Skip to content

PRIVATE AGGREGATION, PROVEN

Proof Tally

Verifiable aggregation · Prio3 · VDAF

Split a salary into two shares, send each with part of a fully linear proof, and watch two aggregators accept the total without either reading the report.

00

Privacy is not validity

Secret sharing hides one measurement and still adds it perfectly, even when the measurement is a lie. Prio3 adds a proof to those shares so the servers can jointly answer one narrow question: is this report shaped correctly?

01

One report, two envelopes

Choose a measurement, split it, then let both aggregators contribute a verifier share. Only their combined verifier can accept.

Measurement type

24-bit range: 0 to 16,777,215. Client-side limits are convenience, not the defense.

  1. 1Enter
  2. 2Shard
  3. 3Prepare
  4. 4Collect

02

Collector tally

The protocol result is computed from output shares. The plain sum is computed separately and compared.