A privacy data protection method, system, data sender, and data receiver
By using Paillier algorithm and random processing technology in privacy data protection, private data is encrypted and obfuscated, and the problem of low confidentiality of privacy data protection in the existing technology is solved, achieving more efficient privacy data protection.
Patent Information
- Application Number
- CN202310176823.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-02-23
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2043-02-23
AI Technical Summary
The confidentiality of the privacy data protection method in the prior art is not high enough, especially when the random numbers multiplied by the numerator and the denominator are consistent, which may lead to the leakage of privacy information.
A security calculation method based on straight lines across two points is adopted, and the key is generated through the Paillier algorithm, and the coordinate difference is randomly processed and numerator confused during the data calculation process to improve the confidentiality of the data.
It effectively avoids privacy leakage in the case of mutually metatropical elements of the numerator and denominator, and improves the confidentiality and computing efficiency of private data.
Smart Images

Figure CN116127518B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of data confidentiality, and particularly to a method and system for protecting privacy data, a data sending end, and a data receiving end. Background Art
[0002] With the rapid development of network communication technology, personal information is easily collected, transmitted, and used by various intelligent terminal devices. If the platform supervision is ineffective, personal privacy information is easily leaked. At the enterprise level, once some trade secrets are leaked, it will cause the loss of the first opportunity in the game with competitors, and then cause huge human and property losses to the enterprise. However, in many scenarios, such as privacy-preserving auctions, private machine learning, electronic voting systems, etc., it is necessary to use the privacy information of multiple parties for some data processing and calculations. For example: In the field of cryptography, secure multi-party computation can securely process the collaborative computing problems of multiple participating parties with private data in a distributed computing scenario. Therefore, how to protect privacy data, achieve the balance between privacy and collaboration, and thus ensure the normal collaboration and data communication between privacy data users is an important technical issue.
[0003] Currently, among the methods for protecting privacy data, the secure calculation method of a straight line passing through two points is a commonly used method. Specifically, when the secure calculation method of a straight line passing through two points is used in the field of spatial information security, first, a variant of the Elgamal algorithm is used to give a secure calculation protocol for a straight line passing through two points, perform key generation and encryption. During the process of calculating the slope, the random numbers multiplied by the numerator and the denominator are the same. Finally, a variant of the Elgamal algorithm is used for decryption.
[0004] However, in the current methods for protecting privacy data, since the random numbers multiplied by the numerator and the denominator are the same during the process of calculating the slope, if the obtained straight line slope is an exact result, when the numerator and denominator are relatively prime, the data points can be speculated, resulting in the leakage of privacy information and insufficient confidentiality of privacy data. Summary of the Invention
[0005] The present application provides a method and system for protecting privacy data, a data sending end, and a data receiving end to solve the problem that the confidentiality of privacy data in the existing privacy data protection methods is not high enough.
[0006] To solve the above technical problems, the embodiments of the present application disclose the following technical solutions:
[0007] A method for protecting privacy data, the method is used for two-party privacy data calculation, and the method includes:
[0008] A security calculation method based on a straight line passing through two points, where the two parties participating in privacy data protection are defined as: the first computing party and the second computing party. The data points of the first computing party correspond to the first coordinates, and the data points of the second computing party correspond to the second coordinates;
[0009] Convert the first coordinates and the second coordinates into integers respectively;
[0010] The first computing party generates the Paillier algorithm key and sends the corresponding public key to the second computing party;
[0011] The first computing party encrypts the first coordinates and sends them to the second computing party;
[0012] The second computing party encrypts the second coordinates, calculates the coordinate difference between the first coordinates and the second coordinates on the ciphertext, randomly processes the coordinate difference, and sends the randomly processed coordinate value to the first computing party;
[0013] After the first computing party decrypts and approximately calculates the quotient of the randomly processed coordinate value, it sends it to the second computing party;
[0014] According to the quotient result and the corresponding relationship between the coordinate values before and after random processing, the second computing party calculates the approximate slope of the two straight lines and sends the approximate slope to the first computing party;
[0015] The two parties determine the straight line passing through the two coordinates according to the approximate slope and their respective data points.
