expand description

An MLE-check round proof is a univariate polynomial in monomial basis with the coefficient of the lowest-degree term truncated off.

Since the verifier knows the claimed linear extrapolation of the polynomial values at the points 0 and 1, the low-degree term coefficient can be easily recovered. Truncating the coefficient off saves a small amount of proof data.

This is an analogous struct to sumcheck::RoundProof, except that we truncate the low-degree coefficient instead of the high-degree coefficient.

In a sumcheck protocol, the verifier has a claimed sum $s$ and the round polynomial $R(X)$ must satisfy $R(0) + R(1) = s$. In an MLE-check protocol, the verifier has a claimed coordinate $\alpha$ and extrapolated value $s$ and the round polynomial must satisfy $(1 - \alpha) R(0) + \alpha R(1) = s$. This difference changes the recovery procedure and which polynomial coefficient is most convenient to truncate.

Tuple Fields§

§0: RoundCoeffs<F>

Implementations§

Source§

impl<F> RoundProof<F>

Source

pub fn truncate(coeffs: RoundCoeffs<F>) -> Self

Truncates the polynomial coefficients to a round proof.

Removes the first coefficient. See the struct documentation for more info.

§Pre-conditions
  • coeffs must not be empty
Source

pub fn recover(self, eval: F, alpha: F) -> RoundCoeffs<F>
where F: FieldOps,

Recovers all univariate polynomial coefficients from the compressed round proof.

The prover has sent coefficients for the purported $i$’th round polynomial $R(X) = \sum_{j=0}^d a_j * X^j$.

However, the prover has not sent the lowest degree coefficient $a_0$. The verifier will need to recover this missing coefficient.

Let $s$ denote the current round’s claimed sum and $\alpha_i$ be the $i$’th coordinate of the evaluation point.

The verifier expects the round polynomial $R_i$ to satisfy the identity $s = (1 - \alpha) R(0) + \alpha R(1)$, or equivalently, $s = R(0) + (R(1) - R(0)) \alpha$.

Using $R(0) = a_0$ $R(1) = \sum_{j=0}^d a_j$ There is a unique $a_0$ that allows $R$ to satisfy the above identity. Specifically, $a_0 = s - \alpha \sum_{j=1}^d a_j$.

Source

pub fn coeffs(&self) -> &[F]

The truncated polynomial coefficients.

Trait Implementations§

Source§

impl<F: Clone> Clone for RoundProof<F>

Source§

fn clone(&self) -> RoundProof<F>

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl<F: Debug> Debug for RoundProof<F>

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl<F: Default> Default for RoundProof<F>

Source§

fn default() -> RoundProof<F>

Returns the “default value” for a type. Read more
Source§

impl<F: Eq> Eq for RoundProof<F>

Source§

impl<F: PartialEq> PartialEq for RoundProof<F>

Source§

fn eq(&self, other: &RoundProof<F>) -> bool

Tests for self and other values to be equal, and is used by ==.
1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Tests for !=. The default implementation is almost always sufficient, and should not be overridden without very good reason.
Source§

impl<F: PartialEq> StructuralPartialEq for RoundProof<F>

Auto Trait Implementations§

§

impl<F> Freeze for RoundProof<F>

§

impl<F> RefUnwindSafe for RoundProof<F>
where F: RefUnwindSafe,

§

impl<F> Send for RoundProof<F>
where F: Send,

§

impl<F> Sync for RoundProof<F>
where F: Sync,

§

impl<F> Unpin for RoundProof<F>
where F: Unpin,

§

impl<F> UnsafeUnpin for RoundProof<F>

§

impl<F> UnwindSafe for RoundProof<F>
where F: UnwindSafe,

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

§

impl<T> Instrument for T

§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided [Span], returning an Instrumented wrapper. Read more
§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self>

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
§

impl<T> Pointable for T

§

const ALIGN: usize

The alignment of pointer.
§

type Init = T

The type for initializers.
§

unsafe fn init(init: <T as Pointable>::Init) -> usize

Initializes a with the given initializer. Read more
§

unsafe fn deref<'a>(ptr: usize) -> &'a T

Dereferences the given pointer. Read more
§

unsafe fn deref_mut<'a>(ptr: usize) -> &'a mut T

Mutably dereferences the given pointer. Read more
§

unsafe fn drop(ptr: usize)

Drops the object pointed to by the given pointer. Read more
Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
§

impl<T> WithSubscriber for T

§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a [WithDispatch] wrapper. Read more
§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a [WithDispatch] wrapper. Read more