Clarifications for background, from pairing with Kris.

Signed-off-by: Daira Hopwood <daira@jacaranda.org>
This commit is contained in:
Daira Hopwood 2021-01-29 19:51:48 +00:00
parent 963a91464a
commit 723ea8feac
3 changed files with 32 additions and 21 deletions

View file

@ -11,6 +11,7 @@ elements.
Halo makes use of _finite fields_ which have a finite number of elements. Finite fields
are fully classified as follows:
- if $\mathbb{F}$ is a finite field, it contains $|\mathbb{F}| = p^k$ elements for some
integer $k \geq 1$ and some prime $p$;
- any two finite fields with the same number of elements are isomorphic. In particular,
@ -22,11 +23,12 @@ We'll write a field as $\mathbb{F}_q$ where $q = p^k$. The prime $p$ is called i
_characteristic_. In the cases where $k \gt 1$ the field $\mathbb{F}_q$ is a $k$-degree
extension of the field $\mathbb{F}_p$. (By analogy, the complex numbers
$\mathbb{C} = \mathbb{R}(i)$ are an extension of the real numbers.) However, in Halo we do
not care about extension fields. Whenever we write $\mathbb{F}_p$ we are referring to what
not use extension fields. Whenever we write $\mathbb{F}_p$ we are referring to what
we call a _prime field_ which has a prime $p$ number of elements, i.e. $k = 1$.
Important notes:
* There are two special elements in any field: $\mathcal{O}$, the additive identity, and
* There are two special elements in any field: $0$, the additive identity, and
$1$, the multiplicative identity.
* The least significant bit of a field element, when represented as an integer in binary
format, can be interpreted as its "sign" to help distinguish it from its additive
@ -49,7 +51,7 @@ integer $a$. If $a$ is nonzero, we can divide by $a$ twice to get $a^{p-2} = a^{
However, it may be more intuitive to understand the set of nonzero elements of
$\mathbb{F}_p$ as a [group], where the group operation is given by multiplication on the
field. We use the notation $\mathbb{F}_p^\times$ for the multiplicative group over the set
$\mathbb{F}_p - \{\mathcal{O}\}$. Groups are simpler and more limited than fields; they
$\mathbb{F}_p - \{0\}$. Groups are simpler and more limited than fields; they
have only _one_ operator $\cdot$ and fewer axioms.
[group]: https://en.wikipedia.org/wiki/Group_(mathematics)
@ -123,8 +125,8 @@ inversion necessary.
A _subgroup_ of a group $G$ with operation $\cdot$, is a subset of elements of $G$ that
also form a group under $\cdot$.
In the previous section we said that $\alpha$ is a generator of the $p - 1$ order
multiplicative group $\mathbb{F}_p^\times$. This is a _composite_ order group, and so by
In the previous section we said that $\alpha$ is a generator of the $(p - 1)$-order
multiplicative group $\mathbb{F}_p^\times$. This group has _composite_ order, and so by
the Chinese remainder theorem[^chinese-remainder] it has strict subgroups. As an example
let's imagine that $p = 11$, and so $p - 1$ factors into $5 \cdot 2$. Thus, there is a
generator $\beta$ of the $5$-order subgroup and a generator $\gamma$ of the $2$-order
@ -153,10 +155,10 @@ of $\mathbb{F}_p^\times$ must divide $p-1.$
In a field $\mathbb{F}_p$ exactly half of all nonzero elements are squares; the remainder
are non-squares or "quadratic non-residues". In order to see why, consider an $\alpha$
that generates the $2$-order multiplicative subgroup of $\mathbb{F}_p^\times$ (this always
exists because $p - 1$ is divisible by $2$ since $p$ is prime) and $\beta$ that generates
the $t$-order multiplicative subgroup of $\mathbb{F}_p^\times$ where $p - 1 = 2t$. Then
every element $a \in \mathbb{F}_p^\times$ can be written uniquely as
that generates the $2$-order multiplicative subgroup of $\mathbb{F}_p^\times$ (this exists
because $p - 1$ is divisible by $2$ since $p$ is a prime greater than $2$) and $\beta$ that
generates the $t$-order multiplicative subgroup of $\mathbb{F}_p^\times$ where $p - 1 = 2t$.
Then every element $a \in \mathbb{F}_p^\times$ can be written uniquely as
$\alpha^i \cdot \beta^j$ with $i \in \mathbb{Z}_2$ and $j \in \mathbb{Z}_t$. Half of all
elements will have $i = 0$ and the other half will have $i = 1$.
@ -226,10 +228,11 @@ The **primitive root of unity**, $\omega,$ is an $n$th root of unity such that
$\omega^i \neq 1$ except when $i \equiv 0 \pmod{n}$.
Important notes:
- if $\alpha$ is an $n$th root of unity, $\alpha$ satisfies $\alpha^n - 1 = 0.$ If
- If $\alpha$ is an $n$th root of unity, $\alpha$ satisfies $\alpha^n - 1 = 0.$ If
$\alpha \neq 1,$ then
$$1 + \alpha + \alpha^2 + \cdots + \alpha^{n-1} = 0.$$
- equivalently, the roots of unity are solutions to the equation
- Equivalently, the roots of unity are solutions to the equation
$$X^n - 1 = (X - 1)(X - \alpha)(X - \alpha^2) \cdots (X - \alpha^{n-1}).$$
- **$\boxed{\omega^{\frac{n}{2}+i} = -\omega^i}$ ("Negation lemma")**. Proof:
$$
@ -245,7 +248,7 @@ Important notes:
(\omega^{\frac{n}{2}+i})^2 = \omega^{n + 2i} = \omega^{n} \cdot \omega^{2i} = \omega^{2i} = (\omega^i)^2.
$$
In other words, if we square each element in the $n$th roots of unity, we would get back
only half the elements, $\{(\omega_n^i)^2\} = \{\omega_{n/2}\}$ (i.e. the $n/2$th roots
only half the elements, $\{(\omega_n^i)^2\} = \{\omega_{n/2}\}$ (i.e. the $\frac{n}{2}$th roots
of unity). There is a two-to-one mapping between the elements and their squares.
## References

