pub trait SumcheckProver<F: Field> {
// Required methods
fn n_vars(&self) -> usize;
fn execute(&mut self) -> Vec<RoundCoeffs<F>>;
fn fold(&mut self, challenge: F);
fn finish(self) -> Vec<F>;
}Expand description
A sumcheck prover with a round-by-round execution interface.
Sumcheck prover logic is accessed via a trait because important optimizations are available depending on the structure of the multivariate polynomial that the protocol targets. For example, Gruen24 observes a significant optimization available to the sumcheck prover when the multivariate is the product of a multilinear composite and an equality indicator polynomial, which arises in the zerocheck protocol.
The trait exposes a round-by-round interface so that protocol execution logic that drives the prover can interleave the executions of the interactive protocol, for example in the case of batching several sumcheck protocols.
The caller must make a specific sequence of calls to the provers. For a prover where
Self::n_vars is $n$, the caller must call Self::execute and then Self::fold $n$
times, and finally call Self::finish. If the calls aren’t made in that order, the prover
will panic.
This trait is not object-safe.
Required Methods§
Sourcefn n_vars(&self) -> usize
fn n_vars(&self) -> usize
The number of variables in the remaining multivariate polynomial.
The number of variables decrements after each Self::fold call, as that binds one free
variable with a concrete challenge.
Sourcefn execute(&mut self) -> Vec<RoundCoeffs<F>>
fn execute(&mut self) -> Vec<RoundCoeffs<F>>
Computes the prover messages for this round as a univariate polynomial.
If Self::fold has already been called on the prover with the values $r_0$, …,
$r_{k-1}$ and the sumcheck prover is proving the sums of the composite polynomials $C_0,
…, C_{m-1}$, then the output of this method for low-to-high evaluation order would be:
$$ R_i = \sum_{v \in B_{n-k-1}} C_i(r_0, …, r_{k-1}, X, {v}), i \in [0, …, m-1] $$
For high-to-low evaluation order the variables are specified in reverse order (starting with the highest indexed one) and hypercube sums are performed over the lower indexed variables.
One entry per claim the prover carries.
Dyn Compatibility§
This trait is dyn compatible.
In older versions of Rust, dyn compatibility was called "object safety".