calculated result verification

Apr 22, 2015 at 5:33 AM
in the paper, the calculated result y is an input for verification, but it seems to me the verification procedure does not use the calculated result y. can some one elaborate it for me? any help is appreciated.
Coordinator
Apr 22, 2015 at 5:29 PM
Where are you looking in the code? In QAP::verify, both the call to computeDVio and to computePVio operate on the circuit inputs and the outputs.
Apr 23, 2015 at 6:08 AM
I was talking about the paper.
It seems to me the calculated result y is not used in the verification procedure.
I am not sure whether I understand it.

thanks.
Coordinator
Apr 23, 2015 at 5:13 PM
The result, y, is part of the IO, which is included in the g_v^{v_io(s)} term, as well as the corresponding w and y terms, in the divisibility check (the first bullet under the Verify algorithm).
Apr 23, 2015 at 7:32 PM
thank you! I did not read the text carefully. it does says "the I/O, u and y, by representing them as coefficients c1, ..., cN",
for which I have to thank fkraiem who told me that in
http://crypto.stackexchange.com/questions/25145/verification-of-pinocchio-verifiable-computation