Check that the commitments in the proof open to the public inputs and the witnesses but with different bases and randomness. This function is only called by the prover, the verifier does not know `witnesses_expected_in_commitment` or `link_v`.
(
vk: &VerifyingKeyWithLink<E>,
proof: &ProofWithLink<E>,
public_inputs_count: usize,
witnesses_expected_in_commitment: &[E::ScalarField],
v: &E::ScalarField,
link_v: &E::Scala
| 411 | /// bases and randomness. This function is only called by the prover, the verifier does not |
| 412 | /// know `witnesses_expected_in_commitment` or `link_v`. |
| 413 | pub fn verify_commitments<E: Pairing>( |
| 414 | vk: &VerifyingKeyWithLink<E>, |
| 415 | proof: &ProofWithLink<E>, |
| 416 | public_inputs_count: usize, |
| 417 | witnesses_expected_in_commitment: &[E::ScalarField], |
| 418 | v: &E::ScalarField, |
| 419 | link_v: &E::ScalarField, |
| 420 | ) -> crate::Result<()> { |
| 421 | verify_link_commitment::<E>( |
| 422 | &vk.link_bases, |
| 423 | &proof.link_d, |
| 424 | witnesses_expected_in_commitment, |
| 425 | link_v, |
| 426 | )?; |
| 427 | verify_witness_commitment::<E>( |
| 428 | &vk.groth16_vk, |
| 429 | &proof.groth16_proof, |
| 430 | public_inputs_count, |
| 431 | witnesses_expected_in_commitment, |
| 432 | v, |
| 433 | ) |
| 434 | } |
| 435 | |
| 436 | /// Given the proof, verify that the commitment in it (`proof.d`) commits to the witness. |
| 437 | pub fn verify_witness_commitment<E: Pairing>( |
no outgoing calls