|
1 | 1 | extern crate bulletproofs; |
2 | | -use bulletproofs::r1cs::{ConstraintSystem, Prover, R1CSError, R1CSProof, Variable, Verifier}; |
| 2 | +use bulletproofs::r1cs::{ |
| 3 | + ConstraintSystem, Prover, R1CSError, R1CSProof, RandomizedConstraintSystem, Variable, Verifier, |
| 4 | +}; |
3 | 5 | use bulletproofs::{BulletproofGens, PedersenGens}; |
4 | 6 |
|
5 | 7 | #[macro_use] |
@@ -71,42 +73,51 @@ For K = 1: |
71 | 73 | struct KShuffleGadget {} |
72 | 74 |
|
73 | 75 | impl KShuffleGadget { |
74 | | - fn fill_cs<CS: ConstraintSystem>(cs: &mut CS, x: &[Variable], y: &[Variable]) { |
| 76 | + fn fill_cs<CS: ConstraintSystem>( |
| 77 | + cs: &mut CS, |
| 78 | + x: Vec<Variable>, |
| 79 | + y: Vec<Variable>, |
| 80 | + ) -> Result<(), R1CSError> { |
75 | 81 | let one = Scalar::one(); |
76 | | - let z = cs.challenge_scalar(b"k-scalar shuffle challenge"); |
77 | 82 |
|
78 | 83 | assert_eq!(x.len(), y.len()); |
79 | 84 |
|
80 | 85 | let k = x.len(); |
81 | 86 | if k == 1 { |
82 | 87 | cs.constrain([(x[0], -one), (y[0], one)].iter().collect()); |
83 | | - return; |
| 88 | + return Ok(()); |
84 | 89 | } |
85 | 90 |
|
86 | | - // Make last x multiplier for i = k-1 and k-2 |
87 | | - let (_, _, last_mulx_out) = cs.multiply(x[k - 1] - z, x[k - 2] - z); |
88 | | - |
89 | | - // Make multipliers for x from i == [0, k-3] |
90 | | - let first_mulx_out = (0..k - 2).rev().fold(last_mulx_out, |prev_out, i| { |
91 | | - let (_, _, o) = cs.multiply(prev_out.into(), x[i] - z); |
92 | | - o |
93 | | - }); |
94 | | - |
95 | | - // Make last y multiplier for i = k-1 and k-2 |
96 | | - let (_, _, last_muly_out) = cs.multiply(y[k - 1] - z, y[k - 2] - z); |
97 | | - |
98 | | - // Make multipliers for y from i == [0, k-3] |
99 | | - let first_muly_out = (0..k - 2).rev().fold(last_muly_out, |prev_out, i| { |
100 | | - let (_, _, o) = cs.multiply(prev_out.into(), y[i] - z); |
101 | | - o |
102 | | - }); |
103 | | - |
104 | | - // Constrain last x mul output and last y mul output to be equal |
105 | | - cs.constrain( |
106 | | - [(first_muly_out, -one), (first_mulx_out, one)] |
107 | | - .iter() |
108 | | - .collect(), |
109 | | - ); |
| 91 | + cs.specify_randomized_constraints(move |cs| { |
| 92 | + let z = cs.challenge_scalar(b"shuffle challenge"); |
| 93 | + |
| 94 | + // Make last x multiplier for i = k-1 and k-2 |
| 95 | + let (_, _, last_mulx_out) = cs.multiply(x[k - 1] - z, x[k - 2] - z); |
| 96 | + |
| 97 | + // Make multipliers for x from i == [0, k-3] |
| 98 | + let first_mulx_out = (0..k - 2).rev().fold(last_mulx_out, |prev_out, i| { |
| 99 | + let (_, _, o) = cs.multiply(prev_out.into(), x[i] - z); |
| 100 | + o |
| 101 | + }); |
| 102 | + |
| 103 | + // Make last y multiplier for i = k-1 and k-2 |
| 104 | + let (_, _, last_muly_out) = cs.multiply(y[k - 1] - z, y[k - 2] - z); |
| 105 | + |
| 106 | + // Make multipliers for y from i == [0, k-3] |
| 107 | + let first_muly_out = (0..k - 2).rev().fold(last_muly_out, |prev_out, i| { |
| 108 | + let (_, _, o) = cs.multiply(prev_out.into(), y[i] - z); |
| 109 | + o |
| 110 | + }); |
| 111 | + |
| 112 | + // Constrain last x mul output and last y mul output to be equal |
| 113 | + cs.constrain( |
| 114 | + [(first_muly_out, -one), (first_mulx_out, one)] |
| 115 | + .iter() |
| 116 | + .collect(), |
| 117 | + ); |
| 118 | + |
| 119 | + Ok(()) |
| 120 | + }) |
110 | 121 | } |
111 | 122 |
|
112 | 123 | pub fn prove<'a, 'b>( |
@@ -144,11 +155,8 @@ impl KShuffleGadget { |
144 | 155 | .map(|v| prover.commit(*v, Scalar::random(&mut blinding_rng))) |
145 | 156 | .unzip(); |
146 | 157 |
|
147 | | - let mut cs = prover.finalize_inputs(); |
148 | | - |
149 | | - Self::fill_cs(&mut cs, &input_vars, &output_vars); |
150 | | - |
151 | | - let proof = cs.prove()?; |
| 158 | + Self::fill_cs(&mut prover, input_vars, output_vars)?; |
| 159 | + let proof = prover.prove()?; |
152 | 160 |
|
153 | 161 | Ok((proof, input_commitments, output_commitments)) |
154 | 162 | } |
@@ -178,11 +186,8 @@ impl KShuffleGadget { |
178 | 186 | .map(|commitment| verifier.commit(*commitment)) |
179 | 187 | .collect(); |
180 | 188 |
|
181 | | - let mut cs = verifier.finalize_inputs(); |
182 | | - |
183 | | - Self::fill_cs(&mut cs, &input_vars, &output_vars); |
184 | | - |
185 | | - cs.verify(proof) |
| 189 | + Self::fill_cs(&mut verifier, input_vars, output_vars)?; |
| 190 | + verifier.verify(proof) |
186 | 191 | } |
187 | 192 | } |
188 | 193 |
|
|
0 commit comments