Struct HidingFriPcs

Source
pub struct HidingFriPcs<Val, Dft, InputMmcs, FriMmcs, R> { /* private fields */ }
Expand description

A hiding FRI PCS. Both MMCSs must also be hiding; this is not enforced at compile time so it’s the user’s responsibility to configure.

Implementations§

Source§

impl<Val, Dft, InputMmcs, FriMmcs, R> HidingFriPcs<Val, Dft, InputMmcs, FriMmcs, R>

Source

pub fn new( dft: Dft, mmcs: InputMmcs, params: FriParameters<FriMmcs>, num_random_codewords: usize, rng: R, ) -> Self

Trait Implementations§

Source§

impl<Val: Clone, Dft: Clone, InputMmcs: Clone, FriMmcs: Clone, R: Clone> Clone for HidingFriPcs<Val, Dft, InputMmcs, FriMmcs, R>

Source§

fn clone(&self) -> HidingFriPcs<Val, Dft, InputMmcs, FriMmcs, R>

Returns a duplicate of the value. Read more
1.0.0 · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl<Val: Debug, Dft: Debug, InputMmcs: Debug, FriMmcs: Debug, R: Debug> Debug for HidingFriPcs<Val, Dft, InputMmcs, FriMmcs, R>

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl<Val, Dft, InputMmcs, FriMmcs, Challenge, Challenger, R> Pcs<Challenge, Challenger> for HidingFriPcs<Val, Dft, InputMmcs, FriMmcs, R>
where Val: TwoAdicField, StandardUniform: Distribution<Val>, Dft: TwoAdicSubgroupDft<Val>, InputMmcs: Mmcs<Val>, FriMmcs: Mmcs<Challenge>, Challenge: TwoAdicField + ExtensionField<Val>, Challenger: FieldChallenger<Val> + CanObserve<FriMmcs::Commitment> + GrindingChallenger<Witness = Val>, R: Rng + Send + Sync,

Source§

type Proof = (Vec<Vec<Vec<Vec<Challenge>>>>, FriProof<Challenge, FriMmcs, Val, Vec<BatchOpening<Val, InputMmcs>>>)

The first item contains the openings of the random polynomials added by this wrapper. The second item is the usual FRI proof.

Source§

fn get_quotient_ldes( &self, evaluations: impl IntoIterator<Item = (Self::Domain, RowMajorMatrix<Val>)>, num_chunks: usize, ) -> Vec<RowMajorMatrix<Val>>

Get the quotient polynomial LDEs. We first decompose the quotient polynomial into num_chunks many smaller polynomials each of degree degree / num_chunks. These quotient polynomials are then randomized as explained in Section 4.2 of https://eprint.iacr.org/2024/1037.pdf .

§Arguments
  • quotient_domain the domain of the quotient polynomial.
  • quotient_evaluations the evaluations of the quotient polynomial over the domain. This should be in standard (not bit-reversed) order.
  • num_chunks the number of smaller polynomials to decompose the quotient polynomial into.
§Panics

This function panics if num_chunks is either 0 or 1. The first case makes no logical sense and in the second case, the resulting commitment would not be hiding.

Source§

const ZK: bool = true

Set to true to activate randomization and achieve zero-knowledge.
Source§

type Domain = TwoAdicMultiplicativeCoset<Val>

The class of evaluation domains that this commitment scheme works over.
Source§

type Commitment = <InputMmcs as Mmcs<Val>>::Commitment

The commitment that’s sent to the verifier.
Source§

type ProverData = <InputMmcs as Mmcs<Val>>::ProverData<DenseMatrix<Val>>

Data that the prover stores for committed polynomials, to help the prover with opening.
Source§

type EvaluationsOnDomain<'a> = HorizontallyTruncated<Val, RowIndexMappedView<BitReversalPerm, DenseMatrix<Val, &'a [Val]>>>

Type of the output of get_evaluations_on_domain.
Source§

type Error = FriError<<FriMmcs as Mmcs<Challenge>>::Error, <InputMmcs as Mmcs<Val>>::Error>

The type of a proof verification error.
Source§

fn natural_domain_for_degree(&self, degree: usize) -> Self::Domain

This should return a domain such that Domain::next_point returns Some.
Source§

fn commit( &self, evaluations: impl IntoIterator<Item = (Self::Domain, RowMajorMatrix<Val>)>, ) -> (Self::Commitment, Self::ProverData)

Given a collection of evaluation matrices, produce a binding commitment to the polynomials defined by those evaluations. If zk is enabled, the evaluations are first randomized as explained in Section 3 of https://eprint.iacr.org/2024/1037.pdf . Read more
Source§

fn commit_preprocessing( &self, evaluations: impl IntoIterator<Item = (Self::Domain, RowMajorMatrix<Val>)>, ) -> (Self::Commitment, Self::ProverData)

Same as commit but without randomization. This is used for preprocessed columns which do not have to be randomized even when ZK is enabled. Note that the preprocessed columns still need to be padded to the extended domain height. Read more
Source§

fn commit_ldes( &self, ldes: Vec<RowMajorMatrix<Val>>, ) -> (Self::Commitment, Self::ProverData)

