Method and apparatus for converting sharing form of target data
By generating a random number y and using its opposite -y modulo 2n to generate and share fragments, combined with secure addition and multiplication, the conversion from Boolean shared form to sum-shared form is realized, which solves the problem of large communication volume in multi-party secure computation and improves computational efficiency.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- ANT BLOCKCHAIN TECHNOLOGY (SHANGHAI) CO LTD
- Filing Date
- 2022-09-13
- Publication Date
- 2026-04-17
AI Technical Summary
In secure multi-party computation, the existing technology suffers from a large amount of communication and affects computational efficiency during the conversion from Boolean sharing to SYN sharing (B2A) form.
By generating a random number y on one side and using its opposite -y modulo 2n to generate and share fragments, combined with secure addition and multiplication, the sum of the target data x and the random number y is calculated bit by bit, reducing the amount of communication and realizing the conversion from Boolean shared form to sum shared form.
It reduces data communication volume, improves the efficiency of multi-party secure computation business processing, avoids the use of complex over-the-air (OT) computation, and improves computation efficiency.
Smart Images

Figure CN115664644B_ABST
Abstract
Description
Technical Field
[0001] This specification relates to the field of secure computing technology, and more particularly to a method and apparatus for converting the shared form of target data in multi-party secure computing. Background Technology
[0002] Secure multi-party computation, also known as secure multi-party computation, allows multiple parties to collaboratively compute the result of a function without disclosing the input data of each party. The result is then made public to one or more of the parties. Typical applications of secure multi-party computation include joint statistical analysis of privacy-preserving multi-party data and machine learning. Here, the function is a statistical operation function, a machine learning algorithm, etc.
[0003] In multi-party secure computation, to prevent the leakage of data and intermediate computation results, the data or intermediate results can be held by each party in a shared manner. Each party holds a data fragment, and the fragments held by all parties are merged to reconstruct the corresponding data. Typically, the computation is performed in a shared state. Thus, the number of data communications and the amount of communication in multi-party secure computation are important factors affecting the efficiency of secure computation. Summary of the Invention
[0004] This specification describes one or more embodiments of a method and apparatus for converting target data into a shared format, in order to solve one or more problems mentioned in the background art.
[0005] According to the first aspect, a method for converting the shared form of target data is provided for use in secure two-party computation. This method converts the Boolean shared form of target data x between the first and second parties into a shared form, where the first and second parties respectively hold a first Boolean fragment and a second Boolean fragment of n bits of the target data x. The method is executed by the first party and includes: obtaining an n-bit random number y; and taking the negative of the random number y modulo 2. n y' is obtained as the first sum-shared fragment of the target data x; based on the first Boolean fragment and the random number y, the second party securely calculates the bit-by-bit summation of the target data x and the random number y to obtain each first sum-shared fragment corresponding to n bits; each first sum-shared fragment is sent to the second party so that the second party can recover the value of the sum z of the target data x and the random number y on each bit based on the n first sum-shared fragments and n second sum-shared fragments, and the sum z serves as the second sum-shared fragment, which together with the first sum-shared fragments constitute the sum-shared form of the target data x.
[0006] In one embodiment, the n bits are denoted as bits 0 to n-1 from the least significant bit to the most significant bit. The step of securely calculating the bit-by-bit summation of the target data x and the random number y with the second party based on the first Boolean segment and the random number y to obtain the respective first summation segments corresponding to the n bits includes: for the i-th bit among the bits 0 to n-1, securely calculating the corresponding carry value c with the second party modulo 2. i The carry value c is obtained. i First carry-part c i0 According to the value x of the i-th bit in the first Boolean segment 0i The value of the i-th bit of the random number y i Carry value c i First carry-part c i0 The sum of the target data x and the random number y is used to obtain the first sum fragment z on the i-th bit.
[0007] In one embodiment, when the i-th bit is the 0th bit, the carry value c i It is 0.
[0008] In one embodiment, when the i-th bit is not the 0th bit, the carry value c i The (i-1)th bit of the target data x, the (i-1)th bit of the random number y, and the carry value c i-1 The sum of the products of two products multiplied together modulo 2.
[0009] In one embodiment, the first party and the second party respectively hold the carry value c. i-1 The first slice, the second slice; the carry value c i The first summation slice is determined as follows: the first item is determined by multiplying the (i-1)th bit of the first Boolean slice with the (i-1)th bit of the random number y; a two-way secure multiplication is performed by multiplying the (i-1)th bit of the random number y with the second Boolean slice held by the second party to obtain the first slice of the corresponding product, which is used as the second item.
[0010] Using the (i-1)th bit of the first Boolean segment and the carry value c held by the second party i-1 The second piece performs a two-way safe multiplication to obtain the first piece of the corresponding product, which serves as the third component; the carry value c is then used. i-1 The first slice is multiplied by the (i-1)th bit of the second Boolean slice held by the second party to obtain the first slice of the corresponding product, which is used as the fourth item; the (i-1)th bit of the random number y is multiplied by the carry value c held by the second party. i-1The second slice undergoes two-way safe multiplication to obtain the first slice of the corresponding product, which serves as the fifth component. The carry value c is determined based on the sum of the first, second, third, fourth, and fifth components. i The first addition and the first slice.
[0011] In another embodiment, the sum of the third and fifth sub-items is replaced by a sixth sub-item, and the operation of determining the third and fifth sub-items is replaced by the following operation of determining the sixth sub-item: summing the (i-1)th bit of the first Boolean segment and the (i-1)th bit of the random number y to obtain a second sum; and then using the second sum and the carry value c held by the second party. i-1 The second slice performs two-way safe multiplication to obtain the first slice of the corresponding product, which is the sixth item.
[0012] In one embodiment, the step of securely calculating the sum of the target data x and the random number y with the second party based on the first Boolean slice and the random number y to obtain the first sum slices corresponding to each of the n bits includes: using the first Boolean slice and the random number y, and the second Boolean slice held by the second party, sequentially determining the auxiliary matrices corresponding to each bit from the lowest bit to the highest bit, to obtain the first slice of each auxiliary matrix, wherein a single auxiliary matrix is a 2-order square matrix, and the first element of the first row is the sum of the corresponding bit of the target data x and the corresponding bit of the random number y in the modulo 2 case, the second element is the product of the corresponding bit of the target data x and the corresponding bit of the random number y, and the elements of the second row are 0 and 1; based on the first slices of each auxiliary matrix, securely determining the column vectors corresponding to each carry value with the second party, to obtain the first slice of each column vector, wherein a single column vector has a dimension of 2, and the first element is the corresponding carry value c. i In the column vector corresponding to the 0th bit, the carry value c0 is 0, and the column vectors corresponding to other bits are the product of the auxiliary matrix corresponding to the previous bit and the column vector. The first element of each column vector is taken as the first slice of the corresponding bit carry value, and it is added modulo 2 with the first Boolean slice and the corresponding bit of the random number y to obtain each first summed slice.
