A Secure Multi-Party Ciphertext Computation Method Based on Blockchain

Through the secure multi-party ciphertext calculation method based on blockchain, the problem of multi-party computing protocols cannot interact is solved, the privacy and correctness of the calculation is realized, the identity authenticity and behavioral punishment of participants are ensured, and the data transmission and calculation process are optimized.

CN115174049BActive Publication Date: 2025-07-08HANGZHOU DIANZI UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210696271.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-06-20
Publication Date
2025-07-08
Estimated Expiration
2042-06-20

AI Technical Summary

Technical Problem

In the prior art, multi-party computing protocols cannot interact effectively, and the accuracy and privacy of the calculation cannot be ensured while ensuring the secrets of the participants are not disclosed.

Method used

A secure multi-party ciphertext calculation method based on blockchain is adopted, through the public-private key pair generation and hash function negotiation in the initialization stage, combined with the secret sharing and verification of encrypted random numbers, the data transmission is optimized using Huffman encoding, and the multiplication operation is converted into addition operation through inadvertent transmission, ensuring the security of participants' identity authentication and data processing.

Benefits of technology

It realizes effective interaction between multi-party computing protocols, ensures the privacy and correctness of the computing, and at the same time, the immutable characteristics of blockchain ensure the authenticity of the identity and behavioral punishment mechanism of the participants.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115174049B_ABST
    Figure CN115174049B_ABST
Patent Text Reader

Abstract

The present invention belongs to the field of privacy computing and discloses a secure multi-party ciphertext calculation method based on blockchain, which includes the following steps: Step 1: Initialization phase: Select a hash function and the respective public and private key pairs of the participating parties; Step 2: Participating party identity authentication; Step 3: Data transmission processing: Multi-party operations require data interaction. Different types of data are processed differently before interaction, mainly encoding the non-numerical type of data that may exist; Step 4: Function operation: Complete the operation under ciphertext conditions, and convert the function to be calculated into a ciphertext addition operation; Step 5: The participating parties jointly complete decryption using their respective private keys. By introducing MPC into the blockchain ecosystem, the present invention can not only enable interaction between MPCs, but also ensure the authenticity of identities by using the characteristics of blockchain such as immutability. At the same time, relevant mechanisms can be introduced to punish the improper behaviors of the participating parties.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of privacy computing, and in particular relates to a secure multi-party ciphertext calculation method based on blockchain. Background Art

[0002] The immutability and traceability of blockchain technology provide a trusted mechanism, and we can store relevant information on the chain for subsequent verification. In the Internet era, multi-party data interaction has become more frequent and the application scenarios are more extensive. The emergence of blockchain technology, to a certain extent, also confirms the demand for multi-party computing. Secure multi-party computing ensures that the parties can jointly complete function calculation without revealing their secrets. Assuming the set of participating parties is {P1, P2, …, P n}, then these n participating parties need to jointly complete the function calculation f(x1, x2, …, x n ). Combining blockchain technology with secure multi-party computing can achieve a perfect combination of verification and calculation. Generally speaking, multi-party computing provides the privacy of calculation, but cannot fully guarantee the correctness. On the other hand, under the existing technology, each multi-party computing protocol cannot interact with each other. Summary of the Invention

[0003] The purpose of the present invention is to provide a secure multi-party ciphertext calculation method based on blockchain to solve the above technical problems.

[0004] To solve the above technical problems, the specific technical solution of a secure multi-party ciphertext calculation method based on blockchain of the present invention is as follows:

[0005] A secure multi-party ciphertext calculation method based on blockchain includes the following steps:

[0006] Step 1: Initialization phase: Select a hash function and the respective public and private key pairs of the participating parties;

[0007] Step 2: Participating party identity authentication:

[0008] Step 2.1: Encrypt the random number: Each participating party independently selects its own random number and performs an encryption operation, and stores it as a tag in the blockchain;

[0009] Step 2.2: Secret sharing of the random number: Each participating party secretly shares the random number selected in Step 2.1 with other parties;

[0010] Step 2.3: Verification operation: Each participating party verifies the secret sharing values received from other participating parties to implement the identity authentication process;

[0011] Step 3: Data Transmission Processing: Multi-party operations require data interaction, and different types of data are processed differently before interaction;

[0012] Step 4: Function Operations: It is stipulated that the participating parties execute the same hash function, perform hash operations on the held data information, and perform further encoding operations on the obtained hash values;

[0013] Step 5: The participating parties jointly complete decryption using their respective private keys.

