Hidden MSB Standardization System, Distributed Processing Device, Hidden MSB Standardization Method, and Computer Program Product

By performing bit decomposition and shifting of vectors through the dispersed processing device in the hidden MSB standardization system, the alignment of MSBs in secret calculation is achieved, the problem of degradation of accuracy in the prior art is solved, and the calculation efficiency and accuracy are improved.

CN116324933BActive Publication Date: 2025-06-27NIPPON TELEGRAPH & TELEPHONE CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202080106069.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-10-16
Publication Date
2025-06-27
Estimated Expiration
2040-10-16

AI Technical Summary

Technical Problem

In secret computing, in order to improve computing efficiency, product sum operations need to be processed in parallel, but the prior art is difficult to normalize and align the highest bits (MSBs) while maintaining accuracy.

Method used

Through the hidden MSB standardization system, the bit decomposition unit, logic or acquisition unit, shift amount acquisition unit and shift unit in the dispersed processing device can be used to shift the MSB of the data with the largest absolute value in the elements contained in the vector and the predetermined bit position, so that the entire vector is shifted together, thereby realizing MSB alignment.

Benefits of technology

The MSB alignment is achieved while maintaining accuracy, improving the efficiency and accuracy of secret calculations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116324933B_ABST
    Figure CN116324933B_ABST
Patent Text Reader

Abstract

The hidden MSB normalization system includes n distributed processing devices. The n distributed processing devices respectively include a bit decomposition unit, a logical OR acquisition unit, a shift amount acquisition unit, and a shift unit. The n bit decomposition units perform bit decomposition on the vector → a]] P after (k,n)-secret sharing, to obtain the bit representation → a]] P of the vector → a]] 2^L . For the vectors → a]] 2^L at each bit position of the bit representation → a i , the n logical OR acquisition units obtain the logical OR of all elements [[A i 2 . The n shift amount acquisition units perform (k,n)-replicated secret sharing on the shift amount ρ used to shift the highest bit of the logical OR [[A0]] 2 ,…,[[A L‑1 2 to a fixed position modulo p, and obtain the shares <<ρ>> p after (k,n)-replicated secret sharing. The n shift units obtain the vector [[2 → a]] P obtained by shifting each element of the vector ρ→ a]] p to the left by ρ bits.​​
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a technique for aligning the most significant bit (hereinafter also referred to as "MSB" (Most Significant Bit)) with a predetermined bit position in secret computing (hereinafter also referred to as "MSB alignment"). Background Art

[0002] In plaintext, the product-sum operation is to repeatedly perform addition, but in secret computing based on secret sharing, in order to improve the computing efficiency, parallel processing is required (refer to Non-Patent Documents 1 and 2). In addition, considering the accuracy, the operations for sum and product-sum need to be particularly configured.

[0003] Prior Art Documents

[0004] Non-Patent Documents

[0005] Non-Patent Document 1: Takashi Nishide, Takuwa Amada, "Multi-Party Computation for Reducing Communication Volume in Floating-Point Arithmetic", Transactions of the Information Processing Society of Japan, Vol. 60, No. 9, pp. 1433-1447, 2019.

[0006] Non-Patent Document 2: Randmets, J., "Programming Languages for Secure Multiparty Computation Application Development", PhD thesis. University of Tartu. 2017. Summary of the Invention

[0007] Problems to be Solved by the Invention

[0008] Since the output of the product-sum is a high bit, it is desired to suppress the MSB to be constant at the input time point. However, if a simple right shift is performed, there is a problem that the precision decreases due to a small reduction in the number of input bits.

[0009] An object of the present invention is to provide a concealed MSB normalization system, a distributed processing device, a concealed MSB normalization method, and a program, which can perform MSB alignment while maintaining the accuracy by shifting the MSB (referred to as vector MSB) of the data with the largest absolute value among the elements included in the vector to align with a predetermined bit position, and shifting the entire vector (referred to as vector MSB normalization).

[0010] Means for Solving the Problems

[0011] To solve the above problems, according to one aspect of the present invention, the hidden MSB normalization system includes n distributed processing devices. The n distributed processing devices each include a bit decomposition unit, a logical OR acquisition unit, a shift amount acquisition unit, and a shift unit. The n bit decomposition units perform bit decomposition on the vector → a]] P after (k,n)-secret sharing to obtain the bit representation → a]] P of the vector → a]] 2^L . The n logical OR acquisition units obtain the logical OR [[A → a]] 2^L of all elements for the vectors → a i at each bit position of the bit representation i 2 . The n shift amount acquisition units perform (k,n)-replicated secret sharing on the shift amount ρ used to shift the most significant bit of the logical OR [[A0]] 2 ,…,[[A L-1 2 to a fixed position with the modulus p, and obtain the (k,n)-replicated secret shared share <<ρ>> p . The n shift units obtain the vector [[2 → a]] P obtained by shifting each element of the vector ρ→ a]] p to the left by ρ bits.

[0012] To solve the above problems, according to another aspect of the present invention, the distributed processing device is included in the hidden MSB normalization system. The distributed processing device includes: a bit decomposition unit that, together with (n - 1) distributed processing devices, performs bit decomposition on the vector → a]] P after (k,n)-secret sharing to obtain the bit representation → a]] P of the vector → a]] 2^L ; a logical OR acquisition unit that, together with (n - 1) distributed processing devices, obtains the logical OR [[A → a]] 2^L of all elements for the vectors → a i at each bit position of the bit representation i 2 ; a shift amount acquisition unit that, together with (n - 1) distributed processing devices, uses the modulus p to perform (k,n)-replicated secret sharing on the shift amount used to shift the most significant bit of the logical OR [[A0]] 2 ​​​,…,[[A L-1 2 Perform (k,n)-replicated secret sharing with the shift amount ρ that shifts the most significant bit of 2 to a fixed position, and obtain the shares after (k,n)-replicated secret sharing <<ρ>> p ; and a shift unit, together with (n-1) dispersion processing devices, obtain a vector → a]] P such that each element of [[2 ρ→ a]] p .

[0013] Effects of the Invention

[0014] According to the present invention, there is an effect that MSB alignment can be performed while maintaining accuracy. Description of the Drawings

[0015] Figure 1 is a diagram showing a structural example of the stealth MSB normalization system according to the first, second, and third embodiments.

[0016] Figure 2 is a diagram showing an example of the processing flow of the stealth MSB normalization system according to the first embodiment.

[0017] Figure 3 is a functional block diagram of the dispersion processing device according to the first embodiment.

[0018] Figure 4 is a diagram showing an example of the processing flow of the stealth MSB normalization system according to the second embodiment.

[0019] Figure 5 is a functional block diagram of the dispersion processing device according to the second embodiment.

[0020] Figure 6 is a diagram showing an example of the processing flow of the stealth MSB normalization system according to the third embodiment.

[0021] Figure 7 is a functional block diagram of the dispersion processing device according to the third embodiment.

[0022] Figure 8 A diagram showing the results of a prototype experiment.

[0023] Figure 9 is a diagram showing a structural example of a computer to which this method is applied. Detailed Embodiments

[0024] ​Hereinafter, embodiments of the present invention will be described. It should be noted that in the drawings used in the following description, structural units having the same function and steps performing the same processing are denoted by the same reference numerals, and redundant description is omitted. In the following description, notations such as " → " etc. should originally be recorded directly above the character immediately following, but due to limitations in the text recording method, they are recorded immediately in front of the character. In the formula, these notations are described in their original positions. In addition, processing performed on a per-element basis of vectors and matrices applies to all elements of the vector and matrix unless otherwise specified.

[0025] <First Embodiment>

[0026] First, the recording method in this embodiment will be described.

[0027] <Recording Method>

[0028] ◎k: Threshold of secret sharing. For example, it is set to 2.

[0029] ◎n: Number of shares of secret sharing, in other words, the number of parties (parties) for secret calculation. For example, it is set to 3.

[0030] ◎P: Prime number. In this embodiment, assume the Mersenne prime number 2 61 -1 to achieve efficient processing.

[0031] ◎p: Number of digits of P. When P is a Mersenne prime number, it is still a prime number and is 61.

[0032] ◎Q: Number of digits of the residue ring. It means the general number of digits including P, p, and the number of digits of the exponent part for floating point (floating decimal point). When considering the share of the exponent part for floating point, it is specifically assumed to be 2 13 -1.

[0033] ◎L: Maximum bit length of the data stored. Assume it is less than p.

[0034] ◎λ: Maximum bit length of the exponent part stored. Assume it is 10 or less.

[0035] ◎[[x]] y : Share obtained by performing (k,n)-secret sharing on the element x modulo y.

[0036] ◎ <x> y : The share after (k, k)-additive secret sharing of the element x modulo y.

[0037] ◎< <x>> y : The share after (k,n)-duplicate secret sharing of the mod y element x. It should be noted that since it is (k,n)-secret sharing, it can be applied to [[x]] y The protocol for the form of the share is also applicable to this share. In the case of this notation method, it especially means that the property of duplicate secret sharing is utilized.

[0038] ◎[[x]] 2^m : The share obtained by arranging m shares of the form [[x]] 2 . It can also be regarded as the bit representation of a numerical value. It should be noted that in the subscript, A^B represents A B , and A_B represents A B .

[0039] ◎ρ○ → a: The vector obtained by rotating the vector → a by ρ. Since rotation is both a numerical value and a permutation, it is distinguished from the multiplication ρ → a for each element.

[0040] ◎x≈y: x and y are equal as real numbers on a computer. That is, the difference is within a certain error range.

[0041] ◎a / d: Integer division operation with truncation after the decimal point. In particular, integer division operation under powers of 2 is equal to right shift.

[0042] [Mathematical formula 1]

[0043] ◎ Real number division operation

[0044] ◎{Proposition}: It is 1 if the proposition holds and 0 if it does not hold.

[0045] Next, the two secret sharings, (k,n)-secret sharing and (k,k)-additive secret sharing, used in this embodiment will be described.

[0046] <(k,n)-secret sharing>

[0047] (k,n)-secret sharing refers to the following security technology: The input plaintext is divided into n segments (called shares) and distributed to n different entities (called parties) respectively. As long as any k of the shares are collected, the plaintext can be restored, and if less than k - 1 shares are obtained, no information about the plaintext can be obtained. For example, there are Shamir's secret sharing, duplicate secret sharing, etc. In this embodiment, it will be distributed by (k,n)-secret sharing, and the group obtained by collecting all the shares with the plaintext being a certain value x (also called the (k,n)-secret sharing value) is expressed as [[x]]. For each share, the share of party r is expressed as [[x]] y r Here, let r = 0, …, n - 1. Since the secret share values are usually distributed among multiple parties, no one holds them, which are hypothetical. Additionally, the column of (k, n)-secret share values, i.e., the column of the plaintext, is expressed as → the list of x as → x]].

[0048] <(k, k)-Additive Secret Sharing>

[0049] (k, k)-Secret Sharing means the case where n = k in (k, n)-Secret Sharing. It cannot be restored unless all the shares of all parties are collected. The (k, k)-Secret Sharing based on replicated secret sharing is specifically called additive secret sharing, which is the simplest method to restore the plaintext by simply adding k shares. In this embodiment, under the modulus y, (k, k)-additive secret sharing is used for distribution, and the group after collecting all the shares of the plaintext being a certain value x (also called (k, k)-additive secret share value) is expressed as <x> y , the share of Party r is expressed as <x> y r In addition, the columns that are (k, k)-additive secret-shared values and the columns of the plaintext are → The list of x is expressed as < → x> P .

[0050] First, several protocols used in the hidden MSB normalization system according to the first embodiment will be described.

[0051] <Multiplication Rotation Protocol>

[0052] Input: Numeral shares [[a]] after (k, n)-secret sharing p , the shares <<ρ>> after replicating and secret-sharing the rotation amount ρ p

[0053] Output: Shares [[2 ρ a P

[0054] Process: Use the numeral shares [[a]] p and the shares <<ρ>> p , and obtain the shares [[2 ρ a after (k, n)-secret sharing of the value 2 obtained by rotating the value a by ρ bits ρ a P . In this example, let k = 2 and n = 3. Hereinafter, the details of the process will be described.

[0055] 1: Round 1

[0056] 2: Convert the numeral shares [[a]] p to (k, k)-additive secret-shared shares p 。In this example, Party 0 and Party 1 hold shares p The conversion from (k,n)-secret sharing to (k,k)-additive secret sharing can be carried out by well-known techniques. For example, refer to Reference 1.

[0057] (Reference 1) Kikuchi, R., Ikarashi, D., Matsuda, T., Hamada, K. and Chida, K., "Efficient Bit-Decomposition and Modulus-Conversion Protocols with an Honest Majority”, Information Security and Privacy - 23rd Australasian Conference, ACISP 2018, Wollongong, NSW, Australia, July 11 - 13, 2018, Proceedings (Susilo, W. and Yang, G., eds.), Lecture Notes in Computer Science, Vol. 10946, Springer, pp. 64 - 82 (online).

[0058] 3: Party 0 and Party 1 share a random number r 01 , Party 1 and Party 2 share r 12 . It should be noted that the random number can be generated by one of the parties that can generate the shared random number and transmitted to the other party, or generated by a third party and transmitted to the corresponding party, or shared using tokens, etc.

[0059] 4: Party 0 calculates

[0060] [Mathematical formula 2]

[0061]

[0062] and sends it to Party 2.

[0063] 5: Party 1 calculates

[0064] [Mathematical formula 3]

[0065]

[0066] and sends it to Party 0.

[0067] 6: Round 2

[0068] 7: Party 0 calculates

[0069] [Mathematical formula 4]

[0070]

[0071] 8: Square 2 calculation

[0072] [Mathematical formula 5]

[0073]

[0074] 9: Round 3

[0075] 10: Shares after (k, k)-additive secret sharing <c> P Convert to shares of (k,n)-secret sharing [[c]] P and output. Here, c = 2 ρ a holds. The conversion from (k,k)-additive secret sharing to (k,n)-secret sharing can be performed by known techniques. For example, refer to Reference 1.

[0076] <Flag column → Numerical share conversion protocol>

[0077] Input: Bit share vector of length p → f]] 2 . Among them, there is only one 1 in → f.

[0078] Output: Mod p share [[b]] of the position of the 1 existing in → f P

[0079] Process: Using the bit share vector → f]] 2 , obtain the shares [[2 → a]] after (k,n)-secret sharing of the position b of the 1 existing in ρ f P . Hereinafter, the details of the process will be described.

[0080] 1: Generate shares

[0081] <<ρ>> p after (k,n)-duplicate secret sharing of the uniform random number ρ modulo p.

