A Method and System for Calculating the Size Relationship between the Mean and Median in Multi-Party Secure Computation
Through homomorphic encryption algorithm and transmission verification function, the security calculation problem of the relationship between the mean and median size of data in multi-party security calculations is solved, and data security calculation and accuracy guarantee are achieved in the absence of a trustworthy third party.
Patent Information
- Application Number
- CN202310537162.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-05-13
- Publication Date
- 2025-07-29
- Estimated Expiration
- 2043-05-13
AI Technical Summary
In the absence of a trusted third party, how to safely calculate the relationship between the mean and median size of the data in the multi-party security calculation task to ensure the independence of the input and the correctness of the calculation, while not leaking the input value to other members participating in the calculation.
The homomorphic encryption algorithm is used to generate public and private keys by the referee, the participant encrypts the data, the initiator calculates the secret state and value data, the referee decrypts the clear state data, and uses the transmission verification function to ensure the security of data transmission. The participant holding the median randomly divides the data for distribution, and finally determines the relationship between the mean and the median magnitude.
On the basis of ensuring the security of private data, the task of calculating the relationship between the mean and median size of all participants is realized, ensuring that the data transmission process is not tampered with, and the accuracy and security of the calculation results are accurate and safe.
Smart Images

Figure FDA0004226797080000012 
Figure FDA0004226797080000016 
Figure FDA0004226797080000018
Abstract
Description
Technical Field
[0001] This application relates to the technical field of multi-party secure computing, and particularly to a method and system for multi-party secure computing of the size relationship between the mean and the median. Background Art
[0002] Multi-party secure computing is to solve the problem of collaborative computing for protecting privacy among a group of mutually untrusted participants. Secure multi-party computing should ensure the independence of inputs, the correctness of calculations, and at the same time not disclose the input values to other members participating in the calculation. It mainly aims at the problem of how to securely calculate a predefined function in the absence of a trusted third party. Secure multi-party computing plays an important role in scenarios such as electronic elections, electronic voting, electronic auctions, secret sharing, and threshold signatures. In actual multi-party secure computing tasks, providing targeted secure multi-party computing algorithms with the goal of achieving the computing task is a problem that those skilled in the art have been working hard to solve. Summary of the Invention
[0003] This application provides a method and system for multi-party secure computing of the size relationship between the mean and the median, which can achieve the task of multi-party secure computing of the size relationship between the mean and the median of all data in a data group.
[0004] In a first aspect, this application provides a method for multi-party secure computing of the size relationship between the mean and the median. The multi-party includes the initiator, referee, and multiple participants of the computing task. The participants and the initiator hold private data, and the initiator and the referee are two different parties. The method includes:
[0005] All participants obtain the same preprocessing instruction to preprocess the private data they hold, obtaining first processed data. The preprocessing instruction includes a rounding instruction;
[0006] The referee generates a set of public keys and private keys, and sends the public keys to all participants; during the calculation process, a set of prime numbers p and q are randomly selected, n = pq, and λ = lcm(p - 1, q - 1) is randomly selected, and the function is defined λ = lcm(p - 1, q - 1), and the function is defined Calculate μ = (L(g λ mod n 2 )) -1 mod n, where the public key is (n, g), and the private key is (λ, μ);
[0007] All participants encrypt the first processed data they hold using the received public keys, obtaining first encrypted data; during the calculation process, the participant randomly selects Calculate where m i represents the first processed data of the participant, and c iThe first encrypted data representing the participating parties;
[0008] Summarize all the first encrypted data to the initiating party. The initiating party obtains the encrypted sum value data based on all the first encrypted data and the constructed additive homomorphic function, and obtains the encrypted difference data corresponding one-to-one with the participating parties based on all the first encrypted data and the constructed subtractive homomorphic function. During the calculation process, the additive homomorphic function is where f represents the encrypted sum value data, k represents the number of participating parties, and the subtractive homomorphic function is z i represents the encrypted difference data corresponding to the i-th participating party;
[0009] Send the encrypted sum value data and all the encrypted difference data to the referee party. The referee party decrypts the encrypted sum value data and all the encrypted difference data using the private key to obtain the plaintext sum value data and the plaintext difference data corresponding one-to-one with the participating parties, and calculates the plaintext mean data based on the plaintext sum value data and the number of participating parties, and determines the participating party holding the median of the private data according to the plaintext difference data, and then sends the plaintext mean data to the initiating party. During the calculation process, construct y = (L(f λ mod n 2 ) · μ) mod n, where y represents the plaintext sum value data, and construct w i represents the plaintext difference data corresponding to the i-th participating party;
[0010] The participating party holding the median of the private data randomly divides the first processed data into at least two and at most the number of participating parties of random segmentation data, and distributes the random segmentation data one by one among all the participating parties, and then summarizes all the random segmentation data to the initiating party. The initiating party calculates the sum value of all the random segmentation data as the median data, and then determines the size relationship between the median data and the plaintext mean data as the size relationship between the mean and the median of the private data.
