Methods for jointly computing data and apparatus for participating in jointly computing data

By using an improved SPDZ protocol and attribute encryption scheme based on ciphertext policy for preprocessing and data encryption on the blockchain, the problems of low computational efficiency and insufficient security in existing medical data sharing systems are solved, enabling fast and accurate medical data sharing and verification.

CN116136910BActive Publication Date: 2026-05-26TENCENT TECHNOLOGY (SHENZHEN) CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
TENCENT TECHNOLOGY (SHENZHEN) CO LTD
Filing Date
2021-11-17
Publication Date
2026-05-26

AI Technical Summary

Technical Problem

Existing secure multi-party computation schemes suffer from low computational efficiency and inaccurate results in medical data sharing, especially when there is malicious behavior from the participants. Schemes based on homomorphic encryption algorithms are highly complex, while schemes based on secret sharing cannot guarantee the correctness and security of the computation. Furthermore, existing blockchain-based medical data sharing systems cannot achieve patient-controlled data sharing and trusted verification of data queryers.

Method used

The improved SPDZ protocol is used for data preparation in the preprocessing stage under the blockchain architecture. The electronic medical records are encrypted using the ciphertext policy attribute encryption scheme (CP-ABE) and stored on the blockchain, so as to realize patient-controlled medical data sharing and trusted verification of data queryers.

Benefits of technology

With a fixed number of participants, the online calculation speed was greatly accelerated, ensuring the accuracy and security of the calculation results, and protecting patient privacy and ensuring the credibility of data queries.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116136910B_ABST
    Figure CN116136910B_ABST
Patent Text Reader

Abstract

This disclosure provides a method for jointly computing data, an apparatus for participating in jointly computing data, a computer-readable storage medium, and a computer program product. The method includes: a first participant in the joint computing calculating a random verification share value corresponding to itself and obtaining a random verification share value corresponding to a second participant in the joint computing; the first participant obtaining an input share value corresponding to itself and performing corresponding calculations on the input share value to obtain a secret share value corresponding to itself; and the first participant performing verification calculations on the secret share value or the input share value corresponding to itself, based on the random verification share value, to obtain a verification share value corresponding to itself. This disclosure allows for the preparation of large amounts of data in advance when the number of participants is relatively fixed, thus accelerating the speed of online computing.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the fields of Internet technology and computer data processing, and more specifically, to a method for jointly computing data, an apparatus for participating in jointly computing data, a computer-readable storage medium, and a computer program product. Background Technology

[0002] With the rapid development of the healthcare industry, medical and health data is increasing rapidly. However, medical and health data is highly private and valuable, and how to achieve privacy protection and sharing of medical data is a problem worthy of research. Solutions based on secure multi-party computation and blockchain technology have been proposed to address these issues.

[0003] Currently, there are two main types of secure multi-party computation (SMC) techniques: one based on homomorphic encryption algorithms and the other based on secret sharing. Homomorphic encryption-based SMCs are typically more complex, leading to lower efficiency. Secret-sharing-based SMCs rely on an honesty model, making it difficult to guarantee the correctness and security of the computation if the participants act maliciously. Therefore, improvements to existing secure SMC techniques are necessary.

[0004] Blockchain is a novel application model of computer technologies, including distributed data storage, peer-to-peer transmission, consensus mechanisms, and encryption algorithms. It is primarily used to organize data chronologically and encrypt it into a ledger, making it tamper-proof and forgery-proof. It also enables data verification, storage, and updating. Currently, due to its immutability, security, privacy, and authenticity, blockchain is suitable for the privacy protection and sharing of medical data. However, current blockchain-based medical data sharing systems cannot achieve patient-controlled sharing of medical data or trusted verification of medical data by data queryers. Therefore, improvements to existing blockchain-based medical data sharing systems are necessary. Summary of the Invention

[0005] To address the aforementioned problems, this disclosure provides a method for jointly computing data, an apparatus for participating in jointly computing data, a computer-readable storage medium, and a computer program product.

[0006] According to one aspect of the present disclosure, a method for jointly computing data is provided, comprising: a first participant in the joint computing calculating a random verification share value corresponding to the first participant and obtaining a random verification share value corresponding to a second participant in the joint computing; the first participant obtaining an input share value corresponding to the first participant and performing corresponding calculations on the input share value to obtain a secret share value corresponding to the first participant, wherein the secret share value corresponding to the first participant and the secret share value corresponding to the second participant together constitute a part of the calculation result of the joint computing; and the first participant performing a verification calculation on the secret share value or the input share value corresponding to the first participant based on the random verification share value corresponding to the first participant to obtain a verification share value corresponding to the first participant, wherein the verification share value corresponding to the first participant and the verification share value corresponding to the second participant together constitute a verification value for verifying a part of the calculation result.

[0007] For example, the method further includes: the first participant making a commitment based on the verification sharing value corresponding to the first participant to obtain a commitment value corresponding to the first participant; the first participant submitting the commitment value corresponding to the first participant to the blockchain of joint computation, wherein the commitment value is verified by each participant in the joint computation.

[0008] For example, obtaining the input sharing value corresponding to the first participant further includes: the first participant receiving a query request from the data querying party, and determining the input sharing value corresponding to each participant in the joint calculation based on the query request.

[0009] For example, the method further includes: one of the participants in the joint computation committing and encrypting the computation result based on the key of the data owner to obtain the committed value and encrypted value of the computation result; and one of the participants in the joint computation submitting the committed value and encrypted value of the computation result to the blockchain of the data querying party.

[0010] For example, the method further includes: in response to the data querying party having the key of the data owner, the data querying party decrypts the encrypted value of the calculation result to obtain the decrypted value of the calculation result; in response to the decrypted value of the calculation result being the same as the promised value, determining that the calculation result is correct.

[0011] For example, the data querying party is a server of a third-party organization, the participating parties in the joint computation are servers of a hospital, and the data owner is a user terminal.

[0012] For example, the first participant is transmitted with a random verification sharing value of the second participant based on an unintentional transmission protocol, and the random verification sharing value of the second participant is determined at least in part based on a first random value and a second random value randomly generated by the second participant.

[0013] For example, ∑[α] i ·[γ] i =∑[α·γ] i =α·γ, α=∑([α] i ), γ=∑([γ] i ), where i is a positive integer less than or equal to the number of participants in the joint computation, α is the first total random value for the joint computation, γ is the second total random value for the joint computation, and MAC(γ) i =[α·γ] i P, the first participant i The random verification shared value.

[0014] For example, each participant in the joint computation participates in calculating the sum of the first addend and the second addend. The input shared value includes a first additive component and a second additive component. Performing corresponding calculations on the input shared value further includes: calculating the sum of the first additive component and the second additive component, and disclosing the sum of the first additive component and the second additive component to the second participant in the joint computation as the secret shared value corresponding to the first participant. The verification calculation of the secret shared value corresponding to the first participant further includes: performing verification calculations on the first additive component to obtain a first addition verification shared value and performing verification calculations on the second additive component to obtain a second addition verification shared value, and calculating the sum of the first addition verification shared value and the second addition verification shared value as the verification shared value corresponding to the first participant.

[0015] For example, regarding the first participant P i The first additive component is [x]. i The second additive component is [y]. i The sum of the first additive component and the second additive component is [x]. i +[y] i The first addition checksum sharing value is MAC(x). i The second addition check sharing value is MAC(y). i Wherein, MAC(x) i = [α] i ·(x-γ)+MAC(γ) i ,MAC(y) i =[α] i ·(y-γ)+MAC(γ) ix is the first addend in the joint calculation, and y is the second addend in the joint calculation.

[0016] For example, the input shared value includes a first multiplication component and a second multiplication component, and the corresponding calculation of the input shared value further includes: performing multiplication calculation on the first multiplication component and the second multiplication component based on the multiplication triplet shared value generated and disclosed in advance by the first participant, wherein the multiplication triplet shared value includes a first random multiplication number, a second random multiplication number and a third random multiplication number.

[0017] For example, regarding the first participant P i The first random multiplication number is [a]. i The second random multiplication number is [b]. i The third random multiplication number is [c]. i , where, a=∑([a] i ),b=∑([b] i ),c=∑([c] i ), c = a·b, i is a positive integer less than or equal to the number of participants in the joint calculation, a is the first total random multiplication number of the joint calculation, b is the second total random multiplication number of the joint calculation, and c is the third total random multiplication number of the joint calculation.

[0018] For example, the participants in the joint computation calculate the product of a first multiplier and a second multiplier. The input shared value includes a first multiplicative component and a second multiplicative component. Performing corresponding calculations on the input shared value further includes: calculating a first multiplicative difference component based on a first random multiplication number and a first multiplicative component, and disclosing the first multiplicative difference component to a second participant in the joint computation; obtaining a second multiplicative difference component based on a second random multiplication number and a second multiplicative component, and disclosing the second multiplicative difference component to a second participant in the joint computation; calculating a first difference fraction and a second difference fraction based on the first multiplicative difference component, the second multiplicative difference component, and relevant data disclosed by each participant in the joint computation; obtaining a secret shared value corresponding to the first participant based on the first multiplicative difference fraction, the second multiplicative difference fraction, and the multiplicative triplet shared value, and disclosing the secret shared value corresponding to the first participant to a second participant in the joint computation.

[0019] For example, regarding the first participant P i The first multiplicative component is [k]. i The second multiplicative component is [l]. i The first multiplication difference component is [∈]. i =[k] i -[a] i The first difference is ∈ = ∑[∈] iThe second difference is δ = ∑[δ] i The second multiplication difference component is [δ]. i =[l] i -[b] i The secret sharing value corresponding to the first participant is [z]. i =[k·j] i =[c] i +∈·[b] i +δ·[a] i +∈·δ.

[0020] For example, the step of verifying and calculating the secret sharing value corresponding to the first participant to obtain the verification sharing value corresponding to the first participant further includes: calculating a secret value based on the secret sharing values ​​disclosed by each participant participating in the joint calculation, and calculating the verification sharing value corresponding to the first participant based on the secret value and the first random value.

[0021] For example, the method further includes: the first participant obtaining a commitment value corresponding to at least one participant from the jointly computed blockchain, and verifying the commitment value corresponding to the at least one participant.

[0022] For example, the method further includes: the first participant obtaining the verification share value corresponding to the other participants in the joint computation from the other participants; the first participant calculating the sum of the verification share values ​​corresponding to each participant in the joint computation, and determining the sum as the verification value of the computation result; and the first participant determining that the computation result of the joint computation is correct in response to the verification value of the computation result being zero.

[0023] According to one aspect of the present disclosure, an apparatus for participating in joint computation of data is provided, comprising: one or more processors; and one or more memories, wherein the memories store computer-readable code that, when executed by the one or more processors, causes the one or more processors to perform the method as described above.

[0024] According to another aspect of the present disclosure, a computer-readable storage medium is provided that stores computer-readable instructions thereon, which, when executed by a processor, cause the processor to perform the method as described in any of the foregoing aspects of the present disclosure.

[0025] According to another aspect of the present disclosure, a computer program product is provided, which includes computer-readable instructions that, when executed by a processor, cause the processor to perform the method as described in any of the foregoing aspects of the present disclosure.

[0026] The above-described aspects of this disclosure enable the sharing and / or multi-party computation of medical data based on a blockchain architecture. In some examples of this disclosure, for medical scenarios involving multi-party collaborative modeling, an improved SPDZ protocol is used, leveraging a relatively independent preprocessing stage to pre-prepare large amounts of data locally with a relatively fixed number of participants, significantly accelerating online computation. In some examples of this disclosure, these examples are combined with blockchain technology to ensure the accuracy of computation results even if most participants are dishonest. In some examples of this disclosure, electronic medical records are encrypted using a ciphertext-policy-based attribute encryption scheme (CP-ABE) and then stored on the blockchain, enabling patient-controlled medical data sharing and trusted medical data verification for data queryers. Attached Figure Description

[0027] The above and other objects, features, and advantages of the present disclosure will become more apparent from the more detailed description of the embodiments thereof in conjunction with the accompanying drawings. The drawings are provided to further illustrate the embodiments of the present disclosure and form part of the specification. They are used together with the embodiments of the present disclosure to explain the disclosure and do not constitute a limitation thereof. In the drawings, the same reference numerals generally represent the same components or steps.

[0028] Figure 1 A schematic diagram of an application scenario according to an embodiment of this disclosure is shown.

[0029] Figure 2A A schematic diagram of a method for jointly calculating data according to an embodiment of this disclosure is shown.

[0030] Figure 2B Another schematic diagram of a method for jointly calculating data according to an embodiment of the present disclosure is shown.

[0031] Figure 3 A flowchart of a method for jointly calculating data according to an embodiment of this disclosure is shown.

[0032] Figure 4 A schematic diagram illustrating the process of key exchange between a hospital, a patient, and an insurance company according to an embodiment of this disclosure is shown.

[0033] Figure 5 A schematic diagram of the architecture of an exemplary computing device according to an embodiment of the present disclosure is shown. Detailed Implementation

[0034] The technical solutions of the embodiments of this disclosure will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this disclosure. All other embodiments obtained by those skilled in the art based on the embodiments of this disclosure without creative effort are within the scope of protection of this disclosure.

[0035] Embodiments of this disclosure relate to cloud computing technology. Cloud computing is a computing model that distributes computing tasks (e.g., calculating user preferences for each of multiple options) across a resource pool consisting of a large number of computers, enabling various application systems to access computing power, storage space, and information services as needed. The network providing these resources is called the "cloud." Resources in the "cloud" appear to users to be infinitely scalable, readily available, on-demand, expandable, and payable only for usage.

[0036] This disclosure provides a method for jointly computing data, an apparatus for participating in jointly computing data, a computer-readable storage medium, and a computer program product.

[0037] First refer to Figure 1 This disclosure describes application scenarios of methods and apparatuses for jointly calculating data according to embodiments of the present disclosure. Figure 1 A schematic diagram of an application scenario 100 according to an embodiment of the present disclosure is shown, wherein a server 110 and a plurality of terminals 120 are schematically illustrated.

[0038] The method according to the embodiments of this disclosure can be implemented on server 110 to process data. Server 110 can be a standalone server for recording and calculating medical data, a server cluster or distributed system consisting of multiple physical servers, or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, location services, and big data and artificial intelligence platforms. This disclosure does not impose specific limitations in these areas.

[0039] As an example, server 110 can act as a participant in Secure Multi-Party Computation (SMC). Secure multi-party computation can be used to solve the problem of privacy-preserving collaborative computation among a group of mutually distrustful participants. It achieves input independence, computational correctness, and decentralization while ensuring that each participant's input values ​​are not leaked to other members participating in the computation. That is, secure multi-party computation can be used to address the problem of how to securely compute an agreed-upon function without a trusted third party, while requiring that each participant cannot obtain any input information from other entities except for the computation result. Currently, secure multi-party computation has been applied to scenarios such as electronic elections, electronic voting, electronic auctions, secret sharing, and threshold signatures. This disclosure primarily uses the sharing of medical-related data as an example for further explanation; those skilled in the art should understand that this disclosure is not limited to this.

[0040] Each of the multiple terminals 120 can be a fixed terminal such as a desktop computer, a mobile terminal with network capabilities such as a smartphone, tablet computer, portable computer, handheld device, personal digital assistant, smart wearable device, vehicle terminal, or any combination thereof; this disclosure does not impose specific limitations on this. Optionally, Figure 1 One or more of the multiple terminals 120 can be used by patients, doctors, researchers, and insurance company personnel.

[0041] In real-world scenarios, multiple parties are often involved, primarily hospitals, patients, and third-party organizations that require medical data, such as medical research institutions and health insurance companies. For example, in a scenario where a user applies for insurance, the insurance company needs to request relevant medical data from hospitals to gain a comprehensive understanding of the user's health. However, to protect user privacy, hospitals cannot directly provide the data to the insurance company, and users may have data stored at multiple hospitals, increasing the difficulty of the assessment. This disclosure utilizes subsequent references. Figures 2A to 3 The described secure multi-party computation system, integrated with blockchain, allows hospitals to collaboratively compute data while protecting their privacy. This computation assesses the health status of specific patients and ultimately provides an evaluation rating to an insurance company, without disclosing any user privacy. Although this disclosure uses medical data as an example, its applications are not limited to this. The examples in this disclosure are applicable to any application scenario that requires both the protection of user privacy (e.g., patient privacy) and multi-party collaborative computation, such as medical data sharing and collaborative risk control modeling of financial data.

[0042] As mentioned above, there are currently two main types of secure multi-party computation schemes: one is secure multi-party computation based on homomorphic encryption algorithms, and the other is secure multi-party computation based on secret sharing. A brief introduction to these two schemes follows.

[0043] For example, in secure multi-party computation schemes based on homomorphic encryption algorithms, each participant homomorphically encrypts the original data and then performs multi-party computation on the ciphertext to avoid leaking private data. Currently, to ensure data sharing without exposing users' private keys to queryers, homomorphic encryption algorithms require the use of proxy re-encryption for secret sharing. However, the computational complexity of such a design is linearly related to the number of participants; that is, as the number of participants increases, the computational complexity increases exponentially, significantly reducing online computation speed and efficiency.

[0044] For example, in a secure multi-party computation scheme based on secret sharing, each participant needs to break down each number into multiple parts and distribute these parts among the participants. Each participant possesses a portion of the original data, and one or a few participants may be unable to reconstruct the original data. In this scheme, only when a certain number of participants participate in the computation can the true data be restored. During computation, each participant only uses local data, and the results are distributed among the participants. When the final result is needed, some data is combined. This process ensures that each party only obtains some random numbers during the computation, but can ultimately calculate the desired result. However, this scheme requires all participants to be "honest." If a malicious participant is present, it will be difficult to obtain a correct and secure result.

[0045] To this end, this disclosure further improves the secure multi-party computation scheme, combining the advantages of blockchain with the secure multi-party computation scheme to realize multi-party computation of medical data within a blockchain architecture. In some examples of this disclosure, for medical scenarios involving multi-party collaborative modeling, an improved SPDZ protocol (pronounced "speedz," a multi-party collaborative computation protocol capable of defending against malicious attackers) is used. This utilizes a relatively independent preprocessing stage to pre-prepare large amounts of data locally when the number of participants is relatively fixed, significantly accelerating online computation. Furthermore, in some examples of this disclosure, electronic medical records are further encrypted using a ciphertext-policy-based attribute encryption scheme (CP-ABE), and then stored on the blockchain, achieving patient-controlled medical data sharing and trusted medical data verification for data users.

[0046] The following reference Figures 2A to 3 A method for jointly calculating data according to embodiments of this disclosure is described.

[0047] For example, Figure 2A A schematic diagram of a method 200 for jointly calculating data according to an embodiment of the present disclosure is shown. Figure 2B Another schematic diagram of a method 200 for jointly calculating data according to an embodiment of the present disclosure is shown. Figure 3 A flowchart of a method 200 for jointly calculating data according to an embodiment of this disclosure is shown.

[0048] See Figure 2A For example, method 200 can be used to perform joint calculations on a patient's Electronic Health Record (EHR), the result of which is, for example, the patient's health score. Due to the rapid development of the healthcare industry and the rapid increase in healthcare data, many medical institutions have adopted electronic health records to record patient medical data. Using EHRs offers many benefits, such as the ability to store EHR data on cloud servers for easy access by doctors. Sharing EHRs can further improve the accuracy of medical diagnoses, facilitate research in medical institutions, and promote the development of public healthcare. However, EHR data is complex, including images from imaging studies, written records of doctor consultations, prescription information, and more. Extracting a health score from an EHR is very complex and involves a large amount of computation.

[0049] For example, neural network models can be used to generate health scores from EHR data of various hospitals through machine learning. With the development of machine learning, various neural network models can be used to accomplish the aforementioned machine learning tasks, such as deep neural network (DNN) models, factorization machine (FM) models, and so on. These neural network models can be implemented as acyclic graphs, where neurons are arranged in different layers. Typically, a neural network model includes an input layer and an output layer, separated by at least one hidden layer. The hidden layer transforms the input received from the input layer into a representation useful for generating the output in the output layer. Network nodes are fully connected to nodes in adjacent layers via edges, and there are no edges between nodes within each layer. Data received at the nodes of the input layer of the neural network is propagated to the nodes of the output layer via any of the hidden layers, activation layers, pooling layers, convolutional layers, etc. The input and output of the neural network model can take various forms, and this disclosure does not limit them.

