Data truncation method, device, storage medium and program product for multi-party secure computation
Patent Information
- Application Number
- CN202610969656.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-06-30
- Publication Date
- 2026-10-02
AI Technical Summary
在无符号截断过程中,为安全丢弃低位比特,需依赖不经意传输协议等MPC密码学原语,这需要在多方之间进行多轮交互,每轮交互传输大量的通信数据,通信开销较大,严重制约了截断协议在神经网络训练等高频乘法场景中的应用性能
[0011]本说明书实施例中,将对定点数乘积对应目标分片的截断处理映射到几何空间中,在几何空间中,将目标分片映射为布尔值,双方互换布尔值的掩码,基于本地布尔值和互换的掩码进行比特乘,从而基于比特乘结果生成符号系数分片,基于该符号系数分片将目标分片转换为有符号分片,对有符号分片进行截断,以得到截断结果。上述过程中,双方在本地执行比特乘,无需复杂的密码学原语进行交互,在保证数据安全的同时,可以极大的降低通信轮次和通信量,提升数据截断效率。
Smart Images

Figure CN122870384A_ABST
Abstract
Description
Technical Field
[0001] This specification relates to the field of information processing technology, and in particular to a data truncation method, device, storage medium, and program product for multi-party secure computation. Background Technology
[0002] In the framework of Secure Multi-party Computation (MPC), multiple participants wish to collaboratively perform machine learning tasks (such as addition or multiplication) without revealing their respective local raw data. To address this, secret sharing techniques have emerged. Each party first divides its local raw data into secret shares using a secret sharing protocol and distributes them to other participants. Subsequent computations (such as addition or multiplication) are performed on these secret shares, ensuring that the original data is never disclosed to other participants.
[0003] In most schemes based on secret sharing technology, fixed-point numbers are used for numerical computation to improve protocol performance. A fixed-point number is a data type representing finite-precision numerical values. Its main characteristic is that the position of the decimal point is fixed; a fixed-point number includes a sign bit, an integer part, and a fractional part. However, multiplication based on fixed-point numbers can multiply the number of decimal places. For example, multiplying two fixed-point numbers with 2 decimal places results in a product with 4 decimal places. This necessitates the introduction of secure truncation protocols to restore the decimal places of the product to their state before the multiplication operation.
[0004] In traditional truncation protocols, a fixed-point number x is converted to an unsigned number, unsigned truncation is performed to safely discard the lowest m bits, and then the truncated unsigned number is restored to a signed number. During unsigned truncation, to safely discard the low-order bits, MPC cryptographic primitives such as the Unsigned Transmission Protocol (UTP) are required. This necessitates multiple rounds of interaction between multiple parties, with each round transmitting a large amount of communication data, resulting in significant communication overhead. This severely limits the performance of truncation protocols in high-frequency multiplication scenarios such as neural network training. Summary of the Invention
[0005] This specification provides a data truncation method, device, storage medium, and program product for multi-party secure computation, which reduces communication overhead during the data truncation process and improves the efficiency of data truncation.
[0006] This specification provides a data truncation method for multi-party secure computation, applied to a first party holding a first target fragment and a second party holding a second target fragment. The first and second target fragments are obtained by mapping a first unsigned representation of a fixed-point product onto a first integer ring. The method includes: mapping the first target fragment from the original geometric space to a third target fragment in the target geometric space. The target geometric space is obtained by cyclically shifting the original geometric space to the right along the horizontal axis, including multiple sub-regions defined based on the value range of the fixed-point product and a first boundary point defining the multiple sub-regions along the horizontal axis. A region corresponds to a symbol coefficient; a first Boolean value is generated based on the relative positional relationship between the third target fragment and the first boundary point; the mask result of the second Boolean value sent by the second party is received, the second Boolean value is generated based on the relative positional relationship between the second target fragment and the second boundary point, the second boundary point is the boundary point defined by multiple sub-regions in the vertical axis direction; a first symbol coefficient fragment is generated based on the bit multiplication result of the first Boolean value and the mask result of the second Boolean value; the first target fragment is mapped to a signed fragment based on the first symbol coefficient fragment; the signed fragment is truncated to obtain the first truncated fragment corresponding to the first target fragment.
[0007] This specification also provides a data truncation method for multi-party secure computation, applied to a second party. The first party holds a first target fragment, and the second party holds a second target fragment. The first and second target fragments are obtained by mapping a first unsigned representation of a fixed-point product onto a first integer ring. The method includes: generating a second Boolean value based on the relative positional relationship between the second target fragment and a second boundary point. The second boundary point is a boundary point defining multiple sub-regions in the target geometric space along the vertical axis. The target geometric space is obtained by cyclically shifting the original geometric space to the right along the horizontal axis. A sub-region corresponds to a symbol coefficient; the first target fragment is mapped to the third target fragment; the mask result of the first Boolean value sent by the first party is received, the first Boolean value is generated based on the relative positional relationship between the third target fragment and the first boundary point, and the second boundary point is the boundary point defined by multiple sub-regions in the horizontal axis direction; the first symbol coefficient fragment is generated based on the bit multiplication result of the mask result of the first Boolean value and the first random mask; the second target fragment is mapped to a signed fragment according to the first symbol coefficient fragment; the signed fragment is truncated to obtain the truncated fragment corresponding to the second target fragment.
[0008] This specification also provides an electronic device, including: a memory and a processor; the memory is used to store one or more computer instructions; the processor is used to execute one or more computer instructions to perform the steps in the method provided in this specification.
[0009] This specification also provides a computer-readable storage medium storing a computer program, which, when executed by a processor, can implement the steps of the method provided in this specification.
[0010] This specification also provides a computer program product, including: a computer program / instructions, which, when executed by a processor, can implement the steps of the method provided in this specification.
[0011] In this embodiment, the truncation process of the target fragment corresponding to the fixed-point product is mapped to a geometric space. In the geometric space, the target fragment is mapped to a Boolean value. Both parties exchange masks of the Boolean values, and perform bit multiplication based on the local Boolean values and the exchanged masks. This generates a signed coefficient fragment based on the bit multiplication result. The target fragment is then converted into a signed fragment based on this signed coefficient fragment, and the signed fragment is truncated to obtain the truncated result. In the above process, both parties perform bit multiplication locally, without the need for complex cryptographic primitives for interaction. While ensuring data security, this greatly reduces the number of communication rounds and the amount of communication, and improves the efficiency of data truncation. Attached Figure Description
[0012] The accompanying drawings, which are included to provide a further understanding of this specification and form part of this specification, illustrate exemplary embodiments and are used to explain this specification, but do not constitute an undue limitation thereof. In the drawings: Figure 1 This is a flowchart illustrating a multi-party secure computation system provided as an exemplary embodiment of this specification.
[0013] Figure 2 This is a schematic diagram of the target geometric space provided in one embodiment of this specification.
[0014] Figure 3 This is a flowchart illustrating a data truncation method for multi-party secure computation provided as an exemplary embodiment of this specification.
[0015] Figure 4 This is a flowchart illustrating a data truncation method for multi-party secure computation provided as an exemplary embodiment of this specification.
[0016] Figure 5 This is a schematic diagram of the structure of an electronic device provided as an exemplary embodiment of this specification. Detailed Implementation
[0017] To make the objectives, technical solutions, and advantages of this specification clearer, the technical solutions of this specification will be clearly and completely described below in conjunction with specific embodiments and corresponding drawings. Obviously, the described embodiments are only a part of the embodiments of this specification, and not all of them. Based on the embodiments in this specification, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this specification.
[0018] It should be noted that, in the case of user information involved in the embodiments of this application, the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, use and processing of related data must comply with the relevant laws, regulations and standards of the relevant countries and regions, and corresponding operation entry points are provided for users to choose to authorize or refuse.
[0019] In a secure multi-party computation framework, the neural network weights, gradients, activation values, etc. involved in machine learning tasks are signed numbers, which can be represented by fixed-point numbers. During the computation process, when two fixed-point numbers are multiplied, the number of decimal places in the product increases exponentially. Therefore, a secure truncation protocol needs to be introduced to restore the number of decimal places in the product to the level before the multiplication operation was performed.
[0020] In one data truncation method, multiple participants collaborate to add a fixed bias value to a fixed-point product (e.g., ...). , (where the bit length is the fixed-point product), so that signed fixed-point products are mapped to unsigned numbers; an unsigned truncation protocol is performed on this unsigned number, i.e., the low-order bits are safely removed. Bit, To truncate the bit length; subtract another fixed bias (e.g., from the truncation result of the unsigned number) ), thus restoring the signed truncation result.
