Circuit for code partitioning for sequential safety computation execution on multiple processors

CN115994018BActive Publication Date: 2026-09-29INTERNATIONAL BUSINESS MACHINE CORPORATION
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211257171.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2021-10-20
Filing Date
2022-10-14
Publication Date
2026-09-29
Estimated Expiration
2042-10-14

Smart Images

  • Figure CN115994018B_ABST
    Figure CN115994018B_ABST
Patent Text Reader

Abstract

Circuitry for partitioning sequential safety computation code for execution on multiple processors. An example system includes a processor that can obtain a circuit that describes operations of sequential safety computation code. The processor can modify the circuit based on a cost function. The processor can partition the circuit into a plurality of sub-circuits. The processor can assign the plurality of sub-circuits to different processors for execution.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The techniques of this invention relate to secure computation code. More specifically, these techniques relate to performing sequential secure computation code, such as sequential fully homomorphic encryption (FHE) codes. Background Technology

[0002] Recent advances in cryptography demonstrate that multiple parties can collaborate and compute functions of their secret inputs without revealing their own. Specifically, cryptographers have shown cryptographic schemes that allow arithmetic operations (such as addition and multiplication) to be applied to ciphertext. The input to such an operation can be ciphertext containing encrypted input values ​​or ciphertext as the output of other operations. However, secure computational code, such as fully homomorphic (FHE) codes, can be slow to execute. Since running operations on ciphertext can be very time-consuming, solutions utilize multiple processors to save runtime. However, in many cases, a particular solution can be described using a sequential programming language. Furthermore, such sequential languages ​​are difficult to parallelize. Manual parallelization is also time-consuming, expensive, error-prone, and may require manual parallelization for each deployment of each project. Summary of the Invention

[0003] According to the embodiments described herein, a system may include a processor that obtains circuitry describing operations of sequence-safe computation code. The processor may further modify the circuitry according to a cost function. The processor may also divide the circuitry into multiple sub-circuits. The processor may then assign these multiple sub-circuits to different processors for execution.

[0004] According to another embodiment described herein, a method may include obtaining circuitry describing sequential fully homomorphic encryption (FHE) code operations via a processor. The method may further include modifying the circuitry according to a cost function via the processor. The method may further include dividing the circuitry into multiple sub-circuits via the processor. The method may also include assigning the multiple sub-circuits to different processors for execution via the processor.

[0005] According to another embodiment described herein, a computer program product for executing sequence-safe computation code may include a computer-readable storage medium with the program code embodied therein. The computer-readable storage medium itself is not a transient signal. The processor-executable program code enables the processor to obtain circuitry describing the operation of the sequence-safe computation code. The program code may also enable the processor to modify the circuitry according to a cost function. The program code may also enable the processor to divide the circuitry into multiple sub-circuits. The program code may also enable the processor to assign these multiple sub-circuits to different processors for execution. Attached Figure Description

[0006] Figure 1This is a block diagram of an example system for executing secure computation code using the generated sub-circuits;

[0007] Figure 2A This is a block diagram of an example method for generating sub-circuits for executing secure computation codes based on the obtained circuit describing secure computation codes;

[0008] Figure 2B It is a block diagram of an example method for generating sub-circuits for executing secure computation code based on the received secure computation code;

[0009] Figure 3 It is a block diagram of an example computing device that can generate sub-circuits for executing secure computing code;

[0010] Figure 4 This is a schematic diagram of an example cloud computing environment based on the embodiments described herein;

[0011] Figure 5 This is a schematic diagram of an example abstract model layer based on the embodiments described herein;

[0012] Figure 6 It is an example tangible, non-transient computer-readable medium that can generate sub-circuits for executing secure computation code. Detailed Implementation

[0013] According to embodiments of the present invention, the system includes a processor capable of obtaining circuitry describing the operation of sequence-safe computation code. For example, the sequence-safe computation code may be sequential fully homomorphic encryption (FHE) code. The processor can modify the circuitry according to a cost function. The processor can divide the circuitry into multiple sub-circuits. The processor can assign these multiple sub-circuits to different processors for execution. Therefore, embodiments of the present invention allow for concurrent execution of sequence-safe computation code on multiple processors, thereby increasing efficiency. Furthermore, these embodiments enable circuit optimization to improve the runtime of the generated circuitry. Additionally, the embodiments also enable the migration of solutions from one language to another using standard descriptions in the form of generated sub-circuits.

[0014] Now for reference Figure 1 The block diagram shows an example system that uses the generated sub-circuits to perform secure computation code. Figure 1The example system 100 includes a circuit extractor 102 communicatively connected to two processors 104A and 104B. For example, the two processors 104A and 104B can be processors from different computing devices. For example, the computing devices can be two servers connected via a network. The circuit extractor 102 includes a mockup executor 106, a circuit generator 108, a circuit modifier 110, and a circuit divider 112. As shown in the figure, the circuit extractor 102 receives sequential FHE code 114 and outputs sub-circuits 116A and 116B for execution by the processors 104A and 104B. For example, sub-circuits 116A and 116B can be arithmetic circuits.

