secret
public
public
inner-product
commitment
collapse
\(v \stackrel{?}{=} g_1(0) + g_1(1)\)
\(g_1(\textcolor{grey}{r_1}) \stackrel{?}{=} g_2(0) + g_2(1)\)
\(g_{n-1}(\textcolor{grey}{r_{n-1}}) \stackrel{?}{=} g_n(0) + g_n(1)\)
\(g_{\mu}(\textcolor{grey}{r_{\mu}}) \stackrel{?}{=} f(\textcolor{grey}{r_1}, \textcolor{grey}{r_2}, \dots, \textcolor{grey}{r_\mu})\)
Hash-based
Pairing-based
IPA-based
Field size
Proof size
Hash-based
Pairing-based
IPA-based
Field size
Proof size
prover sends
verifier can compute
s.t.