[0021] To avoid revealing the plaintext, assume the unsigned number... The secret of addition is shared as , , , It is a positive integer. Among them, the first party P0 holds the slice. The second party, P1, holds the fragment. If each party directly truncates its own fragment locally, i.e., P0 is calculated... P1 calculation However, the sum of the truncation results from both sides is not... .because Among them, the wrap flag. Defined as: To accurately calculate the truncation result, both parties need to jointly calculate... ,calculate Essentially, this is a comparison problem: comparing P0 and P1. Whether it holds true, that is, P0 and P1 using a comparison protocol, compare the holdings of P0. Is it greater than or equal to? . and have In the case of 1 bit, the comparison protocol compares bit by bit starting from the leftmost bit. Each bit comparison requires one accidental transfer (OT) protocol. Each bit needs This unintentional transmission requires at least two rounds of interaction between the parties involved in each OT call. The entire process not only involves numerous communication rounds, but each round also requires the transmission of a significant amount of key material (e.g., 128 bits), leading to a substantial increase in total communication overhead. This is especially true in high-frequency multiplication scenarios such as neural network training, where such truncation is necessary after each multiplication, making communication overhead a major constraint on system performance.
[0022] To address the aforementioned technical problems, in some embodiments of this specification, the unsigned representation of a fixed-point product is mapped to a signed representation using signed coefficients, and truncation of the signed representation is performed. The truncation process of the target fragment corresponding to the fixed-point product is mapped to a geometric space. In this geometric space, the target fragment is mapped to a Boolean value, and both parties exchange masks of these Boolean values. A bitwise multiplication is then performed based on the local Boolean values and the exchanged masks, generating a signed coefficient fragment based on the bitwise multiplication result. This signed coefficient fragment is then used to convert the target fragment into a signed fragment, which is then truncated to obtain the truncated result. In this process, both parties perform bitwise multiplication locally, eliminating the need for complex cryptographic primitives. This significantly reduces communication rounds and volume while ensuring data security, thereby improving data truncation efficiency.
[0023] The technical solutions provided in the various embodiments of this specification are described in detail below with reference to the accompanying drawings.
[0024] Figure 1 This is a flowchart illustrating an exemplary embodiment of a secure multi-party computation system provided in this specification, such as... Figure 1 The system shown includes: a first party 101, a second party 102, and a third party 103.
[0025] In the embodiments described in this specification, the device forms of the first party 101, the second party 102, and the third party 103 are not limited. For example, the first party, the second party, and the third party may all be implemented as servers, or the first party, the second party, and the third party may all be implemented as terminal devices. As another example, the first party and the second party may be implemented as clients, and the third party as a server. Yet another example is that the first party and the second party may be implemented as Internet of Things (IoT) devices, and the third party as a server.
[0026] In the embodiments of this specification, the communication methods between the first party, the second party, and the third party are not limited. For example, from the perspective of communication protocols, the communication methods between the first party and the second party may include, but are not limited to: point-to-point communication based on Transmission Control Protocol (TCP), request and response communication based on Hypertext Transfer Protocol (HTTP) or Hypertext Transfer Protocol Secure (HTTPS), and bidirectional long connections based on WebSockets. From the perspective of transmission media, the communication methods between the first party and the second party may include, but are not limited to: wired communication, wireless communication, Bluetooth communication, and satellite communication. For details regarding the communication methods between the second party and the third party, and between the first party and the third party, please refer to the description of the communication methods between the first party and the second party; these will not be repeated here.
[0027] In the embodiments described in this specification, the first party, the second party, and the third party all maintain their own privacy data. Each party divides its local privacy data into secret shares (or fragments) through a secret sharing protocol and distributes them to other participating parties; subsequent calculations (such as addition or multiplication) are performed on these secret shares, and the privacy data is never disclosed to other participating parties. The secret shares are represented by fixed-point numbers.
[0028] In fixed-point arithmetic, signed numbers are represented using two's complement. While the semantics of this two's complement are signed, at the underlying hardware level, when performing basic arithmetic operations such as addition and multiplication, the bit patterns of the operands are treated as unsigned representations. That is, the arithmetic logic itself does not distinguish between signed and unsigned numbers, only performing modulo operations bit by bit (e.g., modulo...). Unsigned operations of ) are performed. After performing a multiplication operation, if the product result is truncated, the unsigned bit pattern before truncation is reinterpreted as a signed two's complement representation, thus completing the semantically correct truncation based on the signed two's complement representation.
[0029] In the embodiments of this specification, the unsigned representation of a fixed-point product is mapped to a signed representation through signed coefficients, thereby performing truncation on the signed representation without converting the fixed-point product to an unsigned number, performing unsigned truncation, and then converting the unsigned number back to a signed number. The unsigned representation of a fixed-point product refers to storing the fixed-point product in binary form, interpreting the bit pattern of this binary form as an unsigned number, and obtaining the unsigned representation of the fixed-point product. This unsigned representation does not change the numerical value of the fixed-point product, only the interpretation of the bit pattern. Converting a fixed-point product to an unsigned number means adding a fixed bias value to the fixed-point product, for example, the bias value is... , The bit length of the fixed-point product is such that the fixed-point product is converted to an unsigned number. Therefore, the unsigned representation of the fixed-point product is different from the unsigned number obtained by adding a fixed bias value to the fixed-point product.
[0030] The sign coefficient serves as a bridge between the unsigned and signed representations of a fixed-point product. For example, the sign coefficient includes a wrapper flag and a sign flag. A description of the wrapper flag can be found in the preceding embodiments. The sign flag represents the Most Significant Bit (MSB), which is the first bit from the left in the binary representation. In signed number representations (such as two's complement), the MSB is used to indicate positive or negative; for example, 0 for positive and 1 for negative. Exemplarily, the sign coefficient can be represented as... .in, Indicates a surrounding sign. Indicates symbolic markings, This is an unsigned representation.
[0031] For example, through mathematical derivation, the conversion relationship between unsigned and signed representations is derived as follows: , Unsigned representation, ,in, , For the surrounding sign. Further details... .in, For signed representation, MSB is the symbolic flag. Further explanation... .
[0032] remember ,have: Each party hopes to obtain the sign coefficient. One of the fragments.
[0033] In the embodiments described in this specification, the unsigned representation of the fixed-point product is split into two pieces through an additive secret sharing mechanism. For ease of distinction and description, the unsigned representation of the fixed-point product is referred to as the first unsigned representation. The first unsigned representation is mapped to a first target piece and a second target piece on a first integer ring. The first party holds the first target piece, and the second party holds the second target piece.
[0034] The first target slice and the second target slice satisfy the following relationship: x = x_0 + x_1 (mod L). Here, x represents the first unsigned representation of the fixed-point product, x_0 is the first target slice, x_1 is the second target slice, mod represents the modulo operation, and L is the length of the integer ring. L = 2^l indicates that the first and second target slices can be represented by l bits. For example, L = 2^8 = 256.
[0035] In the embodiments of this specification, from a geometric perspective, the original geometric space is defined based on the range of values for the product of fixed-point numbers. Geometric points in the original geometric space are defined by a first target piece and a second target piece, whereby the values corresponding to the first and second target pieces are used as the horizontal and vertical coordinates of a geometric point, transforming the problem of solving for the sign coefficient into the problem of determining the region to which the geometric point belongs. The original geometric space includes multiple sub-regions, each corresponding to a sign coefficient value. These sub-regions may overlap; if a geometric point falls into such an overlapping region, the sign coefficient value cannot be determined. Therefore, the original geometric space is cyclically shifted to the right along the horizontal axis to obtain the target geometric space. The multiple sub-regions included in the target geometric space have different shapes than the sub-regions in the original geometric space. The multiple sub-regions included in the target geometric space do not overlap, and their shapes are symmetrical. A first boundary point is defined along the horizontal axis of these multiple sub-regions. Based on this first boundary point, candidate sub-regions into which the geometric point falls can be determined from the multiple target sub-regions. Then, based on a second boundary point along the vertical axis, the target sub-region to which the geometric point belongs can be determined from the candidate sub-regions, thus uniquely determining the sign coefficient corresponding to the geometric point.
[0036] The overall value of the symbol coefficient is unknown to both the first and second parties. Ultimately, the symbol coefficient is provided to the first party as one symbol coefficient shard and to the second party as another symbol coefficient shard through a secret sharing technique.
[0037] The range of values for the fixed-point product is not limited. For example, considering that in the MPC framework, one bit can be reserved as a sign bit, and another bit can be reserved to allow some special protocols to be executed correctly, the number of bits in the first unsigned representation is reduced by two bits. If it was initially 1 bit, it is changed to 1-2 bits. The range of values for the first unsigned representation satisfies: |x|<2^l / 2^2 =L / 4, where L=2^l.
