A secure aggregation method with a cache layer against server exit and collusion

By employing Cauchy matrix encoding and two-round communication, the problem of secure aggregation where users cannot share information is solved, ensuring computational correctness and privacy security in cases of server exit and collusion, while optimizing communication speed.

CN116489222BActive Publication Date: 2026-07-21SOUTHEAST UNIV

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
SOUTHEAST UNIV
Filing Date
2023-04-27
Publication Date
2026-07-21

AI Technical Summary

Technical Problem

Existing technologies struggle to address security aggregation issues caused by server exits and collusion when users are unaware of the target statistics of the simulation center and cannot share information with each other, especially in caching layer server environments.

Method used

The system employs Cauchy matrix encoding for user and server messages and achieves secure aggregation through two rounds of communication. By using Cauchy matrix encoding for user-uploaded messages and server-shared messages, combined with the decoding steps of the simulation center, the system ensures the correctness of the calculation results and the security of user privacy data in the event of server exit or collusion.

Benefits of technology

In the event of server exit or collusion, the system ensures the accuracy of target statistics calculation and the security of user privacy data, and optimizes communication speed, especially in caching layer server environments, adapting to application scenarios where target statistics change.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116489222B_ABST
    Figure CN116489222B_ABST
Patent Text Reader

Abstract

The application discloses a security aggregation method with a cache layer for server exit and collusion. The method implementation process comprises encoding of user uploaded messages, encoding of shared messages between servers, encoding of first and second round communication messages between a simulation center and servers, and decoding of received messages by the simulation center. The method can be applied to a case that any no more than N-N r servers drop out and any no more than T (T r ) number of servers collude, and the first hop and second hop communication rates are minimum.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of information theory, and in particular to a method for handling K users, N cache layer servers, and any number of no more than N / A cache layers. r A secure aggregation method for preventing server failures and collusion among any number of servers not exceeding T. Background Technology

[0002] In secure aggregation problems, most work focuses on scenarios where users already know the target statistics of the simulation center and can share information with each other. However, in application scenarios where the target statistics change over time or the simulation center does not want users to know the target statistics, it is meaningful to study scenarios where users do not know the target statistics of the simulation center and cannot share information with each other. This invention studies a secure aggregation problem with a caching layer and proposes a secure aggregation method with a caching layer to address server exit and collusion. Summary of the Invention

[0003] Technical Problem: The technical problem to be solved by this invention is to provide a solution for K users, N cache layer servers, and any number of no more than N / N cache layers. r A secure aggregation method for handling server dropouts and collusion by no more than T servers is proposed. This method utilizes a Cauchy matrix to encode target statistics to obtain user-uploaded messages, involves message sharing between servers, the first and second rounds of communication messages sent by servers to the simulation center, and the decoding steps taken by the simulation center to obtain the target statistics. This yields a secure aggregation method with a caching layer for handling server exits and collusion.

[0004] Technical solution: The technical solution adopted in this invention is as follows:

[0005] (1) User message upload: Each user k∈[K] has a private message W k Each message contains There are L symbols in the array, and each user k sends a message D to each server n∈[N]. k,n .

[0006] (2) First round of communication between the server and the SC: When the simulation center (SC) receives a statistical request and sends the coefficient vector f = (f1, ... f2) to the SC, the SC will send the first round of communication between the server and the SC. K When shared with all servers, server n∈[N] calculates the first round of communication messages between the simulation center and the servers based on the received user messages and the coefficient vector of the required statistical tasks. Next, server n encodes the shared encoded message to be shared with other servers. Finally, the server sends the first round of communication messages to the SC.

[0007] (3) Second round of communication between the server and SC: SC sends the first round of communication information N1 to the server (N1 represents the set of servers that successfully communicated in the first round). Based on the first round of communication information, server n∈N1 sends the second round of communication message to SC.

