Method and system for securely computing the size relationship of data in multi-party data

By having the referee generate public and private keys, the participating parties and the applicant encrypt the data, and the referee decrypts the data to calculate the size relationship, the problem of calculating the size of any two parties' data without disclosing the data is solved, thus achieving data confidentiality and accuracy.

CN116566678BActive Publication Date: 2026-05-12LONGTEL INC
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
LONGTEL INC
Filing Date
2023-05-13
Publication Date
2026-05-12

AI Technical Summary

Technical Problem

In the existing technology, how to calculate the data size relationship between any two parties without disclosing the data of any of the participants is an urgent problem to be solved.

Method used

The referee generates public and private keys, the participants and applicants encrypt the data, the referee uses a decryption model to calculate the data size relationship, and determines the data size by the ratio and the decryption value.

Benefits of technology

It enables accurate calculation of the size relationship between any two parties' data without disclosing the data of the participating parties, thus ensuring data confidentiality.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116566678B_ABST
    Figure CN116566678B_ABST
Patent Text Reader

Abstract

This application relates to a method and system for securely computing the size relationship of data in multi-party data, belonging to the field of secure multi-party computation. The method includes a referee obtaining a request instruction sent by the applicant, retrieving a set of prime numbers p and q, and sending a public key to the applicant and participating parties; the participating parties then use a random value r... i and public key pair data d i The encryption yields the first encryption result c. i The data is then sent to the applicant. The applicant encrypts the data d0 using a random value r0 and the public key to obtain a second encrypted result c0. The encrypted results of any two parties are compared to obtain a ratio. The adjudicator obtains the decrypted value based on the ratio and the decryption model. The applicant then uses the decrypted value to determine the size relationship between the data of the two parties. This application has the effect of calculating the size relationship between the data of any two parties without disclosing the data of any participating party.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of secure multi-party computation, and in particular to a method and system for securely computing the size relationship of data in multi-party data. Background Technology

[0002] Secure multi-party computation (SMC) addresses the problem of privacy-preserving collaborative computation among a group of distrustful participants. SMC ensures the independence of inputs and the correctness of computation while preventing the disclosure of input values ​​to other participants. It primarily addresses the challenge of securely computing an agreed-upon function in the absence of a trusted third party. SMC plays a crucial role in scenarios such as electronic elections, electronic voting, electronic auctions, secret sharing, and threshold signatures.

[0003] Therefore, how to calculate the size relationship between the data of any two parties without disclosing the data of any of the participants is an urgent problem to be solved. Summary of the Invention

[0004] This application provides a method and system for securely calculating the size relationship of data in multi-party data, which has the feature of calculating the size relationship of data between any two parties without disclosing the data of any one of the participating parties.

[0005] The purpose of this application is to provide a method for securely calculating the size relationship of data in multi-party data.

[0006] The aforementioned objective of this application is achieved through the following technical solution:

[0007] A method for securely calculating the size relationship of data in multi-party data, comprising a referee, participating parties, and a requester applying to calculate the size relationship of data, with k participating parties, k≥1, and the data of each participating party denoted as d. i , where i∈I, I={i|i∈N * And i≤k}, the applicant's data is denoted as d0, the method includes:

[0008] The adjudicator receives the request instruction sent by the applicant. The adjudicator retrieves a set of prime numbers p and q, and determines the public key (n, g) based on the prime numbers p and q, where n = pq, g ∈ G, and G = {g | g ∈ N*, g <n 2 And (L(g) λ modn 2 )) -1} are integers, where, λ = lcm(p-1, q-1), where lcm(,) is the least common multiple function. The referee sends the public key (n, g) to the applicant and the participants respectively. The referee generates a private key (λ, μ) based on a set of prime numbers p and q and the function L(x), where μ = L(x1). -1 mod n, x1 = g λ modn 2 The adjudicator is also used to determine the value A according to the request instruction and estimation rules.

