A method and device for calculating group statistical parameters based on privacy protection

By encoding the packet information and using the secret sharing algorithm, the unfairness of the participants in the statistical status of the grouping statistical value calculation method in the prior art is solved, and the right to use the information encryption and equal calculation operation of the packet statistics results is realized.

CN114640436BActive Publication Date: 2025-05-09TONGDUN NETWORK TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210126432.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-02-10
Publication Date
2025-05-09
Estimated Expiration
2042-02-10

AI Technical Summary

Technical Problem

The existing packet statistical value calculation method based on homomorphic encryption cannot guarantee the fairness of the statistical status of data holding institutions and packet information holding institutions, and it is difficult to achieve the right to use the information encryption and equal calculation operation of the packet statistical results of each participant.

Method used

By encoding the packet information, a normalized packet encoding matrix is ​​generated, and a secret sharing algorithm is used to enable the first and second participants to generate a random matrix and a random vector, and then calculate the statistical parameter ciphertext, and finally recover the packet statistical parameters through the secret sharing algorithm.

Benefits of technology

The information is encrypted by all participants, and the equal computing operation and use rights of the final group statistics are ensured, avoiding the unfairness of the statistical status of data holding institutions and group information holding institutions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114640436B_ABST
    Figure CN114640436B_ABST
Patent Text Reader

Abstract

The present application relates to a method and device for calculating group statistical parameters based on privacy protection. The method includes: the first participant encodes the group information to generate a normalized group coding matrix; the first participant and the second participant secretly share the normalized group coding matrix and the sample numerical vector; the first participant generates a first random matrix, and converts it into a first key matrix and sends it to the second participant, the second participant generates a first random vector, and converts it into a first key vector and sends it to the first participant; the first participant obtains a first statistical parameter ciphertext according to the first random matrix and the first key vector, and the second participant obtains a second statistical parameter ciphertext according to the first key matrix and the first random vector; the first participant and the second participant respectively recover the group statistical parameters according to the statistical parameter ciphertext through a secret sharing algorithm. The use of this method can ensure the security of the statistical data of all parties.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of data statistics technology, and in particular to a method and device for calculating group statistical parameters based on privacy protection. Background Art

[0002] With the development of statistics, grouped statistical value calculation technology is widely used in scenarios such as indicator system construction and data analysis. Grouped statistical value calculation means: given a piece of data and the corresponding sample grouping information, the statistical value of the samples in each group is calculated, including the sample sum within the group, the sample mean within the group, and the sample variance within the group. In practical applications, there is often a situation where the data is stored in institution A and the sample grouping information is stored in institution B. Both the data and the grouping information are private information of each institution and are not intended to be obtained by other institutions. For example, suppose there are two institutions A and B involved in grouped statistical value calculation; institution A holds the sample grouping information; institution B holds the input value required for statistical value calculation. In the process of data transmission and calculation, in order to ensure data privacy and security, it is often required that while institution B obtains the statistical value of the grouped sample, the grouping information of institution A is not leaked, that is, institution B cannot infer the grouping information owned by institution A, and institution A cannot infer the value of a single sample of institution B.

[0003] Typically, a method based on homomorphic encryption is used to calculate privacy-preserving group statistics. In this method, the data holding agency generates a homomorphic encryption public-private key pair, and transmits the data to the group information holding agency after homomorphic encryption. The group information holding agency then performs statistical calculations on the homomorphic ciphertext, obtains the homomorphic ciphertext statistical results, and transmits them to the data holding agency for decryption. Finally, the data holding agency obtains the group statistical results.

[0004] However, in this method of calculating group statistical values ​​based on homomorphic encryption, the group information holding agency needs to obtain the key from the data holding agency before obtaining the group statistical results. The data holding agency will inevitably obtain the group statistical results. This calculation method cannot guarantee the fairness of the statistical status of the data holding agency and the group information holding agency.

[0005] Therefore, there is an urgent need for a group statistical parameter calculation method that can encrypt the information owned by each participant and allow each participant to have equal computing and operation rights over the final group statistical results. Summary of the invention

[0006] Based on this, it is necessary to provide a method and device for calculating group statistical parameters that can encrypt the information owned by each participant and enjoy equal calculation and operation rights on the final group statistical results in response to the above technical problems.

[0007] A method for calculating group statistical parameters based on privacy protection, the method comprising:

[0008] Encode the group information to generate a normalized group coding matrix;

[0009] The first participant generates a first random matrix, converts it into a first key matrix associated with the normalized block coding matrix, and sends the first key matrix to the second participant;

[0010] The second participant generates a first random vector, converts it into a first key vector associated with the sample numerical vector, and sends the first key vector to the first participant;

[0011] The first participant obtains a first statistical parameter ciphertext according to the first random matrix and the first key vector;

[0012] The second participant obtains a second statistical parameter ciphertext according to the first key matrix and the first random vector;

[0013] The group statistical parameters are recovered by using a secret sharing algorithm according to the first statistical parameter ciphertext and the second statistical parameter ciphertext.

[0014] In one embodiment, encoding the group information to generate a normalized group coding matrix includes:

[0015] Create a matrix G(M, K), where M is the number of individuals in the population, K is the number of groups, and the element values ​​in the matrix G are 0 or 1;

[0016] The normalized group coding matrix H is calculated according to the matrix G. The calculation formula for the value of each element in the normalized group coding matrix H is:

[0017]

[0018] Where m represents the number of individuals in the population, m=1,2,…,M, a single individual can fall into multiple groups, k represents the sequence number of the group, k=1,2,…,K, j represents the number of individuals in the group with sequence number k, j=1,2,…,M, G[j,k] represents the value of the element with sequence number j in the group with sequence number k in the matrix G, sum_j(G[j,k]) represents the sum of the values ​​of all elements in the group with sequence number k in the matrix G; if the individual with sequence number m is in the group with sequence number k, then the value of G[m,k] is 1, if the individual with sequence number m is not in the group with sequence number k, then the value of G[m,k] is 0.

[0019] In one embodiment, the first participant generates a first random matrix, converts it into a first key matrix related to a normalized group coding matrix, and sends the first key matrix to the second participant, including: the first participant generates a first random matrix H_A of the same size as the normalized group coding matrix H, subtracts the normalized group coding matrix H from the first random matrix H_A to obtain a first key matrix H_B, and sends the first key matrix H_B to the second participant; the second participant generates a first random vector, converts it into a first key vector related to a sample numerical vector, and sends the first key vector to the first participant, including: the second participant generates first random vectors X_B and X^2_B, subtracts the sample numerical vector X from the first random vectors X_B and X^2_B to obtain first key vectors X_A and X^2_A, and sends the first key vectors X_A and X^2_A to the first participant.

[0020] In one embodiment, the first participant obtains a first statistical parameter ciphertext according to a first random matrix and a first key vector, including: the first participant obtains a first statistical parameter ciphertext R_A according to the transpose of the first random matrix H_A and multiplies the first key vector X_A; wherein the first statistical parameter ciphertext is a first mean ciphertext; the second participant obtains a second statistical parameter ciphertext according to the first key matrix and the first random vector, including: the second participant obtains a second statistical parameter ciphertext R_B according to the transpose of the first key matrix H_B and multiplies the first random vector X_B; wherein the second statistical parameter ciphertext is a second mean ciphertext; the method of recovering the group statistical parameters according to the first statistical parameter ciphertext and the second statistical parameter ciphertext through a secret sharing algorithm includes: the first participant recovers the group mean according to the first mean ciphertext and the second statistical parameter ciphertext through a secret sharing algorithm, and the second participant recovers the group mean according to the first statistical parameter ciphertext and the second mean ciphertext through a secret sharing algorithm.

