Secret computing device, secret computing method, and program
By calculating the public value 2σ/m in the secret calculation and performing corresponding public value division operations, the multiplication operation and right shift are realized while reducing the calculation cost, solving the problem of high calculation cost in the prior art.
Patent Information
- Application Number
- CN202080093276.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-01-20
- Publication Date
- 2025-06-27
- Estimated Expiration
- 2040-01-20
AI Technical Summary
Existing secret calculation methods require additional right shift operations during multiplication operations, resulting in higher calculation costs.
By calculating the public value 2σ/m and performing the public value division operation of the secret dispersion value [x] and the public value division operation, a secret dispersion value [mx]r of the value whose σ bit is shifted right by mx, thereby realizing the multiplication operation and right shift at the same time.
This method can significantly reduce computing costs, reduce computing costs, and avoid hardware performance limitations caused by overflow.
Smart Images

Figure CN114981860B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a technique for performing multiplication of real values in secret computing. Background Art
[0002] Non-patent document 1 discloses a secret computing method for multiplying a public real value by a secret distributed value.
[0003] Prior art literature
[0004] Non-patent literature
[0005] Non-patent document 1: Dai Igarashi, "Design and installation of secret real number operation group for installation of secret computing AI-O(|p|) bit communication amount O(1) right shift of circle for real numbers," ( Igarashi Dai, "Secret Calculation AI's Secret Calculation Group's Design and Design -O(|p|) Communication Volume O(1)ラウンドの実数向けrightシフト,")In CSS2019,2019. Summary of the invention
[0006] Problems to be solved by the invention
[0007] However, the secret calculation method of Non-Patent Document 1 has a problem that the calculation cost is high because right shift is performed by secret calculation in addition to multiplication in order to prevent overflow.
[0008] The present invention has been made in view of the above point, and an object of the present invention is to reduce the computational cost of a secret computation for multiplying a public real value by a secret shared value.
[0009] Means for solving problems
[0010] X is a real number, [·] is the secret distributed value of ·, σ is a positive integer representing the number of bits of the right shift, and m is a real number. The public value 2 σ / m, using the secret shared value [x] and the obtained public value 2 σ / m’s public value division operation is a secret computation [x] / (2 σ / m), and obtain the secret shared value [mx] which is the value of mx shifted right by σ bits r And output.
[0011] Effects of the Invention
[0012] As described above, in the present invention, the multiplication operation of the real number m and the right shift of σ bits are simultaneously performed, so the calculation cost can be reduced. BRIEF DESCRIPTION OF THE DRAWINGS
[0013] Figure 1Ais a block diagram showing a secret computing device according to an embodiment.
[0014] Figure 1B is a flowchart for showing a secret computing method according to an embodiment.
[0015] Figure 2 is a table showing parameters indicating completion of calculations related to respective elementary functions.
[0016] Figure 3 is a block diagram for explaining a hardware structure. DETAILED DESCRIPTION
[0017] Hereinafter, embodiments of the present invention will be described with reference to the drawings.
[0018] In an embodiment, a secret computing device takes as input a secret-shared value [x] of a real number x, a real number m as a multiplier, and a positive integer σ representing the number of bits of a right shift amount, and obtains a secret-shared value [mx] of a value obtained by right-shifting mx by σ bits r and outputs it. The secret sharing method of the secret-shared value is not limited (key sharing method, secret sharing scheme), for example, an additive secret sharing scheme, a Shamir secret sharing scheme, etc. can be cited. An example of [·] is a secret-shared value (share) obtained by linearly secret-sharing an element · on a residue ring. In addition, a public decimal point position can be selected for an integer on a ring, and thus it can be regarded as a fixed-point real number. In an embodiment, a fixed-point real number represented on a ring in this way is simply referred to as a real number.
[0019] As Figure 1A shown, a secret computing device 1 according to an embodiment includes a public value calculation unit 11, a secret calculation unit 12, and a control unit 19. The secret computing device 1 executes each process under the control of the control unit 19.
[0020] As Figure 1B shown, first, a secret-shared value [x], a real number m, and a positive integer σ are input to the secret computing device 1 (step S10). The secret-shared value [x] is sent to the secret calculation unit 12, and the real number m and the positive integer σ are sent to the public value calculation unit 11.
