2021-02-12 08:17:18 -08:00
<!DOCTYPE HTML>
< html lang = "en" class = "sidebar-visible no-js light" >
< head >
<!-- Book generated using mdBook -->
< meta charset = "UTF-8" >
< title > Vanishing argument - The halo2 Book< / title >
<!-- Custom HTML head -->
< meta content = "text/html; charset=utf-8" http-equiv = "Content-Type" >
< meta name = "description" content = "" >
< meta name = "viewport" content = "width=device-width, initial-scale=1" >
< meta name = "theme-color" content = "#ffffff" / >
2021-10-14 03:44:50 -07:00
< link rel = "icon" href = "../../favicon.svg" >
< link rel = "shortcut icon" href = "../../favicon.png" >
< link rel = "stylesheet" href = "../../css/variables.css" >
2021-02-12 08:17:18 -08:00
< link rel = "stylesheet" href = "../../css/general.css" >
< link rel = "stylesheet" href = "../../css/chrome.css" >
2021-10-14 03:44:50 -07:00
< link rel = "stylesheet" href = "../../css/print.css" media = "print" >
2021-02-12 08:17:18 -08:00
<!-- Fonts -->
< link rel = "stylesheet" href = "../../FontAwesome/css/font-awesome.css" >
2021-10-14 03:44:50 -07:00
< link rel = "stylesheet" href = "../../fonts/fonts.css" >
2021-02-12 08:17:18 -08:00
<!-- Highlight.js Stylesheets -->
< link rel = "stylesheet" href = "../../highlight.css" >
< link rel = "stylesheet" href = "../../tomorrow-night.css" >
< link rel = "stylesheet" href = "../../ayu-highlight.css" >
<!-- Custom theme stylesheets -->
2021-10-14 03:44:50 -07:00
< / head >
2021-02-12 08:17:18 -08:00
< body >
<!-- Provide site root to javascript -->
< script type = "text/javascript" >
var path_to_root = "../../";
var default_theme = window.matchMedia("(prefers-color-scheme: dark)").matches ? "navy" : "light";
< / script >
<!-- Work around some values being stored in localStorage wrapped in quotes -->
< script type = "text/javascript" >
try {
var theme = localStorage.getItem('mdbook-theme');
var sidebar = localStorage.getItem('mdbook-sidebar');
if (theme.startsWith('"') & & theme.endsWith('"')) {
localStorage.setItem('mdbook-theme', theme.slice(1, theme.length - 1));
}
if (sidebar.startsWith('"') & & sidebar.endsWith('"')) {
localStorage.setItem('mdbook-sidebar', sidebar.slice(1, sidebar.length - 1));
}
} catch (e) { }
< / script >
<!-- Set the theme before any content is loaded, prevents flash -->
< script type = "text/javascript" >
var theme;
try { theme = localStorage.getItem('mdbook-theme'); } catch(e) { }
if (theme === null || theme === undefined) { theme = default_theme; }
var html = document.querySelector('html');
html.classList.remove('no-js')
html.classList.remove('light')
html.classList.add(theme);
html.classList.add('js');
< / script >
<!-- Hide / unhide sidebar before it is displayed -->
< script type = "text/javascript" >
var html = document.querySelector('html');
var sidebar = 'hidden';
if (document.body.clientWidth >= 1080) {
try { sidebar = localStorage.getItem('mdbook-sidebar'); } catch(e) { }
sidebar = sidebar || 'visible';
}
html.classList.remove('sidebar-visible');
html.classList.add("sidebar-" + sidebar);
< / script >
< nav id = "sidebar" class = "sidebar" aria-label = "Table of contents" >
< div class = "sidebar-scrollbox" >
2021-10-14 03:44:50 -07:00
< ol class = "chapter" > < li class = "chapter-item expanded affix " > < a href = "../../index.html" > halo2< / a > < / li > < li class = "chapter-item expanded " > < a href = "../../concepts.html" > < strong aria-hidden = "true" > 1.< / strong > Concepts< / a > < / li > < li > < ol class = "section" > < li class = "chapter-item expanded " > < a href = "../../concepts/proofs.html" > < strong aria-hidden = "true" > 1.1.< / strong > Proof systems< / a > < / li > < li class = "chapter-item expanded " > < a href = "../../concepts/arithmetization.html" > < strong aria-hidden = "true" > 1.2.< / strong > PLONKish Arithmetization< / a > < / li > < li class = "chapter-item expanded " > < a href = "../../concepts/chips.html" > < strong aria-hidden = "true" > 1.3.< / strong > Chips< / a > < / li > < li class = "chapter-item expanded " > < a href = "../../concepts/gadgets.html" > < strong aria-hidden = "true" > 1.4.< / strong > Gadgets< / a > < / li > < / ol > < / li > < li class = "chapter-item expanded " > < a href = "../../user.html" > < strong aria-hidden = "true" > 2.< / strong > User Documentation< / a > < / li > < li > < ol class = "section" > < li class = "chapter-item expanded " > < a href = "../../user/dev-tools.html" > < strong aria-hidden = "true" > 2.1.< / strong > Developer tools< / a > < / li > < li class = "chapter-item expanded " > < a href = "../../user/simple-example.html" > < strong aria-hidden = "true" > 2.2.< / strong > A simple example< / a > < / li > < li class = "chapter-item expanded " > < a href = "../../user/lookup-tables.html" > < strong aria-hidden = "true" > 2.3.< / strong > Lookup tables< / a > < / li > < li class = "chapter-item expanded " > < a href = "../../user/gadgets.html" > < strong aria-hidden = "true" > 2.4.< / strong > Gadgets< / a > < / li > < li class = "chapter-item expanded " > < a href = "../../user/tips-and-tricks.html" > < strong aria-hidden = "true" > 2.5.< / strong > Tips and tricks< / a > < / li > < / ol > < / li > < li class = "chapter-item expanded " > < a href = "../../design.html" > < strong aria-hidden = "true" > 3.< / strong > Design< / a > < / li > < li > < ol class = "section" > < li class = "chapter-item expanded " > < a href = "../../design/proving-system.html" > < strong aria-hidden = "true" > 3.1.< / strong > Proving system< / a > < / li > < li > < ol class = "section" > < li class = "chapter-item expanded " > < a href = "../../design/proving-system/lookup.html" > < strong aria-hidden = "true" > 3.1.1.< / strong > Lookup argument< / a > < / li > < li class = "chapter-item expanded " > < a href = "../../design/proving-system/permutation.html" > < strong aria-hidden = "true" > 3.1.2.< / strong > Permutation argument< / a > < / li > < li class = "chapter-item expanded " > < a href = "../../design/proving-system/circuit-commitments.html" > < strong aria-hidden = "true" > 3.1.3.< / strong > Circuit commitments< / a > < / li > < li class = "chapter-item expanded " > < a href = "../../design/proving-system/vanishing.html" class = "active" > < strong aria-hidden = "true" > 3.1.4.< / strong > Vanishing argument< / a > < / li > < li class = "chapter-item expanded " > < a href = "../../design/proving-system/multipoint-opening.html" > < strong aria-hidden = "true" > 3.1.5.< / strong > Multipoint opening argument< / a > < / li > < li class = "chapter-item expanded " > < a href = "../../design/proving-system/inner-product.html" > < strong aria-hidden = "true" > 3.1.6.< / strong > Inner product argument< / a > < / li > < li class = "chapter-item expanded " > < a href = "../../design/proving-system/comparison.html" > < strong aria-hidden = "true" > 3.1.7.< / strong > Comparison to other work< / a > < / li > < / ol > < / li > < li class = "chapter-item expanded " > < a href = "../../design/protocol.html" > < strong aria-hidden = "true" > 3.2.< / strong > Protocol Description< / a > < / li > < li class = "chapter-item expanded " > < a href = "../../design/implementation.html" > < strong aria-hidden = "true" > 3.3.< / strong > Implementation< / a > < / li > < li > < ol class = "section" > < li class = "chapter-item expanded " > < a href = "../../design/implementation/proofs.html" > < strong aria-hidden = "true" > 3.3.1.< / strong > Proofs< / a > < / li > < li class = "chapter-item expanded " > < a href = "../../design/implementation/fields.html" > < strong aria-hidden = "true" > 3.3.2.< / strong > Fields< / a > < / li > < / ol > < / li > < li class = "chapter-item expanded " > < a href = "../../design/gadgets.html" > < strong aria-hidden = "true" > 3.4.< / strong > Gadgets< / a > < / li > < li > < ol class = "section" > < li class = "chapter-item expanded " > < a href = "../../design/gadgets/sha256.html" > < strong aria-hidden = "true" > 3.4.1.< / strong > SHA-256< / a > < / li > < li > < ol class = "section" > < li class = "chapter-item expanded "
