Skip to main content

ZKWrappedProverChannel

Struct ZKWrappedProverChannel 

Source
pub struct ZKWrappedProverChannel<'a, P, NTT, Channel, ReplayFn, A>
where P: PackedField<Scalar: BinaryField>, NTT: AdditiveNTT<Field = P::Scalar> + Sync, Channel: MerkleIPProverChannel<P::Scalar>, A: Allocator,
{ /* private fields */ }
Expand description

A prover channel that wraps a BaseFoldProverChannel and an outer Spartan IOP prover.

This channel records all channel values. On send_*/sample/observe_*, it delegates to the inner BaseFold channel and records each value. After the inner proof is run through this channel, call finish to replay the interaction, fill the outer witness, and generate the outer proof.

The ReplayFn closure is called during finish with a ReplayChannel to replay the inner verification and fill the outer witness. This allows the channel to be generic over different inner verification protocols.

Implementations§

Source§

impl<'a, F, P, NTT, Channel, ReplayFn, A> ZKWrappedProverChannel<'a, P, NTT, Channel, ReplayFn, A>
where F: BinaryField, P: PackedField<Scalar = F>, NTT: AdditiveNTT<Field = F> + Sync, Channel: MerkleIPProverChannel<F>, A: Allocator,

Source

pub fn new( inner_channel: BaseFoldProverChannel<'a, F, P, NTT, Channel, A>, outer_prover: &'a IOPProver<F>, outer_layout: Arc<WitnessLayout<F>>, alloc: &'a A, rng: impl CryptoRng, replay_fn: ReplayFn, ) -> Self

Creates a new ZK-wrapped prover channel.

Commits the outer prover’s precommit oracle on the inner channel as part of construction: a random FieldBuffer<P> the size of the outer precommit oracle segment is sent to the channel and kept for use in Self::finish. This random buffer is the one-time-pad encryption key for the (future) outer encrypted transcript.

The inner channel’s oracle specs are expected to be laid out as [outer_precommit, inner..., outer_private, outer_mask].

§Arguments
  • inner_channel - The BaseFold ZK channel with oracle specs for both inner and outer proofs
  • outer_prover - The IOP prover for the outer (wrapper) constraint system
  • outer_layout - The witness layout for the outer constraint system
  • alloc - Allocator for the outer proof’s working buffers, borrowed from the owning prover
  • rng - RNG used to generate the random precommit buffer (the future OTP key)
  • replay_fn - Closure called during finish with a ReplayChannel to replay the inner verification and fill the outer witness
Source

pub fn finish(self, rng: impl CryptoRng) -> Result<(), Error>
where ReplayFn: FnOnce(&mut ReplayChannel<F>),

Consumes the channel and runs the outer proof.

This should be called after the inner proof has been run through this channel. It:

  1. Creates a ReplayChannel from the recorded interaction
  2. Calls the replay_fn closure to replay the inner verification and fill the outer witness
  3. Validates and generates the outer IOP proof

Trait Implementations§

Source§

impl<F, P, NTT, Channel, ReplayFn, A> IOPProverChannel<P, A> for ZKWrappedProverChannel<'_, P, NTT, Channel, ReplayFn, A>
where F: BinaryField, P: PackedField<Scalar = F>, NTT: AdditiveNTT<Field = F> + Sync, Channel: MerkleIPProverChannel<F>, A: Allocator,

Source§

type Oracle = BaseFoldOracle

Source§

fn remaining_oracle_specs(&self) -> &[OracleSpec]

Returns the specifications for the remaining oracles to be committed. Read more
Source§

fn send_oracle(&mut self, buffer: FieldSlice<'_, P>) -> Self::Oracle

Commits an oracle to the verifier. Read more
Source§

fn prove_oracle_relation( &mut self, oracle: Self::Oracle, transparent: StructuredBuffer<P, A::Vec<P>>, claim: P::Scalar, )

Generates an opening proof for one oracle linear relation. Read more
Source§

fn finalize_oracle(&mut self, oracle: Self::Oracle, buffer: FieldVec<P, A>)

Gives ownership of the oracle buffer to the channel. Read more
Source§

impl<F, P, NTT, Channel, ReplayFn, A> IPProverChannel<F> for ZKWrappedProverChannel<'_, P, NTT, Channel, ReplayFn, A>
where F: BinaryField, P: PackedField<Scalar = F>, NTT: AdditiveNTT<Field = F> + Sync, Channel: MerkleIPProverChannel<F>, A: Allocator,

Source§

fn send_one(&mut self, elem: F)

Sends a single field element to the verifier.
Source§

fn send_public_claim(&mut self, elem: F)

Sends a value the verifier could compute for itself, as advice. Read more
Source§

fn observe_one(&mut self, val: F)

Observes a single field element, feeding it into the Fiat-Shamir state.
Source§

fn sample(&mut self) -> F

Samples a random challenge. Read more
Source§

fn send_many(&mut self, elems: &[F])

