|
| 1 | +#[macro_use] |
| 2 | +extern crate criterion; |
| 3 | + |
| 4 | +use halo2_proofs::arithmetic::FieldExt; |
| 5 | +use halo2_proofs::circuit::{Layouter, SimpleFloorPlanner, Value}; |
| 6 | +use halo2_proofs::plonk::*; |
| 7 | +use halo2_proofs::poly::kzg::multiopen::VerifierGWC; |
| 8 | +use halo2_proofs::poly::{commitment::ParamsProver, Rotation}; |
| 9 | +use halo2_proofs::transcript::{Blake2bRead, Blake2bWrite, Challenge255}; |
| 10 | +use halo2curves::bn256::{Bn256, G1Affine}; |
| 11 | +use halo2curves::pairing::Engine; |
| 12 | +use rand_core::OsRng; |
| 13 | + |
| 14 | +use halo2_proofs::{ |
| 15 | + poly::{ |
| 16 | + kzg::{ |
| 17 | + commitment::{KZGCommitmentScheme, ParamsKZG}, |
| 18 | + multiopen::ProverGWC, |
| 19 | + strategy::SingleStrategy, |
| 20 | + }, |
| 21 | + }, |
| 22 | + transcript::{TranscriptReadBuffer, TranscriptWriterBuffer}, |
| 23 | +}; |
| 24 | + |
| 25 | +use std::marker::PhantomData; |
| 26 | + |
| 27 | +use criterion::{BenchmarkId, Criterion}; |
| 28 | + |
| 29 | +fn criterion_benchmark(c: &mut Criterion) { |
| 30 | + #[derive(Clone, Default)] |
| 31 | + struct MyCircuit<F: FieldExt> { |
| 32 | + _marker: PhantomData<F>, |
| 33 | + } |
| 34 | + |
| 35 | + #[derive(Clone)] |
| 36 | + struct MyConfig { |
| 37 | + selector: Selector, |
| 38 | + table: TableColumn, |
| 39 | + advice: Column<Advice>, |
| 40 | + other_advice: Column<Advice>, |
| 41 | + } |
| 42 | + |
| 43 | + impl<F: FieldExt> Circuit<F> for MyCircuit<F> { |
| 44 | + type Config = MyConfig; |
| 45 | + type FloorPlanner = SimpleFloorPlanner; |
| 46 | + |
| 47 | + fn without_witnesses(&self) -> Self { |
| 48 | + Self::default() |
| 49 | + } |
| 50 | + |
| 51 | + fn configure(meta: &mut ConstraintSystem<F>) -> MyConfig { |
| 52 | + let config = MyConfig { |
| 53 | + selector: meta.complex_selector(), |
| 54 | + table: meta.lookup_table_column(), |
| 55 | + advice: meta.advice_column(), |
| 56 | + other_advice: meta.advice_column(), |
| 57 | + }; |
| 58 | + |
| 59 | + let dummy_selector = meta.complex_selector(); |
| 60 | + |
| 61 | + meta.create_gate("degree 6 gate", |meta| { |
| 62 | + let dummy_selector = meta.query_selector(dummy_selector); |
| 63 | + let constraints = vec![dummy_selector.clone(); 4].iter().fold(dummy_selector.clone(), |acc, val| acc * val.clone()); |
| 64 | + Constraints::with_selector(dummy_selector, Some(constraints)) |
| 65 | + }); |
| 66 | + |
| 67 | + meta.lookup("lookup", |meta| { |
| 68 | + let advice = meta.query_advice(config.advice, Rotation::cur()); |
| 69 | + vec![(advice, config.table)] |
| 70 | + }); |
| 71 | + |
| 72 | + meta.lookup("lookup", |meta| { |
| 73 | + let advice = meta.query_advice(config.advice, Rotation::cur()); |
| 74 | + vec![(advice, config.table)] |
| 75 | + }); |
| 76 | + |
| 77 | + meta.lookup("lookup", |meta| { |
| 78 | + let advice = meta.query_advice(config.advice, Rotation::cur()); |