[0082] 2: Calculate the public value ρο → f through the public value output rotation protocol. It should be noted that since ρ is a uniform random number, → f is determined to be 1 only at one place, so ρο → f is a uniform random number on the rotation representing the numerical value as the bit position, and is secure even if made public. The so-called public value output rotation protocol is a protocol that takes as input the vector → a]] of shares after (k,n)-secret sharing and the shares <<ρ>> Q of the rotation amount ρ after (k,n)-duplicate secret sharing, and obtains ρο → a (public value) obtained by rotating the vector → a by ρ, and can be implemented by known techniques. For example, the random permutation space of the public value output random permutation protocol in Reference 2 can be restricted to random rotations.

[0083] (Reference 2) Ohashi Igarashi, Hiroki Hamada, Ryosuke Kikuchi, Koji Chida, "Improvement of Secret Computation Radix Sort Aimed at Statistical Processing of Internet Environment Response in 1 Second", SCIS2014 The 31st Symposium on Cryptography and Information Security.

[0084] 3: Obtain ρ ○ → Set the position of 1 in f as b'. Relative to the original position of 1, b' = b + ρ.

[0085] 4: Calculate < > p = b'- <<ρ>> p and output it.

[0086] It should be noted that when the length of the input bit share vector → f]] 2 is shorter than p, this protocol can also be applied by padding [[0]] 2 at the high-order bits.

[0087] Hereinafter, the vector MSB normalization implemented in this embodiment will be described.

[0088] <Vector MSB Normalization Protocol>

[0089] Input: Vector of shares → a]] P

[0090] Parameters: Maximum number of bits L of the input, vector length m

[0091] Output: [[2 ρ→ a]] P , <<ρ>> p , where the vector MSB of 2 ρ→ a is the (L - 1)-th bit.

[0092] Processing: Shift the entire vector → a]] P so that the MSB (vector MSB) of the data with the largest absolute value among the elements included in the vector → a]] P is aligned with a fixed position (here it is the (L - 1)-th bit), and obtain the shifted vector [[2 ρ→ a]] P and the shift amount <<ρ>> p . Hereinafter, the details of the processing will be described.

[0093] 1: Obtain the bit representation → a]] P of → a]] 2^L through bit decomposition. Bit decomposition can be performed by known techniques. For example, refer to Reference 1.

[0094] 2: For each bit position 0 ≤ i < L of → a]] 2^L , take the OR of all elements. Let the s-th element of → a i 2 be a → a's s ​, s=0,1,…,m-1,[[a s ]]'s bit representation is set to [[a s ]] 2^L , will [[a s ]] 2^L The share of the ith bit position of is set to [[(a i ) s ]] 2 , then the vector [[ → a i ]]=([[(a i )0]] 2 ,…,

[0095] [[(a i ) m-1 ]] 2 ), the resulting logical or is: [[A i ]] 2 :=[[(a i )0]] 2 OR…OR[[(a i ) m-1 ]] 2 .

[0096] 3-1: 0≤i <L-1下归纳设为:[[f i ]] 2 :=[[f i+1 ∨A i ]] 2 . In which, let [[f L-1 ]] 2 :=[[A L-1 ]] 2 So far, the bit represents f = (f L-1, f L-2 ,…,f0) becomes a format where 01 is arranged with the MSB as the boundary, such as 0,0,0,1,1,…,1.

[0097] 3-2: Set up to pL [[1]] 2 Insert the low order bit, set to ([[f'0]] 2 ,…[[f' L'-1 ]] 2 ):=([[1]] 2 ,…,[[1]] 2 ,[[f0]] 2 ,…[[f L-1 ]] 2 ). L' is the [[1]] that will be inserted into L 2 The number after adding the number of . Through this processing, → The position of the MSB can also be defined when all elements of a are 0.

[0098] 3-3: For 0 ≦ i < L'-1, let [[x i 2 := [[f' i xor f' i+1 2 . Among them, [[x L'-1 2 := [[A L-1 2 . So far, the bit representation x = (x L'-1, x L'-2 , …, x0) becomes a flag where only the MSB position becomes 1, such as 0, 0, 0, 1, 0, …, 0.

[0099] 4: According to the above <Flag Column → Numerical Share Conversion Protocol>, convert [[x L'-1 2 , [[x L'-2 2 , …, [[x0]] 2 into <<ρ>> p . Note that it is in descending order.

[0100] 5: Through the above <Multiplication Rotation>, according to the vector of shares → a]] P and the replicated secret - shared shares <<ρ>> p of the rotation amount, calculate the (k, n) - secret - shared shares [[2 ρ→ a]] P and output. In addition, the multiplication rotation can also be performed by other known techniques.

[0101] Next, a vector MSB normalization system for implementing the above vector MSB normalization will be described.

[0102] <Vector MSB Normalization System Related to the First Embodiment>

[0103] ​​​​​​ < / c> Figure 1 Shows a structural example of the vector MSB normalization system 1 according to the first embodiment, Figure 2 and shows an example of the processing flow of the vector MSB normalization system 1.

[0104] The vector MSB normalization system 1 includes n distributed processing devices 100-r. Here, n is one of the integers of 3 or more, and r = 0, 1,..., n-1. The n distributed processing devices 100-r can communicate with each other via the communication line 2.

[0105] The vector MSB normalization system 1 takes the modulus P of the vector → each element a of s after (k, n)-secret sharing [[a s P as the vector → a]] P as input, performs vector MSB normalization, and obtains the vector [[2 ρ→ a]] P and the shift amount <<ρ>> p and outputs. The maximum bit length L of the share [[a s P and the vector length m of the vector → a]] P are used as parameters.

[0106] The distributed processing device is, for example, a special device configured by reading a special program in a known or dedicated computer having a central processing unit (CPU: Central Processing Unit), a main storage device (RAM: Random Access Memory), etc. The distributed processing device executes each process under the control of the central processing unit, for example. The data input to the distributed processing device or the data obtained in each process is stored in the main storage device, for example, and the data stored in the main storage device is read out to the central processing unit for other processes as needed. At least a part of each processing unit of the distributed processing device may be composed of hardware such as an integrated circuit. Each storage unit included in the distributed processing device can be composed of a main storage device such as a random access memory (RAM: Random Access Memory), or middleware such as a relational database or a key-value memory, for example. In addition, each storage unit does not necessarily need to be provided inside the distributed processing device, and may be configured to be composed of an auxiliary storage device composed of semiconductor storage elements such as a hard disk, an optical disk, or a flash memory (Flash Memory), and provided outside the distributed processing device.

[0107] <Distributed processing device 100-r> ​​

[0108] Figure 3 An example of a functional block diagram of the distributed processing device 100-r.

[0109] The distributed processing device 100-r includes a bit decomposition unit 101, a logical OR acquisition unit 103, a shift amount acquisition unit 105, and a shift unit 107.

[0110] Hereinafter, Figure 2 the processing of each part will be described.

[0111] <Bit decomposition unit 101>

[0112] n bit decomposition units 101 receive the vector of the shares after (k, n)-secret sharing → a]] P ,

[0113] and obtain the bit representation of the vector → a]] P through bit decomposition → a]] 2^L (S101).

