Data processing method and system
By using random rearrangement methods and secret sharing and homomorphic encryption technology in secure two-party computing, the problem of data sequence leakage is solved and data privacy protection is achieved.
Patent Information
- Application Number
- CN202011245256.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-11-10
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2040-11-10
AI Technical Summary
In the existing security two-party calculations, the sequence relationship of data is easily leaked, which violates user privacy requirements.
A random rearrangement method is adopted to randomly rearrange the data of both parties, and through the characteristics of secret sharing and homomorphic encryption, ensuring that neither party can establish a connection between the order and prior to the rearrangement of the data.
Effectively hide the data order, preventing the leakage of sequential relationships and ensuring the confidentiality of the data.
Smart Images

Figure CN114462052B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of data processing, and in particular to a data processing method and system. Background Art
[0002] Secure multi-party computation is a computing protocol in which multiple participants provide inputs and jointly calculate outputs. The characteristic of this protocol is that each participant only knows its own input and the output of the calculation, but cannot know the input of any other participant. For example, in the "millionaire problem", two participants each input their own wealth amount, and finally calculate who has more wealth, but do not know any other information about the other party's wealth value.
[0003] In the case of cooperation between two parties, Party A and Party B cannot know the data content of the other party except the calculation results. However, in the existing technology, the order relationship of the data will inevitably be leaked. For example, Party A can know that the first piece of data of Party B is used in the calculation process. In some scenarios, this does not meet the user's privacy requirements.
[0004] To this end, a data processing scheme that can hide the data order is needed. Summary of the invention
[0005] A technical problem to be solved by the present disclosure is to provide a random reordering method for secure two-party computing, which can randomly reorder the data of both parties, and at the same time, neither party can establish a connection between the order of the rearranged data and the order before the reordering, effectively solving the problem of data sequence leakage.
[0006] According to the first aspect of the present disclosure, a data processing method is provided, including: obtaining an encryption result of a part of data x and a part of data y encrypted by a partner; combining the obtained encryption result with another part of the obtained data x and another part of the obtained data y; generating a result of performing an operation on each of the combined results in a scrambled order and a random number as a disturbance result; and sending the disturbance result to the partner for the partner to decrypt the disturbance result. The method may also include: encrypting the random number and sending it to the partner for the partner to perform a secondary disturbance on the data; and obtaining and decrypting the result of the secondary disturbance.
[0007] According to a second aspect of the present disclosure, a data processing method is provided, including: encrypting a portion of data x and a portion of acquired data y; obtaining a perturbation result of the partner on the encrypted data, wherein the partner combines the acquired encryption result with another portion of the acquired data x and another portion of the acquired data y, respectively, and generates a calculation result of each of the combined results in a scrambled order and a random number as a perturbation result; and decrypting the obtained perturbation result. Similarly, the random number encryption result obtained after the partner encrypts the random number and the previous decryption result can also be perturbed twice.
[0008] According to a third aspect of the present disclosure, a data processing system is provided, including Party A and Party B who respectively use data x and data y to participate in secure two-party computing, wherein Party A encrypts a portion of data x and a portion of acquired data y; Party B combines the acquired encryption result with another portion of acquired data x and another portion of acquired data y respectively; Party B generates a result of operating the combined result in a scrambled order with a random number as a disturbance result; Party A decrypts the acquired disturbance result; and Party B encrypts the random number for Party A to perform a secondary disturbance on the data. Specifically, Party A performing a secondary disturbance on the data includes: Party A performs an inverse operation on the decryption result and the acquired random number encryption result; Party A generates a result of operating the inverse operation result in a scrambled order with Party A's random number as a secondary disturbance result, and Party B decrypts the secondary disturbance result.
[0009] Optionally, the encryption performed by Party A and Party B respectively is homomorphic encryption, and the segmentation and operation rules for the data are shared secretly.
[0010] According to a fourth aspect of the present disclosure, a computing device is provided, comprising: a processor; and a memory on which executable codes are stored, and when the executable codes are executed by the processor, the processor executes the method described in the first aspect above.
[0011] According to a fifth aspect of the present disclosure, a non-temporary machine-readable storage medium is provided, on which executable code is stored. When the executable code is executed by a processor of an electronic device, the processor executes the method described in the first aspect above.
[0012] Therefore, the present invention cleverly utilizes the characteristics of secret sharing and homomorphic encryption, so that when Party A and Party B perform random sorting processing on the data respectively, the private key of the data is held by the other party, so that the confidentiality of the data will not be affected when the two parties process the data respectively, and it can ensure that the final processed data results are randomly sorted in an order unknown to both parties. BRIEF DESCRIPTION OF THE DRAWINGS
[0013] The above and other objects, features and advantages of the present disclosure will become more apparent through a more detailed description of exemplary embodiments of the present disclosure in conjunction with the accompanying drawings, wherein like reference numerals generally represent like components in the exemplary embodiments of the present disclosure.
[0014] Figure 1 An example of secret sharing is shown.
[0015] Figure 2 A schematic diagram showing the composition of a data processing system according to an embodiment of the present invention is shown.
[0016] Figure 3 A flow chart of random data rearrangement according to the present invention is shown.
[0017] Figure 4 An example of random data rearrangement according to the present invention is shown.
[0018] Figure 5 A schematic flow chart of a data processing method according to an embodiment of the present invention is shown.
[0019] Figure 6 An example of a process of Party B executing a data processing method according to the present invention is shown.
[0020] Figure 7 A schematic flow chart of a data processing method according to an embodiment of the present invention is shown.
[0021] Figure 8 An example of a process in which Party A executes a data processing method according to the present invention is shown.
[0022] Fig. 9 A schematic diagram of the structure of a computing device that can be used to implement the above data processing method according to an embodiment of the present invention is shown. DETAILED DESCRIPTION
[0023] The preferred embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although the preferred embodiments of the present disclosure are shown in the accompanying drawings, it should be understood that the present disclosure can be implemented in various forms and should not be limited by the embodiments described herein. On the contrary, these embodiments are provided to make the present disclosure more thorough and complete, and to fully convey the scope of the present disclosure to those skilled in the art.
[0024] In today's data explosion, people's demand for privacy protection is increasing. Secure computing allows people to complete computing tasks while protecting data privacy. Secure computing, the full name of which is Secure Multi-party Computation (SMC), refers to multi-party computing under the premise of protecting data security. Multi-party computing, as the name suggests, refers to multiple participants putting their own data together, performing certain calculations on this large data set, and obtaining the final calculation results.
[0025] The easiest way to implement multi-party computing is to find a trusted third party and perform computing on the multi-party data on the third-party server. However, since the data is stored in plain text on the server, the server operator can know the exact data of each participant, and the risk of security attacks on the server itself is increased.
[0026] In order to solve the above problems, secure multi-party computing can be used to obtain the results of joint computing without each party having to tell the other party the exact data (that is, the real data has never left the party). For example, in large-scale model training and large-scale statistics, since the computing tasks require data from multiple participants, but each participant often does not want (or is not allowed) to exchange or disclose data, secure multi-party computing can be used to implement the above training or statistics.
[0027] In existing secure two-party computations, Party A and Party B cannot know the other party's data content except the computation result, but the order of the data can still be leaked. For example, Party A can know that Party B's first piece of data was used in the computation process. In some scenarios, this does not meet user privacy requirements.
[0028] To this end, the present invention proposes a random reordering method for secure two-party computing, which can randomly reorder the data of both parties. At the same time, neither party can establish a connection between the order of the rearranged data and the order before the rearrangement, effectively solving the problem of data sequence leakage.
[0029] Specifically, Party A and Party B can split their respective data through secret sharing, obtain part of the other party's data, and encrypt part of the data based on the homomorphic encryption property, and randomly rearrange the complete data including the partially encrypted data to achieve obfuscation of the data order.
