Skip to content

Plonk Prover Round 5 的一个问题 #77

Discussion options

You must be logged in to vote

In order for the verifier to be able to reconstruct the commitment to R, it has to be "linear" in the proof items, hence why we can only use each proof item once; any further multiplicands in each term need to be replaced with their evaluations at Z, which do still need to be provided

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by cyl19970726
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
1 participant