[0008] (4) The simulation center (SC) receives the message. and Decode the target statistic

[0009] Among them, the uploaded message D k,n The encoding steps are as follows:

[0010] User k independently Generate a row vector F k Each element in the vector is independent and identically distributed, and follows a uniform distribution. Then user k sends the private message W. k The user-side random variable F is uniformly divided into NT components. k Divide the material evenly into T parts, that is:

[0011] W k =(W k,1 ,…,W k,N-T ),F k =(F k,1 ,…,F k,T )

[0012] For each user k, the message D sent to server n k,n The encoding method is as follows:

[0013]

[0014] Among them, C N×N C represents an N×N Cauchy matrix where all entities in a system are known. N×N Let the element in the i-th row and j-th column be c. i,j =1 / (α) i -β j ), where α i ,β j i∈[N], j∈[N] are from finite fields Given different element values, where q satisfies q≥N+N=2N.

[0015] Compute message sharing between servers The steps are as follows:

[0016] Server n independently in Generate a row vector Zn Each element in the vector is independent and identically distributed, and follows a uniform distribution. Then the server n will calculate the... and the generated Z n Divide into N r -T, T parts, namely:

[0017]

[0018] For the message transmitted from server n to server i The encoding method is as follows:

[0019]

[0020] in, express The i-th row in the array. In a system where all entities are known, the dimension is N×N r The Cauchy matrix, i.e. Let the element in the i-th row and j-th column be g. i,j =1 / (α) i -β j ), where α i ,β j , i∈[N], j∈[N] r ] is from a finite field Given different element values, where q ≥ 2N ≥ N + N r .

[0021] The decoding steps are as follows:

[0022] SC receives N in the second round r Decoding and calculation begin when a message is received. The received messages are then organized into a message matrix Y, i.e.:

[0023]

[0024] Where N3 represents the user set received at this time. Next, The matrix formed by the rows corresponding to n∈N3 is denoted as . from Calculated in Will Combined with the first round of messages Finally, from Calculated in The target statistic is obtained by merging the decoding results.

[0025] Beneficial effects: This invention proposes a general method for the security aggregation problem with caching layers, applicable to K users, N caching layer servers, and any number of up to N / N cache layers. r A server falls out of the queue and any number of servers not exceeding T (T < N) r In cases where multiple servers collude, the correctness of the calculation results and the security of user privacy data are guaranteed, and the communication rate between the first and second hops is minimized. Compared to existing secure aggregation methods, this invention incorporates a caching layer composed of a group of servers, ensuring the correctness of the target statistic calculation and the security of user privacy data even in application scenarios where the target statistic changes over time or the simulation center does not want users to know the target statistic. Under the new model, a Cauchy matrix is ​​used to encode the data and noisy random variables, guaranteeing that the data remains accurate even when the target statistic changes over time (T < N). r In the case of collusion among multiple servers, the security of user privacy data is ensured. Under the new model, an existing two-round communication method is applied to the communication between the server group and the simulation center, guaranteeing the security of user privacy data in any number of no more than N... r The goal is to ensure the accuracy of the calculation results in the event that one server falls behind, and to minimize the communication rate of the second hop. Attached Figure Description

[0026] Figure 1 Consider a system model with K users, N caching layer servers, and server dropout and collusion issues. Figure 2 The system model consists of 2 users, 3 caching layer servers, and 1 server that has fallen out. Detailed Implementation

[0027] The technical solution of the present invention will be described in detail below, but the scope of protection of the present invention is not limited to the embodiments described.

[0028] This invention proposes a secure aggregation method with a caching layer to address server exit and collusion. For example... Figure 1 As shown, the system model of this invention includes K users and N servers, wherein at least N users are active during the entire communication process. r One server remains responsive, and at most T servers will collude; each user k has a private message W. k and random noise F used for encoding k It uploads message D to server n. k,n Each server n has random noise Z used for encoding. n Servers can send messages to each other; the simulation center (SC) sends a coefficient vector f of statistical requests to the server. The server and simulation center communicate in two rounds. In the first round, server n sends a message to the simulation center. The second round sends messages based on the message reception results from the first round.

[0029] The following is an example:

[0030] Consider K = 2 users and N = 3 servers, where at least N r When two servers respond and no servers collude (T=1), assuming the user message length is 2, the parameter q of the finite field is 8, and the target statistic is W1+W2.