[0021] In one embodiment, the above-mentioned group statistical parameter calculation method based on privacy protection further includes:

[0022] The first participant calculates a first ciphertext square mean value based on the first random matrix and the first key vector, and the second participant calculates a second ciphertext square mean value based on the first key matrix and the first random vector;

[0023] The third party generates a related second random vector and a third random vector, sends the third random vector to the first party, and then calculates a second key vector based on the second random vector and the third random vector and sends it to the second party;

[0024] The first participant calculates a first intermediate value ciphertext according to the first statistical parameter ciphertext and the third random vector, and sends the first intermediate value ciphertext to the second participant;

[0025] The second participant calculates a second intermediate value ciphertext based on the second statistical parameter ciphertext and the second key vector, and sends the second intermediate value ciphertext to the first participant;

[0026] The first participant and the second participant respectively recover the first intermediate value plaintext based on the first intermediate value ciphertext and the second intermediate value ciphertext through a secret sharing algorithm;

[0027] The first participant calculates the ciphertext of the first mean square according to the first intermediate value plaintext, the first statistical parameter ciphertext, the first intermediate value ciphertext and the third random vector, and then calculates the ciphertext of the first variance according to the mean of the square of the first ciphertext and the ciphertext of the square of the first mean;

[0028] The second participant calculates the ciphertext of the second squared mean according to the first intermediate value plaintext, the second statistical parameter ciphertext, the second intermediate value ciphertext and the second key vector, and then calculates the ciphertext of the second variance according to the second ciphertext squared mean and the ciphertext of the second squared mean;

[0029] The first participant recovers the group variance based on the ciphertext of the first variance and the ciphertext of the second variance through a secret sharing algorithm, and the second participant recovers the group variance based on the ciphertext of the first variance and the ciphertext of the second variance through a secret sharing algorithm.

[0030] In one embodiment, the first key vectors X_A and X^2_A are obtained by subtracting the sample numerical vector X from the first random vectors X_B and X^2_B, and the first random vectors X_B and X^2_B are generated by the second participant; the first key matrix H_B is obtained by subtracting the normalized group coding matrix H from the first random matrix H_A, and the first random matrix H_A is generated by the first participant, and the first random matrix H_A is the same size as the normalized group coding matrix H; the first participant calculates the first ciphertext square mean based on the first random matrix and the first key vector, and the second participant calculates the second ciphertext square mean based on the first key matrix and the first random vector, including: the first participant multiplies the transpose of the first random matrix H_A with the first key vector X^2_A to obtain the first ciphertext square mean T_A, and the second participant multiplies the first key matrix H_B with the first random vector X^2_B to obtain the second ciphertext square mean T_B.

[0031] In one of the embodiments, the third party generates a related second random vector and a third random vector, sends the third random vector to the first party, and then calculates a second key vector based on the second random vector and the third random vector and sends it to the second party, including: the third party generates second random vectors C_a, C_b and third random vectors C_a_A, C_b_A, sends the third random vectors C_a_A, C_b_A to the first party, subtracts the second random vectors C_a, C_b from the third random vectors C_a_A, C_b_A to obtain second key vectors C_a_B, C_b_B, and sends the second key vectors C_a_B, C_b_B to the second party; wherein C_b=C_a×C_a.

[0032] In one embodiment, the first participant calculates a first intermediate value ciphertext based on the first statistical parameter ciphertext and the third random vector, and sends it to the second participant, including: the first participant subtracts the first statistical parameter ciphertext R_A from C_a_A in the third random vector to obtain a first intermediate value ciphertext D_a_A, and sends it to the second participant; the second participant calculates a second intermediate value ciphertext based on the second statistical parameter ciphertext and the second key vector, and sends it to the first participant, including: the second participant subtracts the second statistical parameter ciphertext R_B from C_a_B in the second key vector to obtain a second intermediate value ciphertext D_a_B, and sends it to the first participant; wherein the first participant recovers the first intermediate value plaintext D_a based on the first intermediate value ciphertext D_a_A and the second intermediate value ciphertext D_a_B through a secret sharing algorithm, and the second participant recovers the first intermediate value plaintext D_a based on the first intermediate value ciphertext D_a_A and the second intermediate value ciphertext D_a_B through a secret sharing algorithm.

[0033] In one embodiment, the first participant calculates the first mean square ciphertext according to the first intermediate value plaintext, the first statistical parameter ciphertext, the first intermediate value ciphertext and the third random vector, and then calculates the first variance ciphertext according to the first ciphertext square mean and the first mean square ciphertext, including: the first participant calculates the first mean square ciphertext S_A according to the first intermediate value plaintext D_a, the first statistical parameter ciphertext R_A, the first intermediate value ciphertext D_a_A and C_b_A in the third random vector, and the formula is:

[0034] S_A=D_a×R_A+D_a×D_a_A+C_b_A;

[0035] The first participant subtracts the first ciphertext square mean T_A from the ciphertext of the first mean square S_A to obtain the ciphertext of the first variance U_A.

[0036] In one embodiment, the second party calculates a ciphertext of the second mean square according to the first intermediate value plaintext, the second statistical parameter ciphertext, the second intermediate value ciphertext and the second key vector, and then calculates a ciphertext of the second variance according to the second ciphertext square mean and the second mean square ciphertext, including:

[0037] The second participant calculates the second mean square ciphertext S_B according to the first intermediate value plaintext D_a, the second statistical parameter ciphertext R_B, the second intermediate value ciphertext D_a_B and the second key vector C_b_B, and the formula is:

[0038] S_B=D_a×R_B+D_a×D_a_B+C_b_B;

[0039] The second participant subtracts the second ciphertext square mean T_B from the ciphertext of the second mean square S_B to obtain the ciphertext of the second variance U_B.

[0040] A group statistical parameter calculation device based on privacy protection, the device comprising:

[0041] The encoding module is used to encode the group information to generate a normalized group encoding matrix;

[0042] A first key sending module, used for the first participant to generate a first random matrix, convert it into a first key matrix related to the normalized block coding matrix, and send the first key matrix to the second participant;

[0043] A second key sending module, used for the second participant to generate a first random vector, convert it into a first key vector related to the sample numerical vector, and send the first key vector to the first participant;

[0044] A first parameter ciphertext calculation module, used by the first participant to obtain a first statistical parameter ciphertext according to a first random matrix and a first key vector;

[0045] A second parameter ciphertext calculation module, used by the second participant to obtain a second statistical parameter ciphertext according to the first key matrix and the first random vector;

[0046] The decryption module is used to recover the group statistical parameters according to the first statistical parameter ciphertext and the second statistical parameter ciphertext through a secret sharing algorithm.

[0047] A computer device comprises a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, the following steps are implemented:

[0048] Encode the group information to generate a normalized group coding matrix;

[0049] The first participant generates a first random matrix, converts it into a first key matrix associated with the normalized block coding matrix, and sends the first key matrix to the second participant;

[0050] The second participant generates a first random vector, converts it into a first key vector associated with the sample numerical vector, and sends the first key vector to the first participant;

[0051] The first participant obtains a first statistical parameter ciphertext according to the first random matrix and the first key vector;

[0052] The second participant obtains a second statistical parameter ciphertext according to the first key matrix and the first random vector;

[0053] The group statistical parameters are recovered by using a secret sharing algorithm according to the first statistical parameter ciphertext and the second statistical parameter ciphertext.

[0054] A computer-readable storage medium stores a computer program, which, when executed by a processor, implements the following steps:

[0055] Encode the group information to generate a normalized group coding matrix;

[0056] The first participant generates a first random matrix, converts it into a first key matrix associated with the normalized block coding matrix, and sends the first key matrix to the second participant;

[0057] The second participant generates a first random vector, converts it into a first key vector associated with the sample numerical vector, and sends the first key vector to the first participant;

[0058] The first participant obtains a first statistical parameter ciphertext according to the first random matrix and the first key vector;

[0059] The second participant obtains a second statistical parameter ciphertext according to the first key matrix and the first random vector;

[0060] The group statistical parameters are recovered by using a secret sharing algorithm according to the first statistical parameter ciphertext and the second statistical parameter ciphertext.

