Boolean circuits for merging and splitting data slices

By optimizing the XOR and AND gate combination in Boolean circuits, the problem of high communication cost in data sharding merging and splitting in secure multi-party computing is solved, and the effect of minimizing communication cost is achieved.

CN113868716BActive Publication Date: 2025-08-19SASI DIGITAL TECHNOLOGY (BEIJING) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111126947.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-09-18
Publication Date
2025-08-19
Estimated Expiration
2041-09-18

AI Technical Summary

Technical Problem

The prior art has high communication costs when merging and splitting data shards in secure multi-party computing, making it difficult to minimize.

Method used

Design a Boolean circuit to optimize the merge and splitting process of data intermediate bits through the combination of XOR and AND gates, reducing the number of AND gates to achieve the minimum communication cost.

Benefits of technology

It realizes minimizing communication costs in the merger and splitting process of data sharding in secure multi-party computing, and improves efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113868716B_ABST
    Figure CN113868716B_ABST
Patent Text Reader

Abstract

The embodiments of this specification provide a Boolean circuit for merging data slices, and a Boolean circuit for splitting data slices, which are implemented using multi-party secure computing, such as an obfuscation circuit. The Boolean circuit for merging data slices includes: a first merging module for merging the intermediate bits of the input data that are not the first and last bits; the first merging module further includes: a first sum calculation unit, which merges the current bit of the first slice, the current bit of the second slice, and the carry of the previous bit through an XOR gate, and outputs the current bit of the input data; a first carry calculation unit, which uses a single AND gate to perform an AND operation on the two intermediate results of the XOR operation of the current bit of the first slice and the current bit of the second slice with the carry of the previous bit, and outputs the carry of the current bit based on the AND operation result. The minimum communication cost can be achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] One or more embodiments of the present disclosure relate to the field of computers, and more particularly, to Boolean circuits for merging and splitting data slices. Background Art

[0002] Secure multi-party computation, also known as multi-party secure computation, involves multiple parties working together to compute the result of a function without revealing the input data of each party involved. The result is then made public to one or more of the parties involved. The input data of each party is often private.

[0003] In secure multi-party computation, data may be split into data shards, or data shards may be merged to obtain data. The above data shards usually refer to addition shards (ADDShare), that is, a number in modulo 2 n The integer ring of the space is split into two additive slices by subtraction. These two additive slices are modulo 2. n Adding on the integer ring of the space can get the original number, and each party holds an addition slice. The addition slice is an unsigned number.

[0004] It is desirable to provide a Boolean circuit for merging data slices and a Boolean circuit for splitting data slices, which can achieve minimum communication cost. Summary of the Invention

[0005] One or more embodiments of this specification describe a Boolean circuit for merging data slices and a Boolean circuit for splitting data slices, which can achieve minimum communication cost.

[0006] In a first aspect, a Boolean circuit for merging data slices is provided, wherein a first slice and a second slice of input data are distributed on a first side and a second side, respectively, and the Boolean circuit comprises:

[0007] a first merging module for merging intermediate bits of the input data that are not the first bit and the last bit; the first merging module further comprises:

[0008] A first sum calculation unit combines the current bit of the first slice, the current bit of the second slice, and the carry of the previous bit of the input data through an XOR gate, and outputs the current bit of the input data;

[0009] The first carry calculation unit uses a single AND gate to perform an AND operation on two intermediate results of performing exclusive OR operations on the current bit of the first slice and the current bit of the second slice and the carry of the previous bit, and outputs the carry of the current bit based on the AND operation result.

[0010] In a possible implementation, the first sum calculation unit includes a first XOR gate and a second XOR gate;

[0011] The first XOR gate receives the carry of the previous bit and the current bit of the first slice, and outputs a first intermediate result;

[0012] The second XOR gate receives the first intermediate result and the current bit of the second slice, and outputs the current bit of the input data;

[0013] The first carry calculation unit includes a third XOR gate, a fourth XOR gate, and a first AND gate as the single AND gate;

[0014] The third XOR gate receives the carry of the previous bit and the current bit of the second slice, and outputs a second intermediate result;

[0015] The first AND gate receives the first intermediate result and the second intermediate result, and outputs the AND operation result;

[0016] The fourth XOR gate receives the carry of the previous bit and the AND operation result, and outputs the carry of the current bit.

[0017] In a possible implementation manner, the Boolean circuit further includes:

[0018] a second merging module for merging the first bit of the input data; the second merging module further comprising:

[0019] The second sum calculation unit receives the first bit of the first slice and the first bit of the second slice by using the fifth XOR gate, and outputs the first bit of the input data;

[0020] The second carry calculation unit receives the first digit of the first slice and the first digit of the second slice using a second AND gate, and outputs the carry of the first digit.