[0030] The basic idea of Secret Sharing (SS) is to split each number x into multiple numbers x1, x2, ..., x n , and distribute these numbers to multiple participants S1, S2, ..., S nThere. Then each participant gets a part of the original data. One or a few participants cannot restore the original data. Only when everyone puts their own data together can the real data be restored. During calculation, each participant directly uses its own local data for calculation, and exchanges some data when appropriate (the exchanged data itself also looks random and does not contain information about the original data). After the calculation is completed, the result is still distributed among the participants in the form of secret sharing, and some data is combined when the result is finally needed. Therefore, secret sharing ensures that each participant sees some random numbers during the calculation process, but still calculates the desired result in the end.
[0031] Figure 1 An example of secret sharing is shown in Figure 1. Suppose A has a secret number x and he wants to distribute it to S1, S2, …, S n Then A first needs to generate n-1 random numbers r1, r2, ..., r n , then calculate the nth number Finally, A sets x1=r1, x2=r2,…,x n =r n , and send them to S1,S2,…,S n The above simple method has the following properties:
[0032] 1. Each number x1, x2, ..., x n They are randomly distributed, and a single one or several of them do not leak any information;
[0033] 2. When all x1, x2, ..., x n When put together, we can restore x, because
[0034] 3. This scheme has the property of additive homomorphism, that is, each participant can directly calculate the sum of the secret data without exchanging any data.
[0035] Assume there is another party B, who also has a secret number y, and together with A, distributes the data to S1, S2, ..., S n To do addition, S1 can calculate z1=x1+y1, S2 can calculate z2=x2+y2, ..., S n You can calculate z n =x n +y n Each participant only operates on the local random number and does not exchange data. According to the nature of secret sharing, we can see that: That is to say, the secret sharing of z=x+y can be obtained, and the result of the sum can be kept private and used for other things. Figure 1 This paper describes a simple example of secret analysis, which satisfies additive homomorphism and ensures that only when all n parties join together can the data be decrypted.
[0036] Homomorphic encryption is a form of encryption that allows people to perform specific forms of algebraic operations on ciphertext to obtain encrypted results, and the results obtained by decrypting them are the same as the results of the same operations on the plaintext. In other words, this technology allows people to perform operations such as retrieval and comparison on encrypted data and obtain correct results without decrypting the data during the entire processing process. In this way, it can truly and fundamentally solve the confidentiality problem when entrusting data and its operations to a third party, and is suitable for use in secure multi-party computing.
[0037] Homomorphic encryption can directly encrypt the original text, and then perform various operations on the ciphertext to finally obtain the resulting ciphertext, which can be formally expressed as:
[0038] x1, x2, ..., x n →[x1],[x2],...,[x n ]
[0039] f([x1], [x2], ..., [x n ])→[f(x1, x2, ..., x n )]
[0040] Therefore, with the help of homomorphic encryption, the same effect can be achieved by operating directly on the ciphertext and operating on the plaintext and then encrypting it. A typical application scenario is: the data holder wants to calculate the large amount of data he holds, but he does not have enough computing resources, so he wants to use the computing power of the cloud server to complete the calculation. If the data is transferred to the cloud server according to the conventional practice, and then the pre-written program is run for calculation, sensitive data will be exposed on the cloud server. Homomorphic encryption can solve this problem. The data holder encrypts the data before transmitting it, and the cloud server calculates as usual after receiving the data. Since the calculation is performed on the ciphertext, there will be no leakage in the cloud. After the result is obtained, the ciphertext of the result is returned to the data holder, and the data holder will get the final result after decrypting it.
[0041] Many well-known public key encryption schemes actually have homomorphic properties, but they only support partial homomorphism, that is, they only support addition or multiplication operations on ciphertext, but not both. For example, the RSA encryption scheme supports homomorphic multiplication. In recent years, some encryption schemes can support (at least under limited conditions or operations) fully homomorphic encryption.
[0042] Here, when the encryption function is E and the plaintext is x, y, additive homomorphism means that if there is an effective algorithm ⊕, E(x+y)=E(x)⊕E(y) or x+y=D(E(x)⊕E(y)) holds, and x and y are not leaked. Multiplicative homomorphism means that if there is an effective algorithm, E(x×y)=E(x)E(y) or xy=D(E(x)E(y)) holds, and x and y are not leaked.
[0043] In the present invention, by cleverly utilizing the characteristics of secret sharing and homomorphic encryption, when Party A and Party B process data separately, the private key of the data is held by the other party, thereby ensuring that the confidentiality of the data will not be affected when the two parties process the data separately.
[0044] Figure 2 FIG. 2 shows a schematic diagram of the composition of a data processing system 200 according to an embodiment of the present invention. Figure 2 As shown, system 200 includes two parties participating in secure two-party computing: Party A 210 and Party B 220. Party A uses data x to participate in secure computing, and Party B uses data y to participate in secure computing. Specifically, Party A can send encrypted data x and y to Party B for disturbance (for example, Party B scrambles the order), and then Party B can process the disturbed data and send it back to Party A for secondary disturbance (for example, Party A scrambles the order again based on the first scrambling). Thus, after using the data processing scheme of the present invention, Party A and Party B can each hold part of the x and part of the y data that meet the requirements of the secret sharing form, and neither of them knows the specific order of the x and y data.
[0045] Figure 3A flow chart of random data rearrangement according to the present invention is shown. In step S310, Party A encrypts a part of data x and a part of acquired data y. Here, a part of data y may be sent to Party A in advance by Party B. Similarly, Party A may send another part of data x to Party B. Subsequently, in step S320, Party B combines the acquired encryption result with another part of acquired data x and another part of data y, respectively. The combined result includes partially encrypted and partially unencrypted data x, and partially encrypted and partially unencrypted data y. Subsequently, in step S330, the operation results of each of the combined results after the order is disrupted and the random number are calculated are generated as the disturbance result. Here, in order to obtain the disturbance result, it can be the order of the operation results after each of the perturbation combination results of Party B is calculated with the random number, or it can be the order of the perturbation combination results of Party B, and then each of them is calculated with the random number. Here, "disturbance" can refer to the order of disrupting the data, for example, randomly disrupting the original order of multiple data.
[0046] Then, in step S340, Party A decrypts the obtained disturbance result. At this time, the decryption result obtained by Party A is, for example, data x and data y from which random numbers have been subtracted, and the true order of data x and data y is unknown to Party A. At this time, both Party A and Party B have part of data x and data y (i.e., Party A has, for example, data x and data y from which random numbers have been subtracted; Party B has the random number), and Party B conceals the true order of the data from Party A through disturbance.
[0047] Subsequently, Party A may perform a second disturbance on the data to conceal the true order of the data from Party B. Specifically, the process may further include: Party B encrypts the random number for Party A to perform a second disturbance on the data.
[0048] Party A's secondary disturbance of the data may include: Party A performs an inverse operation on the decryption result and the obtained random number encryption result; Party A generates an operation result of the inverse operation result with a scrambled order and the operation result of Party A's random number as the secondary disturbance result, and Party B decrypts the secondary disturbance result.
[0049] Similarly, here, in order to obtain the secondary perturbation result, the order of the results of the inverse operation of the perturbation of Party A and the random number of Party A (for example, the random number generated by Party A) can be used, or the order of the results of the inverse operation of the perturbation of Party A and the random number of Party A can be used. Here, "secondary perturbation" can refer to the order of data being disrupted again on the basis of the order that has been disrupted by Party B.
[0050] Here, the encryption performed by Party A and Party B is homomorphic encryption, and the data segmentation and operation are in accordance with the secret sharing segmentation and operation rules. Therefore, the data held by Party A and Party B from beginning to end conforms to the legal form of secret sharing, and through two disturbances, neither Party A nor Party B knows the order of data x and y.