[0021] The real number m and the positive integer σ are input to the public value calculation unit 11. The public value calculation unit 11 calculates a public value 2 σ / m and outputs it (step S11).
[0022] The secret-shared value [x] and the public value 2 output from the public value calculation unit 11 σ / m is input to the secret calculation unit 12. The secret calculation unit 12 performs a secret calculation of the public value division operation of [x] using the secret dispersion value [x] and the public value 2 obtained by the public value calculation unit 11 σ / m, i.e., [x] / (2 σ / m), to obtain the secret dispersion value [mx] of the value obtained by shifting mx to the right by σ bits r and outputs it (step S12).
[0023] The secret calculation device 1 outputs the secret dispersion value [mx] r (step S13).
[0024] <Features of this embodiment>
[0025] Generally, in secret calculation, when performing a multiplication operation of a secret dispersion value [x] by a publicly known real number m and a right shift of σ bits, it becomes a case of performing the multiplication operation first and then the right shift or performing the right shift first and then the multiplication operation. In this case, the calculation cost for performing the multiplication operation and the calculation cost for performing the right shift are required. In contrast, in this embodiment, focusing on the equivalence between the right shift and the division operation, first, the public value 2 σ / m is calculated, and then a secret calculation of the public value division operation using the secret dispersion value [x] and the obtained public value 2 σ / m, i.e., [x] / (2 σ / m), is performed. The value obtained by this secret calculation is equivalent to the secret dispersion value [mx] of the value obtained by shifting the multiplication operation result mx to the right by σ bits r . However, the multiplication operation and the right shift are simultaneously achieved through the secret calculation of the public value division operation with low calculation cost. As a result, the operation cost can be significantly reduced. Those skilled in the art in the field of secret calculation recognize that the division operation is a process with a greater operation cost compared to the multiplication operation and cannot think of using the division operation in the process of the multiplication operation. However, in this embodiment, focusing on the equivalence between the right shift and the division operation, the public value 2 σ / m is calculated, and by performing the secret calculation [x] / (2 σ / m) of the public value division operation, a remarkable and unpredictable effect of reducing the calculation cost can be obtained compared to the case of performing the multiplication operation and the right shift separately. In addition, overflow is a problem based on the performance of the processor installed with the secret calculation, and this method provides a means for solving the problem based on the constraints on this hardware. Thus, this method does not solve a purely mathematical problem but a problem on hardware installation and has a technical feature. The value of σ representing the right shift amount is determined based on the number of bits that can be processed by the processor. That is, the public value 2 σ / m is a value determined based on the hardware requirements.
[0026] [Installation Example]
[0027] The following shows an algorithm capable of installing the above method.
[0028] [Example 1]
[0029] In Example 1, based on the condition c ∈ {0, 1}, a secret-shared value [x] of a real number x is multiplied by one of the two public values m0 and m1. If the magnitudes of the public values m0 and m1 are large, the number of significant bits of the value after the multiplication operation (the number of bits necessary to represent the number in binary) increases, resulting in a number that cannot be multiplied again. Therefore, there are cases where a right shift is necessary. In Example 1, such processing is made efficient.
[0030] Input: [x], multipliers m0, m1, secret-shared value [c] of the condition c ∈ {0, 1}
[0031] Output: [m0x] if c = 0, [m1x] if c = 1
[0032] The secret computing device obtains and outputs secret-shared values [m0x] and [m1x] through secret computing using the secret-shared value [x], multipliers m0, m1, and modulus p (step S21). A specific example of the processing in step S21 will be described later.
[0033] The secret computing device obtains m c The secret-shared value [c? m0x : m1x] of x through secret computing using the secret-shared values [c], [m0x], and [m1x] and outputs it. That is, the secret computing unit 22 obtains and outputs [m0x] when c = 0 and obtains and outputs [m1x] when c = 1 (step S22).
[0034] [Specific Example of the Processing in Step S21]
[0035] A specific example of the processing in step S21 will be described. Here, d0 = 1 / m0 and d1 = 1 / m1 are divisors, p is a positive integer modulus, and q is a positive integer quotient.
