Clarifications for background, from pairing with Kris.

Signed-off-by: Daira Hopwood <daira@jacaranda.org>
This commit is contained in:
Daira Hopwood 2021-01-29 19:51:48 +00:00
parent 963a91464a
commit 723ea8feac
3 changed files with 32 additions and 21 deletions

View file

@ -11,6 +11,7 @@ elements.
Halo makes use of _finite fields_ which have a finite number of elements. Finite fields Halo makes use of _finite fields_ which have a finite number of elements. Finite fields
are fully classified as follows: are fully classified as follows:
- if $\mathbb{F}$ is a finite field, it contains $|\mathbb{F}| = p^k$ elements for some - if $\mathbb{F}$ is a finite field, it contains $|\mathbb{F}| = p^k$ elements for some
integer $k \geq 1$ and some prime $p$; integer $k \geq 1$ and some prime $p$;
- any two finite fields with the same number of elements are isomorphic. In particular, - any two finite fields with the same number of elements are isomorphic. In particular,
@ -22,11 +23,12 @@ We'll write a field as $\mathbb{F}_q$ where $q = p^k$. The prime $p$ is called i
_characteristic_. In the cases where $k \gt 1$ the field $\mathbb{F}_q$ is a $k$-degree _characteristic_. In the cases where $k \gt 1$ the field $\mathbb{F}_q$ is a $k$-degree
extension of the field $\mathbb{F}_p$. (By analogy, the complex numbers extension of the field $\mathbb{F}_p$. (By analogy, the complex numbers
$\mathbb{C} = \mathbb{R}(i)$ are an extension of the real numbers.) However, in Halo we do $\mathbb{C} = \mathbb{R}(i)$ are an extension of the real numbers.) However, in Halo we do
not care about extension fields. Whenever we write $\mathbb{F}_p$ we are referring to what not use extension fields. Whenever we write $\mathbb{F}_p$ we are referring to what
we call a _prime field_ which has a prime $p$ number of elements, i.e. $k = 1$. we call a _prime field_ which has a prime $p$ number of elements, i.e. $k = 1$.
Important notes: Important notes:
* There are two special elements in any field: $\mathcal{O}$, the additive identity, and
* There are two special elements in any field: $0$, the additive identity, and
$1$, the multiplicative identity. $1$, the multiplicative identity.
* The least significant bit of a field element, when represented as an integer in binary * The least significant bit of a field element, when represented as an integer in binary
format, can be interpreted as its "sign" to help distinguish it from its additive format, can be interpreted as its "sign" to help distinguish it from its additive
@ -49,7 +51,7 @@ integer $a$. If $a$ is nonzero, we can divide by $a$ twice to get $a^{p-2} = a^{
However, it may be more intuitive to understand the set of nonzero elements of However, it may be more intuitive to understand the set of nonzero elements of
$\mathbb{F}_p$ as a [group], where the group operation is given by multiplication on the $\mathbb{F}_p$ as a [group], where the group operation is given by multiplication on the
field. We use the notation $\mathbb{F}_p^\times$ for the multiplicative group over the set field. We use the notation $\mathbb{F}_p^\times$ for the multiplicative group over the set
$\mathbb{F}_p - \{\mathcal{O}\}$. Groups are simpler and more limited than fields; they $\mathbb{F}_p - \{0\}$. Groups are simpler and more limited than fields; they
have only _one_ operator $\cdot$ and fewer axioms. have only _one_ operator $\cdot$ and fewer axioms.
[group]: https://en.wikipedia.org/wiki/Group_(mathematics) [group]: https://en.wikipedia.org/wiki/Group_(mathematics)
@ -123,8 +125,8 @@ inversion necessary.
A _subgroup_ of a group $G$ with operation $\cdot$, is a subset of elements of $G$ that A _subgroup_ of a group $G$ with operation $\cdot$, is a subset of elements of $G$ that
also form a group under $\cdot$. also form a group under $\cdot$.
In the previous section we said that $\alpha$ is a generator of the $p - 1$ order In the previous section we said that $\alpha$ is a generator of the $(p - 1)$-order
multiplicative group $\mathbb{F}_p^\times$. This is a _composite_ order group, and so by multiplicative group $\mathbb{F}_p^\times$. This group has _composite_ order, and so by
the Chinese remainder theorem[^chinese-remainder] it has strict subgroups. As an example the Chinese remainder theorem[^chinese-remainder] it has strict subgroups. As an example
let's imagine that $p = 11$, and so $p - 1$ factors into $5 \cdot 2$. Thus, there is a let's imagine that $p = 11$, and so $p - 1$ factors into $5 \cdot 2$. Thus, there is a
generator $\beta$ of the $5$-order subgroup and a generator $\gamma$ of the $2$-order generator $\beta$ of the $5$-order subgroup and a generator $\gamma$ of the $2$-order
@ -153,10 +155,10 @@ of $\mathbb{F}_p^\times$ must divide $p-1.$
In a field $\mathbb{F}_p$ exactly half of all nonzero elements are squares; the remainder In a field $\mathbb{F}_p$ exactly half of all nonzero elements are squares; the remainder
are non-squares or "quadratic non-residues". In order to see why, consider an $\alpha$ are non-squares or "quadratic non-residues". In order to see why, consider an $\alpha$
that generates the $2$-order multiplicative subgroup of $\mathbb{F}_p^\times$ (this always that generates the $2$-order multiplicative subgroup of $\mathbb{F}_p^\times$ (this exists
exists because $p - 1$ is divisible by $2$ since $p$ is prime) and $\beta$ that generates because $p - 1$ is divisible by $2$ since $p$ is a prime greater than $2$) and $\beta$ that
the $t$-order multiplicative subgroup of $\mathbb{F}_p^\times$ where $p - 1 = 2t$. Then generates the $t$-order multiplicative subgroup of $\mathbb{F}_p^\times$ where $p - 1 = 2t$.
every element $a \in \mathbb{F}_p^\times$ can be written uniquely as Then every element $a \in \mathbb{F}_p^\times$ can be written uniquely as
$\alpha^i \cdot \beta^j$ with $i \in \mathbb{Z}_2$ and $j \in \mathbb{Z}_t$. Half of all $\alpha^i \cdot \beta^j$ with $i \in \mathbb{Z}_2$ and $j \in \mathbb{Z}_t$. Half of all
elements will have $i = 0$ and the other half will have $i = 1$. elements will have $i = 0$ and the other half will have $i = 1$.
@ -226,10 +228,11 @@ The **primitive root of unity**, $\omega,$ is an $n$th root of unity such that
$\omega^i \neq 1$ except when $i \equiv 0 \pmod{n}$. $\omega^i \neq 1$ except when $i \equiv 0 \pmod{n}$.
Important notes: Important notes:
- if $\alpha$ is an $n$th root of unity, $\alpha$ satisfies $\alpha^n - 1 = 0.$ If
- If $\alpha$ is an $n$th root of unity, $\alpha$ satisfies $\alpha^n - 1 = 0.$ If
$\alpha \neq 1,$ then $\alpha \neq 1,$ then
$$1 + \alpha + \alpha^2 + \cdots + \alpha^{n-1} = 0.$$ $$1 + \alpha + \alpha^2 + \cdots + \alpha^{n-1} = 0.$$
- equivalently, the roots of unity are solutions to the equation - Equivalently, the roots of unity are solutions to the equation
$$X^n - 1 = (X - 1)(X - \alpha)(X - \alpha^2) \cdots (X - \alpha^{n-1}).$$ $$X^n - 1 = (X - 1)(X - \alpha)(X - \alpha^2) \cdots (X - \alpha^{n-1}).$$
- **$\boxed{\omega^{\frac{n}{2}+i} = -\omega^i}$ ("Negation lemma")**. Proof: - **$\boxed{\omega^{\frac{n}{2}+i} = -\omega^i}$ ("Negation lemma")**. Proof:
$$ $$
@ -245,7 +248,7 @@ Important notes:
(\omega^{\frac{n}{2}+i})^2 = \omega^{n + 2i} = \omega^{n} \cdot \omega^{2i} = \omega^{2i} = (\omega^i)^2. (\omega^{\frac{n}{2}+i})^2 = \omega^{n + 2i} = \omega^{n} \cdot \omega^{2i} = \omega^{2i} = (\omega^i)^2.
$$ $$
In other words, if we square each element in the $n$th roots of unity, we would get back In other words, if we square each element in the $n$th roots of unity, we would get back
only half the elements, $\{(\omega_n^i)^2\} = \{\omega_{n/2}\}$ (i.e. the $n/2$th roots only half the elements, $\{(\omega_n^i)^2\} = \{\omega_{n/2}\}$ (i.e. the $\frac{n}{2}$th roots
of unity). There is a two-to-one mapping between the elements and their squares. of unity). There is a two-to-one mapping between the elements and their squares.
## References ## References