[0011] By adopting the above technical solution, it is possible to achieve the task of calculating the size relationship between the mean and the median of the private data of all participating parties on the basis of ensuring the security of the private data.
[0012] Further, the participating party holding the median of the private data randomly divides the first processed data into the number of participating parties of random segmentation data, retains one random segmentation data by itself, and distributes the other random segmentation data one by one to other participating parties.
[0013] Further, the initiator, the referee, and the participants pre-agree on a transmission verification function, which is a discrete modular operation function. During the data sending process, the sender substitutes the data to be sent into the transmission verification function to obtain a first verification code, and sends the first verification code and the data to be sent to the receiver together. The receiver substitutes the received data into the transmission verification function to obtain a second verification code, and determines whether the data has been tampered with during the transmission process according to whether the first verification code and the second verification code are the same.
[0014] Further, the preprocessing instruction further includes a scaling instruction, and the scaling instruction is before the rounding instruction, and the scaling instruction is used to scale the data by a specified multiple.
[0015] Further, the method for obtaining the preprocessing instruction includes:
[0016] The initiator determines the data scenario and the accuracy requirement according to the computing task, and sends the data scenario to the referee;
[0017] The referee determines the associated data of the data scenario in the big data, performs data analysis on the associated data to obtain the general accuracy value of the associated data, and sends the general accuracy value to the initiator;
[0018] The initiator determines the scaling multiple of the scaling instruction in the preprocessing instruction according to the accuracy requirement and the general accuracy value.
[0019] In a second aspect, the present application provides a system for securely calculating the relationship between the mean and the median of multiple parties. The system includes a server and multiple terminals holding private data. The server serves as the referee, one of the terminals serves as the initiator, and at least two of the terminals serve as participants respectively;
[0020] After the initiator initiates a computing task, all participants obtain the same preprocessing instruction to preprocess the private data they hold, and obtain first processed data. The preprocessing instruction includes a rounding instruction;
[0021] The referee generates a set of public keys and private keys, and sends the public keys to all participants; during the calculation process, a group of prime numbers p and q are randomly selected, n = pq, and randomly select λ = lcm(p - 1, q - 1), define the function Calculate μ = (L(g λ mod n 2 )) -1 mod n, where the public key is (n, g), and the private key is (λ, μ);
[0022] All participants encrypt the first processed data they hold by using the received public keys to obtain first encrypted data; during the calculation process, the participants randomly select Calculation where m i represents the first processed data of the participating party, and c i represents the first encrypted data of the participating party;
[0023] All the first encrypted data are aggregated to the initiating party. The initiating party obtains the ciphertext sum value data according to all the first encrypted data and the constructed additive homomorphic function, and obtains the ciphertext difference data corresponding one-to-one to the participating parties according to all the first encrypted data and the constructed subtractive homomorphic function; during the calculation process, the additive homomorphic function is where f represents the ciphertext sum value data, k represents the number of participating parties, and the subtractive homomorphic function is z i represents the ciphertext difference data corresponding to the i-th participating party;
[0024] The ciphertext sum value data and all the ciphertext difference data are sent to the referee party. The referee party decrypts the ciphertext sum value data and all the ciphertext difference data by using the private key to obtain the plaintext sum value data and the plaintext difference data corresponding one-to-one to the participating parties, and calculates the plaintext mean data according to the plaintext sum value data and the number of participating parties, and determines the participating party holding the median of the private data according to the plaintext difference data, and then sends the plaintext mean data to the initiating party; during the calculation process, construct y = (L(f λ mod n 2 )·μ) mod n, where y represents the plaintext sum value data, and construct w i represents the plaintext difference data corresponding to the i-th participating party;
[0025] The participating party holding the median of the private data randomly divides the first processed data into at least two and at most the number of participating parties of random segmentation data, and distributes the random segmentation data one by one among all the participating parties, and then aggregates all the random segmentation data to the initiating party. The initiating party calculates the sum value of all the random segmentation data as the median data, and then determines the size relationship between the median data and the plaintext mean data as the size relationship between the mean and the median of the private data.
[0026] Further, the participating party is further configured to:
[0027] The participating party holding the median of the private data randomly divides the first processed data into the number of participating parties of random segmentation data, retains one copy of the random segmentation data by itself and distributes the other random segmentation data one by one to other participating parties.
