A Method and System for Multiparty Secure Computation of Skewness Coefficient

Through homomorphic encryption algorithm and data segmentation technology, the calculation problem of skewness coefficient in multi-party security calculations is solved, and secure calculation and data integrity guarantees are achieved in the absence of trustworthy third parties.

CN116582321BActive Publication Date: 2025-07-22LONGTEL INC
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310537156.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-05-13
Publication Date
2025-07-22
Estimated Expiration
2043-05-13

AI Technical Summary

Technical Problem

In the absence of a trusted third party, how to safely calculate the skewness coefficient between multiple parties to ensure the independence of the input and the correctness of the calculation, while not leaking the input value to other members.

Method used

The homomorphic encryption algorithm is used to encrypt the data by generating the public and private keys by the referee. The additive homomorphic function is used to calculate the secret state and value data, and the referee decrypts the clear state and value data, the participant calculates the difference and mean value value, divides the data and reorganizes it, and finally the initiator calculates the skewness coefficient.

Benefits of technology

On the basis of ensuring the security of private data, the task of calculating skewness coefficients is realized by multiple parties, and the integrity of data transmission is guaranteed through transmission verification functions to ensure the accuracy of calculation results.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure FDA0004226796750000012
    Figure FDA0004226796750000012
  • Figure FDA0004226796750000032
    Figure FDA0004226796750000032
Patent Text Reader

Abstract

The present application provides a method and system for calculating the skewness coefficient in multi-party secure computing, belonging to the field of multi-party secure computing, and is used to provide a new solution for achieving the task of calculating the skewness coefficient of a data group in secure multi-party computing. Among them, the multi-party includes the initiator, referee and multiple participants of the computing task. The participants and the initiator hold private data. The initiator and the referee are two different parties. The method includes: the participants preprocess the data, the referee generates a public key and a private key based on a self-developed homomorphic encryption algorithm, and sends the public key to the participants, so that all participants encrypt their private data. All participants aggregate the encrypted data to the initiator. The initiator calculates the encrypted sum value. The referee decrypts the sum value and sends it to the initiator to obtain the mean value. All participants calculate the variance element according to the mean value, divide and reorganize the variance element and then aggregate it to the initiator, so that the initiator can calculate the standard deviation and then calculate the skewness coefficient.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of multi-party secure computing, and in particular, to a method and system for multi-party secure computing skewness coefficient. Background Art

[0002] Multi-party secure computing is to solve the problem of collaborative computing for protecting privacy among a group of mutually untrusted participants. Secure multi-party computing should ensure the independence of inputs, the correctness of calculations, and at the same time, not disclose the input values to other members participating in the calculation. It mainly aims at the problem of how to securely calculate a predefined function in the absence of a trusted third party. Secure multi-party computing plays an important role in scenarios such as electronic elections, electronic voting, electronic auctions, secret sharing, and threshold signatures. In actual multi-party secure computing tasks, providing targeted secure multi-party computing algorithms aiming at achieving the computing tasks is a problem that those skilled in the art have been working hard to solve. Summary of the Invention

[0003] This application provides a method and system for multi-party secure computing skewness coefficient, which can achieve the task of calculating the skewness coefficient of multi-party secure computing data group.

[0004] In a first aspect, this application provides a method for multi-party secure computing skewness coefficient. The multi-party includes the initiator, referee, and multiple participants of the computing task. The participants and the initiator hold private data. The initiator and the referee are two different parties. The method includes:

[0005] All participants obtain the same preprocessing instruction to preprocess the private data they hold, and obtain the first processed data. The preprocessing instruction includes a rounding instruction;

[0006] The referee generates a set of public keys and private keys, and sends the public keys to all participants; during the calculation process, a set of prime numbers p and q are randomly selected, n = pq, and randomly select λ = lcm(p - 1, q - 1), define the function Calculate μ = (L(g λ mod n 2 )) -1 mod n, where the public key is (n, g), and the private key is (λ, μ);

[0007] All participants use the received public keys to encrypt the first processed data they hold, and obtain the first encrypted data; during the calculation process, the participant randomly selects Calculate where m i represents the first processed data of the participant, and c i represents the first encrypted data of the participant;

[0008] Aggregate all the first encrypted data to the initiator. The initiator obtains the encrypted sum value data based on all the first encrypted data and the constructed additive homomorphic function. During the calculation process, the additive homomorphic function is where f represents the encrypted sum value data and k represents the number of participating parties;

[0009] Send the encrypted sum value data to the referee. The referee decrypts the encrypted sum value data using the private key to obtain the plaintext sum value data, calculates the plaintext mean value data based on the plaintext sum value data and the number of participating parties, and distributes the plaintext mean value data to all participating parties. During the calculation process, construct y = (L(f λ mod n 2 )·μ) mod n, where y represents the plaintext sum value data;

[0010] All participating parties calculate the square of the difference between the first processed data and the plaintext mean value data to obtain the squared difference processed data;

[0011] Each participating party randomly divides the squared difference processed data into no less than two and no more than the number of participating parties parts of random split data, and distributes the random split data one by one among all participating parties. Then each participating party calculates the sum value of all the random split data it receives as the squared difference recombination data;

[0012] All participating parties aggregate the squared difference recombination data to the initiator. The initiator calculates the square root of the result of dividing the sum value of all the squared difference recombination data by the number of participating parties as the standard deviation data;

[0013] All participating parties calculate the fourth power of the ratio of the result of subtracting the plaintext mean value data from the first processed data to the standard deviation data to obtain the third-order element data;

[0014] Each participating party randomly divides the third-order element data into no less than two and no more than the number of participating parties parts of third-order split data, and distributes the third-order split data one by one among all participating parties. Then each participating party calculates the sum value of all the third-order split data it receives as the third-order recombination data;

[0015] All participating parties aggregate the third-order recombination data to the initiator. The initiator calculates the result of dividing the sum value of all the third-order recombination data by the number of participating parties as the skewness coefficient data.

