A constant-round multi-party private function calculation method based on multi-party obfuscation circuits

By generating and hiding the parameters of the private circuit topology structure, a secure multi-party computing algorithm is used for blinding processing, solving the problem of low computing efficiency of large circuits in high-latency network environments, and realizing the correctness and privacy of multi-party private function calculations.

CN116506111BActive Publication Date: 2025-08-12SOUTH CHINA AGRICULTURAL UNIVERSITY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202310448079.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-04-24
Publication Date
2025-08-12
Estimated Expiration
2043-04-24

AI Technical Summary

Technical Problem

The existing secure multi-party computing technology is not suitable for situations where the function itself is sensitive and needs to be kept confidential, especially when calculating large circuits in high-latency network environments.

Method used

The constant round multi-party private function calculation method of multi-party obfuscated circuit is adopted. By generating the parameters required to calculate multi-party private functions, the multi-party inadvertent expansion of the permutation algorithm is used to hide the topological structure of the private circuit, and a secure multi-party calculation algorithm is used to perform blinded parameter calculation.

Benefits of technology

The efficiency improvement of multi-party private function computing protocol in a high-latency network environment is achieved, ensuring the accuracy and privacy of the calculation results, and can resist corruption by semi-honest rivals and allow corrupt parties to work together.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116506111B_ABST
    Figure CN116506111B_ABST
Patent Text Reader

Abstract

The present invention provides a constant-round multi-party private function calculation method based on a multi-party obfuscated circuit, the method comprising: generating parameters required for calculating the multi-party private function; using a multi-party oblivious expansion permutation algorithm to hide the private circuit C f The topology structure of the multi-party private function is used to blind the required parameters; a secure multi-party computation algorithm is used to calculate the multi-party private function based on the blinded parameters. This invention can effectively improve the efficiency of the multi-party private function computation protocol when computing large circuits in a high-latency network environment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data security technology, and in particular to a constant-round multi-party private function calculation method based on a multi-party obfuscation circuit. Background Art

[0002] The proliferation of the internet and the development of computing devices have created enormous opportunities for joint privacy-preserving computing, which can occur between trusted or partially trusted partners, or even between competitors. Data and algorithms are valuable in many real-world scenarios. For example, consider a business scenario between a traditional enterprise and an algorithmic company. The traditional enterprise possesses a dataset, while the algorithmic company possesses a powerful data mining algorithm that can process this dataset. On the one hand, the algorithmic company does not intend to disclose the algorithm. On the other hand, because the dataset may contain sensitive information, the traditional enterprise is reluctant to disclose it to others.

[0003] Secure multi-party computation (SMPC) allows two or more parties to collaboratively compute a public function f using their private inputs without the need for a trusted third party. However, the general solution of SMPC is not suitable for certain specific situations, such as where the function itself is also sensitive and needs to be kept confidential. Summary of the Invention

[0004] The purpose of the present invention is to provide a constant-round multi-party private function calculation method based on a multi-party obfuscation circuit, which can effectively improve the efficiency of the multi-party private function calculation protocol when calculating large circuits in a high-latency network environment.

[0005] A constant-round multi-party private function calculation method based on a multi-party garbled circuit, comprising:

[0006] Generate the parameters required to calculate the multi-party private function;

[0007] Using multi-party oblivious extension permutation algorithm to hide private circuit C f The topology of the system is used to blind the required parameters;

[0008] A secure multi-party computing algorithm is used to calculate multi-party private functions based on the blinded parameters.

[0009] Preferably, the private circuit C is hidden by using a multi-party oblivious expansion permutation algorithm. f The topology of the required parameters is blinded including:

[0010] Server P1 generates a FALSE tag locally Shares components with mask values The blind operation obtains the blind FALSE label Shares components with the blinded mask value

[0011] The server and client execute the two-party oblivious expansion permutation algorithm, and server P1 inputs the topology map π f , blinded bit string Blinded Bits XOR value of all blinded bits

[0012] Client P i ,i∈[2,n] input global label offset R i , masking the shared component and FALSE label

[0013] Client P i ,i∈[2,n] gets the blind FALSE label Shares components with the blinded mask value Server P1 cannot obtain additional information.

