Skip to main content

square_transpose

Function square_transpose 

Source
pub fn square_transpose<B: CircuitBuilder, FSub: Field>(
    builder: &mut B,
    inputs: &[B::Wire],
) -> Vec<B::Wire>
where B::Field: ExtensionField<FSub>,
Expand description

Transpose the subfield decomposition of extension field elements.

Given d input wires representing extension field elements (where d is the degree of B::Field over FSub), returns d output wires containing the transposed elements.

Each input element decomposes as input[i] = sum_j coeffs[i][j] * basis(j) where coeffs[i][j] are in FSub. The output satisfies output[j] = sum_i coeffs[i][j] * basis(i), i.e., output[j].get_base(i) == input[i].get_base(j).

The gadget:

  1. Hints the d × d matrix of subfield coefficients
  2. Constrains each coefficient to lie in FSub via the Frobenius endomorphism
  3. Constrains that the coefficients reconstruct each input element
  4. Computes the transposed output as basis linear combinations

§Panics

  • If inputs.len() != B::Field::DEGREE

Instantiating this with a B::Field of characteristic other than 2 fails to compile.