[0036] The secret computing device obtains and outputs a secret-shared value [q] of the quotient q of x / p through secret computing using the secret-shared value [x] and modulus p (step S211).
[0037] The secret computing device uses the secret-shared values [x], [q], divisors d0,..., d n-1And perform secret calculations modulo p to obtain [m0x] = [x / d0] = [(x + qp) / d0] - [q]p / d0, [m1x] = [x / d1] = [(x + qp) / d1] - [q]p / d1 and output them (step S212). The following describes a specific example of the processing in step S212.
[0038] <Specific example of the processing in step S212>
[0039] The public value calculation unit 212a of the secret calculation device uses the multipliers m0, m1 and the positive integers σ0, σ1 to obtain the public values 2 σ0 / m0, 2 σ1 / m1 and output them. Here, σ0, σ1 are positive integers representing the number of bits of the right shift amount required when the multipliers m0, m1 are large (step S212a).
[0040] The secret calculation device performs a secret calculation of public value division using the secret-shared values [x], [q] and modulo p and the public values 2 σ0 / m0, 2 σ1 / m1 to obtain the secret-shared values [(x + qp) / (2 σ0 / m0), [(x + qp) / (2 σ1 / m1)] of the values obtained by right-shifting (x + qp)m0 by σ0 bits and the secret-shared values [(x + qp)m1] of the values obtained by right-shifting (x + qp)m1 by σ1 bits and output them (step S212b).
[0041] The secret calculation device obtains [m0x] = [(x + qp)m0] - [q]pm0 and [m1x] = [(x + qp)m1] - [q]pm1 by secret calculation using the secret-shared values [(x + qp)m0], [(x + qp)m1], [q] and modulo p and the multipliers m0, m1 and outputs them (step S212c).
[0042] <Example 2>
[0043] In Example 2, for an arbitrary function (e.g., elementary function), approximate it with a polynomial function f t (x), and further calculate the difference f t (x) of the function f t (x) before right shift and the approximate function f' u (x) of this function f t (x) - f' t (x) to obtain the secret-shared value [f t (x) - f' t (x)] of ft (x) - f' t (x) after right shift of (f t (x) - f' t (x)) r The secret sharing value of [f t (x) - f' t (x)] r , through the secret calculation of the secret sharing value [f t (x) - f' t (x)] and the secret sharing value [f' r (x)], to obtain the secret sharing value [f t (x)] of the function f after adding f t (x) - f' t (x) and f' t (x). Where x is a real number, [·] is the secret sharing value of ·, n is an integer greater than or equal to 1 (for example, n is an integer greater than or equal to 2), t = 0,..., n - 1, u = 1,..., n - 1, f t (x) is a function of the real number x, f' t (x) is an approximation function of the function f t (x), and the secret sharing value [f'0(x)] of the approximation function f'0(x) is [f'0(x)] = c t (x) is [f' t (x)] = c 0,0 + c 0,1 [x], the secret sharing value [f' u (x)] of the approximation function f' u (x) is [f' u (x)] = c u , 0 + c u,1 [x] + c u,2 [f0(x)] +... + [f u-1 (x)], c t,0 is a public value, c t,1 ,..., c t,n+1 are coefficients. Where c t,1 ,..., c t,n+1 are small values of the effective number of bits, and c t,1 ,..., c t,n+1 are values that do not require shifting due to digital overflow even when multiplied. f t (x) - f' t (x) is positive. There is no limitation on the secret sharing method. For example, addition secret sharing method, Shamir secret sharing method, etc. can be exemplified. Here, since f t (x) - f' t (x) is larger than f tThe magnitude of (x) is also small, so it is possible to suppress the overflow of the secret sharing value [f t (x) - f’ t (x)]. In addition, since the function f t (x) before the right shift calculation and the approximate function f’ t of this function f u (x) are differentiated by f t (x) - f’ t (x), the secret sharing value [f t (x) - f’ t (x)] can be maintained with high precision. Overflow is a problem based on the performance of the processor on which the secret calculation is installed, and this method provides a means to solve the problem based on the constraints on this hardware. Thus, this method is not to solve a purely mathematical problem, but to solve a problem in hardware installation and has technical characteristics. For example, if the secret sharing value [f t (x)] overflows but the secret sharing value [f t (x) - f’ t (x)] does not overflow in the calculation of the processor, this technical characteristic is significant.
