Hidden analog-to-digital conversion system, distributed processing device, hidden analog-to-digital conversion method, and computer program product

Through the hidden analog-to-digital conversion system, n dispersed processing devices are used to perform analog-to-digital conversion, the problem of low analog-to-digital conversion efficiency under the quotient transfer conditions is solved, and efficient analog-to-digital conversion is achieved.

CN116508088BActive Publication Date: 2025-08-15NIPPON TELEGRAPH & TELEPHONE CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202080106070.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-10-16
Publication Date
2025-08-15
Estimated Expiration
2040-10-16

AI Technical Summary

Technical Problem

The prior art cannot efficiently perform modulus transformation when the quotient transfer conditions are not met.

Method used

The hidden analog-to-digital transformation system is adopted, and the first secret dispersion transformation, bit decomposition, addition, first analog-to-digital transformation, second analog-to-digital transformation and second secret dispersion transformation are performed through n dispersion processing devices, and the analog-to-digital transformation protocol is used to perform the analog-to-digital transformation without satisfying the quotient transfer conditions.

Benefits of technology

It realizes efficient analog-to-digital transformation without meeting the quotient transfer conditions, and improves the efficiency and reliability of analog-to-digital transformation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116508088B_ABST
    Figure CN116508088B_ABST
Patent Text Reader

Abstract

The hidden modular conversion system of the present invention converts the (k,n)-secretly distributed share [[a]] p Transformed into shares distributed secretly by (k,k)-addition p , each bit of a'0 is (k,n)-secretly distributed to obtain the share [[a'0]] 2^|p| , the share p Each bit of 1 is (k,n)-secretly distributed to obtain the share [[a1]] 2^|p| , and get the share of the bit representation of a'0+a1 [[a'0+a1]] 2^(|p|+1) , the share [[a'0+a1]] 2^(|p|+1) The most significant bit is set to the share [[q]] 2 , according to the share [[q]] 2 Get share [[q]] Q ,according to p 0、 p 1 get p 0mod Q、 p 1mod Q, set as share<a'> Q , the share<a'> Q Transform to (k,n)-secret distribution and obtain the (k,n)-secret distributed share [[a']] Q , according to the share [[a']] Q and share [[q]] Q Calculate [[a]] Q .
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a technology for performing modulus transformation in secret computing. Background Art

[0002] Modulus-to-digital conversion, which transforms the modulus of a secret shared value, is a fundamental process frequently used in secret computing. Therefore, improving the efficiency of this conversion significantly impacts the overall speed of secret computing.

[0003] As a conventional technique for an efficient analog-to-digital conversion method when a quotient shift condition is satisfied, Non-Patent Document 1 is known.

[0004] Prior art literature

[0005] Non-patent literature

[0006] Non-patent document 1: Kikuchi, R., Ikarashi, D., Matsuda, T., Hamada, K. and Chida, K., "Efficient Bit-Decomposition and Modulus-Conversion Protocols with an HonestMajority", Information Security and Privacy-23rd Australasian Conference, ACISP2018, Wollongong, NSW, Australia, July 11-13, 2018, Proceedings (Susilo, W. and Yang, G., eds.), Lecture Notes in Computer Science, Vol. 10946, Springer, pp. 64-82 (online). Summary of the Invention

[0007] Problems to be solved by the invention

[0008] However, the existing technology has the following problem: it cannot be used when the conditions for business transfer are not met.

[0009] An object of the present invention is to provide a hidden analog-to-digital conversion system, a distributed processing device, a hidden analog-to-digital conversion method, and a program that can efficiently perform analog-to-digital conversion even when a quotient shift condition is not satisfied.