[0013] In one embodiment, the step of securely determining the column vectors corresponding to each carry value based on the first slice of each auxiliary matrix and the second party to obtain the first slice of each column vector includes: based on the first slice of each auxiliary matrix, securely determining the merged matrix of each pair of adjacent auxiliary matrices by secure multiplication with the second party to obtain the first slice of each of the n / 2 merged matrices; recursively calling the first accumulation algorithm with the second party through secure computation to determine the respective accumulation matrices corresponding to each merged matrix to obtain the first slice of each accumulation matrix, wherein the first accumulation algorithm maps a single merged matrix to the product of the single merged matrix and the subsequent merged matrices; the first slice of each accumulation matrix is used as the first slice of the column vector corresponding to the odd-numbered bits in each column vector; and the product of the auxiliary matrix with the even-numbered bits and the corresponding accumulation matrix is determined by the second party through secure multiplication to obtain the first slice of the corresponding product, which is used as the first slice of the column vector with the even-numbered bits, wherein the accumulation matrix corresponding to the even-numbered bit 2j is the (j-1)th accumulation matrix.
[0014] According to the second aspect, a method for converting the shared form of target data is provided for use in secure two-party computation. This method converts the Boolean shared form of target data x between a first party and a second party into a sum-sharing form. The first party and the second party respectively hold a first Boolean fragment and a second Boolean fragment of n bits of the target data x. The method is executed by the second party and includes: based on the second Boolean fragment, performing a secure calculation with the first party of bitwise summation of the target data x and a random number y to obtain n bits corresponding to various second sum-sharing fragments, wherein the random number y is held by the first party; receiving the n first sum-sharing fragments sent by the first party; and recovering the values of the sum z on each bit according to the n first sum-sharing fragments and each second sum-sharing fragment, so as to use the sum z as a second sum-sharing fragment of the target data x, wherein the second sum-sharing fragment and the first party modulo 2 the opposite of the random number y. n The first and shared fragments described by the obtained y' constitute the shared form of the target data x.
[0015] In one embodiment, the n bits are denoted as bits 0 to n-1 from the least significant bit to the most significant bit. The step of securely calculating the bit-by-bit summation of the target data x and the random number y with the first party based on the second Boolean segmentation to obtain each of the n bits corresponding to the respective second summation segments includes: for the i-th bit among the bits 0 to n-1, securely calculating the corresponding carry value c with the first party modulo 2. i The carry value c is obtained. i First carry-part c i0 According to the value x of the i-th bit in the second Boolean segment 1i With carry value c i First carry-part ci1 The sum of the target data x and the random number y is used to obtain the second sum fragment z on the i-th bit.
[0016] In one embodiment, when the i-th bit is not the 0th bit, the carry value c i The (i-1)th bit of the target data x, the (i-1)th bit of the random number y, and the carry value c i-1 The sum of the products of two products multiplied together modulo 2.
[0017] In one embodiment, the step of securely calculating the bit-by-bit summation of the target data x and the random number y based on the second Boolean partition to obtain each second summation partition corresponding to n bits includes: using the second Boolean partition, and with the first Boolean partition held by the first party and the random number y, sequentially determining each auxiliary matrix corresponding to each bit from the lowest bit to the highest bit, to obtain the second partition of each auxiliary matrix, wherein a single auxiliary matrix is a 2-order square matrix, and the first element of the first row is the sum of the corresponding bits of the target data x and the corresponding bits of the random number y in the modulo 2 case, the second element is the product of the corresponding bits of the target data x and the corresponding bits of the random number y, and the elements of the second row are 0 and 1; based on the second partition of each auxiliary matrix, securely determining the column vector corresponding to each carry value with the first party, to obtain the second partition of each column vector, wherein a single column vector has a dimension of 2, and the first element is the corresponding carry value c. i The carry value c0 in the column vector corresponding to the 0th bit is 0, and the column vectors corresponding to other bits are the product of the auxiliary matrix corresponding to the previous bit and the column vector. The first element of each second slice of each column vector is taken as the first slice of the corresponding bit carry value, and it is added modulo 2 with the corresponding bit of the second Boolean slice to obtain each first summed slice.
[0018] In one embodiment, recovering the value of the sum z on each bit based on the n first sum slices and each second sum slice includes: determining the corresponding value for a single bit by performing modulo-2 addition on the corresponding first sum slice and the corresponding second sum slice; or, determining the corresponding value by performing an XOR operation on the corresponding first sum slice and the corresponding second sum slice on a single bit.
[0019] According to a third aspect, a sharing format conversion device for target data is provided for use in secure two-party computation to convert the Boolean sharing format of target data x in the first party and the second party into a sum-shared format, wherein the first party and the second party respectively hold a first Boolean fragment and a second Boolean fragment of n bits of the target data x; the device is located in the first party and includes:
[0020] The acquisition unit is configured to acquire a random number y consisting of n bits.
[0021] The secure computing unit is configured to: calculate the opposite of the random number y modulo 2. n y' is obtained as the first sum-shared slice of the target data x; and based on the first Boolean slice and the random number y, the second party securely calculates the bit-by-bit summation of the target data x and the random number y to obtain each first summation slice corresponding to n bits respectively;
[0022] The sending unit is configured to send each of the first summation fragments to the second party, so that the second party can recover the value of the sum z of the target data x and the random number y on each bit based on the n first summation fragments and the n second summation fragments, wherein the sum z serves as a second summation sharing fragment, which together with the first summation sharing fragments constitutes the summation sharing form of the target data x.
[0023] According to the fourth aspect, a sharing format conversion device for target data is provided for use in two-party secure computation to convert the Boolean sharing format of target data x in the first party and the second party into a sum-shared format, wherein the first party and the second party respectively hold a first Boolean fragment and a second Boolean fragment of n bits of the target data x; the device is located in the second party and includes:
[0024] The secure computing unit is configured to securely calculate, with the first party, bit-by-bit summation of the target data x and the random number y based on the second Boolean segmentation, to obtain each second summation segment corresponding to n bits, wherein the random number y is held by the first party;
[0025] The receiving unit is configured to receive n first summation fragments sent by the first party;
[0026] The merging unit is configured to combine n first summation fragments with each of the second summation fragments to recover the values of the sum z on each bit, so that the sum z is used as the second sum-shared fragment of the target data x. This second sum-shared fragment is combined with the first party to divide the random number y by the negative number y modulo 2. n The first and shared fragments formed by the obtained y' constitute the shared form of the target data x.
[0027] According to a fifth aspect, a computer-readable storage medium is provided having a computer program stored thereon, which, when executed in a computer, causes the computer to perform the method of the first or second aspect.
[0028] According to a sixth aspect, a computing device is provided, including a memory and a processor, characterized in that the memory stores executable code, and when the processor executes the executable code, it implements the method of the first aspect or the second aspect.
[0029] The methods and apparatus provided in the embodiments of this specification propose a novel conversion scheme for Boolean-to-sum-share (B2A) conversion scenarios in two-party secure computation, thereby improving the data processing efficiency of multi-party secure computation. This novel conversion scheme fully utilizes the characteristic that, under Boolean-shared form, the sum and XOR operation results of the bit values corresponding to individual bits of each Boolean slice are consistent in modulo 2. One party generates a random number and generates a sum-shared slice based on its negative. This sum is then used by the other party for secure addition calculation based on the Boolean slice and the random number. The sum of the Boolean slice and the random number is obtained by the other party and used as another sum-shared slice. This method avoids the complex computations of operational technology (OT), reduces data communication volume, and improves the business processing efficiency of multi-party secure computation. Attached Figure Description
[0030] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the following description of the embodiments will be briefly introduced. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0031] Figure 1 This diagram illustrates the data communication between two parties in a secure multiplication process.
