A privacy-preserving multi-matrix multiplication method

By using homomorphic encryption and blinding factors in multi-party privacy calculations, users and participants perform multi-party privacy calculations without leaking matrix element information, solving the problem of relying on outsourcing servers or trusted third parties in the prior art, and achieving efficient matrix multiplication calculations.

CN115865302BActive Publication Date: 2025-05-16NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211179124.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-09-27
Publication Date
2025-05-16
Estimated Expiration
2042-09-27

AI Technical Summary

Technical Problem

The existing technology requires relying on outsourcing servers or trusted third parties to perform multi-party privacy calculations, which has low computing efficiency.

Method used

By using homomorphic encryption and blinding factors, users and multiple participants perform multi-party privacy calculations without revealing matrix element information to achieve matrix multiplication calculations.

Benefits of technology

In the absence of an outsourcing server or a trusted third party, efficient calculation of matrix multiplication is implemented to ensure the privacy protection of matrix element information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115865302B_ABST
    Figure CN115865302B_ABST
Patent Text Reader

Abstract

The present invention relates to the fields of cryptography and information security technology, and discloses a multi-party matrix multiplication calculation method with privacy protection attributes, which is applied to a data interaction system for privacy computing. The data interaction system includes a user with a matrix A composed of plaintext data, and n participant users with matrices B<supgt;(i)< / supgt; composed of plaintext data. When interacting with the n participants, the user obtains the element information of the data matrix AB without revealing the data information of the matrices composed by each party. The present invention solves the problems existing in the prior art, such as the necessity to rely on an outsourcing server or a trusted third party for multi-party privacy computing and low computing efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of cryptography and information security technology, and in particular to a multi-party matrix multiplication calculation method with privacy protection attributes. Background Art

[0002] Matrices play a key role in scientific fields such as artificial intelligence, cryptography, and numerical analysis. Matrix multiplication is an indispensable part of matrix operations, and many scientific computing problems require the use of matrix multiplication. For example, in the field of machine learning, matrix multiplication is required to input data into a neural network; in the field of cryptography, the original matrix is ​​multiplied by a reversible matrix to hide the original matrix; in addition, vector inner product is also a special kind of matrix multiplication. Recently, with the promulgation of laws and regulations related to data security and privacy protection and the need for privacy protection in actual application scenarios, multi-party matrix multiplication with privacy protection attributes has become an important topic in secure multi-party computing.

[0003] The existing technology has the following problems: it must rely on outsourced servers or trusted third parties to perform multi-party privacy computing, and the computing efficiency is low. Summary of the invention

[0004] In order to overcome the shortcomings of the prior art, the present invention provides a multi-party matrix multiplication calculation method with privacy protection attributes, which solves the problems of the prior art that it must rely on outsourced servers or trusted third parties for multi-party privacy calculations and has low calculation efficiency. Without the help of outsourced servers or trusted third parties, users and multiple participants perform multi-party privacy calculations through interaction.

[0005] The technical solution adopted by the present invention to solve the above problems is:

[0006] A multi-party matrix multiplication calculation method with privacy protection attributes is applied to a data interaction system for privacy computing. The data interaction system includes a user with a matrix A composed of plaintext data. n have a matrix B consisting of plaintext data (i) Participants user With n participants When interacting, the user can Get the element information of the data matrix AB; where n ≥ 1 and n is an integer, i represents the participant number, i∈{1,2,...,n}, matrix A is d rows and e columns, and matrix B (i) It is row e and column f.

[0007] As a preferred technical solution, users With n participants When interacting, homomorphic encryption and the introduction of blinding factors are used to avoid leaking data matrices A and B. (i) In the case of element information, the user obtains the plain text result of the data matrix AB; comprising the following steps:

[0008] S1, system initialization: the user selects an encryption algorithm that supports additive homomorphism and publishes the algorithm parameters. Each participant generates a set of blinded parameters and publishes them.

