A Blockchain-Based Batch Secure Aggregation Method and System
By using interpolation method and aggregation function on the blockchain, the problems of insufficient batch-safe aggregation performance and opaque process in the prior art are solved, and efficient batch-safe aggregation and open and transparent calculation process in rational number domains are realized.
Patent Information
- Application Number
- CN202311170524.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-09-12
- Publication Date
- 2025-06-03
- Estimated Expiration
- 2043-09-12
AI Technical Summary
The prior art has insufficient performance and opaque processes when performing batch-safe aggregation on the rational number domain, which cannot effectively solve this problem.
The batch-safe aggregation method based on blockchain is adopted, and the data is hidden in the polynomial through interpolation method, and the aggregation function of unlimited term coefficients is used for aggregation, while the constant term coefficients are safely aggregated, and the transparency and traceability of the blockchain are used to ensure the openness and transparency of the process.
It improves the efficiency of batch safe aggregation in the rational number domain, ensures the openness and transparency of the calculation process, and can be effectively applied in the anti-telecommunication fraud field and other scenarios that require privacy protection.
Smart Images

Figure CN117216089B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the fields of blockchain, secure multi-party computation, etc., and particularly relates to a batch secure aggregation method and system based on blockchain. Background Art
[0002] Secure Multi-Party Computation (SMPC) is to solve the problem of collaborative computing for protecting privacy among a group of mutually untrusted participants. SMPC needs to ensure characteristics such as independence of inputs, correctness of computation, and decentralization, and at the same time does not disclose each input value to other members participating in the computation. It mainly aims at the problem of how to securely compute a predefined function in the case of no trusted third party, and requires that each participating entity cannot obtain any input information of other entities except the computation result. SMPC plays an important role in scenarios such as electronic elections, electronic voting, electronic auctions, threshold signatures, and privacy-secure machine learning.
[0003] The main reason why SMPC cannot be widely implemented is performance. Currently, the industrial community has proposed many methods to optimize the performance of SMPC. For example, converting a linear network into a tree-like or mesh structure for parallel computing; improving an interactive protocol into a non-interactive protocol; using a more performant encryption algorithm. Nevertheless, in the face of batch secure aggregation tasks, the above optimization effects are still limited.
[0004] For batch secure aggregation tasks, a latest optimization idea is to draw on the SIMD (Single Instruction Multiple Data) instruction set. SIMD supports vectorized data parallelism, and one instruction can operate on multiple data simultaneously. Under this optimization idea, SMPC can compute batch data with the overhead of one protocol computation. Currently, methods adopting this optimization idea include pairwise additive masking and Gödel coding. The basic idea of pairwise additive masking is to negotiate a random number pairwise, derive a list of random numbers using a PRG, blind one party's data by adding the random number, and blind the other party's data by subtracting the random number; the basic idea of Gödel coding is to encode batch data into a natural number, perform homomorphic multiplication and then decompose the factors. The biggest drawback of these two methods is that they can only aggregate integers.
[0005] In addition to the performance problem, SMPC also has the characteristic that the process is not transparent, that is, it is impossible to prove to users that the data is used under encryption.
[0006] In the field of anti-telecom fraud, the current research directions include the detection of abnormal behaviors and the interception of fraud information. Abnormal behavior detection means that multiple parties jointly train an AI model to detect abnormal behaviors; the interception of fraud information means that fraud calls, text messages, etc. are blocked at the user end. These two research directions do not consider the privacy security of users. Summary of the Invention
[0007] In view of the deficiencies of the prior art, the problem to be solved by the present invention is how to perform high-performance batch secure aggregation in the rational number field while ensuring that the process is open and transparent. To solve this problem, the present invention proposes a blockchain-based batch secure aggregation method and system.
