Method and apparatus for continuously executing Boolean circuits based on garbled circuits

By using the pre-generated obfuscation table and the xOR value relationship in multi-party security calculations, the input and output labels of the operator circuit are determined, and the problem of low communication efficiency in business scenarios with high computational volume is solved, and efficient continuous execution of Boolean circuits is achieved.

CN114239087BActive Publication Date: 2025-06-17SASI DIGITAL TECHNOLOGY (BEIJING) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111520799.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-13
Publication Date
2025-06-17
Estimated Expiration
2041-12-13

AI Technical Summary

Technical Problem

In the multi-party security calculation process, in business scenarios with large calculation volume, communication volume and communication efficiency have a great impact on the continuous execution efficiency of Boolean circuits, and the existing technology has problems of redundant communication and inefficiency.

Method used

By pre-creating multiple obfuscation tables in the obfuscation circuit and preparing data in the offline preparation stage, in the online business processing stage, the conversion relationship between the input and output labels of each operator circuit is determined to reduce redundant communication.

Benefits of technology

It realizes that in multi-party security calculation, reduces redundant communications, improves service processing efficiency, and improves the efficiency of continuous execution of Boolean circuits by flexibly combining obfuscation tables.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114239087B_ABST
    Figure CN114239087B_ABST
Patent Text Reader

Abstract

The embodiments of this specification provide a method and apparatus for continuously executing Boolean circuits based on garbled circuits. During the business processing of multi-party secure computing, the business processing process is split into a continuous execution process of multiple operator circuits based on garbled circuits. Before the start of the business execution process, a large amount of garbled table data can be pre-stored. Among them, when the output line of the front circuit serves as the input line of the rear circuit, the garbler determines the association relationship between the alternative tags corresponding to the output line of the front circuit and the alternative tags corresponding to the input line of the rear circuit, and the front circuit determines the input tag corresponding to the input line of the rear circuit according to the output tag in the execution result and the association relationship. In this way, the computing party can continuously execute the execution of each operator circuit, reduce redundant communication, and improve the business processing efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] One or more embodiments of this specification relate to the field of secure computing technology, and in particular, to a method and apparatus for continuously executing Boolean circuits based on garbled circuits. Background Art

[0002] A garbled circuit (GC) is a secure multi-party computation protocol that constructs a secure function calculation through a Boolean circuit, enabling participants to calculate results for input values without knowing the specific numbers they input in the calculation formula. Garbled circuits can be used in the process of multi-party secure computation. Secure multi-party computation (SMC) can also be referred to as multi-party secure computation (MPC), which can solve the problem of securely calculating a predefined function in the absence of a trusted third party. Secure multi-party computation can be applied to various service scenarios such as joint training models, private set intersection, and secure comparison. During the continuous execution of a Boolean circuit using the garbled circuit method, the number of Boolean circuits varies according to the complexity of the service scenario. For service scenarios with a large amount of computation, the communication volume and communication efficiency during the computation directly affect the continuous execution efficiency of the Boolean circuit for secure computation. Summary of the Invention

[0003] One or more embodiments of this specification describe a method and apparatus for continuously executing a Boolean circuit based on a garbled circuit to solve one or more problems mentioned in the background art.

[0004] According to a first aspect, a method for continuously executing a Boolean circuit based on a garbled circuit is provided. The Boolean circuit includes a first operator circuit and a second operator circuit. The first output line of the first operator circuit corresponds to the first input line of the second operator circuit. The exclusive OR value between two alternative tags determined by the garbler for a single output line / single input line is a first random string held only locally. The method is executed by a computing party and includes: executing the first operator circuit according to a first garbled table pre-obtained from the garbler to obtain a first output tag corresponding to the first output line, where the first output tag is one of two alternative tags determined by the garbler for the first output line during the generation of the first garbled table; synchronizing with the garbler the selection result of a second garbled table corresponding to the second operator circuit to obtain a first conversion string provided by the garbler for the first output line and the first input line, where the first conversion string is used to describe the conversion relationship between the alternative tags corresponding to the first output line and the first input line for the same candidate bit; determining a first input tag corresponding to the first input line according to the exclusive OR result of the first conversion string and the first output tag; and executing the second operator circuit based on the first input tag and the second garbled table.

[0005] In one embodiment, during the execution of the Boolean circuit, the input tag corresponding to the garbler is obtained from the garbler based on the alternative tags corresponding to the respective input wires, and the input tag corresponding to the computing party is obtained from the garbler via oblivious transfer.

[0006] In a further embodiment, the computing party stores a selected data set previously obtained from the garbler via oblivious transfer. A single piece of selected data in the selected data set includes a single selected bit selected from two candidate bits, and a single selected string corresponding to the single selected bit in the respective two reference strings. The computing party determines based on a single piece of selected data for the single input tag corresponding to a single local input bit.

[0007] In one embodiment, the input bit provided by the computing party includes a first bit. The second input tag corresponding to the first bit is determined as follows: randomly select from the selected data the first selected data corresponding to a first selected bit and a first selected string; provide the first exclusive - or result of the first bit and the first selected bit to the garbler for the garbler to provide two ciphertexts corresponding to the two candidate bits to the computing party according to the first exclusive - or result, where the two ciphertexts are obtained by encrypting the respective two alternative tags with the two reference strings corresponding to the first selected data; decrypt the two ciphertexts with the first selected string to obtain the second input tag.

[0008] Wherein, in the case that the first comparison result is the same, the garbler encrypts the two alternative tags respectively with the two reference strings according to the corresponding candidate bits to obtain the two ciphertexts; in the case that the first comparison result is different, the garbler encrypts the two alternative tags with the two reference strings by cross - encrypting according to the candidate bits to obtain the two ciphertexts.

