Skip to main content

prove

Function prove 

Source
pub fn prove<A, P, Channel>(
    alloc: &A,
    packed_witness: FieldSlice<'_, P>,
    eval_point: &[B128],
    channel: &mut Channel,
) -> RingSwitchOutput<A, P>
where A: Allocator, P: PackedField<Scalar = B128>, Channel: IPProverChannel<B128>,
Expand description

Prove the ring-switching reduction.

Takes the packed witness and evaluation point from shift reduction, and:

  1. Computes partial evaluations s_hat_v
  2. Sends s_hat_v to verifier via channel
  3. Samples row-batching challenges
  4. Computes the ring-switching equality indicator and sumcheck claim

Returns the transparent polynomial and sumcheck claim for BaseFold.

§Arguments

  • alloc - the allocator the ring-switching equality indicator is drawn from
  • packed_witness - the packed witness buffer (B1 polynomial packed into P elements)
  • eval_point - the evaluation point from shift reduction
  • channel - the prover channel for sending/sampling

§Preconditions

  • packed_witness.log_len() + log_packing == eval_point.len() where log_packing is the base-2 log of the extension degree of B128 over B1 (= 7)