[0016] Optionally, the method by which the second computing party encrypts the second coordinates, calculates the coordinate difference between the first coordinates and the second coordinates on the ciphertext, randomly processes the coordinate difference, and sends the randomly processed coordinate value to the first computing party includes:
[0017] The second computing party encrypts the second coordinates;
[0018] On the ciphertext obtained after encryption, calculate the coordinate difference between the first coordinates and the second coordinates respectively according to the abscissa and the ordinate. The coordinate difference includes: the coordinate difference of the abscissa and the coordinate difference of the ordinate;
[0019] Multiply the coordinate difference of the abscissa and the coordinate difference of the ordinate by different random numbers respectively to obtain the randomly processed coordinate value. Each of the random numbers contains multiple prime factors;
[0020] Send the randomly processed coordinate value to the first computing party.
[0021] Optionally, after multiplying the coordinate difference of the abscissa and the coordinate difference of the ordinate by different random numbers respectively to obtain the randomly processed coordinate value, the method further includes:
[0022] Confuse the numerator and denominator of the coordinate values after random processing.
[0023] Optionally, the method for the first computing party to decrypt the coordinate values after random processing, perform approximate calculation to obtain the quotient, and then send them to the second computing party includes:
[0024] The first computing party decrypts the coordinate values after random processing;
[0025] According to the homomorphism of the Paillier algorithm, calculate the results after adjusting the order of the products obtained by multiplying the coordinate differences of the abscissa and the coordinate differences of the ordinate by different random numbers respectively;
[0026] According to the set error range, perform approximate quotient calculation on the results after adjusting the order of the products;
[0027] Send the result of the approximate quotient calculation to the second computing party.
[0028] Optionally, according to the quotient calculation result and the corresponding relationship between the coordinate values before and after random processing, the method for the second computing party to calculate the approximate slope of the two straight lines and send the approximate slope to the first computing party includes:
[0029] The second computing party uses the formula to calculate the approximate slope of the two straight lines, where k is the approximate slope, r 1 , r 2 are the random numbers multiplied by the coordinate differences of the abscissa and the coordinate differences of the ordinate respectively, w 0 , w 1 are the encrypted data before random processing respectively, w' 0 , w' 1 are the encrypted data after random processing respectively, D(w' 0 ), D(w' 1 ) are the decrypted data after random processing respectively, and ε is the approximate error limit;
[0030] Send the approximate slope to the first computing party.
[0031] A privacy data protection system, the system includes:
[0032] A definition module, used to define the two parties participating in privacy data protection as: the first computing party and the second computing party respectively based on the secure calculation method of the straight line passing through two points, where the data points of the first computing party correspond to the first coordinate, and the data points of the second computing party correspond to the second coordinate;
[0033] A data form conversion module, used to convert the first coordinate and the second coordinate into integers respectively;
[0034] A key generation module, which is set in the first computing party, is used to generate Paillier algorithm keys and send the corresponding public key to the second computing party;
[0035] A first coordinate sending module, which is set in the first computing party, is used to encrypt the first coordinate and send it to the second computing party;
[0036] An encryption module, which is set in the second computing party, is used to encrypt the second coordinate;
[0037] A random processing module, which is set in the second computing party, is used to calculate the coordinate difference between the first coordinate and the second coordinate on the ciphertext, perform random processing on the coordinate difference, and send the randomly processed coordinate value to the first computing party;
[0038] A decryption module, which is set in the first computing party, is used to decrypt the randomly processed coordinate value and perform approximate calculation to obtain the quotient, and then send it to the second computing party;
[0039] A slope calculation module, which is set in the second computing party, is used to calculate the approximate slope of the two lines according to the quotient result and the corresponding relationship between the coordinate values before and after random processing, and send the approximate slope to the first computing party;
[0040] A line determination module, which is used for both parties to determine the line passing through the coordinates of both parties according to the approximate slope and their respective data points.
[0041] Optionally, the random processing module includes:
[0042] A coordinate difference calculation unit, which is used to calculate the coordinate difference between the first coordinate and the second coordinate respectively according to the abscissa and ordinate on the ciphertext obtained after encryption. The coordinate difference includes: the coordinate difference of the abscissa and the coordinate difference of the ordinate;
[0043] A random number processing unit, which is used to multiply the coordinate difference of the abscissa and the coordinate difference of the ordinate by different random numbers respectively. Each random number contains multiple prime factors;
[0044] A confusion unit, which is used to confuse the numerator and denominator of the randomly processed coordinate value;
[0045] A sending unit, which is used to send the coordinate value with the numerator and denominator confused to the first computing party.
[0046] A data sending end for protecting privacy data. The data sending end is used for a secure calculation method based on a line passing through two points, and as one of the two parties participating in the protection of privacy data, the data point of the data sending end corresponds to the first coordinate. The data sending end includes:
[0047] A key generation module, which is used to generate Paillier algorithm keys and send the corresponding public key to the data receiving end;
[0048] The first coordinate sending module is used to encrypt the first coordinate and send it to the data receiving end;
[0049] The decryption module is used to decrypt the randomly processed coordinate value from the data receiving end, perform approximate calculation and division, and then send it to the data receiving end.
[0050] A data receiving end for privacy data protection, which is used based on the secure calculation method of a straight line passing through two points, and as the other party in the two parties participating in privacy data protection, the data points of the data receiving end correspond to the second coordinate. The data receiving end includes:
[0051] The encryption module is used to encrypt the second coordinate;
[0052] The random processing module is used to calculate the coordinate difference between the first coordinate and the second coordinate on the ciphertext, perform random processing on the coordinate difference, and send the randomly processed coordinate value to the data sending end;
[0053] The slope calculation module is used to calculate the approximate slope of the two straight lines according to the quotient result and the corresponding relationship between the coordinate values before and after random processing, and send the approximate slope to the data sending end.
[0054] A method for privately calculating the weighted average, which is used for calculating the average value of two-party privacy data. The method includes:
[0055] Define that the first calculating party has N 1 pieces of data, and the average value of N 1 pieces of data is a. The second calculating party has N 2 pieces of data, and the average value of N 2 pieces of data is b;
[0056] By multiplying by the same multiple, the first calculating party and the second calculating party respectively convert their respective relevant data into integers;
[0057] The first calculating party generates the Paillier algorithm key and sends the corresponding public key to the second calculating party;
[0058] The first calculating party encrypts its data quantity and the data converted into integers and sends them to the second calculating party;
[0059] The second calculating party encrypts its data quantity and the data converted into integers, calculates the sum of the data quantities of the first calculating party and the second calculating party and the sum of the data converted into integers on the ciphertext, performs random processing on the calculated sum of the data quantities and the sum of the data, and sends the randomly processed data to the first calculating party;
[0060] After decrypting the randomly processed data and performing approximate quotient calculation, the first computing party sends the result to the second computing party;
[0061] Based on the correspondence between the quotient result and the randomly processed data, the second computing party calculates the approximate average value of all the data and sends the approximate average value to the first computing party.
[0062] The technical solution provided by the embodiments of the present application may include the following beneficial effects:
[0063] The present application provides a privacy data protection method. This method is based on the secure calculation method of a straight line passing through two points. First, the first computing party and the second computing party are defined, and the coordinates of both parties are respectively converted into integers, which is convenient for calculation and helps improve the efficiency of data calculation. Then, the first computing party generates the Paillier algorithm key and sends the public key to the second computing party. Compared with the Elgaimal algorithm in the prior art, in this embodiment, the Paillier algorithm is used to replace the variant of the Elgaimal algorithm to implement additive homomorphic operation, making the decryption efficiency of privacy data higher, thus improving the data calculation efficiency. In this embodiment, the second computing party encrypts the second coordinate, calculates the coordinate difference between the first coordinate and the second coordinate on the ciphertext, and performs random processing on the coordinate difference, thereby effectively avoiding privacy leakage in the case where the numerator and denominator are relatively prime, which is beneficial to further improving the confidentiality of privacy data. Moreover, in this embodiment, the numerator and denominator of the randomly processed coordinate values are confused, which is beneficial to further improving the security of privacy data protection. In addition, when decrypting and performing approximate calculation to obtain the quotient on the randomly processed coordinate values, this approximate quotient calculation method can effectively prevent participants from guessing privacy data through reduction, which is beneficial to further improving the confidentiality of data.
[0064] The present application also provides a privacy data protection system, which mainly includes: a definition module, a data form conversion module, a key generation module, a first coordinate sending module, an encryption module, a random processing module, a decryption module, a slope calculation module, and a straight line determination module. By the definition module, the first computing party and the second computing party participating in privacy data protection are defined. By the data form conversion module, the first coordinate and the second coordinate are converted into integers. By the key generation module, the Paillier algorithm key is generated, thus effectively improving the subsequent decryption efficiency. Through the random processing module, the coordinate difference between the first coordinate and the second coordinate can be calculated on the ciphertext and random processing is performed on the coordinate difference, thereby preventing privacy leakage in the case where the numerator and denominator are relatively prime, which is beneficial to further improving the confidentiality of privacy data. In addition, in this embodiment, the numerator and denominator of the randomly processed coordinate values are also confused by the confusion unit in the random processing module, thereby further improving the confidentiality of privacy data.
