partial-round-collapse.md
Ο 0.0%
Dimensions
hemera/reference/props/partial-round-collapse
partial-round collapse states [1..15] evolve linearly during all 16 partial rounds. precompute the composed linear map. break the sequential dependency for 15 of 16 state elements. ~4Γ prover wall-clock speedup. the observation in partial rounds, only state[0] gets the nonlinear xβ»ΒΉ S-box. statesβ¦