< / div >
2021-02-12 08:17:18 -08:00
< div id = "sidebar-resize-handle" class = "sidebar-resize-handle" > < / div >
< / nav >
< div id = "page-wrapper" class = "page-wrapper" >
< div class = "page" >
< div id = "menu-bar-hover-placeholder" > < / div >
< div id = "menu-bar" class = "menu-bar sticky bordered" >
< div class = "left-buttons" >
< button id = "sidebar-toggle" class = "icon-button" type = "button" title = "Toggle Table of Contents" aria-label = "Toggle Table of Contents" aria-controls = "sidebar" >
< i class = "fa fa-bars" > < / i >
< / button >
< button id = "theme-toggle" class = "icon-button" type = "button" title = "Change theme" aria-label = "Change theme" aria-haspopup = "true" aria-expanded = "false" aria-controls = "theme-list" >
< i class = "fa fa-paint-brush" > < / i >
< / button >
< ul id = "theme-list" class = "theme-popup" aria-label = "Themes" role = "menu" >
< li role = "none" > < button role = "menuitem" class = "theme" id = "light" > Light (default)< / button > < / li >
< li role = "none" > < button role = "menuitem" class = "theme" id = "rust" > Rust< / button > < / li >
< li role = "none" > < button role = "menuitem" class = "theme" id = "coal" > Coal< / button > < / li >
< li role = "none" > < button role = "menuitem" class = "theme" id = "navy" > Navy< / button > < / li >
< li role = "none" > < button role = "menuitem" class = "theme" id = "ayu" > Ayu< / button > < / li >
< / ul >
2021-10-14 03:44:50 -07:00
< button id = "search-toggle" class = "icon-button" type = "button" title = "Search. (Shortkey: s)" aria-label = "Toggle Searchbar" aria-expanded = "false" aria-keyshortcuts = "S" aria-controls = "searchbar" >
2021-02-12 08:17:18 -08:00
< i class = "fa fa-search" > < / i >
< / button >
2021-10-14 03:44:50 -07:00
< / div >
2021-02-12 08:17:18 -08:00
< h1 class = "menu-title" > The halo2 Book< / h1 >
< div class = "right-buttons" >
2021-10-14 03:44:50 -07:00
< a href = "../../print.html" title = "Print this book" aria-label = "Print this book" >
2021-02-12 08:17:18 -08:00
< i id = "print-button" class = "fa fa-print" > < / i >
< / a >
< / div >
< / div >
2021-10-14 03:44:50 -07:00
< div id = "search-wrapper" class = "hidden" >
2021-02-12 08:17:18 -08:00
< form id = "searchbar-outer" class = "searchbar-outer" >
2021-06-05 03:42:23 -07:00
< input type = "search" id = "searchbar" name = "searchbar" placeholder = "Search this book ..." aria-controls = "searchresults-outer" aria-describedby = "searchresults-header" >
2021-02-12 08:17:18 -08:00
< / form >
< div id = "searchresults-outer" class = "searchresults-outer hidden" >
< div id = "searchresults-header" class = "searchresults-header" > < / div >
< ul id = "searchresults" >
< / ul >
< / div >
< / div >
<!-- Apply ARIA attributes after the sidebar and the sidebar toggle button are added to the DOM -->
< script type = "text/javascript" >
document.getElementById('sidebar-toggle').setAttribute('aria-expanded', sidebar === 'visible');
document.getElementById('sidebar').setAttribute('aria-hidden', sidebar !== 'visible');
Array.from(document.querySelectorAll('#sidebar a')).forEach(function(link) {
link.setAttribute('tabIndex', sidebar === 'visible' ? 0 : -1);
});
< / script >
< div id = "content" class = "content" >
< main >
< link rel = "stylesheet" href = "https://cdn.jsdelivr.net/npm/katex@0.12.0/dist/katex.min.css" integrity = "sha384-AfEj0r4/OFrOo5t7NnNe46zW/tFgW6x/bCJG8FqQCEo3+Aro6EYUG4+cU+KJWu/X" crossorigin = "anonymous" >
2021-06-05 03:42:23 -07:00
< h1 id = "vanishing-argument" > < a class = "header" href = "#vanishing-argument" > Vanishing argument< / a > < / h1 >
2021-02-12 08:17:18 -08:00
< p > Having committed to the circuit assignments, the prover now needs to demonstrate that the
various circuit relations are satisfied:< / p >
< ul >
< li > The custom gates, represented by polynomials < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord" > < span class = "mord text" > < span class = "mord" > gate< / span > < / span > < span class = "msupsub" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.21752399999999997em;" > < span style = "top:-2.4558600000000004em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mathnormal mtight" > i< / span > < / span > < / span > < / span > < span class = "vlist-s" > < / span > < / span > < span class = "vlist-r" > < span class = "vlist" style = "height:0.24414em;" > < span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "mclose" > )< / span > < / span > < / span > < / span > .< / li >
< li > The rules of the lookup arguments.< / li >
< li > The rules of the equality constraint permutations.< / li >
< / ul >
< p > Each of these relations is represented as a polynomial of degree < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:0.69444em;vertical-align:0em;" > < / span > < span class = "mord mathnormal" > d< / span > < / span > < / span > < / span > (the maximum degree
of any of the relations) with respect to the circuit columns. Given that the degree of the
assignment polynomials for each column is < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:0.66666em;vertical-align:-0.08333em;" > < / span > < span class = "mord mathnormal" > n< / span > < span class = "mspace" style = "margin-right:0.2222222222222222em;" > < / span > < span class = "mbin" > − < / span > < span class = "mspace" style = "margin-right:0.2222222222222222em;" > < / span > < / span > < span class = "base" > < span class = "strut" style = "height:0.64444em;vertical-align:0em;" > < / span > < span class = "mord" > 1< / span > < / span > < / span > < / span > , the relation polynomials have degree
< span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord mathnormal" > d< / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" > n< / span > < span class = "mspace" style = "margin-right:0.2222222222222222em;" > < / span > < span class = "mbin" > − < / span > < span class = "mspace" style = "margin-right:0.2222222222222222em;" > < / span > < / span > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord" > 1< / span > < span class = "mclose" > )< / span > < / span > < / span > < / span > with respect to < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:0.68333em;vertical-align:0em;" > < / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < / span > < / span > < / span > .< / p >
< blockquote >
< p > In our < a href = "../proving-system.html#example" > example< / a > , these would be the gate polynomials, of
