Method and apparatus for secure processing of privacy data

By distributing privacy data in fragments within the initial modulus space and utilizing secret sharing techniques for secure multiplication, the problem of high communication volume and poor performance in secure exponentiation operations in existing technologies is solved, achieving secure exponentiation operations with low communication volume and high performance.

CN115114662BActive Publication Date: 2026-01-30ANT BLOCKCHAIN TECHNOLOGY (SHANGHAI) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210762917.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-06-30
Publication Date
2026-01-30
Estimated Expiration
2042-06-30

AI Technical Summary

Technical Problem

Existing technologies for secure exponentiation involve large communication volumes and poor performance, making it difficult to perform efficient calculations without leaking private data.

Method used

By distributing privacy data in fragments between the first and second parties in the initial modulus space, and using secret sharing technology to perform secure multiplication operations, the multiplier is constructed and converted into the result of the exponentiation operation, thus realizing secure exponentiation.

Benefits of technology

It achieves secure exponentiation with low communication volume and high performance, ensuring that private data is not leaked.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115114662B_ABST
    Figure CN115114662B_ABST
Patent Text Reader

Abstract

This specification provides a method and apparatus for securely processing privacy data. The method includes: a first party, based at least on its own fragments of privacy data, locally calculating a first data fragment of first intermediate data in a first modulus space; the first intermediate data is a non-negative value; a second data fragment of the first intermediate data in the first modulus space is held by a second party; constructing a first multiplier in a second modulus space using a local exponentiation operation with the first data fragment as the exponent; performing a secure multiplication operation based on the first multiplier provided by the first party and a second multiplier provided by the second party to obtain a first fragment of the multiplication result; the second party obtaining a second fragment of the multiplication result; the second multiplier being constructed by the second party based on its held second data fragment; converting the first fragment of the multiplication result into a first result fragment of the exponentiation result in a target modulus space; and the second party obtaining the corresponding second result fragment. This method enables secure exponentiation operations with low communication overhead and high performance.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This specification relates to one or more embodiments in the field of computers, and more particularly to methods and apparatus for securely processing privacy data. Background Technology

[0002] Secure multi-party computation, also known as secure multi-party computation, involves multiple parties collaboratively calculating the result of a function without disclosing their input data. The result is then made public to one or more of the parties. The input data of each party is often private information.

[0003] In secure multi-party computation, secure exponentiation is sometimes required, which means performing exponentiation on private data without disclosing private data. In existing technologies, secure exponentiation schemes have very high communication volume and poor performance. Summary of the Invention

[0004] This specification describes one or more embodiments of a method and apparatus for securely processing privacy data, which can achieve secure exponentiation and has low communication volume and high performance.

[0005] Firstly, a secure processing method for privacy data is provided, wherein the privacy data is distributed in an initial modular space in a shared manner between a first party and a second party. This method is used to obtain result fragments in a target modular space from the result of a power operation with the public data as the base and the privacy data as the exponent. This method is executed by the first party and includes:

[0006] Based at least on the local fragment of the privacy data, a first data fragment of the first intermediate data in the first modulus space is locally calculated; wherein, the first intermediate data is a non-negative value, and the first modulus corresponding to the first modulus space is determined according to the modulus value of the target modulus space; the second data fragment of the first intermediate data in the first modulus space is held by the second party;

[0007] A first multiplier is constructed in the second modulus space based on a local exponentiation operation using the first data fragment as the exponent; the second modulus corresponding to the second modulus space is determined based on the first modulus.

[0008] Based on the first multiplier provided by this party and the second multiplier provided by the second party, a secure multiplication operation is performed to obtain a first slice of the multiplication result; the second party obtains a second slice of the multiplication result; wherein, the second multiplier is constructed by the second party based on the second data slice it holds; the multiplication result has two possible values;

[0009] The first slice of the multiplication result is converted into the first result slice of the exponentiation result in the target modulus space; the second party obtains the corresponding second result slice.

[0010] In one possible implementation, the local fragment is a fragment of the privacy data multiplied by n raised to the power of d1 in the initial modulus space, and the result fragment is a fragment of the result of the power operation multiplied by n raised to the power of d2 in the target modulus space. The absolute value of the public data is expressed as n raised to the power of k, where k and the privacy data are both integers. The minimum value of the target product of k and the privacy data is u, where u is an integer. The modulus of the target modulus space is n raised to the power of t2.

[0011] The first data fragment of the first intermediate data computed locally in the first module space includes:

[0012] Based on the product of the local segment and k divided by n raised to the power of d1, and then rounded down, the first intermediate data is locally calculated as the first data segment in the first modulus space; the first intermediate data is the result of the target product minus u; the first modulus is the larger value between 0 and -d2-u plus t2.

[0013] In one possible implementation, the local fragment is a fragment of the privacy data multiplied by n raised to the power of d1 in the initial modulus space, and the result fragment is a fragment of the result of the power operation multiplied by n raised to the power of d2 in the target modulus space. The absolute value of the public data is expressed as n raised to the power of k, where k and the privacy data are both integers. The minimum value of the target product of k and the privacy data is u, where u is an integer and u is greater than or equal to 0. The modulus of the target modulus space is n raised to the power of t2.

[0014] The first data fragment of the first intermediate data computed locally in the first module space includes:

[0015] Based on the product of the local partition and k, divided by n raised to the power of d1, and then rounded down, the first intermediate data is locally calculated as the first data partition in the first modulus space; the first intermediate data is the result of the target product; the first modulus is the larger value between 0 and -d2 plus t2.

[0016] Furthermore, the first multiplier constructed in the second modulus space includes:

[0017] If the publicly available data is positive, the first base number is determined to be 1; if the publicly available data is negative, the first base number is determined to be -1.

[0018] Divide the aforementioned segment by n raised to the power of d1, and then round down to determine the first power value;

[0019] Using the first base as the base and the first power as the exponent, perform exponentiation to obtain the first product term;

[0020] Using n as the base and the first data segment as the exponent, perform exponentiation to obtain the second product term;

[0021] Multiplying the first product term by the second product term yields the first multiplier in the second modular space; the second modulus corresponding to the second modular space is the result of a local exponentiation operation with n as the base and twice the first modulus as the exponent.

[0022] Further, the step of converting the first slice of the multiplication result into the first result slice of the exponentiation result in the target modular space includes:

[0023] The multiplication result is treated as n-ary data. The first segment value of the first modulus bit with non-zero bits is extracted from the first segment of the multiplication result, or the second segment value of the first modulus bit with non-zero bits is extracted from the first segment of the multiplication result, so as to determine the first segment of the second intermediate result of the third modulus space.

[0024] Multiply the first slice of the second intermediate result by n raised to the power of d² + u, and then round it to the nearest integer to obtain the first result slice of the power operation result in the target modulus space.

[0025] Furthermore, the first slice of the second intermediate result for determining the third modulus space includes:

[0026] The multiplication result is treated as n-ary data. The first segment value of the first modulus bit of the lower digits and the second segment value of the first modulus bit of the higher digits are extracted from the first segment of the multiplication result.

[0027] The summation of the values ​​of the first segment and the second segment yields the first piece of the second intermediate result in the third modulus space.

[0028] Furthermore, the first slice of the second intermediate result for determining the third modulus space includes:

[0029] The multiplication result is treated as n-ary data. Based on the first slice of the multiplication result held by this party and the second slice of the multiplication result held by the second party, a secure comparison operation is performed to obtain a comparison result of whether the multiplication result is greater than or equal to the first modulus.

[0030] If the comparison result is that the multiplication result is less than the first modulus, then the first segment value of the low first modulus bit of the first segment of the multiplication result is extracted, and the first segment value is used as the first segment of the second intermediate result of the third modulus space.

[0031] If the comparison result is that the multiplication result is greater than or equal to the first modulus, then the second segment value of the high-order first modulus bit of the first segment of the multiplication result is extracted, and the second segment value is used as the first segment of the second intermediate result of the third modulus space.

[0032] In one possible implementation, the local fragment is a fragment of the privacy data multiplied by the power of n to the power of d1 in the initial modulus space, and the result fragment is a fragment of the result of the exponentiation multiplied by the power of n to the power of d2 in the target modulus space. The public data and the privacy data are both integers, the minimum value of the privacy data is u', and the modulus of the target modulus space is the power of n to the power of t2.

[0033] The first data fragment of the first intermediate data computed locally in the first module space includes:

[0034] Based on the local partition divided by n raised to the power of d1 and then rounded down, the first intermediate data is locally calculated as the first data partition in the first modulus space; the first intermediate data is the privacy data minus u'; the first modulus is determined based on n raised to the power of d2, the absolute value of the public data, and n raised to the power of t2.

[0035] In one possible implementation, the local fragment is a fragment of the privacy data multiplied by n raised to the power of d1 in the initial modulus space, where both the public data and the privacy data are integers, and the minimum value of the privacy data is u' and u' is greater than or equal to 0;

[0036] The first data fragment of the first intermediate data computed locally in the first module space includes:

[0037] Based on the local partitioning divided by n raised to the power of d1 and then rounded down, the first intermediate data is locally calculated as the first data partition in the first modulus space; the first intermediate data is the privacy data.

[0038] Furthermore, the first multiplier constructed in the second modulus space includes:

[0039] If the publicly available data is positive, the first base number is determined to be 1; if the publicly available data is negative, the first base number is determined to be -1.

[0040] Divide the aforementioned segment by n raised to the power of d1, and then round down to determine the first power value;

[0041] Using the first base as the base and the first power as the exponent, perform exponentiation to obtain the first product term;

[0042] Using the absolute value of the publicly available data as the base and the first data segment as the exponent, a power operation is performed to obtain the second product term;

[0043] Multiplying the first product term by the second product term yields the first multiplier in the second modular space; the second modulus corresponding to the second modular space is the result of a local exponentiation operation with the absolute value of the disclosed data as the base and twice the first modulus as the exponent.

[0044] Further, the step of converting the first slice of the multiplication result into the first result slice of the exponentiation result in the target modular space includes:

[0045] The multiplication result is treated as data in the absolute value base of the public data. For the first segment of the multiplication result, the first segment value of the first modulus bit with non-zero bits in the lower bits is extracted, or the second segment value of the first modulus bit with non-zero bits in the higher bits is extracted, to determine the first segment of the second intermediate result of the third modulus space; the third modulus corresponding to the third modulus space is the result of local exponentiation with the absolute value of the public data as the base and the first modulus as the exponent.

[0046] Multiply the first slice of the second intermediate result by the absolute value of the public data to the power of u', and then multiply by the scaling term to obtain the first slice of the third intermediate result in the third modulus space; the scaling term is the value obtained by multiplying the third modulus by the power of d2 of n and dividing by the power of t2 of n, and then rounding to the nearest integer.

[0047] Multiply the first slice of the third intermediate result by n raised to the power of t2 and divide by the third modulus, then round to the nearest integer to obtain the first result slice of the power operation result in the target modulus space.

[0048] Furthermore, the first slice of the second intermediate result for determining the third modulus space includes:

[0049] The multiplication result is treated as absolute value data of the public data. The first segment value of the first modulus bit of the lower part of the first segment of the multiplication result is extracted, and the second segment value of the first modulus bit of the higher part is extracted.

[0050] The summation of the values ​​of the first segment and the second segment yields the first piece of the second intermediate result in the third modulus space.

[0051] Furthermore, the first slice of the second intermediate result for determining the third modulus space includes:

[0052] The multiplication result is treated as absolute value data of the public data. Based on the first slice of the multiplication result held by this party and the second slice of the multiplication result held by the second party, a secure comparison operation is performed to obtain a comparison result of whether the multiplication result is greater than or equal to the first modulus.

[0053] If the comparison result is that the multiplication result is less than the first modulus, then the first segment value of the low first modulus bit of the first segment of the multiplication result is extracted, and the first segment value is used as the first segment of the second intermediate result of the third modulus space.

[0054] If the comparison result is that the multiplication result is greater than or equal to the first modulus, then the second segment value of the high-order first modulus bit of the first segment of the multiplication result is extracted, and the second segment value is used as the first segment of the second intermediate result of the third modulus space.