[0051] In order to further illustrate the principle of the present invention, Figure 4 An example of random data rearrangement according to the present invention is shown, and Figure 3 Specific data operation examples of the steps shown.
[0052] In order to ensure the security of their respective data, Party A and Party B can split their respective data to meet the required form of secret sharing. To this end, Party A 410 can split data x into x1 and x2. Party B 420 can split data y into y1 and y2. Common splitting methods include additive secret sharing and multiplicative secret sharing. As shown in the figure, when additive secret sharing is adopted, x=x1+x2, y=y1+y2. In addition, although the example in the figure is not shown, multiplicative secret sharing can also be adopted. When multiplicative secret sharing is adopted, x=x1*x2, y=y1*y2.
[0053] Due to the nature of computer calculations, and in order to avoid the leakage of the values of x and y by their split values when the values of x and y are small, additive secret sharing and multiplicative secret sharing in the form of x=x1+x2mod q, y=y1+y2mod q, and x=x1*x2mod q, y=y1*y2mod q are usually used. Therefore, by performing a remainder operation on a larger value (for example, q can be equal to a known fixed value, a larger fixed value, such as 2 to the power of 64), the range of values of x1, x2, y1, and y2 can be increased, thereby improving the randomness of the values. For this reason, although Figure 3 For the sake of convenience, the "mod q" part is not shown, but it should be understood that for the guarantee of randomness and the natural properties of computer data processing, Figure 3 The division in is understood as the form of x=x1+x2mod q, y=y1+y2mod q, where q can be equal to a known fixed value, such as 2 to the power of 64.
[0054] Party A and Party B can send a portion of their respective data to each other for processing. Specifically, Party B can send the generated y1 to Party A. Party A can send the generated x2 to Party B. At this time, Party A holds x1 and y1, and Party B holds x2 and y2, so both parties hold data that meets the secret sharing requirements.
[0055] After obtaining y1, Party A can perform homomorphic encryption on x1 and y1 to obtain Enc(x1) and Enc(y1). Here, the homomorphic encryption performed by Party A on x1 and y1 needs to be the same as the form of splitting x1 and x2 and y1 and y2. For example, when using additive secret sharing for splitting, the corresponding additive homomorphic encryption can be performed. When using multiplicative secret sharing for splitting, the corresponding multiplicative homomorphic encryption can be performed. Figure 3 In the example, any known or future discovered additive homomorphic encryption function can be used to homomorphically encrypt x1 and y1.
[0056] The first private key can be used to homomorphically encrypt x1 and y1 to obtain Enc(x1) and Enc(y1). Normally, the same secret sharing splitting method needs to be used for x and y, and Party A also performs the same type of homomorphic encryption on x1 and y1. For example, x and y can be split using additive secret sharing, so Party A can perform additive homomorphic encryption on x1 and y1. Since Party A will subsequently need to decrypt the data containing x and y that has been randomly sorted by Party B, the same additive homomorphic encryption method needs to be used for x1 and y1, and the same key is used to encrypt x1 and y1. As can be seen from the above, the "first private key" is used here to represent the same key held by Party A for homomorphically encrypting x1 and y1.
[0057] After obtaining Enc(x1) and Enc(y1), Party A can send them to Party B. At this point, Party B holds Enc(x1) and Enc(y1) as well as x2 and y2. Since Party B does not know the first private key held by Party A, Party B does not know the data x and data y themselves.
[0058] After obtaining Enc(x1) and Enc(y1), Party B can perform homomorphic operations on Enc(x1) and x2 and Enc(y1) and y2 respectively. Similarly, the homomorphic operations performed at this time need to be in the same form as the splitting of x1 and x2 and y1 and y2. For example, when using additive secret sharing for splitting, the corresponding additive homomorphic operations can be performed. When using multiplicative secret sharing for splitting, the corresponding multiplicative homomorphic operations can be performed. Figure 3 In the example, Enc(x1) and x2 and Enc(y1) and y2 can be added separately. According to the definition of additive homomorphism, Enc(x) = Enc(x1) + x2 and Enc(y) = Enc(y1) + y2 can be used to obtain Enc(x) and Enc(y).
[0059] Subsequently, Party B can randomly sort Enc(x) and Enc(y), and send Enc(x) and Enc(y) that meet the secret sharing requirements to Party A, that is, send Enc(x) and Enc(y) that are each operated with a random number unknown to Party A to Party A. Specifically, Party B can perform a first operation result of a first operation on Enc(x) and Enc(y) in a scrambled order and random numbers R and S, and send the first operation result to Party A. The first operation still needs to correspond to the secret sharing form that initially split x and y. For example, in additive secret sharing, the first operation is subtraction; in multiplicative secret sharing, the first operation is division.
[0060] In a specific implementation, Party B may first shuffle the order of Enc(x) and Enc(y) and then perform the first operation with the random number, or may first perform the first operation and then shuffle the order of Enc(x) and Enc(y) after the operation. To this end, Party B randomly shuffles the order of Enc(x) and Enc(y) and generates two random numbers R and S; Party B performs the first operation with R and S respectively and the shuffled Enc(x) and Enc(y), and sends the generated first operation result back to Party A, or Party B generates random numbers R and S and performs the first operation with R and S respectively and Enc(x) and Enc(y); Party B randomly shuffles the order of Enc(x) and Enc(y) after the first operation.
[0061] In either case, Party B can obtain the first operation result of the first operation of Enc(x) and Enc(y) after scrambling and the random numbers R and S. At this point, Party B knows the order of Enc(x) and Enc(y) after scrambling, and knows the corresponding relationship between the random numbers R and S and Enc(x) and Enc(y). Figure 3 In the example, after random sorting, Enc(x) is still in the front and Enc(y) is in the back. At this time, Enc(x)-R and Enc(y)-S can be sent to Party A as the first operation result.
[0062] After obtaining the first operation result, Party A can use the first private key previously encrypted for Enc(x1) and Enc(y1) to decrypt the first operation result, and obtain the second operation result of performing the first operation on R and S with the scrambled x and y respectively. For example, Party A obtains Enc(x)-R and Enc(y)-S. According to the properties of homomorphic encryption, after decrypting using the first private key encrypted for Enc(x1) and Enc(y1), xR and yS can be obtained. At this time, Party A holds xR and yS, but does not know the order of xR and yS, that is, it does not know which of the relevant data of x and y comes first and which comes later. However, Party B knows which of the relevant data of x and y comes first and which comes later, that is, Party B knows that Party A decrypts xR and yS, and Party B holds R and S.
[0063] At this point, A holds xR, yS, and B holds R and S. Both parties still hold the secret sharing form of x and y. The difference is that at this time, A no longer knows the order of x and y (but B knows).
[0064] In addition, it should be understood that although random numbers R and S are used here for representation, as shown above in combination with the definition of secret sharing, the operation of Party B sending Enc(x)-R and Enc(y)-S back to Party A and holding R and S can be regarded as another addition secret split of x and y. For example, xR=x3, yS=y3, R=x4, S=y4 can be set, then x=x3+x4, y=y3+y4. Furthermore, x=x3+x4 mod q, y=y3+y4 mod q.
[0065] Then, just swap the roles of A and B and re-run the above steps to get a new set of secret sharing forms of x and y. At the same time, neither A nor B knows the order of x and y.
[0066] Specifically, Party B can use the second private key to homomorphically encrypt R and S to obtain Enc'(R) and Enc'(S), and send them to Party A. Here, "'" is used to indicate that it is not used for encryption by Party A using the first key.
