Multi-Party Computation Model Measurement Method, Device, Equipment and Storage Medium

By calculating the computational benefit contribution and actual privacy losses of the multi-party computing model, the problems of the multi-party computing model in terms of fairness, privacy protection and cost are solved, and a quantitative measurement method and device are provided to ensure that participants choose the applicable multi-party computing model to avoid privacy leakage and excessive costs.

CN114117512BActive Publication Date: 2025-08-05SHENZHOU RONGAN DIGITAL TECH (BEIJING) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202011626692.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-12-30
Publication Date
2025-08-05
Estimated Expiration
2040-12-30

AI Technical Summary

Technical Problem

The existing multi-party computing model has problems in fairness, data privacy protection and calculation costs, resulting in problems such as leakage of data privacy and excessive implementation costs of participants, and lacks effective quantitative measurement methods for applicability.

Method used

By calculating the calculation income contribution of the output of the second participant regarding the specific input of the first participant and the actual privacy loss of the multi-party computing model to the input of the first participant, the applicability of the multi-party computing model is determined, and a multi-party computing model measurement method, device, electronic equipment and computer-readable storage medium is provided, and the calculation income contribution and actual privacy loss are used for quantitative measurement.

Benefits of technology

It realizes reasonable quantitative measurement of the applicability of multi-party computing models, helps participants choose appropriate models, avoids privacy data leakage and excessive costs, and improves the security and efficiency of multi-party computing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114117512B_ABST
    Figure CN114117512B_ABST
Patent Text Reader

Abstract

The present application provides a multi-party computing model measurement method, device, electronic device and computer-readable storage medium. Among them, a multi-party computing model measurement method includes: for a multi-party computing model, calculating the computational benefit contribution of the output of the second participant with respect to the specific input of the first participant; and calculating the actual privacy loss of the multi-party computing model to the input of the first participant; and determining the applicability of the multi-party computing model based on the computational benefit contribution and the actual privacy loss. The technical solution of the present application can use the above-mentioned computational benefit contribution and actual privacy loss to reasonably quantify the applicability of the multi-party computing model, so that the participants can use quantitative and data-based measurement values to determine the applicability of the multi-party computing model to the participants, avoiding the participants adopting inappropriate multi-party computing models, which may lead to privacy data leakage, excessive implementation costs and other problems.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of data processing technology, and in particular to a multi-party computing model measurement method, device, electronic device, and computer-readable storage medium. Background Art

[0002] In traditional computing models, such as the stand-alone Turing machine model, the input, output, and calculation program of the calculation are all owned by one party alone; multi-party computing refers to the situation where multiple participants provide data or computing resources and conduct joint computing. Common concepts such as distributed computing and centralized computing with data provided by multiple parties all belong to multi-party computing.

[0003] Compared with unilateral computing, multi-party computing will cause problems such as fairness, data privacy protection, and computing costs. Inappropriate multi-party computing models can lead to data privacy leakage of participants and excessively high implementation costs.

[0004] Therefore, it is necessary to provide a technical solution that can quantitatively measure the applicability of the multi-party computing model to assist the participants of the multi-party computing to determine the applicability of the multi-party computing model. Summary of the Invention

[0005] The purpose of the embodiments of the present application is to provide a multi-party computing model measurement method, device, electronic device and computer-readable storage medium to quantitatively measure the applicability of the multi-party computing model to assist the participants of the multi-party computing in determining the applicability of the multi-party computing model.

[0006] To solve the above technical problems, the embodiments of the present application provide the following technical solutions:

[0007] The first aspect of the present application provides a multi-party computing model measurement method, including:

[0008] For a multi-party computation model, calculating the computational benefit contribution of the second party's output with respect to a specific input of the first party; and

[0009] Calculating an actual privacy loss of the multi-party computation model on the input of the first party;

[0010] The applicability of the multi-party computing model is determined based on the computing benefit contribution and the actual privacy loss.

[0011] A second aspect of the present application provides a multi-party computing model measurement device, including:

[0012] a computation benefit contribution determination module for calculating, for a multi-party computation model, a computation benefit contribution of an output of a second participant with respect to a specific input of a first participant; and

[0013] an actual privacy loss determination module, configured to calculate an actual privacy loss of the input of the multi-party computing model to the first party;

[0014] A practicality determination module is used to determine the applicability of the multi-party computing model based on the computing benefit contribution and the actual privacy loss.

[0015] The third aspect of the present application provides an electronic device, comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the method provided in the first aspect of the present application.

[0016] A fourth aspect of the present application provides a computer-readable medium having computer-readable instructions stored thereon, and the computer-readable instructions can be executed by a processor to implement the method provided in the first aspect of the present application.

[0017] Compared to the prior art, the multi-party computing model measurement method provided in the first aspect of this application calculates the computational benefit contribution of the second participant's output with respect to the first participant's specific input, and calculates the actual privacy loss of the multi-party computing model on the first participant's input, and then determines the applicability of the multi-party computing model based on the computational benefit contribution and the actual privacy loss. Thus, the computational benefit contribution and the actual privacy loss can be used to reasonably quantify the applicability of the multi-party computing model, allowing participants to use quantitative, data-based measurement values to determine the applicability of the multi-party computing model to the participants, thereby avoiding problems such as privacy data leakage and excessive implementation costs caused by participants adopting inappropriate multi-party computing models.

