2021-02-12 08:17:18 -08:00
<!DOCTYPE HTML>
2024-02-26 15:57:00 -08:00
< html lang = "en" class = "light" dir = "ltr" >
2021-02-12 08:17:18 -08:00
< head >
<!-- Book generated using mdBook -->
< meta charset = "UTF-8" >
< title > Vanishing argument - The halo2 Book< / title >
2023-01-20 13:40:27 -08:00
2021-02-12 08:17:18 -08:00
<!-- Custom HTML head -->
2023-01-20 13:40:27 -08:00
2021-02-12 08:17:18 -08:00
< meta name = "description" content = "" >
< meta name = "viewport" content = "width=device-width, initial-scale=1" >
2024-02-26 15:57:00 -08:00
< meta name = "theme-color" content = "#ffffff" >
2021-02-12 08:17:18 -08:00
2021-10-14 03:44:50 -07:00
< link rel = "icon" href = "../../favicon.svg" >
< link rel = "shortcut icon" href = "../../favicon.png" >
< link rel = "stylesheet" href = "../../css/variables.css" >
2021-02-12 08:17:18 -08:00
< link rel = "stylesheet" href = "../../css/general.css" >
< link rel = "stylesheet" href = "../../css/chrome.css" >
2021-10-14 03:44:50 -07:00
< link rel = "stylesheet" href = "../../css/print.css" media = "print" >
2023-01-20 13:40:27 -08:00
2021-02-12 08:17:18 -08:00
<!-- Fonts -->
< link rel = "stylesheet" href = "../../FontAwesome/css/font-awesome.css" >
2021-10-14 03:44:50 -07:00
< link rel = "stylesheet" href = "../../fonts/fonts.css" >
2023-01-20 13:40:27 -08:00
2021-02-12 08:17:18 -08:00
<!-- Highlight.js Stylesheets -->
< link rel = "stylesheet" href = "../../highlight.css" >
< link rel = "stylesheet" href = "../../tomorrow-night.css" >
< link rel = "stylesheet" href = "../../ayu-highlight.css" >
<!-- Custom theme stylesheets -->
2023-01-20 13:40:27 -08:00
2021-10-14 03:44:50 -07:00
< / head >
2024-02-26 15:57:00 -08:00
< body class = "sidebar-visible no-js" >
< div id = "body-container" >
2021-02-12 08:17:18 -08:00
<!-- Provide site root to javascript -->
2023-01-20 13:40:27 -08:00
< script >
2021-02-12 08:17:18 -08:00
var path_to_root = "../../";
var default_theme = window.matchMedia("(prefers-color-scheme: dark)").matches ? "navy" : "light";
< / script >
<!-- Work around some values being stored in localStorage wrapped in quotes -->
2023-01-20 13:40:27 -08:00
< script >
2021-02-12 08:17:18 -08:00
try {
var theme = localStorage.getItem('mdbook-theme');
var sidebar = localStorage.getItem('mdbook-sidebar');
if (theme.startsWith('"') & & theme.endsWith('"')) {
localStorage.setItem('mdbook-theme', theme.slice(1, theme.length - 1));
}
if (sidebar.startsWith('"') & & sidebar.endsWith('"')) {
localStorage.setItem('mdbook-sidebar', sidebar.slice(1, sidebar.length - 1));
}
} catch (e) { }
< / script >
<!-- Set the theme before any content is loaded, prevents flash -->
2023-01-20 13:40:27 -08:00
< script >
2021-02-12 08:17:18 -08:00
var theme;
try { theme = localStorage.getItem('mdbook-theme'); } catch(e) { }
if (theme === null || theme === undefined) { theme = default_theme; }
var html = document.querySelector('html');
html.classList.remove('light')
html.classList.add(theme);
2024-02-26 15:57:00 -08:00
var body = document.querySelector('body');
body.classList.remove('no-js')
body.classList.add('js');
2021-02-12 08:17:18 -08:00
< / script >
2024-02-26 15:57:00 -08:00
< input type = "checkbox" id = "sidebar-toggle-anchor" class = "hidden" >
2021-02-12 08:17:18 -08:00
<!-- Hide / unhide sidebar before it is displayed -->
2023-01-20 13:40:27 -08:00
< script >
2024-02-26 15:57:00 -08:00
var body = document.querySelector('body');
var sidebar = null;
var sidebar_toggle = document.getElementById("sidebar-toggle-anchor");
2021-02-12 08:17:18 -08:00
if (document.body.clientWidth >= 1080) {
try { sidebar = localStorage.getItem('mdbook-sidebar'); } catch(e) { }
sidebar = sidebar || 'visible';
2024-02-26 15:57:00 -08:00
} else {
sidebar = 'hidden';
2021-02-12 08:17:18 -08:00
}
2024-02-26 15:57:00 -08:00
sidebar_toggle.checked = sidebar === 'visible';
body.classList.remove('sidebar-visible');
body.classList.add("sidebar-" + sidebar);
2021-02-12 08:17:18 -08:00
< / script >
< nav id = "sidebar" class = "sidebar" aria-label = "Table of contents" >
< div class = "sidebar-scrollbox" >
2023-01-20 13:40:27 -08:00
< ol class = "chapter" > < li class = "chapter-item expanded affix " > < a href = "../../index.html" > halo2< / a > < / li > < li class = "chapter-item expanded " > < a href = "../../concepts.html" > < strong aria-hidden = "true" > 1.< / strong > Concepts< / a > < / li > < li > < ol class = "section" > < li class = "chapter-item expanded " > < a href = "../../concepts/proofs.html" > < strong aria-hidden = "true" > 1.1.< / strong > Proof systems< / a > < / li > < li class = "chapter-item expanded " > < a href = "../../concepts/arithmetization.html" > < strong aria-hidden = "true" > 1.2.< / strong > PLONKish Arithmetization< / a > < / li > < li class = "chapter-item expanded " > < a href = "../../concepts/chips.html" > < strong aria-hidden = "true" > 1.3.< / strong > Chips< / a > < / li > < li class = "chapter-item expanded " > < a href = "../../concepts/gadgets.html" > < strong aria-hidden = "true" > 1.4.< / strong > Gadgets< / a > < / li > < / ol > < / li > < li class = "chapter-item expanded " > < a href = "../../user.html" > < strong aria-hidden = "true" > 2.< / strong > User Documentation< / a > < / li > < li > < ol class = "section" > < li class = "chapter-item expanded " > < a href = "../../user/dev-tools.html" > < strong aria-hidden = "true" > 2.1.< / strong > Developer tools< / a > < / li > < li class = "chapter-item expanded " > < a href = "../../user/simple-example.html" > < strong aria-hidden = "true" > 2.2.< / strong > A simple example< / a > < / li > < li class = "chapter-item expanded " > < a href = "../../user/lookup-tables.html" > < strong aria-hidden = "true" > 2.3.< / strong > Lookup tables< / a > < / li > < li class = "chapter-item expanded " > < a href = "../../user/gadgets.html" > < strong aria-hidden = "true" > 2.4.< / strong > Gadgets< / a > < / li > < li class = "chapter-item expanded " > < a href = "../../user/tips-and-tricks.html" > < strong aria-hidden = "true" > 2.5.< / strong > Tips and tricks< / a > < / li > < li class = "chapter-item expanded " > < a href = "../../user/wasm-port.html" > < strong aria-hidden = "true" > 2.6.< / strong > WASM Guide< / a > < / li > < / ol > < / li > < li class = "chapter-item expanded " > < a href = "../../dev.html" > < strong aria-hidden = "true" > 3.< / strong > Developer Documentation< / a > < / li > < li > < ol class = "section" > < li class = "chapter-item expanded " > < a href = "../../dev/features.html" > < strong aria-hidden = "true" > 3.1.< / strong > Feature development< / a > < / li > < / ol > < / li > < li class = "chapter-item expanded " > < a href = "../../design.html" > < strong aria-hidden = "true" > 4.< / strong > Design< / a > < / li > < li > < ol class = "section" > < li class = "chapter-item expanded " > < a href = "../../design/proving-system.html" > < strong aria-hidden = "true" > 4.1.< / strong > Proving system< / a > < / li > < li > < ol class = "section" > < li class = "chapter-item expanded " > < a href = "../../design/proving-system/lookup.html" > < strong aria-hidden = "true" > 4.1.1.< / strong > Lookup argument< / a > < / li > < li class = "chapter-item expanded " > < a href = "../../design/proving-system/permutation.html" > < strong aria-hidden = "true" > 4.1.2.< / strong > Permutation argument< / a > < / li > < li class = "chapter-item expanded " > < a href = "../../design/proving-system/circuit-commitments.html" > < strong aria-hidden = "true" > 4.1.3.< / strong > Circuit commitments< / a > < / li > < li class = "chapter-item expanded " > < a href = "../../design/proving-system/vanishing.html" class = "active" > < strong aria-hidden = "true" > 4.1.4.