From cd809c57dc44769a45c4581d3d76178de393a34c Mon Sep 17 00:00:00 2001 From: ying tong Date: Fri, 9 Apr 2021 16:53:35 +0800 Subject: [PATCH] Apply suggestions from code review Co-authored-by: str4d --- book/src/design/circuit/gadgets/ecc/var-base-scalar-mul.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/book/src/design/circuit/gadgets/ecc/var-base-scalar-mul.md b/book/src/design/circuit/gadgets/ecc/var-base-scalar-mul.md index 4a1bb52a..e701dc7d 100644 --- a/book/src/design/circuit/gadgets/ecc/var-base-scalar-mul.md +++ b/book/src/design/circuit/gadgets/ecc/var-base-scalar-mul.md @@ -92,7 +92,7 @@ and similarly for $\lambda_{1, i+1}, \lambda_{2, i+1}$. We witness $x_{A,i}, x_{P,i}, x_{A, i+1},$ and $\lambda_{1, i}, \lambda_{2, i}, \lambda_{1, i+1}, \lambda_{2, i+1},$ and specify the following constraints on them (copied from ["Faster variable-base scalar multiplication in zk-SNARK circuits"](https://github.com/zcash/zcash/issues/3924), with some variable name changes): -1. $ +$$ \lambda_{2,i}^2 - (x_{A,i+1} + (\lambda_{1,i}^2 - x_{A,i} - x_{P,i}) + x_{A,i}) = 0, $$