Data processing method and device in multi-party secure computation

By reversing the order of Boolean segments of powers of 2 and calculating the square root of the difference, the problem of high computational complexity and large communication volume of inverting powers of 2 and square root in multi-party secure computation is solved, thus improving data processing efficiency.

CN115987493BActive Publication Date: 2026-04-17ANT BLOCKCHAIN TECHNOLOGY (SHANGHAI) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
ANT BLOCKCHAIN TECHNOLOGY (SHANGHAI) CO LTD
Filing Date
2022-12-02
Publication Date
2026-04-17

AI Technical Summary

Technical Problem

In multi-party secure computation, existing technologies suffer from high computational complexity and large communication volume when dealing with the inverse square root of powers of 2, resulting in low efficiency.

Method used

By reversing the Boolean segments of powers of 2, the square of the difference is calculated and converted into an arithmetic sharing form, reducing computational complexity and improving efficiency.

Benefits of technology

This reduces the computational complexity of finding the square root of the inverse of a power of 2 in multi-party secure computation, thereby improving data processing efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115987493B_ABST
    Figure CN115987493B_ABST
Patent Text Reader

Abstract

The embodiment of the specification provides a method and device for data processing in multi-party secure calculation. In a service processing process based on multi-party secure calculation, arithmetic inverse square root calculation is performed on a power of 2 in a Boolean sharing form constituted by two data parties. Under the corresponding technical concept, the characteristics of the power of 2 in the binary form and the Boolean sharing, and the positional relationship between the power of 2 and the inverse of the power of 2 before and after the decimal point are utilized. The inverse of the power of 2 in the Boolean sharing form is determined through the bit value reverse arrangement in the Boolean slice. Then, the two parties construct the square root value of the power of 2 by squaring through the splitting of the slice in the Boolean sharing form of the inverse of the power of 2. In this way, the data communication amount of the arithmetic inverse square root calculation of the power of 2 can be greatly reduced, and the service processing efficiency of the secure calculation is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This specification relates to one or more embodiments in the field of secure computing technology, and more particularly to methods and apparatus for data processing in multi-party secure computing. Background Technology

[0002] Secure multi-party computation, also known as secure multi-party computation, allows multiple parties to collaboratively compute the result of a function without disclosing the input data of each party. The result is then made public to one or more of the parties. Typical applications of secure multi-party computation include joint statistical analysis of privacy-preserving multi-party data and machine learning. Here, the function is a statistical operation function, a machine learning algorithm, etc.

[0003] In multi-party secure computation, to prevent the leakage of data and intermediate computation results, the data or intermediate results can be held by each party in a shared manner. Each party holds a data fragment, and the fragments held by all parties are merged to reconstruct the corresponding data. Typically, the computation is performed in a shared state. Thus, the number of data communications and the amount of communication in multi-party secure computation are important factors affecting the efficiency of secure computation. Summary of the Invention

[0004] This specification describes one or more embodiments of a data processing method and apparatus for multi-party secure computation, which is used to solve one or more problems mentioned in the background art.

[0005] According to a first aspect, a data processing method for multi-party secure computation is provided, used to determine the arithmetic sharing form of target data between the first and second parties for a power of 2 that constitutes a Boolean sharing form, wherein the target data is data obtained by taking the square root of the inverse power of 2, and the first and second parties respectively hold a first Boolean fragment and a second Boolean fragment representing the power of 2 through n bits, the method being executed by the first party, including: determining a first inverse fragment corresponding to the inverse of the power of 2 based on the reverse order of the values ​​of each bit of the first Boolean fragment, the first inverse fragment and the second party based on the... The second inverse fragment, determined by the reverse arrangement of the values ​​of each bit in the two Boolean fragments, constitutes the Boolean shared form of the power of 2 inverse. Each bit of the first inverse fragment is split into a predetermined number of equally spaced bits, and each first reference value is determined according to the binary number formed by each group of equally spaced bits. The result of summing the squares of the differences between each first reference value and the corresponding second reference value under a predetermined balance coefficient is obtained by the second party, thereby obtaining the first arithmetic fragment of the target data, wherein a single second reference value is determined by the second party from the binary number formed by the corresponding group of equally spaced bits in the second inverse fragment.

[0006] In one embodiment, the least significant bit of the first Boolean segment is bit 0, corresponding to the number of decimal places f; the reverse order of the values ​​of each bit is performed in one of the following ways: converting the least significant bit to the most significant bit in sequence to the most significant bit to the least significant bit, with the number of decimal places after conversion being nf-1; mirroring each bit with the decimal point position between the (f-1)th bit and the fth bit as the axis, with the number of decimal places after mirroring being nf-1; mirroring each other bit with the fth bit as the axis, with the number of decimal places after mirroring being nf.

[0007] In one embodiment, the predetermined number of groups is 4, and the starting bits of each group are the 0th bit, the 1st bit, the 2nd bit, and the 3rd bit, respectively. Each bit corresponding to a single group is arranged from the high bit to the low bit to form a single binary number, and the single first reference value corresponding to the single binary number is the value described by the single binary number.

[0008] In one embodiment, each first reference value corresponds to a second reference value that has the same starting bit, and the square of a single difference corresponds to a single balance coefficient. The single balance coefficient is consistent with the arithmetic value represented by the starting bit of the corresponding first reference value in the first inverse segment. The summation of the squares of the differences between each first reference value and the corresponding second reference value under a predetermined balance coefficient is to use each balance coefficient as a summation factor for the squares of each difference.

[0009] In a further embodiment, the step of securely calculating with the second party the summation of the squares of the differences between each first reference value and the corresponding second reference value under a predetermined balance coefficient to obtain the first arithmetic slice of the target data includes: performing a secure squared protocol with the second party to calculate the squares of the differences between each first reference value and the corresponding second reference value, respectively, to obtain each first square slice corresponding to the square of each difference; and summing each first square slice using each balance coefficient to obtain the first arithmetic slice of the target data.

[0010] In another further embodiment, the step of securely calculating with the second party the sum of the squares of the differences between each first reference value and the corresponding second reference value under a predetermined balance coefficient to obtain the first arithmetic slice of the target data includes: calculating each product of each first reference value and the corresponding second reference value by performing a secure multiplication protocol with the second party to obtain each first multiplication slice; and summing each first multiplication slice with the squares of each locally calculated first reference value based on the corresponding balance coefficient to obtain the first arithmetic slice of the target data.

[0011] In a further embodiment, a single product is the negative pair of 2 resulting from multiplying a single first reference value by a corresponding second reference value.n The modulus is determined.

[0012] In another embodiment, the step of securely calculating with the second party the sum of the squares of the differences between each first reference value and the corresponding second reference value under a predetermined balance coefficient to obtain a first arithmetic slice of the target data includes: summing the square roots of each balance coefficient over each first reference value to obtain a first difference slice; and performing a secure squared protocol with the second party based on the first difference slice to obtain a first arithmetic slice of the target data, wherein, during the execution of the secure squared protocol, the second party provides a second difference slice obtained by summing the square roots of each balance coefficient over each second reference value.

[0013] In a further embodiment, the first difference segment is calculated by summing the coefficients of each first reference value using the square root of each balance coefficient as the coefficient, and modulo 2. n In the case of the result, the second difference segment is the sum of the opposite modulo 2 of the sum of the square roots of each balance coefficient as the coefficients of each second reference value. n The result; the sum of the opposite modulo 2 of the first difference segment, using the square root of each balance coefficient as the coefficient of each first reference value. n In the case of the result, the second difference segment is obtained by summing the coefficients of each second reference value using the square root of each balance coefficient as the coefficient, and modulo 2. n The result.

[0014] In one embodiment, the first Boolean slice is obtained by sequentially performing an XOR operation on each Boolean slice of multiple participating parties other than the second party.

[0015] According to a second aspect, a data processing apparatus for multi-party secure computation is provided, used to determine the arithmetic sharing form of target data between the first and second parties for powers of 2 that constitute a Boolean sharing form, wherein the target data is data obtained by taking the inverse square root of a power of 2, and the first and second parties respectively hold a first Boolean fragment and a second Boolean fragment of a power of 2 represented by n bits, the apparatus being disposed on the first party, comprising:

[0016] The inversion unit is configured to determine the first inverse piece corresponding to the inverse of the power of 2 based on the reverse order of the values ​​of each bit of the first Boolean piece. The first inverse piece and the second inverse piece determined by the second party based on the reverse order of the values ​​of each bit of the second Boolean piece constitute the Boolean shared form of the inverse of the power of 2.

[0017] The reference value determination unit is configured to split each bit of the first inverse segment into a predetermined number of equally spaced bits, and determine each corresponding first reference value according to the binary number formed by each group of equally spaced bits.

[0018] The secure computing unit is configured to sum the squares of the differences between each first reference value and the corresponding second reference value under a predetermined balance coefficient with the second party's secure computing unit, thereby obtaining a first arithmetic slice of the target data, wherein a single second reference value is determined by the second party by a binary number composed of corresponding groups of equally spaced bits in the second inverse slice.

[0019] According to a third aspect, a computer-readable storage medium is provided having a computer program stored thereon, which, when executed in a computer, causes the computer to perform the method of the first aspect.

[0020] According to a fourth aspect, a computing device is provided, including a memory and a processor, characterized in that the memory stores executable code, and when the processor executes the executable code, it implements the method of the first aspect.

[0021] The methods and apparatus provided in the embodiments of this specification address the scenario of inverting and extracting the square root of powers of 2 in two-party secure computation. Considering the complexity of inversion and square root operations, and the special characteristics of powers of 2 in Boolean shared form, a new technical solution for inverting and extracting the square root of powers of 2 is proposed. This solution completes the inversion by reversing the binary data, and then constructs a square root from the inversion result. This solution reduces the computational complexity of inverting and extracting the square root of powers of 2 in multi-party secure computation, thereby improving the data processing efficiency of multi-party secure computation. Attached Figure Description

[0022] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the following description of the embodiments will be briefly introduced. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0023] Figure 1 This diagram illustrates a method flowchart for data processing in a multi-party secure computation performed by a single participant, according to one embodiment.

[0024] Figure 2 This diagram illustrates the data flow for executing a two-party security squared agreement.

[0025] Figure 3 This diagram illustrates the data flow for performing a two-way safe multiplication.

[0026] Figure 4 A schematic block diagram of an apparatus for data processing in a multi-party secure computation with a single participant, according to one embodiment, is shown. Detailed Implementation

[0027] The technical solutions provided in this specification are described below with reference to the accompanying drawings.

[0028] Secret sharing, also known as secret splitting or secret sharing, works by dividing a secret (such as a key or private data) into multiple shares, each held by a different data party. The secret can only be recovered when more than a certain number of parties combine their shares; shares obtained from fewer than the threshold cannot recover any information from the secret. In multi-party secure computation, the threshold number is usually the same as the number of participating parties, and the shares into which the secret is split can also be called fragments.

[0029] Secret sharing is a crucial technique in secure multi-party computation. Common forms of secret sharing in secure multi-party computation include arithmetic sharing, Boolean sharing, and Yao's Sharing. The following description uses the sharing of secret data x as an example to illustrate these various sharing methods.

[0030] Arithmetic sharing, also known as sum sharing, involves dividing an integer x into two slices, x = x... L +x R Mod 2 N The shared form (translated to [0, 2) N The interval (-1] is distributed and stored between the two parties, so that one party does not know x. R The other party is unaware of x L Neither of the two sides can yield the complete form of x. Furthermore, the two sides can be extended to multiple sides, as denoted as x = x1 + x2 + ... + x d Assuming N = 64, then x can be represented as a single fragment of a data set in a single participant using a 64-byte (bit) binary number. One way to split a piece of data x into shared fragments is, for example, by randomly generating d-1 binary shards. 64 The values ​​within the range (such as randomly generated 64-byte binary numbers) are used as d-1 slices, denoted as x1, x2, ..., x... d-1 , and for 2 64 (translate to [0, 2) 64 The interval [-1] is used as another partition by taking the modulo of the interval (x). d = x - x1 - x2 - ... - x d-1 .

[0031] Boolean sharing is a secret sharing method that uses an XOR operation on bits. For example, considering two participants, suppose x is a one-bit data (with a value of 0 or 1), and... In a Boolean shared form between two participants, x0 and x1 are two Boolean shared partitions of x in the two participants, each taking a value of 0 or 1. This represents the XOR operation. A single participant is unaware of the other participant's share and therefore cannot deduce the data x. For data x' consisting of n bits, an n-bit binary number can be randomly generated as one party's Boolean shared share (e.g., x0'). The other party's Boolean shared share (e.g., x1') can be determined by the XOR result of x' and that party's Boolean shared share (x0'⊕x').

[0032] Yao's sharing is a sharing method related to garbled circuits (GC). This specification does not cover this sharing method and will not elaborate on it here.

[0033] Each of the three sharing methods mentioned above has its own advantages and disadvantages. In the process of multi-party secure computation, the sharing method of business data can be transformed for the sake of convenience.

[0034] Boolean to Arithmetic Sharing (B2A) is a common sharing conversion operation. B2A can be implemented using subtraction on a Boolean circuit, but this method is too expensive. To improve performance, both parties can use an OT (oblivious transfer) protocol. In the i-th OT operation targeting the i-th bit, one party (e.g., party A) sends two strings s to the other party (e.g., party B). i,0 s i,1 And make them satisfy: The other party, acting as the receiver, inputs the value of the i-th bit in the local Boolean segment. As a selection bit, it is obtained Furthermore, the sender calculates... Receiver calculation Thus, the Boolean shared form is converted to the AND shared form.

[0035] In practice, it may also involve the conversion of sharing forms between Yao's sharing and Boolean sharing (such as B2Y, Y2B, etc.), the conversion of sharing forms between Yao's sharing and arithmetic sharing (such as A2Y, Y2A, etc.), and the conversion of sharing forms from arithmetic sharing to Boolean sharing (A2B), etc. The conversion between various sharing methods will not be listed one by one here.

[0036] In business processing based on multi-party secure computation, the following scenario is often encountered: a data x, in fixed-point or floating-point form, is represented in a Boolean shared form by two parties (or it may be converted to a Boolean shared form for calculating its inverse), and it is necessary to calculate the inverse of its square root, or the square root of its inverse, denoted as x. -1 / 2 or The result constitutes an arithmetic shared form between the two participants. In this specification, this scenario may be referred to as the inverse square root of arithmetic.

[0037] The concept of fixed-point numbers is as follows: For decimals, Z modulo 2 is generally used. r The shared form, coupled with a fixed-point representation (describing the decimal point position) serving as common knowledge between the two parties, is essentially a fixed-point number representation. A data point 'a' can be represented as a fixed-point number 'd×e'. -f d is an integer. Here, f represents the number of decimal places in binary. For example, suppose a value a = 0.125 and a fixed-point number f = 14, then the integer d in the corresponding fixed-point number is 0.125 × e. f =2048, then the fixed-point number corresponding to a is 2048×e -14 In the shared form, data 'a' can be represented by fragments obtained by splitting the integer part 2048 (e.g., a0 = 987 and a1 = 1061). When 'a' is a power of 2, 'd' is usually also a power of 2. The inverse of 'a' can also be represented using fixed-point numbers, and its integer part is also a power of 2. The decimal point position in fixed-point numbers is usually fixed; the difference between floating-point and fixed-point representations is that the decimal point position can be variable.

[0038] In conventional arithmetic inversion and square root calculations, two parties can first securely perform inversion and square root calculations on x using a division circuit and the Goldreich-Micali-Wigderson Protocol (GMW). The result is presented in a Boolean shared form. Then, the aforementioned B2A protocol is executed to convert the target data for x from the Boolean shared form to the arithmetic shared form. The GMW protocol is a semi-honest secure computation protocol supporting multiple parties based on obfuscated circuits. The objective function of the GMW protocol consists of XOR gates, AND gates, and NOT gates. During secure computation, the GMW protocol consumes a significant amount of data communication.

[0039] When x is a power of 2, using the conventional techniques described above to perform arithmetic inversion and square root extraction incurs significant computational and data communication costs. However, considering powers of 2 (such as 2...),... t The binary representation of 2 has certain special characteristics. This specification provides a new technical approach to perform arithmetic inverse square root extraction on powers of 2 to reduce communication volume and improve business processing efficiency.

[0040] Those skilled in the art will understand that powers of 2 in binary form have the following properties:

[0041] (1) The powers of 2 and their inverses each have only one bit (e.g., the t-th bit counted from the least significant bit as the 0th bit) that is 1, and the rest of the bits are 0. When the powers of 2 are in a Boolean shared form between the two participants, the two Boolean fragments are different by only one bit.

[0042] (2) For integer powers of 2, the bit before the decimal point is 1 and the rest are 0, while for the inverse of integer powers of 2, the bit after the decimal point is 1 and the rest are 0.

[0043] (3) If the least significant bit before the decimal point is designated as the 0th bit, then the inverse of a power of 2 and a power of 2 have the following relationship: 2 t The (t+1)th bit before the decimal point (the t-th bit) is 1, 2. t The inverse of is 1 in the t-th bit after the decimal point.

[0044] Based on the above properties, this specification provides a technical concept that can determine the Boolean shared form corresponding to the inverse of the power of 2 by reversing the Boolean segments of the power of 2, thereby arranging the bits with a value of 1 after the decimal point. Then, for the square root of the inverse of the power of 2, the square of the difference (which can also be converted into a summation) is calculated. While determining the square root value, the segments of each participating party are converted into an arithmetic shared form.

[0045] Specifically, in binary form, the principle of finding the inverse of a power of 2 is as follows: Assume a value 8 = 2. 3 If the number of decimal places f is 4, then its binary form is 1000 0000, where 1 is in the 7th bit, i.e., 8 = 2. 7 ×2 -4 =2 3 The four 0s in the lower bits represent the fractional part after the decimal point, and the bit value 1 is located in the third bit counting from the least significant bit before the decimal point. Reversing the binary data 1000 0000, changing the most significant bit to the least significant bit, we get 0000 0001. If we keep the number of decimal places unchanged, we have: 20 × 2 -4 =2 -4 =8 -1 ×2 -1 If you want to get 8 -1 You can change the number of decimal places to f = 3 (floating point), then 0000 0001 corresponds to 20 × 2. -3 =8 -1 Alternatively, pad with 0s in the least significant bit and truncate the most significant bit to get 0000 0010, corresponding to a decimal place of f = 4 (fixed point) and 2. 1 ×2 -4 =8-1 .

[0046] In the Boolean sharing format, if the first party and the second party each perform the same processing on their local Boolean partitions, they can each obtain a Boolean partition that is the inverse of a power of 2.

[0047] Furthermore, we perform a square root calculation on the inverse of a power of 2. Since the square of a power of 2 is still a power of 2, the square root calculation of the inverse of a power of 2 can be transformed into taking the fourth power and then squaring it. Below, we take the power of 2, p = 2... q The principle is described in detail using the square root of as an example.

[0048] First, determine the number of decimal places f for a fixed-point or floating-point number represented by n bits to be a multiple of 4. This is because, for 2... -f Taking the square root yields 2. -f / 2 However, under the technical concept of this specification, it is necessary to construct a square calculation, and 2 -f / 4 The square of is 2 -f / 2 Therefore, for ease of calculation, f can be set to a multiple of 4. Furthermore, the local Boolean fragment can be divided into four groups of equally spaced bits using the first and second methods in an arithmetic progression of bits (equally spaced bits). Specifically, bits 0, 4, 8, 12... form one group; bits 1, 5, 9... form another group; bits 2, 6, 10... form another group; and bits 3, 7, 11... form yet another group. Alternatively, given that j takes the values ​​0, 1, 2, and 3, the bits corresponding to all i that satisfy 4i + j ≤ n form one group. Assuming the relative position of the decimal point and the bit value remains unchanged within each group, the fixed-point number corresponding to a single group of bit values ​​can be denoted as f / 4.

[0049] Thus, for the bit value of a single group of equally spaced bits, the corresponding arithmetic reference value is determined using its corresponding binary number. Assume the first party holds the first Boolean segment p of p. L The second party holds the second Boolean fragment p of p. R Then the number of fixed points corresponding to a single group is f / 4, and the first side can determine four reference values: y L1 =p0 L ×2 0-f / 4 +p4 L ×2 1-f / 4 +p8 L ×2 2-f / 4 ...; y L2 =p1 L ×2 0-f / 4 +p5 L ×2 1-f / 4 +p9 L ×2 2-f / 4 ...; y L3 =p2 L ×20-f / 4 +p6 L ×2 1-f / 4 +p 10 L ×2 2-f / 4 ...; y L4 =p3 L ×2 0-f / 4 +p7 L ×2 1-f / 4 +p 11 L ×2 2-f / 4 Similarly, the second party determines four reference values: y R1 =p0 R ×2 0-f / 4 +p4 R ×2 1-f / 4 +p8 R ×2 2-f / 4 ...; y R2 =p1 R ×2 0-f / 4 +p5 R ×2 1-f / 4 +p9 R ×2 2-f / 4 ...; y R3 =p2 R ×2 0-f / 4 +p6 R ×2 1-f / 4 +p 10 R ×2 2-f / 4 ...; y R4 =p3 R ×2 0-f / 4 +p7 R ×2 1-f / 4 +p 11 R ×2 2-f / 4 ...

[0050] Since only one bit of a power of 2 is 1, for the four Boolean segments of p, y L1 -y R1 y L2 -y R2 y L3 -y R3 y L4 -y R4 Only one of them is not zero, and among each reference value, when a single bit is raised to the fourth power, it is related to the corresponding bit in p. L There are 4 between the corresponding actual values. 0 / 4 4 1 / 4 4 2 / 4 4 3 / 4 The difference is a multiple of each other. Therefore... The arithmetic value satisfies:

[0051]

[0052] The coefficients 1, √2, 2, and 2√2 corresponding to the square values ​​can be seen as balancing coefficients to balance these multiple differences. Thus, by determining the square of the corresponding difference for each of the four reference values ​​of the first and second sides, the square root of p can be obtained. Furthermore, it can be guaranteed that the square root value is positive.

[0053] Thus, the communication volume in the process of finding the square root of the inverse of a power of 2 is the same as that in the above protocol for calculating the square root of p. This avoids the computational and communication complexity of using division circuits and GMW protocols, reduces communication volume, and improves service processing efficiency.

[0054] The technical concept of this specification is described in detail below.

[0055] Figure 1 The diagram illustrates a data processing flow performed by a single participant in a multi-party secure computation according to one embodiment. It assumes that the participants in the current secure computation are a first party and a second party, and that the power of 2 in the Boolean shared form between the first party and the second party is x = 2. t x is stored in fixed-point or floating-point form. Specifically, assuming the number of decimal places in the fixed-point or floating-point number is f, x is represented as x = d × 2. -f Let d be the integer part of the fixed-point or floating-point number corresponding to x, described by n bits. The integer d forms a shared form in the first and second parts, used to describe x. Then, in binary form... The first party holds the first Boolean segment d, which contains n bits. L From the least significant bit to the most significant bit, for example, denoted as d0. L d1 L ...d n-1 L The second party holds a second Boolean slice d containing n bits. R From the least significant bit to the most significant bit, for example, denoted as d0. R d1 R ...d n-1 R And for a single bit i in the binary form of d, we have: d i =d i L +d i R Modulo 2, or

[0056] Assuming the current single participant is the first party, in a multi-party secure computation scenario, in order to perform arithmetic inverse and square root extraction on x (e.g., given...) ),like Figure 1 As shown, the data processing flow executed by the first party may include: Step 101, determining the first inverse fragment corresponding to the power of 2 based on the reverse order of the values ​​of each bit of the first Boolean fragment, the first inverse fragment and the second inverse fragment determined by the second party based on the reverse order of the values ​​of each bit of the second Boolean fragment constitute a Boolean shared form of the power of 2; Step 102, splitting each bit of the first inverse fragment into a predetermined number of equally spaced bits, and determining each corresponding first reference value according to the binary number composed of each group of equally spaced bits; Step 103, calculating with the second party the sum of the squares of the differences between each first reference value and the corresponding second reference value under a predetermined balance coefficient, thereby obtaining the first arithmetic fragment of the target data, wherein a single second reference value is determined by the second party from the binary number composed of the corresponding group of equally spaced bits in the second inverse fragment.

[0057] First, in step 101, based on the reverse order of the values ​​of each bit in the first Boolean segment, the first inverse segment corresponding to the inverse of the power of 2 is determined.

[0058] The purpose of reversing the values ​​in the first Boolean segment is to move the powers of 2 from before the decimal point to their corresponding positions after the decimal point in fixed-point or floating-point representation, thus determining the inverse of the power of 2. The inverse of the power of 2 can also be called the reciprocal of the power of 2. It can be understood that the power of 2 and its inverse have the following correspondence: the power of 2 is represented by a value of 1 for the j-th decimal place and 0 for the rest, indicating 2... j-1 Then the inverse of a power of 2 has a value of 1 in the (j-1)th decimal place and 0 in the rest. For example, 2 3 If the number of decimal places f = 4, then j = 4, and the power of 2 is 2. 3 It is represented as 0000 1000.0000, and its inverse 2 -3 This is represented as 000000000.001 0000, or 0000.0010 0000. The decimal point is added here for ease of description; in reality, the first Boolean segment does not contain a decimal point, but rather ends at 2. n An integer (n bits) in a defined Abelian group represents the value of that integer with a predetermined number of decimal places. For example, the value of n bits is 0000 10000000, which represents the arithmetic value of the integer 0000 1000 0000 and 2. -4 The product of, i.e., 2 7 ×2 -4 =8.

[0059] As seen in the examples above, for an n-bit fixed-point or floating-point number with an initial decimal place of f, its inverse, when arranged in reverse order, may result in a decimal point shift, such as the number of decimal places becoming nf-1. During the reverse ordering process, only the n-bit integer can be processed. Then, based on the positional relationship between powers of 2 and their inverses before and after the decimal point, the new decimal point position can be described by adjusting the number of decimal places.

[0060] It's understandable that reversing a binary number that is a power of 2 can be done by reversing the first and second Boolean partitions in the same way. The Boolean partition resulting from reversing the first Boolean partition can be denoted as the first inverse partition, such as by using p... L If p represents p, then L Each bit is denoted as p0 from least significant bit to most significant bit. L p1 L ...p n-1 L For example, 001011010011, when reversed, becomes 1100 1011 0100, etc. Reverse sorting can be done in various reasonable ways.

[0061] According to one embodiment, reversing the order can arrange the most significant bit to the least significant bit in reverse order. For example, the (n-1)th bit becomes the least significant bit 0, the (n-2)th bit becomes the least significant bit 1, and so on, to obtain the reversed order result. That is, let p0 L =d n-1 L p1 L =d n-2 L ...p n-1 L =d0 L In this case, with n=12, assuming the initial number of decimal places is f=4, then after reversing, in order to ensure the relationship between the powers of 2 and their inverses after reversing, the number of decimal places can be nf-1=7, that is, 0010 1101.0011 after reversing becomes 1100 1.011 0100.

[0062] According to another embodiment, the first Boolean segment can be mirrored and flipped with the decimal point position (between the (f-1)th bit and the fth bit) determined by the number of decimal places f as the axis to obtain the reversed order result. For example, when f=4, 0010 1101 0011 becomes 1100 1011 0100 after flipping. This essentially mirrors the data before and after the decimal point. For example, adding a decimal point indicates the number of decimal places: 0010 1101.0011 mirrored with the decimal point as the axis yields 1100.10110100. In this case, to ensure the correspondence between powers of 2 and their inverses with respect to the decimal point, the decimal position can be adjusted to nf-1, or a 0 can be added to the lower bits and the higher bits truncated, while simultaneously determining the number of decimal places as nf.

[0063] According to another embodiment, the bits of the first Boolean segment can be mirrored and flipped using the f-th bit (i.e., the bit before the decimal point position indicated by the number of decimal places f) as the axis to obtain the reversed order result. This method keeps the relative position of the decimal point and the f-th bit unchanged (it can also be understood as using the common axis of the f-th bit and the decimal point). For example, 001011010011 flipped with the f-th bit (the bold bit) as the axis becomes 1100 1 011 0100. After this mirror flip, the f-th bit in place becomes the (nf-1)-th bit, and the decimal point should be after this (nf-1)-th bit, so the current number of decimal places can be adjusted to nf-1. Optionally, in order to keep the number of decimal places at nf, zeros can be padded at the low bits and the high bits truncated, which will not be elaborated here.

[0064] In other embodiments, there are other reasonable ways to reverse the numerical values, which will not be elaborated here. The first reference slice after reversal can correspond to the current decimal point position. When the first and second sides are calculated in a fixed-point manner, the current number of decimal places can be converted to f through decimal point conversion to maintain a consistent decimal point position in subsequent calculations. The decimal point conversion method is based on the definition of fixed-point numbers, scaling the integer part by a corresponding factor. Typically, moving the decimal point one place to the lower place reduces the integer part to half. For example, if the current number of decimal places is nf-1 = 7 and f = 4, then the representation of the current number of decimal places is k = d' × 2 - 7 The integer part is d', which, when converted to a fixed-point number with 4 decimal places, is: k = d'' × 2 - 4 =(d'×2- 3 )×2- 4 That is, the decimal point is moved 3 bits to the right, and the integer part d'' is reduced to 2^3 of d'. 3One-third. In floating-point arithmetic, both parties can also record the current number of decimal places to determine the actual value of the data, i.e., the inverse of a power of 2 in various bases (such as decimal), such as 0.125. Optionally, the conversion of the shared form can also be performed only on the integer part.

[0065] It is understandable that, when the second party determines the second inverse partition based on the second Boolean partition in the same way, the first inverse partition and the second inverse partition constitute the inverse of a power of 2 in the Boolean shared form of the first and second parties. The second inverse partition is denoted as p. R The bits are as follows: p0 R p1 R ...p n-1 R .

[0066] Then, in step 102, each bit of the first inverse segment is split into a predetermined number of equally spaced bits, and each corresponding first reference value is determined according to the binary number formed by each group of equally spaced bits.

[0067] Based on the principle described above, the first inverse fragment can be divided into four groups of equally spaced bits. Here, equally spaced bits mean that bits assigned to a group have consistent spacing within the first inverse fragment. For example, if one bit is taken every four bits, then bits 0, 4, 8, 12… are assigned to one group, bits 1, 5, 9, 13… are assigned to another group, and so on. Typically, the starting bits of each group are adjacent to each other, and there is no overlap between any two groups. The bit spacing is consistent with the number of bit groups. For example, if the bit spacing within a group is 4, then there are a total of 4 groups, with starting bits 0, 1, 2, and 3 respectively. It can be understood that the number of bits in each group can be the same or different, depending on the total number of bits in the first inverse fragment. Furthermore, every bit in the first inverse fragment is allocated to a single group. That is, each group completely distributes all the bits in the first inverse fragment.

[0068] Assuming the number of groups is m, for j = 0, 1, 2, ..., m, the j-th group of equally spaced bits can be described by 4i+j bits, where i = 0, 1, 2, 3, ... and 4i+j ≤ n. In this specification, considering the purpose of the corresponding technical concept, computational complexity, and communication volume, m = 4 is preferred. A single group of bits can form a new binary number. With the position of each bit relative to the decimal point unchanged, the number of decimal places f corresponding to the first inverse partition is f / 4. Therefore, the arithmetic form of the binary number corresponding to a single group of bits (e.g., data described in decimal) can be: The numerical value in this arithmetic form can be called the first reference value. A single first reference value is determined by a binary number consisting of corresponding groups of equally spaced bits. For m groups of equally spaced bits, m first reference values ​​can be obtained.

[0069] On the other hand, the second party can divide the second inverse segment into m equally spaced groups of bits in the same way and determine m second reference values. Each second reference value is determined by the second party using a binary number composed of the corresponding equally spaced groups of bits in the second inverse segment. Each first reference value corresponds one-to-one with each second reference value that has the same starting bit.

[0070] Next, through step 103, the first arithmetic slice of the target data is obtained by summing the squares of the differences between each first reference value and the corresponding second reference value under a predetermined balance coefficient, together with the second party's security calculation.

[0071] It can be understood that steps 102 and 103 are for obtaining the square root arithmetic shared form of data p that constitutes a Boolean shared form in the first and second parties (i.e., The process of (arithmetic sharing form). In order to determine The above principles can be used to construct a safe square calculation, effectively avoiding the sign problem in difference calculation. As can be seen from the principles above, Among them, (y L1 -y R1 ) 2 、(y L2 -y R2 ) 2 、(y L3 -y R3 ) 2 、(y L4 -y R4 ) 2 The squares of the differences between each first reference value and the corresponding second reference value correspond to the balance coefficients 1, 2, 3, and 4 respectively. 2.

[0072] It's understandable that the difference here is described in terms of principle. In multi-party secure computation, data can be stored in a shared format; therefore, the difference can also be converted into a data item described in a shared format. For example, in modulo 2... n In the form of sharing, the first reference value y L1 Second reference value y R1 The difference y L1 -y R1 It can be determined by y L1 First-party module 2 n Fragmentation and -y R1 Second Module 2 n The fragmented structure and sharing format.

[0073] Based on a possible design, in order to determine The first party can execute a safe squared protocol with the second party four times, safely calculating the square of each difference (y) respectively. L1 -y R1 ) 2 、(y L2 -y R2 ) 2 、(y L3 -y R3 ) 2 and (y) L4 -y R4 ) 2 That is, calculate y in the arithmetic-shared form formed by each party in the first and second parties respectively. L1 -y R1 y L2 -y R2 y L3 -y R3 and y L4 -y R4 The square value of y, where y L1 -y R1 The two partitions are y L1 and -y R1 Mod 2 n In the form of y L2 -y R2 The two partitions are y L2 and -y R2 Mod 2 n In the form of y L3 -y R3 The two partitions are y L3 and -y R3 Mod 2 n In the form of y L4 -y R4 The two partitions are y L4 and -y R4 Mod 2 n In the form of.

[0074] Figure 2 A flowchart illustrating a specific example of the Security Square Protocol is shown. Figure 2 The calculation principle of the safe square protocol is shown below: For a data x, with the introduction of a disturbance a, we have: x 2 =(xa) 2 +2(xa)a+a 2 Assume data x is constructed and shared by the first and second parties. The first party holds the first fragment x0, and the second party holds the second fragment x1. Let xa be the perturbation value dx, and let the constant term a... 2 =b can be considered as a balance term to eliminate disturbances, and can then be determined by a trusted third party (such as...) Figure 3The diagram shows a random number generator (a server) generating fragments a0, a1, b0, and b1 for each of the numbers a and b. a0 and b0 are provided to the first party, and a1 and b1 are provided to the second party. Here, a0, a1, b0, and b1 can be generated according to the constraint (a0 + a1). 2 = (b0 + b1), where three of these are randomly generated, and the fourth is calculated from the other three. For example, the first party generates random numbers a0 and b0, the second party generates random number a1, and a trusted third party generates random numbers a0, b0, and a1, calculates b1, and provides it to the second party. In this way, offline communication can be limited to the communication of a single data fragment (such as b1).

[0075] Then, the first party can calculate a fragment of the perturbation value dx, dx0 = x0 - a0, and provide it to the second party. Similarly, the second party can calculate another fragment of the perturbation value dx, dx1 = x1 - a1, and provide it to the first party. Thus, both the first and second parties can each calculate the perturbation value dx = dx0 + dx1. In practice, one party can also calculate a fragment of the perturbation value dx and provide it to the other party, while the other party calculates the other fragment locally and provides the perturbation value dx to the other party. In this method, the resulting data communication volume is the number of bits for one data fragment and the communication volume for one data dx, which is consistent with the number of bits for two data fragments.

[0076] Furthermore, both the first and second parties calculate x locally. 2 The corresponding fragments. For example... Figure 3 As shown, in a specific example, the first party can compute a fragment s0 = (x 2 0 = (xa) 2 +2(xa)a0+(a 2 )0=dx×dx+2dx×a0+b0, the second side can be used to calculate another piece s1=(x 2 )1=2(xa)a1+(a 2 )1=2dx×a1+b1. In practice, the first and second parties can also use local data to calculate the corresponding fragments in other ways, such as the second party calculating s1=dx×dx+2dx×a1+b1, the first party calculating s0=2dx×a0+b0, etc., which are not limited here.

[0077] It is worth noting that, unless otherwise specified, each fragment in the execution of the Secure Square protocol is modulo 2. n In the form of. Figure 2 The online traffic generated by the Security Square Protocol shown is the number of bits in two data fragments (e.g., 2n bits).

[0078] As can be seen, the execution result of a single secure squared protocol is an arithmetic sharing of the corresponding squared values ​​between the first and second parties, thus the first party receives four first squared value fragments, and the second party receives four second squared value fragments. Specifically... The calculation involves summing the squared values ​​using corresponding balance coefficients as summing factors. The first party can then use these balance coefficients to sum the squared values ​​obtained locally in segments, thereby obtaining... A fragment in the form of arithmetic sharing, such as the target data (2 t The square root of the inverse, i.e., 2 -t / 2 The first arithmetic partition of the equation is obtained. Similarly, the second partition can be obtained by summing the partitions of the squared values ​​obtained locally using the corresponding balance coefficients. Another partition in the form of arithmetic sharing.

[0079] At this point, the first and second parties complete the square calculation by executing the secure square protocol four times, generating a total of 4n bits of offline communication and 8n bits of online communication.

[0080] According to other possible designs, it is also possible to The square operation in grammar can be broken down into the sum of multiple quadratic polynomials. For example, it can be broken down into:

[0081]

[0082] In this polynomial, the multiplier only involves terms related to each first reference value, which can be calculated locally by the first party, such as y L1 2 y L2 2 y L3 2 y L4 2 The multiplier only involves terms related to each second reference value, which can be calculated locally by the second party, such as y. R1 2 y R2 2 y R3 2 y R4 2 The multiplier involves terms that have both a first reference value and a second reference value, such as -y. L1 ×y R1 -y L2 ×y R2 -y L3 ×y R3 -y L4 ×y R4Each of these can be further divided into two modulo 2 components by the first and second parties. n Based on the multiplier, perform safe multiplication for joint calculation.

[0083] Figure 3 A flowchart illustrating a specific example of safe multiplication is shown. Figure 3 As shown, during the secure multiplication of data 'a' held by the first party and data 'b' held by the second party, a trusted third party (such as...) can be involved. Figure 2 A pseudo-random number generator (in the context of the system) generates random numbers s and v, and two shards z1 and z2 stored in an arithmetic-shared manner, sv = z. A third party can generate various auxiliary parameters according to the constraint sv = z0 + z1. The first party can obtain s and z1 from a trusted third party or generate them locally, while the second party can obtain one of z1 and z2 from the trusted third party and obtain the other from the third party or generate it locally. For example, if s and z1 are generated by the first party using a pseudo-random number generator consistent with the agreement of the trusted third party, v is generated by the second party using a pseudo-random number generator consistent with the agreement of the trusted third party, and z2 is obtained by the second party from the trusted third party, then the offline communication volume can be only the communication volume of a single data shard (such as z1).

[0084] Here, s and v can be considered as perturbation terms for a and b respectively, and e and f represent the perturbation results of a and b after adding noise, respectively. The first party calculates the perturbation result e = as and sends it to the second party, while the second party calculates the perturbation result f = bv and sends it to the first party. At this point, the generated online communication volume is the number of bits for two data fragments (e.g., 2^n). Further, the first party can calculate one shared fragment of a × b, c0 = sf + z0, and the second party can calculate another shared fragment of a × b, c1 = ev + z1. Substituting the expressions for e and f, we have: c0 + c1 = sf + z0 + ev + z1 = ab. That is, c0 and c1 constitute the shared form of the product of a and b.

[0085] Therefore, the result of each of the four safe multiplications can be obtained as a first multiplicative integral slice in both the first and second powers. Correspondingly, the second power yields four second multiplicative integral slices locally. In modulo 2... n In the form of arithmetic sharing, the communication cost for two parties to perform a single secure multiplication is n bits offline and 2n bits online. Therefore, the four secure multiplications in step 103 consume a total of 4n bits of offline communication and 8n bits of online communication.

[0086] Therefore, the first party can determine the target data by using the locally calculated square value and the sum of each multiplicative integral piece under the corresponding balance coefficients. The first arithmetic slice, such as Similarly, the second party can determine the target data by using the locally calculated square value and the sum of the individual multiplicative integral pieces. The second arithmetic partition, such as

[0087] In yet another possible design, since only one of the differences between the four first reference values ​​and the second reference values ​​is not zero, further adjustments can be made. By transforming the expression, we obtain the following equivalent square form: They are respectively balance coefficient 1, 2. The square root. Furthermore, distinguishing between the slices held by the first party and the slices held by the second party within the square brackets, then... Will Let w1 be the first difference partition. Let w2 be the second difference segment. Then the comprehensive difference w is formed by the segments w1 and w2 in the first and second parties in an arithmetic sharing form. For the target data... The calculation is transformed into a pair of w 2 Secure computation for w. 2 Secure computing can be achieved through Figure 2 The security square protocol is shown and will not be elaborated further here.