[0050] However, medical and health data (e.g., EHR data) is highly private and valuable. How to obtain the aforementioned health scores while ensuring the privacy of medical data is a problem worthy of research. This disclosure provides a good solution to this problem using blockchain and secure multi-party computation technology. This disclosure employs an improved SPDZ-based MPC protocol (described in detail below) and provides users with more accurate medical information. When a patient applies for insurance, the insurance company requests the hospital to inquire about the patient's health. The hospital calculates the health score and provides it back to the insurance company without disclosing the patient's privacy information.

[0051] refer to Figure 2A and Figure 2B In this document, the following description uses the example of a server belonging to a third-party organization (e.g., a medical research institution or a medical insurance company), the servers of hospitals as the participants in the joint computation, and the user terminal (e.g., a patient's or an insured person's user terminal) as the data querier. Those skilled in the art should understand that this disclosure is not limited thereto.

[0052] For example, see Figure 2B The insurance specialist wants to underwrite the patient's insurance information, so they send an underwriting request to the insurance company. Next, the insurance company, acting as the data querying party, sends a query request to the server of any of the participating hospitals. Each hospital's server can receive the query request from the data querying party, and then the servers 110 corresponding to each hospital will perform a joint calculation of the patient's health score in response to the query request.

[0053] For example, in some examples, the participants in the federated computation in Method 200 are all composed of hospital servers. Therefore, the number of participants is relatively fixed, and preprocessing of the blockchain and federated computation off-chain can be done in advance to prepare for the subsequent online computation.

[0054] As an example, the preprocessing step of method 200 includes S210, and the online computation steps include S220 and S230. Of course, this disclosure is not limited thereto.

[0055] As an example, in step S210 for preprocessing, the first participant in the joint computation calculates the random verification share value corresponding to the first participant and obtains the random verification share value corresponding to the second participant in the joint computation.

[0056] As an example, as mentioned above, in method 200, the participants in the joint computation can all be servers belonging to the hospital, thus the number of participants is relatively fixed. The first participant can be any of the participants in the joint computation and subsequently serve as the input party for the computation. Since the input party is necessarily honest, it is entitled to obtain the random verification share value corresponding to all other participants in the joint computation. That is, assuming there are N participants in the joint computation, then for any participant other than the first participant P... i Other participants P j (Where i is not equal to j), it needs to disclose its generated random verification sharing value to the first participant (as the input party). The first participant does not need to disclose its random verification sharing value to any participant.

[0057] Optionally, the first participant receives the second participant's random verification share value via an oblivious transfer protocol. This random verification share value is determined at least in part based on a first random value and a second random value randomly generated by the second participant. An oblivious transfer protocol is a cryptographic protocol in which the second participant sends a message from a list of pending messages to the first participant, but afterwards remains oblivious to which message was sent. This protocol is also called an unintentional transfer protocol. Of course, this disclosure does not restrict the interaction scheme between the first participant and other participants, as long as the first participant can obtain the second participant's random verification value.

[0058] For example, regarding the first participant P i The first random value is [α]. i The second random value is [γ]. i The first random value is [α]. i It is the first participant P i Randomly selected, and such that ∑[α] i · [γ] i =∑[α·γ] i =α·γ. Among them, α=∑([α] i ), γ=∑([γ] i Let α be a positive integer less than or equal to the number of participants N in the joint computation, γ be the first total random value for the joint computation, and γ be the second total random value for the joint computation. Knowing the first random value [α]... i And the second random value [γ] i Then, the solution for the first participant P can be obtained and made public. i The random verification sharing value MAC(γ) i =[α·γ] i .

[0059] As used in this article, the symbol [] for values ​​(e.g., [w]) i ) indicates that it is a participant P i For the portion of the total value w that is shared, [w] i Also known as participant P i The shared value. Participant P i Knowing its sharing value [w] i The overall value w cannot be known unless the participant knows the shared values ​​of all other participants. For example, randomly verifying the shared value MAC(γ). i This information can be known to each participant during the preprocessing stage. Thus, any participant can know the product of the first total random value and the second total random value, but they do not know the first and second random values ​​that are private to each participant.

[0060] Optionally, both the first and second random values ​​can be finite fields F. p A member of , where p is the modulus value. In some examples, the finite field F p Including p=2 n All integers in the range -1, where n is greater than zero. Other finite fields may be used in other examples, and this disclosure is not limited thereto. In the SPDZ protocol improved in this disclosure, each participant generates a random verification share value during the preprocessing phase and shares this random verification share value securely for verification calculation during the online computation phase.

[0061] Optionally, in step S210, each participant in the joint computation may also generate and publicly disclose a shared value for the multiplication triples. The shared value for the multiplication triples includes a first random multiplication number, a second random multiplication number, and a third random multiplication number.

[0062] Optionally, the first participant, as the input party, can also obtain the first random multiplication number, the second random multiplication number, and the third random multiplication number corresponding to the second participant from the second participant based on the unintentional transmission protocol.

[0063] For example, "shared value of a multiplication triple" refers to three values ​​([a]). i [b] i [c] i The set of ), where the first random multiplication number is [a]. i The second random multiplication number is [b]. i The third random multiplication number is [c]. i The first random multiplication number [a] i The second random multiplication number [b] i It is the first participant P iThe selection is random, and can result in c = a·b. Where a = ∑([a]) i ),b=∑([b] i ),c=∑([c] i Let i be a positive integer less than or equal to the number of participants in the joint computation, a be the first total random multiplication number, b be the second total random multiplication number, and c be the third total random multiplication number. Optionally, the three numbers in the shared value of the multiplication triple can also be finite fields F. p Members. In other examples, other finite fields may be used, and this disclosure is not limited thereto. In the SPDZ protocol improved in this disclosure, each participant generates a shared value of multiplication triples during the preprocessing phase and shares this shared value of multiplication triples in a secure manner for multi-party multiplication calculations during the online computation phase.

[0064] Therefore, in step S210 for preprocessing, the first participant knows the random verification share values ​​corresponding to each party participating in the joint computation. Optionally, the first participant also knows the multiplication triple share values ​​corresponding to each participant. Apart from the first participant as the input party, each participant in the joint computation only knows its corresponding random verification share value and, optionally, its multiplication triple share value. Simultaneously, each participant in the joint computation also knows its own first random value and second random value.

[0065] Next, in step S220 for online processing, the first participant obtains the input sharing value corresponding to the first participant and performs corresponding calculations on the input sharing value to obtain the secret sharing value corresponding to the first participant. The secret sharing value corresponding to the first participant and the secret sharing value corresponding to the second participant together constitute the calculation result of the joint calculation.

