Skip to main content

prove

Function prove 

Source
pub fn prove<F, P, Channel, A>(
    key_collection: &KeyCollection,
    public_words: &[Word],
    hidden_words: &[Word],
    claims: OperandClaims<F>,
    domain_subspace: &BinarySubspace<F>,
    channel: &mut Channel,
    alloc: &A,
) -> ShiftOutput<F>
where F: BinaryField, P: PackedField<Scalar = F>, Channel: IPProverChannel<F>, A: Allocator,
Expand description

Proves the shift protocol reduction, collapsing every operation’s claims into one.

The result is a single multilinear evaluation claim on the witness. It is reached in five prover phases. A shifted value index names two shifts applied in sequence. The reduction peels them off from the output end inward:

  1. bind the outer shift slot, then the inner one, then the bit position within a word;
  2. bind the bit index of the intermediate word, where the two shift indicators meet;
  3. bind the output bit index the reduction’s first factor attaches to;
  4. reduce what is left to a witness evaluation, against the constraint-matrix multilinear.

§Arguments

  • key_collection: the prover’s key collection for the constraint system.
  • public_words: the constants followed by the inout values, as the circuit declares them.
  • hidden_words: the private values, as the circuit declares them.
  • claims: the operand evaluation claims, all at one constraint point.
  • domain_subspace: the univariate evaluation domain.
  • channel: the prover channel the interactive rounds run over.
  • alloc: the allocator the intermediate buffers are drawn from.

§Returns

The final challenges with the witness evaluation. Also the wiring multilinear’s evaluation, for the caller to send.