[0008] The object of the present invention is achieved by the following technical solutions:
[0009] A blockchain-based batch secure aggregation method, comprising the following steps:
[0010] (1) Batch secure aggregation task negotiation, specifically including the following sub-steps:
[0011] (1.1) n participants P i (i = 1, 2,..., n) negotiate off-chain the data X j (j = 1, 2,..., k) that needs to be batch securely aggregated this time, and establish an index I with the serial number j as the data index item;
[0012] (1.2) P 1 Create a smart contract on the chain and write in the details of the batch secure aggregation task, which details include the index I, the aggregation function F of the non-constant term coefficients 1 , the aggregation function F of the numerator of the constant term coefficient 2 , the maximum value M of the denominator of the constant term coefficient, the first prime number q greater than M, and the public key P 1 of P k ;
[0013] (2) Data hiding, specifically including the following sub-steps:
[0014] (2.1) P i According to the data serial number j of the index I, sequentially query the local data x j , and combine them into interpolation points (j, x j );
[0015] (2.2) P i Perform interpolation calculations on all the interpolation points (j, x j ), and obtain the polynomial polynomial i , the polynomial coefficients are C i,k (k = 0, 1,..., k - 1), and the constant term coefficient is C i,0 ;
[0016] (2.3) P i Disclose other polynomial coefficients C i,0 except C i,k , and use the aggregation function F of the non-constant term coefficients 1Perform aggregation to obtain the aggregated value sumC of the non-constant term coefficients k ;
[0017] (3) Secure aggregation of the constant term coefficients, specifically including the following sub-steps:
[0018] (3.1) All participants P i Privately compute the least common multiple lcm of the denominators denom i of the constant terms;
[0019] (3.2) All participants P i Convert the numerator molecular i of the constant term to molecular i *lcm / denom i ;
[0020] (3.3) All participants P i Privately sum the numerators of the constant terms to obtain sumMolecular, and sumMolecular / lcm to obtain the aggregated value sumC of the constant term coefficients 0 ;
[0021] (4) Calculate the data for batch secure aggregation, specifically including the following sub-steps:
[0022] (4.1) According to sumC k and sumC 0 obtain the aggregated polynomial sumPolyomial, and calculate the value of the polynomial with the sequence number i as the independent variable, which is the data to be securely aggregated;
[0023] Furthermore, the step (3.1) includes the following sub-steps:
[0024] (3.1.1) All participants P i Decompose the denominator denom i into a product of a finite number of prime factors according to the fundamental theorem of arithmetic
[0025]
[0026] (3.1.2) Calculate the maximum exponent max(denom i,l ) of each prime factor one by one, l = 1, 2..., m, and the specific process of each calculation includes the following sub-steps:
[0027] (3.1.2.1) P 1 Represent denom 1,1 as an M-bit binary string denom 1,1 Str, where [0, denom 1,1)The characters in the interval are 0, [denom 1,1 ,M) are 1, use P k to encrypt all characters;
[0028] (3.1.2.2)P 1 Send denom 1,1 S to P 2 , P 2 Send denom 1,1 The [0, denom 2,1 )-bit characters of Str are replaced with 0 encrypted using P k , and repeat this step until P n ;
[0029] (3.1.2.3)P n Send the replaced denom 1,1 Str to P 1 , P 1 Use the private key S k to decrypt all characters, and the number of 0s is max(denom i,1 );
[0030] (3.1.3)P 1 Calculate to obtain the least common multiple lcm;
[0031] Furthermore, the step (3.3) includes the following sub-steps:
[0032] (3.3.1)P i Use the Paillier encryption algorithm and the public key P k to encrypt molecular i , send it to the smart contract, and use the aggregation function F of the constant term coefficient molecule 2 to calculate
[0033] (3.3.2)P 1 Decrypt to obtain sumMolecular, and calculate sumMolecular / lcm to obtain sumC 0 .
[0034] The present invention also provides a blockchain-based batch security aggregation system, which includes the following modules:
[0035] Negotiation module: Each participating party negotiates the data that needs to be batch-aggregated;
[0036] Data Aggregation Module: Hide private batch data in a polynomial through interpolation method, then publicly disclose the non-constant term coefficients of the polynomial and aggregate them, and simultaneously perform secure aggregation on the constant term coefficients;
[0037] Calculation of Aggregated Data Module: Calculate the batch aggregated data from the aggregated polynomial.
[0038] The beneficial effects of the present invention are:
[0039] 1. In the data hiding step, based on the interpolation method, batch data can be effectively hidden in a polynomial. By only performing secure aggregation on the constant term coefficients, the secure aggregation of the entire polynomial coefficients can be completed, thereby improving the processing speed of batch secure aggregation tasks.
[0040] 2. In the secure aggregation step of the constant term coefficients, calculate the least common multiple of the denominators based on a new method for privately finding the maximum value, and find the sum of the numerators based on homomorphic addition, effectively solving the problem of secure aggregation of rational numbers.
[0041] 3. Relying on the transparency and traceability of the blockchain, the opacity in the SMPC protocol is solved, ensuring that the data holder uses the user data according to the established process of the protocol. Description of the Drawings
[0042] Figure 1 It is an activity diagram of privacy computing for the least common multiple provided by an embodiment of the present invention. Detailed Embodiment
[0043] Here, the exemplary embodiments will be described in detail, and the examples are shown in the drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present application.