[0061] The above-mentioned privacy-protection-based group statistical parameter calculation method, device, computer equipment and storage medium, when calculating the group statistical value, encodes the group information by the first participant, and then shares it with the second participant through a secret sharing method. The second participant shares the sample value with the first participant through a secret sharing method, and then the two parties send key data to each other, calculate the statistical parameter ciphertext according to the key data, and finally obtain the group statistical parameters by decryption. The first party and the second party can both obtain the group statistical parameters without affecting the privacy security of the data, thereby ensuring that the first party and the second party have equal computing operation rights over the final group statistical results.

[0062] The technical solution of the present application is that both parties calculate the key data about the statistical parameters without knowing the other party's data. Compared with the homomorphic encryption method, it can support subsequent extended calculations without affecting the accuracy of the results, obtain group statistical parameters faster, and have higher calculation efficiency. The technical basis of the present application is a secret sharing algorithm, which can support a variety of security protocols, including the precise comparison protocol; at the same time, the statistical results can be kept in a fragmented state of secret sharing, which is convenient for direct use in subsequent multi-party secure computing operations, and can also be restored to any participant, and the other participant remains unaware of the group statistical results, which is convenient and fair. BRIEF DESCRIPTION OF THE DRAWINGS

[0063] Figure 1 A schematic diagram of a flow chart of a method for calculating group statistical parameters based on privacy protection in an embodiment;

[0064] Figure 2 It is a flowchart of a method for calculating group statistical parameters based on privacy protection in another embodiment;

[0065] Figure 3 is a structural block diagram of a group statistical parameter calculation device based on privacy protection in one embodiment;

[0066] Figure 4 FIG. 4 is a diagram showing the internal structure of a computer device in one embodiment. DETAILED DESCRIPTION

[0067] In order to make the purpose, technical solution and advantages of the present application more clearly understood, the present application is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0068] In one embodiment, Figure 1 As shown, a method for calculating group statistical parameters based on privacy protection is provided, comprising the following steps:

[0069] S110, encoding the group information to generate a normalized group encoding matrix.

[0070] The first participant is the owner of the grouping information, such as the institution A in the background technology, which holds the sample grouping information, that is, the number of groups and the samples in each group. The encoding method is to encode according to the samples in each group after grouping. The size of the normalized group encoding matrix is ​​(M, K), where M is the number of individuals in the population and K is the number of groups. The value of each element in the normalized group encoding matrix is ​​related to the number of individuals in the group.

[0071] Among them, the first participant sends the normalized group coding matrix to the second participant through the secret sharing algorithm, and the second participant sends the sample numerical vector to the first participant through the secret sharing algorithm. Among them, secret sharing (Secret-Sharing) is an important branch in the field of modern cryptography, an important means in information security and data confidentiality, and a basic application technology in the fields of multi-party secure computing and federated learning. In practical applications, it plays an important role in key management, digital signatures, identity authentication, multi-party secure computing, error correction codes, bank network management and data security. Secret sharing is a technology for sharing secrets among a group of participants. It is mainly used to protect important information and prevent information from being lost, destroyed, or tampered with. It originated from classical cryptographic theory and was first proposed by Sharmir and Blakley in 1979. Simply put, secret sharing refers to the reasonable distribution of shared secrets in a user group to achieve the purpose of all members jointly managing the secret. The secret sharing algorithm can be the Shamir algorithm, of course, other secret sharing algorithms can also be used.

[0072] The second participant is the owner of the sample values, such as institution B in the background technology, and institution B holds the input values ​​required for calculating the statistical values.

[0073] S120, the first participant generates a first random matrix, converts the first random matrix into a first key matrix related to the normalized block coding matrix, and sends the first key matrix to the second participant.

[0074] S130, the second participant generates a first random vector, converts the first random vector into a first key vector related to the sample numerical vector, and sends the first key vector to the first participant.

[0075] S140, the first participant obtains a first statistical parameter ciphertext according to the first random matrix and the first key vector.

[0076] S150, the second participant obtains a second statistical parameter ciphertext according to the first key matrix and the first random vector.

[0077] S150, recovering the group statistical parameters according to the first statistical parameter ciphertext and the second statistical parameter ciphertext by using a secret sharing algorithm.

[0078] The first participant can recover the group statistical parameters based on the first statistical parameter ciphertext (fragmented group statistical parameters) through a secret sharing algorithm. The second participant can recover the group statistical parameters based on the second statistical parameter ciphertext (fragmented group statistical parameters) through a secret sharing algorithm.

[0079] At this time, the first participant can recover the group statistical parameters based on the random number sent by the second participant and through the secret sharing algorithm. At this time, the second participant can recover the group statistical parameters based on the random number sent by the first participant and through the secret sharing algorithm. Of course, the random number can also be generated by a third party and sent to the first participant and the second participant respectively to obtain the group statistical parameters.

[0080] Among them, the group statistical parameters include group sum, group mean and group variance.

[0081] The above-mentioned privacy-protection-based group statistical parameter calculation method, device, computer equipment and storage medium, when calculating the group statistical value, encodes the group information by the first participant, and then shares it with the second participant through a secret sharing algorithm. The second participant shares the sample value with the first participant through the secret sharing algorithm, and then the two parties send key data to each other, calculate the statistical parameter ciphertext according to the key data, and finally obtain the group statistical parameters by decryption. The first party and the second party can both obtain the group statistical parameters without affecting the privacy security of the data, thereby ensuring that the first party and the second party have equal computing operation rights over the final group statistical results.

[0082] The technical solution of the present application is that both parties calculate the key data about the statistical parameters without knowing the other party's data. Compared with the homomorphic encryption method, it can support subsequent extended calculations without affecting the accuracy of the results, obtain group statistical parameters faster, and have higher calculation efficiency. The technical basis of the present application is a secret sharing algorithm, which can support a variety of security protocols, including the precise comparison protocol; at the same time, the statistical results can be kept in a fragmented state of secret sharing, which is convenient for direct use in subsequent multi-party secure computing operations, and can also be restored to any participant, and the other participant remains unaware of the group statistical results, which is convenient and fair.

[0083] In one embodiment, encoding the group information to generate a normalized group coding matrix includes: calculating a normalized group coding matrix H according to a matrix G, and a calculation formula for the value of each element in the normalized group coding matrix H is:

[0084]

[0085] Where m represents the number of individuals in the population, m=1,2,…,M, a single individual can fall into multiple groups, k represents the sequence number of the group, k=1,2,…,K, j represents the number of individuals in the group with sequence number k, j=1,2,…,M, G[j,k] represents the value of the element with sequence number j in the group with sequence number k in the matrix G, sum_j(G[j,k]) represents the sum of the values ​​of all elements in the group with sequence number k in the matrix G; if the individual with sequence number m is in the group with sequence number k, then the value of G[m,k] is 1, if the individual with sequence number m is not in the group with sequence number k, then the value of G[m,k] is 0.

[0086] For example, there is a population, including four individuals A, B, C, and D. A, B, C, and D are numbered 1, 2, 3, and 4 respectively. A and B are divided into the first group. A and B correspond to the first and second elements of the first group respectively, and the first and second elements are both 1. C and D correspond to the third and fourth elements of the first group respectively. C and D are not in the first group. The third and fourth elements are both 0. The first group represents

[1100] ; C and D are divided into the second group. A and B correspond to the first and second elements of the second group respectively. A and B are not in the second group. The first and second elements are both 0. C and D correspond to the third and fourth elements of the second group respectively. The third and fourth elements are both 1. The second group represents

[0011] ; the matrix G is established as follows: G[1,1]=1, G[2,1]=1, G[3,1]=0, G[4,1]=0, G[1,2]=0, G[2,2]=0, G[3,2]=1, G[4,2 ]=1, H[1,1]=G[1,1] / (G[1,1]+G[2,1]+G[3,1]+G[4,1])=1 / (1+1+0+0)=0.5, H[2, 1]=G[2,1] / (G[1,1]+G[2,1]+G[3,1]+G[4,1])=1 / (1+1+0+0)=0.5, H[3,1]=G[3,1 ] / (G[1,1]+G[2,1]+G[3,1]+G[4,1])=0 / (1+1+0+0)=0, H[4,1]=G[4,1] / (G[1,1]+ G[2,1]+G[3,1]+G[4,1])=0 / (1+1+0+0)=0, H[1,2]=G[1,2] / (G[1,2]+G[2,2]+G[3 ,2]+G[4,2])=0 / (0+0+1+1)=0, H[2,2]=G[2,2] / (G[1,2]+G[2,2]+G[3,2]+G[4,2] )=0 / (0+0+1+1)=0, H[3,2]=G[3,2] / (G[1,2]+G[2,2]+G[3,2]+G[4,2])=1 / (0+0+1 +1)=0.5, H[4,2]=G[4,2] / (G[1,2]+G[2,2]+G[3,2]+G[4,2])=1 / (0+0+1+1)=0.5.