[0055] In one possible implementation, the local fragment is a fragment of the privacy data multiplied by n to the power of d1 in the initial modulus space, and the result fragment is a fragment of the result of the power operation multiplied by n to the power of d2 in the target modulus space. The privacy data is not an integer, the public data is represented as n to the power of k, the minimum value of the target product of k and the privacy data is u, and the maximum value is v. Both u and v are integers. The precision of the target product is supported to be d3 decimal places, and the modulus of the target modulus space is n to the power of t2.

[0056] The first data fragment of the first intermediate data computed locally in the first module space includes:

[0057] Based on the product of the local partition and k, divided by n raised to the power of d1, multiplied by n raised to the power of d3', and then rounded to the nearest integer, the first intermediate data is locally calculated as the first data partition in the first modulus space; the first intermediate data is the result of the target product minus u and then multiplied by n raised to the power of d3'; the first modulus is h0 multiplied by n raised to the power of d3', where h0 is determined based on d2, u, v, d2' and t2, d3' is greater than d3, and d2' is greater than d2.

[0058] In one possible implementation, the local fragment is a fragment of the privacy data multiplied by n to the power of d1 in the initial modulus space, and the result fragment is a fragment of the result of the power operation multiplied by n to the power of d2 in the target modulus space. The privacy data is not an integer, the public data is represented as n to the power of k, the minimum value of the target product of k and the privacy data is u, and the maximum value is v. u and v are both integers and u is greater than or equal to 0. The precision of the target product is supported to be d3 decimal places, and the modulus of the target modulus space is n to the power of t2.

[0059] The first data fragment of the first intermediate data computed locally in the first module space includes:

[0060] Based on the product of the local partition and k, divided by n raised to the power of d1, multiplied by n raised to the power of d3', and then rounded to the nearest integer, the first intermediate data is locally calculated as the first data partition in the first modulus space; the first intermediate data is the result of the target product multiplied by n raised to the power of d3'; the first modulus is h0 multiplied by n raised to the power of d3', where h0 is determined based on d2, u, v, d2' and t2, with d3' greater than d3 and d2' greater than d2.

[0061] Furthermore, the first multiplier constructed in the second modulus space includes:

[0062] Divide the aforementioned piecewise segment by n raised to the power of d3', and add d4 to determine the first power value; where d4 is determined based on d2, v, and d2'.

[0063] With n as the base and the first power as the exponent, perform exponentiation, then round to the nearest integer to obtain the first multiplier in the second modular space; the second modulus corresponding to the second modular space is the result of local exponentiation with n as the base and twice h0 as the exponent.

[0064] Further, the step of converting the first slice of the multiplication result into the first result slice of the exponentiation result in the target modular space includes:

[0065] The multiplication result is treated as n-ary data. The first slice of the multiplication result is multiplied by an amplification term to obtain the first slice of the second intermediate result. The amplification term is the result of a local exponentiation operation with n as the base and 2(v-u+d4) as the exponent. Wherein, d4 is determined according to d2, v, and d2'.

[0066] For the first segment of the second intermediate result, extract the first segment value of the low h0 bit containing non-zero bits, or extract the second segment value of the high h0 bit containing non-zero bits, to determine the first segment of the third intermediate result in the third modulus space; the third modulus corresponding to the third modulus space is 2 raised to the power of h0.

[0067] Multiply the first slice of the third intermediate result by n raised to the power of d² + 3u - 4d⁴ - 2v, and then round it to the nearest integer to obtain the first result slice of the power operation result in the target modulus space.

[0068] Furthermore, the first slice of determining the third intermediate result of the third modulus space includes:

[0069] The multiplication result is treated as n-ary data. The first segment value of the low-order h0 bits of the first segment of the second intermediate result is extracted, and the second segment value of the high-order h0 bits is extracted.

[0070] The summation of the values ​​of the first segment and the second segment yields the first slice of the third intermediate result in the third modulus space.

[0071] In one possible implementation, the local fragment is a fragment of the privacy data multiplied by n to the power of d1 in the initial modulus space, and the result fragment is a fragment of the result of the exponentiation multiplied by n to the power of d2 in the target modulus space. The privacy data is an integer, the absolute value of the public data is expressed as n to the power of k, the minimum value of the target product of k and the privacy data is u, and the maximum value is v. Both u and v are integers, the precision of the target product is supported to be d3 decimal places, and the modulus of the target modulus space is n to the power of t2.

[0072] The first data fragment of the first intermediate data computed locally in the first module space includes:

[0073] Based on the product of the local partition and k, divided by n raised to the power of d1, multiplied by n raised to the power of d3', and then rounded to the nearest integer, the first intermediate data is locally calculated as the first data partition in the first modulus space; the first intermediate data is the result of the target product minus u and then multiplied by n raised to the power of d3'; the first modulus is h0 multiplied by n raised to the power of d3', where h0 is determined based on d2, u, v, d2' and t2, d3' is greater than d3, and d2' is greater than d2.

[0074] In one possible implementation, the local fragment is a fragment of the privacy data multiplied by n raised to the power of d1 in the initial modulus space, and the result fragment is a fragment of the result of the power operation multiplied by n raised to the power of d2 in the target modulus space. The privacy data is an integer, the absolute value of the public data is expressed as n raised to the power of k, the minimum value of the target product of k and the privacy data is u, and the maximum value is v. u and v are both integers and u is greater than or equal to 0. The precision of the target product is supported to be d3 decimal places, and the modulus of the target modulus space is n raised to the power of t2.

[0075] The first data fragment of the first intermediate data computed locally in the first module space includes:

[0076] Based on the product of the local partition and k, divided by n raised to the power of d1, multiplied by n raised to the power of d3', and then rounded to the nearest integer, the first intermediate data is locally calculated as the first data partition in the first modulus space; the first intermediate data is the result of the target product multiplied by n raised to the power of d3'; the first modulus is h0 multiplied by n raised to the power of d3', where h0 is determined based on d2, u, v, d2' and t2, with d3' greater than d3 and d2' greater than d2.

[0077] Furthermore, the first multiplier constructed in the second modulus space includes:

[0078] If the publicly available data is positive, the first base number is determined to be 1; if the publicly available data is negative, the first base number is determined to be -1.

[0079] Divide the aforementioned segment by n raised to the power of d1, and then round down to determine the first power value;

[0080] Using the first base as the base and the first power as the exponent, perform exponentiation to obtain the first product term;

[0081] Divide the aforementioned piecewise segment by n raised to the power of d3', and add d4 to determine the second power value; where d4 is determined based on d2, v, and d2'.

[0082] Using n as the base and the second power as the exponent, perform exponentiation, then round to the nearest integer to obtain the second product term;

[0083] Calculate the first product term multiplied by the second product term to obtain the first multiplier in the second modular space; the second modulus corresponding to the second modular space is the result of local exponentiation with base n and exponent of twice h0.

[0084] Further, the step of converting the first slice of the multiplication result into the first result slice of the exponentiation result in the target modular space includes:

[0085] The multiplication result is treated as n-ary data. The first slice of the multiplication result is multiplied by an amplification term to obtain the first slice of the second intermediate result. The amplification term is the result of a local exponentiation operation with n as the base and 2(v-u+d4) as the exponent. Wherein, d4 is determined according to d2, v, and d2'.

[0086] For the first segment of the second intermediate result, extract the first segment value of the low h0 bit containing non-zero bits, or extract the second segment value of the high h0 bit containing non-zero bits, to determine the first segment of the third intermediate result in the third modulus space; the third modulus corresponding to the third modulus space is 2 raised to the power of h0.

[0087] Multiply the first slice of the third intermediate result by n raised to the power of d² + 3u - 4d⁴ - 2v, and then round it to the nearest integer to obtain the first result slice of the power operation result in the target modulus space.

[0088] Furthermore, the first slice of determining the third intermediate result of the third modulus space includes:

[0089] The multiplication result is treated as n-ary data. The first segment value of the low-order h0 bits of the first segment of the second intermediate result is extracted, and the second segment value of the high-order h0 bits is extracted.

[0090] The summation of the values ​​of the first segment and the second segment yields the first slice of the third intermediate result in the third modulus space.

[0091] Secondly, a secure processing apparatus for privacy data is provided, wherein the privacy data is distributed in an initial modular space in a shared manner between a first party and a second party. This apparatus is used to obtain a result fragment in a target modular space from the result of a power operation with the public data as the base and the privacy data as the exponent. The apparatus is located on the first party and includes:

[0092] A local computing unit is configured to locally compute a first data fragment of the first intermediate data in a first modulus space, based at least on the local fragment of the privacy data; wherein the first intermediate data is a non-negative value, and the first modulus corresponding to the first modulus space is determined according to the modulus value of the target modulus space; the second data fragment of the first intermediate data in the first modulus space is held by the second party;

[0093] A multiplier construction unit is used to construct a first multiplier in a second modular space based on a local exponentiation operation using a first data segment obtained by the local computing unit as the exponent; the second modulus corresponding to the second modular space is determined based on the first modulus.

[0094] A secure multiplication unit is used to perform secure multiplication operations based on a first multiplier obtained by the multiplier construction unit provided by the party and a second multiplier provided by the second party, to obtain a first slice of the multiplication result; the second party obtains a second slice of the multiplication result; wherein the second multiplier is constructed by the second party based on the second data slice it holds; the multiplication result has two possible values;

[0095] The result conversion unit is used to convert the first slice of the multiplication result obtained by the safe multiplication unit into the first result slice of the exponentiation result in the target modulus space; the second party obtains the corresponding second result slice.

[0096] Thirdly, a computer-readable storage medium is provided having a computer program stored thereon, which, when executed in a computer, causes the computer to perform the method of the first aspect.

[0097] Fourthly, a computing device is provided, including a memory and a processor, wherein the memory stores executable code, and the processor executes the executable code to implement the method of the first aspect.

[0098] In the method and apparatus provided in the embodiments of this specification, the privacy data is distributed in an initial modular space in a shared manner between the first party and the second party. The method is used to obtain a result fragment in a target modular space from the result of a power operation with the public data as the base and the privacy data as the exponent. First, the first party, at least based on its own fragment of the privacy data, locally calculates a first data fragment of first intermediate data in the first modular space; wherein the first intermediate data is a non-negative value, and the first modulus corresponding to the first modular space is determined according to the modulus of the target modular space; the second data fragment of the first intermediate data in the first modular space is held by the second party; then, based on the first modulus... A first multiplier is constructed in the second modulus space based on the local exponentiation operation of the exponent using the fragmentation as the exponent; the second modulus corresponding to the second modulus space is determined based on the first modulus; then, a secure multiplication operation is performed based on the first multiplier provided by the first party and the second multiplier provided by the second party to obtain a first fragment of the multiplication result; the second party obtains a second fragment of the multiplication result; wherein, the second multiplier is constructed by the second party based on the second data fragment it holds; the multiplication result has two possible values; finally, the first fragment of the multiplication result is converted into a first result fragment of the exponentiation result in the target modulus space; the second party obtains the corresponding second result fragment. As can be seen from the above, this embodiment of the specification, by constructing a multiplier, converts the secure exponentiation operation into a secure multiplication operation, and extracts the exponentiation result from the multiplication result of the secure multiplication operation, thereby enabling secure exponentiation operation with low communication volume and good performance. Attached Figure Description

[0099] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the following description of the embodiments will be briefly introduced. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0100] Figure 1 This is a schematic diagram illustrating an implementation scenario of one embodiment disclosed in this specification;

[0101] Figure 2 This diagram illustrates a secure multiplication operation process according to one embodiment.

[0102] Figure 3 A flowchart illustrating a method for securely processing privacy data according to one embodiment is shown.

[0103] Figure 4 A schematic block diagram of a privacy data security processing apparatus according to one embodiment is shown. Detailed Implementation

[0104] The solution provided in this specification will now be described with reference to the accompanying drawings.