[0044] The present invention is a batch secure aggregation method based on the blockchain, including the following steps:
[0045] (1) Batch secure aggregation task negotiation, specifically including the following sub-steps:
[0046] (1.1) n participants P i (i = 1, 2,..., n) negotiate off-chain the data X j (j = 1, 2,..., k) that needs to be batch securely aggregated this time, and establish an index I with the serial number j as the data index item;
[0047] (1.2) P 1 Create a smart contract on the chain, write the details of the batch secure aggregation task, including the index I, the aggregation function F of the non-constant term coefficients 1, the aggregation function F of the numerator of the constant term coefficient 2 , the maximum value M of the denominator of the constant term coefficient, the first prime number q greater than M, P 1 the public key P of k ;
[0048] (2) Data hiding, specifically including the following sub-steps:
[0049] (2.1) P i Query the local data x in sequence according to the data sequence number j of the index I j , and combine them into interpolation points (j, x j );
[0050] (2.2) P i Perform interpolation calculation on all interpolation points (j, x j ), and obtain the polynomial polynomial i , the polynomial coefficient is C i,k (k = 0, 1,..., k - 1), the constant term coefficient is C i,0 ;
[0051] (2.3) P i Disclose other polynomial coefficients C except C i,0 , and use the aggregation function F of the non-constant term coefficient i,k to perform aggregation to obtain the aggregation value sumC of the non-constant term coefficient 1 ; k ;
[0052] (3) Secure aggregation of the constant term coefficient, specifically including the following sub-steps:
[0053] (3.1) All participants P i Privately calculate the least common multiple lcm of the denominator denom i of the constant term;
[0054] Further, as Figure 1 shown, the step (3.1) includes the following sub-steps:
[0055] (3.1.1) All participants P i Decompose the denominator denom i into the product of a finite number of prime factors according to the fundamental theorem of arithmetic
[0056]
[0057] (3.1.2) Calculate the maximum value max(denom i,l ) of the exponent of each prime factor one by one, l = 1, 2..., m, and the specific process of each calculation includes the following sub-steps:
[0058] (3.1.2.1)P 1 Represent denom 1,1 as a binary string denom 1,1 Str of M bits, where the characters in the interval [0, denom 1,1 ) are 0, and the characters in the interval [denom 1,1 , M) are 1, and encrypt all the characters using P k ;
[0059] (3.1.2.2)P 1 Send denom 1,1 Str to P 2 , P 2 Replace the characters in the [0, denom 1,1 ) bits of denom 2,1 Str with the encrypted 0s using P k , and repeat this step until P n ;
[0060] (3.1.2.3)P n Send the replaced denom 1,1 Str to P 1 , P 1 Decrypt all the characters using the private key S k , and the number of 0s is max(denom i,1 );
[0061] (3.1.3)P 1 Calculate to obtain the least common multiple lcm;
[0062] (3.2)All participants P i Convert the constant term numerator molecular i to molecular i *lcm / denom i ;
[0063] (3.3)All participants P i Perform private summation on the constant term numerator to obtain sumMolecular, and sumMolecular / lcm to obtain the aggregated value sumC of the constant term coefficient 0 ;
[0064] Furthermore, the step (3.3) includes the following sub-steps:
[0065] (3.3.1)P i Encrypt molecular k using the Paillier encryption algorithm and the public key P i, send it into the smart contract and use the aggregation function F of the numerator of the constant term coefficient 2 Calculate in the ciphertext state
[0066] (3.3.2)P 1 Decrypt Obtain sumMolecular, and calculate sumC by sumMolecular / lcm 0 ;
[0067] (4) Calculate the data for batch secure aggregation, which specifically includes the following sub-steps:
[0068] (4.1) According to sumC k and sumC 0 Obtain the aggregated polynomial sumPolyomial, and calculate the value of the polynomial with the serial number i as the independent variable, which is the data that needs to be securely aggregated.
[0069] The present invention also provides a blockchain-based batch secure aggregation system, which includes the following modules:
[0070] Negotiation module: Each participating party negotiates the data that needs to be batch aggregated;
[0071] Data aggregation module: Hide the private batch data in the polynomial through the interpolation method, then publicly disclose and aggregate the non-constant term coefficients of the polynomial, and at the same time perform secure aggregation on the constant term coefficients;
[0072] Calculation of aggregated data module: Calculate the batch aggregated data from the aggregated polynomial.
[0073] Aiming at the performance problem of batch secure aggregation and the problem that some past methods cannot calculate in the rational number field, the present invention proposes a blockchain-based batch secure aggregation method, which greatly improves the efficiency of batch secure aggregation in the rational number field, and at the same time ensures that the calculation process is open and transparent. It can not only be used in fraud identification in the field of anti-telecom fraud, but also can be used in any cross-institutional statistical scenario that requires privacy protection, solves the problem of privacy leakage to a certain extent, and fully exploits the potential data value.