[0009] In one embodiment, the first operator circuit is an operator circuit of the first type, and the first confusion table is determined from multiple confusion tables generated by the garbler for the operator circuit of the first type; the second operator circuit is an operator circuit of the second type, and the second confusion table is determined from multiple confusion tables generated by the garbler for the operator circuit of the second type.

[0010] In one embodiment, the first confusion table and the second confusion table are selected or specified by one of the garbler and the computing party and informed to the other party, or determined through negotiation by both parties.

[0011] According to a second aspect, a method for continuously executing a Boolean circuit based on garbled circuits is provided. The Boolean circuit includes a first operator circuit and a second operator circuit. The first output line of the first operator circuit corresponds to the first input line of the second operator circuit. The XOR value between two alternative tags determined by the garbler for a single output line / single input line is a first random string held only locally. The method is executed by the garbler and includes: synchronizing with the computing party the selection result of the second garbled table corresponding to the second operator circuit; determining, according to the selection result of the second garbled table, a first conversion string for describing the conversion relationship between the alternative tags corresponding to the same candidate bit of the first output line and the first input line; and providing the first conversion string to the computing party for the computing party to determine a first output tag of the first output line based on the first string, so as to execute the second operator circuit.

[0012] In one embodiment, the first conversion string is a string obtained by performing an XOR operation between the alternative tags corresponding to the same candidate bit of the first output line and the first input line.

[0013] According to a third aspect, a device for continuously executing a Boolean circuit based on garbled circuits is provided. The Boolean circuit includes a first operator circuit and a second operator circuit. The first output line of the first operator circuit corresponds to the first input line of the second operator circuit. The XOR value between two alternative tags determined by the garbler for a single output line / single input line is a first random string held only locally. The device is disposed in the computing party and includes:

[0014] An execution unit configured to execute the first operator circuit according to a first garbled table pre-obtained from the garbler to obtain a first output tag corresponding to the first output line, where the first output tag is one of two alternative tags determined by the garbler for the first output line during the process of generating the first garbled table;

[0015] A selection unit configured to synchronize with the garbler the selection result of the second garbled table corresponding to the second operator circuit to obtain a first conversion string provided by the garbler for the first output line and the first input line, where the first conversion string is used to describe the conversion relationship between the alternative tags corresponding to the same candidate bit of the first output line and the first input line;

[0016] A determination unit configured to determine a first input tag corresponding to the first input line according to the XOR result of the first conversion string and the first output tag;

[0017] The execution unit is further configured to execute the second operator circuit based on the first input tag and the second garbled table.

[0018] According to a fourth aspect, there is provided a device for continuously executing a Boolean circuit based on garbled circuits. The Boolean circuit includes a first operator circuit and a second operator circuit. The first output line of the first operator circuit corresponds to the first input line of the second operator circuit. The exclusive OR value between two alternative tags determined by the garbler for a single output line / single input line is a first random string held only locally. The device is provided in the garbler and includes:

[0019] A selection unit configured to synchronize with the computing party the selection result of the second garbled table corresponding to the second operator circuit;

[0020] A determination unit configured to determine, according to the selection result of the second garbled table, a first conversion string for describing the conversion relationship between the alternative tags corresponding to the first output line and the first input line for the same candidate bit;

[0021] A providing unit configured to provide the first conversion string to the computing party for the computing party to determine a first output tag of the first output line based on the first string, so as to execute the second operator circuit.

[0022] According to a fifth aspect, there is provided a computer-readable storage medium having stored thereon a computer program which, when executed on a computer, causes the computer to execute the method of the first aspect or the second aspect.

[0023] According to a sixth aspect, there is provided a computing device including a memory and a processor, characterized in that the memory stores executable code, and when the processor executes the executable code, the method of the first aspect or the second aspect is implemented.

[0024] Through the method and device provided in the embodiments of the present specification, in the process of multi-party secure computing service processing, the service processing process is split into a continuous execution process of multiple operator circuits based on garbled circuits. Before the start of the service execution process, a large amount of garbled table data can be pre-stored. Among them, when the output line of the front circuit is used as the input line of the rear circuit, the garbler determines the association relationship between the alternative tags corresponding to the output line of the front circuit and the alternative tags of the input line of the rear circuit, and the front circuit determines the input tag corresponding to the input line of the rear circuit according to the output tag in the execution result and the association relationship. In this way, the garbled tables of each adjacent operator circuit are independent of each other, and the amount of transmitted data is small. Thus, on the basis of enabling the computing party to continuously execute each operator circuit, the garbled tables can be flexibly combined, redundant communication can be reduced, and the service processing efficiency can be improved. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] To more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0026] Figure 1 Schematic diagram of the garbled circuit logic showing a specific example;

[0027] Figure 2 Schematic diagram of the sequential execution of a Boolean circuit based on a garbled circuit showing a specific example;

[0028] Figure 3 Flowchart of the method for sequential execution of a Boolean circuit based on a garbled circuit executed by a computing party according to an embodiment;

[0029] Figure 4 Flowchart of the method for sequential execution of a Boolean circuit based on a garbled circuit executed by a garbling party according to an embodiment;

[0030] Figure 5 Schematic block diagram of a device for sequential execution of a Boolean circuit based on a garbled circuit provided in a computing party according to an embodiment;

[0031] Figure 6 Schematic block diagram of a device for sequential execution of a Boolean circuit based on a garbled circuit provided in a garbling party according to an embodiment. Detailed implementation manners

[0032] The following describes the technical solutions provided in this specification in conjunction with the drawings.