[0018] The multi-party computing model measurement device provided in the second aspect of this application, the electronic device provided in the third aspect, and the computer-readable storage medium provided in the fourth aspect are based on the same inventive concept as the multi-party computing model measurement method provided in the first aspect of this application, and have the same beneficial effects as the multi-party computing model measurement method provided in the first aspect of this application. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] The above and other objects, features and advantages of the exemplary embodiments of the present application will become readily understood by reading the detailed description below with reference to the accompanying drawings. In the accompanying drawings, several embodiments of the present application are shown in an exemplary and non-limiting manner, and the same or corresponding reference numerals represent the same or corresponding parts, wherein:

[0020] Figure 1 The following schematically illustrates a flow chart of a multi-party computing model measurement method provided by some embodiments of the present application;

[0021] Figure 2Schematically illustrates a schematic diagram of a multi-party computing model measurement device provided by some embodiments of the present application;

[0022] Figure 3 A schematic diagram schematically illustrates an electronic device provided by some embodiments of the present application;

[0023] Figure 4 A schematic diagram of a computer-readable storage medium provided in some embodiments of the present application is schematically shown. DETAILED DESCRIPTION

[0024] Exemplary embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although exemplary embodiments of the present disclosure are shown in the accompanying drawings, it should be understood that the present disclosure can be implemented in various forms and should not be limited by the embodiments described herein. Rather, these embodiments are provided to enable a more thorough understanding of the present disclosure and to fully convey the scope of the present disclosure to those skilled in the art.

[0025] It should be noted that, unless otherwise specified, the technical or scientific terms used in this application should have the common meanings understood by those skilled in the art to which this application belongs.

[0026] In addition, the terms "first" and "second" are used to distinguish different objects, not to describe a specific order. Furthermore, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product, or apparatus comprising a series of steps or elements is not limited to the listed steps or elements, but may optionally include steps or elements not listed, or may optionally include other steps or elements inherent to the process, method, product, or apparatus.

[0027] The embodiments of the present application provide a multi-party computing model measurement method, device, electronic device, and computer-readable storage medium, which are described below with reference to the accompanying drawings.

[0028] In order to facilitate understanding of the embodiments of the present application, first, Figure 1 Some system architectures and inventive concepts of the embodiments of this application are briefly described as follows:

[0029] Please refer to Figure 1 , which schematically shows a flowchart of a multi-party computing model measurement method provided by some embodiments of the present application. The multi-party computing model measurement method may include the following steps:

[0030] Step S101: for a multi-party computing model, calculating the computing benefit contribution of the output of the second participant with respect to the specific input of the first participant.

[0031] In some implementations, this step S101 may include:

[0032] Calculating the average entropy of the output of the function of the multi-party computing model with respect to the second participant; and

[0033] Calculating a specific entropy of an output of the second participant when a function of the multi-party computing model inputs a specific input of the first participant;

[0034] The difference or ratio between the average entropy and the specific entropy is determined as the calculated benefit contribution of the output of the second participant with respect to the specific input of the first participant.

[0035] Specifically, secure multi-party computation is a system in which n participants can securely compute an agreed function f(x1,x2,…,xn)=(y1,y2,…,yn) (the agreed function is the function of the multi-party computing model) without a trusted third party. Suppose the n participants are P1, P2, P3,…,Pn, and the inputs of the function are: P1 holds input x1, P2 holds input x2, P3 holds input x3,…,Pn holds input xn; the outputs of the function are: P1 obtains output y1, P2 obtains output y2, P3 obtains output y3,…,Pn obtains output yn; secure computation means that during the function computation process, each participant cannot obtain the input and output of other participants.

[0036] For example, the millionaire problem: P1 holds a number x1, P2 holds a number x2, and P1 and P2 safely compare whose number is larger: if x1>x2, P1 obtains output 1; if x1<=x2, P1 obtains 0; P2 does not obtain any output; safe comparison means that P1 cannot obtain any information about P2's input x2 during the function calculation process, and P2 cannot obtain any information about P1's input x1 during the calculation process.

[0037] Currently, there are many solutions to the millionaire's problem: for example, a secure comparison scheme based on Yao's garbled circuit, a secure multi-party computation scheme based on secret sharing, a secure comparison scheme based on homomorphic encryption, a secure comparison scheme based on 0-1 encoding, etc.

[0038] The scope of the so-called secure multi-party computation in the embodiments of this application refers to a scheme for securely computing the function f(x1,x2,…,xn)=(y1,y2,…,yn) using technologies including Yao's obfuscation circuits, secret sharing technology, homomorphic cryptography technology, trusted computing technology (TEE, Intel SGX technology, ARM TrustZone, etc.). The original objective function f(x1,x2,…,xn)=(y1,y2,…,yn) in the secure computation scheme only indicates the purpose of participating in the secure computation and explains the relationship between the input and output of each participant, and is unrelated to the specific security technology used.

[0039] Existing research on secure multi-party computation (SMC) focuses on preventing the leakage of private information during the computation process. Specifically, it focuses on preventing a participant, Pi, from obtaining information about the inputs or outputs of other participants through the computation process and its intermediate results. However, the possibility that a participant, Pi, can infer information about the inputs or outputs of other participants through its legitimate function inputs xi and outputs yi has not been fully explored, and evaluation methods are still lacking in this area. The present embodiments focus on the degree of privacy protection provided by the target computation function itself in privacy-preserving computations.

[0040] For example, in the millionaire problem, the input range of the two participants is an integer between 1 and 10. P1's input is 10. The final result obtained by P1 is that P1's input is less than or equal to P2's input. Then P1 can naturally know that P2's input is 10 through its input and output.

[0041] It seems inevitable that a participant Pi in a secure multi-party computation obtains the input or output of other participants through specific input xi, output yi, and function f(x1,x2,…,xn)=(y1,y2,…,yn). However, the privacy of each participant can only be truly protected by measuring the possibility of privacy leakage of each participant in this situation or the degree to which privacy can be protected.

