Skip to main content

ShiftIndSumcheck

Struct ShiftIndSumcheck 

Source
pub struct ShiftIndSumcheck<P: PackedField, A: Allocator> { /* private fields */ }
Expand description

Phase 3 of the shift reduction’s sumcheck: the Word::LOG_BITS rounds binding the bit index the shift indicators read.

Phases 1 and 2 leave the claim

$$ \beta = h(r_j, r_s, r_v) \cdot G, \qquad h(r_j, r_s, r_v) = \sum_i \widetilde{L}(i) \cdot \sum_{\text{op}} \widetilde{eq}(r_v, \text{op}) \cdot \text{ind}_{\text{op}}(i, r_j, r_s), $$

with $G = g(r_j, r_s, r_v)$ the sum over the word index that phase 4 goes on to bind. Unrolling $h$ exposes these rounds as a sumcheck over two multilinears in the bit index — a weight vector and the interpolated shift indicators — with $G$ riding along as a constant.

The two are held apart rather than multiplied together, which is what keeps the round polynomials degree 2. The constant is folded into the weights, so the pair sums to $\beta$ and the rounds are the ones the verifier’s single sumcheck expects. Phase 4 then scales its monster multilinear by the product of the two evaluations these rounds reduce their factors to, which ShiftIndOutput reports separately.

The weights and the point the indicator is read at are the caller’s, not this type’s: a reduction peeling two shifts runs these rounds once per shift slot, differing only in those two arguments.

Implementations§

Source§

impl<F: BinaryField, P: PackedField<Scalar = F>, A: Allocator> ShiftIndSumcheck<P, A>

Source

pub fn new( alloc: &A, weights: &[F], point: &ShiftChallengePoint<'_, F>, g_eval: F, ) -> Self

Builds the two multilinears the rounds run over, from the weights the caller holds and phase 1’s challenges.

§Arguments
  • weights: the weight vector over the bit index, one entry per bit of a word. The reduction supplies the oblong Lagrange evaluations at the univariate challenge.
  • point: the point the shift indicator is read at — phase 1’s challenges for the input bit position, the shift amount and the shift variant.
  • g_eval: g(point), the constant these rounds carry.
§Panics

Panics unless the weights hold one entry per bit position of a word.

Source

pub const fn beta(&self) -> F

The claim these rounds start from, which phase 2 reduced to.

Source

pub fn prove( self, channel: &mut impl IPProverChannel<F>, alloc: &A, ) -> ShiftIndOutput<F>

Proves the Word::LOG_BITS rounds binding the bit index.

Auto Trait Implementations§

§

impl<P, A> Freeze for ShiftIndSumcheck<P, A>
where <P as FieldOps>::Scalar: Freeze, <A as Allocator>::Vec<P>: Freeze,

§

impl<P, A> RefUnwindSafe for ShiftIndSumcheck<P, A>

§

impl<P, A> Send for ShiftIndSumcheck<P, A>

§

impl<P, A> Sync for ShiftIndSumcheck<P, A>
where <A as Allocator>::Vec<P>: Sync,

§

impl<P, A> Unpin for ShiftIndSumcheck<P, A>
where <P as FieldOps>::Scalar: Unpin, <A as Allocator>::Vec<P>: Unpin,

§

impl<P, A> UnsafeUnpin for ShiftIndSumcheck<P, A>
where <P as FieldOps>::Scalar: UnsafeUnpin, <A as Allocator>::Vec<P>: UnsafeUnpin,

§

impl<P, A> UnwindSafe for ShiftIndSumcheck<P, A>
where <P as FieldOps>::Scalar: UnwindSafe, <A as Allocator>::Vec<P>: UnwindSafe,

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

§

impl<T> Instrument for T

§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided [Span], returning an Instrumented wrapper. Read more
§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self>

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
§

impl<T> Pointable for T

§

const ALIGN: usize

The alignment of pointer.
§

type Init = T

The type for initializers.
§

unsafe fn init(init: <T as Pointable>::Init) -> usize

Initializes a with the given initializer. Read more
§

unsafe fn deref<'a>(ptr: usize) -> &'a T

Dereferences the given pointer. Read more
§

unsafe fn deref_mut<'a>(ptr: usize) -> &'a mut T

Mutably dereferences the given pointer. Read more
§

unsafe fn drop(ptr: usize)

Drops the object pointed to by the given pointer. Read more
Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
§

impl<T> WithSubscriber for T

§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a [WithDispatch] wrapper. Read more
§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a [WithDispatch] wrapper. Read more