[0087] For another example, there is a population, including four individuals A, B, C, and D. A, B, C, and D are numbered 1, 2, 3, and 4 respectively. A, B, and C are divided into the first group. A, B, and C correspond to the first element, the second element, and the third element of the first group respectively. The first element, the second element, and the third element are all 1. D corresponds to the fourth element of the first group. D is not in the first group, and the fourth element is 0. The first group represents

[1110] . A, C, and D are divided into the second group. A, C, and D correspond to the first element, the third element, and the fourth element of the second group respectively. The first element, the third element, and the fourth element are all 1. B corresponds to the second element of the second group. B is not in the second group, and the second element is 0. The second group represents

[1011] . The matrix G is established as follows: G[1,1]=1, G[2,1]=1, G[3,1]=1, G[4,1]=0, G[1,2]=1, G[2,2]=0, G[3,2]=1, G[4,2] =1, H[1,1]=G[1,1] / (G[1,1]+G[2,1]+G[3,1]+G[4,1])=1 / (1+1+1+0)=0.33, H[2,1 ]=G[2,1] / (G[1,1]+G[2,1]+G[3,1]+G[4,1])=1 / (1+1+1+0)=0.33, H[3,1]=G[3,1] / (G[1,1]+G[2,1]+G[3,1]+G[4,1])=1 / (1+1+1+0)=0.33, H[4,1]=G[4,1] / (G[1,1]+ G[2,1]+G[3,1]+G[4,1])=0 / (1+1+1+0)=0, H[1,2]=G[1,2] / (G[1,2]+G[2,2]+G[3, 2]+G[4,2])=1 / (1+0+1+1)=0.33, H[2,2]=G[2,2] / (G[1,2]+G[2,2]+G[3,2]+G[4,2 ])=0 / (1+0+1+1)=0, H[3,2]=G[3,2] / (G[1,2]+G[2,2]+G[3,2]+G[4,2])=1 / (1+0+1 +1)=0.33, H[4,2]=G[4,2] / (G[1,2]+G[2,2]+G[3,2]+G[4,2])=1 / (1+0+1+1)=0.33.

[0088] In one embodiment, the first participant generates a first random matrix, converts it into a first key matrix related to a normalized group coding matrix, and sends the first key matrix to the second participant, including: the first participant generates a first random matrix H_A of the same size as the normalized group coding matrix H, subtracts the normalized group coding matrix H from the first random matrix H_A to obtain a first key matrix H_B, and sends the first key matrix H_B to the second participant; the second participant generates a first random vector, converts it into a first key vector related to a sample numerical vector, and sends the first key vector to the first participant, including: the second participant generates first random vectors X_B and X^2_B, subtracts the sample numerical vector X from the first random vector by X_B and X^2_B to obtain first key vectors X_A and X^2_A, and sends the first key vectors X_A and X^2_A to the first participant.

[0089] There is no restriction on the way of taking values ​​of random matrices and random vectors, and they can be taken in a uniform distribution manner.

[0090] In one embodiment, the first participant obtains the first statistical parameter ciphertext according to the first random matrix and the first key vector, including: the first participant obtains the first statistical parameter ciphertext R_A by multiplying the first key vector X_A with the transposition of the first random matrix H_A; wherein the first statistical parameter ciphertext is the first mean ciphertext; the second participant obtains the second statistical parameter ciphertext according to the first key matrix and the first random vector, including: the second participant obtains the second statistical parameter ciphertext R_B by multiplying the first random vector X_B with the transposition of the first key matrix H_B; wherein the second statistical parameter ciphertext is the second mean ciphertext. The statistical parameter is recovered by the secret sharing algorithm based on the first statistical parameter ciphertext and the second statistical parameter ciphertext, including: the first participant recovers the group mean by the secret sharing algorithm based on the first mean ciphertext and the second statistical parameter ciphertext, and the second participant recovers the group mean by the secret sharing algorithm based on the first statistical parameter ciphertext and the second mean ciphertext.

[0091] Specifically, R_A = H_A^T*X_A, R_B = H_B^T*X_B. The group mean is the mean of the group of samples after grouping. The fragment matrix multiplication can be implemented using an existing security protocol, including but not limited to the beavertriple protocol.

[0092] In one of the embodiments, the above-mentioned group statistical parameter calculation method based on privacy protection also includes: the first participant calculates the square mean of the first ciphertext according to the first random matrix and the first key vector, and the second participant calculates the square mean of the second ciphertext according to the first key matrix and the first random vector; the third participant generates a related second random vector and a third random vector, sends the third random vector to the first participant, and then calculates the second key vector according to the second random vector and the third random vector and sends it to the second participant; the first participant calculates the first intermediate value ciphertext according to the first statistical parameter ciphertext and the third random vector, and sends it to the second participant; the second participant calculates the second intermediate value ciphertext according to the second statistical parameter ciphertext and the second key vector, and sends it to the first participant; the first participant and the second participant respectively calculate the first intermediate value ciphertext according to the first intermediate value ciphertext The ciphertext and the second intermediate value ciphertext are restored to the first intermediate value plaintext through the secret sharing algorithm; the first participant calculates the ciphertext of the square of the first mean based on the first intermediate value plaintext, the first statistical parameter ciphertext, the first intermediate value ciphertext and the third random vector, and then calculates the ciphertext of the first variance based on the mean of the square of the first ciphertext and the ciphertext of the square of the first mean; the second participant calculates the ciphertext of the square of the second mean based on the first intermediate value plaintext, the second statistical parameter ciphertext, the second intermediate value ciphertext and the second key vector, and then calculates the ciphertext of the second variance based on the mean of the square of the second ciphertext and the ciphertext of the square of the second mean; the first participant restores the group variance based on the ciphertext of the first variance and the ciphertext of the second variance through the secret sharing algorithm, and the second participant restores the group variance based on the ciphertext of the first variance and the ciphertext of the second variance through the secret sharing algorithm.

[0093] There is no limitation on the way of taking values ​​of the second random vector and the third random vector, and the values ​​can be taken in a uniform distribution manner, and the second random vector and the third random vector have the same size. The group variance is the variance of the group of samples after grouping. In this embodiment, the third party assists in generating a key to encrypt the data of the first party and the data of the second party again to obtain an intermediate value, and then calculates the ciphertext of the square of the mean and the ciphertext of the variance based on the intermediate value, and finally recovers the group variance through the secret sharing algorithm, and adopts a multiple encryption method through the third party to improve the security of the data.

[0094] In one embodiment, the first key vectors X_A and X^2_A are obtained by subtracting the sample numerical vector X from the first random vectors X_B and X^2_B respectively, and the first random vectors X_B and X^2_B are generated by the second participant; the first key matrix H_B is obtained by subtracting the normalized group coding matrix H from the first random matrix H_A, and the first random matrix H_A is generated by the first participant, and the first random matrix H_A is the same size as the normalized group coding matrix H.

[0095] The first participant calculates a first ciphertext square mean based on a first random matrix and a first key vector, and the second participant calculates a second ciphertext square mean based on the first key matrix and the first random vector, including: the first participant multiplies the transpose of the first random matrix H_A with the first key vector X^2_A to obtain the first ciphertext square mean T_A, and the second participant multiplies the first key matrix H_B with the first random vector X^2_B to obtain the second ciphertext square mean T_B.

