IP Library › Granted Patent US 12,652,165
Granted Patent B2
US 12,652,165 · App. 18/690,609 · Granted Jun 9, 2026

Multi-party computation system

Inventors: Daniel J. Weitzner (Washington, DC); Andrew W Lo (Weston, MA); Vinod Vaikuntanathan (Somerville, MA); Taylor Reynolds (Belmont, MA); Leo R. De Castro (Lexington, KY); Jeffrey Schiller (Arlington, MA)
Assignee: Massachusetts Institute of Technology
H04L9/085H04L63/14H04L2209/46
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,652,165
App. No.
18/690,609
Granted
Jun 9, 2026
Kind
B2
Abstract

Some embodiments relate to a system for performing a multi-party computation among a plurality of parties. The system receives encrypted data sets generated by devices associated with the plurality of parties, wherein each of the encrypted data sets is generated by a respective one of the devices by encrypting data using a key shared among the devices. The system performs a computation on an aggregate of the encrypted data sets to obtain an encrypted result of the computation. The system transmits the encrypted result of the computation to at least two of the devices. The system receives partially decrypted shares of the encrypted result generated by the at least two devices, wherein each of the partially decrypted shares is generated by a respective one of the least two devices by partially decrypting the encrypted result using a private key of the respective device. The system generates a decrypted result of the computation using the partially decrypted shares of the encrypted result.

Claims (58)

1 . A system for performing a multi-party computation among a plurality of parties associated with devices, the system comprising:

a processor; and

a non-transitory computer-readable storage medium storing instructions that, when executed by the processor, cause the processor to:

generate a shared key, the generating comprising:

receiving keys from at least some of the devices, the at least some devices including at least two devices associated with at least two of the plurality of parties;

generating the shared key using the keys received from the at least two devices;

transmit the shared key to the devices associated with the plurality of parties;

receive encrypted data sets generated by the devices associated with the plurality of parties, wherein each of the encrypted data sets is generated by a respective one of the devices by encrypting data using the shared key;

perform a computation on an aggregate of the encrypted data sets to obtain an encrypted result of the computation;

transmit the encrypted result of the computation to the at least two devices associated with the at least two parties;

receive partially decrypted shares of the encrypted result generated by the at least two devices, wherein each of the partially decrypted shares is generated by a respective one of the least two devices by partially decrypting the encrypted result using a private key of the respective device; and

generate a decrypted result of the computation using the partially decrypted shares of the encrypted result.

2 . The system of claim 1 , wherein the keys received from the at least some devices are public keys corresponding to private keys of the at least some devices.

3 . The system of claim 1 , wherein the at least some devices include one or more devices in addition to the at least two devices.

4 . The system of claim 1 , wherein the devices consist of the at least some devices.

5 . The system of claim 1 , wherein the devices include one or more devices in addition to the at least some devices.

6 . The system of claim 1 , wherein the shared key comprises a public key.

7 . The system of claim 1 , wherein the instructions cause the processor to transmit the decrypted result to the devices.

8 . The system of claim 1 , wherein generating the decrypted result of the computation comprises combining the partially decrypted shares of the encrypted result to obtain the decrypted result of the computation.

9 . The system of claim 1 , wherein each of the encrypted data sets comprises an encryption of cybersecurity information of a respective one of the plurality of parties.

10 . The system of claim 1 , wherein each of the encrypted data sets is:

checked for at least one error by a respective one of the devices; and

received by the system after it is determined that the encrypted data set does not have the at least one error.

11 . The system of claim 10 , wherein the at least one error for an encrypted data set comprises:

presence of non-numerical data in the encrypted data set;

presence of an input value outside of an allowed range for the input value; and/or

an incomplete form in the encrypted data set.

12 . The system of claim 1 , wherein the instructions cause the processor to:

prior to performing the computation on an aggregate of the encrypted data sets:

determine whether performance of the computation would reveal information about any of the plurality of parties; and

perform the computation on the aggregate of the encrypted data sets when it is determined that performance of the computation would not reveal information about any of the plurality of parties.

13 . The system of claim 12 , wherein determining whether performance of the computation would reveal information about any of the plurality of parties comprises determining if the aggregate of the encrypted data set includes an outlier.