[0033] First, the logical principle of the garbled circuit is described. Figure 1 Schematic diagram of a garbled circuit showing a specific example. As Figure 1 shown, in this specific application scenario, it involves a combination of multiple gate circuits. There are a total of 3 inputs a0, b0, c0, and 4 gate circuits finally output c1. A total of 7 input and output lines a0, b0, c0, d, e, f, c1 are involved. Assuming the garbling party (Garbler) is denoted as A and the computing party (Evaluator) is denoted as B, for each line, the corresponding string of a predetermined length can be generated by Party A, such as denoted as X i 0 、X i 1, representing the true value 0 and the true value 1 respectively, where \(i = a0, b0, c0, d, e, f, c1\). Then, the obfuscator A can generate obfuscation tables for each logic gate respectively. For example, assume that the initial input bits \(a0\) and \(c0\) are held by the obfuscator A, and \(b0\) is held by the computing party B. For the NAND gate circuit with inputs \(a0\) and \(c0\) and output \(d\), there are 4 cases for the true values, and the values of \(a0\), \(c0\), and \(d\) are respectively: \((0, 0, 0)\), \((0, 1, 1)\), \((1, 0, 1)\), \((1, 1, 0)\). The obfuscator A uses strings of various predetermined lengths as labels for the corresponding true values to identify the corresponding true values. Representing this true value correspondence as strings can be: \((X a0 0 , X c0 0 , X d 0 ), (X a0 0 , X c0 1 , X d 1 ), (X a0 1 , X c0 0 , X d 1 ), (X a0 1 , X c0 1 , X d 0 ). Further, encrypt the output label with the input label, for example, encrypt \(X a0 0 \), \(X c0 0 \) to encrypt \(X d 0 \) and denote it as Similarly, encrypt the 4 cases respectively and scramble the order, that is, obfuscate. In this way, an obfuscation table for the NAND gate circuit of \(a0\) and \(c0\) can be obtained and sent to the computing party. Figure 1 In the example shown, the obfuscator A can provide 4 obfuscation tables corresponding one-to-one to 4 logic gates for the computing party B.

[0034] In addition, during the calculation process of the obfuscator and the computing party, the obfuscator sends the label corresponding to the true value bit of the local input (such as \(a0 = 0\)) to the computing party B, and the computing party B does not know the true value represented by this label. For the input value held by the computing party (such as \(b0\)), through the oblivious transfer protocol, it can select its corresponding label from the obfuscator A, and the obfuscator A does not know which label it selects, such as not knowing whether it selects \(X b0 1 \) or \(X b00 After obtaining the confusion tables and input tags of each gate circuit through the calculation method, decrypt along the circuit. For the confusion table of each circuit, there is a row that can be decrypted to obtain the corresponding tag. For example, for the Figure 1 circuit, assuming that the input tag obtained by the computing party B is X a0 1 , X b0 1 , X c0 0 , based on this, X d 1 , X e 1 , X f 1 , X c1 0 can be decrypted in sequence. After that, the obfuscator A and the computing party B can share the results. For example, the computing party B shares X c1 0 with the obfuscator A, or the obfuscator A shares X c1 0 , X c1 1 with the computing party B.

[0035] In the Figure 1 example, if there is only one input bit for the computing party B, then in the circuit calculation process, an oblivious transfer protocol (hereinafter also referred to as OT) needs to be used to obtain the input tag once. In the case where the computing party B holds multiple input bits, the corresponding input tags can be obtained through multiple oblivious transfer protocols. Generally, for the computing party B to obtain the input tag, the obfuscator A can directly send two tags corresponding to two candidate bits (0, 1), and use the obfuscator A as the sender and the computing party B as the receiver to select one corresponding to the input bit through the oblivious transfer method.

[0036] It can be understood that in order to save communication resources in the business processing process, the process of the obfuscator and the computing party for business processing can be divided into an offline preparation stage and an online business processing stage. In the offline preparation stage, the obfuscator and the computing party can prepare data such as confusion tables required online. Here, offline can be understood as that the continuous execution process of the Boolean circuit has not started. For example, input data has not been provided to the prediction model for business prediction, etc., rather than the two parties not being connected to the network and not interacting. The online business processing stage is the process where both parties obtain input data, and the computing party obtains each input tag and performs calculations.

[0037] In the actual business process, a business may require multiple operators. For example, a specific business may include 5,000 multiplication operators, 8,000 addition operators, 1,000 comparison operators, etc. A single operator can be implemented through multiple logic gates, and the overall circuit corresponding to a single operator can be denoted as a single-operator circuit, for example. The actual circuit execution process may be complex. For example, the output line of one circuit is the input line of one or more subsequent circuits, and the input lines of the subsequent circuits can include the output lines of the previous circuits, or can also include input lines determined by the input data or independent of the previous circuits. In conventional technologies, it may be possible to split the output tags into data jointly held by two parties, and connect different operator circuits through methods such as the combination of logic gates (such as exclusive-OR gates) during the subsequent circuit execution. In this way, it may add a part of redundant calculation and redundant communication to the execution of the operator circuit. If a specific business (such as a joint training business model, etc.) includes a large number of operator circuits, for the input and output lines connecting the two circuits before and after, if redundant communication occurs, it may increase the communication burden.

[0038] Reference Figure 2 As shown, it is a schematic illustration of a specific example of the continuous execution of a Boolean circuit based on a garbled circuit. As Figure 2 shown, X, Y, Z, and W can be 4 operator circuits (such as one of a multiplication operator circuit, an addition operator circuit, a comparison operator circuit, etc.), and are sequentially executed in a specific business. A single operator circuit can include multiple logic gates, corresponding to multiple input lines and multiple output lines. Figure 2 In it, the input lines and output lines are indicated by the arrow directions. The lines pointing to the operator circuit are its input lines, and the lines away from the operator circuit are its output lines. From Figure 2 it can be seen that t1, t2, t3, t4, and t5 are both the output lines of one operator circuit and the input lines of another operator circuit. In other words, for the output result itself, the output result of the previous operator circuit corresponds to the input data of another operator circuit.

[0039] Taking t1 as an example, if the true value of the output bit corresponding to the operator circuit X and t1 is 0, then the true value of the input bit corresponding to the operator circuit Y and t1 is also 0; if the true value of the output bit corresponding to the operator circuit X and t1 is 1, then the true value of the input bit corresponding to the operator circuit Y and t1 is also 1. When it is the output line of the operator circuit X, t1 can correspond to alternative tags of the output line such as O t1 0 、O t1 1 , and when it is the input line of the operator circuit Y, t1 can correspond to alternative tags of the output line such as I t1 0 、I t1 1. In conventional technology, when the confusion tables of operator circuits X and Y are independent of each other, the conversion can be performed in the splitting and combining manner described above. The conversion process is, for example, by splitting the output label corresponding to t1 in X into a bit stored by the obfuscating party and the computing party respectively, and then using these two bits as input bits of the two parties respectively, using one input label provided by the obfuscating party and another input label of the computing party determined by the oblivious transmission method, and obtaining the input label corresponding to the operator circuit X at t1 through the processing of a gate circuit (such as an XOR gate). This method introduces at least one redundant communication of a gate circuit.

[0040] To this end, this specification proposes a technical concept for continuous execution of Boolean circuits. When the output line of the previous circuit serves as the input line of the subsequent circuit, the input label of the subsequent circuit can be safely obtained by the calculation party through the output label of the previous circuit and the alternative label of the subsequent circuit.

[0041] According to the technical concept of this specification, in the offline preparation stage, the obfuscator can generate obfuscation tables for various types of operator circuits. Among them, multiple obfuscation tables can be generated for one type of operator circuit. In a single obfuscation table, alternative labels for each input line are randomly generated, and a single input line corresponds to two alternative labels, which are 0 labels (such as corresponding to 0 bits) and 1 labels (such as corresponding to 1 bit) corresponding to candidate bits 0 and 1, respectively. When the corresponding operator circuit is executed according to the alternative labels of the input lines, the alternative labels of each output line of the corresponding operator circuit can be obtained. Reference Figure 1 As shown in FIG. 1 , for a gate circuit, the corresponding confusion table of the gate circuit can be obtained by encrypting the candidate labels of the corresponding output lines through the candidate labels of the input lines and scrambling the order. The confusion tables of each gate circuit in an operator circuit constitute a confusion table of the operator circuit of this type.

[0042] In order to facilitate the determination of the input label of the subsequent circuit by the output label of the previous circuit in the continuous operator circuit, such as by Figure 2 The output of operator circuit X is first labeled with t1 to obtain the input label corresponding to input line t1 in operator circuit Y. The obfuscator can keep the XOR value of the 0 label and the 1 label of a single input line as a fixed random string in the process of generating the alternative labels of the input lines. In this way, the XOR value of the alternative 0 label and 1 label of each output line is also the fixed random string.

[0043] It should be noted that the obfuscator can provide the obfuscation table to the computing party for the computing party to execute the corresponding operator circuit. However, the above random strings generally cannot be leaked to the computing party to avoid disclosing the data privacy of the obfuscator. When the computing party executes the operator circuit, for the input wires of the input data provided by the obfuscator, the obfuscator sends the corresponding input tags to the computing party. For the input wires of the input data provided by the computing party, the obfuscator and the computing party can secretly select the input tags corresponding to the local input bits from the alternative tags of the obfuscator by executing the oblivious transfer protocol.

[0044] After the above offline preparation operations are completed, the obfuscator and the computing party can perform continuous calculations of the operator circuit based on the generated obfuscation table for business processing. Among them, the input tags of the obfuscator are directly sent to the computing party by the obfuscator according to the alternative tags, and the input tags corresponding to the input data of the computing party are selected from the alternative tags of the obfuscator based on the oblivious transfer protocol. From Figure 2 It can be seen that the technical concept of this specification is proposed for sequentially executed Boolean circuits, and is particularly applicable to the continuous execution process of Boolean circuits where the output wires of the previous circuit are used as the input wires of the subsequent circuit.

[0045] Figure 3 Shows the continuous execution process of the Boolean circuit based on the obfuscation circuit according to an embodiment of this specification, which is used to describe the calculation process executed by the computing party in the online service processing stage. Since the input tags of the Boolean circuit are provided by the obfuscator, this process is completed with the cooperation of the obfuscator.

[0046] As Figure 3 shown, assuming that the continuous Boolean circuit includes a first operator circuit and a second operator circuit, the first output wire of the first operator circuit is the first input wire of the second operator circuit, and the exclusive OR value between the two alternative tags determined by the obfuscator for a single output wire / single input wire is the first random string held only locally (confidential to the computing party), then the continuous execution process of the Boolean circuit based on the obfuscation circuit executed by the computing party can include: Step 301, execute the first operator circuit according to the first obfuscation table obtained from the obfuscator in advance to obtain the first output tag corresponding to the first output wire, and the first output tag is one of the two alternative tags determined for the first output wire based on the first obfuscation table; Step 302, synchronize with the obfuscator the selection result of the second obfuscation table corresponding to the second operator circuit to obtain the first conversion string provided by the obfuscator for the first output wire and the first input wire, and the first conversion string is used to describe the conversion relationship between the alternative tags corresponding to the same candidate bit for the first output wire and the first input wire; Step 303, determine the first input tag corresponding to the first input wire according to the exclusive OR result of the first conversion string and the first output tag; Step 304, execute the second operator circuit based on the first input tag and the second obfuscation table.

[0047] First, through step 301, execute the first operator circuit according to the first confusion table obtained in advance from the obfuscator, and obtain the first output label corresponding to the first output wire. Among them, the first confusion table is the confusion table generated by the obfuscator for the first operator circuit or the first operator type corresponding to the first operator circuit. The first confusion table may include the output labels encrypted with the input labels of each gate circuit. It can be understood that there may be multiple copies of the confusion table stored by the computing party for the first operator circuit, and the first confusion table is one of them. The first confusion table may be selected or specified by one party of the obfuscator or the computing party and informed the other party, or may be determined by both parties through negotiation or other means, which is not limited here.

[0048] The obfuscator locally stores alternative labels for each input wire and output wire. For the input data of the obfuscator, the obfuscator can directly provide the corresponding input label to the computing party. For example, when the obfuscator provides an input bit 1 in a gate circuit, it provides the alternative label corresponding to the candidate bit 1 among the two alternative labels corresponding to the corresponding input wire as the corresponding input label. For the input bits corresponding to the input data of the computing party, the corresponding input label can be selected from the corresponding alternative labels of the obfuscator through the oblivious transfer method, and the obfuscator does not know which one the computing party selects.

[0049] In a possible design, in the offline preparation stage, the obfuscator and the computing party can also execute a random oblivious transfer protocol (Random OT, abbreviated as ROT) to use the ROT execution result to determine the corresponding input label for the input bit of the computing party in the online service execution stage. In one ROT process, the computing party can select one of the two reference strings (such as L0, L1) generated by the obfuscator. The selection result is consistent with the candidate bit (0, 1) selected by the computing party from the obfuscator. If the selected bit is denoted as c, the selected reference string can be denoted as Lc. In this way, after one ROT operation, the obfuscator holds the two reference strings corresponding to the two candidate bits, and the computing party holds the selected data, that is: the selected bit selected from the two candidate bits, and the selected string that is consistent with the selected bit among the two reference strings. Among them, the obfuscator does not know the selected bit c and the selected string Lc selected by the computing party. When c = 0, Lc can be L0, and when c = 1, Lc can be L1.

[0050] Once the ROT result can be used for calculation, when the calculation party receives the corresponding input bit, it selects the label corresponding to the input bit from the two alternative labels corresponding to the two candidate bits from the obfuscation party as the input label. The specific principle in one embodiment is as follows: The calculation party sends the comparison result (such as represented by the XOR value) of the input bit and the selection bit to the obfuscation party, and the obfuscation party determines the ciphertexts of the two alternative labels (corresponding to the two candidate bits 0 and 1 respectively) and provides them to the calculation party. The two ciphertexts corresponding to the two alternative labels are encrypted by the obfuscation party through XOR with two reference strings respectively according to the above comparison result. For example, when the comparison result of the input bit and the selection bit is the same (such as the XOR value is 0), the 0 label is encrypted with the reference string corresponding to the 0 bit, and the 1 label is encrypted with the reference string corresponding to the 1 bit. When the comparison result of the input bit and the selection bit is different (such as the XOR value is 1), the 1 label is encrypted with the reference string corresponding to the 0 bit, and the 0 label is encrypted with the reference string corresponding to the 1 bit. In this way, it can be ensured that the calculation party correctly decrypts the ciphertext corresponding to the local input bit through the selection string and obtains the corresponding alternative label as the input label.

[0051] As an example of the reference string, for an input wire, assume that the 0 label and 1 label generated by the obfuscation party are m0 and m1 respectively, and the reference strings are L0 and L1. The calculation party selects a candidate label c and the corresponding selection string Lc through oblivious transfer (such as ROT), and c can be 0 or 1. When determining the input label corresponding to the input bit of the calculation party, the calculation party can compare the input bit with c and send the comparison result to the obfuscation party. When the input bit is the same as c, the obfuscation party sends the XOR result M0 = L0 ^ m0 of L0 and m0 and the XOR result M1 = L1 ^ m1 of L1 and m1 to the calculation party, and the calculation party correctly decrypts one of m0 and m1 through Lc ^ M0 or Lc ^ M1 to obtain the input label corresponding to the input bit. On the other hand, when the input bit is different from c, the obfuscation party sends the XOR result M0 = L0 ^ m1 of L0 and m1 and the XOR result M1 = L1 ^ m0 of L1 and m0 to the calculation party, and the calculation party correctly decrypts one of m0 and m1 through Lc ^ M0 or Lc ^ M1 to obtain the input label corresponding to the input bit.

[0052] The obfuscation party and the calculation party can prepare the reference string in the offline preparation stage. That is to say, the obfuscation party and the calculation party can obtain multiple groups of reference strings (L0, L1) of the obfuscation party and the corresponding (c, Lc) of the calculation party through multiple executions of the ROT operation in the offline preparation stage.

[0053] In this way, the calculation party can select the corresponding input label from the corresponding alternative labels of the obfuscation party through the oblivious transfer method according to the selection data determined by the ROT mentioned above.

[0054] Further, during the process of the computing party executing the operator circuit, the output tags of each gate circuit can be decrypted in sequence according to each input tag, so as to execute the first operator circuit (for example, the operator circuit X in Figure 2 ). The execution result of the computing party for the first operator circuit can include multiple output tags. One output tag represents the true value of one bit, and the true values of multiple output tags describe the corresponding output results. The first output tag can be the output tag corresponding to any output wire (denoted as the first output wire) of the first operator circuit. It can be understood that this first output tag is one of the two alternative tags generated by the obfuscation party for the first output wire.

[0055] Next, in step 302, synchronize with the obfuscation party the second obfuscation table selected for the second operator circuit to obtain the first conversion string provided by the obfuscation party for the first output wire and the first input wire. The second obfuscation table is the obfuscation table generated by the obfuscation party for the second operator circuit. The second obfuscation table can include the encrypted and scrambled output tags of the input tags of each gate circuit of the second operator circuit. It can be understood that there can be multiple copies of the obfuscation table stored by the computing party for the second operator circuit, and the second obfuscation table is any one of them. The selection of the second obfuscation table is independent of the selection of the first obfuscation table. It can be selected or specified by one party of the obfuscation party or the computing party and informed the other party, or determined by both parties through negotiation, etc., which is not limited here.