[0088] The execution result of the safe square protocol is that the first party receives the first arithmetic fragment, and the second party receives the second arithmetic fragment, constituting... This is an arithmetic sharing method. In this method, the first and second parties can each calculate the first difference fragment w1 and the second difference fragment w2 locally. Therefore, the communication volume is consistent with the communication volume of executing a single secure squared protocol, which is n bits offline and 2n bits online. The communication volume is much smaller than the two designs mentioned above.

[0089] Among them, the first and second powers relate to the balance coefficients and their square roots. The calculation can be truncated using approximations, such as retaining three decimal places. 1.414 can be called An approximation of the value. According to one embodiment, taking the first party as an example, during calculation, since each first reference value can be in the form of a fixed-point number or a floating-point number, it can be approximated to a predetermined number of decimal places. The approximate value is multiplied by the integer part of the corresponding first reference value with the corresponding number of decimal places, and the product is rounded to obtain the integer value of the corresponding term in fixed-point or floating-point form. The number of decimal places at this point is the same as the first reference value, which is f / 4. According to another embodiment, the approximate value can be... The approximate value is expressed as a fixed-point or floating-point number, and its integer part is multiplied by the integer part of the first reference value in fixed-point or floating-point form to determine the corresponding product. At this point, the number of decimal places in the product becomes... The sum of the number of decimal places of the corresponding value and the number of decimal places of the first reference value can be kept unchanged or adjusted as needed; this instruction manual does not impose any restrictions on this.

[0090] In more possible designs, it can also be based on (y L4 -y R4 ) 2 Other forms of secure square calculations are constructed to obtain an arithmetic sharing form of the target data, which will not be elaborated here.

[0091] It is understood that the above process only describes the shared form conversion process of the integer part in fixed-point or floating-point form. In practice, the embodiments described above can also be applied to other related calculation processes in cases where data is represented by binary integers and decimal point positions or decimal places, which will not be elaborated here. Among them, the fragmentation of the square root of the inverse of the power of 2 in the shared form can be stored in fixed-point or floating-point form, or it can be converted into arithmetic form (such as decimal values) for storage, which is not limited here.

[0092] It is worth noting that the second-party execution process and the first-party execution process cooperate with each other, as described in the preceding principle description, and Figure 2 The operations performed by the second party involved in the description of the illustrated process also apply. Figure 3 The illustrated process will not be repeated here. It is understood that "first party" and "second party" are used only to distinguish the two participants in the secure computation. The terms "first" and "second" in the above names, such as first reference value, second reference value, first Boolean fragment, second Boolean fragment, first product, second product, etc., are all qualifiers added to the descriptions corresponding to the respective participants. In other words, these "first" and "second" qualifiers describe the correspondence with the corresponding participants. In practice, the operations performed by the first party and the second party can be interchanged, while maintaining the correspondence described above. That is, the "first" and "second" in the names can also be interchanged for correspondence, but this specification does not impose any restrictions on this.

[0093] Furthermore, according to some optional implementation methods, in multi-party secure computation involving more than two parties, to facilitate the arithmetic inversion and square root calculation, the Boolean fragments of one or more parties can be XORed sequentially and then merged into one party. Ultimately, this results in the powers of 2 forming a Boolean shared form distributed across the two parties. In this way, the arithmetic inversion of the target data can be performed by the two parties without revealing the target data. The arithmetic shared fragments obtained by these two parties after the transformation can be randomly split and distributed to other parties, thus forming and sharing the powers of 2 across multiple parties.

[0094] Reviewing the above process, the technical concept provided in this specification, in the process of calculating the square root of the inverse of a power of 2 in a Boolean shared form between two data parties, utilizes the characteristics of powers of 2 and Boolean sharing, as well as the positional relationship of the power of 2 and its inverse with respect to the decimal point. By reversing the bit values ​​in the Boolean segment and changing the number of decimal places, the Boolean shared form of the inverse of the power of 2 is determined. Then, taking advantage of the special characteristic that the inverse of a power of 2 can still be written as a power of 2, the square root of the inverse of the power of 2 is converted into the square of a reference value determined by each party, thus obtaining the corresponding arithmetic shared form. In this way, the complex calculation of the square root of the inverse of data using the circuitry in GMW is avoided, thereby greatly reducing data communication volume. A more efficient and secure calculation method for the square root of the inverse of a power of 2 is provided, improving the efficiency of secure computing business processing.

[0095] According to another embodiment, an apparatus for data processing in a multi-party secure computation provided on the computing side is also provided. Figure 4 A data processing apparatus 400 in a multi-party secure computation according to one embodiment is shown. The apparatus 400 can be located in any of the multiple parties involved in the multi-party secure computation.

[0096] In the two-party secure computation, the target data is divided into a first Boolean fragment and a second Boolean fragment, each consisting of n bits corresponding to the first and second parties, respectively, forming a Boolean shared form. Device 400 is used to invert powers of 2.

[0097] like Figure 4 As shown, the device 400, located in the first party among a plurality of participating parties, includes:

[0098] The inversion unit 401 is configured to determine the first inverse segment corresponding to the inverse of the power of 2 based on the reverse order of the values ​​of each bit of the first Boolean segment. The first inverse segment and the second inverse segment determined by the second party based on the reverse order of the values ​​of each bit of the second Boolean segment constitute a Boolean shared form of the inverse of the power of 2.

[0099] The reference value determination unit 402 is configured to split each bit of the first inverse segment into a predetermined number of equally spaced bits, and determine each corresponding first reference value according to the binary number formed by each group of equally spaced bits.

[0100] The secure computing unit 403 is configured to sum the squares of the differences between each first reference value and the corresponding second reference value under a predetermined balance coefficient with the second party secure computing unit, thereby obtaining a first arithmetic slice of the target data, wherein a single second reference value is determined by the second party by a binary number composed of corresponding groups of equally spaced bits in the second inverse slice.

[0101] It is worth noting that, Figure 4 The device 400 shown is Figure 1 The methods described correspond to, Figure 1 The corresponding descriptions in the method embodiments also apply to the device 400, and will not be repeated here.

[0102] According to another embodiment, a computer-readable storage medium is also provided, on which a computer program is stored, which, when executed in a computer, causes the computer to perform a combination Figure 1 The methods described above.

[0103] According to another embodiment, a computing device is also provided, including a memory and a processor, wherein executable code is stored in the memory, and when the processor executes the executable code, it implements a combination... Figure 1 The methods described above.

[0104] Those skilled in the art will recognize that the functions described in the embodiments of this specification in one or more of the above examples can be implemented using hardware, software, firmware, or any combination thereof. When implemented in software, these functions can be stored in a computer-readable medium or transmitted as one or more instructions or code on a computer-readable medium.