[0021] In a possible implementation manner, the Boolean circuit further includes:

[0022] a third merging module for merging the last bits of the input data; the third merging module comprises a sixth XOR gate and a seventh XOR gate;

[0023] The sixth XOR gate receives the carry of the previous bit and the last bit of the first slice, and outputs a first intermediate result;

[0024] The seventh XOR gate receives the first intermediate result and the last bit of the second slice, and outputs the last bit of the combined input data.

[0025] In a possible implementation, the Boolean circuit is implemented in a manner similar to a garbled circuit.

[0026] In a second aspect, a Boolean circuit for splitting data slices is provided, wherein the Boolean circuit is used to obtain a second slice of input data based on input data and a first slice of input data, and the Boolean circuit includes:

[0027] A first splitting module for splitting the middle bits of the input data that are not the first bit and the last bit; the first splitting module further includes:

[0028] A first difference calculation unit is configured to split the current bit of the input data, the current bit of the first slice, and the borrow of the previous bit input therein through an XOR gate, and output the current bit of the second slice;

[0029] a first borrow inversion unit, using a single AND gate, performing an AND operation on an intermediate result of an XOR operation between a current bit of the first slice and a borrow of a previous bit, and an intermediate result of an XOR operation between a current bit of the input data and the borrow inversion of a previous bit, and outputting a borrow inversion of the current bit based on the AND operation result;

[0030] The first borrow calculation unit utilizes a first NOT gate to invert the borrow of the current bit and output the borrow of the current bit.

[0031] In a possible implementation, the first difference calculation unit includes a first XOR gate and a second XOR gate;

[0032] The first XOR gate receives the borrow bit of the previous bit and the current bit of the first slice, and outputs a first intermediate result;

[0033] The second XOR gate receives the first intermediate result and the current bit of the input data, and outputs the current bit of the second slice;

[0034] The first borrow inversion unit includes a third XOR gate, a fourth XOR gate, and a first AND gate as the single AND gate;

[0035] The third XOR gate receives the inverted borrow bit of the previous bit and the current bit of the input data, and outputs a second intermediate result;

[0036] The first AND gate receives the first intermediate result and the second intermediate result, and outputs a third intermediate result;

[0037] The fourth XOR gate receives the borrow inversion of the previous bit and the third intermediate result, and outputs the borrow inversion of the current bit.

[0038] In a possible implementation manner, the Boolean circuit further includes:

[0039] A second splitting module for splitting the first bit of the input data; the second splitting module further comprises:

[0040] The second difference calculation unit receives the first bit of the input data and the first bit of the first slice using the fifth XOR gate, and outputs the first bit of the second slice;

[0041] A second borrow calculation unit includes a second NOT gate and a second AND gate;

[0042] The second NOT gate receives the first bit of the input data and outputs a first intermediate result;

[0043] The second AND gate receives the first intermediate result and the first bit of the first slice, and outputs a borrow bit of the first bit;

[0044] The second borrow inversion unit receives the borrow of the first bit by using the third NOT gate and outputs the borrow inversion of the first bit.

[0045] In a possible implementation manner, the Boolean circuit further includes:

[0046] A third splitting module for splitting the last bit of the input data; the third splitting module further comprises:

[0047] The sixth XOR gate receives the borrow bit of the previous bit and the last bit of the first slice, and outputs the first intermediate result;

[0048] The seventh XOR gate receives the first intermediate result and the last bit of the input data, and outputs the last bit of the second slice.

[0049] In a possible implementation, the Boolean circuit is implemented in a manner similar to a garbled circuit.

[0050] In a third aspect, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed in a computer, the computer realizes the Boolean circuit of the first aspect or the second aspect.

[0051] In a fourth aspect, a computing device is provided, comprising a memory and a processor, wherein the memory stores executable code, and when the processor executes the executable code, the Boolean circuit of the first aspect or the second aspect is implemented.

[0052] Through the Boolean circuit for merging data slices provided by the embodiment of this specification, the first slice and the second slice of the input data are distributed on the first side and the second side respectively, and the Boolean circuit includes: a first merging module for merging the middle bits of the data that are not the first and last bits of the input data; the first merging module further includes: a first sum calculation unit, which merges the current bit of the first slice, the current bit of the second slice and the carry of the previous bit through an XOR gate, and outputs the current bit of the input data; a first carry calculation unit, which uses a single AND gate to perform an AND operation on the two intermediate results of the XOR operation of the current bit of the first slice and the current bit of the second slice with the carry of the previous bit, and outputs the carry of the current bit based on the AND operation result. As can be seen from the above, in the embodiment of this specification, if the input data is n bits, there are n-2 middle bits of data in the input data, and there are only n-2 AND gates in the circuit for merging the middle bits of the data, which is the minimum, so that for the common Boolean circuit execution method, the minimum communication cost can be achieved.