< / strong > Vanishing argument< / a > < / li > < li class = "chapter-item expanded " > < a href = "../../design/proving-system/multipoint-opening.html" > < strong aria-hidden = "true" > 4.1.5.< / strong > Multipoint opening argument< / a > < / li > < li class = "chapter-item expanded " > < a href = "../../design/proving-system/inner-product.html" > < strong aria-hidden = "true" > 4.1.6.< / strong > Inner product argument< / a > < / li > < li class = "chapter-item expanded " > < a href = "../../design/proving-system/comparison.html" > < strong aria-hidden = "true" > 4.1.7.< / strong > Comparison to other work< / a > < / li > < / ol > < / li > < li class = "chapter-item expanded " > < a href = "../../design/protocol.html" > < strong aria-hidden = "true" > 4.2.< / strong > Protocol Description< / a > < / li > < li class = "chapter-item expanded " > < a href = "../../design/implementation.html" > < strong aria-hidden = "true" > 4.3.< / strong > Implementation< / a > < / li > < li > < ol class = "section" > < li class = "chapter-item expanded " > < a href = "../../design/implementation/proofs.html" > < strong aria-hidden = "true" > 4.3.1.< / strong > Proofs< / a > < / li > < li class = "chapter-item expanded " > < a href = "../../design/implement
2021-10-14 03:44:50 -07:00
< / div >
2024-02-26 15:57:00 -08:00
< div id = "sidebar-resize-handle" class = "sidebar-resize-handle" >
< div class = "sidebar-resize-indicator" > < / div >
< / div >
2021-02-12 08:17:18 -08:00
< / nav >
2024-02-26 15:57:00 -08:00
<!-- Track and set sidebar scroll position -->
< script >
var sidebarScrollbox = document.querySelector('#sidebar .sidebar-scrollbox');
sidebarScrollbox.addEventListener('click', function(e) {
if (e.target.tagName === 'A') {
sessionStorage.setItem('sidebar-scroll', sidebarScrollbox.scrollTop);
}
}, { passive: true });
var sidebarScrollTop = sessionStorage.getItem('sidebar-scroll');
sessionStorage.removeItem('sidebar-scroll');
if (sidebarScrollTop) {
// preserve sidebar scroll position when navigating via links within sidebar
sidebarScrollbox.scrollTop = sidebarScrollTop;
} else {
// scroll sidebar to current active section when navigating via "next/previous chapter" buttons
var activeSection = document.querySelector('#sidebar .active');
if (activeSection) {
activeSection.scrollIntoView({ block: 'center' });
}
}
< / script >
2021-02-12 08:17:18 -08:00
< div id = "page-wrapper" class = "page-wrapper" >
< div class = "page" >
2023-01-20 13:40:27 -08:00
< div id = "menu-bar-hover-placeholder" > < / div >
2024-02-26 15:57:00 -08:00
< div id = "menu-bar" class = "menu-bar sticky" >
2021-02-12 08:17:18 -08:00
< div class = "left-buttons" >
2024-02-26 15:57:00 -08:00
< label id = "sidebar-toggle" class = "icon-button" for = "sidebar-toggle-anchor" title = "Toggle Table of Contents" aria-label = "Toggle Table of Contents" aria-controls = "sidebar" >
2021-02-12 08:17:18 -08:00
< i class = "fa fa-bars" > < / i >
2024-02-26 15:57:00 -08:00
< / label >
2021-02-12 08:17:18 -08:00
< button id = "theme-toggle" class = "icon-button" type = "button" title = "Change theme" aria-label = "Change theme" aria-haspopup = "true" aria-expanded = "false" aria-controls = "theme-list" >
< i class = "fa fa-paint-brush" > < / i >
< / button >
< ul id = "theme-list" class = "theme-popup" aria-label = "Themes" role = "menu" >
2023-01-20 13:40:27 -08:00
< li role = "none" > < button role = "menuitem" class = "theme" id = "light" > Light< / button > < / li >
2021-02-12 08:17:18 -08:00
< li role = "none" > < button role = "menuitem" class = "theme" id = "rust" > Rust< / button > < / li >
< li role = "none" > < button role = "menuitem" class = "theme" id = "coal" > Coal< / button > < / li >
< li role = "none" > < button role = "menuitem" class = "theme" id = "navy" > Navy< / button > < / li >
< li role = "none" > < button role = "menuitem" class = "theme" id = "ayu" > Ayu< / button > < / li >
< / ul >
2021-10-14 03:44:50 -07:00
< button id = "search-toggle" class = "icon-button" type = "button" title = "Search. (Shortkey: s)" aria-label = "Toggle Searchbar" aria-expanded = "false" aria-keyshortcuts = "S" aria-controls = "searchbar" >
2021-02-12 08:17:18 -08:00
< i class = "fa fa-search" > < / i >
< / button >
2021-10-14 03:44:50 -07:00
< / div >
2021-02-12 08:17:18 -08:00
< h1 class = "menu-title" > The halo2 Book< / h1 >
< div class = "right-buttons" >
2021-10-14 03:44:50 -07:00
< a href = "../../print.html" title = "Print this book" aria-label = "Print this book" >
2021-02-12 08:17:18 -08:00
< i id = "print-button" class = "fa fa-print" > < / i >
< / a >
2023-01-20 13:40:27 -08:00
2021-02-12 08:17:18 -08:00
< / div >
< / div >
2021-10-14 03:44:50 -07:00
< div id = "search-wrapper" class = "hidden" >
2021-02-12 08:17:18 -08:00
< form id = "searchbar-outer" class = "searchbar-outer" >
2021-06-05 03:42:23 -07:00
< input type = "search" id = "searchbar" name = "searchbar" placeholder = "Search this book ..." aria-controls = "searchresults-outer" aria-describedby = "searchresults-header" >
2021-02-12 08:17:18 -08:00
< / form >
< div id = "searchresults-outer" class = "searchresults-outer hidden" >
< div id = "searchresults-header" class = "searchresults-header" > < / div >
< ul id = "searchresults" >
< / ul >
< / div >
< / div >
2023-01-20 13:40:27 -08:00
2021-02-12 08:17:18 -08:00
<!-- Apply ARIA attributes after the sidebar and the sidebar toggle button are added to the DOM -->
2023-01-20 13:40:27 -08:00
< script >
2021-02-12 08:17:18 -08:00
document.getElementById('sidebar-toggle').setAttribute('aria-expanded', sidebar === 'visible');
document.getElementById('sidebar').setAttribute('aria-hidden', sidebar !== 'visible');
Array.from(document.querySelectorAll('#sidebar a')).forEach(function(link) {
link.setAttribute('tabIndex', sidebar === 'visible' ? 0 : -1);
});
< / script >
< div id = "content" class = "content" >
< main >
< link rel = "stylesheet" href = "https://cdn.jsdelivr.net/npm/katex@0.12.0/dist/katex.min.css" integrity = "sha384-AfEj0r4/OFrOo5t7NnNe46zW/tFgW6x/bCJG8FqQCEo3+Aro6EYUG4+cU+KJWu/X" crossorigin = "anonymous" >
2021-06-05 03:42:23 -07:00
< h1 id = "vanishing-argument" > < a class = "header" href = "#vanishing-argument" > Vanishing argument< / a > < / h1 >
2021-02-12 08:17:18 -08:00
< p > Having committed to the circuit assignments, the prover now needs to demonstrate that the
various circuit relations are satisfied:< / p >
< ul >
2023-01-20 13:40:27 -08:00
< li > The custom gates, represented by polynomials < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord" > < span class = "mord text" > < span class = "mord" > gate< / span > < / span > < span class = "msupsub" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.2175em;" > < span style = "top:-2.4559em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mathnormal mtight" > i< / span > < / span > < / span > < / span > < span class = "vlist-s" > < / span > < / span > < span class = "vlist-r" > < span class = "vlist" style = "height:0.2441em;" > < span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "mclose" > )< / span > < / span > < / span > < / span > .< / li >
2021-02-12 08:17:18 -08:00
< li > The rules of the lookup arguments.< / li >
< li > The rules of the equality constraint permutations.< / li >
< / ul >
2023-01-20 13:40:27 -08:00
< p > Each of these relations is represented as a polynomial of degree < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:0.6944em;" > < / span > < span class = "mord mathnormal" > d< / span > < / span > < / span > < / span > (the maximum degree