[0015] exist Figure 1 In the example, the circuit extractor 102 of system 100 can automatically generate sub-circuits 116A and 116B for execution on multiple processors 104A and 104B in response to receiving sequential FHE code 114. Specifically, the FHE code is agnostic to the input data. Therefore, the model executor 106 can execute sequential FHE code 114 using any suitable mockup ciphertext. For example, the model executor 106 can run sequential FHE code 114 using a track-keeping model class for each operation performed during execution. In various examples, the model executor 106 can replace the secure computation library of sequential FHE code 114 with a library having the same interface. For example, secure computation libraries for homomorphic encryption might be HElib, first released in 2013; Homomorphic Encryption of Approximate Number Arithmetic (HEAAN), first released in 2016; Simple Encryption Arithmetic Library (SEAL), first released in 2018; PALISADE, first released in 2017; and Fast Fully Homomorphic Encryption on Torus, first released in 2017. A new replacement library can emulate the operations of the original library. Therefore, the sequential FHE code 114 must not be changed before execution. Furthermore, for each operation performed by the library, the new library can log the operation type and its inputs. The model executor 106 can thus use the replacement library to run the sequential FHE code 114 to generate a log of all operations performed during execution. Since the sequential FHE code 114 does not need to consider the input model ciphertext, the same operation can be performed on each input at every step.

[0016] In various examples, circuit generator 108 may log operations performed during the execution of the model ciphertext. For example, circuit generator 108 may collect a log corresponding to the generated operations performed by sequential FHE code 114 and format the log as a description of the circuit. For example, the description may be in graph format. In some examples, the graph may be a directed acyclic graph (DAG). For example, each node in the DAG may represent an operation, and each edge may represent the ciphertext operated on by the node. In various examples, each log entry in the generated log may include a gate type, input wire label, and output wire label.

[0017] In some examples, circuit modifier 110 can apply optimizations to the generated circuit. For example, circuit modifier 110 can modify the circuit structure. In various examples, circuit modifier 110 can extract a polynomial describing the recorded circuit. For example, the polynomial can be a multivariate polynomial, where each input is a variable of the polynomial. Circuit modifier 110 can then generate a second polynomial based on the number of processors to be used to execute sequential FHE code 114 in parallel. The second polynomial can be used to generate a second optimized circuit.

[0018] Still referencing Figure 1 Once the circuit is modified by the circuit modifier 110, the circuit divider 112 can determine which server executes each gate of the modified circuit. Therefore, the circuit divider 112 can divide the circuit generated by the circuit generator 108 into multiple sub-circuits. Each of these sub-circuits can be executed by a different processor. In various examples, the circuit divider 112 can divide the circuit in a way that minimizes the number of crossing edges between the sub-circuits. For example, each crossing edge can represent information to be sent from one sub-circuit to another. In the example where processors 104A and 104B are implemented in independent servers connected by a network, such crossing edges can therefore represent data to be sent from one server to another. Furthermore, the circuit divider 112 can divide the circuit in a way that distributes computation time evenly among the sub-circuits and allows for parallel execution. The circuit divider 112 can then generate a set of sub-circuits that can be used to compute the same polynomial using multiple sub-circuits.

[0019] In some examples, the circuit divider 112 may use a gradient descent-based algorithm to divide the circuit into sub-circuits. For example, the circuit divider 112 may start from a given partition, where each gate is assigned to be executed on one of the servers. In various examples, the circuit divider 112 may repeatedly apply a step in which the circuit divider 112 looks for a local change to the assignment of gates to servers. The algorithm may terminate when the circuit divider 112 cannot find a local change that improves the operating time of the circuit. Since the circuit divider 112 only applies a change when the change improves the operating time of the circuit, the termination of the algorithm can be guaranteed. In some examples, this algorithm may be represented as a gradient descent algorithm. For example, the objective function may be the function {1,…,S} g →R, where S is the number of servers and g is the number of gates. A point in this space is a partition of g gates to S servers. In each iteration of the algorithm, the circuit divider 112 may take a step along the steepest gradient in the small subset of gradients we consider. For example, the gradient descent-based algorithm may take the following form:

[0020] Algorithm 1

[0021] 1 Input: A circuit C having g gates, the number of servers on which C runs.

[0022] 2 Output: A vector p∈{1,…,S} assigning each gate to a server g .