[0096] In one of the embodiments, the third party generates a related second random vector and a third random vector, sends the third random vector to the first party, and then calculates a second key vector based on the second random vector and the third random vector and sends it to the second party, including: the third party generates second random vectors C_a, C_b and third random vectors C_a_A, C_b_A, sends the third random vectors C_a_A, C_b_A to the first party, subtracts the second random vectors C_a, C_b from the third random vectors C_a_A, C_b_A to obtain second key vectors C_a_B, C_b_B, and sends the second key vectors C_a_B, C_b_B to the second party; wherein C_b=C_a×C_a, and C_a×C_a represents element-wise multiplication.

[0097] In one embodiment, the first participant calculates a first intermediate value ciphertext based on the first statistical parameter ciphertext and the third random vector, and sends it to the second participant, including: the first participant subtracts the first statistical parameter ciphertext R_A from C_a_A in the third random vector to obtain a first intermediate value ciphertext D_a_A, and sends it to the second participant; the second participant calculates a second intermediate value ciphertext based on the second statistical parameter ciphertext and the second key vector, and sends it to the first participant, including: the second participant subtracts the second statistical parameter ciphertext R_B from C_a_B in the second key vector to obtain a second intermediate value ciphertext D_a_B, and sends it to the first participant; wherein the first participant recovers the first intermediate value plaintext D_a based on the first intermediate value ciphertext D_a_A and the second intermediate value ciphertext D_a_B through a secret sharing algorithm, and the second participant recovers the first intermediate value plaintext D_a based on the first intermediate value ciphertext D_a_A and the second intermediate value ciphertext D_a_B through a secret sharing algorithm.

[0098] In one embodiment, the first participant calculates a ciphertext of the first squared mean based on the first intermediate value plaintext, the first statistical parameter ciphertext, the first intermediate value ciphertext and the third random vector, and then calculates a ciphertext of the first variance based on the mean of the first ciphertext square and the ciphertext of the first squared mean, including: the first participant calculates a ciphertext of the first squared mean S_A based on the first intermediate value plaintext D_a, the first statistical parameter ciphertext R_A, the first intermediate value ciphertext D_a_A and C_b_A in the third random vector, and the formula is: S_A=D_a×R_A+D_a×D_a_A+C_b_A; the first participant subtracts the first ciphertext square mean T_A from the ciphertext S_A of the first squared mean to obtain a ciphertext of the first variance U_A.

[0099] In one embodiment, the second participant calculates the second mean square ciphertext according to the first intermediate value plaintext, the second statistical parameter ciphertext, the second intermediate value ciphertext and the second key vector, and then calculates the second variance ciphertext according to the second ciphertext square mean and the second mean square ciphertext, including: the second participant calculates the second mean square ciphertext S_B according to the first intermediate value plaintext D_a, the second statistical parameter ciphertext R_B, the second intermediate value ciphertext D_a_B and C_b_B in the second key vector, and the formula is: S_B=D_a×R_B+D_a×D_a_B+C_b_B; the second participant subtracts the second ciphertext square mean T_B from the second mean square ciphertext S_B to obtain the second variance ciphertext U_B.

[0100] In another specific embodiment, Figure 2As shown, a method for calculating group statistical parameters based on privacy protection includes: a first participant encodes group information to generate a normalized group coding matrix H; the first participant sends the normalized group coding matrix H to a second participant through a secret sharing algorithm, and the second participant sends a sample numerical vector X to the first participant through the secret sharing algorithm; the first participant generates a first random matrix H_A of the same size as the normalized group coding matrix H, subtracts the normalized group coding matrix H from the first random matrix to obtain a first key matrix H_B, and sends the first key matrix H_B to the second participant; the second participant generates first random vectors X_B and X^2_B, and sends the sample numerical vector X Subtract the first random vector to obtain the first key vector X_A and X^2_A, and send the first key vector X_A and X^2_A to the first participant; the first participant multiplies the first key vector X_A with the transpose of the first random matrix H_A to obtain the first statistical parameter ciphertext R_A; wherein the first statistical parameter ciphertext is the first mean ciphertext; the second participant multiplies the first random vector X_B with the transpose of the first key matrix H_B to obtain the second statistical parameter ciphertext R_B; wherein the second statistical parameter ciphertext is the second mean ciphertext; the first participant multiplies the first random matrix H_A with the first key vector X^2_A to obtain the first ciphertext square mean T_A, and the second participant A key matrix H_B is multiplied by the first random vector X^2_B to obtain the second ciphertext square mean T_B; the third participant generates the second random vectors C_a, C_b and the third random vectors C_a_A, C_b_A, sends the third random vectors C_a_A, C_b_A to the first participant, subtracts the second random vectors C_a, C_b from the third random vectors C_a_A, C_b_A to obtain the second key vectors C_a_B, C_b_B and sends them to the second participant; the first participant subtracts the first statistical parameter ciphertext R_A from the third random vector C_a_A to obtain the first intermediate value ciphertext D_a_A, and sends it to the second participant; the second participant subtracts the second statistical parameter ciphertext R_A from the third random vector C_a_A to obtain the first intermediate value ciphertext D_a_A, and sends it to the second participant; The ciphertext R_B is subtracted from the second key vector C_a_B to obtain the second intermediate value ciphertext D_a_B, and sent to the first participant; the first participant recovers the first intermediate value plaintext D_a through the secret sharing algorithm based on the second intermediate value ciphertext, and the second participant recovers the first intermediate value plaintext D_a through the secret sharing algorithm based on the first intermediate value ciphertext; the first participant calculates the first mean square ciphertext S_A based on the first intermediate value plaintext D_a, the first statistical parameter ciphertext R_A, the first intermediate value ciphertext D_a_A and the third random vector C_b_A; the first participant subtracts the first ciphertext square mean T_A from the first mean square ciphertext S_A to obtain the first variance ciphertext U_A;The second participant calculates the second mean square ciphertext S_B according to the first intermediate value plaintext D_a, the second statistical parameter ciphertext R_B, the second intermediate value ciphertext D_a_B and the second key vector C_b_B; the second participant subtracts the second ciphertext square mean T_B from the second mean square ciphertext S_B to obtain the second variance ciphertext U_B; the first and second participants recover the group mean plaintext and group variance plaintext according to the ciphertexts R_A, R_B, U_A and U_B through the secret sharing algorithm. ;

[0101] In a specific embodiment, institution A holds the affiliation information of personnel and companies (employee name, which company the employee belongs to), that is, grouping information G; institution B holds the credit score X (employee name, employee credit score) of the same personnel, and hopes to calculate the average and variance of the credit scores of personnel in each company, and the final result is obtained by institution A. Obviously, institution A cannot disclose the company affiliation information to institution B, and institution B cannot disclose the credit score to institution A. According to the grouping statistical parameter calculation method recorded in this application, the processing process is as follows:

[0102] a1, organization A encodes the group information G (in matrix form) to generate a normalized group coding matrix H;

[0103] a2, organization A fragments the normalized block coding matrix H through a secret sharing algorithm and then sends it to organization B;

[0104] a3, institution B uses a secret sharing algorithm to fragment and encode the credit score X (in vector form) of the person, and then sends it to institution A; a3 can be performed at the same time as a1 or a2.