2021-02-12 08:17:18 -08:00
of any of the relations) with respect to the circuit columns. Given that the degree of the
2023-01-20 13:40:27 -08:00
assignment polynomials for each column is < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:0.6667em;vertical-align:-0.0833em;" > < / span > < span class = "mord mathnormal" > n< / span > < span class = "mspace" style = "margin-right:0.2222em;" > < / span > < span class = "mbin" > − < / span > < span class = "mspace" style = "margin-right:0.2222em;" > < / span > < / span > < span class = "base" > < span class = "strut" style = "height:0.6444em;" > < / span > < span class = "mord" > 1< / span > < / span > < / span > < / span > , the relation polynomials have degree
< span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord mathnormal" > d< / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" > n< / span > < span class = "mspace" style = "margin-right:0.2222em;" > < / span > < span class = "mbin" > − < / span > < span class = "mspace" style = "margin-right:0.2222em;" > < / span > < / span > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord" > 1< / span > < span class = "mclose" > )< / span > < / span > < / span > < / span > with respect to < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:0.6833em;" > < / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < / span > < / span > < / span > .< / p >
2021-02-12 08:17:18 -08:00
< blockquote >
< p > In our < a href = "../proving-system.html#example" > example< / a > , these would be the gate polynomials, of
2023-01-20 13:40:27 -08:00
degree < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:0.7278em;vertical-align:-0.0833em;" > < / span > < span class = "mord" > 3< / span > < span class = "mord mathnormal" > n< / span > < span class = "mspace" style = "margin-right:0.2222em;" > < / span > < span class = "mbin" > − < / span > < span class = "mspace" style = "margin-right:0.2222em;" > < / span > < / span > < span class = "base" > < span class = "strut" style = "height:0.6444em;" > < / span > < span class = "mord" > 3< / span > < / span > < / span > < / span > :< / p >
2021-02-12 08:17:18 -08:00
< ul >
2023-01-20 13:40:27 -08:00
< li > < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord" > < span class = "mord text" > < span class = "mord" > gate< / span > < / span > < span class = "msupsub" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.207em;" > < span style = "top:-2.4559em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > 0< / span > < / span > < / span > < / span > < span class = "vlist-s" > < / span > < / span > < span class = "vlist-r" > < span class = "vlist" style = "height:0.2441em;" > < span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "mclose" > )< / span > < span class = "mspace" style = "margin-right:0.2778em;" > < / span > < span class = "mrel" > =< / span > < span class = "mspace" style = "margin-right:0.2778em;" > < / span > < / span > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord" > < span class = "mord mathnormal" > a< / span > < span class = "msupsub" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.3011em;" > < span style = "top:-2.55em;margin-left:0em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > 0< / span > < / span > < / span > < / span > < span class = "vlist-s" > < / span > < / span > < span class = "vlist-r" > < span class = "vlist" style = "height:0.15em;" > < span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "mclose" > )< / span > < span class = "mspace" style = "margin-right:0.2222em;" > < / span > < span class = "mbin" > ⋅< / span > < span class = "mspace" style = "margin-right:0.2222em;" > < / span > < / span > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord" > < span class = "mord mathnormal" > a< / span > < span class = "msupsub" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.3011em;" > < span style = "top:-2.55em;margin-left:0em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > 1< / span > < / span > < / span > < / span > < span class = "vlist-s" > < / span > < / span > < span class = "vlist-r" > < span class = "vlist" style = "height:0.15em;" > < span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "mclose" > )< / span > < span class = "mspace" style = "margin-right:0.2222em;" > < / span > < span class = "mbin" > ⋅< / span > < span class = "mspace" style = "margin-right:0.2222em;" > < / span > < / span > < span class = "base" > < span class = "strut" style = "height:1.0641em;vertical-align:-0.25em;" > < / span > < span class = "mord" > < span class = "mord mathnormal" > a< / span > < span class = "msupsub" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.3011em;" > < span style = "top:-2.55em;margin-left:0em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > 2< / span > < / span > < / span > < / span > < span class = "vlist-s" > < / span > < / span > < span class = "vlist-r" > < span class = "vlist" style = "height:0.15em;" > < span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "mord" > < span class = "mord mathnormal" style = "margin-right:0.03588em;" > ω< / span > < span class = "msupsub" > < span class = "vlist-t" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.8141em;" > < span style = "top:-3.063em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > < span class = "mord mtight" > − < / span > < span class = "mord mtight" > 1< / span > < / span > < / span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mclose" > )< / span > < span class = "mspace
< li > < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord" > < span class = "mord text" > < span class = "mord" > gate< / span > < / span > < span class = "msupsub" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.207em;" > < span style = "top:-2.4559em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > 1< / span > < / span > < / span > < / span > < span class = "vlist-s" > < / span > < / span > < span class = "vlist-r" > < span class = "vlist" style = "height:0.2441em;" > < span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "mclose" > )< / span > < span class = "mspace" style = "margin-right:0.2778em;" > < / span > < span class = "mrel" > =< / span > < span class = "mspace" style = "margin-right:0.2778em;" > < / span > < / span > < span class = "base" > < span class = "strut" style = "height:1.0641em;vertical-align:-0.25em;" > < / span > < span class = "mord" > < span class = "mord mathnormal" style = "margin-right:0.10764em;" > f< / span > < span class = "msupsub" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.3011em;" > < span style = "top:-2.55em;margin-left:-0.1076em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > 0< / span > < / span > < / span > < / span > < span class = "vlist-s" > < / span > < / span > < span class = "vlist-r" > < span class = "vlist" style = "height:0.15em;" > < span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "mord" > < span class = "mord mathnormal" style = "margin-right:0.03588em;" > ω< / span > < span class = "msupsub" > < span class = "vlist-t" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.8141em;" > < span style = "top:-3.063em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > < span class = "mord mtight" > − < / span > < span class = "mord mtight" > 1< / span > < / span > < / span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mclose" > )< / span > < span class = "mspace" style = "margin-right:0.2222em;" > < / span > < span class = "mbin" > ⋅< / span > < span class = "mspace" style = "margin-right:0.2222em;" > < / span > < / span > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord" > < span class = "mord mathnormal" > a< / span > < span class = "msupsub" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.3011em;" > < span style = "top:-2.55em;margin-left:0em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > 2< / span > < / span > < / span > < / span > < span class = "vlist-s" > < / span > < / span > < span class = "vlist-r" > < span class = "vlist" style = "height:0.15em;" > < span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "mclose" > )< / span > < / span > < / span > < / span > < / li >