[0042] About the ideal multi-party computation model:

[0043] A function f(x1,x2,…,xn)=(y1,y2,…,yn) is jointly calculated by n participants P1, P2, P3,…,Pn. P1 holds the input x1, P2 holds the input x2, P3 holds the input x3,…,Pn holds the input xn. The domains of all inputs are public. Apart from this, each participant cannot obtain any information related to the inputs of other participants. All participants cannot obtain any information about the function calculation process (for example, a trusted center collects the inputs of each participant, performs the operation, and finally sends the corresponding calculation results to the corresponding participants. The trusted center will not collude with any participant). After the function calculation is completed, each participant obtains the predetermined calculation result. P1 obtains the output y1, P2 obtains the output y2, P3 obtains the output y3,…,Pn obtains the output yn. Each participant cannot obtain any information about the output of other participants.

[0044] The above situation is the ideal case for multi-party computation. Each party will not obtain any other information from the computation process, and the trusted center will not leak more information to any party. In this case, a participant who wants to attack other participants can only use its own inputs and outputs, as well as the properties of the objective function. The work of the embodiments of this application mainly focuses on measuring the degree of privacy protection of a participant's input or output under ideal conditions, or, conversely, the degree to which a participant's input or output is likely to be obtained by other participants.

[0045] The method to solve this problem can be used to measure the degree of privacy protection or privacy leakage of each participant in the secure multi-party computing scheme based on the characteristics of the objective function itself; and to evaluate the privacy protection strength of the secure computing scheme for the computing process.

[0046] For the above function f(x1,x2,…,xn)=(y1,y2,…,yn), to adapt to the computing environment of the computing device, assume that the input and output of the function are both discrete. Let the domain of the input of each participant be s1,s2,s3,…,sn, where x1∈s1,x2∈s2,x3∈s3,…,xn∈sn; |s1|,|s2|,|s3|,…,|sn| respectively denote the number of possible input values in the domain. Let the range of the output of each participant be v1,v2,v3,…,vn, where y1∈v1,y2∈v2,y3∈v3,…,yn∈vn; |v1|,|v2|,|v3|,…,|vn| respectively denote the number of possible output values in the output range.

[0047] About calculating revenue contribution:

[0048] For an objective function f(x1,x2)=(y1,y2) with only two parties involved, the concept of calculating the benefit contribution is defined to reveal the extent to which the specific input x1 of participant P1 affects the distribution of the output y2 of participant P2 from the perspective of participant P2.

[0049] Suppose the two participants of the objective function f(x1,x2)=(y1,y2) are P1 and P2 respectively. Under ideal secure multi-party computing conditions (the computing process does not leak any information), participant P2 (attacker) attempts to analyze the input x1 or output y1 of participant P1 only through its input x2 and output y2.

[0050] About the average entropy of the function output:

[0051] In the above environment, participant P2 traverses P1's input x1 and P2's input x2, builds a mapping table between function input and output, and counts the frequency a of each possible value of participant P2's output y2 in the output value domain v2. i , a i Represents the frequency of the i-th output value in the value range v2. When the probability distribution of the input x1 of participant P1 and the input x2 of participant P2 are known, a weighted statistical method is used. Let the output probability of each possible output value be definition is the average entropy of the output y2 of the objective function f(x1,x2)=(y1,y2) with respect to the participant P2.

[0052] The weighted statistical method of the frequency of each possible value of output y2: When the probability distribution of the input x1 of participant P1 and the input x2 of participant P2 are known: the probability of each possible value of the input x1 of participant P1 is {p(x1 1 ),p(x1 2 ),…,p(x1 |s1| )}, the probability of each possible value of the input x2 of participant P2 is {p(x2 1 ),p(x2 2 ),…,p(x2 |s2| )}, for every possible input (x1 a ,x2 b ), (1≤a≤|s1|,1≤b≤|s2|), statistical objective function f(x1 a ,x2 b ) outputs the frequency of y2, the number of counts is p(x1 a )*p(x2 b ).

[0053] The average entropy H(f (p2,y2)) reflects the average contribution of all inputs to the output of P2.

[0054] Regarding the specific entropy of the function output:

[0055] In the above environment, if the input x1 of P1 is fixed to a specific value α∈s1 in the domain s1, and the participant P2 traverses all possible inputs x2, then the participant P2 can obtain the new function f (p1,α) =f(α,x2)=all possible outputs y2′ of (y1′,y2′), f (p1,α) represents a function whose fixed participant P1 inputs x1=α; participant P2 constructs a function f (p1,α) =f(ɑ,x2) mapping table between input and output, counting the frequency b of each value of P2's output y2' in the output range v2' i , b i Represents the frequency of the i-th output value in v2′. When the probability distribution of the input x1 of participant P1 and the input x2 of participant P2 is known, a weighted statistical method is used. Let the output probability of each possible output value be definition is the specific entropy of the output y2′ of participant P2 when the input x1 of participant P1 is x1 = α in the fixed objective function f(x1,x2) = (y1,y2).

[0056] Since the input of participant P1 is fixed, the new function f (p1,α) The range of the output of participant P2 is a subset v2′ of the original range v2. This definition reflects the impact of the specific participant P1 input x1=α on the output of participant P2.

[0057] About calculating revenue contribution:

[0058] For the specific input x1=α of participant P1, the difference or ratio between its "average entropy of function output" and "specific entropy of function output" is defined as the calculated benefit contribution of participant P2's output with respect to participant P1's input x1=α.