[0105] a4, organization A generates a first random matrix H_A of the same size as the normalized block coding matrix H, subtracts the normalized block coding matrix H from the first random matrix H_A to obtain a first key matrix H_B, and sends the first key matrix H_B to organization B;

[0106] a5, institution B generates a first random vector X_B, X^2_B, and subtracts the person's credit score X from the first random vector X_B, X^2_B to obtain a first key vector X_A, X^2_A, and sends the first key vector X_A, X^2_A to institution A; wherein steps a4 and a5 are not in order and can be performed simultaneously;

[0107] a6, institution A obtains the first mean ciphertext R_A by multiplying the first key vector X_A by the transpose of the first random matrix H_A; at this point, institution A can recover the plaintext of the average credit score of each person in each company through the secret sharing algorithm;

[0108] a7, institution B obtains the second mean ciphertext R_B by multiplying the first random vector X_B by the transpose of the first key matrix H_B; wherein steps a6 and a7 are not in particular order and can be performed simultaneously;

[0109] a8, organization A multiplies the transpose of the first random matrix H_A and the first key vector X^2_A to obtain the first ciphertext square mean T_A;

[0110] a9, institution B multiplies the first key matrix H_B by the first random vector X^2_B to obtain the second ciphertext square mean T_B;

[0111] a10, organization C generates second random vectors C_a, C_b and third random vectors C_a_A, C_b_A, sends the third random vectors C_a_A, C_b_A to organization A, subtracts the second random vectors C_a, C_b from the third random vectors C_a_A, C_b_A to obtain second key vectors C_a_B, C_b_B, and sends the second key vectors C_a_B, C_b_B to organization B; wherein C_b=C_a×C_a, C_a×C_a represents element-wise multiplication; wherein steps a8, a9 and a10 are not in particular order and can be performed simultaneously;

[0112] a11, organization A subtracts the first statistical parameter ciphertext R_A from C_a_A in the third random vector to obtain the first intermediate value ciphertext D_a_A, and sends it to organization B;

[0113] a12, institution B subtracts the second statistical parameter ciphertext R_B from C_a_B in the second key vector to obtain the second intermediate value ciphertext D_a_B, and sends it to institution A; wherein steps a11 and a12 are not in particular order and can be performed simultaneously;

[0114] a13, institution A and institution B recover the first intermediate value plaintext D_a according to the first intermediate value ciphertext D_a_A and the second intermediate value ciphertext D_a_B through a secret sharing algorithm;

[0115] a14, institution A calculates the first mean square ciphertext S_A according to the first intermediate value plaintext D_a, the first statistical parameter ciphertext R_A, the first intermediate value ciphertext D_a_A and C_b_A in the third random vector, and the formula is: S_A = D_a×R_A+D_a×D_a_A+C_b_A; subtract the first ciphertext square mean T_A from the first mean square ciphertext S_A to obtain the first variance ciphertext U_A;

[0116] a15, institution B calculates the second mean square ciphertext S_B according to the first intermediate value plaintext D_a, the second statistical parameter ciphertext R_B, the second intermediate value ciphertext D_a_B and the second key vector C_b_B, the formula is: S_B = D_a × R_B + D_a × D_a_B + C_b_B; subtract the second ciphertext square mean T_B from the second mean square ciphertext S_B to obtain the second variance ciphertext U_B; wherein steps a14 and a15 are not in order and can be performed simultaneously;

[0117] a16, institution A recovers the variance of the credit score of the personnel through the secret sharing algorithm based on the ciphertext U_A of the first variance. Of course, in step a6, institution A can recover the plaintext of the average credit score of the personnel in each company through the secret sharing algorithm, which can also be carried out in step a16.

[0118] In the existing privacy-preserving group statistics calculation method based on homomorphic encryption, institution B is the data holder, and it can directly obtain the average and variance of the credit score of the personnel. How to enable institution A to obtain the average and variance of the credit score of the personnel without leaking the average and variance of the credit score of the personnel of institution B is still an unresolved issue. The method adopted in this application can select institution A or institution B to obtain the final average and variance of the credit score of the personnel.

[0119] It should be understood that although Figure 1-2 The steps in the flowchart are shown in sequence as indicated by the arrows, but these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise specified in this document, there is no strict order restriction for the execution of these steps, and these steps can be executed in other orders. Moreover, Figure 1-2 At least part of the steps may include multiple steps or multiple stages. These steps or stages are not necessarily performed at the same time, but can be performed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed in turn or alternately with other steps or at least part of the steps or stages in other steps.

[0120] In one embodiment, Figure 3 As shown, a group statistical parameter calculation device based on privacy protection is provided, including: an encoding module 210, a first key sending module 220, a second key sending module 230, a first parameter ciphertext calculation module 240, a second parameter ciphertext calculation module 250 and a decryption module 260, wherein:

[0121] The encoding module 210 is used to encode the group information to generate a normalized group encoding matrix.

[0122] The first key sending module 220 is used for the first participant to generate a first random matrix, convert it into a first key matrix related to the normalized block coding matrix, and send the first key matrix to the second participant.

[0123] The second key sending module 230 is used for the second participant to generate a first random vector, convert it into a first key vector related to the sample numerical vector, and send the first key vector to the first participant.

[0124] The first parameter ciphertext calculation module 240 is used by the first participant to obtain the first statistical parameter ciphertext according to the first random matrix and the first key vector.

[0125] The second parameter ciphertext calculation module 250 is used by the second participant to obtain the second statistical parameter ciphertext according to the first key matrix and the first random vector.

[0126] The decryption module 260 is used to recover the group statistical parameters according to the first statistical parameter ciphertext and the second statistical parameter ciphertext through a secret sharing algorithm.

[0127] In one embodiment, the encoding module 210 includes: a matrix G establishment unit, used to establish a matrix G (M, K), where M is the number of individuals in the population, K is the number of groups, and the element value in the matrix G is 0 or 1; a normalized group coding matrix calculation unit, used to calculate the normalized group coding matrix H according to the matrix G, and the calculation formula for the value of each element in the normalized group coding matrix H is:

[0128]

[0129] Where m represents the number of individuals in the population, m=1, 2, ..., M, a single individual can fall into multiple groups, k represents the sequence number of the group, k=1, 2, ..., K, j represents the number of individuals in the group with sequence number k, j=1, 2, ..., M, G[j,k] represents the value of the element numbered j in the group with sequence number k in the matrix G, sum_j(G[j,k]) represents the sum of the values ​​of all elements in the group with sequence number k in the matrix G; if the individual numbered m is in the group with sequence number k, then the value of G[m,k] is 1, if the individual numbered m is not in the group with sequence number k, then the value of G[m,k] is 0.

[0130] In one embodiment, the first key sending module 220 is further used for the first participant to generate a first random matrix H_A of the same size as the normalized block coding matrix H, and to subtract the normalized block coding matrix H from the first random matrix H_A to obtain a first key matrix H_B, and to send the first key matrix H_B to the second participant;

[0131] The second key sending module 230 is also used for the second participant to generate the first random vector X_B, X^2_B, and subtract the sample numerical vector X from the first random vector X_B, X^2_B to obtain the first key vector X_A, X^2_A, and send the first key vector X_A, X^2_A to the first participant.

[0132] In one embodiment, the first parameter ciphertext calculation module 240 is further used for the first participant to obtain a first statistical parameter ciphertext R_A by multiplying the first key vector X_A by the transpose of the first random matrix H_A; wherein the first statistical parameter ciphertext is a first mean ciphertext;

[0133] The second parameter ciphertext calculation module 250 is also used by the second participant to obtain the second statistical parameter ciphertext R_B by multiplying the first random vector X_B by the transpose of the first key matrix H_B; wherein the second statistical parameter ciphertext is the second mean ciphertext.

[0134] The decryption module 260 is also used for the first participant to restore the group mean based on the first mean ciphertext through a secret sharing algorithm, and the second participant to restore the group mean based on the second mean ciphertext through a secret sharing algorithm.

[0135] In one embodiment, the above-mentioned group statistical parameter calculation device based on privacy protection further includes:

[0136] A ciphertext square mean calculation module, used for the first participant to calculate the first ciphertext square mean according to the first random matrix and the first key vector, and the second participant to calculate the second ciphertext square mean according to the first key matrix and the first random vector;

[0137] A random vector sending module, used for a third party to generate a related second random vector and a third random vector, send the third random vector to the first party, and then calculate a second key vector according to the second random vector and the third random vector and send it to the second party;

[0138] A first intermediate value ciphertext calculation module, used for the first participant to calculate the first intermediate value ciphertext according to the first statistical parameter ciphertext and the third random vector, and send it to the second participant;

[0139] A second intermediate value ciphertext calculation module, used for the second participant to calculate the second intermediate value ciphertext according to the second statistical parameter ciphertext and the second key vector, and send it to the first participant;

[0140] An intermediate value plaintext calculation module is used for the first participant and the second participant to recover the first intermediate value plaintext according to the first intermediate value ciphertext and the second intermediate value ciphertext through a secret sharing algorithm respectively;

[0141] A first variance ciphertext calculation module, used for the first participant to calculate the ciphertext of the first mean square according to the first intermediate value plaintext, the first statistical parameter ciphertext, the first intermediate value ciphertext and the third random vector, and then calculate the ciphertext of the first variance according to the mean of the first ciphertext square and the ciphertext of the first mean square;

[0142] A second variance ciphertext calculation module, in which the second participant calculates a second mean square ciphertext according to the first intermediate value plaintext, the second statistical parameter ciphertext, the second intermediate value ciphertext and the second key vector, and then calculates a second variance ciphertext according to the second ciphertext square mean and the second mean square ciphertext;

[0143] The decryption module is also used for the first participant to recover the group variance based on the ciphertext of the first variance and the ciphertext of the second variance through a secret sharing algorithm, and the second participant to recover the group variance based on the ciphertext of the first variance and the ciphertext of the second variance through a secret sharing algorithm.