[0010] Means for solving problems

[0011] To solve the above problem, according to one aspect of the present invention, a hidden modulus conversion system includes n distributed processing devices. The n distributed processing devices each include a first secret distributed conversion unit, a bit decomposition unit, an addition unit, a first modulus conversion unit, a second modulus conversion unit, a second secret distributed conversion unit, and a share calculation unit. Two of the n distributed processing devices, p0 and p1, each include a second modulus conversion unit. Let the share of plaintext a obtained by (k,n)-secret distribution under modulus p be share [[a]] p , let n in (k,n)-secret distribution be any integer greater than 3, let k be any integer greater than 2 and less than n, and let the share of the plaintext a that is (k,k)-additively secret-distributed under modulo p be the share p , n first secret distribution transformation units convert the (k,n)-secret-distributed share [[a]] p Transformed into the (k, k)-additive secret distributed shares of the distributed processing devices p0 and p1 p , the bit decomposition unit of the distributed processing device p0 uses the quota p 0Calculate a'0:= p 0+(2 |p| -p), the n-bit decomposition unit performs (k,n)-secret distribution on each bit of a'0 to obtain the share [[a'0]] represented by the bit. 2^|p| , for share p Each bit of 1 is (k,n)-secretly distributed to obtain the share represented by the bit [[a1]] 2^|p| , n added parts according to the share [[a'0]] 2^|p| and share[[a1]] 2^|p| , the bit representation of a'0+a1 is obtained by the addition circuit [[a'0+a1]] 2^(|p|+1) , the share [[a'0+a1]] 2^(|p|+1) The most significant bit is set to the share [[q]] 2 , n first analog-to-digital conversion units transform through mod 2→mod Q, according to the share [[q]] 2 Get share [[q]] Q , the two second analog-to-digital conversion parts are respectively based on p 0、 p 1 get p 0mod Q、 p 1mod Q, set as share<a'> Q , n second secret distribution conversion units will share<a'> Q Transform to (k,n)-secret distribution and obtain the (k,n)-secret distributed share [[a']] Q , n shares are calculated based on the share [[a']] Q and share [[q]] Q Calculate [[a]] Q =[[a']] Q -p[[q]] Q .

[0012] To solve the above problem, according to another aspect of the present invention, a distributed processing device is included in a hidden modular conversion system. The distributed processing device includes: a first secret distributed conversion unit, wherein the share of the plaintext a subjected to (k,n)-secret distribution under the modulus p is denoted as share [[a]] p , let n in (k,n)-secret distribution be any integer greater than 3, let k be any integer greater than 2 and less than n, and let the share of the plaintext a that is (k,k)-additively secret-distributed under modulo p be the share p The first secret distribution conversion unit and the (n-1) distribution processing devices together convert the (k,n)-secret distributed share [[a]] p Transformed into the (k, k)-additive secret distributed shares of the distributed processing devices p0 and p1 p ; Bit decomposition unit, set a'0: = p 0+(2 |p| -p), the bit decomposition unit and (n-1) distributed processing devices together perform (k,n)-secret distribution on each bit of a'0 to obtain the share [[a'0]] represented by the bit 2^|p| , for share p Each bit of 1 is (k,n)-secretly distributed to obtain the share represented by the bit [[a1]] 2^|p| ; Adding part, which together with (n-1) distributed processing devices according to the share [[a'0]] 2^|p| and share[[a1]] 2^|p| , the bit representation of a'0+a1 is obtained by the addition circuit [[a'0+a1]] 2^(|p|+1) ; The first analog-to-digital conversion unit converts the share [[a'0+a1]] 2^(|p|+1) The most significant bit is set to the share [[q]] 2 The first analog-to-digital conversion unit and (n-1) distributed processing devices perform mod 2→mod Q conversion, and according to the share [[q]] 2 Get share [[q]] Q The second secret distribution conversion unit will p 0mod Q、 p 1mod Q is set as share<a'> Q The second secret distribution conversion unit and (n-1) distributed processing devices together convert the share<a'> Q Transform to (k,n)-secret distribution and obtain the (k,n)-secret distributed share [[a']] Q and a share calculation unit, which together with the (n-1) distributed processing devices calculates the value of the share [[a']] Q and share [[q]] Q Calculate [[a]] Q =[[a']] Q -p[[q]] Q .