degree < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:0.72777em;vertical-align:-0.08333em;" > < / span > < span class = "mord" > 3< / span > < span class = "mord mathnormal" > n< / span > < span class = "mspace" style = "margin-right:0.2222222222222222em;" > < / span > < span class = "mbin" > − < / span > < span class = "mspace" style = "margin-right:0.2222222222222222em;" > < / span > < / span > < span class = "base" > < span class = "strut" style = "height:0.64444em;vertical-align:0em;" > < / span > < span class = "mord" > 3< / span > < / span > < / span > < / span > :< / p >
< ul >
< li > < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord" > < span class = "mord text" > < span class = "mord" > gate< / span > < / span > < span class = "msupsub" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.20696799999999996em;" > < span style = "top:-2.4558600000000004em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > 0< / span > < / span > < / span > < / span > < span class = "vlist-s" > < / span > < / span > < span class = "vlist-r" > < span class = "vlist" style = "height:0.24414em;" > < span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "mclose" > )< / span > < span class = "mspace" style = "margin-right:0.2777777777777778em;" > < / span > < span class = "mrel" > =< / span > < span class = "mspace" style = "margin-right:0.2777777777777778em;" > < / span > < / span > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord" > < span class = "mord mathnormal" > a< / span > < span class = "msupsub" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.30110799999999993em;" > < span style = "top:-2.5500000000000003em;margin-left:0em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > 0< / span > < / span > < / span > < / span > < span class = "vlist-s" > < / span > < / span > < span class = "vlist-r" > < span class = "vlist" style = "height:0.15em;" > < span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "mclose" > )< / span > < span class = "mspace" style = "margin-right:0.2222222222222222em;" > < / span > < span class = "mbin" > ⋅< / span > < span class = "mspace" style = "margin-right:0.2222222222222222em;" > < / span > < / span > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord" > < span class = "mord mathnormal" > a< / span > < span class = "msupsub" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.30110799999999993em;" > < span style = "top:-2.5500000000000003em;margin-left:0em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > 1< / span > < / span > < / span > < / span > < span class = "vlist-s" > < / span > < / span > < span class = "vlist-r" > < span class = "vlist" style = "height:0.15em;" > < span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "mclose" > )< / span > < span class = "mspace" style = "margin-right:0.2222222222222222em;" > < / span > < span class = "mbin" > ⋅< / span > < span class = "mspace" style = "margin-right:0.2222222222222222em;" > < / span > < / span > < span class = "base" > < span class = "strut" style = "height:1.064108em;vertical-align:-0.25em;" > < / span > < span class = "mord" > < span class = "mord mathnormal" > a< / span > < span class = "msupsub" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.30110799999999993em;" > < span style = "top:-2.5500000000000003em;margin-left:0em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > 2< / span > < / span > < / span > < / span > < span class = "vlist-s" > < / span > < / span > < span class = "vlist-r" > < span class = "vlist" style = "height:0.15em;" > < span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "mord" > < span class = "mord mathnormal" style = "margin-right:0.03588em;" > ω< / span > < span class = "msupsub" > < span class = "vlist-t" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.8141079999999999em;" > < span style = "top:-3.063em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span
< li > < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord" > < span class = "mord text" > < span class = "mord" > gate< / span > < / span > < span class = "msupsub" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.20696799999999996em;" > < span style = "top:-2.4558600000000004em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > 1< / span > < / span > < / span > < / span > < span class = "vlist-s" > < / span > < / span > < span class = "vlist-r" > < span class = "vlist" style = "height:0.24414em;" > < span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "mclose" > )< / span > < span class = "mspace" style = "margin-right:0.2777777777777778em;" > < / span > < span class = "mrel" > =< / span > < span class = "mspace" style = "margin-right:0.2777777777777778em;" > < / span > < / span > < span class = "base" > < span class = "strut" style = "height:1.064108em;vertical-align:-0.25em;" > < / span > < span class = "mord" > < span class = "mord mathnormal" style = "margin-right:0.10764em;" > f< / span > < span class = "msupsub" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.30110799999999993em;" > < span style = "top:-2.5500000000000003em;margin-left:-0.10764em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > 0< / span > < / span > < / span > < / span > < span class = "vlist-s" > < / span > < / span > < span class = "vlist-r" > < span class = "vlist" style = "height:0.15em;" > < span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "mord" > < span class = "mord mathnormal" style = "margin-right:0.03588em;" > ω< / span > < span class = "msupsub" > < span class = "vlist-t" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.8141079999999999em;" > < span style = "top:-3.063em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > < span class = "mord mtight" > − < / span > < span class = "mord mtight" > 1< / span > < / span > < / span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mclose" > )< / span > < span class = "mspace" style = "margin-right:0.2222222222222222em;" > < / span > < span class = "mbin" > ⋅< / span > < span class = "mspace" style = "margin-right:0.2222222222222222em;" > < / span > < / span > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord" > < span class = "mord mathnormal" > a< / span > < span class = "msupsub" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.30110799999999993em;" > < span style = "top:-2.5500000000000003em;margin-left:0em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > 2< / span > < / span > < / span > < / span > < span class = "vlist-s" > < / span > < / span > < span class = "vlist-r" > < span class = "vlist" style = "height:0.15em;" > < span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "mclose" > )< / span > < / span > < / span > < / span > < / li >