[0059] Among them, the larger the difference / ratio, the greater the impact of the specific input on the output distribution of participant P2, and the easier it is for participant P2 to infer the value of participant P1 from its own output.

[0060] This definition can be understood as participant P1 having a specific data x1 = α and jointly calculating the function f(x1, x2) with participant P2. Participant P2 uses a method of continuous trial and error, i.e., iterating over its input x2 to obtain additional output information, thereby inferring the input of participant P1. When participant P2 finds that its output entropy deviates significantly from the function's average (the larger the difference / ratio), it can determine the input value of participant P1.

[0061] Simplification of Multi-Party Computation Functions to Two-Party Computation Functions:

[0062] For a multi-party computation function f(x1, x2, …, xn) = (y1, y2, …, yn), it can be assumed that in the worst-case scenario, n - 1 participating parties collude to spy on the input and output of one of the participating parties. Then, the n - 1 colluding participating parties will obtain the input and output information among themselves. At this time, the model is equivalent to the above-mentioned two-party model, where the n - 1 colluding parties act as one participating party and the attacked party acts as the other participating party.

[0063] Case

[0064] The value ranges of the two participating parties P1 and P2 of a secure comparison function are both {1, 2, 3}, three integers. P2 obtains the result of the comparison function. When x2 > x1, y2 = 1; when x2 = <x1, y2 = 0. All possible results are shown in Table 1 below:

[0065] Table 1

[0066] P1's input x1 P2's input x2 P2 obtains the comparison result y2 1 1 0 1 2 1 1 3 1 2 1 0 2 2 0 2 3 1 3 1 0 3 2 0 3 3 0

[0067] For the above comparison function, the participating party P2 constructs a mapping table (Table 1) between all inputs and outputs, and statistically obtains that the probability of the "0" output is The probability of the "1" output is Then the average entropy of the function output:

[0068] Fixing the input of P1 as 3 for the function f (p1,3) The results are shown in Table 2 below:

[0069] Table 2

[0070] P1's input x1 P2's input x2 P2 obtains the comparison result y2 3 1 0 3 2 0 3 3 0

[0071] As shown in Table 2, the specific entropy of the function output with the input of P1 fixed as 3 is 0, which seriously deviates from the average entropy of the function output. However, there is no difference between the specific entropy and the average entropy when the input of P1 is fixed as 1 and 2.

[0072] The greater the average entropy of the function output of a target function, the better its protection degree for the input. For example, for the symmetric encryption function ENC(m, key), for a fixed key, the output ciphertext still shows characteristics similar to uniform randomness, so it can well protect the plaintext m. <00​​The greater the specific entropy of the function output, the higher the privacy protection of the input α. Then Pi can be more confident in contributing the input α to the function for calculation.

[0074] The average entropy of the function output can be viewed as a comparison between the confidentiality of the target function and a symmetric encryption function of the same output length.

[0075] The specific entropy of the function output can be viewed as a comparison between the target function and the confidentiality of a symmetric encryption function with a fixed key.

[0076] If the specific entropy output by an input function of participant Pi is less than the average entropy of the function output of the objective function for participant Pi, it means that the privacy protection degree of the function for the input value is less than the average level of privacy protection for participant Pi's input value, and participant Pi should use this specific input value with caution in participating in the operation.

[0077] Step S102: Calculate the actual privacy loss of the multi-party computing model for the input of the first participant.

[0078] In some implementations, the multi-party computing model includes multiple intermediate functions, and this step S102 may include:

[0079] Calculating the actual privacy loss of each intermediate function in the multi-party computation model for the input of the first party;

[0080] From the actual privacy loss of each intermediate function on the input of the first participant, the one with the largest value is selected as the actual privacy loss of the multi-party computing model on the input of the first participant.

[0081] Based on the above implementation, in some modified implementations, the above method further includes:

[0082] The intermediate function corresponding to the actual privacy loss with the largest value is determined as the intermediate function with the largest probability of privacy leakage in the multi-party computing model.

[0083] Through this implementation, the intermediate function with the highest probability of privacy leakage in the multi-party computing model can be determined, so that the participating parties can make targeted improvements to the multi-party computing model.

[0084] In some other embodiments, the above method further includes:

[0085] Calculating an ideal privacy loss of the multi-party computation model for the input of the first party;

[0086] Determining the privacy protection strength of the multi-party computing model according to a ratio of the ideal privacy loss to the actual privacy loss;

[0087] Determine the applicability of the multi-party computing model according to the privacy protection strength.

[0088] Specifically, regarding the ideal privacy loss:

[0089] For the objective function f(x1, x2) = (y1, y2) with only two parties participating, the concept of "privacy loss" is defined to reveal the possibility that the participating party P2 infers the distribution of the input x1 of the participating party P1 through its input x2 and output y2.

[0090] Let the two participating parties of the objective function f(x1, x2) = (y1, y2) be P1 and P2 respectively. Under the ideal multi-party computing conditions (no information is leaked during the computing process), the participating party P2 (the attacker) attempts to analyze the input x1 of the participating party P1 only through its input x2 and output y2.

[0091] In an ideal two-party computing environment, for the objective function f(x1, x2) = (y1, y2) with two participating parties P1 and P2 respectively, the participating party P2 traverses the input x1 of P1 and the input x2 of P2 to construct a mapping table between the function input and output. Based on this, the participating party P2 constructs all possible input sets s of the participating party P1 when its specific input x2 = β and output y2 = γ. (x1,x2=β,y2=γ) , let |s (x1,x2=β,y2=γ) | represent the number of elements in the set. Then, for a specific input x2 = β and output y2 = γ, the participating party P2 can determine the input x1 of the participating party P1 with a probability of . Define L(x1, x2 = as the privacy loss of the input of the participating party P1 for the objective function f(x1, x2) = (y1, y2) when x2 = β and output y2 = γ.

