A privacy-preserving secret sharing based proximity testing method

CN117202172BActive Publication Date: 2026-08-21UNIV OF ELECTRONICS SCI & TECH OF CHINA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311179929.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-09-13
Publication Date
2026-08-21
Estimated Expiration
2043-09-13

AI Technical Summary

Technical Problem

现有协议采用混淆电路或者多项式近似的方法,这些方法都存在计算开销和通讯开销较大的问题,使得用户需要等待较长时间才能得到反馈

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure BDA0004446863310000015
    Figure BDA0004446863310000015
  • Figure BDA0004446863310000024
    Figure BDA0004446863310000024
  • Figure BDA0004446863310000028
    Figure BDA0004446863310000028
Patent Text Reader

Abstract

The present application provides a kind of privacy protection based on secret sharing proximity test method, by efficient and safe calculation protocol for trigonometric function and applying it to proximity test model, so that participants can jointly obtain the result of distance calculation without directly disclosing the data value owned by the other party. The present application can timely and accurately complete proximity test while ensuring the protection of private location information. Compared with the existing traditional protocol, the overall accuracy of the model and the accuracy of the calculation result are guaranteed, the communication volume and the calculation amount required during function evaluation are greatly reduced, the communication overhead during proximity test process is reduced, the expected goal of communication efficiency and calculation efficiency is achieved, so that in practical application, the delay perceived by the user is greatly reduced, and the user experience during model calculation under ciphertext is guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to information security technology, and in particular to proximity testing technology for protecting privacy-preserving location information. Technical Background

[0002] Proximity testing is widely used in location services and related services, with broad applications and value in daily life. For example, the "find nearby users" function in instant messaging services or the "find nearby gas stations" function provided by navigation service providers both require proximity testing to determine whether the target and the user are within a certain geographical range, thus ensuring the operation of subsequent functions. However, user location is sensitive data, and directly using user location for calculations cannot solve privacy issues. To ensure data privacy and security, secure multi-party computation schemes can be adopted, allowing the computing parties to complete correct calculations without obtaining plaintext data.

[0003] The computational process for near-testing involves numerous periodic function operations, such as trigonometric functions. Existing protocols employ scrambling circuits or polynomial approximations, both of which incur significant computational and communication overhead, resulting in prolonged waiting times for user feedback. Summary of the Invention

[0004] The technical problem to be solved by the present invention is to provide a method for reducing communication overhead in the near-term testing process by improving the computational efficiency of periodic functions.

[0005] The technical solution adopted by this invention to solve the above-mentioned technical problems is a proximity testing method based on secret sharing that protects privacy, comprising the following steps:

[0006] 1) The two parties that need to conduct proximity testing should each specify their respective latitude and longitude coordinates (ψ). A ,φ A ) and (ψ B ,ψ B ), any test method P b The arithmetic share value of the position coordinates is calculated using the arithmetic share value. After achieving privacy protection for the location coordinates, they are sent to the other party, P. 1-b In latitude and longitude coordinates, the subscripts A and B are used to distinguish between two coordinate systems. A Represents the arithmetic share value. P represents b The obtained longitude ψ A Arithmetic sharing value, where b is the number of the nearest test side, b∈{0,1};

[0007] 2) Any test method P bAfter receiving the arithmetic share value of the other party's location coordinates, perform local proximity calculations as follows:

[0008] a)P b Utilize To calculate in, A privacy-preserving evaluation protocol for the trigonometric function cosπx. To protect privacy, an evaluation protocol for the trigonometric function sinπx is used, where l is the preset bit length, s is the number of decimal places, and N is the minimum positive period of the trigonometric function.

[0009] b)P b Calculate based on the results of the previous step. Simultaneous calculation Π MUL For multiplication agreement;

[0010] c)P b Based on the results of the previous step...

[0011] d)P b Calculate based on the results of the previous two steps. δ is the median distance;

[0012] e)P b Calculate based on the results of the previous step. Π DIV For division agreement, Π SQRT For square root protocol;

[0013] f)P b Calculate based on the results of the previous step. Π ATAN This is the arctangent protocol, where R is the Earth's radius;

[0014] g)P b Calculate the Boolean share value of the local nearest neighbor result based on the results of the previous step. Distributed comparison function Indicated by P b The input data x is compared with the threshold ∈ to determine if x is less than ∈. If x < ∈, then z = 1; otherwise, z = 0. P represents b The calculated Boolean share value;

[0015] h)P b Based on the results from the previous step, obtain the arithmetic share value of the local nearest neighbor result. This is a protocol for converting Boolean sharing to l-bit arithmetic sharing; then, the arithmetic sharing value of the local nearest result is... Send to the other party P 1-b ;

[0016] 3) Any test subject P b Receive the arithmetic share value of the neighboring result from the other party. Then determine whether it is satisfied. If so, it means that the two parties being tested are in a close proximity state, and a close proximity state prompt will be output; otherwise, it means that the two parties being tested are not in a close proximity state.

[0017] This invention utilizes techniques such as function secret sharing and table lookup to establish a privacy-preserving secure trigonometric function computation framework:

[0018] Privacy-preserving evaluation protocol for the trigonometric function cosπx And a privacy-preserving evaluation protocol for the trigonometric function sinπx All of these steps are performed, where f is a trigonometric function used in the calculation:

[0019] Privacy-preserving trigonometric function evaluation protocol Setup steps: Set up a function table with E entries. The calculation results of the trigonometric function f are stored in a table, and a coefficient table for transformation is set up. Where m represents the number of segments in the interval judgment, n represents the number of coefficients in each interval, n=3, the transformation form of the trigonometric function f is f(y)=af(bx+c), x is the input before transformation, y is the input after transformation, and the coefficient table is... The transformation parameters a, b, c for different intervals are stored in the middle.

[0020] For P b , for input protocol Arithmetic sharing value Perform the following steps:

[0021] a)P b give up of high Bit, set the middle value in Indicates taking The t-th position, To round up,

[0022] b)P b enter To Model Protocol Results

[0023] c)P b enter Interval Judgment Protocol Results

[0024] d)P b Set new coefficient i∈[1,n], For the coefficient table of the transformation, the value of the p-th interval is given by n coefficients and m intervals. To calculate P b The i-th coefficient of the arithmetic sharing of the transformation parameter c;

[0025] e) Construct the transformed function from the new coefficients c[i] is the i-th coefficient of the transformation parameter c, i∈[1,n], n=3;

[0026] f) Through Will Transform to a smaller domain to obtain an intermediate value.

[0027] g) Discard The extra bits are used to obtain the intermediate value. in Indicates taking The i-th digit, s is the preset number of decimal places;

[0028] h)P b Invoking the global evaluation protocol Obtain the key k generated by a third party b and random numbers Perform a full-domain assessment calculation to obtain the full-domain assessment. P b Obtain the overall evaluation results

[0029] i)P b To the other party P 1-b send For P b The arithmetic sharing value of the random number r is obtained, so that both parties can reconstruct y″-r;

[0030] j) Overall assessment results Shift each element by a length of y″-r, and each bit in the global evaluation result after the shift is represented as... E is the number of function entries;

[0031] k)P b Calculate the output value The function table corresponding to the i-th bit in the shifted global evaluation result. Items;

[0032] P b Output value As new coefficients, construct the transformed function The input will be the function Output As an agreement The output result.

[0033] This invention proposes an efficient and secure computation protocol for trigonometric functions and applies it to a proximity test model. Through this protocol, participating parties can jointly obtain the function calculation results without directly disclosing their own data values ​​to the other party. Furthermore, the two participating parties sequentially complete the calculation of each step of the model function according to the model structure until the final model prediction result is output.

[0034] The beneficial effects of this invention are that it can complete proximity testing in a timely and accurate manner while ensuring the protection of privacy location information. Compared with existing traditional protocols, it ensures the overall accuracy of the model and the accuracy of the calculation results, and significantly reduces the amount of communication and computation required for function evaluation. It achieves the expected goals of high communication efficiency and high computation efficiency, resulting in a significant reduction in the latency perceived by users in practical applications, and ensuring the user experience when calculating the model under encrypted conditions. Detailed Implementation

[0035] The cryptographic protocols and specific implementation methods involved in this invention are based on the following fundamental algorithms:

[0036] 1) Secret Sharing: Secret sharing is generally divided into two schemes: additive secret sharing and Boolean secret sharing. For arithmetic sharing, in order to share a ring for a large prime number p... The content x is uniformly and randomly selected from one side. The content r above, and will When sending to another party, we typically denote the x shared by this method as... in, <x>This indicates that x is a shared value, and the superscript A indicates arithmetic sharing. <x> A Let x be the arithmetic share value, and let the subscript b represent the two content owner IDs. The participant in the test calculation is the content owner, denoted as P. b Where b∈{0,1}, meaning the two content owners are P0 and P1. For Boolean sharing, if the shared content is a ring... If the content x is given above, then the content possessed by each party is denoted as follows: and And satisfy The superscript B indicates Boolean sharing. <x> B Let x be the boolean share value. This is an XOR operation.

