pub struct ShiftIndSumcheck<P: PackedField, A: Allocator> { /* private fields */ }Expand description
Phase 3 of the shift reduction’s sumcheck: the Word::LOG_BITS rounds binding the bit
index the shift indicators read.
Phases 1 and 2 leave the claim
$$ \beta = h(r_j, r_s, r_v) \cdot G, \qquad h(r_j, r_s, r_v) = \sum_i \widetilde{L}(i) \cdot \sum_{\text{op}} \widetilde{eq}(r_v, \text{op}) \cdot \text{ind}_{\text{op}}(i, r_j, r_s), $$
with $G = g(r_j, r_s, r_v)$ the sum over the word index that phase 4 goes on to bind. Unrolling $h$ exposes these rounds as a sumcheck over two multilinears in the bit index — a weight vector and the interpolated shift indicators — with $G$ riding along as a constant.
The two are held apart rather than multiplied together, which is what keeps the round
polynomials degree 2. The constant is folded into the weights, so the pair sums to $\beta$ and
the rounds are the ones the verifier’s single sumcheck expects. Phase 4 then scales its
monster multilinear by the product of the two evaluations these rounds reduce their factors to,
which ShiftIndOutput reports separately.
The weights and the point the indicator is read at are the caller’s, not this type’s: a reduction peeling two shifts runs these rounds once per shift slot, differing only in those two arguments.
Implementations§
Source§impl<F: BinaryField, P: PackedField<Scalar = F>, A: Allocator> ShiftIndSumcheck<P, A>
impl<F: BinaryField, P: PackedField<Scalar = F>, A: Allocator> ShiftIndSumcheck<P, A>
Sourcepub fn new(
alloc: &A,
weights: &[F],
point: &ShiftChallengePoint<'_, F>,
g_eval: F,
) -> Self
pub fn new( alloc: &A, weights: &[F], point: &ShiftChallengePoint<'_, F>, g_eval: F, ) -> Self
Builds the two multilinears the rounds run over, from the weights the caller holds and phase 1’s challenges.
§Arguments
weights: the weight vector over the bit index, one entry per bit of a word. The reduction supplies the oblong Lagrange evaluations at the univariate challenge.point: the point the shift indicator is read at — phase 1’s challenges for the input bit position, the shift amount and the shift variant.g_eval:g(point), the constant these rounds carry.
§Panics
Panics unless the weights hold one entry per bit position of a word.
Sourcepub fn prove(
self,
channel: &mut impl IPProverChannel<F>,
alloc: &A,
) -> ShiftIndOutput<F>
pub fn prove( self, channel: &mut impl IPProverChannel<F>, alloc: &A, ) -> ShiftIndOutput<F>
Proves the Word::LOG_BITS rounds binding the bit index.
Auto Trait Implementations§
impl<P, A> Freeze for ShiftIndSumcheck<P, A>
impl<P, A> RefUnwindSafe for ShiftIndSumcheck<P, A>
impl<P, A> Send for ShiftIndSumcheck<P, A>
impl<P, A> Sync for ShiftIndSumcheck<P, A>
impl<P, A> Unpin for ShiftIndSumcheck<P, A>
impl<P, A> UnsafeUnpin for ShiftIndSumcheck<P, A>
impl<P, A> UnwindSafe for ShiftIndSumcheck<P, A>
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
§impl<T> Instrument for T
impl<T> Instrument for T
§fn instrument(self, span: Span) -> Instrumented<Self>
fn instrument(self, span: Span) -> Instrumented<Self>
§fn in_current_span(self) -> Instrumented<Self>
fn in_current_span(self) -> Instrumented<Self>
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more