diff --git a/book/src/background/fields.md b/book/src/background/fields.md index cdcefca..db488d3 100644 --- a/book/src/background/fields.md +++ b/book/src/background/fields.md @@ -11,6 +11,7 @@ elements. Halo makes use of _finite fields_ which have a finite number of elements. Finite fields are fully classified as follows: + - if $\mathbb{F}$ is a finite field, it contains $|\mathbb{F}| = p^k$ elements for some integer $k \geq 1$ and some prime $p$; - any two finite fields with the same number of elements are isomorphic. In particular, @@ -22,11 +23,12 @@ We'll write a field as $\mathbb{F}_q$ where $q = p^k$. The prime $p$ is called i _characteristic_. In the cases where $k \gt 1$ the field $\mathbb{F}_q$ is a $k$-degree extension of the field $\mathbb{F}_p$. (By analogy, the complex numbers $\mathbb{C} = \mathbb{R}(i)$ are an extension of the real numbers.) However, in Halo we do -not care about extension fields. Whenever we write $\mathbb{F}_p$ we are referring to what +not use extension fields. Whenever we write $\mathbb{F}_p$ we are referring to what we call a _prime field_ which has a prime $p$ number of elements, i.e. $k = 1$. Important notes: -* There are two special elements in any field: $\mathcal{O}$, the additive identity, and + +* There are two special elements in any field: $0$, the additive identity, and $1$, the multiplicative identity. * The least significant bit of a field element, when represented as an integer in binary format, can be interpreted as its "sign" to help distinguish it from its additive @@ -49,7 +51,7 @@ integer $a$. If $a$ is nonzero, we can divide by $a$ twice to get $a^{p-2} = a^{ However, it may be more intuitive to understand the set of nonzero elements of $\mathbb{F}_p$ as a [group], where the group operation is given by multiplication on the field. We use the notation $\mathbb{F}_p^\times$ for the multiplicative group over the set -$\mathbb{F}_p - \{\mathcal{O}\}$. Groups are simpler and more limited than fields; they +$\mathbb{F}_p - \{0\}$. Groups are simpler and more limited than fields; they have only _one_ operator $\cdot$ and fewer axioms. [group]: https://en.wikipedia.org/wiki/Group_(mathematics) @@ -123,8 +125,8 @@ inversion necessary. A _subgroup_ of a group $G$ with operation $\cdot$, is a subset of elements of $G$ that also form a group under $\cdot$. -In the previous section we said that $\alpha$ is a generator of the $p - 1$ order -multiplicative group $\mathbb{F}_p^\times$. This is a _composite_ order group, and so by +In the previous section we said that $\alpha$ is a generator of the $(p - 1)$-order +multiplicative group $\mathbb{F}_p^\times$. This group has _composite_ order, and so by the Chinese remainder theorem[^chinese-remainder] it has strict subgroups. As an example let's imagine that $p = 11$, and so $p - 1$ factors into $5 \cdot 2$. Thus, there is a generator $\beta$ of the $5$-order subgroup and a generator $\gamma$ of the $2$-order @@ -153,10 +155,10 @@ of $\mathbb{F}_p^\times$ must divide $p-1.$ In a field $\mathbb{F}_p$ exactly half of all nonzero elements are squares; the remainder are non-squares or "quadratic non-residues". In order to see why, consider an $\alpha$ -that generates the $2$-order multiplicative subgroup of $\mathbb{F}_p^\times$ (this always -exists because $p - 1$ is divisible by $2$ since $p$ is prime) and $\beta$ that generates -the $t$-order multiplicative subgroup of $\mathbb{F}_p^\times$ where $p - 1 = 2t$. Then -every element $a \in \mathbb{F}_p^\times$ can be written uniquely as +that generates the $2$-order multiplicative subgroup of $\mathbb{F}_p^\times$ (this exists +because $p - 1$ is divisible by $2$ since $p$ is a prime greater than $2$) and $\beta$ that +generates the $t$-order multiplicative subgroup of $\mathbb{F}_p^\times$ where $p - 1 = 2t$. +Then every element $a \in \mathbb{F}_p^\times$ can be written uniquely as $\alpha^i \cdot \beta^j$ with $i \in \mathbb{Z}_2$ and $j \in \mathbb{Z}_t$. Half of all elements will have $i = 0$ and the other half will have $i = 1$. @@ -226,10 +228,11 @@ The **primitive root of unity**, $\omega,$ is an $n$th root of unity such that $\omega^i \neq 1$ except when $i \equiv 0 \pmod{n}$. Important notes: -- if $\alpha$ is an $n$th root of unity, $\alpha$ satisfies $\alpha^n - 1 = 0.$ If + +- If $\alpha$ is an $n$th root of unity, $\alpha$ satisfies $\alpha^n - 1 = 0.$ If $\alpha \neq 1,$ then $$1 + \alpha + \alpha^2 + \cdots + \alpha^{n-1} = 0.