< li > < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord" > < span class = "mord text" > < span class = "mord" > gate< / span > < / span > < span class = "msupsub" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.20696799999999996em;" > < span style = "top:-2.4558600000000004em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > 2< / span > < / span > < / span > < / span > < span class = "vlist-s" > < / span > < / span > < span class = "vlist-r" > < span class = "vlist" style = "height:0.24414em;" > < span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "mclose" > )< / span > < span class = "mspace" style = "margin-right:0.2777777777777778em;" > < / span > < span class = "mrel" > =< / span > < span class = "mspace" style = "margin-right:0.2777777777777778em;" > < / span > < / span > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord" > < span class = "mord mathnormal" style = "margin-right:0.10764em;" > f< / span > < span class = "msupsub" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.30110799999999993em;" > < span style = "top:-2.5500000000000003em;margin-left:-0.10764em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > 0< / span > < / span > < / span > < / span > < span class = "vlist-s" > < / span > < / span > < span class = "vlist-r" > < span class = "vlist" style = "height:0.15em;" > < span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "mclose" > )< / span > < span class = "mspace" style = "margin-right:0.2222222222222222em;" > < / span > < span class = "mbin" > ⋅< / span > < span class = "mspace" style = "margin-right:0.2222222222222222em;" > < / span > < / span > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord" > < span class = "mord mathnormal" > a< / span > < span class = "msupsub" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.30110799999999993em;" > < span style = "top:-2.5500000000000003em;margin-left:0em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > 3< / span > < / span > < / span > < / span > < span class = "vlist-s" > < / span > < / span > < span class = "vlist-r" > < span class = "vlist" style = "height:0.15em;" > < span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "mclose" > )< / span > < span class = "mspace" style = "margin-right:0.2222222222222222em;" > < / span > < span class = "mbin" > ⋅< / span > < span class = "mspace" style = "margin-right:0.2222222222222222em;" > < / span > < / span > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord" > < span class = "mord mathnormal" > a< / span > < span class = "msupsub" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.30110799999999993em;" > < span style = "top:-2.5500000000000003em;margin-left:0em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > 0< / span > < / span > < / span > < / span > < span class = "vlist-s" > < / span > < / span > < span class = "vlist-r" > < span class = "vlist" style = "height:0.15em;" > < span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "mclose" > )< / span > < / span > < / span > < / span > < / li >
< / ul >
< / blockquote >
< p > A relation is satisfied if its polynomial is equal to zero. One way to demonstrate this is
to divide each polynomial relation by the vanishing polynomial < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord mathnormal" > t< / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "mclose" > )< / span > < span class = "mspace" style = "margin-right:0.2777777777777778em;" > < / span > < span class = "mrel" > =< / span > < span class = "mspace" style = "margin-right:0.2777777777777778em;" > < / span > < / span > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mopen" > (< / span > < span class = "mord" > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "msupsub" > < span class = "vlist-t" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.664392em;" > < span style = "top:-3.063em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mathnormal mtight" > n< / span > < / span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mspace" style = "margin-right:0.2222222222222222em;" > < / span > < span class = "mbin" > − < / span > < span class = "mspace" style = "margin-right:0.2222222222222222em;" > < / span > < / span > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord" > 1< / span > < span class = "mclose" > )< / span > < / span > < / span > < / span > , which
is the lowest-degree monomial that has roots at every < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:0.824664em;vertical-align:0em;" > < / span > < span class = "mord" > < span class = "mord mathnormal" style = "margin-right:0.03588em;" > ω< / span > < span class = "msupsub" > < span class = "vlist-t" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.824664em;" > < span style = "top:-3.063em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mathnormal mtight" > i< / span > < / span > < / span > < / span > < / span > < / span > < / span > < / span > < / span > < / span > < / span > . If relation's polynomial
is perfectly divisible by < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord mathnormal" > t< / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "mclose" > )< / span > < / span > < / span > < / span > , it is equal to zero over the domain (as desired).< / p >
< p > This simple construction would require a polynomial commitment per relation. Instead, we
commit to all of the circuit relations simultaneously: the verifier samples < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:0.625em;vertical-align:-0.19444em;" > < / span > < span class = "mord mathnormal" style = "margin-right:0.03588em;" > y< / span > < / span > < / span > < / span > , and then
the prover constructs the quotient polynomial< / p >
< p > < span class = "katex-display" > < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord mathnormal" > h< / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "mclose" > )< / span > < span class = "mspace" style = "margin-right:0.2777777777777778em;" > < / span > < span class = "mrel" > =< / span > < span class = "mspace" style = "margin-right:0.2777777777777778em;" > < / span > < / span > < span class = "base" > < span class = "strut" style = "height:2.437664em;vertical-align:-0.936em;" > < / span > < span class = "mord" > < span class = "mopen nulldelimiter" > < / span > < span class = "mfrac" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:1.5016639999999999em;" > < span style = "top:-2.314em;" > < span class = "pstrut" style = "height:3em;" > < / span > < span class = "mord" > < span class = "mord mathnormal" > t< / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "mclose" > )< / span > < / span > < / span > < span style = "top:-3.23em;" > < span class = "pstrut" style = "height:3em;" > < / span > < span class = "frac-line" style = "border-bottom-width:0.04em;" > < / span > < / span > < span style = "top:-3.677em;" > < span class = "pstrut" style = "height:3em;" > < / span > < span class = "mord" > < span class = "mord" > < span class = "mord text" > < span class = "mord" > gate< / span > < / span > < span class = "msupsub" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.20696799999999996em;" > < span style = "top:-2.4558600000000004em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > 0< / span > < / span > < / span > < / span > < span class = "vlist-s" > < / span > < / span > < span class = "vlist-r" > < span class = "vlist" style = "height:0.24414em;" > < span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "mclose" > )< / span > < span class = "mspace" style = "margin-right:0.2222222222222222em;" > < / span > < span class = "mbin" > +< / span > < span class = "mspace" style = "margin-right:0.2222222222222222em;" > < / span > < span class = "mord mathnormal" style = "margin-right:0.03588em;" > y< / span > < span class = "mspace" style = "margin-right:0.2222222222222222em;" > < / span > < span class = "mbin" > ⋅< / span > < span class = "mspace" style = "margin-right:0.2222222222222222em;" > < / span > < span class = "mord" > < span class = "mord text" > < span class = "mord" > gate< / span > < / span > < span class = "msupsub" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.20696799999999996em;" > < span