The Polynomial Commitment - notes.0xparc.org
There are many ways of constructing polynomial commitments, including the KZG commitment which relies on elliptic curves and the FRI commitment. Binius will rely on a different kind of polynomial commitment, which has the advantage that it can be made compatible with bits without much memory overhead. Suppose we’d like a way for the prover to commit to some data w ¯ 𝑤 ¯ in a way that’s compatible with the verifier learning (with help from the prover) a value w ̃ (ζ) 𝑤 ~ ( 𝜁 ) in the multilinear extension of w ¯ 𝑤 ¯ where ζ∈ 𝔽 m 𝜁 ∈ 𝐹 𝑚 . As a first attempt, one could simply have the prover hash the values w ¯ 𝑤 ¯ , but there’s not a good way to reveal the value w ̃ (ζ) 𝑤 ~ ( 𝜁 ) without opening the entire commitment and computing w ̃ (ζ) 𝑤 ~ ( 𝜁 ) from scratch. Alternatively, one could write down all the values of w ̃ 𝑤 ~ over 𝔽 m 𝐹 𝑚 and commit to these. The benefit of this approach is that revealing w ̃ (ζ) 𝑤 ~ ( 𝜁 ) requires just opening the
The Polynomial Commitment - notes.0xparc.org Toggle navigation notes.0xparc.org Research Notes Problems Results Search More 0xPARC The Polynomial Commitment The Brakedown Polynomial Commitment The Commitment The Binius Polynomial Commitment The Tower Field Testing and Evaluation Complexity The Polynomial Commitment There are many ways of constructing polynomial commitments, including the KZG commitment which relies on elliptic curves and the FRI commitment. Binius will rely on a different kind of polynomial commitment, which has the advantage that it can be made compatible with bits without mu
Explore this link on the map →related reading
- Binius: highly efficient proofs over binary fieldsvitalik.eth.limo
- Applied Crypto #2: Polynomial Commitments | ZK Learning Resourceslearn.0xparc.org
- KZG polynomial commitments · Dankrad Feistdankradfeist.de
- Commitment scheme - Wikipediaen.wikipedia.org
- Math & Engineeringxn--2-umb.com
- Arithmetization II. “We Need To Go Deeper” | by StarkWare | StarkWare | Mediummedium.com
- ProofsArgsAndZK.pdfpeople.cs.georgetown.edu
- Inner Product Arguments · Dankrad Feistdankradfeist.de
- Explaining Halo 2 - Electric Coin Companyelectriccoin.co
- STARKs, Part I: Proofs with Polynomialsvitalik.eth.limo
- STARKs, Part II: Thank Goodness It's FRI-dayvitalik.eth.limo
- Halo and more: exploring incremental verification and SNARKs without pairingsvitalik.eth.limo