[0009] The participants use numerical value A to represent data d. i Perform encryption to generate encrypted value m i Then based on the random value r i The received public key (n, g) is used to encrypt the value m. i Encryption is performed to obtain the first encrypted result c. i and send the first encrypted result c i To the applicant, r i ∈H, H={r i |r i ∈N * And r i <n};

[0010] The applicant encrypts data d0 using a numerical value A to generate an encrypted value m0, and then encrypts the encrypted value m0 using a random value r0 and the received public key (n, g) to obtain a second encrypted result c0, where r0 ∈ H; the applicant is also used to, upon receiving the first encrypted result c0 sent by the participating party... i At that time, based on the second encryption result c0 and the first encryption result c i Construct ratio α≠β, α={α|α∈N * And α≤k+1}, β={β|β∈N * And β≤k+1}, and send the ratio f to the referee;

[0011] The adjudicator inputs the ratio f into the decryption model y = (L(x2)·μ)modn to obtain the decrypted value y, and returns the decrypted value y to the applicant; the x2 = f λ modn 2 .

[0012] In a preferred embodiment, this application can be further configured such that: the adjudicator is also configured to determine the numerical value A according to the request instruction and the estimation rules, including:

[0013] The request instruction includes data types;

[0014] Based on the data type, match w arrays corresponding to the data type in the database. Each array includes multiple values, where w ∈ W, and W = {w | w ∈ N}. * And w≥2};

[0015] Calculate the difference between any two values ​​in each array;

[0016] Extract the precision value corresponding to the minimum difference of w arrays and construct a precision value sequence (t1,…,t). w );

[0017] Obtain the precision value sequence (t1,…,t) w The first mode, the first proportion corresponding to the first mode, the second mode, and the second proportion corresponding to the second mode are given in the precision value sequence (t1,…,t). w The second mode is the precision value with the highest percentage among the values ​​in the first mode; the second mode is the precision value with the second percentage value that is only smaller than the first percentage value.

[0018] When the first percentage value reaches the first preset value, the first mode is taken as the target value t;

[0019] When the first percentage value is lower than the first preset value, determine whether the sum of the first percentage value and the second percentage value is greater than the first preset value;

[0020] If so, the average of the first mode and the second mode shall be taken as the target value t;

[0021] If not, the precision value sequence (t1,…,t) w The accuracy value whose percentage value is higher than the second preset value is taken as the target accuracy value.

[0022] The average value of the target precision value is taken as the target value t;

[0023] Calculate the value A = 10 t .

[0024] In a preferred embodiment, this application can be further configured such that the minimum difference is taken as its absolute value.

[0025] In a preferred embodiment, this application can be further configured such that: the participating party uses a numerical value A to adjust the data d. i Perform encryption to generate encrypted value m i Includes: Participants will provide data d i Multiply by A, then take the integer part to obtain the encrypted value m. i .

[0026] In a preferred embodiment, this application can be further configured such that: the step based on a random value r... iThe received public key (n, g) is used to encrypt the value m. i Encryption is performed to obtain the first encrypted result c. i include:

[0027] In a preferred embodiment, this application can be further configured such that: the applicant encrypts data d0 using a numerical value A to generate an encrypted value m0, which includes: the applicant multiplies data d0 by A and takes the integer part to obtain the encrypted value m0.

[0028] In a preferred embodiment, this application can be further configured such that: encrypting the encrypted value m0 according to the random value r0 and the received public key (n, g) to obtain the second encrypted result c0 includes:

[0029] This application provides a method for securely calculating the size relationship of data in multi-party data. The method first involves each participating party encrypting its own data and sending the encryption result to the applicant. The applicant also encrypts its own data and then constructs a ratio based on the size relationship between any two parties' data that it needs to know. The ratio f is then sent to the adjudicator; the adjudicator substitutes the ratio f into the decryption model to obtain the decrypted value y. When the decrypted value y is less than 0, the data of participant α is less than the data of participant β; when the decrypted value y is equal to 0, the data of participant α and participant β are equal; when the decrypted value y is greater than 0, the data of participant α is greater than the data of participant β. Since the applicant does not know the original data of participant α and participant β, but only knows the size relationship, this application can achieve the purpose of calculating the size relationship of any two parties' data without the participants disclosing their own data.

[0030] The second objective of this application is to provide a system for securely calculating the size relationship of data in multi-party data.

[0031] The second objective of this application is achieved through the following technical solution:

[0032] A system for securely calculating the size relationship of data in multi-party data includes multiple terminal devices, the system being used to execute the method for securely calculating the size relationship of data in multi-party data as described in any of the preceding claims, wherein the multiple terminal devices are participants in the method.