[0032] Figure 2 This diagram illustrates an interactive flowchart of a shared format transformation of target data performed by two parties according to one embodiment.
[0033] Figure 3 A flowchart illustrating a shared format conversion method for target data performed by a single participant according to one embodiment is shown.
[0034] Figure 4 A flowchart illustrating a shared form conversion method for target data performed by a single participant according to another embodiment is shown.
[0035] Figure 5 A schematic block diagram of a shared format conversion apparatus for target data performed by a single participant according to one embodiment is shown.
[0036] Figure 6 A schematic block diagram of a shared form conversion apparatus for target data performed by a single participant according to another embodiment is shown. Detailed Implementation
[0037] The technical solutions provided in this specification are described below with reference to the accompanying drawings.
[0038] Secret sharing, also known as secret splitting or secret sharing, works by dividing a secret (such as a key or private data) into multiple shares, each held by a different person. The secret can only be recovered when more than a certain number of parties combine their shares; shares obtained from fewer than the threshold cannot recover any information from the secret. In multi-party secure computation, the threshold number is usually the same as the number of participants, and the shares into which the secret is split can also be called fragments.
[0039] Secret sharing is a crucial technique in secure multi-party computation. Common forms of secret sharing in secure multi-party computation include arithmetic sharing, Boolean sharing, and Yao's Sharing. The following description uses the sharing of secret data x as an example to illustrate these various sharing methods.
[0040] Arithmetic sharing, also known as sum sharing, involves dividing an integer x into two slices, x = x... L +x R Mod 2 N The shared form is distributed and stored between two parties, so that one party does not know x. R The other party is unaware of x L Neither of the two sides can yield the complete form of x. Furthermore, the two sides can be extended to multiple sides, as denoted as x = x1 + x2 + ... + x d Assuming N = 64, then x can be represented as a single fragment of a data set in a single participant using a 64-byte (bit) binary number. One way to split a piece of data x into shared fragments is, for example, by randomly generating d-1 binary shards. 64 The values within the range (such as randomly generated 64-byte binary numbers) are used as d-1 slices, denoted as x1, x2, ..., x... d-1 Subtract the difference between these d-1 pieces from x to get 2 64 Take the modulo as another partition, denoted as x. d = (x - x1 - x2 - ... - x d-1 )%2 64 .
[0041] Boolean sharing is a secret sharing method that uses an XOR operation on bits. For example, considering two participants, suppose x is a one-bit data (with a value of 0 or 1), and... In a Boolean shared form between two participants, x0 and x1 are two Boolean shared partitions of x in the two participants, each taking a value of 0 or 1. This represents the XOR operation. A single participant is unaware of the other participant's share and therefore cannot deduce the data x. For data x' consisting of n bits, an n-bit binary number can be randomly generated as one party's Boolean shared share (e.g., x0'). The other party's Boolean shared share (e.g., x1') can be obtained by XORing x' with that party's Boolean shared share. Sure.
[0042] Yao's sharing is a sharing method related to Garbled Circuits (GC), which can be computed using Boolean circuits. Taking two participants (the obfuscator and the computer) as an example, the obfuscator can set a global string R, and the result of R acting on a string representing 0 (e.g., L0) is a string representing 1 (e.g., L1). For example, the XOR result of R and L0 is L1. For instance, one slice x0 of the secret data x in Yao's sharing could be a randomly generated string k0, and another slice could be the XOR value k1 of k0 and the result of R acting on x (e.g., denoted as...). ).
[0043] Each of the three sharing methods described above has its own advantages and disadvantages. Furthermore, these sharing methods can be interchanged. For example:
[0044] Yao to Boolean Sharing (Y2B) involves each participant calculating the XOR result of the desired shared fragment and a string representing 0 locally, which is then used as the corresponding Boolean shared fragment.
[0045] Boolean to Yao Sharing (B2Y) is converted. The first party holding Boolean fragment x0 (e.g., the corresponding obfuscating party) randomly generates Yao fragment k0. Both parties execute the unintentional transfer protocol (OT), and the first party calculates... The second party uses its Boolean fragment x1 as the selection bit to obtain the Yao fragment.
[0046] Arithmetic sharing is converted to Yao sharing (A2Y). Both parties determine the corresponding Yao-shared fragments for the two fragments x0 and x1 of x, resulting in two sets of Yao-shared fragments (x0)0, (x0)1, (x1)0, and (x1)1. Then, each party performs the addition operation on its local Yao-shared fragments to obtain the two Yao-shared fragments of x, such as x000, x1 ... Y 0 = (x0)0 + (x1)0, x Y 1 = (x0)1 + (x1)1;
[0047] Arithmetic to Boolean sharing (A2B) can be implemented using Boolean adder circuits (similar to A2Y) or arithmetic bit extraction circuits. Since Y2B is overhead-free, and A2B sharing is more efficient than Boolean circuits in addition, A2Y and Y2B can be used sequentially to process the corresponding arithmetic slices, resulting in the corresponding Boolean slices. For example, arithmetic slice x... L via Y2B(A2Y(x) L The process yields a Boolean fragment x0;
[0048] Boolean to Arithmetic Sharing (B2A) is a method of converting Boolean sharing to arithmetic sharing. While B2A can be implemented using subtraction on a Boolean circuit, this method is too expensive. To improve performance, both parties can use an OT-based approach. In the i-th OT operation targeting the i-th bit, one party (e.g., party A) sends two strings s to the other party (e.g., party B). i,0 s i,1 And make them satisfy: The other party, acting as the receiver, inputs the value of the i-th bit in the local Boolean segment. As a selection bit, it is obtained Furthermore, the sender calculates Receiver calculation Thus, the Boolean shared form is converted to the AND shared form;
[0049] etc.
[0050] The various sharing methods and their conversions will not be listed here.
[0051] In secure multi-party computation, business data is typically shared among the participants, with each participant holding a shared fragment. Arithmetic sharing (and other forms of sharing) is commonly used due to its ease of computation. During business processing, the sharing format of business data can be transformed for convenience. In the above conventional transformations, the conversion from Boolean sharing to arithmetic sharing (B2A) is implemented based on unobtrusive OT transmission after reducing overhead. According to its principle,... I The communication throughput for B2A using n bits is n(n+1) / 2 bits offline and 2n bits online. This still represents a significant communication throughput. Those skilled in the art will understand that "offline" here refers to parameter preparation processes independent of the business processing, such as when the sender sends two strings s. i,0 si,1 The process of the receiver determining the selected bits, etc., while online refers to the business processing process, which is the process of calculating using real parameters combined with pre-prepared parameters.
[0052] To further reduce communication overhead and improve the efficiency of multi-party secure computation, this specification proposes a new B2A conversion protocol. First, it needs to be clarified that for a value in Boolean shared form consisting of n-bit Boolean fragments, after conversion to a sum-shared form, the number of bits in a single arithmetic shared fragment is usually still n. The conversion principle is explained below.
[0053] For a value x stored in Boolean shared form between two participants (hereinafter referred to as the first party P0 and the second party P1), its two Boolean partitions can be denoted as x0 and x1, then This represents the XOR operation. Converting the value x from Boolean shared form to AND shared form is denoted as B2A(x). Assume the first party P0 generates a value in the interval [0, 2]. n A random number y is generated if the first party P0 and the second party P1 can safely compute a modulo 2. n The value z = B2A(x) + y, and z is merged into the second party P1's holding, then: the -y held by the first party is shifted to [0, 2]. n The value y' in the interval, and z held by the second party P1, can form the sum-shared form of x in the first and second parties, that is, complete B2A(x).