[0066] For example, as mentioned above, in Figure 2A In this scenario, an insurance specialist wants to underwrite a patient's insurance application, so they send an underwriting request to the insurance company. Next, the insurance company, acting as the data querying party, sends a query request to the server of any of the participating hospitals. The following assumes that the first participating party receives the query request from the data querying party, and then the servers 110 corresponding to each hospital will perform joint calculations of the patient's health score in response to the query request.

[0067] Next, the first participant receiving the query request will determine the input sharing values ​​corresponding to each participant in the joint computation based on the query request. In one example, to obtain the input sharing values, each participant also needs to obtain authorization for the input values ​​(e.g., the patient's EHR data). For example, servers 110-1 to 110-N corresponding to the hospitals participating in the joint computation can obtain authorization for their EHR data from the patient, who is the data owner. For example, as... Figure 2A As shown, the key-related number A is obtained from the patient. Alternatively, the participating parties in the joint computation can also obtain the key-related number C from the blockchain's public ledger to obtain the patient's authorization. This will be discussed later. Figure 4 This disclosure describes another detailed example of how hospitals can access patients’ optional shared privacy data. However, those skilled in the art will understand that there may be other implementations of this disclosure, and this disclosure does not impose any restrictions on the scheme by which participating parties obtain the data owner’s key.

[0068] In one example, the parties involved in the joint computation need to verify the patient data obtained by the first party. Suppose the first party obtains the input value x based on the patient's authorization. However, the first party is unsure whether the other parties involved in the joint computation are trustworthy, therefore, all parties need to participate in verifying the input value x.

[0069] Because in step S210, each participant P j They have already assigned their own second random number [γ]. j Send to the first participant P, who is the input party i Where j ≠ i and j ≤ N, j is an integer, and N is the total number of participants. At this point, the first participant P... i This allows us to know all the shared values ​​of the second total random number γ, thus reconstructing γ.

[0070] Next, the first participant, P i Its own share value relative to the input value x can be set to [x]. i = x - γ + [γ] i Then the other participating parties P j Its own share value relative to the input value x can be set to [x]. j =[γ] j First participant P i (x-γ) will be disclosed to the remaining parties. Afterwards, the first participant, P... i With other participants P in the joint computation j All will be targeted at themselves [x] i Or [x] j Generate a random verification sharing value MAC(x). iOr MAC(x) j For example, MAC(x) i =[α] i ·(x-γ)+MAC(γ) i MAC(x) j =[α] j ·(x-γ)+MAC(γ) j .

[0071] Participant P j The random verification share value MAC(x) generated from its share value for x. j Share with the first participant, P i Therefore P i This can be achieved by verifying MAC(x). i +∑MAC(x) j Whether MAC(x) equals α·x is used to determine if a malicious party is involved. For example, if MAC(x)... i + ∑MAC(x) j If MAC(x) = α·x, then all participants in the joint computation are trustworthy; otherwise, a malicious participant exists. Therefore, in this disclosure, MAC(x) and x are homomorphic / isomorphic. As used herein, the terms "homomorphic" and "isomorphic" refer to properties of cryptosystems in which mathematical operations can be applied to encrypted values ​​to produce encrypted results that match the results of performing the same operations on plaintext values, without revealing the content of the encrypted value or result to the computing device performing the operation.

[0072] As mentioned above, due to the aforementioned MAC(γ) j and MAC(γ) i All values ​​are generated during the preprocessing stage. In the online stage, only simple linear operations are needed to verify the input value x, which greatly speeds up the online calculation and can quickly determine whether there is a malicious party.

[0073] As mentioned above, obtaining a patient's health score likely involves the use of neural networks. The computation of neural network models requires a large number of addition and multiplication operations.

[0074] As an example of addition, suppose that the participants in the joint computation need to calculate the sum of the first addend and the second addend, and the input shared value includes the first additive component and the second additive component. Then, in step S220, performing the corresponding calculation on the input shared value may further include: calculating the sum of the first additive component and the second additive component, and disclosing the sum of the first additive component and the second additive component to the second participant in the joint computation as the secret shared value corresponding to the first participant.

[0075] For example, regarding the first participant P i The first additive component is [x]. i The second additive component is [y]. i The sum of the first additive component and the second additive component is [x]. i +[y] i The first participant, P i The corresponding secret sharing value is [z]. i =[x] i +[y] i Summarize the secret shared values ​​from all parties [z] i The result of the addition operation can be obtained. The secret shared value of any two participants can only be used as part of the result, thus ensuring the security and privacy of the calculation.

[0076] As an example of multiplication, suppose the participants in the joint computation calculate the product of a first multiplier k and a second multiplier l, and the input shared value includes the first multiplication component [k]. i Second-multiplication component [l] i .

[0077] Therefore, in step S220, for the first participant P i The step of performing the corresponding calculation on the input shared value may further include: based on a first random multiplication number [k] i And the first multiplicative component [a] i Calculate the first multiplication difference component [∈]. i =[k] i -[a] i The first multiplication difference component is disclosed to the second participant in the joint computation; based on the second random multiplication number and the second multiplication component, the second multiplication difference component [δ] is obtained. i =[l] i -[b] i The second multiplication difference component is disclosed to the second participant in the joint computation; based on the first multiplication difference component, the second multiplication difference component, and the relevant data disclosed by each participant in the joint computation, the first difference component ∈ = ∑[∈] is calculated. i The second difference fraction δ = ∑[δ] i Based on the first multiplication difference, the second multiplication difference, and the shared value of the multiplication triple, obtain the secret shared value [z] corresponding to the first participant. i =[k·j] i =[c] i +∈·[b] i +δ· [a] i+∈·δ, and disclose the secret shared value corresponding to the first participant to the second participant in the joint computation. Summarize the secret shared values ​​of all parties [z]. i The result of the multiplication operation can then be obtained. The secret shared value between any two participants can only be used as a part of the result, thus ensuring the security and privacy of the calculation.

[0078] Next, in step S230 for online processing, the first participant performs a verification calculation on the secret sharing value or input sharing value corresponding to the first participant based on the random verification sharing value corresponding to the first participant to obtain the verification sharing value corresponding to the first participant. The verification sharing value corresponding to the first participant and the verification sharing value corresponding to the second participant together constitute a verification value for verifying the calculation result.

[0079] For example, continuing with the above addition example, the verification calculation of the secret sharing value corresponding to the first participant further includes: performing verification calculation on the first addition component to obtain a first addition verification sharing value and performing verification calculation on the second addition component to obtain a second addition verification sharing value, and calculating the sum of the first addition verification sharing value and the second addition verification sharing value as the verification sharing value corresponding to the first participant.