[0028] Further, the initiator, the referee, and the participants pre-agree on a transmission verification function, which is a discrete modular operation function. During the data sending process, the sender substitutes the data to be sent into the transmission verification function to obtain a first verification code, and sends the first verification code and the data to be sent to the receiver together. The receiver substitutes the received data into the transmission verification function to obtain a second verification code, and determines whether the data has been tampered with during the transmission process based on whether the first verification code and the second verification code are the same.
[0029] Further, the preprocessing instruction is obtained by the initiator, and the initiator is further configured to:
[0030] The preprocessing instruction further includes a scaling instruction, which is before the rounding instruction, and the scaling instruction is used to scale the data by a specified multiple.
[0031] Further, the initiator is further configured to:
[0032] The initiator determines the data scenario and the accuracy requirement according to the computing task, and sends the data scenario to the referee;
[0033] The referee determines the associated data of the data scenario in the big data, performs data analysis on the associated data to obtain the general accuracy value of the associated data, and sends the general accuracy value to the initiator;
[0034] The initiator determines the scaling multiple of the scaling instruction in the preprocessing instruction according to the accuracy requirement and the general accuracy value.
[0035] In summary, the present application at least includes the following beneficial effects:
[0036] 1. A method and system for securely calculating the size relationship between the mean and median of multiple parties are provided. Based on the homomorphic encryption algorithm, it can complete the task of calculating the size relationship between the mean and median of the private data held by all participants while ensuring the security of the private data held by the participants;
[0037] 2. Using the transmission verification function can ensure that the data is not tampered with during the transmission process, which is beneficial to ensuring the accuracy of the calculation result; 3. The preprocessing instruction is determined according to the associated data of the data scenario in the big data, which is beneficial to ensuring the rationality of the first processed data.
[0038] It should be understood that the content described in the invention content part is not intended to limit the key or important features of the embodiments of the present application, nor is it used to limit the scope of the present application. Other features of the present application will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] The present application has no drawings. DETAILED DESCRIPTION OF THE INVENTION
[0040] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the following clearly and completely describes the technical solutions in the embodiments of this application. Obviously, the described embodiments are some, but not all, of the embodiments of this application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in this application without creative efforts belong to the scope of protection of this application.
[0041] In addition, the term "and / or" in this article is merely a description of the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent three situations: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / " in this article generally represents an "or" relationship between the associated objects before and after.
[0042] This application provides a method and system for securely calculating the size relationship between the mean and median in a multi-party setting. By using a homomorphic encryption algorithm and performing calculations based on private data, it can calculate the size relationship between the mean and median while ensuring the security of private data.
[0043] In a first aspect, an embodiment of this application discloses a method for securely calculating the size relationship between the mean and median in a multi-party setting.
[0044] An exemplary operating environment in which the embodiments of this application can run includes an initiator, a referee, and multiple participants. Among them, the initiator, the referee, and multiple participants are all communicatively connected to each other. Each participant holds private data. The referee and the initiator are two different parties, and the initiator can also be one of the participants.
[0045] In a specific implementation process, the participants are terminals, the initiator is one of the participants and also a terminal, and the referee is a server.
[0046] This method can be executed in the aforementioned operating environment.
[0047] This method specifically includes the following steps:
[0048] S201: All participants obtain the same preprocessing instruction to preprocess the private data they hold, obtaining first processed data.
[0049] The preprocessing instruction includes a rounding instruction.
[0050] The preprocessing instruction further includes a scaling instruction. The scaling instruction is before the rounding instruction and is used to scale the data by a specified multiple.
[0051] Specifically, the ideal purpose of the preprocessing instruction is to rewrite the valid data bits of all private data into integers through scaling, and the size relationship of different private data needs to be reflected. While ensuring that the data is completely undistorted, the highest non-zero bit and the lowest non-zero bit of all private data need to be determined separately during the rewriting, and then all private data need to be scaled so that the lowest non-zero bit of all private data is scaled to no less than the units digit. In the case of amplification, for example, the highest non-zero bit of the first private data is the ten thousandth digit and the lowest non-zero bit is the thousandth digit, the highest non-zero bit of the second private data is the thousandth digit and the lowest non-zero bit is the ten thousandth digit, and the highest non-zero bit of the third private data is the hundredth digit and the lowest non-zero bit is the hundredth digit. In this case, the highest non-zero bit of the three private data is the hundredth digit and the lowest non-zero bit is the ten thousandth digit. In this case, to perform distortion-free scaling on the three private data, all three private data need to be magnified ten thousand times. Of course, when rewriting private data, in order to reduce the amount of computation, it is also necessary to try to ensure that the lowest non-zero bit of all private data is no higher than the units digit. In the case of reduction, for example, the highest non-zero bit of the first private data is 10 billion bits and the lowest non-zero bit is 10,000 bits, the highest non-zero bit of the second private data is 100 million bits and the lowest non-zero bit is 1,000 bits, and the highest non-zero bit of the third private data is 1 billion bits and the lowest non-zero bit is 100,000 bits. In order to perform distortion-free scaling on the three private data, all the three private data need to be reduced by a thousand times.
[0052] Ideally, the aforementioned scaling principle ensures that all valid bits of scaled private data are retained after rounding, preventing distortion of the private data after executing preprocessing instructions. However, in some special cases, such as when the number of bits between the highest and lowest bits of all private data exceeds the processing capabilities of the hardware environment (server, terminal), some precision must be discarded. This essentially involves appropriately expanding the maximum data range that the hardware environment can handle at a certain precision. The general operation is to discard one or two lowest bits, which will not be detailed here.
[0053] In some cases, to reduce computational difficulty, some precision can be sacrificed while maintaining a certain level of accuracy. This situation needs to be considered in conjunction with the accuracy requirements of the computational task, so the method for obtaining preprocessing instructions has been improved.
[0054] The method for obtaining the pre-processing instruction includes: the initiator determines the data scenario and accuracy requirements based on the computing task, and sends the data scenario to the referee; the referee determines the associated data of the data scenario in the big data, performs data analysis on the associated data to obtain the general accuracy value of the associated data, and sends the general accuracy value to the initiator; the initiator determines the scaling factor of the scaling instruction in the pre-processing instruction based on the accuracy requirement and the general accuracy value.
[0055] When a computing task is determined, the data population targeted by the computing task and the requirements for the result are also determined. Among them, the targeted data population corresponds to a data scenario, and the data scenario contains tags that can identify associated data in big data. The requirements for the result correspond to the precision requirements. In the description of the computing task, the requirements for the result are generally included. For example, when calculating money, the unit is accurate to cents (RMB), that is, the accurate value is to the percentile of yuan (RMB). When calculating power generation, the unit accurate value is to the units digit of kilowatt-hours.
[0056] The precision requirement includes the required precision digit. The required precision digit is the limit on the highest position of the lowest non-zero digit, and generally directly reflects that the lowest non-zero digit cannot be higher than the preset digit. The precision requirement is directly determined according to the description of the computing task. Here, a comparison model can be designed, or it can be directly input manually.
[0057] Associated data is the data in big data that carries tags corresponding to the data scenario. The general precision value of associated data is a data range, which reflects the positions of the highest non-zero digit and the lowest non-zero digit of all associated data. Of course, it can also reflect the number of digits between the highest non-zero digit and the lowest non-zero digit of all associated data, that is, the general significant digits.
[0058] According to the capabilities of the hardware environment (server, terminal), a recommended significant digit and a maximum significant digit are also preset in advance. When the initiator determines the scaling factor according to the precision requirement and the general precision value, the recommended significant digit and the maximum significant digit are also considered. The processing logic is as follows: If the number of significant digits of the general precision value is not more than the recommended significant digit, then when scaling, it is scaled by the scaling factor that scales the lowest non-zero digit of the general precision value to the units digit. If the number of significant digits of the general precision value is more than the recommended significant digit, then when scaling, it is scaled by the scaling factor that scales the preset digit of the required precision digit to the units digit. If scaling by the scaling factor that scales the preset digit of the required precision digit to the units digit causes the number of significant digits of the scaled data to exceed the maximum significant digit, then a result of insufficient processing capacity is returned.
[0059] In an example, the scaling factor of the scaling instruction is an integer power of 10. Of course, the scaling factor can be any multiple according to requirements.
[0060] In an example, assume there are k participants (k is an integer and k≥2), and the initiator is also one of the participants. The private data held by the k participants are a i , i = 1, 2, …, k. The private data held by the initiator is a1, and the other private data are held by the other participants in turn. The preprocessing instruction is to multiply the private data by 10 t times (t ∈ N, pre-acquisition) and then round it. The first processed data obtained by the participant is m i, where \(i = 1, 2, \ldots, k\), the first processing data of the initiator is \(m_1\), and the other first processing data respectively correspond to the other participating parties, that is, within the allowable accuracy range, it is considered that \(m\) i = 10 t a i .
[0061] S202: The referee generates a set of public and private keys and sends the public key to all participating parties.