[0053] A Boolean circuit for splitting data slices provided by an embodiment of this specification is used to obtain a second slice of input data based on input data and a first slice of input data. The Boolean circuit includes: a first splitting module for splitting the middle bit of the data that is not the first and last bit of the input data; the first splitting module further includes: a first difference calculation unit, which splits the current bit of the input data input therein, the current bit of the first slice, and the borrow bit of the previous bit through an XOR gate, and outputs the current bit of the second slice; a first borrow inversion unit, which uses a single AND gate to perform an AND operation on the intermediate result of the XOR operation of the current bit of the first slice and the borrow bit of the previous bit, and the intermediate result of the XOR operation of the current bit of the input data and the borrow bit inversion of the previous bit, and outputs the borrow bit inversion of the current bit based on the AND operation result; a first borrow calculation unit, which uses a first NOT gate to invert the borrow bit inversion of the current bit and output the borrow bit of the current bit. As can be seen from the above, in the embodiment of this specification, if the input data is n bits, there are n-2 data middle bits in the input data, and there are only n-2 AND gates in the circuit to split the data middle bits, which is the minimum. Therefore, for the execution method of common Boolean circuits, the minimum communication cost can be achieved. BRIEF DESCRIPTION OF THE DRAWINGS

[0054] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0055] Figure 1A schematic diagram of an implementation scenario of an embodiment disclosed in this specification;

[0056] Figure 2 This is a schematic diagram of an implementation scenario of another embodiment disclosed in this specification;

[0057] Figure 3 This is a schematic diagram of an implementation scenario of another embodiment disclosed in this specification;

[0058] Figure 4 A schematic diagram of a Boolean circuit structure for merging data slices according to one embodiment is shown;

[0059] Figure 5 FIG. 4 is a schematic diagram showing a circuit structure of a first merging module 41 according to an embodiment;

[0060] Figure 6 A schematic diagram of a Boolean circuit structure for merging data slices according to another embodiment is shown;

[0061] Figure 7 A schematic diagram of a Boolean circuit structure for merging data slices according to another embodiment is shown;

[0062] Figure 8 A schematic diagram of a Boolean circuit structure for splitting data slices according to one embodiment is shown;

[0063] Figure 9 FIG. 8 is a schematic diagram showing a circuit structure of a first splitting module 81 according to an embodiment;

[0064] Figure 10 A schematic diagram of a Boolean circuit structure for splitting data slices according to another embodiment is shown;

[0065] Figure 11 A schematic diagram of a Boolean circuit structure for splitting data slices according to another embodiment is shown. DETAILED DESCRIPTION

[0066] The solution provided in this specification is described below in conjunction with the accompanying drawings.

[0067] Figure 1 This is a schematic diagram of an implementation scenario of an embodiment disclosed in this specification. This implementation scenario involves a Boolean circuit for merging data slices. Figure 1The first and second slices of the input data are distributed on the first and second sides respectively. The input of the Boolean circuit includes the first slice a0 of the input data and the second slice a1 of the input data, and the output is the input data a. Among them, the first slice a0 and the second slice a1 belong to addition slices, with a length of n bits, that is, n bits. a, a0, and a1 are all unsigned numbers, a=a0+a1. The Boolean circuit is used to merge addition slices, that is, to realize the function of the addition circuit.

[0068] A Boolean circuit is a collection of logic gates connected by wires that compute a function on a set of inputs and output a result. Logic gates include AND, XOR, and NOT gates, which implement Boolean functions. Generally, a function can be compiled into a set of AND, XOR, and NOT gates to complete the calculation.

[0069] In the embodiments of this specification, the number of AND gates for merging the middle bits of data in the circuit is minimized, thereby achieving the minimum communication cost for the execution mode of a common Boolean circuit.

[0070] The communication cost includes the communication volume and the number of communication rounds.

[0071] Figure 2 This is a schematic diagram of another implementation scenario of the embodiment disclosed in this specification. This implementation scenario involves a Boolean circuit for splitting data slices. Figure 2 The Boolean circuit is used to obtain the second slice of the input data based on the input data and the first slice of the input data. The input of the Boolean circuit includes the input data b and the first slice b0 of the input data, and the output is the second slice b1 of the input data, wherein the first slice b0 and the second slice b1 are addition slices with a length of n bits, i.e., n bits. b, b0, and b1 are all unsigned numbers, b1=b-b0. The Boolean circuit is used to split the addition slice, that is, to realize the function of the subtraction circuit.

[0072] In the embodiments of this specification, the number of AND gates used to split the middle bits of data in the circuit is minimized, thereby achieving the minimum communication cost for the execution of common Boolean circuits.

