New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Loading player…

ZKMPC: Bring public auditability into MPC | Devcon SEA

DevconThu, Oct 9, 2025, 12:00 AM

In multi-party computation (MPC), participants collaboratively compute without revealing private inputs. To secure MPC on a blockchain, preventing collusion is essential. We developed a "publicly auditable" version of SPDZ, a widely-used MPC protocol, that enables third-party verification through zero-knowledge proofs (ZKP) collaboratively generated by multiple parties. We will also demonstrate application examples, such as a Game Master-free werewolf game. Speaker(s): Task Ohmori, Yusuke Nakae Skill level: Intermediate Track: Applied Cryptography Keywords: ZKP, MPC, collaboration, zk-snark Follow us: https://twitter.com/efdevcon, https://twitter.com/ethereum, https://warpcast.com/devcon Learn more about devcon: https://www.devcon.org/ Learn more about ethereum: https://ethereum.org/ Visit the https://archive.devcon.org/ to gain access to the entire library of Devcon talks with the ease of filtering, playlists, personalized suggestions, decentralized access on Swarm, IPFS and more. Devcon is the Ethereum conference for developers, researchers, thinkers, and makers. Devcon SEA was held in Bangkok, Thailand on Nov 12 - Nov 15, 2024. Devcon is organized and presented by the Ethereum Foundation. To find out more, please visit https://ethereum.foundation/