[0016] By adopting the above technical solution, it is possible to complete the task of calculating the skewness coefficient of the private data of all participating parties while ensuring the security of private data.

[0017] Further, each participating party randomly divides the differential processed data into no less than two and no more than the number of participating parties of randomly segmented data, and distributes the randomly segmented data one by one among all participating parties. Then, each participating party calculates the sum value of all the randomly segmented data it receives as the differential recombination data.

[0018] Each participating party randomly divides the differential processed data into the number of participating parties of randomly segmented data, retains one portion of the randomly segmented data for itself, and distributes the other randomly segmented data one by one to other participating parties.

[0019] And / or

[0020] Further, each participating party randomly divides the third-order element data into no less than two and no more than the number of participating parties of third-order segmented data, and distributes the third-order segmented data one by one among all participating parties. Then, each participating party calculates the sum value of all the third-order segmented data it receives as the third-order recombination data.

[0021] Each participating party randomly divides the third-order element data into the number of participating parties of third-order segmented data, retains one portion of the third-order segmented data for itself, and distributes the other third-order segmented data one by one to other participating parties.

[0022] Further, the initiator, the referee party, and the participating parties pre-agree on a transmission verification function, and the transmission verification function is a discrete modular operation function. During the data sending process, the sending party substitutes the data to be sent into the transmission verification function to obtain a first verification code, and sends the first verification code and the data to be sent to the receiving party together. The receiving party substitutes the received data into the transmission verification function to obtain a second verification code, and determines whether the data is tampered with during the transmission process according to whether the first verification code and the second verification code are the same.

[0023] Further, the preprocessing instruction further includes a scaling instruction, and the scaling instruction is before the rounding instruction, and the scaling instruction is used to scale the data by a specified multiple.

[0024] Further, the method for obtaining the preprocessing instruction includes:

[0025] The initiator determines the data scenario and accuracy requirement according to the calculation task, and sends the data scenario to the referee party;

[0026] The referee party determines the associated data of the data scenario in the big data, performs data analysis on the associated data to obtain the general accuracy value of the associated data, and sends the general accuracy value to the initiator;

[0027] The initiator determines the scaling multiple of the scaling instruction in the preprocessing instruction according to the accuracy requirement and the general accuracy value.

[0028] Second aspect, the present application provides a system for calculating the skewness coefficient of multi-party secure computing. The system includes a server and multiple terminals holding private data. The server serves as the referee party, one terminal serves as the initiating party, and at least two terminals respectively serve as participating parties;

[0029] After the initiating party initiates a computing task, all participating parties obtain the same preprocessing instruction to preprocess the private data they hold to obtain first processed data. The preprocessing instruction includes a rounding instruction;

[0030] The referee party generates a set of public keys and private keys and sends the public keys to all participating parties; during the calculation process, a set of prime numbers p and q are randomly selected, n = pq, and λ = lcm(p - 1, q - 1) is randomly selected, and the function is defined. Calculate μ = (L(g λ mod n 2 )) -1 mod n, where the public key is (n, g), and the private key is (λ, μ);

[0031] All participating parties use the received public key to encrypt the first processed data they hold to obtain first encrypted data; during the calculation process, the participating party randomly selects Calculate where m i represents the first processed data of the participating party, and c i represents the first encrypted data of the participating party;

[0032] All the first encrypted data are aggregated to the initiating party, and the initiating party obtains the ciphertext sum value data according to all the first encrypted data and the constructed additive homomorphic function; during the calculation process, the additive homomorphic function is where f represents the ciphertext sum value data, and k represents the number of participating parties;

[0033] The ciphertext sum value data is sent to the referee party. The referee party decrypts the ciphertext sum value data using the private key to obtain the plaintext sum value data, calculates the plaintext mean value data according to the plaintext sum value data and the number of participating parties, and distributes the plaintext mean value data to all participating parties; during the calculation process, construct y = (L(f λ mod n 2 )·μ) mod n, where y represents the plaintext sum value data;

[0034] All participating parties calculate the square of the difference between the first processed data and the plaintext mean value data to obtain the difference square processed data;

[0035] Each participating party randomly divides the differential processed data into at least two and at most the number of participating parties of randomly divided data, and distributes the randomly divided data one by one among all participating parties. Then each participating party calculates the sum value of all the randomly divided data it receives as the differential recombined data;

[0036] All participating parties summarize the differential recombined data to the initiating party, and the initiating party calculates the square root of the result of dividing the sum value of all differential recombined data by the number of participating parties as the standard deviation data;

[0037] All participating parties calculate the fourth power of the ratio of the result of subtracting the clear state mean data from the first processed data to the standard deviation data to obtain the third-order element data;

[0038] Each participating party randomly divides the third-order element data into at least two and at most the number of participating parties of third-order divided data, and distributes the third-order divided data one by one among all participating parties. Then each participating party calculates the sum value of all the third-order divided data it receives as the third-order recombined data;

[0039] All participating parties summarize the third-order recombined data to the initiating party, and the initiating party calculates the result of dividing the sum value of all third-order recombined data by the number of participating parties as the skewness coefficient data.