[0054] To calculate z, we need to calculate each bit of z (a total of n bits). Where i represents the i-th bit among the n bits from 0 to n-1, the Boolean form of the i-th bit of z is: z i =x i +y i +c i Modulo 2. Where c i This indicates the carry from the previous bit (e.g., i-1 bits). Specifically, when i = 0, c0 = 0; when i is 1 to n-1, c0 = 0. i This can be described by the following formula: c i =x i-1 y i-1 +x i-1 c i-1 +y i-1 c i-1 Modulo 2, the principle is: in c i-1 When x is 0, i-1 and y i-1 If neither of them is 0, then c i =1, generate a carry in the i-th bit, otherwise c i=0, no carry is generated at the i-th bit; in c i-1 If c is 1, it means there is a carry in the (i-1)th bit, then c i By x i-1 y i-1 c i-1 Jointly decided, x i-1 y i-1 If both x are 0, then no carry occurs. i-1 y i-1 If any bit is non-zero, then a carry-1 is generated in the i-th bit, x. i-1 y i-1 If none of them are 0, then c can be obtained by modulo 2. i =1 generates a carry at the i-th bit.
[0055] It is understandable that y is generated by the first party, therefore, y i Held by the first party, while x i The first and second parties constitute a Boolean shared form. In Boolean form, since each bit has only two possible values, 0 and 1, if the two values of the same bit are the same, their XOR value, or their sum modulo 2, is 0; otherwise, if the two values of the same bit are different, their XOR value, or their sum modulo 2, is 1. In other words, Modulo 2. For example, suppose x0 = 11010001, x1 = 10011101, That is, 76. Where, in the 2nd bit (i=2), x 02 =0, x 12 =1, Modulo 2 = 1, and similarly, the 3rd and 6th bits follow the same logic. However, in the 1st bit, x... 01 =x 11 =0, Modulo 2 = 0, the same applies to the 5th bit. The 0th bit, x 01 =x 11 =1, without considering carry (carry is determined by c) i (Control), then there is Modulo 2 = 0, and the same applies to the 4th and 7th bits. Thus, in z... i =x i +y i +c i In the modulo 2 calculation process, x in the Boolean shared form can be used directly. 0i +x 1i Modulo 2 represents the value x of the i-th bit. i .
[0056] The first and second parties can be based on the z described above. i =x i +y i+c i Modulo-2 calculation of the bit slices of z. Where, x i This is equivalent to the i-th bit in the Boolean slices of the first and second parties (e.g., denoted as x respectively). 0i x 1i The summation modulo 2, y i Held by the first party, c i The first and second parties have corresponding modulo 2 Boolean partitions (e.g., denoted as c respectively). 0i c 1i Therefore, the first party can calculate x. 0i +y i +c 0i And send the calculation result to the second party (communication volume is n bits), since y i The randomness of c 0i Based on secure computation, therefore, sharing x 0i +y i +c 0i The calculation results will not reveal x 0i It will not leak y i and c 0i Thus, the second party can calculate x. 1i +c 1i +(x 0i +y i +c 0i ), thereby restoring z i The binary form of z is obtained. This z and the -y held by the first party constitute the Boolean shared form x, which is converted into the shared form B2A(x).
[0057] In this way, the conversion from Boolean sharing to arithmetic sharing implemented via obfuscated circuits or OT can be changed to a conversion based on secure addition and secure multiplication, reducing computational complexity and improving the efficiency of business processing involving data B2A.
[0058] Based on the above principles Figure 2 This diagram illustrates the interaction flow between two participants when converting data x from Boolean shared form to AND shared form. It can be understood that in Boolean shared form, each bit takes the value 0 or 1, and a single Boolean slice is n bits. In AND shared form, the data is stored in binary. When converting between Boolean and AND shared forms, the number of bits is usually the same; therefore, the number of bits in a single AND shared slice can also be n. A single participant can be any computer, device, or server with certain communication and computing capabilities.
[0059] refer to Figure 2 As shown, the process for converting data x in Boolean shared form to AND shared form provided in this specification includes the following steps:
[0060] Step 201: The first party obtains an n-bit random number y. The random number y can be generated by the first party or pre-generated by a semi-trusted third party and sent to the first party. To reduce communication overhead, it can be generated by the first party. The random number y can be generated using any random number generation method, and there are no restrictions here. The random number y can be represented as an n-bit binary number.
[0061] Based on the principles described above, to determine the sum-sharing form of the target data x, a sum-sharing partition can be constructed based on -y. In the sum-sharing form, a single partition is calculated modulo 2. n Mapped to [0, 2] n The interval is [-1]. When y is in the range [0, 2], ... n In the case of the interval [-1], -y may exceed that interval, so -y can be shifted by an integer number of 2s. n to [0, 2] n -1] interval (increment or decrease of integer 2s) n Let y' be the first and shared partition of the target data x.
[0062] Another shared fragment of the target data x, denoted as the second shared fragment z, needs to be securely determined by both the first and second parties, and held by the second party. Based on the principles described above, the second shared fragment z can be determined bit by bit, with each bit being the sum of the corresponding bits of x and y modulo 2.
[0063] Therefore, in step 202, the first party and the second party securely calculate the sum of the target data x and the random number y bit by bit modulo 2.
[0064] Based on the principles described above, to determine the sum z of the target data x and the random number y, two Boolean-shared segments of the sum z can be determined in the first and second parties. For a single Boolean segment, the result of the XOR operation on a single bit is consistent with the result of the modulo-2 summation. If the i-th bit has the same value in both Boolean segments (either 1 or 0), the XOR result is 0, and the modulo-2 summation result is also 0. If the i-th bit has different values in the two Boolean segments (one is 1, and the other is 0), then both the XOR result and the modulo-2 summation result are 1.
[0065] Therefore, the first and second parties can securely calculate the modulo-2 sum bit by bit for the target data x and the random number y, and obtain the corresponding sum slices in the first and second parties respectively. A slice corresponding to a single bit is a bit value of 0 or 1. To obtain the actual sum data, the carry-over of each bit needs to be considered. That is, for the i-th bit, z... i =x i +yi +c i Modulo 2. Where c i Let c0 be the carry of the i-th bit, and c0 = 0. It can be understood that in the process of adding binary numbers, calculations are usually performed from the least significant bit to the most significant bit. The carry of the i-th bit can be determined by the (i-1)-th bit, and the carry of the (i+1)-th bit is determined by the i-th bit. Therefore, except for the 0th bit, the carry of a single bit i can be determined by the value x in the (i-1)-th bit. i-1 The numerical value of y i-1 and carry value c i-1 Determined. Considering the special properties of the product of 0 and 1, the carry of the i-th bit can be x. i-1 y i-1 and c i-1 The sum of the products of two pairs modulo 2: c i =x i-1 y i-1 +x i-1 c i-1 +y i-1 c i-1 .