[0044] The secret computing device takes as input the secret sharing value [x] ∈ [L, R) of the real number x and performs the following secret calculation to output the secret sharing value [f n-1 (x)] of the target function f n-1 (x). Here, L and R are real numbers satisfying L < R, and [L, R) represents a left-closed and right-open interval from L or more and less than R. Here, an example of the following case is described: n = 3, a, b, c, d, f, g, h, i, j, k, s, m, n, o, p, q, α, β, γ, δ, ζ are real numbers, f0(x) = y = δx 2 + ax, f1(x) = z = y(ζy + b) + cx, f2(x) = w = γ(z(αz + d) + y(βx + f) + gx), f’0(x) = ix + j, f’1(x) = ky + sx + m, f’2(x) = nz + oy + px + q.
[0045] Input: [x] ∈ [L, R)
[0046] Set parameters: a, b, c, d, f, g, H, i, j, k, s, m, n, o, p, q, α, β, γ, δ, ζ
[0047] Output: Secret sharing value [f n-1 (x)] corresponding to the target function (e.g., elementary function) f n-1 (x)]
[0048] 1: The secret computing device secretly computes [y’] = [x(δx + a - i) - j] through sum of products, and secretly computes the y’ with the decimal point position lowered through right shift r of the secret dispersion value [y’] r .
[0049] 2: The secret computing device obtains [y] = [y’ + (ix + j)] through secret computing using the secret dispersion value [y’] r .
[0050] 3: The secret computing device secretly computes [z’] = [y(ζy + b - k) + (c - s)x - m] through sum of products, and obtains the z’ with the decimal point position lowered through right shift r of the secret dispersion value [z’] r .
[0051] 4: The secret computing device obtains [z] = [z’ + (ky + sx + m)] through secret computing using the secret dispersion value [z’] r .
[0052] 5: The secret computing device secretly computes [w’ / γ] = [z(αz + d - n / γ) + (βx + f - o / γ)y + (g - p)x + (H - q) / γ], performs the processing of steps S10 to S13 with [x] = [w’ / γ] and m = γ, and simultaneously performs multiplication based on γ and lowering of the decimal point position to obtain [w’].
[0053] 6: The secret computing device obtains and outputs [w] = [w’ + (nz + oy + px + q)] through secret computing.
[0054] <Example 3>
[0055] In Example 3, the secret dispersion value of the exponential function value exp(x) of the secret dispersion value [x] of the real number x is obtained. Since the input of the exponential function has additivity, the input is decomposed into the following three parts.
[0056] I. The minimum value μ of the assumed input
[0057] II. The upper u bits x0,..., x of t bits or more below the decimal point of x - μ u-1
[0058] III. The number x representing all bits more lower than x0 of x - μ ρ
[0059] Let exp x = exp μ exp 2-t x0, …, exp 2 u-t-1 x u-1 exp x ρ 。expμ is a public value, exp 2 - t x0, …, exp 2 u-t-1 x u-1 is the position calculated through the table. exp x ρ is the position calculated through approximation, and is normalized by [0, 2 -t )
[0060] Input: [x]
[0061] Output: [exp(x)]
[0062] Set the completed parameter: t = -1
[0063] 1: The secret computing device secretly computes [x'] = [x] - μ. Here, μ is the assumed minimum value of x.
[0064] 2: The secret computing device secretly computes, and extracts the bits above the t bits below the decimal point through bit decomposition and performs a mod p transformation to obtain [x'0], …, [x' u-1
[0065] 3: The secret computing device secretly computes that for each 0 ≤ i < u, f i , ε i are respectively set as the mantissa part and the exponent part of exp(2 i-t )
[0066] 4: The secret computing device secretly computes that for i = 0, …, u - 1, if x' i’ = 0, then set F i = 1, if x' i’ = 1, then set F i = f i , and obtain
[0067] [Number 1]
[0068]
[0069] 5: The secret computing device secretly computes that for each 0 ≤ i < u, it calculates [ε' i through the if-then-else gate (gate) publicly selected: = if [x' i then 2 εi else 1.
