Skip to main content

IntMulProver

Struct IntMulProver 

Source
pub struct IntMulProver<'a, 'alloc, A: Allocator, P, Channel> { /* private fields */ }
Expand description

A helper structure that encapsulates switchover settings and the prover channel for the integer multiplication protocol.

Implementations§

Source§

impl<'a, 'alloc, A: Allocator, P, Channel> IntMulProver<'a, 'alloc, A, P, Channel>

Source

pub const fn new( switchover: usize, channel: &'a mut Channel, alloc: &'alloc A, ) -> Self

Source§

impl<'alloc, A, F, P, Channel> IntMulProver<'_, 'alloc, A, P, Channel>
where A: Allocator, F: BinaryField<Underlier: Divisible<u64>>, P: PackedField<Scalar = F>, Channel: IOPProverChannel<P, A>,

Source

pub fn prove(&mut self, witness: Witness<'_, 'alloc, A, P>) -> IntMulOutput<F>

Prove an integer multiplication statement.

This method consumes a Witness in order to reduce integer multiplication statement to evaluation claims on 1-bit multilinears. More formally:

  • witness contains po2-sized integer arrays a, b, c_lo and c_hi that satisfy a * b = c_lo | c_hi << Word::BITS, as well as the layers of the constant- and variable-base GKR product check circuits
  • The proving consists of five phases:
    • Phase 1: GKR tree roots for B & C are evaluated at a sampled point, after which reductions are performed to obtain evaluation claims on $(b * (G^{a_i} - 1) + 1)^{2^i}$
    • Phase 2: Frobenius twist is applied to obtain claims on $b * (G^{a_i} - 1) + 1$
    • Phase 3: Two batched sumchecks:
      • Selector mlecheck to reduce claims on $b * (G^{a_i} - 1) + 1$ to claims on $G^{a_i}$ and $b$, then recombine the $2^k$ per-bit b claims into one via a sampled $r_I^b$
      • First layer of GPA reduction for the c_lo || c_hi combined c tree
    • Phase 4: Batched product check over the three depth-LOG_N_LIMBS constant-base trees (a, c_lo, c_hi), reducing the roots to per-limb evaluation claims
    • Phase 5: The per-limb claims are Frobenius-twisted onto the shared power table i ↦ G^i and read from it via a committed logup* lookup; a final batched sumcheck brings the reduced index claim, a single-claim rerandomization (MLE-eval) of the recombined b exponent claim from phase 3, and the overflow parity zerocheck to one shared point

The output of this protocol is a set of evaluation claims on the b selectors representing all of a, b, c_lo and c_hi as column-major bit matrices, at a common evaluation point. The logup* pushforward commitment carries its two relations into the channel inside phase 5.

Auto Trait Implementations§

§

impl<'a, 'alloc, A, P, Channel> !UnwindSafe for IntMulProver<'a, 'alloc, A, P, Channel>

§

impl<'a, 'alloc, A, P, Channel> Freeze for IntMulProver<'a, 'alloc, A, P, Channel>

§

impl<'a, 'alloc, A, P, Channel> RefUnwindSafe for IntMulProver<'a, 'alloc, A, P, Channel>
where P: RefUnwindSafe, Channel: RefUnwindSafe, A: RefUnwindSafe,

§

impl<'a, 'alloc, A, P, Channel> Send for IntMulProver<'a, 'alloc, A, P, Channel>
where P: Send, Channel: Send,

§

impl<'a, 'alloc, A, P, Channel> Sync for IntMulProver<'a, 'alloc, A, P, Channel>
where P: Sync, Channel: Sync,

§

impl<'a, 'alloc, A, P, Channel> Unpin for IntMulProver<'a, 'alloc, A, P, Channel>
where P: Unpin,

§

impl<'a, 'alloc, A, P, Channel> UnsafeUnpin for IntMulProver<'a, 'alloc, A, P, Channel>

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

§

impl<T> Instrument for T

§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided [Span], returning an Instrumented wrapper. Read more
§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self>

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
§

impl<T> Pointable for T

§

const ALIGN: usize

The alignment of pointer.
§

type Init = T

The type for initializers.
§

unsafe fn init(init: <T as Pointable>::Init) -> usize

Initializes a with the given initializer. Read more
§

unsafe fn deref<'a>(ptr: usize) -> &'a T

Dereferences the given pointer. Read more
§

unsafe fn deref_mut<'a>(ptr: usize) -> &'a mut T

Mutably dereferences the given pointer. Read more
§

unsafe fn drop(ptr: usize)

Drops the object pointed to by the given pointer. Read more
Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
§

impl<T> WithSubscriber for T

§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a [WithDispatch] wrapper. Read more
§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a [WithDispatch] wrapper. Read more