[0040] Further, the participating party is further configured to:

[0041] Each participating party randomly divides the differential processed data into the number of participating parties of randomly divided data, keeps one copy of the randomly divided data by itself, and distributes the other randomly divided data one by one to other participating parties;

[0042] and / or

[0043] Each participating party randomly divides the third-order element data into the number of participating parties of third-order divided data, keeps one copy of the third-order divided data by itself, and distributes the other third-order divided data one by one to other participating parties.

[0044] Further, the initiating party, the referee party and the participating parties pre-agree on a transmission verification function, and the transmission verification function is a discrete modular operation function. During the data sending process, the sending party substitutes the data to be sent into the transmission verification function to obtain a first verification code, and sends the first verification code and the data to be sent to the receiving party together. The receiving party substitutes the received data into the transmission verification function to obtain a second verification code, and judges whether the data is tampered with during the transmission process according to whether the first verification code and the second verification code are the same.

[0045] Further, the preprocessing instruction is obtained by the initiating party, and the initiating party is further configured to:

[0046] The preprocessing instruction further includes a scaling instruction, which is before the rounding instruction and is used to scale data by a specified multiple.

[0047] Further, the initiator is further configured to:

[0048] The initiator determines the data scenario and accuracy requirement according to the computing task, and sends the data scenario to the referee;

[0049] The referee determines the associated data of the data scenario in the big data, performs data analysis on the associated data to obtain the general accuracy value of the associated data, and sends the general accuracy value to the initiator;

[0050] The initiator determines the scaling multiple of the scaling instruction in the preprocessing instruction according to the accuracy requirement and the general accuracy value.

[0051] In summary, the present application at least includes the following beneficial effects:

[0052] 1. Provided is a method and system for securely calculating the skewness coefficient by multiple parties, which can, based on the homomorphic encryption algorithm, accomplish the task of calculating the skewness coefficient of the private data held by all participating parties while ensuring the security of the private data held by the participating parties;

[0053] 2. Using the transmission verification function can ensure that the data is not tampered with during the transmission process, which is beneficial to ensuring the accuracy of the calculation result; 3. The preprocessing instruction is determined according to the associated data of the data scenario in the big data, which is beneficial to ensuring the rationality of the first processed data.

[0054] It should be understood that the content described in the invention content part is not intended to limit the key or important features of the embodiments of the present application, nor is it used to limit the scope of the present application. Other features of the present application will become easily understood through the following description. Brief Description of the Drawings

[0055] The present application has no drawings. Detailed Embodiments

[0056] To make the objectives, technical solutions and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the embodiments of the present application. Obviously, the described embodiments are some, but not all, of the embodiments of the present application. All other embodiments obtained by those of ordinary skill in the art without creative efforts based on the embodiments in the present application belong to the scope of protection of the present application.

[0057] In addition, the term "and / or" in this text is merely a relational description of associated objects, indicating that there can be three relationships. For example, A and / or B can represent three situations: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / " in this text generally represents an "or" relationship between the preceding and following associated objects.

[0058] The present application provides a method and system for securely calculating the skewness coefficient of multiple parties. Among them, a homomorphic encryption algorithm is used to perform calculations based on private data, and the calculation of the skewness coefficient can be realized on the basis of ensuring the security of private data.

[0059] In a first aspect, an embodiment of the present application discloses a method for securely calculating the skewness coefficient of multiple parties.

[0060] An exemplary operating environment in which the embodiments of the present application can run includes an initiator, a referee, and multiple participants. Among them, the initiator, the referee, and multiple participants are all communicatively connected to each other. Each participant holds private data. The referee and the initiator are two different parties, and the initiator can also be one of the participants.

[0061] In the specific implementation process, the participant is a terminal, the initiator is one of the participants and also a terminal, and the referee is a server.

[0062] This method can be executed by the aforementioned operating environment.

[0063] This method specifically includes the following steps:

[0064] S201: All participants obtain the same preprocessing instruction to preprocess the private data they hold, and obtain the first processed data.

[0065] The preprocessing instruction includes a rounding instruction.

[0066] The preprocessing instruction further includes a scaling instruction. The scaling instruction is before the rounding instruction, and the scaling instruction is used to scale the data by a specified multiple.

[0067] Specifically, the ideal purpose of the preprocessing instruction is to rewrite the valid data bits of all private data into integers by means of scaling, and the size relationship of different private data needs to be reflected. Under the condition of ensuring that the data is completely undistorted, the highest non-zero bit and the lowest non-zero bit of all private data need to be determined separately during rewriting, and then all private data are scaled so that the lowest non-zero bit of all private data is scaled to not less than the unit digit. In the case of enlargement, for example, the highest non-zero bit of the first private data is ten thousand digits and the lowest non-zero bit is thousandth digits, the highest non-zero bit of the second private data is thousandth digits and the lowest non-zero bit is ten thousandth digits, the highest non-zero bit of the third private data is one hundred thousand digits and the lowest non-zero bit is one hundredth digits, then the highest non-zero bit of the three private data is one hundred thousand digits and the lowest non-zero bit is ten thousandth digits, at this time, the three private data are scaled without distortion, and the three private data need to be enlarged ten thousand times. Of course, when rewriting private data, in order to reduce the amount of calculation, it is also necessary to try to make the lowest non-zero bit of all private data not higher than the unit digit. In the case of reduction, for example, the highest non-zero bit of the first private data is 10 billion bits and the lowest non-zero bit is 10,000 bits, the highest non-zero bit of the second private data is 100 million bits and the lowest non-zero bit is 1,000 bits, and the highest non-zero bit of the third private data is 1 billion bits and the lowest non-zero bit is 100,000 bits, then to perform distortion-free scaling of the three private data, the three private data need to be reduced by a thousand times.

[0068] Through the aforementioned scaling principle, ideally, it can be ensured that all valid bits of the scaled private data can be retained after rounding, avoiding distortion of the private data after executing the preprocessing instructions. However, in some special cases, such as when the number of bits between the highest and lowest bits of all private data exceeds the processing capacity of the hardware environment (server, terminal), some precision must be discarded. This situation is essentially to appropriately expand the maximum data range that the hardware environment can handle at a certain precision. The general operation is to discard one to two lowest bits, which will not be elaborated here.

[0069] In some cases, in order to reduce the difficulty of calculation, some precision can be appropriately abandoned on the basis that the calculation result can guarantee a certain precision. In this case, it is necessary to consider the precision requirements of the calculation task, so the method of obtaining preprocessing instructions is also improved here.

[0070] The method for obtaining the pre-processing instruction includes: the initiator determines the data scenario and accuracy requirements according to the computing task, and sends the data scenario to the referee; the referee determines the associated data of the data scenario in the big data, performs data analysis on the associated data to obtain the general accuracy value of the associated data, and sends the general accuracy value to the initiator; the initiator determines the scaling multiple of the scaling instruction in the pre-processing instruction according to the accuracy requirement and the general accuracy value.

[0071] When a computing task is determined, the data group targeted by the computing task and the requirements for the result are also determined. Among them, the targeted data group corresponds to a data scenario, and the data scenario contains tags that can identify associated data in big data. The requirements for the result correspond to the precision requirements. The description of the computing task generally includes the requirements for the result. For example, when calculating money, the unit is accurate to cents (RMB), that is, the precision value is accurate to the hundredth place of yuan (RMB). When calculating power generation, the unit is accurate to the ones place of kilowatt-hours.

[0072] The precision requirement includes the required precision digit. The required precision digit is the limit on the highest position of the lowest non-zero digit, and generally directly reflects that the lowest non-zero digit cannot be higher than the preset digit. The precision requirement is directly determined according to the description of the computing task. Here, a comparison model can be designed, or it can be directly input manually.

[0073] Associated data is the data in big data that carries tags corresponding to the data scenario. The general precision value of associated data is a data range, which reflects the positions of the highest non-zero digit and the lowest non-zero digit of all associated data. Of course, it can also reflect the number of digits between the highest non-zero digit and the lowest non-zero digit of all associated data, that is, the general significant digits.

[0074] According to the capabilities of the hardware environment (server, terminal), a recommended significant digit and a maximum significant digit are also preset in advance. When the initiator determines the scaling factor according to the precision requirement and the general precision value, the recommended significant digit and the maximum significant digit are also considered. The processing logic is as follows: If the number of significant digits of the general precision value is not more than the recommended significant digit, then when scaling, it is scaled according to the scaling factor that scales the lowest non-zero digit of the general precision value to the ones place. If the number of significant digits of the general precision value is more than the recommended significant digit, then when scaling, it is scaled according to the scaling factor that scales the preset digit of the required precision digit to the ones place. If scaling according to the scaling factor that scales the preset digit of the required precision digit to the ones place causes the number of significant digits of the scaled data to exceed the maximum significant digit, then a result of insufficient processing capacity is returned.

[0075] In one example, the scaling factor of the scaling instruction is an integer power of 10. Of course, the scaling factor can be any multiple according to requirements.

[0076] In one example, assume there are k participants (k is an integer and k ≥ 2), and the initiator is also one of the participants. The private data held by the k participants are a i , i = 1, 2,..., k. The private data held by the initiator is a1, and the other private data are held by the other participants in turn. The preprocessing instruction is to multiply the private data by 10 t times (t ∈ N, pre-acquisition) and then round. The first processed data obtained by the participant is m i, i = 1, 2, …, k, the first processing data of the initiator is m1, and the other first processing data respectively correspond to the other participating parties, that is, within the allowable accuracy range, it is considered that m i = 10 t a i .

[0077] S202: The referee generates a set of public keys and private keys, and sends the public keys to all participating parties.

[0078] During the calculation process, the referee randomly selects a set of prime numbers p and q, n = pq, and randomly selects indicating that g is an integer between 1 and n 2 λ = lcm(p - 1, q - 1), indicating that λ is the least common multiple of p - 1 and q - 1; define the function calculate μ = (L(g λ mod n 2 )) -1 mod n, where mod is the remainder function. The obtained results are that the public key is (n, g), and the private key is (λ, μ).

[0079] Regarding the selection of prime numbers, a prime number library (usually large prime numbers for encryption requirements) is pre - stored in the referee, and a set can be randomly selected in each calculation task.

[0080] S203: All participating parties use the received public keys to encrypt the first processing data they hold to obtain the first encrypted data.

[0081] During the calculation process, the participating party randomly selects calculate where m i represents the first processing data of the participating party, c i represents the first encrypted data of the participating party, i = 1, 2, …, k.

[0082] Among them, after the initiator receives (n, g), it randomly selects indicating that r1 is an integer between 1 and n, and calculate c1 is the first encrypted data of the initiator; the other first encrypted data respectively correspond to the other participating parties.

