A method for optimizing the number of rounds of secure multi-party computation based on LWE assumption
By adopting instantiated encoding and nested chain structure calculation methods based on LWE assumptions in secure multi-party calculations, the problem of inefficient communication wheel counts in the prior art is solved, and the round optimization and high security calculation are realized.
Patent Information
- Application Number
- CN202210807188.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-07-10
- Publication Date
- 2025-05-02
- Estimated Expiration
- 2042-07-10
AI Technical Summary
The existing secure multi-party computing technology has inefficient efficiency in the number of communication rounds, resulting in many protocol interactions and low efficiency.
The safe multi-party calculation round number optimization method based on the LWE assumption is adopted, and the input of the participants is encoded through LWE instantiated encoding, and the nested chain structure is calculated in the multi-linear mapping system to reduce the number of communication rounds.
It realizes that the number of communication rounds is significantly reduced while ensuring security and reliability of protocol results, and the number of rounds is optimized, which improves the computing efficiency.
Smart Images

Figure CN115276956B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of information security technology and cryptography, and relates to secure multi-party computing technology. Background Art
[0002] Secure multi-party computation refers to multiple distributed participants jointly computing a common function, and each participant's private input is calculated to obtain the corresponding output, which is secure in the sense that each participant can only obtain his own information from the output. Security lies in the fact that each participant can only obtain his own information from the output and no other information, and the results of the protocol can be securely transmitted.
[0003] Generate the trapdoor matrix corresponding to each of the n participants, and input the element m=m1+m2. Sampling matrix For all x i in In Gaussian distribution sampling For all i where 1≤i≤n, sample a uniform distribution matrix And calculate A i =[A′|G i -A′R i ], if A i Not based on the trapdoor R of the previous level i-1 To generate the current level D i Matrix, then return the matrix A with trapdoors i , and the corresponding trapdoor matrix R i , otherwise resample the matrix and calculate the matrix A i . Summary of the invention
[0004] The present invention adopts the following technical solution:
[0005] The private input of the participants in the secure multi-party computation is encoded by LWE instantiation: Input matrix A i ∈U A , and the trapdoor set R, input s i ←S, sample a LWE error matrix e i ←χ m or Using Trapdoor R i ∈R calculation Enter s i Encoding to In, output
[0006] The specific calculation operation is as follows: Assume that there are n participants P1, P2, ..., P n , there are s1,s2,...,s n Corresponding to the input of each participant, Assume there are n+1 matrices U with trapdoors A ={A,A1,…,A n}, each participant uses the corresponding matrix A i ∈U A For i Encode, P1 encodes its own s1 P2 encodes its own s2 Until P n For n Encoding The whole process forms a nested chain structure, based on the matrix A with trapdoors in the previous level. i-1 To generate the current matrix So that the input s i Encoded to In, i is hidden. In a multilinear mapping system, given n pairing operations from level 1 to level n, A and Multiply the encoded results of all parties together:
[0007]
[0008] where e noise The noise obtained by the final multiplication is expressed by the product of the above formula, which encodes s1s2...s n The example is nested in n layers. The information with the same level of coding can be combined with each other and the corresponding addition and subtraction operations can be performed.
[0009] The protocol instantiates and encodes the inputs of all parties through LWE, and then each party transmits it on the broadcast channel. After receiving the encoded inputs of all participants, the corresponding calculation operations are performed, and the calculation results are sent out on the broadcast channel. The whole process is carried out on the broadcast channel, and only two rounds of interaction are required, which greatly reduces the number of communication rounds, achieves round optimization, and the protocol has a high security strength. BRIEF DESCRIPTION OF THE DRAWINGS
[0010] Figure 1 The specific implementation methods of the scheme are described in detail. DETAILED DESCRIPTION
[0011] The technical solution in the embodiment of the present invention will be described clearly and completely below in conjunction with the accompanying drawings in the embodiment of the present invention. The present invention provides a secure multi-party computing round number optimization solution based on the LWE assumption. The specific steps are as follows:
[0012] Round 1: N participants P1, P2, ..., P n ,s1,s2,...,s n Corresponding to the input of each participant,
[0013] Step 1: Encode the input using the LWE instance encoding scheme LWE encode (k,q,s i );
[0014] Step 2: Generate a session id sid and transmit it on the broadcast channel
[0015] Round 2: For all participants’ P i , do the following:
[0016] Step 1: When party P i Received, (P j ,input,sid,·) j∈[n]\i Time record (P j ,input,sid,·), and verify the proof, ignoring the subsequent (P j ,input,·);
[0017] Step 2: Enter the code through verification Added to the operation, if a participant receives the coded input from the other n-1 participants, the participant uses the arithmetic circuit to calculate and output the result y: = ∏ i=[n] s i A n +e noise ;
[0018] Step 3: Output (P i ,output,y), and transmit it on the broadcast channel. If any participant terminates during the protocol, output (P i ,output,{sid} abort ,y), indicating withdrawal from the protocol, other participants will not calculate their input.
