IP Library › Granted Patent US 12,732,341
Granted Patent B2
US 12,732,341 · App. 18/695,676 · Granted Sep 8, 2026

Secure computation using multi-party computation and a trusted execution environment

Inventors: Gang Wang (Mountain View, CA); Marcel M. Moti Yung (Mountain View, CA)
Assignee: Google LLC
H04L9/008H04L9/0618H04L9/085
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,732,341
App. No.
18/695,676
Granted
Sep 8, 2026
Kind
B2
Abstract

Methods, systems, and apparatus, including computer programs encoded on a computer storage medium, for using cryptography, secure MPC, and a TEE to perform computations in ways that preserve data privacy and protect the security of data of each party that is involved in the computation process. In one aspect, a first MPC system of a cluster of MPC systems receives, from a computing system, a first secret share of input data. The first MPC system sends, to an application running in a TEE separate from the cluster of MPC systems, first secret shares of a set of data items generated based at least in part on the first secret share of the input data. The application is configured to generate secret shares of application output data. The first MPC system performs, in collaboration with the one or more second MPC systems of the cluster, one or more secure multi-party computations.

Claims (55)

1 . A computer-implemented method comprising:

receiving, from a computing system and by a first multi-party computation (MPC) system of a cluster of MPC systems, a first secret share of input data;

sending, by the first MPC system and to an application running in a trusted execution environment (TEE) separate from the cluster of MPC systems, first secret shares of a set of data items generated based at least in part on the first secret share of the input data, wherein the application is configured to generate secret shares of application output data, the secret shares of the application output data generated based on one or more computations using plaintext values of the set of data items, the plaintext values of the set of data items being generated using (i) the first secret shares of the set of data items and (ii) respective second secret shares of the set of data items provided by one or more second MPC systems of the cluster;

performing, by the first MPC system in collaboration with the one or more second MPC systems of the cluster, one or more secure multi-party computations using: (i) the first secret share of the input data, (ii) a respective second secret share of the input data received by each of the one or more second MPC systems, (iii) a first secret share of the output data received from the application by the first MPC system, and (iv) a respective second secret share of the output data received from the application by each of the one or more second MPC systems; and

sending, by the first MPC system, a first secret share of result data resulting from the one or more secure multi-party computations to at least one of (i) the computing system or (ii) one or more additional computing systems different from the computing system.

2 . The computer-implemented method of claim 1 , wherein the computing system generates plaintext result data by combining the first secret share of the result data with a respective secret share of the result data received from each of the one or more second MPC systems.

3 . The computer-implemented method of claim 1 , wherein the application is configured to:

compute plaintext values of the set of data items by combining the first secret shares of the set of data items with respective second secret shares of the set of data items received from the one or more second MPC systems;

perform one or more computations using at least the plaintext values of the second set of data items;

generate secret shares of application output data generated based on the one or more computations;

provide the first secret share of the application output data to the first MPC system; and

provide, to each second MPC system, the respective second secret share of the application output data for the second MPC system.

4 . The computer-implemented method of claim 1 , further comprising:

receiving, from the computing system by the first MPC system, a respective encrypted second secret share of the input data for each of the one or more second MPC systems; and

providing, by the first MPC system to each second MPC system, the respective encrypted second secret share of the input data for the second MPC system.

5 . The computer-implemented method of claim 4 , wherein the first MPC system receives the first secret share of the input data and the respective encrypted second secret share of the input data for each of the one or more second MPC systems in a composite request sent from the computing system.

6 . The computer-implemented method of claim 1 , wherein sending, by the first MPC system, a first secret share of result data resulting from the one or more secure multi-party computations to the computing system comprises sending a composite message comprising the first secret share of the result data and respective encrypted second secret shares of the result data received from the one or more second MPC systems.

7 . The computer-implemented method of claim 1 , wherein sending, by the first MPC system, the first secret shares of the set of the data items to the application comprises sending, to the application, a composite message comprising the first secret shares of the set of data items and respective encrypted second secret shares of the set of data items received from the one or more second MPC systems.

8 . The computer-implemented method of claim 7 , further comprising:

receiving, from the application by the first MPC system, the first secret share of the application output data and a respective encrypted second secret share of the application output data for each of the one or more second MPC systems; and

providing, to each second MPC system, the respective encrypted second secret shares of the application output data.

9 . The method of claim 1 , further comprising verifying trustworthiness of the application running in the TEE prior to sending the first secret shares of the first set of data items to the application.

10 . The method of claim 1 , wherein the one or more computations performed by the application comprise (i) one or more vector dot product computations, (ii) one or more sorting operations, or (iii) a combination of (i) and (ii).

11 . The method of claim 1 , further comprising generating the first secret shares of the set of data items based on the first secret share of the input data and additional data stored by the first MPC system.

