Skip to content

Consider blinding at top of polys in Ultra #1666

@ledwards2225

Description

@ledwards2225

Ultra ZK has sensitivity to the dyadic size of the circuit due to the fact that we blind in the last entries of the dyadic size. If we blind at the top instead, nearly everything should have cost proportional to actual gate count.

Note: Unfortunately this is probably not straightforward for Mega since the ecc op columns complicate things. Worth considering if there is an easy workaround but if not then seems ok to do it for Ultra only.

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions