Secure multi-party computation method and apparatus
By processing data in parallel through data fragmentation and rotating MPC roles in secure multi-party computation, the problem of high network transmission consumption is solved, achieving efficient resource utilization and improving computational efficiency.
Patent Information
- Application Number
- CN202211674733.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-26
- Publication Date
- 2025-11-07
- Estimated Expiration
- 2042-12-26
AI Technical Summary
In secure multi-party computation, network transmission consumption is one of the main bottlenecks, leading to insufficient utilization of network and computing resources.
By dividing data into multiple groups and performing computational processing in parallel with other participants, participants take turns playing the role of MPC to perform different computation and transmission tasks, thus optimizing resource utilization.
It improves the utilization of network and computing resources, balances the use of network bandwidth, and enhances the efficiency of secure multi-party computation.
Smart Images

Figure CN115904726B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] One or more embodiments of the present specification relate to the technical field of secure multi-party computation, and in particular to a secure multi-party computation method and device. BACKGROUND
[0002] Privacy computing is a major supporting technology in the data security era, which can provide the ability of "calculable but invisible" and "data not moving value moving".
[0003] Secure multi-party computation (mpc) is an important technology in privacy computing, which means that multiple participants jointly compute a result based on cryptographic protocols, and do not disclose any data information to other participants.
[0004] In secure multi-party computation, a large number of interactions will occur between multiple participants, and network transmission consumption is one of the main bottlenecks. SUMMARY
[0005] One or more embodiments of the present specification describe a secure multi-party computation method and device, which can effectively improve the utilization of network resources and computing resources.
[0006] In a first aspect, a secure multi-party computation method is provided, which is used for performing at least one target processing on a batch of data; each data in the batch of data is distributed in the form of a shard among n participants; the method is executed by any first participant in the n participants, and includes:
[0007] Dividing the local shard of each data in the batch of data into m groups, and corresponding to allocate m threads; using the m threads, performing each target processing in combination with other participants on the m groups in parallel, wherein the first participant assumes different secure multi-party computation (mpc) roles in at least part of the m groups of threads, and the different mpc roles perform different target computations and / or target transmissions for the one target processing.
[0008] In a possible implementation, the using the m threads to perform the one target processing in combination with other participants on the m groups in parallel includes:
[0009] Using the i th thread, based on the local shard of the first group allocated to the i th thread, in combination with other threads of other participants allocated to other shards of the first group, performing first computation and first transmission corresponding to the first role assumed by the first participant in the i th thread, to realize the one target processing for the first group.
[0010] In a possible implementation, the one target processing is a truncation processing, and the different mpc roles include a computing party and a receiving party.
[0011] In a possible implementation, the first group includes first data, and the first role is the computing party.
[0012] The first computing includes: generating a first random number in an agreed value range; dividing the first random number by 2 raised to the power of t to obtain a first quotient; and determining, based at least on the first quotient, a first shard of a truncation processing result of the first data; t is a truncation bit number.
[0013] The first transmission includes: sending, to a second participant acting as the receiving party, a difference value between the first shard of the first data and the first random number, so that the second participant determines a second shard of the truncation processing result based at least on the difference value, the truncation bit number, and a second shard of the first data held by the second participant.
[0014] In a possible implementation, the first group includes first data, and the first role is the receiving party.
[0015] The first transmission includes: receiving, from a second participant acting as the computing party, a difference value obtained by subtracting a first random number from a second shard of the first data held by the second participant;
[0016] The first computing includes: summing the difference value and the first shard of the first data, and dividing a sum result by 2 raised to the power of t to obtain a second quotient; and determining, based on the second quotient, the first shard of the truncation processing result.
[0017] In a possible implementation, the at least one target processing includes: oblivious transfer (OT), logic-to-digital conversion, digital-to-logic conversion, digital multiplication by logic, ciphertext selection, and out-of-order.
[0018] In a possible implementation, the dividing, into m groups, of the local shard of each data in the batch of data includes:
[0019] The local shard of each data in the batch of data is equally divided into m groups.
[0020] In a possible implementation, for the same data in the batch of data, the number of shards held by each of the n participants is the same.
[0021] In a possible implementation, the batch of data is unevenly distributed among the n participants, and the mpc role assumed by each of the n participants is determined based on the data currently held by the participant.
[0022] In a possible implementation, the m groups include a first group, and the one target processing for the first group is performed by p participants including the first participant, where p < n.
[0023] In a possible implementation, the m groups of threads each include a different number of threads.
[0024] In a possible implementation, the n participants each run a different number of threads.
[0025] In a second aspect, a secure multi-party computation apparatus is provided, configured to perform at least one target processing on a batch of data, each data in the batch of data being distributed in the form of a shard among n participants, and the apparatus being arranged at any first participant among the n participants, and including:
[0026] A division unit, configured to divide a local shard of each data in the batch of data into m groups, and assign the m groups to m threads respectively;
[0027] An execution unit, configured to perform, by using the m threads, the one target processing in parallel on the m groups in cooperation with other participants, wherein the first participant assumes different secure multi-party computation (mpc) roles in at least some groups of the m threads, and the different mpc roles perform different target computations and / or target transmissions for the one target processing.
[0028] In a possible implementation, the execution unit is specifically configured to:
[0029] perform, by using an i-th group of threads, a first computation and a first transmission corresponding to a first role assumed by the first participant in the i-th group of threads, in cooperation with other groups of threads of other participants that are assigned a first group of the first group, to implement the one target processing for the first group.
[0030] In a possible implementation, the one target processing is a truncation processing, and the different mpc roles include a computation party and a receiving party.
[0031] In a possible implementation, the first group includes first data, and the first role is the computation party, and the execution unit includes:
[0032] A first computation module, configured to generate a first random number within an agreed value range, divide the first random number by 2 raised to the power of t to obtain a first quotient, and determine a first shard of a truncation processing result of the first data based at least on the first quotient, where t is a truncation bit number.
[0033] The first transmission module is configured to send, to a second participant acting as the receiving party, a difference value between the first shard of the first data and the first random number, so that the second participant determines a second shard of the truncation processing result based on at least the difference value, the number of truncated bits, and a second shard of the first data held by the second participant.
[0034] In a possible implementation, the first group includes first data, and the first role is the receiving party; and the execution unit includes:
[0035] The second transmission module is configured to receive, from a second participant acting as the computing party, a difference value obtained by subtracting a second shard of the first data held by the second participant from the first random number;
[0036] The second calculation module is configured to sum the difference value and the first shard of the first data, and divide the sum by 2 raised to the power of t to obtain a second quotient value; and determine the first shard of the truncation processing result based on the second quotient value.
[0037] In a possible implementation, the at least one target processing includes: oblivious transfer (OT), conversion from a logic quantity to a digital quantity, conversion from a digital quantity to a logic quantity, multiplication of a digital quantity by a logic quantity, ciphertext selection, and out-of-order.
[0038] In a possible implementation, the division unit is specifically configured to:
[0039] The local shard of each data in the batch of data is equally divided into m groups.
[0040] In a possible implementation, the number of shards held by each of the n participants is the same for the same data in the batch of data.
[0041] In a possible implementation, the batch of data is unevenly distributed among the n participants, and the mpc role assumed by each of the n participants is determined based on the data currently held by the participant.
[0042] In a possible implementation, the m groups include a first group, and the target processing for the first group is performed by p participants including the first participant in the n participants, where p < n.
[0043] In a possible implementation, the m groups of threads include different numbers of threads.
[0044] In a third aspect, a computer readable storage medium is provided, having stored thereon a computer program which, when executed in a computer, causes the computer to perform the method of the first or second aspect.
[0045] In a fourth aspect, a computing device is provided, comprising a memory having stored therein executable code and a processor which, when executing the executable code, implements the method of the first or second aspect.
[0046] The secure multi-party computation method and device provided by one or more embodiments of the present specification can rotate the mpc roles of each participant in the process of performing a target processing on a batch of data. Since the calculation amount or transmission amount of different mpc roles is different in most cases of secure multi-party computation, in the present scheme, the mpc roles of each participant can be switched, so that the resources (including network resources and computing resources) of each participant can be effectively utilized. BRIEF DESCRIPTION OF DRAWINGS
[0047] In order to more clearly illustrate the technical solutions of the embodiments of the present specification, the drawings needed in the embodiment description will be briefly introduced as follows. Obviously, the drawings in the following description are only some embodiments of the present specification, and other drawings can be obtained by those skilled in the art without creative labor on the basis of these drawings.
[0048] Figure 1 An implementation scenario diagram of an embodiment disclosed in the present specification is shown.
[0049] Figure 2 A secure multi-party computation method flowchart according to an embodiment is shown.
[0050] Figure 3 A data truncation processing method diagram is shown.
[0051] Figure 4 A secure multi-party computation device diagram according to an embodiment is shown. DETAILED DESCRIPTION
[0052] The schemes provided by the present specification will be described below in conjunction with the drawings.
[0053] Figure 1 An implementation scenario diagram of an embodiment disclosed in the present specification is shown. Figure 1 In the embodiment, n participants jointly perform at least one target processing on a batch of data. Each participant can be implemented as any device, platform, server or device cluster with computing and processing capabilities.
[0054] The at least one target processing includes several items of cut-off processing, oblivious transfer (OT), logic-to-digital conversion, digital-to-logic conversion, digital-to-logic multiplication, ciphertext selection, and out-of-order.
[0055] Each data d[i] in the batch of data is distributed in the form of a shard among the n participants, where i is a positive integer, and 1≤i≤N, N is the total number of the batch of data. For example, participant 1 holds shards: <d[1]>1, <d[2]>1, …, participant 2 holds shards: <d[1]>2, <d[2]>2, …, and participant n holds shards: <d[1]>n, <d[2]>n, …. n n …
[0056] Specifically, each participant can run m groups of threads: thread group 1-thread group m locally to perform the target processing on the batch of data, and each participant can assume different secure multi-party computation (mpc) roles in at least some of the m groups of threads it runs. For example, participant 1 assumes mpc role 1 in thread group 2, participant 2 assumes mpc role n in thread group 2, and participant n assumes mpc role 2 in thread group 2, and then the participants can jointly perform a target processing on a group of data d[i], …, d[x] using thread group 2 they run, where x is a positive integer, and 1≤x≤N.
[0057] It should be understood that the thread group numbers (such as 1 and 2, etc.) are only used to distinguish thread groups that process different shard groups. For example, thread group 1 run by participant 1 and thread group 1 run by participant 2 refer to thread groups used by the two participants to process the same shard group, rather than referring to the same thread group run by participant 1 and participant 2.
[0058] In addition, each participant can hold only one shard for each data in the batch of data, or can hold two or more shards, such as participant 1 can also hold shards: <d[1]>1, <d[1]>2, <d[2]>1, <d[2]>2, …, as long as it can support the rotation of mpc roles by the participants, which is not limited in the present specification.
[0059] It should be noted that in actual applications, a target processing on each group of the m groups can also be performed by p participants out of the n participants, where p
[0060] Finally, it should be noted that the number of threads run by each of the n participants can be different. That is, the total number of threads in the m groups of threads run by each of the n participants is different.
[0061] Figure 2 A flowchart of a secure multi-party computation method according to an embodiment is shown. The method can be performed by any device, apparatus, platform, cluster of devices having computing, processing capabilities. As such, the method can be performed by a secure multi-party computation system 1000 as shown in FIG. 10. Figure 1 The method can be performed by any of the n participants. As shown, the method can include the following steps: Figure 2 The method can include the following steps:
[0062] At step S202, the local shards of each data in the batch of data are divided into m groups and are assigned to m threads respectively.
[0063] It should be noted that each data in the batch of data is distributed in the form of shards among the n participants. In one example, the number of shards held by each of the n participants for the same data in the batch of data is the same. That is, the batch of data is equally distributed among the n participants.
[0064] For example, participant 1 holds shards: <d[1]>1, <d[2]>1, …, participant 2 holds shards: <d[1]>2, <d[2]>2, …, and participant n holds shards: [<d[1] n , <d[2]> n …].
[0065] For another example, participant 1 holds shards: <d[1]>1, <d[1]>2, <d[2]>1, <d[2]>2, …, participant 2 holds shards: <d[1]>2, <d[1]>3, <d[2]>2, <d[2]>3, …
[0066] In another example, the batch of data can also be unequally distributed among the n participants, such that the mpc role assumed by each of the n participants is determined based on the data currently held by each of the n participants.