[0013] Effects of the Invention

[0014] According to the present invention, analog-to-digital conversion can be efficiently performed even when the quotient transfer condition is not satisfied. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] Figure 1 This is a diagram showing a configuration example of a concealed analog-to-digital conversion system according to the first embodiment.

[0016] Figure 2 This is a diagram showing an example of a processing flow of the concealed analog-to-digital conversion system according to the first embodiment.

[0017] Figure 3 This is a functional block diagram of the distributed processing device according to the first embodiment.

[0018] Figure 4 It is a figure which shows the result of the actual machine experiment.

[0019] Figure 5 This is a diagram showing an example of the configuration of a computer to which this method is applied. DETAILED DESCRIPTION

[0020] Hereinafter, the embodiments of the present invention will be described. In addition, in the drawings used for the following description, components having the same function or steps performing the same processing are marked with the same reference numerals, and repeated descriptions are omitted. In the following description, the symbols used in the text are “ →” The symbols should be written directly above the character that follows, but due to limitations in text notation, they are written immediately before the character. In the formula, these symbols are written in their original positions. Furthermore, unless otherwise specified, processing performed on each element of a vector or matrix is assumed to apply to all elements of that vector or matrix.

[0021] <First embodiment>

[0022] First, the notation in this embodiment will be described.

[0023] <Notation>

[0024] ◎k: Secret sharing threshold. For example, set it to 2.

[0025] n: The number of secret distribution, in other words, the number of secret calculations. For example, it is set to 3.

[0026] ◎P:prime number. For example, let it be the Mersenne prime number 2 61 -1.

[0027] ◎p: The number of bits in P. When P is a Mersenne prime, it remains prime. For example, it is set to 61.

[0028] ◎[[x]] y : The mod y element is (k,n)-secretly distributed.

[0029] ◎ <x> y : The mod y factor x is secretly distributed using (k,k)-addition.

[0030] ◎[[x]] 2^m :Change [[x]] 2 The number of shares in the form of m is arranged. Sometimes it is also regarded as a bit representation of a value. In addition, A^B in the addition sign means A B 、A_B means A B .

[0031] Next, two secret distribution methods, namely, (k,n)-secret distribution and (k,k)-addition secret distribution, used in this embodiment will be described.

[0032] <(k,n)-Secret Scattering>

[0033] The so-called (k,n)-secret distribution is to divide the input plaintext into n pieces (called shares) and distribute them to n different entities (called "party") P = (p0,···,p n-1 ), the plaintext can be recovered by gathering any k shares, and if less than k-1 shares are gathered, all information about the plaintext cannot be obtained. Examples include Shamir's secret distribution and copy secret distribution. In this embodiment, the group in which all shares are gathered so that the plaintext is a certain value x is distributed using (k,n)-secret distribution under modulo y is denoted as [[x]] y For each share, square p r The share of y r Here, let r = 0,…,n-1.

[0034] <(k,k)-additive secret dispersion>

[0035] The so-called (k,k)-secret distribution refers to the case where n=k in the (k,n)-secret distribution. Unless all parties' shares are combined, it cannot be restored. The (k,k)-secret distribution based on copy secret distribution is particularly called additive secret distribution. It is the simplest method to restore the plaintext by simply adding k shares. In this embodiment, the group where all shares are combined such that the plaintext is a certain value x and distributed by (k,k)-additive secret distribution under modulo y is denoted as <x> y , the square p r The share is recorded as <x> y r 。

[0036] <Non-quotient transfer modular transformation protocol>

[0037] Next, the non-quotient transfer modular transformation protocol used in this embodiment will be described.