[0073] Figure 3 This is a schematic diagram of an implementation scenario of another embodiment disclosed in this specification. This implementation scenario involves a first Boolean circuit for merging data slices, a second Boolean circuit as a calculation operator, and a third Boolean circuit for splitting data slices. The above-mentioned calculation operators are used to implement specific calculation functions. Figure 3The first Boolean circuit receives the first slice a0 of the data input by the first party and the second slice a1 of the data input by the second party, and outputs the data a obtained by adding a0 and a1; the second Boolean circuit receives the above data a, and outputs the data b processed by a specific calculation function; the third Boolean circuit receives the above data b and the first slice b0 of the data b input by the first party, and outputs the second slice b1 of the data b obtained by subtracting b and b0 to the second party.

[0074] A garbled circuit (GC) is a two-party secure multi-party computation protocol. It uses cryptographic functions to generate an obfuscation table for a Boolean circuit implementing a computational function. The result is calculated for two inputs, and the input of one party is not leaked to the other during the computation process. Currently, the optimal implementation of a garbled circuit requires no communication for XOR and NOT gates, requiring only local computation. However, AND gates require cryptographic computation and communication, and in general applications, communication volume is the bottleneck for throughput. The communication volume of a garbled circuit is positively correlated with the number of AND gates in the Boolean circuit.

[0075] Obfuscated circuits are commonly used to implement functions like division, comparison, and selection. As a computational operator, they can also implement entire computational logic. Secret sharing is commonly used to implement operations like addition and multiplication, requiring significantly less communication than obfuscated circuits. Secret sharing is based on the addition of slices.

[0076] The obfuscation circuit implements the above calculation operator. When the calculation operator is executed, its input may be the calculation result of secret sharing, and its output may be the calculation input of secret sharing. That is, the input or output of the operator of the obfuscation circuit may be an addition slice.

[0077] The embodiments of this specification propose a solution for input addition slicing and output addition slicing of a garbled circuit that requires only one round of communication and has the least number of AND gates.

[0078] It should be noted that, according to the different specific input and output requirements, the aforementioned first Boolean circuit, second Boolean circuit and third Boolean circuit can also have other combinations. For example, when the calculation operator is executed, there is only a requirement to merge data slices for the input, and there is no requirement to split data slices for the output, then the circuit structure only includes the aforementioned first Boolean circuit and second Boolean circuit; or, when the calculation operator is executed, there is no requirement to merge data slices for the input, and there is only a requirement to split data slices for the output, then the circuit structure only includes the aforementioned second Boolean circuit and third Boolean circuit.

[0079] Figure 4 FIG. 1 shows a schematic diagram of a Boolean circuit structure for merging data slices according to an embodiment, wherein the first slice and the second slice of the input data are distributed on the first side and the second side respectively. Figure 4 As shown, the Boolean circuit 400 includes:

[0080] A first merging module 41 for merging the middle bits of the input data that are not the first bit and the last bit; the first merging module 41 further includes:

[0081] The first sum calculation unit 411 combines the current bit of the first slice, the current bit of the second slice, and the carry of the previous bit of the input data through an XOR gate, and outputs the current bit of the input data;

[0082] The first carry calculation unit 412 uses a single AND gate to perform an AND operation on two intermediate results of the XOR operation of the current bit of the first slice and the current bit of the second slice with the carry of the previous bit, and outputs the carry of the current bit based on the AND operation result.

[0083] Among them, the exclusive OR gate: c = XOR (a, b), means c = a^b.

[0084] AND gate: c = AND(a,b), which means c = a & b.

[0085] Optionally, as an embodiment, the first sum calculation unit 411 includes a first XOR gate and a second XOR gate;

[0086] The first XOR gate receives the carry of the previous bit and the current bit of the first slice, and outputs a first intermediate result;

[0087] The second XOR gate receives the first intermediate result and the current bit of the second slice, and outputs the current bit of the input data;

[0088] The first carry calculation unit 412 includes a third XOR gate, a fourth XOR gate, and a first AND gate as the single AND gate;

[0089] The third XOR gate receives the carry of the previous bit and the current bit of the second slice, and outputs a second intermediate result;

[0090] The first AND gate receives the first intermediate result and the second intermediate result, and outputs the AND operation result;

[0091] The fourth XOR gate receives the carry of the previous bit and the AND operation result, and outputs the carry of the current bit.

