pub fn prove<F: Field, P: PackedField<Scalar = F>, Data: Deref<Target = [P]>>(
main_prover: impl MleCheckProver<F>,
mask: Mask<P, Data>,
channel: &mut impl IPProverChannel<F>,
) -> ProveZKOutput<F>Expand description
Executes the zero-knowledge MLE-check proving protocol for a single multivariate polynomial.
This function proves a single MLE-check while batching with a Libra mask polynomial to achieve zero-knowledge. The mask polynomial has the separable form $g(X_0, \ldots, X_{n-1}) = \sum_i g_i(X_i)$ where each $g_i$ is a univariate polynomial.
§Protocol Flow
- Compute and write
mask_eval(MLE of mask polynomial at the evaluation point) - Sample
batch_challengeand batch evaluation claims - For each round, batch the main and mask round polynomials
- Write
mask_eval_out(mask evaluation at the challenge point)
§Arguments
main_prover- The MLE-check prover for the main polynomial. Must carry exactly one claim.mask- The mask polynomial.channel- The channel for sending prover messages and sampling challenges
§Returns
Returns ProveZKOutput containing the main polynomial’s multilinear evaluations
and the round challenges.
§Pre-conditions
- The mask’s univariate degree must be at least the degree of the main prover’s round polynomials.
- The two round polynomials are added coefficient by coefficient, so a shorter mask leaves the high-degree coefficients uncovered and the protocol is no longer hiding.
§Panics
Panics if the main prover emits more than one round polynomial. Panics if the mask’s round polynomial is shorter than the main prover’s.