View file

@ -208,9 +208,12 @@ $\frac{A(X) + B(X) - C(X)}{Z_H(X)} = H(X),$ we are satisfied that $A(X) + B(X) -
over $\mathcal{H}.$ over $\mathcal{H}.$
## Lagrange basis functions ## Lagrange basis functions
> TODO: explain what a basis is in general (briefly).
Polynomials are commonly written in the monomial basis (e.g. $X, X^2, ... X^n$). However, Polynomials are commonly written in the monomial basis (e.g. $X, X^2, ... X^n$). However,
when working over a multiplicative subgroup, we find a more natural expression in the when working over a multiplicative subgroup of order $n$, we find a more natural expression
Lagrange basis. in the Lagrange basis.
Consider the order-$n$ multiplicative subgroup $\mathcal{H}$ with primitive root of unity Consider the order-$n$ multiplicative subgroup $\mathcal{H}$ with primitive root of unity
$\omega$. The Lagrange basis corresponding to this subgroup is a set of functions $\omega$. The Lagrange basis corresponding to this subgroup is a set of functions
@ -231,7 +234,7 @@ Now, we can write our polynomial as a linear combination of Lagrange basis funct
$$A(X) = \sum_{i = 0}^{n-1} a_i\mathcal{L_i}(X), X \in \mathcal{H},$$ $$A(X) = \sum_{i = 0}^{n-1} a_i\mathcal{L_i}(X), X \in \mathcal{H},$$
which is equivalent to saying that $p(X)$ evaluates to $a_0$ at $\omega^0$, which is equivalent to saying that $p(X)$ evaluates to $a_0$ at $\omega^0$,
$p(\omega^1) = a_1, p(\omega^2) = a_2, \cdots,$ and so on. to $a_1$ at $\omega^1$, to $a_2$ at $\omega^2, \cdots,$ and so on.
When working over a multiplicative subgroup, the Lagrange basis function has a convenient When working over a multiplicative subgroup, the Lagrange basis function has a convenient
sparse representation of the form sparse representation of the form
@ -244,9 +247,9 @@ where $c_i$ is the barycentric weight. (To understand how this form was derived,
[^barycentric].) For $i = 0,$ we have [^barycentric].) For $i = 0,$ we have
$c = 1/n \implies \mathcal{L}_0(X) = \frac{1}{n} \frac{(X^{n} - 1)}{X - 1}$. $c = 1/n \implies \mathcal{L}_0(X) = \frac{1}{n} \frac{(X^{n} - 1)}{X - 1}$.
Suppose we are given a set of evaluation points $\{x_0, x_1, \cdots, x_{n-1}\}$.
Since we cannot assume that the $x_i$'s form a multiplicative subgroup, we consider also Since we cannot assume that the $x_i$'s form a multiplicative subgroup, we consider also
the Lagrange polynomials $\mathcal{L}_i$'s in the general case. Given a set of evaluation the Lagrange polynomials $\mathcal{L}_i$'s in the general case. Then we can construct:
points $\{x_0, x_1, \cdots, x_{n-1}\},$ we can construct
$$ $$
\mathcal{L}_i(X) = \prod_{j\neq i}\frac{X - x_j}{x_i - x_j}, i \in [0..n-1]. \mathcal{L}_i(X) = \prod_{j\neq i}\frac{X - x_j}{x_i - x_j}, i \in [0..n-1].
@ -255,7 +258,8 @@ $$
Here, every $X = x_j \neq x_i$ will produce a zero numerator term $(x_j - x_j),$ causing Here, every $X = x_j \neq x_i$ will produce a zero numerator term $(x_j - x_j),$ causing
the whole product to evaluate to zero. On the other hand, $X= x_i$ will evaluate to the whole product to evaluate to zero. On the other hand, $X= x_i$ will evaluate to
$\frac{x_i - x_j}{x_i - x_j}$ at every term, resulting in an overall product of one. This $\frac{x_i - x_j}{x_i - x_j}$ at every term, resulting in an overall product of one. This
gives the desired Kronecker delta behaviour $\mathcal{L_i}(x_j) = \delta_{ij}.$ gives the desired Kronecker delta behaviour $\mathcal{L_i}(x_j) = \delta_{ij}$ on the
set $\{x_0, x_1, \cdots, x_{n-1}\}$.
### Lagrange interpolation ### Lagrange interpolation
Given a polynomial in its evaluation representation Given a polynomial in its evaluation representation

View file

@ -1,7 +1,11 @@
# [WIP] UltraPLONK arithmetisation # [WIP] UltraPLONK arithmetisation
We work over a multiplicative subgroup
$\mathcal{H} =\{1, \omega, \omega^2, \cdots, \omega^{n-1}\},$ where $\omega$ is primitive We call the field over which the circuit is defined $\mathbb{F} = \mathbb{F}_p$.
root of unity, in the Lagrange basis corresponding to these points.
Let $n = 2^k$, and assume that $\omega$ is a primitive root of unity of order $n$ in
$\mathbb{F}^\times$, so that $\mathbb{F}^\times$ has a multiplicative subgroup
$\mathcal{H} = \{1, \omega, \omega^2, \cdots, \omega^{n-1}\}$. This forms a Lagrange
basis corresponding to the points in the subgroup.
## Polynomial rules ## Polynomial rules
A polynomial rule defines a constraint that must hold between its specified columns at A polynomial rule defines a constraint that must hold between its specified columns at