[0038] The non-quotient transfer modular transformation protocol used in this embodiment can efficiently perform modular transformation over a prime field even when the conditions for quotient transfer are not satisfied. The quotient transfer condition mentioned here means that there are a specified number of idle bits. In the protocol, it is set that a'0 + a1 = a + qp + 2 |p| -p = a + 2 |p| -(1 - q)p. Where, if q = 0, then a'0 + a1 = 2 |p| -(p - a), and according to a < p, a'0 + a1 is less than 2 [[ID=ID=18]] |p| 。That is, On the other hand, if q = 1, then a'q + a1 = 2 |p| + a, and according to a ≥ 0, a'0 + a1 is 2 |p| Above. That is, Therefore, the highest-order bit of a'0 + a1, that is, the |p|-th bit, is equal to q.

[0039] The following describes the non-quotient transfer modular transformation protocol using the above relationship.

[0040] Input: Shares [[a]] after (k, n)-secret sharing p

[0041] Parameters: Number of bits |p| of p

[0042] Output: Shares [[a]] after (k, n)-secret sharing under different modulus Q Q

[0043] Step 1: Transform the shares [[a]] p into shares after (k, k)-additive secret sharing p . Assume k = 2, and p0 and p1 have a share p The transformation from (k,n)-secret sharing to (k,k) additive secret sharing can be performed using a known technique, for example, using Non-Patent Document 1.

[0044] Step 2: Instead of performing mod p on p0, add Z to a'0:= p 0+(2 |p| -p) is calculated, and each bit of a'0 is (k,n)-secretly distributed to obtain the share of bit representation [[a'0]] 2^|p| The bit decomposition can be performed using a known technique, for example, using Non-Patent Document 1.

[0045] Step 3: Square p1 p Each bit of 1 is (k,n)-secretly distributed to obtain the share represented by the bit [[a1]] 2^|p| .

[0046] Step 4: Obtain the bit representation of a'0+a1 through the addition circuit [[a'0+a1]] 2^(|p|+1) . After the addition circuit is calculated, the bit length increases by 1 from |p| to |p|+1.

[0047] Step 5: Replace [[a'0+a1]] 2^(|p|+1) The most significant bit is set to [[q]] 2 q is the share p The quotient of 0+ q when 1=a+qp.

[0048] Step 6: Through mod 2 → mod Q transformation, according to [[q]] 2 Get [[q]] Q For example, the mod2→modQ conversion can be performed using a known technique, such as Non-Patent Document 1.

[0049] Step 7: Squares p0 and p1 are respectively based on p 0、 p 1 get p 0mod Q、 p 1mod Q, set to<a'> Q Here, a'=a+qp mod Q holds.

[0050] Step 8: Distribute the shares obtained through (k,k)-secret<a'> Q Transform to (k,n)-secret distribution and obtain the share [[a']] after (k,n)-secret distribution Q The transformation from (k, k) additive secret sharing to (k, n)-secret sharing can be performed using known techniques, for example, using Non-Patent Document 1.

[0051] Step 9: Calculate [[a]] Q =[[a']] Q -p[[q]] Q And output.

[0052] Next, a hidden analog-to-digital conversion system for implementing the above-mentioned non-quotient transfer analog-to-digital conversion protocol will be described.

[0053] <Secret A / D Conversion System 1 of First Embodiment>

[0054] Figure 1 Represents a configuration example of the stealthy modular transformation system 1 related to the first embodiment, Figure 2 Represents a processing flow example of the stealthy modular transformation system 1.

[0055] The hidden analog-to-digital conversion system 1 includes n distributed processing devices 100 - r , where n is an integer greater than or equal to 3, and r = 0, 1, ..., n-1. The n distributed processing devices 100 - r can communicate with each other via a communication line 2 .

[0056] The hidden modulus conversion system 1 performs a (k,n)-secret distribution of the value a modulo p, and the share [[a]] p Using the number of bits of p as input, |p|, find the share [[a]] obtained by (k,n)-secretly distributing the value a with a modulus Q different from the modulus p. Q , and output. In addition, P and Q are public.