[0070] 6: The secret computing device obtains, through secret computation, the product [ε’ i of [ε’] related to each i ([ε’ = ε’0…ε’ u-1 ). This is the power value of 2 in the exponent part of the upper bits of exp(x’).
[0071] 7: The secret computing device obtains the following mathematical formula through secret computation.
[0072] [Equation 2]
[0073]
[0074] This is the number representing the lower bits of exp(x’).
[0075] 8: The secret computing device obtains [w] from [x’ ρ through secret computation. Here, w is a polynomial approximating the exponential function exp x ρ of x’. For example, the secret computing device uses the method of Example 2 with x = x’ ρ to obtain [w]. ρ
[0074]
[0076] 9: The secret computing device obtains [w][f’][ε’]exp(μ) through secret computation and outputs it. In the multiplication of exp(μ), the processes of steps S10 to S13 with [x] = [w][f’][ε’] and m = exp(μ) are performed, and at the same time, the multiplication of exp(μ) and the shift of the decimal point position are performed to obtain [w][f’][ε’]exp(μ).
[0077] [Examples of parameters for the completion of calculations related to each elementary function]
[0078] Figure 2 Shows the parameters for the completion of calculations in the cases where the elementary functions are the reciprocal function, square root function, reciprocal of the square root function, exponential function, and logarithmic function. In addition, ex, ey, and ez respectively represent the decimal point positions of x, y, and z. Furthermore, e’x, e’y, and e’z respectively represent the decimal point positions of x’, y’, and z’ before the right shift. These decimal point positions represent the bit positions of the decimal point counted from the lower bits. The value representing this bit position starts from 0, and when the e1-th bit counted from the lower bits represents 1, the decimal point position is recorded as e1.
[0079] [Hardware structure]
[0080] The secret computing device 1 in the embodiment is a device configured to execute a prescribed program by a general-purpose or dedicated computer including a processor (hardware processor) such as a CPU (central processing unit) and a memory such as a RAM (random-access memory) and a ROM (read-only memory). The computer may include one processor and a memory, or may include a plurality of processors and memories. The program may be installed in the computer or may be pre-recorded in a ROM or the like. In addition, instead of an electronic circuit (circuitry) that realizes a functional structure by reading a program such as a CPU, a part or all of the processing units may be configured by an electronic circuit that can realize a processing function without using a program. In addition, the electronic circuit constituting one device may include a plurality of CPUs.
[0081] Figure 3 The block diagram showing the hardware structure of the secret computing device 1 in the embodiment. As Figure 3As shown, the secret computing device 1 in this example has a CPU (Central Processing Unit) 10a, an input unit 10b, an output unit 10c, a RAM (Random Access Memory) 10d, a ROM (Read Only Memory) 10e, an auxiliary storage device 10f, and a bus 10g. The CPU 10a in this example has a control unit 10aa, an arithmetic unit 10ab, and a register 10ac, and executes various arithmetic processes according to various programs loaded into the register 10ac. In addition, the output unit 10c is an output terminal where data is output, a display, etc., and a LAN card, etc. controlled by the CPU 10a loaded with a prescribed program. In addition, the RAM 10d is an SRAM (Static Random Access Memory), a DRAM (Dynamic Random Access Memory), etc., and has a program area 10da for storing prescribed programs and a data area 10db for storing various data. In addition, the auxiliary storage device 10f is, for example, a hard disk, an MO (Magneto-Optical disc), a semiconductor memory, etc., and has a program area 10fa for storing prescribed programs and a data area 10fb for storing various data. In addition, the bus 10g is connected to the CPU 10a, the input unit 10b, the output unit 10c, the RAM 10d, the ROM 10e, and the auxiliary storage device 10f in a form where information can be interacted. The CPU 10a writes the programs in the program area 10fa of the auxiliary storage device 10f into the program area 10da of the RAM 10d according to the loaded OS (Operating System) program. Similarly, the CPU 10a writes various data in the data area 10fb of the auxiliary storage device 10f into the data area 10db of the RAM 10d. And, the addresses on the RAM 10d where the programs and data are written are stored in the register 10ac of the CPU 10a. The control unit 10ab of the CPU 10a sequentially reads these addresses stored in the register 10ac, reads programs and data from the areas on the RAM 10d indicated by the read addresses, causes the arithmetic unit 10ab to sequentially execute the arithmetic indicated by the programs, and stores the arithmetic results in the register 10ac. Through such a structure, Figure 1A the functional structure of the secret computing device 1 shown is realized.
