Two candidate approaches for univariate sumcheck over roots of unity are presented. The first takes the form of a multilinear evaluation protocol, which can be combined with the standard multivariate sumcheck protocol. The other consists of a direct reduction from univariate sumcheck to multilinear evaluation, which can be combined with Gemini (Bootle et al., Eurocrypt 2022). Both approaches optionally support a very natural exponential round reduction from $m$ to $\log(m)$ while retaining asymptotically optimal linear prover time.
翻译:本文提出了两种在单位根上实现单变量求和校验的候选方案。第一种方案采用多线性求值协议的形式,可与标准多变量求和校验协议结合使用。另一种方案通过将单变量求和校验直接归约为多线性求值问题,可与Gemini协议(Bootle等人,Eurocrypt 2022)结合使用。两种方案均支持从$m$轮到$\log(m)$轮的指数级轮数缩减(此为可选项),同时保持渐进最优的线性证明者计算时间。