[0092] Figure 5The following is a schematic diagram of the circuit structure of the first merging module 41 according to one embodiment. The first merging module 41 includes an XOR gate 51, an XOR gate 52, an XOR gate 53, an AND gate 54, and an XOR gate 55, which correspond to the first XOR gate, the second XOR gate, the third XOR gate, the first AND gate, and the fourth XOR gate, respectively. XOR gate 51 receives the carry bit of the previous bit and the current bit a0[i] of the first slice and outputs the first intermediate result t0; XOR gate 52 receives the first intermediate result t0 and the current bit a1[i] of the second slice and outputs the current bit a[i] of the input data; it can be understood that a[i] = carry^a0[i]^a1[i]. Among them, the XOR gate 53 receives the carry of the previous bit and the current bit a1[i] of the second slice, and outputs the second intermediate result t1; the AND gate 54 receives the first intermediate result t0 and the second intermediate result t1, and outputs the AND operation result t2; the XOR gate 55 receives the carry of the previous bit and the AND operation result t2, and outputs the carry of the current bit; it can be understood that carry = (carry^a0[i])&(carry^a1[i])^carry.

[0093] The first merging module 41 is specifically configured to perform the following processes in sequence:

[0094] t0=XOR(carry,a0[i])

[0095] a[i]=XOR(t0,a1[i])

[0096] t1=XOR(carry,a1[i])

[0097] t2=AND(t0,t1)

[0098] carry=XOR(carry,t2)

[0099] It is understandable that the circuit structure provided in the embodiments of this specification is not unique. Figure 5 A slight modification on the basis of the circuit structure shown can also achieve the purpose of outputting the current bit a[i] of the input data and outputting the carry of the current bit. Taking a[i] as an example, the above modification can be, but is not limited to, exchanging the order of XOR objects. For example, a[i]=a1[i]^carry^a0[i], and the aforementioned a[i]=carry^a0[i]^a1[i] have the same execution effect and will not affect the correctness of a[i].

[0100] Figure 6 FIG. 1 shows a schematic diagram of a Boolean circuit structure for merging data slices according to another embodiment. Figure 6 , the Boolean circuit 400 further includes:

[0101] A second merging module 42 for merging the first bit of the input data; the second merging module 42 further includes:

[0102] The second sum calculation unit 421 receives the first bit of the first slice and the first bit of the second slice using the fifth XOR gate, and outputs the first bit of the input data;

[0103] The second carry calculation unit 422 receives the first digit of the first slice and the first digit of the second slice using a second AND gate, and outputs the carry of the first digit.

[0104] The second merging module 42 is specifically configured to perform the following processing:

[0105] a[0]=XOR(a0[0],a1[0])

[0106] carry=AND(a0[0],a1[0])

[0107] It is understandable that there is no strict execution order for the above two logical operations. You can determine a[0] first and then determine carry; you can also determine carry first and then determine a[0].

[0108] Figure 7 FIG. 1 shows a schematic diagram of a Boolean circuit structure for merging data slices according to another embodiment. Figure 7 , the Boolean circuit 400 further includes:

[0109] a third merging module 43 for merging the last bits of the input data; the third merging module 43 comprises a sixth XOR gate and a seventh XOR gate;

[0110] The sixth XOR gate receives the carry of the previous bit and the last bit of the first slice, and outputs a first intermediate result;

[0111] The seventh XOR gate receives the first intermediate result and the last bit of the second slice, and outputs the last bit of the combined input data.

[0112] The third merging module 43 is specifically configured to perform the following processing:

[0113] t0=XOR(carry,a0[n-1])

[0114] a[n-1]=XOR(t0,a1[n-1])

[0115] It can be understood that when merging the last bit of the input data, it is only necessary to determine the last bit of the merged input data, and there is no need to determine the carry bit.

[0116] Optionally, as an embodiment, the Boolean circuit adopts an execution mode of a garbled circuit.

[0117] Through the Boolean circuit for merging data slices provided by the embodiment of this specification, the first slice and the second slice of the input data are distributed on the first side and the second side respectively, and the Boolean circuit includes: a first merging module for merging the middle bits of the data that are not the first and last bits of the input data; the first merging module further includes: a first sum calculation unit, which merges the current bit of the first slice, the current bit of the second slice and the carry of the previous bit through an XOR gate, and outputs the current bit of the input data; a first carry calculation unit, which uses a single AND gate to perform an AND operation on the two intermediate results of the XOR operation of the current bit of the first slice and the current bit of the second slice with the carry of the previous bit, and outputs the carry of the current bit based on the AND operation result. As can be seen from the above, in the embodiment of this specification, if the input data is n bits, there are n-2 middle bits of data in the input data, and there are only n-2 AND gates in the circuit for merging the middle bits of the data, which is the minimum, so that for the common Boolean circuit execution method, the minimum communication cost can be achieved.