[0105] Figure 1 This is a schematic diagram illustrating an implementation scenario of one embodiment disclosed in this specification. This implementation scenario involves the secure processing of privacy data, which is distributed in an initial modular space in a shared manner between a first party and a second party. The method is used to obtain result fragments in a target modular space from the result of a power operation with the public data as the base and the privacy data as the exponent. Figure 1 As shown, the scenario for secure processing of privacy-preserving data involves participant A and participant B, also referred to as the first party and the second party, or simply Party A and Party B. Each participant can be any device, platform, server, or device cluster with computing and processing capabilities. Both parties must jointly determine the result of the aforementioned exponentiation operation while protecting data privacy, specifically through secret sharing.

[0106] Secret sharing, also known as secret splitting or secret sharing, is a cryptographic technique originally used for managing secret information. Its basic principle is to split the secret into multiple shares, each held by a different participant. The secret can only be recovered by merging the shares of each participant exceeding a threshold number; no information can be recovered from fewer shares. In multi-party secure computation, the threshold number is usually the same as the number of participants. When used in multi-party secure computation, secret sharing employs share conversion: First, each party splits its input data into shares and exchanges them; then, each party performs a conversion operation on its local shares, obtaining a new share that becomes the result of the computation; finally, the parties merge all the new shares to obtain the final result.

[0107] Reference Figure 1 Party A holds a shard of x. <x>0, Party B holds another slice of x. <x>1. Specifically, Party A and Party B each hold x×n d1 modulus n t1 A partition, i.e., round(x×n) d1 )= <x> 0+ <x>1%n t1 It's understandable that `round` can be seen as an integer function, which rounds a value to a specified number of decimal places; it can also be called rounding to the nearest integer. (Slicing) <x>0 and <x>1 is an integer, modulo n t1 The space, also known as the initial modulo space. If the integer part of x is much smaller or much larger than t1 bits, it needs to be multiplied by an n. d1 This ensures that the rounded information is not lost. The value of n depends on the number system used; in typical binary representation, n is 2, and in decimal representation, n is 10. In the embodiments described in this specification, the examples following this specification will primarily use an n value of 2.

[0108] 'a' is public data, meaning that both Party A and Party B know the value of 'a'.

[0109] After Party A and Party B perform a secure multi-party computation based on secret sharing, Party A obtains a. x A shard x >0, Party B receives a x Another fragment x >1, if another y = a x Then, A and B each hold a slice of y; specifically, A and B each hold y×n. d2 modulus n t2 A partition, i.e., round(y×n) d2 )= <y> 0+ <y>1%n t2 Fragmentation <y>0 and <y>1 is an integer, modulo n t2 space, that is, the target modular space. It can be understood that in secret sharing, the shards must be integers, and secret sharing can only operate on integers. If the integer part of a number is much smaller or much larger than the number of modular digits, a power of n needs to be multiplied.

[0110] In the embodiments of this specification, in secure multi-party computation based on secret sharing, a x can be expressed as an exponential operation with base n. Specifically, a x is converted to an exponential operation with base n, sign(a) x ×n kx . Where a = sign(a) × n k . Also, z = kx. It can be understood that sign can be regarded as a sign function, whose function is to extract the sign of a value. For example, when a > 0, sign(a) = 1; when a = 0, sign(a) = 0; when a < 0, sign(a) = -1.

[0111] The range of z supported in secure multi-party computation is [u, v]. Both u and v are integers. If z < u, the result is 0; if z > v, the result overflows or intermediate operations will overflow. The precision of z supported in secure multi-party computation is d3 digits after the decimal point.

[0112] It can be understood that private data can be any data that is not convenient to be made public, which can be but is not limited to data representing users' personal information, or trade secrets, etc.

[0113] In the embodiments of this specification, based on the secure multiplication operation under secret sharing to obtain the power operation result, thus enabling secure power operation, with low communication volume and good performance.

[0114] There are already implementation solutions with better performance for the secure multiplication operation under secret sharing.

[0115] Figure 2 Shows a schematic diagram of the secure multiplication operation processing process according to an embodiment. Refer to Figure 2 In a secure multiplication operation, b and c are two pieces of data that require privacy protection. The first party has a fragment b0 of b and a fragment c0 of c, while the second party has another fragment b1 of b and another fragment c1 of c. The goal is to obtain the product bc of the two data pieces, so that the first party obtains one fragment of the product and the second party obtains the other fragment. First, the third party sends u0, v0, and z0 to the first party and u1, v1, and z1 to the second party, where (u0 + u1) × (v0 + v1) = (z0 + z1). Then, the first party, based on its own fragment b0 of b and the fragment u0 of u received from the third party, locally calculates e0 = b0 - u0. The first party, based on its own fragment c0 of c and the fragment v0 of v received from the third party, locally calculates f0 = c0 - v0. The first party sends e0 and f0 to the second party. Then, the second party, based on its own fragment b1 of b, calculates... The first party receives a fragment u1 of u from a third party and calculates e1 = b1 - u1 locally. The second party, based on a fragment c1 of c it holds and a fragment v1 of v received from a third party, calculates f1 = c1 - v1 locally. The second party sends e1 and f1 to the first party. Finally, the first and second parties each calculate e = bu and f = cv locally. The first party calculates h0 = ef + u0f + ev0 + z0 locally and uses h0 as a fragment of the multiplication result of bc. The second party calculates h1 = u1f + ev1 + z1 locally and uses h1 as a fragment of the multiplication result of bc. It can be proven that h0 + h1 = ef + uf + ev + uv = (e + u)(f + v) = bc.

[0116] Where u is the first random number generated by a third party, u0 is the first slice of the first random number, and u1 is the second slice of the first random number; v is the second random number generated by a third party, v0 is the first slice of the second random number, and v1 is the second slice of the second random number.

[0117] In the embodiments described in this specification, the above processing procedure can be used whenever safe multiplication operations are required.

[0118] Figure 3 This diagram illustrates a method for securely processing privacy data according to one embodiment, which can be based on... Figure 1 The implementation scenarios shown, and Figure 2 The illustrated secure multiplication operation process involves the privacy data being distributed in a shared manner between the first and second parties in the initial modular space. The method is used to obtain a result fragment in the target modular space of the result of a power operation with the public data as the base and the privacy data as the exponent. This method is executed by the first party. It is understood that the first and second parties need to cooperate during the execution of this method. Since their processing procedures are similar, the focus is on describing the processing procedure of one party. Figure 3 As shown, the method for securely processing privacy data in this embodiment includes the following steps:

[0119] First, in step 31, based at least on the local fragment of the privacy data, a first data fragment of the first intermediate data in the first modulus space is locally calculated; wherein, the first intermediate data is a non-negative value, and the first modulus corresponding to the first modulus space is determined according to the modulus value of the target modulus space; the second data fragment of the first intermediate data in the first modulus space is held by the second party. It can be understood that the privacy data is an exponent, and this step transforms the exponent in the fragmented state, including transforming the modulus of its fragments from fragments in the initial modulus space to fragments in the first modulus space; it also includes transforming it to a non-negative value, thereby satisfying that the sum of the first data fragment and the second data fragment equals the first intermediate data, or equals the sum of the first intermediate data and the first modulus.

[0120] Then, in step 32, a first multiplier is constructed in the second modular space based on a local exponentiation operation using the first data segment as the exponent; the second modulus corresponding to the second modular space is determined based on the first modulus. It is understood that the first party constructs the first multiplier, and the second party constructs the second multiplier, such that the product of the first multiplier and the second multiplier includes information from the aforementioned exponentiation operation.

[0121] Next, in step 33, a secure multiplication operation is performed based on the first multiplier provided by this party and the second multiplier provided by the second party to obtain a first slice of the multiplication result; the second party obtains a second slice of the multiplication result; wherein, the second multiplier is constructed by the second party based on the second data slice it holds; the multiplication result has two possible values. It is understood that since the sum of the first data slice and the second data slice equals the first intermediate data, or equals the sum of the first intermediate data and the first modulus, the multiplication result has two possible values.

[0122] The selection of the second modulus ensures that the non-zero bits of the multiplication result are either in the lower-order first modulus bit or in the higher-order first modulus bit.

[0123] Finally, in step 34, the first slice of the multiplication result is converted into the first result slice of the exponentiation result in the target modulus space; the second party obtains the corresponding second result slice. It is understood that, since the multiplication result has two possible values, the above conversion includes determining the unique value of the exponentiation result through these two values, and also involves modulus conversion.

[0124] The method provided in this specification embodiment distributes the privacy data in an initial modular space in a shared manner between the first party and the second party. This method is used to obtain a result fragment in a target modular space from the result of a power operation with the public data as the base and the privacy data as the exponent. First, the first party, at least based on its own fragment of the privacy data, locally calculates a first data fragment of the first intermediate data in the first modular space; wherein the first intermediate data is a non-negative value, and the first modulus corresponding to the first modular space is determined according to the modulus of the target modular space; the second data fragment of the first intermediate data in the first modular space is held by the second party; then, based on the first data... The fragmentation, as a local exponentiation operation, is constructed using a first multiplier in a second modular space. The second modular space corresponds to a second modular number determined based on the first modular number. Then, a secure multiplication operation is performed based on the first multiplier provided by the first party and the second multiplier provided by the second party, resulting in a first fragment of the multiplication result. The second party obtains a second fragment of the multiplication result. The second multiplier is constructed by the second party based on its held second data fragments. The multiplication result has two possible values. Finally, the first fragment of the multiplication result is converted into a first result fragment of the exponentiation result in the target modular space. The second party obtains the corresponding second result fragment. As can be seen from the above, this embodiment of the specification, by constructing a multiplier, converts secure exponentiation into secure multiplication, and extracts the exponentiation result from the multiplication result of the secure multiplication, thereby achieving secure exponentiation with low communication volume and high performance.

[0125] Reference Figure 1 In the implementation scenario shown, 'a' represents public data and 'x' represents private data. The question is whether 'a' and 'x' are integers, and when 'a = sign(a) × n'... k Is k an integer? Figure 3 The specific execution methods for each step shown are slightly different.

[0126] The specific execution methods for each of the above steps are described below for several different scenarios.

[0127] Case 1: Both k and x are integers.

[0128] In this case, the sign of 'a' can be either positive or negative. If d1 >= 0, x can be accurately recovered from the fragments of x. If d1 < 0, x cannot be accurately recovered from the fragments of x, and only a positive sign of 'a' is supported.

[0129] In one example, the local fragment is a fragment of the privacy data multiplied by n to the power of d1 in the initial modulus space, the result fragment is a fragment of the result of the exponentiation multiplied by n to the power of d2 in the target modulus space, the absolute value of the public data is expressed as n to the power of k, k and the privacy data are both integers, the minimum value of the target product of k and the privacy data is u, u is an integer, and the modulus of the target modulus space is n to the power of t2;

[0130] The first data fragment of the first intermediate data computed locally in the first module space includes:

[0131] Based on the product of the local segment and k divided by n raised to the power of d1, and then rounded down, the first intermediate data is locally calculated as the first data segment in the first modulus space; the first intermediate data is the result of the target product minus u; the first modulus is the larger value between 0 and -d2-u plus t2.

[0132] For example, a x Convert to a base-2 exponentiation operation: sign(a) x ×2 kx a = sign(a) × 2 k Let z = kx. The range of z is [u, v]. Both the first and second parties securely compute c = kx - u, each obtaining a partition of c modulo h0. The first party computes... <c>0=floor(k <x>0 / 2 d1 )%h0, second-party calculation <c>1=ceil(k <x>1 / 2 d1 -u)%h0, that is, c=kx-u, with a value range of [0,vu], and c is a non-negative number. And we have... <c> 0+ <c>1 = c or c + h0 = kx - u or kx - u + h0.

[0133] Understandably, `c` represents the first intermediate data, and `h0` represents the first modulus. The `floor` function rounds down, returning the largest integer not greater than the specified expression. The `ceil` function rounds up, returning the smallest integer greater than or equal to the specified expression.

[0134] If d² + u >= 0, then h₀ = t²; otherwise, h₀ = t² - d² - u. That is, h₀ = t² + max(0, -d² - u).

