ZKP8.2 FRI (Univariate) Polynomial Commitment

ZKP学习笔记

ZK-Learning MOOC课程笔记

Lecture 8: FRI-based Polynomial Commitments and Fiat-Shamir (Justin Thaler)

8.2 FRI (Univariate) Polynomial Commitment

  • Recall: Univariate Polynomial Commitments
    ZKP8.2 FRI (Univariate) Polynomial Commitment_第1张图片

  • Initial Attempt from Lecture 4 (Merkle Tree)
    ZKP8.2 FRI (Univariate) Polynomial Commitment_第2张图片

ZKP8.2 FRI (Univariate) Polynomial Commitment_第3张图片

  • Fixing the first problem (Want P time linear in degree, not field size)
    ZKP8.2 FRI (Univariate) Polynomial Commitment_第4张图片

在这里插入图片描述

  • Biger blowup factor -> more prover time, less verifier time, shorter proofs
  • The key subset: roots of unity
    ZKP8.2 FRI (Univariate) Polynomial Commitment_第5张图片

ZKP8.2 FRI (Univariate) Polynomial Commitment_第6张图片

  • Example
    ZKP8.2 FRI (Univariate) Polynomial Commitment_第7张图片

ZKP8.2 FRI (Univariate) Polynomial Commitment_第8张图片

  • Fixing the second problem

    • Merkle tree does not tell you any structure of the vertor at all
      ZKP8.2 FRI (Univariate) Polynomial Commitment_第9张图片

    • The (interactive) low-degree test: Folding Phase
      ZKP8.2 FRI (Univariate) Polynomial Commitment_第10张图片

      • Example
        ZKP8.2 FRI (Univariate) Polynomial Commitment_第11张图片
    • The (interactive) low-degree test: Query Phase
      ZKP8.2 FRI (Univariate) Polynomial Commitment_第12张图片

  • Back to the folding phase: more details

    • The (interactive) low-degree test: Folding Phase
      ZKP8.2 FRI (Univariate) Polynomial Commitment_第13张图片

ZKP8.2 FRI (Univariate) Polynomial Commitment_第14张图片

  • Example
    ZKP8.2 FRI (Univariate) Polynomial Commitment_第15张图片

  • The (interactive) low-degree test: Folding Phase
    ZKP8.2 FRI (Univariate) Polynomial Commitment_第16张图片

  • Compare to Lecture 7
    ZKP8.2 FRI (Univariate) Polynomial Commitment_第17张图片

你可能感兴趣的:(零知识证明,零知识证明,笔记)