[0114] <Logical OR acquisition unit 103>

[0115] n logical OR acquisition units 103 receive the bit representation → a]] 2^L , and for each bit position 0 ≤ i < L of the vector → a i , obtain the logical OR of all elements [[A i 2 . Among them, let the s-th element of the vector → a be a s , s = 0, 1,..., m - 1, [[a s 's bit representation be [[a s 2^L , [[a s 2^L 's share at the i-th bit position be [[(a i )s]] 2 , then the vector → a i = ([[(a i )0]] 2 ,..., [[(a i ) m-1 2 ), and the obtained logical OR is: [[A i 2 := [[(a i )0]]​​​​​ 2 OR…OR[[(a i ) m-1 2 。

[0116] <Shift amount acquisition unit 105>

[0117] n shift amount acquisition units 105 receive the logical OR [[A i 2 (0 ≤ i < L), and taking the maximum number of bits L ≤ p - 1 as a parameter, find the shift amount <<ρ>> → A]] 2 =([[A0]] 2 ,…,[[A L-1 2 ) to shift the MSB to a fixed position (s105). p (s105).

[0118] For example, find the shift amount <<ρ>> as follows p 。

[0119] First, set the n shift amount acquisition units 105 to [[f L-1 2 :=[[A L-1 2 , and inductively set it to [[f i 2 :=[[f i+1 ∨A i 2 in the case of 0 ≤ i < L - 1. Through this process, the bit representation f = (f L-1, f L-2 ,…,f0) becomes a form arranged with 01 with the MSB as the boundary, such as 0,0,0,1,1,…,1.

[0120] Next, set the n shift amount acquisition units 105 to [[x L-1 2 :=[[A L-1 2 , and set it to [[x i 2 :=[[f i xor f i+1 2 in the case of 0 ≦ i < L - 1. Through this process, the bit representation x = (x L-1, x L-2 ,…,x0) becomes a flag with only the MSB position being 1, such as 0,0,0,1,0,…,0.

[0121] ​​​​​​​​​​​Finally, n shift amount acquisition units 105 convert the column of length p [[x L-1 2 , [[x L-2 2 , …, [[x0]] 2 , [[1]] 2 , …, [[1]] 2 into <<ρ>> p .

[0122] <Shift unit 107>

[0123] The n shift units 107 receive → a]] P and <<ρ>> p , and find the vector [[2 → a]] P whose elements are left-shifted by ρ bits (S107) and output it. For example, according to the above <Multiplication rotation>, based on the vector ρ→ a]] p of shares and the shares <<ρ>> → a]] P of the replicated secret dispersion of the rotation amount, find the shares [[2 p after (k, n)-secret dispersion ρ a P .

[0124] <Effect>

[0125] With such a structure, MSB alignment can be performed while maintaining the accuracy.

[0126] <Second Embodiment>

[0127] The description will be centered on the parts different from the first embodiment.

[0128] In the second embodiment, the fixed-point vector product and using vector MSB normalization in the first embodiment will be described. First, several protocols used in the fixed-point vector product and in the second embodiment will be described.

[0129] <Shift amount hiding left and right shift protocol>

[0130] Input: Numerical share [[a]] p , share <<ρ>> Q of the left shift amount that can be positive or negative,

[0131] Parameter: The upper limit M max ​​​, the maximum MSB position M allowed by the share lim

[0132] Output: the value of ρ after s right shifts P

[0133] 1: First, set u := M lim -M max +1,

[0134] [Mathematical formula 6]

[0135]

[0136] . u is the size of the range of right shift amounts that can be covered by the hidden right shift with a single shift amount (covering 0 to (M lim -M max ))), and d is the number of times of hidden right shift required for right shifting in the range of 1 to (M max -1) bits. When the right shift amount is less than or equal to 0, left shift can be performed. When the right shift amount is M max or more, the output is always 0.

[0137] 2: Calculate <<ρ>> by using the modulus conversion of quotient shift p . The modulus conversion of quotient shift can be performed by a well-known technique. For example, refer to Reference 1.

[0138] 3: Calculate by size comparison

[0139] [[f0]] 2 := [[{ρ ≥ -M max +1}]] 2 ,

[0140] [[f1]] 2 := [[{ρ ≥ -M max +1+u}]] 2 ,…,

[0141] [[f d-1 2 := [[{ρ ≥ -M max +1+(d-1)u}]] 2 ,

[0142] [[f L 2 := [[{ρ ≥ 0}]] 2

[0143] . Here, note that f L 、f d-1 、f d-2 ​​, … are transitive signs.

[0144] 4: Through the mod 2 → mod p conversion, according to [[f1]] 2 , [[f2]] 2 , …, [[f d-1 2 , [[f L calculate < <f1> > p 、< <f2>> p ,..., <<f d-1 >> p , <<f L >> p 。Among them, < <f0>> p In addition, the mod 2 → mod p conversion can be performed by known techniques. For example, refer to Reference 1.

[0145] 5: Calculate <<ρ'>> p := <<ρ>> p + M max - 1 - uΣ 1≦i<d <<f i >> p + ((d - 1)u - M max + 1) <<f L >> p .

[0146] 6: Use [[a]] p and <<ρ'>> p , and calculate [[b]] according to the <Multiplication Rotation Protocol> P := [[2ρ'a]] P . In addition, as the multiplication rotation protocol, known techniques can also be used.

[0147] 7: Calculate by publicly disclosing the right shift amount in batches

[0148] [[c0]] P := [[2 ρ 'a / 2 M _ (max)-1 P ,

[0149] [[c1]] P := [[2 ρ 'a / (2 M _ (max)-1-u )]] P , …,

[0150] [[c d-1 P := [[2 ρ 'a / (2 M _ (max)-1-(d-1)u )]] P .

[0151] 8: Calculate [[f0]], [[f1]], …, [[f P , [[f1]] P , …, [[f d-1 P , [[f L P . Here, [[f0]] is required P .​​​​

[0152] 9: Calculate by product sum

[0153] [[s]] := [[c0]] P [[f0]] P + ([[c1]] - [[c0]]) P [[f1]] P + … + ([[c d-1 - [[c d-2 ) P [[f d-1 P + ([[b]] P - [[c d-1 P )[[f L P

[0154] And output. Note that this formula is for the selection gate of the transitional flag.

[0155] Next, the fixed-point (fixed decimal point) vector product sum implemented in this embodiment will be described.

[0156] <Fixed-point vector product sum protocol>

[0157] Input: Fixed-point number vector → a]] P , → b]] P

[0158] Parameter: Vector length m

[0159] Output: [[c]] P , where Σ 0≦i<m a i b i ≈ c

[0160] 1: Through the vector MSB normalization protocol of the first embodiment, normalize the fixed-point number vectors → a]] P , → b]] P respectively to obtain the vectors with adjusted MSB positions and shift amounts, ( → 2 ρ _ a→ a]] P , << ρ a >> p ), ([2 ρ _ b→ b]] P ​​​, <<ρ b >> p )。

[0161] 2: According to <<ρ a >> p , <<ρ b >> p , through the mod p → mod Q conversion, we get [[ρ a Q , [[ρ b Q . In addition, the mod p → mod Q conversion can be carried out by known techniques. For example, using Reference 1. In addition, modulus conversions other than Reference 1 can also be used. For example, the technique of Reference 1 needs to satisfy the condition of a vacant position of a predetermined number of digits (hereinafter also referred to as the condition of quotient transfer), but modulus conversions that do not satisfy the condition of quotient transfer can also be used. Hereinafter, the modulus conversion that does not satisfy the condition of quotient transfer will be described.

[0162] <Non-quotient-transfer modular conversion protocol>

[0163] Input: The share [[a]] after (k, n)-secret sharing p

[0164] Parameter: The number of digits |p| of p

[0165] Output: The share [[a]] after (k, n)-secret sharing with a different modulus Q Q

[0166] 2-1: Convert the share [[a]] p into the share after (k, k)-additive secret sharing p Let k = 2, and parties p0 and p1 hold shares p The conversion from (k, n)-secret sharing to (k, k)-additive secret sharing can be carried out by well-known techniques. For example, using Reference 1.