[0067] Step S202 can specifically be to divide the local shards of each data in the batch of data equally into m groups, such that the m groups are also referred to as m shard groups.
[0068] For example, assume that the batch of data is represented as: d[1], d[2], d[3], …, d[N], where N is the total number of the batch of data. Then the m groups obtained by equal division can be represented as: d[1], …, d[N / m], d[(N / m)+1], …, d[2N / m], …, d[N(m-1) / m], …, d[N].
[0069] It should be understood that, since each participant only holds a data shard, each participant actually divides the group by the local shard of each data in the batch, and each of the m groups obtained includes the local shard of each data.
[0070] In addition, the number of threads included in each of the m groups of threads can be different.
[0071] Step S204, using m groups of threads, performing each target processing jointly with other participants on m groups in parallel.
[0072] The target processing here can include any of the following: truncation processing (also known as right shift processing), oblivious transfer (OT), and logical quantity to digital quantity conversion, etc.
[0073] The above target processing includes several of the following: truncation processing, oblivious transfer OT, logical quantity to digital quantity conversion, digital quantity to logical quantity conversion, digital quantity multiplication by logical quantity, ciphertext selection, and out-of-order.
[0074] Among them, the first participant plays different secure multi-party computation (mpc) roles in at least some of the m groups of threads, and different mpc roles perform different target calculations and / or target transmissions for a target processing.
[0075] Taking a target processing as an example, step S204 is specifically, using the ith group of threads, based on the local shard of the first group assigned to the ith group of threads, jointly performing, with other groups of threads in other participants assigned other shards of the first group, a first calculation and a first transmission corresponding to a first role played by the first participant in the ith group of threads, to realize a target processing for the first group. Wherein, 1≤i≤m.
[0076] It should be understood that, since the target processing process for each data in the same group is similar, the following will be described taking a target processing for a certain data as an example. In addition, it should be understood that the processing process of each thread group for the assigned shard group is also similar.
[0077] Taking the first participant as Figure 1 Taking participant 1 in the above as an example, the ith group of threads can be thread group 1 running on participant 1, and the other group of threads can be thread group 1 running on participants 2 to n, that is, the ith group of threads and the other group of threads are used to jointly perform a target processing on the same shard group.
[0078] Taking the target processing as truncation processing as an example, the mpc roles can include a calculating party and a receiving party.
[0079] When the first participant acts as the computing party, i.e., when the first role is the computing party, the first computation can include:
[0080] For any first data in the first group, the first participant generates a first random number within a predetermined value range. The first random number is divided by 2 raised to the power of t to obtain a first quotient. At least based on the first quotient, a first slice of the truncation result of the first data is determined, and t is the number of truncation bits.
[0081] In one example, the predetermined value range can be, for example, [2 -63 , 2 63 ], and the first random number can be represented as r', and the first quotient can be represented as r' / 2 t .
[0082] In one example, the first participant can take the difference between the first quotient and a predetermined random number r0 as a first slice of the truncation result of the first data, and take the predetermined random number as another first slice.
[0083] In addition, the first transmission can include sending the difference between the first slice of the first data and the first random number to the second participant acting as the receiving party, so that the second participant determines a second slice of the truncation result based on at least the received difference, the number of truncation bits, and the second slice of the first data held by the second participant.
[0084] For example, the second participant can sum the received difference and the second slice of the first data held by the second participant, and divide the sum by 2 raised to the power of t to obtain a second quotient. Then, the second quotient can be determined as a second slice of the truncation result held by the second participant, and the shared random number can be determined as another second slice.
[0085] Of course, in actual applications, the second participant can also receive the another second slice from the first participant, and the present specification will not be repeated here.
[0086] The above is a description of the first participant acting as the computing party, and the following describes the first participant acting as the receiving party.
[0087] When the first participant acts as the receiving party, i.e., when the first role is the receiving party, the first transmission can include:
[0088] Receiving, from the second participant acting as the computing party, a difference value obtained by the second participant from the difference between the second slice of the first data held by the second participant and the first random number.
[0089] The definition of the first random number can be referred to the description above, and the present specification will not be repeated here.
[0090] The first calculation mentioned above may include:
[0091] The received difference is summed with the first fragment of the first data held by the first participant, and the sum is divided by 2 to the power of t to obtain the second quotient. Based on the second quotient, the first fragment of the truncation processing result held by the first participant is determined.
[0092] In one example, the first participant can use the calculated second quotient as a first slice of the truncated processing result held by the first participant, and the shared random number as another first slice.
[0093] Of course, in practical applications, the first participant may also receive another first fragment from the second participant, which will not be elaborated on in this specification.
[0094] The following examples illustrate the secure computing method provided in this solution.
[0095] Figure 3 This diagram illustrates a data truncation process. Figure 3 In this scenario, three parties, A, B, and C, jointly perform truncation processing on data x. The data x is split into three shards: x0, x1, and x2. Party A holds shards x0 and x1, Party B holds shards x1 and x2, and Party C holds shards x0 and x2.
[0096] Figure 3 In this process, C acts as the calculator, while A and B act as the receivers. Specifically, C can perform the following calculation: generate first random numbers r′ and r1, where r′∈[2]. -63 ,2 63 In addition, a shared random number r0 with party A can be generated. Then, the second random number r2 = (r′ / 2) is calculated. t )-r0-r1. After that, C can use r0 as a fragment z0 of the truncated result z of the data x held by C, and use the sum of r1 and r2 as another fragment z2 of z.
[0097] In addition to the calculations mentioned above, C can also perform the following transmissions:
[0098] The difference between the data x fragment x2 and the first random number r′, x2-r′, is sent to party A. Party A then uses its shared random number r0 with party C as a fragment z0 of its data z. Furthermore, party A can sum the received difference x2-r′ with its data x fragments x0 and x1, and divide the sum by 2 to the power of t to obtain the quotient: (x2-r′+x0+x1) / 2. t As another fragment z1 of z it holds.
[0099] and the difference between the shard x0 of the data x and the first random number r': x0-r' is sent to the B party, in addition, the shard z2 can also be sent to the B party, so that the B party can take the received shard z2 as one shard z2 of the z held by the B party, in addition, the B party can also sum the received difference x2-r' and the shards x1 and x2 of the data x held by the B party, and divide the sum by 2 raised to the power of t to obtain the quotient: (x0-r'+x1+x2) / 2 t another shard z1 of the z held by the B party.
[0100] As can be seen from the above example, no data is transmitted between the A party and the B party, data transmission is performed between the A party and the C party and between the B party and the C party, and the amount of data transmitted between the B party and the C party is relatively large, so that in the process of the above-mentioned secure multi-party computation, a part of the network bandwidth is occupied, and the other part is not fully utilized.
[0101] In order to balance the network resources, the roles of the parties can be rotated in other groups of threads running in parallel with the thread group processing the data x, for example, in the thread group processing the data y, the A party can be switched to the role of the C party, so that the A party performs the calculation and transmission of the C party.
[0102] It should be understood that in a plurality of parallel running thread groups, the A party, the B party and the C party can effectively utilize the network resources between two of the three parties by rotating the mpc roles, so as to greatly improve the utilization rate of the network resources.
[0103] The above is a description of three parties, in actual application, for the case of two parties, there is also a problem of effectively utilizing the 5 bidirectional bandwidth, so that the switching of the mpc role of the present solution can also be used for reference.
[0104] In addition, the switching of the mpc role of the present solution can also improve the utilization rate of the computing resources.
[0105] In summary, in the present solution, the network resources and computing resources of each party can be effectively utilized by switching the mpc role of each party.
[0106] Corresponding to the above-mentioned secure multi-party computation method, an embodiment of the present specification also provides a secure multi-party computation device for performing at least one target processing on a batch of data, each data in the batch of data is in a shard form,
[0107] distributed in n parties, the device is arranged in any first party of the n parties. As shown in the figure, the device can include: Figure 4
[0108] The division unit 402 is configured to divide the local shard of each data in the batch of data into m groups and assign the m groups of threads correspondingly.
[0109] In some embodiments, the m groups of threads each contain a different number of threads.
[0110] In some embodiments, the batch of data is unevenly distributed among the n participants, and the mpc role assumed by each of the n participants is determined based on the data currently held by the participant.
[0111] In some embodiments, the number of shards held by each of the n participants is the same for the same data in the batch of data.
[0112] The division unit 402 is specifically configured to:
[0113] divide the local shard of each data in the batch of data into m groups.
[0114] The execution unit 404 is configured to perform, by using the m groups of threads, m target processes in parallel on the m groups, wherein the first participant assumes different mpc roles in at least some of the m groups of threads, and the different mpc roles perform different target computations and / or target transmissions for a target process.
[0115] The execution unit 404 is specifically configured to: by using the ith group of threads, based on the local shard of the first group assigned to the ith group of threads, jointly perform, with other groups of threads assigned to other shards of the first group among the other participants, a first computation and a first transmission corresponding to a first role assumed by the first participant in the ith group of threads, to implement a target process for the first group.
[0116] The execution unit 404 is specifically configured to: by using the ith group of threads, based on the local shard of the first group assigned to the ith group of threads, jointly perform, with other groups of threads assigned to other shards of the first group among the other participants, a first computation and a first transmission corresponding to a first role assumed by the first participant in the ith group of threads, to implement a target process for the first group.
[0117] In some embodiments, the at least one target process includes several of the following: oblivious transfer (OT), conversion of a logical quantity to a digital quantity, conversion of a digital quantity to a logical quantity, multiplication of a digital quantity by a logical quantity, ciphertext selection, and out-of-order.
[0118] In some other embodiments, the target process is a truncation process, and the different mpc roles include a computing party and a receiving party.
[0119] In some embodiments, the first group includes first data, the first role is a computing party, and the execution unit 404 includes:
[0120] The first computation module 4042 is configured to generate a first random number within a predetermined value range, divide the first random number by 2 raised to the power of t to obtain a first quotient, and determine a first shard of a truncation result of the first data based on at least the first quotient; t is a truncation bit number.
[0121] The first transmission module 4044 is configured to send, to the second participant acting as a receiver, a difference value between the first fragment of the first data and the first random number, so that the second participant determines a second fragment of the truncation processing result based on at least the difference value, the number of truncated bits, and the second fragment of the first data held by the second participant.
[0122] In some embodiments, the first group includes the first data, the first role is the receiver, and the execution unit 404 includes:
[0123] The second transmission module 4046 is configured to receive, from the second participant acting as a computing party, a difference value obtained by subtracting the first random number from the second fragment of the first data held by the second participant.
[0124] The second calculation module 4048 is configured to sum the received difference value and the first fragment of the first data, divide the sum result by 2 raised to the power of t to obtain a second quotient value, and determine the first fragment of the truncation processing result based on the second quotient value.
[0125] In some embodiments, the m groups include the first group, and an objective processing of the first group is performed by p participants including the first participant in the n participants, where p < n.
[0126] The functions of each functional module of the above-described embodiments of the apparatus can be realized by each step of the above-described method embodiments, and thus the specific working process of the apparatus provided by one embodiment of the present specification will not be described here.
[0127] The secure multi-party computing apparatus provided by one embodiment of the present specification can effectively improve the utilization rate of network resources and computing resources.
[0128] According to another aspect, embodiments also provide a computer-readable storage medium having stored thereon a computer program which, when executed in a computer, causes the computer to perform the method described in conjunction with Figure 2 or Figure 3 the described method.
[0129] According to still another aspect, embodiments also provide a computing device including a memory and a processor, the memory having stored thereon executable code that, when executed by the processor, facilitates performance of the method described in conjunction with Figure 2 or Figure 3 the described method.
[0130] Each of the embodiments described in this specification has at least one implementation, of which an example has been provided above. Thus, methods have been described in terms of specific embodiments. Other embodiments have been suggested, and still other embodiments will occur to those skilled in the art. The terms "device," "apparatus," and "method" are used only in their broadest, generic sense, and are not meant to be limiting as to a strictly mechanical or a strictly electrical device, or a strictly methodical process. In particular, the device embodiments are described relatively simply, since they are substantially similar to the method embodiments. Reference should be made to the method embodiments for relevant details.
[0131] In one embodiment, a processor (which word also includes CPUs, state machines, etc.) has circuitry among its hardware elements that enables it to read and write memory. Certain of the processor's functionality can be implemented in software and / or firmware (which is programmable
[0132] In one embodiment, a processor (which word also includes CPUs, state machines, etc.) has circuitry among its hardware elements that enables it to read and write memory. Certain of the processor's functionality can be implemented in software and / or firmware (which is programmable
[0133] In one embodiment, a processor (which word also includes CPUs, state machines, etc.) has circuitry among its hardware elements that enables it to read and write memory. Certain of the processor's functionality can be implemented in software and / or firmware (which is programmable
[0134] Those skilled in the art will realize that the basic techniques of the present application can be extended to provide numerous other possibilities.
[0135] The functions described can be implemented in hardware, software, firmware or any combination thereof. If implemented in software, the functions can be stored or transmitted over as one or more instructions or code on a computer-readable medium. Computer-readable media include both computer storage media and communication media including any medium that facilitates transfer of a computer program from one place to another. Storage media can be any available media that can be accessed by a general purpose or special purpose computer. By way of example, and not limitation, such computer-readable media can comprise RAM, ROM, EEPROM, CD-ROM or other optical disk storage, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to carry or store desired computer program code in the form of instructions or data structures and that can be accessed by a general-purpose or special-purpose computer, or a general-purpose or special-purpose processor.
[0136] In fact, it would be rare for the functions to be implemented in a single place or time, and the functions might be spread out over due time, and over due space, among multiple computers and multiple locations.
[0137] The foregoing description of specific embodiments will so fully reveal the general nature of the embodiments herein that others can modify various embodiments herein for various uses and / or conditions. Those skilled in the art will recognize, or be able to ascertain using no more than routine experimentation, many equivalents to the specific embodiments described herein. Therefore, it is intended that the scope of the embodiments herein be defined by the following claims whenever appropriately interpreted.
[0138] The above detailed description has further explained the purpose, technical scheme and beneficial effects of the present specification. It should be understood that the above description is only a specific embodiment of the present specification and is not intended to limit the present specification
[0139] The scope of protection of the present specification should include any modifications, equivalent replacements, improvements and the like made on the basis of the technical scheme of the present specification.
Claims
1. A secure multi-party computation method for performing at least one objective processing on a batch of data; wherein each piece of data in the batch of data is distributed unequally among n participants in a fragmented manner; The method is performed by any first participant in the n participants, comprising: dividing the local shard of each data in the batch of data into m groups and correspondingly assigning to m groups of threads; using the m groups of threads, performing each target processing in conjunction with other participants in parallel on the m groups, wherein, in a target processing, the first participant assumes different secure multi-party computation (MPC) roles in at least some groups of the m groups of threads, and the different MPC roles perform different target computations and / or target transmissions for a target processing; the MPC role assumed by the first participant in any group is determined based on the data currently held by the first participant.
2. The method of claim 1, wherein, The using the m groups of threads, performing each target processing in conjunction with other participants in parallel on the m groups, comprises: using the ith group of threads, based on the first group assigned to the ith group of threads and other groups of threads assigned to other shards of the first group of other participants, performing a first computation and a first transmission corresponding to the first role assumed by the first participant in the ith group of threads to achieve a target processing for the first group.
3. The method of claim 2, wherein, The target processing is truncation processing, and the different MPC roles include a computing party and a receiving party.
4. The method of claim 3, wherein, The first group includes first data, and the first role is the computing party; The first computation includes generating a first random number within an agreed value range; dividing the first random number by 2 raised to the power of t to obtain a first quotient value; determining a first shard of a truncation processing result of the first data based on at least the first quotient value; t is the number of truncation bits; The first transmission includes sending the difference between the first shard of the first data and the first random number to a second participant assuming the receiving party, so that the second participant determines a second shard of the truncation processing result based on at least the difference, the number of truncation bits, and a second shard of the first data held by the second participant.