[0009] S2, user matrix element processing: the user maps the data A into an e-dimensional row vector a and encrypts it to obtain the ciphertext It means that for each element {a1,a2,…a e}The ciphertext vector encrypted using the homomorphic encryption algorithm selected in S1, represents the ciphertext of a1 after encryption using the homomorphic encryption algorithm selected in S1, that is,

[0010] S3, privacy-preserving matrix multiplication: Participants calculate new ciphertext and the blinding factor η i , and Sent to the user, where express

[0011] S4, matrix multiplication result acquisition: the user aggregates the data sent by all participants to obtain After decryption, AB is obtained.

[0012] As a preferred technical solution, step S1 includes the following steps:

[0013] S11, User Select an encryption algorithm that supports additive homomorphism and publish a finite cyclic group and The group generator g of

[0014] S12, each participant In the group A set of blinding parameters is randomly generated and published.

[0015] As a preferred technical solution, step S2 includes the following steps:

[0016] S21, User Use the Chinese remainder theorem to map all elements in each column of matrix A into an element value to obtain the row vector a;

[0017] S22, User Encrypt each element in the row vector a to obtain the ciphertext

[0018] As a preferred technical solution, step S3 includes the following steps:

[0019] S31, User send For each participant

[0020] S32, Participant According to the matrix multiplication rules and the homomorphic properties of the encryption system, use the matrix B (i) The elements and Calculate to get new ciphertext

[0021] S33, Participant Calculate a set of blinding factors η based on the published blinding parameters i , where η i The number of elements in is consistent with the dimension of vector a;

[0022] S34, Participant calculate Send the results to the user

[0023] As a preferred technical solution, step S4 includes the following steps:

[0024] S41, User By collecting data sent by all participants, the data is aggregated and obtained

[0025] S42, Decryption And use the Chinese Remainder Theorem to map aB to AB.

[0026] As a preferred technical solution, it is characterized by:

[0027] In step S11, the additive homomorphic encryption algorithm has the following homomorphic properties: Among them, a represents plain text, Indicates the encrypted ciphertext of a;

[0028] In step S12, each participant Random Selection Then announce in, Represents a random number, Represents the blinding parameter for random number generation.

[0029] As a preferred technical solution:

[0030] In step S21, the user Select the Chinese remainder theorem parameters and replace the matrix elements {a rk}Map to data M by column k , encode the matrix A into a row vector a=(M1,M2,...,M e ), where r = {1, 2, ..., d}, k = {1, 2, ..., e};

[0031] In step S22, the user Use encryption algorithm to encrypt data (M1, M2, ..., M e ) are encrypted respectively to obtain the ciphertext

[0032] As a preferred technical solution:

[0033] In step S32, each participant Received Then, use its own matrix Elements in Calculate in sequence and get The calculation formula is:

[0034]

[0035]

[0036] In step S33, a blinding factor is generated based on a two-round anonymous voting protocol, and the blinding factor is calculated according to the blinding parameter Each participant Calculate the blinding factor in, represents the updated blinding parameter, then Eq. Heng established;

[0037] In step S34, the participants The calculation formula for blinding the new ciphertext using the blinding factor is:

[0038] As a preferred technical solution:

[0039] In step S41, the user Calculated based on the properties of the blinding technique and homomorphic encryption system: where j = {1, 2, ..., f};

[0040] In step S42, the user Use the decryption algorithm to obtain

[0041] According to the Chinese remainder theorem parameters in step S21, Mapping to {c 1j ,c 2j ,...,c dj}, j = {1, 2, ..., f}), thereby obtaining the plaintext data C; wherein C = AB is a matrix with d rows and f columns.

[0042] Compared with the prior art, the present invention has the following beneficial effects:

[0043] The present invention realizes the calculation of matrix multiplication while ensuring that the matrix element information of users and participants is not leaked, without the need for outsourcing servers or trusted third parties. In addition, in the implementation process, efficient use of plaintext space is achieved through Chinese remainder theorem mapping, thereby improving calculation efficiency and having high practicality. BRIEF DESCRIPTION OF THE DRAWINGS

[0044] Figure 1 It is a schematic diagram of the steps of the present invention;

[0045] Figure 2 It is a flow chart of the present invention. DETAILED DESCRIPTION

[0046] In order to facilitate those skilled in the art to understand and implement the present invention, the present invention is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the implementation examples described herein are only used to illustrate and explain the present invention and are not used to limit the present invention.