[0167] 2-2: Party p0 calculates a'0 := by addition over Z without performing mod p p 0 + (2 |p| - p), perform (k, n)-secret sharing on each bit of a'0 to obtain the shares [[a'0]] in bit representation 2^|p| . Bit decomposition can be carried out by well-known techniques. For example, utilize Reference 1.

[0168] 2 - 3: Party p1 pairs p Perform secret sharing on each bit (k, n) of 1 to obtain the share in bit representation [[a1]] 2^|p| .

[0169] 2 - 4: Obtain the share [[a'0+a1]] of the bit representation of a'0 + a1 through the addition circuit 2^(|p|+1) . Here, after the addition circuit calculation, the bit length increases by 1 from p to p + 1.

[0170] 2 - 5: Set the most significant bit of [[a'0+a1]] 2^(|p|+1) to [[q]] 2 . q is the share p The quotient, which is expressed as 0+ q when 1 = a + qp.

[0171] 2-6: Through the mod 2 → mod Q conversion, according to [[q]] 2 obtain [[q]] Q . For example, the mod 2 → mod Q conversion can be performed by known techniques. For example, using Reference 1.

[0172] 2-7: The squares p0, p1 are respectively based on p 0、 p 1 obtained p 0 modulo Q, p 1 mod Q, denoted as <a'> Q . Here, a' = a + qp mod Q holds.

[0173] 2-8: Convert the share <a'>Q after (k,k)-secret sharing to (k,n)-secret sharing to obtain the share [[a']] after (k,n)-secret sharing Q . The conversion from (k,k)-additive secret sharing to (k,n)-secret sharing can be performed by a well-known technique. For example, refer to Reference 1.

[0174] 2-9: Calculate [[a]] Q = [[a']] Q - p[[q]] Q Calculate and output.

[0175] For example, when p = 61, in order to leave a blank space, the value can only be taken up to 31. Therefore, it can be considered that there are many cases where the mod p → mod Q conversion does not satisfy the condition of using quotient transfer at this time. Therefore, it is best to use a non-quotient transfer modulus conversion protocol.

[0176] 3: Calculate [[c]] P := [[Σ 0≦i<m 2 ρ _ a a i 2 ρ _ b b i P .

[0177] 4: Calculate [[-ρ a -ρ b Q , and obtain <<-ρ a -ρ b >> Q .

[0178] 5: According to the above <shift amount hiding left and right shift protocol>, use <<-ρ a -ρ b >> Q to shift [[c]] P , and output the value after shifting [[c]] P by (-ρ a -ρ b ) bits.

[0179] Next, a vector MSB normalization system for implementing the above <fixed-point vector product sum protocol> will be described.

[0180] <Vector MSB normalization system according to the second embodiment>

[0181] Figure 1 represents an example of the structure of the vector MSB normalization system 1 related to the second embodiment, Figure 4 represents an example of the processing flow of the vector MSB normalization system 1.

[0182] The vector MSB normalization system 1 inputs two fixed-point vectors → a]] P , → b]] P , calculates the product sum [[c]] of the elements P and outputs it. Where Σ​​ 0≦i<m a i b i ≈c. The vector → a]] P , → b]] P sets the vector length m of as a parameter.

[0183] <Dispersion processing device 100-r>

[0184] Figure 5 An example of a functional block diagram representing the dispersion processing device 100-r.

[0185] In addition to the bit decomposition unit 101, the logical OR acquisition unit 103, the shift amount acquisition unit 105, and the shift unit 107, the dispersion processing device 100-r further includes an analog-to-digital conversion unit 109, a product-sum calculation unit 111, a secret dispersion conversion unit 113, and a shift amount hiding left-right shift unit 115.

[0186] Hereinafter, Figure 4 the processing of each part will be described.

[0187] Regarding S101 to S107, as described in the first embodiment. The vector MSB normalization system 1 sets the fixed-point vectors → a]] P , → b]] P as inputs, performs vector MSB normalization, and obtains the vector and shift amount after vector MSB normalization ( → 2 ρ _ a→ a]] P , <<ρ a >> p ), ([[2 ρ _ b→ b]] P , <<ρ b >> p ). The processing after S109 will be described.

[0188] <Analog-to-digital conversion unit 109>

[0189] n analog-to-digital conversion units 109 receive ( → 2 ρ _ a→ a]] P , <<ρ a >> p ), ([[2 ρ _ b→ b]] P , <<ρ b >> p ), according to <<ρ a >> p , <<ρ b >> p Through the mod p → mod Q conversion, obtain [[ρ a Q , [[ρ b Q (S109).

[0190] <Product - sum calculation unit 111>

[0191] n product - sum calculation units 111 receive the shares → 2 ρ _ a→ a]] P and ([[:2 ρ _ b→ b]] P to calculate the product - sum [[c]] P : = [[Σ 0≦i<m 2 ρ _ a a i 2 ρ _ b b i P (S111).

[0192] <Secret dispersion conversion unit 113>

[0193] n secret dispersion conversion units 113 receive [[ρ a Q , [[ρ b Q to calculate [[-ρ a -ρ b Q , and through secret dispersion conversion, obtain <<-ρ a -ρ b >> Q (S113).

[0194] <Shift - amount hiding left - right shift unit 115>

[0195] The shift - amount hiding left - right shift unit 115 receives the share of the product - sum [[c]] P and the share of the shift amount

[0196] <<-ρ​​​​​​ a -ρ b >> Q , according to the <Shift Amount Concealed Left-Right Shift Protocol> above, shift [[c]] P shift

[0197] <<-ρ a -ρ b >> Q bits (S115), and output the shifted value. Additionally, instead of using the <Shift Amount Concealed Left-Right Shift Protocol> above, the shares of the product-sum [[c]] P and the shares of the shift amount

[0198] <<-ρ a -ρ b >> Q , can be used to obtain, through well-known techniques, the value after shifting [[c]] P <<-ρ a -ρ b >> Q bits.

[0199] <Third Embodiment>

[0200] The description will be centered on the differences from the First Embodiment.

[0201] In the Third Embodiment, the floating-point vector product-sum that utilizes vector MSB normalization in the First Embodiment will be described. First, several protocols used in the floating-point vector product-sum related to the Third Embodiment will be described.

[0202] <Exponent Part Unification Protocol for Floating-Point Vectors>

[0203] Input: Floating-point vector ( → a]] P , → ρ a Q ), where, in this embodiment, the mantissa part is set as a and the exponent part is set as ρ a , and the real number x is represented as x = 2 ρ _ a a.

[0204] → a]] P = ([[a0]] P , …, → a m-1 P ), → ρ a Q = ([[ρ​​​​ a_0 Q ,…, [[ρ a_m-1 Q ), floating-point vector ( → a]] P , → ρ a Q ) represents the i-th (0 ≤ i < m - 1) real number such as 2 ρ _ (a _ i) a i as such.

[0205] Output: ( → b]] P , [[ρ max Q ), where for each i-th element 2 ρ _ (a _ i) a i ≈ 2 ρ _ max b i Process: For the floating-point vector ( → a]] P , → ρ a Q ), make the exponent part → ρ a Q uniform to the maximum value [[ρ max Q , shift the mantissa unit → a P right by the difference → ρ dif Q := → ρ a Q - [[ρ max Q , and obtain the floating-point vector with the exponent part unified.

[0206] 1: Through maximum value calculation, obtain the maximum value from all the elements included in [[→ρ a Q as [[ρ max Q .

