PLONKish Arithmetization - The halo2 Book
The arithmetization used by Halo 2 comes from PLONK, or more precisely its extension UltraPLONK that supports custom gates and lookup arguments. We'll call it PLONKish. PLONKish circuits are defined in terms of a rectangular matrix of values. We refer to rows, columns, and cells of this matrix with the conventional meanings. A PLONKish circuit depends on a configuration: A finite field F, where cell values (for a given statement and witness) will be elements of F. The number of columns in the matrix, and a specification of each column as being fixed, advice, or instance. Fixed columns are fixed by the circuit; advice columns correspond to witness values; and instance columns are normally used for public inputs (technically, they can be used for any elements shared between the prover and verifier). A subset of the columns that can participate in equality constraints. A maximum constraint degree. A sequence of polynomial constraints. These are multivariate polynomials over F that must ev
PLONKish Arithmetization - The halo2 Book Keyboard shortcuts Press ← or → to navigate between chapters Press S or / to search in the book Press ? to show this help Press Esc to hide this help Auto Light Rust Coal Navy Ayu The halo2 Book PLONKish Arithmetization The arithmetization used by Halo 2 comes from PLONK , or more precisely its extension UltraPLONK that supports custom gates and lookup arguments. We’ll call it PLONKish . PLONKish circuits are defined in terms of a rectangular matrix of values. We refer to rows , columns , and cells of this matrix with the conventional meanings. A PLONK
Explore this link on the map →related reading
- Honey I SNARKED the GPT - EZKL Blogblog.ezkl.xyz
- A High-Level Technical Overview of Fully Homomorphic Encryption || Math ∩ Programmingjeremykun.com
- Chips - The halo2 Bookzcash.github.io
- From AIRs to RAPs - how PLONK-style arithmetization works - HackMDhackmd.io
- Lookup argument - The halo2 Bookzcash.github.io
- Pearl Whitepaperpearlresearch.ai
- ZK-Friendly Hash Functions | Zellic — Researchzellic.io
- HyperPlonk: Plonk with Linear-Time Prover and High-Degree Custom Gateseprint.iacr.org
- Explaining Halo 2 - Electric Coin Companyelectriccoin.co
- Binius: highly efficient proofs over binary fieldsvitalik.eth.limo
- 17 misconceptions about SNARKs - a16z cryptoa16zcrypto.com
- Arithmetic Circuits for ZK | RareSkillsrareskills.io