[0118] Figure 8 FIG. 1 shows a schematic diagram of a Boolean circuit structure for splitting data slices according to an embodiment, wherein the Boolean circuit is used to obtain a second slice of the input data based on the input data and the first slice of the input data. Figure 8 As shown, the Boolean circuit 800 includes:

[0119] A first splitting module 81 for splitting the middle bits of the input data that are not the first bit and the last bit; the first splitting module 81 further includes:

[0120] The first difference calculation unit 811 splits the current bit of the input data, the current bit of the first slice, and the borrow bit of the previous bit input thereto through an XOR gate, and outputs the current bit of the second slice;

[0121] The first borrow negation unit 812 uses a single AND gate to perform an AND operation on an intermediate result of an XOR operation between the current bit of the first slice and the borrowed bit of the previous bit, and an intermediate result of an XOR operation between the current bit of the input data and the borrowed bit negation of the previous bit, and outputs the borrowed bit negation of the current bit based on the AND operation result.

[0122] The first borrow calculation unit 813 uses a first NOT gate to invert the borrow of the current bit and output the borrow of the current bit.

[0123] Optionally, as an embodiment, the first difference calculation unit 811 includes a first XOR gate and a second XOR gate;

[0124] The first XOR gate receives the borrow bit of the previous bit and the current bit of the first slice, and outputs a first intermediate result;

[0125] The second XOR gate receives the first intermediate result and the current bit of the input data, and outputs the current bit of the second slice;

[0126] The first borrow inversion unit 812 includes a third XOR gate, a fourth XOR gate, and a first AND gate as the single AND gate;

[0127] The third XOR gate receives the inverted borrow bit of the previous bit and the current bit of the input data, and outputs a second intermediate result;

[0128] The first AND gate receives the first intermediate result and the second intermediate result, and outputs a third intermediate result;

[0129] The fourth XOR gate receives the borrow inversion of the previous bit and the third intermediate result, and outputs the borrow inversion of the current bit.

[0130] Figure 9 The circuit structure diagram of the first splitting module 81 according to one embodiment is shown. The first splitting module 81 includes an XOR gate 91, an XOR gate 92, an XOR gate 93, an AND gate 94, an XOR gate 95, and a NOT gate 96, which correspond to the first XOR gate, the second XOR gate, the third XOR gate, the first AND gate, the fourth XOR gate, and the first NOT gate. The XOR gate 91 receives the borrow bit of the previous bit and the current bit b0[i] of the first slice and outputs the first intermediate result t0; the XOR gate 92 receives the first intermediate result t0 and the current bit b[i] of the input data and outputs the current bit b1[i] of the second slice. It can be understood that b1[i] = b[i]^b0[i]^borrow. XOR gate 93 receives the previous bit's borrow_inv and the current bit b[i] of the input data, and outputs the second intermediate result t1. AND gate 94 receives the first intermediate result t0 and the second intermediate result t1, and outputs the third intermediate result t2. XOR gate 95 receives the previous bit's borrow_inv and the third intermediate result t2, and outputs the current bit's borrow_inv. It can be understood that borrow_inv = (borrow_inv^b[i]) & (borrow^b0[i])^borrow_inv. NOT gate 96 receives the current bit's borrow_inv and outputs the current bit's borrow. It can be understood that borrow = INV(borrow_inv).

[0131] The first splitting module 81 is specifically configured to perform the following processes in sequence:

[0132] t0=XOR(borrow,b0[i])

[0133] b1[i]=XOR(t0,b[i])

[0134] t1=XOR(borrow_inv,b[i])

[0135] t2=AND(t0,t1)

[0136] borrow_inv=XOR(borrow_inv,t2)

[0137] borrow = INV (borrow_inv)

[0138] It is understandable that the circuit structure provided in the embodiments of this specification is not unique. Figure 9 With slight changes based on the circuit structure shown, the purpose of outputting the current bit b1[i] of the second slice, outputting the borrow inversion of the current bit borrow_inv, and outputting the borrow of the current bit borrow can also be achieved. Taking b1[i] as an example, the above changes can be, but are not limited to, exchanging the order of XOR objects. For example, b1[i]=borrow^b[i]^b0[i], and the aforementioned b1[i]=b[i]^b0[i]^borrow, the execution effects of the two are the same, and will not affect the correctness of b1[i].

[0139] Figure 10 FIG. 1 shows a schematic diagram of a Boolean circuit structure for splitting data slices according to another embodiment. Figure 10 , the Boolean circuit 800 further includes:

[0140] A second splitting module 82 for splitting the first digit of the input data; the second splitting module 82 further comprises:

[0141] The second difference calculation unit 821 receives the first bit of the input data and the first bit of the first slice using the fifth XOR gate, and outputs the first bit of the second slice;

[0142] The second borrow calculation unit 822 includes a second NOT gate and a second AND gate;

[0143] The second NOT gate receives the first bit of the input data and outputs a first intermediate result;

[0144] The second AND gate receives the first intermediate result and the first bit of the first slice, and outputs a borrow bit of the first bit;

[0145] The second borrow inversion unit 823 receives the borrow bit of the first position by using the third NOT gate and outputs the inversion of the borrow bit of the first position.