14 . A method for performing a multi-party computation among a plurality of parties associated with devices, the method comprising:

generating a shared key, the generating comprising:

receiving keys from at least some of the devices, the at least some devices including at least two devices associated with at least two of the plurality of parties;

generating the shared key using the keys received from the at least two devices;

transmitting the shared key to the devices associated with the plurality of parties;

receiving encrypted data sets generated by devices associated with the plurality of parties, wherein each of the encrypted data sets is generated by a respective one of the devices by encrypting data using the shared key to obtain the encrypted data set;

performing a computation on an aggregate of the encrypted data sets to obtain an encrypted result of the computation;

transmitting the encrypted result of the computation to the at least two devices associated with the at least two parties;

receiving partially decrypted shares of the encrypted result generated by the at least two devices, wherein each of the partially decrypted shares is generated by a respective one of the least two devices by partially decrypting the encrypted result using a private key of the respective device; and

generating a decrypted result of the computation using the partially decrypted shares of the encrypted result.

15 . The method of claim 14 , wherein the keys received from the at least some devices are public keys corresponding to private keys of the at least some devices.

16 . A device comprising:

a processor; and

non-transitory computer-readable storage medium storing instructions that, when executed by the processor, cause the processor to:

generate a public key corresponding to a private key of the device;

transmit, to a computer system, the public key;

receive, from the computer system, a key shared with one or more other devices, wherein the shared key is generated by the computer system using the public key;

encrypt data using the shared key to obtain an encrypted data set;

transmit, to the computer system, the encrypted data set;

receive, from the computer system, an encrypted result of a computation performed on an aggregate of:

the encrypted data set; and

one or more encrypted data sets generated by the one or more other devices;

partially decrypt, using a private key of the device, the encrypted result to obtain a partially decrypted share of the encrypted result;

transmit, to the computer system, the partially decrypted share of the encrypted result; and

receive, from the computer system, a decrypted result of the computation.

17 . The device of claim 16 , wherein the shared key is generated by the computer system using the public key and one or more public keys of the one or more other devices.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 14, 2025
From: WEITZNER, DANIEL J.; LO, ANDREW W.; VAIKUNTANATHAN, VINOD; REYNOLDS, TAYLOR; DE CASTRO, LEO R.; SCHILLER, JEFFREY
To: MASSACHUSETTS INSTITUTE OF TECHNOLOGY
Reel/Frame 070237/0236 →
Continuity (3)
Provisional Application 63242144 · Sep 9, 2021
Provisional Application 63242150 · Sep 9, 2021
Related Publication 20250015979A1 · Jan 9, 2025
References Cited (12)
US 20180173894A1 · Boehler · 2018 [cited by examiner]
US 20200279045A1 · Tueno · 2020 [cited by examiner]
Castro, “Practical Homomorphic Encryption Implementations & Applications”, Feb. 2020 (Year: 2020). [cited by examiner]
International Search Report and Written Opinion for International Application No. PCT/US2022/042952 mailed Dec. 20, 2022. [cited by applicant]
International Preliminary Report on Patentability for International Application No. PCT/US2022/042952 mailed Mar. 21, 2024. [cited by applicant]
Benaloh, ElectionGuard Preliminary Specification v0.85. Sep. 2019 https://github.com/microsoft/ElectionGuard-SDK-specification/blob/master/Informal/ElectionGuardSpecificationv0.85.pdf (Last accessed Dec. 6, 2022). [cited by applicant]
Elahi et al., Privex: Private collection of traffic statistics for anonymous communication networks. Proceedings of the 2014 ACM SIGSAC Conference on Computer and Communications Security Nov. 3, 2014:1068-79. [cited by applicant]
Melis et al., Efficient private statistics with succinct sketches. arXiv preprint arXiv:1508.06110. Jan. 6, 2016. 15 pages. [cited by applicant]
Pereira, Internet voting with Helios. Real-World Electronic Voting: Design, Analysis and Deployment. 2016. 36 pages. [cited by applicant]
Pestana et al., Themis: Decentralized and trustless ad platform with reporting integrity. arXiv preprint arXiv:2007.05556. Jul. 10, 2020. 17 pages. [cited by applicant]
[No Author Listed], csail / ipri-scram. Github. https://github.com/CSAIL/ipri-scram. Last accessed Apr. 8, 2025. 3 pages. [cited by applicant]
De Castro et al., SCRAM: A Platform for Securely Measuring Cyber Risk. HDSR. Sep. 16, 2020;2:76. [cited by applicant]