[0062] During the calculation process, the referee randomly selects a set of prime numbers \(p\) and \(q\), \(n = pq\), and randomly selects indicating that \(g\) is an integer between 1 and \(n\) 2 and \(\lambda=\text{lcm}(p - 1, q - 1)\), indicating that \(\lambda\) is the least common multiple of \(p - 1\) and \(q - 1\); define the function calculate \(\mu=(L(g\) λ \(\text{mod}n\) 2 )) -1 \(\text{mod}n\), where \(\text{mod}\) is the remainder function. The obtained results are that the public key is \((n, g)\) and the private key is \((\lambda, \mu)\).
[0063] Regarding the selection of prime numbers, the referee pre-stores a prime number library (usually large prime numbers for encryption requirements), and can randomly select a set during each calculation task.
[0064] S203: All participating parties use the received public key to encrypt the first processing data they hold to obtain the first encrypted data.
[0065] During the calculation process, the participating party randomly selects calculate where \(m\) i represents the first processing data of the participating party, \(c\) i represents the first encrypted data of the participating party, \(i = 1, 2, \ldots, k\).
[0066] Among them, after the initiator receives \((n, g)\), it randomly selects indicating that \(r_1\) is an integer between 1 and \(n\), and calculates \(c_1\) is the first encrypted data of the initiator; the other first encrypted data respectively correspond to the other participating parties.
[0067] S204: Aggregate all the first encrypted data to the initiator. The initiator obtains the ciphertext sum value data according to all the first encrypted data and the constructed additive homomorphic function, and obtains the ciphertext difference data corresponding to each participating party according to all the first encrypted data and the constructed subtractive homomorphic function.
[0068] The aggregation action is specifically that all other participating parties send the first encrypted data to the initiator, and the initiator calculates the ciphertext sum value data.
[0069] During the calculation process, the constructed additive homomorphic function is where f represents the ciphertext sum value data, and k represents the number of participating parties.
[0070] During the calculation process, the constructed subtractive homomorphic function is There are k pieces of ciphertext difference data, and z i represents the ciphertext difference data corresponding to the i-th participating party.
[0071] S205: Send the ciphertext sum value data and all ciphertext difference data to the referee. The referee uses the private key to decrypt the ciphertext sum value data and all ciphertext difference data to obtain the plaintext sum value data, the plaintext difference data corresponding one by one to the participating parties, and the participating party that holds the median of the private data determined according to the plaintext difference data, and then sends the plaintext mean data to the initiator.
[0072] During the calculation process, construct y = (L(f λ mod n 2 )·μ) mod n, where y represents the plaintext sum value data. The plaintext mean data is equal to y / k. It should be understood that within the allowable precision range, the plaintext mean data is 10 t times the mean of the private data held by all participating parties.
[0073] During the calculation process, construct w i represents the plaintext difference data corresponding to the i-th participating party. The i-th plaintext difference data reflects the difference between the first processed data of the initiator minus the first processed data of the i-th participating party, specifically equal to 10 t times the difference between the private data held by the initiator minus the private data held by the i-th participating party.
[0074] S206: The participating party that holds the median of the private data randomly divides the first processed data into at least two and at most the number of participating parties of random segmentation data, and distributes the random segmentation data one by one among all participating parties, and then aggregates all the random segmentation data to the initiator. The initiator calculates the sum value of all the random segmentation data as the median value data, and then determines the size relationship between the median value data and the plaintext mean data as the size relationship between the mean and the median of the private data.
[0075] Specifically, the referee triggers the actions of the participating parties that hold the private data. The participating party that holds the median of the private data randomly divides the first processed data into the number of participating parties of random segmentation data, retains one copy of the random segmentation data by itself and distributes the other random segmentation data one by one to other participating parties.
[0076] In this way, although the referee knows the participating party holding the private data, it cannot obtain the private data (i.e., the median of the private data) of the participating party holding the private data. Although the initiator knows the private data (i.e., the median of the private data) of the participating party holding the private data, it does not know which participating party this private data comes from, thus ensuring the security of the private data of the participating parties.
[0077] It should be understood that if there are an odd number of participating parties, the participating party holding the median of the private data is uniquely determined. However, if there are an even number of participating parties, the median is the two middle participating parties. At this time, both of the two middle participating parties can be regarded as the participating parties holding the median of the private data, and both of the two middle participating parties use the aforementioned method in this step to confidentially transmit their own first processed data to the initiator. The initiator calculates the average value of the first processed data of the two middle participating parties as the median value data.
[0078] Within the allowable range of accuracy, the median value data is equal to 10 t times the median of the private data, and the explicit mean data is equal to 10 t times the mean of the private data. Therefore, the size relationship between the median value data and the explicit mean data can directly reflect the size relationship between the mean and the median of the private data. In this way, the size relationship between the mean and the median of the private data held by all participating parties can be realized, while ensuring the security of the private data.
[0079] Furthermore, the initiator, the referee and the participating parties pre-agree on a transmission verification function, and the transmission verification function is a discrete modular operation function. During the data sending process, the sending party substitutes the data to be sent into the transmission verification function to obtain a first verification code, and sends the first verification code and the data to be sent to the receiving party together. The receiving party substitutes the received data into the transmission verification function to obtain a second verification code, and judges whether the data is tampered with during the transmission process according to whether the first verification code and the second verification code are the same.
[0080] In an example, the transmission verification function is D = E F mod H, where F is the data to be transmitted, D is the verification code, E is an integer and E is a generator of, G and H are both prime numbers and H divides G - 1. During the actual transmission process, the sending party substitutes the data F1 to be sent into the transmission verification function to obtain a first verification code D1, and sends F1 and D1 to the receiving party together. The receiving party receives the data F'1 and the first verification code D'1. The receiving party substitutes F'1 into the transmission verification function to obtain a second verification code D2. The receiving party verifies whether the received first verification code D'1 and the second verification code D2 are equal, and can determine whether the data is tampered with during the transmission process, thus ensuring the security of data transmission and being conducive to ensuring the accuracy of the calculation result.
[0081] It should be noted that for the foregoing method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that this application is not limited by the described action sequence, because according to this application, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all optional embodiments, and the actions and modules involved are not necessarily essential to this application.
[0082] The above is the introduction of the method embodiments. The following further illustrates the solution of this application through system embodiments.
[0083] In a second aspect, an embodiment of this application discloses a system for securely calculating the size relationship between the mean and median of multiple parties. The system includes a server and multiple terminals holding private data. The server acts as the referee party, one terminal acts as the initiating party, and at least two terminals act as participating parties respectively.
[0084] After the initiating party initiates a calculation task,
[0085] All participating parties obtain the same preprocessing instruction to preprocess the private data they hold to obtain the first processed data. The preprocessing instruction includes a rounding instruction;
[0086] The referee party generates a set of public keys and private keys and sends the public keys to all participating parties; during the calculation process, a set of prime numbers p and q are randomly selected, n = pq, and λ = lcm(p - 1, q - 1) is randomly selected, and the function is defined. Calculate μ = (L(g mod n λ )) 2 mod n, where the public key is (n, g) and the private key is (λ, μ); -1
[0087] All participating parties use the received public keys to encrypt the first processed data they hold to obtain the first encrypted data; during the calculation process, the participating party randomly selects Calculate where m i represents the first processed data of the participating party, and c i represents the first encrypted data of the participating party;
[0088] All the first encrypted data are aggregated to the initiating party. The initiating party obtains the encrypted sum value data according to all the first encrypted data and the constructed additive homomorphic function, and obtains the encrypted difference data corresponding to each participating party according to all the first encrypted data and the constructed subtractive homomorphic function; during the calculation process, the additive homomorphic function is Among them, f represents the encrypted sum value data, k represents the number of participating parties, and the subtraction homomorphic function is z i represents the encrypted difference data corresponding to the i-th participating party;
[0089] Send the encrypted sum value data and all encrypted difference data to the referee party. The referee party uses the private key to decrypt the encrypted sum value data and all encrypted difference data to obtain the plaintext sum value data and the plaintext difference data corresponding to each participating party one by one, and calculates the plaintext mean data according to the plaintext sum value data and the number of participating parties, and determines the participating party holding the median of the private data according to the plaintext difference data, and then sends the plaintext mean data to the initiator; During the calculation process, construct y = (L(f λ modn 2 )·μ)modn, where y represents the plaintext sum value data, and construct w i represents the plaintext difference data corresponding to the i-th participating party;
[0090] The participating party holding the median of the private data randomly divides the first processed data into at least two and at most the number of participating parties of random segmentation data, and distributes the random segmentation data one by one among all participating parties, and then aggregates all the random segmentation data to the initiator. The initiator calculates the sum value of all the random segmentation data as the median data, and then determines the size relationship between the median data and the plaintext mean data as the size relationship between the mean and the median of the private data.
[0091] Further, the participating party is further configured as:
[0092] The participating party holding the median of the private data randomly divides the first processed data into the number of participating parties of random segmentation data, retains one copy of the random segmentation data by itself, and distributes the other random segmentation data to other participating parties one by one.
[0093] Further, the initiator, the referee party and the participating party pre-agree on a transmission verification function. The transmission verification function is a discrete modular operation function. During the data sending process, the sender substitutes the data to be sent into the transmission verification function to obtain the first verification code, and sends the first verification code and the data to be sent to the receiver together. The receiver substitutes the received data into the transmission verification function to obtain the second verification code, and judges whether the data is tampered with during the transmission process according to whether the first verification code and the second verification code are the same.
[0094] Further, the preprocessing instruction is obtained by the initiator. The initiator is further configured as:
[0095] The preprocessing instruction further includes a scaling instruction, which is before the rounding instruction and is used to scale data by a specified multiple.
[0096] Further, the initiator is further configured to:
[0097] The initiator determines the data scenario and accuracy requirement according to the computing task, and sends the data scenario to the referee;
[0098] The referee determines the associated data of the data scenario in the big data, performs data analysis on the associated data to obtain the general accuracy value of the associated data, and sends the general accuracy value to the initiator;
[0099] The initiator determines the scaling multiple of the scaling instruction in the preprocessing instruction according to the accuracy requirement and the general accuracy value.
[0100] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working process of the described system can refer to the corresponding process in the foregoing method embodiment, and will not be elaborated here.
[0101] The above description is only the preferred embodiment of the present application and the description of the applied technical principle. Those skilled in the art should understand that the scope of disclosure involved in the present application is not limited to the technical solution formed by the specific combination of the above technical features, and should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the foregoing disclosure concept. For example, the technical solutions formed by mutually replacing the above features with the technical features (but not limited to) having similar functions disclosed in the present application.
Claims
1. A method for securely calculating the size relationship between the mean and median in a multi-party setting, where the multi-party includes the initiator of the computing task, the referee, and multiple participants. The participants and the initiator hold private data, and it is characterized in that The initiator and the referee are two different parties, and the method includes: All participating parties obtain the same preprocessing instruction to preprocess the private data they hold, obtaining first processed data. The preprocessing instruction includes a rounding instruction; A set of public and private keys is generated by the referee and the public key is sent to all participants; during the calculation process, a set of prime numbers p and q are randomly selected, n = pq, and λ = lcm(p - 1, q - 1), and the function is calculated μ = (L(g λ mod n 2 )) -1 mod n, where the public key is (n, g) and the private key is (λ, μ); All participating parties encrypt the first processed data they hold using the received public key to obtain the first encrypted data; during the calculation process, the participating party randomly selects Calculate where m i represents the first processed data of the participating party, and c i represents the first encrypted data of the participating party; Summarize all the first encrypted data to the initiator. The initiator obtains the encrypted sum value data based on all the first encrypted data and the constructed additive homomorphic function, and obtains the encrypted difference data corresponding to each participant one by one based on all the first encrypted data and the constructed subtractive homomorphic function; during the calculation process, the additive homomorphic function is where f represents the encrypted sum value data, k represents the number of participants, and the subtractive homomorphic function is z i represents the encrypted difference data corresponding to the i-th participant; Send the encrypted sum data and all encrypted difference data to the referee. The referee decrypts the encrypted sum data and all encrypted difference data using the private key to obtain the plaintext sum data and the plaintext difference data corresponding to each participant one by one, calculates the plaintext average data based on the plaintext sum data and the number of participants, and determines the participant holding the median of the private data based on the plaintext difference data. Then, the referee sends the plaintext average data to the initiator; during the calculation process, construct y = (L(f λ mod n 2 )·μ) mod n, where y represents the plaintext sum data, and construct w i represents the plaintext difference data corresponding to the i-th participant; The participating party holding the median of the private data randomly divides the first processed data into at least two and at most the number of participating parties of randomly divided data, and distributes the randomly divided data one by one among all participating parties. Then, all the randomly divided data is aggregated to the initiator. The initiator calculates the sum value of all the randomly divided data as the median data, and then determines the size relationship between the median data and the explicit mean data as the size relationship between the mean and the median of the private data.
2. The method according to claim 1, wherein The participating party holding the median of the private data randomly divides the first processed data into the number of participating parties of randomly divided data, retains one portion of the randomly divided data by itself, and distributes the other randomly divided data to other participating parties one by one.
3. The method according to claim 1 or 2, wherein The initiator, the referee, and the participating parties pre-agree on a transmission verification function, which is a discrete modular operation function. During the data sending process, the sender substitutes the data to be sent into the transmission verification function to obtain a first verification code, and sends the first verification code and the data to be sent to the receiver together. The receiver substitutes the received data into the transmission verification function to obtain a second verification code, and determines whether the data has been tampered with during the transmission process according to whether the first verification code and the second verification code are the same.