[0080] For example, regarding the first participant P i The first additive component is [x]. i The second additive component is [y]. i The first addendum check share value MAC(x) of the first addendum component can be obtained by solving this problem. i =[α·x] i , and the second addition check sharing value MAC(y) of the second addition component. i =[α·y] i Therefore, the verification sharing value corresponding to the first participant is MAC(z). i =MAC(x) i +MAC(y) i If verification of the calculation results is required, the first participating party will disclose its corresponding verification sharing value, MAC(z). i Therefore, all parties involved in the joint calculation can calculate the verification value MAC(z) = ∑MAC(z) of the calculation result. i =α*(x+y)=α*z. Alternatively, the first participant, as the input party, can obtain the shared verification value MAC(z) from the other parties. j And we can calculate MAC(z) = ∑MAC(z). i=α*(x+y)=α*z. Since the first total random value α of the joint calculation is known to all parties involved in the joint calculation, any participating party can verify whether the calculation result is correct or whether there is a malicious party. The calculation result in the multiplication example can also be verified in a similar way, which will not be elaborated here.

[0081] For example, the calculation results can be verified using another example. For example, for the first participant P... i Step S230 may further include: based on the secret shared value [z] disclosed by each participating party in the joint computation. i Calculate the secret value z; then, based on the secret value z and the first random value [α], calculate the secret value z. i Calculate the first participant P i The corresponding verification sharing value check i =MAC(z) i -z·[α] i MAC(z) i The method for obtaining this can be found in the examples above, such as MAC(z). i =[α·z] i In this example, the first participant can continue to obtain the verification sharing value (check) corresponding to the other participants in the joint computation from the other participants. j The first participant calculates the sum of the verification sharing values ​​corresponding to each participant in the joint computation. i +∑(check j The sum is then determined as the verification value of the calculation result; the first participant, in response to the verification value of the calculation result being zero, determines that the calculation result of the joint calculation is correct.

[0082] Next, optionally, method 200 further includes step S240, which is used to submit the commitment values ​​of the parties to the blockchain public ledger to verify the calculation result. In step S240, the verification sharing value check corresponding to the first participant... i Make a commitment to obtain the commitment value corresponding to the first participant (commit(check)) i ), and submit the commitment value corresponding to the first participant to the jointly computed blockchain (commit (check)). i The commitment value will be verified by each of the participating parties in the joint calculation. Furthermore, for example, in step S240, the first participating party P... i Obtain at least one participant P from the jointly computed blockchain. j The corresponding commitment value is commit (check). j), and commit (check) the commitment value corresponding to the at least one participating party. j The verification of the commitment value can be performed using blockchain verification schemes well-known to those skilled in the art, and will not be elaborated upon here.

[0083] Next, optionally, continue to refer to Figure 2B After verifying the calculation results as described above, one of the multiple participants in the joint calculation (which could be the first participant P) can then perform the verification. i (This could be any participating party), based on the data owner's key (e.g., key-related number A), commits to and encrypts the computation result z to obtain the committed value and encrypted value of the computation result. The participating party can then continue to submit the committed value and encrypted value of the computation result to the data querying party's blockchain.

[0084] Then, in response to the data querying party (e.g., an insurance company) possessing the key of the data owner, the data querying party decrypts the encrypted value of the calculation result to obtain the decrypted value of the calculation result. If the decrypted value of the calculation result matches the promised value, the calculation result is determined to be correct. That is, patients can control whether to share their medical data with insurance companies, and insurance companies, as the data querying party, can also trust the calculation results (e.g., health scores) provided in the blockchain's public ledger.

[0085] Therefore, the above-mentioned aspects of this disclosure realize the sharing and / or multi-party computation of medical data based on a blockchain architecture. In some examples of this disclosure, for medical scenarios involving multi-party collaborative modeling, an improved SPDZ protocol is used, utilizing a relatively independent preprocessing stage to complete the preparation of large amounts of data locally in advance when the number of participants is relatively fixed, greatly accelerating the speed of online computation. Furthermore, this disclosure combines the improved SPDZ with blockchain to achieve a fast, resistant to (n-1) malicious parties, and user-controllable secure multi-party computation scheme. This scheme adopts linear secret sharing, and the various random verification sharing values ​​mentioned above can be used to detect whether the data has been altered. After the computation is completed, the correctness of the computation result can be guaranteed simply by verifying whether the verification value of the computation result is zero.

[0086] In another example disclosed herein, the patient can randomly generate a symmetric key k and provide it to the hospital. The hospital can package the hash value corresponding to the calculation result z and send it to the blockchain, then encrypt the calculation result using the symmetric key k and send it to the insurance company. The insurance company requests the key k from the patient, or, with the user's consent, decrypts the result z using the key k, hashes the result, compares it with the hash value on the blockchain, and accepts it if they match; otherwise, it discards it.

[0087] Furthermore, in some examples disclosed herein, electronic medical records can also be encrypted using a policy-based attribute encryption scheme (CP-ABE) and then stored on a blockchain, enabling patient-controlled medical data sharing and trusted medical data verification for data queryers.

[0088] See below Figure 4 The following description further illustrates an example process involving key exchange in this disclosure, and those skilled in the art should understand that this disclosure is not limited thereto.

[0089] Figure 4 This diagram illustrates the process of key exchange between a hospital, a patient, and an insurance company according to an embodiment of this disclosure. The hospital, patient, insurance company, blockchain public ledger, and data storage nodes together constitute the secret exchange system (hereinafter referred to as the system).

[0090] Let AA node be the CA (Certificate Authority) node on the consortium blockchain, representing a designated authority. AA node randomly generates the system's security parameters and outputs the system's public parameters and master key 'a'. The system's public parameters include two bilinear groups G and G'. T Let g be a generator of G, and let h1 and h2 be two hash functions. Let e ​​be the hash function of G × G → G. T As a bilinear mapping, the attribute set U is defined by the AA node, where for each x∈U, elements α, β, ... are randomly selected. Finally, the AA node publicly discloses the system's common parameters {G,G}. T ,e(g,g) α ,g β ,g a ,h1,h2}.

[0091] When a data user (e.g., an insurance company) needs to query data, the AA node assigns it a unique identifier uid and an attribute set Auid. The AA node randomly selects α1 and α2, where α = (α1 + α2) mod p, and sends the query to the data user. Send to data storage node

[0092] The data storage node stores the patient's encrypted data. Specifically, this data can be stored using the following scheme: The patient can randomly choose a symmetric key k to encrypt the data F into C. F = Enc k (F). Next, the patient needs to index the data F; for example, the patient's name can be selected as the index w. The patient defines an access strategy (M, ρ) to encrypt the symmetric key k and the index w. Here, M is an l×n matrix, and ρ maps each row of M to a specific attribute. A vector v = (s, y2, y3, ..., y...) is randomly selected. n )∈Z p , where s is the chosen secret. Calculate λ. i =M i ·v. CT={(M,ρ),C=e(g,g) αs ·k,C′=g s ,

[0093]

[0094] Next, the patient uploaded C,C′,Enc(F) to the cloud server. After receiving the information, the cloud server sent feedback to the data owner regarding the file storage location F. id The patient's reaction to F id Encrypt using the content key k to obtain Enc(F). location , will (B,C i ,C′ i ,Enc(F) location The transaction is stored in the blockchain public ledger, h(Enc(F)), packaged, its hash value is calculated, and then the transaction is signed and a verification request is submitted to the master node. The blockchain master node executes the consensus algorithm to verify the transaction.

