Expand description
Zero-fraction padding for batching fractional-addition trees of unequal depths.
A batch runs one uniform layer schedule, so every tree in it must be of the same depth. Padding lifts a tree of depth $m$ to the batch’s depth $n \ge m$. The $n - m$ extra leaf positions hold the zero fraction $0/1$, the additive identity. So the tree’s fractional sum is unchanged and the verifier never learns the individual depths.
The padding variables are the lowest ones. Padding a witness $(N, D)$ over $\nu = n - m$ of them gives
$$ N’(X_\text{pad}, X_\text{real}) = N(X_\text{real}) \cdot \text{eq}(0^\nu; X_\text{pad}), \qquad D’(X_\text{pad}, X_\text{real}) = 1 + \bigl( D(X_\text{real}) - 1 \bigr) \cdot \text{eq}(0^\nu; X_\text{pad}), $$
so the numerators are zero-padded and the denominators one-padded.
The prover never materializes a padded witness.
PaddedBatch holds the trees and how deep each one sits.
Every layer it pops hands out one PaddedLayerProver per tree.
Each of those wraps the tree’s own layer prover in a ZeroPadMleCheckProver.
That wrapper corrects the unpadded layer’s messages at a cost of $O(1)$ per round.
A tree the batch has not reached yet has no layer to wrap.
It contributes a ConstantFraction instead.
unpad_leaf_claim inverts the identity above on the claims the batch outputs.
Functions§
- unpad_
leaf_ claim - Reduces a leaf claim on a zero-fraction-padded witness to the claim on the witness itself.