4. The method according to claim 1 or 2, characterized in that The preprocessing instruction further includes a scaling instruction, which is before the rounding instruction, and the scaling instruction is used to scale the data by a specified multiple.
5. The method according to claim 4, characterized in that, The method for obtaining the preprocessing instruction includes: The initiator determines the data scenario and the accuracy requirement according to the calculation task, and sends the data scenario to the referee; The referee determines the associated data of the data scenario in the big data, performs data analysis on the associated data to obtain the general accuracy value of the associated data, and sends the general accuracy value to the initiator; The initiator determines the scaling multiple of the scaling instruction in the preprocessing instruction according to the accuracy requirement and the general accuracy value.
6. A system for securely calculating the size relationship between the mean and median of multiple parties, characterized in that, It includes a server and multiple terminals holding private data. The server serves as the referee, one terminal serves as the initiator, and at least two terminals respectively serve as participating parties; After the initiator initiates a calculation task, All participating parties obtain the same preprocessing instruction to preprocess the private data they hold, obtaining first processed data. The preprocessing instruction includes a rounding instruction; A set of public and private keys is generated by the referee and the public key is sent to all participants; during the calculation process, a set of prime numbers p and q are randomly selected, n = pq, and λ = lcm(p - 1, q - 1), and the function is calculated as μ = (L(g λ mod n 2 )) -1 mod n, where the public key is (n, g) and the private key is (λ, μ); All participating parties encrypt the first processed data they hold using the received public key to obtain the first encrypted data; during the calculation process, the participating party randomly selects Calculate where m i represents the first processed data of the participating party, and c i represents the first encrypted data of the participating party; Aggregate all the first encrypted data to the initiator. The initiator obtains the encrypted sum value data based on all the first encrypted data and the constructed additive homomorphic function, and obtains the encrypted difference data corresponding to each participant one by one based on all the first encrypted data and the constructed subtractive homomorphic function. During the calculation process, the additive homomorphic function is where f represents the encrypted sum value data, k represents the number of participants, and the subtractive homomorphic function is z i represents the encrypted difference data corresponding to the i-th participant; Send the encrypted sum data and all encrypted difference data to the referee. The referee decrypts the encrypted sum data and all encrypted difference data using the private key to obtain the plaintext sum data and the plaintext difference data corresponding to each participant one by one. Then, calculate the plaintext average data based on the plaintext sum data and the number of participants, and determine the participant holding the median of the private data according to the plaintext difference data. Next, send the plaintext average data to the initiator. During the calculation process, construct y = (L(f λ mod n 2 )·μ) mod n, where y represents the plaintext sum data, and construct w i represents the plaintext difference data corresponding to the i-th participant; The participating party holding the median of the private data randomly divides the first processed data into at least two and at most the number of participating parties of randomly divided data, and distributes the randomly divided data one by one among all participating parties. Then, all the randomly divided data is aggregated to the initiator. The initiator calculates the sum value of all the randomly divided data as the median data, and then determines the size relationship between the median data and the explicit mean data as the size relationship between the mean and the median of the private data.
7. The system according to claim 6, wherein The participating party is further configured to: The participating party holding the median of the private data randomly divides the first processed data into the number of participating parties of randomly divided data, retains one portion of the randomly divided data by itself, and distributes the other randomly divided data to other participating parties one by one.
8. The system according to claim 6 or 7, characterized in that, The initiator, referee, and participant pre - agree on a transmission verification function, which is a discrete modular operation function. During the data sending process, the sender substitutes the data to be sent into the transmission verification function to obtain a first verification code, and sends the first verification code and the data to be sent to the receiver together. The receiver substitutes the received data into the transmission verification function to obtain a second verification code, and determines whether the data has been tampered with during transmission based on whether the first verification code and the second verification code are the same.
9. The system according to claim 6 or 7, characterized in that, The pre - processing instruction is obtained by the initiator, and the initiator is further configured to: The pre - processing instruction further includes a scaling instruction, which is before the rounding instruction, and the scaling instruction is used to scale the data by a specified multiple.
10. The system according to claim 9, characterized in that, The initiator is further configured to: The initiator determines the data scenario and accuracy requirement according to the calculation task, and sends the data scenario to the referee; The referee determines the associated data of the data scenario in the big data, analyzes the associated data to obtain the general accuracy value of the associated data, and sends the general accuracy value to the initiator; The initiator determines the scaling multiple of the scaling instruction in the pre - processing instruction according to the accuracy requirement and the general accuracy value.
Citation Information
Patent Citations
Multi-party data security calculation method and device, electronic equipment and storage medium
CN114866317A
Method and system for secure multi-party calculation of median in data
CN116094695A