kayabaNerve / full-chain-membership-proofs

18 stars 1 forks source link

Application of divisors to efficiently prove addition in-circuit hasn't been reviewed #23

Open kayabaNerve opened 1 year ago

kayabaNerve commented 1 year ago

While divisors are understood, being part of the underlying geometry of elliptic curves and in-use in pairing-curve-based solutions, this application from Eagen is novel. We should have it, and the efficiency gains via logarithmic derivatives, reviewed. Specifically, the first interpolation check provided in 3.2 of https://eprint.iacr.org/2022/596, and the ability to simplify it with logarithmic derivatives (yet not the z coordinate work as we do not use it, which is notable as the provided logarithmic derivative transform is for the z coordinate solution, making our transform distinct from anything directly in paper).