12 . A system comprising:

one or more processors; and

one or more storage devices storing instructions that, when executed by the one or more processors, cause the one or more processor to perform operations comprising:

receiving, from a computing system and by a first multi-party computation (MPC) system of a cluster of MPC systems, a first secret share of input data;

sending, by the first MPC system and to an application running in a trusted execution environment (TEE) separate from the cluster of MPC systems, first secret shares of a set of data items generated based at least in part on the first secret share of the input data, wherein the application is configured to generate secret shares of application output data, the secret shares of the application output data generated based on one or more computations using plaintext values of the set of data items, the plaintext values of the set of data items being generated using (i) the first secret shares of the set of data items and (ii) respective second secret shares of the set of data items provided by one or more second MPC systems of the cluster;

performing, by the first MPC system in collaboration with the one or more second MPC systems of the cluster, one or more secure multi-party computations using: (i) the first secret share of the input data, (ii) a respective second secret share of the input data received by each of the one or more second MPC systems, (iii) a first secret share of the output data received from the application by the first MPC system, and (iv) a respective second secret share of the output data received from the application by each of the one or more second MPC systems; and

sending, by the first MPC system, a first secret share of result data resulting from the one or more secure multi-party computations to at least one of (i) the computing system or (ii) one or more additional computing systems different from the computing system.

13 . The system of claim 12 , wherein the operations further comprise:

generating plaintext result data by combining the first secret share of the result data with a respective secret share of the result data received from each of the one or more second MPC systems.

14 . The system of claim 12 , wherein the application is configured to:

compute plaintext values of the set of data items by combining the first secret shares of the set of data items with respective second secret shares of the set of data items received from the one or more second MPC systems;

perform one or more computations using at least the plaintext values of the second set of data items;

generate secret shares of application output data generated based on the one or more computations;

provide the first secret share of the application output data to the first MPC system; and

provide, to each second MPC system, the respective second secret share of the application output data for the second MPC system.

15 . The system of claim 12 , wherein the operations further comprise:

receiving, from the computing system by the first MPC system, a respective encrypted second secret share of the input data for each of the one or more second MPC systems; and

providing, by the first MPC system to each second MPC system, the respective encrypted second secret share of the input data for the second MPC system.

16 . The system of claim 12 , wherein sending, by the first MPC system, a first secret share of result data resulting from the one or more secure multi-party computations to the computing system comprises sending a composite message comprising the first secret share of the result data and respective encrypted second secret shares of the result data received from the one or more second MPC systems.

17 . A non-transitory computer readable storage medium carrying instructions that, when executed by one or more processors, cause the one or more processors to perform operations comprising:

receiving, from a computing system and by a first multi-party computation (MPC) system of a cluster of MPC systems, a first secret share of input data;

sending, by the first MPC system and to an application running in a trusted execution environment (TEE) separate from the cluster of MPC systems, first secret shares of a set of data items generated based at least in part on the first secret share of the input data, wherein the application is configured to generate secret shares of application output data, the secret shares of the application output data generated based on one or more computations using plaintext values of the set of data items, the plaintext values of the set of data items being generated using (i) the first secret shares of the set of data items and (ii) respective second secret shares of the set of data items provided by one or more second MPC systems of the cluster;

performing, by the first MPC system in collaboration with the one or more second MPC systems of the cluster, one or more secure multi-party computations using: (i) the first secret share of the input data, (ii) a respective second secret share of the input data received by each of the one or more second MPC systems, (iii) a first secret share of the output data received from the application by the first MPC system, and (iv) a respective second secret share of the output data received from the application by each of the one or more second MPC systems; and sending, by the first MPC system, a first secret share of result data resulting from the one or more secure multi-party computations to at least one of (i) the computing system or (ii) one or more additional computing systems different from the computing system.

18 . The non-transitory computer readable storage medium of claim 17 , wherein the operations further comprise:

generating plaintext result data by combining the first secret share of the result data with a respective secret share of the result data received from each of the one or more second MPC systems.

19 . The non-transitory computer readable storage medium of claim 17 , wherein the application is configured to:

compute plaintext values of the set of data items by combining the first secret shares of the set of data items with respective second secret shares of the set of data items received from the one or more second MPC systems;

perform one or more computations using at least the plaintext values of the second set of data items;

generate secret shares of application output data generated based on the one or more computations;

provide the first secret share of the application output data to the first MPC system; and