[0038] The number of sub-regions included in the target geometric space is not limited. For example, there can be two, three, or four sub-regions, etc., without limitation. Figure 2 The diagram illustrates a target geometric space comprising four sub-regions: B', C', D', and E'. Different sub-regions correspond to coefficients with different signs. For example, in... Figure 2 In this context, the sign coefficients for subregions B' and C' are 1, and the sign coefficients for subregions D' and E' are 2, without any restrictions.
[0039] In the embodiments described in this specification, the first party maps the first target slice from the original geometric space to a third target slice in the target geometric space. The second party holds the second target slice. The corresponding values of the third and second target slices are used as the x and y coordinates of a geometric point in the target geometric space, respectively. The problem of solving the sign coefficient is regarded as the problem of determining which target sub-region the target geometric point belongs to. In order to efficiently determine which target sub-region the target geometric point belongs to, both parties generate Boolean values based on their held slices and exchange Boolean value masks. Based on the bit multiplication result of the exchanged mask and the local Boolean value, a sign coefficient slice is generated. Here, to protect data security, neither party knows the target sub-region to which the target geometric point belongs. Each party holds a slice of the sign coefficient corresponding to the target sub-region.
[0040] In the embodiments of this specification, multiple sub-regions in the target geometric space are defined by a first dividing point along the horizontal axis. The first dividing point serves as a reference for spatial division of the target geometric space. For example, the target geometric space can be divided based on a vertical line passing through the first dividing point, thereby defining some sub-regions among the multiple sub-regions. The first party generates a first Boolean value based on the relative positional relationship between the third target piece and the first dividing point. The first party performs masking processing on the first Boolean value to obtain a masked result of the first Boolean value, and provides the masked result of the first Boolean value to the second party.
[0041] In the embodiments described in this specification, the second party generates a second Boolean value based on the relative positional relationship between the second target fragment and the second boundary point. The second party performs masking processing on the second Boolean value to obtain a masked result of the second Boolean value, and sends the masked result of the second Boolean value to the first party.
[0042] In the embodiments of this specification, the first party performs a bit multiplication on the mask results of the first Boolean value and the second Boolean value, and generates a first signed coefficient fragment based on the bit multiplication result. The first party maps the first target fragment to a signed fragment based on the first signed coefficient fragment; and performs truncation processing on the signed fragment to obtain the first truncated fragment corresponding to the first target fragment.
[0043] In the embodiments of this specification, the second party performs a bit multiplication on the mask result of the second Boolean value and the random mask, and generates a signed coefficient fragment (hereinafter referred to as the second signed coefficient fragment for ease of distinction) based on the bit multiplication result. The second target fragment is mapped to a signed fragment based on the second signed coefficient fragment; the signed fragment is truncated to obtain the second truncated fragment corresponding to the second target fragment.
[0044] Specifically, the first symbol coefficient fragment held by the first party and the second symbol coefficient fragment held by the second party can be recovered to the symbol coefficient fragment corresponding to the target sub-region. That is, it satisfies the following condition. .in, Indicates the partitioning of the sign coefficients. This indicates the first symbol coefficient partition. This indicates the second symbol coefficient partitioning. The length of the integer ring containing the sign coefficient slice.
[0045] The method by which the first party truncates the signed fragments to obtain the first truncated fragment corresponding to the first target fragment is not limited. For example, if truncating... If the number of bits is 1, then calculate the result. , This indicates the slice corresponding to the signed representation of the first unsigned representation.
[0046] The method by which the second party truncates the signed fragments to obtain the second truncated fragment corresponding to the second target fragment is not limited. For example, if truncating... If the number of bits is 1, then calculate the result. , This indicates that the first unsigned representation corresponds to another piece of the signed representation.
[0047] In the embodiments of this specification, the truncation process of the target fragment corresponding to the fixed-point product is mapped to a geometric space. In the geometric space, the target fragment is mapped to a Boolean value. Both parties exchange masks of the Boolean values, and perform bit multiplication based on the local Boolean values and the exchanged masks. This generates a signed coefficient fragment based on the bit multiplication result. The target fragment is then converted into a signed fragment based on this signed coefficient fragment, and the signed fragment is truncated to obtain the truncated result. In the above process, both parties perform bit multiplication locally, without the need for complex cryptographic primitives for interaction. While ensuring data security, this greatly reduces the number of communication rounds and the amount of communication, and improves the efficiency of data truncation.
[0048] In one optional embodiment, the method for generating the first Boolean value based on the relative positional relationship between the third target piece and the first boundary point is not limited. One implementation for generating the first Boolean value based on the region affiliation of the third target piece in the target geometric space includes: dividing multiple sub-regions into mutually exclusive first and second partitions by a vertical line corresponding to the first boundary point (hereinafter referred to as the first boundary line for ease of description); if the third target piece is greater than or equal to the horizontal coordinate value, then a first bit value is used as the first Boolean value; the first bit value indicates that the third target piece belongs to the first partition; if the third target piece is less than the horizontal coordinate value, then a second bit value is used as the first Boolean value; the second bit value indicates that the third target piece belongs to the second partition.
[0049] The shape of the target geometry is not limited. The shape of the target geometry can include, but is not limited to, squares, rectangles, triangles, circles, and irregular shapes. For example, in... Figure 2In this context, the target geometric space can be a square with side length L. A coordinate system is established with the lower left corner of the square as the origin. The four points in the target geometric space are represented as (0,0), (0,L), (L,0), and (L,L). For example, points on the first dividing line all correspond to the same x-coordinate value. For instance, the first dividing line could be x=L / 2, x=L / 3, or x=L / 4, etc., without limitation. The first dividing line divides the target geometric space into a first partition and a second partition. The first partition can be the region to the right of the first dividing line, and the second partition can be the region to the left of the first dividing line. Using the third target fragment as the x-coordinate value, the x-coordinate value corresponding to the first boundary point is compared with that of the third target fragment. If the third target fragment is greater than or equal to the x-coordinate value corresponding to the first boundary line, the first bit value is used as the first Boolean value, indicating that the third target fragment belongs to the first partition (i.e., the region to the right of the first boundary line). If the third target fragment is less than the x-coordinate value corresponding to the first boundary line, the second bit value is used as the first Boolean value, indicating that the third target fragment belongs to the second partition (i.e., the region to the left of the first boundary line). For example, the first bit value can be 1 and the second bit value can be 0, or the first bit value can be 1 and the second bit value can be -1; there are no restrictions on this.
[0050] In one optional embodiment, the method by which the first party generates the first symbol coefficient slice based on the bit multiplication result of the masking results of the first Boolean value and the second Boolean value is not limited. A specific example is provided below: the first party performs a bit multiplication on the masking results of the first Boolean value and the second Boolean value to obtain a bit multiplication result; to protect the security of the bit multiplication result, the first party obtains a first random mask sent by a third party; the first random mask is used to mask the bit multiplication result to obtain a first symbol coefficient slice, which is a slice of the symbol coefficients corresponding to the target sub-region to which the target geometric point belongs.
[0051] The bit lengths of the first Boolean value and the second Boolean value are not limited, and the bit lengths of the first Boolean value and the second Boolean value are the same. For example, this bit length is less than the bit length of the first target fragment. The bit lengths of the first unsigned representation, the first target fragment, and the third target fragment are the same.
[0052] Bit multiplication can be understood as a bitwise logical AND operation. The first Boolean value is a binary bit string, and the mask result of the second Boolean value is also a binary bit string. The AND operation is performed bit by bit on the two binary bit strings in the local machine of the first party.
[0053] Optionally, a random mask from a third party can be used to mask the first Boolean value. Specifically, the third party sends a second random mask to the first party, and the first party can also receive the second random mask sent by the third party. The sum of the first Boolean value and the second random mask is calculated as the masking result of the first Boolean value. The third party provides a third and a fourth random mask to the second party. The third random mask is used by the second party to mask the second Boolean value, and the fourth random mask c1 is used by the second party to generate the second symbol coefficient fragment corresponding to the second target fragment, satisfying a*b=c, c=c0+c1(mod L1), where * represents multiplication, a is the second random mask, b is the third random mask, c0 is the first random mask, and c1 is the fourth random mask. a, b, c, c0, and c1 are all integers on the second integer ring, and L1 is the length of the second integer ring. The length of the second integer ring is less than the length of the first integer ring, which refers to the integer ring containing the first unsigned representation, the first target fragment, and the second target fragment.
[0054] In the above process, the bit length of the random mask and Boolean value sent by the third party to the first party and the second party is less than the length of the first integer ring. This means that the amount of communication in each communication is reduced, and the amount of computation for performing bit multiplication operations locally by the first party is reduced. This can further reduce the amount of computation for data truncation and improve truncation efficiency.
