G.Mercury, Both Ways at Once

This one needs a wider screen.

The walkthrough keeps the evaluation table, the two folds running out of its margins, the protocol transcript and the verifier's checks on screen together and steps them as one thing. The whole argument is that two different routes across that table arrive at the same number — which you cannot see if only one of them fits.

It needs at least 1024 × 600 logical pixels — a landscape tablet, a laptop, or a desktop.

this screen: —

On a tablet, turning it to landscape is usually enough. Otherwise open this page on a laptop or a desktop.

Read what it does instead →
G. Mercury, Both Ways at Once multilinear PCS walkthrough
Speed 1.1 s
ready
step 1 / 1

Protocol

click to jump

Transcript

nothing sent prover → verifier

The evaluation table

32 values, 4 × 8 row i = k mod 4 · column j = ⌊k / 4⌋
step 1 setup

Working

Two threads, one number

the committed table F — 4 × 8
fold rows by u₁ h = Ψu₁TF
fold columns by α g = F A
then evaluate at α h(α)
then evaluate at u₁ ĝ(u₁)
the linchpin
=
Both routes are the same sum over the table, taken in a different order.

Trust chain

0 of 4 links

What the verifier holds

Verifier checks

waiting