[0067] Party A obtains Enc'(R) and Enc'(S), and performs the inverse operation of the first operation on Enc'(R) and Enc'(S) and the result of the second operation, to obtain Enc'(x) and Enc'(y) in a scrambled order. Here, if the first operation is subtraction, the inverse operation is addition; if the first operation is division, the inverse operation is multiplication. Figure 3In the example, Enc'(x) and Enc'(y) can be added to xR and yS as the second operation results, respectively, to obtain Enc'(x)=Enc'(R)+xR, Enc'(y)=Enc'(S)+yS.
[0068] Subsequently, Party A generates the third operation result of the second operation of Enc'(x) and Enc'(y) which have been scrambled twice and the random numbers M and N. Similar to the random sorting performed by Party B previously, in the specific implementation, Party A may scramble the order of Enc'(x) and Enc'(y) first and then perform the second operation with the random numbers, or may perform the second operation first and then scramble the order of Enc'(x) and Enc'(y) after the operation. To this end, Party A randomly scrambles the order of Enc'(x) and Enc'(y) and generates two random numbers M and N; Party A performs the second operation of M and N with the scrambled Enc'(x) and Enc'(y) respectively, and sends the generated third operation result back to Party B, or Party A generates random numbers M and N, and performs the second operation of M and N with Enc'(x) and Enc'(y) respectively; Party A randomly scrambles the order of Enc'(x) and Enc'(y) after the second operation.
[0069] In either case, Party A can obtain the third operation result of the second operation of Enc'(x) and Enc'(y) that have been randomly sorted twice and random numbers M and N. At this point, Party A knows how Enc'(x) and Enc'(y) are randomly sorted twice by Party A, and knows the corresponding relationship between random numbers M and N and Enc'(x) and Enc'(y). Figure 3 In the example, after random sorting, Enc'(y) is in front and Enc'(x) is in the back. At this time, Enc'(y)-M and Enc'(x)-N can be sent to Party B as the third operation result.
[0070] Party B uses the second private key to decrypt the third operation result, and obtains the fourth operation result of the second operation of M and N with x and y after the second scrambled order. For example, Party B obtains Enc'(y)-M and Enc'(x)-N as shown in the figure. According to the properties of homomorphic encryption, after decrypting using the second private key encrypted with Enc'(R) and Enc'(S), yM and xN can be obtained. At this time, Party A holds M and N. Although it knows how the order of yM and xN is scrambled in the secondary random sorting, it does not know the order of xR and yS in the initial random sorting by Party B; Party B holds yM and xN, but does not know the order of yM and xN.
[0071] At this point, A holds M and N, and B holds yM and xN. Both parties still hold the secret shared form of x and y, and at this time, A and B no longer know the order of x and y (so each of them randomly sorted them while the other party kept the private key).
[0072] In addition, it should also be understood that although random numbers M and N are used here to represent it, as shown above in combination with the definition of secret sharing, the operation of Party A sending Enc'(y)-M and Enc'(x)-N back to Party B and holding M and N can be regarded as another addition secret split of x and y. For example, yM=x5,xN=y5,M=x6,N=y6 can be set, at this time x=x5+x6, y=y5+y6, and further, x=x5+x6mod q, y=y5+y6 mod q.
[0073] Therefore, the present invention cleverly utilizes the characteristics of secret sharing and homomorphic encryption, so that when Party A and Party B process data separately, the private key of the data is held by the other party, so that the confidentiality of the data will not be affected when the two parties process the data separately. Furthermore, by randomly shuffling the data once by Party A and Party B respectively, the final order is the superposition of the random sorting results of both parties, thereby ensuring that neither party knows the order of the data.
[0074] This solution does not restrict specific secret sharing schemes and homomorphic schemes. For example, Figure 4 The additive homomorphism shown can also be replaced by multiplicative homomorphism. In this case, the secret sharing scheme can be replaced by multiplicative secret sharing, that is, x=x1*x2, y=y1*y2, and further, x=x1*x2mod q, y=y1*y2mod q. Subsequently, the forms of x / R, y / S, y / M, x / N, etc. can be obtained.
[0075] In other words, in the addition implementation, Party A's secret sharing splitting of data x into x1 and x2, and Party B's secret sharing splitting of data y into y1 and y2 may include: Party A performs additive secret sharing splitting on data x: x=x1+x2modq; and Party B performs additive secret sharing splitting on data y: y=y1+y2modq. Party A obtains y1 and uses the first private key to homomorphically encrypt x1 and y1 to obtain Enc(x1) and Enc(y1) may include: Party A uses the first key to perform additive homomorphic encryption on x1 to obtain Enc(x1); and Party A uses the first key to perform additive homomorphic encryption on y1 to obtain Enc(y1). Party B obtains x2 and Enc(x1) and Enc(y1), and performs homomorphic operations on Enc(x1) and x2 and Enc(y1) and y2 respectively to obtain Enc(x) and Enc(y), which may include: Party B performs additive homomorphic operations on Enc(x1) and x2 to obtain Enc(x); and Party B performs additive homomorphic operations on Enc(y1) and y2 to obtain Enc(y). At this time, the first operation is a subtraction operation, and the subsequent homomorphic encryption for R and S should also be the corresponding additive homomorphic encryption, and the inverse operation of the first operation is the corresponding addition operation. The second operation has the same nature as the first operation, which is also a subtraction operation, and the inverse operation of the second operation is also a corresponding addition operation.
[0076] In the multiplication implementation, Party A's secret sharing splitting of data x into x1 and x2, and Party B's secret sharing splitting of data y into y1 and y2 may include: Party A performs multiplication secret sharing splitting on data x: x=x1*x2modq; and Party B performs multiplication secret sharing splitting on data y: y=y1*y2modq. Party A obtains y1 and uses the first private key to homomorphically encrypt x1 and y1 to obtain Enc(x1) and Enc(y1) may include: Party A uses the first key to perform multiplication homomorphic encryption on x1 to obtain Enc(x1); and Party A uses the first key to perform multiplication homomorphic encryption on y1 to obtain Enc(y1). Party B obtains x2 and Enc(x1) and Enc(y1), and performs homomorphic operations on Enc(x1) and x2 and Enc(y1) and y2 respectively to obtain Enc(x) and Enc(y), which may include: Party B performs a multiplication homomorphic operation on Enc(x1) and x2 to obtain Enc(x); and Party B performs a multiplication homomorphic operation on Enc(y1) and y2 to obtain Enc(y). The first operation is a division operation, and the subsequent homomorphic encryption of R and S should also be the corresponding multiplication homomorphic encryption, and the inverse operation of the first operation is the corresponding multiplication operation. The second operation has the same nature as the first operation, which is also a division operation, and the inverse operation of the second operation is also the corresponding multiplication operation.
[0077] Here, any additive homomorphic or multiplicative homomorphic function can be used to implement homomorphic encryption. In other embodiments, a fully homomorphic function can also be used. When using a fully homomorphic function, since it is necessary to decrypt the data for random number calculation by the other party, in a complete operation on data x and y, usually only a simple additive homomorphism or a simple multiplicative homomorphism is used, and there are rarely application scenarios in which both additive and multiplicative homomorphism are used.
[0078] In actual use, if only one piece of data x from Party A and one piece of data y from Party B are included, even if both parties are disturbed, the sorting results are no more than two: x first and y second, or y first and x second. Obviously, the random sorting method of the present invention can better show its perturbation and hide the effect of sorting when both parties of Party A include multiple pieces of data. For this purpose, it is assumed that the data x provided by Party A for cooperation includes multiple pieces of data x, and the data y provided by Party B for cooperation includes multiple pieces of data y.