[0023] 3: = initial vector in {1,…,S} g

[0024] 4 Descent step:

[0025] / / Find the best gradient

[0026] 5K: = neighbors of p

[0027] 6k: = argmin k∈K Time(k) / / Take the next step if it saves time

[0028] 7 If Time(k) < Time(p) then

[0029] 8 p ∶= k

[0030] 9 Go to line 4

[0031] 10 End

[0032] wherein, the objective function Time:{1,…,S} g→R takes the assignment of g gates to one of S servers as input and outputs the computation time required for that assignment. Line 3 states the algorithm starts from the initial starting point. In some examples, the initial starting point can be an assignment that assigns all gates to a single server, a random assignment, or any other assignment. In various examples, the initial assignment is set to the variable p, which holds the best assignment found so far throughout the algorithm. Lines 4-9 perform the gradient descent step. In these lines, the algorithm attempts to find an assignment better than p. If such an assignment is found, the circuit partitioner 112 replaces p with the better assignment and repeats another iteration of gradient descent. In some examples, the circuit partitioner 112 may consider only a small subset of candidates in the entire space, typically those that are close to p by some metric (i.e., neighbors). Line 5 states the algorithm considers all the neighbors of p. In the context of g gates being assigned to S servers, this could be, for example, all assignments of n ≥ 1 gates that are different from p, where n is a parameter. For example, if n = 6, the algorithm would consider all assignments of g-6 gates that satisfy p. In line 6, the circuit divider 112 can calculate the time required to compute each assigned circuit in subset K and set k as the assignment with the shortest time. Then, if the time of k is better than that of p, in line 8, the circuit divider 112 can change p to k, and then repeat gradient descent in lines 4-9.

[0033] In some examples, the circuit divider 112 can use constrained optimization to partition the variables x1,…,x among the servers. n To optimize a certain performance metric P. For example, circuit divider 112 can use constrained optimization calculations to divide the circuit generated by circuit generator 108 into multiple sub-circuits. For example, system 100 may contain N servers, including two servers executing on processors 104A and 104B respectively, and must complete O operations in the shortest possible time. Each operation may have a set preceding operation P. o And a set immediately preceding operation IP o Furthermore, system 100 may have a set of terminal operations TO. Each operation may have a known processing time that depends on the task and operation, but is independent of any server. In various examples, circuit partitioner 112 can determine which operations should be executed on which server and in what order by minimizing the total processing time optimization objective. For example, the constrained optimization can be formulated as the following MILP problem:

[0034]

[0035] The parameters include: pt o , which is the processing time of operation o; commTime, which represents the communication time between servers; W, which is a large number. Variables include: o2s o,n It is the decision to execute operation o on server n; x o1,o2 This indicates that the decision to perform operation o1 is executed before operation o2; ct o `o1` represents the completion time of operation `o2`; `makespan` represents the maximum completion time of all tasks. In various examples, any number of example constraint sets can be included to constrain the optimization. For example, in the first example constraint set, if operation `o2` immediately follows operation `o1`, then the completion time of operation `o2` may be equal to or greater than the completion time of operation `o1` plus the processing time of operation `o2` plus the communication time (if the operations are executed on different servers). In the second example constraint set, the maximum completion time may be greater than or equal to the completion time of all terminal operations. For example, a terminal operation could be an operation without a successor. In the third example constraint set, if operations `o1` and `o2` do not have a predefined priority order, both operations will be executed on the same server, and operation `o1` should be executed before operation `o2`, then the completion time of operation `o1` should be greater than the completion time of operation `o1` plus the processing time of operation `o2`. In the fourth constraint set, if operation `o1` precedes operation `o2`, the corresponding decision variable is set to 1. In the fifth example constraint set, at most one priority is allowed: either `o1` before `o2` or `o2` before `o1`. In the sixth example constraint, if there is no predefined priority order between o1 and o2, and both o1 and o2 will run on the same server, then the order can be defined as o1 before o2 or o2 before o1. Finally, in the seventh example constraint set, each operation must be executed on a server.

[0036] For example, the input sequence FHE code 114 of system 100 can be code written by the developer in any suitable high-level language such as C++. For instance, code that calculates the product of a, b, c, and d could be received in the following form:

[0037] ab = mul(a,b)

[0038] cd = mul(c,d)

[0039] x = mul(ab, cd)

[0040] The first line of code calculates the product of a and b and stores it in the variable ab. The second line of code calculates the product of c and d and stores it in the variable cd. The third line of code calculates the product of ab and cd to obtain the product of a, b, d, and d. In this example, the output of circuit generator 108 can be a description of an arithmetic circuit. For example, the output of circuit generator 108 could be: [multiplication gate, with inputs 'a' and 'b', and an output named 'ab'], [multiplication gate, with inputs 'c' and 'd', and an output named 'cd'], [multiplication gate, with inputs 'ab' and 'cd', and an output named 'x']. The output of circuit extractor 102 can be a first sub-circuit [multiplication gate, having inputs 'a' and 'b', and an output named 'ab'] 116A and a second sub-circuit [multiplication gate, having inputs 'c' and 'd', and an output named 'cd'], [multiplication gate, having inputs 'ab' and 'cd', and an output named 'x'] 116B. The first sub-circuit 116 can be executed in parallel by the sub-circuit 116B executed by the first processor 104A and the second processor 104B.

[0041] It should be understood that, Figure 1 The block diagram is not intended to represent that system 100 will include Figure 1 All components shown. Conversely, system 100 may include fewer components or Figure 1 Additional components not illustrated herein (e.g., additional client devices or additional resource servers, etc.). For example, in the example where the circuit describing sequential FHE code 114 is available and directly provided to circuit divider 112, model executor 106 and circuit generator 108 can be removed. In various examples, sequential FHE code 114 can be any other sequential secure computation code. For example, secure computation code can be other forms of homomorphic encryption, MPC with Beaver Triples, scrambled circuits, or any other suitable secure computation code. Furthermore, in some examples, circuit modifier 110 and circuit divider 112 can be implemented as a single module.