| 79 | + vec![(advice, config.table)] |
| 80 | + }); |
| 81 | + |
| 82 | + meta.lookup("lookup", |meta| { |
| 83 | + let advice = meta.query_advice(config.advice, Rotation::cur()); |
| 84 | + vec![(advice, config.table)] |
| 85 | + }); |
| 86 | + |
| 87 | + meta.lookup("lookup", |meta| { |
| 88 | + let advice = meta.query_advice(config.advice, Rotation::cur()); |
| 89 | + vec![(advice, config.table)] |
| 90 | + }); |
| 91 | + |
| 92 | + /* |
| 93 | + - We need degree at least 6 because 6 - 1 = 5 and we need to go to extended domain of 8n |
| 94 | + - Our goal is to get to max degree of 9 because now 9 - 1 = 8 and that will fit into domain |
| 95 | + |
| 96 | + - base degree = table_deg + 2 |
| 97 | + - if we put input_expression_degree = 1 |
| 98 | + => degree = base + 1 = 3 + 1 = 4 |
| 99 | + - we can batch one more with 5 more lookups |
| 100 | + */ |
| 101 | + |
| 102 | + config |
| 103 | + } |
| 104 | + |
| 105 | + fn synthesize( |
| 106 | + &self, |
| 107 | + config: MyConfig, |
| 108 | + mut layouter: impl Layouter<F>, |
| 109 | + ) -> Result<(), Error> { |
| 110 | + layouter.assign_table( |
| 111 | + || "8-bit table", |
| 112 | + |mut table| { |
| 113 | + for row in 0u64..(1 << 8) { |
| 114 | + table.assign_cell( |
| 115 | + || format!("row {}", row), |
| 116 | + config.table, |
| 117 | + row as usize, |
| 118 | + || Value::known(F::from(row)), |
| 119 | + )?; |
| 120 | + } |
| 121 | + |
| 122 | + Ok(()) |
| 123 | + }, |
| 124 | + )?; |
| 125 | + |
| 126 | + layouter.assign_region( |
| 127 | + || "assign values", |
| 128 | + |mut region| { |
| 129 | + for offset in 0u64..(1 << 10) { |
| 130 | + config.selector.enable(&mut region, offset as usize)?; |
| 131 | + region.assign_advice( |
| 132 | + || format!("offset {}", offset), |
| 133 | + config.advice, |
| 134 | + offset as usize, |
| 135 | + || Value::known(F::from((offset % 256))), |
| 136 | + )?; |
| 137 | + } |
| 138 | + for offset in 1u64..(1 << 10) { |
| 139 | + config.selector.enable(&mut region, offset as usize)?; |
| 140 | + region.assign_advice( |
| 141 | + || format!("offset {}", offset), |
| 142 | + config.other_advice, |
| 143 | + offset as usize - 1, |
| 144 | + || Value::known(F::from((offset % 256))), |
| 145 | + )?; |
| 146 | + } |
| 147 | + Ok(()) |
| 148 | + }, |
| 149 | + ) |
| 150 | + } |
| 151 | + } |
| 152 | + |
| 153 | + fn keygen(k: u32) -> (ParamsKZG<Bn256>, ProvingKey<G1Affine>) { |
| 154 | + let params: ParamsKZG<Bn256> = ParamsKZG::new(k); |
| 155 | + let empty_circuit: MyCircuit<<Bn256 as Engine>::Scalar> = MyCircuit { |
| 156 | + _marker: PhantomData, |
| 157 | + }; |
| 158 | + let vk = keygen_vk(¶ms, &empty_circuit).expect("keygen_vk should not fail"); |
| 159 | + let pk = keygen_pk(¶ms, vk, &empty_circuit).expect("keygen_pk should not fail"); |
| 160 | + (params, pk) |
| 161 | + } |
| 162 | + |
