Zero-knowledge proof composition and recursion. Part 6: cycles of curves

Опубликовано: 04 Ноябрь 2024
на канале: David Wong
454
10

In this new series of video, following the series of videos on PLONK (    • How does PLONK work? Part 1: What's P...  ) I introduce the different ideas and schemes behind proof composition and proof recursion. In this series of videos we will go through pre-proof recursion schemes like Sangria and Nova, and IVC/PCD schemes following the BCTV14 paper, and later the Halo paper.

This video explains a detail used in a lot of recursive zero-knowledge protocols in order to efficiently implement verifier circuits: cycles of curves. It also introduces the Pasta curves: Pallas and Vesta.

The pasta curves: https://o1-labs.github.io/proof-syste...
BCTV14 (Succinct Non-Interactive Zero Knowledge for a von Neumann Architecture): https://eprint.iacr.org/2013/879

Timestamps

00:00 Scalar fields and base fields
04:28 The problem with the change of fields
05:34 Using more than one curve
07:18 Cycles of curves
08:10 The pasta curves
09:44 Where is this used?