[0066] To calculate c i This can be iterated sequentially from 0 to n-1 bits, such as: c0 = 0 (publicly available); c1 = x0y0 + 0 + 0; c2 = x1y1 + x1c1 + y1c1; c3 = x2y2 + x2c2 + y2c2... Here, y i Held by the first party, x i Boolean partitions of x in the first and second parties 0i x 1i The result modulo 2, therefore, regarding x i The product term can be split into (x 0i +x 1i The product term modulo 2. For example, c1 = x0y0 = (x 01 +x 11 If y = 0 modulo 2, then both parties need to perform safe multiplication to calculate the multiplier x held by the first party. 1i The product of the multiplier y0 held by the second party modulo 2 yields a shared form where c1 has a share on both P0 and P1.
[0067] For the bits after the second bit, the first party holds the carry value c. i-1 First slice c (i-1)0 And the first party holds x i-1 First slice x (i-1)0 y i-1 The second party holds the carry value c. i-1 The second segment c (i-1)1 xi-1 First slice x (i-1)1 In calculating c i At that time, we have: c i =(x (i-1)0 +x (i-1)1 )y i-1 +(x (i-1)0 +x (i-1)1 (c) (i-1)0 +c (i-1)1 )+y i-1 (c (i-1)0 +c (i-1)1 Therefore, the first party can compute x locally. (i-1)0 y i-1 x (i-1)0 c (i-1)0 y i-1 c (i-1)0 The second party can calculate x locally. (i-1)1 c (i-1)1 Furthermore, the first party can perform secure multiplication of single bits of data with the second party to calculate x. (i-1)1 y i-1 x (i-1)0 c (i-1)1 x (i-1)1 c (i-1)0 y i-1 c (i-1)1 Thus, the first side obtains the first slice of each product term, and the second side obtains the second slice of each product term. The first side can use the sum of the locally calculated terms as the first slice, and the first slice of each product term as the second, third, fourth, and fifth slices respectively, and the sum of them modulo 2 as c. i The first summation slice. Similarly, the second side can be the second slice of each product term, along with the locally computed x. (i-1)1 c (i-1)1 Perform a modulo 2 summation, and use the result as c. i The second summation slice. In an optional embodiment, for secure multiplication x (i-1)0 c (i-1)1 and y i-1 c (i-1)1 Because of c (i-1)1 Held by a second party, x (i-1)0 and y i-1 Held by the first party, x can (i-1)0 and y i-1 The first party sums the results locally and then performs a safe multiplication with the second party, thereby further reducing the amount of communication.
[0068] Taking c2 as an example: the calculation of x1y1 is similar to x0y0, involving one modulo-2 secure multiplication; since c1 and x1 each have a fragment in P0 and P1 respectively, the split x1c1 involves two modulo-2 multiplications: multiplying the fragment of c1 in P0 by the fragment of x1 in P1, and multiplying the fragment of c1 in P1 by the fragment of x1 in P0; and since y1 is held by P0, y1c1 involves a modulo-2 secure multiplication of y1 held by P0 with the fragment of c1 in P1; thus, the calculation of c2 can involve four single-bit secure multiplications. Similarly, the subsequent bit-related c3, c4, etc., each involve four modulo-2 secure multiplications.
[0069] The calculation process for safe multiplication is as follows: Figure 1 As shown, the first party holds multiplier a and the second party holds multiplier b (both a and b are defined in a space of size 2). N Given numbers in the Abelian group A), and considering the need for secure multiplication of a and b by both parties, the secure multiplication process is as follows: First, the first party obtains a random number u, and the second party obtains a random number v. u and v can be obtained by a third party (…). Figure 1 The random number generator (in this context, a random number generator server) generates and distributes the numbers to the first and second parties, or the first and second parties can generate them locally. The third party generates u and v locally or obtains u and v from the first and second parties, calculates u×v, and splits it according to the sum-sharing method to obtain random fragments z0 and z1, then z0 + z1 = u×v = uv. The third party can provide z0 and z1 to the first and second parties respectively. Assume the first party receives z0 and the second party receives z1. Here, u and v can be seen as perturbation or noise terms for a and b respectively, with e and f representing the perturbation results after adding noise to a and b respectively. The first party calculates the perturbation result e = au and sends it to the second party, while the second party calculates the perturbation result f = bv and sends it to the first party. Further, the first party can calculate one sum-sharing fragment c0 = uf + z0 for a×b, and the second party can calculate another sum-sharing fragment c1 = eb + z1 for a×b. Substituting the expressions for e and f, we get: c0 + c1 = uf + z0 + eb + z1 = ub - uv + z0 + ab - ub + z1 = ab. In other words, c0 and c1 form a sum-shared form of the product of a and b.
[0070] The communication data consists of data u, v, z0, and z1 sent offline by the service provider, and data e and f exchanged between the two data providers when online. Therefore, the secure multiplication of one bit offline and online communication costs 4 bits and 2 bits, respectively. Under the PRF mechanism, each data provider can generate relevant random numbers according to a consistent random number generation method and the same random number seed. Only one random number that satisfies the constraints is generated by the service provider and sent to the corresponding data provider. For example, Figure 1In the illustrated process, the first party and the service party each generate random numbers u and z0 locally, while the second party and the service party each generate random number v locally. The service party determines z1 according to the constraint z0 + z1 = uv and provides it to the second party. Therefore, under the PRF mechanism, secure multiplication of one bit requires 1 bit offline and 2 bits online communication. Thus, carry calculation of n bits can generate n bits of offline communication and 2n bits of online communication.
[0071] To further reduce communication volume, based on this concept, an iterative scheme based on the multiplication of the auxiliary matrix and column vector is proposed by constructing auxiliary matrices and column vectors using elements with extended values of 0 and 1.
[0072] Specifically, according to the carry c i The method for determining c, assuming c i Expanded into a 2-dimensional column vector, with one dimension being c. i If the other dimension is 1, then:
[0073]
[0074] Here, mod2 indicates that the operation is performed modulo 2 (i.e., shifted to the interval [0, 1]).
[0075] The transformation matrix between two column vectors is called the auxiliary matrix, denoted as A. i Then we have:
[0076] i = 1, 2, ..., n-1,
[0077] Then recursively, in the modulo 2 case, we have: If the last bit is the (n-1)th bit, then
[0078] In one possible implementation, a accumulator f (which may be called the first accumulator) can be used to make the accumulator from A... i The set A = (A n-1 A n-2 ...A0) to another set B = (B n-1 B n-2 ...B0) satisfies a right-to-left cumulative mapping, i.e., f(A) = B, such that a single element in B is the product of its corresponding element in set A and its right-hand side elements. Specifically, suppose i is any number from 0 to n-1, then B i =A i ×……A0. If i=0, then B0=A0. Therefore, set B constitutes the set of column vectors corresponding to each carry bit, i.e.
[0079] Because of A i Only with x i-1 y i-1 Therefore, to reduce communication complexity, some alternative implementations can combine the products of multiple consecutive elements in set A, and these products can be computed in parallel. Taking the combination of pairwise element-wise products as an example, D can be calculated. j =A 2j+1 ×A 2j The value of j can be 0, 1, ..., n / 2-1, for a total of n / 2 values. As an example, when j = 0, D0 = A1 × A0; when j = 1, D1 = A3 × A2, and so on. Due to the definition above... From A n-2 Up to A0, there are n-1 possible combinations, where n is usually a power of 2 (an even number). Therefore, A can also be defined. n-1 identity matrix Therefore, the elements in set D can be the product of two adjacent, non-repeating elements in set A, for a total of n / 2 elements.
