pub fn square_transpose<B: CircuitBuilder, FSub: Field>(
builder: &mut B,
inputs: &[B::Wire],
) -> Vec<B::Wire>where
B::Field: ExtensionField<FSub>,Expand description
Transpose the subfield decomposition of extension field elements.
Given d input wires representing extension field elements (where d is the degree of
B::Field over FSub), returns d output wires containing the transposed elements.
Each input element decomposes as input[i] = sum_j coeffs[i][j] * basis(j) where
coeffs[i][j] are in FSub. The output satisfies output[j] = sum_i coeffs[i][j] * basis(i),
i.e., output[j].get_base(i) == input[i].get_base(j).
The gadget:
- Hints the
d × dmatrix of subfield coefficients - Constrains each coefficient to lie in
FSubvia the Frobenius endomorphism - Constrains that the coefficients reconstruct each input element
- Computes the transposed output as basis linear combinations
§Panics
- If
inputs.len() != B::Field::DEGREE
Instantiating this with a B::Field of characteristic other than 2 fails to compile.