Security Experts:

Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Protection

Google Open-Sources Cryptographic Protocol

Google this week rolled out a new type of multi-party computation (MPC) to help organizations better collaborate with confidential data sets. 

Google this week rolled out a new type of multi-party computation (MPC) to help organizations better collaborate with confidential data sets. 

Meant to augment the cryptographic protocol known as private set intersection (PSI), the new MPC is called Private Join and Compute and has been released as open source. 

The tool allows organizations to gain aggregated insights about each other’s data without any of them learning any information about individuals in the datasets. 

With this cryptographic protocol, organizations can encrypt identifiers and associated data, and then join them so they can do certain types of calculations on the overlapping set of data and draw useful information from both datasets in aggregate. 

“All inputs (identifiers and their associated data) remain fully encrypted and unreadable throughout the process. Neither party ever reveals their raw data, but they can still answer the questions at hand using the output of the computation. This end result is the only thing that’s decrypted and shared in the form of aggregated statistics,” Google explains

Private Join and Compute combines two fundamental cryptographic techniques, namely PSI, which allows two parties to privately join sets and discover common identifiers, and homomorphic encryption, which makes it possible to perform certain types of computation directly on encrypted data without having to decrypt it first.

Thus, only the size of the joined set and the statistics of its associated values are revealed. Individual items are encrypted using random keys and are not available in raw form to the other party or anyone else, Google says. 

The company says it is committed to applying MPC and encryption technologies to more concrete, real-world issues through making privacy technology more widely available. The technology is expected to help advance research in fields that require organizations to work together, including public policy, diversity and inclusion, healthcare, and car safety standards. 

“Private Join and Compute keeps individual information safe while allowing organizations to accurately compute and draw useful insights from aggregate statistics. By sharing the technology more widely, we hope this expands the use cases for secure computing,” Google says. 

Related: Google Introduces Open Source Cross-Platform Crypto Library

Related: Fitting Forward Secrecy Into Today’s Security Architecture

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Click to comment

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this webinar to learn best practices that organizations can use to improve both their resilience to new threats and their response times to incidents.

Register

Join this live webinar as we explore the potential security threats that can arise when third parties are granted access to a sensitive data or systems.

Register

Expert Insights

Related Content

Application Security

Cycode, a startup that provides solutions for protecting software source code, emerged from stealth mode on Tuesday with $4.6 million in seed funding.

Data Protection

The CRYSTALS-Kyber public-key encryption and key encapsulation mechanism recommended by NIST for post-quantum cryptography has been broken using AI combined with side channel attacks.

Data Protection

The cryptopocalypse is the point at which quantum computing becomes powerful enough to use Shor’s algorithm to crack PKI encryption.

Application Security

Many developers and security people admit to having experienced a breach effected through compromised API credentials.

Compliance

The three primary drivers for cyber regulations are voter privacy, the economy, and national security – with the complication that the first is often...

Application Security

Fortinet on Monday issued an emergency patch to cover a severe vulnerability in its FortiOS SSL-VPN product, warning that hackers have already exploited the...

Cybersecurity Funding

CommandK announced that it has raised $3 million in a seed funding round for a solution designed to help organizations secure sensitive data.

Cybersecurity Funding

Los Gatos, Calif-based data protection and privacy firm Titaniam has raised $6 million seed funding from Refinery Ventures, with participation from Fusion Fund, Shasta...