Source: Proofs, Arguments, and Zero-Knowledge, chapter 10.3.1
Let be a univariate polynomial of degree defined over a field with a multiplicative subgroup with . Then, iff. there exists polynomials (degree ) and such that:
where is the vanishing polynomial of :
→ The prover sends , , and → The prover requests evaluation proofs for all polynomials at a random point to check the identity