| 163 | + fn prover(k: u32, params: &ParamsKZG<Bn256>, pk: &ProvingKey<G1Affine>) -> Vec<u8> { |
| 164 | + let rng = OsRng; |
| 165 | + |
| 166 | + let circuit: MyCircuit<<Bn256 as Engine>::Scalar> = MyCircuit { |
| 167 | + _marker: PhantomData, |
| 168 | + }; |
| 169 | + |
| 170 | + let mut transcript = Blake2bWrite::<_, _, Challenge255<G1Affine>>::init(vec![]); |
| 171 | + create_proof::<KZGCommitmentScheme<Bn256>, ProverGWC<'_, Bn256>, _, _, _, _>( |
| 172 | + params, |
| 173 | + pk, |
| 174 | + &[circuit], |
| 175 | + &[&[]], |
| 176 | + rng, |
| 177 | + &mut transcript, |
| 178 | + ) |
| 179 | + .expect("proof generation should not fail"); |
| 180 | + transcript.finalize() |
| 181 | + } |
| 182 | + |
| 183 | + fn verifier(params: &ParamsKZG<Bn256>, vk: &VerifyingKey<G1Affine>, proof: &[u8]) { |
| 184 | + let strategy = SingleStrategy::new(params); |
| 185 | + let mut transcript = Blake2bRead::<_, _, Challenge255<G1Affine>>::init(proof); |
| 186 | + assert!(verify_proof::< |
| 187 | + KZGCommitmentScheme<Bn256>, |
| 188 | + VerifierGWC<'_, Bn256>, |
| 189 | + Challenge255<G1Affine>, |
| 190 | + Blake2bRead<&[u8], G1Affine, Challenge255<G1Affine>>, |
| 191 | + SingleStrategy<'_, Bn256>, |
| 192 | + >(params, vk, strategy, &[&[]], &mut transcript) |
| 193 | + .is_ok()); |
| 194 | + } |
| 195 | + |
| 196 | + let k_range = 16..=16; |
| 197 | + |
| 198 | + let mut keygen_group = c.benchmark_group("plonk-keygen"); |
| 199 | + keygen_group.sample_size(10); |
| 200 | + for k in k_range.clone() { |
| 201 | + keygen_group.bench_with_input(BenchmarkId::from_parameter(k), &k, |b, &k| { |
| 202 | + b.iter(|| keygen(k)); |
| 203 | + }); |
| 204 | + } |
| 205 | + keygen_group.finish(); |
| 206 | + |
| 207 | + let mut prover_group = c.benchmark_group("plonk-prover"); |
| 208 | + prover_group.sample_size(10); |
| 209 | + for k in k_range.clone() { |
| 210 | + let (params, pk) = keygen(k); |
| 211 | + |
| 212 | + prover_group.bench_with_input( |
| 213 | + BenchmarkId::from_parameter(k), |
| 214 | + &(k, ¶ms, &pk), |
| 215 | + |b, &(k, params, pk)| { |
| 216 | + b.iter(|| prover(k, params, pk)); |
| 217 | + }, |
| 218 | + ); |
| 219 | + } |
| 220 | + prover_group.finish(); |
| 221 | + |
| 222 | + let mut verifier_group = c.benchmark_group("plonk-verifier"); |
| 223 | + for k in k_range { |
| 224 | + let (params, pk) = keygen(k); |
| 225 | + let proof = prover(k, ¶ms, &pk); |
| 226 | + |
| 227 | + verifier_group.bench_with_input( |
| 228 | + BenchmarkId::from_parameter(k), |
| 229 | + &(¶ms, pk.get_vk(), &proof[..]), |
| 230 | + |b, &(params, vk, proof)| { |
| 231 | + b.iter(|| verifier(params, vk, proof)); |
| 232 | + }, |
| 233 | + ); |
| 234 | + } |
| 235 | + verifier_group.finish(); |
| 236 | +} |
| 237 | + |
| 238 | +criterion_group!(benches, criterion_benchmark); |
| 239 | +criterion_main!(benches); |
0 commit comments