matter-labs-archive / sapling-crypto

Zcash "Sapling" cryptography gadgets along with additions. Uses our Ethereum compatible bellman under the hood
Other
15 stars 9 forks source link

reduce baby_jubjub edwards addition constraints by one #1

Closed kobigurk closed 5 years ago

shamatar commented 5 years ago

Hello @kobigurk

Thank you for a pull request. May I ask you to also check if it's possible to make as efficient function, but using a set of formulas from here that do not even depend on the "a" parameter?

kobigurk commented 5 years ago

Interesting, thanks for the reference!

Formulas 3 and 9 seem to be useful as well for some cases, since pedersen hashes don't have point doublings involved. Can't promise, but I might take a look at this.

The proposed improvement is independent of this, though.