style = "top:-2.4558600000000004em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > 1< / span > < / span > < / span > < / span > < span class = "vlist-s" > < / span > < / span > < span class = "vlist-r" > < span class = "vlist" style = "height:0.24414em;" > < span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "mclose" > )< / span > < span class = "mspace" style = "margin-right:0.2222222222222222em;" > < / span > < span class = "mbin" > +< / span > < span class = "mspace" style = "margin-right:0.2222222222222222em;" > < / span > < span class = "minner" > ⋯< / span > < span class = "mspace" style = "margin-right:0.2222222222222222em;" > < / span > < span class = "mbin" > +< / span > < span class = "mspace" style = "margin-right:0.2222222222222222em;" > < / span > < span class = "mord" > < span class = "mord mathnormal" style = "margin-right:0.03588em;" > y< / span > < span class = "msupsub" > < span class = "vlist-t" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.824664em;" > < span style = "top:-3.063em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mathnormal mtight" > i< / span > < / span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mspace" style = "margin-right:0.2222222222222222em;" > < / span > < span class = "mbin" > ⋅< / span > < span class = "mspace" style = "marg
< p > where the numerator is a random (the prover commits to the cell assignments before the
verifier samples < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:0.625em;vertical-align:-0.19444em;" > < / span > < span class = "mord mathnormal" style = "margin-right:0.03588em;" > y< / span > < / span > < / span > < / span > ) linear combination of the circuit relations.< / p >
< ul >
< li > If the numerator polynomial (in formal indeterminate < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:0.68333em;vertical-align:0em;" > < / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < / span > < / span > < / span > ) is perfectly divisible by
< span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord mathnormal" > t< / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "mclose" > )< / span > < / span > < / span > < / span > , then with high probability all relations are satisfied.< / li >
< li > Conversely, if at least one relation is not satisfied, then with high probability
< span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord mathnormal" > h< / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" > x< / span > < span class = "mclose" > )< / span > < span class = "mspace" style = "margin-right:0.2222222222222222em;" > < / span > < span class = "mbin" > ⋅< / span > < span class = "mspace" style = "margin-right:0.2222222222222222em;" > < / span > < / span > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord mathnormal" > t< / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" > x< / span > < span class = "mclose" > )< / span > < / span > < / span > < / span > will not equal the evaluation of the numerator at < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:0.43056em;vertical-align:0em;" > < / span > < span class = "mord mathnormal" > x< / span > < / span > < / span > < / span > . In this case,
the numerator polynomial would not be perfectly divisible by < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord mathnormal" > t< / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "mclose" > )< / span > < / span > < / span > < / span > .< / li >
< / ul >
2021-11-29 21:05:15 -08:00
< h2 id = "committing-to-hx" > < a class = "header" href = "#committing-to-hx" > Committing to < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord mathnormal" > h< / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "mclose" > )< / span > < / span > < / span > < / span > < / a > < / h2 >
2021-02-12 08:17:18 -08:00
< p > < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord mathnormal" > h< / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "mclose" > )< / span > < / span > < / span > < / span > has degree < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" > d< / span > < span class = "mspace" style = "margin-right:0.2222222222222222em;" > < / span > < span class = "mbin" > − < / span > < span class = "mspace" style = "margin-right:0.2222222222222222em;" > < / span > < / span > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord" > 1< / span > < span class = "mclose" > )< / span > < span class = "mord mathnormal" > n< / span > < span class = "mspace" style = "margin-right:0.2222222222222222em;" > < / span > < span class = "mbin" > − < / span > < span class = "mspace" style = "margin-right:0.2222222222222222em;" > < / span > < / span > < span class = "base" > < span class = "strut" style = "height:0.69444em;vertical-align:0em;" > < / span > < span class = "mord mathnormal" > d< / span > < / span > < / span > < / span > (because the divisor < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord mathnormal" > t< / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "mclose" > )< / span > < / span > < / span > < / span > has degree < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:0.43056em;vertical-align:0em;" > < / span > < span class = "mord mathnormal" > n< / span > < / span > < / span > < / span > ). However, the
polynomial commitment scheme we use for Halo 2 only supports committing to polynomials of
degree < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:0.66666em;vertical-align:-0.08333em;" > < / span > < span class = "mord mathnormal" > n< / span > < span class = "mspace" style = "margin-right:0.2222222222222222em;" > < / span > < span class = "mbin" > − < / span > < span class = "mspace" style = "margin-right:0.2222222222222222em;" > < / span > < / span > < span class = "base" > < span class = "strut" style = "height:0.64444em;vertical-align:0em;" > < / span > < span class = "mord" > 1< / span > < / span > < / span > < / span > (which is the maximum degree that the rest of the protocol needs to commit
to). Instead of increasing the cost of the polynomial commitment scheme, the prover split
< span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord mathnormal" > h< / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "mclose" > )< / span > < / span > < / span > < / span > into pieces of degree < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:0.66666em;vertical-align:-0.08333em;" > < / span > < span class = "mord mathnormal" > n< / span > < span class = "mspace" style = "margin-right:0.2222222222222222em;" > < / span > < span class = "mbin" > − < / span > < span class = "mspace" style = "margin-right:0.2222222222222222em;" > < / span > < / span > < span class = "base" > < span class = "strut" style = "height:0.64444em;vertical-align:0em;" > < / span > < span class = "mord" > 1< / span > < / span > < / span > < / span > < / p >