[0207] 2: Calculate → ρ​​​​​​​​​​​​ dif Q := → ρ a Q - [[ρ max Q 。Subtract → ρ a from each element of Q ρ max Q 。

[0208] 3: According to the <Shift Amount Hiding Left - Right Shift Protocol> above, shift each element of → ρ dif by Q each element of → a]] P as → b]] P 。However, since → ρ dif has non - negative elements, it is a right shift, so the left - shift branch can be omitted.

[0209] 4: Output ( → b]] P , [[ρ max Q )。

[0210] Next, the floating - point vector dot - product sum implemented in this embodiment will be described.

[0211] <Floating - point Vector Dot - Product Sum Protocol>

[0212] Input: Floating - point vectors ( → a]] P , → ρ a Q ), ( → b]] P , → ρ b Q )

[0213] Parameter: Vector length m

[0214] Output: ([c]] P , <<ρ b >> Q ), where Σ 0≦i<m 2 (ρ _ a) _ i(ρ _ ​​​​​​ b) _ i a i b i ≈2 ρ _ b b。

[0215] 1: Obtain the vector and shift amount with the MSB positions adjusted for → a]] P 、 → b]] P according to the <Vector MSB Normalization Protocol>, ( → a']], <<ρ' a >> p ), ( → b']], <<ρ' b >> p ).

[0216] 2: Obtain [[ρ a' Q 、[[ρ b' Q through the mod p → mod Q conversion.

[0217] 3: According to the <Exponential Part Unification Protocol for Floating-Point Vectors> above, obtain the vector and exponential part after unifying the exponential parts of ( → a']] P 、 → ρ a -ρ a' Q ), ( → b']] P 、 → ρ b -ρ b' Q ), ( → a”]], [[ρ a” Q ), ( → b”]], [[ρ b” Q .

[0218] 4: Calculate [[c]] P := [[Σ 0≦i<m a” i b” i P , and obtain ([[c]] P , [[ρ a” +ρ b” Q ​​​​​​​​)。

[0219] Further, if the number of bits of the input is known to some extent, or if the number of bits of a and b is known to be high to some extent due to adjustment of the MSB, etc., then a right shift is publicly performed by a predetermined number of bits σ by a known shift amount.

[0220] On the other hand, in the case where the number of bits is not clear, the MSB is aligned with a fixed position by the same method as in the first embodiment, and then the MSB is right-shifted to an appropriate bit position by a known shift amount. Let the right shift amount be [[σ]] Q 。

[0221] Hereinafter, a vector MSB normalization system for implementing the above <floating-point vector product sum protocol> will be described.

[0222] <Vector MSB Normalization System According to the Third Embodiment>

[0223] Figure 1 Shows a structural example of the vector MSB normalization system 1 according to the second embodiment, Figure 6 Shows an example of the processing flow of the vector MSB normalization system 1.

[0224] The vector MSB normalization system 1 takes two floating-point vectors ( → a]] P , → ρ a Q ), ( → b]] P , → ρ b Q ) as inputs, calculates the product sum of the elements ([[c]] P , <<ρ c >> Q ) and outputs it. Among them, Σ 0≦

[0225] i<m 2 (ρ _ a) _ i(ρ _ b) _ i a i b i ≈2 ρ _ c c. The vector → a]] P ​​, → b]] P Set the vector length m of P as a parameter.

[0226] <Dispersion processing device 100-r>

[0227] Figure 7 An example of a functional block diagram showing the dispersion processing device 100-r.

[0228] In addition to the bit decomposition unit 101, the logical OR acquisition unit 103, the shift amount acquisition unit 105, and the shift unit 107, the dispersion processing device 100-r further includes an analog-to-digital conversion unit 117, an exponent unification unit 119, and a product-sum unit 121.

[0229] Hereinafter, Figure 6 The processing of each part will be described.

[0230] Regarding S101 to S107, as described in the first embodiment. The vector MSB normalization system 1 receives two floating-point vectors ( → a]] P , → ρ a Q ), ( → b]] P , → ρ b Q ) as inputs, and → a]] P , → b]] P Perform vector MSB normalization, and obtain the vector sum and shift amount after vector MSB normalization ( → a']] P , <<ρ' a >> p ), ( → b']] P , <<ρ' b >> p ). The processing after S117 will be described.

[0231] <Analog-to-digital conversion unit 117>

[0232] n analog-to-digital conversion units 117 receive <<ρ' a >> p and <<ρ' b >> p , and obtain [[ρ a' Q , [[ρ b' ​​​​ Q (S117).

[0233] <Exponent Unification Unit 119>

[0234] n Exponent Unification Units 119 receive two floating-point vectors ( → a]] P , → ρ a Q ),( → b]] P , → ρ b Q )'s exponent parts → ρ a Q 、 → ρ b Q 、vector MSB-normalized vectors → a']] P , → b']] P 、mod p → mod Q-converted shift amounts [[ρ a' Q 、[[ρ b' Q ,According to the <Exponent Part Unification Protocol of Floating-Point Vectors> above, obtain the unified ( → a']] P , → ρ a -ρ a' Q ),( → b']] P , → ρ b -ρ b' Q )'s exponent parts of vectors and exponent parts,( → a”]] P ,[[ρ a” Q ),( → b”]] P ,[[ρ b” Q )(S119).

[0235] <Product-Sum Unit 121>

[0236] n Product-Sum Units 121 calculate [[c]] P :=[[Σ 0≦i<m a”​​​​​​​​​​ i b” i P to obtain ([[$c$]] P and [[ρ a” + ρ b” Q )(S121).

[0237] (Processing efficiency)

[0238] Regarding the processing efficiency of the algorithm, evaluate the multiplication rotation as element operation, flag column → numerical conversion, shift amount hiding left - right shift protocol, and floating - point addition and multiplication for comparison.

[0239] (1) Multiplication rotation: Communication volume (4 / 3)|P| bits, 2 rounds

[0240] (2) Flag column → numerical conversion: Communication volume (4 / 3)|L| bits, 2 rounds

[0241] (4) Shift amount hiding left - right shift protocol - part two -: Communication volume ((5 / 3)d+(10 / 3))|P|+(2d + 1)|p|, number of rounds λ + 4

[0242] (5) Floating - point addition: Communication volume ((5 / 3)d+(19 / 3))|P|+3|Q|+2λ+(4d + 1)|p|, number of rounds 2λ + 7

[0243] (6) Floating - point multiplication: Communication volume (8 / 3)|P|, 3 rounds

[0244] d is the division number d in the shift amount hiding left - right shift protocol.

[0245] As a comparison object, in Reference 2, there are two methods for addition. If the cost below the logarithm is rounded, the communication volume can be expressed as 22|P|+5|Q|+O(log|P|+log|Q|).

[0246] (Reference 2) Takashi Nishide, Takuma Amada, "Multi - party Computation for Floating - Point Operations with Reduced Communication Volume", Transactions of the Information Processing Society of Japan, Vol.60, No.9, pp.1433 - 1447 (2019).

[0247] The number of rounds is preferably the constant 42. For multiplication, the communication volume is 12|P|+O(1), and the number of rounds is the constant 23. Considering that d is typically 1, for addition it is 6|P|+3|Q|+2λ+5|p|. Considering |P| = 61, |Q| = 13, λ = 10, |p| = 6, the efficiency of this method is about 3 times. Since addition is more complex, even if the shift as an element is speeded up, it seems that the difference will not be extremely large. For multiplication, the speed is up to about 5 times.​​

[0248] <Actual Machine Performance Evaluation>

[0249] Report the results of the actual machine experiment. The following is the multiparty calculation of three machines.