[0080] Understandably, for A i The calculation involves x. i-1 In the second-party fragmentation and the first-party held y i-1 For secure multiplication calculations, the communication throughput is 4 offline and 2 online. A 2j+1 ×A 2j For multiplication of two 2x2 square matrices, based on the dependencies between elements, there is at most 2 bytes of offline communication and 6 bytes of online communication.
[0081] Furthermore, by applying the previously mentioned cumulative function f to set D, we obtain f(D)→E. Then, in set E, E... j =D j ×……D0. The value of j is 0, 1……n / 2-1. As an example, we have: E0=D0=A1×A0, E1=D1×D0=A3×A2×A1×A0,……that is, E j =A 2j+1 ×……A0=B 2j+1 Therefore, we can obtain the odd-numbered terms of B, and the even-numbered terms of B are: B 2j =A 2j+1 ×E j-1 Thus, the elements of B have been calculated. Furthermore, the calculation results of set B constitute a Boolean shared form in both the first and second rounds. Since a single element of B is a two-dimensional vector, B... i The value of the first dimension is c. i Therefore, based on the calculation result of B, the carry-in c can be obtained. iWhere i = 0, 1, 2...n-1. Following this principle, recursively calling the accumulation function f will sequentially obtain each set with half the number of elements until only two elements remain in the set. Finally, the accumulation function f is called again to obtain the product of these two elements. The total number of calls is denoted as R(n), then R(n) = R(n / 2) + 1. Recursively, R(n) = log₂n. The communication volume C(n) = C(n / 2) + nT, where T is the communication volume corresponding to the secure multiplication of two 2x2 matrices (such as the offline 2 bytes and online 6 bytes described earlier). Substituting the call volume R(n) into the equation, the communication volume is recursively calculated as C(n) = 2nT.
[0082] Thus, by calling the accumulation algorithm, the carry c corresponding to each bit can be calculated. i The total communication volume of the cumulative algorithm is at most 4n bytes offline and 12n bytes online.
[0083] With each carry c i Both the first and second parties can each locally compute the local fragmentation of each bit in (x+y). Taking the i-th bit as an example, the first party can compute z... i0 =x i0 +y i0 +c i0 As the first summation fragment of the i-th bit, the second party can calculate z. i1 =x i1 +c i1 , as the second summation segment of the i-th bit.
[0084] Step 203: The first party sends the respective first sum fragments corresponding to each bit to the second party. Since a single first sum fragment of the first party is composed of x... i0 y i0 and secure computing c i0 Therefore, z is provided to the second party. i0 It will not leak x i0 or y i0 Data privacy is ensured. The communication volume for this step is n bits.
[0085] Step 204: The second party recovers the value of the sum z of the target data x and the random number y on each bit based on each first summation fragment and each second summation fragment.
[0086] It is understandable that, for a single bit, the corresponding single first summation fragment and the second summation fragment constitute the Boolean shared form of the sum z. Therefore, the corresponding value can be recovered through an XOR operation or modulo 2 addition, which will not be elaborated here. According to the principle mentioned above, this sum z can be used as the second summation shared fragment for converting the target data x from the Boolean shared form to the summation shared form, together with the first summation shared fragment y' held by the first party to constitute the summation shared form of the target data x.
[0087] In summary, under the technical concept of this specification, the communication volume includes: n bits offline and 2n bits online for calculating Ai; at most 4n bits offline and 12n bits online for the accumulation algorithm; and n bits provided by the first party for each summation fragment. Compared with conventional technologies, the offline communication volume is 5n bits and the online communication volume is 15n bits, which is much smaller than the communication volume of B2A conversion in conventional technologies.
[0088] refer to Figure 3 The diagram illustrates the operational flow performed by the first party in the shared data transformation process for the target data. Here, the first party is the participant holding the random number as the first and shared shard; this name does not constitute a substantial limitation on the participant. Specifically, the operational flow performed by the first party includes the following steps:
[0089] Step 301: Obtain a random number y of n bits;
[0090] Step 302, take the opposite of the random number y, minus y modulo 2. n Obtain y' as the first and shared fragment of the target data x;
[0091] Step 303: Based on the first Boolean segment and the random number y, the second party securely calculates the bit-by-bit summation of the target data x and the random number y to obtain the first summation segment corresponding to each of the n bits;
[0092] Step 304: Send each of the first summation fragments to the second party so that the second party can recover the value of the sum z of the target data x and the random number y on each bit based on the n first summation fragments and the n second summation fragments. The sum z is used as the second summation sharing fragment, which together with the first summation sharing fragments constitutes the summation sharing form of the target data x.
[0093] Steps 303 and 304 are processes that assist the second party in obtaining the second and shared fragment z. These processes are based on the random number y in step 301. The process of determining the first and shared fragment based on y is completed independently by the first party. Therefore, the process of determining the first and shared fragment in step 302 and the process of assisting the second party in obtaining the second and shared fragment z in steps 303 and 304 are independent of each other. They can be executed in parallel or in reverse order (e.g., steps 303 and 304 are executed first, followed by step 302). No limitation is made here.
[0094] Figure 4 The diagram illustrates the operational flow performed by a second party in the shared format transformation process for target data. Here, the second party is the participant that obtains the sum of the random number and the target data as the second and shared shards; this name does not constitute a substantial limitation on the participant. Specifically, the operational flow performed by the second party includes the following steps:
[0095] Step 401: Based on the second Boolean segmentation, the first party securely calculates the bit-by-bit summation of the target data x and the random number y to obtain the second summation segments corresponding to each of the n bits;
[0096] Step 402: Receive n first summation fragments sent by the first party;
[0097] Step 403: Based on the n first summation slices and each of the second summation slices, recover the value of the sum z on each bit, so that the sum z is used as the second summation shared slice of the target data x. This second summation shared slice and the first summation shared slice are the opposite of the random number y - y modulo 2. n The first and shared fragments formed by the obtained y' constitute the shared form of the target data x.
[0098] It is worth noting that, Figure 3 , Figure 4 The operation procedures shown correspond to respectively Figure 2 The corresponding operations performed by the first and second parties in the process, therefore, for Figure 2 The descriptions of the relevant participants also apply to Figure 3 , Figure 4 The process will not be elaborated here.
[0099] Reviewing the above process, under the technical concept provided in this specification, the target data x, which is a single piece of Boolean shared data of n bits, is transformed into a group defined in the Abelian group {2}. n In the process of sharing over a group, one party determines a sharing partition based on a random number. Meanwhile, both parties utilize secure multiplication and secure addition between individual bits to satisfy the conditions defined in the Abelian group {2}. 1The shared-form conversion method, which securely calculates the sum of each bit of the target data x and the random number y, yields corresponding sum fragments for each of the two participating parties. Since the single sum fragment generated by the random number generator incorporates the Boolean fragments of the corresponding bits of the target data x, the numerical values of the corresponding bits of the random number, and the carry fragments, it can be shared with the other party. The other party can then reconstruct the sum of each bit of the target data x and the random number y, using it as another shared-form fragment of the target data, thus completing the shared-form conversion. This method avoids the large amount of data communication caused by unintentional transmissions, providing a more efficient B2A conversion method and improving the business processing efficiency of secure computation.
