Skip to main content

prove_phase_2

Function prove_phase_2 

Source
pub fn prove_phase_2<F, P, Channel, A>(
    key_collection: &KeyCollection,
    words: SegmentWords<'_>,
    prepared: &PreparedOperandClaims<F>,
    phase_1_output: Phase1Output<F>,
    shift_ind_eval: F,
    epsilon: F,
    channel: &mut Channel,
    alloc: &A,
) -> ShiftOutput<F>
where F: BinaryField, P: PackedField<Scalar = F>, Channel: IPProverChannel<F>, A: Allocator,
Expand description

Proves the second phase of the shift protocol reduction.

Folds the value-vector words by the bit-position challenge. Builds the constraint-matrix multilinear’s two segments. Then runs a sumcheck between them, with a sparse first round over the segment selector.

§Arguments

  • key_collection: the prover’s key collection for the constraint system.
  • words: the value-vector words.
  • prepared: the prepared claim of each operation, indexed by the operation a key names.
  • phase_1_output: the challenges and evaluation the first phase produced.
  • shift_ind_eval: the scalar weighting every shift key.
  • epsilon: the claim this phase’s rounds prove.
  • channel: the prover channel the interactive rounds run over.
  • alloc: the allocator the intermediate buffers are drawn from.

shift_ind_eval is the product of the two indicator evaluations. Those are what the earlier bit-index phases reduced to.

§Returns

The combined challenges with the witness evaluation, and the wiring multilinear’s evaluation.