< p > < span class = "katex-display" > < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord" > < span class = "mord mathnormal" > h< / span > < span class = "msupsub" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.30110799999999993em;" > < span style = "top:-2.5500000000000003em;margin-left:0em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > 0< / span > < / span > < / span > < / span > < span class = "vlist-s" > < / span > < / span > < span class = "vlist-r" > < span class = "vlist" style = "height:0.15em;" > < span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "mclose" > )< / span > < span class = "mspace" style = "margin-right:0.2222222222222222em;" > < / span > < span class = "mbin" > +< / span > < span class = "mspace" style = "margin-right:0.2222222222222222em;" > < / span > < / span > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord" > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "msupsub" > < span class = "vlist-t" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.7143919999999999em;" > < span style = "top:-3.113em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mathnormal mtight" > n< / span > < / span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mord" > < span class = "mord mathnormal" > h< / span > < span class = "msupsub" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.30110799999999993em;" > < span style = "top:-2.5500000000000003em;margin-left:0em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > 1< / span > < / span > < / span > < / span > < span class = "vlist-s" > < / span > < / span > < span class = "vlist-r" > < span class = "vlist" style = "height:0.15em;" > < span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "mclose" > )< / span > < span class = "mspace" style = "margin-right:0.2222222222222222em;" > < / span > < span class = "mbin" > +< / span > < span class = "mspace" style = "margin-right:0.2222222222222222em;" > < / span > < / span > < span class = "base" > < span class = "strut" style = "height:0.66666em;vertical-align:-0.08333em;" > < / span > < span class = "minner" > ⋯< / span > < span class = "mspace" style = "margin-right:0.2222222222222222em;" > < / span > < span class = "mbin" > +< / span > < span class = "mspace" style = "margin-right:0.2222222222222222em;" > < / span > < / span > < span class = "base" > < span class = "strut" style = "height:1.188em;vertical-align:-0.25em;" > < / span > < span class = "mord" > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "msupsub" > < span class = "vlist-t" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.938em;" > < span style = "top:-3.113em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > < span class = "mord mathnormal mtight" > n< / span > < span class = "mopen mtight" > (< / span > < span class = "mord mathnormal mtight" > d< / span > < span class = "mbin mtight" > − < / span > < span class = "mord mtight" > 1< / span > < span class = "mclose mtight" > )< / span > < / span > < / span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mord" > < span class = "mord mathnormal" > h< / span > < span class = "msupsub" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.3361079999999999em;" > < span style = "top:-2.5500000000000003em;margin-left:0em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > < span class = "mord mathnormal mtight" > d< / span > < span class = "mbin mtight" > − < / span > < span class = "mord mtight" > 1< / span > < / span > < / span > < / span > < / span > < span class = "vlist-s" > < / span > < / span > < s
< p > and produces blinding commitments to each piece< / p >
2021-05-03 15:55:00 -07:00
< p > < span class = "katex-display" > < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:0.68611em;vertical-align:0em;" > < / span > < span class = "mord mathbf" > H< / span > < span class = "mspace" style = "margin-right:0.2777777777777778em;" > < / span > < span class = "mrel" > =< / span > < span class = "mspace" style = "margin-right:0.2777777777777778em;" > < / span > < / span > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mopen" > [< / span > < span class = "mord text" > < span class = "mord" > Commit< / span > < / span > < span class = "mopen" > (< / span > < span class = "mord" > < span class = "mord mathnormal" > h< / span > < span class = "msupsub" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.30110799999999993em;" > < span style = "top:-2.5500000000000003em;margin-left:0em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > 0< / span > < / span > < / span > < / span > < span class = "vlist-s" > < / span > < / span > < span class = "vlist-r" > < span class = "vlist" style = "height:0.15em;" > < span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "mclose" > ))< / span > < span class = "mpunct" > ,< / span > < span class = "mspace" style = "margin-right:0.16666666666666666em;" > < / span > < span class = "mord text" > < span class = "mord" > Commit< / span > < / span > < span class = "mopen" > (< / span > < span class = "mord" > < span class = "mord mathnormal" > h< / span > < span class = "msupsub" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.30110799999999993em;" > < span style = "top:-2.5500000000000003em;margin-left:0em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > 1< / span > < / span > < / span > < / span > < span class = "vlist-s" > < / span > < / span > < span class = "vlist-r" > < span class = "vlist" style = "height:0.15em;" > < span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "mclose" > ))< / span > < span class = "mpunct" > ,< / span > < span class = "mspace" style = "margin-right:0.16666666666666666em;" > < / span > < span class = "minner" > …< / span > < span class = "mspace" style = "margin-right:0.16666666666666666em;" > < / span > < span class = "mpunct" > ,< / span > < span class = "mspace" style = "margin-right:0.16666666666666666em;" > < / span > < span class = "mord text" > < span class = "mord" > Commit< / span > < / span > < span class = "mopen" > (< / span > < span class = "mord" > < span class = "mord mathnormal" > h< / span > < span class = "msupsub" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.3361079999999999em;" > < span style = "top:-2.5500000000000003em;margin-left:0em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > < span class = "mord mathnormal mtight" > d< / span > < span class = "mbin mtight" > − < / span > < span class = "mord mtight" > 1< / span > < / span > < / span > < / span > < / span > < span class = "vlist-s" > < / span > < / span > < span class = "vlist-r" > < span class = "vlist" style = "height:0.208331em;" > < span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "mclose" > ))]< / span > < span class = "mord" > .< / span > < / span > < / span > < / span > < / span > < / p >
2021-06-05 03:42:23 -07:00
< h2 id = "evaluating-the-polynomials" > < a class = "header" href = "#evaluating-the-polynomials" > Evaluating the polynomials< / a > < / h2 >
2021-02-12 08:17:18 -08:00
< p > At this point, all properties of the circuit have been committed to. The verifier now
wants to see if the prover committed to the correct < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord mathnormal" > h< / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "mclose" > )< / span > < / span > < / span > < / span > polynomial. The verifier
samples < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:0.43056em;vertical-align:0em;" > < / span > < span class = "mord mathnormal" > x< / span > < / span > < / span > < / span > , and the prover produces the purported evaluations of the various polynomials
at < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:0.43056em;vertical-align:0em;" > < / span > < span class = "mord mathnormal" > x< / span > < / span > < / span > < / span > , for all the relative offsets used in the circuit, as well as < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord mathnormal" > h< / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "mclose" > )< / span > < / span > < / span > < / span > .< / p >