[0135] In one example, the local fragment is a fragment of the privacy data multiplied by n to the power of d1 in the initial modulus space, the result fragment is a fragment of the result of the exponentiation multiplied by n to the power of d2 in the target modulus space, the absolute value of the public data is expressed as n to the power of k, k and the privacy data are both integers, the minimum value of the target product of k and the privacy data is u, u is an integer and u is greater than or equal to 0, and the modulus of the target modulus space is n to the power of t2;

[0136] The first data fragment of the first intermediate data computed locally in the first module space includes:

[0137] Based on the product of the local partition and k, divided by n raised to the power of d1, and then rounded down, the first intermediate data is locally calculated as the first data partition in the first modulus space; the first intermediate data is the result of the target product; the first modulus is the larger value between 0 and -d2 plus t2.

[0138] For example, if u>=0, then the aforementioned c=kx-u can be replaced by c=kx, which satisfies that c is a non-negative number.

[0139] Furthermore, the first multiplier constructed in the second modulus space includes:

[0140] If the publicly available data is positive, the first base number is determined to be 1; if the publicly available data is negative, the first base number is determined to be -1.

[0141] Divide the aforementioned segment by n raised to the power of d1, and then round down to determine the first power value;

[0142] Using the first base as the base and the first power as the exponent, perform exponentiation to obtain the first product term;

[0143] Using n as the base and the first data segment as the exponent, perform exponentiation to obtain the second product term;

[0144] Multiplying the first product term by the second product term yields the first multiplier in the second modular space; the second modulus corresponding to the second modular space is the result of a local exponentiation operation with n as the base and twice the first modulus as the exponent.

[0145] For example, first-party calculation Second-party calculation If a is a positive number, sign(a) is 1. and It can be omitted. If a is negative, sign(a) is -1.

[0146] It is understandable that w0 is the first multiplier, w1 is the second multiplier, and 2 h2 Let h2 be the second modulus. Let h2 = 2h0.

[0147] In the embodiments of this specification, the safe multiplication operation in step 33 is the safe calculation between both parties. Regardless of the sign of x, if d1>=0, then <x> 0+ <x>1 / 2 d1 and x and x%2 h0 They have the same parity, therefore we have therefore,

[0148] It is understandable that 'b' represents the result of the multiplication, and |b| has only one bit that is 1, which belongs to either the lower h0 bit or the higher h0 bit. The first slice of the multiplication result obtained by the first side is denoted as... 0; the second slice of the result obtained from the second power is denoted as . 1.

[0149] Further, the step of converting the first slice of the multiplication result into the first result slice of the exponentiation result in the target modular space includes:

[0150] The multiplication result is treated as n-ary data. The first segment value of the first modulus bit with non-zero bits is extracted from the first segment of the multiplication result, or the second segment value of the first modulus bit with non-zero bits is extracted from the first segment of the multiplication result, so as to determine the first segment of the second intermediate result of the third modulus space.

[0151] Multiply the first slice of the second intermediate result by n raised to the power of d² + u, and then round it to the nearest integer to obtain the first result slice of the power operation result in the target modulus space.

[0152] For example, the result of multiplication, b, can take two values: b = sign(a). x 2 kx-u Or sign(a) x 2 kx-u+h0 We need to obtain b′=sign(a) based on b. x 2 kx-u b′ is the second intermediate result. The first party holds a slice of b′.<b′> 0, the second party holds another fragment of b′.<b′> 1. First-party calculation of the first result fragment. <y>0 = round(<b′> 0×2 d2+u )%2 t2 The second party calculates the second result fragment. <y>1 = round(<b′> 1×2 d2+u )%2 t2 Where +u is optional; if c = kx, then here... <y>0=round(<b′>0×2 d2 )%2 t2 , <y>1 = round(<b′> 1×2 d2 )%2 t2 .

[0153] In this case, an approximation algorithm can be used to make b′ approximately equal to sign(a). x 2 kx-u Alternatively, an exact algorithm can be used to make b′ exactly equal to sign(a). x 2 kx-u .

[0154] Furthermore, the first slice of the second intermediate result for determining the third modulus space includes:

[0155] The multiplication result is treated as n-ary data. The first segment value of the first modulus bit of the lower digits and the second segment value of the first modulus bit of the higher digits are extracted from the first segment of the multiplication result.

[0156] The summation of the values ​​of the first segment and the second segment yields the first piece of the second intermediate result in the third modulus space.

[0157] This example belongs to the category of approximation algorithms. For example, first-party computation...<b′> 0 = 0+round( 0 / 2 h0 )%2 h0 Second-party calculation<b′> 1 = 1+round( 1 / 2 h0 )%2 h0 .

[0158] It can be verified that if b = sign(a) x 2 kx-u Then b%2 h0 =sign(a) x 2 kx-u And round ( 0 / 2 h0 )+round( 1 / 2 h0 )%2 h0 ≈0; if b = sign(a) x 2 kx-u+h0 Then b%2 h0 =0 and round( 0 / 2 h0 )+round( 1 / 2 h0 )%2 h0 ≈sign(a) x 2 kx-u Therefore, b′≈sign(a) x 2 kx-u .

[0159] Furthermore, the first slice of the second intermediate result for determining the third modulus space includes:

[0160] The multiplication result is treated as n-ary data. Based on the first slice of the multiplication result held by this party and the second slice of the multiplication result held by the second party, a secure comparison operation is performed to obtain a comparison result of whether the multiplication result is greater than or equal to the first modulus.

[0161] If the comparison result is that the multiplication result is less than the first modulus, then the first segment value of the low first modulus bit of the first segment of the multiplication result is extracted, and the first segment value is used as the first segment of the second intermediate result of the third modulus space.

[0162] If the comparison result is that the multiplication result is greater than or equal to the first modulus, then the second segment value of the high-order first modulus bit of the first segment of the multiplication result is extracted, and the second segment value is used as the first segment of the second intermediate result of the third modulus space.

[0163] This example belongs to the category of exact algorithms. For example, the first and second parties' security comparison e = ( <c> 0+ <c>(1≥h0), each party obtains a fragment of the comparison result e, and performs the following security selection protocol based on the comparison result e, resulting in:

[0164] If e = 0, then b' = b%2 h0 =sign(a) x 2 kx-u If e == 1, then<b′> 0 = floor( 0 / 2 h0 );<b′>1=ceil( 1 / 2 h0 Therefore, b′=sign(a). x 2 kx-u .

[0165] Case 2: Both a and x are integers.

[0166] In this case, the sign of 'a' can be either positive or negative. If d1 >= 0, x can be accurately recovered from the fragments of x. If d1 < 0, x cannot be accurately recovered from the fragments of x, and only a positive sign of 'a' is supported.

[0167] In one example, the local fragment is a fragment of the privacy data multiplied by n raised to the power of d1 in the initial modulus space, and the result fragment is a fragment of the result of the power operation multiplied by n raised to the power of d2 in the target modulus space. The public data and the privacy data are both integers, the minimum value of the privacy data is u', and the modulus of the target modulus space is n raised to the power of t2.

[0168] The first data fragment of the first intermediate data computed locally in the first module space includes:

[0169] Based on the local partition divided by n raised to the power of d1 and then rounded down, the first intermediate data is locally calculated as the first data partition in the first modulus space; the first intermediate data is the privacy data minus u'; the first modulus is determined based on n raised to the power of d2, the absolute value of the public data, and n raised to the power of t2.

[0170] For example, the range of x is [u', v']. Both the first and second parties securely compute c = xu', each obtaining a slice of c modulo h0. Specifically, the first party computes... <c>0=floor( <x>0 / 2 d1 )%h0, second-party calculation <c>1=ceil( <x>1 / 2 d1 -u')%h0, that is, c = xu', with a value range of [0, v'-u'], and c is a non-negative number. And we have... <c> 0+ <c>1 = c or c + h0 = xu' or xu' + h0.

[0171] It is understandable that c represents the first intermediate data and h0 represents the first modulus. The value of h0 is related to the subsequent processing, so it will be introduced later.

[0172] In one example, the local fragment is a fragment of the privacy data multiplied by n raised to the power of d1 in the initial modulus space, where both the public data and the privacy data are integers, and the minimum value of the privacy data is u' and u' is greater than or equal to 0;

[0173] The first data fragment of the first intermediate data computed locally in the first module space includes:

[0174] Based on the local partitioning divided by n raised to the power of d1 and then rounded down, the first intermediate data is locally calculated as the first data partition in the first modulus space; the first intermediate data is the privacy data.

[0175] For example, if u' >= 0, then the aforementioned c = xu' can be replaced by c = x, which satisfies that c is a non-negative number.

[0176] Furthermore, the first multiplier constructed in the second modulus space includes:

[0177] If the publicly available data is positive, the first base number is determined to be 1; if the publicly available data is negative, the first base number is determined to be -1.

[0178] Divide the aforementioned segment by n raised to the power of d1, and then round down to determine the first power value;

[0179] Using the first base as the base and the first power as the exponent, perform exponentiation to obtain the first product term;

[0180] Using the absolute value of the publicly available data as the base and the first data segment as the exponent, a power operation is performed to obtain the second product term;

[0181] Multiplying the first product term by the second product term yields the first multiplier in the second modular space; the second modulus corresponding to the second modular space is the result of a local exponentiation operation with the absolute value of the disclosed data as the base and twice the first modulus as the exponent.

[0182] For example, first-party calculation Second-party calculation If a is a positive number, sign(a) is 1. and It can be omitted. If a is negative, sign(a) is -1.

[0183] It is understandable that w0 is the first multiplier, w1 is the second multiplier, and |a| h2 Let h2 be the second modulus. Let h2 = 2h0.

[0184] In the embodiments of this specification, the safe multiplication operation in step 33 is the safe calculation between both parties. Regardless of the sign of x, if d1>=0, then <x> 0+ <x>1 / 2 d1 The parity of x is the same as that of x, therefore we have therefore,

[0185] It is understandable that 'b' represents the result of the multiplication. In base |a|, |b| has only one bit that is 1, which belongs to either the lower h0 bit or the higher h0 bit. The first slice of the multiplication result obtained by the first side is denoted as... 0; the second slice of the result obtained from the second power is denoted as . 1.

[0186] Further, the step of converting the first slice of the multiplication result into the first result slice of the exponentiation result in the target modular space includes:

[0187] The multiplication result is treated as data in the absolute value base of the public data. For the first segment of the multiplication result, the first segment value of the first modulus bit with non-zero bits in the lower bits is extracted, or the second segment value of the first modulus bit with non-zero bits in the higher bits is extracted, to determine the first segment of the second intermediate result of the third modulus space; the third modulus corresponding to the third modulus space is the result of local exponentiation with the absolute value of the public data as the base and the first modulus as the exponent.

[0188] Multiply the first slice of the second intermediate result by the absolute value of the public data to the power of u', and then multiply by the scaling term to obtain the first slice of the third intermediate result in the third modulus space; the scaling term is the value obtained by multiplying the third modulus by the power of d2 of n and dividing by the power of t2 of n, and then rounding to the nearest integer.

[0189] Multiply the first slice of the third intermediate result by n raised to the power of t2 and divide by the third modulus, then round to the nearest integer to obtain the first result slice of the power operation result in the target modulus space.

[0190] For example, the result of multiplication, b, can take two values: b = sign(a). x |a| x-u′ Or sign(a) x |a| x-u′+h0 We need to obtain b′=sign(a) based on b. x |a| x-u′ b′ is the second intermediate result. The first party holds a slice of b′.<b′> 0, the second party holds another fragment of b′.<b′> 1. Both parties calculate the safety of b″ = b′ × |a| u′ ×round(2 d2 ×|a| h0 / 2 t2 )%|a| h0 b″ is a third intermediate result. The first party holds a fragment of b″.<b″> 0, the second party holds another fragment of b″.<b″> 1. h0 should be large enough to prevent overflow when calculating b″. |a| h0 ≥2 t2 This will satisfy the requirement. The first-party computes the first result fragment. <y>0 = round(<b″> 0×2 t2 / |a| h0 )%2 t2 The second party calculates the second result fragment. <y>1 = round(<b″> 1×2 t2 / |a| h0 )%2 t2 Among them, when calculating b″, ×|a| u′ Optional, if c = x, then b″ = b′ × round(2) d2 ×|a| h0 / 2 t2 )%|a| h0 This example includes conversion handling between non-divisible moduli. Calculating b″ and y involves scaling and modulo conversion, requiring round(2... d2 ×|a| h0 / 2 t2 )≈2 d2 ×|a| h0 / 2 t2 h0 should be large enough and appropriate enough.