[0092] This definition indicates that the possibility that the input x1 of the participating party P1 takes a specific value increases from the original to . The greater the value of the privacy loss, the greater the possibility of uniquely determining an input.

[0093] For example, the value ranges of a comparison function for P1 and P2 are respectively {1, 2, 3}, three integers. P2 obtains the result of the comparison function. When x2 > x1, y2 = 1; when x2 = <x1, y2 = 0. Construct Table 3 as follows according to the results in Table 1:

[0094] Table 3

[0095]

[0096] From the perspective of participant P2, when its input is 2 and its output is 1, it can be uniquely determined that the input of participant P1 is 1; when its input is 3 and its output is 0, it can be uniquely determined that the input of participant P1 is 3.

[0097] Privacy loss can indicate the size of the search space required by participant P2 when P2 infers the input of participant P1 from its input and output from the perspective of participant P2. The greater the loss, the smaller the search space.

[0098] For example, the hash function HASH(x1||β)=γ. If all elements that collide with the input x1 can be determined, the larger the range of the set, the smaller the possibility of uniquely determining the true value of x1.

[0099] Regarding actual privacy loss:

[0100] In the ideal multi-party computing scenario described above, each participant only knows their own input and output, and does not know any other information. However, in actual secure multi-party computing implementation schemes, such as delegated computing based on homomorphic cryptography and secure multi-party computing based on secret sharing, the parties use cryptographic or information theory-based security measures to exchange data without a trusted third party. After the calculation is completed, each party can obtain the same output as in the ideal situation, but in addition, each party will obtain a large amount of intermediate interaction information.

[0101] The actual secure multi-party computation scheme can be modeled as a process where the original objective function undergoes a series of equivalent transformations to ultimately obtain the same result as the ideal objective function. The so-called equivalent transformation means that two different computational processes produce the same output result for the same input.

[0102] Assume that in an ideal computing environment, the two participants of the objective function f(x1,x2)=(y1,y2) are P1 and P2, the inputs are x1 and x2, and the corresponding outputs are y1 and y2. Assume that the security equivalent transformation of the objective function f(x1,x2)=(y1,y2) is f′(x1,x2)=f m (…f3(f2(f1(x1,x2),…),…),…)=(y1,y2). For the same input (x1,x2), the secure multi-party computation function f′(x1,x2) and the ideal objective function f(x1,x2) output the same result (y1,y2). The secure multi-party computation function f′(x1,x2) consists of m intermediate functions f1(), f2(),…, f m () is composed of, after each intermediate function is completed, each party will obtain the corresponding output (y (1,1) ,y (1,2) ), (y (2,1) ,y (2,2) ),…,(y(m-1,1) ,y (m-1,2) ), (y (m,1) =y1,y (m,2) y2), and each party will reconstruct the input of the next intermediate function based on the output of the previous intermediate function (x (1,1) =x1,x (1,2) =x2),(x (2,1) ,x (2,2) ),…,(x (m,1) ,x (m,2) ). The intermediate input and output are equivalent to the process in which each party obtains data through interaction and performs the next operation in the actual secure multi-party computation process. The change in the input data view of participant P1 during the entire secure computation process is x1=x (1,1) →x (2,1) →…→x (m,1) , the change of output data view is y (1,1) →y (2,1) →…→y (m,1) =y1; the change in the input data view of participant P2 is x2=x (1,2) →x (2,2) →…→x (m,2) , the change of output data view is y (1,2) →y (2,2) →…→y (m,2) =y2.

[0103] Regarding actual privacy loss:

[0104] Suppose the secure computational scheme for the objective function f(x1,x2)=(y1,y2) is f′(x1,x2)=f m (…f3(f2(f1(x1,x2),…),…),…)=(y1,y2), the inputs of each intermediate function are (x (1,1) =x1,x (1,2) =x2),(x (2,1) ,x (2,2) ),…,(x (m,1) ,y (m,2) ), where x (i,1) is the input of the participant P1 of the i-th (1≤i≤m) intermediate function, x (i,2) is the input of the participant P2 of the i-th intermediate function; the output of each intermediate function is (y (1,1) ,y (1,2) ), (y (2,1) ,y (2,2) ),…,(y (m-1,1) ,y (m-1,2) ), (y (m,1) =y1,y (m,2) =y2), where y(i,1) is the output of participant P1 of the i-th intermediate function, y (i,2) is the output of participant P2 of the i-th intermediate function; the input data view of participant P1 changes to x1=x in the entire calculation process. (1,1) →x (2,1) →…→x (m,1) , the output data change view is y (1,1) →y (2,1) →…→y (m,1) =y1; the input data view of participant P2 changes to x2=x (1,2) →x (2,2) →…→x (m,2) , the output data change view is y (1,2) →y (2,2) →…→y (m,2) =y2; when participant P2 fixes input x2 = β and output y2 = γ, the i-th intermediate function f i The privacy loss of (…f3(f2(f1(x1,x2),…),…),…)(1≤i≤m) is L i =L(x1,x2=β,y (i,2) ,f i (…f3(f2(f1(x1,x2),…),…),…)), where the maximum privacy loss is defined as the secure computation scheme f′(x1,x2)=f m (…f3(f2(f1(x1,x2),…),…),…)=(y1,y2) When participant P2 inputs x2=β and outputs y2=γ, the actual privacy loss of participant P1’s input x1 is L(x1,x2=β,y2=γ,f′(x1,x2))=max{L i |1≤i≤m}.