[0079] At this time, Party A can divide the multiple pieces of data x used for cooperation into their respective x1 and x2, and Party B can divide the multiple pieces of data y used for cooperation into their respective y1 and y2. When performing the initial disturbance, further, the first operation result of generating the first operation of Enc(x) and Enc(y) after the scrambled order and the random numbers R and S includes: for each piece of data contained in Enc(x) and Enc(y), each randomly generates a random number to perform the first operation. The third operation result of generating the second operation of Enc'(x) and Enc'(y) after the second scrambled order and the random numbers M and N includes: for each piece of data contained in Enc'(x) and Enc'(y), each randomly generates a random number to perform the second operation. This ensures that the random number of each piece of data is generated separately. In other words, Party B can randomly scramble the order of multiple pieces of Enc(x) and Enc(y) so that the data from the two parties are mixed and randomly sorted. When performing a secondary disturbance, Party A can cause the two parties' data that have been mixed and randomly sorted to be randomly mixed and sorted a second time, thereby hiding the sorted data from both parties.
[0080] For example, the data x used by Party A for cooperation may include four pieces of data, a1, a2, a3 and a4, and the data y used by Party B for cooperation may include four pieces of data, b1, b2, b3 and b4. At this time, Party A and Party B may first perform secret sharing on their respective data a1, a2, a3 and a4 and b1, b2, b3 and b4, and obtain the first operation result through homomorphic encryption of part of the data by Party A and random sorting and random number operation of the encrypted data by Party B. For example, after the first disturbance (disruption of the order, such as random sorting) by Party B, the order of the data changes from a1, a2, a3, a4, b1, b2, b3, b4 in the order of source to b2, a4, b4, a2, a1, b1, b3, a3, and the 8 pieces of data after the change each subtract a random number (corresponding to R and S) whose size and order Party B knows. Subsequently, through Party A's secondary random perturbation, the order of the data can be changed from b2, a4, b4, a2, a1, b1, b3, a3 to b1, b2, a3, a2, a1, b3, a4, b4, and each of the changed 8 data is subtracted from a random number (corresponding to M and N) whose size and order is known to Party A.
[0081] For the final sorting, for example, b1, b2, a3, a2, a1, b3, a4, b4 obtained after the second random sorting, since Party B only knows its first random sorting, and Party A only knows the second random sorting based on the first random sorting, neither Party A nor Party B knows the order of the final sorting, thus hiding the order of the cooperation data. In normal cooperation, the amount of data invested by Party A and Party B is usually not in the single digit, but in the thousands, tens of thousands, or even higher orders of data, so the random sorting result at this time is used for stronger non-traceability, thereby avoiding the leakage of the data order relationship.
[0082] Thus, the system can perform secure two-party computation using M and N held by Party A and the fourth operation result held by Party B, for example, model training on the cloud held by Party A.
[0083] For example, Party A has data x, Party B has data y, and both parties plan to use secure multi-party computing to run an algorithm (e.g., machine learning training) on the entire data set {x, y}. If the random reordering technology is not used, then in order to train a machine learning model, both parties will inevitably know how many times x and y were read during the training of the model. For example, the first 50% of the 10,000 x data and the first 50% of the 10,000 y data were used in the first round of training, and the remaining 50% of the 10,000 y data and the remaining 50% of the 10,000 y data were used in the second round of training. This does not meet the user privacy requirements in some scenarios. However, by using the random reordering calculation of the present invention, both parties only know that 10,000 data were used in the first round of training, and 10,000 data were used in the second round, thereby ensuring the hiding of the data order.
[0084] The present invention can also be implemented as a data processing method performed by Party A or Party B with the cooperation of the other party. Figure 5 FIG. 1 is a schematic flow chart of a data processing method according to an embodiment of the present invention. The method may be performed by Party B (the first perturbation party). Figure 2-4 The Party B described here refers to Party A as the partner.
[0085] In step S510, the encryption result of the partner encrypting a part of data x and a part of data y is obtained. In step S520, the encryption result is combined with another part of the obtained data x and another part of the obtained data y. In step S530, the operation result of each of the combined results in a scrambled order and a random number is generated as a disturbance result. In step S540, the disturbance result is sent to the partner for the partner to decrypt the disturbance result. In this way, the first random sorting achieved by the own party is completed.
[0086] To further explain Party B’s operation, Figure 6 The flow chart of the data processing method performed by the second party according to the present invention is shown, and Figure 5 Specific data operation examples of the steps shown.
[0087] In step S610, a part x2 of the data x used for cooperation by the partner is obtained, wherein the partner divides the data x used for cooperation into x1 and x2.
[0088] In step S620, the data y for cooperation is divided into y1 and y2, and y1 is sent to the cooperation party. It should be understood that in other embodiments, the execution order of steps S610 and S620 can also be exchanged, for example, both parties A and B divide the data at the same time and send part of the data later.
[0089] In step S630, the acquiring partner uses the first private key to homomorphically encrypt x1 and y1 to obtain Enc(x1) and Enc(y1).
[0090] In step S640, homomorphic operations are performed on Enc(x1) and x2, and Enc(y1) and y2, respectively, to obtain Enc(x) and Enc(y).
[0091] In step S650, a first operation result of performing a first operation on the shuffled Enc(x) and Enc(y) and the random numbers R and S is generated.
[0092] In step S660, the first operation result thus generated is sent back to the partner, and the first operation result is decrypted by the partner using the first private key to obtain a second operation result of the first operation performed by R and S respectively with the scrambled x and y.
[0093] Figure 6 The process shown can be seen as Figure 5 The process shown is refined, and the above steps S610-S630 can be regarded as sub-steps 1-3 of step S510, and steps S640-S660 correspond to steps S520-S540.
[0094] After the first random sorting is completed by the party itself, a second random sorting can be performed by the partner. To this end, the method may further include: encrypting the random number and sending it to the partner for the partner to perform a second disturbance on the data; and obtaining the result of the second disturbance and decrypting it. Specifically, the partner's second disturbance on the data includes: performing an inverse operation on the decryption result and the obtained random number encryption result; generating an operation result of the inverse operation result with a disrupted order and performing an operation on the partner's random number as the second disturbance result.
[0095] In the case of using symbolic description, the second perturbation step may include: using the second private key to homomorphically encrypt R and S to obtain Enc'(R) and Enc'(S); sending Enc'(R) and Enc'(S) to the partner, and the partner performs the inverse operation of the first operation with the second operation result on Enc'(R) and Enc'(S); obtaining the third operation result, wherein the partner generates the third operation result of the second operation of Enc'(x) and Enc'(y) which are twice scrambled and random numbers M and N; using the second private key to decrypt the third operation result, and obtain the fourth operation result of the second operation of M and N respectively with x and y which are twice scrambled. After the perturbation by the partner, neither party knows the order of x and y, and both parties still hold the required secret sharing form.
[0096] Figure 7FIG. 1 is a schematic flow chart of a data processing method according to an embodiment of the present invention. The method may be performed by Party A (secondary disturbance party). Figure 2-4 The party described is Party A, and the partner is Party B.
[0097] In step S710, a part of data x and a part of acquired data y are encrypted. In step S720, a disturbance result of the partner on the encrypted data is acquired, wherein the partner combines the acquired encryption result with another part of acquired data x and another part of acquired data y, respectively, and generates a calculation result of each of the combined results in a scrambled order and a random number as a disturbance result. In step S730, the acquired disturbance result is decrypted.
[0098] To further explain Party A's operation, Figure 8 The flow chart of the data processing method performed by Party A according to the present invention is shown, and Figure 7 Specific data operation examples of the steps shown.
[0099] In step S810, data x for cooperation is divided into x1 and x2, and x2 is sent to the partner. In step S820, a part y1 of data y for cooperation of the partner is obtained, wherein the partner divides data y for cooperation into y1 and y2.
[0100] In step S830, x1 and y1 are homomorphically encrypted using the first private key to obtain Enc(x1) and Enc(y1), and Enc(x1) and Enc(y1) are sent to the partner. In step S840, a first operation result is obtained, wherein the partner performs homomorphic operations on Enc(x1) and x2 and Enc(y1) and y2 respectively to obtain Enc(x) and Enc(y), and generates a first operation result of the first operation of Enc(x) and Enc(y) in a scrambled order with random numbers R and S. In step S850, the first operation result is decrypted using the first private key to obtain a second operation result of the first operation of R and S with the scrambled x and y respectively.
[0101] Figure 8 The process shown can be seen as Figure 7 The process shown is refined, and the above steps S810-S830 can be regarded as sub-steps 1-3 of step S710, and steps S840-S850 correspond to steps S720-S730.
[0102] Thus, the first random sorting implemented by the partner is completed. Subsequently, the second random sorting implemented by the partner can be performed. To this end, the method may also include: obtaining Enc'(R) and Enc'(S) obtained by homomorphically encrypting R and S using the second private key by the partner; performing the inverse operation of the first operation on Enc'(R) and Enc'(S) with the second operation result to obtain Enc'(x) and Enc'(y) in a scrambled order; generating a third operation result of a second operation of Enc'(x) and Enc'(y) with the second scrambled order and random numbers M and N; and sending the generated third operation result back to the partner, and the partner uses the second private key to decrypt the third operation result to obtain a fourth operation result of a second operation of M and N with the second scrambled order x and y respectively. After the disturbance by the partner, neither party knows the order of x and y, and both parties still hold the required secret sharing form.
[0103] Subsequently, no matter from which perspective, the result after the secondary random sorting can be used for secure two-party computation. To this end, the method further includes: performing secure two-party computation using M and N respectively held by the two parties and the fourth operation result.
[0104] Similarly, when performing the first operation and the second operation, the operation with the random number may be performed first and then the random sorting may be performed, or the random sorting may be performed first and then the operation with the random number may be performed.
[0105] To this end, generating the first operation result of the first operation of the scrambled Enc(x) and Enc(y) and the random numbers R and S may include: randomly scrambling the order of Enc(x) and Enc(y), generating random numbers R and S, and performing the first operation on R and S respectively with the scrambled Enc(x) and Enc(y); or generating random numbers R and S, performing the first operation on R and S respectively with Enc(x) and Enc(y), and randomly scrambling the order of Enc(x) and Enc(y) after the first operation. In either case, the sorted position of the random numbers needs to be recorded to ensure the correct restoration of each piece of data.
[0106] Similarly, generating a third operation result of a second operation between Enc'(x) and Enc'(y) that have been scrambled twice and random numbers M and N may include: randomly scrambling the order of the scrambled Enc'(x) and Enc'(y) twice to generate random numbers M and N, and performing a second operation on M and N respectively with Enc'(x) and Enc'(y) that have been scrambled twice to obtain the third operation result; or generating random numbers M and N, performing a third operation on M and N respectively with Enc'(x) and Enc'(y) that have been scrambled, and randomly scrambling the order of Enc'(x) and Enc'(y) after the second operation twice to obtain the third operation result.
[0107] When using additive homomorphism, dividing the data x used for cooperation into x1 and x2, and dividing the data y used for cooperation into y1 and y2 includes: performing additive secret sharing on the data x: x=x1+x2modq; and performing additive secret sharing on the data y: y=y1+y2modq. Obtaining the cooperation party to use the first private key to perform homomorphic encryption on x1 and y1 to obtain Enc(x1) and Enc(y1) includes: performing additive homomorphic encryption on x1 using the first key to obtain Enc(x1); and performing additive homomorphic encryption on y1 using the first key to obtain Enc(y1). Performing homomorphic operations on Enc(x1) and x2 and Enc(y1) and y2 respectively to obtain Enc(x) and Enc(y) includes: performing additive homomorphic operations on Enc(x1) and x2 to obtain Enc(x); and performing additive homomorphic operations on Enc(y1) and y2 to obtain Enc(y). At this time, the first operation is a subtraction operation, and the subsequent homomorphic encryption for R and S should also be the corresponding additive homomorphic encryption, and the inverse operation of the first operation is the corresponding addition operation. The second operation has the same nature as the first operation, which is also a subtraction operation, and the inverse operation of the second operation is also the corresponding addition operation.
[0108] In the multiplication implementation, Party A's secret sharing splitting of data x into x1 and x2, and Party B's secret sharing splitting of data y into y1 and y2 may include: Party A performs multiplication secret sharing splitting on data x: x=x1*x2modq; and Party B performs multiplication secret sharing splitting on data y: y=y1*y2modq. Party A obtains y1 and uses the first private key to homomorphically encrypt x1 and y1 to obtain Enc(x1) and Enc(y1) may include: Party A uses the first key to perform multiplication homomorphic encryption on x1 to obtain Enc(x1); and Party A uses the first key to perform multiplication homomorphic encryption on y1 to obtain Enc(y1). Party B obtains x2 and Enc(x1) and Enc(y1), and performs homomorphic operations on Enc(x1) and x2 and Enc(y1) and y2 respectively to obtain Enc(x) and Enc(y), which may include: Party B performs a multiplication homomorphic operation on Enc(x1) and x2 to obtain Enc(x); and Party B performs a multiplication homomorphic operation on Enc(y1) and y2 to obtain Enc(y). The first operation is a division operation, and the subsequent homomorphic encryption of R and S should also be the corresponding multiplication homomorphic encryption, and the inverse operation of the first operation is the corresponding multiplication operation. The second operation has the same nature as the first operation, which is also a division operation, and the inverse operation of the second operation is also the corresponding multiplication operation.
[0109] In addition, in actual application scenarios, the data input by both parties A and B include multiple data, so the disturbance involves mixed disturbances of multiple x and multiple y. Therefore, splitting the data x used for cooperation into x1 and x2 includes: splitting the multiple data x used for cooperation into x1 and x2 respectively, and splitting the data y used for cooperation into y1 and y2 includes: splitting the multiple data y used for cooperation into y1 and y2 respectively. And, randomly disrupting the order of Enc(x) and Enc(y) includes: randomly disrupting the order of multiple Enc(x) and Enc(y) so that the data from the two parties are mixed and randomly sorted. Secondary random shuffling of the order of Enc'(x) and Enc'(y) after the order is disrupted includes: causing the two parties' data that have been mixed and randomly sorted to be randomly mixed and sorted twice.
[0110] Furthermore, the first operation result of the first operation of Enc(x) and Enc(y) after the order is scrambled and the random numbers R and S includes: for each piece of data included in Enc(x) and Enc(y), a random number is randomly generated to perform the first operation. The third operation result of the second operation of Enc'(x) and Enc'(y) after the order is scrambled twice and the random numbers M and N is generated: for each piece of data included in Enc'(x) and Enc'(y), a random number is randomly generated to perform the second operation. This ensures that the random number of each piece of data is generated separately.
[0111] Fig. 9 A schematic diagram of the structure of a computing device that can be used to implement the above data processing method according to an embodiment of the present invention is shown.
[0112] See also Fig. 9 , the computing device 900 includes a memory 910 and a processor 920 .
[0113] The processor 920 may be a multi-core processor or may include multiple processors. In some embodiments, the processor 920 may include a general-purpose main processor and one or more special coprocessors, such as a graphics processing unit (GPU), a digital signal processor (DSP), etc. In some embodiments, the processor 920 may be implemented using a customized circuit, such as an application-specific integrated circuit (ASIC) or a field programmable gate array (FPGA).