Transcript

[Music] [Music] okay hello everyone uh today I we' like to talk about ZK MPC U bringing public audity into multiparty computation yeah or MPC uh today I'm excited to share our latest advant advancement in this field for you okay this is the today's outline but yeah let's start from introduction and please give me a little bit time to yeah for the team introduction also yoi Inc is a Japanese fintech company to helps and entrepreneurs and businesses to grow uh interesting uh uh increasing asset liquidity with Innovative Financial Solutions and we are doing R&D for uh zkp and MPC to focus on secure and efficient computation so today I would like to talk about the project which have received two ESP grants from the is foundation and this is our team member uh This Is Us Nakai a researcher and developer and I'm task and last he is not here but we have Masa Masa uh co-founder CEO so uh let's go into the topic uh let let me first introduce about the importance of the secure computation uh and MPC so secure computation in data driven world is uh is really essential it allows us to protect the sensitive uh information such as healthare and financial and it enables useful analysis without exposing information and multiparty computation uh or MPC is a key technology for this purpose uh so yeah uh it enables multiple parties to jointly comput functions while keeping their inputs private and they only have to share the final results so this will ensure the secure collaboration so uh let's think why uh the third party verification for MPC is essential uh especially the case we are using dishonest majority protocols like speeds uh when we are using uh dishonest majority protocols uh participants like Alice and Bob can verify them within themselves that calculation results are computed correctly however they cannot directly prove uh the correctness to the third party such as Charlie so in this case Charlie will think can I trust this result uh yeah that's why uh adding C party verification to MPC is a very uh essential uh uh especially for use cases like application to blockchain uh finance and medical data analytics so uh this will is the overview for the rest of the uh presentation uh firstly uh we will uh show how to uh introduce the public ail into spe NPC protocol by introducing the collaborative DK snarks uh next we will secure consistency of the secret input which enable third party to verify the input conat using par and commitment and next we will uh show our enhanc of the bitwise support for public auditable auditable speeds so speeds is well suited for arithmetic operations but not effective for uh bitwise operation so we support uh functions kind of such kind of uh comparisons conditional branching and de bit composition and so on and this will expand the range of possible applications and as a application uh we implemented the game master free werewolf or sometimes called Mafia game uh using MPC to Showcase how our enhancement will make the MPC more versatile to uh collaborative use cases okay I I'll pass to yusuke on next uh to achieve what we introduced we need to understand the backgrounds and issues uh in more depths and we which we will explain firstly let us begin with the uh MPC protocol Basics uh MPC uses the techniques called secret sharing uh which is uh data is splitted to some shares and each party has uh it shares one by one and there are some kind of secret sharing like additive secret sharing and Shia SEC Shing and so on let's consider the example of addition X X and Y is shared and the addition of X Plus Y is uh can be obtained by simply addition of the their shares and however multiplication and other more complicated operation needs uh needs Communication in intermediate steps yeah and space space is one of the well known NPC protocol proposed in 2011 and this is uh use this uses additive suet sharing so it is suitable for uh arithmetic operation like addition and multiplication and so on and there are two phases uh one is preprocessing and the other is online phase and the next we talk about the P MPC uh publicly auditable MPC is the most important concept in our session in order NPC uh the correctness of MPC calculation can be verified by uh participants however pmpc uh impos MPC on uh of third party verification it was proposed in 2014 however the efficient implementation does not exist at the time however uh in 20 21 the coopertive Z snacks which is the one of efficient uh implementation of public auditable MPC uh was proposed by oir and Bon the idea of ctive snack is to prove uh to prove by m m provs and the call KZ commitment uh KZ commitment is a kind of polinomial commit M uh which is used in DK s and pro and verifier uh communicate with uh each other and commitment uh Pro compute commitment and send to proof to verifier and verifier uh last check that the pairing of uh specific calculation and uh probative ZK SNS uses the uh poal commitment uh in dkp uh like Marin and pron and so on and we focus on the mathematically aspects of collaborative snacks uh it's it uh idea is very simple uh the pi I is a proof uh proof generated by Shadow input and Pi is the total proof this techniques uses the linearity of polinomial commitment and uh if we generate uh the proof uh each party then this is a share of total proof however if we want to uh use collaborative ZK or pmpc on blockchain uh there are some issues to be solved the figure shows that DK snacks and NPC additive oriented and bitwise oriented NPC uh roughly speaking we want to develop techniques in this Vision uh which satisfice all three uh Legions the first issue is the consistency of secret inputs space uh in space uh there are pre preprocessing phase and online phase so we have to ensure that the consistency of secret inputs and this figure shows that conventional NPC and the public auditable NPC and the second issue is requirement for the general purpose computations speace based NPC is suitable for arithmetic operations however uh not suitable for bitwise operations so we have to uh you have to implement such uh bitwise operations uh which is efficient for Speed yeah and this uh effects on constraint generation in zkp because of restriction of finite felds which can be used in zkp and next uh we focus on the first challenges the secure consistency of secret inputs in MPC uh in especially in space uh the data input data uh is generated by using auxilary data uh created in PR processing phase so we have to uh we have to be more cautious than usual the committed data uh sorry we solve these problems by using commitment uh we we commit uh input data uh before the input shares generated so and at add at constraint to dkp so we can verify that the uh data in preprocessing and online phase and the proving phase is uh must be same and we choose p and commitment uh to implement and there are some constraints uh we implemented for example uh L constraint and and so on and we focus on second changes bitwise operation support Recall why uh bitwise operation difficult in space uh space uses additive secret sharing so bit de compos and comparison uh such operation U will be more more costly than uh addition and multiplication so if we using uh larger finite Fields then more constraint needs so we can't uh it is difficult to implement bitwise operations uh implementation uh we added especially uh equality zero test and comparison test and uh bit decomposition uh on speace based MPC and if we also implemented share conversion protocol because Pedas and commitment needs uh two different finite fears and let's look the uh algorithm detail this shows the equality zero test let's imagine that you have the data X of share of data X and we want to uh calculate X is zero or not firstly we generate the landom share r with uh Associated bit with bwise share and uh calculate X+ R and publishe them uh this denote as C if x is zero then R and C must be same so we use this fact and calculate uh AI uh this is bitwise and output the uh total an of all AI uh this means uh one if xal is zero and otherwise this means zero and surprisingly uh bitwise operation uh doesn't uh need for additional constraint uh for each party even if uh this can be considered as separation of dkp programs and the uh NPC programs so we focus on each Legions and next we want to show applications and demo video we developed a we game Sorry game master free well of game uh this flow chart shows that uh well of game flow chart wh of game for well game is a a game uh the players are divided into two teams one is Bard team and the other is we team and prayer uh whose Ro is hidden and uh by using specific Ro action and voting and uh player aim to victory for their teams usually we of game is is necessary for necessary sorry game master is necessary for we of game however we developed uh game master free wealth game by our CK MPC here is the list of we implemented the protocol in the DK where Ro assignment Anonymous voting where of f for ter check and victory condition such computation is done by MPC and uh we can check the con check the correctness of such actions let's pick up the ler assignment in dkw uh players inputs the shuffle Matrix uh by secret shares and then compute uh the lws by grouping protocol and they generate uh collaborative proof of L assignment protocol then uh if the verification is correct uh then they they are informed uh their RS this is a demo video of our bpc uh this is four people case uh the Alice and Bob and charie and Dave they legister name and then set up began uh right the way and the L assignment protocol is long is running and proof here is proof generation by MPC after the proof generation uh the proof is verified and they are uh Alice is fortun uh both Is wealth and Charis and Dave are villagers and the night pH uh they they do uh special action AR Fortune teror uh Divine B and B attacked to char and the discussion phase and boting phase is here ice and Bob and Dave are both then again the proof generation is started after the verification of the proof uh Dae was executed here and finally the vory condition check program uh is running here also generating uh collaborative proof after creating and verification game is over weides win here at trust uh we looking to the Future Prospect of our zkm PC if it is it becomes available on blockchain uh it it can be used as a more it can be used as a sty NPC module on blockchain with smart contract and uh it can be also applied to some regions like machine learnings and medical and financial data uh such case uh where multiple party needs to share data and that's DK MPC can reduce the security risks and ensure that the correctness of calculation thank you for listening thank you once again uh very nice talk you covered many things uh we got an overview of all of MPC uh background on different protocols all that you've implemented U demo everything and future I think it was really nice talk thank you very much H we have some questions um maybe I will start at the bottom so maybe I missed it but which snark did you implement growth 16 or something else uh ah sorry uh I I don't write gross 16 however uh gross 16 is also implemented for our zkm PC like Marlin and pron yeah so plon Marlin and gr6 yes very nice cool uh did you implement everything from scratch or did you use some existing libraries uh in the part of our program is uh existing libraries uh for example the crypto cryptographic uh Primitives uh we use this aqu workx library and uh the collaborate with s part uh we refer to the original work however uh in pre-processing phase of spe and the bitwise operations uh bitwise operation region we we light uh from scratch nice impressive cool and maybe one last question for me is um where would you be most excited to see this used what sort of developer or application would you really love to see building this I think your examples that you did with the games and the demo is super nice but outside of your team uh who would you love to see using it ah okay I'm really interested if this is used in kind of uh medical case or to make the machine learning model uh together with a different organization so if each organization has a different secret data and they don't want to reveal the data to each other but still they can make learn the model to create uh to create the model or to also do the yeah um estimation from the model so I'm really excited to combine this uh technology with machine learning yeah and you think it's efficient enough to do um some machine learning in MPC yes yes so if if we use MPC in machine learning we the model itself can be private or don't have to be rebuilded to anyone yeah very nice cool well that's all the questions we have um we'd like to thank the speakers again for a very nice talk um thank you thank you so we have a few minutes six minutes before the LA next and last session

Automatic transcript — names and jargon may be misspelled.