[0037] 2) Function Secret Sharing: Function secret sharing is a secure computation scheme that secretly divides a function into two parts, allowing participants to obtain the shared function value with respect to the public input on their respective functions. This scheme uses the Gen algorithm and the Eval algorithm. Algorithm Gen(1 λ λ is a security parameter, f is the objective function, Gen is called by a trusted third party to generate two keys k0 and k1 and distribute them to P0 and P1 respectively. The algorithm Eval(b,k) → k0,k1: λ is a security parameter, f is the objective function, Gen is called by a trusted third party to generate two keys k0 and k1 and distribute them to P0 and P1 respectively. b ,x)→y b : Called by the computational participant, P b The result calculated by Fang is f b (x), and satisfy f0(x)+f1(x)=f(x).

[0038] 3) Black-box protocol: The following black-box protocol exists, which can obtain the corresponding output for a given input and can guarantee safety and correctness.

[0039] a) Distributed Point Function (DPF): By P b enter <x> b After calculation according to the protocol This indicates that the input data x and α are compared for equality, satisfying z = β{x = α} or z = 0{x ≠ α}, where α represents the threshold, β represents the output value, and {A} represents conditions A and P. b Obtain protocol output <z> b .

[0040] b) Distributed Comparison Function (DCF): By P b enter <x> b After calculation according to the protocol This indicates that the input data x is compared with α, and the comparison is performed to determine if z = β{x < α} or z = 0{x ≥ α}. b Obtain protocol output

[0041] c) Distributed interval function (DIF): By P b enter <x> b After calculation according to the protocol This indicates that the input data x is considered to belong to the range of the interval endpoints a and b, satisfying z = β{x∈[a,b]} or P b Obtain protocol output

[0042] d) Arithmetic-to-Boolean sharing conversion protocol B2A: It is a protocol that converts Boolean shares to l-bit arithmetic shares; the protocol converts the input Boolean shares... Convert to corresponding arithmetic sharing

[0043] e) AND Agreement: Π AND , by P b enter Input data with x and y distributed in two directions, P is calculated using a protocol. b get satisfy

[0044] f) Multiplication Protocol (MUL): Π MUL , by P b enter According to the protocol calculation, P b get satisfy

[0045] g) Square root protocol (SQRT): Π SQRT , by P b enter According to the protocol calculation, P b get satisfy

[0046] h) Division Protocol (DIV): Π DIV , by P b enter According to the protocol calculation, P b get satisfy

[0047] i) Arctangent Protocol (ATAN): This protocol Π ATAN By P b enter According to the protocol calculation, P b get satisfy

[0048] j) Global Assessment Protocol: By P b enter in It is the group where the output is located, and it is called during the protocol execution process. Subdistributed point function protocol It can evaluate all numbers within the entire domain. After calculation, P b Obtain full-domain assessment in, Each component i represents the evaluation result of the distributed point function for the corresponding number. P b get

[0049] The efficient and secure computation protocol for neural network models designed in this invention consists of the following sub-protocols for different function operations:

[0050] 1) Modular Protocol Book It can make the calculation method P b In possession Calculate below and satisfy The minimum positive period N is used as the modulus.

[0051] Offline phase:

[0052] a) A trusted third party T selects a random number r, and both parties generate [the following]: and satisfy

[0053] b) T call Generate keys k0 and k1 for both parties;

[0054] c)T will and k b Send to P b ;

[0055] Online phase:

[0056] a)P b Will Send to another computing party P 1-b ;

[0057] b)P b The evaluation was conducted and obtained in

[0058]

[0059] c)P b Convert the result from Boolean sharing to arithmetic sharing.

[0060] d)P b calculate

[0061] 2) Interval Judgment Protocol For the interval [a, b], the ascending sequence {m1, ..., m} n-1 } Divide it into n intervals, and this protocol is in P b have The two sides each calculate the vector. Boolean sharing in Each component indicates whether x belongs to this subinterval, i.e.

[0062] Offline phase:

[0063] a) Trusted third party T calls sequentially Calculate key pairs for n intervals

[0064] b) T sends to P0 and P1 respectively. and The superscript i represents the i-th interval, i∈[1,n];

[0065] Online phase: P b calculate i∈[1,n].

[0066] Based on the above protocol, this invention proposes a security assessment scheme for trigonometric functions. This invention transforms fixed-length points into a number of fixed points with dynamic lengths using the aforementioned protocol, and leverages the periodic properties of trigonometric functions to reduce overhead during the assessment process while maintaining assessment accuracy.

[0067] Privacy-preserving trigonometric function evaluation protocol

[0068] Input: Calculate the square P b enter N is the minimum positive period of function f, with bit length l, number of decimal places s, and a safety parameter λ. It is a function table with E entries. The function calculation results are stored in the form of a table, where f∈{sinπx,cosπx,tanπx} is a trigonometric function used for the calculation, and the coefficient table is used for the transformation. Where m represents the number of segments for interval judgment, and n represents the number of coefficients in each interval. In this protocol, n = 3 is taken, and the transformation to be considered is f(y) = af(bx + c), where x is the input before transformation, y is the input after transformation, and the coefficient table stores the transformation parameters a, b, c for different intervals.

[0069] Output: P b get satisfy

[0070] Agreement steps:

[0071] l) Discard of high Bit, set the middle value in Indicates taking The i-th position, To round up;

[0072] m)P b Calling the mode protocol enter Results

[0073] n)P b Invoke the range judgment protocol enter Results

[0074] o)P b Set new coefficient i∈[1,n], For the coefficient table of the transformation, the value of the p-th interval is given by n coefficients and m intervals. To calculate P b The i-th coefficient of the arithmetic sharing of the transformation parameter c.

[0075] p) Construct the transformed function from the new coefficients, i.e. c[i] is the i-th coefficient of the transformation parameter c, i∈[1,n], n=3;

[0076] q) Through Will Transform to a smaller domain and obtain Where b is the participant number.

[0077] r) Discard The extra bits are obtained in Indicates taking The i-th digit, s is the preset number of decimal places;

[0078] s)P b Call Obtain the key k generated by a third party b and random numbers Perform a full-domain assessment calculation to obtain the full-domain assessment. P b Obtain the overall evaluation results

[0079] t)P b To another direction P 1-b send Thus, both sides can reconstruct y″-r

[0080] u) to Shift each element by a length of y″-r, that is...

[0081] v)P b calculate

[0082] w)P b Calculation results This serves as the final output of the protocol.

[0083] Privacy-protecting proximity testing scheme

[0084] Input: Calculate P for each party b The input represents the latitude and longitude coordinates of each location (ψ). A ,φ A ) and (ψ B ,φ B ) sharing value Set the threshold ε, bit length l, number of decimal places s, and minimum positive period N; A Indicates arithmetic sharing; the subscripts A and B of longitude ψ and latitude φ are used to distinguish between the two coordinate systems; set N=2;

[0085] Both parties conducted tests and calculations respectively:

[0086] h)P b calculate Privacy-preserving cosine function evaluation protocol

[0087] i)P b calculate

[0088] j)P b calculate

[0089] k)P b calculate

[0090] l)P b calculate

[0091] m)P b calculate

[0092] n)P b calculate

[0093]

[0094] o)P b calculate

[0095]

[0096] p)P b calculate δ is the median value;

[0097] q)P b calculate

[0098] r)P b calculate

[0099] s)P b calculate

[0100] t)P b calculate

[0101] Output: P b get satisfy in R is the Earth's radius. The distance between the two is the threshold. If it is less than the threshold, output 1; otherwise, output 0. An output result of 1 indicates that the distance between the input coordinate value and the target point is less than the threshold, indicating that the target and the user are in a near state. 0 indicates that it is greater than the threshold, indicating that the target and the user are in a far state.< / x> < / x> < / z> < / x> < / x> < / x> < / x>

Claims

1. A privacy-preserving proximity testing method based on secret sharing, characterized in that, Includes the following steps: 1) The two parties that need to conduct proximity testing should each specify their respective latitude and longitude coordinates (ψ). A ,φ A ) and (ψ B ,φ B ), any test method P b The arithmetic share value of the position coordinates is obtained through preprocessing. The subscripts A and B in latitude and longitude coordinates are used to distinguish between two coordinate systems. A Represents the arithmetic share value. P represents b The obtained longitude ψ A Arithmetic sharing value, where b is the number of the nearest test side, b∈{0,1}; 2) Any test case P b After receiving the arithmetic share value of the other party's location coordinates, perform local proximity calculations as follows: a)P b Utilize To calculate in, A privacy-preserving evaluation protocol for the trigonometric function cosπx. To protect privacy, an evaluation protocol for the trigonometric function sinπx is used, where l is the preset bit length, s is the number of decimal places, and N is the minimum positive period of the trigonometric function. b)P b Calculate based on the results of the previous step. Simultaneous calculation Π MUL For multiplication agreement; c)P b Based on the results of the previous step... d)P b Calculate based on the results of the previous two steps. δ is the median value; e)P b Calculate based on the results of the previous step. Π DIV For division agreement, Π SQRT For square root protocol; f)P b Calculate based on the results of the previous step. Π ATAN This is the arctangent protocol, where R is the Earth's radius; a)P b Calculate the Boolean share value of the local nearest neighbor result based on the results of the previous step. Distributed comparison function Indicated by P b The input data x is compared with the threshold ∈ to determine if x is less than ∈. If x < ∈, then z = 1; otherwise, z = 0. P represents b The calculated Boolean share value; h)P b Based on the results from the previous step, obtain the arithmetic share value of the local nearest neighbor result. This is a protocol for converting Boolean sharing to l-bit arithmetic sharing; then, the arithmetic sharing value of the local nearest result is... Send to the other party P 1-b ; 3) Any test subject P b Receive the arithmetic share value of the neighboring result from the other party. Then determine whether it is satisfied. If so, it means that the two parties being tested are in a close proximity state, and a close proximity state prompt will be output; otherwise, it means that the two parties being tested are not in a close proximity state.

2. The method as described in claim 1, characterized in that, Privacy-preserving evaluation protocol for the trigonometric function cosπx And a privacy-preserving evaluation protocol for the trigonometric function sinπx All of these steps are implemented, where f∈{sinπx,cosπx,tanπx} is a trigonometric function form used for calculation: Privacy-preserving trigonometric function evaluation protocol Setup steps: Set up a function table with E entries. The calculation results of the trigonometric function f are stored in a table, and a coefficient table for transformation is set up. Where m represents the number of segments in the interval judgment, n represents the number of coefficients in each interval, n=3, the transformation form of the trigonometric function f is f(y)=af(bx+c), x is the input before transformation, y is the input after transformation, and the coefficient table is... The transformation parameters a, b, c for different intervals are stored in the middle. For P b , for input protocol Arithmetic sharing value Perform the following steps: a)P b give up of high Bit, set the middle value in Indicates taking The t-th position, To round up, b)P b enter To Model Protocol Results c)P b enter Interval Judgment Protocol Results d)P b Set new coefficient i∈[1,n], For the coefficient table of the transformation, the value of the p-th interval is given by n coefficients and m intervals. To calculate P b The i-th coefficient of the arithmetic sharing of the transformation parameter c; e) Construct the transformed function from the new coefficients c[i] is the i-th coefficient of the transformation parameter c, i∈[1,n]. In the context of trigonometric functions, n=3; f) Through Will Transform to a smaller domain to obtain an intermediate value. g) Discard The extra bits are used to obtain the intermediate value. in Indicates taking The i-th digit, s is the preset number of decimal places; h)P b Invoking the global evaluation protocol Obtain the third-party generated key k b and random numbers Perform a full-domain assessment calculation to obtain the full-domain assessment. P b Obtain the overall assessment results i)P b To the other party P 1-b send For P b The arithmetic share of the random number r. Thus, both parties can reconstruct y″-r; j) Overall assessment results Shift each element by a length of y″-r, and each bit in the global evaluation result after the shift is represented as... E is the number of function entries; k)P b Calculate the output value The function table corresponding to the i-th bit in the shifted global evaluation result. Items; l)P b Output value As new coefficients, construct the transformed function The input will be the function Output As an agreement The output result.

3. The method as described in claim 2, characterized in that, set up Modular Protocol Let P b In possession Lower output and satisfy The specific implementation method is as follows: Offline stage: a) A trusted third party T selects a random number r, and both parties generate [the following]: and satisfy b) The Gen algorithm in the T function's secret sharing generates the key k for both parties. b and k 1-b ; c)T will and k b Send to P b ; Online phase: a)P b Will Send to another party P 1-b ; b)P b Boolean sharing is obtained through the Eval algorithm in function secret sharing. The data input to the Eval algorithm This is an XOR operation; c)P b Share Boolean Share this as arithmetic d)P b Obtain the modal protocol output 4. The method as described in claim 2, characterized in that, set up Interval determination protocol For the interval [a, b], the ascending sequence {m1, ..., m} n-1 } Divide it into n intervals, and this protocol is in P b have The two sides each calculate the vector. Boolean sharing in Each component indicates whether x belongs to this subinterval, i.e. This indicates that the range of input data x and interval endpoints a and b is determined. If x ∈ [a, b], then z = β; otherwise, z = 0. Offline phase: a) A trusted third party T sequentially calls the Gen algorithm in the secret sharing function to calculate key pairs for n intervals. b) T respectively directs P b and P 1-b send and The superscript i represents the i-th interval, i∈[1,n]; Online phase: P b Boolean sharing is obtained through the Eval algorithm in function secret sharing. i∈[1,n].