{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,9]],"date-time":"2026-07-09T22:33:28Z","timestamp":1783636408849,"version":"3.55.0"},"reference-count":24,"publisher":"Association for Computing Machinery (ACM)","issue":"2","license":[{"start":{"date-parts":[[2016,1,25]],"date-time":"2016-01-25T00:00:00Z","timestamp":1453680000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["Commun. ACM"],"published-print":{"date-parts":[[2016,1,25]]},"abstract":"<jats:p>\n            To instill greater confidence in computations outsourced to the cloud, clients should be able to\n            <jats:italic>verify<\/jats:italic>\n            the correctness of the results returned. To this end, we introduce Pinocchio, a built system for efficiently verifying general computations while relying only on cryptographic assumptions. With Pinocchio, the client creates a public evaluation key to describe her computation; this setup is proportional to evaluating the computation once. The worker then evaluates the computation on a particular input and uses the evaluation key to produce a proof of correctness. The proof is only 288 bytes, regardless of the computation performed or the size of the IO. Anyone can check the proof using a public verification key.\n          <\/jats:p>\n          <jats:p>Crucially, our evaluation on seven applications demonstrates that Pinocchio is efficient in practice too. Pinocchio's verification time is a fixed 10 ms plus 0.4--15 \u03bcs per IO element: 5--7 orders of magnitude less than previous work; indeed Pinocchio is the first general-purpose system to demonstrate verification cheaper than native execution (for some apps). The worker's proof effort is still expensive, but Pinocchio reduces it by 19\u00d7--60\u00d7 relative to prior work. As an additional feature, Pinocchio allows the worker to include private inputs in the computation and prove that she performed the computation correctly without revealing any information about the private inputs to the client. Finally, to aid development, Pinocchio provides an end-to-end toolchain that compiles a subset of C into programs that implement the verifiable computation protocol.&lt;!-- END_PAGE_1 --&gt;<\/jats:p>","DOI":"10.1145\/2856449","type":"journal-article","created":{"date-parts":[[2016,1,26]],"date-time":"2016-01-26T13:25:01Z","timestamp":1453814701000},"page":"103-112","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":190,"title":["Pinocchio"],"prefix":"10.1145","volume":"59","author":[{"given":"Bryan","family":"Parno","sequence":"first","affiliation":[{"name":"Microsoft Research"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jon","family":"Howell","sequence":"additional","affiliation":[{"name":"Microsoft Research"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Craig","family":"Gentry","sequence":"additional","affiliation":[{"name":"IBM Research"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mariana","family":"Raykova","sequence":"additional","affiliation":[{"name":"SRI International"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2016,1,25]]},"reference":[{"key":"e_1_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1145\/278298.278306"},{"key":"e_1_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2014.36"},{"key":"e_1_2_1_3_1","volume-title":"Proceedings of USENIX Security","author":"Ben-Sasson E.","year":"2014","unstructured":"Ben-Sasson , E. , Chiesa , A. , Tromer , E. , Virza , M. Succinct non-interactive zero knowledge for a von Neumann architecture . In Proceedings of USENIX Security ( 2014 ). Ben-Sasson, E., Chiesa, A., Tromer, E., Virza, M. Succinct non-interactive zero knowledge for a von Neumann architecture. In Proceedings of USENIX Security (2014)."},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/2517349.2522733"},{"key":"e_1_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1145\/571637.571640"},{"key":"e_1_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/2038916.2038945"},{"key":"e_1_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/2090236.2090245"},{"key":"e_1_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/2517872.2517878"},{"key":"e_1_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.5555\/1881412.1881445"},{"key":"e_1_2_1_10_1","volume-title":"EUROCRYPT","author":"Gennaro R.","year":"2013","unstructured":"Gennaro , R. , Gentry , C. , Parno , B. , Raykova , M. Quadratic span programs and succinct NIZKs without PCPs . In EUROCRYPT ( 2013 ). Originally published as Cryptology ePrint Archive, Report 2012\/215. Gennaro, R., Gentry, C., Parno, B., Raykova, M. Quadratic span programs and succinct NIZKs without PCPs. In EUROCRYPT (2013). Originally published as Cryptology ePrint Archive, Report 2012\/215."