[0144] In one embodiment, the first key vector X_A, X^2_A is obtained by subtracting the sample numerical vector X from the first random vector X_B, X^2_B, and the first random vector X_B, X^2_B is generated by the second participant; the first key matrix H_B is obtained by subtracting the normalized group coding matrix H from the first random matrix H_A, and the first random matrix H_A is generated by the first participant, and the first random matrix H_A is the same size as the normalized group coding matrix H.

[0145] The ciphertext square mean calculation module is also used for the first participant to multiply the transpose of the first random matrix H_A with the first key vector X^2_A to obtain the first ciphertext square mean T_A, and the second participant to multiply the first key matrix H_B with the first random vector X^2_B to obtain the second ciphertext square mean T_B.

[0146] In one of the embodiments, the random vector sending module is also used for the third party to generate a second random vector C_a, C_b and a third random vector C_a_A, C_b_A, send the third random vector C_a_A, C_b_A to the first party, subtract the second random vector C_a, C_b from the third random vector C_a_A, C_b_A to obtain a second key vector C_a_B, C_b_B, and send the second key vector C_a_B, C_b_B to the second party; wherein C_b=C_a×C_a.

[0147] In one of the embodiments, the first intermediate value ciphertext calculation module is also used for the first participant to subtract the first statistical parameter ciphertext R_A from the third random vector C_a_A to obtain the first intermediate value ciphertext D_a_A, and send it to the second participant; the second intermediate value ciphertext calculation module is also used for the second participant to subtract the second statistical parameter ciphertext R_B from the second key vector C_a_B to obtain the second intermediate value ciphertext D_a_B, and send it to the first participant; wherein the first participant recovers the first intermediate value plaintext D_a according to the second intermediate value ciphertext D_a_B through a secret sharing algorithm, and the second participant recovers the first intermediate value plaintext D_a according to the first intermediate value ciphertext D_a_A through a secret sharing algorithm.

[0148] Among them, the first variance ciphertext calculation module includes: a first mean square ciphertext calculation unit, which is used by the first participant to calculate the first mean square ciphertext S_A according to the first intermediate value plaintext D_a, the first statistical parameter ciphertext R_A, the first intermediate value ciphertext D_a_A and the third random vector C_b_A, and the formula is: S_A=D_a×R_A+D_a×D_a_A+C_b_A; the first variance ciphertext calculation unit is used by the first participant to subtract the first ciphertext square mean T_A from the first mean square ciphertext S_A to obtain the first variance ciphertext U_A.

[0149] Among them, the second variance ciphertext calculation module includes: a second mean square ciphertext calculation unit, which is used by the second participant to calculate the second mean square ciphertext S_B according to the first intermediate value plaintext D_a, the second statistical parameter ciphertext R_B, the second intermediate value ciphertext D_a_B and the second key vector C_b_B, and the formula is: S_B=D_a×R_B+D_a×D_a_B+C_b_B; the second variance ciphertext calculation unit is used by the second participant to subtract the second ciphertext square mean T_B from the second mean square ciphertext S_B to obtain the second variance ciphertext U_B.

[0150] For the specific limitations of the group statistical parameter calculation device based on privacy protection, please refer to the limitations of the group statistical parameter calculation method based on privacy protection in the above text, which will not be repeated here. Each module in the above-mentioned group statistical parameter calculation device based on privacy protection can be implemented in whole or in part by software, hardware and a combination thereof. The above-mentioned modules can be embedded in or independent of the processor in the computer device in the form of hardware, or can be stored in the memory of the computer device in the form of software, so that the processor can call and execute the operations corresponding to the above modules.

[0151] In one embodiment, a computer device is provided. The computer device may be a server, and its internal structure diagram may be as follows: Figure 4As shown. The computer device includes a processor, a memory and a network interface connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store group information or sample numerical vector data. The network interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, a group statistical parameter calculation method based on privacy protection is implemented.

[0152] Those skilled in the art will understand that Figure 4 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine certain components, or have a different arrangement of components.

[0153] In one embodiment, a computer device is further provided, including a memory and a processor, wherein a computer program is stored in the memory, and the processor implements the steps in the above method embodiments when executing the computer program.

[0154] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps in the above-mentioned method embodiments are implemented.

[0155] Those of ordinary skill in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, storage, database or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory or optical memory, etc. Volatile memory can include random access memory (RAM) or external cache memory. As an illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM).

[0156] The technical features of the above embodiments may be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0157] The above-mentioned embodiments only express several implementation methods of the present application, and the descriptions thereof are relatively specific and detailed, but they cannot be understood as limiting the scope of the invention patent. It should be pointed out that, for a person of ordinary skill in the art, several variations and improvements can be made without departing from the concept of the present application, and these all belong to the protection scope of the present application. Therefore, the protection scope of the patent of the present application shall be subject to the attached claims.

Claims

1. A method for calculating group statistical parameters based on privacy protection, characterized in that: The method comprises: Encode the group information to generate a normalized group coding matrix; The first participant generates a first random matrix, converts it into a first key matrix associated with the normalized block coding matrix, and sends the first key matrix to the second participant; The second participant generates a first random vector, converts it into a first key vector associated with the sample numerical vector, and sends the first key vector to the first participant; The first participant obtains a first statistical parameter ciphertext according to the first random matrix and the first key vector, including: the first participant obtains the first statistical parameter ciphertext by multiplying the first key vector by the transpose of the first random matrix, and the first statistical parameter ciphertext is a first mean ciphertext; The second participant obtains a second statistical parameter ciphertext according to the first key matrix and the first random vector, including: the second participant obtains the second statistical parameter ciphertext by multiplying the first random vector by the transpose of the first key matrix, wherein the second statistical parameter ciphertext is a second mean ciphertext; The group statistical parameters are recovered by using a secret sharing algorithm according to the first statistical parameter ciphertext and the second statistical parameter ciphertext.

2. The method according to claim 1, characterized in that The step of encoding the group information to generate a normalized group coding matrix includes: Create a matrix G (M, K), where M is the number of individuals in the population, K is the number of groups, and the element values ​​in the matrix G are 0 or 1; The normalized group coding matrix H is calculated according to the matrix G. The calculation formula for the value of each element in the normalized group coding matrix H is: Among them, m represents the number of individuals in the population, m=1,2,...,M, a single individual can fall into multiple groups, k represents the sequence number of the group, k=1,2,...,K, j represents the number of individuals in the group with sequence number k, j=1,2,...,M, G[j,k] represents the value of the element numbered j in the group with sequence number k in the matrix G, sum_j(G[j,k]) represents the sum of the values ​​of all elements in the group with sequence number k in the matrix G; if the individual numbered m is in the group with sequence number k, then the value of G[m,k] is 1, if the individual numbered m is not in the group with sequence number k, then the value of G[m,k] is 0.

