zk-SNARK friends: I think I understand Kate polynomial commitments and QAP encodings. I'm trying to grok how to combine these s.t. verifier can check that a proof used the poly representing the "expected" program. Pinocchio uses these extra elements; help me see why this works?
Conversation
Haven't had a chance to read through the paper in full detail, but has a really good blog post sequence discussing Pinocchio protocol:
electriccoin.co/blog/snark-exp
See especially part 6 for an answer to your question I think...
1
2
Thank you, yes, part 6 helps! I now think I understand the role of the "alpha" encodings in the Pinocchio proof, but not yet why both those and also the "beta" summation term are necessary. Will keep at it…


