Skip to content

ECCVM: properly handle transcript polynomial univariate evaluations #768

Description

@ledwards2225

The ECCVM needs to open the five ECC op transcript polynomials as univariates so consistency can be established in the Translator. This was overlooked in the original implementation. For now, we've introduced a new round to the ECCVM protocol that establishes a batched univariate opening claim for this purpose. This is inefficient in that it requires an entirely separate IPA opening protocol. Ideally we would find a way to batch everything into one IPA opening which may require shplonk.

Note: IPA cannot handle polynomials for which the latter half of the coefficients are 0. This arises in general for our transcript polynomials since the ECCVM has a large fixed size that may not be fully utilized. To get around this we simply batch the constant polynomial 1 in with the other 5. This is likely not a long term solution.

Activity

  1. added this to the RollupIVC milestone on Apr 15, 2024
  2. maramihali commented on Apr 16, 2024

    @maramihali

    Benchmark for native IPA
    image

  3. maramihali commented on Apr 16, 2024

    @maramihali

    Idea to avoid two IPA openings without reviving Shplonk: https://hackmd.io/_dcQgfPjTPutOopViZLv-Q

  4. maramihali commented on Jun 24, 2024

    @maramihali

    AztecProtocol/aztec-packages#7164 removes the need for a second opening but we still need the hack_polynomial for IPA to work.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions