Methods, devices, and systems for multi-party secure computing
By randomly generating bit strings and encryption and decryption operations in multi-party security calculations, the problem of additional computing in the prior art is solved, and efficient multi-party security calculations are achieved.
Patent Information
- Application Number
- CN202111537805.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-15
- Publication Date
- 2025-06-27
- Estimated Expiration
- 2041-12-15
AI Technical Summary
In the prior art, in multi-party security calculation, in order to convert the calculation results of the obfuscated circuit into a secret sharing shard, additional operations need to be introduced into the obfuscated circuit, resulting in a reduced calculation efficiency.
The first bit string is randomly generated by the first party as the first party shard of the obfuscating circuit output line, and two second bit strings are determined based on the bit string. Then, the second bit string is encrypted using the obfuscation string marked in the obfuscation circuit and provided to the second party for decryption, thereby obtaining the respective shards and achieving privacy protection of the calculation results.
There is no need to introduce additional operations into the obfuscated circuit, and the calculation results of the obfuscated circuit are directly converted into secret sharing shards, which significantly improves the efficiency of multi-party security calculations.
Smart Images

Figure CN114239090B_ABST
Abstract
Description
Technical Field
[0001] One or more embodiments of this specification relate to the field of security technology, and in particular, to a method, apparatus, and system for secure multi-party computation. Background Art
[0002] Secure Multi-Party Computation (MPC), also known as secure multi-party computation, means that multiple parties jointly calculate the result of a function without revealing the input data of each party to this function, and the calculation result is disclosed to one or more of them.
[0003] Both garbled circuits and secret sharing can achieve secure multi-party computation. Each has its own advantages and disadvantages and can be used in combination. For example, first perform a first secure operation based on a garbled circuit, and then perform a second secure operation based on secret sharing on the calculation result. It should be noted that in order to achieve data privacy protection, the above calculation result cannot be exposed to any party, which requires converting the calculation result of the garbled circuit into secret sharing shards.
[0004] In traditional technologies, in order to achieve the above conversion, additional operations such as subtraction usually need to be introduced into the garbled circuit, which greatly affects the efficiency of secure multi-party computation. Summary of the Invention
[0005] One or more embodiments of this specification describe a method, apparatus, and system for secure multi-party computation, which can improve the efficiency of secure multi-party computation.
[0006] In a first aspect, a method for secure multi-party computation is provided, including:
[0007] For any i-th output line among the n output lines of the garbled circuit, the first party randomly generates a first bit string as the first-party shard corresponding to the i-th output line, where the actual true values of the n output lines constitute n bits of the calculation result of the garbled circuit;
[0008] The first party determines two second bit strings based on the first bit string, and the two second bit strings respectively correspond to the two true values of the i-th output line;
[0009] The first party encrypts the two second bit strings respectively by using two garbled strings labeled with the two true values of the i-th output line in the garbled circuit, and provides the two encryption results to the second party;
[0010] The second party uses the actual confusion string corresponding to the actual true value of the i-th output line to decrypt the two encrypted results, and obtains the second-party shard corresponding to the i-th output line; wherein, the actual confusion string is obtained by jointly executing the confusion circuit with the first party;
[0011] The first party and the second party respectively determine the shards of the computing result on their own sides based on the shards on their own sides corresponding to each output line among the n output lines.
[0012] On the second hand, a method for multi-party secure computation is provided, including:
[0013] For any i-th output line among the n output lines of the confusion circuit, a first bit string is randomly generated as the first-party shard corresponding to the i-th output line, where the actual true values of the n output lines constitute n bits of the computing result of the confusion circuit;
[0014] Based on the first bit string, two second bit strings are determined, and the two second bit strings respectively correspond to the two true values of the i-th output line;
[0015] Using the two confusion strings respectively labeled with the two true values of the i-th output line in the confusion circuit, the two second bit strings are encrypted correspondingly, and the two encrypted results are provided to the second party for the second party to obtain the second-party shard corresponding to the i-th output line by decrypting the two encrypted results, and further determine the second-party shard of the computing result;
[0016] Based on the first-party shards corresponding to each output line among the n output lines, the first-party shard of the computing result is determined.
[0017] On the third hand, a system for multi-party secure computation is provided, including:
[0018] A first party, configured to, for any i-th output line among the n output lines of the confusion circuit, randomly generate a first bit string as the first-party shard corresponding to the i-th output line, where the actual true values of the n output lines constitute n bits of the computing result of the confusion circuit;
[0019] The first party is further configured to, based on the first bit string, determine two second bit strings, and the two second bit strings respectively correspond to the two true values of the i-th output line;
[0020] The first party is further configured to use the two confusion strings respectively labeled with the two true values of the i-th output line in the confusion circuit to encrypt the two second bit strings correspondingly, and provide the two encrypted results to the second party;
[0021] The second party is configured to use the actual obfuscation string corresponding to the actual true value of the i-th output line to decrypt the two encrypted results, and obtain the second-party shard corresponding to the i-th output line; wherein, the actual obfuscation string is obtained by jointly executing the obfuscation circuit with the first party;
[0022] The first party and the second party are further configured to respectively determine the local shards of the calculation result based on the local shards corresponding to each output line among the n output lines.
[0023] In a fourth aspect, a device for multi-party secure computation is provided, including:
[0024] A generating unit is configured to randomly generate a first bit string as the first-party shard corresponding to an arbitrary i-th output line among the n output lines of the obfuscation circuit, where the actual true values of the n output lines constitute n bits of the calculation result of the obfuscation circuit;
[0025] A determining unit is configured to determine two second bit strings based on the first bit string, and the two second bit strings respectively correspond to the two true values of the i-th output line;
[0026] An encrypting unit is configured to respectively encrypt the two second bit strings by using two obfuscation strings respectively labeled for the two true values of the i-th output line in the obfuscation circuit, and provide the two encrypted results to the second party for the second party to obtain the second-party shard corresponding to the i-th output line by decrypting the two encrypted results, and further determine the second-party shard of the calculation result;
[0027] The determining unit is further configured to determine the first-party shard of the calculation result based on the first-party shards corresponding to each output line among the n output lines.
[0028] In a fifth aspect, a computer storage medium is provided, on which a computer program is stored. When the computer program is executed on a computer, the computer is made to execute the method of the first aspect or the second aspect.
[0029] In a sixth aspect, a computing device is provided, including a memory and a processor. An executable code is stored in the memory, and when the processor executes the executable code, the method of the first aspect or the second aspect is implemented.
[0030] The method, device, and system for multi-party secure computation provided by one or more embodiments of this specification. For each output wire of the garbled circuit, the first party randomly generates a first bit string as the corresponding first-party shard. Subsequently, the first party also determines, for each output wire, two second bit strings corresponding to the two true values of each output wire, encrypts them, and provides them to the second party. As a result, the second party decrypts the two encrypted results to obtain the second-party shards corresponding to each output wire. Finally, the first party and the second party respectively determine the shards of the calculation result of the garbled circuit based on their respective shards corresponding to each output wire. It can be seen that in the embodiments of this specification, without introducing additional operations in the garbled circuit, it is possible to convert the calculation result of the garbled circuit into secret-sharing shards, thereby greatly improving the efficiency of multi-party secure computation. BRIEF DESCRIPTION OF THE DRAWINGS
[0031] To more clearly illustrate the technical solutions of the embodiments of this specification, the accompanying drawings required for the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings in the following description are only some embodiments of this specification. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0032] Figure 1 Shows a schematic diagram of a gate circuit according to an embodiment;
[0033] Figure 2 Is a schematic diagram of an implementation scenario disclosed in an embodiment of this specification;
[0034] Figure 3 Shows an interaction diagram of the method for multi-party secure computation according to an embodiment;
[0035] Figure 4 Shows a schematic diagram of the system for multi-party secure computation according to an embodiment;
[0036] Figure 5 Shows a schematic diagram of the device for multi-party secure computation according to an embodiment. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0037] The solutions provided by this specification will be described below with reference to the accompanying drawings.
[0038] Before describing the solutions provided by the embodiments of this specification, the following explanations will be made on two multi-party secure computation methods: garbled circuits and secret sharing.
[0039] Secret sharing, also known as secret splitting or secret sharing, is a cryptographic technique originally used for the management of secret information. Its basic principle is to split a secret into multiple shares and distribute them to different people for safekeeping. Only when more than the threshold number of people combine their shares can the secret be recovered, and fewer than the threshold number of people cannot recover any information about the secret. In multi-party secure computation, the threshold number is usually the same as the number of participants.
[0040] When secret sharing is used in multi-party secure computation, the share conversion technique is adopted. First, the input data of each party is split into shares and exchanged with each other. Then each party performs a conversion operation on multiple local shares respectively to obtain a new share for each. Finally, all parties combine all the new shares to obtain the operation result.
[0041] It should be noted that multi-party secure computation based on secret sharing can include secure multiplication and addition / subtraction, but does not support other operations.
[0042] Garbled Circuit (GC) realizes multi-party secure computation by using a computer to simulate an Application-Specific Integrated Circuit (ASIC). Any given computational task can be implemented using an ASIC designed for it, that is, multiple logic gates (AND gates, XOR gates, etc.) are connected according to the operation logic to form a gate circuit, and the gate circuit is used for computation. For example, the operation s = a AND b AND d can be computed using the gate circuit shown as Figure 1 shown.
[0043] Figure 1 In, this circuit consists of 2 AND gates. The input wires of AND gate 1 are a and b, and the output wire is c. The input wires of AND gate 2 are c and d, and the output wire is s. The garbled circuit represents the computational task as a gate circuit and encrypts (also known as labeling) each wire of the gate. The encrypted gate circuit is called a garbled circuit. Finally, multi-party secure computation is achieved by using a computer to execute the operations of the garbled circuit.
[0044] Specifically, multi-party secure computation based on garbled circuits mainly includes two stages: garbled table generation and operation. One of the two parties participating in multi-party secure computation serves as the garbled circuit generator (hereinafter referred to as the circuit generator), and generates the garbled circuit in the garbled table generation stage; the other party serves as the garbled circuit executor (hereinafter referred to as the circuit executor), and executes the garbled circuit in the operation stage.
[0045] The process of the circuit generator generating the garbled table will be described first below.
[0046] The operation logic of each operation gate can be represented and executed using a truth table. For example, Figure 1 the truth table of AND gate 1 in Figure 1 can be as shown in Table 1.
[0047] Table 1
[0048] a b c 0 0 0 0 1 0 1 0 0 1 1 1
[0049] The truth table of an operation gate shows the corresponding truth values of the output line (e.g., c) when the two input lines of the gate (e.g., a and b) take any values. Each row of the truth table corresponds to a combination of input values of the two input lines.
[0050] In order to hide the actual truth values of each line during the operation of the circuit, the truth values 0 and 1 of each line are respectively labeled with two random bit strings (hereinafter referred to as obfuscation strings), and the obfuscation strings labeled for each line are different. In one example, after labeling each line in Figure 1 the truth table shown in Table 1 can be as follows. In Table 2, X with different subscripts represents different obfuscation strings.
[0051] Table 2
[0052] a b c <![CDATA[X0 a > <![CDATA[X0 b > <![CDATA[X0 c > <![CDATA[X0 a > <![CDATA[X1 b > <![CDATA[X0 c > <![CDATA[X1 a > <![CDATA[X0 b > <![CDATA[X0 c > <![CDATA[X1 a > <![CDATA[X1 b > <![CDATA[X1 c >
[0053] Next, for each row of the above table, using the obfuscation strings of the two input lines as keys, the obfuscation string of the output line is encrypted, and the obfuscation table shown in Table 3 is obtained.
[0054] Table 3
[0055]
[0056]
[0057] Finally, after shuffling the order of each row, the obfuscation table of AND gate 1 is ready.
[0058] It can be obtained from Table 3 that if an obfuscation string of input line a and an obfuscation string of input line b are obtained, only one row can be decrypted to obtain an obfuscation string of output line c. During this process, the original truth values cannot be obtained from the obfuscation strings.
[0059] After the obfuscation table is ready, the circuit generator sends the obfuscation tables of all gates to the circuit executor.
[0060] The above is the description of the obfuscation table generation process. The following will further describe the operation process of the circuit executor.
[0061] First, the circuit executor obtains the actual obfuscation strings of the actual truth values of each initial input line of the gate circuit. Here, the initial input lines refer to each input line corresponding to the input data of both parties, such as, Figure 1 a, b, and d in
[0062] Specifically, for each input wire corresponding to the input data of the circuit generator, the circuit generator sends the actual obfuscated string of the actual true value of each input wire to the circuit executor.
[0063] For each input wire corresponding to the input data of the circuit executor, the two parties execute a 1-out-of-2 OT protocol once. During the execution of this protocol, the circuit generator acts as the OT protocol sender and prepares the obfuscated string of true value 0 and the obfuscated string of true value 1 as the two inputs of the OT protocol. The circuit executor acts as the OT protocol receiver and uses its possessed actual true value as the OT option. The execution result of the OT protocol is that the circuit executor obtains the actual obfuscated string of its possessed actual true value.
[0064] Secondly, the circuit executor decrypts a row in the obfuscation table of each gate of the circuit according to the actual obfuscated string of the actual true value of the initial input wire it obtains, and obtains an obfuscated string of the output wire. For example, obtain Figure 1 an obfuscated string of the output wire s in
[0065] For example, in the example shown in Figure 1 it is possible to first use the obfuscated strings of input wires a and b to decrypt a row of the obfuscation table of AND gate 1 to obtain an obfuscated string of input wire c. Then use the obfuscated strings of input wires c and d to decrypt a row of the obfuscation table of AND gate 2 to obtain an obfuscated string of s.
[0066] Finally, the circuit executor sends the obfuscated string of the output wire of the circuit to the circuit generator, and the circuit generator translates the obfuscated string back to the corresponding true value, which is the operation result.
[0067] Generally, multi-party secure computation based on obfuscated circuits can be for any computation, but the communication volume is very large.
[0068] Since obfuscated circuits and secret sharing each have their own advantages and disadvantages, they can be combined and used. The currently most popular combination method is the ABY multi-party secure computation framework, and the following will explain this combination method with examples.
[0069] Suppose the first party and the second party need to securely compute C = g(f(A, B)), where the operation of the function f() is implemented based on obfuscated circuits, and the operation of the function g() is implemented based on secret sharing. And the first party is the circuit generator, and A is the input data of the first party; the second party is the circuit executor, and B is the input data of the second party.
[0070] Let D = f(A, B). It should be understood that for privacy protection, D cannot be exposed to any party. Therefore, the prior art uses garbled circuits to securely compute D2 = f1(A, B, D1). Among them, f1(A, B, D1) = f(A, B) - D1, where D1 is randomly generated by the first party as the first-party shard of D. The securely computed result of f1 is the second-party shard D2 of D, which is obtained by the second party. After that, the two parties use the secret sharing technology to securely compute the function g1(D1, D2) = g1(D1 + D2).
[0071] It can be seen from this that when the prior art combines the use of garbled circuits and secret sharing, additional computations need to be introduced, such as f(A, B) - D1, to convert the computed result of the garbled circuit into secret sharing shards. However, the performance of the garbled circuit for implementing subtraction operations is usually poor because a subtraction requires t AND gates, where t is the number of bits of the secret sharing shard, which will affect the computational efficiency of multi-party secure computation.
[0072] For this reason, the inventors of the present application propose a more efficient secure computing scheme, which can convert the computed result of the garbled circuit into secret sharing shards without introducing additional operations in the garbled circuit. The following is a detailed description.
[0073] Figure 2 It is a schematic diagram of the implementation scenario disclosed in an embodiment of this specification. Figure 2 In this, the first party and the second party can be implemented as any device, platform, server, or cluster of devices with computing and processing capabilities.
[0074] Specifically, for each output line of the garbled circuit, the first party randomly generates corresponding first bit strings: D[0]1, D[1]1,..., D[n - 1]1 as the corresponding first-party shards. After that, the first party also determines, for each output line, two second bit strings {0 - D[0]1, 1 - D[0]1}, {0 - D[1]1, 1 - D[1]1},..., {0 - D[n - 1]1, 1 - D[n - 1]1} corresponding to the two truth values 0 and 1 of each output line, and encrypts them and provides them to the second party. Thus, the second party decrypts the two encrypted results to obtain the corresponding second-party shards of each output line: D[0]2, D[1]2,..., D[n - 1]2. Finally, the first party and the second party respectively determine the shards D1 and D2 of the computed result of the garbled circuit based on the shards of their own parties corresponding to each output line.
[0075] After the first party and the second party respectively determine their own shards D1 and D2, the first party and the second party can jointly perform the target operation based on secret sharing on the shards D1 and D2 determined by themselves. The target operation here can include multiplication, addition, subtraction, etc.
[0076] It should be noted that during the above-mentioned secure calculation process, the first party can only calculate and obtain the first-party shard D1 of the calculation result, and the second party can only calculate and obtain the second-party shard D2 of the calculation result. Neither party can know the calculation result D, thus realizing the privacy protection of the calculation result.
[0077] Figure 3 Shows a method interaction diagram of multi-party secure calculation according to an embodiment. As Figure 3 shown, the method may at least include the following steps.
[0078] Step 302, for any i-th output line among the n output lines of the garbled circuit, the first party randomly generates a first bit string as the first-party shard corresponding to the i-th output line.
[0079] Among them, the actual true values of the n output lines constitute n bits of the garbled circuit calculation result.