[0057] A distributed processing device is a special device that is constructed by reading a special program into a well-known computer or a special-purpose computer, such as a central processing unit (CPU) and a main storage device (RAM). The distributed processing device performs various processes under the control of the central processing unit. The data input to the distributed processing device and the data obtained through various processes are stored in the main storage device, and the data stored in the main storage device is read out to the central processing unit as needed for other processes. At least a part of each processing unit of the distributed processing device can also be composed of hardware such as an integrated circuit. The various storage units of the distributed processing device can be composed of main storage devices such as RAM (Random Access Memory), or middleware such as a relational database or a key-value storage library. However, each storage unit does not necessarily need to have a distributed processing device inside it, and can also be composed of an auxiliary storage device composed of semiconductor memory elements such as a hard disk, an optical disk or flash memory, and be equipped outside the distributed processing device.

[0058] <Distributed Processing Device 100-r>

[0059] Figure 3 An example of a functional block diagram of the distributed processing device 100 - r is shown.

[0060] The distributed processing device 100 - r includes a first secret distribution conversion unit 101 , a bit decomposition unit 103 , an addition unit 105 , a first analog-to-digital conversion unit 109 , a second analog-to-digital conversion unit 111 , a second secret distribution conversion unit 115 , and a share calculation unit 117 .

[0061] In addition, in this embodiment, k in the (k,k)-additive secret sharing is set to k=2, and n in the (k,n)-secret sharing is set to an arbitrary integer value greater than or equal to 3. k is set to an arbitrary integer value greater than or equal to 2 and less than or equal to n, for example, k=2 and n=3.

[0062] Below, using Figure 2 The processing of each part is explained.

[0063] <First Secret Distribution and Conversion Unit 101>

[0064] The n first secret distribution conversion units 101 convert the (k, n)-secret-distributed share [[a]] p Transformed into shares distributed secretly by (k,k)-addition p (S101) As described above, k in the (k, k)-additive secret sharing is set to k=2, and the distributed processing device 100-0 corresponding to the square p0 has a share p 0, the distributed processing device 100-1 corresponding to the square p1 has a share p 1.

[0065] <Bit Decomposition Unit 103>

[0066] The bit decomposition unit 103 of the distributed processing device 100-0 uses the quota p 0 and p, without mod p, but by adding on Z, for a'0:= p 0+(2 |p| -p) is calculated. In addition, when p When 0 is a scalar value, p 0+(2 |p| -p) is the sum of the indicator values. p When 0 is a vector, p 0+(2 |p| -p) refers to p 0 plus (2 |p| -p).

[0067] The n-bit decomposition unit 103 performs (k,n)-secret distribution on each bit of a'0 to obtain the share [[a'0]] represented by the bit. 2^|p| (S103-0).

[0068] In addition, the n bit decomposition units 103 have a share of the distributed processing device 100-1. p Each bit of 1 is (k,n)-secretly distributed to obtain the share represented by the bit [[a1]] 2^|p| (S103-1).

[0069] <Adding Unit 105>

[0070] The n adding units 105 calculate the value of the share [[a'0]] obtained in S103-0 and S103-1. 2^|p| and share[[a1]] 2^|p| , through the addition circuit, we get the bit representation of a'0+a1 [[a'0+a1]] 2^(|p|+1) (S105).

[0071] <First A / D Converter 109>

[0072] [[a'0+a1]] 2^(|p|+1) The most significant bit is set to the share [[q]] 2 In addition, q is the share p The quotient of 0+ q when 1=a+qp.

[0073] The n first analog-to-digital conversion units 109 perform mod 2→mod Q conversion, and according to the share [[q]] 2 , get share [[q]] Q (S109).

[0074] <Second A / D Converter 111>

[0075] The two second analog-to-digital converters 111 (the second analog-to-digital converters 111 of the distributed processing device 100-0 and the distributed processing device 100-1) are respectively based on p 0、 p 1 get p 0mod Q、 p 1mod Q, set as share<a'> Q (S111) Here, a'=a+qp mod Q holds.