< li > < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord" > < span class = "mord text" > < span class = "mord" > gate< / span > < / span > < span class = "msupsub" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.207em;" > < span style = "top:-2.4559em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > 2< / span > < / span > < / span > < / span > < span class = "vlist-s" > < / span > < / span > < span class = "vlist-r" > < span class = "vlist" style = "height:0.2441em;" > < span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "mclose" > )< / span > < span class = "mspace" style = "margin-right:0.2778em;" > < / span > < span class = "mrel" > =< / span > < span class = "mspace" style = "margin-right:0.2778em;" > < / span > < / span > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord" > < span class = "mord mathnormal" style = "margin-right:0.10764em;" > f< / span > < span class = "msupsub" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.3011em;" > < span style = "top:-2.55em;margin-left:-0.1076em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > 0< / span > < / span > < / span > < / span > < span class = "vlist-s" > < / span > < / span > < span class = "vlist-r" > < span class = "vlist" style = "height:0.15em;" > < span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "mclose" > )< / span > < span class = "mspace" style = "margin-right:0.2222em;" > < / span > < span class = "mbin" > ⋅< / span > < span class = "mspace" style = "margin-right:0.2222em;" > < / span > < / span > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord" > < span class = "mord mathnormal" > a< / span > < span class = "msupsub" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.3011em;" > < span style = "top:-2.55em;margin-left:0em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > 3< / span > < / span > < / span > < / span > < span class = "vlist-s" > < / span > < / span > < span class = "vlist-r" > < span class = "vlist" style = "height:0.15em;" > < span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "mclose" > )< / span > < span class = "mspace" style = "margin-right:0.2222em;" > < / span > < span class = "mbin" > ⋅< / span > < span class = "mspace" style = "margin-right:0.2222em;" > < / span > < / span > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord" > < span class = "mord mathnormal" > a< / span > < span class = "msupsub" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.3011em;" > < span style = "top:-2.55em;margin-left:0em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > 0< / span > < / span > < / span > < / span > < span class = "vlist-s" > < / span > < / span > < span class = "vlist-r" > < span class = "vlist" style = "height:0.15em;" > < span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "mclose" > )< / span > < / span > < / span > < / span > < / li >
2021-02-12 08:17:18 -08:00
< / ul >
< / blockquote >
< p > A relation is satisfied if its polynomial is equal to zero. One way to demonstrate this is
2023-01-20 13:40:27 -08:00
to divide each polynomial relation by the vanishing polynomial < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord mathnormal" > t< / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "mclose" > )< / span > < span class = "mspace" style = "margin-right:0.2778em;" > < / span > < span class = "mrel" > =< / span > < span class = "mspace" style = "margin-right:0.2778em;" > < / span > < / span > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mopen" > (< / span > < span class = "mord" > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "msupsub" > < span class = "vlist-t" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.6644em;" > < span style = "top:-3.063em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mathnormal mtight" > n< / span > < / span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mspace" style = "margin-right:0.2222em;" > < / span > < span class = "mbin" > − < / span > < span class = "mspace" style = "margin-right:0.2222em;" > < / span > < / span > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord" > 1< / span > < span class = "mclose" > )< / span > < / span > < / span > < / span > , which
is the lowest-degree polynomial that has roots at every < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:0.8247em;" > < / span > < span class = "mord" > < span class = "mord mathnormal" style = "margin-right:0.03588em;" > ω< / span > < span class = "msupsub" > < span class = "vlist-t" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.8247em;" > < span style = "top:-3.063em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mathnormal mtight" > i< / span > < / span > < / span > < / span > < / span > < / span > < / span > < / span > < / span > < / span > < / span > . If relation's polynomial
2021-02-12 08:17:18 -08:00
is perfectly divisible by < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord mathnormal" > t< / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "mclose" > )< / span > < / span > < / span > < / span > , it is equal to zero over the domain (as desired).< / p >
< p > This simple construction would require a polynomial commitment per relation. Instead, we
2023-01-20 13:40:27 -08:00
commit to all of the circuit relations simultaneously: the verifier samples < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:0.625em;vertical-align:-0.1944em;" > < / span > < span class = "mord mathnormal" style = "margin-right:0.03588em;" > y< / span > < / span > < / span > < / span > , and then
2021-02-12 08:17:18 -08:00
the prover constructs the quotient polynomial< / p >
2023-01-20 13:40:27 -08:00
< p > < span class = "katex-display" > < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord mathnormal" > h< / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "mclose" > )< / span > < span class = "mspace" style = "margin-right:0.2778em;" > < / span > < span class = "mrel" > =< / span > < span class = "mspace" style = "margin-right:0.2778em;" > < / span > < / span > < span class = "base" > < span class = "strut" style = "height:2.4377em;vertical-align:-0.936em;" > < / span > < span class = "mord" > < span class = "mopen nulldelimiter" > < / span > < span class = "mfrac" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:1.5017em;" > < span style = "top:-2.314em;" > < span class = "pstrut" style = "height:3em;" > < / span > < span class = "mord" > < span class = "mord mathnormal" > t< / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "mclose" > )< / span > < / span > < / span > < span style = "top:-3.23em;" > < span class = "pstrut" style = "height:3em;" > < / span > < span class = "frac-line" style = "border-bottom-width:0.04em;" > < / span > < / span > < span style = "top:-3.677em;" > < span class = "pstrut" style = "height:3em;" > < / span > < span class = "mord" > < span class = "mord" > < span class = "mord text" > < span class = "mord" > gate< / span > < / span > < span class = "msupsub" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.207em;" > < span style = "top:-2.4559em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > 0< / span > < / span > < / span > < / span > < span class = "vlist-s" > < / span > < / span > < span class = "vlist-r" > < span class = "vlist" style = "height:0.2441em;" > < span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "mclose" > )< / span > < span class = "mspace" style = "margin-right:0.2222em;" > < / span > < span class = "mbin" > +< / span > < span class = "mspace" style = "margin-right:0.2222em;" > < / span > < span class = "mord mathnormal" style = "margin-right:0.03588em;" > y< / span > < span class = "mspace" style = "margin-right:0.2222em;" > < / span > < span class = "mbin" > ⋅< / span > < span class = "mspace" style = "margin-right:0.2222em;" > < / span > < span class = "mord" > < span class = "mord text" > < span class = "mord" > gate< / span > < / span > < span class = "msupsub" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.207em;" > < span style = "top:-2.4559em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > 1< / span > < / span > < / span > < / span > < span class = "vlist-s" > < / span > < / span > < span class = "vlist-r" > < span class = "vlist" style = "height:0.2441em;" > < span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "mclose" > )< / span > < span class = "mspace" style = "margin-right:0.2222em;" > < / span > < span class = "mbin" > +< / span > < span class = "mspace" style = "margin-right:0.2222em;" > < / span > < span class = "minner" > ⋯< / span > < span class = "mspace" style = "margin-right:0.2222em;" > < / span > < span class = "mbin" > +< / span > < span class = "mspace" style = "margin-right:0.2222em;" > < / span > < span class = "mord" > < span class = "mord mathnormal" style = "margin-right:0.03588em;" > y< / span > < span class = "msupsub" > < span class = "vlist-t" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.8247em;" > < span style = "top:-3.063em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mathnormal mtight" > i< / span > < / span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mspace" style = "margin-right:0.2222em;" > < / span > < span class = "mbin" > ⋅< / span > < span class = "mspace" style = "margin-right:0.2222em;" > < / span > < span class = "mord" > < span class = "mord text" > < span class = "mord" > gate< / span > < / span > < span class = "msupsub" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist"
2021-02-12 08:17:18 -08:00
< p > where the numerator is a random (the prover commits to the cell assignments before the
2023-01-20 13:40:27 -08:00
verifier samples < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:0.625em;vertical-align:-0.1944em;" > < / span > < span class = "mord mathnormal" style = "margin-right:0.03588em;" > y< / span > < / span > < / span > < / span > ) linear combination of the circuit relations.< / p >
2021-02-12 08:17:18 -08:00
< ul >
2023-01-20 13:40:27 -08:00
< li > If the numerator polynomial (in formal indeterminate < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:0.6833em;" > < / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < / span > < / span > < / span > ) is perfectly divisible by
2021-02-12 08:17:18 -08:00
< span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord mathnormal" > t< / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "mclose" > )< / span > < / span > < / span > < / span > , then with high probability all relations are satisfied.< / li >
< li > Conversely, if at least one relation is not satisfied, then with high probability
2023-01-20 13:40:27 -08:00
< span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord mathnormal" > h< / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" > x< / span > < span class = "mclose" > )< / span > < span class = "mspace" style = "margin-right:0.2222em;" > < / span > < span class = "mbin" > ⋅< / span > < span class = "mspace" style = "margin-right:0.2222em;" > < / span > < / span > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord mathnormal" > t< / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" > x< / span > < span class = "mclose" > )< / span > < / span > < / span > < / span > will not equal the evaluation of the numerator at < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:0.4306em;" > < / span > < span class = "mord mathnormal" > x< / span > < / span > < / span > < / span > . In this case,
2021-02-12 08:17:18 -08:00
the numerator polynomial would not be perfectly divisible by < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord mathnormal" > t< / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "mclose" > )< / span > < / span > < / span > < / span > .< / li >
< / ul >
2021-11-29 21:05:15 -08:00
< h2 id = "committing-to-hx" > < a class = "header" href = "#committing-to-hx" > Committing to < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord mathnormal" > h< / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "mclose" > )< / span > < / span > < / span > < / span > < / a > < / h2 >
2023-01-20 13:40:27 -08:00
< p > < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord mathnormal" > h< / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "mclose" > )< / span > < / span > < / span > < / span > has degree < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord mathnormal" > d< / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" > n< / span > < span class = "mspace" style = "margin-right:0.2222em;" > < / span > < span class = "mbin" > − < / span > < span class = "mspace" style = "margin-right:0.2222em;" > < / span > < / span > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord" > 1< / span > < span class = "mclose" > )< / span > < span class = "mspace" style = "margin-right:0.2222em;" > < / span > < span class = "mbin" > − < / span > < span class = "mspace" style = "margin-right:0.2222em;" > < / span > < / span > < span class = "base" > < span class = "strut" style = "height:0.4306em;" > < / span > < span class = "mord mathnormal" > n< / span > < / span > < / span > < / span > (because the divisor < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord mathnormal" > t< / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "mclose" > )< / span > < / span > < / span > < / span > has degree < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:0.4306em;" > < / span > < span class = "mord mathnormal" > n< / span > < / span > < / span > < / span > ). However, the
2021-02-12 08:17:18 -08:00
polynomial commitment scheme we use for Halo 2 only supports committing to polynomials of
2023-01-20 13:40:27 -08:00
degree < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:0.6667em;vertical-align:-0.0833em;" > < / span > < span class = "mord mathnormal" > n< / span > < span class = "mspace" style = "margin-right:0.2222em;" > < / span > < span class = "mbin" > − < / span > < span class = "mspace" style = "margin-right:0.2222em;" > < / span > < / span > < span class = "base" > < span class = "strut" style = "height:0.6444em;" > < / span > < span class = "mord" > 1< / span > < / span > < / span > < / span > (which is the maximum degree that the rest of the protocol needs to commit
2021-02-12 08:17:18 -08:00
to). Instead of increasing the cost of the polynomial commitment scheme, the prover split
2023-01-20 13:40:27 -08:00
< span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord mathnormal" > h< / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "mclose" > )< / span > < / span > < / span > < / span > into pieces of degree < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:0.6667em;vertical-align:-0.0833em;" > < / span > < span class = "mord mathnormal" > n< / span > < span class = "mspace" style = "margin-right:0.2222em;" > < / span > < span class = "mbin" > − < / span > < span class = "mspace" style = "margin-right:0.2222em;" > < / span > < / span > < span class = "base" > < span class = "strut" style = "height:0.6444em;" > < / span > < span class = "mord" > 1< / span > < / span > < / span > < / span > < / p >
