|
|
@ -11245,8 +11245,8 @@ The same \quadraticConstraintProgram is used for compression and decompression. |
|
|
|
|
|
|
|
\pnote{ |
|
|
|
The point-on-curve check could be omitted if $(u, \varv)$ were already known to be on the curve. |
|
|
|
However, the \Sapling circuit never omits it \todo{CHECK}; this provides a redundant consistency |
|
|
|
check on the elliptic curve arithmetic in some cases. |
|
|
|
However, the \Sapling circuit never omits it; this provides a consistency check on the elliptic |
|
|
|
curve arithmetic. |
|
|
|
} |
|
|
|
|
|
|
|
|
|
|
|