[0114] The memory 910 may include various types of storage units, such as system memory, read-only memory (ROM), and permanent storage devices. Among them, ROM can store static data or instructions required by the processor 920 or other modules of the computer. The permanent storage device may be a readable and writable storage device. The permanent storage device may be a non-volatile storage device that does not lose the stored instructions and data even after the computer is powered off. In some embodiments, the permanent storage device uses a large-capacity storage device (such as a magnetic or optical disk, flash memory) as a permanent storage device. In some other embodiments, the permanent storage device may be a removable storage device (such as a floppy disk, optical drive). The system memory may be a readable and writable storage device or a volatile readable and writable storage device, such as a dynamic random access memory. The system memory may store some or all instructions and data required by the processor at run time. In addition, the memory 910 may include any combination of computer-readable storage media, including various types of semiconductor memory chips (DRAM, SRAM, SDRAM, flash memory, programmable read-only memory), and disks and / or optical disks may also be used. In some embodiments, the memory 910 may include a readable and / or writable removable storage device, such as a laser disc (CD), a read-only digital versatile disc (e.g., DVD-ROM, double-layer DVD-ROM), a read-only Blu-ray disc, an ultra-density optical disc, a flash memory card (e.g., SD card, mini SD card, Micro-SD card, etc.), a magnetic floppy disk, etc. The computer-readable storage medium does not include carrier waves and transient electronic signals transmitted wirelessly or wired.
[0115] The memory 910 stores executable codes, and when the executable codes are processed by the processor 920 , the processor 920 can execute the data processing method mentioned above.
[0116] The data processing method and system according to the present invention have been described in detail above with reference to the accompanying drawings. The present invention cleverly utilizes the characteristics of secret sharing and homomorphic encryption, so that when Party A and Party B perform random sorting processing on the data respectively, the private key of the data is held by the other party, so that the data processing by both parties will not affect the confidentiality of the data, and it can ensure that the final processed data results are randomly sorted in an order unknown to both parties.
[0117] In addition, the method according to the present invention may also be implemented as a computer program or a computer program product, which includes computer program code instructions for executing the above steps defined in the above method of the present invention.
[0118] Alternatively, the present invention may also be implemented as a non-temporary machine-readable storage medium (or computer-readable storage medium, or machine-readable storage medium) on which executable code (or computer program, or computer instruction code) is stored. When the executable code (or computer program, or computer instruction code) is executed by a processor of an electronic device (or computing device, server, etc.), the processor executes the various steps of the above-mentioned method according to the present invention.
[0119] Those skilled in the art will further appreciate that the various illustrative logical blocks, modules, circuits, and algorithm steps described in connection with the disclosure herein may be implemented as electronic hardware, computer software, or a combination of both.
[0120] The flow chart and block diagram in the accompanying drawings show the possible architecture, function and operation of the system and method according to multiple embodiments of the present invention. In this regard, each square box in the flow chart or block diagram can represent a part of a module, program segment or code, and the part of the module, program segment or code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the square box can also occur in a sequence different from that marked in the accompanying drawings. For example, two continuous square boxes can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each square box in the block diagram and / or flow chart, and the combination of the square boxes in the block diagram and / or flow chart can be implemented with a dedicated hardware-based system that performs the specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.
[0121] The embodiments of the present invention have been described above, and the above description is exemplary, not exhaustive, and is not limited to the disclosed embodiments. Many modifications and variations will be apparent to those of ordinary skill in the art without departing from the scope and spirit of the described embodiments. The terms used herein are selected to best explain the principles of the embodiments, practical applications, or improvements to the technology in the market, or to enable other persons of ordinary skill in the art to understand the embodiments disclosed herein.
Claims
1. A data processing method, comprising: Obtain an encryption result of a part of data x and a part of data y encrypted by the partner using the first private key, where the encryption result is obtained by the partner performing homomorphic encryption; combining the obtained encryption result with another part of the obtained data x and another part of the obtained data y, respectively, the combined result including the partially encrypted and partially unencrypted data x and the partially encrypted and partially unencrypted data y respectively subjected to homomorphic operation; Generate a result of performing an operation on each of the combined results in a disrupted order and a random number as a disturbance result; as well as Send the perturbation result to the partner for the partner to decrypt the perturbation result. The generating of the operation results of the combination results in the disrupted order and the random number as the disturbance result includes: the order of the results of the operations of the perturbation combination results and the random numbers; or Perturb the order of the combined results and then operate them with the random number.
2. The method of claim 1, further comprising: Encrypting the random number and sending it to the partner for the partner to perform secondary disturbance on the data; as well as Get the result of the secondary perturbation and decrypt it.
3. The method of claim 1, wherein: The secondary disturbances to the data by the partners include: Perform an inverse operation on the decryption result and the obtained random number encryption result; Generate the result of the inverse operation result with the scrambled order and the operation result of the partner's random number as the secondary perturbation result.
4. The method of claim 3, wherein: The encryption result obtained by the partner of encrypting a part of data x and a part of data y includes: Obtain a portion x2 of the data x used for cooperation by the partner, wherein the partner divides the data x used for cooperation into x1 and x2; Split the data y used for cooperation into y1 and y2, and send y1 to the partner; The partner uses the first private key to homomorphically encrypt x1 and y1 to obtain Enc(x1) and Enc(y1). Combining the obtained encryption result with another part of the obtained data x and another part of the obtained data y respectively comprises: Perform homomorphic operations on Enc(x1) and x2, and Enc(y1) and y2 respectively to obtain Enc(x) and Enc(y). The results of the operations of generating the scrambled combination results and the random numbers include: Generate a first operation result of performing a first operation on Enc(x) and Enc(y) in a scrambled order and random numbers R and S; The perturbation result is sent to the partner, and the partner's decryption of the perturbation result includes: The first operation result thus generated is sent back to the partner, and the partner decrypts the first operation result using the first private key to obtain a second operation result of performing the first operation on R and S respectively with the scrambled x and y.
5. The method of claim 4, wherein: Splitting the data x for cooperation into x1 and x2, and splitting the data y for cooperation into y1 and y2 includes: Perform additive secret sharing on data x: x = x1 + x2 mod q; and Add the data y to share the secret: y = y1 + y2 mod q, Obtaining the homomorphic encryption of x1 and y1 by the partner using the first private key to obtain Enc(x1) and Enc(y1) includes: Perform additive homomorphic encryption on x1 using the first private key to obtain Enc(x1); and Use the first private key to perform additive homomorphic encryption on y1 to obtain Enc(y1). Perform homomorphic operations on Enc(x1) and x2, and Enc(y1) and y2, respectively, to obtain Enc(x) and Enc(y), including: Performing homomorphic addition operations on Enc(x1) and x2 to obtain Enc(x); and Perform addition homomorphic operation on Enc(y1) and y2 to obtain Enc(y).
6. The method of claim 4, wherein: Splitting the data x for cooperation into x1 and x2, and splitting the data y for cooperation into y1 and y2 includes: Perform multiplication secret sharing on the data x: x = x1*x2modq; and Perform multiplication secret sharing on the data y: y = y1*y2modq, Obtaining the homomorphic encryption of x1 and y1 by the partner using the first private key to obtain Enc(x1) and Enc(y1) includes: Use the first private key to perform multiplication homomorphic encryption on x1 to obtain Enc(x1); and Use the first private key to perform multiplication homomorphic encryption on y1 to obtain Enc(y1). Perform homomorphic operations on Enc(x1) and x2, and Enc(y1) and y2, respectively, to obtain Enc(x) and Enc(y), including: Perform homomorphic multiplication operation on Enc(x1) and x2 to obtain Enc(x); and Perform homomorphic multiplication operation on Enc(y1) and y2 to obtain Enc(y).
