binius_ip_prover/sumcheck/prove.rs
1// Copyright 2025 Irreducible Inc.
2// Copyright 2026 The Binius Developers
3//! Prover implementation for the sumcheck protocol.
4//!
5//! This module provides functionality for executing the sumcheck proving protocol,
6//! which allows a prover to convince a verifier that a claimed sum over a multivariate
7//! polynomial is correct through an interactive proof protocol.
8
9use binius_field::Field;
10
11use super::{
12 common::{MleCheckProver, SumcheckProver},
13 drive::{self, MleCheckRounds, SumcheckRounds},
14};
15use crate::channel::IPProverChannel;
16
17/// Executes the sumcheck proving protocol for a single multivariate polynomial.
18///
19/// This function drives the interactive sumcheck protocol, where the prover convinces
20/// a verifier that a claimed sum over a multivariate polynomial is correct. The protocol
21/// proceeds in rounds, with one round per variable in the polynomial.
22///
23/// # Arguments
24///
25/// * `prover` - An implementation of [`SumcheckProver`] that computes the polynomial evaluations
26/// for each round. The prover must evaluate exactly one composition polynomial per round.
27/// * `channel` - The channel for sending prover messages and sampling challenges.
28///
29/// # Returns
30///
31/// Returns [`ProveSingleOutput`] containing:
32/// - `multilinear_evals`: Final evaluations of the multilinear polynomials at the challenge point
33/// - `challenges`: The verifier challenges used in each round
34///
35/// # Panics
36///
37/// Panics if the prover returns more than one composition polynomial from its `execute()` method.
38///
39/// # Protocol Flow
40///
41/// For each of the `n_vars` rounds:
42/// 1. The prover computes univariate polynomial coefficients via `execute()`
43/// 2. These coefficients are written to the channel
44/// 3. A challenge is sampled from the channel
45/// 4. The prover folds the polynomial with this challenge via `fold()`
46///
47/// After all rounds, `finish()` is called to obtain the final multilinear evaluations.
48pub fn prove_single<F: Field>(
49 prover: impl SumcheckProver<F>,
50 channel: &mut impl IPProverChannel<F>,
51) -> ProveSingleOutput<F> {
52 drive::single(SumcheckRounds(prover), channel)
53}
54
55/// Executes the MLE-check proving protocol for a single multivariate polynomial.
56///
57/// Analogous to [`prove_single`] for the MLE-check protocol instead of sumcheck.
58pub fn prove_single_mlecheck<F: Field>(
59 prover: impl MleCheckProver<F>,
60 channel: &mut impl IPProverChannel<F>,
61) -> ProveSingleOutput<F> {
62 drive::single(MleCheckRounds(prover), channel)
63}
64
65/// Output of the sumcheck proving protocol for a single multivariate polynomial.
66///
67/// Contains the final evaluations and challenges generated during the interactive
68/// protocol execution.
69pub struct ProveSingleOutput<F: Field> {
70 /// Evaluations of the multilinear polynomials at the challenge point.
71 ///
72 /// After the sumcheck protocol completes, these are the values of each multilinear
73 /// polynomial evaluated at the point formed by all verifier challenges.
74 pub multilinear_evals: Vec<F>,
75 /// Verifier challenges for each round of the sumcheck protocol.
76 ///
77 /// One challenge is generated per variable in the multivariate polynomial,
78 /// with challenges\[i\] corresponding to the i-th round of the protocol.
79 /// NB: reverse when folding high-to-low to obtain evaluation claim.
80 pub challenges: Vec<F>,
81}