[0083] S204: Aggregate all the first encrypted data to the initiator, and the initiator obtains the ciphertext sum value data according to all the first encrypted data and the constructed additive homomorphic function.

[0084] The aggregation action is specifically that all other participating parties send the first encrypted data to the initiator, and the initiator calculates the ciphertext sum value data. During the calculation process, the constructed additive homomorphic function is Wherein, f represents the encrypted sum value data, and k represents the number of participating parties.

[0085] S205: Send the encrypted sum value data to the referee. The referee decrypts the encrypted sum value data using the private key to obtain the plaintext sum value data, calculates the plaintext average value data based on the plaintext sum value data and the number of participating parties, and distributes the plaintext average value data to all participating parties.

[0086] During the calculation process, construct y = (L(f λ mod n 2 )·μ) mod n, where y represents the plaintext sum value data. The plaintext average value data is equal to y / k. It should be understood that within the allowable precision range, the plaintext average value data is 10 t times the average of the private data held by all participating parties.

[0087] S206: All participating parties calculate the square of the difference between the first processed data and the plaintext average value data to obtain the squared difference processed data.

[0088] Combined with the foregoing, it is known that the first processed data of the participating parties are m i , respectively, and the plaintext average value data of all participating parties is y / k. Then the squared difference processed data of the participating parties are (m i - y / k) 2 . Taking the initiator as an example, the squared difference processed data of the initiator is (m1 - y / k) 2 , and the other squared difference processed data belong to other participating parties.

[0089] S207: Each participating party randomly divides the squared difference processed data into at least two and at most the number of participating parties' portions of random split data, and distributes the random split data one by one among all participating parties. Then each participating party calculates the sum value of all the random split data it receives as the squared difference recombination data.

[0090] After the squared difference processed data is generated into random split data, it can prevent the squared difference processed data from being traced. At least two random split data obtained by each participating party after splitting the squared difference processed data can be randomly distributed among all participating parties. To avoid the small probability event that all the random split data of one participating party are sent to another participating party, resulting in the tracing of its squared difference processed data, it is agreed that at least two portions of the squared difference processed data of one participating party need to be distributed one by one among all participating parties. That is, if there are two random split data, two are randomly selected from all participating parties and sent separately one by one. If there are ten random split data, ten participating parties are randomly selected from all participating parties and sent separately one by one. To avoid invalid splitting actions, the number of random split data obtained by one participating party after splitting needs to be no more than the number of participating parties k.

[0091] In one example, each participating party randomly divides the differential processed data into the same number of parts as the number of participating parties. Each party retains one part of the randomly divided data and distributes the other parts of the randomly divided data to the other participating parties one by one. Let the identifiers of all participating parties be A i , the differential processed data of the initiating party A1 is B i . For the splitting and distribution process, the initiating party is A1, and the differential split data of the initiating party is B1, which is randomly split into k parts, namely B 11 , B 12 , B 13 ,..., B 1k , B1 = B 11 + B 12 + B 13 +... + B 1k . In actual distribution, the initiating party retains B 11 , and sends B 12 , B 13 ,..., B 1k to A2, A3,..., A k in sequence according to the subscript correspondence; the differential processed data of the k-th participating party A k is B k . For the splitting and distribution process, the k-th participating party A k , the differential split data of the k-th participating party is B k , which is randomly split into k parts, namely B k1 , B k2 , B k3 ,..., B kk , B k = B k1 + B k2 + B k3 +... + B kk . In actual distribution, the initiating party retains B kk , and sends B k1 , B k2 ,..., B k(k-1) to A1, A2,..., A k-1 .

[0092] Thus, each participating party including the initiating party can obtain k pieces of randomly divided data, and these k pieces of randomly divided data come from k participating parties respectively. Taking the initiating party as an example, the k pieces of randomly divided data used by the initiating party to generate the differential recombination data are B 11 , B 21 , B 31 ,..., B k1, and the same applies to other participating parties. For example, the k random split data used by the k-th participating party to generate the differential recombination data are B 1k , B 2k , B 3k ,..., B kk . Let the differential recombination data be C i , then C i = B 1i + B 2i + B 3i +... + B ki . For example, the differential recombination data C1 of the initiator = B 11 + B 21 + B 31 +... + B k1 , and the differential recombination data C k of the k-th participating party = B 1k + B 2k + B 3k +... + B kk .

[0093] S208: All participating parties aggregate the differential recombination data to the initiator, and the initiator calculates the square root of the result of dividing the sum of all differential recombination data by the number of participating parties as the standard deviation data.

[0094] Aggregation means that all other participating parties send the differential recombination data to the initiator. The initiator calculates the standard deviation data of all participating parties It should be understood that since the standard deviation data utilizes the first processed data and the explicit mean data, the calculated standard deviation data is 10 t times the standard deviation of the private data actually held by all participating parties.

[0095] S209: All participating parties calculate the fourth power of the ratio of the result of subtracting the explicit mean data from the first processed data to the standard deviation data to obtain the third-order element data.

[0096] In the method of this step, let the third-order element data of the i-th participating party be J i , so this third-order element data is equal to the fourth power of the ratio of the result of subtracting the private data mean from the private data to the private data standard deviation within the error tolerance. The k participating parties each hold a third-order element data. For example, the third-order element data of the initiator The third-order element data of the k-th participating party

[0097] S210: Each participating party randomly divides the third-order element data into no less than two and no more than the number of participating parties portions of third-order segmentation data, and distributes the third-order segmentation data one by one among all participating parties. Then each participating party calculates the sum value of all the received third-order segmentation data as the third-order recombination data.