[0100] According to another embodiment, this specification also provides a corresponding sharing format conversion device for target data. Figure 5 A device 500 is shown, in which a participant (such as the first party) holds a random number as the first and shares a fragment. Figure 5 As shown, the device 500 includes:
[0101] Unit 501 is configured to obtain a random number y consisting of n bits;
[0102] The secure computing unit 502 is configured to: calculate the opposite of the random number y modulo 2. n Obtain y' as the first shared slice of the target data x; and, based on the first Boolean slice and the random number y, calculate the bit-by-bit sum of the target data x and the random number y with the second party to obtain the first sum slices corresponding to the n bits respectively;
[0103] The sending unit 503 is configured to send each of the first summation fragments to the second party so that the second party can recover the value of the sum z of the target data x and the random number y on each bit based on the n first summation fragments and the n second summation fragments. The sum z serves as the second summation sharing fragment, which together with the first summation sharing fragments constitutes the summation sharing form of the target data x.
[0104] on the other hand, Figure 6 An apparatus 600 is shown that is configured to obtain the sum of a random number and target data as a second and shared fragment participant. Figure 6 As shown, the device 600 includes:
[0105] The secure computing unit 601 is configured to sum bit by bit with the first party's secure computing target data x and random number y based on the second Boolean segmentation to obtain each second summation segment corresponding to n bits.
[0106] The receiving unit 602 is configured to receive n first summation fragments sent by the first party;
[0107] Merging unit 603 is configured to recover the value of the sum z on each bit based on n first sum fragments and each second sum fragment, so as to use the sum z as the second sum shared fragment of the target data x, which is combined with the second sum shared fragment of the first sum fragment by taking the opposite of the random number y modulo 2. n The first and shared fragments described by the obtained y' constitute the shared form of the target data x.
[0108] It is worth noting that, Figure 5 , Figure 6 The devices 500, 600 and shown are Figure 3 , Figure 4 Corresponding to the described method, Figure 3 , Figure 4 The corresponding descriptions in the method embodiments also apply to devices 500 and 600, and will not be repeated here.
[0109] According to another embodiment, a computer-readable storage medium is also provided, on which a computer program is stored, which, when executed in a computer, causes the computer to perform a combination Figure 3 , Figure 4 The methods described above.
[0110] According to another embodiment, a computing device is also provided, including a memory and a processor, wherein executable code is stored in the memory, and when the processor executes the executable code, it implements a combination... Figure 2 , Figure 3 The methods described above.
[0111] Those skilled in the art will recognize that the functions described in the embodiments of this specification in one or more of the above examples can be implemented using hardware, software, firmware, or any combination thereof. When implemented in software, these functions can be stored in a computer-readable medium or transmitted as one or more instructions or code on a computer-readable medium.
[0112] The above specific embodiments further illustrate the purpose, technical solution, and beneficial effects of the technical concept of this specification. It should be understood that the above are merely specific embodiments of the technical concept of this specification and are not intended to limit the scope of protection of the technical concept of this specification. Any modifications, equivalent substitutions, improvements, etc., made on the basis of the technical solutions of the embodiments of this specification should be included within the scope of protection of the technical concept of this specification.
Claims
1. A method for converting the shared form of target data in a two-party secure computation, wherein the target data x in the Boolean shared form of the first party and the second party is converted into a sum-shared form, wherein the first party and the second party respectively hold a first Boolean fragment and a second Boolean fragment of n bits of the target data x; The method is performed by a first party and includes: Get a random number y consisting of n bits; obtaining the inverse -y of the random number y modulo 2 n obtaining y' as the first and shared slice of the target data x; Based on the first Boolean slice and the random number y, the second party securely calculates the bit-by-bit summation of the target data x and the random number y to obtain each first summation slice corresponding to n bits, and at the same time, each second summation slice corresponding to n bits is obtained by the second party; Each first summation fragment is sent to the second party so that the second party can recover the value of the sum z of the target data x and the random number y on each bit based on the n first summation fragments and the n second summation fragments. The sum z serves as the second summation sharing fragment, which together with the first summation sharing fragments constitutes the summation sharing form of the target data x.
2. The method as described in claim 1, wherein, The n bits are denoted as bits 0 to n-1 from the least significant bit to the most significant bit. The step of calculating the bit-by-bit summation of the target data x and the random number y based on the first Boolean segment and the random number y, and obtaining the respective first summation segments corresponding to the n bits, includes: For the i-th bit in the 0-th to n-1-th bits, a carry value c corresponding to the secure computation with the second party on the basis of modulo 2 i , to obtain a first carry slice c i of the carry value c i0 ; Based on the value x of the i-th bit in the first Boolean segment 0i The value of the i-th bit of the random number y i Carry value c i First carry-part c i0 The sum of the target data x and the random number y is used to obtain the first sum fragment z on the i-th bit.
3. The method as described in claim 2, wherein, When the i-th bit is the 0th bit, the carry value c i It is 0.
4. The method of claim 2, wherein, When the i-th bit is not the 0th bit, the carry value c i The (i-1)th bit of the target data x, the (i-1)th bit of the random number y, and the carry value c i-1 The sum of the products of two pairs of products modulo 2.
5. The method of claim 4, wherein, The first party and the second party each hold the carry value c. i-1 The first fragment, the second fragment; The carry value c i The first summation slice is determined in the following way: The first item is determined by multiplying the (i-1)th bit of the first Boolean segment with the (i-1)th bit of the random number y; By performing a two-party secure multiplication using the (i-1)th bit of the random number y and the second Boolean fragment held by the second party, the first fragment of the corresponding product is obtained, which serves as the second item. Using the (i-1)th bit of the first Boolean segment and the carry value c held by the second party i-1 The second slice performs two-way safe multiplication to obtain the first slice of the corresponding product, which is used as the third item; Using the carry value c i-1 The first slice and the (i-1)th bit of the second Boolean slice held by the second party are subjected to a two-party secure multiplication to obtain the first slice of the corresponding product, which is used as the fourth item; The (i-1)th bit of the random number y is compared with the carry value c held by the second party. i-1 The second slice performs two-way safe multiplication to obtain the first slice of the corresponding product, which is used as the fifth item; The carry value c is determined by summing the first item, the second item, the third item, the fourth item, and the fifth item. i The first addition and the first slice.
6. The method of claim 5, wherein, The summation of the third and fifth items is replaced by the sixth item, and the operation to determine the third and fifth items is replaced by the following operation to determine the sixth item: The second sum is obtained by summing the (i-1)th bit of the first Boolean segment and the (i-1)th bit of the random number y. The second summation is combined with the carry value c held by the second party. i-1 The second slice performs two-way safe multiplication to obtain the first slice of the corresponding product, which is the sixth item.
7. The method of claim 1, wherein, The step of calculating the sum of the target data x and the random number y based on the first Boolean segment and the random number y, and obtaining the first summation segments corresponding to n bits respectively, includes: By using the first Boolean segment and the random number y, and the second Boolean segment held by the second party, from the lowest bit to the highest bit, the auxiliary matrices corresponding to each bit are determined in sequence to obtain the first segment of each auxiliary matrix. Each auxiliary matrix is a 2-order square matrix, and the first element of the first row is the sum of the corresponding bit of the target data x and the corresponding bit of the random number y in the modulo 2 case, the second element is the product of the corresponding bit of the target data x and the corresponding bit of the random number y, and the elements of the second row are 0 and 1. Based on the first partition of each auxiliary matrix, and the second party securely determines the column vectors corresponding to each carry value, the first partition of each column vector is obtained. Each column vector has a dimension of 2, and its first element is the corresponding carry value c. i In the column vector corresponding to the 0th bit, the carry value c0 is 0, and the column vectors corresponding to other bits are the product of the auxiliary matrix corresponding to the previous bit and the column vector. The first element of each column vector's first slice is used as the first slice of the corresponding bit carry value. This slice is then summed modulo 2 with the first Boolean slice and the corresponding bit of the random number y to obtain each first summed slice.