[0065] The present application further provides a data sender for privacy data protection, which includes a key generation module, a first coordinate sending module, and a decryption module. The present application further provides a data receiver for privacy data protection, which includes an encryption module, a random processing module, and a slope calculation module. The key generation module in the data sender and the random processing module in the data receiver also have the corresponding technical effects of the above privacy data protection method and system, which will not be elaborated here.
[0066] The present application further provides a method for privately calculating a weighted average, which is equivalent to allocating weights in the ratio of N 1 , N2, and calculating the weighted average of two averages. By randomly processing the sum of the number of data and the sum of data of both parties, this method can effectively avoid privacy leakage in the case where the numerator and denominator are relatively prime, which is beneficial to further improving the confidentiality of privacy data. Moreover, this embodiment adopts an approximate quotient calculation method, which can effectively prevent participants from guessing privacy data through reduction, which is beneficial to further improving the confidentiality of data, so as to calculate the average value of all data without leaking data information.
[0067] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present application. BRIEF DESCRIPTION OF THE DRAWINGS
[0068] The accompanying drawings herein are incorporated into the specification and form a part of the specification, showing embodiments consistent with the present application, and are used together with the specification to explain the principles of the present application.
[0069] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the accompanying drawings required for the description of the embodiments or the prior art. Obviously, for those of ordinary skill in the art, other drawings can also be obtained based on these drawings without creative efforts.
[0070] Figure 1 It is a schematic flowchart of a privacy data protection method provided by an embodiment of the present application;
[0071] Figure 2 It is a schematic structural diagram of a privacy data protection system provided by an embodiment of the present application;
[0072] Figure 3 It is a schematic flowchart of a method for privately calculating a weighted average provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0073] To enable those skilled in the art to better understand the technical solutions in this application, the following will clearly and completely describe the technical solutions in the embodiments of this application in conjunction with the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in this application without creative efforts shall fall within the scope of protection of this application.
[0074] To better understand this application, the following will explain the implementation manners of this application in detail in conjunction with the accompanying drawings.
[0075] Embodiment 1
[0076] See Figure 1 , Figure 1 which is a schematic flowchart of a privacy data protection method provided by an embodiment of this application. As can be seen from Figure 1 , the privacy data protection method in this embodiment mainly includes the following processes:
[0077] S1: Based on the secure calculation method of a straight line passing through two points, define the two parties participating in privacy data protection as: the first calculation party and the second calculation party. The data points of the first calculation party correspond to the first coordinates, and the data points of the second calculation party correspond to the second coordinates.
[0078] This application belongs to a method for securely calculating a straight line passing through data points between two parties. When executing the method in this application, first define the two parties participating in privacy data protection.
[0079] S2: Convert the first coordinates and the second coordinates into integers respectively.
[0080] That is, multiply the coordinates of the data points of both parties by the same multiple to make them all converted into integers. Assume that the first coordinates are (x 1 , y 1 ), and the second coordinates are (x 2 , y 2 ). Multiply the first coordinates and the second coordinates by the same multiple to make them converted into integers, and correspondingly obtain (X 1 , Y 1 ) and (X 2 , Y 2 ). This method can convert them into integers while ensuring that the fraction size remains unchanged, which is beneficial for facilitating subsequent calculations.
[0081] S3: The first calculation party generates the Paillier algorithm key and sends the corresponding public key to the second calculation party.
[0082] First, introduce the Paillier algorithm:
[0083] (1) Key generation: Select two large prime numbers p and q, let n = pq, λ = lcm(p - 1, q - 1), and they satisfy gcd(λ, n) = 1. Select g such that gcd(L(g λ mod n 2 ), n) = 1, and take (n, g) as the public key and λ as the private key;
[0084] (2) Encryption: For any Select a random number The ciphertext is c = g m r n mod n 2 .
[0085] (3) Decryption: For The plaintext is Let E(m) denote the encryption of the plaintext m, and D(c) denote the decryption of the ciphertext c.
[0086] According to the additive homomorphism of the Paillier algorithm, for any, There is (E(m 1 )E(m 2 )) = m 1 + m 2 mod n, so, if There is also D(E(m 1 )E(m 2 )) = m 1 + m 2 .
[0087] Therefore, combining step S3, it can be seen that the first computing party generates the algorithm keys (n, g, λ), and sends the public key (n, g) to the second computing party.
[0088] S4: The first computing party encrypts the first coordinate and sends it to the second computing party.
[0089] The first computing party encrypts (X 1 , Y 1 ) to obtain E(X 1 ), E(Y 1 ) and sends them to the second computing party.
[0090] S5: The second computing party encrypts the second coordinate, calculates the coordinate difference between the first coordinate and the second coordinate on the ciphertext, randomly processes the coordinate difference, and sends the randomly processed coordinate value to the first computing party.
[0091] Specifically, step S5 includes the following process:
[0092] S51: The second computing party encrypts the second coordinate.
[0093] S52: Calculate the coordinate differences between the first coordinate and the second coordinate on the ciphertext obtained after encryption, respectively, according to the abscissa and the ordinate. The coordinate differences include: the abscissa coordinate difference and the ordinate coordinate difference.
[0094] The actual operation on the ciphertext in this embodiment is: the abscissa of the first computing party is multiplied by the inverse of the abscissa of the second computing party, and the ordinate of the first computing party is multiplied by the inverse of the ordinate of the second computing party.
[0095] S53: Multiply the abscissa coordinate difference and the ordinate coordinate difference by different random numbers respectively to obtain the randomly processed coordinate values. Each random number contains multiple prime factors.
[0096] Corresponding to "multiplying the abscissa coordinate difference and the ordinate coordinate difference by different random numbers respectively", the actual operation on the ciphertext in this embodiment is: the random power of the coordinate difference.
[0097] S55: Send the randomly processed coordinate values to the first computing party.
[0098] According to the above steps S51 - S54, the second computing party encrypts the data (X 2 , Y 2 ), to obtain E(X 2 ), E(Y 2 ), and calculates to obtain where r 1 , r 2 are random numbers containing multiple prime factors, and after confusing w 0 , w 1 , w' 0 , w' 1 is obtained and sent to the first computing party. The method of confusing w 0 , w 1 can specifically be the method of adjusting the order.
[0099] Furthermore, after step S53, step S54 is further included: confusing the numerator and denominator of the randomly processed coordinate values.
[0100] Then step S55 sends the coordinate values with the numerator and denominator confused to the first computing party.
[0101] Continue to refer to Figure 1 It can be known that after the second computing party sends the randomly processed coordinate values to the first computing party, step S6 is executed: the first computing party decrypts the randomly processed coordinate values and performs approximate calculation to find the quotient, and then sends it to the second computing party.
[0102] Specifically, step S6 includes the following process:
[0103] S61: The first computing party decrypts the randomly processed coordinate values.
[0104] S62: According to the homomorphism of the Paillier algorithm, calculate the results after adjusting the order of the products obtained by multiplying the coordinate differences of the abscissa and the coordinate differences of the ordinate by different random numbers respectively.
[0105] S62: According to the set error range, approximately calculate the quotient of the result after adjusting the order of the products.
[0106] S64: Send the result of the approximate quotient calculation to the second computing party.
[0107] As can be seen from the above steps S61 - S64, the first computing party decrypts w′ 0 , w′ 1 , and according to the homomorphism of the Paillier algorithm, the results after confusing r 1 (X 1 - X 2 ), r 2 (Y 1 - Y 2 ) can be obtained. Let them be D(w′ 0 ), D(w′ 1 ). According to the error requirement, select a smaller approximate error limit, calculate and then send it to the second computing party.
[0108] In this embodiment, by adding noise and using the method of approximate quotient calculation, it is very difficult for participants to restore to the original data form, thus effectively preventing participants from inferring private data through reduction, which is beneficial to improving data confidentiality. To balance data accuracy and data confidentiality, the approximate error limit in this embodiment can take a very small value ε = 10 -6 min{D(w′ 0 ), D(w′ 1 )}.
[0109] S7: According to the random numbers, the quotient results, and the corresponding relationship between the coordinate values before and after random processing, the second computing party calculates the approximate slope of the two lines and sends the approximate slope to the first computing party.
[0110] Specifically, step S7 includes the following process:
[0111] S71: The second computing party uses the formula to calculate the approximate slope of the two lines.
[0112] Among them, k is the approximate slope, r 1 , r 2 are random numbers, w 0 , w 1are the encrypted data before random processing, w' 0 , w' 1 are the encrypted data after random processing, D(w' 0 ), D(w' 1 ) are the decrypted data after random processing, and ε is the approximation error limit.
[0113] S72: Send the approximate slope to the first computing party.
