A method for optimizing the number of rounds of secure multi-party computation based on LWE assumption

By adopting instantiated encoding and nested chain structure calculation methods based on LWE assumptions in secure multi-party calculations, the problem of inefficient communication wheel counts in the prior art is solved, and the round optimization and high security calculation are realized.

CN115276956BActive Publication Date: 2025-05-02GUIZHOU UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210807188.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-07-10
Publication Date
2025-05-02
Estimated Expiration
2042-07-10

AI Technical Summary

Technical Problem

The existing secure multi-party computing technology has inefficient efficiency in the number of communication rounds, resulting in many protocol interactions and low efficiency.

Method used

The safe multi-party calculation round number optimization method based on the LWE assumption is adopted, and the input of the participants is encoded through LWE instantiated encoding, and the nested chain structure is calculated in the multi-linear mapping system to reduce the number of communication rounds.

Benefits of technology

It realizes that the number of communication rounds is significantly reduced while ensuring security and reliability of protocol results, and the number of rounds is optimized, which improves the computing efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115276956B_ABST
    Figure CN115276956B_ABST
Patent Text Reader

Abstract

There are many distributed interaction scenarios in big data networks, which require joint computing in different environments. In traditional secure multi-party computing (SMPC), there are constant rounds or more rounds of interactions, which greatly increases the communication overhead. In this paper, we solve the problem of optimizing the complexity of the number of rounds by constructing a secure multi-party computing protocol based on the polynomial problem assumption. Based on the trapdoor matrix, multi-linear mapping operations are used to perform multi-party interactive computing. The results are transmitted through a broadcast channel to construct a protocol scheme with round optimization. Security analysis shows that the protocol achieves static security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of information security technology and cryptography, and relates to secure multi-party computing technology. Background Art

[0002] Secure multi-party computation refers to multiple distributed participants jointly computing a common function, and each participant's private input is calculated to obtain the corresponding output, which is secure in the sense that each participant can only obtain his own information from the output. Security lies in the fact that each participant can only obtain his own information from the output and no other information, and the results of the protocol can be securely transmitted.

[0003] Generate the trapdoor matrix corresponding to each of the n participants, and input the element m=m1+m2. Sampling matrix For all x i in In Gaussian distribution sampling For all i where 1≤i≤n, sample a uniform distribution matrix And calculate A i =[A′|G i -A′R i ], if A i Not based on the trapdoor R of the previous level i-1 To generate the current level D i Matrix, then return the matrix A with trapdoors i , and the corresponding trapdoor matrix R i , otherwise resample the matrix and calculate the matrix A i . Summary of the invention

[0004] The present invention adopts the following technical solution:

[0005] The private input of the participants in the secure multi-party computation is encoded by LWE instantiation: Input matrix A i ∈U A , and the trapdoor set R, input s i ←S, sample a LWE error matrix e i ←χ m or Using Trapdoor R i ∈R calculation Enter s i Encoding to In, output

[0006] The specific calculation operation is as follows: Assume that there are n participants P1, P2, ..., P n , there are s1,s2,...,s n Corresponding to the input of each participant, Assume there are n+1 matrices U with trapdoors A ={A,A1,…,A n}, each participant uses the corresponding matrix A i ∈U A For i Encode, P1 encodes its own s1 P2 encodes its own s2 Until P n For n Encoding The whole process forms a nested chain structure, based on the matrix A with trapdoors in the previous level. i-1 To generate the current matrix So that the input s i Encoded to In, i is hidden. In a multilinear mapping system, given n pairing operations from level 1 to level n, A and Multiply the encoded results of all parties together:

[0007]

[0008] where e noise The noise obtained by the final multiplication is expressed by the product of the above formula, which encodes s1s2...s n The example is nested in n layers. The information with the same level of coding can be combined with each other and the corresponding addition and subtraction operations can be performed.

[0009] The protocol instantiates and encodes the inputs of all parties through LWE, and then each party transmits it on the broadcast channel. After receiving the encoded inputs of all participants, the corresponding calculation operations are performed, and the calculation results are sent out on the broadcast channel. The whole process is carried out on the broadcast channel, and only two rounds of interaction are required, which greatly reduces the number of communication rounds, achieves round optimization, and the protocol has a high security strength. BRIEF DESCRIPTION OF THE DRAWINGS

[0010] Figure 1 The specific implementation methods of the scheme are described in detail. DETAILED DESCRIPTION

[0011] The technical solution in the embodiment of the present invention will be described clearly and completely below in conjunction with the accompanying drawings in the embodiment of the present invention. The present invention provides a secure multi-party computing round number optimization solution based on the LWE assumption. The specific steps are as follows:

[0012] Round 1: N participants P1, P2, ..., P n ,s1,s2,...,s n Corresponding to the input of each participant,

[0013] Step 1: Encode the input using the LWE instance encoding scheme LWE encode (k,q,s i );

[0014] Step 2: Generate a session id sid and transmit it on the broadcast channel

[0015] Round 2: For all participants’ P i , do the following:

[0016] Step 1: When party P i Received, (P j ,input,sid,·) j∈[n]\i Time record (P j ,input,sid,·), and verify the proof, ignoring the subsequent (P j ,input,·);

[0017] Step 2: Enter the code through verification Added to the operation, if a participant receives the coded input from the other n-1 participants, the participant uses the arithmetic circuit to calculate and output the result y: = ∏ i=[n] s i A n +e noise ;

[0018] Step 3: Output (P i ,output,y), and transmit it on the broadcast channel. If any participant terminates during the protocol, output (P i ,output,{sid} abort ,y), indicating withdrawal from the protocol, other participants will not calculate their input.

Claims

1. A method for optimizing the number of rounds of secure multi-party computation based on the LWE assumption, the specific steps of which are as follows: Generate the trapdoor matrix corresponding to each of the n participants, and input the element m=m1+m2. Sampling matrix For all x i in In Gaussian distribution sampling For all i where 1≤i≤n, sample a uniform distribution matrix And calculate A i =[A′|G i -A′R i ], if A i Not based on the trapdoor R of the previous level i-1 To generate the current level D i Matrix, then return the matrix A with trapdoors i , and the corresponding trapdoor matrix R i , otherwise resample the matrix and calculate the matrix A i; The private input of the participants in the secure multi-party computation is encoded by LWE instantiation: Input matrix A i ∈U A , and the trapdoor set R, input s i ←S, sample a LWE error matrix e i ←χ m or Using Trapdoor R i ∈R calculation Enter s i Encoding to In, output ; The specific calculation operation is as follows: Assume that there are n participants P1, P2, ..., P n , there are s1,s2,...,s n Corresponding to the input of each participant, Assume there are n+1 matrices U with trapdoors A ={A,A1,…,A n }, each participant uses the corresponding matrix A i ∈U A For i Encode, P1 encodes its own s1 P2 encodes its own s2 Until P n For n Encoding The whole process forms a nested chain structure, based on the matrix A with trapdoors in the previous level. i-1 To generate the current matrix So that the input s i Encoded to In, i is hidden; in a multilinear mapping system, given n pairing operations from level 1 to n, A and Multiply the encoded results of all parties together: where e noise The noise obtained by the final multiplication is expressed by the product of the above formula, which encodes s1s2...s n The example is nested in n layers; the information with the same level of coding can be combined with each other and the corresponding addition and subtraction operations can be performed; The protocol instantiates and encodes the input of each party through LWE, and then each party transmits it on the broadcast channel. After receiving the encoded input of all participants, the corresponding calculation operations are performed, and the calculation results are sent out on the broadcast channel. The whole process is carried out on the broadcast channel, and only two rounds of interaction are required, which greatly reduces the number of communication rounds, achieves round optimization, and the protocol has a high security strength; Round 1: N participants P1, P2, ..., P n ,s1,s2,...,s n Corresponding to the input of each participant, Step 1: Encode the input using the LWE instance encoding scheme LWE encode (k,q,s i ); Step 2: Generate a session id sid and transmit it on the broadcast channel Round 2: For all participants’ P i , do the following: Step 1: When party P i Received, (P j ,input,sid,·) j∈[n]\i Time record (P j ,input,sid,·), and verify the proof, ignoring the subsequent (P j ,input,·); Step 2: Enter the code through verification Added to the operation, if a participant receives the coded input from the other n-1 participants, the participant uses the arithmetic circuit to calculate and output the result y: = ∏ i=[n] s i A n +e noise ; Step 3: Output (P i ,output,y), and transmit it on the broadcast channel. If any participant terminates during the protocol, output (P i ,output,{sid} abort ,y), indicating withdrawal from the protocol, other participants will not calculate their input.

Citation Information

Patent Citations

  • An NTRU type multi-key fully homomorphic encryption method with a fast homomorphic operation process

    CN109936435A

  • Secure multi-party computation scheme based on information entropy under semi-honesty model

    CN113378191A