zorch.pcs.ipa.config¶
IPA wire types on the pcs seam.
The commitment is a bare array — a batch of G1 points, one Pedersen
commitment P = ⟨a, G⟩ per polynomial — so it is a named alias like KZG's. The
proof carries structure (the per-round cross terms plus the collapsed scalar) and
crosses the open/verify @jit boundary, so it is a registered-pytree dataclass
like FriProof.
IpaProof
dataclass
¶
One polynomial's opening proof.
l, r are the round cross terms L_j, R_j (G1 affine, [k] each
for k = log₂ n rounds); a is the single field scalar the coefficient
vector collapses to after the last fold. The verifier needs no folded b
scalar in the proof — it recomputes b = h(x) from the round challenges in
O(log n) (see math.eval_challenge_poly). A registered pytree so the proof
crosses the open/verify @jit boundary.
Source code in zorch/pcs/ipa/config.py
22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 | |
IpaZkProof
dataclass
¶
One polynomial's hiding opening proof — the no-zk IpaProof plus the two
elements blinding adds.
l, r, a are the fold's cross terms and collapsed scalar exactly as in
IpaProof: the zk fold runs the same recurrence, only on a blinded
(commitment, coeffs). hiding_comm is the Pedersen commitment to the blinding
polynomial (⟨hiding_poly, G⟩ + s·hiding_rand) and rand the accumulated
commitment randomness; the verifier re-folds both into the statement before
replaying the fold (see prover._open_one_zk / verifier.reduce_opening_zk). A
registered pytree so it crosses the open/verify @jit boundary.
Source code in zorch/pcs/ipa/config.py
43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 | |