[0080] The above-mentioned garbled circuit can be generated by the first party, and it can be used for any secure calculation of the first data of the first party and the second data of the second party, such as secure multiplication, secure comparison, and secure addition and subtraction, etc.
[0081] In one example, the above-mentioned first bit string may include t bits, where t ≥ n.
[0082] Step 304, the first party determines two second bit strings based on the first bit string, and the two second bit strings respectively correspond to the two true values of the i-th output line.
[0083] As mentioned above, the two true values of the i-th output line may include true value 0 and true value 1. The above determination of the two second bit strings may specifically include: taking the difference between true value 0 and the first bit string as one of the two second bit strings. Taking the difference between true value 1 and the first bit string as the other second bit string.
[0084] For example, assume t = 4, and the first bit string is D[i]1 = 0110. Then one of the above second bit strings is: 0 - D[i]1 = 0 - 0110 = 1010. The other second bit string is: 0 - D[i]1 = 1 - 0110 = 1011.
[0085] Step 306, the first party encrypts the two second bit strings corresponding to the two true values respectively marked for the i-th output line in the garbled circuit, and provides the two encryption results to the second party.
[0086] In one example, the above two garbled strings can be represented as L[i] 0 and L[i] 1, the number of bits included in each of the two obfuscation strings is determined based on the size of the security parameter. For example, if the size of the security parameter is 128 bits, then the number of bits included in the obfuscation string is 128.
[0087] The above-mentioned corresponding encryption of the two second bit strings may include: encrypting one of the second bit strings by using the first obfuscation string labeled with the true value 0 for the i-th output wire, and encrypting the other second bit string by using the second obfuscation string labeled with the true value 1 for the i-th output wire.
[0088] In one example, the first obfuscation string can be truncated to a predetermined length and then XORed with one of the second bit strings, and the result of the XOR operation is used as the encryption result of the one second bit string. The encryption method for the other second bit string is similar.
[0089] In another example, the first obfuscation string can also be hashed, and then the obtained hash value is XORed with one of the second bit strings, and the result of the XOR operation is used as the encryption result of the one second bit string. The encryption method for the other second bit string is similar.
[0090] In addition, during the process of encrypting the two second bit strings, all the bits of each of the two second bit strings can be encrypted, or only some of the bits of each of the two second bit strings can be encrypted. For example, only the t - i bits starting from the least significant bit of each of the two second bit strings are encrypted. Where 0 ≤ i ≤ n - 1.
[0091] It should be understood that when only the t - i bits starting from the least significant bit of each of the two second bit strings are encrypted, then the encrypted t - i bits of each of the two second bit strings can be used as the two encryption results mentioned above.
[0092] Finally, after obtaining the two encryption results, the first party can also shuffle the order of the two encryption results and then provide the shuffled two encryption results to the second party.
[0093] Step 308, the second party decrypts the two encryption results by using the actual obfuscation string corresponding to the actual true value of the i-th output wire to obtain the second party's shard corresponding to the i-th output wire.
[0094] Among them, the above-mentioned actual obfuscation string can be obtained by the second party through jointly executing an obfuscation circuit with the first party. Among them, the steps of the second party and the first party jointly executing the obfuscation circuit can be executed simultaneously with steps 302 - 306, or can be executed before step 302, and this specification does not make a limitation on this.
[0095] The joint execution of the garbled circuit by the second party and the first party may specifically include: The first party labels each wire (including input wires and output wires) in the garbled circuit, and then for each gate (such as an AND gate) that needs to generate a garbled table, first generates the corresponding truth table, then replaces the truth values in the truth table with the garbled strings of each wire, and obtains the corresponding garbled table after two symmetric encryptions and scrambling. After that, the first party can send each garbled table to the second party.
[0096] The second party first obtains the actual garbled strings of the actual truth values of the initial input wires (each input wire corresponding to the input data of both parties), and then uses a row in the garbled table of each gate of its decryption circuit to obtain the actual garbled strings corresponding to the actual truth values of each output wire.
[0097] In one example, the second party can first select one of the two encrypted results according to the actual garbled string, and then use the actual garbled string to decrypt the selected encrypted result to obtain the second-party shard corresponding to the i-th output wire.
[0098] In another example, the second party decrypts both encrypted results, and then combines a predetermined rule, such as whether the format of the decryption result conforms to a predetermined specification, to select one of the decryption results as the second-party shard corresponding to the i-th output wire.
[0099] The following combines the above another example to illustrate the decryption process of the second party as follows:
[0100] If the above two encrypted results are obtained by truncating two garbled strings to a predetermined length and then performing an exclusive OR operation with two second bit strings, then the second party can decrypt by truncating the actual garbled string to a predetermined length and then performing an exclusive OR operation with the two encrypted results. And if the above two encrypted results are obtained by first performing a hash operation on two garbled strings and then performing an exclusive OR operation on the two obtained hash values with two second bit strings, then the second party can first perform a hash operation on the actual garbled string and then perform an exclusive OR operation on the obtained hash value with the two encrypted results for decryption.
[0101] It should be understood that since the actual garbled string obtained by the second party is one of the two garbled strings respectively labeled by the first party for the two truth values of the i-th output wire, the second party can only decrypt one of the encrypted results.
[0102] In addition, it should also be noted that if all bits of each of the two second bit strings are encrypted in step 306, then the second-party shard decrypted by the second party includes t bits. The following combines the foregoing example for illustration.
[0103] If the actual confusion string obtained by the second party corresponds to the true value 0, the second-party shard decrypted by the second party is D[i]2 = 1010, and if the actual confusion string obtained by the second party corresponds to the true value 1, the second-party shard decrypted by the second party is D[i]2 = 1011, and both of them include t bits.
[0104] If only the t - i bits starting from the least significant bit of each of the two second-bit strings are encrypted in step 306, then the second-party shard decrypted by the second party includes t - i bits. The following is an illustration in combination with the foregoing example.