[0033] In summary, this application includes at least one of the following beneficial technical effects:

[0034] This application can determine the size relationship of any two data points between the applicant and the participating parties without the participating parties disclosing their own data. Even if the adjudicator has a decryption model, it will not obtain the data of the participating parties and the applicant. As for the applicant, it only knows the size relationship of the two data points it needs and does not know the original data of the participating parties, thus ensuring the confidentiality of the data. Attached Figure Description

[0035] Figure 1 This is a schematic diagram of a system for securely calculating the data size relationship in multi-party data according to an embodiment of this application.

[0036] Figure 2 This is a flowchart of a method for securely calculating the size relationship of data in multi-party data according to an embodiment of this application.

[0037] Figure 3 This is a schematic diagram of the structure of a smart terminal according to an embodiment of this application.

[0038] Explanation of reference numerals in the attached diagram: 1. Terminal device; 2. CPU; 3. ROM; 4. RAM; 5. Bus; 6. I / O interface; 7. Input section; 8. Output section; 9. Storage section; 10. Communication section; 11. Driver; 12. Removable medium. Detailed Implementation

[0039] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0040] This application provides a system for securely calculating the size relationship of data in multi-party data, with reference to... Figure 1 The system includes multiple terminal devices 1, which are interconnected. The communication connection between the terminal devices 1 can be via a local area network, the Internet, mobile communication networks, satellite communication networks, or communication methods such as WiFi modules or LoRa modules; the specific communication method is not limited. Each terminal device 1 has a unique device identifier to ensure that the source of data transmitted by each terminal device 1 can be determined.

[0041] In this example, terminal device 1 in the system is divided into three parties: the referee, the participant, and the applicant. The referee can be any of the participants or a third party independent of them. When the referee is any of the participants, it is not a fixed terminal device 1. Instead, it is randomly selected as the referee in the current calculation of the data relationship between the two parties. Therefore, in the next calculation, the referee may become a participant or continue to act as a referee. When the referee is a third party independent of the participants, to avoid storing excessive encrypted data and risking data leakage during a network attack, terminal device 1 is still randomly selected as the referee. In other words, the referee is not a fixed terminal device 1.

[0042] At the same time, the applicant is not a fixed terminal device 1. When terminal device 1 has a need to calculate the size relationship between the two parties' data and issues a request instruction to calculate the size relationship between the data, terminal device 1 is the applicant. When terminal device 1 is not the applicant, but needs to provide the data it has, terminal device 1 will be included as a participant in the set for calculating the size relationship between the two parties' data.

[0043] Based on the above scenario involving referees, participants, and applicants, this application proposes a method for securely calculating the data size relationship in multi-party data. For ease of subsequent explanation, the number of participants is denoted as k (k≥1), and the amount of data possessed by each participant is denoted as d. i , where i∈I, I={i|i∈N * And i≤k}, and the data owned by the applicant is denoted as d0. Data d i Data d0 can be data such as the number of votes in electronic elections, the price of electronic auctions, and corporate revenue. It should be noted that when data d... i When calculating the number of votes in the electronic election for the participating party, data d0 also represents the number of votes in the electronic election for the applicant party, thus ensuring that the calculated relationship between the two parties' data has practical value.

[0044] like Figure 2 As shown, the main process of the method for securely calculating the size relationship of data in multi-party data is described below.

[0045] Step S1: The applicant sends a request instruction to the adjudicator.

[0046] When an applicant needs to know the size relationship between two data sources (K+1 sources, including itself), it generates a request instruction based on its own available data and the data type of that source. Therefore, the request instruction includes a request content and a data type. The request content involves calculating the size relationship between the two data sources, while the data type sent by the applicant is used to calculate this relationship.

[0047] Of course, the applicant may also request the calculation of the size relationship between two or more sides of the K+1 side data, including its own.

[0048] Step S2: The adjudicator receives the request instruction sent by the applicant, retrieves a set of prime numbers p and q, establishes a public key (n, g) based on the prime numbers p and q, establishes a private key (λ, μ) based on the retrieved prime numbers p and q and a preset linear function L(x), and determines the value A based on the data type and estimation rules.