[0105] The significance of actual privacy loss is to find the step with the greatest privacy leakage during the execution of the security solution. Since the entire privacy protection solution f′(x1,x2) is equivalent to the objective function, the actual privacy loss is at least equal to the ideal privacy loss of the objective function.

[0106] Privacy protection strength

[0107] Regarding the strength of privacy protection:

[0108] For an objective function f(x1,x2)=(y1,y2) and a specific secure computation scheme f′(x1,x2)=f m(…f3(f2(f1(x1,x2),…),…),…)=(y1,y2), defining the privacy protection strength of the secure computation scheme when participant P2 inputs x2=β and outputs y2=γ as the ratio between the ideal privacy loss of the objective function and the actual privacy loss of the secure computation scheme.

[0109] The privacy protection strength reflects the additional privacy leakage caused by the secure computing scheme to the objective function during the calculation process. Compared with the protection of the input data privacy by the objective function's own characteristics under an ideal operating environment, the higher the security strength of a secure privacy computing scheme (the closer it is to 1), the closer it is to the ideal operating conditions, and the less additional privacy leakage caused by its calculation process.

[0110] Step S103: Determine the applicability of the multi-party computing model based on the computational benefit contribution and the actual privacy loss.

[0111] Based on any of the aforementioned embodiments of the present application, in some other modified embodiments, the above method further includes:

[0112] Calculating the privacy protection cost of the multi-party computing model;

[0113] Determining the applicability of the multi-party computing model based on the computational benefit contribution and the actual privacy loss includes:

[0114] The applicability of the multi-party computing model is determined according to the computing benefit contribution, the actual privacy loss, and the privacy protection cost.

[0115] The privacy protection cost mentioned above includes the additional communication overhead and additional computing overhead when the multi-party computing model is applied.

[0116] Specifically, regarding the cost of privacy protection:

[0117] The privacy protection cost is the additional communication and computational overhead required to implement the secure computation function of the objective function compared to the ideal operation (when there is a trusted center), which represents the price to be paid for privacy protection.

[0118] For a centralized multi-party computation of the objective function f(x1,x2,…,xn)=(y1,y2,…,yn), the communication overhead is at most 2n times. This means each party sends inputs to the trusted center and receives outputs from it. The computational overhead is the time complexity T(f(x1,x2,…,xn)) required for the trusted center to execute the function f(x1,x2,…,xn) locally.

[0119] A secure computational scheme f′(x1,x2,…,xn)=f to achieve the objective function f(x1,x2,…,xn)=(y1,y2,…,yn) m (…f3(f2(f1(x1,x2,…,xn),…),…),…)=(y1,y2,…,yn), its communication overhead is at most 2mn 2 The computation time is T(f′(x1,x2,…,xn))=n*{T(f1(x1,x2,…,xn))+T((f2(…))+…+T(f m (…)}, all n participants need to perform related calculations locally.

[0120] Then the privacy protection cost is: the additional communication overhead is 2mn 2 -2n data transmissions, the additional computational overhead is T(f′(x1,x2,…,xn))-T(f(x1,x2,…,xn)).

[0121] The multi-party computing model measurement method provided in the embodiments of the present application calculates the computational benefit contribution of the second participant's output with respect to the first participant's specific input, and calculates the actual privacy loss of the multi-party computing model for the first participant's input, and then determines the applicability of the multi-party computing model based on the computational benefit contribution and the actual privacy loss. This allows the computational benefit contribution and the actual privacy loss to be used to perform a reasonable quantitative measurement of the applicability of the multi-party computing model, allowing the participants to use quantitative, data-based measurement values to determine the applicability of the multi-party computing model for the participants, thereby avoiding problems such as privacy data leakage and excessive implementation costs caused by the participants adopting inappropriate multi-party computing models.

[0122] It should be noted that one of the purposes of the above examples is to provide a method for measuring the privacy protection of each party's data by the target computation function under an ideal multi-party computation model, a method for measuring the privacy protection strength of secure multi-party computation, and a method for calculating the privacy protection cost. The following supplementary explanations of the relevant concepts are as follows:

[0123] 1. Calculate the profit contribution: the contribution of participant Y to the result of function F;

[0124] 2. Ideal privacy loss: The minimum privacy leakage of participant Y under the condition of accurate calculation (without considering differential privacy such as perturbation);

[0125] 3. Actual privacy loss: The actual privacy of participant Y is leaked during the secure multi-party computation process and its results.

[0126] 4. Privacy protection strength: comparison of actual privacy loss and ideal privacy loss;

[0127] 5. Privacy protection cost: Compared with plaintext computing, secure multi-party computing increases computing and communication overhead;

[0128] 6. Calculating benefit contribution > actual privacy loss + privacy protection cost. This is the significance of privacy computing.

[0129] 7. The smaller the actual privacy loss, the better. The maximum benefit should be a balance between privacy loss and protection cost.

[0130] In the above embodiment, a multi-party computing model measurement method is provided. Correspondingly, the present application also provides a multi-party computing model measurement device. The multi-party computing model measurement device provided in the embodiment of the present application can implement the above multi-party computing model measurement method. The multi-party computing model measurement device can be implemented by software, hardware, or a combination of software and hardware. For example, the multi-party computing model measurement device can include integrated or separate functional modules or units to perform the corresponding steps in the above methods. Please refer to Figure 2 , which schematically illustrates a first schematic diagram of a multi-party computing model measurement device provided by some embodiments of the present application. Since the device embodiments are substantially similar to the method embodiments, the description is relatively brief. For relevant details, please refer to the description of the method embodiments. The device embodiments described below are merely illustrative.