[0105] If the actual confusion string obtained by the second party corresponds to the true value 0 and i is equal to 1, the second-party shard decrypted by the second party is D[i]2 = 010; and if the actual confusion string obtained by the second party corresponds to the true value 1 and i is equal to 1, the second-party shard decrypted by the second party is D[i]2 = 011, and both of them include 4 - 1 = 3 bits.
[0106] So far, the first party has obtained the first-party shard corresponding to the i-th output line among the n output lines, and the second party has obtained the second-party shard corresponding to the i-th output line among the n output lines. Similarly, the first party and the second party can each obtain their own shards of other output lines respectively.
[0107] Step 310, the first party and the second party respectively determine their own shards of the calculation result based on their own shards corresponding to each output line among the n output lines.
[0108] It should be understood that in practical applications, the step for the first party to determine its own shard of the calculation result can be executed at any time after step 302.
[0109] Specifically, the first party determining its own shard of the calculation result may include: for the i-th output line, the first party calculates the product of 2 to the power of i and the corresponding first-party shard to obtain the i-th first product. Where 0 ≤ i ≤ n - 1. Based on the n first products calculated for the n output lines, the first-party shard of the calculation result is determined.
[0110] The second party determining its own shard of the calculation result may include: for the i-th output line, the second party calculates the product of 2 to the power of i and the corresponding second-party shard to obtain the i-th second product. Based on the n second products calculated for the n output lines, the second-party shard of the calculation result is determined.
[0111] In one example, if all bits of each of the two second bit strings are encrypted, or in other words, the second-party shard obtained by the second party through decryption includes t bits, then the first-party shard for determining the calculation result specifically may include: summing n first products and using the summation result as the first-party shard of the calculation result. And the second-party shard for determining the calculation result by the second party may include: summing n second products and using the summation result as the second-party shard of the calculation result.
[0112] Of course, in practical applications, the above summation result can also be modulo 2 t and the modulo result is used as the first-party shard or the second-party shard.
[0113] In one example, the first-party shard of the calculation result can be determined according to the following formula:
[0114]
[0115] where D1 is the first-party shard of the calculation result, n is the number of output lines of the garbled circuit, and D[i]1 is the first-party shard of the i-th output line.
[0116] And, the second-party shard of the calculation result is determined according to the following formula:
[0117]
[0118] D2 is the first-party shard of the calculation result, n is the number of output lines of the garbled circuit, and D[i]2 is the second-party shard of the i-th output line.
[0119] In another example, if the t - i bits starting from the least significant bit of each of the two second bit strings are encrypted, or in other words, the second-party shard obtained by the second party through decryption includes t - i bits, then the first-party shard for determining the calculation result specifically may include: summing n first products and using the modulo result of the summation result modulo 2 to the power of t as the first-party shard of the calculation result. And the second-party shard for determining the calculation result by the second party may include: summing n second products and using the modulo result of the summation result modulo 2 to the power of t as the second-party shard of the calculation result.
[0120] Of course, in practical applications, it is also possible to first modulo each first product or second product by 2 to the power of t, then sum the modulo results, and then modulo the summation result by 2 to the power of t again to obtain the first-party shard or the second-party shard.
[0121] It should be noted that in step 306 of the embodiments of this specification, the reason why the partial bits of the two second bit strings can be encrypted is that when determining the first-party shard and the second-party shard of the calculation result, the first-party shard or the second-party shard of each output line is multiplied by 2 to the power of i, and a modulo operation is performed on the product or the final summation result.
[0122] As is well known to those skilled in the art, multiplying a binary bit string by 2 to the power of i is equivalent to performing a left shift of i bits on the binary bit string. Taking the modulo of the left-shifted binary string by 2 to the power of t is equivalent to removing the i bits starting from the highest bit. That is, only the t - i bits starting from the lowest bit actually participate in the summation operation. Therefore, the first party can only encrypt the t - i bits starting from the lowest bit of each of the two second bit strings, so that the second party only obtains the t - i bits starting from the lowest bit of one of the second bit strings as the corresponding second-party shard.
[0123] The correctness of this solution will be described below with examples.
[0124] First, take the example of encrypting all bits. Assume n = 3, t = 4, then i = 0, 1, 2; also assume that the calculation result is 7, and the corresponding binary number is: 111, that is, D[0]=1, D[1]=1, D[2]=1, and D[0]1 = r1, D[1]1 = r2, D[2]1 = r3. Then D[0]2 = 1 - r1, D[1]2 = 1 - r2, D[2]2 = 1 - r3; where r1, r2, and r3 can be represented in any base.
[0125] Then, according to formula 1, D1 = 2 0 ·r1 + 2 1 ·r2 + 2 2 ·r3
[0126] = r1 + 2r2 + 4r3;
[0127] And according to formula 2, D2 = 2 0 ·(1 - r1)+2 1 ·(1 - r2)+2 2 ·(1 - r3)
[0128] = 1 - r1 + 2 - 2r2 + 4 - 4r3;
[0129] Finally, D1 + D2 = 1 + 2 + 4 = 7.
[0130] Taking the example of encrypting the lowest t - i bits starting from the least significant bit, assume n = 3, t = 4, then t = 0, 1, 2; also assume the calculation result is 7, and the corresponding binary number is: 111, that is, D[0]=1, D[1]=1, D[2]=1, and D[0]1 = 0110, D[1]1 = 1011, D[2]1 = 1100. Then D[0]2 = 1011 (including 4 - 0 = 4 bits), D[1]2 = 110 (including 4 - 1 = 3 bits), D[2]2 = 01 (including 4 - 2 = 2 bits). Among them, the original D[0]2, D[1]2, and D[2]2 are: 1011, 0110, and 0101 respectively.
[0131] Thus, D1=(2 0 ·(0110)+2 1 ·(1011)+2 2 ·(1100)) % 10000
[0132] =(00110 + 10110 + 110000) % 10000
[0133] =1100
[0134] D2=(2 0 ·(1011)+2 1 ·(110)+2 2 ·(01)) % 10000
[0135] =(1011 + 1100 + 0100) % 10000
[0136] =1011
[0137] Finally, D1 + D2=(01100 + 1011) % 10000 = 7.
[0138] It should be understood that the above is only an exemplary illustration. In practical applications, it is also possible to first take the modulus of each product and then take the modulus of the summation result. This specification does not make a limitation on this. For example:
[0139] D1=(2 0 ·(0110)+2 1 ·(1011)+2 2 ·(1100)) % 10000
[0140] =(00110 % 10000 + 10110 % 10000 + 110000 % 10000) % 10000
[0141] =(0110 + 0110 + 0000) % 10000
[0142] =1100
[0143] It should be noted that when determining D1 and D2 above according to modulo operation, the sum result D1 + D2 should also be modulo 2 to the power of t.
[0144] It should be understood that the above is only an exemplary illustration. In practical applications, the value range of n can be [1, 128], the value range of t can be [8, 128], and t ≥ n is always satisfied.
[0145] In summary, the multi-party secure computing method provided in the embodiments of this specification can convert the calculation result of the garbled circuit into secret sharing shards without introducing additional operations in the garbled circuit, thereby greatly improving the multi-party secure computing efficiency. In addition, in the process of providing two second bit strings to the second party, the method of only encrypting some bits can further ensure data security.
[0146] Corresponding to the above multi-party secure computing method, an embodiment of this specification also provides a multi-party secure computing system, as Figure 4 shown, the system may include:
[0147] A first party 402, configured to randomly generate a first bit string as the first party shard corresponding to the i-th output line among any n output lines of the garbled circuit, where the actual true values of the n output lines constitute n bits of the garbled circuit calculation result.
[0148] The first party 402 is further configured to determine two second bit strings based on the first bit string, and the two second bit strings respectively correspond to the two true values of the i-th output line.
[0149] Among them, the two true values of the i-th output line include true value 0 and true value 1; specifically, the first party 402 is configured to:
[0150] Take the difference between the true value 0 and the first bit string as one of the two second bit strings;
[0151] Take the difference between the true value 1 and the first bit string as the other second bit string.
[0152] The first party 402 is further configured to use two garbled strings respectively labeled with the two true values of the i-th output line in the garbled circuit to encrypt the two second bit strings respectively, and provide the two encryption results to the second party 404.
[0153] Specifically, the first party 402 is configured to:
[0154] Use the first garbled string labeled with the true value 0 of the i-th output line to encrypt one second bit string;
[0155] Encrypt another second bit string using a second garbled string labeled with a true value of 1 for the i-th output wire.
[0156] The second party 404 is used to decrypt the two encrypted results using the actual garbled string corresponding to the actual true value of the i-th output wire to obtain the second party shard corresponding to the i-th output wire. The actual garbled string is obtained by jointly executing a garbled circuit with the first party 402.
[0157] The first party 402 and the second party 404 are also used to respectively determine the local shards of the calculation result based on the local shards corresponding to each output wire among the n output wires.
[0158] Specifically, the first party 402 is used for:
[0159] For the i-th output wire, calculate the product of 2 to the power of i and the corresponding first party shard to obtain the i-th first product. Based on the n first products calculated for the n output wires, determine the first party shard of the calculation result; where 0 ≤ i ≤ n - 1.
[0160] Specifically, the second party 404 is used for:
[0161] For the i-th output wire, calculate the product of 2 to the power of i and the corresponding second party shard to obtain the i-th second product. Based on the n second products calculated for the n output wires, determine the second party shard of the calculation result.
[0162] Among them, all bits of each of the above two second bit strings are encrypted;
[0163] Specifically, the first party 402 is also used for:
[0164] Sum the n first products and use the sum result as the first party shard of the calculation result.
[0165] Specifically, the second party 404 is also used for:
[0166] Sum the n second products and use the sum result as the second party shard of the calculation result.
[0167] Optionally, the second bit string includes t bits, and n ≤ t;
[0168] Specifically, the first party 402 is used for:
[0169] Use two garbled strings to respectively encrypt the t - i bits starting from the least significant bit of each of the two second bit strings;
[0170] Use the encrypted t - i bits of each of the two second bit strings as the two encrypted results.
[0171] Specifically, the first party 402 is also used for:
[0172] Sum the n first products, and use the result of taking the modulus of the sum with respect to 2 to the power of t as the first-party shard of the calculation result.
[0173] The second party 404 is further specifically configured to:
[0174] Sum the n second products, and use the result of taking the modulus of the sum with respect to 2 to the power of t as the second-party shard of the calculation result.
[0175] Optionally, the first party 402 is specifically configured to:
[0176] Provide the two encrypted results to the second party 404 after scrambling.
[0177] The second party 404 is specifically configured to:
[0178] Use the actual confusion string corresponding to the actual true value of the i-th output line to decrypt the two scrambled encrypted results.
[0179] Optionally, the first party 402 and the second party 404 are further configured to jointly perform a target operation based on secret sharing based on the respective local shards of the calculation results they determine.
[0180] The functions of the functional modules of the device in the above embodiments of this specification can be implemented by the steps in the above method embodiments. Therefore, the specific working process of the device provided in an embodiment of this specification will not be repeated here.
[0181] The multi-party secure computing system provided in an embodiment of this specification can greatly improve the efficiency of multi-party secure computing.
[0182] Corresponding to the above multi-party secure computing method, an embodiment of this specification also provides a multi-party secure computing device, as Figure 5 shown, the device may include:
[0183] A generating unit 502, configured to randomly generate a first bit string as the first-party shard corresponding to the i-th output line for any of the n output lines of the confusion circuit, where the actual true values of the n output lines constitute n bits of the calculation result of the confusion circuit.
[0184] A determining unit 504, configured to determine two second bit strings based on the first bit string, where the two second bit strings respectively correspond to the two true values of the i-th output line.
[0185] An encryption unit 506 is configured to respectively encrypt two second bit strings corresponding to two true values respectively labeled for the i-th output line in the garbled circuit, and provide the two encryption results to a second party, so that the second party can obtain the second-party shard corresponding to the i-th output line by decrypting the two encryption results, and further determine the second-party shard of the calculation result.
[0186] A determination unit 504 is further configured to determine the first-party shard of the calculation result based on the first-party shards corresponding to the respective output lines among the n output lines.
[0187] The functions of the functional modules of the device in the above embodiments of this specification can be implemented by the respective steps of the above method embodiments. Therefore, the specific working process of the device provided in an embodiment of this specification will not be repeated here.
[0188] The device for multi-party secure computing provided in an embodiment of this specification can greatly improve the efficiency of multi-party secure computing.
[0189] According to an embodiment of another aspect, there is also provided a computer-readable storage medium, on which a computer program is stored. When the computer program is executed on a computer, the computer is made to execute the method described in conjunction with Figure 3 what is described.
[0190] According to an embodiment of still another aspect, there is also provided a computing device, including a memory and a processor. An executable code is stored in the memory. When the processor executes the executable code, the method described in conjunction with Figure 3 what is described is implemented.
[0191] The various embodiments in this specification are all described in a progressive manner. The same or similar parts among the various embodiments can be referred to each other. Each embodiment focuses on the differences from other embodiments. In particular, for the device embodiments, since they are basically similar to the method embodiments, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiments.
[0192] The steps of the methods or algorithms described in connection with the disclosure of this specification may be implemented in hardware or by a processor executing software instructions. The software instructions may be composed of corresponding software modules, and the software modules may be stored in a RAM memory, flash memory, ROM memory, EPROM memory, EEPROM memory, register, hard disk, removable hard disk, CD-ROM, or any other form of storage medium well known in the art. An exemplary storage medium is coupled to the processor so that the processor can read information from the storage medium and write information to the storage medium. Of course, the storage medium may also be a component of the processor. The processor and the storage medium may be located in an ASIC. Additionally, the ASIC may be located in a server. Of course, the processor and the storage medium may also exist as discrete components in the server.
[0193] Those skilled in the art should be able to realize that in one or more of the above examples, the functions described in the present invention can be implemented by hardware, software, firmware, or any combination thereof. When implemented using software, these functions can be stored in a computer-readable medium or transmitted as one or more instructions or codes on a computer-readable medium. The computer-readable medium includes computer storage media and communication media, where the communication media includes any medium that facilitates the transfer of a computer program from one place to another. The storage medium can be any available medium accessible by a general-purpose or special-purpose computer.
[0194] The above describes specific embodiments of this specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in a different order than in the embodiments and still achieve the desired result. Additionally, the processes depicted in the figures do not necessarily require the specific order or sequential order shown to achieve the desired result. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0195] The specific embodiments described above further elaborate on the purpose, technical solutions, and beneficial effects of this specification. It should be understood that the above is only the specific embodiments of this specification and is not used to limit the protection scope of this specification. Any modifications, equivalent replacements, improvements, etc. made on the basis of the technical solutions of this specification should be included within the protection scope of this specification.
Claims
1. A method for multi-party secure computation, comprising: For any i-th output line among the n output lines of the garbled circuit, the first party randomly generates a first bit string as the first-party shard corresponding to the i-th output line, wherein the actual truth values of the n output lines constitute n bits of the calculation result of the garbled circuit; Based on the first bit string, the first party determines two second bit strings, and the two second bit strings respectively correspond to the two truth values of the i-th output line; The first party uses two garbled strings respectively labeled with the two truth values of the i-th output line in the garbled circuit to encrypt the two second bit strings correspondingly, and provides the two encryption results to the second party; The second party uses the actual garbled string corresponding to the actual truth value of the i-th output line to decrypt the two encryption results, and obtains the second-party shard corresponding to the i-th output line; wherein, the actual garbled string is obtained by jointly executing the garbled circuit with the first party; The first party and the second party respectively determine the shards of the calculation result of each party based on the shards of each party corresponding to each output line among the n output lines.
2. The method according to claim 1, wherein Determining the shards of the calculation result of each party includes: For the i-th output line, the first party calculates the product of 2 to the power of i and the corresponding first-party shard to obtain the i-th first product; based on the n first products calculated for the n output lines, determine the first-party shard of the calculation result; wherein, 0 ≤ i ≤ n - 1; For the i-th output line, the second party calculates the product of 2 to the power of i and the corresponding second-party shard to obtain the i-th second product; based on the n second products calculated for the n output lines, determine the second-party shard of the calculation result.
3. The method according to claim 2, wherein All bits of each of the two second bit strings are encrypted; Determining the first-party shard of the calculation result includes: Summing the n first products, and taking the sum result as the first-party shard of the calculation result; Determining the second-party shard of the calculation result includes: Summing the n second products, and taking the sum result as the second-party shard of the calculation result.
4. The method according to claim 2, wherein, The second bit string includes t bits, and n ≤ t; Correspondingly encrypting the two second bit strings includes: Using the two garbled strings to encrypt the t - i bits starting from the least significant bit of each of the two second bit strings correspondingly; Taking the encrypted t - i bits of each of the two second bit strings as the two encryption results.
5. The method according to claim 4, wherein Determining the first-party shard of the calculation result includes: Summing the n first products, and taking the modulo result of the sum result modulo 2 to the power of t as the first-party shard of the calculation result; Determining the second-party shard of the calculation result includes: Summing the n second products, and taking the modulo result of the sum result modulo 2 to the power of t as the second-party shard of the calculation result.
6. The method according to claim 1, wherein, The two truth values of the i-th output line include truth value 0 and truth value 1; Determining the two second bit strings includes: Take the difference between the true value 0 and the first bit string as one of the two second bit strings; Take the difference between the true value 1 and the first bit string as the other second bit string of the two second bit strings.
7. The method according to claim 6, wherein, The corresponding encryption of the two second bit strings includes: Encrypt the one second bit string by using the first confusion string labeled with the true value 0 for the i-th output line; Encrypt the other second bit string by using the second confusion string labeled with the true value 1 for the i-th output line.
8. The method according to claim 1, wherein The providing the two encryption results to the second party includes: Provide the two encryption results to the second party after scrambling; The decrypting the two encryption results includes: The second party decrypts the two scrambled encryption results by using the actual confusion string corresponding to the actual true value of the i-th output line.
9. The method according to claim 1, further comprising: The first party and the second party jointly perform the target operation based on secret sharing based on their respective local shards of the calculated result.
10. A method for multi-party secure computation, performed by a first party, includes: For any i-th output line among the n output lines of the confusion circuit, randomly generate a first bit string as the local shard of the first party corresponding to the i-th output line, where the actual true values of the n output lines constitute n bits of the calculation result of the confusion circuit; Based on the first bit string, determine two second bit strings, and the two second bit strings respectively correspond to the two true values of the i-th output line; Use the two confusion strings respectively labeled with the two true values of the i-th output line in the confusion circuit to correspondingly encrypt the two second bit strings, and provide the two encryption results to the second party for the second party to obtain the local shard of the second party corresponding to the i-th output line by decrypting the two encryption results, and further determine the local shard of the second party of the calculated result; Based on the local shards of the first party corresponding to each output line among the n output lines, determine the local shard of the first party of the calculated result.
11. A multi-party secure computation system includes: A first party, configured to, for any i-th output line among the n output lines of the confusion circuit, randomly generate a first bit string as the local shard of the first party corresponding to the i-th output line, where the actual true values of the n output lines constitute n bits of the calculation result of the confusion circuit; The first party is further configured to, based on the first bit string, determine two second bit strings, and the two second bit strings respectively correspond to the two true values of the i-th output line; The first party is further configured to use the two confusion strings respectively labeled with the two true values of the i-th output line in the confusion circuit to correspondingly encrypt the two second bit strings, and provide the two encryption results to the second party; The second party is configured to decrypt the two encryption results by using the actual confusion string corresponding to the actual true value of the i-th output line to obtain the local shard of the second party corresponding to the i-th output line; where the actual confusion string is obtained by jointly performing the confusion circuit with the first party; The first party and the second party are further respectively configured to determine the local shard of the calculation result based on the local shards corresponding to each output line among the n output lines.
12. The system according to claim 11, wherein The first party is specifically configured to: For the i-th output line, calculate the product of 2 to the power of i and the corresponding first-party shard to obtain the i-th first product; determine the first-party shard of the calculation result based on the n first products calculated for the n output lines; where 0 ≤ i ≤ n - 1; The second party is specifically configured to: For the i-th output line, calculate the product of 2 to the power of i and the corresponding second-party shard to obtain the i-th second product; determine the second-party shard of the calculation result based on the n second products calculated for the n output lines.
13. The system according to claim 12, wherein, All bits of each of the two second bit strings are encrypted; The first party is further specifically configured to: Sum the n first products and use the sum result as the first-party shard of the calculation result; The second party is further specifically configured to: Sum the n second products and use the sum result as the second-party shard of the calculation result.
14. The system according to claim 12, wherein, The second bit string includes t bits, and n ≤ t; The first party is specifically configured to: Use the two confusion strings to encrypt the t - i bits starting from the least significant bit of each of the two second bit strings; Use the encrypted t - i bits of each of the two second bit strings as the two encryption results.
15. The system according to claim 14, wherein The first party is further specifically configured to: Sum the n first products and use the result of taking the modulus of the sum with respect to 2 to the power of t as the first-party shard of the calculation result; The second party is further specifically configured to: Sum the n second products and use the result of taking the modulus of the sum with respect to 2 to the power of t as the second-party shard of the calculation result.
16. The system according to claim 11, wherein, The two true values of the i-th output line include true value 0 and true value 1; the first party is specifically configured to: Use the difference between true value 0 and the first bit string as one of the two second bit strings; Use the difference between true value 1 and the first bit string as the other second bit string of the two second bit strings.
17. The system according to claim 16, wherein, The first party is further specifically configured to: Use the first confusion string labeled with true value 0 for the i-th output line to encrypt one of the second bit strings; Use the second confusion string labeled with true value 1 for the i-th output line to encrypt the other second bit string.
18. The system according to claim 11, wherein, The first party is specifically configured to: Provide the two encrypted results in a scrambled order to the second party; The second party is specifically configured to: Use the actual confusion string corresponding to the actual true value of the i-th output line to decrypt the two encrypted results in the scrambled order.
19. The system according to claim 11, wherein The first party and the second party are further configured to jointly perform a target operation based on secret sharing based on the local shards of the calculation result determined by each of them.
20. A multi-party secure computing device, disposed in the first party, includes: A generating unit, configured to randomly generate a first bit string as a first-party shard corresponding to the i-th output line among any of the n output lines of the garbled circuit, where the actual true values of the n output lines constitute n bits of the calculation result of the garbled circuit; A determining unit, configured to determine two second bit strings based on the first bit string, where the two second bit strings respectively correspond to two true values of the i-th output line; An encrypting unit, configured to respectively encrypt the two second bit strings by using two garbled strings respectively labeled with the two true values of the i-th output line in the garbled circuit, and provide two encryption results to a second party, so that the second party can obtain a second-party shard corresponding to the i-th output line by decrypting the two encryption results, and further determine the second-party shard of the calculation result; The determining unit is further configured to determine a first-party shard of the calculation result based on the first-party shards corresponding to each output line among the n output lines.
21. A computer-readable storage medium having a computer program stored thereon, wherein, When the computer program is executed on a computer, it causes the computer to execute the method according to any one of claims 1-10.
22. A computing device, comprising a memory and a processor, wherein, The memory stores executable code, and when the processor executes the executable code, it implements the method according to any one of claims 1-10.
Citation Information
Patent Citations
Joint data processing method and device for protecting privacy
CN112487489A
Multi-party safety computing method and device, electronic equipment and storage medium
CN112765616A