-
Notifications
You must be signed in to change notification settings - Fork 0
Description
The paper uses polynomial amortization trick to maintain the communication cost of many nullity checks in a single nullity-check plus one additional
Since transcript (applied to FS transformation) before obtaining Pi_NULLITY_Proof. So much for adding P_secure (Essentially equals to P_vec) is enough to convert the code into Strong Fiat-Shamir Transformation.
I did some math and ensured that it may has no need to append transcript, for
TODO: It would also affect zk_amortized_7, but due to lack of research about amortized version of the paper, the pull request related to this issues would only change zk_protocol_7.