[0131] like Figure 2 As shown, a multi-party computing model measurement device 10 may include:

[0132] A calculation benefit contribution determination module 101 is configured to calculate, for a multi-party calculation model, a calculation benefit contribution of an output of a second participant with respect to a specific input of a first participant; and

[0133] an actual privacy loss determination module 102, configured to calculate an actual privacy loss of the multi-party computing model for the input of the first participant;

[0134] The applicability determination module 103 is configured to determine the applicability of the multi-party computing model according to the computing benefit contribution and the actual privacy loss.

[0135] In some modified implementations of the embodiments of the present application, the multi-party computing model includes multiple intermediate functions;

[0136] The actual privacy loss determination module 102 includes:

[0137] an intermediate function privacy loss calculation unit, configured to calculate an actual privacy loss of each intermediate function in the multi-party computing model for the input of the first participant;

[0138] A maximum privacy loss selection unit is configured to select the maximum privacy loss from the actual privacy loss of each intermediate function on the input of the first participant as the actual privacy loss of the multi-party computing model on the input of the first participant.

[0139] In some modified implementations of the embodiments of the present application, the apparatus 10 further includes:

[0140] The privacy leakage function determination module is used to determine the intermediate function corresponding to the actual privacy loss with the largest value as the intermediate function with the largest privacy leakage probability in the multi-party computing model.

[0141] In some modified implementations of the embodiments of the present application, the revenue contribution calculation and determination module 101 includes:

[0142] an average entropy calculation unit, configured to calculate an average entropy of an output of the function of the multi-party computing model with respect to the second participant; and

[0143] a specific entropy calculation unit, configured to calculate a specific entropy of an output of the second participant when a function of the multi-party computing model inputs a specific input of the first participant;

[0144] The calculation benefit contribution determination unit is used to determine the difference or ratio between the average entropy and the specific entropy as the calculation benefit contribution of the output of the second participant with respect to the specific input of the first participant.

[0145] In some modified implementations of the embodiments of the present application, the apparatus 10 further includes:

[0146] an ideal privacy loss determination module, configured to calculate an ideal privacy loss of the multi-party computing model for the input of the first party;

[0147] a privacy protection strength determination module, configured to determine the privacy protection strength of the multi-party computing model according to a ratio of the ideal privacy loss to the actual privacy loss;

[0148] The privacy protection strength application module is used to determine the applicability of the multi-party computing model according to the privacy protection strength.

[0149] In some modified implementations of the embodiments of the present application, the apparatus 10 further includes:

[0150] A privacy protection cost calculation module, used to calculate the privacy protection cost of the multi-party computing model;

[0151] The applicability determination module 103 includes:

[0152] A suitability determination unit is configured to determine the suitability of the multi-party computing model according to the computing benefit contribution, the actual privacy loss, and the privacy protection cost.

[0153] In some modified implementations of the embodiments of the present application, the privacy protection cost includes additional communication overhead and additional computing overhead when the multi-party computing model is applied.

[0154] The multi-party computing model measurement device 10 provided in the embodiment of the present application is based on the same inventive concept as the multi-party computing model measurement method provided in the aforementioned embodiment of the present application and has the same beneficial effects.

[0155] An embodiment of the present application also provides an electronic device corresponding to any multi-party computing model measurement method provided in the aforementioned embodiment. The electronic device can be any electronic device with data computing functions to execute the above-mentioned multi-party computing model measurement method.

[0156] Please refer to Figure 3 , which shows a schematic diagram of an electronic device provided by some embodiments of the present application. Figure 3 As shown, the electronic device 20 may include: a processor 200, a memory 201, a bus 202 and a communication interface 203, and the processor 200, the communication interface 203 and the memory 201 are connected via the bus 202; the memory 201 stores a computer program that can be run on the processor 200, and when the processor 200 runs the computer program, it executes the multi-party computing model measurement method provided in any of the aforementioned embodiments of the present application.

[0157] The memory 201 may include high-speed random access memory (RAM) and may also include non-volatile memory, such as at least one disk storage. The system network element and at least one other network element are connected via at least one communication interface 203 (which may be wired or wireless), and the Internet, wide area network, local area network, metropolitan area network, etc. may be used.

[0158] Bus 202 may be an ISA bus, a PCI bus, or an EISA bus. The bus may be divided into an address bus, a data bus, a control bus, and the like. Memory 201 is used to store programs, and processor 200 executes the programs upon receiving execution instructions. The multi-party computing model measurement method disclosed in any of the aforementioned embodiments of the present application may be applied to or implemented by processor 200.

[0159] The processor 200 may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method can be completed by hardware integrated logic circuits in the processor 200 or by software instructions. The above processor 200 may be a general-purpose processor, which may include a central processing unit (CPU), a network processor (NP), etc.; it may also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), an off-the-shelf field programmable gate array (FPGA) or other programmable logic device, discrete gate or transistor logic device, or discrete hardware component. The various methods, steps, and logic block diagrams disclosed in the embodiments of this application can be implemented or executed. The general-purpose processor may be a microprocessor or any conventional processor. The steps of the method disclosed in the embodiments of this application can be directly implemented and executed by a hardware decoding processor, or by a combination of hardware and software modules in the decoding processor. The software module can be located in a storage medium mature in the art, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, etc. The storage medium is located in the memory 201 , and the processor 200 reads the information in the memory 201 and completes the steps of the above method in combination with its hardware.

[0160] The electronic device provided in the embodiment of the present application and the multi-party computing model measurement method provided in the embodiment of the present application are based on the same inventive concept and have the same beneficial effects as the methods adopted, operated or implemented therein.