[0014] Furthermore, the said Step 1 includes:

[0015] The participating parties jointly negotiate to determine the hash function and the cryptographic algorithm that satisfies additive homomorphism. The i-th participating party generates its own public-private key pair (pk i , sk i ). For non-numerical type data, it is converted using the hash function, and then the obtained hash value is Huffman-encoded into a bit string form.

[0016] Furthermore, the said Step 2.1 includes the following specific steps:

[0017] n participating parties each independently select a random number r i , 1 ≤ i ≤ n, and then perform an encryption operation e(r i ) = tag i , and record tag i as the identity identifier of the i-th participating party and store it on the blockchain.

[0018] Furthermore, the said Step 2.2 includes the following specific steps:

[0019] Each participating party performs secret sharing on the independently selected random numbers r i , 1 ≤ i ≤ n,

[0020] r i = r 1,i + r 2,i + … + r n,i , 1 ≤ i ≤ n. After completing the secret sharing, the i-th participating party obtains r i,1 , r i,2 , …, r i,n . Furthermore, the participating party performs an encryption operation e i = e(r i,1 ) + e(r i,2 ) + … + e(r i,n ) on the received secret sharing values of random numbers from other participants locally, and saves this value to the blockchain.

[0021] Furthermore, the said Step 2.3 includes the following specific steps:

[0022] Participant verification and check if they are equal. As long as the participants correctly execute the secret sharing, this equation will definitely hold. If the verification fails, the protocol will terminate.

[0023] Furthermore, step 3 includes the following specific steps:

[0024] Step 3.1: Processing of numerical type data:

[0025] For numerical type data, it can be directly converted into the corresponding bit string according to the numerical value.

[0026] Step 3.2: Processing of non - numerical type data:

[0027] For non - numerical type data, each participant calculates the corresponding hash value locally according to the hash function specified in the initialization phase. Since the hash value is in the form of a string, to reduce the transmission overhead, first count the weight of each character, and then encode the hash value into a binary bit string using the Huffman coding method.

[0028] Furthermore, step 4 includes the following specific steps:

[0029] After passing the identity verification and performing corresponding processing on the data to be transmitted, the n participants respectively hold the data x1, x2, …, x n , and jointly calculate the function f(x1, x2, …, x n ). Each algorithm can be expressed as a combination of addition and multiplication:

[0030] Step 4.1: Multi - party addition operation:

[0031] Each participant encrypts the data using their own public key and then discloses the ciphertext, satisfying so that each participant can perform the addition operation without interaction;

[0032] Step 4.2: Multi - party multiplication operation:

[0033] Using oblivious transfer, convert multiplication into addition. Two participants are respectively denoted as Alice and Bob. Assume they hold a and b respectively. After oblivious transfer (OT), to achieve ab = m + n, one party holds m and the other holds n. After successfully converting it into an addition operation, perform the same operation according to step 4.1 to achieve the multi - party multiplication operation.

[0034] Furthermore, the oblivious transfer in step 4.2 is implemented as follows:

[0035] 1. Bob randomly selects ρ random numbers, s0, s1, …, s ρ-1 , and then prepares ρ pairs of binary tuples where

[0036] 2. Alice represents the a she holds in the form of a bit string, a ρ-1 , …, a0, and the two parties perform ρ oblivious transfers, that is, ρ times In the i-th oblivious transfer, Alice, according to the bit position a i corresponding to her own bit string, selects from the i-th pair of binary tuples of Bob to obtain

[0037] 3. Alice defines Bob defines

[0038] Verify the correctness of this process. Since a is represented in the form of a bit string, a ρ-1 , …, a0, a is denoted as: The verification is as follows:

[0039]

[0040] Thus, the multiplication operation among multiple parties can be completed.

[0041] Furthermore, in step 5, the participating parties use their respective private keys sk i , 1 ≤ i ≤ n to jointly complete decryption.

[0042] A secure multi-party ciphertext calculation method based on blockchain of the present invention has the following advantages: The method of the present invention is similar to regarding MPC as a component of the blockchain, and performing on-chain management for each MPC (or simply understanding that a block represents an MPC function calculation, and the head block is used as an identity authentication block). In the mechanism where MPC exists alone, it is difficult for one MPC to interact with another MPC because they are likely to exist at different time nodes. By introducing MPC into the blockchain ecosystem, not only can MPCs complete interactions, but also the immutability and other characteristics of the blockchain can be used to ensure the authenticity of identities. At the same time, relevant mechanisms can be introduced to punish the improper behaviors of the participating parties. BRIEF DESCRIPTION OF THE DRAWINGS

[0043] Figure 1 is the flowchart of the multi-party calculation method of the present invention;

[0044] Figure 2 is the structural schematic diagram of the secure multi-party calculation architecture based on blockchain of the present invention;

[0045] Figure 3 It is the diagram of the identity authentication scheme in the initialization stage of the present invention;

[0046] Figure 4 It is the diagram for analyzing the data encoding method of the present invention:

[0047] Figure 5 It is the diagram of the multi-party addition calculation scheme of the present invention;

[0048] Figure 6 It is the diagram of the multi-party multiplication calculation scheme of the present invention. Specific implementation mode

[0049] In order to better understand the purpose, structure and function of the present invention, the following further describes in detail a secure multi-party ciphertext calculation method based on blockchain of the present invention with reference to the accompanying drawings.

[0050] A secure multi-party ciphertext calculation method based on blockchain of the present invention, as Figure 1 shown, is the step flow chart of the present invention. In specific implementation, it includes the following steps:

[0051] Step 1: Initialization stage:

[0052] The participating parties jointly negotiate to determine a hash function and a cryptographic algorithm that satisfies additive homomorphism, such as the Paillier encryption algorithm. The i-th participating party generates its own public and private key pair (pk i , sk i ). In addition, the hash function is used to process non-numerical type data. In order to reduce the transmission overhead during data interaction between participating parties, the hash function is used to convert non-numerical type data, and then the obtained hash value is Huffman encoded into a bit string form.

[0053] Step 2: Participating party identity authentication:

[0054] In the present invention, we rely on the characteristics of blockchain to help achieve the identity authentication of participating parties. As a key step, only after the participating parties pass the verification are they eligible to participate in the multi-party calculation process.

[0055] Step 2.1: Encrypt random numbers:

[0056] As Figure 2 shown, n participating parties each independently select a random number r i , 1 ≤ i ≤ n, and then perform an encryption operation e(r i ) = tag i locally, and record tag i as the identity identifier of the i-th participating party and store it on the blockchain.

[0057] Step 2.2: Secret sharing of random numbers:

[0058] As Figure 3 shown, each participating party will perform secret sharing on the randomly selected random number r i , 1 ≤ i ≤ n. r i = r 1,i + r 2,i + … + r n,i , 1 ≤ i ≤ n. After completing the secret sharing, the i-th participating party obtains r i,1 , r i,2 , …, r i,n . Further, the participating party performs an encryption operation e i = e(r i,1 ) + e(r i,2 ) + … + e(r i,n ) on the secret sharing values of the random numbers received from other participants locally and saves this value to the blockchain.

[0059] Step 2.3: Verification operation:

[0060] The participating party verifies whether and are equal. Since the encryption algorithm we use satisfies the additive homomorphic property, as long as the participating party correctly performs the secret sharing, this equation must hold. In this way, it can be determined whether there are dishonest parties among the participating parties. As long as the verification fails, the protocol is terminated.

[0061] Step 3: Data transmission processing:

[0062] Multi-party operations need to complete data interaction, and different types of data are processed differently before interaction.

[0063] Step 3.1: Processing of numerical type data:

[0064] As Figure 4 shown, for numerical type data, it can be directly converted into the corresponding bit string according to the numerical size. Step 3.2: Processing of non-numerical type data:

[0065] For non-numerical type data, each participating party locally calculates the corresponding hash value according to the hash function specified in the initialization phase. Since the hash value is in the form of a string, to reduce the transmission overhead, first count the weight of each character, and then encode the hash value into a binary bit string using the Huffman coding method.

[0066] Step 4: Function operation:

[0067] After passing the identity verification and performing corresponding processing on the data to be transmitted, the n participants respectively hold the data x1, x2, …, x n, jointly calculate the function f(x1, x2, …, x n ). Since each algorithm can be expressed as a combination of addition and multiplication, we only need to complete the secure multi-party computation schemes for addition and multiplication.

[0068] Step 4.1: Multi-party addition operation:

[0069] As Figure 5 shown, each participant encrypts the data using its own public key and then publishes the ciphertext. Since the cryptosystem we adopt has the property of additive homomorphism, it satisfies such that each participant can perform the addition operation without interaction.

[0070] Step 4.2: Multi-party multiplication operation:

[0071] As Figure 6 shown, compared with the addition operation that can be achieved without interaction, in the multiplication operation, we do not perform homomorphic encryption on the original data. Instead, we use oblivious transfer to transform the multiplication into the form of addition. Taking two participants as an example, denoted as Alice and Bob respectively. Suppose they hold a and b respectively. After oblivious transfer (OT), to achieve ab = m + n, one party holds m and the other holds n. After successfully transforming it into an addition operation, we can perform the same operation according to Step 4.1 to achieve the multi-party multiplication operation. The specific realization of oblivious transfer is as follows:

[0072] (1), Bob randomly selects ρ random numbers, s0, s1, …, s ρ-1 , and then prepares ρ pairs of binary tuples where it is defined that

[0073] (2), Alice represents the held a in the form of a bit string, a ρ-1 , …, a0. The two parties perform ρ times of oblivious transfer, that is, ρ times of In the i-th oblivious transfer, Alice obtains i from the i-th pair of binary tuples of Bob according to the bit position a

[0074] (3), Alice defines Bob defines

[0075] Through the above way of oblivious transfer, we have successfully transformed the addition calculation of the two parties into a multiplication operation. Now, let's verify the correctness of this process. Since a is represented in the form of a bit string, a ρ-1 , …, a0, note that a can also be denoted as: The verification is as follows:

[0076]

[0077] Thus, we can complete the multiplication operation among multiple parties.

[0078] Step 5: The participating parties use their respective private keys sk i , where 1 ≤ i ≤ n, to jointly complete decryption.

[0079] It can be understood that the present invention is described by means of some embodiments. Those skilled in the art will know that, without departing from the spirit and scope of the present invention, various changes or equivalent replacements can be made to these features and embodiments. Additionally, under the teaching of the present invention, these features and embodiments can be modified to adapt to specific situations and materials without departing from the spirit and scope of the present invention. Therefore, the present invention is not limited by the specific embodiments disclosed herein, and all embodiments falling within the scope of the claims of this application belong to the scope protected by the present invention.

Claims

1. A secure multi-party ciphertext calculation method based on blockchain, characterized in that, It includes the following steps: Step 1: Initialization phase: Select a hash function and the public-private key pairs of each participant; Step 2: Participant identity authentication: Step 2.1: Encrypt the random number: Each participant independently selects its own random number and performs an encryption operation, and stores it as a tag in the blockchain; Step 2.2: Secret sharing of the random number: Each participant secretly shares the random number selected in Step 2.1 with other parties; Step 2.3: Verification operation: Each participant verifies the secret sharing values received from other participants to implement the identity authentication process; Step 3: Data transmission processing: Multi-party operations need to complete data interaction, and different types of data are processed differently before interaction; Step 3.1: Processing of numerical type data: For numerical type data, it can be directly converted into the corresponding bit string according to the numerical size; Step 3.2: Processing of non-numerical type data: For non-numerical type data, each participant locally calculates the corresponding hash value according to the hash function specified in the initialization phase. Since the hash value is in the form of a string, to reduce the transmission overhead, first count the weight of each character, and then encode the hash value into a binary bit string using the Huffman coding method; Step 4: Function operation: It is stipulated that each participant executes the same hash function, performs a hash operation on the held data information, and performs a further encoding operation on the obtained hash value; After authentication and corresponding processing of the data to be transmitted, n participants respectively hold the data x1, x2, …, x n , and jointly calculate the function f(x1, x2, …, x n ). Each algorithm can be expressed as a combination of addition and multiplication: Step 4.1: Multi-party addition operation: Each participant encrypts the data using its own public key Then the ciphertext is made public, satisfying so that each participant can perform addition operations without interaction; Step 4.2: Multi-party multiplication operation: Using oblivious transfer, convert multiplication into addition. Two participants are denoted as Alice and Bob respectively. Assume that they hold a and b respectively. After oblivious transfer (OT), to achieve ab = m + n, one party holds m and the other holds n. After successfully converting to an addition operation, perform the same operation according to Step 4.1 to achieve multi-party multiplication operation; Step 5: The participants jointly complete decryption using their respective private keys.

2. The secure multi-party ciphertext calculation method based on blockchain according to claim 1, wherein The said Step 1 includes: The participating parties jointly negotiate and determine a hash function and a cryptographic algorithm that satisfies additive homomorphism. The i-th participating party generates its own public-private key pair (pk i , sk i ). The hash function is used to convert non-numerical data, and then the obtained hash value is Huffman-encoded into a bit string form.

3. The secure multi-party ciphertext calculation method based on blockchain according to claim 1, wherein The said Step 2.1 includes the following specific steps: n participants each independently select a random number r i , 1 ≤ i ≤ n, and then perform an encryption operation e(r i ) = tag i , and record tag i as the identity identifier of the i-th participant and store it on the blockchain.

4. The secure multi-party ciphertext calculation method based on blockchain according to claim 1, characterized in that The said Step 2.2 includes the following specific steps: Each participant will perform secret sharing on the randomly selected random number r i , where 1 ≤ i ≤ n. r i = r 1,i + r 2,i + … + r n,i , where 1 ≤ i ≤ n. After completing the secret sharing, the i-th participant obtains r i,1 , r i,2 , …, r i,n . Further, the participant performs an encryption operation e i = e(r i,1 ) + e(r i,2 ) + … + e(r i,n ) locally on the secretly shared values of the random numbers received from other participants, and saves this value to the blockchain.

5. The secure multi-party ciphertext calculation method based on blockchain according to claim 1, wherein The said Step 2.3 includes the following specific steps: Participant Verification and are checked for equality. As long as the participants execute the secret sharing correctly, this equation will definitely hold. If the verification fails, the protocol is terminated.

6. The secure multi-party ciphertext calculation method based on blockchain according to claim 1, characterized in that The oblivious transfer in the said Step 4.2 is implemented as follows: Step 4.2.1, Bob randomly selects ρ random numbers, s0, s1, …, s ρ-1 , and then prepares ρ pairs of binary tuples where the definition is Step 4.2.

2. Alice represents the held \(a\) in the form of a bit string, \(a\) ρ-1 , …, \(a_0\). The two parties perform \(\rho\) oblivious transfers, that is, \(\rho\) times In the \(i\)-th oblivious transfer, Alice, according to the bit position \(a\) corresponding to her own bit string i obtains from the \(i\)-th pair of binary tuples of Bob obtain Step 4.2.3, Alice defines Bob defines Verify the correctness of this process. Since a is represented in the form of a bit string, a ρ-1 ,…,a0, a is denoted as: Verification is as follows: Thus, the multiplication operation between multiple parties can be completed.

7. The secure multi-party ciphertext calculation method based on blockchain according to claim 1, wherein The parties involved in step 5 use their respective private keys sk i , 1 ≤ i ≤ n to jointly complete decryption.

Citation Information

Patent Citations

  • Risk data sharing method and system based on secure multi-party computing and block chain

    CN111611609A

  • Secure multi-party computing method and system based on block chain

    CN114124347A