[0191] In this case, an approximation algorithm can be used to make b′ approximately equal to sign(a). x |a| x-u′ Alternatively, an exact algorithm can be used to make b′ exactly equal to sign(a). x |a| x-u′ .

[0192] Furthermore, the first slice of the second intermediate result for determining the third modulus space includes:

[0193] The multiplication result is treated as absolute value data of the public data. The first segment value of the first modulus bit of the lower part of the first segment of the multiplication result is extracted, and the second segment value of the first modulus bit of the higher part is extracted.

[0194] The summation of the values ​​of the first segment and the second segment yields the first piece of the second intermediate result in the third modulus space.

[0195] This example belongs to the category of approximation algorithms. For example, first-party computation...<b′> 0 = 0+round( 0 / |a| h0 )%|a| h0 Second-party calculation<b′> 1 = 1+round( 1 / |a| h0 )%|a| h0 .

[0196] It can be verified that if b = sign(a) x |a| x-u′ Then b%|a| h0 =sign(a) x |a| x-u′ And round ( 0 / |a| h0 )+round( 1 / |a| h0 )%|a| h0 ≈0; if b = sign(a) x |a| x-u′+h0 Then b%|a| h0 =0 and round( 0 / |a| h0 )+round( 1 / |a| h0 )%|a| h0 ≈sign(a) x |a| x-u′ Therefore, b′≈sign(a) x |a| x-u′ .

[0197] Furthermore, the first slice of the second intermediate result for determining the third modulus space includes:

[0198] The multiplication result is treated as absolute value data of the public data. Based on the first slice of the multiplication result held by this party and the second slice of the multiplication result held by the second party, a secure comparison operation is performed to obtain a comparison result of whether the multiplication result is greater than or equal to the first modulus.

[0199] If the comparison result is that the multiplication result is less than the first modulus, then the first segment value of the low first modulus bit of the first segment of the multiplication result is extracted, and the first segment value is used as the first segment of the second intermediate result of the third modulus space.

[0200] If the comparison result is that the multiplication result is greater than or equal to the first modulus, then the second segment value of the high-order first modulus bit of the first segment of the multiplication result is extracted, and the second segment value is used as the first segment of the second intermediate result of the third modulus space.

[0201] This example belongs to the category of exact algorithms. For example, the first and second parties' security comparison e = ( <c> 0+ <c>(1≥h0), each side obtains a fragment of the comparison result e, and based on the comparison result e, performs the following two security choices, resulting in:

[0202] If e = 0, then b′ = b%|a| h0 =sign(a) x |a| x-u′ If e == 1, then<b′> 0 = floor( 0 / |a| h0 );<b′> 1=hide( 1 / |a| h0 Therefore, b′=sign(a). x |a| x-u′ .

[0203] Case 3: x is not an integer.

[0204] In this case, the sign of 'a' is non-negative.

[0205] In one example, the local fragment is a fragment of the privacy data multiplied by n to the power of d1 in the initial modulus space, and the result fragment is a fragment of the result of the power operation multiplied by n to the power of d2 in the target modulus space. The privacy data is not an integer, the public data is represented as n to the power of k, the minimum value of the target product of k and the privacy data is u, and the maximum value is v. Both u and v are integers. The precision of the target product is supported to be d3 decimal places, and the modulus of the target modulus space is n to the power of t2.

[0206] The first data fragment of the first intermediate data computed locally in the first module space includes:

[0207] Based on the product of the local partition and k, divided by n raised to the power of d1, multiplied by n raised to the power of d3', and then rounded to the nearest integer, the first intermediate data is locally calculated as the first data partition in the first modulus space; the first intermediate data is the result of the target product minus u and then multiplied by n raised to the power of d3'; the first modulus is h0 multiplied by n raised to the power of d3', where h0 is determined based on d2, u, v, d2' and t2, d3' is greater than d3, and d2' is greater than d2.

[0208] For example, a x Convert to a base-2 exponentiation operation: sign(a) x ×2 kx a = sign(a) × 2 k Let z = kx. The range of z is [u, v]. The safety calculation for both the first and second parties is c = (kx - u) × 2. d3′ Each obtains a partition of c modulo h1. The first method calculates... <c>0=round((k <x>0 / 2 d1 )×2 d3′ )%h1, second-party calculation <c>1=round((k <x>1 / 2 d1 -u)×2 d3′ )%h1, that is, c=(kx-u)×2 d3′ The value range is [0, (vu)×2]. d3′ ], where c is a non-negative number. And we have ( <c> 0+ <c>1) / 2 d3′ =c / 2 d3′ Or (c+h1) / 2 d3′ ≈kx-u or kx-u+h0.

[0209] It is understandable that c is the first intermediate data and h1 is the first modulus. Also, h1 = h0 × 2. d3′ If k is a decimal or d3'-d1<0, it will introduce a certain error. The effect can be reduced by slightly increasing the value of d3'.

[0210] In one example, the local fragment is a fragment of the privacy data multiplied by n to the power of d1 in the initial modulus space, and the result fragment is a fragment of the result of the power operation multiplied by n to the power of d2 in the target modulus space. The privacy data is not an integer, the public data is represented as n to the power of k, the minimum value of the target product of k and the privacy data is u, and the maximum value is v. u and v are both integers and u is greater than or equal to 0. The precision of the target product is supported to be d3 decimal places, and the modulus of the target modulus space is n to the power of t2.

[0211] The first data fragment of the first intermediate data computed locally in the first module space includes:

[0212] Based on the product of the local partition and k, divided by n raised to the power of d1, multiplied by n raised to the power of d3', and then rounded to the nearest integer, the first intermediate data is locally calculated as the first data partition in the first modulus space; the first intermediate data is the result of the target product multiplied by n raised to the power of d3'; the first modulus is h0 multiplied by n raised to the power of d3', where h0 is determined based on d2, u, v, d2' and t2, with d3' greater than d3 and d2' greater than d2.

[0213] For example, if u>=0, then the aforementioned c=(kx-u)×2 d3′ It can be replaced by c = kx × 2 d3′ , which satisfies that c is a non-negative number.

[0214] Furthermore, the first multiplier constructed in the second modulus space includes:

[0215] Divide the aforementioned piecewise segment by n raised to the power of d3', and add d4 to determine the first power value; where d4 is determined based on d2, v, and d2'.

[0216] With n as the base and the first power as the exponent, perform exponentiation, then round to the nearest integer to obtain the first multiplier in the second modular space; the second modulus corresponding to the second modular space is the result of local exponentiation with n as the base and twice h0 as the exponent.

[0217] For example, first-party calculation And ensure that the number of significant digits does not exceed v-u+d4; if it does, round off the excess digits to 0; the second calculation And ensure that the number of significant digits does not exceed v-u+d4. If it does, round the extra digits to 0.

[0218] It is understandable that w0 is the first multiplier, w1 is the second multiplier, and 2 h2 Let h2 be the second modulus. Let h2 = 2h0.

[0219] In the embodiments of this specification, the safe multiplication operation in step 33 is the safe calculation of b = w0 × by both parties. or 2 kx-u+2d4+h0 .

[0220] Understandably, b represents the result of the multiplication. The first slice of the result obtained from the first side is denoted as... 0; the second slice of the result obtained from the second power is denoted as . 1.

[0221] It is understandable that y can be derived from... and The product is extracted, but since safe multiplication can only be performed on integers, the two multipliers need to be scaled and rounded before safe multiplication. Scaling is necessary because the result y requires scaling by 2. d2 After multiplying and splitting into fragments, the result y has at most v+d2 bits stored in each fragment. On the other hand, to ensure the precision of y, the multiplier needs to be increased. Because... The minimum value is 1, magnified by 2. d4 =2 d2+(v+d2′) The requirement can be met, where i = 0 or 1.

[0222] Further, the step of converting the first slice of the multiplication result into the first result slice of the exponentiation result in the target modular space includes:

[0223] The multiplication result is treated as n-ary data. The first slice of the multiplication result is multiplied by an amplification term to obtain the first slice of the second intermediate result. The amplification term is the result of a local exponentiation operation with n as the base and 2(v-u+d4) as the exponent. Wherein, d4 is determined according to d2, v, and d2'.

[0224] For the first segment of the second intermediate result, extract the first segment value of the low h0 bit containing non-zero bits, or extract the second segment value of the high h0 bit containing non-zero bits, to determine the first segment of the third intermediate result in the third modulus space; the third modulus corresponding to the third modulus space is 2 raised to the power of h0.

[0225] Multiply the first slice of the third intermediate result by n raised to the power of d² + 3u - 4d⁴ - 2v, and then round it to the nearest integer to obtain the first result slice of the power operation result in the target modulus space.

[0226] For example, the result of multiplication, b, can take two values: b = 2. kx-u+2d4 or 2 kx-u+2d4+h0 We need to obtain b′=b×2 based on b. 2(v-u+d4) b′ is the second intermediate result. The first party holds a slice of b′.<b′> 0, the second party holds another fragment of b′.<b′> 1. b′ has at most 2(v-u+d4)-1 significant digits, all located in either the lower h0 bit or the higher h0 bit. Here, h0 is required to be greater than max(kx-u+2d4)+2(v-u+d4)=3v-3u+4d4. Therefore, b″=2 needs to be obtained from b′. kx-3u+4d4+2v b″ is a third intermediate result. The first party holds a fragment of b″.<b″> 0, the second party holds another fragment of b″.<b″> 1. First-party calculation of the first result fragment. <y>0 = round(<b″> 0×2 d2+3u-4d4-2v )%2 t2 The second party calculates the second result fragment. <y>1 = round(<b″> 1×2 d2+3u-4d4-2v )%2 t2 Here, we require h0 + d2 + 3u - 4d4 - 2v ≥ t2, which means h0 ≥ t2 - (d2 + 3u - 4d4 - 2v) = t2 + 4d4 + 2v - d2 - 3u. Alternatively, h0 = t2 - (d2 + 3u - 4d4 - 2v) satisfies the requirement. Based on the previous analysis, we also have d4 = d2 + (v + d2') and h0 = t2 - (d2 + 3u - 4d4 - 2v) = t2 - d2 - 3u + 2v + 4d2 + 4v + 4d2' = t2 - 3u + 6v + 3d2 + 4d2'.

[0227] Among them, an approximation algorithm can be used to make b″ approximately equal to 2. kx-3u+4d4+2v .

[0228] Furthermore, the first slice of determining the third intermediate result of the third modulus space includes:

[0229] The multiplication result is treated as n-ary data. The first segment value of the low-order h0 bits of the first segment of the second intermediate result is extracted, and the second segment value of the high-order h0 bits is extracted.

[0230] The summation of the values ​​of the first segment and the second segment yields the first slice of the third intermediate result in the third modulus space.

[0231] For example, the safe calculation for both parties is b″ = b′ + round(b′ / 2). h0 )%2 h0 The `round` function represents rounding down the slice.

[0232] It can be verified that if b = 2 kx-u+2d4 Then b′%2 h0 =2 kx-u+2d4+2(v-u+d4) =2 kx-3u+4d4+2v And round(b′ / 2) h0 )%2 h0 ≈0; if b = 2 kx-u+2d4+h0 Then b′%2 h0 =0 and round(b′ / 2) h0 )%2 h0 ≈2 kx-3u+4d4+2v Therefore, b″≈2 kx-3u+4d4+2v .

[0233] Case 4: x is an integer.

[0234] In this case, the sign of 'a' can be either positive or negative. If d1 >= 0, x can be accurately recovered from the fragments of x. If d1 < 0, x cannot be accurately recovered from the fragments of x, and only a positive sign of 'a' is supported.

[0235] Case 4 is handled similarly to Case 3, except that the sign is handled. If the sign of 'a' is positive, then the sign does not need to be handled.

[0236] In one example, the local fragment is a fragment of the privacy data multiplied by n to the power of d1 in the initial modulus space, and the result fragment is a fragment of the result of the power operation multiplied by n to the power of d2 in the target modulus space. The privacy data is an integer, the absolute value of the public data is expressed as n to the power of k, the minimum value of the target product of k and the privacy data is u, and the maximum value is v. Both u and v are integers, the precision of the target product is supported to be d3 decimal places, and the modulus of the target modulus space is n to the power of t2.