[0049] Specifically, when the referee receives the request instruction, it first randomly selects a set of large prime numbers p and q from a large prime number table. The prime numbers in the large prime number table are typically 512 bits or more. Then, based on a pre-established function, it obtains n = pq, and then selects g, where g must satisfy: g ∈ G, G = {g | g ∈ N*, g <n 2 And (L(g) λ modn 2 )) -1} are integers, where, λ = lcm(p-1, q-1), where lcm(,) is the least common multiple function, thus obtaining the public key (n, g). After generating the public key, the referee sends it to both the applicant and the participants.

[0050] At the same time, the referee also establishes a private key (λ, μ) based on the retrieved prime numbers p and q and the pre-defined linear function L(x), where μ = L(x1). -1 mod n, x1 = g λ modn 2 After establishing the private key (λ, μ), the adjudicator stores it for subsequent decryption of data returned by the applicant. It should be noted that after decrypting the data returned by the applicant, the adjudicator automatically clears the private key (λ, μ) to prevent the adjudicator from using the newly generated private key to decrypt data returned by the applicant in subsequent selections, thus avoiding any confounding events.

[0051] In addition, when the referee receives the request instruction, it will extract the data type from the request instruction and match it with w arrays in the database that correspond to the data type. Each array contains multiple values, where w ∈ W, and W = {w | w ∈ N}. *And w≥2}. In this example, the database is pre-established and stored on a server outside of terminal device 1. The database is composed of publicly available data crawled from the Internet or data input by experts in related fields. When the adjudicator receives a request instruction, it matches the corresponding array in the database according to the data type in the request instruction. For example, if the applicant wants to calculate the ranking of its turnover among the turnovers of party K+1, it matches an array related to turnover in the database. The existence of multiple arrays is due to the different sources of the values. This application places values ​​from the same source in one array, which is why one data type corresponds to multiple arrays. Taking turnover as an example, the sources of turnover values ​​include publicly available data from corporate finance and tax departments, publicly available data from local financial management departments, and data predicted by economic policy experts, etc.

[0052] After the referee obtains w sets of arrays corresponding to the data type, the estimation rules will be used to calculate the w sets of arrays until the value A is determined. The specific calculation process is shown in steps S21 to A28:

[0053] Step S21: Calculate the difference between any two values ​​in each array.

[0054] Step S21: Extract the precision value corresponding to the minimum difference of the w arrays and construct a precision value sequence (t1,…,t). w ).

[0055] First, after calculating the difference between any two values ​​in each array, extract the minimum difference value from each array. Then, transform the minimum differences of the w arrays to obtain the corresponding precision values, thus constructing a precision value sequence (t1,…,t). wThe minimum difference is taken as its absolute value. The conversion relationship between the minimum difference and the precision value is: the magnitude of the precision value is equal to the number of significant decimal places of the minimum difference. For example, there are 5 arrays, namely arrays A, B, C, D, and E. Array A = [1.23432, 2.34672, 9.23012], array B = [0.89271, 8.839217, 9.371836, 8.839217], array C = [3.398479, 3.6379167], array D = [4.19738, 0.397491, 3.398719, 9.038781], array D = [0.94974, 0.37625, 8.378167], array E = [8.2751 ... If we have [.78276,8.162], then the minimum difference value of array A is (2.34672-1.2432) = 1.1124, the minimum difference value of array B has two minimum differences and the minimum difference value is (9.371836-8.839217) = 0.532619, the minimum difference value of array C is (3.6379167-3.398479) = 0.2394377, the minimum difference value of array D is (0.94974-0.37625) = 0.57349, and the minimum difference value of array E is (8.2751-8.162) = 0.1131. Therefore, the precision value corresponding to the minimum difference of array A is 4, the precision value corresponding to the minimum difference of array B is two and both are 6, the precision value corresponding to the minimum difference of array C is 7, the precision value corresponding to the minimum difference of array D is 5, and the precision value corresponding to the minimum difference of array E is 4. Since each array only takes one minimum difference, the precision value sequence is [4,6,7,5,4].

[0056] Step S23: Obtain the precision value sequence (t1,…,t) w The first mode, the first proportion corresponding to the first mode, the second mode, and the second proportion corresponding to the second mode in the precision value sequence (t1,…,t) are given. The first mode refers to the precision value sequence (t1,…,t) w The second mode is the precision value with the highest percentage among the first and second modes.