[0055] For the second party: In one optional embodiment, the method for generating the second Boolean value based on the relative positional relationship between the second target fragment and the second boundary point is not limited. An example is provided below: multiple sub-regions are divided into two mutually exclusive partitions by a horizontal line corresponding to the second boundary point (hereinafter referred to as the second boundary line for ease of distinction and description). For ease of distinction and description, these two partitions are respectively referred to as the third partition and the fourth partition. If the second target fragment is greater than or equal to the ordinate value corresponding to the second boundary point, then the first bit value is used as the second Boolean value; the first bit value indicates that the second target fragment belongs to the third partition. If the second target fragment is less than the ordinate value, then the second bit value is used as the second Boolean value; the second bit value indicates that the second target fragment belongs to the fourth partition.
[0056] The descriptions of the target geometric space, the first bit value, and the second bit value can be found in the aforementioned embodiments and will not be repeated here. The second boundary line is not limited; for example, it can be a horizontal straight line, a vertical straight line, or a diagonal line, or even an irregular line. For example, all points on the second boundary line correspond to the same ordinate value. For instance, the first boundary line can be y=L / 2, y=L / 3, or y=L / 4, etc., without limitation. The second boundary line divides the target geometric space into a third partition and a fourth partition. The third partition can be the area above the second boundary line, and the fourth partition can be the area below the second boundary line.
[0057] In this example, taking the first boundary line as x = L / 2 and the second boundary line as y = L / 2, the first party generates a first Boolean value through the third target segment indicating whether the target geometric point is located in the left or right half of the target geometric space. The second party generates a second Boolean value through the second target segment indicating whether the target geometric point is located in the upper or lower half of the target geometric space. Therefore, based on the overlapping area of the first and second Boolean values, the target sub-region where the target geometric point is located can be determined. For example, in... Figure 2 In the diagram, if the first Boolean value is 1 and the second Boolean value is 1, it means that the target geometric point is located in the target sub-regions corresponding to B' and C' in the diagram, and the sign coefficient of the target sub-region is 1.
[0058] In one optional embodiment, the method for generating the first symbol coefficient fragment based on the bit multiplication result of the mask result of the first Boolean value and the random mask (corresponding to the aforementioned third random mask) is not limited. A specific embodiment is provided below, including: performing a bit multiplication on the mask result of the first Boolean value and the third random mask to obtain a bit multiplication result; obtaining a random mask (corresponding to the aforementioned fourth random mask) sent by a third party; and performing masking processing on the bit multiplication result according to the fourth random mask to obtain a second symbol coefficient fragment.
[0059] The explanation of bit multiplication can be found in the aforementioned embodiments and will not be repeated here. Regarding the implementation method of masking the bit multiplication result according to the second random mask to obtain the second symbol coefficient fragment, please refer to the aforementioned implementation method of masking the bit multiplication result according to the first random mask to obtain the second symbol coefficient fragment. Further optionally, the implementation method for masking the second Boolean value based on the third random mask provided by the third party to obtain the masked result of the second Boolean value is not limited. A specific example is provided below: receiving the third random mask sent by the third party; calculating the sum of the second Boolean value and the third random mask as the masked result of the second Boolean value; wherein the third party provides the first party with the first random mask and the second random mask, the second random mask is used by the first party to mask the first Boolean value, and the first random mask is used by the first party to generate the first symbol coefficient fragment corresponding to the third target fragment, satisfying a*b=c, c=c0+c1(mod L1), where * represents multiplication, a is the second random mask, b is the third random mask, c0 is the first random mask, c1 is the fourth random mask, a, b, c, c0, and c1 are all integers on the second integer ring, L1 is the length of the second integer ring, and the length of the second integer ring is less than the length of the first integer ring.
[0060] In an optional embodiment, the implementation method by which the first party maps the first target piece from the original geometric space to the third target piece in the target geometric space is not limited. An example is provided below: based on the range of values for a fixed-point product, an original geometric space is determined, the original geometric space including multiple initial sub-regions and corresponding boundary segmentation points; the original geometric space is cyclically shifted right based on the boundary segmentation points to obtain the target geometric space; based on the cyclic right shift distance, the first target piece is mapped from the original geometric space to the third target piece in the target geometric space.
[0061] In this scenario, multiple sub-regions in the original geometric space overlap. The boundary dividing point refers to the coordinate point of the overlapping region. By performing a cyclic translation on the original geometric space, the boundary dividing point corresponding to the overlapping region is called the new spatial boundary point, thus obtaining the target geometric space without overlapping regions. The distance of the cyclic right translation can be L / 4, L / 3, or L / 5, etc., and is not limited thereto.
[0062] Specifically, based on the cyclic right shift distance, the first target piece is mapped from the original geometric space to the third target piece in the target geometric space. The third target piece can be represented as: .in, For the third target fragment, For the first target fragment, This represents the distance of the cyclic right shift.
[0063] In an optional embodiment, the implementation of mapping the first target fragment to a signed fragment based on the first signed coefficient fragment is not limited. An example is provided below: based on the mapping relationship between the first target fragment and the third target fragment, the correspondence between the first signed coefficient and the second signed coefficient is determined; the first signed coefficient refers to the signed coefficient corresponding to the first unsigned representation, and the second signed coefficient refers to the signed coefficient corresponding to the second unsigned representation, where the second unsigned representation is an unsigned number expressed through the third target fragment and the second target fragment; based on the correspondence between the first and second signed coefficients, the first signed coefficient fragment is converted into a signed coefficient fragment (hereinafter referred to as the third signed coefficient fragment for ease of distinction and description); based on the third signed coefficient fragment, the first target fragment is mapped to a signed fragment.
[0064] Here, the first unsigned representation corresponds to a first signed coefficient, used to map the first unsigned representation to a signed representation. For ease of distinction and description, the unsigned number expressed through the third target partition and the second target partition is called the second unsigned representation. For example, ,in, This is the second unsigned representation. For the third target fragment, For the second target fragment, is the length of the first integer ring. Wherein, the second unsigned representation corresponds to a second signed coefficient, used to map the second unsigned representation to a signed representation.
[0065] Specifically, based on the mapping relationship between the first target fragment and the third target fragment, the correspondence between the first symbol coefficient and the second symbol coefficient is determined. For example, the correspondence between the first symbol coefficient and the second symbol coefficient could be: ,in, The first sign coefficient, The third sign coefficient, This is an indicator function used to determine the first target fragment. Is it less than If so, then If not, then .
[0066] Therefore, based on the correspondence between the first and second symbol coefficients, the first symbol coefficient slice is converted into a third symbol coefficient slice.
[0067] The method of mapping the first target fragment to a signed fragment based on the second sign coefficient is not limited. For example, ,in, For signed fragments, For the second sign coefficients, slice them. For the first target fragment, The length of the integer ring.
[0068] Optionally, the implementation method for converting the first symbol coefficient piece into a second symbol coefficient piece based on the correspondence between the first and second symbol coefficients is not limited. A specific example is provided below, including: determining the magnitude relationship between the first target piece and the translation distance; calculating a third Boolean value corresponding to the magnitude relationship; the translation distance is the distance to the target geometric space where the third target piece is located obtained by cyclically translating the original geometric space where the first target piece is located; and calculating the difference between the first symbol coefficient piece and the third Boolean value based on the correspondence between the first and second symbol coefficients, using this difference as the third symbol coefficient piece.
[0069] Specifically, based on the determined relationship between the first target piece and the translation distance, a third Boolean value corresponding to this relationship is calculated. This third Boolean value is used to correct the offset caused by the cyclic translation. For example, the third Boolean value can be represented by an indicator function: ,in, For the first target fragment, For the translation distance, if The third Boolean value is 1, if The third Boolean value is 0.
[0070] Based on the correspondence between the first and second sign coefficients, the difference between the first sign coefficient slice and the third Boolean value is calculated, and this difference is used as the third sign coefficient slice. For example, the conversion formula between the first and second sign coefficient slices is as follows: in, For the first symbol coefficient, slice, For the third sign coefficients, slice them. The length of the second integer ring. It is the third Boolean value.
[0071] In the second aspect, the implementation method of mapping the second target fragment to a signed fragment based on the first sign coefficient fragmentation is not limited. For example, ,in, For signed fragments, For the second sign coefficients, slice them. For the second target fragment, The length of the integer ring.