[0237] The first data fragment of the first intermediate data computed locally in the first module space includes:

[0238] Based on the product of the local partition and k, divided by n raised to the power of d1, multiplied by n raised to the power of d3', and then rounded to the nearest integer, the first intermediate data is locally calculated as the first data partition in the first modulus space; the first intermediate data is the result of the target product minus u and then multiplied by n raised to the power of d3'; the first modulus is h0 multiplied by n raised to the power of d3', where h0 is determined based on d2, u, v, d2' and t2, d3' is greater than d3, and d2' is greater than d2.

[0239] For example, a x Convert to a base-2 exponentiation operation: sign(a) x ×2 kx a = sign(a) × 2 k Let z = kx. The range of z is [u, v]. The safety calculation for both the first and second parties is c = (kx - u) × 2. d3′ Each obtains a partition of c modulo h1. The first method calculates... <c>0=round((k <x>0 / 2 d1 )×2 d3′ )%h1, second-party calculation <c>1=round((k <x>1 / 2 d1 -u)×2 d3′ )%h1, that is, c=(kx-u)×2 d3′ The value range is [0, (vu)×2]. d3′ ], where c is a non-negative number. And we have ( <c> 0+ <c>1) / 2 d3′ =c / 2 d3′ Or (c+h1) / 2 d3′ ≈kx-u or kx-u+h0.

[0240] It is understandable that c is the first intermediate data and h1 is the first modulus. Also, h1 = h0 × 2. d3′ If k is a decimal or d3'-d1<0, it will introduce a certain error. The effect can be reduced by slightly increasing the value of d3'.

[0241] In one example, the local fragment is a fragment of the privacy data multiplied by n to the power of d1 in the initial modulus space, and the result fragment is a fragment of the result of the exponentiation multiplied by n to the power of d2 in the target modulus space. The privacy data is an integer, the absolute value of the public data is expressed as n to the power of k, the minimum value of the target product of k and the privacy data is u, and the maximum value is v. u and v are both integers and u is greater than or equal to 0. The precision of the target product is supported to be d3 decimal places, and the modulus of the target modulus space is n to the power of t2.

[0242] The first data fragment of the first intermediate data computed locally in the first module space includes:

[0243] Based on the product of the local partition and k, divided by n raised to the power of d1, multiplied by n raised to the power of d3', and then rounded to the nearest integer, the first intermediate data is locally calculated as the first data partition in the first modulus space; the first intermediate data is the result of the target product multiplied by n raised to the power of d3'; the first modulus is h0 multiplied by n raised to the power of d3', where h0 is determined based on d2, u, v, d2' and t2, with d3' greater than d3 and d2' greater than d2.

[0244] For example, if u>=0, then the aforementioned c=(kx-u)×2 d3′ It can be replaced by c = kx × 2 d3′ , which satisfies that c is a non-negative number.

[0245] Furthermore, the first multiplier constructed in the second modulus space includes:

[0246] If the publicly available data is positive, the first base number is determined to be 1; if the publicly available data is negative, the first base number is determined to be -1.

[0247] Divide the aforementioned segment by n raised to the power of d1, and then round down to determine the first power value;

[0248] Using the first base as the base and the first power as the exponent, perform exponentiation to obtain the first product term;

[0249] Divide the aforementioned piecewise segment by n raised to the power of d3', and add d4 to determine the second power value; where d4 is determined based on d2, v, and d2'.

[0250] Using n as the base and the second power as the exponent, perform exponentiation, then round to the nearest integer to obtain the second product term;

[0251] Calculate the first product term multiplied by the second product term to obtain the first multiplier in the second modular space; the second modulus corresponding to the second modular space is the result of local exponentiation with base n and exponent of twice h0.

[0252] For example, first-party calculation And ensure that the number of significant digits does not exceed v-u+d4; if it does, round off the excess digits; second calculation And ensure that the number of significant digits does not exceed v-u+d4. If it does, round off the extra digits.

[0253] It is understandable that w0 is the first multiplier, w1 is the second multiplier, and 2 h2 Let h2 be the second modulus. Let h2 = 2h0.

[0254] In the embodiments of this specification, the safe multiplication operation in step 33 is the safe calculation of b = w0 × by both parties. If d1≥0, then ( <x> 0+ <x>1) / 2 d1 The parity of x is the same as that of x. therefore,

[0255] Understandably, b represents the result of the multiplication. The first slice of the result obtained from the first side is denoted as... 0; the second slice of the result obtained from the second power is denoted as . 1.

[0256] Understandably, the result y requires scaling by 2. d2 After multiplying and splitting into fragments, the result y has at most v+d2 bits stored in each fragment; to ensure the precision of y, the multiplier needs to be increased. Because The minimum value is 1, magnified by 2. d4 =2 d2+(v+d2′) The requirement can be met, where i = 0 or 1.

[0257] Further, the step of converting the first slice of the multiplication result into the first result slice of the exponentiation result in the target modular space includes:

[0258] The multiplication result is treated as n-ary data. The first slice of the multiplication result is multiplied by an amplification term to obtain the first slice of the second intermediate result. The amplification term is the result of a local exponentiation operation with n as the base and 2(v-u+d4) as the exponent. Wherein, d4 is determined according to d2, v, and d2'.

[0259] For the first segment of the second intermediate result, extract the first segment value of the low h0 bit containing non-zero bits, or extract the second segment value of the high h0 bit containing non-zero bits, to determine the first segment of the third intermediate result in the third modulus space; the third modulus corresponding to the third modulus space is 2 raised to the power of h0.

[0260] Multiply the first slice of the third intermediate result by n raised to the power of d² + 3u - 4d⁴ - 2v, and then round it to the nearest integer to obtain the first result slice of the power operation result in the target modulus space.

[0261] For example, the result of multiplication, b, can take two values: b = sign(a). x 2 kx-u+2d4 Or sign(a) x 2 kx-u+2d4+h0 We need to obtain b′=b×2 based on b. 2(v-u+d4) b′ is the second intermediate result. The first party holds a slice of b′.<b′> 0, the second party holds another fragment of b′.<b′> 1. b′ has at most 2(v-u+d4)-1 significant digits, all located in either the lower h0 bit or the higher h0 bit. Here, it is required that h0 > max(kx-u+2d4)+2(v-u+d4) = 3v-3u+4d4. We need to obtain b″ = sign(a) based on b′. x 2 kx-3u+4d4+2v b″ is a third intermediate result. The first party holds a fragment of b″.<b″> 0, the second party holds another fragment of b″.<b″> 1. First-party calculation of the first result fragment. <y>0 = round(<b″> 0×2 d2+3u-4d4-2v )%2 t2 The second party calculates the second result fragment. <y>1 = round(<b″> 1×2 d2+3u-4d4-2v )%2 t2 Here, we require h0 + d2 + 3u - 4d4 - 2v ≥ t2, which means h0 ≥ t2 - (d2 + 3u - 4d4 - 2v) = t2 + 4d4 + 2v - d2 - 3u. Alternatively, h0 = t2 - (d2 + 3u - 4d4 - 2v) satisfies the requirement. Based on the previous analysis, we also have d4 = d2 + (v + d2') and h0 = t2 - (d2 + 3u - 4d4 - 2v) = t2 - d2 - 3u + 2v + 4d2 + 4v + 4d2' = t2 - 3u + 6v + 3d2 + 4d2'.

[0262] Among these, an approximation algorithm can be used to make b″ approximately equal to sign(a). x 2 kx-3u+4d4+2v .

[0263] Furthermore, the first slice of determining the third intermediate result of the third modulus space includes:

[0264] The multiplication result is treated as n-ary data. The first segment value of the low-order h0 bits of the first segment of the second intermediate result is extracted, and the second segment value of the high-order h0 bits is extracted.

[0265] The summation of the values ​​of the first segment and the second segment yields the first slice of the third intermediate result in the third modulus space.

[0266] For example, the safe calculation for both parties is b″ = b′ + round(b′ / 2). h0 )%2 h0 The `round` function represents rounding down the slice.

[0267] It can be verified that if b = sign(a) x 2 kx-u+2d4 Then b′%2 h0 =sign(a) x 2 kx-u+2d4+2(v-u+d4) =sign(a) x 2 kx-3u+4d4+2v And round(b′ / 2) h0 )%2 h0 ≈0; if b = sign(a) x 2 kx-u+2d4+h0 Then b′%2 h0 =0 and round(b′ / 2) h0 )%2 h0 ≈sign(a) x 2 kx-3u+4d4+2v Therefore, b″≈sign(a) x 2 kx-3u+4d4+2v .

[0268] The method provided in this specification embodiment distributes the privacy data in an initial modular space in a shared manner between the first party and the second party. This method is used to obtain a result fragment in a target modular space from the result of a power operation with the public data as the base and the privacy data as the exponent. First, the first party, at least based on its own fragment of the privacy data, locally calculates a first data fragment of the first intermediate data in the first modular space; wherein the first intermediate data is a non-negative value, and the first modulus corresponding to the first modular space is determined according to the modulus of the target modular space; the second data fragment of the first intermediate data in the first modular space is held by the second party; then, based on the first data... The fragmentation, as a local exponentiation operation, is constructed using a first multiplier in a second modular space. The second modular space corresponds to a second modular number determined based on the first modular number. Then, a secure multiplication operation is performed based on the first multiplier provided by the first party and the second multiplier provided by the second party, resulting in a first fragment of the multiplication result. The second party obtains a second fragment of the multiplication result. The second multiplier is constructed by the second party based on its held second data fragments. The multiplication result has two possible values. Finally, the first fragment of the multiplication result is converted into a first result fragment of the exponentiation result in the target modular space. The second party obtains the corresponding second result fragment. As can be seen from the above, this embodiment of the specification, by constructing a multiplier, converts secure exponentiation into secure multiplication, and extracts the exponentiation result from the multiplication result of the secure multiplication, thereby achieving secure exponentiation with low communication volume and high performance.

[0269] According to another embodiment, a secure processing apparatus for privacy data is also provided, which is used to perform the present specification. Figure 3 The method provided in the illustrated embodiment involves the privacy data being distributed in an initial modular space in a shared manner between a first party and a second party. The apparatus is used to obtain a result fragment in a target modular space of the result of a power operation with the public data as the base and the privacy data as the exponent. The apparatus is located on the first party. Figure 4 A schematic block diagram of a privacy data security processing apparatus according to one embodiment is shown. Figure 4 As shown, the system 400 includes:

[0270] Local computing unit 41 is used to locally compute a first data fragment of the first intermediate data in a first modulus space, based at least on the local fragment of the privacy data; wherein the first intermediate data is a non-negative value, and the first modulus corresponding to the first modulus space is determined according to the modulus value of the target modulus space; the second data fragment of the first intermediate data in the first modulus space is held by the second party;

[0271] The multiplier construction unit 42 is used to construct a first multiplier in the second modular space based on a local exponentiation operation using the first data fragment obtained by the local computing unit 41 as the exponent; the second modulus corresponding to the second modular space is determined based on the first modulus.

[0272] The secure multiplication unit 43 is used to perform secure multiplication operations based on the first multiplier obtained by the multiplier construction unit 42 provided by the party and the second multiplier provided by the second party, to obtain a first slice of the multiplication result; the second party obtains a second slice of the multiplication result; wherein the second multiplier is constructed by the second party based on the second data slice it holds; the multiplication result has two possible values;

[0273] The result conversion unit 44 is used to convert the first slice of the multiplication result obtained by the safe multiplication unit 43 into the first result slice of the exponentiation result in the target modulus space; the second party obtains the corresponding second result slice.

[0274] Optionally, as an embodiment, the local fragment is a fragment of the privacy data multiplied by n to the power of d1 in the initial modulus space, and the result fragment is a fragment of the result of the exponentiation multiplied by n to the power of d2 in the target modulus space. The absolute value of the public data is expressed as n to the power of k, where k and the privacy data are both integers. The minimum value of the target product of k and the privacy data is u, where u is an integer. The modulus of the target modulus space is n to the power of t2.