< p > < span class = "katex-display" > < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord" > < span class = "mord mathnormal" > h< / span > < span class = "msupsub" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.3011em;" > < span style = "top:-2.55em;margin-left:0em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > 0< / span > < / span > < / span > < / span > < span class = "vlist-s" > < / span > < / span > < span class = "vlist-r" > < span class = "vlist" style = "height:0.15em;" > < span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "mclose" > )< / span > < span class = "mspace" style = "margin-right:0.2222em;" > < / span > < span class = "mbin" > +< / span > < span class = "mspace" style = "margin-right:0.2222em;" > < / span > < / span > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord" > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "msupsub" > < span class = "vlist-t" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.7144em;" > < span style = "top:-3.113em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mathnormal mtight" > n< / span > < / span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mord" > < span class = "mord mathnormal" > h< / span > < span class = "msupsub" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.3011em;" > < span style = "top:-2.55em;margin-left:0em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > 1< / span > < / span > < / span > < / span > < span class = "vlist-s" > < / span > < / span > < span class = "vlist-r" > < span class = "vlist" style = "height:0.15em;" > < span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "mclose" > )< / span > < span class = "mspace" style = "margin-right:0.2222em;" > < / span > < span class = "mbin" > +< / span > < span class = "mspace" style = "margin-right:0.2222em;" > < / span > < / span > < span class = "base" > < span class = "strut" style = "height:0.6667em;vertical-align:-0.0833em;" > < / span > < span class = "minner" > ⋯< / span > < span class = "mspace" style = "margin-right:0.2222em;" > < / span > < span class = "mbin" > +< / span > < span class = "mspace" style = "margin-right:0.2222em;" > < / span > < / span > < span class = "base" > < span class = "strut" style = "height:1.188em;vertical-align:-0.25em;" > < / span > < span class = "mord" > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "msupsub" > < span class = "vlist-t" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.938em;" > < span style = "top:-3.113em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > < span class = "mord mathnormal mtight" > n< / span > < span class = "mopen mtight" > (< / span > < span class = "mord mathnormal mtight" > d< / span > < span class = "mbin mtight" > − < / span > < span class = "mord mtight" > 1< / span > < span class = "mclose mtight" > )< / span > < / span > < / span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mord" > < span class = "mord mathnormal" > h< / span > < span class = "msupsub" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.3361em;" > < span style = "top:-2.55em;margin-left:0em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > < span class = "mord mathnormal mtight" > d< / span > < span class = "mbin mtight" > − < / span > < span class = "mord mtight" > 1< / span > < / span > < / span > < / span > < / span > < span class = "vlist-s" > < / span > < / span > < span class = "vlist-r" > < span class = "vlist" style = "height:0.2083em;" > < span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mopen" > (< / span > < span class = "mord mathnor
2021-02-12 08:17:18 -08:00
< p > and produces blinding commitments to each piece< / p >
2023-01-20 13:40:27 -08:00
< p > < span class = "katex-display" > < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:0.6861em;" > < / span > < span class = "mord mathbf" > H< / span > < span class = "mspace" style = "margin-right:0.2778em;" > < / span > < span class = "mrel" > =< / span > < span class = "mspace" style = "margin-right:0.2778em;" > < / span > < / span > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mopen" > [< / span > < span class = "mord text" > < span class = "mord" > Commit< / span > < / span > < span class = "mopen" > (< / span > < span class = "mord" > < span class = "mord mathnormal" > h< / span > < span class = "msupsub" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.3011em;" > < span style = "top:-2.55em;margin-left:0em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > 0< / span > < / span > < / span > < / span > < span class = "vlist-s" > < / span > < / span > < span class = "vlist-r" > < span class = "vlist" style = "height:0.15em;" > < span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "mclose" > ))< / span > < span class = "mpunct" > ,< / span > < span class = "mspace" style = "margin-right:0.1667em;" > < / span > < span class = "mord text" > < span class = "mord" > Commit< / span > < / span > < span class = "mopen" > (< / span > < span class = "mord" > < span class = "mord mathnormal" > h< / span > < span class = "msupsub" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.3011em;" > < span style = "top:-2.55em;margin-left:0em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > 1< / span > < / span > < / span > < / span > < span class = "vlist-s" > < / span > < / span > < span class = "vlist-r" > < span class = "vlist" style = "height:0.15em;" > < span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "mclose" > ))< / span > < span class = "mpunct" > ,< / span > < span class = "mspace" style = "margin-right:0.1667em;" > < / span > < span class = "minner" > …< / span > < span class = "mspace" style = "margin-right:0.1667em;" > < / span > < span class = "mpunct" > ,< / span > < span class = "mspace" style = "margin-right:0.1667em;" > < / span > < span class = "mord text" > < span class = "mord" > Commit< / span > < / span > < span class = "mopen" > (< / span > < span class = "mord" > < span class = "mord mathnormal" > h< / span > < span class = "msupsub" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.3361em;" > < span style = "top:-2.55em;margin-left:0em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > < span class = "mord mathnormal mtight" > d< / span > < span class = "mbin mtight" > − < / span > < span class = "mord mtight" > 1< / span > < / span > < / span > < / span > < / span > < span class = "vlist-s" > < / span > < / span > < span class = "vlist-r" > < span class = "vlist" style = "height:0.2083em;" > < span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "mclose" > ))]< / span > < span class = "mord" > .< / span > < / span > < / span > < / span > < / span > < / p >
2021-06-05 03:42:23 -07:00
< h2 id = "evaluating-the-polynomials" > < a class = "header" href = "#evaluating-the-polynomials" > Evaluating the polynomials< / a > < / h2 >
2024-02-26 15:57:00 -08:00
< p > At this point, we have committed to all properties of the circuit. The verifier now
2021-02-12 08:17:18 -08:00
wants to see if the prover committed to the correct < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord mathnormal" > h< / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "mclose" > )< / span > < / span > < / span > < / span > polynomial. The verifier
2023-01-20 13:40:27 -08:00