Commits to a collection of LDE evaluation matrices.
Source§

fn get_evaluations_on_domain<'a>( &self, prover_data: &'a Self::ProverData, idx: usize, domain: Self::Domain, ) -> Self::EvaluationsOnDomain<'a>

Given prover data corresponding to a commitment to a collection of evaluation matrices, return the evaluations of those matrices on the given domain. Read more
Source§

fn get_evaluations_on_domain_no_random<'a>( &self, prover_data: &'a Self::ProverData, idx: usize, domain: Self::Domain, ) -> Self::EvaluationsOnDomain<'a>

This is the same as get_evaluations_on_domain but without randomization. This is used for preprocessed columns which do not have to be randomized even when ZK is enabled.
Source§

fn open( &self, rounds: Vec<(&Self::ProverData, Vec<Vec<Challenge>>)>, challenger: &mut Challenger, ) -> (OpenedValues<Challenge>, Self::Proof)

Open a collection of polynomial commitments at a set of points. Produce the values at those points along with a proof of correctness. Read more
Source§

fn open_with_preprocessing( &self, rounds: Vec<(&Self::ProverData, Vec<Vec<Challenge>>)>, challenger: &mut Challenger, is_preprocessing: bool, ) -> (OpenedValues<Challenge>, Self::Proof)

Open a collection of polynomial commitments at a set of points, when there is preprocessing data. It is the same as open when ZK is disabled. Produce the values at those points along with a proof of correctness. Read more
Source§

fn verify( &self, rounds: Vec<(Self::Commitment, Vec<(Self::Domain, Vec<(Challenge, Vec<Challenge>)>)>)>, proof: &Self::Proof, challenger: &mut Challenger, ) -> Result<(), Self::Error>

Verify that a collection of opened values is correct. Read more
Source§

fn get_opt_randomization_poly_commitment( &self, ext_trace_domains: impl IntoIterator<Item = Self::Domain>, ) -> Option<(Self::Commitment, Self::ProverData)>

Source§

const TRACE_IDX: usize = _

Index of the trace commitment in the computed opened values.
Source§

const QUOTIENT_IDX: usize = _

Index of the quotient commitments in the computed opened values.
Source§

const PREPROCESSED_TRACE_IDX: usize = _

Index of the preprocessed trace commitment in the computed opened values.
Source§

fn commit_quotient( &self, quotient_domain: Self::Domain, quotient_evaluations: DenseMatrix<<Self::Domain as PolynomialSpace>::Val>, num_chunks: usize, ) -> (Self::Commitment, Self::ProverData)

Commit to the quotient polynomial. We first decompose the quotient polynomial into num_chunks many smaller polynomials each of degree degree / num_chunks. This can have minor performance benefits, but is not strictly necessary in the non zk case. When zk is enabled, this commitment will additionally include some randomization process to hide the inputs. Read more

Auto Trait Implementations§

§

impl<Val, Dft, InputMmcs, FriMmcs, R> !Freeze for HidingFriPcs<Val, Dft, InputMmcs, FriMmcs, R>

§

impl<Val, Dft, InputMmcs, FriMmcs, R> !RefUnwindSafe for HidingFriPcs<Val, Dft, InputMmcs, FriMmcs, R>

§

impl<Val, Dft, InputMmcs, FriMmcs, R> Send for HidingFriPcs<Val, Dft, InputMmcs, FriMmcs, R>
where Dft: Send, InputMmcs: Send, R: Send, FriMmcs: Send, Val: Send,

§

impl<Val, Dft, InputMmcs, FriMmcs, R> !Sync for HidingFriPcs<Val, Dft, InputMmcs, FriMmcs, R>

§

impl<Val, Dft, InputMmcs, FriMmcs, R> Unpin for HidingFriPcs<Val, Dft, InputMmcs, FriMmcs, R>
where Dft: Unpin, InputMmcs: Unpin, FriMmcs: Unpin, Val: Unpin, R: Unpin,

§

impl<Val, Dft, InputMmcs, FriMmcs, R> UnwindSafe for HidingFriPcs<Val, Dft, InputMmcs, FriMmcs, R>
where Dft: UnwindSafe, InputMmcs: UnwindSafe, FriMmcs: UnwindSafe, Val: UnwindSafe, R: UnwindSafe,

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self>

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

impl<T> Pointable for T

Source§

const ALIGN: usize

The alignment of pointer.
Source§

type Init = T

The type for initializers.
Source§

unsafe fn init(init: <T as Pointable>::Init) -> usize

Initializes a with the given initializer. Read more
Source§

unsafe fn deref<'a>(ptr: usize) -> &'a T

Dereferences the given pointer. Read more
Source§

unsafe fn deref_mut<'a>(ptr: usize) -> &'a mut T

Mutably dereferences the given pointer. Read more
Source§

unsafe fn drop(ptr: usize)

Drops the object pointed to by the given pointer. Read more
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V

Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more