mirror of
https://github.com/saymrwulf/pasta_curves-source.git
synced 2026-09-04 20:03:39 +00:00
Only return Guard from OpeningProof.verify()
This commit is contained in:
parent
d41fcf842b
commit
5f1cd6ced2
3 changed files with 12 additions and 35 deletions
|
|
@ -265,7 +265,7 @@ impl<C: CurveAffine> Proof<C> {
|
||||||
|
|
||||||
// Verify the opening proof
|
// Verify the opening proof
|
||||||
let default_msm = MSM::default(¶ms);
|
let default_msm = MSM::default(¶ms);
|
||||||
let (challenges, guard) = self
|
let guard = self
|
||||||
.opening
|
.opening
|
||||||
.verify(
|
.verify(
|
||||||
params,
|
params,
|
||||||
|
|
@ -277,7 +277,7 @@ impl<C: CurveAffine> Proof<C> {
|
||||||
)
|
)
|
||||||
.unwrap();
|
.unwrap();
|
||||||
|
|
||||||
let msm: &MSM<C> = &guard.use_challenges(params, challenges).unwrap();
|
let msm: &MSM<C> = &guard.use_challenges(params).unwrap();
|
||||||
|
|
||||||
msm.is_zero(params)
|
msm.is_zero(params)
|
||||||
}
|
}
|
||||||
|
|
|
||||||
|
|
@ -5,8 +5,7 @@
|
||||||
|
|
||||||
use super::{Coeff, Error, LagrangeCoeff, Polynomial};
|
use super::{Coeff, Error, LagrangeCoeff, Polynomial};
|
||||||
use crate::arithmetic::{
|
use crate::arithmetic::{
|
||||||
best_fft, best_multiexp, get_challenge_scalar, parallelize, Challenge, Curve, CurveAffine,
|
best_fft, best_multiexp, parallelize, Challenge, Curve, CurveAffine, Field,
|
||||||
Field,
|
|
||||||
};
|
};
|
||||||
use crate::transcript::Hasher;
|
use crate::transcript::Hasher;
|
||||||
use std::ops::{Add, AddAssign, Mul, MulAssign};
|
use std::ops::{Add, AddAssign, Mul, MulAssign};
|
||||||
|
|
@ -249,25 +248,17 @@ impl<C: CurveAffine> Params<C> {
|
||||||
/// A guard returned by the verifier
|
/// A guard returned by the verifier
|
||||||
#[derive(Debug)]
|
#[derive(Debug)]
|
||||||
pub struct Guard<C: CurveAffine> {
|
pub struct Guard<C: CurveAffine> {
|
||||||
/// MSM
|
|
||||||
msm: MSM<C>,
|
msm: MSM<C>,
|
||||||
|
|
||||||
/// Negation of z1 value in the OpeningProof
|
|
||||||
neg_z1: C::Scalar,
|
neg_z1: C::Scalar,
|
||||||
|
|
||||||
allinv: C::Scalar,
|
allinv: C::Scalar,
|
||||||
|
|
||||||
challenges_sq: Vec<C::Scalar>,
|
challenges_sq: Vec<C::Scalar>,
|
||||||
|
challenges_sq_packed: Vec<Challenge>,
|
||||||
}
|
}
|
||||||
|
|
||||||
impl<C: CurveAffine> Guard<C> {
|
impl<C: CurveAffine> Guard<C> {
|
||||||
/// Lets caller supply the challenges and obtain an MSM with updated
|
/// Lets caller supply the challenges and obtain an MSM with updated
|
||||||
/// scalars and points.
|
/// scalars and points.