7. The method of claim 4, wherein: The random number is encrypted and sent to the partner, and the partner's secondary disturbance of the data includes: Use the second private key to homomorphically encrypt R and S to obtain Enc'(R) and Enc'(S); Send Enc'(R) and Enc'(S) to the partner, and the partner performs the inverse operation of the first operation on Enc'(R) and Enc'(S) with the second operation result, Obtaining the results of the secondary perturbation and decrypting them includes: Obtaining a third operation result, wherein the partner generates a third operation result of performing a second operation on Enc'(x) and Enc'(y) that have been scrambled twice and the random numbers M and N; The third operation result is decrypted using the second private key to obtain a fourth operation result of performing a second operation on M and N respectively with x and y that have been scrambled twice.
8. The method of claim 7, wherein: Generating a first operation result of performing a first operation on Enc(x) and Enc(y) in a scrambled order and random numbers R and S includes: Randomly disrupt the order of Enc(x) and Enc(y), generate random numbers R and S, and perform a first operation on R and S respectively with the disrupted Enc(x) and Enc(y); or Generate random numbers R and S, perform a first operation on R and S respectively with Enc(x) and Enc(y), and randomly shuffle the order of Enc(x) and Enc(y) after the first operation.
9. The method of claim 8, wherein: The third operation result of generating the second operation of Enc'(x) and Enc'(y) which have been twice shuffled and the random numbers M and N comprises: Randomly shuffle the order of Enc'(x) and Enc'(y) twice to generate random numbers M and N, and perform a second operation on M and N respectively with Enc'(x) and Enc'(y) which have been shuffled twice to obtain a third operation result; or Generate random numbers M and N, perform a third operation on M and N respectively with the shuffled Enc'(x) and Enc'(y), randomly shuffle the order of Enc'(x) and Enc'(y) after the second operation, and obtain a third operation result.
10. The method of claim 7, wherein: Splitting the data x for collaboration into x1 and x2 includes: Split the multiple pieces of data x used for cooperation into x1 and x2, and Splitting the data y for collaboration into y1 and y2 includes: Split the multiple pieces of data y used for cooperation into y1 and y2, and Randomly disrupting the order of Enc(x) and Enc(y) includes: Randomly shuffle the order of multiple Enc(x) and Enc(y) so that the data from both sides are mixed and randomly sorted. The order of Enc'(x) and Enc'(y) after the scrambled order is randomly scrambled twice including: The two data that have been mixed and randomly sorted are randomly mixed and sorted again.
11. The method of claim 10, wherein: Generating a first operation result of performing a first operation on Enc(x) and Enc(y) in a scrambled order and random numbers R and S includes: For each piece of data contained in Enc(x) and Enc(y), a random number is randomly generated for each piece of data to perform the first operation. The third operation result of generating the second operation of Enc'(x) and Enc'(y) which have been twice shuffled and the random numbers M and N comprises: For each piece of data included in Enc'(x) and Enc'(y), a random number is randomly generated to perform the second operation.
12. A data processing system, comprising a party A and a party B participating in a secure two-party computation using data x and data y respectively, wherein: Party A homomorphically encrypts part of data x and part of acquired data y using the first key; Party B combines the obtained encryption result with another part of the obtained data x and another part of the obtained data y, respectively, and the combined result includes the partially encrypted and partially unencrypted data x and the partially encrypted and partially unencrypted data y that are respectively subjected to homomorphic operations; Party B generates the results of operations of the shuffled combination results and the random numbers as the disturbance results; Party A decrypts the obtained disturbance results. Wherein, Party B generates the operation results of each of the combination results in the disrupted order and the random number as the disturbance result, including: The order of the calculation results of the perturbation combination results of Party B and the random numbers; or Party B perturbs the order of the combination results and then calculates them with the random numbers.
13. The system of claim 12, wherein: Party B encrypts the random number for Party A to perform secondary disturbance on the data. Among them, Party A's secondary disturbance of the data includes: Party A performs an inverse operation on the decrypted result and the obtained random number encryption result; Party A generates the result of the inverse operation with the scrambled order and the operation result of Party A's random number as the secondary perturbation result, and Party B decrypts the secondary disturbance results.
14. The system of claim 13, wherein: The encryption performed by Party A and Party B is homomorphic encryption, and the data segmentation and operation are combined with secret sharing of segmentation and operation rules.
15. The system of claim 14, wherein: Party A splits the data x into x1 and x2 through secret sharing; Party B splits the data y into y1 and y2 by secret sharing, and Party A homomorphically encrypts part of data x and part of acquired data y, including: Party A obtains y1 and uses the first private key to homomorphically encrypt x1 and y1 to obtain Enc(x1) and Enc(y1). Party B combines the obtained encryption result with another part of the obtained data x and another part of the obtained data y respectively, including: Party B obtains x2, Enc(x1) and Enc(y1), and performs homomorphic operations on Enc(x1) and x2, and Enc(y1) and y2, respectively, to obtain Enc(x) and Enc(y). Party B generates the results of the operations of the shuffled combination results and the random numbers, as the disturbance results, including: Party B generates a first operation result of performing a first operation on Enc(x) and Enc(y) in a scrambled order and random numbers R and S, Party A decrypts the obtained disturbance results including: Party A uses the first private key to decrypt the first operation result, and obtains the second operation result of performing the first operation on R and S respectively with the scrambled x and y. Party B encrypts the random number including: Party B uses the second private key to homomorphically encrypt R and S to obtain Enc'(R) and Enc'(S). Party A performs an inverse operation on the decrypted result and the obtained random number encryption result, including: Party A obtains Enc'(R) and Enc'(S), and performs the inverse operation of the first operation on Enc'(R) and Enc'(S) and the result of the second operation to obtain Enc'(x) and Enc'(y) in a scrambled order; Party A generates the result of the inverse operation after the order is disrupted and performs the operation on Party A's random number, which includes: Party A generates a third operation result of performing a second operation on Enc'(x) and Enc'(y) which have been shuffled twice and the random numbers M and N; and Party B's decryption of the secondary disturbance results includes: Party B uses the second private key to decrypt the third operation result, and obtains a fourth operation result of performing the second operation on M and N respectively with x and y after the second scrambling.
16. The system of claim 15, wherein: The first operation result of the first operation performed by Party B on the Enc(x) and Enc(y) generated in a scrambled order and the random numbers R and S includes: Party B randomly shuffles the order of Enc(x) and Enc(y) and generates two random numbers R and S; Party B performs a first operation on R and S respectively with the scrambled Enc(x) and Enc(y), and sends the generated first operation result back to Party A, or Party B generates random numbers R and S, and performs a first operation on R and S with Enc(x) and Enc(y) respectively; Party B randomly shuffles the order of Enc(x) and Enc(y) after the first operation.
17. The system of claim 15, wherein: The third operation result of the second operation of Enc'(x) and Enc'(y) generated by Party A and the random numbers M and N includes: Party A randomly shuffles the order of Enc'(x) and Enc'(y) again and generates two random numbers M and N; Party A performs the second operation on M and N respectively with Enc'(x) and Enc'(y) which have been shuffled twice, and sends the generated third operation result back to Party B, or Party A generates random numbers M and N, and performs a third operation on M and N respectively with Enc'(x) and Enc'(y) in a scrambled order; The order of Enc'(x) and Enc'(y) after the second operation is randomly disrupted twice to obtain a third operation result.
18. The system of claim 17, wherein: The system performs secure two-party computation using M and N held by Party A and the fourth operation result held by Party B, respectively.
19. A computing device comprising: processor; as well as A memory having executable codes stored thereon, which, when executed by the processor, causes the processor to execute the method according to any one of claims 1 to 11.
20. A non-transitory machine-readable storage medium having executable codes stored thereon, which, when executed by a processor of an electronic device, causes the processor to execute the method according to any one of claims 1 to 11.
Citation Information
Patent Citations
Data processing method and device, data identification method and device and medium
CN109756459A
Gradients over distributed datasets
US20170310643A1