[0072] In one optional embodiment, in the three-party secure computation, the fixed-point product is generated during the three-party interaction. The first unsigned representation of the fixed-point product is mapped on the first integer ring to a first initial fragment, a second initial fragment, and a third initial fragment, which are held by the first party, the second party, and the third party in the three-party secure computation, respectively. For example, the first party holds the first and second initial fragments, the second party holds the second and third initial fragments, and the third party holds the first and third initial fragments. When truncation is performed on the fixed-point product, to further reduce communication traffic, it is converted to a two-party secure computation. During the two-party secure computation, truncation is performed, with the third party acting as an auxiliary party. Based on this, before performing truncation, a first mapping operation from three-party secure computation to two-party secure computation can also be performed: the first party in the three-party secure computation is treated as the first party in the two-party secure computation; based on the first initial fragment and the second initial fragment held by the first party in the three-party secure computation, the first target fragment held by the first party in the two-party secure computation is constructed; the second party in the three-party secure computation is treated as the second party in the two-party secure computation; and the third initial fragment held by the second party in the three-party secure computation is treated as the second target fragment held by the second party in the two-party secure computation; and the third party in the three-party secure computation is treated as the third party that distributes random masks to the first party and the second party in the two-party secure computation to assist in the two-party secure computation.
[0073] For example, if the three parties are: the first party P0, the second party P1, and the third party P2, and the three parties hold the shards (x0,x1), (x1,x2), and (x2,x0) respectively, and satisfy x = x0 + x1 + x2 mod L, then when the first mapping operation is performed, the first party P0 calculates y0 = x0 + x1, and P1 calculates y1 = x2. At this time, y0 + y1 = x0 + x1 + x2 mod L. Therefore, it can be considered that the first party holds y0, the second party holds y1, and the two parties perform two-party secure computation. P2 can be considered as a third party used to distribute some random numbers to assist in the computation.
[0074] Optionally, after the two-party secure computation performs the truncation operation, the first party in the two-party secure computation obtains the first truncated fragment corresponding to the first target fragment, and the second party in the two-party secure computation calculates the second truncated fragment corresponding to the second target fragment. A second mapping operation from two-party secure computation to three-party secure computation can be performed: so that each of the three parties maintains a fragment after truncation by the product of the number of vertices.
[0075] Specifically, the first party generates a fifth random mask and provides it to the third party in the secure computation. Based on the fifth random mask, the first truncated fragment is masked to obtain a masked result for the first truncated fragment, which is then sent to the second party. The first party receives the masked result for the second truncated fragment sent by the second party. Based on the masked results of the first and second truncated fragments, a third truncated fragment is generated, and the fifth random mask is used as the fourth truncated fragment. Therefore, the first party holds both the third and fourth truncated fragments.
[0076] The second party generates a sixth random mask and sends it to the third party. Based on this sixth random mask, the third party performs masking on the second truncated fragment to obtain the masked result of the second truncated fragment. Based on the masked results of the first and second truncated fragments, the third truncated fragment is generated. The sixth random mask is then used as the fifth truncated fragment. Therefore, the second party holds both the third and fifth truncated fragments.
[0077] The third party receives the fifth random mask sent by the first party and the sixth random mask sent by the second party. It uses the fifth random mask as the fourth truncated fragment and the sixth random mask as the fifth truncated fragment. Therefore, the third party holds both the fourth and fifth truncated fragments.
[0078] The following is a scenario-based embodiment where the first unsigned representation of the fixed-point product is an integer on the integer ring, the length of which is... , Let the length be bits. Assume the first unsigned representation... The initial states held by the three parties are: P0(1,3), P1(3,5), and P2(5,1). The objective is to compute three slices where (x>>k) = 2. x>>k means truncating k bits from x, where k = 2.
[0079] Step 1: Remapping three-party secure computation to two-party secure computation, with P2 acting as the auxiliary party: P0 obtains =1+3=4, P1 is obtained =5. Satisfies .
[0080] Step 2: Calculate the sign coefficient Two partitions: and .
[0081] a. Map the first target fragment to the third target fragment: .
[0082] b. First Party: Execution That is, to judge To determine whether the condition is true (i.e., 196 ≥ 256 / 2 is true), the input to P0 is the first Boolean value m = 1.
[0083] Second party: Execution That is, to judge Whether it is valid, The input to P1 is the second Boolean value n=0.
[0084] With the cooperation of P2, bit multiplication is calculated to obtain the third symbol coefficient fragment d0 and the second symbol coefficient fragment d1. P0 holds d0, and P1 holds d1. The bit multiplication process is as follows: P2 generates a random mask (c0=3, c1=1), (a=3, b=1); it sends (a=3, c0=3) to P0 and (b=1, c1=1) to P1. a, b, c0, and c1 are all integer rings. integers above, This is the truncation length.
[0085] P0 performs masking on the first Boolean value, obtaining the masked result m+a=1+3=4, and sends the masked result of the first Boolean value to P1; P1 performs masking on the second Boolean value, obtaining the masked result of the second Boolean value n+b=1, and sends the masked result of the second Boolean value to P0.
[0086] P0 calculates the bit product of the first Boolean value m and the masked result (n+b) of the second Boolean value, and performs masking on the bit product m(n+b) to obtain m(n+b)+c0=3 (i.e. d0 above); P1 calculates the bit product of the random mask -b and the mask result (m+a) of the first Boolean value, and then masks the bit product -b(m+a) to obtain -b(m+a)+c1=(-4+1)mod =1 (i.e., d1 above).
[0087] At this point, P0 obtains the third symbol coefficient fragment d0=3, and P1 obtains the second symbol coefficient fragment d1=1; it is clear that d0+d1 modulo... =0 (This is correct because 1*0=0, which satisfies d=1*0).
[0088] c. P0 calculates the first symbolic coefficient fragment. 3 + 1 - 1 = 3.
[0089] P1 Second Symbol Coefficient Partition 1, (obviously, That's also correct, because ) Step 3: Calculate the truncation: a. P0 calculates the first truncation segment. .
[0090] b. P1 calculates the second truncation slice. c. . Step 4: Mapping two-party secure computation back to three-party secure computation: That is, z0, That is, z1.
[0091] a. P0 and P2 generate random masks simultaneously, for example, r0 = 1; P1 and P2 generate random masks simultaneously, r1 = 2.
[0092] b. P0 calculates z0–r0 = 64 as the mask result for the first truncated fragment and sends the mask result to P1.
[0093] P1 calculates z1 - r1 = 191 as the mask result for the second truncation fragment and sends the mask result to P0.
[0094] c. P0 calculates the sum of the mask results of the first truncated fragment and the mask results of the second truncated fragment, and uses it as the third truncated fragment 64+191=255. P0 uses the random mask r0 as the fourth truncated fragment, and P0 holds (1,64+191=255).
[0095] P1 calculates the sum of the mask results of the first truncated fragment and the mask results of the second truncated fragment, and uses it as the third truncated fragment 64+191=255. The random mask r1 is used as the fifth truncated fragment, and P1 holds (64+191=255,2).
[0096] P2 holds random masks r0 and r1, which are used as the fourth and fifth truncation fragments, respectively, i.e., P2 holds (2,1).
[0097] Among them, the third, fourth, and fifth truncated pieces satisfy 1 + 255 + 2 mod L = (x >> k) = 2.
[0098] In the embodiments described in this specification, when calculating the truncation, ,in, The carry term is discarded, resulting in a probabilistic 1-bit error for the entire scheme, leading to high precision. It does not rely on complex cryptographic primitives, resulting in lower communication overhead and higher performance. Specifically, if k is the ring length and m is the number of bits to be truncated, the communication overhead for the secure three-party computation is (k+m, k+m, m), and the number of communication rounds is (2, 2, 1). For example, when k=64, m is typically around 20, hence the low communication overhead.
[0099] Based on the aforementioned multi-party secure computation system, embodiments of this specification also provide a data truncation method for multi-party secure computation, applied to a first party. The first party holds a first target fragment, and the second party holds a second target fragment. The first and second target fragments are obtained by mapping a first unsigned representation of a fixed-point product onto a first integer ring. Figure 3 As shown, the method includes: 301. Map the first target piece from the original geometric space to the third target piece in the target geometric space. The target geometric space is obtained by cyclically shifting the original geometric space to the right along the horizontal axis. It includes multiple sub-regions defined based on the value range of the fixed-point product and the first boundary point of the multiple sub-regions defined in the horizontal axis direction. Each sub-region corresponds to a sign coefficient.
[0100] 302. Generate the first Boolean value based on the relative positional relationship between the third target segment and the first boundary point.
[0101] 303. Receive the mask result of the second Boolean value sent by the second party. The second Boolean value is generated based on the relative positional relationship between the second target fragment and the second boundary point. The second boundary point is the boundary point that defines multiple sub-regions in the vertical axis direction.
[0102] 304. Generate the first symbol coefficient fragment based on the bit multiplication result of the masking results of the first Boolean value and the second Boolean value.
[0103] 305. Based on the first sign coefficient, map the first target fragment to a signed fragment.
[0104] 306. Truncate the signed fragments to obtain the first truncated fragment corresponding to the first target fragment.