samples < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:0.4306em;" > < / span > < span class = "mord mathnormal" > x< / span > < / span > < / span > < / span > , and the prover produces the purported evaluations of the various polynomials
at < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:0.4306em;" > < / span > < span class = "mord mathnormal" > x< / span > < / span > < / span > < / span > , for all the relative offsets used in the circuit, as well as < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord mathnormal" > h< / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "mclose" > )< / span > < / span > < / span > < / span > .< / p >
2021-02-12 08:17:18 -08:00
< blockquote >
< p > In our < a href = "../proving-system.html#example" > example< / a > , this would be:< / p >
< ul >
2023-01-20 13:40:27 -08:00
< li > < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord" > < span class = "mord mathnormal" > a< / span > < span class = "msupsub" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.3011em;" > < span style = "top:-2.55em;margin-left:0em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > 0< / span > < / span > < / span > < / span > < span class = "vlist-s" > < / span > < / span > < span class = "vlist-r" > < span class = "vlist" style = "height:0.15em;" > < span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" > x< / span > < span class = "mclose" > )< / span > < / span > < / span > < / span > < / li >
< li > < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord" > < span class = "mord mathnormal" > a< / span > < span class = "msupsub" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.3011em;" > < span style = "top:-2.55em;margin-left:0em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > 1< / span > < / span > < / span > < / span > < span class = "vlist-s" > < / span > < / span > < span class = "vlist-r" > < span class = "vlist" style = "height:0.15em;" > < span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" > x< / span > < span class = "mclose" > )< / span > < / span > < / span > < / span > < / li >
< li > < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord" > < span class = "mord mathnormal" > a< / span > < span class = "msupsub" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.3011em;" > < span style = "top:-2.55em;margin-left:0em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > 2< / span > < / span > < / span > < / span > < span class = "vlist-s" > < / span > < / span > < span class = "vlist-r" > < span class = "vlist" style = "height:0.15em;" > < span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" > x< / span > < span class = "mclose" > )< / span > < / span > < / span > < / span > , < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:1.0641em;vertical-align:-0.25em;" > < / span > < span class = "mord" > < span class = "mord mathnormal" > a< / span > < span class = "msupsub" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.3011em;" > < span style = "top:-2.55em;margin-left:0em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > 2< / span > < / span > < / span > < / span > < span class = "vlist-s" > < / span > < / span > < span class = "vlist-r" > < span class = "vlist" style = "height:0.15em;" > < span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" > x< / span > < span class = "mord" > < span class = "mord mathnormal" style = "margin-right:0.03588em;" > ω< / span > < span class = "msupsub" > < span class = "vlist-t" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.8141em;" > < span style = "top:-3.063em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > < span class = "mord mtight" > − < / span > < span class = "mord mtight" > 1< / span > < / span > < / span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mclose" > )< / span > < / span > < / span > < / span > < / li >
< li > < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord" > < span class = "mord mathnormal" > a< / span > < span class = "msupsub" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.3011em;" > < span style = "top:-2.55em;margin-left:0em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > 3< / span > < / span > < / span > < / span > < span class = "vlist-s" > < / span > < / span > < span class = "vlist-r" > < span class = "vlist" style = "height:0.15em;" > < span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" > x< / span > < span class = "mclose" > )< / span > < / span > < / span > < / span > < / li >
< li > < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord" > < span class = "mord mathnormal" style = "margin-right:0.10764em;" > f< / span > < span class = "msupsub" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.3011em;" > < span style = "top:-2.55em;margin-left:-0.1076em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > 0< / span > < / span > < / span > < / span > < span class = "vlist-s" > < / span > < / span > < span class = "vlist-r" > < span class = "vlist" style = "height:0.15em;" > < span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" > x< / span > < span class = "mclose" > )< / span > < / span > < / span > < / span > , < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:1.0641em;vertical-align:-0.25em;" > < / span > < span class = "mord" > < span class = "mord mathnormal" style = "margin-right:0.10764em;" > f< / span > < span class = "msupsub" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.3011em;" > < span style = "top:-2.55em;margin-left:-0.1076em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > 0< / span > < / span > < / span > < / span > < span class = "vlist-s" > < / span > < / span > < span class = "vlist-r" > < span class = "vlist" style = "height:0.15em;" > < span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" > x< / span > < span class = "mord" > < span class = "mord mathnormal" style = "margin-right:0.03588em;" > ω< / span > < span class = "msupsub" > < span class = "vlist-t" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.8141em;" > < span style = "top:-3.063em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > < span class = "mord mtight" > − < / span > < span class = "mord mtight" > 1< / span > < / span > < / span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mclose" > )< / span > < / span > < / span > < / span > < / li >
< li > < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord" > < span class = "mord mathnormal" > h< / span > < span class = "msupsub" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.3011em;" > < span style = "top:-2.55em;margin-left:0em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > 0< / span > < / span > < / span > < / span > < span class = "vlist-s" > < / span > < / span > < span class = "vlist-r" > < span class = "vlist" style = "height:0.15em;" > < span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" > x< / span > < span class = "mclose" > )< / span > < / span > < / span > < / span > , ..., < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord" > < span class = "mord mathnormal" > h< / span > < span class = "msupsub" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.3361em;" > < span style = "top:-2.55em;margin-left:0em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > < span class = "mord mathnormal mtight" > d< / span > < span class = "mbin mtight" > − < / span > < span class = "mord mtight" > 1< / span > < / span > < / span > < / span > < / span > < span class = "vlist-s" > < / span > < / span > < span class = "vlist-r" > < span class = "vlist" style = "height:0.2083em;" > < span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" > x< / span > < span class = "mclose" > )< / span > < / span > < / span > < / span > < / li >
2021-02-12 08:17:18 -08:00
< / ul >
< / blockquote >
