pub struct IntMulProver<'a, 'alloc, A: Allocator, P, Channel> { /* private fields */ }Expand description
A helper structure that encapsulates switchover settings and the prover channel for the integer multiplication protocol.
Implementations§
Source§impl<'a, 'alloc, A: Allocator, P, Channel> IntMulProver<'a, 'alloc, A, P, Channel>
impl<'a, 'alloc, A: Allocator, P, Channel> IntMulProver<'a, 'alloc, A, P, Channel>
pub const fn new( switchover: usize, channel: &'a mut Channel, alloc: &'alloc A, ) -> Self
Source§impl<'alloc, A, F, P, Channel> IntMulProver<'_, 'alloc, A, P, Channel>where
A: Allocator,
F: BinaryField<Underlier: Divisible<u64>>,
P: PackedField<Scalar = F>,
Channel: IOPProverChannel<P, A>,
impl<'alloc, A, F, P, Channel> IntMulProver<'_, 'alloc, A, P, Channel>where
A: Allocator,
F: BinaryField<Underlier: Divisible<u64>>,
P: PackedField<Scalar = F>,
Channel: IOPProverChannel<P, A>,
Sourcepub fn prove(&mut self, witness: Witness<'_, 'alloc, A, P>) -> IntMulOutput<F>
pub fn prove(&mut self, witness: Witness<'_, 'alloc, A, P>) -> IntMulOutput<F>
Prove an integer multiplication statement.
This method consumes a Witness in order to reduce integer multiplication statement to
evaluation claims on 1-bit multilinears. More formally:
witnesscontains po2-sized integer arraysa,b,c_loandc_hithat satisfya * b = c_lo | c_hi << Word::BITS, as well as the layers of the constant- and variable-base GKR product check circuits- The proving consists of five phases:
- Phase 1: GKR tree roots for B & C are evaluated at a sampled point, after which reductions are performed to obtain evaluation claims on $(b * (G^{a_i} - 1) + 1)^{2^i}$
- Phase 2: Frobenius twist is applied to obtain claims on $b * (G^{a_i} - 1) + 1$
- Phase 3: Two batched sumchecks:
- Selector mlecheck to reduce claims on $b * (G^{a_i} - 1) + 1$ to claims on $G^{a_i}$
and $b$, then recombine the $2^k$ per-bit
bclaims into one via a sampled $r_I^b$ - First layer of GPA reduction for the
c_lo || c_hicombinedctree
- Selector mlecheck to reduce claims on $b * (G^{a_i} - 1) + 1$ to claims on $G^{a_i}$
and $b$, then recombine the $2^k$ per-bit
- Phase 4: Batched product check over the three depth-
LOG_N_LIMBSconstant-base trees (a,c_lo,c_hi), reducing the roots to per-limb evaluation claims - Phase 5: The per-limb claims are Frobenius-twisted onto the shared power table
i ↦ G^iand read from it via a committed logup* lookup; a final batched sumcheck brings the reduced index claim, a single-claim rerandomization (MLE-eval) of the recombinedbexponent claim from phase 3, and the overflow parity zerocheck to one shared point
The output of this protocol is a set of evaluation claims on the b selectors representing
all of a, b, c_lo and c_hi as column-major bit matrices, at a common evaluation
point. The logup* pushforward commitment carries its two relations into the channel inside
phase 5.
Auto Trait Implementations§
impl<'a, 'alloc, A, P, Channel> !UnwindSafe for IntMulProver<'a, 'alloc, A, P, Channel>
impl<'a, 'alloc, A, P, Channel> Freeze for IntMulProver<'a, 'alloc, A, P, Channel>
impl<'a, 'alloc, A, P, Channel> RefUnwindSafe for IntMulProver<'a, 'alloc, A, P, Channel>
impl<'a, 'alloc, A, P, Channel> Send for IntMulProver<'a, 'alloc, A, P, Channel>
impl<'a, 'alloc, A, P, Channel> Sync for IntMulProver<'a, 'alloc, A, P, Channel>
impl<'a, 'alloc, A, P, Channel> Unpin for IntMulProver<'a, 'alloc, A, P, Channel>where
P: Unpin,
impl<'a, 'alloc, A, P, Channel> UnsafeUnpin for IntMulProver<'a, 'alloc, A, P, Channel>
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more
§impl<T> Instrument for T
impl<T> Instrument for T
§fn instrument(self, span: Span) -> Instrumented<Self>
fn instrument(self, span: Span) -> Instrumented<Self>
§fn in_current_span(self) -> Instrumented<Self>
fn in_current_span(self) -> Instrumented<Self>
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
Converts
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
Converts
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more