[0082] The above-described program can be pre-recorded in a computer-readable recording medium. Examples of computer-readable recording mediums are non-transitory recording mediums. Examples of such recording mediums are magnetic recording devices, optical discs, magneto-optical recording media, semiconductor memories, etc.
[0083] The distribution of the program is carried out, for example, by selling, transferring, leasing, etc. removable recording media such as DVDs and CD-ROMs on which the program is recorded. Further, it can also be a structure in which the program is stored in the storage device of a server computer and the program is transferred from the server computer to other computers via a network to circulate the program. As described above, a computer that executes such a program, for example, first temporarily stores the program recorded in a removable recording medium or the program transferred from a server computer in its own storage device. Then, at the time of execution processing, the computer reads the program stored in its own storage medium and executes the processing according to the read program. In addition, as another embodiment of the program, it can also be that the computer directly reads the program from a removable recording medium and executes the processing according to the program. Further, it can also be that each time the program is transferred from the server computer to the computer, the processing according to the obtained program is sequentially executed. In addition, it can also be a structure that does not transfer the program from the server computer to the computer, but only realizes the processing function through the execution instruction and result acquisition, that is, a structure that executes the above-described processing through a so-called ASP (Application Service Provider) type of service. Additionally, it is assumed that the program in this embodiment contains information for the processing of an electronic computer and information referred to in the program (data, etc. that although not a direct instruction for the computer, has the nature of prescribing the computer's processing).
[0084] In each embodiment, it is assumed that this device is configured by executing a prescribed program on a computer, but at least a part of these processing contents can also be realized by hardware.
[0085] Furthermore, the present invention is not limited to the above-described embodiments. For example, the above various processes are not limited to being executed sequentially according to the description, but can also be executed in parallel or individually based on the processing capabilities of the executing device or as necessary. In addition, needless to say, appropriate changes can be made within the scope not departing from the purpose of the present invention.
[0086] Industrial Applicability
[0087] The present invention can be used, for example, in machine learning and real-value multiplication operations in data mining that perform data anonymization and secret computing.
[0088] Reference Numeral Explanation
[0089] 1 Secret computing device
Claims
1. A secret computing device, wherein, x is a real number, [·] is the secret-shared value of ·, σ is a positive integer representing the number of bits of the right shift amount, and m is a real number, the secret computing device has: The public value calculation unit obtains the public value 2 σ / m; and The secret calculation unit performs secret calculation of the public value division operation of [x] using the secret dispersion value [x] and the public value 2 obtained by the public value calculation unit σ / m of the public value division operation of [x] / (2 σ / m), and obtains the secret dispersion value [mx] of the value obtained by shifting mx to the right by σ bits r and outputs it the value of σ is determined based on the number of bits that the processor of the secret computing device can process.
2. A secret computing method, wherein, x is a real number, [·] is the secret-shared value of ·, σ is a positive integer representing the number of bits of the right shift amount, and m is a real number, the secret computing method has: Public value calculation step, the public value calculation unit obtains the public value 2 σ / m; and The secret calculation step, where the secret calculation unit performs a secret calculation of the public value division operation of [x] using the secret dispersion value [x] and the public value 2 obtained by the public value calculation unit σ / m of the public value division operation [x] / (2 σ / m), to obtain the secret dispersion value [mx] of the value obtained by shifting mx to the right by σ bits r and outputs it the value of σ is determined based on the number of bits that the processor can process.
3. A computer program product, which includes a computer program that enables a computer to function as the secret computing device of claim 1.
Citation Information
Patent Citations
Secret spreadsheet division calculation device and method
JP2014164144A
Method and apparatus for securely processing secret data
US20080240443A1