[0098] Specifically, each participating party randomly divides the third-order element data into the number of participating parties portions of third-order segmentation data, retains one portion of the third-order segmentation data for itself, and distributes the other third-order segmentation data one by one to other participating parties. In this step, the process of dividing the third-order element data into third-order segmentation data and then recombining it into third-order recombination data can specifically refer to the process of dividing the differential square processing data into differential square segmentation data and then recombining it into differential square recombination data in step S207, which will not be publicly repeated here.

[0099] S211: All participating parties aggregate the third-order recombination data to the initiating party, and the initiating party calculates the result of dividing the sum value of all the third-order recombination data by the number of participating parties as the skewness coefficient data.

[0100] Aggregation means that all other participating parties send the third-order recombination data to the initiating party. The initiating party calculates the skewness coefficient data K of all participating parties as K = (O1 + O2 + O3 +... + O k ) / k, where O i represents the third-order recombination data of the i-th participating party. In this way, the calculation of the skewness coefficient of the private data held by all participating parties is realized, while ensuring the security of the private data.

[0101] Furthermore, the initiating party, the referee party, and the participating parties pre-arrange a transmission verification function, and the transmission verification function is a discrete modular operation function. During the data sending process, the sending party substitutes the data to be sent into the transmission verification function to obtain the first verification code, and sends the first verification code and the data to be sent to the receiving party together. The receiving party substitutes the received data into the transmission verification function to obtain the second verification code, and judges whether the data has been tampered with during the transmission process according to whether the first verification code and the second verification code are the same.

[0102] In an example, the transmission verification function is D = E F mod H, where F is the data for transmission, D is the verification code, E is an integer and E is The generator of, where both G and H are prime numbers and H divides G - 1. During the actual transmission process, the sender substitutes the data F1 to be sent into the transmission verification function to obtain the first verification code D1, and sends F1 and D1 to the receiver together. The receiver receives the data F’1 and the first verification code D’1. The receiver substitutes F’1 into the transmission verification function to obtain the second verification code D2. The receiver verifies whether the received first verification code D’1 is equal to the second verification code D2, so as to determine whether the data has been tampered with during the transmission process, thereby ensuring the security of data transmission and being conducive to ensuring the accuracy of the calculation results.

[0103] It should be noted that for the foregoing method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that this application is not limited by the described action sequence, because according to this application, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all optional embodiments, and the actions and modules involved are not necessarily essential to this application.

[0104] The above is the introduction of the method embodiments. The following further illustrates the solution of this application through system embodiments.

[0105] In a second aspect, an embodiment of this application discloses a system for securely calculating the skewness coefficient among multiple parties. The system includes a server and multiple terminals holding private data. The server acts as the referee party, one terminal acts as the initiating party, and at least two terminals act as participating parties respectively.

[0106] After the initiating party initiates a calculation task,

[0107] All participating parties obtain the same preprocessing instruction to preprocess the private data they hold to obtain the first processed data. The preprocessing instruction includes a rounding instruction;

[0108] The referee party generates a set of public keys and private keys, and sends the public keys to all participating parties; during the calculation process, a set of prime numbers p and q are randomly selected, n = pq, and a random selection is made λ = lcm(p - 1, q - 1), and the function is defined as Calculate μ = (L(g λ mod n 2 )) -1 mod n, where the public key is (n, g), and the private key is (λ, μ);

[0109] All participating parties use the received public keys to encrypt the first processed data they hold to obtain the first encrypted data; during the calculation process, the participating party randomly selects Calculate where mi The first processed data of the participating party, c i represents the first encrypted data of the participating party;

[0110] All the first encrypted data are aggregated to the initiator, and the initiator obtains the ciphertext sum value data according to all the first encrypted data and the constructed additive homomorphic function; during the calculation process, the additive homomorphic function is where f represents the ciphertext sum value data, and k represents the number of participating parties;

[0111] The ciphertext sum value data is sent to the referee party, and the referee party decrypts the ciphertext sum value data using the private key to obtain the plaintext sum value data, calculates the plaintext mean value data according to the plaintext sum value data and the number of participating parties, and distributes the plaintext mean value data to all participating parties; during the calculation process, construct y = (L(f λ mod n 2 )·μ) mod n, where y represents the plaintext sum value data;

[0112] All participating parties calculate the square of the difference between the first processed data and the plaintext mean value data to obtain the difference square processed data;

[0113] Each participating party randomly divides the difference square processed data into no less than two and no more than the number of participating parties of random segmentation data, and distributes the random segmentation data one by one among all participating parties, and then each participating party calculates the sum value of all the random segmentation data received by itself as the difference square recombination data;

[0114] All participating parties aggregate the difference square recombination data to the initiator, and the initiator calculates the square root value of the result of dividing the sum value of all the difference square recombination data by the number of participating parties as the standard deviation data;

[0115] All participating parties calculate the fourth power of the ratio of the result of subtracting the plaintext mean value data from the first processed data to the standard deviation data to obtain the third-order element data;

[0116] Each participating party randomly divides the third-order element data into no less than two and no more than the number of participating parties of third-order segmentation data, and distributes the third-order segmentation data one by one among all participating parties, and then each participating party calculates the sum value of all the third-order segmentation data received by itself as the third-order recombination data;

[0117] All participating parties aggregate the third-order recombination data to the initiator, and the initiator calculates the result of dividing the sum value of all the third-order recombination data by the number of participating parties as the skewness coefficient data.