View file

@ -208,9 +208,12 @@ $\frac{A(X) + B(X) - C(X)}{Z_H(X)} = H(X),$ we are satisfied that $A(X) + B(X) -
over $\mathcal{H}.$
## Lagrange basis functions
> TODO: explain what a basis is in general (briefly).
Polynomials are commonly written in the monomial basis (e.g. $X, X^2, ... X^n$). However,
when working over a multiplicative subgroup, we find a more natural expression in the
Lagrange basis.
when working over a multiplicative subgroup of order $n$, we find a more natural expression
in the Lagrange basis.
Consider the order-$n$ multiplicative subgroup $\mathcal{H}$ with primitive root of unity
$\omega$. The Lagrange basis corresponding to this subgroup is a set of functions
@ -231,7 +234,7 @@ Now, we can write our polynomial as a linear combination of Lagrange basis funct
$$A(X) = \sum_{i = 0}^{n-1} a_i\mathcal{L_i}(X), X \in \mathcal{H},$$
which is equivalent to saying that $p(X)$ evaluates to $a_0$ at $\omega^0$,
$p(\omega^1) = a_1, p(\omega^2) = a_2, \cdots,$ and so on.
to $a_1$ at $\omega^1$, to $a_2$ at $\omega^2, \cdots,$ and so on.
When working over a multiplicative subgroup, the Lagrange basis function has a convenient
sparse representation of the form
@ -244,9 +247,9 @@ where $c_i$ is the barycentric weight. (To understand how this form was derived,
[^barycentric].) For $i = 0,$ we have
$c = 1/n \implies \mathcal{L}_0(X) = \frac{1}{n} \frac{(X^{n} - 1)}{X - 1}$.
Suppose we are given a set of evaluation points $\{x_0, x_1, \cdots, x_{n-1}\}$.
Since we cannot assume that the $x_i$'s form a multiplicative subgroup, we consider also
the Lagrange polynomials $\mathcal{L}_i$'s in the general case. Given a set of evaluation
points $\{x_0, x_1, \cdots, x_{n-1}\},$ we can construct
the Lagrange polynomials $\mathcal{L}_i$'s in the general case. Then we can construct:
$$
\mathcal{L}_i(X) = \prod_{j\neq i}\frac{X - x_j}{x_i - x_j}, i \in [0..n-1].
@ -255,7 +258,8 @@ $$
Here, every $X = x_j \neq x_i$ will produce a zero numerator term $(x_j - x_j),$ causing
the whole product to evaluate to zero. On the other hand, $X= x_i$ will evaluate to
$\frac{x_i - x_j}{x_i - x_j}$ at every term, resulting in an overall product of one. This
gives the desired Kronecker delta behaviour $\mathcal{L_i}(x_j) = \delta_{ij}.$
gives the desired Kronecker delta behaviour $\mathcal{L_i}(x_j) = \delta_{ij}$ on the
set $\{x_0, x_1, \cdots, x_{n-1}\}$.
### Lagrange interpolation
Given a polynomial in its evaluation representation

View file

@ -1,7 +1,11 @@
# [WIP] UltraPLONK arithmetisation
We work over a multiplicative subgroup
$\mathcal{H} =\{1, \omega, \omega^2, \cdots, \omega^{n-1}\},$ where $\omega$ is primitive
root of unity, in the Lagrange basis corresponding to these points.
We call the field over which the circuit is defined $\mathbb{F} = \mathbb{F}_p$.
Let $n = 2^k$, and assume that $\omega$ is a primitive root of unity of order $n$ in
$\mathbb{F}^\times$, so that $\mathbb{F}^\times$ has a multiplicative subgroup
$\mathcal{H} = \{1, \omega, \omega^2, \cdots, \omega^{n-1}\}$. This forms a Lagrange
basis corresponding to the points in the subgroup.
## Polynomial rules
A polynomial rule defines a constraint that must hold between its specified columns at