[0074] After considering the specification and the practice disclosed herein, those skilled in the art will readily think of other implementation schemes of the present application. The present application aims to cover any variations, uses or adaptations of the present application, and these variations, uses or adaptations follow the general principles of the present application and include the common general knowledge or conventional technical means in the technical field not disclosed in the present application.
[0075] It should be understood that the present application is not limited to the exact structures described above and shown in the drawings, and various modifications and changes can be made without departing from its scope.
Claims
1. A batch security aggregation method based on blockchain, characterized in that, it includes the following steps: (1) Batch security aggregation task negotiation, specifically including the following sub-steps: (1.1) n participants P i (i = 1, 2, …, n) Off-chain negotiate the data X that needs to be batch safely aggregated this time j (j = 1, 2, …, k), establish an index I with the serial number j as the data index item (1.2)P 1 Create a smart contract on the chain and write the details of the batch secure aggregation task, which include the index I, the aggregation function F of the non-constant term coefficients 1 , the aggregation function F of the numerator of the constant term coefficient 2 , the maximum value M of the denominator of the constant term coefficient, the first prime number q greater than M, and P 1 's public key P k ; (2) Data hiding, specifically including the following sub-steps: (2.1)P i Query the local data x sequentially according to the data serial number j of the index I j , and combine them into interpolation points (j, x j ); (2.2)P i Interpolate all interpolation points (j, x j ) to obtain the polynomial polynomial i , and the polynomial coefficients are C i,k (k = 0, 1,..., k - 1), and the constant term coefficient is C i,0 ; (2.3)P i Disclose other polynomial coefficients C i,0 except C i,k , and use the aggregation function F 1 with non-constant term coefficients to perform aggregation to obtain the aggregated value sumC k ; (3) Constant term coefficient security aggregation, specifically including the following sub-steps: (3.1) All participants P i The denominator denom of the privacy calculation constant term i The least common multiple lcm; (3.2) All participants P i Convert the constant term numerator molecular i to molecular i *lcm / denom i ; (3.3) All participants P i Perform a privacy sum on the constant-term numerator to obtain sumMolecular, and divide sumMolecular by lcm to obtain the aggregated value sumC of the constant-term coefficient 0 ; (4) Calculate the data of batch security aggregation, specifically including the following sub-steps: (4.1) According to sumC k and sumC 0 the aggregated polynomial sumPolyomial is obtained, and the value of the polynomial is calculated with the serial number i as the independent variable, which is the data that needs to be securely aggregated.
2. The batch security aggregation method based on blockchain according to claim 1, characterized in that, the step (3.1) includes the following sub-steps: (3.1.1) All participants P i Decompose the denominator denom according to the fundamental theorem of arithmetic i into a product of a finite number of prime factors (3.1.2) Calculate the maximum exponent max(denom i,l ), l = 1, 2, …, m for each prime factor one by one. The specific process of each calculation includes the following sub-steps: (3.1.2.1)P 1 Represent denom 1,1 as an M-bit binary string denom 1,1 Str, where the characters in the interval [0, denom 1,1 ) are 0, and the characters in the interval [denom 1,1 , M) are 1, and encrypt all the characters using P k ; (3.1.2.2)P 1 Send denom 1,1 Str to P 2 , P 2 Replace the [0, denom 1,1 Str] characters with 0 encrypted using P 2,1 , and repeat this step until P k ; n ; (3.1.2.3)P n Send the replaced denom 1,1 Str to P 1 , P 1 uses the private key S k to decrypt all characters, and the number of 0s is max(denom i,1 ); (3.1.3)P 1 Calculate to obtain the least common multiple lcm.
3. The batch security aggregation method based on blockchain according to claim 1, characterized in that, the step (3.3) includes the following sub-steps: (3.3.1)P i Use the Paillier encryption algorithm and the public key P k to encrypt molecular i , and send it to the smart contract. Use the aggregation function F of the constant term coefficient molecule 2 to calculate in the ciphertext state (3.3.2)P 1 Decryption Get sumMolecular, calculate sumMolecular / lcm to get sumC 0 .
4. A system of the batch security aggregation method based on blockchain according to claim 1, characterized in that, the system includes the following modules: Negotiation module: Each participating party negotiates the data that needs to be batch aggregated; Data aggregation module: Hide the private batch data in a polynomial by interpolation method, then publicly disclose and aggregate the non-constant term coefficients of the polynomial, and at the same time perform secure aggregation on the constant term coefficients; Calculate aggregated data module: Calculate the batch aggregated data from the aggregated polynomial.
Citation Information
Patent Citations
Space big data management method and system based on cloud service
CN111832059A
Methods for generating and executing smart contract transaction and device
WO2021114819A1