Open Pratyush opened 3 years ago
One question:
For the index
function, you mentioned "same for proving and verifying".
Do you mean that they remain unchanged? Or that you will add an index to it (which seems unnecessary, since the PK and VK suffice).
For the index function, you mentioned "same for proving and verifying".
By that I mean that proving will take in the ipk
and assignment (x, w)
explicitly, instead of taking in ipk
and CS: ConstraintSynthesizer
Summary
Introduce a low-level API for setup, indexing, proving, and verifying that directly reasons about the relation, instead of going via our
ConstraintSystem
API.Problem Definition
Right now, for proving R1CS via our
SNARK
traits, we have to go via theConstraintSynthesizer
(and henceConstraintSystem
) trait. This is unsatisfactory for a couple of reasons:1) Using our libraries with external R1CS formats like
zkinterface
incurs performance overheads because we have to convert toConstraintSystem
and then back to matrices, instead of directly reading the matrices from the external format. 2) Therelations
crate is at the moment more about data structures for working with a particular relation (R1CS) rather than about the relation itself. For example, theR1CS
relation consists of(i, x, w)
wherei
consists of theR1CS
matrices, andx
andw
are the public input and witness, respectively. However, the currentark_relations::r1cs
module doesn't have any data structure reflecting these, and only has data structures likeConstraintSystemRef
.Proposal
Add a
Relation
trait inrelations
that looks like:SNARK
trait as follows:Additionally, we add a new R1CS-specific trait:
(We might need equivalents for
PreprocessingSNARK
.)For Admin Use