[0114] S8: The two parties determine the straight line passing through the coordinates of the two parties according to the approximate slope and their respective data points.
[0115] Specifically, the first computing party and the second computing party combine the approximate slope k and their own data points to obtain the required straight line y = k(x - x i ) + y i , i = 1, 2.
[0116] As can be seen from the above method, the final result calculated by the method in the embodiment is an approximated decimal, and it is very difficult to restore the original rational form. Therefore, it is not feasible for the participants to directly infer the original data from the final result. For the first computing party, in addition to the final result slope k, all it obtains are the values of r 1 (x 1 - x 2 ), r 2 (y 1 - y 2 ) after being confused. Since the values of r 1 , r 2 are unknown, the first computing party cannot infer the values of x 1 - x 2 and y 1 - y 2 . Since the two random numbers selected by the second computing party both have multiple random factors, it is very difficult for the first computing party to determine whether x 1 - x 2 and y 1 - y 2 are relatively prime. Even if they are relatively prime, due to the confusion of the coordinate results, the first computing party does not know the corresponding relationship of the coordinates, and r 1 , r 2 both contain multiple random factors, so the values of x 1 - x 2 and y 1 - y 2 cannot be obtained, and thus the private data of the other party cannot be obtained. And for the second computing party, in addition to the final result, all the data it obtains are It also cannot infer the values of x 1 - x 2 and y 1-y 2 value, so it is impossible to obtain the other party's private data. Therefore, the method in this embodiment can effectively improve the confidentiality of data.
[0117] Embodiment 2
[0118] Based on the Figure 1 embodiment shown, refer to Figure 2 , Figure 2 which is a schematic structural diagram of a private data protection system provided by an embodiment of the present application. As Figure 2 can be seen, the private data protection system in this embodiment mainly includes: a definition module, a data form conversion module, a key generation module, a first coordinate sending module, an encryption module, a random processing module, a decryption module, a slope calculation module, and a straight line determination module.
[0119] Among them, the definition module is used to define the two parties participating in private data protection as: the first calculation party and the second calculation party based on the secure calculation method of a straight line passing through two points. The data point of the first calculation party corresponds to the first coordinate, and the data point of the second calculation party corresponds to the second coordinate. The data form conversion module is used to convert the first coordinate and the second coordinate into integers respectively. The key generation module is set in the first calculation party and is used to generate the Paillier algorithm key and send the corresponding public key to the second calculation party. The first coordinate sending module is set in the first calculation party and is used to encrypt and send the first coordinate to the second calculation party. The encryption module is set in the second calculation party and is used to encrypt the second coordinate. The random processing module is set in the second calculation party and is used to calculate the coordinate difference between the first coordinate and the second coordinate on the ciphertext, perform random processing on the coordinate difference, and send the randomly processed coordinate value to the first calculation party. The decryption module is set in the first calculation party and is used to decrypt the randomly processed coordinate value and perform approximate calculation to find the quotient, and then send it to the second calculation party. The slope calculation module is set in the second calculation party and is used to calculate the approximate slope of the two straight lines according to the random number, the quotient result, and the corresponding relationship between the coordinate values before and after random processing, and send the approximate slope to the first calculation party. The straight line determination module is used for the two parties to determine the straight line passing through the coordinates of the two parties according to the approximate slope and their respective data points.
[0120] Furthermore, the random processing module includes: a coordinate difference calculation unit, a random number processing unit, a confusion unit, and a sending unit. Among them, the coordinate difference calculation unit is used to calculate the coordinate differences between the first coordinate and the second coordinate on the ciphertext obtained after encryption according to the abscissa and ordinate respectively. The coordinate differences include: the coordinate difference of the abscissa and the coordinate difference of the ordinate; the random number processing unit is used to multiply the coordinate difference of the abscissa and the coordinate difference of the ordinate by different random numbers respectively, and each random number contains multiple prime factors; the confusion unit is used to confuse the numerator and denominator of the coordinate values after random processing; the sending unit is used to send the coordinate values with the numerator and denominator confused to the first computing party.
[0121] The decryption module includes: a decryption unit, an adjustment structure calculation unit, an approximation calculation unit, and a quotient result sending unit. Among them, the decryption unit is used to decrypt the coordinate values after random processing; the adjustment structure calculation unit is used to calculate the results after adjusting the order of the products obtained by multiplying the coordinate differences of the abscissa and the coordinate differences of the ordinate by different random numbers respectively according to the homomorphism of the Paillier algorithm; the approximation calculation unit is used to approximately calculate the quotient of the results after adjusting the order of the products according to the set error range; the quotient result sending unit is used to send the result of the approximate calculation of the quotient to the second computing party.