[0057] For the generated precision value sequence (t1,…,t) w Extract the precision value sequence (t1,…,t) w The first mode and second mode of the precision value sequence [4,6,7,5,4] are calculated, and the ratio of the first mode to all precision values ​​in the precision value sequence is used as the first proportion value. Similarly, the second proportion value corresponding to the second mode is calculated. As in the examples of steps S21 and S22 above, the first mode of the precision value sequence [4,6,7,5,4] is 4, and the corresponding first proportion value is 40%. The second modes are 6, 7 and 5, and the corresponding second proportion values ​​are 20% for each.

[0058] Step S24: When the first proportion value reaches the first preset value, the first mode is taken as the target value t.

[0059] Step S25: When the first percentage value is lower than the first preset value, determine whether the sum of the first percentage value and the second percentage value is greater than the first preset value.

[0060] Step S26: If so, then take the average of the first mode and the second mode as the target value t.

[0061] Step S27: If not, convert the precision value sequence (t1,…,t) w The accuracy value whose percentage of the accuracy value is higher than the second preset value is taken as the target accuracy value, and the average value of the target accuracy value is taken as the target value t.

[0062] Step S28: Calculate the value A = 10 t .

[0063] In this application, the first preset value is 80% and the second preset value is 20%. In other examples, the first and second preset values ​​can be set according to actual needs, but the principle to be followed is: the more different precision values ​​in the precision value sequence, the lower the first and second preset values; the more identical precision values ​​in the precision value sequence, the higher the first and second preset values, thereby improving the accuracy of the calculated value A.

[0064] In summary, after obtaining the precision value sequence (t1,…,t…), w ) and the precision value sequence (t1,…,t w After determining the first mode, second mode, first proportion value corresponding to the first mode, and second proportion value corresponding to the second mode in the calculation, the first proportion value is first compared with the first preset value. When the first proportion value reaches the first preset value, the first mode is taken as the target value t, and the value A = 10 is calculated. t When the first proportion is lower than the first preset value, it is determined whether the sum of the first proportion and the second proportion is greater than the first preset value. If so, the average of the first mode and the second mode is taken as the target value t. At this time, the calculated value A = 10. t Otherwise, the precision value sequence (t1,…,t) will be used. w The precision value whose percentage corresponding to the precision value in the calculation is higher than the second preset value is taken as the target precision value. Then, the average of the target precision values ​​is taken as the target value t. At this time, the calculated value A = 10 is obtained. t .

[0065] It should be noted that the target value t is calculated in steps S21 to S28 above in order to determine the magnitude of the value A, because A = 10.t As t increases, the value A also increases. In this application, after calculating the value A, the adjudicator sends the value A to both the applicant and the participating parties.

[0066] Step S3: The participants use numerical value A to evaluate data d. i Perform encryption to generate encrypted value m i Then based on the random value r i The received public key (n, g) is used to encrypt the value m. i Encryption is performed to obtain the first encrypted result c. i and send the first encrypted result c i To the applicant, r i ∈H, H={r i |r i ∈N * And r i <n}。

[0067] First, after obtaining the value A, the participants calculate the encrypted value m. i =[Ad i ], i.e., the encrypted value m i For the participants to share their own data i The result is obtained by multiplying by A and then rounding down to the integer part. This is used to distinguish the encrypted value m from different participants. i To ensure the accuracy of the magnitude relationship of the final calculated data, the magnitude of value A is compared with the data d. i The correlation is necessary for the calculations in steps S21 to S28 described above to proceed. This ensures that the data d... i After multiplying by A, each resulting encrypted value m i All of them can be distinguished from other encrypted values, such as data d. i The values ​​are 0.265 and 0.255 respectively. Only by multiplying them by 100 and then rounding can their magnitudes be distinguished, resulting in values ​​of 26 and 25. However, in practical applications, since 0.265 and 0.255 cannot be sent in plaintext to the applicant or other participants, neither the applicant nor the participants can determine by how many times to multiply them to ensure that their encrypted values ​​are effectively distinguishable. Therefore, they can only estimate the number of significant decimal places for the group including the applicant and all participants, i.e., estimate the target value t, in order to increase the encrypted value m. i Its use value.

[0068] Then, using the random value r i and the received public key (n, g) to pair with data m i Encrypt to obtain the first encrypted result c. i First encryption result c i The encryption formula is: It should be noted that in order for the judges to successfully calculate the size relationship of the data, the following relationship must be satisfied: n 2 >K+1, which means obtaining all the first encryption results c i They are all in the same cyclic group. Specifically, when all the first encryption results c i When they are all in the same cyclic group, it means For n 2 The quotients after taking the remainder are the same, therefore they can be understood as the first encrypted result c. i and There is a relationship between them. If The first encryption result Conversely, when n 2 When <k+1, it is impossible to guarantee all first encryption results c. i If all the data are in the same cyclic group, the calculated data size relationship will be inaccurate, or even impossible to calculate successfully. The random value r mentioned above... i It is a value randomly selected by the participants from set H, which can effectively prevent other participants, applicants, or judges from using the first encrypted result c. i Estimated data d i Or data m i The specific value.

[0069] In other specific embodiments, a random value r can also be used. i Construct the first encryption result c i and Other proportional relationships between them are not restricted here.

[0070] Step S4: The applicant encrypts the data d0 using the numerical value A to generate an encrypted value m0, and then encrypts the encrypted value m0 using the random value r0 and the received public key (n, g) to obtain the second encrypted result c0, where r0∈H; the applicant also uses this to encrypt the data d0 using the first encrypted result c0 sent by the participating party. i At that time, based on the second encryption result c0 and the first encryption result c i Construct ratio α≠β, α={α|α∈N * And α≤k+1}, β={β|β∈N * And β≤k+1}, and send the ratio f to the referee.

[0071] Similarly, to ensure that data d0 is not leaked to other participants or the adjudicator, the applicant needs to encrypt data d0 using the public key (n, g). Specifically, first, m0 = [Ad0], and then the second encryption result is obtained according to the encryption formula. It should be noted that the formula for calculating the second encryption result c0 also needs to satisfy n 2>K+1. When the inequality n 2 When K+1 is established, the applicant uses the second encryption result c0 and the first encryption result c i Construct ratio

[0072] α≠β, α={α|α∈N * And α≤k+1}, β={β|β∈N * And β≤k+1}.

[0073] It should be noted that when the applicant needs to calculate the size relationship of data from more than V parties, where 3 ≤ V ≤ k+1, the applicant needs to construct V-1 ratios f, and must use the encryption result of one party as the benchmark, that is, use the encryption result of one party as the denominator or numerator. In this example, the encryption result of one party is used as the numerator. For example, if the applicant needs to know the size relationship of the data from the first participant, the second participant, and the fourth participant, then the applicant needs to construct... and or and or and Then send the ratios f1 and f2 to the referee respectively.

[0074] Step S5: The adjudicator inputs the ratio f into the decryption model y = (L(x2)·μ)modn to obtain the decrypted value y, and returns the decrypted value y to the applicant; where x2 = f λ modn 2 .

[0075] It should be noted that, due to the constructed ratio It also includes random values ​​r0 and r. i Therefore, the ratio f cannot accurately reflect the size relationship between the data of participant α and participant β. Thus, it is necessary to decrypt the data by comparing the ratio f using a decryption model corresponding to the encryption formula, and then determine the size relationship between the two data based on the size relationship of the decrypted values ​​y.

[0076] First, based on the private key (λ, μ) calculated in step S2, construct the decryption model y = (L(x2)·μ)modn, x2 = f λ modn 2 Then, the ratio f is input into the decryption model to obtain the decrypted value y.

[0077] It should be noted that the decryption formula y=(L(f) λ modn 2 )·L(g λ modn 2 )-1 From mod n, we can see that since n needs to be satisfied... 2 >g λ And n 2 >f λ Therefore, g λ modn 2 =g λ f λ modn 2 =f λ Furthermore, because the linear function L(x) is represented by L(x) in the formula for calculating μ... -1 It is presented in the form of L(x) in the formula for calculating the decrypted value y, and... Therefore, the decrypted value y can reflect the relationship between the data of participant α and the data of participant β. Specifically, the decrypted value y = c α -c β In other words, when the decrypted value y is less than 0, the data of participant α is less than the data of participant β; when the decrypted value y is equal to 0, the data of participant α and the data of participant β are equal; when the decrypted value y is greater than 0, the data of participant α is greater than the data of participant β.

[0078] As mentioned above, the applicant can also request the calculation of the size relationship of the data of k+1 parties, including itself. This can also be considered as calculating the order of the k+1 parties' data. The specific calculation process is as follows: First, the applicant's encryption result or the encryption result of any participating party is used as the denominator. This example uses the applicant's encryption result as the denominator. Then, construct... i = 1, ..., k; the adjudicator uses the decryption model to analyze f respectively. i Decryption yields y i Sort the decrypted values ​​to obtain the decryption sequence (y1,…,y). k Since the denominator is the applicant's encrypted result, the distance between the applicant's data and its own data is 0, i.e., y0 = 0. Therefore, y0 is placed into the decryption sequence (y1, ..., y...). k The new decryption sequence (y0, y1, ..., y) is obtained from the decryption sequence. k Then, the new decryption sequence (y0, y1, ..., y) is used. k The decrypted value y in ) i Sort the sequence in ascending order to obtain the sorted sequence (s0, s1, ..., s). k The applicant obtains the sorted sequence (s0, s1, ..., s). kAfter that, the sorting of data of each participant, including itself, is known, and the sorting of its own data in the K+1 side is also known. Furthermore, during the calculation process, it will not obtain data from any side other than its own data d0, thus solving the problem of securely calculating the sorting of multi-party data.

[0079] Alternatively, the applicant may request the calculation of the total range of the k+1-way data, including its own data. As in the example above for calculating the ranking of the k+1-way data, the adjudicator uses a decryption model to process f... i Decryption yields y i Sort the decrypted values ​​to obtain the decryption sequence (y1,…,y). k ), and put y0 into the decryption sequence (y1,…,y k The new decryption sequence (y0, y1, ..., y) is obtained from the decryption sequence. k After that, we can start from the new decryption sequence (y0, y1, ..., y). k Select a maximum value and a minimum value, and then subtract the minimum value from the maximum value to obtain the range of data for k+1 sides, including the applicant.

[0080] Therefore, the applicant can construct different ratios as needed, and the adjudicator can then provide the applicant with the required data relationship between two or more parties based on the ratios, or even calculate the total range of data for the k+1 parties, including the applicant. Of course, the applicant can also use this to request the calculation of other relevant data, with the adjudicator providing the calculation results; there are no restrictions on this.

[0081] To better execute the above method, this application also provides an electronic device, which includes a memory and a processor.

[0082] like Figure 3 As shown, the electronic device includes a central processing unit (CPU), which can perform various appropriate actions and processes based on programs stored in read-only memory (ROM) or programs loaded from storage into random access memory (RAM). RAM4 also stores various programs and data required for system operation. CPU2, ROM3, and RAM4 are interconnected via bus 5. Input / output (I / O) interfaces are also connected to bus 5.

[0083] The following components are connected to I / O interface 6: an input section 7 including a keyboard, mouse, etc.; an output section 8 including a cathode ray tube (CRT), liquid crystal display (LCD), etc., and speakers, etc.; a storage section 9 including a hard disk, etc.; and a communication section 10 including a network interface card such as a LAN card, modem, etc. The communication section 10 performs communication processing via a network such as the Internet. A drive 11 is also connected to I / O interface 6 as needed. A removable medium 12, such as a disk, optical disk, magneto-optical disk, semiconductor memory, etc., is installed on drive 11 as needed so that computer programs read from it can be installed into storage section 9 as needed.

[0084] Specifically, according to embodiments of this application, the flowchart above refers to... Figure 2 The described process can be implemented as a computer software program. For example, embodiments of this application include a computer program product comprising a computer program carried on a machine-readable medium, the computer program containing program code for performing the methods shown in the flowchart. In such embodiments, the computer program can be downloaded and installed from a network via communication section 10, and / or installed from removable medium 12. When the computer program is executed by a central processing unit (CPU), it performs the functions defined in the system of this application.

[0085] It should be noted that the computer-readable medium shown in this application can be a computer-readable signal medium or a computer-readable storage medium, or any combination of the two. A computer-readable storage medium can be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this application, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In this application, a computer-readable signal medium can include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. Computer-readable signal media can also be any computer-readable medium other than computer-readable storage media, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to: wireless, wire, optical fiber, RF, or any suitable combination thereof.

[0086] The flowcharts in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in the flowchart may represent a module, segment, or portion of code, which contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that combinations of each block in the flowchart can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0087] On the other hand, this application also provides a computer-readable storage medium, which may be included in the smart terminal described in the above embodiments; or it may exist independently and not assembled into the smart terminal. The aforementioned computer-readable storage medium stores one or more programs, which are used by one or more processors to execute a method describing the secure computation of data size relationships in multi-party data as described in this application.

[0088] The above description is merely a preferred embodiment of this application and an explanation of the technical principles employed. Those skilled in the art should understand that the scope of this application is not limited to technical solutions formed by specific combinations of the above-described technical features, but should also cover other technical solutions formed by arbitrary combinations of the above-described technical features or their equivalents without departing from the foregoing application concept. For example, technical solutions formed by substituting the above features with (but not limited to) technical features with similar functions claimed in this application.

Claims

1. A method for securely calculating the size relationship of data in multi-party data, characterized in that: Let there be a referee, participating parties, and a requester seeking to calculate the relationship between the size of the data. There are k participating parties, k≥1, and the data of the participating parties are denoted as... ,in, The applicant's data is recorded as The method includes: The adjudicator receives the request instruction sent by the applicant. The adjudicator retrieves a set of prime numbers p and q, and determines the public key (n, g) based on the prime numbers p and q, where n = pq, g ∈ G. and Let be an integer, where, , , It is a least common multiple function. The referee sends the public key (n, g) to the applicant and the participants respectively; the referee uses it to determine the least common multiple function based on a set of prime numbers p and q and the function. Generate private key ,in, , The adjudicator is also used to determine the value A according to the request instruction and estimation rules. The determination steps include: The request instruction includes data types; Based on the data type, match w arrays corresponding to the data type in the database. Each array contains multiple values. , ; Calculate the difference between any two values ​​in each array; Extract the precision value corresponding to the minimum difference of w arrays to construct a precision value sequence. ; Obtain the precision value sequence The first mode, the first proportion corresponding to the first mode, the second mode, and the second proportion corresponding to the second mode are given in the sequence. The first mode refers to the precision value sequence. The second mode is the precision value with the highest proportion, and the second mode is the precision value with the second proportion value being only less than the first proportion value. When the first percentage value reaches the first preset value, the first mode is taken as the target value t; When the first percentage value is lower than the first preset value, determine whether the sum of the first percentage value and the second percentage value is greater than the first preset value; If so, the average of the first mode and the second mode shall be taken as the target value t; If not, the precision value sequence The accuracy value whose proportion is higher than the second preset value is taken as the target accuracy value; The average value of the target precision value is taken as the target value t; Calculate the value A=10 t ; The participants used numerical value A to analyze the data. Perform encryption to generate encrypted values Then based on the random value Encrypt the value using the received public key (n, g). Encryption is performed to obtain the first encryption result. and send the first encrypted result. To the applicant, ; The applicant uses numerical value A to analyze the data. Perform encryption to generate encrypted values Then based on the random value Encrypt the value using the received public key (n, g). Encryption is performed to obtain the second encryption result. , The applicant is also used to, upon receiving the first encryption result sent by the participating party, At that time, based on the second encryption result And the first encryption result Construct ratio α≠β and, , and send the ratio f to the referee; The referee inputs the ratio f into the decryption model. In the process, the decrypted value y is obtained, and the decrypted value y is returned to the applicant; .

2. The method for securely calculating the data size relationship in multi-party data according to claim 1, characterized in that: The minimum difference is taken as its absolute value.

3. The method for securely calculating the data size relationship in multi-party data according to claim 1, characterized in that: The participating parties used a numerical value A to analyze the data. Perform encryption to generate encrypted values Including: Participants will provide data Multiply by A, then take the integer part to obtain the encrypted value. .

4. The method for securely calculating the data size relationship in multi-party data according to claim 1, characterized in that: The random value Encrypt the value using the received public key (n, g). Encryption is performed to obtain the first encryption result. include: .

5. The method for securely calculating the data size relationship in multi-party data according to claim 1, characterized in that: The applicant used numerical value A to analyze the data. Perform encryption to generate encrypted values Including: The applicant will submit the data Multiply by A, then take the integer part to obtain the encrypted value. .

6. The method for securely calculating the data size relationship in multi-party data according to claim 1, characterized in that: The random value Encrypt the value using the received public key (n, g). Encryption is performed to obtain the second encryption result. include: 。 7. A system for securely calculating the size relationship of data in multi-party data, used to perform the method as described in any one of claims 1-6, characterized in that: It includes multiple terminal devices (1), which are participants in the method.