[0105] In one optional embodiment, multiple sub-regions are divided into mutually exclusive first and second partitions by a vertical line corresponding to a first dividing point. A first Boolean value is generated based on the relative position of the third target fragment and the first dividing point, including: if the third target fragment is greater than or equal to the horizontal coordinate value corresponding to the first dividing point, then the first bit value is used as the first Boolean value, indicating that the third target fragment belongs to the first partition; if the third target fragment is less than the horizontal coordinate value, then the second bit value is used as the first Boolean value, indicating that the third target fragment belongs to the second partition.
[0106] In one optional embodiment, generating a first symbol coefficient fragment based on the bit multiplication result of the masking results of the first Boolean value and the second Boolean value includes: performing a bit multiplication on the masking results of the first Boolean value and the second Boolean value to obtain a bit multiplication result; obtaining a first random mask sent by a third party; and performing masking processing on the bit multiplication result based on a second random mask to obtain the first symbol coefficient fragment.
[0107] Optionally, it further includes: receiving a second random mask sent by a third party; calculating the sum of a first Boolean value and the first random mask as the mask result of the first Boolean value; sending the mask result of the first Boolean value to the second party for the second party to calculate the bit multiplication result; wherein, the third party provides a third random mask and a fourth random mask to the second party, the third random mask is used for the second party to perform masking processing on the second Boolean value, and the fourth random mask c1 is used for the second party to generate the second symbol coefficient fragment corresponding to the second target fragment, and satisfies a*b=c, c=c0+c1(mod L1), k is the truncation length, a is the second random mask, b is the third random mask, c0 is the first random mask, c1 is the fourth random mask, a, b, c, c0, c1 are all integers on the second integer ring, L1 is the length of the second integer ring, and the length of the second integer ring is less than the length of the first integer ring.
[0108] In one optional embodiment, mapping the first target piece from the original geometric space to a third target piece in the target geometric space includes: determining the original geometric space based on the range of values of the fixed-point product, the original geometric space including multiple sub-regions and boundary segmentation points corresponding to the multiple sub-regions; performing a cyclic right shift on the original geometric space based on the boundary segmentation points to obtain the target geometric space; and mapping the first target piece from the original geometric space to a third target piece in the target geometric space based on the cyclic right shift distance.
[0109] In one optional embodiment, mapping a first target partition to a signed partition based on a first signed coefficient partition includes: determining a correspondence between a first signed coefficient and a second signed coefficient based on the mapping relationship between the first target partition and a third target partition; the first signed coefficient refers to the signed coefficient corresponding to a first unsigned representation, and the second signed coefficient refers to the signed coefficient corresponding to a second unsigned representation, wherein the second unsigned representation is an unsigned number expressed through the third target partition and the second target partition; converting the first signed coefficient partition to a second signed coefficient partition based on the correspondence between the first and second signed coefficients; and mapping the first target partition to a signed partition based on the second signed coefficient partition.
[0110] Optionally, based on the correspondence between the first and second symbol coefficients, the first symbol coefficient piece is converted into a second symbol coefficient piece, including: determining the size relationship between the first target piece and the translation distance, and calculating the third Boolean value corresponding to the size relationship; the translation distance is the distance in the target geometric space where the third target piece is located obtained by cyclically translating the original geometric space where the first target piece is located; based on the correspondence between the first and second symbol coefficients, the difference between the first symbol coefficient piece and the third Boolean value is calculated and used as the second symbol coefficient piece.
[0111] In an optional embodiment, in the three-party secure computation, the first unsigned representation of the fixed-point product is mapped on the first integer ring to a first initial fragment, a second initial fragment, and a third initial fragment, and the first initial fragment, the second initial fragment, and the third initial fragment are held by the first party, the second party, and the third party in the three-party secure computation, respectively; the method further includes: a first remapping operation from the three-party secure computation to the two-party secure computation: treating the first party in the three-party secure computation as the first party in the two-party secure computation; constructing a first target fragment held by the first party in the two-party secure computation based on the first initial fragment and the second initial fragment held by the first party in the three-party secure computation; treating the second party in the three-party secure computation as the second party in the two-party secure computation; and treating the third party in the three-party secure computation as the third party that distributes random masks to the first party and the second party in the two-party secure computation to assist in the two-party secure computation.
[0112] Optionally, if the first party in the two-party secure computation obtains the first truncated fragment corresponding to the first target fragment, and the second party in the two-party secure computation calculates the second truncated fragment corresponding to the second target fragment, the method further includes: a second mapping operation from the two-party secure computation to the three-party secure computation: generating a fifth random mask and providing it to the third party in the three-party secure computation; performing masking processing on the first truncated fragment based on the fifth random mask to obtain the masking result of the first truncated fragment and sending it to the second party, so that the second party can use the masking result of the first truncated fragment... The masking result of the second truncated fragment is used to generate the third truncated fragment. The masking result of the second truncated fragment is obtained by masking the second truncated fragment based on the sixth random mask. The masking result of the second truncated fragment sent by the second party is received. Based on the masking result of the first truncated fragment and the masking result of the second truncated fragment, the third truncated fragment is generated, and the fifth random mask is used as the fourth truncated fragment. The second party holds the third truncated fragment and uses the sixth random mask as the fifth truncated fragment e3. The third party holds the fourth truncated fragment and the fifth truncated fragment.
[0113] This specification also provides another data truncation method for multi-party secure computation, applied to the second party. The first party holds a first target fragment, and the second party holds a second target fragment. The first and second target fragments are obtained by mapping a first unsigned representation x of a fixed-point product onto a first integer ring, such as... Figure 4 As shown, the method includes: 401. Based on the relative positional relationship between the second target piece and the second boundary point, generate the second Boolean value. The second boundary point is the boundary point defined by multiple sub-regions in the target geometric space along the vertical axis. The target geometric space is obtained by cyclically shifting the original geometric space to the right along the horizontal axis. One sub-region corresponds to one sign coefficient. The first target piece is mapped to the third target piece.
[0114] 402. Receive the mask result of the first Boolean value sent by the first party. The first Boolean value is generated based on the relative positional relationship between the third target fragment and the first boundary point. The second boundary point is the boundary point that defines multiple sub-regions in the horizontal axis direction.
[0115] 403. Generate the first symbol coefficient slice based on the mask result of the first Boolean value and the bit multiplication result of the first random mask.
[0116] 404. Based on the first sign coefficient partitioning, map the second target partitioning to a signed partitioning; truncate the signed partitioning to obtain the truncated partitioning corresponding to the second target partitioning.
[0117] In one optional embodiment, multiple sub-regions are divided into mutually exclusive first and second partitions by a horizontal line corresponding to the second boundary point; a second Boolean value is generated based on the relative position of the second target piece and the second boundary point, including: if the second target piece is greater than or equal to the ordinate value corresponding to the second boundary point, then the first bit value is used as the second Boolean value; the first bit value indicates that the second target piece belongs to the first partition; if the second target piece is less than the ordinate value, then the second bit value is used as the second Boolean value; the second bit value indicates that the second target piece belongs to the second partition.
[0118] In one optional embodiment, generating a first symbol coefficient fragment based on the mask result of the first Boolean value and the bit multiplication result of the first random mask includes: receiving a first random mask and a second random mask sent by a third party; performing a bit multiplication on the mask result of the first Boolean value and the first random mask to obtain a bit multiplication result; and performing masking processing on the bit multiplication result according to the second random mask to obtain the first symbol coefficient fragment.
[0119] Optionally, the method provided in the embodiments of this specification further includes: calculating the sum of a second Boolean value and a first random mask as the mask result of the second Boolean value; sending the mask result of the second Boolean value to a first party for the first party to calculate the bit multiplication result; wherein, a third party provides a third random mask and a fourth random mask to the first party, the third random mask is used for the first party to perform masking processing on the first Boolean value, and the fourth random mask is used for the first party to generate a second symbol coefficient fragment corresponding to the third target fragment, and satisfies a*b=c, c=c0+c1(mod L1), k is the truncation length, a is the first random mask, b is the third random mask, c0 is the second random mask, c1 is the fourth random mask, a, b, c, c0, and c1 are all integers on the second integer ring, L1 is the length of the second integer ring, and the length of the second integer ring is less than the length of the first integer ring.
[0120] For detailed implementation methods and effect descriptions in the above method embodiments, please refer to the foregoing embodiments, which will not be repeated here.
[0121] It should be noted that the execution subject of each step of the method provided in the above embodiments can be the same device, or the method can be executed by different devices. For example, the execution subject of steps 101 to 104 can be device A; or the execution subject of steps 101 and 102 can be device A, and the execution subject of step 103 can be device B; and so on.