3. The method according to claim 1, characterized in that The first participant generates a first random matrix, converts the first random matrix into a first key matrix related to a normalized block coding matrix, and sends the first key matrix to the second participant, including: The first participant generates a first random matrix H_A of the same size as the normalized block coding matrix H, subtracts the normalized block coding matrix H from the first random matrix H_A to obtain a first key matrix H_B, and sends the first key matrix H_B to the second participant; The second participant generates a first random vector, converts the first random vector into a first key vector associated with the sample numerical vector, and sends the first key vector to the first participant, including: The second participant generates a first random vector X_B, X^2_B, and subtracts the sample numerical vector X from the first random vector X_B, X^2_B to obtain a first key vector X_A, X^2_A, and sends the first key vector X_A, X^2_A to the first participant.

4. The method according to claim 3, characterized in that The method of recovering the group statistical parameter by using a secret sharing algorithm according to the first statistical parameter ciphertext and the second statistical parameter ciphertext comprises: The first participant recovers the group mean based on the first mean ciphertext and the second statistical parameter ciphertext through a secret sharing algorithm, and the second participant recovers the group mean based on the first statistical parameter ciphertext and the second mean ciphertext through a secret sharing algorithm.

5. The method according to claim 1, characterized in that Also includes: The first participant calculates a first ciphertext square mean value based on the first random matrix and the first key vector, and the second participant calculates a second ciphertext square mean value based on the first key matrix and the first random vector; The third party generates a related second random vector and a third random vector, sends the third random vector to the first party, and then calculates a second key vector based on the second random vector and the third random vector and sends it to the second party; The first participant calculates a first intermediate value ciphertext according to the first statistical parameter ciphertext and the third random vector, and sends the first intermediate value ciphertext to the second participant; The second participant calculates a second intermediate value ciphertext based on the second statistical parameter ciphertext and the second key vector, and sends the second intermediate value ciphertext to the first participant; The first participant and the second participant respectively recover the first intermediate value plaintext based on the first intermediate value ciphertext and the second intermediate value ciphertext through a secret sharing algorithm; The first participant calculates the ciphertext of the first mean square according to the first intermediate value plaintext, the first statistical parameter ciphertext, the first intermediate value ciphertext and the third random vector, and then calculates the ciphertext of the first variance according to the mean of the square of the first ciphertext and the ciphertext of the square of the first mean; The second participant calculates the ciphertext of the second squared mean according to the first intermediate value plaintext, the second statistical parameter ciphertext, the second intermediate value ciphertext and the second key vector, and then calculates the ciphertext of the second variance according to the second ciphertext squared mean and the ciphertext of the second squared mean; The first participant recovers the group variance based on the ciphertext of the first variance and the ciphertext of the second variance through a secret sharing algorithm, and the second participant recovers the group variance based on the ciphertext of the first variance and the ciphertext of the second variance through a secret sharing algorithm.

6. The method according to claim 5, characterized in that The first key vectors X_A and X^2_A are obtained by subtracting the sample numerical vector X from the first random vectors X_B and X^2_B, and the first random vectors X_B and X^2_B are generated by the second participant; The first key matrix H_B is obtained by subtracting the normalized block coding matrix H from the first random matrix H_A. The first random matrix H_A is generated by the first participant. The first random matrix H_A has the same size as the normalized block coding matrix H. The first participant calculates the first ciphertext square mean according to the first random matrix and the first key vector, and the second participant calculates the second ciphertext square mean according to the first key matrix and the first random vector, including: The first participant multiplies the transpose of the first random matrix H_A with the first key vector X^2_A to obtain the first ciphertext square mean T_A, and the second participant multiplies the first key matrix H_B with the first random vector X^2_B to obtain the second ciphertext square mean T_B.

7. The method according to claim 5, characterized in that The third party generates a related second random vector and a third random vector, sends the third random vector to the first party, and then calculates a second key vector according to the second random vector and the third random vector and sends the second key vector to the second party, including: The third party generates a second random vector C_a, C_b and a third random vector C_a_A, C_b_A, sends the third random vector C_a_A, C_b_A to the first party, subtracts the second random vector C_a, C_b from the third random vector C_a_A, C_b_A to obtain a second key vector C_a_B, C_b_B, and sends the second key vector C_a_B, C_b_B to the second party; wherein C_b=C_a × C_a.

8. The method according to claim 5, characterized in that The first participant calculates a first intermediate value ciphertext according to the first statistical parameter ciphertext and the third random vector, and sends the first intermediate value ciphertext to the second participant, including: The first participant subtracts the first statistical parameter ciphertext R_A from the third random vector C_a_A to obtain a first intermediate value ciphertext D_a_A, and sends it to the second participant; The second participant calculates a second intermediate value ciphertext according to the second statistical parameter ciphertext and the second key vector, and sends the second intermediate value ciphertext to the first participant, including: The second participant subtracts the second statistical parameter ciphertext R_B from the second key vector C_a_B to obtain a second intermediate value ciphertext D_a_B, and sends it to the first participant; Among them, the first participant recovers the first intermediate value plaintext D_a based on the first intermediate value ciphertext D_a_A and the second intermediate value ciphertext D_a_B through the secret sharing algorithm, and the second participant recovers the first intermediate value plaintext D_a based on the first intermediate value ciphertext D_a_A and the second intermediate value ciphertext D_a_B through the secret sharing algorithm.

9. The method according to claim 5, characterized in that The first participant calculates a ciphertext of the first mean square according to the first intermediate value plaintext, the first statistical parameter ciphertext, the first intermediate value ciphertext and the third random vector, and then calculates a ciphertext of the first variance according to the square mean of the first ciphertext and the ciphertext of the square of the first mean, including: The first participant calculates the first mean square ciphertext S_A according to the first intermediate value plaintext D_a, the first statistical parameter ciphertext R_A, the first intermediate value ciphertext D_a_A and the third random vector C_b_A. The formula is: S_A= D_a × R_A+ D_a × D_a_A+ C_b_A; The first participant subtracts the first ciphertext square mean T_A from the ciphertext of the first mean square S_A to obtain the ciphertext of the first variance U_A.

10. The method according to any one of claims 5 to 9, characterized in that: The second participant calculates a ciphertext of the second mean square according to the first intermediate value plaintext, the second statistical parameter ciphertext, the second intermediate value ciphertext and the second key vector, and then calculates a ciphertext of the second variance according to the second ciphertext square mean and the second mean square ciphertext, including: The second participant calculates the second mean square ciphertext S_B according to the first intermediate value plaintext D_a, the second statistical parameter ciphertext R_B, the second intermediate value ciphertext D_a_B and the second key vector C_b_B. The formula is: S_B = D_a × R_B + D_a × D_a_B + C_b_B; The second participant subtracts the second ciphertext square mean T_B from the ciphertext of the second mean square S_B to obtain the ciphertext of the second variance U_B.

11. A group statistical parameter calculation device based on privacy protection, characterized in that: The device comprises: The encoding module is used to encode the group information to generate a normalized group encoding matrix; A first key sending module, used for the first participant to generate a first random matrix, convert it into a first key matrix related to the normalized block coding matrix, and send the first key matrix to the second participant; A second key sending module, used for the second participant to generate a first random vector, convert it into a first key vector related to the sample numerical vector, and send the first key vector to the first participant; A first parameter ciphertext calculation module, used for the first participant to obtain a first statistical parameter ciphertext according to a first random matrix and a first key vector, including: the first participant obtains a first statistical parameter ciphertext by multiplying the first key vector by the transpose of the first random matrix, and the first statistical parameter ciphertext is a first mean ciphertext; A second parameter ciphertext calculation module, used for the second participant to obtain a second statistical parameter ciphertext according to the first key matrix and the first random vector, including: the second participant obtains the second statistical parameter ciphertext according to the transposition of the first key matrix and multiplying the first random vector, wherein the second statistical parameter ciphertext is a second mean ciphertext; The decryption module is used to recover the group statistical parameters according to the first statistical parameter ciphertext and the second statistical parameter ciphertext through a secret sharing algorithm.

12. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 10 are implemented.

13. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 10 are implemented.

Citation Information

Patent Citations

  • Method and device for jointly processing data by two parties

    CN111162896A

  • Privacy protection linear regression method based on secret sharing and random disturbance

    CN113065145A