[0275] The local computing unit 41 is specifically used to calculate the first data fragment of the first intermediate data in the first modulus space based on the product of the local fragment and k divided by n raised to the power of d1 and then rounded down; the first intermediate data is the result of the target product minus u; the first modulus is the larger value between 0 and -d2-u plus t2.

[0276] Optionally, as an embodiment, the local fragment is a fragment of the privacy data multiplied by n to the power of d1 in the initial modulus space, and the result fragment is a fragment of the result of the exponentiation multiplied by n to the power of d2 in the target modulus space. The absolute value of the public data is expressed as n to the power of k, where k and the privacy data are both integers. The minimum value of the target product of k and the privacy data is u, where u is an integer and u is greater than or equal to 0. The modulus of the target modulus space is n to the power of t2.

[0277] The local computing unit 41 is specifically used to calculate the first data fragment of the first intermediate data in the first modulus space based on the product of the local fragment and k divided by n raised to the power of d1 and then rounded down; the first intermediate data is the result of the target product; the first modulus is the larger value between 0 and -d2 plus t2.

[0278] Furthermore, the multiplier construction unit 42 includes:

[0279] The first determining subunit is used to determine the first base as 1 if the publicly disclosed data is positive, and to determine the first base as -1 if the publicly disclosed data is negative;

[0280] The second determining subunit is used to divide the local segment by n raised to the power of d1 and then round down to determine the first power value;

[0281] The first exponentiation subunit is used to perform exponentiation with the first base obtained by the first determining subunit as the base and the first exponent obtained by the second determining subunit as the exponent, to obtain the first product term;

[0282] The second exponentiation subunit is used to perform exponentiation with n as the base and the first data segment as the exponent to obtain the second product term;

[0283] The multiplication subunit is used to multiply the first product term obtained by the first exponentiation subunit with the second product term obtained by the second exponentiation subunit to obtain the first multiplier in the second modulus space; the second modulus corresponding to the second modulus space is the result of local exponentiation with n as the base and twice the first modulus as the exponent.

[0284] Furthermore, the result conversion unit 44 includes:

[0285] A subunit is determined to treat the multiplication result as n-ary data, and to extract the first segment value of the first modulus bit with non-zero bits in the first segment of the multiplication result, or to extract the second segment value of the first modulus bit with non-zero bits in the first segment of the multiplication result, so as to determine the first segment of the second intermediate result of the third modulus space.

[0286] The transformation subunit is used to multiply the first slice of the second intermediate result obtained by the determining subunit by n raised to the power of d2+u, and then round it to the nearest integer to obtain the first result slice of the power operation result in the target modulus space.

[0287] Furthermore, the determining subunit is specifically used for:

[0288] The multiplication result is treated as n-ary data. The first segment value of the first modulus bit of the lower digits and the second segment value of the first modulus bit of the higher digits are extracted from the first segment of the multiplication result.

[0289] The summation of the values ​​of the first segment and the second segment yields the first piece of the second intermediate result in the third modulus space.

[0290] Furthermore, the determining subunit is specifically used for:

[0291] The multiplication result is treated as n-ary data. Based on the first slice of the multiplication result held by this party and the second slice of the multiplication result held by the second party, a secure comparison operation is performed to obtain a comparison result of whether the multiplication result is greater than or equal to the first modulus.

[0292] If the comparison result is that the multiplication result is less than the first modulus, then the first segment value of the low first modulus bit of the first segment of the multiplication result is extracted, and the first segment value is used as the first segment of the second intermediate result of the third modulus space.

[0293] If the comparison result is that the multiplication result is greater than or equal to the first modulus, then the second segment value of the high-order first modulus bit of the first segment of the multiplication result is extracted, and the second segment value is used as the first segment of the second intermediate result of the third modulus space.

[0294] The apparatus provided in the embodiments of this specification distributes the privacy data in an initial modular space in a shared manner between the first party and the second party. The method is used to obtain a result fragment in a target modular space from the result of a power operation with the public data as the base and the privacy data as the exponent. First, the local computing unit 41 of the first party, based at least on its own fragment of the privacy data, locally computes a first data fragment of first intermediate data in the first modular space; wherein the first intermediate data is a non-negative value, and the first modulus corresponding to the first modular space is determined according to the modulus of the target modular space; the second data fragment of the first intermediate data in the first modular space is held by the second party; then, the multiplier construction unit 42, based on the first data... The fragmentation, as a local exponentiation operation, is constructed using a first multiplier in a second modular space. The second modular space corresponds to a second modular number determined based on the first modular number. Then, the secure multiplication unit 43 performs a secure multiplication operation based on the first multiplier provided by itself and the second multiplier provided by the second party, obtaining a first fragment of the multiplication result. The second party obtains a second fragment of the multiplication result. The second multiplier is constructed by the second party based on its second data fragments. The multiplication result has two possible values. Finally, the result conversion unit 44 converts the first fragment of the multiplication result into a first result fragment of the exponentiation result in the target modular space. The second party obtains the corresponding second result fragment. As can be seen from the above, this embodiment of the specification, by constructing a multiplier, converts secure exponentiation into secure multiplication, and extracts the exponentiation result from the multiplication result of the secure multiplication, thereby enabling secure exponentiation with low communication volume and high performance.

[0295] According to another embodiment, a computer-readable storage medium is also provided, on which a computer program is stored, which, when executed in a computer, causes the computer to perform a combination Figure 3 The method described.

[0296] According to another embodiment, a computing device is also provided, including a memory and a processor, wherein the memory stores executable code, and when the processor executes the executable code, it implements a combination... Figure 3 The method described.

[0297] Those skilled in the art will recognize that, in one or more of the examples above, the functions described in this invention can be implemented using hardware, software, firmware, or any combination thereof. When implemented in software, these functions can be stored in a computer-readable medium or transmitted as one or more instructions or code on a computer-readable medium.

[0298] The specific embodiments described above further illustrate the purpose, technical solution, and beneficial effects of the present invention. It should be understood that the above description is only a specific embodiment of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc., made on the basis of the technical solution of the present invention should be included within the scope of protection of the present invention.< / y> < / y> < / x> < / x> < / c> < / c> < / x> < / c> < / x> < / c> < / y> < / y> < / c> < / c> < / x> < / c> < / x> < / c> < / c> < / c> < / y> < / y> < / x> < / x> < / c> < / c> < / x> < / c> < / x> < / c> < / c> < / c> < / y> < / y> < / y> < / y> < / x> < / x> < / c> < / c> < / x> < / c> < / x> < / c> < / y> < / y> < / y> < / y> ​​< / x> < / x> < / x> < / x> < / x> < / x>

Claims

1. A method for secure processing of privacy data, the privacy data being distributed in a form of shares among a first party and a second party in an initial modulus space, the method being used to obtain a result share of a result of an exponentiation operation with a public data as a base and the privacy data as an exponent in a target modulus space, the method being performed by the first party, comprising: locally computing a first data share of a first intermediate data in a first modulus space based on at least a first party share of the privacy data; wherein the first intermediate data is a non-negative value, a first modulus corresponding to the first modulus space being determined according to a modulus value of the target modulus space; a second data share of the first intermediate data in the first modulus space being held by the second party; constructing a first multiplier in a second modulus space according to a local exponentiation operation with the first data share as an exponent; a second modulus corresponding to the second modulus space being determined based on the first modulus; performing a secure multiplication operation according to the first multiplier provided by the first party and a second multiplier provided by the second party to obtain a first share of a multiplication result; the second party obtaining a second share of the multiplication result; wherein the second multiplier is constructed by the second party according to a second data share held by the second party; the multiplication result having two values; and converting the first share of the multiplication result into a first result share of the result of the exponentiation operation in the target modulus space; the second party obtaining a corresponding second result share. The first party share is a share of the privacy data multiplied by n raised to the power of d1 in the initial modulus space, the result share is a share of the result of the exponentiation operation multiplied by n raised to the power of d2 in the target modulus space, an absolute value of the public data is expressed in the form of n raised to the power of k, k and the privacy data are integers, a minimum value of a target product of k and the privacy data is u, u is an integer, and a modulus value of the target modulus space is n raised to the power of t2. The locally computing the first data share of the first intermediate data in the first modulus space comprises: locally computing the first data share of the first intermediate data in the first modulus space based on a product of the first party share and k divided by n raised to the power of d1 and then rounded down; the first intermediate data being a result of the target product minus u; and the first modulus being a larger one of 0 and -d2-u plus t2. The first party share is a share of the privacy data multiplied by n raised to the power of d1 in the initial modulus space, the result share is a share of the result of the exponentiation operation multiplied by n raised to the power of d2 in the target modulus space, an absolute value of the public data is expressed in the form of n raised to the power of k, k and the privacy data are integers, a minimum value of a target product of k and the privacy data is u, u is an integer and u is greater than or equal to 0, and a modulus value of the target modulus space is n raised to the power of t2. The locally computing the first data share of the first intermediate data in the first modulus space comprises: locally computing the first data share of the first intermediate data in the first modulus space based on a product of the first party share and k divided by n raised to the power of d1 and then rounded down; the first intermediate data being a result of the target product; and the first modulus being a larger one of 0 and -d2 plus t2.

2. The method of claim 1, wherein, ​ ​ ​ 3. The method of claim 1, wherein, ​ ​ ​ 4. The method of claim 2, wherein, The first multiplier in the second modulus space is constructed, comprising: If the public data is positive, determining the first base as 1, and if the public data is negative, determining the first base as -1; Dividing the first part of the first side by n raised to the power of d1, and then rounding down to determine the first power value; Performing power operation with the first base as the base and the first power value as the exponent to obtain the first product term; Performing power operation with n as the base and the first data part as the exponent to obtain the second product term; Multiplying the first product term and the second product term to obtain the first multiplier in the second modulus space, wherein the second modulus corresponding to the second modulus space is the result of local power operation with n as the base and 2 times the first modulus as the exponent.

5. The method of claim 2, wherein, The first part of the multiplication result is converted into the first result part of the power operation result in the target modulus space, comprising: Taking the multiplication result as n-base data, extracting the first segmented value of the first modulus bit in the low bit of the first part of the multiplication result in which there is a non-0 bit, or extracting the second segmented value of the first modulus bit in the high bit of the first part of the multiplication result in which there is a non-0 bit, to determine the first part of the second intermediate result in the third modulus space; Multiplying the first part of the second intermediate result by n raised to the power of d2+u, and then rounding to obtain the first result part of the power operation result in the target modulus space.

6. The method of claim 5, wherein, The first part of the second intermediate result in the third modulus space is determined, comprising: Taking the multiplication result as n-base data, extracting the first segmented value of the first modulus bit in the low bit of the first part of the multiplication result, and extracting the second segmented value of the first modulus bit in the high bit of the first part of the multiplication result; Summing the first segmented value and the second segmented value to obtain the first part of the second intermediate result in the third modulus space.

7. The method of claim 5, wherein, The first part of the second intermediate result in the third modulus space is determined, comprising: Taking the multiplication result as n-base data, performing a secure comparison operation according to the first part of the multiplication result of the first party and the second part of the multiplication result of the second party to obtain a comparison result of whether the multiplication result is greater than or equal to the first modulus; If the comparison result is that the multiplication result is less than the first modulus, extracting the first segmented value of the first modulus bit in the low bit of the first part of the multiplication result to obtain the first part of the second intermediate result in the third modulus space; If the comparison result is that the multiplication result is greater than or equal to the first modulus, extracting the second segmented value of the first modulus bit in the high bit of the first part of the multiplication result to obtain the first part of the second intermediate result in the third modulus space.

8. The method of claim 1, wherein, The first part of the first side is a part of the multiplication of the private data and n raised to the power of d1 in the initial modulus space, the result part is a part of the multiplication of the power operation result and n raised to the power of d2 in the target modulus space, the public data and the private data are integers, the minimum value of the private data is u', and the modulus value of the target modulus space is n raised to the power of t2; The first data part of the local calculation of the first intermediate data in the first modulus space comprises: locally calculating a first data segment of the first intermediate data in a first modulus space based on the first party segment divided by d1 power of n and then rounded down; the first intermediate data is the privacy data minus u'; and the first modulus is determined according to d2 power of n, an absolute value of the public data and t2 power of n.

