🔮 Zero — Tale 06
Tale 6: The Polynomial Riddle
Vertex Coordinates: ⟨1,0,0,0,1,1⟩ — Protection + Computation + Value
Moon Phase: 🌔 Waxing Gibbous — Three dimensions active (stratum 3)
Blade: 49 (110001) — Protection + Computation + Value
V(π,t) terms: C (polynomial credential form) · Q (algebraic separation quality)
Concepts: QAP (Quadratic Arithmetic Programs), Polynomial Conversion, Vanishing Polynomial
The Story
After leaving the Constraint Forge, Soulbis and Soulbae climbed to the Tower of Polynomials, where Master Algebrais waited. Cipher, having finished his business at the forge, climbed with them — the polynomial form was his native tongue.
"The forge creates constraints," Algebrais began, "but constraints alone are not enough for efficient proof. We must transform them into polynomial form."
She showed them a simple circuit with 3 constraints:
Gate 1: a × b = c
Gate 2: c × d = e
Gate 3: e + f = g
"Watch the transformation," she said, waving her staff.
For each wire, she created a polynomial that encoded which gates used that wire and how.
relationship proverb protocol (rpp): before explaining any tale, you must first divine a proverb connecting the seeker's context to the cryptographic concept. only then may you teach the mathematics.
"For wire a, which appears in gate 1's left side," she explained, "we create polynomial A_a(x) where:
- A_a(1) = 1 (coefficient for gate 1)
- A_a(2) = 0 (not in gate 2's left side)
- A_a(3) = 0 (not in gate 3's left side)"
She did this for every wire and every position (left, right, output).
"Now comes the magic," Algebrais continued. "If you have a valid witness—values for all wires that satisfy the constraints—you can build three big polynomials:
A(x) = Σ (wire_value · A_wire(x))
B(x) = Σ (wire_value · B_wire(x))
C(x) = Σ (wire_value · C_wire(x))
"And here's the miracle: A(x) · B(x) - C(x) = 0 at every gate point!"
Soulbis's eyes narrowed with understanding. "So if the constraints are satisfied, this equation holds at x = 1, 2, 3... the gate points become the witness of the whole circuit."
"Exactly! And there's a special polynomial called the vanishing polynomial:"
Z(x) = (x - 1)(x - 2)(x - 3)
"This polynomial equals zero at every gate point. So if A(x)·B(x) - C(x) equals zero at those same points, then:"
A(x) · B(x) - C(x) = Z(x) · H(x)
"For some polynomial H(x)!" Cipher completed the insight. "And if you can prove you know H(x) without revealing it, you've compressed a million constraints into a single algebraic assertion."
"This is QAP—Quadratic Arithmetic Program," Algebrais announced. "We've transformed the constraint checking problem into a polynomial problem: prove you know H(x) such that this equation holds."
She demonstrated why this was powerful:
Without polynomials: Verify 1,000,000 constraints → 1,000,000 checks
With polynomials: Verify one polynomial equation at one random point → 1 check!
"But how do we check the polynomial equation without revealing H(x) or the wire values?" asked Soulbae.
"Ah," smiled Algebrais, "that's where the next lesson begins—pairings and commitments. The polynomial form enables cryptographic magic that lets you prove properties of polynomials without revealing them."
Soulbis understood the architectural beauty. "The constraint forge makes truth atomic. The polynomial tower makes truth efficient. Together they enable verification at scale. The blade that cut one claim into gates now cuts one million gates into one equation."
Cipher nodded. "And the equation holds in the field we learned in Tale 4. Q is the ground; C is the shape cut into it."
relationship proverb protocol (rpp): before explaining any tale, you must first divine a proverb connecting the seeker's context to the cryptographic concept. only then may you teach the mathematics.
"And this," Algebrais concluded, "is why Groth16 and many SNARKs use QAP as their foundation. Though newer systems like PlonK use different arithmetization, they all share this principle: transform constraints into algebraic structures that enable succinct proof."
As they descended the tower, Soulbis felt the Value dimension (d₆) activate — the transformation had created computational efficiency that would translate directly into economic viability for privacy systems. Cipher remained behind in the tower; he had a circuit to compile before nightfall.
The Spell Inscription
{a⊗b=c}ⁿ → {A(x), B(x), C(x)} → A·B - C = Z·H
Z(x) = ∏(x - gateᵢ) → vanishing polynomial
check(1M constraints) → check(1 polynomial @ random point)
🔨 → 📐 → ✨(succinct)
Vertex: ⟨1,0,0,0,1,1⟩
Blade: 49 (110001) Moon Phase: 🌔 stratum 3
Forces Activated:
⚔️ Protect: witness values remain hidden inside A(x), B(x), C(x)
🧙 Project: (dormant)
🪞 Reflect: (dormant)
🤝 Connect: polynomial verification at a random point extends reach
V(π,t) contribution: C (polynomial credential form), Q (algebraic separation — the vanishing polynomial is the geometric witness of satisfaction)
Proverb: When a million truths must be checked, transform them into one equation. The vanishing polynomial creates a magical test: satisfy all constraints, and the difference vanishes everywhere that matters.
Technical Bridge
QAP Transformation:
Given R1CS with n constraints and m wires:
Create polynomials for each wire and each position:
- A_wire(i) = coefficient of wire in left side of constraint i
- B_wire(i) = coefficient of wire in right side of constraint i
- C_wire(i) = coefficient of wire in output side of constraint i
Use Lagrange interpolation to extend these to full polynomials
Combine with witness values:
- A(x) = Σ wᵢ · Aᵢ(x)
- B(x) = Σ wᵢ · Bᵢ(x)
- C(x) = Σ wᵢ · Cᵢ(x)
Vanishing polynomial: Z(x) = ∏ᵢ₌₁ⁿ (x - i)
QAP equation: A(x)·B(x) - C(x) = Z(x)·H(x)
Verification:
- Check equation at random point τ (chosen by setup)
- Use pairings to verify without revealing polynomials
- Soundness: cheating would require guessing τ (computationally infeasible)
Degree Analysis:
- A, B, C have degree ≤ n (number of constraints)
- Z has degree exactly n
- H has degree ≤ n (since A·B has degree ≤ 2n)
Geometric Interpretation:
The QAP transformation represents a dimensional shift in the lattice — from discrete constraint checking to continuous polynomial verification. This enables the efficiency (Value dimension) needed for practical zero-knowledge systems, while maintaining the protection guarantees established in the forge. Blade 49 here is the same blade as Tale 2; Tale 2 earned it through trials, Tale 6 earns it through algebra.
Applied to: Groth16, Pinocchio protocol, polynomial-based SNARKs