[0042] Figure 2A This is a flowchart of an example method for generating sub-circuits for executing secure computation code. Method 200A can be used with, for example... Figure 3 The computing device 300 in the middle can be implemented by any suitable computing device, and refer to Figure 1 The system 100 described below is used for example. For instance, the method described below can be derived from... Figure 3 Processor 302 or Figure 6 The processor 602 implements this separately.

[0043] In block 202, the processor obtains circuitry describing the operations of the sequence-safe computation code. For example, the sequence-safe computation code could be a sequence fully homomorphic (FHE) encryption code.

[0044] In block 204, the processor modifies the circuit. For example, the circuit can be modified to optimize latency or throughput when executed on multiple processors across different machines coupled via a network. In various examples, the processor can extract the fundamental polynomial of the circuit, generate a second polynomial that minimizes the cost function, and generate the modified circuit based on the second polynomial.

[0045] In box 206, the processor divides the circuit into multiple sub-circuits. For example, the processor can generate a polynomial describing the circuit and then split that polynomial into multiple polynomials with no shared variables. In various examples, circuit partitioning is based on reducing the computational time difference between sub-circuits and reducing the amount of data that needs to be sent between sub-circuits. In some examples, the processor uses a gradient descent-based algorithm to partition the circuit into multiple sub-circuits. For example, the processor can use Algorithm 1 to partition the circuit. In some examples, the processor uses constrained optimization to partition the circuit into multiple sub-circuits. For example, the processor can use Equation 1 to partition the circuit.

[0046] In block 208, the processor assigns the multiple sub-circuits to different processors for execution. For example, the individual sub-circuits can be assigned to different processors. In various examples, the processors may reside in different computing devices coupled via network connections. In various examples, the processors can then execute the sub-circuits. In this way, the execution of sequentially safe computation code is parallelized across multiple processors or computing devices.

[0047] Figure 2A The flowchart is not intended to show that the operations of method 200A should be performed in any particular order, or that all operations of method 200A should be included in every case. Furthermore, method 200A may include any appropriate number of additional operations. For example, method 200A may include converting the circuit into different code associated with different libraries to test performance improvements.

[0048] Figure 2B This is a flowchart of an example method for generating sub-circuits for executing secure computation code. Method 200B can use, for example... Figure 3 The computing device 300 is implemented using any suitable computing device, and references Figure 1 The system 100 is described. For example, the method described below can be described by... Figure 3 Processor 302 or Figure 6 The processor 602 implements this respectively. Figure 2B include Figure 2A The box is similarly referenced.

[0049] In box 210, the processor receives sequence-safe computation code. For example, the sequence-safe computation code could be a sequence fully homomorphic (FHE) encryption code.

[0050] In box 212, the processor executes sequence-safe computation code. For example, sequence-safe computation code can be executed using model ciphertext as input. In various examples, the processor can use a replacement library that records the operations performed during execution to execute secure computation code.

[0051] In block 214, the processor generates a circuit based on recorded operations performed in response to the execution of the sequentially safe computation code. For example, the recorded operations may be formatted as a graph. In some examples, this graph may be a directed acyclic graph (DAC). In various examples, the generated circuit may be an arithmetic circuit.

[0052] In boxes 204, 206, and 208, the processor executes... Figure 2A The blocks described in the diagram are similarly referenced. For example, in block 204, the processor modifies the circuit. In block 206, the processor divides the circuit into multiple sub-circuits. In block 208, the processor assigns these multiple sub-circuits to different processors for execution.

[0053] Figure 2B The flowchart is not intended to suggest that the operations of method 200B should be performed in any particular order, or that all operations of method 200B should be included in every case. Furthermore, method 200B may include any appropriate number of additional operations. For example, method 200B may include converting the circuit into different code associated with different libraries to test performance improvements.

[0054] It should be understood that while this disclosure includes a detailed description of cloud computing, the implementation of the teachings given herein is not limited to cloud computing environments. Rather, embodiments of the invention can be implemented in conjunction with any other type of computing environment now known or developed hereafter.

[0055] Cloud computing is a service delivery model that enables convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, network bandwidth, servers, processing, memory, storage, applications, virtual machines, and services), which can be rapidly provisioned and released with minimal management effort or interaction with the service provider. This cloud model may include at least five features, at least three service models, and at least four deployment models.

[0056] The features are as follows:

[0057] On-demand self-service: Cloud consumers can unilaterally and automatically provide computing power, such as server time and network storage, as needed, without requiring human interaction with the service provider.

[0058] Extensive network access: Capabilities are available through networks and accessed via standard mechanisms that facilitate the use of heterogeneous thin client or thick client platforms (e.g., mobile phones, laptops, and PDAs).

[0059] Resource pooling: A provider's computing resources are pooled to serve multiple consumers using a multi-tenant model, where different physical and virtual resources are dynamically assigned and reassigned as needed. There is a sense of location independence because consumers typically do not have control or knowledge of the exact location of the resources provided, but may be able to specify the location at a higher level of abstraction (e.g., country, state, or data center).

[0060] Rapid flexibility: The ability to provide capacity quickly and flexibly, automatically scaling down and up rapidly in some situations to scale up rapidly. For consumers, the available supply capacity often appears unlimited and can be purchased in any quantity at any time.

[0061] Measuring services: Cloud systems automatically control and optimize resource usage by leveraging metering capabilities at a level of abstraction appropriate to the service type (e.g., storage, processing, bandwidth, and active user accounts). Resource usage can be monitored, controlled, and reported, providing transparency to both service providers and consumers.

[0062] The service model is as follows:

[0063] Software as a Service (SaaS): This provides consumers with the ability to use the provider's applications running on cloud infrastructure. Applications can be accessed from different client devices via thin client interfaces such as web browsers (e.g., web-based email). Consumers do not manage or control the underlying cloud infrastructure, including the network, servers, operating system, storage, or even individual application capabilities, with possible exceptions such as limited user-specific application configuration settings.

[0064] Platform as a Service (PaaS): This provides consumers with the ability to deploy applications created or acquired by the consumer using programming languages ​​and tools supported by the provider onto cloud infrastructure. Consumers do not manage or control the underlying cloud infrastructure, including networks, servers, operating systems, or storage, but they have control over the deployed applications and the configuration of any application hosting environment.

[0065] Infrastructure as a Service (IaaS): The capabilities offered to consumers are processing, storage, networking, and other basic computing resources that enable consumers to deploy and run arbitrary software, which may include operating systems and applications. Consumers do not manage or control the underlying cloud infrastructure, but rather have control over the operating system, storage, deployed applications, and potentially limited control over selected networking components (e.g., host firewalls).

[0066] The deployment model is as follows:

[0067] Private cloud: A cloud infrastructure that operates solely for an organization. It can be managed by the organization or a third party and can exist on-site or off-site.

[0068] Community cloud: A cloud infrastructure shared by several organizations and supporting a specific community with shared concerns (e.g., tasks, security requirements, policies, and compliance considerations). It can be managed by an organization or a third party and can exist on-site or off-site.

[0069] Public cloud: Makes cloud infrastructure available to the public or large industry groups and is owned by an organization that sells cloud services.

[0070] Hybrid cloud: A cloud infrastructure is a combination of two or more clouds (private, community, or public) that remain a single entity but are bound together by standardized or proprietary technologies that enable data and applications to be ported (e.g., cloud bursting for load balancing between clouds).

[0071] Cloud computing environments are service-oriented, focusing on statelessness, loose coupling, modularity, and semantic interoperability. At the heart of cloud computing is the infrastructure comprising a network of interconnected nodes.

[0072] Figure 3 This is a block diagram of an example computing device that can generate sub-circuits for executing secure computing code. Computing device 300 can be, for example, a server, desktop computer, laptop, tablet, or smartphone. In some examples, computing device 300 can be a cloud computing node. Computing device 300 can be described in the general context of computer system executable instructions (e.g., program modules) that execute on the computer system. Generally, program modules can include routines, programs, objects, components, logic, data structures, etc., that perform specific tasks or implement specific abstract data types. Computing device 300 can be implemented in a distributed cloud computing environment, where tasks are performed by remote processing devices linked via a communication network. In a distributed cloud computing environment, program modules can reside in local and remote computer system storage media, including memory storage devices.

[0073] Computing device 300 may include a processor 302 for executing stored instructions and a memory device 304 for providing temporary storage space for the operation of said instructions during operation. The processor may be a single-core processor, a multi-core processor, a computing cluster, or any other configuration. Memory device 304 may include random access memory (RAM), read-only memory, flash memory, or any other suitable memory system.

[0074] Processor 302 can be connected via system interconnect 306 (e.g., PCI The computing device 300 is connected to an input / output (I / O) device interface 308, which is adapted to connect the computing device 300 to one or more I / O devices 310. The I / O devices 310 may include a keyboard and pointing devices, wherein the pointing devices may include a touchpad or a touchscreen, etc. The I / O devices 310 may be built into the computing device 300 or may be devices connected externally to the computing device 300.

[0075] Processor 302 can also be connected via system interconnect 306 to a display interface 312 adapted to connect computing device 300 to display device 314. Display device 314 may include a display screen as a built-in component of computing device 300. Display device 314 may also include a computer monitor, television, or projector, etc., externally connected to computing device 300. Furthermore, network interface controller (NIC) 316 may be adapted to connect computing device 300 to network 318 via system interconnect 306. In some embodiments, NIC 316 may use any suitable interface or protocol, such as Internet Minicomputer System Interface, to transmit data. Network 318 may be a cellular network, radio network, wide area network (WAN), local area network (LAN), or the Internet, etc. External computing device 320 may be connected to computing device 300 via network 318. In some examples, external computing device 320 may be an external web server 320. In some instances, external computing device 320 may be a cloud computing node.