5. The method of claim 3, wherein, The first group includes first data, and the first role is the receiving party; The first transmission includes receiving, from a second participant assuming the computing party, a difference value obtained by subtracting a second shard of the first data held by the second participant from a first random number; The first computation includes summing the difference value and the first shard of the first data, and dividing the sum by 2 raised to the power of t to obtain a second quotient value; determining the first shard of the truncation processing result based on the second quotient value.
6. The method of claim 1, wherein, The at least one target processing includes several items in oblivious transfer (OT), logic-to-digital conversion, digital-to-logic conversion, digital multiplication by logic, ciphertext selection, and out-of-order.
7. The method of claim 1, wherein, The dividing the local shard of each data in the batch of data into m groups, comprises: The m groups include a first group, and a target processing for the first group is performed by p participants including the first participant in the n participants, wherein p 8. The method of claim 1, wherein, 9. The method of claim 1, wherein, The m groups of threads each include different numbers of threads.
10. The method of claim 1, wherein, The n participants each run different numbers of threads.
11. A secure multi-party computation apparatus for performing at least one target process on a batch of data; each data in the batch of data is unevenly distributed in a form of a shard among n participants. The device is arranged at any first participant among the n participants, and includes: a dividing unit, configured to divide local shards of each data in the batch of data into m groups, and correspondingly allocate the m groups to m groups of threads; an executing unit, configured to perform, by using the m groups of threads, each target processing in cooperation with other participants, in parallel on the m groups; in one target processing, the first participant assumes different secure multi-party computation (mpc) roles in at least some groups of the m groups of threads, and the different mpc roles perform different target computations and / or target transmissions for one target processing; the mpc role assumed by the first participant in any group is determined based on data currently held by the first participant.
12. The apparatus of claim 11, wherein, The executing unit is specifically configured to: perform, by using an ith group of threads, a first computation and a first transmission corresponding to a first role assumed by the first participant in the ith group of threads, in cooperation with other groups of threads allocated with other shards of a first group allocated to the first participant, to implement one target processing for the first group.
13. The apparatus of claim 12, wherein, The one target processing is truncation processing, and the different mpc roles include a computation party and a receiving party.
14. The apparatus of claim 13, wherein, The first group includes first data, and the first role is the computation party; the executing unit includes: a first computation module, configured to generate a first random number in a predetermined value range, divide the first random number by 2 raised to the power of t to obtain a first quotient, and determine a first shard of a truncation processing result of the first data based on at least the first quotient; t is a truncation bit number; a first transmission module, configured to send a difference between the first shard of the first data and the first random number to a second participant assuming the receiving party, so that the second participant determines a second shard of the truncation processing result based on at least the difference, the truncation bit number, and a second shard of the first data held by the second participant.
15. The apparatus of claim 13, wherein, The first group includes first data, and the first role is the receiving party; the executing unit includes: a second transmission module, configured to receive, from a second participant assuming the computation party, a difference obtained by subtracting a first random number from a second shard of the first data held by the second participant; a second computation module, configured to sum the difference and a first shard of the first data, divide the sum by 2 raised to the power of t to obtain a second quotient, and determine the first shard of the truncation processing result based on the second quotient.
16. The apparatus of claim 11, wherein, The at least one target processing includes several items in oblivious transfer (OT), logic-to-digital conversion, digital-to-logic conversion, digital multiplication by logic, ciphertext selection, and out-of-order.
17. The apparatus of claim 11, wherein, The dividing unit is specifically configured to: divide local shards of each data in the batch of data into m groups equally.
18. The apparatus of claim 11, wherein, The m groups include a first group, and an objective process for the first group is performed by p participants including the first participant among the n participants, where p < n.
19. The apparatus of claim 11, wherein, The m groups of threads each include a different number of threads.
20. A computer readable storage medium having stored thereon a computer program, wherein, The computer program is configured to cause the computer to perform the method of any one of claims 1-10 when the computer program is executed in the computer.
21. A computing device comprising a memory and a processor, wherein, The memory stores executable code, and the processor implements the method of any one of claims 1-10 when executing the executable code. The memory stores executable code, and the processor implements the method of any one of claims 1-10 when executing the executable code.
Citation Information
Patent Citations
Secure multi-party computing method and related equipment
CN114329533A
Data processing method and device, equipment, storage medium and program product
CN114647857A