[0105] The above specific embodiments further illustrate the purpose, technical solution, and beneficial effects of the technical concept of this specification. It should be understood that the above are merely specific embodiments of the technical concept of this specification and are not intended to limit the scope of protection of the technical concept of this specification. Any modifications, equivalent substitutions, improvements, etc., made on the basis of the technical solutions of the embodiments of this specification should be included within the scope of protection of the technical concept of this specification.

Claims

1. A data processing method in multi-party secure computation, used to determine the arithmetic sharing form of target data between two parties for a power of 2 constituting a Boolean sharing form between the first and second parties, wherein, The target data is obtained by taking the inverse square root of a power of 2. The first party and the second party respectively hold a first Boolean segment and a second Boolean segment representing a power of 2 using n bits. The method is executed by the first party and includes: Based on the reverse order of the values ​​of each bit in the first Boolean segment, the first inverse segment corresponding to the inverse of the power of 2 is determined. The first inverse segment and the second inverse segment determined by the second party based on the reverse order of the values ​​of each bit in the second Boolean segment constitute the Boolean shared form of the inverse of the power of 2. Each bit of the first inverse segment is split into a predetermined number of equally spaced bits, and each first reference value in a one-to-one arithmetic form is determined according to the binary number formed by each group of equally spaced bits. The first arithmetic slice of the target data is obtained by summing the squares of the differences between each first reference value and the corresponding second reference value under a predetermined balance coefficient, together with the second party's secure calculation. The first arithmetic slice is obtained by summing the squares of the differences between each first reference value and the corresponding second reference value under a predetermined balance coefficient. The second reference value is in arithmetic form and is determined by the second party as a binary number consisting of corresponding groups of equally spaced bits in the second inverse slice.

2. The method as described in claim 1, wherein, The least significant bit of the first Boolean segment is bit 0, corresponding to the number of decimal places f; the reverse order of the values ​​of each bit is performed in one of the following ways: Convert the least significant bit to the most significant bit in order, and the number of decimal places after conversion is nf-1. Using the position of the decimal point between the (f-1)th bit and the fth bit as the axis, each bit is mirrored and flipped, and the number of decimal places after the flip is nf-1; Using the f-th bit as the axis, mirror and flip all other bits, resulting in nf decimal places.

3. The method of claim 1, wherein, The predetermined number of groups is 4, and the starting bits of each group are the 0th bit, the 1st bit, the 2nd bit, and the 3rd bit, respectively. Each bit corresponding to a single group is arranged from the high bit to the low bit to form a single binary number. The single first reference value corresponding to the single binary number is the value described by the single binary number.

4. The method of claim 1, wherein, Each first reference value corresponds to a second reference value that has the same starting bit. The square of a single difference corresponds to a single balance coefficient. The single balance coefficient is consistent with the arithmetic value represented by the starting bit of the corresponding first reference value in the first inverse segment. The summation of the squares of the differences between each first reference value and the corresponding second reference value under a predetermined balance coefficient is to use each balance coefficient as a summation coefficient for the squares of each difference.

5. The method of claim 4, wherein, The first arithmetic slice of the target data obtained by summing the squares of the differences between each first reference value and the corresponding second reference value under a predetermined balance coefficient, together with the second-party security calculation, includes: By executing a security squared protocol with the second party, the squares of the differences between each first reference value and the corresponding second reference value are calculated to obtain the first squared slices corresponding to the squares of each difference. The first arithmetic slice of the target data is obtained by summing each first square slice using each balance coefficient.

6. The method of claim 4, wherein, The first arithmetic slice of the target data obtained by summing the squares of the differences between each first reference value and the corresponding second reference value under a predetermined balance coefficient, together with the second-party security calculation, includes: By executing a secure multiplication protocol with the second party, each first reference value is multiplied by the corresponding second reference value to obtain each first multiplication integral slice; Each first multiplicative integral slice is summed with the squared values ​​of each locally calculated first reference value based on the corresponding balance coefficient to obtain the first arithmetic slice of the target data.

7. The method of claim 6, wherein, A single product is the negative of the product of a single first reference value and the corresponding second reference value, plotted against 2. n The modulus is determined.

8. The method of claim 4, wherein, The first arithmetic slice of the target data obtained by summing the squares of the differences between each first reference value and the corresponding second reference value under a predetermined balance coefficient, together with the second-party security calculation, includes: The first difference segment is obtained by summing the first reference value with the square root of each balance coefficient as the summation coefficient. Based on the first difference slice and the second party performing a safe square protocol, a first arithmetic slice of the target data is obtained. During the execution of the safe square protocol, the second party provides a second difference slice obtained by summing the square roots of each balance coefficient with each second reference value.

9. The method of claim 8, wherein: In the first difference segment, the square root of each balance coefficient is used as the coefficient of each first reference value, and the sum is modulo 2. n In the case of the result, the second difference segment is the sum of the opposite modulo 2 of the sum of the square roots of each balance coefficient as the coefficients of each second reference value. n The result; The first difference segment is the sum of the opposite modulo 2 of the square roots of each balance coefficient, which are respectively used as the coefficients of each first reference value. n In the case of the result, the second difference segment is obtained by summing the coefficients of each second reference value using the square root of each balance coefficient as the coefficient, and modulo 2. n The result.

10. The method of claim 1, wherein, The first Boolean slice is obtained by sequentially performing an XOR operation on each Boolean slice of the multiple participating parties other than the second party.

11. A data processing apparatus for multi-party secure computation, used to determine the arithmetic sharing form of target data between two parties for a power of 2 constituting a Boolean sharing form between the first and second parties, wherein, The target data is obtained by taking the inverse square root of a power of 2. The first and second parties respectively hold a first Boolean segment and a second Boolean segment representing a power of 2 using n bits. The device is located on the first party and includes: The inversion unit is configured to determine the first inverse piece corresponding to the inverse of the power of 2 based on the reverse order of the values ​​of each bit of the first Boolean piece. The first inverse piece and the second inverse piece determined by the second party based on the reverse order of the values ​​of each bit of the second Boolean piece constitute the Boolean shared form of the inverse of the power of 2. The reference value determination unit is configured to split each bit of the first inverse segment into a predetermined number of equally spaced bits, and determine each first reference value in a one-to-one arithmetic form according to the binary number formed by each group of equally spaced bits. The secure computing unit is configured to sum the squares of the differences between each first reference value and the corresponding second reference value under a predetermined balance coefficient with the second party's secure computing unit, thereby obtaining a first arithmetic slice of the target data, wherein a single second reference value is in arithmetic form and is determined by the second party as a binary number composed of corresponding groups of equally spaced bits in the second inverse slice.

12. A computer-readable storage medium having a computer program stored thereon, which, when executed in a computer, causes the computer to perform the method of any one of claims 1-10.

13. A computing device comprising a memory and a processor, wherein: The memory stores executable code, and when the processor executes the executable code, it implements the method of any one of claims 1-10.

Citation Information

Patent Citations

  • Method, device and system for performing form conversion on privacy data fragments

    CN113688426A

  • Data query method and device based on multi-party security computing

    CN115080615A