# "Collaborative Confidential Compute" by Auryn Mcmillan // ECC#2 - Buenos Aires 2025

- Channel: [Ethereum Cypherpunk Congress](https://streameth.org/ethereum-cypherpunk-congress)
- Date: 2026-01-09
- Duration: 13:41
- Topics: web3, privacy, now, crypto, cryptography, blockchain, data, security, human right, rights, tech, technology, internet, open source, free, freedom, ethereum, hackers, ethics, cypherpunk, dev, developer, dapp, decentralization, bitcoin, computer, surveillance, cyber, peer2peer, p2p, love, solidity, zk, zero knowledge, education, academy, w3pn, congress, ethereum cypherpunk, buenos aires, argentina, vitalik buterin, privacidad, Education
- Watch: https://streameth.org/watch/yt-gvVhTEmNy-k
- YouTube: https://www.youtube.com/watch?v=gvVhTEmNy-k

## Description

Auryn McMillan from Enclave introduces concept of collaborative confidential compute, explains blockchains auctions and brings Enclave's Ciphernodes on their testnet.

Ethereum Cypherpunk Congress by Web3Privacy Now is the world's largest cypherpunk and human rights event.
4500 people gathering in Buenos Aires to celebrate privacy with internet freedom leaders like Richard Stallman, Vitalik Buterin, Roger Dingledine, and Eva Galperin. 

Join us in building a free internet for all.

Website: https://web3privacy.info/
Congress site: https://congress.web3privacy.info/

## Transcript

Hey, I'm Orin uh from Nosis Guild. I'm going to talk today about uh collaborative confidential compute. Uh so this is a class of problems that we're building some solutions for. uh there's there's a variety of uh protocols and and organizations and whatnot building uh solutions around this uh or kind of ideulating on it and a bunch of really interesting research that happen has happened over the last few years pushing this space forward. Um but yeah going to kind of introduce the concept uh and then uh a new trilmma just because what's a what's a blockchain protocol without a new trilmma. Um so aggregating inputs from multiple parties is this kind of fundamentally powerful technique. Uh it's a critical component behind a lot of our most interesting most impactful uh the most interesting impactful things that we do right it's it's a critical component to our democracies to our markets uh to to training AI to doing research and to to producing social media feeds. Um, I I I'm liking it to the spirit bomb here. For any Dragon Ball Z fans, you can you can I guess many many small inputs from many many people can produce things that are dramatically more impactful than any individual acting alone. Um, but a lot of these kind of systems come with this this fundamental trade-off, this this big caveat uh in that privacy in them sucks. If you're if you're aggregating inputs from from many people, generally it means making a huge compromise on privacy. Um, and where these systems do have some element of privacy baked in, then they tend to come with some other set of caveats uh that that make them equally untenable. Part of this is due to economic influences, right? There's this this firms have this massive uh economic interest in this financial incentive to hoover up user data. uh as much as possible to silo it because the information asymmetry is the thing that's valuable. But beyond that uh there's this uh deeper kind of structural challenge uh that I'll describe here as the the collaborative computing trilmma. Um in an ideal world you can take uh multiple inputs from many different parties arbitrarily aggregate them uh in a way that uh preserves privacy for uh people providing inputs. But in practice we we end up compromising on at least one of those properties uh aggregation verifiability and confidentiality. Um and and this is a a forced compromise, right? Things are are fundamentally incompatible in a way that forces us to always make a compromise on one of properties. Uh and so just to be clear on terms by verifiability, I mean that participants and observers can independently check the integrity of a system and uh verify the correctness of its outputs. uh by confidential I mean that uh inputs and intermediate states uh remain private and only the the kind of pre-agreed on aggregation is revealed. Um and then lastly that the the system can meaningfully aggregate and what I mean by that is is can meaningfully manipulate combine uh and compute over data uh from multiple independent sources without having to ideally without having to to uh collect all of that data in one uh one central place give one one party access to that data. uh the the collaborative compute trillemma essentially states that we can pick any two of these three and then must compromise on the third. Uh so a few familiar examples just to kind of ground this this idea each compromises on at least one of these properties in order to achieve the other uh one or two. Um so we'll start some start with some systems that are reasonably familiar probably to a lot of folks here. Um first is uh programmable blockchains like Ethereum. So we have this shared state machine and some consensus rules that allow a network of of nodes, a network of validators and and kind of external uh observers to uh follow the network or or participate in in producing blocks for the network to validate that inputs to the network that the state transitions uh on the network. uh all follow the the set of rules uh for for that network, right? That that the state transitions are valid, that the audit they are applied makes sense or at least is a universal agreed on order of uh the application. Um and in other words to to take many private many inputs and aggregate them in a verifiable way. But the trade-off here is that in order to do this, anyone needs to be able to look at the historic inputs to recomputee the current state. So it's an explicit trade-off of privacy in order to achieve verifiable aggregation. And a more kind of practical or traditional example would be something like a English auction, a first price auction, right? This is your your prototypical auction where biders raise their hand or shout out their bid, raise a paddle, something like this to signal that they want to place a bid in the auction. Uh there is agreed upon rules on how bidding works like every bid has a given increment over the current price or the the bidder can shout out an arbitrary increment. Um but being able to observe the inputs the bids and knowing in advance the rules of an English auction uh any any participant any observer can guarantee or or can be kind of insured of the correctness of the outcome. So again it's verifiable and an aggregation but at the cost of privacy. An alternate auction type which is generally considered to be a bit more economically efficient is a sealed bid second price auction, a victory auction. And so in practice, the way that this works in most cases is you have an auctioneer who is trusted to accept all of the private bids to calculate the result, the bidder and the price that they pay and then to reveal only that information to uh to to the public in order to settle the auction. And so in this case, you're trading off both confidentiality in that you're still having to reveal your information to the auctioneer as well as uh verifiability in order to have this this uh aggregation of of bids that is more privacy preserving but still not kind of perfectly privacy preserving. Um again a compromise on on verifiability and uh and confidentiality in order to achieve the specific aggregation. Um so another approach to this or another another kind of branch of these trade-offs here is where we choose to constrain what types of aggregations or our capacity for aggregations in order to have something that is verifiable and confidential. And so this is where uh Zcash, privacy pools, rail gun, uh these kind of private UTXO based systems uh fit in. You're you're explicitly trading off your ability to do aggregations to to to have kind of shared secret state in order to have a system that is both private or confidential uh and verifiable. Uh so these systems hide your inputs uh and and allow you to to benefit from the the privacy set. Um but there's no shared secret state that uh participants can can collectively manipulate. There's no aggregation. Um and then I think the the most typical trade-off in this in this space here is uh confidential aggregation without verifiability. The the prototypical example here is secret ballot voting. The the state-of-the-art in in most worthwhile democracies is step into a voting booth, write your vote on a piece of paper, drop it into a box, and shake the box with all of the other ballots. And this gives you a a confidential aggregation, but at the explicit trade-off of verifiability, right? you are probably not present for the counting of the votes. There's no way for you to kind of mathematically verify that uh that the votes correspond to the inputs. But uh yeah, this is an explicit trade-off so as to give this uh confidential aggregation uh to things like coercion resistance, collusion resistance. Um so what we're working on at Enclave is uh a a solution to this confidential compute trilmark. Um the idea is to allow many private inputs to be computed collaboratively or computed over collaboratively producing a verifiable output uh while preserving pre uh privacy for inputs and intermediate states uh and then giving you a verifiable outcome. uh with game theoretic guarantees around uh the the input and intermediate state privacy. So in other words uh aggregation verifiability and confidentiality uh packaged together in in one product and I want to be clear here that this is not without trade-offs. the the the triilmer still applies, but we do think that it's a best-in-class uh solution to this category of problems, essentially allowing us to radically distribute trust in privacy and and uh guarantee it with game theory and economic guarantees in a way that has not been done yet. um we are able to have cryptographic guarantees of correct execution with game theory guarantees of uh secured confidentiality. Uh so ultimately enabled us to build uh enclave uh is this convergence of essentially the holy trinity of uh cryptographic methods maturing simultaneously over the last few years. So we have zero knowledge proofs, fully homorphic encryption and multi-party computation. ZKPs allow us to make the entire process end to end verifiable. Fully homorphic encryption allows us to compute over encrypted data such that we can produce an output cipher text that when decrypted gives us the same result as if we ran the computation on plain text. And then MPC allows us to radically distribute trust in the keys that can ultimately decrypt the output cipher text and could in theory decrypt any of the inputs as well. And this is where this critical fourth component comes in there, a system of economic guarantees. So penalties and rewards for uh malicious and and honest behavior respectively. Um, so we get again cryptographic guarantees of correctness with game theory guarantees around privacy. Um, and this is where you folks come in. Uh, so we're gearing up to launch Enclave in Q1 next year. Um, and we need a critical mass of cipher punks to run what we're calling cipher nodes in Enclave. Um, what's ultimately going to make Enclave interesting, what's going to make it useful, what's going to make it valuable is having a very large, very broadly distributed, very high quality set of node operators uh collectively securing the collaborative confidential compute requests on our network. Uh, and so we're running an internal test net right now and and are going to start opening it up to external node operators here in the near future, the next few weeks or monthish. Um, and so yeah, we're just starting to kind of collect uh interest from potential node operators. Um, so yeah, I guess if if you're interested uh out of out of curiosity, out of cipher punk instincts, uh, for fun or for profit, then yeah, head over to enclave.gg/ciphonode. And, uh, yeah, we would love to hear from you or just come find me after the talk. We have a little booth in the back. Uh, yeah, we're we're really excited for what we're enabling with Enclave. And again, critical component is hitting that uh that critical mass of great quality node operators. And I think that that the folks here showing up for Cippy Punk Congress is is that core for us. We really want to make sure that the folks getting involved early on are aligned and in it for the the ethos of for the cipher punk ethos. Um yeah, so that's it for me. Thanks everyone.
