Skip to main content

prove_public_eval

Function prove_public_eval 

Source
pub fn prove_public_eval<A, P, Channel>(
    alloc: &A,
    public_words: &[Word],
    r_j: &[B128],
    r_y: &[B128],
    channel: &mut Channel,
)
where A: Allocator, P: PackedField<Scalar = B128>, Channel: IPProverChannel<B128>,
Expand description

Proves the public segment’s evaluation claim.

The shift closes over the public segment as a bit matrix, at r_j over the bit within a word and the low coordinates of r_y over the word index. The verifier holds the segment but not its bits, so the claim is stated here and reduced in two steps:

  1. a ring-switch onto the segment’s packed form, leaving the claim sum_x P(x) A(x) against the ring-switching indicator;
  2. a sumcheck over the packed segment’s own variables, leaving one evaluation of each factor.

Nothing here is committed, so the verifier finishes on its own: it evaluates the packed segment’s multilinear from the words it holds, and the indicator from its succinct formula.

§Arguments

  • alloc - the allocator the packed segment and the indicator are drawn from
  • public_words - the public segment, unpadded
  • r_j - the bit-index challenges
  • r_y - the word-index challenges, of which the segment spans the low ones
  • channel - the prover channel for sending/sampling

§Preconditions

  • r_y must have at least as many coordinates as the packed segment spans words