[0118] Furthermore, the participating party is further configured to:

[0119] Each participating party randomly divides the differential processed data into the same number of parts as the number of participating parties, retains one part of the randomly divided data for itself, and distributes the other randomly divided data to other participating parties one by one;

[0120] and / or

[0121] Each participating party randomly divides the third-order element data into the same number of parts as the number of participating parties, retains one part of the third-order divided data for itself, and distributes the other third-order divided data to other participating parties one by one.

[0122] Further, the initiator, the referee, and the participating parties pre-agree on a transmission verification function, and the transmission verification function is a discrete modular operation function. During the data sending process, the sender substitutes the data to be sent into the transmission verification function to obtain a first verification code, and sends the first verification code and the data to be sent to the receiver together. The receiver substitutes the received data into the transmission verification function to obtain a second verification code, and determines whether the data has been tampered with during the transmission process according to whether the first verification code and the second verification code are the same.

[0123] Further, the preprocessing instruction is obtained by the initiator, and the initiator is further configured to:

[0124] The preprocessing instruction further includes a scaling instruction, and the scaling instruction is before the rounding instruction, and the scaling instruction is used to scale the data by a specified multiple.

[0125] Further, the initiator is further configured to:

[0126] The initiator determines the data scenario and accuracy requirement according to the calculation task, and sends the data scenario to the referee;

[0127] The referee determines the associated data of the data scenario in the big data, performs data analysis on the associated data to obtain the general accuracy value of the associated data, and sends the general accuracy value to the initiator;

[0128] The initiator determines the scaling multiple of the scaling instruction in the preprocessing instruction according to the accuracy requirement and the general accuracy value.

[0129] Those skilled in the art can clearly understand that for the convenience and simplicity of description, the specific working process of the described system can refer to the corresponding process in the foregoing method embodiments, and will not be elaborated here.

[0130] The above description is only a preferred embodiment of the present application and an explanation of the applied technical principles. Those skilled in the art should understand that the scope of disclosure involved in the present application is not limited to the technical solutions formed by the specific combination of the above technical features, but should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the foregoing disclosure concept. For example, the technical solutions formed by mutually replacing the above features with the technical features (but not limited to) disclosed in the present application that have similar functions.

Claims

1. A method for calculating the skewness coefficient of multi-party secure computing, where the multi-party includes the initiator, referee, and multiple participants of the computing task, and the participants and the initiator hold private data, characterized in that, The initiator and the referee are two different parties, and the method includes: All the participants obtain the same preprocessing instruction to preprocess the private data held by themselves to obtain first processed data, wherein the preprocessing instruction includes a rounding instruction; The referee generates a set of public and private keys and sends the public key to all participants; during the calculation process, a set of prime numbers p and q are randomly selected, n = pq, and λ = lcm(p - 1, q - 1), and the function Calculate μ = (L(g λ mod n 2 )) -1 mod n, where the public key is (n, g) and the private key is (λ, μ); All participating parties use the received public key to encrypt the first processed data they hold to obtain the first encrypted data; during the calculation process, the participating parties randomly select Calculate where m i represents the first processed data of the participating party, and c i represents the first encrypted data of the participating party; All the first encrypted data are aggregated to the initiator, and the initiator obtains the encrypted sum value data based on all the first encrypted data and the constructed additive homomorphic function; during the calculation process, the additive homomorphic function is where f represents the encrypted sum value data, and k represents the number of participants; Send the encrypted sum value data to the referee. The referee decrypts the encrypted sum value data using the private key to obtain the plaintext sum value data, calculates the plaintext mean value data based on the plaintext sum value data and the number of participants, and distributes the plaintext mean value data to all participants; during the calculation process, construct y = (L(f λ mod n 2 )·μ) mod n, where y represents the plaintext sum value data; All participants calculate the square of the difference between the first processed data and the clear state mean data to obtain the difference square processed data; Each participant randomly divides the difference-processed data into no less than two and no more than the number of participants, and distributes the random split data to all participants one by one. After that, each participant calculates the sum of all the random split data it receives as the difference-recombined data. All participants will collect the difference square reorganization data to the initiator, and the initiator will calculate the square root of the sum of all difference square reorganization data divided by the number of participants to obtain the standard deviation data; All participants calculate the fourth power of the ratio of the result of the first processed data minus the bright state mean data to the standard deviation data to obtain the third-order element data; Each participant randomly divides the third-order element data into three-order segmentation data of no less than two and no more than the number of participants, and distributes the three-order segmentation data to all participants one by one. After that, each participant calculates the sum of all the three-order segmentation data received by itself as the third-order reorganization data; All participants summarize the third-order reorganization data to the initiator, and the initiator calculates the sum of all third-order reorganization data and divides it by the number of participants to obtain the skewness coefficient data.

2. The method according to claim 1, wherein Each participant randomly divides the difference-processed data into no less than two and no more than the number of participants, and distributes the random segmentation data to all participants one by one. After that, each participant calculates the sum of all the random segmentation data it receives and uses it as the difference-reorganized data. Each participant randomly divides the difference-processed data into random split data of the same number as the participant, retains one copy of the random split data for itself and distributes the other random split data to other participants one by one; and / or Each participant randomly divides the third-order element data into three-order segmentation data of no less than two and no more than the number of participants, and distributes the three-order segmentation data to all participants one by one. After that, each participant calculates the sum of all the three-order segmentation data received by itself as the third-order reorganization data. Each participant randomly divides the third-order element data into third-order segmentation data of the same number as the participant, retains one copy of the third-order segmentation data for itself and distributes the other third-order segmentation data to other participants one by one.

3. The method according to claim 1 or 2, characterized in that, The initiator, the referee and the participants agree in advance on a transmission verification function, which is a discrete modular operation function. During the data sending process, the sender substitutes the data to be sent into the transmission verification function to obtain a first verification code, and sends the first verification code together with the data to be sent to the receiver. The receiver substitutes the received data into the transmission verification function to obtain a second verification code, and determines whether the data has been tampered with during the transmission process based on whether the first verification code and the second verification code are the same.

4. The method according to claim 1 or 2, characterized in that, The pre-processing instruction further includes a scaling instruction, which is before the rounding instruction and is used to scale the data by a specified multiple.

5. The method according to claim 4, wherein The method for obtaining the preprocessing instruction includes: The initiator determines the data scenario and accuracy requirements based on the computing task, and sends the data scenario to the referee; The referee determines the associated data of the data scenario in the big data, performs data analysis on the associated data to obtain the general accuracy value of the associated data, and sends the general accuracy value to the initiator; The initiator determines the scaling multiple of the scaling instruction in the preprocessing instruction according to the accuracy requirement and the general accuracy value.

6. A system for calculating the skewness coefficient of multi-party secure computing, characterized in that, It includes a server and a plurality of terminals holding private data, wherein the server serves as a referee, one of the terminals serves as an initiator, and at least two of the terminals serve as participants respectively; After the initiator initiates the computing task, All the participants obtain the same preprocessing instruction to preprocess the private data held by themselves to obtain first processed data, wherein the preprocessing instruction includes a rounding instruction; A set of public and private keys is generated by the referee and the public key is sent to all participants; during the calculation process, a set of prime numbers p and q are randomly selected, n = pq, and λ = lcm(p - 1, q - 1), and the function is calculated μ = (L(g λ mod n 2 )) -1 mod n, where the public key is (n, g) and the private key is (λ, μ); All participating parties use the received public key to encrypt the first processed data they hold to obtain the first encrypted data; during the calculation process, the participating parties randomly select Calculate where m i represents the first processed data of the participating party, and c i represents the first encrypted data of the participating party; Summarize all the first encrypted data to the initiator, and the initiator obtains the encrypted sum value data based on all the first encrypted data and the constructed additive homomorphic function; during the calculation process, the additive homomorphic function is where f represents the encrypted sum value data, and k represents the number of participants; Send the encrypted sum value data to the referee. The referee decrypts the encrypted sum value data using the private key to obtain the plaintext sum value data, calculates the plaintext mean value data based on the plaintext sum value data and the number of participants, and distributes the plaintext mean value data to all participants; during the calculation process, construct y = (L(f λ mod n 2 )·μ) mod n, where y represents the plaintext sum value data; All participants calculate the square of the difference between the first processed data and the clear state mean data to obtain the difference square processed data; Each participant randomly divides the difference-processed data into no less than two and no more than the number of participants, and distributes the random split data to all participants one by one. After that, each participant calculates the sum of all the random split data it receives as the difference-recombined data. All participants will collect the difference square reorganization data to the initiator, and the initiator will calculate the square root of the sum of all difference square reorganization data divided by the number of participants to obtain the standard deviation data; All participants calculate the fourth power of the ratio of the result of the first processed data minus the bright state mean data to the standard deviation data to obtain the third-order element data; Each participant randomly divides the third-order element data into three-order segmentation data of no less than two and no more than the number of participants, and distributes the three-order segmentation data to all participants one by one. After that, each participant calculates the sum of all the three-order segmentation data received by itself as the third-order reorganization data; All participants summarize the third-order reorganization data to the initiator, and the initiator calculates the sum of all third-order reorganization data and divides it by the number of participants to obtain the skewness coefficient data.

7. The system according to claim 6, characterized in that The participants are further configured to: Each participant randomly divides the difference-processed data into random split data of the same number as the participant, retains one copy of the random split data for itself and distributes the other random split data to other participants one by one; and / or Each participant randomly divides the third-order element data into third-order segmentation data of the same number as the participant, retains one copy of the third-order segmentation data for itself and distributes the other third-order segmentation data to other participants one by one.

8. The system according to claim 6 or 7, characterized in that, The initiator, the referee and the participants agree in advance on a transmission verification function, which is a discrete modular operation function. During the data sending process, the sender substitutes the data to be sent into the transmission verification function to obtain a first verification code, and sends the first verification code together with the data to be sent to the receiver. The receiver substitutes the received data into the transmission verification function to obtain a second verification code, and determines whether the data has been tampered with during the transmission process based on whether the first verification code and the second verification code are the same.

9. The system according to claim 6 or 7, characterized in that The pre-processing instruction is obtained by the initiator, and the initiator is further configured to: The preprocessing instruction further includes a scaling instruction, which is before the rounding instruction and is used to scale data by a specified multiple.

10. The system according to claim 9, characterized in that, The initiator is further configured to: The initiator determines a data scenario and a precision requirement according to a computing task, and sends the data scenario to the referee; The referee determines associated data of the data scenario in big data, performs data analysis on the associated data to obtain a general precision value of the associated data, and sends the general precision value to the initiator; The initiator determines the scaling multiple of the scaling instruction in the preprocessing instruction according to the precision requirement and the general precision value.

Citation Information

Patent Citations

  • Encryption method and system based on privacy protection

    CN111371545A

  • Method and system for secure multi-party calculation of median in data

    CN116094695A