[0076] Processor 302 can also be connected via system interconnect 306 to storage device 322, which may include hard disk drives, optical disk drives, USB flash drives, drive arrays, or any combination thereof. In some examples, the storage device may include receiver module 324, code executor module 326, circuit generator module 328, circuit modifier module 330, circuit divider module 332, and transmitter module 334. Receiver module 322 can receive sequentially safe computation code. For example, sequentially safe computation code may be sequential FHE code. Code executor module 326 can execute sequentially safe computation code using a substitution library that records the operation type and input for each operation. Circuit generator module 328 can obtain a circuit describing the operations of the sequentially safe computation code. For example, the circuit may be an arithmetic circuit. In various examples, the circuit may be converted into a second code different from the safe computation code. Circuit generator module 328 can generate the circuit based on operations performed in response to the execution of the sequentially safe computation code. Circuit modifier module 330 can modify the circuit based on a cost function. In various examples, the circuit modifier module 330 can extract the fundamental polynomial of the circuit, generate a second polynomial that minimizes the cost function, and generate a modified circuit based on the second polynomial. In some examples, the circuit modifier module 330 can iteratively modify the circuit. For example, for higher dimensions, the circuit modifier module 330 can repeatedly run Newton's method, also known as the Newton-Raphson method, until a polynomial of the form (xa)(xb)(xc)…(xn) is determined. The circuit partitioner module 332 can partition the circuit into multiple sub-circuits. For example, the circuit partitioner module 332 can randomly assign each node to a server. Then, the circuit partitioner module 332 can resolve all node pairs and switch their assigned servers. If the switching does not improve the cost function, the circuit partitioner module 332 can revert this change. In various examples, the circuit partitioner module 332 can consider all pairs in this way and repeatedly switch until there are no more pairs to switch. In some examples, the circuit partitioner module 332 can use a gradient descent-based algorithm to partition the circuit. For example, the circuit partitioning module 332 can partition the circuit using Algorithm 1 described above. In some examples, the circuit partitioning module 332 can use constraint optimization to partition the circuit. For example, the circuit partitioning module 332 can use any combination of Equation 1 described above and various constraints described herein to solve the partitioning problem as a constraint optimization problem. The circuit partitioning module 332 can accept various constraints, such as gate X being the input to gate Y (appropriately stated), gate X requiring time to compute, and ciphertext C requiring time to transmit. Then, the circuit partitioning module 332 can minimize the objective function. For example, the objective function can be to minimize the completion time of the final gate.The transmitter module 334 can assign the multiple sub-circuits to different processors for execution. Then, the transmitter module 334 can distribute and send the multiple sub-circuits to different processors for execution.

[0077] It should be understood that, Figure 3 The block diagram is not intended to indicate that computing device 300 includes Figure 3 All components shown. Conversely, computing device 300 may include fewer components or Figure 3 Additional components not shown (e.g., additional memory components, built-in controllers, modules, additional network interfaces, etc.). For example, computing device 300 may further include a code conversion module (not shown) for converting circuitry into different code associated with different libraries to test performance improvements. Furthermore, any functionality of receiver module 324, code executor module 326, circuit generator module 328, circuit modifier module 330, circuit divider module 332, and transmitter module 334 may be implemented partially or entirely in hardware and / or processor 302. For example, functionality may be implemented using application-specific integrated circuits, logic implemented in the built-in controller, or logic implemented in processor 302. In some embodiments, the functionality of receiver module 324, code executor module 326, circuit generator module 328, circuit modifier module 330, circuit divider module 332, and transmitter module 334 may be implemented using logic, wherein, as described herein, logic may include any suitable hardware (e.g., processor, etc.), software (e.g., application programs, etc.), firmware, or any suitable combination of hardware, software, and firmware.

[0078] See now Figure 4 The description illustrates a cloud computing environment 50. As shown, the cloud computing environment 400 includes one or more cloud computing nodes 402 to which local computing devices used by cloud consumers can communicate. These local computing devices include, for example, personal digital assistants (PDAs) or cellular phones 404A, desktop computers 404B, laptop computers 404C, and / or automotive computer systems 404N. Nodes 402 can communicate with each other. They can be physically or virtually grouped (not shown) in one or more networks, such as private clouds, community clouds, public clouds, or hybrid clouds, or combinations thereof, as described above. This allows the cloud computing environment 400 to provide infrastructure, platforms, and / or software as services that cloud consumers do not need to maintain on their local computing devices. It should be understood that... Figure 4 The types of computing devices 404A-N shown are intended to be illustrative only, and computing node 402 and cloud computing environment 400 can communicate with any type of computerized device via any type of network and / or network-addressable connection (e.g., using a web browser).

[0079] See now Figure 5 This demonstrates the 400 (cloud computing environment) Figure 4 This provides a set of functional abstractions. It should be understood beforehand. Figure 5 The components, layers, and functions shown are intended to be illustrative only, and embodiments of the invention are not limited thereto. As shown, the following layers and corresponding functions are provided:

[0080] The hardware and software layer 500 includes hardware and software components. Examples of hardware components include: a mainframe 501; a RISC (Reduced Instruction Set Computer) based server 502; a server 503; a blade server 504; a storage device 505; and network and networking components 506. In some embodiments, software components include network application server software 507 and database software 508.