[0161] The present application also provides a computer-readable medium corresponding to the multi-party computing model measurement method provided in the above embodiment. Figure 4 The computer-readable storage medium shown is a CD 30, on which a computer program (ie, a program product) is stored. When the computer program is run by a processor, it executes the multi-party computing model measurement method provided by any of the aforementioned embodiments.

[0162] It should be noted that examples of the computer-readable storage medium may also include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other optical or magnetic storage media, which are not listed here one by one.

[0163] The computer-readable storage medium provided in the above-mentioned embodiments of the present application and the multi-party computing model measurement method provided in the embodiments of the present application are based on the same inventive concept and have the same beneficial effects as the methods adopted, run or implemented by the application programs stored therein.

[0164] It should be noted that the flowcharts and block diagrams in the accompanying drawings show the possible architectures, functions and operations of the systems, methods and computer program products according to multiple embodiments of the present application. In this regard, each box in the flowchart or block diagram can represent a module, a program segment or a part of a code, and the module, program segment or a part of the code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in an order different from that marked in the accompanying drawings. For example, two consecutive boxes can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, and the combination of boxes in the block diagram and / or flowchart, can be implemented with a dedicated hardware-based system that performs the specified function or action, or can be implemented with a combination of dedicated hardware and computer instructions.

[0165] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0166] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are merely schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some communication interface, the indirect coupling or communication connection of the device or unit can be electrical, mechanical or other forms.

[0167] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0168] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0169] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and may include several instructions to enable a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium may include: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

[0170] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some or all of the technical features therein. These modifications or replacements do not deviate the essence of the corresponding technical solutions from the scope of the technical solutions of the embodiments of the present application, and they should all be included in the scope of the claims and description of the present application.

Claims

1. A multi-party computing model measurement method, characterized in that: include: For a multi-party computation model, calculating a computational benefit contribution of a second participant's output with respect to a specific input of a first participant, wherein the computational benefit contribution is used to indicate the degree of influence of the first participant's input on the distribution of the second participant's output from the perspective of the second participant; and Calculating the actual privacy loss of the multi-party computation model for the input of the first party, wherein the privacy loss is used to indicate the likelihood that the second party can infer the input distribution of the first party through its corresponding input and output; Determining the applicability of the multi-party computing model based on the computational benefit contribution and the actual privacy loss; The method further comprises: Calculating the privacy protection cost of the multi-party computing model; Determining the applicability of the multi-party computing model based on the computational benefit contribution and the actual privacy loss includes: The applicability of the multi-party computing model is determined according to the computing benefit contribution, the actual privacy loss, and the privacy protection cost.

2. The method according to claim 1, characterized in that The multi-party computing model includes multiple intermediate functions; Calculating an actual privacy loss of the multi-party computing model's input to the first party includes: Calculating the actual privacy loss of each intermediate function in the multi-party computation model for the input of the first party; From the actual privacy loss of each intermediate function on the input of the first participant, the one with the largest value is selected as the actual privacy loss of the multi-party computing model on the input of the first participant.

3. The method according to claim 2, characterized in that The method further comprises: The intermediate function corresponding to the actual privacy loss with the largest value is determined as the intermediate function with the largest probability of privacy leakage in the multi-party computing model.

4. The method according to claim 1, wherein The step of calculating the computational benefit contribution of the output of the second participant with respect to the specific input of the first participant in the multi-party computation model includes: Calculating the average entropy of the output of the function of the multi-party computing model with respect to the second participant; and Calculating a specific entropy of an output of the second participant when a function of the multi-party computing model inputs a specific input of the first participant; The difference or ratio between the average entropy and the specific entropy is determined as the calculated benefit contribution of the output of the second participant with respect to the specific input of the first participant.

5. The method according to claim 1, wherein The method further comprises: Calculating an ideal privacy loss of the multi-party computation model for the input of the first party; Determining the privacy protection strength of the multi-party computing model according to a ratio of the ideal privacy loss to the actual privacy loss; The applicability of the multi-party computing model is determined according to the privacy protection strength.

6. The method according to claim 1, characterized in that The privacy protection cost includes additional communication overhead and additional computing overhead when the multi-party computing model is applied.

7. A multi-party computing model measurement device, characterized in that: include: a computational benefit contribution determination module, configured to calculate, for a multi-party computational model, a computational benefit contribution of a second participant's output with respect to a specific input of a first participant, wherein the computational benefit contribution is used to indicate the degree of influence of the first participant's input on the distribution of the second participant's output from the perspective of the second participant; and an actual privacy loss determination module, configured to calculate an actual privacy loss of the multi-party computation model for the input of the first party, wherein the privacy loss is used to indicate the likelihood that the second party can infer the input distribution of the first party through its corresponding inputs and outputs; a suitability determination module, configured to determine the suitability of the multi-party computing model based on the computational benefit contribution and the actual privacy loss; The device further comprises: A privacy protection cost calculation module, used to calculate the privacy protection cost of the multi-party computing model; The applicability determination module includes: a applicability determination unit, configured to determine the applicability of the multi-party computing model according to the computing benefit contribution, the actual privacy loss, and the privacy protection cost.

8. An electronic device comprising: A memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the method according to any one of claims 1 to 6.

9. A computer-readable medium, characterized in that Computer-readable instructions are stored thereon, and the computer-readable instructions can be executed by a processor to implement the method according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Big data platform privacy protection evaluation method and device based on Del entropy method

    CN108416227A

  • Multi-party safety calculation method and device, and electronic equipment

    CN109241016A