[0056] After the second obfuscation table is selected, the obfuscation party can determine the first conversion string and provide it to the computing party. The first conversion string can be independently generated and provided by the obfuscation party, and is used to describe the conversion relationship between the alternative tags corresponding to the same candidate bit for the first output wire and the first input wire. Specifically, the first conversion string can be the string for converting between the two 0 tags corresponding to the candidate bit 0 of the first output wire and the first input wire, or the string for converting between the two 1 tags corresponding to the candidate bit 1 of the first output wire and the first input wire. For example, for Figure 2 the circuit shown, the alternative tags determined by the obfuscation party for the output wire t1 of the operator circuit X are, for example, O t1 0 、O t1 1 , where the exclusive OR result O t1 0 ∧O t1 1 is the random string R generated by the obfuscation party. The alternative tags determined by the obfuscation party for the input wire t1 of the operator circuit Y are, for example, I t1 0 、I t1 1 , I t10 Exclusive OR result with I t1 1 is also R. "∧" represents the exclusive OR operation on the strings on both sides of it. For 0 bit, the first conversion string can be t1 as the 0 label O of the output line of X t1 0 ∧I t1 1 is also R. "∧" represents the exclusive OR operation on the strings on both sides of it. For 0 bit, the first conversion string can be t1 as the 0 label O of the output line of X t1 0 and t1 as the 0 label I of the output line of Y t1 0 The string converted by the exclusive OR operation can be, for example, O t1 0 ∧I t1 0 Similarly, for 1 bit, the first conversion string can be t1 as the 1 label O of the output line of X t1 1 and t1 as the 1 label I of the output line of Y t1 1 The string converted by the exclusive OR operation can be, for example, O t1 1 ∧I t1 1 .

[0057] For the random string R, it can be a string randomly generated by the obfuscator and consistent with the number of bits of the alternative label. In practice, a random string R can be used commonly in all obfuscation tables of this operation. In one embodiment, for an input line in the operator circuit, when generating its corresponding two alternative labels, a random alternative label can be generated first, such as randomly generating a 0 label, and then performing an exclusive OR operation on the 0 label and R, and the result of the exclusive OR operation is used as the other alternative label, such as a 1 label. In another embodiment, when generating the obfuscation table, two alternative labels are generated first for the first input line, and the exclusive OR result of the two alternative labels is used as the random string R, and the subsequent input lines use this random string R to generate alternative labels. In this way, in all obfuscation tables, the exclusive OR result between the two alternative labels of a single input line or a single output line is R

[0058] Then, in step 303, the first input label corresponding to the first input line is determined according to the exclusive OR result of the first conversion string and the first output label. Here, the first output label of the first output line in the first operator circuit is converted into the first input label corresponding to the first input line in the second operator circuit through the first conversion string. The conversion method is that the first input label is the exclusive OR result of the first conversion string and the first output label

[0059] As an example, such as Figure 2The shown circuit X is used as the first operator circuit, and Y as the second operator circuit. The shared first output line and the first input line are t1. Assume the first conversion string is O t1 0 ∧I t1 0 , then when the first output label is O t1 0 corresponding to 0 bit, the computing party calculates according to O t1 0 and the exclusive OR result of O t1 0 ∧I t1 0 to obtain the first input label I t1 0 , which exactly corresponds to 0 bit. When the first output label is O t1 1 corresponding to 1 bit, the computing party calculates according to O t1 1 and the exclusive OR result of O t1 0 ∧I t1 0 to obtain the first input label as R∧I t1 0 =I t1 1 , which exactly corresponds to 1 bit. Similarly, when the first conversion string is O t1 1 ∧I t1 1 , the same result can be obtained. In this way, it is ensured that the output label of the first output line and the input label of the first input line correspond to the same truth bit, so as to effectively convert the output label of the first operator circuit into the input label of the second operator circuit.

[0060] Furthermore, through step 304, the second operator circuit is executed based on the first input label and the second confusion table. It can be understood that the second confusion table corresponds to a confusion table, including the confusion tables of each gate circuit in the second operator circuit. The computing party can use the second confusion table to decrypt the corresponding output labels sequentially according to each gate circuit, so as to execute the second operator circuit.

[0061] Among them, the second operator circuit may further include other input lines outside the first input line, corresponding to other input tags. The other input lines correspond to other input data. The other input data may include at least one of the following: output data from the first operator circuit or other previous operator circuits, original input data from the obfuscator or the computing party. Among them: the input tags of the output lines from the first operator circuit or other previous operator circuits are the same as the tags of the first input line, and are obtained based on the execution result of the first operator circuit; the input tags of the input data from the obfuscator can be directly provided by the obfuscator; the input tags of the input data from the computing party can be obtained by the computing party from the obfuscator through an oblivious transfer protocol (such as GOT based on the ROT result).

[0062] It should be noted that before executing a certain gate circuit, the corresponding input tags need to be obtained first. And in the case where the gate circuits designed in an operator circuit are relatively complex, some input tags may also be obtained during the execution process of the operator circuit. In practice, all other input tags of the second operator circuit can be obtained first, and then the second operator circuit is executed, or the required other input tags can be obtained during the execution process of the second operator circuit.

[0063] And Figure 3 cooperatively Figure 4 shows a continuous execution process of a Boolean circuit based on a garbled circuit executed by an obfuscator. As Figure 4 shown, this process may include:

[0064] Step 401, synchronize with the computing party the selection result of the second garbled table corresponding to the second operator circuit;

[0065] Step 402, according to the second garbled table, determine the first conversion string for describing the conversion relationship between the alternative tags corresponding to the same candidate bit of the first output line and the first input line;

[0066] Step 403, provide the first conversion string to the computing party for the computing party to determine the first output tag of the first output line based on the first string, so as to execute the second operator circuit.

[0067] Among them, in one embodiment, the first conversion string is the string obtained by performing an exclusive OR operation between the alternative tags corresponding to the same candidate bit of the first output line and the first input line.

[0068] Reviewing the above process, in the business processing based on garbled circuits, for each operator circuit, multiple garbled tables are pre-generated in the offline preparation stage, and each garbled table is independent of each other. For operator circuits with a correlation relationship, the properties of Boolean circuits are cleverly utilized to determine the conversion relationship between the output label and the input label, so as to convert the output label of the previous circuit into the input label of the subsequent circuit, and without the computing party knowing the true value of the output bit, the output label and the input label before and after the conversion correspond to the same true value bit. In this way, for the business processing process involving multiple operator circuits, multiple garbled tables can be pre-generated for each type of operator circuit respectively, and can be flexibly combined during the business processing process, reducing redundant communication, thereby improving the business processing efficiency.

[0069] According to an embodiment of another aspect, there is also provided a Boolean circuit continuous execution device based on garbled circuits provided in a computing party. Figure 5 Fig. shows a Boolean circuit continuous execution device 500 based on garbled circuits according to an embodiment, which can be provided in a computing party. Assuming that the continuous Boolean circuit includes a first operator circuit and a second operator circuit, the first output line of the first operator circuit is the first input line of the second operator circuit, and the exclusive OR value between two alternative labels determined by the garbler for a single output line / single input line is a first random string held only locally.

[0070] As Figure 5 shown, the device 500 includes:

[0071] An execution unit 501, configured to execute the first operator circuit according to a first garbled table obtained in advance from the garbler, and obtain a first output label corresponding to the first output line, where the first output label is one of two alternative labels determined by the garbler for the first output line during the generation of the first garbled table;

[0072] A selection unit 502, configured to synchronize with the garbler the selection result of the second garbled table corresponding to the second operator circuit, so as to obtain a first conversion string provided by the garbler for the first output line and the first input line, where the first conversion string is used to describe the conversion relationship between the alternative labels corresponding to the first output line and the first input line for the same candidate bit;

[0073] A determination unit 503, configured to determine a first input label corresponding to the first input line according to the exclusive OR result of the first conversion string and the first output label;

[0074] The execution unit 501 is further configured to execute the second operator circuit based on the first input label and the second garbled table.

[0075] In an alternative implementation, the first operator circuit is of the first operator type, and the first confusion table is determined from multiple confusion tables generated by the obfuscator for the first operator type; the second operator circuit is of the second operator type, and the second confusion table is determined from multiple confusion tables generated by the obfuscator for the second operator type.

[0076] In an alternative implementation, the first confusion table and the second confusion table are selected or specified by one of the obfuscator and the computing party and informed to the other party, or determined through negotiation by both parties.

[0077] Corresponding to the apparatus 500, the present specification further provides a Boolean circuit continuous execution apparatus based on an obfuscation circuit provided in the obfuscator. Figure 6 The Boolean circuit continuous execution apparatus 600 shown in an embodiment can be provided in the obfuscator.

[0078] As Figure 6 shown, the apparatus 600 includes:

[0079] A selection unit 601 configured to synchronize with the computing party the selection result of the second confusion table corresponding to the second operator circuit;

[0080] A determination unit 602 configured to determine, according to the selection result of the second confusion table, a first conversion string for describing the conversion relationship between alternative tags corresponding to the first output line and the first input line corresponding to the same candidate bit;

[0081] A providing unit 603 configured to provide the first conversion string to the computing party for the computing party to determine the first output tag of the first output line based on the first string, so as to execute the second operator circuit.

[0082] It should be noted that Figure 5 、 Figure 6 The apparatuses 500 and 600 shown correspond to Figure 3 、 Figure 4 the methods described, Figure 3 、 Figure 4 the corresponding descriptions in the method embodiments of

[0083] also apply to the apparatuses 500 and 600, and will not be elaborated here.

[0083] According to an embodiment of another aspect, there is also provided a computer-readable storage medium having a computer program stored thereon, and when the computer program is executed in a computer, the computer is caused to execute the method described in connection with Figure 3 、 Figure 4 and so on.

[0084] According to an embodiment of still another aspect, there is also provided a computing device including a memory and a processor, where the memory stores executable code, and when the processor executes the executable code, the method described in connection with Figure 3 、Figure 4 The methods described by etc.

[0085] Those skilled in the art should be able to realize that in one or more of the above examples, the functions described in the embodiments of this specification can be implemented by hardware, software, firmware, or any combination thereof. When implemented using software, these functions can be stored in a computer-readable medium or transmitted as one or more instructions or codes on a computer-readable medium.

[0086] The specific embodiments described above further elaborate on the purpose, technical solutions, and beneficial effects of the technical concept of this specification. It should be understood that the above are only specific embodiments of the technical concept of this specification and are not used to limit the protection scope of the technical concept of this specification. Any modifications, equivalent replacements, improvements, etc. made on the basis of the technical solutions of the embodiments of this specification should be included within the protection scope of the technical concept of this specification.

Claims

1. A method for continuous execution of a Boolean circuit based on garbled circuits, the Boolean circuit comprising a first operator circuit and a second operator circuit, a first output line of the first operator circuit corresponding to a first input line of the second operator circuit, and an exclusive OR value between two alternative tags determined by the garbler for a single output line / single input line being a first random string held only locally; The method is executed by the computing party and includes: Executing a first operator circuit according to a first confusion table obtained in advance from the obfuscating party to obtain a first output tag corresponding to the first output wire, where the first output tag is one of two alternative tags for the first output wire based on the first confusion table; Synchronizing with the obfuscating party the selection result of a second confusion table corresponding to a second operator circuit to obtain a first conversion string provided by the obfuscating party for the first output wire and the first input wire, where the first conversion string is used to describe the conversion relationship between the alternative tags corresponding to the same candidate bit for the first output wire and the first input wire; Determining a first input tag corresponding to the first input wire according to the exclusive OR result of the first conversion string and the first output tag; Executing the second operator circuit based on the first input tag and the second confusion table.