provide, to each second MPC system, the respective second secret share of the application output data for the second MPC system.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 6, 2024
From: WANG, GANG; YUNG, MARCEL M. MOTI
To: GOOGLE LLC
Reel/Frame 067321/0010 →
Priority Claims (1)
IL 292083 · Apr 8, 2022 · national
Continuity (1)
Related Publication 20260128854A1 · May 7, 2026
References Cited (26)
US 11646878B2 · Sofia · 2023 [cited by examiner]
US 20250068766A1 · Gupta · 2025 [cited by examiner]
CN 109101822 · 2018 [cited by applicant]
CN 111563261 · 2020 [cited by applicant]
EP 3591893 · 2021 [cited by applicant]
WO WO2021083179 · 2021 [cited by applicant]
Beaver, “Efficient multiparty protocols using circuit randomization.” Advances in Cryptology—Crypto'91: Proceedings 11. Springer Berlin Heidelberg, 1992, 13 pages. [cited by applicant]
Choi et al., “Secure multiparty computation and trusted hardware: Examining adoption challenges and opportunities”. Security and Communication Networks, Apr. 2019, 28 pages. [cited by applicant]
Cloud.google.com [online], “Cloud Functions” Apr. 2016, retrieved on Mar. 21, 2023, retrieved from URL <https://cloud.google.com/functions>, 9 pages. [cited by applicant]
Docs.aws.amazon.com [online], “What is AWS Lambda?” Nov. 2014, retrieved on Mar. 21, 2023, retrieved from URL <https://docs.aws.amazon.com/lambda/latest/dg/welcome.html>, 4 pages. [cited by applicant]
Felsen, “Secure Two-Party Computation: ABY versus Intel SGX” Master Thesis for the degree of Engineering, University of Technische Universitat Darmstadt, Jan. 10, 2019, 111 pages. [cited by applicant]
Github.com [online], “Dovekey_auction.md” Mar. 2021, retrieved on Mar. 21, 2023, retrieved from URL <https://github.com/google/ads-privacy/blob/master/proposals/dovekey/dovekey_auction.md>, 9 pages. [cited by applicant]
Github.com [online], “Dovekey_auction_secure_2pc.md” Mar. 2021, retrieved on Mar. 21, 2023, retrieved from URL <https://github.com/google/ads-privacy/blob/master/proposals/dovekey/dovekey_auction_secure_2pc.md>, 18 page… [cited by applicant]
Github.com [online], “Parakeet.md : API flow for Adserving” Feb. 2021, retrieved on Mar. 21, 2023, retrieved from URL <https://github.com/WICG/privacy-preserving-ads/blob/main/Parakeet.md#api-flow-for-ad-serving>, 23 pa… [cited by applicant]
Github.com [online], “README.md” Nov. 2020, retrieved on Mar. 24, 2023, retrieved from URL <https://github.com/google/ads-privacy/blob/master/proposals/scaup/README.md>, 11 pages. [cited by applicant]
International Preliminary Report on Patentability in International Appln. No. PCT/US2022/051323, mailed on Oct. 17, 2024, 7 pages. [cited by applicant]
International Search Report and Written Opinion in International Appln. No. PCT/US2022/051323, mailed on Mar. 31, 2023, 14 pages. [cited by applicant]
Office Action in Israel Appln. No. 292083, mailed on Jun. 19, 2024, 4 pages. [cited by applicant]
Wikipedia.org [online], “Cryptographic nonce” Sep. 2006, retrieved on Mar. 21, 2023, retrieved from URL <https://en.wikipedia.org/wiki/Cryptographic_nonce>, 3 pages. [cited by applicant]
Wikipedia.org [online], “Secret Sharing” Feb. 2004, retrieved on Mar. 21, 2023, retrieved from URL <https://en.wikipedia.org/wiki/Secret_sharing>, 8 pages. [cited by applicant]
Wikipedia.org [online], “Secure multi-party computation” created on May 2004, retrieved on Mar. 21, 2023, retrieved from URL <https://en.wikipedia.org/wiki/Secure_multi-party_computation>, 13 pages. [cited by applicant]
Wikipedia.org [online], “Trusted Execution Environment” created on Jun. 2013, retrieved on Mar. 21, 2023, retrieved from URL <https://en.wikipedia.org/wiki/Trusted_execution_environment>, 11 pages. [cited by applicant]
Wikipedia.org [online], “Turing Completeness” Sep. 2001, retrieved on Mar. 21, 2023, retrieved from URL <https://en.wikipedia.org/wiki/Turing_completeness>, 9 pages. [cited by applicant]
Bahmani et al., “Secure Multiparty Computation from SGX.” Cryptology ePrint Archive, Nov. 2016, 38 pages. [cited by applicant]
Kumar et al., “Cryptflow: Secure tensorflow inference.” 2020 IEEE Symposium on Security and Privacy (SP). IEEE, May 2020, 336-353. [cited by applicant]
Office Action in Indian Appln. No. 202417016102, mailed on Jun. 1, 2026, 11 pages (with English translation). [cited by applicant]