9. The method of claim 1, wherein, the first party segment is a segment of the privacy data multiplied by d1 power of n in the initial modulus space, the public data and the privacy data are integers, and a minimum value of the privacy data is u' and u' is greater than or equal to 0; the locally calculating the first data segment of the first intermediate data in the first modulus space comprises: locally calculating a first data segment of the first intermediate data in a first modulus space based on the first party segment divided by d1 power of n and then rounded down; the first intermediate data is the privacy data.

10. The method of claim 8, wherein, the constructing the first multiplier in the second modulus space comprises: if the public data is positive, determining the first base as 1, and if the public data is negative, determining the first base as -1; determining a first power value by dividing the first party segment by d1 power of n and then rounding down; performing a power operation with the first base as a base and the first power value as an exponent to obtain a first product term; performing a power operation with the absolute value of the public data as a base and the first data segment as an exponent to obtain a second product term; multiplying the first product term and the second product term to obtain the first multiplier in the second modulus space; and the second modulus space corresponds to a second modulus which is a result of a local power operation with the absolute value of the public data as a base and 2 times the first modulus as an exponent.

11. The method of claim 8, wherein, the converting the first segment of the multiplication result into the first result segment of the power operation result in the target modulus space comprises: extracting, for the first segment of the multiplication result, a first segmented value of the first modulus bit in a low bit where a non-0 bit exists or a second segmented value of the first modulus bit in a high bit where a non-0 bit exists, to determine a first segment of a second intermediate result in a third modulus space; the third modulus space corresponds to a third modulus which is a result of a local power operation with the absolute value of the public data as a base and the first modulus as an exponent; multiplying the first segment of the second intermediate result by u' power of the absolute value of the public data and then by a scaling item to obtain a first segment of a third intermediate result in a third modulus space; the scaling item is a value obtained by multiplying d2 power of n by the third modulus divided by t2 power of n and then rounding up; multiplying the first segment of the third intermediate result by t2 power of n divided by the third modulus and then rounding up to obtain the first result segment of the power operation result in the target modulus space.

12. The method of claim 11, wherein, the determining the first segment of the second intermediate result in the third modulus space comprises: extracting, for the first segment of the multiplication result, a first segmented value of the first modulus bit in a low bit and a second segmented value of the first modulus bit in a high bit; Summing the first segment value and the second segment value to obtain a first piece of the second intermediate result of the third modulus space.

13. The method of claim 11, wherein, The determining the first piece of the second intermediate result of the third modulus space comprises: Regarding the multiplication result as data in the absolute value system of the public data, performing a secure comparison operation according to the first piece of the multiplication result possessed by the first party and the second piece of the multiplication result of the second party to obtain a comparison result of whether the multiplication result is greater than or equal to the first modulus; If the comparison result is that the multiplication result is less than the first modulus, extracting a first segment value of the first modulus bit at the low bit of the first piece of the multiplication result, and taking the first segment value as the first piece of the second intermediate result of the third modulus space; If the comparison result is that the multiplication result is greater than or equal to the first modulus, extracting a second segment value of the first modulus bit at the high bit of the first piece of the multiplication result, and taking the second segment value as the first piece of the second intermediate result of the third modulus space.

14. The method of claim 1, wherein, The first-party piece is a piece of the initial modulus space of the privacy data multiplied by n to the power of d1, the result piece is a piece of the target modulus space of the power operation result multiplied by n to the power of d2, the privacy data is not an integer, the public data is expressed in the form of n to the power of k, the minimum value of k and the target product of the privacy data is u, and the maximum value is v, u and v are both integers, the supported precision of the target product is d3 digits after the decimal point, and the modulus value of the target modulus space is n to the power of t2; The local calculation of the first data piece of the first intermediate data in the first modulus space comprises: The local calculation of the first data piece of the first intermediate data in the first modulus space is based on the product of the first-party piece and k divided by n to the power of d1, multiplied by n to the power of d3', and rounded to an integer; the first intermediate data is the result of the target product minus u and multiplied by n to the power of d3'; the first modulus is h0 multiplied by n to the power of d3', h0 is determined according to d2, u, v, d2', and t2, d3' is greater than d3, and d2' is greater than d2.

15. The method of claim 1, wherein, The first-party piece is a piece of the initial modulus space of the privacy data multiplied by n to the power of d1, the result piece is a piece of the target modulus space of the power operation result multiplied by n to the power of d2, the privacy data is not an integer, the public data is expressed in the form of n to the power of k, the minimum value of k and the target product of the privacy data is u, and the maximum value is v, u and v are both integers and u is greater than or equal to 0, the supported precision of the target product is d3 digits after the decimal point, and the modulus value of the target modulus space is n to the power of t2; The local calculation of the first data piece of the first intermediate data in the first modulus space comprises: locally calculate a first data slice of the first intermediate data in a first modulus space based on a product of the first party slice and k multiplied by d1 power of n, multiplied by d3' power of n, and rounded to an integer; the first intermediate data is a result of the target product multiplied by d3' power of n; the first modulus is h0 multiplied by d3' power of n, and h0 is determined according to d2, u, v, d2', and t2, d3' is greater than d3, and d2' is greater than d2.

16. The method of claim 14, wherein, The first multiplier in the second modulus space is constructed, comprising: determining a first power value by dividing the first party slice by d3' power of n and adding d4; wherein d4 is determined according to d2, v, and d2'; performing power operation with n as the base and the first power value as the exponent, and rounding to an integer to obtain the first multiplier in the second modulus space; and a second modulus corresponding to the second modulus space is a result of local power operation with n as the base and 2 times h0 as the exponent.

17. The method of claim 14, wherein, The first slice of the multiplication result is converted into the first result slice of the power operation result in the target modulus space, comprising: taking the multiplication result as n-based data, multiplying the first slice of the multiplication result by an amplification term to obtain the first slice of the second intermediate result; the amplification term is a result of local power operation with n as the base and 2(v-u+d4) as the exponent; wherein d4 is determined according to d2, v, and d2'; extracting a first segmented value of h0 bits of a low bit in which there is a non-0 bit or extracting a second segmented value of h0 bits of a high bit in which there is a non-0 bit from the first slice of the second intermediate result to determine the first slice of the third intermediate result in the third modulus space; a third modulus corresponding to the third modulus space is h0 power of 2; multiplying the first slice of the third intermediate result by d2+3u-4d4-2v power of n, and rounding to an integer to obtain the first result slice of the power operation result in the target modulus space.

18. The method of claim 17, wherein, The first slice of the third intermediate result in the third modulus space is determined, comprising: taking the multiplication result as n-based data, extracting a first segmented value of h0 bits of a low bit and a second segmented value of h0 bits of a high bit from the first slice of the second intermediate result; summing the first segmented value and the second segmented value to obtain the first slice of the third intermediate result in the third modulus space.

19. The method of claim 1, wherein, The first party slice is a slice of the privacy data multiplied by d1 power of n in the initial modulus space, the result slice is a slice of the power operation result multiplied by d2 power of n in the target modulus space, the privacy data is an integer, an absolute value of the public data is expressed in the form of k power of n, k and a minimum value of the target product of the privacy data are u, and a maximum value is v, u and v are both integers, a supported precision of the target product is d3 digits after the decimal point, and a modulus value of the target modulus space is t2 power of n; The first data slice of the first intermediate data in the first modulus space is locally calculated, comprising: locally calculate a first data slice of the first intermediate data in a first modulus space based on a product of the first party slice and k divided by d1 power of n, multiplied by d3' power of n, and rounded to an integer; the first intermediate data is a result of the target product minus u multiplied by d3' power of n; the first modulus is h0 multiplied by d3' power of n, h0 is determined according to d2, u, v, d2' and t2, d3' is greater than d3, and d2' is greater than d2.

20. The method of claim 1, wherein, The first party slice is a slice of the privacy data multiplied by d1 power of n in the initial modulus space, the result slice is a slice of the power operation result multiplied by d2 power of n in the target modulus space, the privacy data is an integer, an absolute value of the public data is expressed in a form of k power of n, a minimum value of the target product of k and the privacy data is u, a maximum value of the target product is v, u and v are both integers and u is greater than or equal to 0, the supported precision of the target product is d3 digits after the decimal point, and a modulus value of the target modulus space is t2 power of n; The method for locally calculating the first data slice of the first intermediate data in the first modulus space comprises the following steps: locally calculate a first data slice of the first intermediate data in a first modulus space based on a product of the first party slice and k divided by d1 power of n, multiplied by d3' power of n, and rounded to an integer; the first intermediate data is a result of the target product minus u multiplied by d3' power of n; the first modulus is h0 multiplied by d3' power of n, h0 is determined according to d2, u, v, d2' and t2, d3' is greater than d3, and d2' is greater than d2.

21. The method of claim 19, wherein, The method for constructing the first multiplier in the second modulus space comprises the following steps: if the public data is positive, determine the first base number as 1, and if the public data is negative, determine the first base number as -1; determine a first power value by dividing the first party slice by d1 power of n and rounding down; perform a power operation with the first base number as a base and the first power value as an exponent to obtain a first product term; determine a second power value by dividing the first party slice by d3' power of n and adding d4; wherein d4 is determined according to d2, v and d2'; perform a power operation with n as a base and the second power value as an exponent, and round to an integer to obtain a second product term; calculate a product of the first product term and the second product term to obtain the first multiplier in the second modulus space; a second modulus corresponding to the second modulus space is a result of a local power operation with n as a base and 2 times h0 as an exponent.

22. The method of claim 19, wherein, The method for converting the first slice of the multiplication result into the first result slice of the power operation result in the target modulus space comprises the following steps: treat the multiplication result as n-base data, multiply the first slice of the multiplication result by an amplification term to obtain a first slice of a second intermediate result; the amplification term is a result of a local power operation with n as a base and 2(v-u+d4) as an exponent; wherein d4 is determined according to d2, v and d2'. extracting a first segment value of h0 bits of low bits of non-0 bits or a second segment value of h0 bits of high bits of non-0 bits from the first segment of the second intermediate result to determine a first segment of a third intermediate result of a third modulus space; the third modulus space corresponding to a third modulus of 2 raised to the power of h0; multiplying the first segment of the third intermediate result by n raised to the power of d2+3u-4d4-2v, and rounding to obtain a first result segment of the power operation result in the target modulus space. 23.A privacy data processing apparatus, the privacy data being distributed in a form of shares between a first party and a second party in an initial modulus space, the apparatus being configured to obtain a result segment of a power operation result in a target modulus space, the power operation result having a public data as a base and the privacy data as an exponent, the apparatus being arranged at the first party and comprising: a local computing unit configured to locally compute a first data segment of a first intermediate data in a first modulus space based on at least a first share of the privacy data; wherein the first intermediate data is a non-negative value, and a first modulus corresponding to the first modulus space is determined according to a modulus value of the target modulus space; a second data segment of the first intermediate data in the first modulus space being held by the second party; a multiplier constructing unit configured to construct a first multiplier in a second modulus space according to a local power operation having the first data segment obtained by the local computing unit as an exponent; a second modulus corresponding to the second modulus space being determined based on the first modulus; a secure multiplication unit configured to perform a secure multiplication operation according to the first multiplier obtained by the multiplier constructing unit provided by the first party and a second multiplier provided by the second party to obtain a first segment of a multiplication result; the second party obtaining a second segment of the multiplication result; wherein the second multiplier is constructed by the second party according to the second data segment held by the second party; the multiplication result having two values; a result converting unit configured to convert the first segment of the multiplication result obtained by the secure multiplication unit into a first result segment of the power operation result in the target modulus space; the second party obtaining a corresponding second result segment. 24.A computer readable storage medium having stored thereon a computer program, which, when executed in a computer, causes the computer to perform the method of any one of claims 1-22. 25.A computing device comprising a memory and a processor, the memory having stored thereon executable code that, when executed by the processor, performs the method of any one of claims 1-22.

Citation Information

Patent Citations

  • Method and system for improving secure multi-party computing efficiency

    CN111143894A

  • Method and device for processing private data

    CN112506469A