2. The method according to claim 1, wherein, During the execution of the Boolean circuit, an input tag corresponding to the obfuscating party provided based on alternative tags of the corresponding input wire is obtained from the obfuscating party, and an input tag corresponding to the computing party is obtained from the obfuscating party via an oblivious transfer method.

3. The method according to claim 2, wherein, The computing party stores a selection data set obtained in advance from the obfuscating party via an oblivious transfer method. A single piece of selection data in the selection data set includes a single selection bit selected from two candidate bits and a single selection string corresponding to the single selection bit in the corresponding two reference strings. The computing party determines based on a single piece of selection data for a single input tag corresponding to a local single input bit.

4. The method according to claim 3, wherein, The input bit provided by the computing party includes a first bit, and the second input tag corresponding to the first bit is determined by the following method: Randomly selecting a first piece of selection data corresponding to a first selection bit and a first selection string from the selection data; Providing the first comparison result corresponding to the first bit and the first selection bit to the obfuscating party for the obfuscating party to provide two ciphertexts corresponding to the two candidate bits to the computing party according to the first comparison result. The two ciphertexts are obtained by encrypting the corresponding two alternative tags with the two reference strings corresponding to the first piece of selection data respectively; Decrypting the two ciphertexts with the first selection string to obtain the second input tag.

5. The method according to claim 4, wherein: When the first comparison result is the same, the obfuscating party encrypts the two alternative tags respectively with the two reference strings according to the corresponding candidate bits to obtain the two ciphertexts; When the first comparison result is different, the obfuscating party encrypts the two alternative tags crosswise with the two reference strings according to the candidate bits to obtain the two ciphertexts.

6. The method according to claim 1, wherein, The first operator circuit is of a first operator type, and the first confusion table is determined from multiple confusion tables generated by the obfuscating party for the first operator type; the second operator circuit is of a second operator type, and the second confusion table is determined from multiple confusion tables generated by the obfuscating party for the second operator type.

7. The method according to claim 1 or 6, wherein, The first confusion table and the second confusion table are selected or specified by one of the obfuscating party and the computing party and informed to the other party, or determined through negotiation by both parties.

8. A method for continuous execution of a Boolean circuit based on garbled circuits, the Boolean circuit comprising a first operator circuit and a second operator circuit, a first output line of the first operator circuit corresponding to a first input line of the second operator circuit, and an exclusive OR value between two alternative tags determined by the garbler for a single output line / single input line being a first random string held only locally; The method is executed by the obfuscating party and includes: Synchronize with the computing party on the selection result of the second confusion table corresponding to the second operator circuit; Determine a first conversion string for describing the conversion relationship between the alternative labels corresponding to the same candidate bits of the first output line and the first input line according to the selection result of the second confusion table; Provide the first conversion string to the computing party for the computing party to determine the first output label of the first output line based on the first conversion string, so as to execute the second operator circuit.

9. The method according to claim 8, wherein the first conversion string is a string obtained by performing an exclusive OR operation between alternative tags of the first output line and the first input line corresponding to the same candidate bit.

10. A continuous execution device for a Boolean circuit based on garbled circuits, the Boolean circuit including a first operator circuit and a second operator circuit, a first output line of the first operator circuit corresponding to a first input line of the second operator circuit, and an exclusive OR value between two alternative tags determined by the garbler for a single output line / single input line being a first random string held only locally; The device is provided in the computing party and includes: An execution unit configured to execute a first operator circuit according to a first confusion table pre-obtained from the confusion party to obtain a first output label corresponding to the first output line, where the first output label is one of two alternative labels determined by the confusion party for the first output line during the generation of the first confusion table; A selection unit configured to synchronize with the confusion party on the selection result of the second confusion table corresponding to the second operator circuit to obtain a first conversion string provided by the confusion party for the first output line and the first input line, where the first conversion string is used to describe the conversion relationship between the alternative labels corresponding to the same candidate bits of the first output line and the first input line; A determination unit configured to determine a first input label corresponding to the first input line according to the exclusive-or result of the first conversion string and the first output label; The execution unit is further configured to execute the second operator circuit based on the first input label and the second confusion table.

11. The device according to claim 10, wherein, The first operator circuit is of a first operator type, and the first confusion table is determined from multiple confusion tables generated by the confusion party for the first operator type; the second operator circuit is of a second operator type, and the second confusion table is determined from multiple confusion tables generated by the confusion party for the second operator type.

12. The device according to claim 10 or 11, wherein, The first confusion table and the second confusion table are selected or specified by one of the confusion party and the computing party and notified to the other party, or determined through negotiation by both parties.

13. A continuous execution device for a Boolean circuit based on garbled circuits, the Boolean circuit including a first operator circuit and a second operator circuit, a first output line of the first operator circuit corresponding to a first input line of the second operator circuit, and an exclusive OR value between two alternative tags determined by the garbler for a single output line / single input line being a first random string held only locally; The device is provided in the confusion party and includes: A selection unit configured to synchronize with the computing party on the selection result of the second confusion table corresponding to the second operator circuit; A determination unit configured to determine a first conversion string for describing the conversion relationship between the alternative labels corresponding to the same candidate bits of the first output line and the first input line according to the selection result of the second confusion table; A providing unit configured to provide the first conversion string to the computing party for the computing party to determine the first output label of the first output line based on the first conversion string, so as to execute the second operator circuit.

14. A computer-readable storage medium having stored thereon a computer program which, when executed on a computer, causes the computer to execute the method according to any one of claims 1-9.

15. A computing device, comprising a memory and a processor, characterized in that, The memory stores executable code, and when the processor executes the executable code, the method described in any one of claims 1-9 is implemented.

Citation Information

Patent Citations

  • Confusion circuit generation method and device, prediction result determination method and device and electronic equipment

    CN111125727A

  • Multi-party joint neural network training method and apparatus for achieving security defense

    WO2021082633A1