},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/1374376.1374396"},{"key":"e_1_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.5555\/646139.680794"},{"key":"e_1_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1109\/CCC.2007.10"},{"key":"e_1_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/129712.129782"},{"key":"e_1_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISCA.2005.14"},{"key":"e_1_2_1_17_1","volume-title":"Proceedings of USENIX Security","author":"Meiklejohn S.","year":"2010","unstructured":"Meiklejohn , S. , Erway , C.C. , K\u00fcp\u00e7\u00fc , A. , Hinkle , T. , Lysyanskaya , A. ZKPDL : A language-based system for efficient zero-knowledge proofs and electronic cash . In Proceedings of USENIX Security ( 2010 ). Meiklejohn, S., Erway, C.C., K\u00fcp\u00e7\u00fc, A., Hinkle, T., Lysyanskaya, A. ZKPDL: A language-based system for efficient zero-knowledge proofs and electronic cash. In Proceedings of USENIX Security (2010)."},{"key":"e_1_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.5555\/1884265.1884275"},{"key":"e_1_2_1_19_1","doi-asserted-by":"crossref","DOI":"10.1007\/978-1-4614-1460-5","volume-title":"Bootstrapping Trust in Modern Computers","author":"Parno B.","year":"2011","unstructured":"Parno , B. , McCune , J.M. , Perrig , A. Bootstrapping Trust in Modern Computers . Springer , New York\/Dordrecht\/Heidelberg\/London, 2011 . DOI: 10.1007\/978-1-4614-1460-5. 10.1007\/978-1-4614-1460-5 Parno, B., McCune, J.M., Perrig, A. Bootstrapping Trust in Modern Computers. Springer, New York\/Dordrecht\/Heidelberg\/London, 2011. DOI: 10.1007\/978-1-4614-1460-5."},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-28914-9_24"},{"key":"e_1_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/2465351.2465359"},{"key":"e_1_2_1_22_1","volume-title":"Proceedings of the ISOC NDSS","author":"Setty S.","year":"2012","unstructured":"Setty , S. , McPherson , R. , Blumberg , A.J. , Walfish , M. Making argument systems for outsourced computation practical (sometimes) . In Proceedings of the ISOC NDSS ( 2012 ). Setty, S., McPherson, R., Blumberg, A.J., Walfish, M. Making argument systems for outsourced computation practical (sometimes). In Proceedings of the ISOC NDSS (2012)."},{"key":"e_1_2_1_23_1","volume-title":"Proceedings of USENIX Security","author":"Setty S.","year":"2012","unstructured":"Setty , S. , Vu , V. , Panpalia , N. , Braun , B. , Blumberg , A.J. , Walfish , M. Taking proof-based verified computation a few steps closer to practicality . In Proceedings of USENIX Security ( 2012 ). Setty, S., Vu, V., Panpalia, N., Braun, B., Blumberg, A.J., Walfish, M. Taking proof-based verified computation a few steps closer to practicality. In Proceedings of USENIX Security (2012)."},{"key":"e_1_2_1_24_1","volume-title":"The Very Large Databases Conference (VLDB)","author":"Sion R.","year":"2005","unstructured":"Sion , R. Query execution assurance for outsourced databases . In The Very Large Databases Conference (VLDB) ( 2005 ). Sion, R. Query execution assurance for outsourced databases. In The Very Large Databases Conference (VLDB) (2005)."},{"key":"e_1_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-40084-1_5"}],"container-title":["Communications of the ACM"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2856449","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2856449","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T04:54:12Z","timestamp":1750222452000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2856449"}},"subtitle":["nearly practical verifiable computation"],"short-title":[],"issued":{"date-parts":[[2016,1,25]]},"references-count":24,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2016,1,25]]}},"alternative-id":["10.1145\/2856449"],"URL":"https:\/\/doi.org\/10.1145\/2856449","relation":{},"ISSN":["0001-0782","1557-7317"],"issn-type":[{"value":"0001-0782","type":"print"},{"value":"1557-7317","type":"electronic"}],"subject":[],"published":{"date-parts":[[2016,1,25]]},"assertion":[{"value":"2016-01-25","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}