[0047] Example 1

[0048] The present invention is a multi-party matrix multiplication calculation method that is efficient and has privacy protection properties, combining a homomorphic encryption algorithm and an anonymous voting protocol in view of the characteristics of matrices and the need for data privacy protection.

[0049] like Figure 1 , Figure 2 As shown, an efficient and privacy-preserving multi-party matrix multiplication calculation method is characterized in that: the method includes a user with a d×e matrix A has an e×f matrix B (i) Participants The user With n participants Interaction, without leaking matrix element information Get the plaintext result of matrix AB, where The following steps are involved:

[0050] S1: System initialization;

[0051] S2: user matrix element processing;

[0052] S3: privacy-preserving matrix multiplication calculation;

[0053] S4: Obtain the matrix multiplication result.

[0054] Preferably, the specific implementation of step S1 includes the following sub-steps:

[0055] S11: User Choose an encryption system that supports additive homomorphism, and exposes cyclic groups and group generators.

[0056] S12: Each participant A set of blinding parameters is randomly generated and published.

[0057] Preferably, the specific implementation of step S2 includes the following sub-steps:

[0058] S21: User Use the Chinese remainder theorem to map all elements in each column of matrix A into an element value to obtain an e-dimensional row vector a.

[0059] S22: User Encrypts every element in row vector a. Represents the ciphertext vector after encrypting each element in vector a, that is,

[0060] Preferably, the specific implementation of step S3 includes the following sub-steps:

[0061] S31: User send For each participant

[0062] S32: Participants According to the matrix multiplication rules and the homomorphic properties of the encryption system, use the matrix B (i) The elements and Calculate to get new ciphertext

[0063] S33: Participants Calculate a set of blinding factors η based on the public blinding parameters i , η i The number of elements in is consistent with the dimension of vector a;

[0064] S34: Participants calculate Send the results to the user express

[0065] Preferably, the specific implementation of step S4 includes the following sub-steps:

[0066] S41: User By collecting data from all participants and performing aggregation operations on the data

[0067] S42: Decryption And use the Chinese Remainder Theorem to map aB to AB.

[0068] Example 2

[0069] like Figure 1 , Figure 2 As shown, as a further optimization of Example 1, this embodiment also includes the following technical features:

[0070] The present invention provides an efficient multi-party matrix multiplication calculation method with privacy protection attributes, wherein the method includes a user having a d×e matrix A has an e×f matrix B (i) Participants Where i = {1, 2, ..., n}. The user With n participants Interaction, without leaking matrix element information Get the plaintext result of matrix AB,

[0071] Please see Figure 1 The present invention provides an efficient multi-party matrix multiplication calculation method with privacy protection attributes, which includes four parts: system initialization, user matrix element processing, privacy-preserving matrix multiplication calculation, and matrix multiplication result acquisition.

[0072] System initialization consists of the following two parts:

[0073] Step 1.1: User Select to support additive homomorphic encryption algorithm and public cyclic group and group generator g. User Arbitrarily select an additive homomorphic encryption algorithm (such as the Paillier algorithm, the BGN algorithm, etc.) and determine the plaintext space of the encryption algorithm Represents a set of non-negative integers less than N. The encryption system must have the following homomorphic properties: represents the encrypted ciphertext of a. The finite cyclic group used by the encryption system The group generator g is made public to the participants. For negative number encryption, the plaintext space {0,1,...,N-1} of the encryption function needs to be divided into three parts: 0; {1,2,...,(N-1) / 2} represents positive integers; {(N-1) / 2,(N-1) / 2+1,...,N-1} represents negative integers. If the decryption obtains a data m∈{0,1,2,...,(N-1) / 2}, then the decryption result is m itself. If m∈{(N-1) / 2,(N-1) / 2+1,...,N-1}, then the decryption result needs to be mapped to m=mN.