[0122] For the parts not described in detail in this embodiment, reference can be made to Figure 1 the embodiments shown, and the two embodiments can be referred to each other, which will not be elaborated here.
[0123] Embodiment III
[0124] The present application also provides a data sender for protecting privacy data. The data sender is used for the secure calculation method based on a straight line passing through two points and is used as one of the two parties participating in the protection of privacy data. The data points of the data sender correspond to the first coordinate. The data sender includes: a key generation module, a first coordinate sending module, and a decryption module. Among them, the key generation module is used to generate the Paillier algorithm key and send the corresponding public key to the data receiver; the first coordinate sending module is used to encrypt and send the first coordinate to the data receiver; the decryption module is used to decrypt the coordinate values after random processing from the data receiver, perform approximate calculation of the quotient, and then send it to the data receiver.
[0125] The working principle of the data sender in this embodiment has been elaborated in detail in Figure 1 and Figure 2 the embodiments shown, which will not be elaborated here.
[0126] Embodiment IV
[0127] The present application also provides a data receiver for privacy data protection, which is used for the secure calculation method based on the straight line passing through two points, and as the other party in the two parties participating in privacy data protection, the data points of the data receiver correspond to the second coordinates. The data receiver includes: an encryption module, a random processing module, and a slope calculation module. Among them, the encryption module is used to encrypt the second coordinates; the random processing module is used to calculate the coordinate difference between the first coordinate and the second coordinate on the ciphertext, perform random processing on the coordinate difference, and send the randomly processed coordinate values to the data sender; the slope calculation module is used to calculate the approximate slope of the two straight lines according to the random number, the quotient result, and the corresponding relationship between the coordinate values before and after random processing, and send the approximate slope to the data sender.
[0128] The working principle of the data receiver in this embodiment has been elaborated in detail in the embodiments shown in Figure 1 and Figure 2 and will not be elaborated here.
[0129] Embodiment Five
[0130] The present application also provides a method for privately calculating the weighted average. The method mainly includes the following processes:
[0131] S100: Define that the first calculating party has N 1 pieces of data, the average value of N 1 pieces of data is a, the second calculating party has N 2 pieces of data, and the average value of N 2 pieces of data is b.
[0132] S200: By multiplying by the same multiple, the first calculating party and the second calculating party respectively convert their respective relevant data into integers.
[0133] By multiplying by the same multiple s, the first calculating party converts aN 1 into an integer Y 1 , and the second calculating party converts bN 2 into an integer Y 2 .
[0134] S300: The first calculating party generates the Paillier algorithm key and sends the corresponding public key to the second calculating party.
[0135] The first calculating party generates the Paillier algorithm secret key (n, g, λ), and sends the public key (n, g) to the second calculating party.
[0136] S400: The first calculating party encrypts its data quantity and the data converted into integers and sends them to the second calculating party.
[0137] The first calculating party encrypts the data N 1 , Y1 , obtain E(N 1 ), E(Y 1 ), and send them to the second computing party.
[0138] S500: The second computing party encrypts the number of its data and the data converted into integers, and calculates the sum of the number of data of the first computing party and the number of data of the second computing party, as well as the sum of the data converted into integers, on the ciphertext, randomly processes the calculated sum of the number of data and the sum of the data, and sends the randomly processed data to the first computing party.
[0139] The second computing party encrypts the data N 2 , Y 2 , obtain E(N 2 ), E(Y 2 ), calculate to obtain where r 1 , r 2 is a random number containing multiple prime factors, and after confusing (adjusting the order) w 0 , w 1 , obtain w′ 0 , w′ 1 , and send them to the first computing party.
[0140] Furthermore, in this embodiment, the magnitudes of the random numbers r 1 , r 2 can be restricted. For example, they are restricted to: r 1 ≈ r 2 ·s·b, so that the magnitudes of the numerator and denominator obtained by decryption in step S600 can differ less, which is beneficial to improving the accuracy of the calculation result.
[0141] S600: The first computing party decrypts the randomly processed data and performs approximate quotient calculation, and then sends it to the second computing party.