< p > The verifier checks that these evaluations satisfy the form of < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord mathnormal" > h< / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" style = "margin-right:0.07847em;" > X< / span > < span class = "mclose" > )< / span > < / span > < / span > < / span > :< / p >
2023-01-20 13:40:27 -08:00
< p > < span class = "katex-display" > < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:2.4377em;vertical-align:-0.936em;" > < / span > < span class = "mord" > < span class = "mopen nulldelimiter" > < / span > < span class = "mfrac" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:1.5017em;" > < span style = "top:-2.314em;" > < span class = "pstrut" style = "height:3em;" > < / span > < span class = "mord" > < span class = "mord mathnormal" > t< / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" > x< / span > < span class = "mclose" > )< / span > < / span > < / span > < span style = "top:-3.23em;" > < span class = "pstrut" style = "height:3em;" > < / span > < span class = "frac-line" style = "border-bottom-width:0.04em;" > < / span > < / span > < span style = "top:-3.677em;" > < span class = "pstrut" style = "height:3em;" > < / span > < span class = "mord" > < span class = "mord" > < span class = "mord text" > < span class = "mord" > gate< / span > < / span > < span class = "msupsub" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.207em;" > < span style = "top:-2.4559em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > 0< / span > < / span > < / span > < / span > < span class = "vlist-s" > < / span > < / span > < span class = "vlist-r" > < span class = "vlist" style = "height:0.2441em;" > < span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" > x< / span > < span class = "mclose" > )< / span > < span class = "mspace" style = "margin-right:0.2222em;" > < / span > < span class = "mbin" > +< / span > < span class = "mspace" style = "margin-right:0.2222em;" > < / span > < span class = "minner" > ⋯< / span > < span class = "mspace" style = "margin-right:0.2222em;" > < / span > < span class = "mbin" > +< / span > < span class = "mspace" style = "margin-right:0.2222em;" > < / span > < span class = "mord" > < span class = "mord mathnormal" style = "margin-right:0.03588em;" > y< / span > < span class = "msupsub" > < span class = "vlist-t" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.8247em;" > < span style = "top:-3.063em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mathnormal mtight" > i< / span > < / span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mspace" style = "margin-right:0.2222em;" > < / span > < span class = "mbin" > ⋅< / span > < span class = "mspace" style = "margin-right:0.2222em;" > < / span > < span class = "mord" > < span class = "mord text" > < span class = "mord" > gate< / span > < / span > < span class = "msupsub" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.2175em;" > < span style = "top:-2.4559em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mathnormal mtight" > i< / span > < / span > < / span > < / span > < span class = "vlist-s" > < / span > < / span > < span class = "vlist-r" > < span class = "vlist" style = "height:0.2441em;" > < span > < / span > < / span > < / span > < / span > < / span > < / span > < span class = "mopen" > (< / span > < span class = "mord mathnormal" > x< / span > < span class = "mclose" > )< / span > < span class = "mspace" style = "margin-right:0.2222em;" > < / span > < span class = "mbin" > +< / span > < span class = "mspace" style = "margin-right:0.2222em;" > < / span > < span class = "minner" > …< / span > < / span > < / span > < / span > < span class = "vlist-s" > < / span > < / span > < span class = "vlist-r" > < span class = "vlist" style = "height:0.936em;" > < span > < / span > < / span > < / span > < / span > < / span > < span class = "mclose nulldelimiter" > < / span > < / span > < span class = "mspace" style = "margin-right:0.2778em;" > < / span > < span class = "mrel" > =< / span > < span class = "mspace" style = "margin-right:0.2778em;" > < / span > < / span > < span class = "base" > < span class = "strut" style = "height:1em;vertical-align:-0.25em;" > < / span > < span class = "mord" > < span class = "mord mathnormal" > h< / span > < span class = "msupsub" > < span class = "vlist-t vlist-t2" > < span class = "vlist-r" > < span class = "vlist" style = "height:0.3011em;" > < span style = "top:-2.55em;margin-left:0em;margin-right:0.05em;" > < span class = "pstrut" style = "height:2.7em;" > < / span > < span class = "sizing reset-size6 size3 mtight" > < span class = "mord mtight" > 0< / span > < / span > < / span > < / span > < sp
2021-02-12 08:17:18 -08:00
< p > Now content that the evaluations collectively satisfy the gate constraints, the verifier
needs to check that the evaluations themselves are consistent with the original
2023-01-20 13:40:27 -08:00
< a href = "circuit-commitments.html" > circuit commitments< / a > , as well as < span class = "katex" > < span class = "katex-html" aria-hidden = "true" > < span class = "base" > < span class = "strut" style = "height:0.6861em;" > < / span > < span class = "mord mathbf" > H< / span > < / span > < / span > < / span > . To implement this
2021-02-12 08:17:18 -08:00
efficiently, we use a < a href = "multipoint-opening.html" > multipoint opening argument< / a > .< / p >
< / main >
< nav class = "nav-wrapper" aria-label = "Page navigation" >
<!-- Mobile navigation buttons -->
2021-10-14 03:44:50 -07:00
< a rel = "prev" href = "../../design/proving-system/circuit-commitments.html" class = "mobile-nav-chapters previous" title = "Previous chapter" aria-label = "Previous chapter" aria-keyshortcuts = "Left" >
2021-02-12 08:17:18 -08:00
< i class = "fa fa-angle-left" > < / i >
< / a >
2023-01-20 13:40:27 -08:00
2024-02-26 15:57:00 -08:00
< a rel = "next prefetch" href = "../../design/proving-system/multipoint-opening.html" class = "mobile-nav-chapters next" title = "Next chapter" aria-label = "Next chapter" aria-keyshortcuts = "Right" >
2021-02-12 08:17:18 -08:00
< i class = "fa fa-angle-right" > < / i >
< / a >
2023-01-20 13:40:27 -08:00
2021-02-12 08:17:18 -08:00
< div style = "clear: both" > < / div >
< / nav >
< / div >
< / div >
< nav class = "nav-wide-wrapper" aria-label = "Page navigation" >
2021-10-14 03:44:50 -07:00
< a rel = "prev" href = "../../design/proving-system/circuit-commitments.html" class = "nav-chapters previous" title = "Previous chapter" aria-label = "Previous chapter" aria-keyshortcuts = "Left" >
2021-02-12 08:17:18 -08:00
< i class = "fa fa-angle-left" > < / i >
< / a >
2023-01-20 13:40:27 -08:00
2024-02-26 15:57:00 -08:00
< a rel = "next prefetch" href = "../../design/proving-system/multipoint-opening.html" class = "nav-chapters next" title = "Next chapter" aria-label = "Next chapter" aria-keyshortcuts = "Right" >
2021-02-12 08:17:18 -08:00
< i class = "fa fa-angle-right" > < / i >
< / a >
2021-10-14 03:44:50 -07:00
< / nav >
2021-02-12 08:17:18 -08:00
< / div >
2023-01-20 13:40:27 -08:00
< script >
2021-02-12 08:17:18 -08:00
window.playground_copyable = true;
< / script >
2023-01-20 13:40:27 -08:00
< script src = "../../elasticlunr.min.js" > < / script >
< script src = "../../mark.min.js" > < / script >
< script src = "../../searcher.js" > < / script >
< script src = "../../clipboard.min.js" > < / script >
< script src = "../../highlight.js" > < / script >
< script src = "../../book.js" > < / script >
2021-02-12 08:17:18 -08:00
<!-- Custom JS scripts -->
2023-01-20 13:40:27 -08:00
2024-02-26 15:57:00 -08:00
< / div >
2021-02-12 08:17:18 -08:00
< / body >
< / html >