|
||||||
pub fn use_challenges(
|
pub fn use_challenges(mut self, params: &Params<C>) -> Result<MSM<C>, Error> {
|
||||||
mut self,
|
|
||||||
params: &Params<C>,
|
|
||||||
challenges_sq_packed: Vec<Challenge>,
|
|
||||||
) -> Result<MSM<C>, Error> {
|
|
||||||
let mut scalars: Vec<C::Scalar> = vec![];
|
let mut scalars: Vec<C::Scalar> = vec![];
|
||||||
let mut bases: Vec<C> = vec![];
|
let mut bases: Vec<C> = vec![];
|
||||||
|
|
||||||
|
|
@ -281,22 +272,7 @@ impl<C: CurveAffine> Guard<C> {
|
||||||
}
|
}
|
||||||
|
|
||||||
// - [z1] G
|
// - [z1] G
|
||||||
let mut allinv = C::Scalar::one();
|
let s = compute_s(&self.challenges_sq, self.allinv * &self.neg_z1);
|
||||||
let mut challenges_sq = Vec::with_capacity(params.k as usize);
|
|
||||||
|
|
||||||
for challenge_sq_packed in challenges_sq_packed.iter() {
|
|
||||||
let challenge_sq: C::Scalar = get_challenge_scalar(*challenge_sq_packed);
|
|
||||||
challenges_sq.push(challenge_sq);
|
|
||||||
|
|
||||||
let challenge = challenge_sq.deterministic_sqrt();
|
|
||||||
let challenge = challenge.unwrap();
|
|
||||||
|
|
||||||
let challenge_inv = challenge.invert();
|
|
||||||
let challenge_inv = challenge_inv.unwrap();
|
|
||||||
allinv *= &challenge_inv;
|
|
||||||
}
|
|
||||||
|
|
||||||
let s = compute_s(&challenges_sq, allinv * &self.neg_z1);
|
|
||||||
scalars.extend(&s);
|
scalars.extend(&s);
|
||||||
bases.extend(¶ms.g);
|
bases.extend(¶ms.g);
|
||||||
|
|
||||||
|
|
@ -308,7 +284,7 @@ impl<C: CurveAffine> Guard<C> {
|
||||||
/// Lets caller supply the purported G point and simply appends it to
|
/// Lets caller supply the purported G point and simply appends it to
|
||||||
/// return an updated MSM.
|
/// return an updated MSM.
|
||||||
pub fn use_g(mut self, g: C) -> Result<MSM<C>, Error> {
|
pub fn use_g(mut self, g: C) -> Result<MSM<C>, Error> {
|
||||||
&self.msm.other_scalars.push(self.allinv * &self.neg_z1);
|
&self.msm.other_scalars.push(self.neg_z1);
|
||||||
&self.msm.other_bases.push(g);
|
&self.msm.other_bases.push(g);
|
||||||
|
|
||||||
Ok(self.msm)
|
Ok(self.msm)
|
||||||
|
|
@ -436,11 +412,11 @@ fn test_opening_proof() {
|
||||||
let opening_proof = opening_proof.unwrap();
|
let opening_proof = opening_proof.unwrap();
|
||||||
// Verify the opening proof
|
// Verify the opening proof
|
||||||
let msm = MSM::default(¶ms);
|
let msm = MSM::default(¶ms);
|
||||||
let (challenges, guard) = opening_proof
|
let guard = opening_proof
|
||||||
.verify(¶ms, msm, &mut transcript_dup, x, &p, v)
|
.verify(¶ms, msm, &mut transcript_dup, x, &p, v)
|
||||||
.unwrap();
|
.unwrap();
|
||||||
|
|
||||||
let msm = guard.use_challenges(¶ms, challenges).unwrap();
|
let msm = guard.use_challenges(¶ms).unwrap();
|
||||||
|
|
||||||
assert!(msm.is_zero(¶ms));
|
assert!(msm.is_zero(¶ms));
|
||||||
break;
|
break;
|
||||||
|
|
|
||||||
|
|
@ -16,7 +16,7 @@ impl<C: CurveAffine> OpeningProof<C> {
|
||||||
x: C::Scalar,
|
x: C::Scalar,
|
||||||
p: &C,
|
p: &C,
|
||||||
v: C::Scalar,
|
v: C::Scalar,
|
||||||
) -> Result<(Vec<Challenge>, Guard<C>), Error> {
|
) -> Result<Guard<C>, Error> {
|
||||||
// Check for well-formedness
|
// Check for well-formedness
|
||||||
if self.rounds.len() != params.k as usize {
|
if self.rounds.len() != params.k as usize {
|
||||||
return Err(Error::OpeningError);
|
return Err(Error::OpeningError);
|
||||||
|
|
@ -136,9 +136,10 @@ impl<C: CurveAffine> OpeningProof<C> {
|
||||||
neg_z1,
|
neg_z1,
|
||||||
allinv,
|
allinv,
|
||||||
challenges_sq,
|
challenges_sq,
|
||||||
|
challenges_sq_packed,
|
||||||
};
|
};
|
||||||
|
|
||||||
Ok((challenges_sq_packed, guard))
|
Ok(guard)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue