pub fn prove<F, P, Channel, A>(
key_collection: &KeyCollection,
public_words: &[Word],
hidden_words: &[Word],
claims: OperandClaims<F>,
domain_subspace: &BinarySubspace<F>,
channel: &mut Channel,
alloc: &A,
) -> ShiftOutput<F>Expand description
Proves the shift protocol reduction, collapsing every operation’s claims into one.
The result is a single multilinear evaluation claim on the witness. It is reached in five prover phases. A shifted value index names two shifts applied in sequence. The reduction peels them off from the output end inward:
- bind the outer shift slot, then the inner one, then the bit position within a word;
- bind the bit index of the intermediate word, where the two shift indicators meet;
- bind the output bit index the reduction’s first factor attaches to;
- reduce what is left to a witness evaluation, against the constraint-matrix multilinear.
§Arguments
key_collection: the prover’s key collection for the constraint system.public_words: the constants followed by the inout values, as the circuit declares them.hidden_words: the private values, as the circuit declares them.claims: the operand evaluation claims, all at one constraint point.domain_subspace: the univariate evaluation domain.channel: the prover channel the interactive rounds run over.alloc: the allocator the intermediate buffers are drawn from.
§Returns
The final challenges with the witness evaluation. Also the wiring multilinear’s evaluation, for the caller to send.