JA

Why secure computation and secret sharing matter now — a view from the data market

Introduction

Training data for generative AI, medical records, financial data — data you want to use but cannot let out of the building is everywhere in business. Secure multi-party computation (MPC) and secret sharing are drawing attention as the technical answer to that contradiction.

Most people have heard the names without ever seeing what exactly they protect, or why the interest is spiking now. In this post I follow the mechanism with actual numbers first, then work through the reasons these techniques are wanted: market trends, regulatory movement, and deployments that already exist.

Here is what this post covers:

Caught between using data and not being able to release it

The data held by companies, hospitals, and financial institutions is valuable, but constraints keep it from being used freely.

  • Regulations such as Japan’s Act on the Protection of Personal Information, GDPR, and HIPAA impose strict conditions on providing personal data externally or joining it across organizations
  • Even when a company wants to train generative AI on another company’s data or its own customer data, there is strong resistance to handing the data itself to an external AI vendor
  • Hospitals that want to match records against each other face high costs in obtaining patient consent and in anonymization

This dilemma — the data is worth using, but the raw data cannot be handed over — is the fundamental reason secure computation and secret sharing are wanted. Running the computation while the data stays encrypted and distributed, rather than collected in one place, lets you extract the value while staying inside the rules.

Split on the way in, add without reassembling on the way out

Words alone make this hard to picture, so here is the most basic form with actual numbers. The two techniques are a pair: secret sharing acts when data goes in, secure computation when it is aggregated.

First, going in. A value is split into several fragments (shares) that add back up to the original, and each share is left with a different server.

Company A's value of 100 split into three shares that add back up to 100, one held by each of three servers Company A's data 100 split three ways at random Server 1 share 63 Server 2 share 21 Server 3 share 16

How to read it: 63, 21, and 16 all look unrelated to the original 100. And they are — one share, or even two, tells you nothing about it. Only all three together add back up to 100. The scheme shown here needs every share to reconstruct; there are also threshold schemes (Shamir’s secret sharing) where the value survives losing some of them.

Now the aggregation. Reassembling the data here would defeat the point, so the computation runs on the shares themselves. Say we want the sum of Company A’s 100 and Company B’s 40.

Three servers each add their own shares, then pool the partial results so that only the total of 140 is reconstructed Server 1 A's share: 63 B's share: 12 sum: 75 Server 2 A's share: 21 B's share: 5 sum: 26 Server 3 A's share: 16 B's share: 23 sum: 39 75 + 26 + 39 = 140 only the total is reconstructed

How to read it: no server ever sees anything but the numbers in its own hands. Pool them at the end and you still get 140, the sum of Company A’s 100 and Company B’s 40. The original 100 and 40 never appear anywhere.

What the figure does not show is that the cost is far from uniform. Addition finishes with each server adding up what it holds, but multiplication and comparison do not work that way: the servers have to talk to each other while computing, and the cost climbs accordingly.

Why the market is expanding fast

Research firms agree on a high growth rate for the secure computation (MPC) market. The scope each survey covers differs, so the figures vary, but they broadly converge: somewhere between $1.0B and $1.9B recently, growing two- to fourfold by 2030–2035.

Research firmRecent market sizeForecastCAGR
Research and Markets$1.87B (2026)$3.72B in 203212.07%
Straits Research$1.09B (2026)$2.73B in 203412.18%
Precedence Research$1.11B (2026)$2.98B in 203511.63%
Mordor Intelligence$0.96B (2025)$1.67B in 203011.67%
Strategic Market Research$1.2B (2024)$4.6B in 203024.5%

The growth drivers they have in common are these.

  • Privacy regulation is tightening globally, with GDPR, CCPA, and HIPAA leading the way
  • Demand for safe cross-organizational data collaboration and analysis is rising, centered on finance and healthcare
  • As generative AI spreads, so does demand for “Confidential AI” — training and operating models while keeping sensitive data protected
  • In financial services specifically, one forecast has the market growing from $1.8B in 2025 to $20.5B in 2034 (CAGR 32.5%), so adoption in regulated industries is growing faster than anywhere else

Regulatory movement in Japan

The market forecasts are mostly from overseas research, but Japan is building out its own framework for using medical data, and that is creating real demand for secure computation and secret sharing.

  • The Next Generation Medical Infrastructure Act (enacted 2017, amended act in force April 2024) set up a scheme where certified operators can link and analyze anonymized medical information together with public databases such as the NDB (the national claims database) and the long-term care database
  • From autumn 2025, an amendment has been under discussion that would permit secondary use of data without consent where the purpose is statistical, including AI development, which would widen the scope of data use further
  • In the EU, the EHDS (European Health Data Space) regulation entered into force in March 2025, obliging data holders to share health data

The more the rules say data may be shared and linked, the more actual operation needs technical backing for computing safely without handing over raw data. That is where secure computation and secret sharing come in.

Deployments that already exist

This may sound like a story about the future, but several systems are already in production or in field trials.

  • H-LINCOS, developed by NICT together with Kochi Health Sciences Center and others, uses secret sharing to distribute electronic health records across multiple institutions, so they can be restored quickly even in a disaster
  • NICT has also run trials combining quantum cryptography with secret sharing to transmit and distribute health records while keeping them confidential
  • A Cabinet Office document describes a case where MPC was used to visualize surveillance data (JANIS) from multiple hospitals by secondary medical area, with each institution’s data kept confidential
  • NEC is researching what it calls highly confidential federated learning, combining federated learning with MPC-based protection of the model parameters, to block inference attacks on the training data while limiting the loss in model accuracy

How secure computation differs from neighboring technologies

Secure computation is not the only way to use data without letting it out. Which one fits depends on what you are protecting.

TechnologyWhat it protectsIn one line
Federated learningWhere the data sitsThe data never moves; only the learned updates are pooled
Secure computation (MPC) and secret sharingThe intermediate state of the computationData is split into shares and computed on without ever being reassembled
Homomorphic encryptionThe intermediate state of the computationOperations run directly on ciphertext (close in purpose to MPC)
Differential privacyThe outputNoise is added to results so individuals cannot be identified

In federated learning, a trace of the data still leaves the building in the form of model parameters, which leaves the risk of inference attacks against those parameters. Combining it with secure computation so that the parameters themselves stay confidential during training and aggregation is exactly what NEC’s highly confidential federated learning is aiming at.

Wrapping up

The reason secure computation and secret sharing are needed comes down to satisfying two demands at once — the value of using data, and privacy and regulatory compliance — without moving the raw data. Behind the double-digit growth rates that every research firm is forecasting are two large currents: tightening regulation, and rising demand for Confidential AI. Implementation is progressing first in industries that handle highly sensitive data, healthcare and finance, and the technology will only become more important in the context of training data for generative AI.

The mechanism itself, as the figures showed, works with nothing more than adding numbers that were never reassembled. Bring multiplication and comparison into it, though, and the communication cost changes completely — which makes deciding how much to compute under encryption the practical question. That is worth a post of its own.

References