Skip to content

LibraryConfidential compute2015Design paperCorpus record

Enigma: Decentralized Computation Platform with Guaranteed Privacy

Secret Network. Guy Zyskind, Oz Nathan, Alex Pentland.

The 2015 Enigma paper from MIT: private contracts executed over secret-shared data, so nodes compute without seeing the raw inputs. Secret Network is a later project in this lineage, using different machinery. This page is about the Enigma paper, which the historic library does not hold.

Enigma's paper splits data so that a set of nodes can compute on it together without any one node seeing the underlying secret, using secret sharing rather than a single trusted box.

The five-minute read

The computation needs the data, and the operator must not have it

That is the problem. Encryption at rest does not solve it, because the computer that runs the job usually decrypts. Enigma's answer is to avoid a single computer that can decrypt.

Secret sharing splits the input

Each node holds a share. A threshold of shares can reconstruct. Fewer cannot. The computation is designed to run on shares.

A public chain is the coordinator, not the data store

The paper uses a blockchain for control, identity and settlement. The private data stays off it, in the shared computation layer.

Contracts can call private computation

The design goal is a public contract that triggers a private function and receives only the result it is supposed to see. Specifying that interface is as important as the cryptography.

Multi-party computation has a performance cost the paper does not wish away

Shares, rounds of communication, and a threshold assumption are the price of not trusting one box. A deployment that quietly uses one server has left the paper.

One action, walked through

  1. A user secret-shares an input among the computation nodes. No single node receives the plaintext.
  2. A public contract records the request and the identity of the function to run.
  3. Nodes run the agreed protocol on their shares, exchanging messages the protocol requires.
  4. The result, and only the result, is returned to the contract or the user. Intermediate shares are not published.
  5. If fewer than the threshold of nodes are honest, the privacy or the correctness claim fails in the way the paper's model predicts.

The argument, unpacked

The threshold is the trust model

Secret sharing does not remove trust. It changes 'trust this operator' into 'do not let this many of these operators collude'. A study should say the number. Without the number, the design is a mood.

Correctness and privacy are different failures

Nodes can try to learn the secret, or they can try to return the wrong result. A protocol may defend one better than the other. The paper has to be read for both. A marketing line about 'encrypted computation' usually blurs them.

The chain sees the request

Metadata, function names, and who called are often public even when inputs are shared. For many businesses the metadata is the secret. The paper's split helps only if the public half has been examined.

What has to be true

  • Fewer than the threshold of nodes collude or are compromised.
  • The function being evaluated was correctly turned into a share-wise protocol. A bad circuit is a bad result the cryptography will faithfully compute.
  • Nodes stay online for the rounds the protocol needs. Multi-party computation does not love absentees.
  • Users can verify they are talking to the real set of nodes, not a lookalike that asks for plaintext 'as a convenience'.

What happened after the paper

Enigma the project evolved, and the broader field moved through multi-party computation, hardware enclaves and zero-knowledge proofs as competing answers to private computation. This paper is the secret-sharing answer. It should not be cited as a description of a later product that swapped in a different foundation.

What to check before you use the idea

  • What is the collusion threshold, in numbers?
  • Does the protocol guarantee correctness, privacy, or both?
  • What metadata remains public on the coordinating chain?
  • Is the live system still secret sharing, or has it moved to enclaves or proofs?

Terms

Secret sharing
Splitting a value into shares so a threshold can reconstruct it and a smaller set learns nothing.
Multi-party computation
A protocol in which parties compute a function of their private inputs without revealing those inputs.
Threshold
How many shares, or nodes, are required before the secret or the result can be produced.
Coordinator chain
The public ledger that records requests and settlement, not the private data.

The problem the paper names

A public contract reveals its inputs. Many agreements — a credit check, a medical rule, a sealed bid — cannot be published in order to be settled. Enigma's proposal is to split data across nodes, compute on the shares, and reveal only the agreed output.

What the design proposes

  • Secret sharing splits an input so no single node holds it.
  • A computation protocol produces an output without reconstructing the input on one machine.
  • A public ledger can store the resulting commitment or payment while the data stays in the private layer.

How the mechanism is specified

  • The privacy claim is as strong as the sharing threshold and the honesty assumption in the protocol.
  • Performance and the class of programs that are practical are constraints the paper is working under, not details to skip.
  • Secret Network's later trusted-execution design is a different technical bet. Do not cite Enigma as if it specified that implementation.

What this page does not treat as proven

  • This is not the Secret Network documentation.
  • Multi-party computation among a small, static set is a different trust model from a public chain.
  • The paper does not make every smart contract private.

Why a venture studio still reads it

The right citation when a venture says 'private smart contracts' and means secret sharing, as opposed to a proof, a trusted enclave, or simply an access-control list. Those four are different products. Enigma is the first.

This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.

Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.