Sends multiple field elements to the verifier.
Source§

fn observe_many(&mut self, vals: &[F])

Observes multiple field elements, feeding them into the Fiat-Shamir state.
Source§

fn sample_many(&mut self, n: usize) -> Vec<F>

Samples n random challenges.
Source§

fn sample_array<const N: usize>(&mut self) -> [F; N]

Samples a fixed-size array of random challenges.
Source§

impl<F, P, NTT, Channel, ReplayFn, A> WordIPProverChannel<F> for ZKWrappedProverChannel<'_, P, NTT, Channel, ReplayFn, A>
where F: BinaryField, P: PackedField<Scalar = F>, NTT: AdditiveNTT<Field = F> + Sync, Channel: MerkleIPProverChannel<F>, A: Allocator,

Source§

type Word = <Channel as WordIPProverChannel<F>>::Word

The word type this channel carries. Read more
Source§

fn observe_words(&mut self, words: &[Self::Word])

Feeds words into the Fiat-Shamir state, each as eight little-endian bytes.
Source§

fn sample_bits(&mut self, bits: usize) -> Self::Word

Samples a uniform word of the given bit width, matching what the verifier samples. Read more

Auto Trait Implementations§

§

impl<'a, P, NTT, Channel, ReplayFn, A> Freeze for ZKWrappedProverChannel<'a, P, NTT, Channel, ReplayFn, A>
where <<P as FieldOps>::Scalar as UnderlierView>::Underlier: Sized, <P as FieldOps>::Scalar: Sized, ReplayFn: Freeze, Channel: Freeze, A: Freeze, <A as Allocator>::Vec<P>: Freeze,

§

impl<'a, P, NTT, Channel, ReplayFn, A> RefUnwindSafe for ZKWrappedProverChannel<'a, P, NTT, Channel, ReplayFn, A>

§

impl<'a, P, NTT, Channel, ReplayFn, A> Send for ZKWrappedProverChannel<'a, P, NTT, Channel, ReplayFn, A>
where <<P as FieldOps>::Scalar as UnderlierView>::Underlier: Sized, <P as FieldOps>::Scalar: Sized, ReplayFn: Send, Channel: Send, A: Send, <Channel as MerkleIPProverChannel<<P as FieldOps>::Scalar>>::Commitment: Send,

§

impl<'a, P, NTT, Channel, ReplayFn, A> Sync for ZKWrappedProverChannel<'a, P, NTT, Channel, ReplayFn, A>
where <<P as FieldOps>::Scalar as UnderlierView>::Underlier: Sized, <P as FieldOps>::Scalar: Sized, ReplayFn: Sync, Channel: Sync, <A as Allocator>::Vec<P>: Sync, <Channel as MerkleIPProverChannel<<P as FieldOps>::Scalar>>::Commitment: Sync,

§

impl<'a, P, NTT, Channel, ReplayFn, A> Unpin for ZKWrappedProverChannel<'a, P, NTT, Channel, ReplayFn, A>
where <<P as FieldOps>::Scalar as UnderlierView>::Underlier: Sized, <P as FieldOps>::Scalar: Sized + Unpin, ReplayFn: Unpin, Channel: Unpin, A: Unpin, <A as Allocator>::Vec<P>: Unpin, <Channel as MerkleIPProverChannel<<P as FieldOps>::Scalar>>::Commitment: Unpin,

§

impl<'a, P, NTT, Channel, ReplayFn, A> UnsafeUnpin for ZKWrappedProverChannel<'a, P, NTT, Channel, ReplayFn, A>
where <<P as FieldOps>::Scalar as UnderlierView>::Underlier: Sized, <P as FieldOps>::Scalar: Sized, ReplayFn: UnsafeUnpin, Channel: UnsafeUnpin, A: UnsafeUnpin, <A as Allocator>::Vec<P>: UnsafeUnpin,

§

impl<'a, P, NTT, Channel, ReplayFn, A> UnwindSafe for ZKWrappedProverChannel<'a, P, NTT, Channel, ReplayFn, A>

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

§

impl<T> Instrument for T

§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided [Span], returning an Instrumented wrapper. Read more
§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self>

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
§

impl<T> Pointable for T

§

const ALIGN: usize

The alignment of pointer.
§

type Init = T

The type for initializers.
§

unsafe fn init(init: <T as Pointable>::Init) -> usize

Initializes a with the given initializer. Read more
§

unsafe fn deref<'a>(ptr: usize) -> &'a T

Dereferences the given pointer. Read more
§

unsafe fn deref_mut<'a>(ptr: usize) -> &'a mut T

Mutably dereferences the given pointer. Read more
§

unsafe fn drop(ptr: usize)

Drops the object pointed to by the given pointer. Read more
Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
§

impl<T> WithSubscriber for T

§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a [WithDispatch] wrapper. Read more
§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a [WithDispatch] wrapper. Read more