[0074] Step 1.2: Each participant A set of blinding parameters is randomly generated and announced. If there is only one participant, this section can be omitted. Each participant In the group Randomly select f elements from Then publish the blinding parameters

[0075] The specific implementation of user matrix element processing includes the following sub-steps:

[0076] Step 2.1: User Use the Chinese remainder theorem to map all elements in each column of the matrix A into an element value to obtain the row vector a. Since encryption systems generally only encrypt and decrypt integers and have a fixed plaintext space, the matrix elements are assumed to be integers. If the data to be encrypted contains decimals, it can be mapped to integer space before the scheme starts, and then inversely mapped back to the original space after the scheme ends. In addition, the value range of the matrix elements needs to be determined, which can be known in advance or determined before the operation is performed. User Select d random numbers u j , satisfying a jk ∈{-u j ,1-u j ,...,u j}, where j = {1,2,...,d}, k = {1,2,...,e}. Participants Negotiate a random number v and publish it, satisfying When selecting a value, you can keep it consistent with the maximum element or choose a value larger than the maximum element. In order to improve the efficiency of the algorithm, you should try to select a value close to the maximum element.

[0077] user Use the Chinese remainder theorem to convert the matrix elements {a ji}Map to data M by column i , encode the matrix A into a row vector a=(M1,M2,...,M e ). The kth element M of the row vector ak = ∑ j=1 a jk H j T j (mod h), k = {1, 2, ..., e}, where h represents the product of d pairwise relatively prime positive integers, i.e., h = h1h2...h d , {h1, h2, ..., h d} are pairwise relatively prime, and the value range of h j is h j > e·2u j ·2v, and h needs to satisfy h·2v·e·n < N - 1; H j represents the product of d - 1 pairwise relatively prime positive integers except h j , i.e., T j represents the inverse of H j modulo h j , i.e., H j T j ≡ 1 (mod h j ), j = {1, 2, ..., d}; According to the Chinese Remainder Theorem, by calculating M k (mod h j ) the single data a jjk can be recovered. When the matrix is large, due to the limitation of h·2v·e·n < N - 1, it may be necessary to package it into multiple data. Here, multiple data are still abstractly regarded as one, and the processing method is the same.

[0078] Step 2.2: The user encrypts each element in the row vector a. The user uses the encryption algorithm of the encryption system to encrypt the data (M1, M2, ..., M e ) respectively to obtain ciphertext

[0079] The specific implementation of privacy - protected matrix multiplication includes the following sub - steps:

[0080] Step 3.1: The user sends to each participant

[0081] Step 3.2: The participant according to the matrix multiplication rule and the additive homomorphism property of the encryption system, uses the elements of matrix B (i) and to calculate to obtain a new ciphertext After each participant receives and uses the held matrix Elements in Calculate in sequence and get According to the homomorphism of encryption technology,

[0082]

[0083] Step 3.3: Participants Calculate a set of blinding factors η based on the public blinding parameters i The blinding factor is generated based on a two-round anonymous voting protocol and is calculated based on the blinding parameters in the initialization phase. Each participant Calculate the blinding factor All participants The product of the j-th blinding factor is 1, that is,

[0084] Step 3.4: Participants calculate Send the results to the user Each participant calculate And send it to the user

[0085] The specific implementation of matrix multiplication result acquisition includes the following sub-steps:

[0086] Step 4.1: User By collecting data from all participants and performing aggregation operations on the data user Calculated based on the properties of the blinding technique and encryption system

[0087] Step 4.2: Decryption And use the Chinese remainder theorem to map aB to AB. User Use the decryption algorithm to obtain According to the properties of the Chinese remainder theorem, we can calculate A d×f matrix C can be obtained.

[0088] As described above, the present invention can be preferably implemented.

[0089] All features disclosed in all embodiments in this specification, or steps in all methods or processes implicitly disclosed, except for mutually exclusive features and / or steps, can be combined and / or expanded or replaced in any manner.

[0090] The above description is only a preferred embodiment of the present invention and does not limit the present invention in any form. According to the technical essence of the present invention, within the spirit and principles of the present invention, any simple modification, equivalent replacement and improvement made to the above embodiment still falls within the protection scope of the technical solution of the present invention.

