MCPcopy Create free account
hub / github.com/docknetwork/crypto / round_2

Method round_2

bulletproofs_plus_plus/src/range_proof.rs:417–444  ·  view source on GitHub ↗

Prover Round 2: Prover has committed to d_vec and m_vec in the previous round. Received challenge e. # The reciprocal commitment: R The prover computes the commitment R = r_r0 * G + + where r_i = (1/ (e + d_i)) r_r_i are chosen to be all zeros. As before, the values r_r0 being random is sufficient to prove that the commitment is hiding.

(
        &mut self,
        rng: &mut R,
        e: G::ScalarField,
        setup_params: &SetupParams<G>,
    )

Source from the content-addressed store, hash-verified

415 /// r_r_i are chosen to be all zeros. As before, the values r_r0 being random is sufficient to prove that the commitment is hiding.
416 ///
417 fn round_2<R: RngCore>(
418 &mut self,
419 rng: &mut R,
420 e: G::ScalarField,
421 setup_params: &SetupParams<G>,
422 ) {
423 // compute r_i = (1/ (e + d_i))
424 let mut r = cfg_iter!(self.r1_sec.as_ref().unwrap().d_vec)
425 .map(|x| (e + x))
426 .collect::<Vec<_>>();
427 batch_inversion(&mut r);
428
429 let mut r_r1_vec = ark_std::iter::repeat(G::ScalarField::zero())
430 .take(8)
431 .collect::<Vec<_>>();
432 {
433 // Balance out remaining terms in final l_vec
434 r_r1_vec[4] = -self.r1_sec.as_ref().unwrap().r_d1_vec[5].clone(); // T^7
435 r_r1_vec[1] = -self.r1_sec.as_ref().unwrap().r_d1_vec[2].clone(); // T^3
436 }
437 let (r_r0, R) = setup_params.gen_randomness_and_compute_commitment(rng, &r_r1_vec, &r);
438 self.r2_sec = Some(Round2Secrets {
439 r_vec: r,
440 r_r0,
441 r_r1_vec,
442 });
443 self.r2_comm = Some(Round2Commitments { R });
444 }
445
446 /// Prover Round 3: Prover has committed to r_vec in the previous round.
447 /// Received challenge (x, y, q, lambda, delta). Already has e from round 1

Callers 1

proveMethod · 0.80

Calls 4

mapMethod · 0.80
cloneMethod · 0.80
as_refMethod · 0.45

Tested by

no test coverage detected