[0146] The second splitting module 82 is specifically configured to perform the following processing:

[0147] b1[0]=XOR(b[0],b0[0])

[0148] t0=INV(b[0])

[0149] borrow=AND(t0,b0[0])

[0150] borrow_inv = INV(borrow)

[0151] It can be understood that the first bit of the second fragment b1[0]=b[0]^b0[0], the first bit borrow=(~b[0])&b0[0], and the first bit borrow inversion borrow_inv=~borrow.

[0152] Figure 11 FIG. 1 shows a schematic diagram of a Boolean circuit structure for splitting data slices according to another embodiment. Figure 11 , the Boolean circuit 800 further includes:

[0153] A third splitting module 83 for splitting the last bit of the input data; the third splitting module 83 further comprises:

[0154] The sixth XOR gate receives the borrow bit of the previous bit and the last bit of the first slice, and outputs the first intermediate result;

[0155] The seventh XOR gate receives the first intermediate result and the last bit of the input data, and outputs the last bit of the second slice.

[0156] The third splitting module 83 is specifically configured to perform the following processing:

[0157] t0=XOR(borrow,b0[n-1])

[0158] b1[n-1]=XOR(t0,b[n-1])

[0159] It can be understood that the last bit of the second fragment b1[n-1]=b[n-1]^b0[n-1]^borrow. When splitting the last bit of the input data, it is only necessary to determine the last bit of the second fragment after the split, and there is no need to determine the borrow bit and the borrow bit inversion.

[0160] Optionally, as an embodiment, the Boolean circuit adopts an execution mode of a garbled circuit.

[0161] A Boolean circuit for splitting data slices provided by an embodiment of this specification is used to obtain a second slice of input data based on input data and a first slice of input data. The Boolean circuit includes: a first splitting module for splitting the middle bit of the data that is not the first and last bit of the input data; the first splitting module further includes: a first difference calculation unit, which splits the current bit of the input data input therein, the current bit of the first slice, and the borrow bit of the previous bit through an XOR gate, and outputs the current bit of the second slice; a first borrow inversion unit, which uses a single AND gate to perform an AND operation on the intermediate result of the XOR operation of the current bit of the first slice and the borrow bit of the previous bit, and the intermediate result of the XOR operation of the current bit of the input data and the borrow bit inversion of the previous bit, and outputs the borrow bit inversion of the current bit based on the AND operation result; a first borrow calculation unit, which uses a first NOT gate to invert the borrow bit inversion of the current bit and output the borrow bit of the current bit. As can be seen from the above, in the embodiment of this specification, if the input data is n bits, there are n-2 data middle bits in the input data, and there are only n-2 AND gates in the circuit to split the data middle bits, which is the minimum. Therefore, for the execution method of common Boolean circuits, the minimum communication cost can be achieved.

[0162] According to another embodiment, there is also provided a computer readable storage medium having a computer program stored thereon, which, when executed in a computer, enables the computer to realize the combination of Figures 4 to 11 The Boolean circuit described.

[0163] According to another embodiment, a computing device is provided, including a memory and a processor, wherein the memory stores executable code, and when the processor executes the executable code, the system realizes the combination of Figures 4 to 11 The Boolean circuit described.

[0164] Those skilled in the art will appreciate that, in one or more of the above examples, the functions described herein may be implemented using hardware, software, firmware, or any combination thereof. When implemented using software, these functions may be stored in a computer-readable medium or transmitted as one or more instructions or codes on a computer-readable medium.

[0165] The specific implementation methods described above further illustrate the objectives, technical solutions and beneficial effects of the present invention in detail. It should be understood that the above description is only a specific implementation method of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent replacements, improvements, etc. made on the basis of the technical solution of the present invention should be included in the scope of protection of the present invention.

Claims

1. A Boolean circuit for merging data slices, wherein a first slice and a second slice of input data are distributed on a first side and a second side, respectively, the Boolean circuit comprising: a first merging module for merging middle bits of data other than the first and last bits of the input data; The first merging module further comprises: A first sum calculation unit combines the current bit of the first slice, the current bit of the second slice, and the carry of the previous bit of the input data through an XOR gate, and outputs the current bit of the input data; The first carry calculation unit uses a single AND gate to perform an AND operation on two intermediate results of performing exclusive OR operations on the current bit of the first slice and the current bit of the second slice and the carry of the previous bit, and outputs the carry of the current bit based on the AND operation result.