[0250] ◎CPU: Xeon Gold 6144 3.5GHz, 6 cores and 2 threads

[0251] ◎Memory: 768GB

[0252] ◎NW: 10Gbps ring topology

[0253] ◎Operating System: CentOS7.3

[0254] Figure 8 It is the performance of each operation.

[0255] As a parameter, the upper limit of the MSB position is very important and is set to 28 bits here (29-bit number since it starts from 0). The maximum MSB position where quotient transfer can be used in mod p with reference signs is 57, provided that it is within half of it. 28 bits exceed single precision and can be considered sufficient to run most applications.

[0256] As the sum-of-products operation, matrix multiplication is actually selected. This is because matrix multiplication consists of the sum-of-products and is extremely important in aspects such as machine learning. Specifically, the left matrix is set to have 100 rows, and the number of rows × number of columns = "number of items", and the right matrix is set to a vector with the length of the number of columns of the left matrix. The processing volume is equal to repeating the sum-of-products with the size as the number of columns only for the number of times equivalent to the number of rows.

[0257] As scales, three values of 1000 items, 1 million items, and 10 million items are recorded, and the actual number of rounds is measured by setting the latency to 100 ms extremely. In addition, in addition to the passive model, the performance of the active model is also shown (the protocol is extended from the passive version). The security parameter of the active model is 8 bits, and the attack detection rate is approximately 99%. Different from computational security, offline attacks are impossible, so this probability is sufficient to suppress attacks.

[0258] <Other Variants>

[0259] The present invention is not limited to the above-described embodiments and variants. For example, the above various processes are not only executed in time series according to the description, but can also be executed in parallel or individually according to the processing capabilities of the devices performing the processes. In addition, appropriate changes can be made without departing from the gist of the present invention.

[0260] <Program and Recording Medium>

[0261] The various processes described above can be implemented by causing Figure 9 the storage unit 2020 of the computer shown to read a program for executing each step of the above method, and causing the control unit 2010, the input unit 2030, the output unit 2040, etc. to operate.

[0262] A program describing the processing content can be recorded in a computer-readable recording medium. As a computer-readable recording medium, for example, it can be any medium such as a magnetic recording device, an optical disc, a magneto-optical recording medium, a semiconductor memory, etc.

[0263] In addition, the distribution of this program is carried out, for example, by selling, transferring, or renting mobile recording media such as DVDs and CD-ROMs on which the program is recorded. Further, it can also be configured such that the program is stored in the storage device of a server computer, and via a network, the program is transmitted from the server computer to other computers, thereby distributing the program.

[0264] For example, a computer executing such a program first temporarily stores the program recorded in a mobile recording medium or the program transmitted from a server computer in its own storage device. Then, when performing processing, the computer reads the program stored in its own recording medium and executes the processing according to the read program. In addition, as another execution mode of this program, it can also be that the computer directly reads the program from a mobile recording medium and executes the processing based on the program. Further, it can also be configured such that each time the program is transmitted from a server computer to this computer, the processing based on the received program is successively executed. In addition, it can also be configured to execute the above processing through a so-called application service provider (ASP: Application Service Provider) type service that realizes the processing function only by obtaining its execution instruction and result without transmitting the program from the server computer to this computer. Additionally, in the program in this mode, it includes information in the form of a program (data, etc. that are not direct instructions to the computer but have the nature of prescribing the processing of the computer) as information provided for the electronic computer to perform processing.

[0265] In addition, in this mode, this device is configured by executing a predetermined program on a computer, but at least a part of these processing contents can also be implemented in hardware. < / f1> ​​< / x> < / x> < / x> < / x>

Claims

1. A hidden MSB normalization system, comprising n decentralized processing devices, Each of the n decentralized processing devices includes a bit decomposition unit, a logical OR acquisition unit, a shift amount acquisition unit, and a shift unit, The n bit decomposition units perform bit decomposition on the vector → a]] P after (k, n)-secret sharing, to obtain the bit representation of the vector → a]] P , → a]] 2^L , For the bit representation → a]] 2^L of each bit position i of the vector → a i , obtain the logical OR of all elements [[A i 2 , where If the s-th element of the vector → a is set to a s , s = 0, 1, …, m - 1, and the bit representation of [[a s is set to [[a s 2^L , and the share of the i-th bit position of [[a s 2^L is set to [[(a i ) s 2 , then the vector → a i = ([[(a i )0]] 2 , …, [[(a i ) m-1 2 ), and the logical OR calculated is: [[A i 2 := [[(a i )0]] 2 OR … OR [[(a i ) m-1 2 ,​​​​​​ ​ n of the shift amount acquisition units use the modulus p for the shift amount ρ that shifts the most significant bit for logical OR [[A0]] 2 ,…,[[A L-1 2 to the fixed position, perform (k,n)-replicated secret sharing, and obtain the share <<ρ>> after (k,n)-replicated secret sharing p ,​ n of the shift units obtain a vector obtained by shifting each element of the vector → a]] P to the left by ρ bits as the vector [[2 ρ→ a]] p , where P: prime number; k: threshold of secret sharing; L: maximum number of bits of the input; 0 ≤ i < L; m: vector length.

2. The hidden MSB normalization system according to claim 1, According to the fixed-point vector → a]] P 、 → b]] P Find the vector and shift amount after shifting the most significant bit to a fixed position ([ ρ _ a→ a]] P , <<ρ a >> p ), ([ ρ _ b→ b]] P , <<ρ b >> p ), Each of the n decentralized processing devices includes an analog-to-digital conversion unit, a product-sum calculation unit, a secret sharing conversion unit, and a shift amount hidden left-right shift unit, The n analog-to-digital conversion units perform a mod p→mod Q conversion and obtain [[ρ a >> p 、[[ρ b >> p according to <<ρ a Q 、[[ρ b Q ;​​ n of the product-sum calculation units calculate [[c]] P := [[Σ 0≦i<m 2 ρ _ a a i 2 ρ _ b b i P ,​ n of the secret dispersion conversion units calculate [[-ρ a Q according to the [[ρ b Q and the [[ρ a -ρ b Q . Through secret dispersion conversion, the shares <<-ρ a -ρ b >> Q after (k, n)-replicated secret dispersion are obtained.​​​ n of the shift amount hiding left and right shift units receive the share of the product-sum [[c]] P and the share of the shift amount <<-ρ a -ρ b >> Q , for [[c]] P perform <<-ρ a -ρ b >> Q displacement shift, Among them, Q: number of bits of the residue class ring.