[0122] Furthermore, some processes described in the above embodiments and accompanying drawings include multiple operations appearing in a specific order. However, it should be clearly understood that these operations may not be executed in the order they appear herein, or they may be executed in parallel. The operation numbers, such as 101, 102, etc., are merely used to distinguish different operations and do not represent any execution order. Additionally, these processes may include more or fewer operations, and these operations may be executed sequentially or in parallel. It should be noted that the descriptions such as "first" and "second" in this document are used to distinguish different messages, devices, modules, etc., and do not represent a sequential order, nor do they limit "first" and "second" to different types.
[0123] In this specification, unless explicitly stated otherwise, "receiving and sending data" does not necessarily mean direct receiving and sending; it can also mean indirect receiving and sending. For example, A receiving data sent by B can be understood as A directly receiving data sent by B, or it can be understood as A indirectly receiving data sent by B through other entities such as C. Similarly, B sending data to A can be understood as B sending data directly to A, or it can be understood as B indirectly sending data to A through other entities such as C. Here, C can be one entity, or it can be two or more entities.
[0124] Figure 5 This specification illustrates a schematic diagram of an electronic device provided in an exemplary embodiment, which is suitable for the data truncation method for multi-party secure computation provided in the foregoing embodiments. For example... Figure 5 As shown, the electronic device 700 mainly consists of a communication interface 702, a user interface 704, a processor 706, and a memory 708. These components are interconnected and communicate with each other through a system bus, network, or other connection mechanism 410. The communication interface 702 enables the device 700 to communicate with other devices, access networks, and transmission networks via analog or digital modulation. For example, the communication interface 702 may include a chipset and antenna for wireless communication with a radio access network or access point. Furthermore, the communication interface 702 can also be a wired interface such as Ethernet, Token Ring, or a USB port, or a wireless interface such as Wi-Fi (Wireless Fidelity), Bluetooth, Global Positioning System (GPS), or wide-area wireless interface such as WiMAX (Wireless Maximum) or LTE (Long Term Evolution). Of course, the communication interface 702 can also support other forms of physical layer interfaces and standard or proprietary communication protocols. The communication interface 702 may also include multiple physical communication interfaces, such as a Wi-Fi interface, a Bluetooth interface, and a wide-area wireless interface.
[0125] User interface 704 includes receiving user input and providing output to the user. Therefore, user interface 704 may include input components such as a keypad, keyboard, touch-sensitive or presence-sensitive panel, computer mouse, trackball, joystick, microphone, still camera, and video camera, and output components such as a display screen (which may be combined with a touch-sensitive panel), CRT (Cathode Ray Tube), LCD (Liquid Crystal Display), LED (Light Emitting Diode), display using DLP (Digital Light Processing) technology, printer, and other known or future similar devices. User interface 704 may also generate auditory output via speakers, speaker jacks, audio output ports, audio output devices, headphones, and other known or future similar devices. In some embodiments, user interface 704 may include software, circuitry, or other forms of logic capable of transmitting and receiving data from external user input / output devices. Additionally or alternatively, electronic device 700 may support remote access from other devices via communication interface 702 or another physical interface (not shown). User interface 704 can be configured to receive user input, the position and movement of which can be indicated by an indicator or cursor described herein. User interface 704 can also be configured as a display device for rendering or displaying text fragments.
[0126] Processor 706 may include one or more general-purpose processors and / or special-purpose processors. Memory 708 may include one or more volatile and / or non-volatile memory components and may be integrated wholly or partially with processor 706. Memory 708 may include removable and non-removable components.
[0127] The processor 706 is capable of executing program instructions 718 (e.g., compiled or uncompiled program logic and / or machine code) stored in memory 708 to perform the various functions described herein.
[0128] Memory 708 may contain non-transitory computer-readable media, such as Static Random-Access Memory (SRAM), Electrically Erasable Programmable Read-Only Memory (EEPROM), Erasable Programmable Read-Only Memory (EPROM), Programmable Read-Only Memory (PROM), Read-Only Memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk. Memory 708 stores program instructions that, when executed by device 700, enable device 700 to perform any of the methods, processes, or functions disclosed in this specification and / or the accompanying drawings. Processor 706 executing program instructions 718 may cause processor 706 to use data 712.
[0129] For example, program instructions 718 may include an operating system 722 (e.g., an operating system kernel, device drivers, and / or other modules) installed on device 700 and one or more applications 720 (e.g., a browser, social application, or game application). Similarly, data 712 may include operating system data 716 and application data 714. Operating system data 716 is primarily accessible to the operating system 722, while application data 714 is primarily accessible to one or more applications 720. Application data 714 may reside in a file system visible or hidden from the user of device 700.
[0130] Application 720 can communicate with operating system 722 through one or more application programming interfaces (APIs). These APIs help application 720 read and / or write application data 714, transmit or receive information via communication interface 702, receive or display information on user interface 704, etc.
[0131] In some terminology, application 720 may be simply referred to as "app". Furthermore, application 720 can be downloaded to device 700 through one or more online app stores or app markets. However, applications can also be installed on device 700 in other ways, such as through a web browser or a physical interface on electronic device 700 (e.g., a USB port).
[0132] Accordingly, embodiments of this specification also provide a computer-readable storage medium storing a computer program, which, when executed by a processor, enables the processor to implement the steps in the above-described method embodiments. The computer-readable storage medium includes volatile or non-volatile or a combination thereof, and can be removable or non-removable. Examples of computer-readable storage media include, but are not limited to, phase-change random access memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random-access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), flash memory or other memory technologies, CD-ROM, Digital Video Disc (DVD) or other optical storage, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transmission medium. Accordingly, embodiments of this specification also provide a computer program product, which includes a computer program or instructions that, when executed by a processor, cause the processor to implement the steps in the above-described method embodiments. It should be understood that each step or combination of steps in the above-described method flow can be implemented by the computer program or instructions. Furthermore, these computer programs or instructions can be applied to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device, enabling the processor of the general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing device to function as an apparatus for implementing the corresponding functions in the above-described method embodiments.
[0133] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, product, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, product, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, product, or apparatus that includes that element.
[0134] This specification uses specific terms to describe embodiments thereof. Terms such as "an embodiment," "one embodiment," and / or "some embodiments" refer to a particular feature, structure, or characteristic associated with at least one embodiment of this specification. Therefore, it should be emphasized and noted that references to "an embodiment," "one embodiment," or "an alternative embodiment" in different locations throughout this specification do not necessarily refer to the same embodiment. Furthermore, those skilled in the art can combine and integrate the different embodiments or examples described herein, as well as the features of those different embodiments or examples, without contradiction.
[0135] The terminology used in the embodiments of this specification is for the purpose of describing particular embodiments only and is not intended to be limiting of this specification. The singular forms “a,” “the,” and “the” used in the embodiments of this specification and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise. “Multiple” generally includes at least two, but does not exclude the inclusion of at least one. “A plurality” generally includes at least two, but does not exclude the inclusion of at least one.
[0136] It should be understood that the term "and / or" used in this article is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, and B existing alone. Additionally, the character " / " in this article generally indicates that the preceding and following related objects have an "or" relationship.
[0137] The above are merely embodiments of this specification and are not intended to limit this specification. Various modifications and variations can be made to this specification by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this specification should be included within the scope of the claims of this specification.
Claims
1. A data truncation method for multi-party secure computation, characterized in that, Applied to a first party, the first party holds a first target fragment, and a second party holds a second target fragment, wherein the first and second target fragments are obtained by mapping a first unsigned representation of a fixed-point product onto a first integer ring, the method includes: The first target piece is mapped from the original geometric space to the third target piece in the target geometric space. The target geometric space is obtained by cyclically shifting the original geometric space to the right along the horizontal axis. It includes multiple sub-regions defined based on the value range of the fixed-point product and the first dividing point of the multiple sub-regions in the horizontal axis direction. Each sub-region corresponds to a sign coefficient. A first Boolean value is generated based on the relative positional relationship between the third target segment and the first boundary point; The mask result of the second Boolean value sent by the second party is received. The second Boolean value is generated based on the relative positional relationship between the second target fragment and the second boundary point. The second boundary point is the boundary point defined by the multiple sub-regions in the vertical axis direction. The first symbol coefficient fragment is generated based on the bit multiplication result of the masking results of the first Boolean value and the second Boolean value; Based on the first sign coefficient partitioning, the first target partition is mapped to a signed partition; The signed fragment is truncated to obtain the first truncated fragment corresponding to the first target fragment.
2. The method according to claim 1, characterized in that, The multiple sub-regions are divided into mutually exclusive first and second partitions by the vertical line corresponding to the first dividing point. Based on the relative positional relationship between the third target fragment and the first boundary point, a first Boolean value is generated, including: If the third target fragment is greater than or equal to the x-coordinate value corresponding to the first boundary point, then the first bit value is used as the first Boolean value, and the first bit value indicates that the third target fragment belongs to the first partition; If the third target fragment is smaller than the horizontal coordinate value, then the second bit value is used as the first Boolean value; the second bit value indicates that the third target fragment belongs to the second partition.
3. The method according to claim 1, characterized in that, Based on the bit multiplication result of the masking results of the first Boolean value and the second Boolean value, a first symbol coefficient fragment is generated, including: Perform a bitwise multiplication on the masked results of the first Boolean value and the second Boolean value to obtain the bitwise multiplication result; Obtain the first random mask sent by the third party; The bit multiplication result is masked according to the second random mask to obtain the first symbol coefficient fragment.
4. The method according to claim 3, characterized in that, Also includes: Receive a second random mask sent by a third party; The sum of the first Boolean value and the first random mask is calculated as the mask result of the first Boolean value; The mask result of the first Boolean value is sent to the second party so that the second party can calculate the bit multiplication result; The third party provides the second party with a third random mask and a fourth random mask. The third random mask is used by the second party to mask the second Boolean value. The fourth random mask c1 is used by the second party to generate the second symbol coefficient fragment corresponding to the second target fragment, and satisfies a*b=c, c=c0+c1(mod L1). a is the second random mask, b is the third random mask, c0 is the first random mask, c1 is the fourth random mask, a, b, c, c0, and c1 are all integers on the second integer ring, and L1 is the length of the second integer ring, which is less than the length of the first integer ring.
5. The method according to claim 1, characterized in that, Mapping the first target piece from the original geometric space to the third target piece in the target geometric space includes: Based on the range of values of the fixed-point product, the original geometric space is determined, which includes multiple sub-regions and the boundary dividing points corresponding to the multiple sub-regions; Based on the boundary segmentation points, the original geometric space is cyclically shifted to the right to obtain the target geometric space; Based on the cyclic right shift distance, the first target piece is mapped from the original geometric space to the third target piece in the target geometric space.
6. The method according to claim 1, characterized in that, Based on the first sign coefficient partitioning, mapping the first target partition to a signed partition includes: Based on the mapping relationship between the first target fragment and the third target fragment, the correspondence between the first symbol coefficient and the second symbol coefficient is determined; The first sign coefficient refers to the sign coefficient corresponding to the first unsigned representation, and the second sign coefficient refers to the sign coefficient corresponding to the second unsigned representation. The second unsigned representation is an unsigned number expressed by the third target fragment and the second target fragment. Based on the correspondence between the first symbol coefficient and the second symbol coefficient, the first symbol coefficient fragment is converted into a second symbol coefficient fragment; Based on the second sign coefficient sharding, the first target shard is mapped to a signed shard.
7. The method according to claim 6, characterized in that, Based on the correspondence between the first and second symbol coefficients, the first symbol coefficient fragment is converted into a second symbol coefficient fragment, including: Determine the relationship between the first target piece and the translation distance, and calculate the third Boolean value corresponding to the relationship; the translation distance is the distance to the target geometric space where the third target piece is located obtained by cyclically translating the original geometric space where the first target piece is located. Based on the correspondence between the first symbol coefficient and the second symbol coefficient, the difference between the first symbol coefficient slice and the third Boolean value is calculated and used as the second symbol coefficient slice.
8. The method according to any one of claims 1-7, characterized in that, In the third-party secure computation, the first unsigned representation of the fixed-point product is mapped on the first integer ring to a first initial fragment, a second initial fragment, and a third initial fragment, and the first initial fragment, the second initial fragment, and the third initial fragment are held by the first party, the second party, and the third party in the third-party secure computation, respectively. The method further includes: a first mapping operation from three-party secure computation to two-party secure computation. The first party in the three-party secure computation is taken as the first party in the two-party secure computation. Based on the first initial fragment and the second initial fragment held by the first party in the three-party secure computation, the first target fragment held by the first party in the two-party secure computation is constructed. The second party in the three-party secure computation is treated as the second party in the two-party secure computation, and the third initial fragment held by the second party in the three-party secure computation is treated as the second target fragment held by the second party in the two-party secure computation; and In three-party secure computation, the third party is used to distribute random masks to the first and second parties to assist in two-party secure computation.
9. The method according to claim 8, characterized in that, In the case that the first party in the two-party secure computation obtains the first truncated fragment corresponding to the first target fragment, and the second party in the two-party secure computation calculates the second truncated fragment corresponding to the second target fragment, the method further includes: a second mapping operation from two-party secure computation to three-party secure computation. Generate a fifth random mask and provide it to the third party in the secure computation. The first truncated fragment is masked based on the fifth random mask to obtain the mask result of the first truncated fragment and send it to the second party so that the second party can generate the third truncated fragment based on the mask result of the first truncated fragment and the mask result of the second truncated fragment. The mask result of the second truncated fragment is obtained by masking the second truncated fragment based on the sixth random mask. Receive the mask result of the second truncated fragment sent by the second party; Based on the mask results of the first truncated fragment and the mask results of the second truncated fragment, the third truncated fragment is generated, and the fifth random mask is used as the fourth truncated fragment. The second party holds the third truncated fragment and uses the sixth random mask as the fifth truncated fragment e3, while the third party holds the fourth truncated fragment and the fifth truncated fragment.
10. A data truncation method for multi-party secure computation, characterized in that, Applied to a second party, where the first party holds a first target fragment and the second party holds a second target fragment, the first and second target fragments are obtained by mapping a first unsigned representation of a fixed-point product onto a first integer ring, the method comprising: Based on the relative positional relationship between the second target piece and the second boundary point, a second Boolean value is generated. The second boundary point is the boundary point defined by multiple sub-regions in the target geometric space along the vertical axis. The target geometric space is obtained by cyclically shifting the original geometric space to the right along the horizontal axis. One sub-region corresponds to one sign coefficient. The first target piece is mapped to the third target piece. The mask result of the first Boolean value sent by the first party is received. The first Boolean value is generated based on the relative positional relationship between the third target fragment and the first boundary point. The second boundary point is the boundary point defined by the multiple sub-regions in the horizontal axis direction. Based on the mask result of the first Boolean value and the bit multiplication result of the first random mask, a first symbol coefficient fragment is generated; Based on the first sign coefficient partition, the second target partition is mapped to a signed partition; the signed partition is truncated to obtain the truncated partition corresponding to the second target partition.
11. The method according to claim 10, characterized in that, The multiple sub-regions are divided into mutually exclusive first and second partitions by the horizontal line corresponding to the second boundary point. Based on the relative positional relationship between the second target fragment and the second boundary point, a second Boolean value is generated, including: If the second target fragment is greater than or equal to the ordinate value corresponding to the second boundary point, then the first bit value is used as the second Boolean value; the first bit value indicates that the second target fragment belongs to the first partition; If the second target fragment is smaller than the vertical coordinate value, then the second bit value is used as the second Boolean value; the second bit value indicates that the second target fragment belongs to the second partition.
12. The method according to claim 10, characterized in that, Based on the masking result of the first Boolean value and the bit multiplication result of the first random mask, a first symbol coefficient slice is generated, including: Receive the first and second random masks sent by a third party; Perform a bitwise multiplication on the mask result of the first Boolean value and the first random mask to obtain the bitwise multiplication result; The bit multiplication result is masked according to the second random mask to obtain the first symbol coefficient fragment.
13. The method according to claim 12, characterized in that, Also includes: The sum of the second Boolean value and the first random mask is calculated as the mask result of the second Boolean value; The mask result of the second Boolean value is sent to the first party so that the first party can calculate the bit multiplication result; The third party provides the first party with a third random mask and a fourth random mask. The third random mask is used by the first party to perform masking processing on the first Boolean value. The fourth random mask is used by the first party to generate a second symbol coefficient fragment corresponding to the third target fragment, and satisfies a*b=c, c=c0+c1(mod L1), where a is the first random mask, b is the third random mask, c0 is the second random mask, c1 is the fourth random mask, a, b, c, c0, and c1 are all integers on the second integer ring, and L1 is the length of the second integer ring, which is less than the length of the first integer ring.
14. An electronic device, characterized in that, include: A memory and a processor; the memory is used to store one or more computer instructions; the processor is used to execute the one or more computer instructions for: performing the steps of the method according to any one of claims 1-13.
15. A computer-readable storage medium storing a computer program, characterized in that, When a computer program is executed by a processor, it is able to perform the steps of the method described in any one of claims 1-13.
16. A computer program product, characterized in that, include: A computer program / instruction that, when executed by a processor, enables the implementation of the steps in the method according to any one of claims 1-13.