2. The Boolean circuit according to claim 1, wherein The first sum calculation unit includes a first XOR gate and a second XOR gate; The first XOR gate receives the carry of the previous bit and the current bit of the first slice, and outputs a first intermediate result corresponding to the middle bit of the input data; The second XOR gate receives the first intermediate result corresponding to the middle bit of the input data and the current bit of the second slice, and outputs the current bit of the input data; The first carry calculation unit includes a third XOR gate, a fourth XOR gate, and a first AND gate as the single AND gate; The third XOR gate receives the carry of the previous bit and the current bit of the second slice, and outputs a second intermediate result corresponding to the middle bit of the input data; The first AND gate receives a first intermediate result corresponding to a middle bit of the input data and a second intermediate result corresponding to a middle bit of the input data, and outputs the AND operation result; The fourth XOR gate receives the carry of the previous bit and the AND operation result, and outputs the carry of the current bit.

3. The Boolean circuit according to claim 1, wherein The Boolean circuit further includes: a second merging module for merging the first bit of the input data; the second merging module further comprising: The second sum calculation unit receives the first bit of the first slice and the first bit of the second slice by using the fifth XOR gate, and outputs the first bit of the input data; The second carry calculation unit receives the first digit of the first slice and the first digit of the second slice using a second AND gate, and outputs the carry of the first digit.

4. The Boolean circuit according to claim 1, wherein The Boolean circuit further includes: a third merging module for merging the last bits of the input data; the third merging module comprises a sixth XOR gate and a seventh XOR gate; The sixth XOR gate receives the carry of the previous bit and the last bit of the first slice, and outputs a first intermediate result corresponding to the last bit of the input data; The seventh XOR gate receives the first intermediate result corresponding to the last bit of the input data and the last bit of the second slice, and outputs the merged last bit of the input data.

5. The Boolean circuit according to claim 1, wherein The Boolean circuit adopts the execution mode of a garbled circuit.

6. A Boolean circuit for splitting data into slices, the Boolean circuit being configured to obtain a second slice of input data based on input data and a first slice of the input data, the Boolean circuit comprising: A first splitting module for splitting middle bits of data other than the first and last bits of the input data; The first splitting module further includes: A first difference calculation unit is configured to split the current bit of the input data, the current bit of the first slice, and the borrow of the previous bit input therein through an XOR gate, and output the current bit of the second slice; a first borrow inversion unit, using a single AND gate, performing an AND operation on an intermediate result of an XOR operation between a current bit of the first slice and a borrow of a previous bit, and an intermediate result of an XOR operation between a current bit of the input data and the borrow inversion of a previous bit, and outputting a borrow inversion of the current bit based on the AND operation result; The first borrow calculation unit utilizes a first NOT gate to invert the borrow of the current bit and output the borrow of the current bit.

7. The Boolean circuit according to claim 6, wherein The first difference calculation unit includes a first XOR gate and a second XOR gate; The first XOR gate receives the borrow bit of the previous bit and the current bit of the first slice, and outputs a first intermediate result corresponding to the middle bit of the input data; The second XOR gate receives the first intermediate result and the current bit of the input data, and outputs the current bit of the second slice; The first borrow inversion unit includes a third XOR gate, a fourth XOR gate, and a first AND gate as the single AND gate; The third XOR gate receives the inverted borrow bit of the previous bit and the current bit of the input data, and outputs a second intermediate result corresponding to the middle bit of the input data; The first AND gate receives a first intermediate result corresponding to a data middle bit of the input data and a second intermediate result corresponding to a data middle bit of the input data, and outputs a third intermediate result; The fourth XOR gate receives the borrow inversion of the previous bit and the third intermediate result, and outputs the borrow inversion of the current bit.

8. The Boolean circuit according to claim 6, wherein The Boolean circuit further includes: A second splitting module for splitting the first bit of the input data; the second splitting module further comprises: The second difference calculation unit receives the first bit of the input data and the first bit of the first slice using the fifth XOR gate, and outputs the first bit of the second slice; A second borrow calculation unit includes a second NOT gate and a second AND gate; The second NOT gate receives the first bit of the input data and outputs a first intermediate result corresponding to the first bit of the input data; The second AND gate receives the first intermediate result corresponding to the first bit of the input data and the first bit of the first slice, and outputs a borrow bit of the first bit; The second borrow inversion unit receives the borrow of the first bit by using the third NOT gate and outputs the borrow inversion of the first bit.

9. The Boolean circuit according to claim 6, wherein The Boolean circuit further includes: A third splitting module for splitting the last bit of the input data; the third splitting module further comprises: a sixth XOR gate, receiving the borrow bit of the previous bit and the last bit of the first slice, and outputting a first intermediate result corresponding to the last bit of the input data; The seventh XOR gate receives the first intermediate result corresponding to the last bit of the input data and the last bit of the input data, and outputs the last bit of the second slice.

10. The Boolean circuit according to claim 6, wherein The Boolean circuit adopts the execution mode of a garbled circuit.

Citation Information

Patent Citations

  • Collaborative computing method, system and device for protecting data privacy of two parties

    CN111177790A

  • Circuit and method converting boolean and arithmetic masks

    US20100235417A1