[0076] For example, (i) when p 0, p When 1 is less than Q, we can directly get p 0, p 1 as p 0mod Q、 p 1modQ, when p 0, p When 1 is Q or above, it can be calculated p 0mod Q, p 1mod Q, (ii) can also be ignored p 0, p The relationship between 1 and Q can be calculated. p 0mod Q, p 1mod Q.

[0077] Since only the second A / D converter 111 of the distributed processing device 100 - 0 and the distributed processing device 100 - 1 performs S111 , only the distributed processing device 100 - 0 and the distributed processing device 100 - 1 may include the second A / D converter 111 .

[0078] <Second Secret Distribution and Conversion Unit 115>

[0079] The n second secret distribution conversion units 115 convert the (k, k)-secret-distributed shares<a'> Q Transform to (k,n)-secret distribution and obtain the (k,n)-secret distributed share [[a']] Q (S115).

[0080] <Share Calculation Unit 117>

[0081] The n share calculation units 117 calculate the value of the share [[a']] Q and share [[q]] Q Calculate [[a]] Q =[[a']] Q -p[[q]] Q (S117) and output as the output value of the secret analog-to-digital conversion system.

[0082] <Effect>

[0083] According to the above configuration, even when the conditions for quotient transfer are not satisfied, analog-to-digital conversion can be performed efficiently.

[0084] (Processing efficiency)

[0085] The processing efficiency of the algorithm is evaluated. In the hidden analog-to-digital conversion system according to this embodiment, the communication volume is |Q|+|p| bits and |p| rounds.

[0086] <Actual machine performance evaluation>

[0087] Figure 4 The following is the result of a multi-party computation on three machines.

[0088] ◎CPU: Xeon Gold 6144 3.5GHz, 6cores x 2sockets

[0089] ◎Memory: 768GB

[0090] ◎NW: 10Gbps ring topology

[0091] ◎OS: CentOS 7.3

[0092] Three scales were recorded: 1,000, 1,000, and 10,000,000 items. The actual number of rounds was measured by setting the delay to a maximum of 100ms. Throughput is [M op / s], and the number of rounds is dimensionless. In addition to the passive model, the performance of the active model (extended from the passive version) is also shown. The active model has an 8-bit security parameter and an attack detection rate of approximately 99%. Unlike computationally intensive security, offline attacks are impossible, so this probability is sufficient to suppress attacks.

[0093] <Other Modifications>

[0094] The present invention is not limited to the above-mentioned embodiments and modifications. In addition, the various processes described above are not limited to being performed in a time series as described, but may also be performed in parallel or individually according to the processing capacity of the device performing the processing or as needed. In addition, appropriate changes can be made within the scope of the purpose of the present invention.

[0095] <Program and Recording Medium>

[0096] The above-mentioned various treatments can be Figure 5 The storage unit 2020 of the computer shown reads a program for executing each step of the above-mentioned method, and operates the control unit 2010, the input unit 2030, the output unit 2040, etc. to implement the method.

[0097] The program describing the processing contents can be recorded on a computer-readable recording medium, such as a magnetic recording device, an optical disc, a magneto-optical recording medium, or a semiconductor memory.

[0098] Furthermore, the program can be distributed by, for example, selling, transferring, or renting a removable recording medium such as a DVD or CD-ROM that stores the program. Alternatively, the program can be distributed by storing the program in a storage device of a server computer and forwarding the program from the server computer to other computers via a network.

[0099] A computer that executes such a program, for example, first temporarily stores a program recorded in a removable recording medium or a program forwarded from a server computer in its own storage device. Then, when executing a process, the computer reads the program stored in its own storage medium and executes the process according to the read program. In addition, as another embodiment of the program, the computer can also directly read the program from the removable recording medium and execute the process according to the program. Furthermore, it can also be that each time the program is forwarded from the server computer to the computer, the process according to the obtained program is executed in sequence. In addition, it can also be a structure in which the program is not forwarded from the server computer to the computer, but the processing function is realized only by the execution instruction and the result obtained, that is, the structure in which the above-mentioned process is executed by a so-called ASP (Application Service Provider, Application Service Provider) type service. In addition, it is assumed that the program of this method contains information for the processing of the electronic computer and in accordance with the program (although not a direct instruction to the computer, it has the nature of data that specifies the processing of the computer, etc.).

[0100] In this embodiment, the present apparatus is configured by executing a predetermined program on a computer, but at least a portion of the processing contents may be realized by hardware.< / x> < / x> < / x>

Claims

1. A hidden analog-to-digital conversion system, comprising n distributed processing devices, wherein: The n distributed processing devices each include a first secret distribution conversion unit, a bit decomposition unit, an addition unit, a first analog-to-digital conversion unit, a second analog-to-digital conversion unit, a second secret distribution conversion unit, and a share calculation unit. Two distributed processing devices p0 and p1 among the n distributed processing devices each include a second analog-to-digital conversion unit. Let the share of the plaintext a that is (k,n)-secretly distributed under modulus p be share [[a]] p , let n in (k,n)-secret distribution be any integer greater than 3, let k be any integer greater than 2 and less than n, and let the share of the plaintext a that is (k,k)-additively secret-distributed under modulo p be the share p , n first secret distribution conversion units convert the (k,n)-secret-distributed share [[a]] p The distributed processing devices p0 and p1 each have a share p 0、 p 1's share of the (k,k)-additive secret distribution p , The bit decomposition unit of the distributed processing device p0 uses a quota p 0Calculate a'0:= p 0+(2 |p| -p), The n bit decomposition units obtain the bit representation share [[a'0]] by arranging the shares obtained by performing (k,n)-secret distribution on each bit of a'0 into |p| pieces. 2^|p| , and get the share p The shares of each bit of 1 that are (k,n)-secretly distributed are arranged into |p| shares, and the shares represented by the bits are [[a1]] 2^|p| , The n adding units are based on the share [[a'0]] 2^|p| and the said share [[a1]] 2^|p| , the bit representation of a'0+a1 is obtained by the addition circuit [[a'0+a1]] 2^(|p|+1) , The share [[a'0+a1]] 2^(|p|+1) The most significant bit is set to the share [[q]] 2 , n of the first analog-to-digital conversion units perform mod 2→mod Q conversion, according to the share [[q]] 2 Get share [[q]] Q , The second analog-to-digital conversion parts are respectively based on p 0、 p 1 get p 0mod Q、 p 1mod Q, set as share<a'> Q , The n second secret distribution conversion units convert the shares<a'> Q Transform to (k,n)-secret distribution and obtain the (k,n)-secret distributed share [[a']] Q , The n share calculation units calculate the value of the share [[a']] Q and the said share [[q]] Q Calculate [[a]] Q =[[a']] Q -p[[q]] Q .

2. A distributed processing device, comprising: The first secret distribution conversion unit assumes that the share of the plaintext a obtained by (k,n)-secret distribution under modulo p is share [[a]] p , let n in (k,n)-secret distribution be any integer greater than 3, let k be any integer greater than 2 and less than n, and let the share of the plaintext a that is (k,k)-additively secret-distributed under modulo p be the share p The first secret distribution conversion unit and the (n-1) distribution processing devices together convert the (k,n)-secret distributed share [[a]] p The distributed processing devices p0 and p1 each have a share p0、 p 1's share of the (k,k)-additive secret distribution p ; Bit decomposition unit, let a'0:= p 0+(2 |p| -p), the bit decomposition unit and the (n-1) distribution processing devices together obtain the bit representation share [[a'0]] by arranging the shares obtained by performing (k,n)-secret distribution on each bit of a'0 into |p| pieces. 2^|p| , and get the share p The shares of each bit of 1 that are (k,n)-secretly distributed are arranged into |p| shares, and the shares represented by the bits are [[a1]] 2^|p| ; The adding unit, together with the (n-1) distributed processing devices, generates an output signal according to the share [[a'0]] 2^|p| and the said share [[a1]] 2^|p| , the bit representation of a'0+a1 is obtained by the addition circuit [[a'0+a1]] 2^(|p|+1) ; The first analog-to-digital conversion unit converts the share [[a'0+a1]] 2^(|p|+1) The most significant bit is set to the share [[q]] 2 The first analog-to-digital conversion unit and the (n-1) distributed processing devices perform mod 2→mod Q conversion, and according to the share [[q]] 2 Get share [[q]] Q ; The second secret distribution conversion unit will p 0mod Q、 p 1mod Q is set as share<a'> Q The second secret distribution conversion unit and (n-1) the distributed processing devices together convert the share<a'> Q Transform to (k,n)-secret distribution and obtain the (k,n)-secret distributed share [[a']] Q ; as well as A share calculation unit, which works together with (n-1) of the distributed processing devices according to the share [[a']] Q and the said share [[q]] Q Calculate [[a]] Q =[[a']] Q -p[[q]] Q .

3. A hidden analog-to-digital conversion method, using a hidden analog-to-digital conversion system comprising n distributed processing devices, The n distributed processing devices each include a first secret distribution conversion unit, a bit decomposition unit, an addition unit, a first analog-to-digital conversion unit, a second analog-to-digital conversion unit, a second secret distribution conversion unit, and a share calculation unit. Two distributed processing devices p0 and p1 among the n distributed processing devices each include a second analog-to-digital conversion unit. The hidden modulus conversion method comprises: In the first secret distribution transformation step, let the share of the plaintext a (k,n)-secret distribution under modulus p be share [[a]] p , let n in (k,n)-secret distribution be any integer greater than 3, let k be any integer greater than 2 and less than n, and let the share of the plaintext a that is (k,k)-additively secret-distributed under modulo p be the share p , n first secret distribution conversion units convert the (k,n)-secret-distributed share [[a]] p The distributed processing devices p0 and p1 each have a share p 0、 p 1's share of the (k,k)-additive secret distribution p ; Bit decomposition step, let a'0:= p 0+(2 |p| -p), the n bit decomposition units obtain the bit representation share [[a'0]] which is a sequence of |p| shares obtained by performing (k,n)-secret distribution on each bit of a'0. 2^|p| , and get the share p The shares of each bit of 1 that are (k,n)-secretly distributed are arranged into |p| shares, and the shares represented by the bits are [[a1]] 2^|p| ; In the adding step, n adding parts are added according to the share [[a'0]] 2^|p| and the said share [[a1]] 2^|p| , the bit representation of a'0+a1 is obtained by the addition circuit [[a'0+a1]] 2^(|p|+1) ; The first modular conversion step converts the share [[a'0+a1]] 2^(|p|+1) The most significant bit is set to the share [[q]] 2 , n of the first analog-to-digital conversion units perform mod 2→mod Q conversion, according to the share [[q]] 2 Get share [[q]] Q ; The second analog-to-digital conversion step, the two second analog-to-digital conversion parts are respectively based on p 0、 p 1 get p 0mod Q、 p 1mod Q, set as share<a'> Q ; In the second secret distribution transformation step, n of the second secret distribution transformation units convert the shares<a'> Q Transform to (k,n)-secret distribution and obtain the (k,n)-secret distributed share [[a']] Q ; as well as In the share calculation step, n share calculation units calculate the value of the share [[a']] Q and the said share [[q]] Q Calculate [[a]] Q =[[a']] Q -p[[q]] Q .

4. A computer program product comprising a computer program for causing a computer to function as the distributed processing apparatus according to claim 2.

Citation Information

Patent Citations

  • Runtime customization infrastructure

    CN105593919A

  • Distributed privacy-preserving verifiable computation

    US20190372768A1