[0014] Preferably, the parameters required to generate and calculate the multi-party private function include:

[0015] Server P1 uses the compiler to compile the server's private function f into a Boolean circuit C f , randomly assign the outgoing line index line index, and extract the mapping relationship π between the outgoing line and the incoming line f ;

[0016] Open private circuit C to the client f Some information Where m represents the number of circuit input lines, g represents the number of circuit gates, o represents the number of circuit output lines, OW is the outgoing line index set, and IW is the incoming line index set. is the final output line index;

[0017] The server and client uniformly randomly generate preprocessing information locally, and the global label offset R i , FALSE label TRUE label Mask value shared components The superscript i represents the participant P i The generated data, the FALSE label corresponds to the true value 0 on the Boolean circuit line, and the TRUE label corresponds to the true value 1 on the Boolean circuit line;

[0018] Server P1 generates a blinded bit string uniformly and randomly locally Blinded Bits

[0019] Preferably, a secure multi-party computing algorithm is used to calculate the multi-party private function based on the blinded parameters, specifically:

[0020] Each participant in the computation of the multi-party private function jointly executes the obfuscation algorithm, and server P1 obtains the obfuscated circuit output;

[0021] Each participant obtains the mask value shared component of the input line from the other participant, performs XOR operation on all the mask value shared components to obtain the mask value, performs XOR operation on the input and the mask value to obtain the public value, obtains the obfuscation label through the public value, and sends the obfuscation label to the server P1;

[0022] Based on the information provided by the blinded bit string and the topology map, server P1 locally calculates the garbled circuit according to the topology structure and obtains the final public value;

[0023] Server P1 obtains the mask value of the final output line from each participant, performs an XOR operation on the final public value and the mask value of the final output line, and outputs the actual bit.

[0024] Preferably, each participant in computing the multi-party private function jointly executes the obfuscation algorithm, and the server P1 obtains the obfuscated circuit output including:

[0025] Participant P i Set the TRUE label to The blinded TRUE label is

[0026] The participants jointly execute the garbled circuit algorithm, and the input of each participant is the global label offset R i , the mask value sharing component of the output line Mask value sharing component of incoming line The mask value shared component of the final output line FALSE label for outgoing line and TRUE label FALSE tag for incoming lines and TRUE label FALSE label for the final output line and TRUE label

[0027] The output obtained by server P1 is the garbled circuit GC, and the client cannot obtain additional information.

[0028] Preferably, each participant obtains the mask value shared component of the input line from another participant, performs XOR operation on all mask value shared components to obtain a mask value, performs XOR operation on the input and the mask value to obtain a common value, obtains an obfuscation label through the common value, and sends the obfuscation label to the server P1, including:

[0029] For each Boolean circuit input line w, if the input value is provided for the input line , then the other participants P j (j≠i) Send mask value shared component Give P i , P i Sending public values To all parties involved;

[0030] Participant P j Put the label on the input line w Send to server P1;

[0031] Finally, server P1 has all the labels on the input line w

[0032] Preferably, based on the blinded bit string and the information provided by the topology mapping, the server P1 locally calculates the obfuscation circuit according to the topology structure, and obtaining the final public value includes:

[0033] The incoming line OW and the outgoing line IW label connection: For the gate g currently being calculated, the input line is u, v, the output line is w, α and β represent the common values on the input lines u and v respectively, and γ represents the common value on the output line w; P1 maps π according to the topology f The information provided is obtained by using a blinded bit string Get the confusion labels on the input lines u and v respectively

[0034] According to the topological mapping π f Provided information, P1 locally calculates the obfuscated NAND gates according to the topology P1 uses the input line u,v calculated in the previous step to confuse the label and calculate P1 will and the confusion labels generated on the output line w For comparison, if Then the common value on the output line w is γ=0; if Then the common value on the output line w is γ = 1; otherwise, P1 terminates the protocol;

[0035] If the protocol is not aborted, it is repeated until all obfuscation gates are computed.

[0036] Preferably, the server P1 obtains the mask value of the final output line from each participant, performs an XOR operation on the final public value and the mask value of the final output line, and outputs the actual bits including:

[0037] For each circuit’s final output line w, client P i , i∈[2,n] sends the mask value shared component To server P1, server P1 performs the unmasking operation locally and calculates the actual output bits to be

[0038] When applied to a scenario where all participants can obtain the output, server P1 will label the corresponding final output line w Send to P i ,P i Will and locally generated obfuscation labels For comparison, if Then the common value on the output line w is α w =0; if Then the common value on the output line w is α w =1; otherwise, P i Abort the protocol. If the protocol does not abort, all parties share the masked value shared component. All participants P i Can calculate the actual output bits

[0039] A constant-round multi-party private function computation system based on a multi-party garbled circuit, comprising:

[0040] Initialization module, used to generate parameters required for calculating multi-party private functions;

[0041] The first data processing module is used to hide the private circuit C using the multi-party oblivious expansion permutation algorithm f The topology of the system is used to blind the required parameters;

[0042] The second data processing module is used to calculate the multi-party private function according to the blinded parameters using a secure multi-party computing algorithm.