[0095] When the insurance company needs to access the data, it needs to access each attribute 'a' in its attribute set. i Random selection calculate w′ is the keyword searched by the data user. The data user then sets (uid, T) i ,T′ i The data is uploaded to the blockchain. When a data user's search keyword w′ and their attribute set satisfy the access structure (M,ρ), the blockchain node will upload Enc(F). location Send B and the data user's account on the blockchain to the cloud server.

[0096] Data storage nodes use a private key for decryption. The data storage node sends A to the insurance company. The insurance company uses the private key SK.uid And A decrypts the symmetric key k, for Enc(F) location Decrypt to obtain the location of Enc(F), find Enc(F) in the data storage node, and then decrypt it with k to obtain the data file F.

[0097] Therefore, in some examples disclosed herein, electronic medical records are encrypted using a policy-based attribute encryption scheme (CP-ABE) and then stored on the blockchain, thereby enabling patient-controlled medical data sharing and trusted medical data verification for data users.

[0098] According to another aspect of this disclosure, this disclosure also provides an apparatus (such as a server) for participating in joint computation of data, comprising: one or more processors; and one or more memories, wherein the memories store computer-readable code that, when executed by the one or more processors, causes the one or more processors to perform the methods described above.

[0099] According to another aspect of this disclosure, a computing device is also provided that can be used as a terminal device or a server. For example... Figure 5 As shown, computing device 1100 may include a bus 1110, one or more CPUs 1120, read-only memory (ROM) 1130, random access memory (RAM) 1140, a communication port 1150 connected to a network, input / output components 1160, a hard disk 1170, etc. Storage devices in computing device 1100, such as ROM 1130 or hard disk 1170, may store various data or files used for computer processing and / or communication, as well as program instructions executed by the CPU. Computing device 1100 may also include a user interface 1180. Of course, Figure 5 The architecture shown is merely exemplary and can be omitted as needed when implementing different devices. Figure 5 One or more components in the computing device shown.

[0100] The embodiments of this disclosure can also be implemented as a computer-readable storage medium. A computer-readable storage medium according to embodiments of this disclosure stores computer-readable instructions. When the computer-readable instructions are executed by a processor, the recommendation information processing method and recommendation information sorting method according to embodiments of this disclosure, as described with reference to the above figures, can be performed. The computer-readable storage medium includes, but is not limited to, volatile memory and / or non-volatile memory. Volatile memory may include, for example, random access memory (RAM) and / or cache memory. Non-volatile memory may include, for example, read-only memory (ROM), hard disk, flash memory, etc.

[0101] According to embodiments of this disclosure, a computer program product or computer program is also provided, which includes computer-readable instructions stored in a computer-readable storage medium. A processor of a computer device can read the computer-readable instructions from the computer-readable storage medium and execute the computer-readable instructions, causing the computer device to perform the methods described in the various embodiments above.

[0102] According to another aspect of the embodiments of the present disclosure, a computer-readable storage medium is also provided, having stored thereon computer-readable instructions that, when executed by a processor, cause the processor to perform the method as described in any of the foregoing aspects of the present disclosure.

[0103] According to another aspect of the embodiments of the present disclosure, a computer program product is also provided, which includes computer-readable instructions that, when executed by a processor, cause the processor to perform the method as described in any of the foregoing aspects of the present disclosure.

[0104] Therefore, the above-mentioned aspects of this disclosure realize the sharing and / or multi-party computation of medical data based on a blockchain architecture. In some examples of this disclosure, for medical scenarios involving multi-party collaborative modeling, the improved SPDZ protocol is used, and a relatively independent preprocessing stage is employed to complete the preparation of large amounts of data locally in advance when the number of participants is relatively fixed, greatly accelerating the speed of online computation. In some examples of this disclosure, electronic medical records are encrypted using a ciphertext-policy-based attribute encryption scheme (CP-ABE), and then stored on the blockchain, achieving patient-controlled medical data sharing and trusted medical data verification for data queryers.

[0105] Those skilled in the art will understand that the contents disclosed herein can be varied and modified in many ways. For example, the various devices or components described above can be implemented in hardware, or in software, firmware, or a combination of some or all of the three.

[0106] Furthermore, as shown in this disclosure and the claims, unless the context clearly indicates otherwise, the words "a," "an," "an," and / or "the" are not specifically singular and may include plural forms. The terms "first," "second," and similar terms used in this disclosure do not indicate any order, quantity, or importance, but are merely used to distinguish different components. Similarly, the terms "comprising" or "including" and similar terms mean that the element or object preceding the word covers the element or object listed following the word and its equivalents, without excluding other elements or objects. The terms "connected" or "linked" and similar terms are not limited to physical or mechanical connections, but may include electrical connections, whether direct or indirect.

[0107] Furthermore, flowcharts are used in this disclosure to illustrate the operations performed by the system according to embodiments of this disclosure. It should be understood that the preceding or following operations are not necessarily performed in exact order. Instead, various steps can be processed in reverse order or simultaneously. Additionally, other operations can be superimposed on these processes, or one or more steps can be removed from these processes.

[0108] Unless otherwise defined, all terms used herein (including technical and scientific terms) shall have the same meaning as commonly understood by one of ordinary skill in the art to which this disclosure pertains. It should also be understood that terms such as those defined in a common dictionary shall be interpreted as having a meaning consistent with their meaning in the context of the relevant art, and not as having an idealized or highly formalized meaning, unless expressly defined herein.

[0109] The present disclosure has been described in detail above; however, it will be apparent to those skilled in the art that the present disclosure is not limited to the embodiments described herein. The present disclosure can be implemented in modified and altered ways without departing from the spirit and scope defined by the claims. Therefore, the description herein is for illustrative purposes only and is not intended to be restrictive.

Claims

1. A method for jointly computing data, comprising: The first participant in the joint computation calculates the random verification sharing value corresponding to the first participant and obtains the random verification sharing value corresponding to the second participant in the joint computation. The first participant obtains the input sharing value corresponding to the first participant, and performs corresponding calculations on the input sharing value to obtain the secret sharing value corresponding to the first participant. The secret sharing value corresponding to the first participant and the secret sharing value corresponding to the second participant together constitute the calculation result of the joint calculation. The first participant performs a verification calculation on the secret sharing value or input sharing value corresponding to the first participant based on the random verification sharing value corresponding to the first participant to obtain the verification sharing value corresponding to the first participant. The verification sharing value corresponding to the first participant and the verification sharing value corresponding to the second participant together constitute a verification value used to verify the calculation result.