3. The hidden MSB normalization system according to claim 1, According to the floating-point vectors( → a]] P , → ρ a Q ),( → b]] P , → ρ b Q ) find the vectors and shift amounts ( → a']] P , <<ρ' a >> p )、( → b']] P , <<ρ' b >> p ) after shifting the most significant bit,​​ Each of the n decentralized processing devices includes an analog-to-digital conversion unit, an exponent unification unit, and a product-sum calculation unit, n of the analog-to-digital conversion units perform a mod p→mod Q conversion on the <<ρ' a >> p and the <<ρ' b >> p to obtain [[ρ a' Q , [[ρ b' Q ,​​ The n exponent unification units use the floating-point vectors ( → a P , → ρ a ) Q ), ( → b P , → ρ b ) Q ) of the exponent parts → ρ a ), Q and → ρ b ), Q and the vectors → a' P and → b' P after shifting the most significant bit, and the shift amounts [[ρ a' ) Q and[[ρ b' ) Q , to obtain a unified → a' P , → ρ a -ρ a' ) Q ), ( → b' P , → ρ b -ρ b' ) Q ) of the exponent parts of the vectors and the exponent parts, ( → a” P ,[[ρ a” ) Q ), ( → b” P ,[[ρ b” ) Q ), n of the product-sum calculation units calculate [[c]] P := [[Σ 0≦i<m a” i b” i P , obtaining ([[c]] P , [[ρ a” + ρ b” Q ), where Q: number of bits of the residue class ring. ​​ 4. A decentralized processing device, included in a hidden MSB normalization system, the decentralized processing device comprising: A bit decomposition unit, together with (n - 1) decentralized processing devices, performs bit decomposition on the vector of shares after (k, n)-secret sharing to obtain the bit representation of the vector → a]] P ; → a]] P → a]] 2^L ;​ A logical OR acquisition unit, together with (n - 1) distributed processing devices, for the bit representation → a]] 2^L of each bit position i of the vector → a i , obtains the logical OR of all elements [[A i 2 , where, if the s-th element of the vector → a is set to a s , s = 0, 1,..., m - 1, the bit representation of [[a s is set to [[a s 2^L , the share of the i-th bit position of [[a s 2^L is set to [[(a i ) s 2 , then the vector → a i = ([[(a i )0]] 2 ,..., [[(a i ) m-1 2 ), and the obtained logical OR is: [[A i 2 := [[(a i )0]] 2 OR... OR [[(a i ) m-1 2 ;​​​​​​​ A shift amount acquisition unit, together with (n - 1) dispersion processing devices, performs (k, n)-replicated secret sharing on a shift amount ρ for shifting the most significant bit of a logical OR [[A0]] 2 ,…,[[A L-1 2 to a fixed position modulo p, and obtains shares <<ρ>> after (k, n)-replicated secret sharing p ; and​ A shift unit, together with (n-1) decentralized processing devices, obtains a vector → a]] P by left-shifting each element of the vector by ρ bits to obtain a vector [[2 ρ→ a]] p , where P: prime number; k: threshold of secret sharing; L: maximum number of bits of the input; 0 ≤ i < L; m: vector length.

5. A hidden MSB normalization method, using a hidden MSB normalization system including n decentralized processing devices, Each of the n decentralized processing devices includes a bit decomposition unit, a logical OR acquisition unit, a shift amount acquisition unit, and a shift unit, The hidden MSB normalization method includes the following steps: Bit decomposition step, where n of the bit decomposition units perform bit decomposition on the vector of shares after (k, n)-secret sharing → a]] P to obtain the bit representation of the vector → a]] P ; → a]] 2^L ; Logical OR acquisition step, for the bit representation → a]] 2^L of each bit position i of the vector → a i , obtain the logical OR of all elements [[A i 2 , where If the s-th element of the vector → a is set as a s , s = 0, 1, …, m - 1, and the bit representation of [[a s is set as [[a s 2^L , and the share of the i-th bit position of [[a s 2^L is set as [[(a i ) s 2 , then the vector → a i = ([[(a i )0]] 2 , …, [[(a i ) m-1 2 ), and the logical OR obtained is: [[A i 2 := [[(a i )0]] 2 OR … OR [[(a i ) m-1 2 ;​​​​​​ ​ Shift amount acquisition step, where n of the shift amount acquisition units use modulus p for the highest bit shift amount ρ that shifts the bit used for logical OR [[A0]] 2 ,…,[[A L-1 2 to a fixed position, perform (k,n)-replicated secret sharing on ρ, and obtain the share <<ρ>> after (k,n)-replicated secret sharing p ;​ and Shift step, where n of the shift units find the vector obtained by shifting each element of the vector → a]] P to the left by ρ bits, which is the vector [[2 ρ→ a]] p , where P: prime number; k: threshold of secret sharing; L: maximum number of bits of the input; 0 ≤ i < L; m: vector length.

6. The hidden MSB normalization method according to claim 5, Based on the fixed-point vector → a]] P and → b]] P find the vector and shift amount after shifting the most significant bit to a fixed position ([ ρ _ a→ P a a , <<ρ p ]]), ( ρ _ b→ P b b , <<ρ p ]]),​​​​​​​​​​​​​​​​​​​​ Each of the n decentralized processing devices includes an analog-to-digital conversion unit, a product-sum calculation unit, a secret sharing conversion unit, and a shift amount hidden left-right shift unit, The hidden MSB normalization method includes the following steps: Analog-to-digital conversion step, where n of the analog-to-digital conversion units are converted by mod p → mod Q, according to <<ρ a >> p and <<ρ b >> p to obtain [[ρ a Q and [[ρ b Q ;​​ Product-sum calculation steps, where n of the product-sum calculation units calculate [[c]] P := [[Σ 0≦i<m 2 ρ _ a a i 2 ρ _ b b i P ;​ Secret dispersion conversion step, n of the secret dispersion conversion units calculate [[ρ a Q and [[ρ b Q to calculate [[-ρ a -ρ b Q . Through secret dispersion conversion, the shares <<-ρ a -ρ b >> Q after (k, n)-replicated secret dispersion are obtained; and​​​ Shift amount hiding left - right shift step, n of the shift amount hiding left - right shift units receive the share of the product - sum [[c]] P and the share of the shift amount << - ρ a -ρ b >> Q , for [[c]] P perform << - ρ a -ρ b >> Q bit - shift Among them, Q: number of bits of the residue class ring.

7. The hidden MSB normalization method according to claim 5, Based on the floating-point vectors ( → a]] P , → ρ a Q ),( → b]] P , → ρ b Q ) find the vectors and shift amounts after shifting the most significant bit ( → a']] P ,<<ρ' a >> p )、( → b']] P ,<<ρ' b >> p ),​​ Each of the n decentralized processing devices includes an analog-to-digital conversion unit, an exponent unification unit, and a product-sum calculation unit, The hidden MSB normalization method includes the following steps: Analog-to-digital conversion step, where n of the analog-to-digital conversion units perform operations on the <<ρ' a >> p and the <<ρ' b >> p to perform a mod p → modQ conversion, obtaining [[ρ a' Q and [[ρ b' Q ; and ​​ Exponent unification step, where n of the exponent unification units use the floating-point vectors ( → a]] P , → ρ a Q ),( → b]] P , → ρ b Q ) for the exponent parts → ρ a Q 、 → ρ b Q 、and the vectors after shifting the most significant bit → a']] P 、 → b']] P 、and the shift amounts after the mod p → mod Q conversion [[ρ a' Q 、[[ρ b' Q , to obtain vectors that unify the ( → a']] P , → ρ a -ρ a' Q )、( → b']] P , → ρ b -ρ b' Q ) for the exponent parts, and the vectors and exponent parts of ( → a”]] P ,[[ρ a” Q )、( → b”]] P ,[[ρ b” Q );​​​​​​​​​​ and Sum-product calculation steps, where n of the sum-product calculation units calculate [[c]] P := [[Σ 0≦i<m a” i b” i P , obtaining ([[c]] P , [[ρ a” +ρ b” Q ),​​ where Q: number of bits of the residue class ring.

8. A computer program product, including a computer program, the computer program for causing a computer to function as the decentralized processing device of claim 4.

Citation Information

Patent Citations

  • Apparatus and method for vector horizontal logical instruction

    CN107003842A

  • Improved lattice-based key exchange protocol algorithm

    CN109617686A