Skip to main content

prove

Function prove 

Source
pub fn prove<F: Field, P: PackedField<Scalar = F>, Data: Deref<Target = [P]>>(
    main_prover: impl MleCheckProver<F>,
    mask: Mask<P, Data>,
    channel: &mut impl IPProverChannel<F>,
) -> ProveZKOutput<F>
Expand description

Executes the zero-knowledge MLE-check proving protocol for a single multivariate polynomial.

This function proves a single MLE-check while batching with a Libra mask polynomial to achieve zero-knowledge. The mask polynomial has the separable form $g(X_0, \ldots, X_{n-1}) = \sum_i g_i(X_i)$ where each $g_i$ is a univariate polynomial.

§Protocol Flow

  1. Compute and write mask_eval (MLE of mask polynomial at the evaluation point)
  2. Sample batch_challenge and batch evaluation claims
  3. For each round, batch the main and mask round polynomials
  4. Write mask_eval_out (mask evaluation at the challenge point)

§Arguments

  • main_prover - The MLE-check prover for the main polynomial. Must carry exactly one claim.
  • mask - The mask polynomial.
  • channel - The channel for sending prover messages and sampling challenges

§Returns

Returns ProveZKOutput containing the main polynomial’s multilinear evaluations and the round challenges.

§Pre-conditions

  • The mask’s univariate degree must be at least the degree of the main prover’s round polynomials.
  • The two round polynomials are added coefficient by coefficient, so a shorter mask leaves the high-degree coefficients uncovered and the protocol is no longer hiding.

§Panics

Panics if the main prover emits more than one round polynomial. Panics if the mask’s round polynomial is shorter than the main prover’s.