< blockquote >
< p > In our < a href = "../proving-system.html#example" > example< / a > , this would be:< / p >
< ul >
< li > < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord" > < span class = "mord mathnormal" > a< / span > < span class = "msupsub" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.30110799999999993em;" > < span style = "top:-2.5500000000000003em;margin-left:0em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > 0< / span > < / span > < / span > < / span > < span class = "vlist-s" > < / span > < / span > < span class = "vlist-r" > < span class = "vlist" style = "height:0.15em;" > < span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" > x< / span > < span class = "mclose" > )< / span > < / span > < / span > < / span > < / li >
< li > < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord" > < span class = "mord mathnormal" > a< / span > < span class = "msupsub" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.30110799999999993em;" > < span style = "top:-2.5500000000000003em;margin-left:0em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > 1< / span > < / span > < / span > < / span > < span class = "vlist-s" > < / span > < / span > < span class = "vlist-r" > < span class = "vlist" style = "height:0.15em;" > < span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" > x< / span > < span class = "mclose" > )< / span > < / span > < / span > < / span > < / li >
< li > < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord" > < span class = "mord mathnormal" > a< / span > < span class = "msupsub" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.30110799999999993em;" > < span style = "top:-2.5500000000000003em;margin-left:0em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > 2< / span > < / span > < / span > < / span > < span class = "vlist-s" > < / span > < / span > < span class = "vlist-r" > < span class = "vlist" style = "height:0.15em;" > < span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" > x< / span > < span class = "mclose" > )< / span > < / span > < / span > < / span > , < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:1.064108em;vertical-align:-0.25em;" > < / span > < span class = "mord" > < span class = "mord mathnormal" > a< / span > < span class = "msupsub" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.30110799999999993em;" > < span style = "top:-2.5500000000000003em;margin-left:0em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > 2< / span > < / span > < / span > < / span > < span class = "vlist-s" > < / span > < / span > < span class = "vlist-r" > < span class = "vlist" style = "height:0.15em;" > < span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" > x< / span > < span class = "mord" > < span class = "mord mathnormal" style = "margin-right:0.03588em;" > ω< / span > < span class = "msupsub" > < span class = "vlist-t" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.8141079999999999em;" > < span style = "top:-3.063em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > < span class = "mord mtight" > − < / span > < span class = "mord mtight" > 1< / span > < / span > < / span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mclose" > )< / span > < / span > < / span > < / span > < / li >
< li > < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord" > < span class = "mord mathnormal" > a< / span > < span class = "msupsub" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.30110799999999993em;" > < span style = "top:-2.5500000000000003em;margin-left:0em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > 3< / span > < / span > < / span > < / span > < span class = "vlist-s" > < / span > < / span > < span class = "vlist-r" > < span class = "vlist" style = "height:0.15em;" > < span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" > x< / span > < span class = "mclose" > )< / span > < / span > < / span > < / span > < / li >
< li > < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord" > < span class = "mord mathnormal" style = "margin-right:0.10764em;" > f< / span > < span class = "msupsub" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.30110799999999993em;" > < span style = "top:-2.5500000000000003em;margin-left:-0.10764em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > 0< / span > < / span > < / span > < / span > < span class = "vlist-s" > < / span > < / span > < span class = "vlist-r" > < span class = "vlist" style = "height:0.15em;" > < span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" > x< / span > < span class = "mclose" > )< / span > < / span > < / span > < / span > , < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:1.064108em;vertical-align:-0.25em;" > < / span > < span class = "mord" > < span class = "mord mathnormal" style = "margin-right:0.10764em;" > f< / span > < span class = "msupsub" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.30110799999999993em;" > < span style = "top:-2.5500000000000003em;margin-left:-0.10764em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > 0< / span > < / span > < / span > < / span > < span class = "vlist-s" > < / span > < / span > < span class = "vlist-r" > < span class = "vlist" style = "height:0.15em;" > < span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" > x< / span > < span class = "mord" > < span class = "mord mathnormal" style = "margin-right:0.03588em;" > ω< / span > < span class = "msupsub" > < span class = "vlist-t" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.8141079999999999em;" > < span style = "top:-3.063em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > < span class = "mord mtight" > − < / span > < span class = "mord mtight" > 1< / span > < / span > < / span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mclose" > )< / span > < / span > < / span > < / span > < / li >
< li > < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord" > < span class = "mord mathnormal" > h< / span > < span class = "msupsub" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.30110799999999993em;" > < span style = "top:-2.5500000000000003em;margin-left:0em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > 0< / span > < / span > < / span > < / span > < span class = "vlist-s" > < / span > < / span > < span class = "vlist-r" > < span class = "vlist" style = "height:0.15em;" > < span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" > x< / span > < span class = "mclose" > )< / span > < / span > < / span > < / span > , ..., < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord" > < span class = "mord mathnormal" > h< / span > < span class = "msupsub" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.3361079999999999em;" > < span style = "top:-2.5500000000000003em;margin-left:0em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > < span class = "mord mathnormal mtight" > d< / span > < span class = "mbin mtight" > − < / span > < span class = "mord mtight" > 1< / span > < / span > < / span > < / span > < / span > < span class = "vlist-s" > < / span > < / span > < span class = "vlist-r" > < span class = "vlist" style = "height:0.208331em;" > < span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" > x< / span > < span class = "mclose" > )< / span > < / span > < / span > < / span > < / li >