[0081] The virtualization layer 510 provides an abstraction layer from which the following examples of virtual entities can be provided: virtual server 511; virtual storage 512; virtual network 513, including virtual private network; virtual application and operating system 514; and virtual client 515.

[0082] In one example, the management layer 520 may provide the following functionalities: Resource Provisioning 521 provides dynamic procurement of computing resources and other resources used to perform tasks within the cloud computing environment. Metering and Pricing 522 provides cost tracking as resources are utilized within the cloud computing environment and bills or invoices for the consumption of these resources. In one example, these resources may include application software licenses. Security provides authentication for cloud consumers and tasks, as well as protection for data and other resources. User Portal 523 provides access to the cloud computing environment for consumers and system administrators. Service Level Management 524 provides cloud resource allocation and management to ensure that required service levels are met. Service Level Agreement (SLA) Planning and Fulfillment 525 provides pre-scheduling and procurement of cloud resources based on anticipated future needs according to the SLA.

[0083] The workload layer 530 provides examples of functionalities that can leverage a cloud computing environment. Examples of workloads and functionalities that can be provided from this layer include: mapping and navigation 531; software development and lifecycle management 532; virtual classroom instruction delivery 533; data analytics and processing 534; transaction processing 535; and secure computing code processing 536.

[0084] This invention can be a system, method, and / or computer program product at any possible level of technical detail integration. The computer program product may include a computer-readable storage medium having computer-readable program instructions thereon for causing a processor to execute aspects of the invention.

[0085] Computer-readable storage media can be tangible devices capable of retaining and storing instructions for use by an instruction execution device. Computer-readable storage media can be, for example, but not limited to, electronic storage devices, magnetic storage devices, optical storage devices, electromagnetic storage devices, semiconductor storage devices, or any suitable combination of the foregoing. A non-exhaustive list of more specific examples of computer-readable storage media includes: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), static random access memory (SRAM), portable compact disk read-only memory (CD-ROM), digital universal disk (DVD), memory sticks, floppy disks, mechanical encoding devices such as punched cards or protrusions in slots having instructions recorded thereon, and any suitable combination of the foregoing. As used herein, computer-readable storage media should not be construed as transient signals themselves, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through waveguides or other transmission media (e.g., light pulses passing through fiber optic cables), or electrical signals emitted through wires.

[0086] The computer-readable program instructions described herein can be downloaded from a computer-readable storage medium to a corresponding computing / processing device, or downloaded to an external computer or external storage device via a network (e.g., the Internet, a local area network, a wide area network, and / or a wireless network). The network may include copper transmission cables, optical transmission fibers, wireless transmissions, routers, firewalls, switches, gateway computers, and / or edge servers. A network adapter card or network interface in each computing / processing device receives computer-readable program instructions from the network and forwards them to a computer-readable storage medium within the corresponding computing / processing device.

[0087] Computer-readable program instructions used to perform the operations of this invention may be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state setting data, or source code or object code written in any combination of one or more programming languages, including object-oriented programming languages ​​(such as Java, Smalltalk, C++, etc.) and conventional procedural programming languages ​​(such as the "C" programming language or similar programming languages). The computer-readable program instructions may be executed entirely on a user's computer, partially on a user's computer, as a standalone software package, partially on a user's computer and partially on a remote computer, or entirely on a remote computer or server. In the latter case, the remote computer may be connected to the user's computer via any type of network (including a local area network (LAN) or a wide area network (WAN)) or may be connected to an external computer (e.g., via the Internet using an Internet service provider). In some embodiments, electronic circuitry including, for example, programmable logic circuitry, field-programmable gate arrays (FPGAs), or programmable logic arrays (PLAs) may be personalized to execute computer-readable program instructions by utilizing state information from the computer-readable program instructions in order to perform aspects of this invention.

[0088] This document describes various aspects of the invention with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer-readable program instructions.

[0089] These computer-readable program instructions may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions / actions specified in one or more blocks of a flowchart and / or block diagram. These computer-readable program instructions may also be stored in a computer-readable storage medium that causes a computer, programmable data processing apparatus, and / or other device to operate in a particular manner, such that the computer-readable storage medium storing the instructions includes an article of manufacture containing instructions that implement aspects of the functions / actions specified in the blocks of the flowchart and / or block diagram.

[0090] Computer-readable program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable apparatus, or other device to produce computer-implemented processing, such that the instructions executed on the computer, other programmable apparatus, or other device perform the functions / actions specified in one or more blocks of a flowchart and / or block diagram.

[0091] Now for reference Figure 6 A block diagram of an example tangible, non-transient computer-readable medium 600 is shown, which can generate sub-circuits for executing secure computation code. Processor 602 can access the tangible, non-transient computer-readable medium 600 via computer interconnect 604. Furthermore, the tangible, non-transient computer-readable medium 600 may include instructions for processor 602 to perform... Figure 2A and 2B The code for the operation of method 200A or 200B.