Claims
1. A method for optimizing the number of rounds of secure multi-party computation based on the LWE assumption, the specific steps of which are as follows: Generate the trapdoor matrix corresponding to each of the n participants, and input the element m=m1+m2. Sampling matrix For all x i in In Gaussian distribution sampling For all i where 1≤i≤n, sample a uniform distribution matrix And calculate A i =[A′|G i -A′R i ], if A i Not based on the trapdoor R of the previous level i-1 To generate the current level D i Matrix, then return the matrix A with trapdoors i , and the corresponding trapdoor matrix R i , otherwise resample the matrix and calculate the matrix A i; The private input of the participants in the secure multi-party computation is encoded by LWE instantiation: Input matrix A i ∈U A , and the trapdoor set R, input s i ←S, sample a LWE error matrix e i ←χ m or Using Trapdoor R i ∈R calculation Enter s i Encoding to In, output ; The specific calculation operation is as follows: Assume that there are n participants P1, P2, ..., P n , there are s1,s2,...,s n Corresponding to the input of each participant, Assume there are n+1 matrices U with trapdoors A ={A,A1,…,A n }, each participant uses the corresponding matrix A i ∈U A For i Encode, P1 encodes its own s1 P2 encodes its own s2 Until P n For n Encoding The whole process forms a nested chain structure, based on the matrix A with trapdoors in the previous level. i-1 To generate the current matrix So that the input s i Encoded to In, i is hidden; in a multilinear mapping system, given n pairing operations from level 1 to n, A and Multiply the encoded results of all parties together: where e noise The noise obtained by the final multiplication is expressed by the product of the above formula, which encodes s1s2...s n The example is nested in n layers; the information with the same level of coding can be combined with each other and the corresponding addition and subtraction operations can be performed; The protocol instantiates and encodes the input of each party through LWE, and then each party transmits it on the broadcast channel. After receiving the encoded input of all participants, the corresponding calculation operations are performed, and the calculation results are sent out on the broadcast channel. The whole process is carried out on the broadcast channel, and only two rounds of interaction are required, which greatly reduces the number of communication rounds, achieves round optimization, and the protocol has a high security strength; Round 1: N participants P1, P2, ..., P n ,s1,s2,...,s n Corresponding to the input of each participant, Step 1: Encode the input using the LWE instance encoding scheme LWE encode (k,q,s i ); Step 2: Generate a session id sid and transmit it on the broadcast channel Round 2: For all participants’ P i , do the following: Step 1: When party P i Received, (P j ,input,sid,·) j∈[n]\i Time record (P j ,input,sid,·), and verify the proof, ignoring the subsequent (P j ,input,·); Step 2: Enter the code through verification Added to the operation, if a participant receives the coded input from the other n-1 participants, the participant uses the arithmetic circuit to calculate and output the result y: = ∏ i=[n] s i A n +e noise ; Step 3: Output (P i ,output,y), and transmit it on the broadcast channel. If any participant terminates during the protocol, output (P i ,output,{sid} abort ,y), indicating withdrawal from the protocol, other participants will not calculate their input.
Citation Information
Patent Citations
An NTRU type multi-key fully homomorphic encryption method with a fast homomorphic operation process
CN109936435A
Secure multi-party computation scheme based on information entropy under semi-honesty model
CN113378191A