Repository navigation
🥷 Version 0.6.2: Add ZK-STARK section - #49
DarkWindman wants to merge 9 commits into
Conversation
|
|
||
| \begin{document} | ||
|
|
||
| In previous schemes, the verifier relied on algebraic structures: pairings in KZG, and group homomorphisms in Pedersen commitments. Here, we rely on nothing but hash functions. We need to verify that a committed function is a low-degree polynomial by examining only a few of its evaluations. Verifying this directly is impossible: the function could perfectly match a polynomial everywhere except at a single, unchecked point. |
There was a problem hiding this comment.
We need to verify that a committed function is a low-degree polynomial by examining only a few of its evaluations
Why do we even care about this and how that is related to hash functions ?
There was a problem hiding this comment.
I guess a reader would need some example which problem we try to solve (e.g. see or this more classical example with Fibonacci series).
There was a problem hiding this comment.
We discussed that with @DarkWindman and came to the same conclusion. The section will have more example and exercise blocks soon; the current version in non-finalized.
The Fibonacci example is nice and we will likely include it; the only problem is that this resource is too high-level, so we'll make sure to make it more rigor and suitable for our formalization.
| \end{equation*} | ||
| This representation admits non-determinism: the verification polynomials may have much lower degree than any polynomial that computes the next state. For instance, the transition $y = x^{-1}$ requires computing $x^{q-2}$, but it is verified by the degree-$2$ polynomial $xy - 1$. | ||
|
|
||
| \subsubsection{Trace interpolation} |
There was a problem hiding this comment.
Again, we need an example. Perhaps show how the mentioned before Fibonacci evaluation is encoded in AIR
| A non-zero polynomial $f \in \mathbb{F}[T]$ of degree $d$ has at most $d$ roots in $\mathbb{F}$. | ||
| \end{corollary} | ||
|
|
||
| Also, this might not be immediately obvious, but we can also divide polynomials in the same way as we divide integers. The result of division is not always a polynomial, so we also get a remainder. |
There was a problem hiding this comment.
By the way this sentence sounds cringy 🥲
| \subsection{Linear Codes} | ||
| %-------------------------------- | ||
| \begin{intuition} | ||
| Suppose the sender wants to send a message $m$ over a noisy channel. The sender first uses an encoding function to map the $k$ message symbols into $n$ symbols, called a \emph{codeword}, and then sends it over the channel. The receiver gets a \emph{received word} of $n$ symbols and tries to decode it, recovering the original $k$ message symbols. | ||
| \end{intuition} |
There was a problem hiding this comment.
I think we need a more gentle introduction. For instance, historically, why do we even care about error-correction codes (ECC) and what they achieve. What constructions can be built using ECC. Why do they matter in ZK?
| \end{intuition} | ||
|
|
||
| \begin{definition}[Code]\label{def:code} | ||
| A \emph{code} of block length $n$ over an alphabet $\Sigma$ is a subset $C \subseteq \Sigma^n$, whose elements are called \emph{codewords}. We write $M := |C|$ for the number of codewords and $k := \log_{|\Sigma|} M$ for the number of message symbols. An \emph{encoding} for $C$ is an injective map $E : \Sigma^k \to \Sigma^n$ whose image is $C$. |
There was a problem hiding this comment.
Again, everything is quite sudden. What is alphabet? Why do we need an encoding function? (answer: we want to extend the length of an input to add some additional redundant information such as parity bits, for example).
There was a problem hiding this comment.
Take a look at these lectures to get some intuition: https://www.canal-u.tv/chaines/inria/1-error-correcting-codes-and-cryptography
| \end{equation*} | ||
| \end{definition} | ||
|
|
||
| While comparing individual vectors is helpful, a code's effectiveness depends on the entire set. Specifically, we care about the distance between codewords, where the worst-case spacing between any two codewords is the defining metric. |
There was a problem hiding this comment.
"is the defining metric" sounds AI-ish :)
| and the \emph{relative minimum distance} of $C$ is $\mu(C) := \frac{1}{n} d_{\min}(C)$. | ||
| \end{definition} | ||
|
|
||
| The minimum distance is the foundation of error correction. If $d_{\min}(C) = d$, introducing fewer than $d$ errors will never result in another valid codeword. Furthermore, with fewer than $d/2$ errors, the corrupted string remains strictly closer to the original codeword than to any other. Essentially, a larger minimum distance forces codewords further apart, so the original codeword can be recovered as long as fewer than $d/2$ errors occur. |
There was a problem hiding this comment.
Some illustration would be nice
| \end{equation*} | ||
| from the codeword for $f(T)$. | ||
|
|
||
| Let $D$ be a subgroup of even order $n$ of the multiplicative group of the field, and let $\omega$ be a generator of this subgroup. Let $\{f(\omega^i)\}_{i=0}^{n-1}$ be the codeword for $f(T)$, corresponding to evaluation on $D$. Let $D^\star=\langle \omega^2\rangle$ be another domain of half the length, and let $\{f_E(\omega^{2i})\}_{i=0}^{n/2-1}$, $\{f_O(\omega^{2i})\}_{i=0}^{n/2-1}$ and $\{f^\star(\omega^{2i})\}_{i=0}^{n/2-1}$ be the codewords for $f_E(T)$, $f_O(T)$ and $f^\star(T)$, respectively, corresponding to evaluation on $D^\star$. As a result, we can rewrite the definition of $f^\star(T)$: |
There was a problem hiding this comment.
Just say that
The reader already knows this machinery from the NTT section
There was a problem hiding this comment.
Additionally, I don't like notation
| \begin{definition}[FRI protocol]\label{def:fri} | ||
| Let $f_0 := f$ be given on $D_0 := D = \langle \omega \rangle$ of order $n$, with $\deg f < k = 2^r$. | ||
| \begin{itemize} | ||
| \item \textbf{Commit phase.} For $i = 0, 1, \ldots, r-1$: |
| \begin{itemize} | ||
| \item \textbf{Commit phase.} For $i = 0, 1, \ldots, r-1$: | ||
| \begin{algoen} | ||
| \item the prover sends the Merkle root of the codeword of $f_i$ on $D_i$; |
There was a problem hiding this comment.
What is
| transformation (\Cref{subsection:fiat-shamir}): each challenge $\beta_i$ and each starting point $x_0$ | ||
| is derived by hashing the Merkle roots sent so far. | ||
| \end{remark} | ||
|
|
There was a problem hiding this comment.
As of now, I don't understand why I need to even verify
Additionally, as I've written above, we need definitions of IOPP (e.g., because it is not clear what security notions FRI should satisfy in the first place).
| \begin{definition}\label{def:aet} | ||
| Let $\mathbb{F}_q$ be the field of definition, and the computation describes the evolution of a state of $w$ registers for $\tau$ cycles. Then we define the \emph{algebraic execution trace (AET)} is the table of $\tau \times w$ field elements where every row describes the state of the system at the given point in time, and every column tracks the value of the given register. | ||
| \end{definition} |
There was a problem hiding this comment.
I am already lost here. I think since you are planning to rework this section, I will review it later
0e64969 to
3d3eb77
Compare
Objective
This PR adds ZK-STARKs to the book. Specifically, we include