Uploaded June 2026 | Updated September 2026, 3 weeks ago
Production Multi-Party Computation via the Distributed Aggregation Protocol
Tim Geoghegan and J.C. Jones, Internet Security Research Group
Multi-party computation (MPC) has long promised privacy-preserving data aggregation, but practical deployments remain rare. The Distributed Aggregation Protocol (DAP), currently progressing through IETF standardization, changes this narrative. We present Divvi Up, a production deployment of DAP processing billions of contributions from widely-deployed applications including Mozilla Firefox. Unlike research prototypes demonstrating MPC feasibility on small datasets, Divvi Up operates at internet scale with multiple independent aggregation servers performing secure multi-party computation on real user data.
This talk covers the architecture of DAP and demonstrates how modern MPC can move beyond academic proofs-of-concept to provide practical, scalable privacy infrastructure. Attendees will learn about deploying privacy-preserving telemetry in production environments and understand the benefits and challenges of deploying MPC to improve privacy, such as:
Composing private aggregation with differential privacy
Computational overhead in clients and browsers
Tradeoffs between flexibility and privacy
View the full PEPR '26 program at usenix.org/conference/pepr26/program
Production Multi-Party Computation via the Distributed Aggregation Protocol
Tim Geoghegan and J.C. Jones, Internet Security Research Group
Multi-party computation (MPC) has long promised privacy-preserving data aggregation, but practical deployments remain rare. The Distributed Aggregation Protocol (DAP), currently progressing through IETF standardization, changes this narrative. We present Divvi Up, a production deployment of DAP processing billions of contributions from widely-deployed applications including Mozilla Firefox. Unlike research prototypes demonstrating MPC feasibility on small datasets, Divvi Up operates at internet scale with multiple independent aggregation servers performing secure multi-party computation on real user data.
This talk covers the architecture of DAP and demonstrates how modern MPC can move beyond academic proofs-of-concept to provide practical, scalable privacy infrastructure. Attendees will learn about deploying privacy-preserving telemetry in production environments and understand the benefits and challenges of deploying MPC to improve privacy, such as:
Composing private aggregation with differential privacy
Computational overhead in clients and browsers
Tradeoffs between flexibility and privacy
View the full PEPR '26 program at usenix.org/conference/pepr26/program