[0043] The present invention constructs a multi-party private function computing protocol based on homomorphic encryption and a multi-party private function computing protocol based on a switching network, respectively, to achieve the correctness and privacy of the multi-party private function computing scheme, can resist the corruption of up to n-1 participants by semi-honest adversaries, and allows corrupt participants to collude, and can effectively improve the efficiency of the multi-party private function computing protocol when calculating large circuits in a high-latency network environment. BRIEF DESCRIPTION OF THE DRAWINGS

[0044] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the invention and, together with the description, serve to explain the principles of the invention.

[0045] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.

[0046] Figure 1 is a flow chart of the present invention;

[0047] Figure 2 It is a system structure diagram of the present invention;

[0048] Figure 3 is a schematic diagram of a Boolean circuit of the present invention;

[0049] Figure 4 Schematic diagram of the mapping relationship of the present invention;

[0050] Figure 5 A flow chart of parameters required for generating the present invention;

[0051] Figure 6 This is a flow chart of the calculation private function of the present invention. DETAILED DESCRIPTION

[0052] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.

[0053] It should be noted that all directional indications in the embodiments of the present invention (such as up, down, left, right, front, back, etc.) are only used to explain the relative position relationship, movement status, etc. between the various components under a certain specific posture (as shown in the accompanying drawings). If the specific posture changes, the directional indication will also change accordingly.

[0054] In addition, the descriptions of "first", "second", etc. in the present invention are for descriptive purposes only and should not be understood as indicating or implying their relative importance or implicitly indicating the number of the indicated technical features. Therefore, the features defined as "first" or "second" may explicitly or implicitly include at least one of such features. In addition, the technical solutions between the various embodiments can be combined with each other, but this must be based on the fact that they can be implemented by ordinary technicians in this field. When the combination of technical solutions is contradictory or cannot be implemented, it should be deemed that such combination of technical solutions does not exist and is not within the scope of protection required by the present invention.

[0055] The general solution of secure multi-party computing technology is not applicable to situations where the function itself is also sensitive and needs to be kept confidential. The purpose of private function computing proposed in this invention is to securely calculate the function without leaking any information other than the information revealed by the output. Except for the size of the function and the upper limit of the input and output lengths, other information about the function is hidden.

[0056] Example 1

[0057] A constant-round multi-party private function calculation method based on a multi-party garbled circuit, comprising:

[0058] S100 generates parameters required for calculating multi-party private functions;

[0059] S200 uses a multi-party oblivious expansion permutation algorithm to hide private circuit C f The topology of the system is used to blind the required parameters;

[0060] S300 uses a secure multi-party computing algorithm to calculate multi-party private functions based on blinded parameters.

[0061] Preferably, S200 uses a multi-party oblivious expansion permutation algorithm to hide the private circuit C f The topology of the required parameters is blinded including:

[0062] Server P1 completes the FALSE tag generated by itself locally Shares components with mask values The blind operation obtains the blind FALSE label Shares components with the blinded mask value

[0063] The server and client execute the two-party oblivious expansion permutation algorithm, and server P1 inputs the topology map π f , blinded bit string Blinded Bits XOR value of all blinded bits

[0064] For each incoming line iw h ∈IW, h=1,...,N, server P1 sets its blinded FALSE label to The shared component with the blinded mask value is

[0065] Client P i ,i∈[2,n] input global label offset R i , masking the shared component and FALSE label

[0066] Client P i ,i∈[2,n] gets the blind FALSE label Shares components with the blinded mask value Server P1 cannot obtain additional information.

[0067] For i∈[2,n], client P i and server P1 respectively execute the two-party oblivious expansion permutation algorithm, where the input of server P1 is the mapping π f , blinded bit string Blinded Bits XOR value of all blinded bits Client P i The input is the global label offset R i , masking the shared component and FALSE label Finally, for i∈[2,n], client P i The output is its own blinded FALSE label Shares components with the blinded mask value Server P1 cannot obtain additional information.

[0068] Preferably, S100 generates the parameters required to calculate the multi-party private function, referring to Figure 5 ,include:

[0069] S101 server P1 uses the compiler to compile the server's private function f into a Boolean circuit C f , randomly assign the outgoing line index line index, and extract the mapping relationship π between the outgoing line and the incoming line f ;

[0070] S102 Open private circuit C to the client f Some information Where m represents the number of circuit input lines, g represents the number of circuit gates, o represents the number of circuit output lines, OW is the outgoing line index set, and IW is the incoming line index set. is the final output line index;

[0071] S103 The server and client uniformly randomly generate preprocessing information locally, and the global label offset R i , FALSE label TRUE label Mask value shared components The superscript i represents the participant P i The generated data, the FALSE label corresponds to the true value 0 on the Boolean circuit line, and the TRUE label corresponds to the true value 1 on the Boolean circuit line;

[0072] S104 Server P1 generates a blinded bit string uniformly and randomly locally Blinded Bits

[0073] Server P1 compiles the private function f into a Boolean circuit C f , extracting public information about Boolean circuits Sent to all clients, where m represents the number of circuit input lines, g represents the number of circuit gates, o represents the number of circuit output lines, ow is the outgoing wire index, and OW is the outgoing wire index set, the number is M = m + go, that is, OW: {ow1,…,ow M}; iw is the incoming wire index, IW is the incoming wire index set, the number is N = 2g, that is, IW: {iw1,…,iw N}; is the final output line index, i.e. The above indexes are all chosen randomly.

