Plonk is a fast and flexible succinct non-interactive argument of knowledge that employs univariate polynomial commitments. In contrast, HyperPlonk utilizes multilinear polynomial commitments, preserving Plonk’s flexibility while eliminating the need for an FFT during proof generation. Both proof systems utilize the permutation argument to verify wire identity. We present a novel approach called permutation argument via bases transformation (PABT) for proving the wiring identity. Unlike existing methods that rely on the grand product check, PABT achieves this goal through bases transformations and polynomial evaluation protocols. The key insight lies in the utilization of Pedersen vector commitments, which allow for the conversion of commitment for wire values into commitment for permuted wire values via bases transformation. We point out that based on polynomial commitments similar to Pedersen vector commitments, our scheme will have better efficiency compared to permutation arguments based on grand product checks. Ultimately, we present two constructions of permutation arguments based on different proof systems: one utilizing Bulletproofs and the other employing Dory.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Permutation Argument via Bases Transformation

  • Yu Wang

摘要

Plonk is a fast and flexible succinct non-interactive argument of knowledge that employs univariate polynomial commitments. In contrast, HyperPlonk utilizes multilinear polynomial commitments, preserving Plonk’s flexibility while eliminating the need for an FFT during proof generation. Both proof systems utilize the permutation argument to verify wire identity. We present a novel approach called permutation argument via bases transformation (PABT) for proving the wiring identity. Unlike existing methods that rely on the grand product check, PABT achieves this goal through bases transformations and polynomial evaluation protocols. The key insight lies in the utilization of Pedersen vector commitments, which allow for the conversion of commitment for wire values into commitment for permuted wire values via bases transformation. We point out that based on polynomial commitments similar to Pedersen vector commitments, our scheme will have better efficiency compared to permutation arguments based on grand product checks. Ultimately, we present two constructions of permutation arguments based on different proof systems: one utilizing Bulletproofs and the other employing Dory.