[0092] like Figure 6 As shown, the various software components discussed herein can be stored on a tangible, non-transient computer-readable medium 600. For example, receiver module 606 includes code for receiving sequentially safe computation code. In some examples, the sequentially safe computation code may be sequential FHE code. Code executor module 608 includes code for executing the sequentially safe computation code. Code executor module 608 also includes code for executing the safe computation code using a replacement library of operations performed during recorded execution. Circuit generator module 610 includes code for obtaining a circuit describing the operations of the sequentially safe computation code. Circuit generator module 610 also includes code for generating a circuit based on operations performed in response to the execution of the recorded sequentially safe computation code. In various examples, circuit generator module 610 includes code for formatting the recorded operations into a graph. Circuit modifier module 612 includes code for modifying the circuit based on a cost function. In various examples, circuit modifier module 612 includes code for extracting the fundamental polynomial of the circuit, generating a second polynomial that minimizes the cost function, and generating the modified circuit based on the second polynomial. Circuit partitioner module 614 includes code for partitioning the circuit into multiple sub-circuits. The transmitter module 616 includes code that assigns the plurality of sub-circuits to different processors for execution. The transmitter module 616 can then send the plurality of sub-circuits to different processors for execution.

[0093] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. Each block in a flowchart or block diagram may represent a module, segment, or portion of instructions, including one or more executable instructions for implementing a specified logical function. In some alternative implementations, the functions marked in the blocks may occur in a non-linear order. For example, depending on the functions involved, two consecutively shown blocks may actually be executed substantially simultaneously, or these blocks may sometimes be executed in reverse order. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, may be implemented using a dedicated hardware-based system that performs the specified function or action or executes a combination of dedicated hardware and computer instructions. It should be understood that, depending on the specific application, the tangible, non-transient computer-readable medium 600 may include... Figure 6 Any number of additional software components not shown. For example, the computer-readable medium 600 may also include a code conversion module (not shown) for converting the circuitry into different codes associated with different libraries to test performance improvements.

[0094] The descriptions set forth herein have been given for purposes of illustration and description, but are not intended to be exhaustive or limited to the forms disclosed. Many modifications and variations will be apparent to those skilled in the art without departing from the scope and spirit of this disclosure. The terminology used herein has been chosen to best explain the principles and practical application of one or more aspects set forth herein, or to enable others skilled in the art to understand the embodiments disclosed herein.

Claims

1. A system comprising a processor, said processor: Receive order-safe computation code; Use a library that records the operation type and input replacement for each of the multiple recorded operations to perform sequentially safe computation code; The circuit is generated based on the recorded operations performed in response to the execution of the sequentially safe computation code; Circuit modification based on cost function; The modified circuit is divided into multiple sub-circuits, thereby reducing the amount of data sent between the sub-circuits; and These multiple sub-circuits are assigned to different processors for execution.

2. The system according to claim 1, wherein, The processor extracts the basic polynomial of the circuit, generates a second polynomial that minimizes the cost function, and generates a modified circuit based on the second polynomial.

3. The system according to claim 1, wherein, The processor iteratively modifies the circuitry.

4. The system according to claim 1, wherein, The processor uses a gradient descent-based algorithm to partition the circuit.

5. The system according to claim 1, wherein, The processor uses constraint optimization to partition the circuit.

6. The system according to claim 1, wherein, The modified circuit can be converted into a second code that is different from the sequentially safe computation code.

7. A computer-implemented method, comprising: Receive sequentially safe computation code through the processor; The processor executes sequentially safe computation code using a replacement library that records the operation type of each of the multiple recorded operations and the input; The circuit is generated by the processor based on the recorded operations performed in response to the execution of sequentially safe computation code; The processor modifies the circuit based on a cost function. The processor divides the modified circuit into multiple sub-circuits, thereby reducing the amount of data sent between the sub-circuits; and The processor assigns the multiple sub-circuits to different processors for execution.

8. The computer-implemented method according to claim 7, wherein, The execution of order-safe computation code includes using a replacement library that records the operations performed during execution to perform order-safe computation code.

9. The computer-implemented method according to claim 7, wherein, Generating the modified circuit involves formatting the recorded operations as a diagram.

10. The computer-implemented method according to claim 7, wherein, The circuit modification process involves extracting the fundamental polynomial of the circuit, generating a second polynomial that minimizes the cost function, and generating the modified circuit based on the second polynomial.

11. The computer-implemented method of claim 7, further comprising using the processor to convert the modified circuitry into different code associated with different libraries to test performance improvements.

12. The computer-implemented method of claim 7, wherein the sequential secure computation code is sequential fully homomorphic encryption (FHE) code.

13. A computer program product for executing sequentially safe computation code, the computer program product having program code embodied therein, the program code being executable by a processor to cause the processor to perform the method as described in any one of claims 7 to 12.

Citation Information

Patent Citations

  • Fully Homomorphic Encryption from Monoid Algebras

    US20170134158A1

  • Homomorphic evaluation of tensor programs

    US20200076570A1