Claims

1. A multi-party matrix multiplication calculation method with privacy protection attributes, characterized in that: The data interaction system applied to privacy computing includes a user with a matrix A composed of plaintext data. n have a matrix B consisting of plaintext data (i) Participants user With n participants When interacting, the user can Get the element information of the data matrix AB; where n ≥ 1 and n is an integer, i represents the participant number, i∈{1,2,...,n}, matrix A is d rows and e columns, and matrix B (i) It is row e and column f. user With n participants When interacting, homomorphic encryption and blinding factors are used to avoid leaking data matrices A and B. (i) In the case of element information, the user obtains the plain text result of the data matrix AB; including the following steps: S1, system initialization: the user selects an encryption algorithm that supports additive homomorphism and publishes the algorithm parameters. Each participant generates a set of blinded parameters and publishes them. S2, user matrix element processing: the user maps the data A into an e-dimensional row vector a and encrypts it to obtain the ciphertext It means that for each element {a1,a2,…a e }The ciphertext vector encrypted using the homomorphic encryption algorithm selected in S1, represents the ciphertext of a1 after encryption using the homomorphic encryption algorithm selected in S1, that is, S3, privacy-preserving matrix multiplication: Participants calculate new ciphertext and the blinding factor η i , and Sent to the user, where express S4, matrix multiplication result acquisition: the user aggregates the data sent by all participants to obtain After decryption, AB is obtained; Step S2 includes the following steps: S21, User Use the Chinese remainder theorem to map all elements in each column of matrix A into an element value to obtain the row vector a; S22, User Encrypt each element in the row vector a to obtain the ciphertext Step S4 includes the following steps: S41, User By collecting data sent by all participants, the data is aggregated and obtained S42, Decryption And use the Chinese Remainder Theorem to map aB to AB.

2. A multi-party matrix multiplication calculation method with privacy protection attributes according to claim 1, characterized in that: Step S1 includes the following steps: S11, User Select an encryption algorithm that supports additive homomorphism and publish a finite cyclic group and The group generator g of S12, each participant In the group A set of blinding parameters is randomly generated and published.

3. The multi-party matrix multiplication calculation method with privacy protection attribute according to claim 2, characterized in that: Step S3 includes the following steps: S31, User send For each participant S32, Participant According to the matrix multiplication rules and the homomorphic properties of the encryption system, use the matrix B (i) The elements and Calculate to get new ciphertext S33, Participant Calculate a set of blinding factors η based on the published blinding parameters i , where η i The number of elements in is consistent with the dimension of vector a; S34, Participant calculate Send the results to the user 4. The method for multi-party matrix multiplication with privacy protection attribute according to claim 3, characterized in that: In step S11, the additive homomorphic encryption algorithm has the following homomorphic properties: Among them, a represents plain text, Indicates the encrypted ciphertext of a; In step S12, each participant Random Selection Then announce in, Represents a random number, Represents the blinding parameter for random number generation.

5. The method for multi-party matrix multiplication with privacy protection attribute according to claim 4, characterized in that: In step S21, the user Select the Chinese remainder theorem parameters and replace the matrix elements {a rk }Map to data M by column k , encode the matrix A into a row vector a=(M1,M2,...,M e ), where r = {1, 2, ..., d}, k = {1, 2, ..., e}; In step S22, the user Use encryption algorithm to encrypt data (M1, M2, ..., M e ) are encrypted respectively to obtain the ciphertext 6. The method for multi-party matrix multiplication with privacy protection properties according to claim 5, characterized in that: In step S32, each participant Received Then, use its own matrix Elements in Calculate in sequence and get The calculation formula is: In step S33, a blinding factor is generated based on a two-round anonymous voting protocol, and the blinding factor is calculated according to the blinding parameter Each participant Calculate the blinding factor in, represents the updated blinding parameter, then Eq. Heng established; In step S34, the participants The calculation formula for blinding the new ciphertext using the blinding factor is:

7. The method for multi-party matrix multiplication with privacy protection properties according to claim 6, characterized in that: In step S41, the user Calculated based on the properties of the blinding technique and homomorphic encryption system: where j = {1, 2, ..., f}; In step S42, the user Use the decryption algorithm to obtain According to the Chinese remainder theorem parameters in step S21, Mapping to {c 1j ,c 2j ,...,c dj }, j = {1, 2, ..., f}, thereby obtaining the plaintext data C; wherein C = AB is a matrix with d rows and f columns.

Citation Information

Patent Citations

  • Homomorphism-based cloud-assisted dynamic universal secure multi-party computing method

    CN110266721A

  • Factorization machine model construction method and equipment and readable storage medium

    CN112016698A