2. The method as described in claim 1, wherein, The method further includes: The commitment value corresponding to the first participant is obtained by making a commitment based on the verification sharing value corresponding to the first participant. The first participant submits its commitment value to the blockchain for joint computation, wherein the commitment value is verified by each participant in the joint computation.

3. The method as described in claim 1, wherein, The step of obtaining the input sharing value corresponding to the first participant further includes: the first participant receiving a query request from the data querying party, and determining the input sharing value corresponding to each participant in the joint calculation based on the query request.

4. The method of claim 3, wherein, The method further includes: One of the participants in the joint computation, based on the key of the data owner, commits to and encrypts the computation result to obtain the committed value and encrypted value of the computation result; One of the multiple participants in the joint computation submits a commitment value and a cryptographic value of the computation result to the blockchain of the data querying party.

5. The method of claim 4, wherein, The method further includes: In response to the data querying party having the key of the data owner, the data querying party decrypts the encrypted value of the calculation result to obtain the decrypted value of the calculation result; If the decrypted value and the committed value of the calculation result are the same, the calculation result is determined to be correct.

6. The method as described in any one of claims 3-5, wherein, The data querying party is a server of a third-party organization, the participating parties in the joint calculation are the servers of the hospital, and the data owner is the user terminal.

7. The method of claim 1, wherein, The first participant acquires the random verification sharing value of the second participant by transmitting it via an unintentional transmission protocol. The random verification sharing value of the second participant is determined at least in part based on a first random value and a second random value randomly generated by the second participant.

8. The method of claim 1, wherein, For the first participant P i The first random value is [α]. i The second random value is [γ]. i , where ∑[α] i ·[γ] i =∑[α·γ] i =α·γ, α=∑([α] i ), γ=∑([γ] i ), where i is a positive integer less than or equal to the number of participants in the joint computation, α is the first total random value for the joint computation, γ is the second total random value for the joint computation, and MAC(γ) i =[α·γ] i P, the first participant i The random verification shared value.

9. The method of claim 8, wherein, The participants in the joint computation calculate the sum of the first addend and the second addend, and the input shared value includes the first additive component and the second additive component. The step of performing the corresponding calculation on the input shared value also includes: Calculate the sum of the first additive component and the second additive component, and disclose the sum of the first additive component and the second additive component to the second participant participating in the joint calculation as the secret shared value corresponding to the first participant; The step of verifying and calculating the secret sharing value corresponding to the first participant also includes: A verification calculation is performed on the first additive component to obtain a first additive verification share value, and a verification calculation is performed on the second additive component to obtain a second additive verification share value. The sum of the first addition check share value and the second addition check share value is calculated as the check share value corresponding to the first participant.

10. The method of claim 9, wherein, For the first participant P i The first additive component is [x]. i The second additive component is [y]. i The sum of the first additive component and the second additive component is [x]. i +[y] i The first addition checksum sharing value is MAC(x). i The second addition check sharing value is MAC(y). i , where MAC(x) i =[α] i ·(x-γ)+MAC(γ) i MAC(y) i =[α] i ·(y-γ)+MAC(γ) i x is the first addend in the joint calculation, and y is the second addend in the joint calculation.

11. The method of claim 1, wherein, The input shared value includes a first multiplication component and a second multiplication component, and the corresponding calculation on the input shared value further includes: Based on the shared value of the multiplication triplet generated and disclosed in advance by the first participant, multiplication is performed on the first multiplication component and the second multiplication component. The shared value of the multiplication triplet includes a first random multiplication number, a second random multiplication number, and a third random multiplication number.

12. The method of claim 11, wherein, For the first participant P i The first random multiplication number is [a]. i The second random multiplication number is [b]. i The third random multiplication number is [c]. i , Among them, a=∑([a] i ), b=∑([b] i ), c = ∑([c] i ), c = a·b, i is a positive integer less than or equal to the number of participants in the joint calculation, a is the first total random multiplication number of the joint calculation, b is the second total random multiplication number of the joint calculation, and c is the third total random multiplication number of the joint calculation.

13. The method of claim 12, wherein, The participants in the joint computation calculate the product of the first multiplier and the second multiplier. The input shared value includes a first multiplicative component and a second multiplicative component. Performing corresponding calculations on the input shared value further includes: Based on the first random multiplication number and the first multiplication component, the first multiplication difference component is calculated, and the first multiplication difference component is disclosed to the second participant in the joint computation. Based on the second random multiplication number and the second multiplication component, the second multiplication difference component is obtained and disclosed to the second participant in the joint computation. Based on the first multiplication difference component, the second multiplication difference component, and the relevant data disclosed by each participating party in the joint calculation, the first difference fraction and the second difference fraction are calculated; Based on the first multiplication difference, the second multiplication difference, and the shared value of the multiplication triple, the secret shared value corresponding to the first participant is obtained, and the secret shared value corresponding to the first participant is disclosed to the second participant participating in the joint computation.

14. The method of claim 13, wherein, For the first participant P i The first multiplicative component is [k]. i The second multiplicative component is [l]. i The first multiplication difference component is [∈]. i =[k] i -[a] i The first difference is ∈ = ∑[∈] i The second difference is δ = ∑[δ] i The second multiplication difference component is [δ]. i =[l] i -[b] i The secret sharing value corresponding to the first participant is [z]. i =[k·j] i =[c] i +∈·[b] i +δ·[a] i +∈·δ.

15. The method of claim 1, wherein, The step of verifying and calculating the secret sharing value corresponding to the first participant to obtain the verification sharing value corresponding to the first participant also includes: The secret value is calculated based on the shared secret values ​​disclosed by each participating party in the joint computation. Based on the secret value and the first random value, calculate the verification sharing value corresponding to the first participant.

16. The method of claim 2, wherein, The method further includes: The first participant obtains the commitment value corresponding to at least one participant from the jointly computed blockchain and verifies the commitment value corresponding to the at least one participant.

17. The method of claim 1, wherein, The method further includes: The first participant obtains the verification sharing value corresponding to the other participants in the joint calculation. The first participant calculates the sum of the verification sharing values ​​corresponding to each participant in the joint calculation, and determines the sum as the verification value of the calculation result; The first participant determines that the joint calculation result is correct in response to the verification value of the calculation result being zero.

18. An apparatus for participating in joint computation of data, comprising: One or more processors; as well as One or more memories, wherein computer-readable code is stored in the memories, which, when executed by the one or more processors, causes the one or more processors to perform the method as described in any one of claims 1-17.

19. A computer-readable storage medium having stored thereon computer-readable instructions, which, when executed by a processor, cause the processor to perform the method as described in any one of claims 1-17.

20. A computer program product comprising computer-readable instructions that, when executed by a processor, cause the processor to perform the method as described in any one of claims 1-17.