< / ul >
< / blockquote >
< p > The verifier checks that these evaluations satisfy the form of < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord mathnormal" > h< / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "mclose" > )< / span > < / span > < / span > < / span > :< / p >
< p > < span class = "katex-display" > < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:2.437664em;vertical-align:-0.936em;" > < / span > < span class = "mord" > < span class = "mopen nulldelimiter" > < / span > < span class = "mfrac" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:1.5016639999999999em;" > < span style = "top:-2.314em;" > < span class = "pstrut" style = "height:3em;" > < / span > < span class = "mord" > < span class = "mord mathnormal" > t< / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" > x< / span > < span class = "mclose" > )< / span > < / span > < / span > < span style = "top:-3.23em;" > < span class = "pstrut" style = "height:3em;" > < / span > < span class = "frac-line" style = "border-bottom-width:0.04em;" > < / span > < / span > < span style = "top:-3.677em;" > < span class = "pstrut" style = "height:3em;" > < / span > < span class = "mord" > < span class = "mord" > < span class = "mord text" > < span class = "mord" > gate< / span > < / span > < span class = "msupsub" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.20696799999999996em;" > < span style = "top:-2.4558600000000004em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > 0< / span > < / span > < / span > < / span > < span class = "vlist-s" > < / span > < / span > < span class = "vlist-r" > < span class = "vlist" style = "height:0.24414em;" > < span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" > x< / span > < span class = "mclose" > )< / span > < span class = "mspace" style = "margin-right:0.2222222222222222em;" > < / span > < span class = "mbin" > +< / span > < span class = "mspace" style = "margin-right:0.2222222222222222em;" > < / span > < span class = "minner" > ⋯< / span > < span class = "mspace" style = "margin-right:0.2222222222222222em;" > < / span > < span class = "mbin" > +< / span > < span class = "mspace" style = "margin-right:0.2222222222222222em;" > < / span > < span class = "mord" > < span class = "mord mathnormal" style = "margin-right:0.03588em;" > y< / span > < span class = "msupsub" > < span class = "vlist-t" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.824664em;" > < span style = "top:-3.063em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mathnormal mtight" > i< / span > < / span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mspace" style = "margin-right:0.2222222222222222em;" > < / span > < span class = "mbin" > ⋅< / span > < span class = "mspace" style = "margin-right:0.2222222222222222em;" > < / span > < span class = "mord" > < span class = "mord text" > < span class = "mord" > gate< / span > < / span > < span class = "msupsub" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.21752399999999997em;" > < span style = "top:-2.4558600000000004em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mathnormal mtight" > i< / span > < / span > < / span > < / span > < span class = "vlist-s" > < / span > < / span > < span class = "vlist-r" > < span class = "vlist" style = "height:0.24414em;" > < span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" > x< / span > < span class = "mclose" > )< / span > < span class = "mspace" style = "margin-right:0.2222222222222222em;" > < / span > < span class = "mbin" > +< / span > < span class = "mspace" style = "margin-right:0.2222222222222222em;" > < / span > < span class = "minner" > …< / span > < / span > < / span > < / span > < span class = "vlist-s" > < / span > < / span > < span class = "vlist-r" > < span class = "vlist" style = "height:0.936em;" > < span > < / span > < / span > < / span > < / span > < / span > < span class = "mclose nulldelimiter" > < / span > < / span > < span class = "mspace" style = "margin-right:0.2777777777777778em;" > < / span > < span class = "mrel" > =< / span > < span class = "mspace" style = "margin-right:0.2777777777777778em;" > < / span > < / span > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord" > < span class = "mord mathnormal" > h< / span > < span class = "msupsub" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.30110799999999993em;" > < span style = "to
< p > Now content that the evaluations collectively satisfy the gate constraints, the verifier
needs to check that the evaluations themselves are consistent with the original
2021-05-03 15:55:00 -07:00
< a href = "circuit-commitments.html" > circuit commitments< / a > , as well as < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:0.68611em;vertical-align:0em;" > < / span > < span class = "mord mathbf" > H< / span > < / span > < / span > < / span > . To implement this
2021-02-12 08:17:18 -08:00
efficiently, we use a < a href = "multipoint-opening.html" > multipoint opening argument< / a > .< / p >
< / main >
< nav class = "nav-wrapper" aria-label = "Page navigation" >
<!-- Mobile navigation buttons -->
2021-10-14 03:44:50 -07:00
< a rel = "prev" href = "../../design/proving-system/circuit-commitments.html" class = "mobile-nav-chapters previous" title = "Previous chapter" aria-label = "Previous chapter" aria-keyshortcuts = "Left" >
2021-02-12 08:17:18 -08:00
< i class = "fa fa-angle-left" > < / i >
< / a >
2021-10-14 03:44:50 -07:00
< a rel = "next" href = "../../design/proving-system/multipoint-opening.html" class = "mobile-nav-chapters next" title = "Next chapter" aria-label = "Next chapter" aria-keyshortcuts = "Right" >
2021-02-12 08:17:18 -08:00
< i class = "fa fa-angle-right" > < / i >
< / a >
< div style = "clear: both" > < / div >
< / nav >
< / div >
< / div >
< nav class = "nav-wide-wrapper" aria-label = "Page navigation" >
2021-10-14 03:44:50 -07:00
< a rel = "prev" href = "../../design/proving-system/circuit-commitments.html" class = "nav-chapters previous" title = "Previous chapter" aria-label = "Previous chapter" aria-keyshortcuts = "Left" >
2021-02-12 08:17:18 -08:00
< i class = "fa fa-angle-left" > < / i >
< / a >
2021-10-14 03:44:50 -07:00
< a rel = "next" href = "../../design/proving-system/multipoint-opening.html" class = "nav-chapters next" title = "Next chapter" aria-label = "Next chapter" aria-keyshortcuts = "Right" >
2021-02-12 08:17:18 -08:00
< i class = "fa fa-angle-right" > < / i >
< / a >
2021-10-14 03:44:50 -07:00
< / nav >
2021-02-12 08:17:18 -08:00
< / div >
2021-10-14 03:44:50 -07:00
< script type = "text/javascript" >
2021-02-12 08:17:18 -08:00
window.playground_copyable = true;
< / script >
2021-10-14 03:44:50 -07:00
< script src = "../../elasticlunr.min.js" type = "text/javascript" charset = "utf-8" > < / script >
2021-02-12 08:17:18 -08:00
< script src = "../../mark.min.js" type = "text/javascript" charset = "utf-8" > < / script >
< script src = "../../searcher.js" type = "text/javascript" charset = "utf-8" > < / script >
< script src = "../../clipboard.min.js" type = "text/javascript" charset = "utf-8" > < / script >
< script src = "../../highlight.js" type = "text/javascript" charset = "utf-8" > < / script >
< script src = "../../book.js" type = "text/javascript" charset = "utf-8" > < / script >
<!-- Custom JS scripts -->
< / body >
< / html >