pub struct NTTLookup(/* private fields */);Expand description
A precomputed lookup table for fast LDE operations on 64-bit binary field elements.
This structure stores precomputed LDE evaluations for all possible 8-bit input combinations, enabling fast computation of the full 64-bit LDE through table lookups and additions. See the module-level documentation for the LDE definition and the Flock compression it uses.
§Structure
The internal data structure is a boxed array Box<[[PackedRijndael64x8b; 256]; 2]> where:
- First dimension: the byte-position parity
b % 2. Only these two tables are stored; the remaining six byte positions are recovered by permutation (see the module-level “Compressed storage” notes). - Second dimension: the 8-bit value (0-255) for that byte.
Each entry holds the ROWS_PER_HYPERCUBE_VERTEX LDE evaluations of that byte’s coefficients,
packed into a single PackedRijndael64x8b.
Implementations§
Source§impl NTTLookup
impl NTTLookup
Sourcepub fn new(subspace: &BinarySubspace<B8>) -> Self
pub fn new(subspace: &BinarySubspace<B8>) -> Self
Creates a new NTT lookup table by precomputing all possible NTT evaluations for 8-bit input chunks across all byte positions in a 64-bit word.
§Parameters
subspace: Binary subspace of dimensionSKIPPED_VARS + 1. Its lower half defines the NTT input domain and its upper half the output domain at which evaluations are precomputed.
§Constraints
- Subspace dimension must equal
SKIPPED_VARS + 1
§Panics
Panics if subspace.dim() != SKIPPED_VARS + 1.
Sourcepub fn ntt(&self, input: Word) -> PackedRijndael64x8b
pub fn ntt(&self, input: Word) -> PackedRijndael64x8b
Computes the LDE of 64 1-bit coefficients using the precomputed lookup tables.
The 64-bit input is split into eight bytes B₀, B₁, …, B₇. By linearity the LDE of the
input is the sum of the per-byte LDEs: LDE(input) = LDE(B₀) + LDE(B₁) + ... + LDE(B₇).
Only two byte-position tables are stored, so the LDE of byte position b is reconstructed
from the table for parity b % 2 by permuting its packed evaluations according to b / 2.
This permutation is the translation of the output domain exploited by the Flock compression
(see the module-level “Compressed storage” notes); in the packed representation it is a
permutation of the four 128-bit lanes, lane[i] <- lane[i ^ (b / 2)]. The loop is unrolled
over b, so the parity select and lane index are compile-time constants.
Used directly only in tests; univariate_round_message_extension_domain accesses the tables
inline to compute three LDE evaluations at once, which is more efficient.
§Returns
A PackedRijndael64x8b holding the ROWS_PER_HYPERCUBE_VERTEX LDE evaluations over the
output domain.
Trait Implementations§
Auto Trait Implementations§
impl Freeze for NTTLookup
impl RefUnwindSafe for NTTLookup
impl Send for NTTLookup
impl Sync for NTTLookup
impl Unpin for NTTLookup
impl UnsafeUnpin for NTTLookup
impl UnwindSafe for NTTLookup
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
§impl<T> Instrument for T
impl<T> Instrument for T
§fn instrument(self, span: Span) -> Instrumented<Self>
fn instrument(self, span: Span) -> Instrumented<Self>
§fn in_current_span(self) -> Instrumented<Self>
fn in_current_span(self) -> Instrumented<Self>
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more