[0142] The first computing party decrypts w′ 0 , w′ 1 . According to the homomorphism of the Paillier algorithm, the confused result of r 1 (N 1 +N 2 ), r 2 (Y 1 +Y 2 ) can be obtained. Let it be D(w′ 0 ), D(w′ 1 ). According to the set error requirement, select a smaller approximate error limit. A very small value ε can be selected. ε = 10 -6 min{D(w′ 0), D(w′ 1 )}, the calculated result is and then sent to the second computing party.
[0143] In this embodiment, by adding noise and using the method of approximate quotient calculation, it is very difficult for participants to restore to the original data form, thus effectively preventing participants from speculating on private data through reduction, which is beneficial to improving data confidentiality. To balance data accuracy and data confidentiality, the approximate error limit in this embodiment can take a very small value ε = 10 -6 min{D(w′ 0 ), D(w′ 1 )}.
[0144] S700: According to the corresponding relationship between the quotient result and the data after random processing, the second computing party calculates the approximate average value of all data and sends the approximate average value to the first computing party.
[0145] The second computing party passes through w 0 , w 1 and w′ 0 , w′ 1 corresponding relationship, and combined with r 1 , r 2 values, approximately calculates the average value k of all data, and sends the approximate average value k to the first computing party. The calculation method of the average value of all data in this embodiment is:
[0146] The method provided in this embodiment is equivalent to the secure calculation method of two-party weighted average. Its principle is the same as that of the Figure 1 embodiment shown, which is to obtain new values for the original data using different random numbers and confuse the new values, thereby improving data confidentiality. The main difference is that the final results obtained by the two are different. Correspondingly, Figure 1 the embodiment shown in
[0147] The above are only specific embodiments of the present application, enabling those skilled in the art to understand or implement the present application. Various modifications to these embodiments will be obvious to those skilled in the art. The general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application will not be limited to these embodiments shown herein, but will conform to the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A method for calculating the weighted average of privacy computing, characterized in that, The method is used for calculating the average value of private data of two parties, and weights are allocated according to the ratio of N 1 , N2, and the weighted average of the two average values is calculated. The method includes: Define that the first computing party has N 1 pieces of data, and the average value of the N 1 pieces of data is a. The second computing party has N 2 pieces of data, and the average value of the N 2 pieces of data is b; By multiplying by the same multiple, the first computing party and the second computing party respectively convert their respective relevant data into integers. Specifically, by multiplying by the same multiple s, the first computing party converts aN 1 into an integer Y 1 , and the second computing party converts bN 2 into an integer Y 2 ; the first computing party generates the Paillier algorithm key and sends the corresponding public key to the second computing party; specifically: the first computing party generates the Paillier algorithm secret key (n, g, λ), and sends the public key (n, g) to the second computing party; The first computing party encrypts the number of its data and the data converted into an integer and sends them to the second computing party; specifically: the first computing party encrypts the data N 1 ,Y 1 , to obtain E(N 1 ), E(Y 1 ), and sends them to the second computing party; The second computing party encrypts the number of its data and the data converted into integers, calculates the sum of the number of the first computing party's data and the number of the second computing party's data, and the sum of the data converted into integers on the ciphertext, randomly processes the calculated sum of the number of data and the sum of the data, and sends the randomly processed data to the first computing party; specifically: the second computing party encrypts the data N 2 ,Y 2 , to obtain E(N 2 ), E(Y 2 ), and calculates to obtain where r 1 , r 2 is a random number containing multiple prime factors, and after randomly adjusting the order of w 0 , w 1 , w' 0 , w' 1 is obtained and sent to the first computing party; After decrypting the randomly processed data and performing approximate quotient calculation, the first computing party sends it to the second computing party; specifically: the first computing party decrypts w' 0 , w' 1 , and according to the homomorphism of the Paillier algorithm, obtains the result after confusing r 1 (N 1 + N 2 ), r 2 (Y 1 + Y 2 ), and sets it as D(w' 0 ), D(w' 1 ). According to the set error requirement ε, calculates and sends it to the second computing party, where ε = 10 -6 min{D(w' 0 ), D(w' 1 )}; According to the correspondence between the quotient result and the data after random processing, the second computing party calculates the approximate average value of all the data and sends the approximate average value to the first computing party. Specifically, the second computing party passes through w 0 , w 1 and w' 0 , w' 1 correspondence, and combines with r 1 , r 2 values, approximately calculates the average value k of all the data, and sends the approximate average value k to the first computing party; the calculation method of the average value of all the data is:
Citation Information
Patent Citations
Multi-party security computing method and device, equipment and storage medium
CN112906044A