[0031] (1) User message upload: Each user k∈[K] has a private message W k Each message contains The two symbols in the diagram represent a message D sent by each user k to each server n∈[N]. k,n :

[0032]

[0033] Among them, F1 and F2 are user-independent. The generated row vector W has a length of 1. k (1), W k (2) is from W k It was obtained by dividing it evenly into two parts.

[0034] (2) First round of communication between the server and the SC: When the simulation center (SC) receives a statistical request and shares the coefficient vector f = (1, 1) with all servers, the server n ∈ [N] calculates the first round of communication message between the simulation center and the server based on the received user message and the coefficient vector of the required statistical task. Next, server n encodes the message and shares it with other servers.

[0035]

[0036] Finally, the server sends the first round of communication messages to the SC.

[0037] (3) Second round of communication between the server and SC: SC sends the first round of communication information N1 to the server (N1 represents the set of servers that successfully communicated in the first round). Based on the first round of communication information, server n∈N1 sends the second round of communication message to SC.

[0038] (4) The simulation center receives the message. and Decode the required W = W1 + W2:

[0039] When N1 = {1, 2, 3}, there is no second round of communication. This is obtained from the results of the first round of communication. calculate Get W1,1 +W 2,1 and W 1,2 +W 2,2 The result of merging is W = W1 + W2.

[0040] When N1 = {1, 2}, since N r =2, then N2 = {1,2}, and from the results of the second round of communication, we get Y = (Y1) {1 ,2},(1,1) Y2 {1,2},(1,1) ),calculate get The first round of merger news received calculate Get W 1,1 +W 2,1 and W 1,2 +W 2,2 The result is W = W1 + W2. The other cases where |N1| = 2 follow a similar decoding method.

Claims

1. A secure aggregation method with a caching layer for server exit and collusion, characterized in that, Includes the following steps: (1) User message upload: Each user They all have a private message Each message contains a finite field L symbols in the middle, each user To each server Send a message ; (2) First round of communication between the server and the simulation center: When the simulation center (SC) receives a statistical request and sends the coefficient vector When shared with all servers, the server Based on the received user messages and the coefficient vector of the target statistics, calculate the first round of communication messages between the simulation center and the server. Next, server n encodes the shared message to be shared with other servers. Finally, the server sends the first round of communication messages to the SC. (3) Second round of communication between the server and the simulation center: SC sends the first round of communication information to the server. , This represents the set of servers that successfully communicated in the first round; servers Based on the first round of communication, a second round of communication messages are sent to the SC. ; (4) The simulation center, based on the received message and Decode the target statistic ; In step (1), the message is uploaded. The encoding steps are as follows: user Independently Generate a row vectors T represents the number of colluding servers that the method can tolerate, and each element in the vector is independent, identically distributed, and follows a uniform distribution; then the user Private messages Evenly divided into Partial, random variables on the user side Divide the material evenly into T parts, that is: ; For each user Send to server News The encoding method is as follows: ; in, A Cauchy matrix of dimension N×N represents a system in which all entities are known. Let the elements in the i-th row and j-th column be set as ,in , , , It comes from a finite field Different element values, among which satisfy ; Step (2) consists of the following steps, including the first round of communication messages and inter-server shared messages; Calculate the first round of communication messages between SC and the server. The steps are as follows: ; Compute message sharing between servers The steps are as follows: Server n independently in Generate a row vectors N r This represents the number of servers that will respond. Each element in the vector is independent, identically distributed, and follows a uniform distribution. Then, the number of servers n will be calculated. and generated Divided into T parts, namely: ; For the message transmitted from server n to server i The encoding method is as follows: ; in, express The i-th row in; The dimension of a system is known to all entities. The Cauchy matrix, i.e. Let the elements in the i-th row and j-th column be set as ,in , , , It comes from a finite field Different element values, among which satisfy ; The second round of communication messages in step (3) The encoding steps are as follows: ; In step (4) The decoding steps are as follows: SC received in the second round Decoding and calculation begin when a message is received, and the messages received at this time are used to form a message matrix Y, that is: ; in This indicates the user set received at this point; then, Chinese correspondence The matrix composed of rows is denoted as . ,from Calculated in ;Will Combined with the first round of messages Finally, from Calculated in The target statistic is obtained by merging the decoding results. .