[0074] The output line represents the Boolean circuit C f The input lines and the output lines of all non-output gates are the set, and the input lines represent the Boolean circuit C f The set of input lines for each gate in the , and the mapping relationship π between the outgoing and incoming lines is extracted from the randomly assigned outgoing and incoming line indices f , the mapping from OW to IW is defined as π f :OW→IW, mapping π f ow i Mapping to iw j (i.e. π f (ow i )→iw j ), if and only if ow i ∈OW and iw j ∈IW corresponds to circuit C f Note that if one outgoing wire corresponds to multiple incoming wires, the mapping π f Not a function, but its inverse Always a function. Circuit structure example is Figure 3 As shown, the Boolean circuit C f The outgoing wires are ow1 to ow7, the incoming wires are iw1 to iw8, the circuit input wires are x1 to x5, and the circuit output wires are The input lines x1 to x5 are connected to the output lines ow1 to ow5 in sequence. i and incoming line iw j The connection relationship can be seen from the mapping relationship π f ; Mapping relationship πf Examples include Figure 4 As shown, i Mapping to iw j (i.e. π f (ow i )→iw j ).

[0075] The security parameter is selected as κ, and each participant P i Uniformly randomly select a κ-bit global label offset R i ←{0,1} κ ; for each outgoing line k ∈OW, k=1,...,M uniformly randomly generates FALSE labels of κ bits Shares components with a 1-bit mask value in Set TRUE label Output lines for each output gate Uniformly randomly generate mask value sharing components FALSE tag TRUE label

[0076] Server P1 is for each incoming line iw h ∈IW, h=1,...,N randomly generates a blinded bit string of κ bits and 1-bit blinding bit in

[0077] Preferably, S300 uses a secure multi-party computing algorithm to calculate the multi-party private function based on the blinded parameters, referring to Figure 6 ,include:

[0078] S301: Each participant in the multi-party private function jointly executes the obfuscation algorithm, and the server P1 obtains the obfuscated circuit output;

[0079] S302: Each participant obtains the mask value shared component of the input line from the other participant, performs XOR operation on all the mask value shared components to obtain the mask value, performs XOR operation on the input and the mask value to obtain a common value, obtains an obfuscation label based on the common value, and sends the obfuscation label to the server P1;

[0080] S303: Based on the blinded bit string and the information provided by the topology mapping, server P1 locally calculates the garbled circuit according to the topology structure to obtain the final public value;

[0081] S304: Server P1 obtains the mask value of the final output line from each participant, performs an XOR operation on the final public value and the mask value of the final output line, and outputs the actual bit.

[0082] Preferably, each participant in calculating the multi-party private function in S301 jointly executes the obfuscation algorithm, and the server P1 obtains the obfuscated circuit output including:

[0083] Participant P i Set the TRUE label to The blinded TRUE label is

[0084] The participants jointly execute the garbled circuit algorithm, and the input of each participant is the global label offset R i , the mask value sharing component of the output line Mask value sharing component of incoming line The mask value shared component of the final output line FALSE label for outgoing line and TRUE label FALSE tag for incoming lines and TRUE label FALSE label for the final output line and TRUE label

[0085] The output obtained by server P1 is the garbled circuit GC, and the client cannot obtain additional information.

[0086] Each participant P i For each incoming line iw h ∈IW, h=1,...,N Set blind TRUE labels All participants P i Jointly execute the garbled circuit algorithm, where each participant P i The input is the global label offset R i , the mask value sharing component of the output line Mask value sharing component of incoming line FALSE label for outgoing line and TRUE label FALSE tag for incoming lines and TRUE label FALSE label for the final output line and TRUE label Finally, the server P1 obtains the output as the garbled circuit GC, which consists of all the garbled NAND gates. Composition, of which Here g represents the gate index, the input lines are u, v and the output line is w, each α, β∈{0,1}, α and β represent the common values on the input lines u and v respectively, || represents the splicing symbol; F 2 Represents a dual-key pseudo-random function, with two κ-bit labels as input As the key, g||j is used as the seed of the pseudo-random function, which outputs a κ-bit pseudo-random value.

[0087] Preferably, in step S302, each participant obtains a mask value shared component of an input line from another participant, performs an XOR operation on all mask value shared components to obtain a mask value, performs an XOR operation on the input and the mask value to obtain a common value, obtains an obfuscation label using the common value, and sends the obfuscation label to the server P1, including:

[0088] For each Boolean circuit input line w, if P i Provides input value for this input line , then the other participants P j (j≠i) Send mask value shared component Give P i , P i Sending public values To all parties involved;

[0089] Participant P j Put the label on the input line w Send to server P1;

[0090] Finally, server P1 has all the labels on the input line w

[0091] For each circuit input line w: If P i This input line provides the input value , then the other participants P j (j≠i) Send mask value shared component Give P i , P i Calculate mask value If P i Provides input value for input line w The participants, then P i Sending public values To other participants; each participant P j Enter this into the label on line w Send to server P1. Finally, server P1 has all the labels on the input line w

[0092] Preferably, in step S303, based on the blinded bit string and the information provided by the topology mapping, the server P1 locally calculates the obfuscation circuit according to the topology structure, and obtaining the final public value includes:

[0093] Incoming line OW and outgoing line IW label connection stage: For the gate g currently being calculated, the input lines are u, v, and the output line is w. α and β represent the common values on the input lines u and v respectively, and γ represents the common value on the output line w. P1 maps π according to the topology f The information provided is obtained by using a blinded bit string Get the confusion labels on the input lines u and v respectively

[0094] According to the topological mapping π f Provided information, P1 locally calculates the obfuscated NAND gates according to the topology P1 uses the input line u,v calculated in the previous step to confuse the label and calculate P1 will and the confusion labels generated on the output line w For comparison, if Then the common value on the output line w is γ=0; if Then the common value on the output line w is γ = 1; otherwise, P1 terminates the protocol;

[0095] If the protocol is not aborted, it is repeated until all obfuscation gates are computed.

[0096] Preferably, in step S304, the server P1 obtains the mask value shared components of the final output line from each participant, performs an XOR operation on all the mask value shared components to obtain a mask value, performs an XOR operation on the final common value and the mask value of the final output line, and outputs the actual bits including:

[0097] For each circuit’s final output line w, client P i , i∈[2,n] sends the mask value shared component To server P1, server P1 performs the unmasking operation locally and calculates the actual output bits to be

[0098] When applied to a scenario where all participants can obtain the output, server P1 will label the corresponding final output line w Send to P i ,P i Will and locally generated obfuscation labels For comparison, if Then the common value on the output line w is αw =0; if Then the common value on the output line w is α w =1; otherwise, P i Abort the protocol. If the protocol does not abort, all parties share the masked value shared component. All participants P i Can calculate the actual output bits

[0099] The multi-party oblivious extension permutation algorithm is composed of a two-party oblivious extension permutation algorithm, and the implementation methods of the two-party oblivious extension permutation algorithm include a two-party oblivious extension permutation algorithm based on a switching network and a two-party oblivious extension permutation algorithm based on homomorphic encryption.

[0100] Assume that the multi-party oblivious expansion permutation algorithm runs between server P1 and client P2, including the following steps:

[0101] Set the security parameter to κ, server P1 inputs the extended permutation π:{1,...,M}→{1,...,N}, a random control bit θ←{0,1}, and a random blinding bit string t j ←{0,1} κ and a random blinding bit θ j ←{0,1}, where j=1,…,N represents the incoming line index. The input of client P2 is a random global label offset R←{0,1} κ , random label L i ←{0,1} κ and a random mask value λ i ←{0,1}, where i=1,…,M represents the outgoing line index.

[0102] Client P2 uses the homomorphic encryption key generation algorithm to generate a public-private key pair (pk, sk)← $ Gen(1 κ ), and sends the public key pk to the server P1, where the homomorphic encryption scheme is E=(Gen,Enc,Dec), Gen is the key generation algorithm, Enc is the encryption algorithm, and Dec is the decryption algorithm. In addition, the client P2 uses the public key pk to encrypt the global label offset R and label L it inputs. i , mask value λ i Encrypt to ciphertext Enc pk (R||0),Enc pk (L1||λ1),…,Enc pk (L M ||λ M ) and sends it to server P1.

[0103] According to the extended permutation π, server P1 calculates the blinded tag and the ciphertext of the blinded tag and sends them to client P2.

[0104] If the control bit θ j =0, then P1 calculates and sends j=1,…,N for P2;

[0105] If the control bit θ j =1, then P1 calculates and sends Give to P2.

[0106] Client P2 decrypts the ciphertext using the private key sk

[0107] get

[0108] Blinded Labels Blinded Labels Server P1 cannot obtain additional information.

[0109] Furthermore, based on the two parties' inadvertent extension of the permutation algorithm process in the exchange network, assuming that the algorithm runs between the server P1 and the client P2, the following steps are included:

[0110] The common input is a switching network with a security parameter of κ, q switches, and N input / outputs, where each switch has two inputs, two outputs, and two selection bits.

[0111] The input of server P1 is (1) According to the extended permutation π:{1,...,M}→{1,...,N}, server P1 generates the selection bit vector of the switching network Each selected bit is 1 bit of data; (2) blinded bit string vector where t j ∈{0,1} κ ; (3) Blind bit vector where θ j ∈{0,1}; (4) control bit θ∈{0,1}.

[0112] The input of client P2 is (1) global label offset R←{0,1} k ; (2) Label vector (NM additional virtual inputs are added, and the virtual inputs are replaced with random k-bit data), where L j ∈{0,1} κ ; (3) Mask value vector (NM additional virtual inputs are added, and the virtual inputs are replaced with random 1-bit data), where λ j ∈{0,1}.

[0113] Define 2q+N circuit lines in the switching network as w1,…,w 2q+N , for 1≤i≤2q+N, client P2 uniformly randomly generates a κ-bit bit string r for each line of the switching network i ∈{0,1} κ and 1 bit of bit τ i ∈{0,1}; for each input line w i and w j , and the output line w k and w l For switch u, client P2 calculates the random encoding table as shown in Table 1, where s0(u) and s1(u) represent the two selection bits of the u-th switch, each of which is 1 bit of data; a ,a∈[0,3] respectively includes two κ-bit data and Two 1-bit data and

[0114] Server P1 and client P2 perform 4-choose-1 oblivious transfer (OT), where the input of server P1 (as the receiver) is s(u)=2s1(u)+s0(u), s(u) is two bits of data, and the input of client P2 (as the sender) is (T0, T1, T2, T3). Server P1 obtains the random code T of switch u by selecting bits s1(u) and s0(u) s(u) .

[0115] Table 1 Random coding table

[0116]

[0117]

[0118] For each input line w i , client P2 blinds its input bits Directly sent to server P1; In addition, server P1 and client P2 perform 2-choose-1 oblivious transfer (OT), where the input of server P1 (as the receiver) is a 1-bit control bit θ, and the input of client P2 (as the sender) is Server P1 obtains the blinded input bit string Client P2 cannot obtain additional information.

[0119] Server P1 uses the blinded input from client P2 z iAnd the random coding of the switching network, calculate the switching network according to the topological sorting, for each input line w i and w j , and the output line w k and w l The server P1 completes the following operations: If s1(u)=0, then otherwise If s0(u)=0, then otherwise Server P1 finally obtains the blinded values of all output lines of the switching network. Server P1 will further blind these values using its random value and send them to client P2. That is, for each output line w k ,w l The output switch h (1≤h≤N / 2) of server P1 calculates:

[0120]

[0121] For each output line w k ,w l The output switch h (1≤h≤N / 2), client P2 uses the random bit string r generated by itself k ,r l and random bits τ k ,τ l The above values are unblinded to obtain the final blinded labels and blinded mask values, that is, So, finally client P2 gets the output Server P1 cannot obtain additional information.

[0122] All participants have private circuit C f (Consists of only NAND gates) Where m represents the number of circuit input lines, g represents the number of circuit gates, o represents the number of circuit output lines, OW is the outgoing line index set, and IW is the incoming line index set. is the final output line index; n represents the number of participants, and κ represents the security parameter. In addition, each participant P i Has the following private inputs: (1) global label offset R i ∈{0,1} κ ; (2) The mask value sharing component of the input line, output line and final output line (3) Labels for your own incoming, outgoing, and final output lines

[0123] Calculate the confusion and not gate in Here g represents the gate index, the input lines are u, v and the output line is w, each α, β∈{0,1}, α and β represent the common values on the input lines u and v respectively, || represents the splicing symbol; F 2 represents a two-key pseudorandom function (it requires two keys and remains secure as long as at least one key is secret), taking as input two κ-bit tags As the key, g||j is used as the seed of the pseudo-random function, and a κ-bit pseudo-random value is output.

[0124] Server P1 obtains the garbled circuit GC, which consists of all the garbled NAND gates. composition.

[0125] Assume that a two-party oblivious extension permutation algorithm based on homomorphic encryption runs between server P1 and client P2, which includes the following steps:

[0126] Set the security parameter to κ, server P1 inputs the extended permutation π:{1,...,M}→{1,...,N}, a random control bit θ←{0,1}, and a random blinding bit string t j ←{0,1} κ and a random blinding bit θ j ←{0,1}, where j=1,…,N represents the incoming line index. The input of client P2 is a random global label offset R←{0,1} κ , random label L i ←{0,1} κ and a random mask value λ i ←{0,1}, where i=1,…,M represents the outgoing line index.