$$ -- equivalently, the roots of unity are solutions to the equation +- Equivalently, the roots of unity are solutions to the equation $$X^n - 1 = (X - 1)(X - \alpha)(X - \alpha^2) \cdots (X - \alpha^{n-1}).$$ - **$\boxed{\omega^{\frac{n}{2}+i} = -\omega^i}$ ("Negation lemma")**. Proof: $$ @@ -245,7 +248,7 @@ Important notes: (\omega^{\frac{n}{2}+i})^2 = \omega^{n + 2i} = \omega^{n} \cdot \omega^{2i} = \omega^{2i} = (\omega^i)^2. $$ In other words, if we square each element in the $n$th roots of unity, we would get back - only half the elements, $\{(\omega_n^i)^2\} = \{\omega_{n/2}\}$ (i.e. the $n/2$th roots + only half the elements, $\{(\omega_n^i)^2\} = \{\omega_{n/2}\}$ (i.e. the $\frac{n}{2}$th roots of unity). There is a two-to-one mapping between the elements and their squares. ## References diff --git a/book/src/background/polynomials.md b/book/src/background/polynomials.md index 230fba6..5e4c164 100644 --- a/book/src/background/polynomials.md +++ b/book/src/background/polynomials.md @@ -208,9 +208,12 @@ $\frac{A(X) + B(X) - C(X)}{Z_H(X)} = H(X),$ we are satisfied that $A(X) + B(X) - over $\mathcal{H}.$ ## Lagrange basis functions + +> TODO: explain what a basis is in general (briefly). + Polynomials are commonly written in the monomial basis (e.g. $X, X^2, ... X^n$). However, -when working over a multiplicative subgroup, we find a more natural expression in the -Lagrange basis. +when working over a multiplicative subgroup of order $n$, we find a more natural expression +in the Lagrange basis. Consider the order-$n$ multiplicative subgroup $\mathcal{H}$ with primitive root of unity $\omega$. The Lagrange basis corresponding to this subgroup is a set of functions @@ -231,7 +234,7 @@ Now, we can write our polynomial as a linear combination of Lagrange basis funct $$A(X) = \sum_{i = 0}^{n-1} a_i\mathcal{L_i}(X), X \in \mathcal{H},$$ which is equivalent to saying that $p(X)$ evaluates to $a_0$ at $\omega^0$, -$p(\omega^1) = a_1, p(\omega^2) = a_2, \cdots,$ and so on. +to $a_1$ at $\omega^1$, to $a_2$ at $\omega^2, \cdots,$ and so on. When working over a multiplicative subgroup, the Lagrange basis function has a convenient sparse representation of the form @@ -244,9 +247,9 @@ where $c_i$ is the barycentric weight. (To understand how this form was derived, [^barycentric].) For $i = 0,$ we have $c = 1/n \implies \mathcal{L}_0(X) = \frac{1}{n} \frac{(X^{n} - 1)}{X - 1}$. +Suppose we are given a set of evaluation points $\{x_0, x_1, \cdots, x_{n-1}\}$. Since we cannot assume that the $x_i$'s form a multiplicative subgroup, we consider also -the Lagrange polynomials $\mathcal{L}_i$'s in the general case. Given a set of evaluation -points $\{x_0, x_1, \cdots, x_{n-1}\},$ we can construct +the Lagrange polynomials $\mathcal{L}_i$'s in the general case. Then we can construct: $$ \mathcal{L}_i(X) = \prod_{j\neq i}\frac{X - x_j}{x_i - x_j}, i \in [0..n-1]. @@ -255,7 +258,8 @@ $$ Here, every $X = x_j \neq x_i$ will produce a zero numerator term $(x_j - x_j),$ causing the whole product to evaluate to zero. On the other hand, $X= x_i$ will evaluate to $\frac{x_i - x_j}{x_i - x_j}$ at every term, resulting in an overall product of one. This -gives the desired Kronecker delta behaviour $\mathcal{L_i}(x_j) = \delta_{ij}.$ +gives the desired Kronecker delta behaviour $\mathcal{L_i}(x_j) = \delta_{ij}$ on the +set $\{x_0, x_1, \cdots, x_{n-1}\}$. ### Lagrange interpolation Given a polynomial in its evaluation representation diff --git a/book/src/background/upa.md b/book/src/background/upa.md index 4ffaeb9..3a4000b 100644 --- a/book/src/background/upa.md +++ b/book/src/background/upa.md @@ -1,7 +1,11 @@ # [WIP] UltraPLONK arithmetisation -We work over a multiplicative subgroup -$\mathcal{H} =\{1, \omega, \omega^2, \cdots, \omega^{n-1}\},$ where $\omega$ is primitive -root of unity, in the Lagrange basis corresponding to these points. + +We call the field over which the circuit is defined $\mathbb{F} = \mathbb{F}_p$. + +Let $n = 2^k$, and assume that $\omega$ is a primitive root of unity of order $n$ in +$\mathbb{F}^\times$, so that $\mathbb{F}^\times$ has a multiplicative subgroup +$\mathcal{H} = \{1, \omega, \omega^2, \cdots, \omega^{n-1}\}$. This forms a Lagrange +basis corresponding to the points in the subgroup. ## Polynomial rules A polynomial rule defines a constraint that must hold between its specified columns at