8. The method of claim 7, wherein, The first slice based on each auxiliary matrix, and the first slice of each column vector obtained by the second party securely determining the column vectors corresponding to each carry value, include: Based on the first partition of each auxiliary matrix, and the merged matrix of the auxiliary matrices that are safely determined to be adjacent to each other by the second party based on safe multiplication, the first partition of each of the n / 2 merged matrices is obtained. The first accumulation algorithm is recursively called by the second party through secure computation to determine the respective accumulation matrices corresponding to each merge matrix, thereby obtaining the first slice of each accumulation matrix. The first accumulation algorithm maps a single merge matrix to the product of the single merge matrix and the subsequent merge matrices. The first slice of each cumulative matrix is used as the first slice of the column vector corresponding to the odd number of bits in each column vector. The product of the auxiliary matrix for the even-numbered bits determined by the second party through secure multiplication and its corresponding cumulative matrix is used to obtain the first slice of the corresponding product, which serves as the first slice of the column vector of the even-numbered bits. The cumulative matrix corresponding to the even-numbered bit 2j is the (j-1)th one.
9. A method for converting the shared form of target data in a two-party secure computation, wherein the target data x in the Boolean shared form of the first party and the second party is converted into a sum-shared form, wherein the first party and the second party respectively hold a first Boolean fragment and a second Boolean fragment of n bits of the target data x; The method is performed by a second party and includes: Based on the second Boolean segment, the first party securely calculates the bit-by-bit summation of the target data x and the random number y to obtain each second summation segment corresponding to n bits. At the same time, each first summation segment corresponding to n bits is obtained by the first party, wherein the random number y is held by the first party. Receive n first summation fragments sent by the first party; Based on the n first summation fragments and each of the second summation fragments, the values of the sum z on each bit are recovered, so that the sum z is used as the second sum-shared fragment of the target data x. This second sum-shared fragment and the first party modulo 2 the opposite of the random number y - y. n The first and shared fragments described by the obtained y' constitute the shared form of the target data x.
10. The method of claim 9, wherein, The n bits are denoted as bits 0 to n-1 from the least significant bit to the most significant bit. The step of securely calculating the bit-by-bit summation of the target data x and the random number y based on the second Boolean segmentation, to obtain the respective second summation segments corresponding to the n bits, includes: For the i-th bit among bits 0 to n-1, the corresponding carry value c is safely calculated modulo 2 with the first method. i The carry value c is obtained. i First carry-part c i0 ; Based on the value x of the i-th bit in the second Boolean segment 1i With carry value c i First carry-part c i1 The sum of the target data x and the random number y is used to obtain the second sum fragment z on the i-th bit.
11. The method of claim 9, wherein, When the i-th bit is not the 0th bit, the carry value c i The (i-1)th bit of the target data x, the (i-1)th bit of the random number y, and the carry value c i-1 The sum of the products of two pairs of products modulo 2.
12. The method of claim 9, wherein, The step of calculating the bit-by-bit summation of the target data x and the random number y based on the second Boolean segmentation, and obtaining the respective second summation segments corresponding to n bits, includes: By using the second Boolean segment, together with the first Boolean segment held by the first party and the random number y, from the lowest bit to the highest bit, the auxiliary matrices corresponding to each bit are determined in sequence to obtain the second segment of each auxiliary matrix. Each auxiliary matrix is a 2-order square matrix, and the first element of the first row is the sum of the corresponding bits of the target data x and the corresponding bits of the random number y in the modulo 2 case, the second element is the product of the corresponding bits of the target data x and the corresponding bits of the random number y, and the elements of the second row are 0 and 1. Based on the second partition of each auxiliary matrix, and the first party securely determines the column vectors corresponding to each carry value, the second partition of each column vector is obtained. Each column vector has a dimension of 2, and its first element is the corresponding carry value c. i In the column vector corresponding to the 0th bit, the carry value c0 is 0, and the column vectors corresponding to other bits are the product of the auxiliary matrix corresponding to the previous bit and the column vector. The first element of each column vector's second slice is used as the first slice of the corresponding bit carry value. This first slice is then summed modulo 2 with the corresponding bit of the second Boolean slice to obtain each first summed slice.
13. The method of claim 9, wherein, The step of recovering the value of the sum z in each bit based on the n first summation slices and each second summation slice includes: For a single bit, the corresponding value is determined by modulo-2 addition of the first and second summation slices; or For a single bit, the corresponding first summation slice and second summation slice are XORed to determine the corresponding value.
14. A sharing format conversion device for target data, used in two-party secure computation, to convert the Boolean sharing format of target data x in the first party and the second party into a sharing format, wherein the first party and the second party respectively hold a first Boolean fragment and a second Boolean fragment of n bits of the target data x; The device is located in the first party and includes: The acquisition unit is configured to acquire a random number y consisting of n bits. The secure computing unit is configured to: calculate the opposite of the random number y modulo 2. n y' is obtained as the first shared slice of the target data x; and based on the first Boolean slice and the random number y, the second party securely calculates the bit-by-bit summation of the target data x and the random number y to obtain each first summation slice corresponding to n bits respectively, while each second summation slice corresponding to n bits is obtained by the second party. The sending unit is configured to send each of the first summation fragments to the second party, so that the second party can recover the value of the sum z of the target data x and the random number y on each bit based on the n first summation fragments and the n second summation fragments, wherein the sum z serves as a second summation sharing fragment, which together with the first summation sharing fragments constitutes the summation sharing form of the target data x.
15. A sharing format conversion device for target data, used in two-party secure computation, to convert the Boolean sharing format of target data x in the first party and the second party into a sharing format, wherein the first party and the second party respectively hold a first Boolean fragment and a second Boolean fragment of n bits of the target data x; The device is located on the second party and includes: The secure computing unit is configured to perform a bit-by-bit summation of the target data x and the random number y with the first party based on the second Boolean segmentation, to obtain each second summation segment corresponding to n bits respectively, while each first summation segment corresponding to n bits is obtained by the first party, wherein the random number y is held by the first party; The receiving unit is configured to receive n first summation fragments sent by the first party; The merging unit is configured to combine n first summation fragments with each of the second summation fragments to recover the values of the sum z on each bit, so that the sum z is used as the second sum-shared fragment of the target data x. This second sum-shared fragment is combined with the first party to divide the random number y by the negative number y modulo 2. n The first and shared fragments described by the obtained y' constitute the shared form of the target data x.
16. A computer-readable storage medium having a computer program stored thereon, which, when executed in a computer, causes the computer to perform the method of any one of claims 1-13.
17. A computing device, comprising a memory and a processor, characterized in that, The memory stores executable code, and when the processor executes the executable code, it implements the method of any one of claims 1-13.
Citation Information
Patent Citations
Method, device and system for performing form conversion on privacy data fragments
CN113688426A
Highest bit carry calculation method for protecting data privacy
CN113761469A