[0127] Client P2 uses the homomorphic encryption key generation algorithm to generate a public-private key pair (pk, sk)← $ Gen(1 k ), and sends the public key pk to the server P1, where the homomorphic encryption scheme is E=(Gen,Enc,Dec), Gen is the key generation algorithm, Enc is the encryption algorithm, and Dec is the decryption algorithm. In addition, the client P2 uses the public key pk to encrypt the global label offset R and label L it inputs. i , mask value λ i Encrypt to ciphertext Enc pk (R), Enc pk (L1),…,Enc pk (L M ), Enc pk (λ1),…,Enc pk (λ M ) and sends it to server P1.

[0128] According to the extended permutation π, server P1 calculates the blinded tag and the ciphertext of the blinded tag and sends them to client P2.

[0129] If the control bit θ=0, P1 calculates and sends and to P2;

[0130] If the control bit θ=1, P1 calculates and sends and Give to P2.

[0131] Client P2 decrypts the ciphertext using the private key sk and get

[0132] Blinded Labels Blinded Labels Server P1 cannot obtain additional information.

[0133] The multi-party obfuscation algorithm includes the following steps:

[0134] Input: All parties have private circuit C f (Consists of only NAND gates) Where m represents the number of circuit input lines, g represents the number of circuit gates, o represents the number of circuit output lines, OW is the outgoing line index set, and IW is the incoming line index set. is the final output line index; n represents the number of participants, and κ represents the security parameter. In addition, each participant P i Has the following private inputs: (1) global label offset R i ∈{0,1} κ ; (2) The mask value sharing component of the input line, output line and final output line (3) Labels for your own incoming, outgoing, and final output lines

[0135] Calculation: Calculate the confusion and not gate in Here g represents the gate index, the input lines are u, v and the output line is w, each α, β∈{0,1}, α and β represent the common values on the input lines u and v respectively, || represents the splicing symbol; F 2 represents a two-key pseudorandom function (it requires two keys and remains secure as long as at least one key is secret), taking as input two k-bit tags As the key, g||j is used as the seed of the pseudo-random function, and a κ-bit pseudo-random value is output.

[0136] Output: Server P1 obtains the garbled circuit GC, which consists of all the garbled NAND gates composition.

[0137] Example 2

[0138] A constant-round multi-party private function computation system based on a multi-party garbled circuit, comprising:

[0139] Initialization module, used to generate parameters required for calculating multi-party private functions;

[0140] A data processing module is used to hide the private circuit C according to the required parameters using a multi-party oblivious expansion permutation algorithm f The topological structure calculates multi-party private functions.

[0141] The present invention constructs a multi-party private function computing protocol based on homomorphic encryption and a multi-party private function computing protocol based on a switching network, respectively, to achieve the correctness and privacy of the multi-party private function computing scheme, can resist the corruption of up to n-1 participants by semi-honest adversaries, and allows corrupt participants to collude, and can effectively improve the efficiency of the multi-party private function computing protocol when calculating large circuits in a high-latency network environment.

[0142] The foregoing description is intended only to provide specific embodiments of the present invention, which will enable those skilled in the art to understand and implement the present invention. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention is not intended to be limited to the embodiments shown herein, but is intended to be accorded the widest scope consistent with the principles and novel features claimed herein.

Claims

1. A constant-round multi-party private function calculation method based on a multi-party garbled circuit, characterized in that: include: Generate the parameters required to calculate the multi-party private function; Using multi-party oblivious extension permutation algorithm to hide private circuit C f The topology of the system is used to blind the required parameters; The multi-party oblivious expansion permutation algorithm is used to hide the private circuit C f The topology of the required parameters is blinded including: Server P1 generates a FALSE tag locally Shares components with mask values The blind operation obtains the blind FALSE label Shares components with the blinded mask value The server and client execute the two-party oblivious expansion permutation algorithm, and server P1 inputs the topology map π f , blinded bit string Blinded Bits XOR value of all blinded bits Client P i ,i∈[2,n] input global label offset R i , masking the shared component and FALSE label Client P i ,i∈[2,n] gets the blind FALSE label Shares components with the blinded mask value Server P1 cannot obtain additional information; Use secure multi-party computing algorithm to calculate multi-party private functions based on blinded parameters; The parameters required for generating and calculating the multi-party private function include: Server P1 uses the compiler to compile the server's private function f into a Boolean circuit C f , randomly assign the outgoing line index line index, and extract the mapping relationship π between the outgoing line and the incoming line f ; Open private circuit C to the client f Some information Where m represents the number of circuit input lines, g represents the number of circuit gates, o represents the number of circuit output lines, OW is the outgoing line index set, and IW is the incoming line index set. is the final output line index; The server and client uniformly randomly generate preprocessing information locally, and the global label offset R i , FALSE label TRUE label Mask value shared components The superscript i represents the participant P i The generated data, the FALSE label corresponds to the true value 0 on the Boolean circuit line, and the TRUE label corresponds to the true value 1 on the Boolean circuit line; Server P1 generates a blinded bit string uniformly and randomly locally Blinded Bits The method of using a secure multi-party computing algorithm to calculate a multi-party private function based on blinded parameters includes: Each participant in the computation of the multi-party private function jointly executes the obfuscation algorithm, and server P1 obtains the obfuscated circuit output; Each participant obtains the mask value shared component of the input line from the other participant, performs XOR operation on all the mask value shared components to obtain the mask value, performs XOR operation on the input and the mask value to obtain the public value, obtains the obfuscation label through the public value, and sends the obfuscation label to the server P1; Based on the information provided by the blinded bit string and the topology map, server P1 locally calculates the garbled circuit according to the topology structure and obtains the final public value; Server P1 obtains the mask value of the final output line from each participant, performs an XOR operation on the final public value and the mask value of the final output line, and outputs the actual bit.

2. The method for calculating a constant-round multi-party private function based on a multi-party obfuscation circuit according to claim 1, characterized in that: Each participant in the calculation of the multi-party private function jointly executes the obfuscation algorithm, and the server P1 obtains the obfuscated circuit output including: Participant P i Set the TRUE label to The blinded TRUE label is The participants jointly execute the garbled circuit algorithm, and the input of each participant is the global label offset R i , the mask value sharing component of the output line Mask value sharing component of incoming line The mask value shared component of the final output line FALSE label for outgoing line and TRUE label FALSE tag for incoming lines and TRUE label FALSE label for the final output line and TRUE label The output obtained by server P1 is the garbled circuit GC, and the client cannot obtain additional information.

3. The constant-round multi-party private function calculation method based on a multi-party obfuscation circuit according to claim 1, characterized in that: Each participant obtains the mask value shared component of the input line from another participant, performs XOR operation on all mask value shared components to obtain a mask value, performs XOR operation on the input and the mask value to obtain a common value, obtains an obfuscation label based on the common value, and sends the obfuscation label to the server P1, including: For each Boolean circuit input line ow, if P i Provides input value for this input line , then the other participants P j (j≠i) Send mask value shared component Give P i , P i Sending public values To all parties involved; Participant P j Put the label on the input line now Send to server P1; Finally, server P1 owns all the labels on the input line ow 4. The method for calculating a constant-round multi-party private function based on a multi-party obfuscation circuit according to claim 1, characterized in that: According to the blinded bit string and the information provided by the topology mapping, the server P1 locally calculates the obfuscation circuit according to the topology structure to obtain the final public value, including: The incoming line OW and the outgoing line IW are labeled and connected. For the gate g currently being calculated, the input lines are u and v, and the output line is w. α and β represent the common values on the input lines u and v respectively, and γ represents the common value on the output line w. P1 maps π according to the topology f The information provided is obtained by using a blinded bit string Get the confusion labels on the input lines u and v respectively According to the topological mapping π f Provided information, P1 locally calculates the obfuscated NAND gates according to the topology P1 uses the input line u,v calculated in the previous step to confuse the label and calculate P1 will and the confusion labels generated on the output line w For comparison, if Then the common value on the output line w is γ=0; if Then the common value on the output line w is γ = 1; otherwise, P1 terminates the protocol; If the protocol is not aborted, it is repeated until all obfuscation gates are computed.

5. The constant-round multi-party private function calculation method based on a multi-party obfuscation circuit according to claim 1, characterized in that: The server P1 obtains the mask value of the final output line from each participant, performs an XOR operation on the final public value and the mask value of the final output line, and outputs the actual bits including: For each circuit’s final output line w, client P i , i∈[2,n] sends the mask value shared component To server P1, server P1 performs the unmasking operation locally and calculates the actual output bits to be When applied to a scenario where all participants can obtain the output, server P1 will label the corresponding final output line w Send to P i ,P i Will and locally generated obfuscation labels For comparison, if Then the common value on the output line w is α w =0; if Then the common value on the output line w is α w =1; otherwise, P i Abort the protocol. If the protocol does not abort, all parties share the masked value. All participants P i Can calculate the actual output bits 6. A constant-round multi-party private function calculation system based on a multi-party obfuscation circuit, applied to a constant-round multi-party private function calculation method based on a multi-party obfuscation circuit according to any one of claims 1 to 5, characterized in that: include: Initialization module, used to generate parameters required for calculating multi-party private functions; The first data processing module is used to hide the private circuit C using the multi-party oblivious expansion permutation algorithm f The topology of the system is used to blind the required parameters; The second data processing module is used to calculate the multi-party private function according to the blinded parameters using a secure multi-party computing algorithm.